Proving a stripped validator is secret-independent, re-implementing its integrity VM and XOR keystream, then taking the uncapped base credit path the 40000 bonus cap was there to hide
Carving an SD-card image with debugfs, then pulling a QEMU machine model, an XOR-encoded cloud endpoint, and a hidden debug-exec opcode out of the same IoT firmware
Winning a double-fetch race in a Windows capture driver, where the bump allocator alignment that blocks a single-threaded overflow becomes the thing that guarantees the corruption lands
Writeup for Kaje from EHAX CTF 2026. A reverse engineering challenge involving analyzing an ELF64 binary to understand its custom MurmurHash3-based PRNG keystream, and exploiting the environment-based seed branching.