CYBERSECURITY · FULLSTACK · LEADERSHIP

pwn.college Orange Beltpwn.college Yellow BeltWanna check out my pwn.college history?

Breaking systems
to build resilient ones.

“If it works the first time, I get suspicious.”

Portfolio preview
0
0
1
0
1
1
0
0
1
0
0

Get to know me a bit?

About me and profile scan

I'm Pratham Hegde, an MS Cybersecurity student at Arizona State University researching at SEFCOM Lab, the Applied Cryptography Lab, and NYU's Secure Systems Lab. I spend most of my time finding out how things break -- through security research, penetration testing, and pwn.college challenges where things rarely work on the first try.

Profile Scanner

Education highlights

Background

Software Developer & Pwner

Barrett Honors College · Arizona State University

  • 4.18 GPA
  • 6× Dean's List
  • 3 degrees before turning 21
  • MS Cybersecurity, graduating May 2027
  • Fulton Schools IMPACT Award — 1 of 10 selected from 10,000 students
  • HackHarvard 2025 Winner
  • Applying to PhD programs, Fall 2027

pwn challenges

Encrypted Data

???

█████████████████

Challenge: knowledge

The first program almost everyone writes

Encrypted Data

???

█████████████████████████

Challenge: personal

What’s my favorite anime?

Encrypted Data

???

█████████████████████████

Challenge: personal

My favorite ice cream flavor

Fun Fact

I practice more than 5 forms of martial arts

> wm34igpaml
> 977m39yv8ld
> hysu0m301uq
> x6rnshoz6h
> pnxwmpknzpn
> pcdkxafz8n
> 99pyv1vris6
> aypuwxm4nfg
> czmjekyjwgu
> nahuldklo6
> mtkqsjo55be
> miagk0f9qvr
> gftqs5awmi6
> hb4eru9oh3t
> 77qhpl5vcfu
> myopz3pcds
> hkg593wic34
> hw8c7tr1b6f
> wk3iv7nuwmo
> yexxhcx3tqi
> zm4q43qi2j8
> b0chenwkshb
> idpcvcqcd9
> 0az178ydi6sr
> ktw85qfygkg
> 4cojqegol8e
> a0ns5creuvu
> a6ehsm85da8
> 64gzwdb2z8x
> f50ph6esnk
> p7tdrr2twd
> bdi2oqiz9nk
> 62eezyiyuef
> 3tdwaolpc9p
> ix61tpmgwl
> dydk4xochot
> kwuky6xj3r
> 5vb6up21vpr
> 5yiyp4u0pe5
> 1gsve14my4j
> 3cch5o8lgq9
> 25fr7h0kp2d
> waut6dpyawo
> kvabocahmgo
> nfnzdndbt
> my0tj9b9jbe
> 79sb3pcrs6m
> urjre6cf6e
> 4jlnwcg8o7
> odkvg9q6ybn

EXPERIENCE

NYU Secure Systems Lab

Graduate Researcher

New York, NY (Remote)

July 2026 - PresentResearch
>

Contributing to gittuf, an open-source supply chain security framework for Git built on TUF, incubating under the Linux Foundation's OpenSSF

>

Shipped multiple contributions fixing bugs in core RSL synchronization logic, annotation entry numbering, and silent error swallowing in commit operations

>

Completed a full docstring audit across ~55 command files to improve codebase documentation and developer onboarding

>

Investigating RSL annotation authorization as a liveness and DoS vector, supporting server-side implementation work under mentorship from a PhD student

>

Conducting structured code reviews using a three-layer framework: DCO/CI compliance, technical soundness, and code quality

ASU Career Services, Arizona State University

Management Intern

Tempe, AZ

Jul 2026 - PresentOperations
>

Supporting career services operations and program management using CareerLink (12Twenty), ASU's enterprise career management platform

>

Produced a 20-page job market research report analyzing employment trends and hiring patterns for international students, serving dual audiences of students and employer partners

>

Collaborating with program managers and associate directors on events, systems access, and student-facing initiatives

Todd Agriscience

Cybersecurity Intern

Tempe, AZ

Jun 2026 - PresentSecurity
>

Conducted a pre-start security assessment of the production web platform and internal Next.js monorepo, uncovering 8 confirmed findings across HIGH, MEDIUM, and LOW severity tiers

>

Audited the full application stack (Next.js App Router, Supabase, Drizzle ORM, Sanity CMS, Stripe, Cloudflare/Vercel) for misconfigurations, insecure data flows, and exposed attack surfaces

>

Delivered a structured vulnerability report to the CEO with remediation recommendations, prioritized by exploitability and business impact

>

Performed ongoing PR security reviews to catch regressions and enforce secure development practices across the engineering team

Applied Cryptography Lab, Arizona State University

Graduate Researcher

Tempe, AZ

Jun 2026 - PresentResearch
>

Implementing ZkLoRA: a zero-knowledge proof system for verifiable LoRA fine-tuning, enabling cryptographic proof that AI model adaptation occurred correctly without revealing model weights

>

Built a full backward pass stack with 8 ZK gadgets including SoftmaxBackward, GELUBackward, RMSNormBackward, AttentionBackward, and SGDOptimizer using the emp-zkml framework

>

Developed end-to-end training step tests at distilGPT2 scale, debugging activation range errors through weight initialization scaling

>

Research bridges zero-knowledge proof systems with practical ML deployment for trustworthy and verifiable AI

SEFCOM Lab, Arizona State University

Graduate Researcher

Tempe, AZ

Jun 2026 - PresentResearch
>

Designed and executed a security benchmark for AI-generated web applications, attacking 12 LLM-generated apps across 5 attack scenarios using a custom Playwright-based exploit verification pipeline and CAF metric

>

Key finding: security failures concentrate at integration boundaries rather than isolated logic, with missing rate limiting as the dominant vulnerability class across all prompt strategies

>

Worked on an evaluation framework for MCP server security (the tool-use protocol powering LLM agents), helping identify no-box attack surfaces including prompt injection via malicious tool descriptions and cross-agent trust boundary violations

University College, Arizona State University

Web Experience Designer

Tempe, AZ

Apr 2025 - Jul 2026Design & Development
>

Conceptualized and developed 10+ responsive web pages using ASU's branded design system, enhancing mobile usability and increasing user engagement

>

Conducted 20+ user research interviews and usability tests, leading to improved navigation flow and reduced bounce rates across redesigned pages

>

Oversaw front-end, back-end, and design efforts across UC's entire web portfolio, streamlining content workflows and accelerating site update processes

UNIUS

Software Development Intern

Remote

Aug 2024 - Dec 2024Development
>

Designed and optimized user-facing features using Next.js and React, resulting in a 30% reduction in page load times and improved user engagement across platforms

>

Collaborated with cross-functional teams to integrate front-end components with back-end APIs, ensuring seamless data flow and consistent feature delivery across deployments

< 66b103d771 />
< 406669171c />
< f0e0afac6f />
< 62387da57d />
< f731fecbd2 />
< 0939453861 />
< c84cf86c88 />
< 105985a258 />
< 18737580cc />
< 69efaac38a />
< a6b48dae50 />
< 3e015fe2b4 />
< c603c6bd6c />
< 16ca41dd91 />
< 71efdb424c />
< 0d5406d4e3 />
< 37b88a9606 />
< 6a8508a0d3 />
< d3cb4f3729 />
< b8568faa12 />
< a0160f9717 />
< 84a7db39ce />
< edf9a59290 />
< ebd3c5051b />
< bc4c9974cd />
< dce2b516fb />
< 5559326bee />
< b6a8647e27 />
< 8b4392d165 />
< 4d1916e1e5 />
< 3dbfcdf7ca />
< 7c835c184b />
< 3d6f14f8a7 />
< 50ca16224c />
< 5f0f6a6554 />
< 1d071a2584 />
< c1d51d07ba />
< 3712b9d781 />
< 02c03be80f />
< 535a1ecd11 />

$PROJECTS

Check out the projects that display me best.

FEATURED

Vibe Coding Security Benchmark

Honors Thesis · AI-Generated Code Security

Benchmarked 12 LLM-generated web applications across 5 attack scenarios using a custom Playwright-based exploit verification pipeline and CAF metric. Key finding: security failures concentrate at integration boundaries, not isolated logic bugs.

PythonPlaywrightFlaskExpressReact

> 12 apps · 5 attack types · published

FEATURED

YC API Penetration Test

Production Security Audit

Cold-emailed a YC founder, got pre-authorized API access, and confirmed a cross-tenant cache isolation vulnerability (CWE-200/208) reproducible 10/10 times. Full writeup published.

PythonBurp SuiteREST APIsCWE-200

> 10/10 confirmed · $300 bounty

FEATURED

SpectralQuant Security Benchmark

Original Research · KV Cache Attack Surface

Identified that the static calibrated eigenbasis in SpectralQuant creates a predictable attack surface. Targeted eigenbasis perturbations outperformed random noise in 91.7% of cases across 28 layers of Qwen2.5-1.5B.

PythonPyTorchQwen2.5NumPy

> 91.7% attack success rate

$TECH STACK

[01]

Languages

>Python
>Go
>JavaScript
>TypeScript
>C/C++
>SQL

6 TOOLS

[02]

Frontend

>React/Next.js
>TailwindCSS
>Bootstrap

3 TOOLS

[03]

Backend

>Django
>Flask
>REST API Development
>PostgreSQL
>MySQL
>Firebase

6 TOOLS

[04]

Security & Reverse Engineering

>GDB
>pwntools
>Burp Suite
>Reverse Engineering
>Playwright
>Shell Scripting
>Linux
>Git

8 TOOLS

[05]

Cryptography & AI

>Zero-Knowledge Proofs
>emp-zkml
>PyTorch
>TensorFlow
>LLM Integration
>Prompt Engineering

6 TOOLS

[06]

Core CS

>DSA
>Automated Testing
>Debugging
>TUF / Supply Chain Security

4 TOOLS

// zh4j5aiuip
// 46uzuvcat1
// 9huwfi5ijn
// t7guvi3109
// 0bhn3u6a0f
// vted3kz08h
// b8468tnhud
// z77968bp09
// 1sklj579wb
// dlnh204pv2
// 4x4nrycdpg
// swgte4vplu
// 05zhxpb6aw
// g4rjo3ld8q
// 24j5yt18c3
// 391vzd11d2
// msuutcz7nf
// kxlte6crk1
// myahbw180b
// 8gizjn3sjv
// d214t7hgd9
// bj6cwy8mhx
// ntgs439vvb
// ih6xfa4dgh
// 5cpcov5310
// wet30b4xxv
// iki9tvmi9n
// h5tswypbqn
// 7ix6df40fg
// r1hfa4ve4x