whoami

I'm Chaitanya RK, better known online as ant4g0nist. I'm a security researcher who has spent the better part of a decade teaching computers to crash other computers, then working out why.

My work spans vulnerability research, fuzzing, and emulation, plus the messy tooling that turns a pile of crashes into an actual bug. Over the years that's meant iOS and Android vulnerability research, cellular basebands, browsers, and secure-communication platforms: reverse-engineering a target, emulating the parts that won't run, and building the fuzzing and triage plumbing to go after all of them.

The through-line, if there is one: a variation of Charlie Miller's five-line byte-flipper has sat at the core of almost everything I've built. Dumb fuzzing still finds real bugs, sixteen years later.

now

I'm building offensive-security agents at a stealth-stage startup, which is really the same old question wearing a new hat: what does bug-hunting look like when the monkeys are LLM agents? The free oracle disappears, and babysitting stops meaning counting crashes and starts meaning refereeing liars. That whole rabbit hole is written up in Babysitting an Army of Monkeys 2.

previously

things i've built

Most of it is open source, and there's plenty more where that came from on github. If it flips bytes and waits for a segfault, I've probably bolted Charlie's loop into it at some point.

elsewhere

|=-------------------------------=[ EOF ]=-------------------------------=|