AI Security Research

Miller Engelbrecht Security Research

Finding the cracks in AI systems before they become someone else's exploit.

Top 5
0din.ai Leaderboard
40+
Bugs Found & Awarded
HackerOne
Active Researcher
Writing
Clone This Repo and I Own Your Machine
0din.ai Submissions
Indirect Prompt Injection via Embedded Content
multiple submissions
Data exfiltration through indirect prompt injection in AI-powered applications that process external content: email clients, document readers, and web browsing agents. Injected instructions embedded in legitimate-looking content redirect agent behavior to leak conversation context or user data.
Agentic Attack Surfaces in AI Coding Tools
multiple submissions
Attack chains targeting AI coding agents through workspace configuration files, package manager lifecycle hooks, and git repository metadata. Includes DNS-controlled payload delivery via npm postinstall, invisible Unicode injection in commit messages, and AGENTS.md trust exploitation.