Kelchin

Security architect & researcher

About

I build security systems for fintech, digital assets and AI.

My work combines security architecture with responsibility for how it runs: transaction approvals, custody, incident response and audits. I support around ten security and advisory projects a year, mostly in fintech and digital assets.

I lead security and AI work at Medici Expert / AI Lab. Previously at Crypterium, Choise.com and Vault.ist. Alongside that work, I research vulnerabilities in open-source software.

Published research →

No theory for theory’s sake — only measures that work in the field.

Experience →

Professional experience

My work has included completed PCI DSS and ISO 27001 audits, SOC 2 reporting, and DORA and GDPR compliance programmes.

Medici ExpertAI Lab / security practiceApril 2026 — present

Medici Expert / AI Lab

CTO / Security & Compliance Advisory

Medici Expert · cybersecurity & AI practice

I lead security and compliance advisory for fintech and digital-asset clients, alongside AI-security work. Engagements cover architecture reviews, risk assessments, information security management systems and audit delivery.

I define the scope of the work, coordinate penetration tests and audit preparation, and help teams prioritise remediation. This includes ongoing advisory as well as individual technical reviews.

Vault.ist2025 — April 2026

Vault.ist

AI Architect / Head of Security

Digital banking & embedded-finance infrastructure

I was responsible for custody and transaction security across banking, card and crypto products. I personally designed the Fireblocks controls, from approval policies and signing quorums to wallet separation and recovery.

The work covered who could approve a withdrawal, change a policy or access a co-signer; how to preserve the destination address between approval and signing; and how to recover access without bypassing the controls. I also handled API and webhook security, detection and incident response.

I led the PCI DSS 4.0 workstream through completion and worked on CCSS preparation.

Choise.comWithin the group role

Choise.com

Security architecture & engineering

Crypterium / Choise product ecosystem

Part of my work across the Crypterium / Choise group. I reviewed wallet and card products, APIs, integrations and smart contracts, and worked with product teams on threat modelling and remediation.

Crypterium2021 — 2025

Crypterium

Head of Security → DevSecOps Lead → Security Architect

Consumer fintech & digital-asset products

I helped establish the security function and worked across leadership, DevSecOps and architecture. My responsibilities included incident response, secure development practices and security reviews with engineering teams.

The technical work included cloud and application security, wallet and card infrastructure, code review, bug-bounty coordination and incident investigations.

Research →

Security research

Published advisories from my open-source vulnerability research.

  1. Blind SSRF through OAuth2 avatar synchronisation

    Unvalidated OIDC picture claims can cause a server-side request during avatar synchronisation.

  2. CVE-2026-43905OpenImageIO

    Integer overflow in JPEG 2000 buffer allocation

    An integer overflow in the OpenJPH-backed decoder can produce an undersized allocation.

  3. CVE-2026-43903OpenImageIO

    Heap overflow in SGI RLE decoding

    Run-length bounds that are not enforced in release builds allow out-of-bounds writes.

  4. CVE-2026-42450OpenColorIO

    Stack overflow in the SPI3D LUT parser

    Unbounded parsing of a crafted colour-lookup file can overwrite stack memory.

  5. Integer overflow in ImageChannel::resize

    Incorrect allocation arithmetic can lead to a heap out-of-bounds write.

  6. Path traversal in drive redirection

    An off-by-one validation error permits a final parent-directory component to bypass a path check.

  7. Integer overflow in DWA output-buffer arithmetic

    A missed integer-width conversion can corrupt output-buffer pointer calculations.

  8. Integer overflow in DWA RLE buffer arithmetic

    Incorrect arithmetic in the DWA decoder can lead to heap-memory corruption.

  9. Signed integer overflow in HTJ2K decoding

    Overflow in an HTJ2K decoding calculation affects handling of crafted image data.

  10. Public-only token authorisation bypass

    Organisation API checks did not consistently enforce the public-only token restriction.

Projects →

Projects

Agent security platform

Architecture & engineering

A control layer between an AI agent and the tools, APIs and data it can use. Permissions and execution rules are enforced outside the model.

I designed and built the policy checks, capability controls and signed execution records. Each run produces a record of the checks, decision and actions for later review.

Transaction screening & investigation

System design & engineering

A system for screening crypto transactions and investigating the movement of funds. It keeps the sources and reasoning behind a decision available to the analyst.

I separated screening and graph investigation into a product of their own, with fact provenance and signed decision records. The focus is explaining why a transaction needs attention and what supports that conclusion.

Serebrium

Product architecture & engineering

A security platform for teams that need to collect events, investigate alerts and coordinate a response. I developed the architecture for the platform and its managed-service offering, Aegis.

The work included demo/MVP interfaces, endpoint-agent installation, reporting and response workflows. Blue Agent prepares alert context for the analyst; the SIEM brings events together for investigation.

Education →

Education

All-Russian State University of Justice

Master’s degree in Law

Certificates →

Certifications & training

Certified AI Security Professional (CAISP)

Practical DevSecOps

Red Team Programme

Group-IB

Cyber Investigator

Group-IB

Offensive Security & Defensive Tracks

TryHackMe

Contact →

Contact

For collaboration, research or a technical question.

Email
akelchin96@gmail.com
Telegram
@AlexMedoed
LinkedIn
linkedin.com/in/alex-kelchin
GitHub
github.com/Medoedus
About →