Security & Hall of Fame

At TwentyOne, we take the security of our users very seriously. We deeply appreciate the cybersecurity community that helps us keep the platform bulletproof.

Responsible Disclosure Policy

We highly value the time and expertise of security researchers. While our program currently does not offer financial compensation, we are committed to providing public, indefinite recognition in our Security Hall of Fame for valid vulnerability reports.

Rules of Engagement

Non-destructive research is welcome. The use of automated scanners, aggressive tools, or tests that degrade user data and system stability requires explicit prior authorization.

Recognized Researchers

Kolakaluri Abhishek

Security Researcher

Security Researcher that has contributed to improving our platform's stability.

  • Reported: August 09, 2026
  • Mitigated: v2.8.3 (Beta)
  • Resolved findings:
    Email Verification Bypass Allows Authentication and Access to an Unverified Account (CWE-287 / CWE-302)

Vijendra Chauhan

Security Researcher

Security Researcher and Bug Bounty Hunter with a strong interest in web application security, vulnerability research, and responsible disclosure. Passionate about identifying security flaws, improving application security, and continuously expanding expertise in offensive security and ethical hacking.

  • Reported: July 16, 2026
  • Mitigated: v2.7.1 (Beta)
  • Resolved findings:
    Improper Neutralization of Input During Web Page Generation (CWE-79)

Vivek Udane

Security Researcher

"I'm a Bug Hunter passionate about web security"

  • Reported: July 14, 2026
  • Mitigated: v2.7.1 (Beta)
  • Resolved findings:
    Improper Neutralization of Input During Web Page Generation (CWE-79)
    URL Redirection to Untrusted Site (CWE-601)

Faizan Mirza

Security Researcher

Independent Security Researcher with a strong interest in Web Application Security, Vulnerability Research, and Responsible Disclosure. Passionate about identifying security vulnerabilities and helping organizations improve their security posture through ethical security research.

  • Reported: July 12, 2026
  • Mitigated: v2.7.0 (Beta)
  • Resolved findings:
    Improper Restriction of Excessive Authentication Attempts (CWE-307)

Pragati Mahajan

Security Researcher

Security Researcher specializing in Web, API and Mobile Security. Passionate about responsible vulnerability disclosure, penetration testing, and helping organizations strengthen their security posture.

  • Reported: July 12, 2026
  • Mitigated: v2.7.0 (Beta)
  • Resolved findings:
    Improper Neutralization of Input During Web Page Generation (CWE-79)

Aftab Inamdar

Security Researcher

Discoverer of security vulnerabilities in web applications. This researcher has made significant contributions to improving our platform's security.

  • Reported: July 07, 2026
  • Mitigated: v2.6.7 (Beta)
  • Resolved findings:
    Improper Neutralization of Input During Web Page Generation (CWE-79)

Michal Biesiada

Security Researcher

Security researcher. Mainly focused on Offensive Security, Pentesting, Red Teaming. Educator, Mentor, Writer.

  • Reported: July 07, 2026
  • Mitigated: v2.6.7 (Beta)
  • Resolved findings:
    Improper Input Validation (CWE-20)
    Exposure of Sensitive Information to an Unauthorized Actor (CWE-200)

Yasir Ansari

Security Researcher

Investigates and identifies vulnerabilities in web applications. His contributions have been instrumental in enhancing the security of our platform.

  • Reported: July 07, 2026
  • Mitigated: v2.6.7 (Beta)
  • Resolved findings:
    Generation of Error Message Containing Sensitive Information (CWE-209)

Hemant Mohite

Security Researcher

Security researcher. New vulnerabilities are discovered through meticulous testing and analysis. His contributions have significantly enhanced the security posture of our platform.

  • Reported: July 06, 2026
  • Mitigated: v2.6.6 (Beta)
  • Resolved findings:
    Lack of Email Canonicalization Allows Account Cloning (CWE-694)

Pramod Rathod

Security Researcher

Independent security researcher and bug bounty enthusiast. His testing and clear reporting helped us identify and resolve critical vulnerabilities.

  • Reported: July 01, 2026
  • Mitigated: v2.6.5 (Beta)
  • Resolved findings:
    Publicly Accessible .htaccess Configuration (CWE-538)

Shubham Maruti Pawar

Web Penetration Tester

Securing real-world systems through deep reconnaissance and manual testing. Reported valid bugs to NASA, Flipkart & Gov of India.

  • Reported: June 29, 2026
  • Mitigated: v2.6.5 (Beta)
  • Resolved findings:
    Improper Account Linking Leading to Account Takeover (CWE-288)

Huntersoham

Security Researcher

huntersecsoham@gmail.com Email visible by researcher consent

Independent security researcher and dedicated bug bounty specialist. His diligent analysis and transparent communication style were key in identifying and resolving critical security gaps, significantly strengthening the platforms defense against unauthorized access.

  • Reported: June 28, 2026
  • Mitigated: v2.6.4 (Beta)
  • Resolved findings:
    Missing Re-authentication for Sensitive Functionality (CWE-306)

BurgSec

Security Researcher

BurgSec offers a wide variety of Cyber Security Services including but not limited to Penetration testing, SAST, DAST, SOC 2 Type II Audit, Vulnerability Assessment, PCI DSS Compliance Audit and many more.

  • Reported: June 19, 2026
  • Mitigated: v2.6.3 (Beta)
  • Resolved findings:
    Session Replay on Logout
    Weak Password Policy

Help us improve TwentyOne and secure your place here.

Found a vulnerability?

Security is a collaborative effort. If you have discovered a valid attack vector, contact us immediately so we can protect our community.

Contact Security

Version Control

Date Version Changes
August 18, 2026 2.8.5 Beta
In this version and in the following ones, we have focused on improving the code structure to facilitate maintenance and scalability of the project. However, this may lead to unexpected errors, so we appreciate your understanding and patience as we work on these improvements.
The introduction of the Dividend Tracking feature required significant code restructuring, which may lead to unexpected bugs.
We are also aware of areas where dividend integration is still pending (e.g., Q-Core 21, Alerts). We appreciate your patience and understanding as we continue to refine these systems.
  • Resolved a UI layout overlap issue within the portfolio section.
  • Implemented comprehensive Dividend Tracking functionality.
  • Updated the documentation in the User Guide under User Guide / 6. Manage Portfolio / 6.5. Dividend Tracking.
  • Integrated dividend data into key analytics: Modigliani M2, Price vs. Average Cost, Real Profit, Risk-Return Bubble, UPI Stress Analysis, and Volatility charts.
  • Improved the UI and aesthetics of the Portfolio Wizard.
  • Adapted various performance metrics to fully support the new dividend logic.
August 14, 2026 2.8.4 Beta
In this version and in the following ones, we have focused on improving the code structure to facilitate maintenance and scalability of the project. However, this may lead to unexpected errors, so we appreciate your understanding and patience as we work on these improvements.
  • We modernized the app’s architecture by organizing our code into clean, modular components. This means faster load times, fewer bugs, and a rock-solid foundation for future updates
  • We migrated inline JavaScript from certain app pages to external script files.
  • Redesigned the Journal Unlock screen into a modern, minimalist full-screen view.
  • Added rate-limiting middleware to the journal unlock and portfolio export routes to prevent brute-force attacks and server abuse.
  • The delete journal entry button has been fixed and its visual style has been redesigned.
  • Full integration of all alert parameters: All alert parameters have been mapped and connected to RiskManager.js to ensure every custom configuration value is actively used in the system's risk calculation and evaluation logic.
  • Redesigned the metrics section with a cleaner, more organized, and professional design.
August 09, 2026 2.8.3 Beta
In this version and in the following ones, we have focused on improving the code structure to facilitate maintenance and scalability of the project. However, this may lead to unexpected errors, so we appreciate your understanding and patience as we work on these improvements.
  • Refactored the UI JavaScript file into clean, well-organized modules for improved maintainability.
  • Decoupled HTML templates from JavaScript logic by migrating to external views and modernizing the architecture with dedicated, modular components for each feature.
  • Redesigned the Portfolio Section with a cleaner, more elegant and minimalist approach.
  • Expanded the Data Export functionality; Journal Entries and Notes are now included in the JSON portfolio backups.
  • Resolved (CWE-287 / CWE-302): Email Verification Bypass Allows Authentication and Access to an Unverified Account.
  • Improved System Status Page
August 08, 2026 2.8.2 Beta
In this version and in the following ones, we have focused on improving the code structure to facilitate maintenance and scalability of the project. However, this may lead to unexpected errors, so we appreciate your understanding and patience as we work on these improvements.
  • Reorganized the controllers structure for better maintainability.
  • Reorganized the JavaScript structure for better maintainability.
  • Reorganized the routes structure for better maintainability.
  • Refactor chart logic into independent JS modules
August 03, 2026
August 04, 2026
2.8.1 Beta
2.8.11 Beta
  • Added a "Quick Edit" feature in the Total Net Worth panel, allowing users to instantly adjust the total value of any asset for a specific month by clicking the pencil icon.
  • Added a 1-click "Delete Folder" functionality that instantly un-groups all associated assets without removing the actual asset data from the portfolio.
  • Implemented a global Quick Access context menu (right-click) for streamlined asset and folder creation directly from the portfolio management view.
  • Introduced a comprehensive "Create Folder" wizard allowing bulk selection of assets, chart grouping, and target strategy configuration in a single interface.
  • Added dynamic conflict warnings in the folder creation wizard to instantly alert users when selecting assets already assigned to other folders.
  • Enhanced the Home view to intelligently consolidate assets belonging to the same folder into a single unified block within the summary bar chart and the ticker marquee when the "Group in Charts" option is active.
  • Resolved a formatting issue with currency strings.
  • Fixed a display bug where the asset visibility toggle (eye icon) would revert to an incorrect visual state upon reloading the page due to boolean conversion errors.
  • Updated the User Guide Section to document the new context menu and the fast-track folder creation methods. (See User Guide / 6. Manage Portfolio).

2.8.11 Changes
  • Add "New Folder" button to the Asset Configuration table header for better contextual access.
  • Added intelligent folder suggestions (fuzzy search) to the Folder Creation Wizard and Asset Sidebar to prevent duplicate folders with varying capitalization.
  • Implemented automatic property inheritance: selecting an existing folder in the wizard or sidebar now automatically loads its grouping and target strategies.
  • Streamlined transaction editing: Modifying a transaction from the Global Transaction History now skips the decision wizard and goes straight to the editing form.
  • Optimized investment tracking: Creating a new Investment asset now jumps directly to the transaction form, bypassing unnecessary prompts.
  • Enhanced the Metrics header to display the Annualized Return (CAGR) of investments by default for users with active investment assets, including a quick-toggle badge to switch between Investments CAGR and Absolute Performance.
July 22, 2026
July 25, 2026
July 26, 2026
2.8.0 Beta
2.8.01 Beta
2.8.02 Beta

2.8.01 Changes
  • User Guide have been updated. (See User Guide / 5. Debts).
  • Sidebar navigation has been refined with a new "WORKSPACE" visual divider for better grouping of daily tracking tools.
  • Enhanced mobile responsiveness for debts section
  • Fixed vertical alignment of the action buttons (Edit, Amortize, Void) in the debts section.
  • Fixed regex validation in input forms to properly support international characters in debts section.

2.8.02 Changes
  • Integrated a real-time Service Status Monitor. (See System Status Page).
  • Refined the mobile user interface and container styling for Q-Core 21™ Insights.
  • Expanded the Data Export functionality; active debt records are now included in the JSON portfolio backups.
  • Redesigned the Security Section with a modernized user interface and implemented direct access links for smoother navigation.
July 20, 2026 2.7.1 Beta
  • Fixed CWE-79 (A security issue in the Knowledge Base search engine that could allow malicious script execution).
  • Patched CWE-601 (A vulnerability that could have been used to redirect users to unauthorized external websites).
  • Improved database stability by securing our backend search queries against overload attacks.
  • Graphs now feature an integrated UI for seamless management expand charts for detailed analysis or hide them instantly via the new context badge. (See User Guide / 3. Metrics).
  • Implemented real-time viability checks for all metrics. Charts automatically adjust to your available data, providing clear status indicators and preventing visualization of incomplete datasets.
  • User Guide Section Updated.
  • llms.txt file has been updated to include the latest information about our platform.
  • Improved fluidity in metrics by pausing inactive charts when expanding a view and implementing staggered loading to prevent interface lag.
  • Implemented a new settings panel for folders, enabling users to rename folders, toggle grouping in charts, and define global portfolio targets that apply to the entire category. (Outdated: User Guide / 5. Manage Portfolio / 5.4 Folders).
  • Updated the Smart Target Control Graph dropdown to include folders as selectable units, while introducing a filter to exclusively display assets or folders that have a target allocation greater than 0%.
  • Enhanced the alerts to calculate folder-level exposure by aggregating the current weights of all underlying assets, ensuring that rebalancing alerts now correctly account for both individual assets and grouped folder.
  • Privacy Policy and Terms of Service have been updated.
  • Publics Sections Improved.
July 13, 2026 2.7.0 Beta
  • We have introduced a new folder structure for a cleaner portfolio.
  • We have fixed a frontend problem in the portfolio management system.
  • User Guide has been updated with the latest information (Outdated: User Guide / 5.Manage Portfolio / 5.4 Folders).
  • Now the version control includes links to make everything more accessible.
  • Resolved CWE-307 (Improper Restriction of Excessive Authentication Attempts).
  • Resolved Stored XSS bypass in Portfolio module (CWE-79). Previous server-side mitigation was not robust enough.
  • Hall of Fame has been updated with a pagination system to show the researchers.
July 09, 2026
July 10, 2026
2.6.7 Beta
2.6.71 Beta
  • Fixed CWE-209 (Excessive error details disclosure in Stripe payment controller).
  • Fixed CWE-20 (Implemented strict validation and sanitization for the 'Full Name' field during registration to prevent Email/Content Spoofing).
  • All email addresses have been removed from the public Hall of Fame to ensure GDPR compliance and prevent automated scraping.
  • Researchers who wish to display their contact information or professional links (LinkedIn/Portfolio) may now provide explicit written consent.
  • Fixed CWE-79 (Stored XSS vulnerability in the Portfolio module by adding server-side validation and output encoding for the 'ticker' parameter).
  • Integrated a new system to view notes directly within the performance chart.

2.6.71 Changes
  • Fixed Product Page HTTP 500 error.
  • Note marker animations synchronized to appear sequentially as the line chart renders.
  • The Notes section now allows selecting a custom date for each note (previously the date defaulted to the creation day).
  • Implemented secure Quick Notes system, and added double-click note creation to the main chart.
July 06, 2026 2.6.6 Beta
  • Resolved CWE-694 (Use of Multiple Resources with Duplicate Identifier).
  • Privacy Policy and Terms update. We have added new clauses and updated the design.
  • Articles section updated. Cleaned up and refreshed look.
  • Hall of Fame Update: Implemented better overall organization.
  • Search engine integration in User Guide Section.
  • On mobile devices, Q-Core 21 cards are now expandable; simply tap on any insight to open.
July 01, 2026
July 03, 2026
2.6.5 Beta
2.6.51 Beta
  • Resolved CWE-288 (Improper Account Linking Leading to Account Takeover).
  • Resolved CWE-538 (Exposure of Sensitive Information through .htaccess Configuration).
  • Adjusted Volatility & Return chart.
  • Updated Open Graph button interface.
  • Temporarily disabled "Goals" module for upcoming redesign.
  • Admin Panel: Enhanced manual email sending capabilities.
  • Implemented server-side validation to exclude empty transactions from being saved.
  • Enhanced navigation flow and stability within the Portfolio transaction wizard.

2.6.51 Changes
  • Resolved CWE-770 (Allocation of Resources Without Throttling) in the password recovery email functionality.
  • Ban System: Implemented enhanced ban management features in Admin Panel.
June 29, 2026 2.6.4 Beta
  • Resolved CWE-306 (Missing Authentication for Critical Function), CWE-285 (Improper Authorization), and CWE-639 (Authorization Bypass).
  • Implemented mandatory OTP re-authentication for account deletion and data export.
  • Fixed Assets Breakdown calculation for Working Capital assets.
  • Metrics Board: Enhanced responsiveness, auto-resize charts, and locked scroll on zoom.
  • Added Seasonal Liquidity chart and Q-Core 21 insight.
  • Fixed Smart Target Control logic and sidebar navigation bugs.
  • Reordered User Guide for better accessibility.
June 24, 2026 2.6.3 Beta
  • Resolved CWE-613 (Insufficient Session Expiration). Logout now correctly invalidates active session cookies, preventing session hijacking.
  • Implemented CWE-1395 (Use of Known-Compromised Credentials) protection via automated checks against global credential leak databases.
  • Migrated infrastructure to Cloudflare for global speed optimization.
  • Implemented advanced DDoS and malicious bot protection.
  • Refined responsive design for improved tablet and mobile navigation.
  • Added featured images to all educational articles.
  • Launched the Security Hall of Fame section to recognize ethical researchers.
June 21, 2026 2.6.2 Beta
  • Optimized welcome page images for faster loading.
  • Revamped login and registration interface.
  • Implemented secure session cookies.
  • Added Terms & Conditions acceptance during registration.
  • Integrated Terms & Conditions into registration email.
  • Deployed new sidebar menu and a new cookie banner.
  • Refactored and organized payment processing logic.
Showing results