Kelchin

Security architect & researcher

About

I build security systems for fintech, digital assets and AI.

I work on security for financial products and AI systems: architecture reviews, application security, custody controls and incident response.

Currently at Medici AI Lab. Previously at Crypterium, Choise.com and Vault.ist. I also research vulnerabilities in open-source software.

Published research →

No theory for theory’s sake — only measures that work in the field.

— Alex Kelchin
Experience →

Professional experience

Medici AI Lab

CTO / Security & Compliance Advisory

Medici Expert · cybersecurity & AI practice

I work on security and AI-security projects for fintech and digital-asset businesses. This includes risk assessments, architecture reviews, information security management systems and audit preparation.

I also coordinate penetration tests and certification work, and help define the scope and delivery of ongoing security advisory services.

Vault.ist2025 — April 2026

Vault.ist

AI Architect / Head of Security

Digital banking & embedded-finance infrastructure

I led security for banking, card and crypto products, covering transaction approvals, ledger checks, custody and blockchain signing.

I designed Fireblocks signing policies, wallet separation and recovery procedures. Other work included API and webhook security, privileged access, cloud security, detection and incident response.

I led the PCI DSS 4.0 workstream and worked on CCSS preparation.

Choise.comWithin the group role

Choise.com

Security architecture & engineering

Crypterium / Choise product ecosystem

Part of my work across the Crypterium / Choise group. I reviewed wallet and card products, APIs, integrations and smart contracts, and worked with product teams on threat modelling and remediation.

Crypterium2021 — 2025

Crypterium

Head of Security → DevSecOps Lead → Security Architect

Consumer fintech & digital-asset products

I worked across security leadership, DevSecOps and architecture, helping establish the security function, incident response and secure development practices.

The technical work included cloud and application security, wallet and card infrastructure, code review, bug-bounty coordination and incident investigations.

Research →

Security research

Published advisories from my open-source vulnerability research.

  1. Blind SSRF through OAuth2 avatar synchronisation

    Unvalidated OIDC picture claims can cause a server-side request during avatar synchronisation.

  2. CVE-2026-43905OpenImageIO

    Integer overflow in JPEG 2000 buffer allocation

    An integer overflow in the OpenJPH-backed decoder can produce an undersized allocation.

  3. CVE-2026-43903OpenImageIO

    Heap overflow in SGI RLE decoding

    Run-length bounds that are not enforced in release builds allow out-of-bounds writes.

  4. CVE-2026-42450OpenColorIO

    Stack overflow in the SPI3D LUT parser

    Unbounded parsing of a crafted colour-lookup file can overwrite stack memory.

  5. Integer overflow in ImageChannel::resize

    Incorrect allocation arithmetic can lead to a heap out-of-bounds write.

  6. Path traversal in drive redirection

    An off-by-one validation error permits a final parent-directory component to bypass a path check.

  7. Integer overflow in DWA output-buffer arithmetic

    A missed integer-width conversion can corrupt output-buffer pointer calculations.

  8. Integer overflow in DWA RLE buffer arithmetic

    Incorrect arithmetic in the DWA decoder can lead to heap-memory corruption.

  9. Signed integer overflow in HTJ2K decoding

    Overflow in an HTJ2K decoding calculation affects handling of crafted image data.

  10. Public-only token authorisation bypass

    Organisation API checks did not consistently enforce the public-only token restriction.

Projects →

Projects

Agent security platform

Co-founder · architecture & research

A platform for controlling AI-agent permissions, checking tool calls against policies and recording actions for review. My work covers architecture, local deployment and signed execution records.

Transaction-risk analysis

System design · validation tooling

A prototype for reviewing transaction-risk signals and controlling financial actions. I work on policy checks, tenant isolation, request validation and execution records.

Serebrium / Aegis

Security-platform architecture

A security-operations prototype combining event analysis, asset information and assisted response. I designed the components for event collection, analysis and reporting.

Security agents

Evaluation design · automation

Experimental agents for adversarial testing, defensive checks and security analysis. I work on tool permissions, repeatable tests and evaluation criteria.

Architecture · access controls

An internal research assistant for legal and compliance documents, with document-level access controls and audit logging. My work covers retrieval architecture and access to source material.

Security-operations automation

Workflow design · engineering

Workflows for security reviews, evidence collection, incident documentation and reporting. I build tools to track findings, assign remediation and retain the supporting records.

Education →

Education

All-Russian State University of Justice

Master’s degree in Law

Certificates →

Certifications & training

Certified AI Security Professional (CAISP)

Practical DevSecOps

Red Team Programme

Group-IB

Cyber Investigator

Group-IB

Offensive Security & Defensive Tracks

TryHackMe

Contact →

Contact

For collaboration, research or a technical question.

Email
akelchin96@gmail.com
Telegram
@AlexMedoed
LinkedIn
linkedin.com/in/alex-kelchin
GitHub
github.com/Medoedus
About →