Zaidu Abubakar

Riciplay - Multi-agent AI for bug bounty & security research.

by
Bug bounty hunting is still mostly manual — paste a URL, get noise, spend hours triaging false positives. Riciplay fixes that with a multi-agent AI system: a Leader + 10 specialists across Web2 & Web3, running structured investigation phases from recon to exploitation. Built-in proof engine, 7-stage confidence audit, report validator, browser-based terminal, and crypto payments.

Add a comment

Replies

Best
Zaidu Abubakar
Hey Product Hunt 👋 I started Riciplay because I was frustrated with my own bug bounty workflow. I'm a self-taught developer doing authorized security research on platforms like HackenProof, and every tool I used felt like it was built for a different person — enterprise scanners with massive setups, AI tools that hallucinate findings, and no single place that took you from "I have a target URL" all the way to "I have a report ready to submit." So I built it myself. On mobile. From Termux on Android The hardest problem wasn't the scanner or even the AI — it was false positives. Early versions of the investigation pipeline would surface findings that looked real but weren't. That pushed me to build the proof engine, the 7-stage confidence audit, the argumentation system where agents debate each other. Every major feature came from a real pain I hit while doing actual research. What started as a personal toolkit is now a full platform — multi-agent AI investigations across Web2 and Web3, a browser-based terminal, report validator, Chrome extension, GitHub scanner, and crypto payments for a community that lives on-chain. Today's launch is Phase 30, which was entirely focused on noise reduction and AI hallucination prevention — because the most important thing a security tool can do is not waste your time. Happy to answer anything — architecture, how the agent pipeline works, the Web3 side, whatever you're curious about. 🔐