Available for work

Kenji Subagja

Bug Hunter & Backend Engineer

I break backend systems for a living — auth flows, APIs, access control — then write it up properly for the team that has to fix it. Off the clock, I'm building the same kind of systems I spend my day trying to break.

33 valid reports · 14 critical & high severity · 3 years in backend engineering
About

I build backend systems, then try to break them.

I started as a backend developer — APIs, databases, auth, the plumbing most people never see. Building that plumbing made me curious about exactly where it cracks, which is what pulled me into bug bounty.

Those two things run in parallel now. When I'm shipping a feature, I think about how I'd attack it. When I'm testing someone else's system, I think about the engineer who has to patch it by tomorrow morning.

I run private and public bug bounty programs, take on backend contracts on the side, and occasionally write up interesting findings once disclosure allows it.

Stack

What I actually work with

No frontend frameworks — this is the offensive-and-backend half of the stack.

Languages
Go, Python, TypeScript, PHP, Bash
Backend
Node.js / Express, REST APIs, gRPC, GraphQL
Data
PostgreSQL, MongoDB, Redis, MySQL
Security
Burp Suite, Nuclei, Nmap, OWASP ZAP, SQLMAP, custom recon tooling
Infra
Docker, Linux, AWS
Vulnerability disclosure log

33 valid reports and counting

Real findings across the bug bounty programs I've tested.

33total valid
Critical7High7Medium5Low14
SeverityTitleProgramDate
CriticalTrustPay webhook forgery grants free subscriptionGirlfriendGPTAug 2026
CriticalWebhook race condition mints unlimited coinsGirlfriendGPTAug 2026
CriticalBOLA self-grants EDITOR on any documentLuminPDFAug 2026
CriticalPrivilege escalation to super-admin of any companyTrack3DAug 2026
CriticalIDOR by NIK leaks full PII and plaintext passwordsPratamaJX2Apr 2026
CriticalPath traversal to arbitrary file read and RCESawahluntoApr 2026
Page 1 of 6
Experience

Short version

Freelance Backend Engineer & Security Researcher

2022 — Present
Independent

while building small tools on contract for individual clients and community use, Taking private bug bounty invites and running public disclosures as a security researcher.

Contact

Have a system that needs testing, or a backend that needs building?

Open to private bug bounty programs, security research collaborations, and backend contract work.