Daniel Garcia (cr0hn) — Co-Founder
I find and break API security before attackers do. 20+ years hunting vulnerabilities: BOLA, broken auth, injection, SSRF, and the new attack surfaces that MCP servers and LLM tool-calling are opening right now. Alias: cr0hn. Founder of one of Spain's largest cybersecurity conferences. What I work on: — API threat modeling with OWASP API Top 10 as baseline — LLM security: prompt injection defense, MCP server hardening, tool-calling attack surfaces — Python security tooling and open-source CVE research — Training security-aware development teams I've audited APIs and systems across finance, healthtech, and critical infrastructure. The pattern I keep seeing: Teams ship fast and assume the framework handles security. It doesn't. If you build APIs or ship LLM-powered products in production and want them to survive the first real attack — that's exactly what I work on. Weekly analysis on API security and LLM threats: vamosallio.com
Stackforce AI infers this person is a Cybersecurity Expert specializing in API security and LLM threat research.
Experience: 14 yrs 4 mos
Skills
- Cybersecurity
- Management
- Python
- Security-by-design
- Backend Architecture
Career Highlights
- 20+ years of experience in cybersecurity.
- Founder of one of Spain's largest cybersecurity conferences.
- Expert in API security and LLM threat research.
Work Experience
MCP Hub
Co-Founder (3 mos)
Santander
Artificial Intelligence Principal Engineer (8 mos)
Alice & Bob
Founder (1 yr 8 mos)
Token City
Software & Security Engineering Advisor (1 yr)
42Crunch
API Security Research & Software architect (2 yrs 2 mos)
Transaction Network Services
Software & Security Engineering Advisor (3 mos)
confidential
Advisor on cybersecurity (9 mos)
42Crunch
API Security Research consultant (1 yr 4 mos)
CIRCLES
Principal Backend Architect (1 yr 7 mos)
INCIBE - Instituto Nacional de Ciberseguridad
Part of Jury of Hackton in Cybercamp 2017 (1 yr)
BBVA
Security Technical Leader at BBVA Innovation Labs Security (4 yrs 8 mos)
Security Researcher at BBVA Innovation Labs Security (9 mos)
OWASP Madrid Chapter
Chapter Leader (5 yrs 7 mos)
Abirtone
Company Owner (2 yrs 3 mos)
ISBAN
IT Security Architect (11 mos)
Buguroo Offensive Security
Security research and pentester (1 yr 8 mos)
Freelance
Independent security research and pentester (1 mo)
Ecija
Security research and pen-tester (1 yr 8 mos)
Telefónica
Security auditor and pentester (2 yrs 11 mos)
Education
Engineer's degree at Universidad de Castilla-La Mancha