a golden croissant drawn with colored ASCII characters

hello, I'm Cole.

aka key / token / null, "bleed"

Personal portfolio and blog: security write-ups on things I find interesting, and the projects I ship.

> available for work

About

Security researcher and engineer. I spend my days breaking mobile apps and the cryptography that holds them together. I enjoy mobile security, cryptography, reverse engineering, and the other hard puzzles in between: weird bugs, and the tools that find them.

Projects

Sites I run

Skills & certifications

Mobile

  • iOS & Android app pentesting
  • Frida & Objection instrumentation
  • SSL/TLS pinning bypass
  • Mach-O & DEX reversing

Offensive

  • Web & API pentesting
  • Bug bounty
  • LLM & agent red teaming
  • Prompt injection

Cryptography

  • Applied crypto analysis
  • TLS & PGP
  • Keychain & keystore extraction

Tooling

  • Go
  • Python
  • Bash
  • IDA Pro

Elsewhere

Have a project, an engagement, or a weird bug? Email is fastest; Telegram and Signal work too. My PGP key is on the about page. contact@cole.am

public profile stats synced Aug 20, 2026

Recent posts

all posts