# Sam Curry

> Mediated Wiki article. Canonical URL: https://mediated.wiki/source/Sam_Curry
> Markdown URL: https://mediated.wiki/source/Sam_Curry.md
> Source: https://en.wikipedia.org/wiki/Sam_Curry
> Source revision: 1354782997
> License: Creative Commons Attribution-ShareAlike 4.0 International (https://creativecommons.org/licenses/by-sa/4.0/)

For the Scottish footballer, see [Sam Currie](/source/Sam_Currie).

**Sam Curry** (born October 17, 1999) is an American [ethical hacker](/source/Ethical_hacker), [bug bounty](/source/Bug_bounty) hunter, and cybersecurity entrepreneur.[1][2] He has uncovered high‑impact security flaws across a range of technologies and industries. Notably, he led a 2022 project that exposed remote‑control vulnerabilities affecting 20 car manufacturers,[3] and in 2024 he and a colleague revealed a weakness that allowed bypassing of Transportation Security Administration (TSA) airport security screenings.[4]

## Early life and education

Curry grew up in [Omaha, Nebraska](/source/Omaha,_Nebraska) and began hacking at age 12, initially by modifying online video games.[5] He received his first bug‑bounty payout at 15 and by 18 had earned over US$500,000 in rewards.[1]

## Career

### Palisade Security

In 2018 Curry founded the security consulting group Palisade Security, through which he reported serious vulnerabilities in companies including [Apple](/source/Apple_Inc.), [Starbucks](/source/Starbucks), [Atlassian](/source/Atlassian), and [Tesla](/source/Tesla,_Inc.).[6][7] In September 2022, Google mistakenly wired Curry US$249,999.99, an error he publicized and later returned to the company.[8]

### Automotive research

In December 2022, Curry led research that exploited telematics endpoints from SiriusXM to remotely unlock, start, and locate vehicles made by Porsche, Mercedes‑Benz, Ferrari, Toyota, and others.[3]

### Domain registry vulnerabilities

In June 2023, Curry and collaborators demonstrated critical flaws in the infrastructure of multiple country-code top-level domains (ccTLDs), including [.ai](/source/.ai) and [.ly](/source/.ly).[9]

### Loyalty‑program vulnerabilities

In August 2023, Curry, Ian Carroll, and Shubham Shah revealed API flaws in the [Points.com](/source/Points.com) loyalty platform that could grant attackers virtually unlimited airline miles and administrator access to dozens of travel rewards programs.[10]

### 2023 federal detainment

Upon returning from Japan on 15 September 2023, Curry was detained by IRS-CI and DHS agents at Washington Dulles International Airport and served a grand-jury subpoena linked to a cryptocurrency phishing investigation. The subpoena was withdrawn days later.[11]

### Cable modem vulnerabilities

In 2024 Curry discovered an authorization bypass in Cox Communications' device management APIs that allowed attackers to remotely reconfigure or access millions of customer modems.[12]

### Airport security vulnerability

In August 2024, Curry and Ian Carroll disclosed a flaw in the TSA's Known Crewmember (KCM) system that could allow unauthorized access through airport security checkpoints and even cockpit credentials.[13]

### Recruitment‑platform vulnerabilities

In July 2025 a *Wired* investigation revealed that Curry and Ian Carroll had exposed vulnerabilities in McDonald's AI hiring platform, which allowed access to personal data from millions of job applicants.[14]

## Conference speaking

Curry has presented at [DEF CON](/source/DEF_CON), [Black Hat](/source/Black_Hat_Briefings), [Kernelcon](https://kernelcon.org), and [NULLify](https://nullify.uno/) security meet‑ups.[15][16] At DEF CON 32 in 2024, Curry gave a talk titled "Hacking Millions of Modems and Investigating Who Hacked My Modem".[17]

## Selected publications

- Curry, Sam. "We Hacked Apple for 3 Months: Here's What We Found" (2021).[6]
- Curry, Sam. "Web Hackers vs. The Auto Industry: Critical Vulnerabilities in Ferrari, BMW, Rolls Royce, Porsche, and More" (2023).[18]
- Newman, Lily Hay. "Hackers Could Have Scored Unlimited Airline Miles by Targeting One Platform" (2023).[10]

## Philanthropy

In April 2021, Curry donated a US$50,000 bug‑bounty reward to help fund an infant's heart surgery.[19]

## See also

- [Bug bounty program](/source/Bug_bounty_program)
- [Ethical hacking](/source/Ethical_hacking)

## References

1. Ganz, Amy (30 July 2018). ["Teen makes six figures hacking Google, Facebook legally"](https://www.foxbusiness.com/technology/teen-makes-six-figures-hacking-google-facebook-legally). *Fox Business*. Retrieved 14 July 2025.

1. Paul, Kari (23 July 2018). ["This 18‑year‑old's hacking side hustle has earned him $100,000—and it's totally legal"](https://www.marketwatch.com/story/this-18-year-olds-hacking-side-hustle-has-earned-him-100000-and-its-legal-2018-07-23). *MarketWatch*. Retrieved 14 July 2025.

1. Lakshmanan, Ravie (5 December 2022). ["SiriusXM Vulnerability Lets Hackers Remotely Unlock and Start Connected Cars"](https://thehackernews.com/2022/12/siriusxm-vulnerability-lets-hackers.html). *The Hacker News*. Retrieved 14 July 2025.

1. Gatlan, Sergiu (30 August 2024). ["Researchers find SQL injection to bypass airport TSA security checks"](https://www.bleepingcomputer.com/news/security/researchers-find-sql-injection-to-bypass-airport-tsa-security-checks/). *BleepingComputer*. Retrieved 14 July 2025.

1. Haworth‑Elsayed, Jessica (23 April 2019). ["School's out: Meet the teen hackers swapping books for bugs"](https://portswigger.net/daily-swig/schools-out-meet-the-teen-hackers-swapping-books-for-bugs). *PortSwigger*. Retrieved 14 July 2025.

1. Curry, Sam (8 April 2021). ["We Hacked Apple for 3 Months: Here's What We Found"](https://samcurry.net/hacking-apple/). *samcurry.net*. Retrieved 14 July 2025.

1. Pritchard, Stephen (10 May 2021). ["Pega Infinity hotfix released after researchers flag critical authentication bypass vulnerability"](https://portswigger.net/daily-swig/pega-infinity-hotfix-released-after-researchers-flag-critical-authentication-bypass-vulnerability). *PortSwigger*. Retrieved 14 July 2025.

1. Hernandez, Joe (16 September 2022). ["He got an unexplained $250,000 payment from Google. The company says it was a mistake"](https://www.npr.org/2022/09/16/1123290407/google-250000-dollar-payment-hacker). *NPR*. Retrieved 14 July 2025.

1. Targett, Edward (14 June 2023). ["Hackers could have taken over every single .ai domain"](https://www.thestack.technology/dot-ai-domains-hacking-registries/). *The Stack*. Retrieved 14 July 2025.

1. Newman, Lily Hay (3 August 2023). ["Hackers Could Have Scored Unlimited Airline Miles by Targeting One Platform"](https://www.wired.com/story/points-travel-rewards-platform-flaws/). *Wired*. Retrieved 14 July 2025.

1. Whittaker, Zack (27 September 2023). ["Security researcher warns of chilling effect after feds search phone at airport"](https://techcrunch.com/2023/09/27/sam-curry-chilling-effect-phone-search-airport/). *TechCrunch*. Retrieved 14 July 2025.

1. Fadilpašić, Sead (4 June 2024). ["Cox fixes modem security flaw that could have affected millions"](https://www.techradar.com/pro/security/cox-fixes-modem-security-flaw-that-could-have-affected-millions). *TechRadar*. Retrieved 14 July 2025.

1. Lakshmanan, Ravie (30 August 2024). ["Tired of airport security queues? SQL inject yourself into the cockpit, claim researchers"](https://www.theregister.com/2024/08/30/sql_injection_known_crewmember/). *The Register*. Retrieved 14 July 2025.

1. Greenberg, Andy (9 July 2025). ["McDonald's AI Hiring Bot Exposed Millions of Applicants' Data to Hackers Who Tried the Password '123456'"](https://www.wired.com/story/mcdonalds-ai-hiring-chat-bot-paradoxai/). *Wired*. Retrieved 14 July 2025.

1. ["The Talks that Define DEF CON 27"](https://www.bugcrowd.com/blog/the-talks-that-define-def-con-27/). *Bugcrowd*. 5 August 2019. Retrieved 14 July 2025.

1. Murphy, Margi (10 August 2019). ["Inside Black Hat, the world's biggest ethical hacker conference in Las Vegas"](https://www.telegraph.co.uk/technology/2019/08/10/inside-black-hat-worlds-biggest-ethical-hacker-conference-las/). *The Telegraph*. Retrieved 14 July 2025.

1. ["DEF CON 32 – Hacking Millions of Modems (and Investigating Who Hacked My Modem)"](https://infocondb.org/con/def-con/def-con-32/hacking-millions-of-modems-and-investigating-who-hacked-my-modem). *InfoconDB*. Retrieved 14 July 2025.

1. Curry, Sam (26 January 2023). ["Web Hackers vs. The Auto Industry"](https://samcurry.net/web-hackers-vs-the-auto-industry). *samcurry.net*. Retrieved 14 July 2025.

1. Franceschi‑Bicchierai, Lorenzo (26 April 2021). ["Researchers Secure Bug Bounty Payout to Help Raise Funds for Infant's Surgery"](https://www.vice.com/en/article/researchers-secure-bug-bounty-payout-to-help-raise-funds-for-infants-surgery/). *Vice*. Retrieved 14 July 2025.

---
Adapted from the Wikipedia article [Sam Curry](https://en.wikipedia.org/wiki/Sam_Curry) by Wikipedia contributors ([contributor history](https://en.wikipedia.org/wiki/Sam_Curry?action=history)). Available under [Creative Commons Attribution-ShareAlike 4.0 International](https://creativecommons.org/licenses/by-sa/4.0/). Changes may have been made.
