XChronos
Security Research
What is XChronos?
XChronos is a founder-operated security research initiative focused on identifying and validating security issues in selected open-source projects. Its objective is to document reproducible findings, coordinate disclosure with maintainers and publish accurate technical records when appropriate.
The initiative was established in response to the growth of cybercrime reporting and reported losses. In 2025, the FBI’s Internet Crime Complaint Center received 1,008,597 complaints and recorded $20.877 billion in reported losses, 26% more than in 2024. These figures do not represent all cybercrime, but they provide measurable context for XChronos’s focus on careful, reproducible security research. FBI IC3, 2025 Annual Report (PDF).
- Founder
- Eduardo Camarillo
- Operating model
- Founder-operated
- Published
- Specification
- Version 1.0
01 / Mandate
Scope and operating model.
XChronos selects active open-source projects for source review, controlled verification, maintainer coordination and technical publication.
Research program
Project selection, white-box review, controlled verification, coordinated disclosure and public technical records.
Commissioned engagements
Private scopes, schedules, retesting and confidential deliverables are handled separately by Eduardo Camarillo.
Project nominations are considered as research candidates. Selection remains discretionary and a nomination does not guarantee review.
02 / Method
Review and publication process.
Each investigation records its selection basis, scope, review method, validation work and disclosure history.
- 01
Selection
Selection considers project activity, user exposure, technical scope and the availability of a disclosure channel.
- 02
Scope
The record identifies the reviewed version, trust boundaries, assumptions and exclusions.
- 03
Review
Source-level analysis is primary. Controlled dynamic verification is used only when necessary and authorized.
- 04
Validation
Candidate findings are traced, reproduced where possible and tested against compensating controls. Classification follows this review.
- 05
Disclosure
Confirmed findings are reported through the project's available private channel. Publication reflects the coordination status.
03 / Selection
Project selection criteria.
Selection considers project activity, user exposure, practical function, technical surface and disclosure feasibility.
- 01Privacy and secure communications
- 02Software used by vulnerable communities
- 03Health, personal safety and sensitive data
- 04Authentication, authorization and secrets
- 05Projects with active users and maintainers
- 06Infrastructure and widely reused components
Dynamic verification is limited to authorized local or self-hosted environments. Testing scope excludes third-party production infrastructure unless explicit authorization exists.
04 / Disclosure
Disclosure procedure.
Reports use the project's published security policy or another available private channel. Coordination periods are adjusted to the finding and maintainer response.
Proof-of-concept detail is restricted while affected users remain exposed.
Sensitive data is neither collected beyond necessity nor included in publications.
The publication records contact attempts, responses and remediation status.
Corrections are added when subsequent evidence changes the assessment.
05 / Archive
Publication archive.
Entries identify the reviewed version, scope, method, evidence, limitations, disclosure timeline and remediation state.
No investigation has been published under the XChronos name as of 20 September 2026.
Publication-state reference
- Reported
- Sent to the project through a reasonable private channel.
- Acknowledged
- Receipt or partial validity has been recognized.
- Confirmed
- Supported by direct evidence or maintainer confirmation.
- Fixed
- A correction or accepted mitigation is available.
- Disputed
- The technical or impact assessment remains contested.
- No response
- Reasonable contact attempts received no response.
- Informational
- A relevant observation without direct exploitable impact.
- Not exploitable
- The investigated hypothesis was rejected under the reviewed conditions.
06 / Governance
Current governance.
XChronos is founded and operated by Eduardo Camarillo, who is responsible for project selection, technical standards, publication and use of the name.
External contributors may be credited on individual investigations. Representation of XChronos requires authorization from the founder.