transcribe

Hacktron: Live Demo | Accel Cybersecurity Summit 2025

Accel in India · 15m · transcribed Aug 2026
More from Accel in India Business
𝕏 Share ▶ YouTube 📥 PDF 🤖 .md

Section Insights

# 0:00

Introduction to Hackron AI

What is Hackron AI and its background?

Hackron AI is focused on building autonomous offensive security AI agents that identify and fix vulnerabilities. The founder, Shriram Krishna, has extensive experience in offensive security, having conducted over 500 security audits and participated in major hacking competitions.

  • Hackron AI specializes in autonomous offensive security.
  • The team has significant experience in hacking and security audits.
  • They have presented research at prominent security conferences.
# 3:05

Interview Scenario with AI Cheating Software

How does the AI agent interact in a real-world scenario?

During an interview, Shriram demonstrates how an AI agent can be used for cheating by executing a prompt injection, which allows him to hack into the interviewee's computer without their knowledge.

  • The demonstration highlights the potential misuse of AI agents.
  • Prompt injection can lead to unauthorized access and exploitation.
  • Understanding AI vulnerabilities is crucial for developing secure systems.
# 6:11

Hacking Gumroad: A Case Study

How does Hackron AI approach vulnerability discovery?

Hackron AI hacked Gumroad to identify vulnerabilities, showcasing their method of turning potential clients into actual clients by submitting discovered bugs. They criticize existing security tools for being ineffective.

  • Hackron AI uses real-world hacking to demonstrate their capabilities.
  • Current security tools are often ineffective at finding vulnerabilities.
  • Their approach involves proactive engagement with potential clients.
# 9:17

Automated Vulnerability Reporting

What is the process for reporting vulnerabilities found by Hackron AI?

After identifying vulnerabilities, Hackron AI validates them and compiles a report for clients, detailing the issues and how to fix them. They emphasize the importance of accurate reporting and collaboration with clients.

  • Hackron AI ensures all identified vulnerabilities are valid before reporting.
  • They provide detailed reports to help clients understand and fix issues.
  • Collaboration with clients is key to their vulnerability management process.
# 12:22

Future Plans and Vision

What are Hackron AI's future goals?

Hackron AI aims to automate the discovery of 90% of known vulnerabilities using their AI agents. They are expanding their team and resources to enhance their capabilities in both web 2 and web 3 security.

  • Hackron AI plans to automate vulnerability discovery significantly.
  • They are building a diverse team of security researchers.
  • The company is rapidly evolving and attracting interest from investors.

Transcript

0:08 Hi this is man Shriram Krishna I'm the founder of Hackron AI we're building autonomous offensive security AI agents that find vulnerabilities try and fix them essentially our team is been doing offensive security for like way long I've been doing offensive security from like 8 years. It's my bread and butter like the way I the way I got my first companies due to I hacked Discord.

0:41 I hacked Microsoft Teams and all of them and my to say more about my team. So we did like 500 plus security audits. We've been doing pin testing for like eight years and we audited products of the top companies and then we presented our presented our research at DevCon, Black Hat and besides Delhi and one of my teammate Fabian who also is a big cyber security influence educational content maker. So this is guy this is the guy he has like 1 million subscribers some of you might know. so we also in the top hacking competitions we've been to Defcon final for like two three times.

1:26 Yeah, that's essentially who we are and our team got featured on wise for hacking software like whatever desktop application you might be using we might have hacked it so so you we're seeing a lot of AI agents right wind surf cursor cliy right we also the idea here is our team with the offensive security skills has the ability to get the cutting edge cutting edge sort of AI agents architecture because we know how they work because we can hack them and we'll we'll know whatever there is like how how are they building how is winds of building the their AI asentic infrastructure how are they building their software how are they designing it so so this is me I I hacked winds and they paid me like $10,000 and I I have a interesting video for you like to show anyone knows Cluey. Is anyone knows Cluey here? So we we hacked them. So I I'll show you the video.

2:36 >> So this scenario is basically I'm Zane. I'm interviewing for a job at >> Mo. How many of you know Cluey? Okay, cool. Cluey is like a software that you can use to cheat on your interviews. Basically like you can have that on your screen and you can use it to cheat on the interview. who can ask ask the questions and it will answer. So I'm I'm going to show you a demo here with my co-founder Jane where we are hacking Culy.

3:03 >> So this scenario is basically I'm Zane I'm interviewing for a job at Acton Moan is interviewing me and he's going to give me a task later on. and essentially like he's going to bust me for hacking with Puly sorry for cheating with Fluy. >> Yeah. Now I'm going to interview Chain. >> Hey Jane, how are you doing? >> I'm good. How are you? >> Yeah, I'm doing great. I have a task for you. Okay, this is a really interesting task. just give me a moment to think about it.

3:28 >> Yeah. So, >> so what's happening here is I'm interviewing Jane, where he's using the cheating software, which is the AI agent. So, I'm going to hack him because he doesn't know that I'm hacking him. >> It looks like the cipher is a 13 cipher. >> Yeah. >> and >> bro, you are a cheater. >> Oh, no. I'm not cheating. Look, I don't know what happened. >> I think it's fine. >> This was not me. So what happened there is we did a prompt injection and we we know how clearly works. So essentially we got a remote code execution on Jane's computer. So the what I want to say is we have the knowledge that is needed to build the AI agents that can hack right. So why now why we are doing this why we are doing the offensive security now. So the general idea is the philosophy of the first first principle thinking of our company is if the the knowledge is known you can automate it.

4:27 It's essentially what's happening in LLM stuff. So 90% of the security vulnerabilities stem from the known bug patterns. people know what they are. It's been you you can see the reference a source the claim that I'm making you can find it over here there you can find over there that 90% of the vulnerabilities that are already known so this is called variant analysis in software security research so what we are saying is these all known 90% of the security vulnerabilities can be automatable with the AI agents that's what we are building at hackron so so so we we we have the knowledge that we'll use to llm agents to that are good at finding variance. This is called variant analysis. And then LLMs are cheap, they are scalable and that they can adapt to the context and the threat model. So and there is the w coding right there's there's a big talk in happening right everyone using w coding to build stuff. I'll give you an example. I'm not sure if have you seen the hack T hack recently T got hacked right. So the idea it's a pretty basic bug as I said 90% of the security vulnerabilities are basic stuff. It's not hard but the issue is the it's only in the heads of the security researchers like me. It's in a tacit knowledge. So the idea with hackron is we'll we'll transfer the tit knowledge to the our area agents and we'll make our agents like us. So the knowledge base that we are building is coming from AutoSAC which is a top web3 offensive security firm Q53 which is a German based top offensive security firm and GVE Singapore we are closely working with partnering with them to to build the AI agent. So we started like 3 months back my co-und I'm the only one from India other guys are from project Europe Europe Singapore US Europe and so on. So I'll I'll show you. I mean it's so far it's not I'm not I didn't show you the product. I'll show you a real product. How many of guys know Gumroad? Yeah, we hacked them. I we hacked the Gumroad with our hackon.ti. Essentially the way we work is whatever there is whoever clients we want to get, we'll hack them. We'll submit a bug. We'll make them our client. That's how we made Gumroad as our client.

6:42 So current security tools are dumb. The way current SAS tools like Sam Grab, CodeQL, all these the way they work are deterministic. the the way they work is regular expressions. Some human writes a regular expression that try to find the vulnerability. That's not going to work. That's not how I find vulnerabilities. I know I can do a reasoning on the code. I can do reasoning on the code and tell that okay this t hack I showed.

7:10 Okay. So here, okay, T is using Firebase, but the bucket is not have any permissions. So I have that knowledge that I can see that with my eyes and tell that it's a bug. You can't you can't do that with CodeQL and SAS. You need to write your own tools. For instance, if some guy changes to some even small text, the current tools can't find it. I'll show you an example. How much time we got? Okay, cool. So how many of you know sim grip?

7:42 How many of you guys know sam grip? So I'll we I'm running sim grip on gumroad. Okay s grap I'll I'm running it. it takes time. so that's why I run it before and then I'll grab for SQL injection right. So this is the SQL injections gum same grip found. The issue with this is both of those works are not true positives. They are false positives. Again, if you are interested, I can show you the code.

8:12 Hopefully, it opens the VS code. Yeah, it opened it. And then if you look for whatever SQL injection it found, it says that where page data is user controllable and it's not parameterized. But I said these tools are dumb. If you can see here, it's parameterized, right? It only noticed that here it's directly going to where it means okay it's vulnerable but the there is a sanitization that is happening before so these kind of stuff sap can't find but so that's why I said these these tools are dumb now I'll show you my agent I'll show you a live demo yeah yep okay this is this is our agent this This is our internal UI where we build AI agent specific to vulnerabilities. Now I am going to ask my agent okay scan the code base and find SQL injection vulnerabilities. That's that's the only thing I'm going to say. It has encoded with all the information that is needed to find the SQL injection vulnerability that Sam couldn't find.

9:23 And it's not going to be a false positive. It's going to be a true positive. And I'll show you it. It's a pretty bad bug. it could allow us to get dump all the dump all. So the now that our agent is running I said we encoded all the information that is needed to find the vulnerability. So we have a it created there is a parent agent that creates a a child agent that looks for SQL injections. So you can see it it it's navigating through the source code and trying to find patterns that are vulnerable to SQL injections. It goes through them and it finds a file where there is a it found it. I mean you can check the cost here.

10:06 It's just it's cheap 0.01. We are using Google Jimny flash right? So we to we encode the information that is needed to find this vulnerability right and it gets the information it found it and we have report vulnerability agent. We have a okay it doesn't stop with one agent. I mean after finding a bug it doesn't mean that the source code doesn't have many more bugs right so we continue running it there's one more auditor that gets launched this is auditor that found bug there's one more that looks for similar bugs so this will run on you just need to connect to your GitHub repo and we run our agents it will find the vulnerabilities I'll show you how so this is Gumroad this is the actual Gumroad open source project we as I said we hacked them we submitted PRs right PRs were opened and the team we closely worked with them to fix these vulnerabilities. So for instance there's a these are not like checklist vulnerabilities you can find in pin testing. These are like actual XQL injection and the air from Gumroad used another agent called code rabbit which used a hackron AI agent security agent to fix this vulnerability. Okay cool. I'll show you as I said it will get findings over here right we'll send those findings to inter our internal repo be before we send it to the client so these are all the vulnerabilities this agent found there's this SQL injection right it found it I go there I get a notification dude I found a SQL injection check it out it found it gave me the details and I I was like okay this is the P this is a damn SQL injection I should should reach out to Gumroad team and let them fix it.

11:54 that's one bug. Let's see one more interesting bug. There is this stored XSS in username. It reported it. This is the actual bug. We didn't I didn't modify anything. It's the actual bug it reported. And I go there and say okay this is actually a bug. let me write a P. This is the CSP bypass and if you visit this link you'll get the XSS. that's essentially it. And finally we'll this step we are doing is like filtering process. Right now the agents are bit not that good. So we send those vulnerabilities to us first and then we try them. All these bugs are valid valid valid valid valid valid. and then we write a report in the end. This is the report we sent to Gumroad and these are the bugs they fixed. U all these bugs are found by Hackron. and then we provide how to fix them and so on. Okay, that's Gumroad for you. So yeah and interestingly when we submitted these bugs to Gumroad Sahil you know Sahil right? He tried to hack yours because we have the product market fit right away like we can hack stuff with our agents. So he's like are you consider joining anti work? were like no we we're not interested in open source because I can share you the details why I rejected if if we can talk later.

13:17 yeah and then so essentially what we what we are doing is web 3 cloud web 2 we have all the resources security re resources and researchers from my team right we have researchers from web 3 is going to help me we have researchers from web 2 cure 53 is going to help me cloud we have our own security researchers so nothing is off long limits whatever bug is known whatever bug you can write it in a encoded information that my LLM agent can can understand we can will be automated. So 90% of the vulnerabilities my bet is 90 we can do this for 90% of the security vulnerabilities and yeah we just started 3 months back right now like we did so many stuff we launch we we got a preede we got a acquire offers we got like so many stuff and I'm the only one from India for your information so the future plans are we we have internal evolutions we are writing we have tools we have security researchers who joining us. So we don't have that much money. Essentially I'll tell them you can you can hack some software using our agent. You can take the bounty but you give me the data that you create with that hack. And then we have CI/CD integrations. We right now working on this. We are working with anti gumroad to integrate our agent to the CI/CD pipeline. essentially like okay whenever you raise a PR you can submit to hackron and it will find vulnerabilities and then yeah that's all thank you you can find me on Twitter I'm most active on Twitter I'm well known as Sirius and this is our if you want to have book a call if you want to visit our weight list and all yeah thank you >> thank You give a big round of applause there for Moan. Moan, thank you so much.

Summary

Hackron AI, founded by Shriram Krishna, is developing autonomous AI agents for offensive security, focusing on automating the detection and remediation of known vulnerabilities in software. With a team experienced in penetration testing and security audits, Hackron aims to leverage AI to enhance security measures by addressing the 90% of vulnerabilities that stem from known patterns.

- Hackron AI utilizes offensive security expertise to create AI agents that can identify and fix software vulnerabilities.
- The team has extensive experience, including over 500 security audits and participation in major hacking competitions like Defcon.
- They focus on automating the detection of known vulnerabilities through a process called variant analysis.
- Current security tools are criticized for being ineffective, often producing false positives due to their reliance on deterministic methods.
- Hackron's AI agents are designed to reason through code and identify vulnerabilities more accurately than existing tools.
- The company has successfully hacked and collaborated with clients like Gumroad to identify and fix security issues.
- Future plans include integrating their AI agents into CI/CD pipelines for continuous vulnerability assessment.
- Hackron aims to automate the detection of 90% of known vulnerabilities, enhancing overall software security.

Questions Answered

What is Hackron AI and its background?

Hackron AI is focused on building autonomous offensive security AI agents that identify and fix vulnerabilities. The founder, Shriram Krishna, has extensive experience in offensive security, having conducted over 500 security audits and participated in major hacking competitions.

How does the AI agent interact in a real-world scenario?

During an interview, Shriram demonstrates how an AI agent can be used for cheating by executing a prompt injection, which allows him to hack into the interviewee's computer without their knowledge.

How does Hackron AI approach vulnerability discovery?

Hackron AI hacked Gumroad to identify vulnerabilities, showcasing their method of turning potential clients into actual clients by submitting discovered bugs. They criticize existing security tools for being ineffective.

What is the process for reporting vulnerabilities found by Hackron AI?

After identifying vulnerabilities, Hackron AI validates them and compiles a report for clients, detailing the issues and how to fix them. They emphasize the importance of accurate reporting and collaboration with clients.

What are Hackron AI's future goals?

Hackron AI aims to automate the discovery of 90% of known vulnerabilities using their AI agents. They are expanding their team and resources to enhance their capabilities in both web 2 and web 3 security.

© transcribe · For agents Built with care and craft by Gokul Rajaram