Software developer & security researcher

ToprakYağcıoğlu

I build apps for iPhone and Mac. On the side I look for security holes in other people’s backends. Twice I found real ones.

22, from Türkiye, living in Madrid. Guitar since 13, and I still can’t play Echoes without cheating.

Portrait of Toprak
Out now · iOS
Öğrenci Nerede YerWhere students in Istanbul eat, rated by students. Free on iPhone.
Download on theApp Store
Selected work
  1. GlitchMy pentest tool · private alpha
  2. ToneForgeThe rig I play through every day
  3. AboutThe longer version

Ships

Two are out. Two are still on my desk.

01 · Out now · iOS · free

Öğrenci Nerede Yer

The name is Turkish for “where do students eat?”. Students in Istanbul rate places on taste, price and vibe, post what they ate, find someone to eat with, and chat.

It’s React Native and Expo on top of Supabase. Twenty Postgres tables, every one of them behind row-level security, and ten Zustand stores that update the screen before the server answers.

The bug I remember most: chat getting out of sync when a phone came back online after hours offline. Delete your account and it’s really gone. That part runs in an Edge Function, for GDPR.

  • TypeScript
  • React Native
  • Expo
  • Supabase
  • Postgres
  • Zustand
  • Sentry

02 · In development · private alpha

Glitch

My own pentest tool for macOS. Think Burp Suite, with a coding agent living inside it.

Every request goes through mitmproxy and is saved to disk. Right-click one and an agent starts on just that request, with its own MCP server and a fixed scope.

The scanner is a Python planner that hands work to small specialist agents. A verifier checks every finding before it counts. Findings are plain files, so if the database breaks, Glitch rebuilds it from them.

It’s in private alpha. If you want to see it, ask me and I’ll show you on a call.

  • Electron
  • TypeScript
  • Python
  • mitmproxy
  • MCP
  • SQLite
That verifier is what turned it from a chat toy into a tool.
Glitch workspace: the driver agent in the middle, findings on the right
The workspace. The driver works in the middle, proven findings stack up on the right.
The Wire: list of requests captured by the proxy
The wire: every request the proxy caught.
The Dossier: security findings report
The dossier: the report you hand to a triager.

03 · Open source · MIT · 70★

Dusty

A free Mac cleaner that shows you everything before it deletes anything.

Dusty scanning caches and listing them by size

I wanted a cleaner I could trust on my own Mac. Dusty only touches a fixed list of cache and junk folders. Documents, Photos and Mail are out of reach.

It finds the usual developer mess: Xcode DerivedData, old simulators, npm, pip, cargo and Homebrew caches, local Time Machine snapshots. Files go to the Trash first, you get an Undo, and every deletion is written to a log you can open.

It’s signed and notarised. One command to install:

brew install --cask yagcioglutoprak/tap/dusty
  • Swift
  • SwiftUI
  • MenuBarExtra
  • SwiftPM
  • Homebrew

04 · In development · macOS

ToneForge

A guitar rig that runs on my Mac. I built it because nothing I owned sounded like the tone in my head.

29Effects
118Presets
9Amp models
~8 MSRound trip

The audio code is plain C. It never allocates and never locks, because on the audio thread one hiccup is a click you can hear. Everything above the audio thread is Swift.

Inside: an octaver, a harmoniser, a tuner, Fuzz Face and Big Muff models, tube amps with real tonestack values, MIDI and a 60-second looper. YIN pitch detection was my excuse to read DSP papers in cafés. I play through it every day. It’s not public yet, but I can send you a signed build.

  • Swift
  • SwiftUI
  • AVAudioEngine
  • C DSP
  • CoreMIDI

Breaks

Two real bugs, both fixed.

HackerOne · @toprak_yProfile and resolved reports ↗

Amazon

Fixed · responsible disclosure

Details stay private, per the programme rules.

Trendyol

Fixed · responsible disclosure

Details stay private, per the programme rules.

Found it, wrote it up, sent it in.

I found one bug in Amazon and one in Trendyol, and reported both through responsible disclosure. Both teams confirmed them and shipped a fix.

I can’t publish the details. That’s the deal when a company lets you test them. Ask me in person and I’ll tell you what I can.

About

The longer version.

Hi. I’m Toprak, 22, from Türkiye. I spent the last three years in Wrocław studying software engineering at WSB Merito, and I’m in my third year now. In August I joined ShuttleCloud, and in September I moved to Madrid for the job.

Outside work I’m usually building something. I use coding agents a lot. They let me ship more than I could alone, but the part I enjoy is the plumbing around them: planners, small specialist agents, custom MCP servers, and keeping all of it on task. Glitch is where I try those ideas.

The security side is HackerOne and mitmproxy. I like opening an app, watching its traffic, and finding the one thing the backend trusted too much.

I like finding the one thing the backend trusted too much.

Guitar came before all of it. I started at 13. Most days it’s Pink Floyd, The Doors, Jimi Hendrix or Bob Marley in my ears. I learn Gilmour’s solos by ear, slowly, and my bends are still not where I want them.

Other things: I make Turkish coffee every day and burn it a little most days. My French is close to B2. My Spanish is at zero, and Madrid is fixing that fast.

Stack

In order of how often I use it.

Languages

TypeScript, Swift, Python, JavaScript, SQL, C, Bash.

Native & mobile

React Native, Expo, SwiftUI, AppKit, AVAudioEngine.

Backend

Supabase, Postgres (RLS, RPCs), Node, Flask, Deno.

DevOps

GitHub Actions, EAS Build, Docker, nginx, Sentry.

Security

mitmproxy, Burp Suite, Model Context Protocol, responsible disclosure.