Web & API Testing
Deep manual testing of web apps and APIs — authentication, access control, business logic, and injection flaws.
Available for engagements & private programs
Bug bounty hunter & penetration tester focused on finding the high-impact vulnerabilities that matter before someone with bad intentions does.
I'm Wolfy — a bug bounty hunter and penetration tester.
I primarily work with casinos and GPT sites but have past experience with companies such as Red Bull, DHL and Telenet via their Intigriti programs
Deep manual testing of web apps and APIs — authentication, access control, business logic, and injection flaws.
Subdomain enumeration, asset discovery, and fingerprinting to map the full attack surface before going deep.
RCE, SSRF, LFI, IDOR and access-control chains — the findings that actually move risk, with reproducible PoCs.
Impact-first write-ups with reproduction steps and remediation guidance triagers and engineers can act on.
Kind words from people I've worked with across the community.
Got a program, a target, or a security question? Reach out — I'm happy to talk scope.
Discord @wolfyyy___ Intigriti @wolfy6848 X / Twitter @wolfy6848