hi, we're Heartbreaking

a bunch of security researchers who also happen to be friends!


preview build: most writeups are still on their way. for CVP review, I can share the underlying reports or preliminary details on request at contact@heartbreak.ing.

we find some weird shit, then take the rest of us along for the ride

funny logic issues

How to keep a stolen Discord account permanently – ft. Dolfieswriteup pending
lost your account? recovered it via support? no you didn't!

glaring management and PR issues

How a 9 month '// TODO' led to breaking Discord's E2EE (DAVE) in six pieces – ft. Ashwriteup pending
a random comment on an innocent .cpp file, followed by a better audit than Trail of Bits

scaled (and Distributed!) Denial of Service with just a few thousand links

How to IP ban someone from Cloudflare and Discord via... their Shop – ft. Jay Taelienwriteup pending
who said you had to burn their router to stop them from using the internet?


we also have your average token cybersecurity researcher experiences

token supply chain vulnerability ft. eva and daniel

How we pwned X (Twitter), Vercel, Cursor, Discord, and hundreds of companies through a supply-chain attack

how to hack discord, vercel and more with one easy trick

our first at-scale collab ft. CVE-2025-67842, CVE-2025-67843, CVE-2025-67844, CVE-2025-67845, and CVE-2025-67846

token CISO/security team denial, threats, and drama

XSS protections? What are those?
an embarrassment in modern XSS security ft. Twitter a/k/a X, and Cursor

token HackerOne Triage experience

How NOT to triage a regressed, cache-reliant bug fixwriteup pending

the underlying report is available to CVP reviewers on request... much thanks to Valve and percybysshe for taking over <3

token Bugcrowd Triage exp-

ah wait, one of us is banned from Bugcrowd for leaking public, exposed sourcemaps, whoops