vmfunc
| vmfunc | |
|---|---|
| File:Celeste Jessin in 2025.jpgCeleste Jessin in 2025.jpg Celeste Jessin in 2025 | |
| Born | 2006 Paris, France |
| Other names | Celeste Jessin, Celeste |
| 💼 Occupation | Computer hacker, security researcher, software developer |
| Known for | Persona identity verification exposure, SIF pentesting suite |
| 🌐 Website | vmfunc |
vmfunc, also known as Celeste Jessin or Celeste (born 2006), is a computer hacker, security researcher, and software developer specializing in reverse engineering, exploit development, and vulnerability research.[1][2] vmfunc is a member of ud2, a collaborative reverse engineering and capture-the-flag group, and the developer of the open-source SIF penetration testing suite.[2][3]
In February 2026, vmfunc and collaborators published a report exposing privacy vulnerabilities in Persona, an identity-verification provider used by OpenAI and Discord, leading Discord to end its partnership with the company.[4][5] The investigation was covered by publications including Malwarebytes, Kotaku, PC Gamer, Cybernews, and DL News, the latter of which described vmfunc as "widely regarded as credible because of their track record of technical investigations."[6]
Early life
vmfunc was born in 2006 in Paris, France.[7] According to vmfunc's personal website, vmfunc has also resided in Switzerland, Germany, and the United States.[7]
Career
Security tools
vmfunc is the developer of SIF, an open-source penetration testing and reconnaissance suite written in Go.[3] SIF provides directory fuzzing, subdomain enumeration, port scanning, and vulnerability assessment through a modular architecture that supports custom scan definitions.[3][8] The suite is distributed through multiple package managers, including Nixpkgs, Homebrew, and the Arch User Repository.[8]
Software protection analysis
In December 2025, Adafruit Industries featured vmfunc's analysis of the Enigma Protector software protection system, published through the ud2 group.[2] Enigma Protector employs RSA signatures, hardware-bound licensing, anti-debugging measures, and VM-based code obfuscation. The research showed that these protections could be bypassed by using the legacy MS-DOS xcopy command to extract unprotected files during the installation process.[2]
Persona identity verification exposure
In February 2026, vmfunc and researchers MDL and Dziurwa published a report titled "The Watchers," identifying an exposed development environment belonging to Persona, an identity-verification provider used by companies including OpenAI, Discord, and Roblox.[4][1][5] The researchers found that approximately 53 megabytes of internal source code were accessible via unprotected JavaScript source maps on a server authorized through the Federal Risk and Authorization Management Program (FedRAMP).[1][9]
The exposed codebase contained internal screening tools, including an OpenAI-specific watchlist infrastructure established since November 2023, automated reporting integrations with financial regulators including the Financial Crimes Enforcement Network (FinCEN) and FINTRAC, and 269 distinct verification checks on users.[1][9][10] The code also indicated that the platform performed facial recognition screening against terrorism and sanctions watchlists, tracked cryptocurrency wallet addresses, and retained biometric data for up to three years.[9][10]
Following the publication, Persona CEO Rick Song contacted vmfunc directly, requesting the removal of employee names from the report, which vmfunc complied with.[11] Discord subsequently ended its age-verification partnership with Persona.[4][5][12]
Reception
DL News described vmfunc as "widely regarded as credible because of their track record of technical investigations that other security experts have repeatedly validated."[6] Multiple independent security specialists confirmed to DL News that the Persona investigation and its findings appeared legitimate.[6]
Persona CEO Rick Song stated publicly that he "admire[d] @vmfunc's work and their clear talent."[6][11]
The Rage, in an extensive report on the Persona findings, described vmfunc as a security researcher whose investigation prompted questions about the scope of biometric data collection by identity-verification providers.[13]
References
- ↑ 1.0 1.1 1.2 1.3 Naprys, Ernestas (2026-02-19). "Persona leak exposes global surveillance capabilities". Cybernews. Retrieved 2026-02-21.
- ↑ 2.0 2.1 2.2 2.3 Barela, Anne (2025-12-08). "Cracking $200 software protection in a day with xcopy". Adafruit Industries. Retrieved 2026-02-21.
- ↑ 3.0 3.1 3.2 Emms, Steve (2026-01-14). "sif – pentesting (recon/exploitation) suite". LinuxLinks. Retrieved 2026-02-21.
- ↑ 4.0 4.1 4.2 Arntz, Pieter (2026-02-20). "Age verification vendor Persona left frontend exposed, researchers say". Malwarebytes. Retrieved 2026-02-21.
- ↑ 5.0 5.1 5.2 Kotzer, Zack (2026-02-21). "Discord's First Age-Verification 'Experiment' Alarms Hackers". Kotaku. Retrieved 2026-02-21.
- ↑ 6.0 6.1 6.2 6.3 Craig, Tim; Kelly, Liam (2026-02-19). "OpenAI KYC provider accused of sharing users' crypto addresses with federal agencies". DL News. Retrieved 2026-02-21.
- ↑ 7.0 7.1 "vmfunc.gg". vmfunc.gg. Retrieved 2026-02-21.
- ↑ 8.0 8.1 "vmfunc/sif: the blazing-fast pentesting suite". GitHub. Retrieved 2026-02-21.
- ↑ 9.0 9.1 9.2 Gülen, Kerem (2026-02-19). "Is ChatGPT spying for the feds? The 53MB leak behind OpenAI's ID checks". Dataconomy. Retrieved 2026-02-21.
- ↑ 10.0 10.1 "Security researchers claim Persona performs '269 individual verification checks' on user data". PC Gamer. 2026-02-20. Retrieved 2026-02-21.
- ↑ 11.0 11.1 "Persona CEO releases full email chain with vmfunc, as dispute heats up". PiunikaWeb. 2026-02-19. Retrieved 2026-02-21.
- ↑ "Discord age checks spark concern after vendor code appears online". Interesting Engineering. 2026-02-20. Retrieved 2026-02-21.
- ↑ L33tz, L0la (2026-02-19). "Hackers Expose Age-Verification Software Powering Surveillance Web". The Rage. Retrieved 2026-02-21.
External links
Category:2006 births Category:Living people Category:Hackers Category:Reverse engineering Category:People from Paris
This article "Vmfunc (security researcher)" is from Wikipedia. The list of its authors can be seen in its historical and/or the page Edithistory:Vmfunc (security researcher). Articles copied from Draft Namespace on Wikipedia could be seen on the Draft Namespace of Wikipedia and not main one.
