Hey, I'm Max Harari.
My security research is primarily done through HackerOne, where I hunt for vulnerabilities in production systems and open source projects. Since late 2025, I've earned over $17,000 in bounties and disclosed high-impact vulnerabilities to Netflix, Vercel, Node.js, GitLab, and Slack. I'm also Netflix's #1 hacker as of 2026 (#3 all-time) on HackerOne's leaderboard.
I care deeply about open source, and have contributed to major projects such as Node.js and Bun in my free time. I've also authored several semi-popular open source projects such as HVNC and VisualSploit, and I'm the #2 contributor to Kon. The source code for this website is available here!
If you get to know me, you'll find that my morality is inseparable from who I am. It shapes what I believe in, how I treat others, how I conduct my research, and what I choose to pursue. Technology is, almost paradoxically, a fundamentally moral and human venture. My goal is to treat it as such.
Have something worth securing? Get in touch.