_jensec Profile Banner
Jenish Sojitra Profile
Jenish Sojitra

@_jensec

Followers
20K
Following
7K
Statuses
2K

BBH at HackerOne. $2M in Bug Bounties. Security at Exodus. Freedom Maximalist

India 🇮🇳
Joined July 2017
Don't wanna be here? Send us removal request.
@_jensec
Jenish Sojitra
4 months
Last month was my highest in bug bounty so far with almost $131k in bounty. Total paid reports: 18 Average reward: $7.3k Category: most were logical findings via reversing mobile applications and discovering internal endpoints leading to code execution and missing auth etc
Tweet media one
92
111
2K
@_jensec
Jenish Sojitra
4 days
@konfushon @fransrosen @albinowax @Rhynorater That’s not JSON injection
1
0
10
@_jensec
Jenish Sojitra
16 days
RT @halfin: Running bitcoin
0
43K
0
@_jensec
Jenish Sojitra
16 days
@jsn_yrty @crypt0grapherr Hard to say without looking full convo but looks like miscommunication
0
0
1
@_jensec
Jenish Sojitra
18 days
Finally remote workers realising bali is just touristic hell hole. Dirty and congested.
@marc_louvion
Marc Lou
19 days
Startup World Tour 🌎 has started! My wife and I are looking for a new place to live because Bali no longer fits. So we're slowly traveling the world until we find a place that clicks. We just landed in New Zealand (south). Next will be Japan, South Korea, India, and later this year, Europe and America. We'll also organize 1 meetup per country 🤝 To get informed about the upcoming events, join my Discord below!
Tweet media one
0
0
8
@_jensec
Jenish Sojitra
18 days
RT @jprichardson: The US should not have a strategic CRYPTO reserve. The US should only hold bitcoin. I'm one of the biggest proponents…
0
349
0
@_jensec
Jenish Sojitra
18 days
RT @soamjena: This was my home back then—a small town in Odisha, Rourkela, where I was born, grew up, and studied till class 12 (1988-2006)…
0
2K
0
@_jensec
Jenish Sojitra
19 days
No. Want to work with program who invest in hackers. Shows commitment
@Hack_All_Things
Roy Davis
21 days
If Zoom were to host an In-Person Live Hacking Event in Denver Colorado (USA) sometime over the Summer of 2025, during which over $500,000 in bounties were up for grabs, would you be willing to cover your own travel expenses?
0
1
20
@_jensec
Jenish Sojitra
26 days
@samm0uda @Meta @phwd_ @JosipFranjkovic @vulnano Consistency pays off. Great numbers. Congrats 🙌
0
0
9
@_jensec
Jenish Sojitra
26 days
@nmatt0 Great content, congratulations
0
0
4
@_jensec
Jenish Sojitra
29 days
RT @GodfatherOrwa: One more example for bad behavior / Scam in paid subscription for bugbounty I was there for…
0
31
0
@_jensec
Jenish Sojitra
29 days
RT @theabrahack: I just released a new blog post, in this post we take a deep dive into a Critical Local File Inclusion issue in the Charti…
0
6
0
@_jensec
Jenish Sojitra
1 month
Very common technique to drain crypto funds from developers these days. Stay safe
@cryptostaker22
cryptostaker | peanuts
1 month
Hey everyone, My Metamask just got hacked for ~13k USD today. Not sure if my credentials are affected as well, if anyone received something suspicious from me, don't click on any links or entertain them. My suspicion is on me running npm i and npm run start on a folder I downloaded 10 hours ago, which spun up the localhost. I didn't realize I was hacked until 10 hours later when I wanted to transfer some money elsewhere. It seems like my wallet is simultaneously drained from all chains (zksync, base, op, polygon, eth) My wallet address: 0x7c982E9563C6D6863eB62d65225530791cfDd341 Some malicious addresses: 0xcc9967aefced28d139a333ba15b7f8c60e0ef058 It all started when someone approached me on LinkedIn and asked me if I could do some audit work for him. Seems innocent. He wanted me to check his react app and will give me some solidity code to audit. I thought that was harmless enough, so I asked him for more documentations. He gave me a link to a gitlab folder with a react app and javascript. I don't know much about javascript but I know how to run npm i and npm start, so I did just that. I gave him my opinions on the website (it was really pretty shitty, I should have known something was up on hindsight), but the solidity code was nowhere to be found in the Gitlab link. I thought it was probably in another link, so I asked him for it. He did not reply. 10 hours later, I found out I was hacked. Post-mortem, I read through the javascript files and notice some connections here and there to web3js and Metamask. Still really don't understand what happened in the script. I really didn't expect to be hacked, especially coming from an auditing industry. What an irony. I thought I was safe enough, didn't download any executables and programs, made sure I kept my seed phrase safe offline, but I guess social engineering attacks finds its way. Note to all security auditors and everyone else out there: If you have to deploy something to a local server, make sure your Metamask is not connected to your browser. Try to use incognito every time as well. Even better, don't download and run any folders/file, and if you have to, make to log out of all your wallets and don't save anything in the browser. Also, I probably won't use LinkedIn anytime soon, what a letdown. Better get clients through the web3 connections. I thought I wanted to try something new. I know the money is probably gone forever and this is a pricey lesson, but if anyone is able to help or if anyone wants to know more information, please reach out to me. Also, I'd appreciate a share, ensure that nobody else fall victim to this type of hack as well.
2
3
17
@_jensec
Jenish Sojitra
1 month
RT @NYSE: "This bell rings for financial self-sovereignty." - JP Richardson, @exodus Founder & CEO. Check out the highlights from the Exodu…
0
59
0
@_jensec
Jenish Sojitra
1 month
Thailand 🇹🇭 is one of the best places in o live if you are working remotely, doing bug bounties or indie hacking. Great food 🍛 , spectacular beaches 🏖️ and international community of like minded people. Also highly affordable.
4
0
101
@_jensec
Jenish Sojitra
1 month
@jay_kaklotar72 Stay focused and disciplined
1
0
2
@_jensec
Jenish Sojitra
1 month
0
0
1
@_jensec
Jenish Sojitra
2 months
@rikeshbaniya @Hacker0x01 will do that at some point next year
0
0
1
@_jensec
Jenish Sojitra
2 months
@_zwink @Hacker0x01 while I 100% apply manual methods I have seen increasingly success with automation in other bug bounty hunters. I agree right place and right time matters.
2
0
15
@_jensec
Jenish Sojitra
2 months
@amanmahendra_ @Hacker0x01 On HackerOne, nope close to 1.5M. Overall yep
1
0
7