Hello, I'm
Offensive & Application Security Engineer focused on AI security and AI red teaming. I break LLM and agentic systems, run red-team engagements across web, mobile, API, cloud and Web3, and build offensive tooling that turns findings into fixes.
Chinmay Lohani Security Engineer

Chinmay Lohani

Offensive & Application Security Engineer. AI red teaming, LLM and agentic system security, pentesting, and offensive tooling.

ABOUT ME

I am an Offensive & Application Security Engineer at Coinbase, where I spend most of my time on AI security and AI red teaming: attacking LLM-backed features, agentic workflows, and the tool/RAG surfaces around them. My work covers direct and indirect prompt injection, jailbreaks, tool and function-call abuse, model/plugin supply chain risk, and data-exfiltration paths, mapped against the OWASP LLM Top 10, NIST AI RMF, and MITRE ATLAS.

Alongside AI, I run classic offensive and application security work: 200+ security assessments and red-team engagements across web, mobile, API, cloud-native, and Onchain Web3 systems, threat modeling (STRIDE), secure code review, and embedding SAST/DAST/SCA into CI/CD. I also build the tooling I use, including AI-assisted pentesting pipelines that automate recon, test generation, exploit validation, and reporting, cutting assessment timelines from about a week to hours.

My background runs deep on the low-level side too: reverse-engineering ransomware and malware with IDA Pro, Ghidra, and x64dbg to map IOCs and TTPs to MITRE ATT&CK, building adversary simulations with custom EDR/WAF evasion payloads and obfuscated C2 tradecraft, and shifting security left by wiring SAST, SCA, and dependency scanning into engineering pipelines. Previously with Johns Hopkins University, Sigma Computing, and Mercedes-Benz R&D. I hold an M.S. in Security Informatics from Johns Hopkins and a B.Tech in Computer Science from IIIT Sri City, and I am an active CTF player.

ARSENAL

A live shell into what I actually work with. Pick a command on the left and it runs.

chinmay@redteam: ~
chinmay@redteam:~$ whoami --focus
roleOffensive & Application Security Engineer @ Coinbase
focusAI red teaming · LLM & agentic system security · AppSec · Onchain Web3
depththreat modeling, secure code review, exploit development, malware reverse engineering
buildsAI-assisted pentesting pipelines, fuzz harnesses, offensive tooling in Python & Go
eduM.S. Security Informatics, Johns Hopkins · B.Tech CSE, IIIT Sri City
200+
security assessments & red-team engagements
1 wk → hrs
assessment turnaround with AI-assisted tooling
Best Paper
IEEE CCWC 2024, out of the full conference track
1st
ETHGlobal SF 2024 · HopHacks 2023
#64
globally, CodeChef 2020 Cook-Off
5★ / 4★
HackerRank · CodeChef competitive programming
paperBest Paper Award — "Assuring Safe Navigation and Network Operations of Autonomous Ships", IEEE CCWC 2024
ethglobal1st Place — ETHGlobal San Francisco 2024, Web3 / DeFi security track
hophacks1st Place — HopHacks 2023, the Johns Hopkins flagship hackathon
ranking#64 globally, CodeChef 2020 Cook-Off · #1500 globally, Google Hash Code 2020
ratings5-star HackerRank · 4-star CodeChef
certsGoogle Cybersecurity · IBM Security Analyst · Cryptography I (Stanford)
# Frameworks and scanners I use to probe LLM and agentic systems at scale.
PyRITgarakpromptfooCounterfitGiskardHarmBenchInspectAdversarial Robustness Toolbox
# Attack classes I test for across models, tools, and retrieval surfaces.
Direct Prompt InjectionIndirect Prompt InjectionCrescendoTree of Attacks (TAP)Skeleton KeyMany-shot JailbreakPAIRAdversarial Suffixes (GCG)Tool & Function AbuseRAG PoisoningAgentic Autonomy AbuseSystem-Prompt LeakageModel ExtractionTraining-Data Leakage
# The standards I map findings and coverage against.
OWASP LLM Top 10OWASP ML Top 10MITRE ATLASNIST AI RMFGoogle SAIF
# Red team and penetration testing across the full stack.
Web / API PentestMobile PentestCloud & Network PentestRed TeamAdversary SimulationExploit DevelopmentMITRE ATT&CKPurple TeamCobalt StrikeSliverBloodHoundImpacketMetasploitNuclei
# Finding classes of bugs before they ship, then keeping them out.
Threat Modeling (STRIDE)Secure Code ReviewSecure SDLCOWASP Top 10 & ASVSAPI SecuritySAST / DAST / SCA / IASTFuzzing (Jazzer, libFuzzer)Burp SuiteOWASP ZAPSemgrepCodeQLSnyk
# Where the code runs, and how security rides along with it.
AWSGCPAzureKubernetesDockerTerraformGitHub ActionsJenkinsIaC ScanningCI/CD Security
# Taking binaries and malware apart to see how they really behave.
IDA ProGhidraRadare2x64dbgMalware AnalysisSandbox InstrumentationIOC & TTP MappingDetection Engineering
# What I write tooling, exploits, and harnesses in.
PythonGoJavaScript / TypeScriptCC++BashPowerShellSolidity
loading

PROJECTS

ALLAI SECURITYRED TEAMPUBLISHEDSECURITYMLWEBBLOCKCHAIN
AI
OFFENSIVE
SECURITY

AI-Assisted Offensive Security Tooling

Built LLM-driven pentesting tooling that automates reconnaissance, test-case generation, exploit validation, evidence collection, and report writing. Chained model calls behind deterministic guardrails and cached context aggressively, reducing assessment timelines from roughly a week to hours at about 10% of standard LLM token cost.

Created at: February 12, 2026
OFFENSIVE
SECURITY
BLOCKCHAIN

Onchain & Web3 Offensive
Security Program

Spearheaded Onchain offensive security assessments after identifying the lack of a standardized pentest path. Integrated threat modeling into repeatable attack-surface discovery and mapped Web2-to-Web3 integration points, maturing coverage from an undefined baseline to 70% across DeFi products and Onchain systems.

Created at: October 2, 2025
AI
SECURITY
ML

AIxCC Autonomous
Security Fuzzing

Built Java + Jazzer fuzzing pipelines for the AI Cyber Challenge targeting XSS, command injection, and insecure deserialization. Produced reusable fuzz harnesses, seed corpora, and crash-triage automation to let autonomous systems find and reproduce memory- and injection-class bugs without human drivers.

Created at: June 18, 2025
OFFENSIVE
SECURITY

Ransomware & Malware
Reverse Engineering

Reverse-engineered ransomware and malware samples with IDA Pro, Ghidra, and x64dbg to extract exploit techniques, persistence mechanisms, and evasion tactics, mapping IOCs and TTPs to MITRE ATT&CK for detection engineering. Built Python tooling and sandbox instrumentation to automate unpacking, string/IOC extraction, and triage across sample batches.

Created at: April 22, 2025
OFFENSIVE
SECURITY

EDR/WAF Evasion
& C2 Tradecraft

Engineered custom EDR and WAF evasion payloads and obfuscated command-and-control tradecraft to validate detection coverage during adversary simulations. Exposed gaps in endpoint telemetry across 15+ application and infrastructure assessments and drove new detection logic with the blue team.

Created at: July 30, 2024
SECURITY

CAPTCHA

Innovated a human-solvable CAPTCHA system in Golang to bolster security against offline dictionary attacks. The system featured three unique puzzles: Sudoku, Chess, & Cryptographic Hash Puzzle. Performed comparative analysis with cutting edge solutions leading to our finding of 30% less likelihood of successful dictionary attacks against offline files.

Created at: January 25, 2024
ML

Deep Learning based Disease Classifier for X-Rays

Trained and tuned a deep-learning classifier over chest X-ray imagery, handling class imbalance and augmentation to improve detection of disease markers, and published the notebook and results on Kaggle.

Created at: December 10, 2023
PUBLISHED
SECURITY
ML

Assuring Safe Navigation & Network
Operations of Autonomous Ships

Best Paper Award at IEEE CCWC 2024. I implemented an ML security monitor for maritime ICS infrastructure, achieving 98.5% accuracy in detecting cyber threats on ICS networks and validating its effectiveness through penetration tests against power systems and weapon controls.

Created at: November 30, 2023
OFFENSIVE
SECURITY

Angband

Developed proof-of-concept exploit achieving root access by reverse engineering Angband game binary to locate format string vulnerability. Used IDA Pro and GDB to analyze vulnerability and craft input to exploit stack overflow, redirect code execution flow, and open remote shell.

Created at: November 14, 2023
OFFENSIVE
SECURITY

Penetration Testing and Vulnerability Assessment
of OpenEMR

Performed security testing of OpenEMR, identifying vulnerabilities like SQLi, DoS, buffer overflows, and XSS. Used tools including Burp Suite, OWASP ZAP, SQLMAP, and Wireshark to detect issues. Documented proof of exploitation along with remediation recommendations.

Created at: October 14, 2023
OFFENSIVE
SECURITY

Duke Nukem II

Exploited buffer overflow in Duke Nukem game binary to achieve remote root shell access. Reverse-engineered binary using Ghidra to identify vulnerable function and crafted malicious input. Developed proof-of-concept demonstrating arbitrary code execution via shellcode injection and redirecting control flow using buffer overflow technique.

Created at: September 20, 2023
SECURITY

Open-Source Web Server Security Assessment

Conducted threat modeling on an open-source web server using SciTool Understand and Microsoft Threat Modeling Tool. Produced an executive summary detailing risks and employed Ghidra and Veles for reverse engineering, bolstering the system's security posture.

Created at: August 30, 2023
SECURITY
ML

Intrusion Detection System for IoT

Simulated DDoS attack in IoT devices, like flooding on CoAP network using Cooja simulator, leveraged the simulation data to train an ML model for detection of unusual traffic.

Created at: March 24, 2023
SECURITY
WEB
BLOCKCHAIN

Blockchain-based e-voting System

Designed and built a tamper-proof, decentralized e-voting system on the Ethereum blockchain through commit-reveal mechanisms. Hardened system security by building Solidity smart contracts with audited OpenZeppelin libraries, optimized consensus algorithms, IPFS integration and MetaMask identity management resulting in enhanced transparency, scalability, and reduced gas costs by 8%.

Created at: December 1, 2022
ML

Card Fraud Detection

Investigated anonymized card data, identified feature relationships through visualizations, and engineered ensemble models to detect credit card fraud with 99.9% accuracy, reducing false positives by 20%.

Created at: October 24, 2022
WEB
BLOCKCHAIN

OpenZepplin Supply chain

Developed blockchain-based supply chain system using Solidity, OpenZeppelin, Truffle, and Web3, integrating web interfaces for server-chain communication. Enhanced efficiency by 10% and improved security.

Created at: August 16, 2022
WEB

News-Aggregator

Developed a MERN-based web application for integrating news from assorted sources of varying genres by applying several information retrieval techniques, resulting in 30% reduction in similar sentences by applying cosine-based similarity detection.

Created at: February 20, 2022
WEB

IRS Library Manager

Developed an Information-Retrieval System for a large database of books with user-friendly interface using Flask. This gives an easy and extended version to library-management systems built for large scale institutions.

Created at: November 5, 2021
WEB

GATEWAY application for societies

Developed and presented a management system for apartments in the area, facilitating easy communication, complaint and announcement forums, and other utilities to provide a smoother management experience for residents of a community.

Created at: July 12, 2021

EXPERIENCE