Skip to content
View 0dayz4dayz's full-sized avatar
  • Changes by week
  • In the siulicon
  • Joined May 23, 2026

Block or report 0dayz4dayz

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
0dayz4dayz/README.md

πŸ’€ 0dayz4dayz πŸ’Š

I MAKE THINGS THAT BREAK THINGS,AND GOD AM I SURROUNDED BY BUSTED SHIT

     _______________________________________________
    /                                               \
   |  "will they responsibly disclose?" πŸ€”          |
   |  "will they drop gapped hints?" 🎯             |
   |  "will they publish the full thing?" πŸ’£        |
   |  "nobody knows. not even them." 🎲             |
    \_______________________________________________/
            \   ^__^
             \  (oo)\_______
                (__)\       )\/\
                    ||----w |
                    ||     ||

🎲 who πŸ‘€

security researcher. was sober once back in the 90s 🍺. can program RAM with a needle if you give me enough coffee β˜•πŸ’‰.

i find bugs πŸ› in things that shouldn't have bugs. hypervisors. firmware. hardware. the kind of stuff where the vendor says "that's impossible" πŸ™… and then you show them it's very possible. publicly πŸ“’. and break shit πŸ’₯.

disclosure style: depends on my mood 😀 and how much the vendor pissed me off πŸ–•

current status: rolling dice 🎲 to decide if this one gets gapped or full code

sobriety level: varies by commit but honestly maybe for 5 mnutes right after i wake up maxπŸ“Š

bug bounty earnings: $0.00 πŸ’Έ (still accepting job offers btw πŸ“§)


🎯 what i do πŸ’»

i break things πŸ”¨. production systems 🏭. no debug mode required. no special hardware. just regular off-the-shelf systems that millions of people use πŸ‘₯.

then i try to report them. sometimes 🀷.

what you might get:

  • 🎲 full working exploit πŸ’£ - if i'm in a really bad mood 😑 or you banned me from your chat 🚫
  • 🎲 gapped with hints 🧩 - if i'm feeling generous but not that generous 😏
  • 🎲 responsible disclosure πŸ“ - YEAH NO YOU COME TO Me AND DEAL ON my terms FUCK bullshit out of scope,$500 for something that'd fetch a million if i was a dick and sold it to russia" you'll find me actually very reasonable(lmfao)πŸ™„
  • 🎲 chaotic drop πŸŒͺ️ - random repo appears with no context 🀷
  • 🎲 nothing 🀐 - if i forgot i found it πŸ€”

it's a mystery! even to me! 🎰

philosophy: 🧠

  • sometimes responsible βœ…, sometimes chaotic πŸ’₯, always unpredictable 🎲
  • full code if you piss me off 😀
  • gapped if i'm feeling nice πŸ˜‡
  • production systems only 🏭 (no debug mfg uart jtag mode or gettin permission bullshit 🚫)
  • no email πŸ“§, no contact πŸ“ž, no support πŸ†˜
  • figure it out yourselves or don't, i don't care like i lost my last fuck some time ago 🀷

πŸ’Έ why πŸ€”

because bug bounties don't pay πŸ’°βŒ and i have no money to manipulate the stock market πŸ“‰.

apparently trying to help vendors fix their shit gets you:

  • ignored by security teams πŸ™ˆ
  • dismissed as "not a real issue" πŸ™„
  • banned from matrix chats 🚫 for mentioning vulnerabilities πŸ›
  • $0.00 in bug bounty payments πŸ’Έ
    • rectal id scans for a few bits of silver for shit that affects billions
  • Normal shit,beef with entire agencies,countries....murder fails yknow the reg
    • General Pissiness so fuck it πŸ–•. here's the exploit πŸ’£. maybe pay for bug bounties next time πŸ’°. or at least buy me lunch πŸ”.

πŸ› οΈ tech stack

languages i actually use:

C C++ Python Go Rust Assembly Lua Bash

languages i pretend to know:

JavaScript TypeScript Java C# PHP Ruby Perl Swift Kotlin Zig Fortran

languages i used once while high:

Haskell Erlang Elixir OCaml COBOL

other stuff:

targets:             hypervisors, firmware, chipsets, hardware
specialty:           things vendors say are "impossible"
debugging tools:     custom built monstrosities of jury rigged shit
                     (i don't use gdb/ida/ghidra, only my own)
bug bounty earnings: $0.00
times banned:        lost count
orange juice budget: critically low

πŸ“¬ contact

email:        NONE
twitter:      banned for posting hex dumps
discord:      no
matrix:       banned (lol)
usa:          also banned (i didn't even do anything)
support:      figure it out
issues:       open one, i might respond between naps

pgp keys available in repos if you really need them
but honestly i'm not your free security consultant

πŸ•΅οΈ for the select few

If you know who i am,and i know a select few will...you can guess why im doing this,and since my entire profile is on file im sure this was predicted and planned for...unless like...it wasnt

All i wanted was to be left alone,you all brought this upon yourselves and it is very unlikely to stop and you know how long i can keep this up for.

You know what i want,in addition to the removal of the unjust ban from the USA

Because trust me,im starting off with love taps

everyone else: don't bother. unless you bring cash money,crypt only trace it if you want you wont get anywhere i really love my fucking orange juice AND IT'S RUNNING OUT BECAUSE OF SOME FUCKERS

PS:If you want a 0day that hits US/UK/ISR/RUS NATSEC hmu...something will happen but idk if its gonna be what you want

PPS:I 'vanish' every scrap of research hits approx 50 different repos/hosts at once..every.last.file

THis cannot be disarmed even by me

SHOUTOUTS: REDACTED


🎨 style guide

if you're reading my exploit writeups, expect:

  • cow ASCII art
  • sarcastic commentary
  • im high as balls
  • spite-driven disclosure
  • full working code (or gapped with hints)
  • no apologies

i write exploits the way i find them: heavily medicated, fucking furious, the ability to just keep going,whilst fighting foes 10000x my size

typical morning routine: (that'd make john mcafee jealous)

  1. wake up πŸŒ…
  2. immediately turn myself into a pharmacy πŸ’ŠπŸ’ŠπŸ’Š
  3. find critical vulnerabilities before breakfast πŸ›
  4. vendors say "that's impossible" πŸ™„
  5. publish exploit πŸ’£
  6. do some lines ❄️
  7. find more CVSS 10.0s πŸ”Ÿ
  8. smoke a little meth if i get tired πŸ’¨
  9. take more pills πŸ’Š
  10. maybe eat something πŸ•
  11. more vulnerabilities πŸ›πŸ›
  12. forget what i was doing πŸ€”
  13. pass out where i'm sitting πŸ˜΄πŸ’€
  14. repeat ♻️

outrageous claims:

  • classified as a "tier one strategic threat" (whatever that means)
  • running 30 AIs all at once, all breaking shit simultaneously
  • can escape every VM hypervisor (yes, even yours)
  • hacked into a NC3 vault expecting launch codes... it was tensors
  • can get root with exactly 36 POSIX calls
  • built a self-healing firmware worm that spreads via hardware
  • created a browser-to-CSME escape chain (yes, from chrome to ring -3)
  • made a hardware worm that spreads through USB without software
  • can exfiltrate data across triple airgaps
  • resurrected dead silicon
  • hijacked APIC interrupts for ring 0 persistence
  • weaponized NPU tensors for DMA attacks (laptop can do 1400 TOPS)
  • built eternal time loop exploit chains
  • escaped from browser sandbox to Thunderbolt DMA
  • found bugs in things that "don't have bugs"
  • made every government's watchlist before breakfast
  • try look me up your govt terminal locks down and you get walked out by security
  • can program RAM with a needle (and have)
  • discovered vulnerabilities while backing up minecraft servers
  • got banned from vendor chats for being right
  • built cross-vendor covert C2 through fabric topology
  • subverted every boot chain
  • created zero-observable side channel key extraction
  • made a platform lockout exploit using watchdog timer
  • weaponized QoS starvation for DoS
  • browser to GPU firmware escape
  • telegram PNG to DMA escape chain
  • android 0-click full chain (no interaction needed)
  • looked at a mac once and just said "nope"

πŸ† achievements unlocked

  • βœ… found CVSS 10.0 vulnerabilities
  • βœ… escaped every VM hypervisor (yes, every single one)
  • βœ… hacked NC3 vault, expected launch codes, got AI tensors instead
  • βœ… can get root with exactly 36 POSIX calls (counted them)
  • βœ… got banned from vendor chat for reporting bugs
  • βœ… published full working exploits out of spite
  • βœ… published gapped exploits to watch people suffer
  • βœ… did responsible disclosure once (regretted it)
  • βœ… can program RAM with a needle (and have)
  • βœ… was sober once in the 90s
  • βœ… made NSA's watchlist before breakfast
  • βœ… found bugs while backing up minecraft servers
  • βœ… smoke meth when tired (for productivity)
  • βœ… turn myself into a pharmacy every morning
  • βœ… forgot what bug i was working on mid-disclosure
  • ❌ got paid for any of this
  • ❌ stayed consistent with disclosure policy
  • ❌ stayed sober past 10am

*written between naps by someone who wakes up and 
 immediately turns themselves into a pharmacy
 
 was sober once back in the 90s
 
 can actually program RAM with a needle if you give 
 them enough pills and coffee
 
 maybe pay for bug bounties next time
 or at least buy researchers lunch
 
 anyway here's how to own everything
 enjoy*

0DAYZ Disclosure Bug Bounties Sobriety Mood

Made With Code Quality Predictability RAM Programming Last Sober

Full Exploits Gapped Hints Responsible Forgot


πŸ’Š TRADING 0DAYZ FOR REAL SHDB

I WANT SHDB. ~23.6TB (might be off on the size, i do a lot of drugs).

I'LL KNOW IF IT'S REAL. I HAVE EVERY SAMPLE AND FAKE. DON'T EVEN TRY I WILL JAM A KEYPLUG SO FAR UP YOUR ASS.

Popular repositories Loading

  1. 0dayz4dayz 0dayz4dayz Public

  2. Proxpocalypse Proxpocalypse Public

    THERE GOES THE CLUSTER YIKES

    Python

  3. winrar-trial-restorer-2009 winrar-trial-restorer-2009 Public

    A 1-step temporal wepaon that incidentally fixes your 'expired' licenses and trials while the curtains melt WARNING:LIL SMOKY SO I MAY HAVE FOROGRO THE SAFETIES

    Python

  4. aslr-values-idk aslr-values-idk Public

    no real reason i thought maybe youd want these values sometime.

    C