Hello from Hackyboiz!
Our previous account was unfortunately suspended due to a thumbnail-related guideline violation. 😭
We've also spent the past few months reorganizing and preparing for a new chapter of Hackyboiz(season 2.), so it's great to finally be back and sharing research with everyone again.
Today, we're excited to introduce the first article in our Chrome Full-Chain Exploitation series.
Think of it as cultivating exploit primitives and gradually building a complete full chain. ⛰️
Wipeload(Wipe Payload for Building Exploit Primitives) Project
Ready to join the climb?
https://t.co/L9si5RugGT
#Hackyboiz #Wipeload #ChromeFullChain #BrowserExploitation #V8 #SandboxEscape #WindowsLPE #CyberSecurity
Our Pwn2Own Berlin 2026 journey — the results:
🥉 3rd place overall
💰 $95,750
🎯 5/5 entries successful
🔓 9 unique 0-days
⭐ Sole contestants on Chroma and Ollama
Targets down: Chroma, Megatron, Ollama, LiteLLM, Claude.
See you at the next Pwn2Own!
#Pwn2Own#P2OBerlin
After two setbacks, @yibarrack landed it on the last try — a successful exploit on Anthropic Claude Code at Pwn2Own Berlin 2026.
A real-world 0-day, ruled a collision on a subtle definitional call. We respect Anthropic’s judgment — they’ve been excellent throughout.
#Pwn2Own #P2OBerlin
@yibarrack just made it count at Pwn2Own Berlin 2026.
5 bugs, 4 of them 0-days, hours of relentless work — LiteLLM down for $17,750 and 3.75 MoP points.
The kind of result that only comes from not giving up. Huge respect.
#Pwn2Own#P2OBerlin
Seoul → Berlin. Pwn2Own 2026, our 3rd year in a row.
Out of Bounds is bringing 5 entries this year. Full schedule:
https://t.co/TDpkZepWXm
If you're at OffensiveCon, hit me up — happy to meet.
#Pwn2Own#OffensiveCon
Technical analysis of the TP-Link ER605 Pre-Auth RCE exploit chain by @yibarrack.
This writeup documents the reproduction of CVE-2024-5242, 5243, and 5244, detailing a 2-stage exploitation process to bypass ASLR on MIPS32 LE.
Full report: https://t.co/Wg9wz459e7