Skip to content
← home
Casey Ellis

Casey Ellis

Hacker, founder, advisor, and pioneer of crowdsourced security. Founder of Bugcrowd, co-founder of disclose.io, principal of Tall Poppy Group. Board member at SRLDF.

Hot Takes

Security is an afterthought, and that's economics

There are some black pill truths around security (the "nothing's ever going to change" kind) that need to be reconciled.

30 Sep 2026 · 1 min read
Hot Takes

I can just do stuff

Personally, I'm hacking on stuff again. With AI in the toolkit it feels kind of like the early 2000s in some ways:

29 Sep 2026 · 1 min read
Hot Takes

The law matters less than the legal team

I'm not a lawyer, and if I was, I'm not your lawyer. With anti-hacking laws there's a

28 Sep 2026 · 1 min read
Hot Takes

The hackers weren't lying

A lot of what's actually happening right now is people realizing that, no, the hackers weren't lying this whole time.

25 Sep 2026 · 1 min read
Hot Takes

Fixing everything is a fool's errand

Vulnerability management is a bit of a fool's errand if your goal is to make sure that everything's fixed. We&

24 Sep 2026 · 1 min read
Hot Takes

Root is the product

For those of us on offense, root (full control of the target) is the product. If we're just doing pure offense, that&

23 Sep 2026 · 1 min read
Hot Takes

We think like that because we're like that

People in security greatly overestimate the ability and the propensity for people to think like bad guys in the way that we do. We

22 Sep 2026 · 1 min read
Title slide: Don't be the tooling, build the tooling. Casey Ellis, [un]prompted.au, Sydney 2026, on a purple disclose.io background.
Building

Don't be the tooling, build the tooling: [un]prompted.au talk

Slides from my [un]prompted.au talk on using AI to build deterministic tooling, with lookup.disclose.io as the worked example.

21 Sep 2026 · 1 min read
Hot Takes

You don't kill a bug by finding it

I've never really believed that you just kill a bug by finding it. This is the guy who started Bugcrowd, so I

21 Sep 2026 · 1 min read
Across the Pondcast episode 45 art: AI & Bug Bounties with Casey John Ellis, next to the Across the Pondcast logo
Security

AI and bug bounties: notes from 68 minutes on Across the Pondcast

68 minutes with Tib3rius and Andy Swift on Across the Pondcast, cut down to the salient points and timestamped: how Bugcrowd started, what AI has actually done to bug bounty, why a VDP is the sane fallback, and where researchers should point next.

18 Sep 2026 · 8 min read
Hot Takes

A convict colony thing

Australia has always punched above its weight from an offensive security standpoint. I think it's a convict colony thing that just shows

18 Sep 2026 · 1 min read
AI Security Podcast thumbnail: Ashish Rajan and Casey Ellis under the title The AI Slop-demic
Security

A lot of people are just sitting on zero-day right now

I sat down with Ashish Rajan on the AI Security Podcast after Black Hat. The bit worth writing down: the triage queues are noisy enough that good researchers are sitting on zero-day. Plus export controls, attack graphs, port 3000, and why leaders should go use this stuff at home.

17 Sep 2026 · 4 min read