# XChronos Security Research XChronos is a founder-operated security research initiative focused on identifying and validating security issues in selected open-source projects. Its objective is to document reproducible findings, coordinate disclosure with maintainers and publish accurate technical records when appropriate. The initiative was established in response to the growth of cybercrime reporting and reported losses. In 2025, the FBI Internet Crime Complaint Center received 1,008,597 complaints and recorded $20.877 billion in reported losses, 26% more than in 2024. These figures do not represent all cybercrime, but they provide measurable context for the initiative's focus on careful, reproducible security research. Source: FBI IC3 2025 Annual Report — https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf Current state as of 20 September 2026: no investigation has been published under the XChronos name. ## Operating model - Selection considers project activity, user exposure, technical scope and disclosure feasibility. - Source-level analysis is primary; dynamic verification is controlled and authorized. - Candidate findings are traced, reproduced where possible and reviewed against compensating controls. Confirmed findings are reported through available private channels. - Commissioned assessments and confidential work are separate from XChronos. - AI may be used for code reading, documentation review, hypothesis generation and report preparation. Eduardo Camarillo reviews reproduction, classification and publication decisions. ## Identity - Founder and operator: Eduardo Camarillo - Website: https://xchronos.noir0x63.org/ - Formal specification: version 1.0, published 20 September 2026