mny.lol INDEPENDENT / SECURITY RESEARCH
RESEARCH WITH PERMISSION.NO AUTOPILOT. NO SHORTCUTS.

researcher@mny:~$ whoami

Question
everything.
Stay in scope.

Independent security researchers & bug bounty hunters. We find vulnerabilities in authorized programs and report them so they get fixed.

hello@mny.lol

MODEL-ASSISTED. HUMAN-VERIFIED.

01 — EXPLORE02 — VERIFY03 — DISCLOSESCROLL TO READ

Tools do the heavy lifting.
People make the call.

Language models help us look closer.
Responsibility stays with us.

[01]

research.assist()

Look deeper.

We use language models to review code, triage potential issues, and draft clear reports.

[02]

human.verify()

Prove the finding.

A person checks every finding before submission. Models are tools, never autopilot.

[03]

report.private()

Help get it fixed.

Actionable reports go privately to the affected program, with time for the vendor to fix.

// NON-NEGOTIABLE

Permission first.
Always.

Good research respects the system
and the people behind it.

01

Explicit scope.

Only in-scope targets, under each program’s published rules.

REQUIRED
02

Respect the limits.

Follow rate limits and testing restrictions. Stay within the agreed boundaries.

REQUIRED
03

Minimum data.

No access to or retention of data beyond what’s needed to demonstrate an issue.

REQUIRED
04

Coordinated disclosure.

Report privately. Give the vendor time to fix before anything is public.

REQUIRED

researcher@mny:~$ mail hello@mny.lol

Let’s compare notes_

hello@mny.lol

For programs, questions, and responsible disclosure.