hi, we're Heartbreaking
a bunch of security researchers who also happen to be friends!
preview build: most writeups are still on their way. for CVP review, I can share the underlying reports or preliminary details on request at contact@heartbreak.ing.
we find some weird shit, then take the rest of us along for the ride
funny logic issues
How to keep a stolen Discord account permanently – ft. Dolfieswriteup pending
lost your account? recovered it via support? no you didn't!
glaring management and PR issues
How a 9 month '// TODO' led to breaking Discord's E2EE (DAVE) in six pieces – ft. Ashwriteup pending
a random comment on an innocent .cpp file, followed by a better audit than Trail of Bits
scaled (and Distributed!) Denial of Service with just a few thousand links
How to IP ban someone from Cloudflare and Discord via... their Shop – ft. Jay Taelienwriteup pending
who said you had to burn their router to stop them from using the internet?
we also have your average token cybersecurity researcher experiences
token supply chain vulnerability ft. eva and daniel
how to hack discord, vercel and more with one easy trick
our first at-scale collab ft. CVE-2025-67842, CVE-2025-67843, CVE-2025-67844, CVE-2025-67845, and CVE-2025-67846
token CISO/security team denial, threats, and drama
XSS protections? What are those?
an embarrassment in modern XSS security ft. Twitter a/k/a X, and Cursor
token HackerOne Triage experience
How NOT to triage a regressed, cache-reliant bug fixwriteup pending
the underlying report is available to CVP reviewers on request... much thanks to Valve and percybysshe for taking over <3
token Bugcrowd Triage exp-
ah wait, one of us is banned from Bugcrowd for leaking public, exposed sourcemaps, whoops