Black-box teardown
Static and dynamic analysis of closed binaries — tracing call graphs, recovering protocols, and documenting undocumented behavior.
Ponzi Labs is a workshop for reverse engineering and software design — a rotating bench of projects pulled apart, instrumented, and rebuilt. To prove the point, this page has already read you. Everything below is your client, resolved live.
A stable signature derived from how your GPU rasterizes a test image — distinctive enough to single you out in a crowd.
Nothing here is stored or transmitted to us — it is resolved in your browser and on public lookup endpoints, then forgotten on refresh. The point is simply how much a single page request gives away.
A hash of how your audio stack renders a test tone — a second independent signature alongside the canvas hash.
Your installed text-to-speech engines — they leak your OS, region, and every language pack you've added.
None of the above triggered a single permission prompt. This is the baseline a website silently reads the instant you arrive — before you click anything.
Static and dynamic analysis of closed binaries — tracing call graphs, recovering protocols, and documenting undocumented behavior.
Capturing, decoding and re-implementing proprietary wire protocols into clean, documented client libraries.
Designing software from the metal up — clean architectures, careful interfaces, and tools that respect the people using them.
Fingerprinting, telemetry and tracking research — like the readout above. Understanding exposure in order to defend against it.
Ponzi Labs is a reverse-engineering and software-design lab at ponzi.io. It takes software apart — black-box teardowns, protocol reconstruction, systems design, and client-instrumentation research — and rebuilds it cleanly.
Black-box teardowns and binary analysis, device firmware reverse engineering, proprietary protocol reconstruction, systems and API design, and client fingerprinting and privacy research.
No. The live readout is resolved in your browser and at the Cloudflare edge, then forgotten on refresh — nothing is stored or sent to a server. It exists to show how much a single page request reveals.
Reach Ponzi Labs through the contact section at ponzi.io. The lab is open to reverse-engineering and software-design work.
Reverse engineering, software design, or just a hard problem that needs a second set of eyes. The lab is open.
Thanks — your message is in. We'll reply by email, usually within a couple of days.