Bug Bounty Hunter · 19 Years Old · Algeria

Adem Ziane
Berroudja

At 19, #1 all-time in Algeria on Bugcrowd. 283+ vulnerabilities found at a 97.59% accuracy rate — top 1% globally across all severity tiers. Over half my submissions are P1 and P2 criticals: the kind that prevent data breaches, account takeovers, and system compromises.

Trusted across 35 Hall of Fame programs — 20 of them private, invitation-only engagements with real companies shipping real products. I find genuine, high-impact vulnerabilities in production systems and report them with precision. Web apps, APIs, Android, CTF — same standard across everything. Open for employment.

Alhamdulillah for everything.

#1
All-Time Algeria — Bugcrowd
283+
Vulnerabilities Found
50%+
P1 / P2 Critical Severity
97.6%
Submission Accuracy

Vulnerability Write-ups

In-depth breakdowns of real vulnerabilities discovered and responsibly disclosed across private and public programs.

Experience & Achievements

A timeline of milestones across bug bounty platforms and security research.

All-Time Bugcrowd

#1 Ranked Researcher — Algeria

Second highest-ranked Algerian bug bounty hunter of all time. Ranked #376 globally with 1,607 points and 97.59% accuracy across 283 vulnerabilities.

All-Time Bugcrowd

Hall of Fame — 35 Programs

Recognized across 35 Hall of Fame programs — 20 private and 15 public — for consistent high-quality vulnerability submissions at critical impact levels.

All-Time HackerOne

464 Reputation — 10 Vulnerabilities

Active on HackerOne with 12 credits earned and consistent submission streak. Open for employment opportunities through the platform.

Ongoing Independent

Security Research & Content

Published multiple technical write-ups on Medium covering OSINT, web security, API vulnerabilities, and bug bounty methodology. Active CTF competitor in web, machine, and OSINT categories.

Skills & Focus

Specialized areas of offensive security with hands-on experience across real production targets.

Web Application Security

XSS, SQL injection, CSRF, SSRF, RCE, IDOR, authentication bypass, business logic flaws, and chained exploit development.

API Security Testing

REST and GraphQL assessment, JWT manipulation, rate limiting bypass, mass assignment, and insecure endpoint discovery.

Android Application Testing

APK reverse engineering, insecure data storage analysis, intent-based attacks, WebView vulnerabilities, and client-side security review.

Open-Source Intelligence (OSINT)

Google dorking, passive reconnaissance, data leak discovery, open-source intelligence gathering, and footprinting.

CTF Competitions

Web exploitation, OSINT challenges, reverse engineering, and machine-based capture-the-flag across multiple platforms.

Development & Scripting

Front-end development, JavaScript, Python for exploit and tool development, and Bash scripting for automation and recon workflows.

Code Review & Analysis

Manual source code auditing across PHP, Python, and JavaScript to identify logic flaws, insecure implementations, and vulnerabilities that automated scanners miss.

Technical Writing

Vulnerability disclosure reports, methodology write-ups, and educational content for the security community on Medium.

Where to Find Me

Active across major bug bounty platforms, professional networks, and the security community.

Contact

Available for full-time roles, freelance consulting, and responsible disclosure collaboration.

Let's work together.

I'm open to security roles, consulting engagements, and collaboration with other researchers. If you're building a security team or need a dedicated bug bounty hunter, reach out.