We clicked an Instagram ad to buy a ticket. The login screen had a critical bug, and we are not telling you how it broke.
Nobody hired us to look at this site. We looked anyway, found a critical bug in the only login it had, and chose to disclose it quietly instead of writing a how-to.
Nobody paid us to audit this site. We found a critical login bug anyway, and chose not to explain how.
We clicked an Instagram ad, landed on an event page, and got to checkout. The only way to log in was a phone number and a text code. Everything else about the site felt rushed, so out of habit we tested that one login step. It broke, badly enough that we are not going to explain how in this post. Nobody hired us to look. We looked anyway, wrote it up, and sent it to them for free.
A login screen with one job
The only way into the app was a one-time code sent by text. Ask for a code, type it in, you are in. Out of habit, the kind you cannot switch off once you have spent enough time auditing other people's software, we tested how that step held up under pressure. It did not hold up. What we found was critical severity: serious enough to affect every user on the site, sitting on the only door into the app.
Why we sent an email instead of a screenshot
The easy version of this story is a screenshot and a joke. We did not do that. We wrote up what we found in plain language, wrote a second, more technical version with exactly what an engineer would need to fix it, and sent both directly to the company. No public callout, no company name attached anywhere, no waiting to see what happened first. The point was never to prove we could find something. It was to make sure a stranger with worse intentions did not find it first.
This is also, bluntly, the job. GattyWorks sells software audits: a senior engineer and designer pair going through a live product the way an attacker would, before an attacker does. This was that same read, done on a site nobody was paying us to look at, because the habit does not turn off just because there is no invoice attached.
The part that scales
Finding one bug on one site is a nice story. It is not the business. The business is doing this on purpose, repeatedly, for products that are not ours.
That means knowing who to actually contact at a company, running the same structured checks instead of poking around by hand, and keeping a record so a second pass a month later does not start from zero. We have built our own tooling for exactly that: it works out the right person to reach, runs repeatable scans, keeps a history so nothing gets re-checked from scratch, and helps us pick which product is worth a closer look in the first place. None of it is specific to this one company. It is how every audit starts.
The reason that machinery is worth building is the size of the bill on the other side. The bug sat on the only login the app had. Leave it until a busy event and the cheap version of that day is a drained text-message budget. The expensive version is every paying user locked out at once, support on fire, and people leaving for whoever is still up. A senior pair of eyes on that one flow for two days costs a rounding error next to that. An audit is just paying the small version of the bill, on purpose, while it is still small.
What we would tell any team running a login screen
If the only door into your product is a login step, that door deserves the same scrutiny as the feature you are actually selling. A second pair of eyes on it before a busy weekend is cheap compared to the alternative. We are not going to pretend every team has time to audit its own work while also shipping it. That is exactly the gap a Surface Audit exists to close, in 48 hours, without slowing down what you are building.
Next step: if your login, checkout, or signup flow is the only thing standing between your product and a bad week, a Surface Audit gets a senior pair of eyes on it in 48 hours. Email hello@gattyworks.com; every brief gets a reply within 24 hours.