
When IP Whitelisting Isn't What It Seems: A Real-World Case Study from the Binance API
A case study on how Binance's listenKey design bypasses IP whitelisting, why Bugcrowd dismissed it, and what this teaches us about API secur...

A case study on how Binance's listenKey design bypasses IP whitelisting, why Bugcrowd dismissed it, and what this teaches us about API secur...

2026-04-29 — A fake recruiter tried to walk me into opening a malicious VSCode workspace.I refused, preserved the artifacts, mapped the infr...

I wanted to re-open an old Binance API security issue. Not because I enjoy re-litigating old reports. Because the last thirteen days made th...

Operation Endgame disrupted 326 servers and 142 domains. Three months after disclosure, the StealC malware routes I documented still respond...