Inside the Approach of a Top GitHub Bug Hunter
As part of its Cybersecurity Awareness Month activities, the GitHub Security Bug Bounty team has been profiling standout researchers who participate in its public program. The latest spotlight is on André Storfjord Kristiansen, known as @dev-bio, a researcher recognized for uncovering injection-related vulnerabilities and for filing reports that help the team move quickly on impact assessment.
GitHub’s bug bounty program remains a core part of its security strategy, particularly as AI-assisted development features expand. The company has also been auditing the researchers in its public program, inviting those who consistently demonstrate expertise and impact to an exclusive VIP bounty program. VIP researchers gain early access to beta features, direct engagement with GitHub Bug Bounty staff and engineers, and exclusive Hacktocat swag, including a brand new collection released this year.
From Curiosity to Coincidental Discoveries
Kristiansen’s entry into bug bounty hunting was not the result of a structured plan. He got involved while working on a personal project in his spare time. With a background in software engineering and a natural curiosity about how systems behave, he often finds himself dissecting new features to see how they handle edge cases. That curiosity has led him to findings with substantial impact.
For Kristiansen, the appeal is in demonstrating how seemingly minor issues can become real vulnerabilities. Exploring small anomalies, tracing their implications, and showing how they can escalate feels rewarding, he says.
His process reflects that mindset. Rather than relying on a rigid methodology, his most significant discoveries have been coincidental and the result of being sidetracked by his own curiosity. When something seems unusual, he digs deeper, peeling back layers until he fully understands the mechanism. From there, he carefully documents each step to map out potential attack paths and builds a comprehensive picture of the vulnerability before reporting.
Favorite Bug Classes and Research Tools
Kristiansen is drawn to injection-related vulnerabilities, subtle logic flaws, and overlooked assumptions. Lately, he has been exploring novel techniques for bypassing strict content security policies. What drives him is showing how benign findings can be chained together to produce significant impact, often exposing weaknesses in the underlying design of a system.
In his professional work as a security engineer, Kristiansen specializes in software supply chain security, a field he says is often neglected but increasingly critical. He spends time researching gaps and developing mitigations for emerging threats, and works closely with some of the best security talent in Norway.
For personal research, he prefers to write his own tools rather than depend on off-the-shelf utilities, because it gives him a deeper understanding of the problem and reveals new areas to explore. None of his tools have been published yet, but he plans to release a toolkit for building comprehensive offline graphs of GitHub organizations, complete with an extensible query suite to quickly uncover common misconfigurations and hidden attack paths.
Staying Ahead of the Curve
To keep up with vulnerability trends, Kristiansen reads write-ups from other researchers to see how they approach problems and what kinds of bugs are being found. He also makes an effort to get ahead of the curve by identifying research areas that are underexplored.
His advice to researchers new to bug bounty hunting: do not settle for a simple finding. Dig deeper to understand its full implications, because understanding the broader picture can turn a seemingly benign issue into one with substantial impact.
Kristiansen also balances his security work with life as a new father in Norway. He credits his partner for giving him the uninterrupted time to work on late-night side projects. When he steps away from the keyboard, he prefers spending time outdoors hiking, camping, and cross-country skiing, which he says helps him return with a clear mind and renewed focus.
“What keeps me going is the thrill of showing how seemingly minor issues can have real-world impact... taking something small and possibly overlooked, exploring its implications, and demonstrating how it could escalate into a serious vulnerability feels very rewarding.”
Kristiansen has set up a page where he plans to publish interesting content in the near future, and he is active on LinkedIn. GitHub continues to accept findings through the its HackerOne page, and each report from the security community is treated as a chance to improve security across GitHub, its products, and its customers.



