0x0doteth / Security researcher / India
Assume nothing.Trust no input.
I'm Balvant Chavda, also known as 0x0doteth on HackerOne, security advisories, and bug bounty platforms. I research vulnerabilities in mobile apps, web applications, cloud services, and smart contracts.
Recent write-ups
Bugs I found and how they worked.
Published
When WebView bites back
An exported Android activity loaded attacker-controlled content in a WebView and allowed JavaScript execution.
- Vector
- Exported activity
- Outcome
- JavaScript execution
Published
The function that could mint forever
A missing authorization check allowed the contract to mint tokens without a supply limit.
- Vector
- Missing authorization
- Outcome
- Unlimited minting
Published
How a news app leaked OAuth codes
A conflicting Android deep link let another app receive an OAuth authorization code.
- Vector
- Deep-link collision
- Outcome
- Code interception
Published
SQLi: finding to exploitation
How I confirmed a SQL injection, demonstrated database impact, and reported it responsibly.
- Vector
- Unsafe input
- Outcome
- Database access
Assigned vulnerabilities · Discovered by Balvant Chavda (0x0doteth)
Assigned CVEs.
Security acknowledgements
Hall of fame and thanks received.
Organizations that acknowledged or credited my vulnerability reports.

.svg.png)
.svg.png)
About
Who is 0x0doteth?
0x0doteth is the security research handle of Balvant Chavda (also written as Chavda Balvant). Balvant is an independent cybersecurity researcher from India, specializing in vulnerability discovery, bug bounty hunting, and responsible disclosure.
Under the handle 0x0doteth, Balvant has published 11+ CVEs affecting products from Adobe Commerce, Adobe Content Credentials, and Nextcloud. He has been acknowledged in security Hall of Fame programs by Google, Microsoft, Apple, Meta, Amazon Web Services, Adobe, GitHub, Intel, Coinbase, PayPal, Salesforce, and over a dozen other organizations.
The username 0x0doteth appears on HackerOne, Adobe Security Bulletins, Nextcloud Security Advisories, and GitHub security advisories as a credited researcher.
Books and notes
What I’m reading.
Five books I keep returning to, and the idea each one left behind.
The Brothers Karamazov
My notes on faith, doubt, responsibility, and how people justify their choices.
Explanations that change what is possible.
Decisions, incentives, and long horizons.
Attention, restraint, and self-command.
Power, dignity, and the cost of survival.
Weekend Learnings
Notes from the rabbit holes.
Twelve short notes from whatever caught my attention.
View all Weekend Learnings ↗
↗
↗