Hello, I'm keybleed.
Personal portfolio and blog: Write-ups on things I find interesting, and the projects I ship.
About
Security researcher and engineer. By day I do crypto security for an unnamed company: I enjoy reverse engineering apps, mobile security, and llms.
Projects
nibkit
iOS NIB/XIB/Storyboard decompiler in Go: object trees, outlet and action wiring, segue graphs, plus an MCP server so agents can drive it.
pocketmind
Local-first AI assistant for Android: GGUF model chat, an on-device RAG knowledge base that cites your own files, and sandboxed long-running agents. No cloud, no account.
Sites I run
Untrust Labs
Account intelligence: resolve an email, phone, username, or crypto address to its accounts, plus on-demand virtual investigation devices.
Nullsec
A mobile reverse-engineering playground: dynamic research devices, agents, and an orchestrator for breaking mobile targets.
keysto.re
A Tor-only marketplace and anonymous LLM compute service. Onion-only, no logs, Monero only.
Skills & certifications
Mobile
- iOS & Android app pentesting
- Frida & Objection instrumentation
- SSL/TLS pinning bypass
- Mach-O & DEX reversing
Offensive
- Web & API pentesting
- Bug bounty
- LLM & agent red teaming
- Prompt injection
Cryptography
- Applied crypto analysis
- Keychain & keystore extraction
Tooling
- Go
- Rust
- Bash
- Swift / Kotlin
- IDA Pro
- CompTIA Security+ CompTIA
- CompTIA Network+ CompTIA
- OSCP OffSec
Services
Penetration testing
iOS and Android apps, web, APIs.
Reverse engineering
Binaries, protocols, Large Projects.
Tooling
Research and automation tools in Go and Rust.
Consulting
Advisory, secure code review.
Elsewhere
[email protected]
public profile stats synced Aug 31, 2026