Mobile security startup Oversecured launches after self-funding $1 million, thanks to bug bounty payouts

You might not have heard of Sergei Toshin, but you should know his work.
Toshin is a 23-year-old security researcher in Moscow who focuses largely on mobile app security. With his knowledge of what different mobile security flaws looked like, Toshin built a custom Android mobile app vulnerability scanner to quickly and automatically find vulnerabilities in an app’s code, he told TechCrunch.
The scanner works by decompiling the Android app and running through the source code line-by-line — just as a human would — and detecting possible flaws in code where a vulnerability could be triggered. It takes a set of rules, which effectively describes different kinds of vulnerabilities, and searches for vulnerable code that meets those conditions, Toshin said.
Once the scanner finishes, it spits out a report describing where the vulnerabilities are in the code.
It was using this scanner, which he developed over the course of the last two years, that he was able to speed up the process of finding bugs.
“To participate in a bug bounty, I would just download the app and copy the vulnerabilities identified in the vulnerability report,” he said.
In August, he revealed details of an Android vulnerability that allowed malicious apps to steal sensitive user data from other apps on the same device. Two weeks later, he dropped details of a bug in TikTok’s Android app that could have led to hijacking of user accounts.
These are just two out of hundreds of security bugs he has reported to companies through their bug bounty programs, a way for researchers to warn companies of potential issues while getting paid for their findings.
“It occurred to me to launch a startup and begin helping other companies find vulnerabilities in their mobile apps,” Toshin told TechCrunch.

One of the vulnerability scanner’s reports for an Android app. (Image: Oversecured)
And that’s how Oversecured was founded. But how Toshin funded his startup was somewhat unconventional.
What’s unusual about Oversecured is not that it’s self-funded, but it launched out of a product that effectively paid for itself. Toshin netted more than $1 million in bug bounties in a year using his scanner, in large part thanks to Google’s security rewards program, which pays security researchers far more for security bugs found in Android apps with over 100 million installs.
Oversecured is not yet profitable, but Toshin has also not taken any venture-backed funding to date. The company now has about five developers, as well as designers and translators as all efforts focus on building and improving the scanner.
The startup so far only supports scanning Android apps. Toshin said the scanner is open to bug hunters and security researchers, who can pay to scan each app — with five scans tossed in for free.
But Toshin is betting big on allowing enterprise customers to buy access to the scanner and integrate it with their development tools. Oversecured launched its B2B offering last week, allowing app makers to integrate the scanner directly into their existing app development processes to find bugs during coding.
Toshin said that enterprise customers will soon get support for scanning Swift source code for iOS apps.
Oversecured joins a number of other established app security companies in the space. But Toshin is confident that his technology stands among the crowd.
“It’s important to find everything,” he said.
Read more:
You might not have heard of Sergei Toshin, but you should know his work. Toshin is a 23-year-old security researcher in Moscow who focuses largely on mobile app security. With his knowledge of what different mobile security flaws looked like, Toshin built a custom Android mobile app vulnerability scanner to…
Recent Posts
- Reddit is experiencing outages again
- OpenAI confirms 400 million weekly ChatGPT users – here’s 5 great ways to use the world’s most popular AI chatbot
- Elon Musk’s AI said he and Trump deserve the death penalty
- Grok resets the AI race
- The GSA is shutting down its EV chargers, calling them ‘not mission critical’
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010