case studies
Real exploits, found by the Muster engine.
Autonomous discovery against some of the most scrutinized platforms in the world, reported responsibly, with proof.
Muster found a full account takeover in Airbnb's HotelTonight infrastructure
The Muster engine identified a debug endpoint on HotelTonight's staging API that leaked password reset tokens in plaintext, enabling immediate, zero-interaction account takeover of any user, including access to PII and live authentication tokens.
Read case study →Muster discovered a vulnerability in Uber and earned a bug bounty
The Muster engine independently identified an infrastructure vulnerability exposing sensitive internal assets across Uber's attack surface, reported it through their bug bounty program, and received official recognition and a bounty award.
Read case study →Muster found an unauthenticated relay vulnerability in MetaMask's transaction infrastructure
The Muster engine identified a critical misconfiguration in MetaMask's tx-sentinel relay infrastructure that allowed any website to submit sponsored transactions on Polygon and Monad, with no authentication and fully permissive CORS.
Read case study →findings via public bug-bounty programs and client engagements · not affiliated with or endorsed by these companies