Discover the incredible line-up of speakers we have presenting in the village for DEF CON 34.
Explore their bios and find out more about the talks and workshops they'll be delivering throughout the event.
Aidan serves as a senior consultant for Coalfire's DivisionHex, specializing in web application penetration testing, forensic analysis of payment card skimmers, and hardware hacking. He spends his time identifying vulnerabilities to protect hardware, systems, and data from threat actors through manual testing, hardware hacking, and automated tools.
Prior to joining Coalfire in 2025, Aidan served as a lead hardware tester for IBM X-Force Red, conducting unique engagements for clients worldwide. His leading analysis of payment card skimmers led him to present alongside major retailers at the Food Industry Association’s Asset Protection and Grocery Resilience conference, as well as the Skimming and Payment Terminal Attack working group. He showcased his technical research by speaking at Hardwear.io USA 2025 and writing a blog mini-series for Coalfire. Aidan gives back to the cybersecurity community through volunteering at conferences such as Hardwear.io and DEFCON.
Skimmers, Shimmers, and You
Join me as I present my latest research on fraudulent payment devices such as card skimmers and shimmers, building on insights from close collaboration with major retailers, law enforcement, and the United States Secret Service! I will outline the evolving landscape of payment threats and share findings from my hands-on reverse engineering of over 130 fraudulent devices, including ATM, fuel pump, and both point-of-sale skimmers and shimmers. Learn why reliably detecting skimmers is challenging and the latest tools and techniques used to both spot and conceal these malicious devices. Peek behind the curtain of payment security with me to explore how cards are cloned and contactless payments relayed from across the world. You’ll learn how skimmers disproportionally affect U.S. citizens on government benefits and ways to best protect yourself in the ever-changing landscape of digital payments!
Levi stepped up to own the security of an engineering org during the pressures of a data breach. He’s reduced security defects, improved platform performance, and kept the org PCI compliant under QSA scrutiny.
In his own time, he implements OAuth and OIDC for fun and has accidentally become a high impact maintainer in the passkeys ecosystem.
At 50x more authorizations per minute than typical and all for the same amount, alarms go off at issuing banks for a good reason. I'll share the story of how a card-testing adversary abused a misfeature that checked if a card is valid before vaulting it and how their strategies and my defenses evolved over a week long battle. I will share the techniques I used that ultimately distinguished legitimate customer traffic from automated abuse through residential proxies and creative scripts.
Kevin has over 4 decades of technology experience including development on every platform from mainframes to embedded systems with roles from system programmer to CTO. His first Defcon was in 2000 (Yay Alexis Park!) and it opened up a new world for him. He has been involved with PCI since 2005 as a level 1 merchant and PCI Qualified Security Assessor (QSA). He has written books on Rock 'n' Roll as well as Gravehunting (really!).
If your company accepts, processes, stores, transmits, dreams about, or accidentally leaves cardholder data on a sticky note, congratulations - you get the privilege of dealing with PCI DSS. For organizations processing enough transactions, the reward for your success is an on-site assessment conducted by a Qualified Security Assessor (QSA). Think of it as inviting a well-dressed, highly trained auditor to examine every corner of your security program and ask uncomfortable questions about decisions made by people who left the company three years ago.
In an ideal world, your controls are well-documented, operating effectively and everyone knows exactly where the evidence is stored. In the real world, someone discovers during the assessment that the quarterly review hasn't happened since the last presidential administration, nobody can explain a firewall rule labeled "DO NOT TOUCH" and a frantic war room appears overnight.
This session explores the most common (and a few impressively creative) ways organizations derail their PCI assessments. We'll cover how to avoid discovering critical compliance gaps in front of your QSA, why "we thought someone else was doing that" is not a valid control and how to prevent your assessment from turning into a high-stakes race against the reporting deadline.
Come learn how not to fail your PCI assessment spectacularly... preferably before your next assessment cycle.
Senior Team Lead, Grupo Salinas
Since the age of 12, I've dedicated myself to computer science with a special focus on security. Now, at 22, I continue to explore this world with the same passion, driven by the constant evolution of technology and its endless learning curve.
I have a degree in Computer Forensics and Cybersecurity, and I'm currently pursuing a Master's degree in Artificial Intelligence and Cybersecurity.
The analysis begins at Ring -3, advancing toward the positive rings. Starting from the on-screen user
perspective imposes too many limitations. The shift in approach was deliberate: rather than assuming a
conventional attack vector such as connecting an external device or performing a kiosk-level bypass the
decision was made to start from the deepest layers of the system. This compromise is detected for the
following reason:
- DMA protection exists at the BIOS level.
The goal of this compromise is to activate PCI/PCIe through BIOS in order to perform a DMA
This section will be referred to as "BIOS Unprotection."
How was this achieved?
Two methods were identified:
A bridge was found that triggers a BIOS configuration reset.
BIOS duplication with encryption validation bypass (enables both Downgrade and Upgrade).
DMA or complete chain will not be shown since it is a delicate topic but BIOS research will be deepened
since it does not only apply to ATMs.
Ken Pyle is a cybersecurity researcher, exploit developer, professor, and conference speaker specializing in vulnerability discovery, reverse engineering, adversarial cryptanalysis, and advanced offensive security research. He has disclosed vulnerabilities affecting major technology vendors and has presented research at leading security conferences including DEF CON, ShmooCon, and RSA Conference. He also serves as a graduate cybersecurity instructor, mentoring the next generation of security professionals.
His research focuses on systemic and architectural weaknesses in complex systems, protocol-level attacks, polyglot and semantic attack techniques, exploit development, cryptography, critical infrastructure security, and the intersection of emerging technologies with offensive and defensive cybersecurity. His work emphasizes novel attack surfaces, unconventional exploitation methodologies, and the security implications of design decisions across hardware, software, and communication protocols.
Using decades-old OpenJDK PBKDF flaws, forgotten RFCs, hash collisions, and a few semantic edge cases, we’ll compromise multiple cryptographic systems with little more than a handful of carefully chosen values and several “useless” tools.
This talk explores how implementation bugs, legacy compatibility, and architectural assumptions can undermine otherwise sound cryptography—and why the real attack surface is often everything around the algorithm.
Ariana Mirian is a security researcher who has worked at the intersection of empirical measurement and security for over a decade, bringing a data driven lens to security decisions and intelligence. At BeeSafe AI, she is using this experience to drive novel methods that collect data on trust-based scams to prevent victim losses. Prior to this, she worked as a senior security researcher at Censys, where she led measurement-driven research to map the Internet ecosystem. She earned her PhD in Computer Science and Engineering at UC San Diego, where she used Internet-scale measurement to study real-world security posture and develop data-driven methods across cybercrime, Internet-wide scanning, and enterprise security.
Pig butchering and other interactive online scams build trust over weeks to months, making them both highly effective and extremely difficult to study. In this talk, I will describe how we measure ground truth on this difficult and growing ecosystem.
First, I’ll describe the design of an LLM-driven system that can sustain realistic, long-term engagement with scammers for weeks to months, enabling large-scale investigation of their tactics in the wild. I will discuss how we attract scam attempts, maintain thousands of convincing dialogues over time, and navigate the "milestones" scammers use to advance victims toward payment. I'll end with what this approach uncovered about scammer workflows (such as the “cross-platform” jump the majority of them use) and how this measurement drives understanding of the pig-butchering ecosystem to power data-driven scam defenses in the payments ecosystem.
Furkan Fatih Demir is an independent security researcher and penetration tester with experience conducting authorized security assessments across financial services, aviation, public sector, and education industries. Their work spans a broad range of offensive security disciplines, with a particular focus on uncovering business logic vulnerabilities and security gaps that evade conventional tooling. Over the course of their career, they have identified critical vulnerabilities in production systems across multiple regulated industries, including authenticated findings in financial institution environments.
Buy Now Pay Later has grown from a niche convenience to a $560 billion global ecosystem used by approximately 380 million people. Klarna, Afterpay, Affirm, and PayPal Pay Later process billions in transactions annually — and every transaction flows through a series of REST API calls. Security research on BNPL has focused entirely on fraud: account takeover, synthetic identity, first-party fraud. No one has looked at the API layer. This talk does.
We systematically test the BNPL payment flow — session creation, authorization, order management, and capture — using public sandbox environments. Our methodology focuses on business logic flaws: scenarios where the API functions exactly as designed but can be abused in ways developers never anticipated.
Confirmed finding: Klarna's capture endpoint accepts any captured_amount value down to 1 cent ($0.01) on a fully authorized order, with no minimum validation. A $100 authorized order can be captured for $0.01 — returning HTTP 201 Created with Klarna-Order-Validation: Valid. In vulnerable merchant implementations, customers receive goods while only $0.01 is collected — a $99.99 financial loss per transaction.
Attendees will leave with a practical attack methodology for BNPL integrations, an open-source reference implementation (vulnerable + patched), and a merchant-side security checklist.
Matt Burch is a Principal Security Researcher at Atredis Partners with 20 years of experience breaking things that aren't supposed to break. From the embedded components of ATM platforms to complex SCADA/OT environments, Matt specializes in identifying critical flaws in hardened, enterprise-class systems. He is best known for his research into ATM disk encryption and MDM security, work that has been highlighted in Wired Magazine and presented at DEF CON 32.
Matt is a reverse engineer and tool developer who has authored and contributed to various public projects. His career spans roles as an offensive security lead, expert witness, and technical advisor. Matt’s current research is a deep-dive into the ATM software supply chain, specifically targeting the subversion of TPM-backed roots of trust and the analysis of custom cryptographic primitives.
ATMs are the ultimate high-stakes target, often holding upwards of $400,000 in a single enclosure. While the global financial industry relies on a narrow pool of manufacturers, the software supply chain securing these "vaults" remains an under-examined attack surface. Following my disclosure of 6 code execution vulnerabilities affecting Diebold Nixdorf at DEF CON 32, this research dives deeper into the foundational security layer: CryptWare CryptoPro Secure Disk for BitLocker.
CryptoPro acts as a proprietary security wrapper, adding pre-boot authorization, custom TPM protections, and an obfuscated encryption layer to the standard BitLocker architecture. In this session, I will highlight the nuances of the CryptoPro architecture, including, secret storage through unallocated disk space, TPM sealing logic, and the layered crypto architecture used to secure system secrets. I will demonstrate how these deficiencies provide a path for code execution and full compromise of the Windows BitLocker encryption keys.
In addition to the technical walk through, I will release ragavan, a custom exploitation toolkit designed to automate secret extraction, decryption, TPM unsealing, and compromise of a CryptoPro-protected platform.