About
The one who knows the cipher and keeps the gate.
CypherWarden is a security channel that attacks what gets shipped today: AI and LLM apps, mobile apps, web 2.0, web3 and smart contracts, IoT, the cloud and APIs. Think like the attacker, answer like the keeper.
It is made by Romeo Koati, an independent developer and bug bounty hunter in Yaoundé, Cameroon. The videos start from real work: reports filed on public programs, labs rebuilt from scratch, tools written for the job.
There are two channels: CypherWarden in English, and CypherWarden FR in French, where serious offensive content on AI, web3 and IoT is still rare.
The name
Two words, one job.
A variant of cipher: the code, the encryption system, the root of everything that keeps data confidential. The y points to the cypherpunks of the 1990s, who laid the groundwork of modern cryptography. It carries a hacker meaning that the spelling with an i does not.
The keeper someone entrusts with something, with the authority to enforce it: a prison warden, a game warden. Stronger than guard, which is just a watchman. A warden answers for what is in their keeping.
Four rules for every video
Authorised or nothing
Labs, CTFs, our own devices, and bug bounty programs within scope. A target without permission never appears on screen.
We show the request
Facecam and screen capture: the request, the response, the line of code. Dead ends stay in, because that is what the work looks like.
We give the outcome
Accepted, duplicate, out of scope, informative: the program's answer is part of the story, and so is the bounty when there is one.
The fix closes the video
Every attack ends with the defence: what a developer changes so it never happens again.