DEV Community

Cover image for When GitHub Goes Silent: A Security Researcher's Account Suspension Story
KL3FT3Z
KL3FT3Z

Posted on

When GitHub Goes Silent: A Security Researcher's Account Suspension Story

Loss of Docker and LLM security audit tools

On the evening of July 8, 2026, I tried to log into my GitHub account and found myself completely locked out. No warning email. No explanation. Just a login screen that refused to recognize me.

This is the story of what happened, what I did about it, and where things stand now.


The Account

My username was @toxy4ny. I had built a modest but engaged community there:

  • ~2,000 followers
  • 800+ stars across repositories
  • Tools like flibustier (Docker security auditing), redteam-ai-benchmark (LLM robustness evaluation), and others

Everything I published was open-source, educational, and explicitly intended for authorized security research. My work operates under a full framework of professional licenses, contracts, SLAs, and NDAs.

I last accessed the account normally on the afternoon of July 8. By evening, authentication failed completely. The GitHub Status page showed "Actions is currently status yellow," but I have no way to know if that was related or a coincidence.


What I Did

1. Filed a Support Ticket

I used GitHub's "Cannot sign in" form at support.github.com/contact/cannot_sign_in, selecting "Account locked or suspended."

Ticket number: 4548644

I received an auto-reply acknowledging the ticket and warning of "high volumes." I then sent a follow-up with additional context: my professional background, links to my DEV Community articles documenting the research behind each tool, and a clear statement of willingness to cooperate — including making repositories private or removing any flagged content if needed.

Status: No human response. Zero.

2. Reached Out to Leadership

I wrote directly to Kyle Daigle, GitHub's COO, at his public email (kdaigle@github.com). The letter explained the situation, my professional standing, and my commitment to resolving any concerns transparently.

Status: No response.

3. Checked for Public Information

I searched for any news, discussions, or community mentions of my account suspension. Nothing. No Hacker News threads, no Reddit posts, no blog coverage. The block appears to have happened quietly, without public explanation.

I also encountered what appeared to be an AI-generated summary (Google AI Overview) referencing my repositories and suggesting "community concerns" about ethical use. I could not verify this text in any primary source. It may have been synthetic inference rather than factual reporting.


What I Did Next

While waiting for a response that may never come, I took action to protect my work and my community.

Migrated to GitLab

I created gitlab.com/toxy4ny and began transferring repositories:

  • flibustier — Docker security scanner
  • redteam-ai-benchmark — LLM red teaming framework
  • perforator — stress-testing tools
  • decoy-hunter — honeypot detection scanner
  • COPY-FAIL — hardened C implementation for authorized penetration testing

I also built a profile README documenting my background, projects, and contact information.

Why GitLab?

GitLab has a historically more permissive stance toward security research tools. While no platform is immune to account actions, GitLab's self-hosted option (Community Edition) offers a path to true independence if needed.


The Bigger Picture

This isn't just about one account. It's about a pattern many security researchers know too well:

  • Automated enforcement without human review
  • Opaque processes where the accused cannot see the accusation
  • Asymmetric power between platforms and individual contributors

I don't know why my account was suspended. GitHub hasn't told me. I may never know. What I do know is that two years of community building, open-source contributions, and public research can vanish overnight — not because of a clear violation, but because of a black box.


Where Things Stand

Action Status
GitHub Support Ticket #4548644 🟡 No response
Email to Kyle Daigle (COO) 🟡 No response
GitHub account restoration 🔴 Unknown / unlikely
GitLab migration 🟢 Active
Community notification 🟢 In progress

What You Can Do

If you've used my tools, starred my repositories, or found my work useful:

If you're a security researcher with a similar story, I'd like to hear it. These patterns only change when they're documented.


Final Thought

Platforms don't owe us explanations. But communities do owe each other transparency. I'll keep building, keep publishing, and keep documenting — regardless of where the code lives.

The work matters more than the host.


KL3FT3Z (toxy4ny)

Certified Penetration Tester & Red Teamer

Offensive AI Laboratory, HackTeam.RED

tags: github, cybersecurity, opensource, redteam, gitlab

Top comments (8)

Collapse
 
gnomeman4201 profile image
GnomeMan4201

Man Sorry to hear about the lockout…opaque enforcement without human review is a real problem across platforms, not just for security tooling. Good on you for documenting it and migrating proactively. Hope GitHub gives you a real answer.

That being said I thought you were mad at me by un-staring my repos. When it’s someone who has been there from the start of my journey such as yourself , I noticed right away.

Collapse
 
toxy4ny profile image
KL3FT3Z

Unfortunately, when an account is fully banned, all forks of the original source and stars are automatically wiped out; I believe even issues and PRs get removed. GitHub has remained silent so far, but I view this as a badge of international recognition: you aren't a real hacker or cybersecurity professional unless GitHub has nuked your repositories and banned you at least once in your life. For me, a GitHub ban is a mark of quality. It means my tools were important, interesting, and popular within the community. And the fact that they were likely reported by Blue Team or DFIR companies—or their SOCs—is also a mark of quality and an acknowledgment that my tools actually work, even though they label them "dual-use tools."

Collapse
 
gnomeman4201 profile image
GnomeMan4201

I did not say it but I was thinking the same thing. Your GitHub situation means you are doing something that the upper echelon deem dangerous. You are the real deal and your tools show that. Keep doing what you are doing in my opinion. You have genuine followers that will be behind you no matter what platform you have to move to.

Thread Thread
 
toxy4ny profile image
KL3FT3Z • Edited

Thank you for the flattering assessment of my work! It motivates me to keep going and create new things for our community. And yes, if I get banned everywhere, there is always the option of self-hosting Gitea on my own servers—where I make the rules. If the “Le Securite de Carton" crowd considers my tools a threat to the education of others, it only shows their lack of confidence as cybersecurity professionals and their inability to protect even themselves. Banning a tool is the easy way out, but it is impossible to ban the very idea of ​​progress and the evolution of a field like offensive cybersecurity.

Thread Thread
 
gnomeman4201 profile image
GnomeMan4201

Thank you. Hacking and even openly discussing the offensive mindset behind cybersecurity is still treated as taboo by people who do not understand how the field actually works. That lack of understanding makes the path into real security research unnecessarily unclear.

What you are doing helps pave that path for people coming up behind you. You are showing them how to learn real concepts, study bleeding-edge techniques, think like an attacker, and understand dual-use security tools instead of being told that anything offensive is automatically malicious.

Honestly, once you spend enough time in the darker areas of the internet, you realize that many malicious actors are either kids or complete dumb-asses relying on one source for premade tools and scam kits. Half of them probably could not tell the difference between a legitimate cookie stealer and a fake one secretly installing a keylogger on their own machine. You know exactly what I mean?

I will say personally I have learned several mind changing things from your work if that means anything.

Thread Thread
 
toxy4ny profile image
KL3FT3Z

I completely understand you and fully share your position and views. Let me add a thought of my own. If you manufacture high-quality, premium knives and sell them openly, the responsibility for how the knife is used lies with the person who buys and uses it. A knife can be used to slice sausage-or to cut people. Yet, it never occurs to anyone to put the knife manufacturer on trial; instead, judgment falls solely on the criminal who used it for malicious purposes. If we follow that logic, half the items in the world are "dual-use": knives, axes, shovels, forks, chopsticks, medicines-practically anything we use in daily life can become a weapon in the hands of an idiot and cause harm to another person. Yet, for some reason, this concept fails to register with the DFIR and SOC (Blue Team) communities-even though we are well aware of modern infrastructure attacks known as "Living off the Land," where hackers use exclusively legitimate network tools. By their logic, we would have to ban absolutely everything-even FTP, SSH, and RDP clients-both their use and their development!

Thread Thread
 
gnomeman4201 profile image
GnomeMan4201

I think the real problem begins when we judge tools by what they are capable of rather than by how they are developed, presented, and used. Security knowledge is rarely cleanly defensive or offensive; the distinction usually comes from context and conduct. Treating offensive research as inherently irresponsible avoids the difficult conversation, but it does not make the underlying threats disappear.

That is also why I have always been drawn to the offensive mindset. It is more direct, less sanitized, and fundamentally resistant to complacency. At its best, offensive security is not about causing harm; it is about refusing to look away from how systems actually fail.

Thread Thread
 
toxy4ny profile image
KL3FT3Z

I completely agree! My life principle is: attack while you defend! Because only this path can truly protect us from cybercriminals. While we struggle with the moral principles of legality, others will hack systems and corporations without a twinge of conscience. Until we learn to think like criminals, cybersecurity will always be 10 steps behind the real criminals.