it was never about the bounty

nightmare eclipse says the feud everyone reported as a bug bounty dispute started with his firing

7 min read
in this post

introduction

nightmare eclipse, chaotic eclipse, dead eclipse, msnightmare. he's been through a few names these past few months

he's been casually dropping windows exploits since april, starting with bluehammer. most target defender or something around it

other researchers were posting about their own problems with msrc too. reports ignored, downgraded, or patched without a reply

i'd only followed it through the articles until he opened a discord server last evening

what everyone knew

it started on march 26th 2026 with a blog post:

But someone violated our agreement and left me homeless with nothing. They knew this will happen and they still stabbed me in the back anyways, this is their decision not mine.

then a week later he dropped bluehammer

he didnt say what the agreement was. in may he was still talking about unpaid reports:

You defame me in public with your CVE-2026-45585 advisory even though you literally deleted the Microsoft account I used to report bugs to you with and I got zero pennies from doing so.

the coverage i read treated it as a bug bounty dispute

microsoft answered on may 28th with an msrc post - "A shared responsibility: Protecting customers through Coordinated Vulnerability Disclosure". the vulnerabilities werent responsibly disclosed, customers were being put at risk, and they brought up the digital crimes unit and were working with law enforcement. they faced so much backslash that within days they put out a softer version: no intention of pursuing people doing or publishing security research, plus an admission that some of their interactions with researchers had fallen short

discord server

on august 18th, around 8:42 pm cest, the twitter account everyone attributes to him posted an invite

screenshot of the discord invite screen for a server called MSLoversClub, 90 online, 267 members

so i joined. there were bit more than 200 members, few text channels, one of them being called questions-that-may-or-may-not-be-answered (which aged well)

i kept running DiscordChatExporter over the channels every so often, because i felt like this server won't last

the microsoft story

at 9:32 pm he opened a thread. first message: "The Microsoft story"

someone asked how he even talks to microsoft. email, something encrypted?

im genuinely curious what typa communication do you have with msftlike how do they communicate w youis it thru like email or something encrypted?I was an employeeholy shitIt was internal Microsoft emails/Teams
What was your role at MS?What was your role at MS?Security Researcher at MSRC Vulnerabilities and Mitigations

i'd been reading about him as an external researcher. this was the first time i'd seen him say he worked at msrc

getting fired

There was a meeting between me and my CISO which is Tom Gallagherwas thinking this is probably just like another meetinghe's new so maybe he wants to know meturns out it was not the casewhen i joined the meeting, HR was thereI knew it was all overbut I still wanted to know whyTom Gallagher told me, I did actions that have harmed "Microsoft customers"I asked for details or anything, they said no, we're not giving you any details

this was october 2024, which somebody in the channel noticed straight away:

no when ? why ? how ? no nothingso from what I understood in the timeline, it was in october 2024? wasn't it way before your first vulnerability posted on X? Or am I missing somethingso from what I understood in the timeline, it was in october 2024? wasn't it way bef…yeap2024, October

so about eighteen months between that meeting and the first exploit going out

the severance offers

he said we're not telling you anything else, sign this paper and get the fuck outthe offer they gave me was insultingly low20,000€ and fuck off
they hired a lawyer, sent me an emailsaying "OMG Microsoft paid you really well since you only worked here for 6 months, this is a great severance, you should take it"I obviously refusednew offer was 27,000€obviously I refused again, that much work I put for MSFTthat 3 years of sweat I put for Microsoftwas just not worth a 27,000€ severance

he also said he was up for a promotion, and that his own manager only found out the day before

the accusation

he begged gallagher for another meeting just to find out the reason for his firing. he got one:

he told me I'm completely blacklisted from ever entering Microsoft again and I will have a horrible referral if I asked for one from MicrosoftThe only thing that I got from him was, He just does not trust me and would never say whyAfter a while I got an email from him claiming that I "I gave vulnerability details to a third party" with no more details, no who is this third party, when did it happen ? questions we'll never know

access

Microsoft has suspiciously kept my access to every single thing I had access to even if the decision was to actually fire mefor almost 2 weeks I had unrestricted access to all communications/source codeI felt like there was some sort honeypot waiting for me to do some sort of mistake to justify the firingbut they scrutinized the records mullions of times and did not find any valid reason to fire memy record was just clean

i asked if the two weeks couldve been his notice period, if he was still in probezeit

then he gave the dates:

Until late Oct/Sept (i don't remember when exactly) they revoked all of my access to everythingI did not get a termination letter until next year, I can still remember it, horrible day and then I get a Microsoft official termination 3 of March 2025Last working day30 June 2025

so the actual termination came months after the meeting. that doesnt explain the two weeks of access

court

he says people around him pushed him to sue. the hearing was may 2025

this was microsoft's defence:

they claimed that I was working in germany illegalyinsane thing is they are the ones who did my visaand i scrutinized everything, all of my documents were validthe visa explicitly says I'm allowed to work for MSFTmy residence permit says "NOT AUTHORIZED TO WORK, SEE ADDITIONAL SHEET"Microsoft SPECIFICALLY pointed at that, hey he isn't allowed to work here so that's why we fired himafter a long argument, I brought them the additional sheetthat once again says "Authorized to work for Microsoft Deutschland GMBH"

the additional sheet is where the work permission lives. so he brought that:

OOOOOOOmg our bad, see we requested those documentations from him multiple times but he never replied to usI asked, where tf did you ask for them ?In your work emailbro you blocked my work email a long time agohow tf am i supposed to get them ?court decided that them sending emails and me not receiving them was just a miscommunication

the threat claim

then microsoft argued he'd threatened them, with a witness:

yeap, they said that I threatened them and there are witnesseswho is the witness ? "Tom Gallagher"the dude who is totally not gonna lie for corpo profile, has no consequences of him lying or whatsoever

he put the end of the case a month before bluehammer, though the dates dont line up:

okay who am i wasting my time withclearly I'm not winningthen bluehammer happend in Apriland yall are aware of the rest

my questions

i asked whether he'd been fired without notice, and whether he'd asked for the reason in writing:

i (unfortunately) also live in germany, so i was wondering, was that a fristlose kündigung? asking because under §626(2) BGB, if you request it, the employer has to give you the reason in writing. did you ever request that from microsoft, what did they say?if you request it, the employer has to give you the reason in writing. did you ever request that from microsoft, what did they say?they refused, there is nothing you can do about it

the channel kept getting locked and unlocked so i dm'd him too, about whether he ever tried a neutral third party (cert/cc or similar) before any of this went public:

sorry for dming you, this is related to what you're discussing right now, and im afraid you might have moved on to other questions by the time the channel unlocks

i (unfortunately) also live in germany, so i was wondering, was that a fristlose kündigung? asking because under §626(2) BGB, if you request it, the employer has to give you the reason in writing. did you ever request that from microsoft, what did they say?
i wonder if he ever ever try bringing in a third-party mediator/coordinator like cert/cc to try and resolve w/ ms before going publictheir response is go fuck yourselfI tried everythingMS has enough money to be over the lawthere is nothing you can do about it

i also asked if microsoft ever named the third party in court:

After a while I got an email from him claiming that I "I gave vulnerability details…when this went to court, did microsoft ever name the said third party?when this went to court, did microsoft ever name the said third party?nowhen this went to court, did microsoft ever name the said third party?they never said anything about me ever leaking anything

someone asked whether the court documents are public. "not yet"

not the bounty

at 11:05 pm cest i asked whether microsoft ever produced any evidence for the leak claim:

do they have evidendce though? did ms ever produce any logs,etc in court, supporting the claim that you shared vuln details with anyone?do they have evidendce though? did ms ever produce any logs,etc in court, supporting…no, it was plain go fuck yourselfssoit was no me protesting abt bountyit was just protesting this unusual firing technique

so why had he kept the firing quiet?

it was just protesting this unusual firing techniqueif this was about the firing from the start, why did you keep the employment part vague publicly for so long?

he didnt answer. a couple minutes later the server disappeared from my sidebar. on twitter shortly after: "Closed, too much headache"

fact checking

i saved the chat, but i dont have his court documents or a way to check who was behind the account

employment history

the verge and krebs had already reported that he might be an ex employee. the register asked microsoft about it on may 28th and got no answer

i kept seeing september 2022 to june 2025 given as his employment dates, usually citing krebs or the register. i checked both and couldnt find those dates in either. some write ups mentioned linkedin and hackerone too, but i couldnt trace it back

gallagher’s role

he calls tom gallagher his CISO. gallagher is vp of engineering at msrc. somebody in the channel checked his linkedin:

The direct threat was from Tom Gallagher, had a meeting with him, he was CISO at the October 2024, was working for MSRC for two years and a half at that pointHis LinkedIn says 27 years

the dates

he said "that March last year", then put bluehammer a month later. bluehammer was april 2026. did he mean march this year?

microsoft's lawyer told him he'd only been there six months, he says three years. both can be true. the visa sheet names "Microsoft Deutschland GMBH" specifically. so if he moved onto the german payroll partway through, that job would only be six months old, while microsoft as a whole is still three (?)

what he admitted

and then theres this, fourteen minutes before he started the story:

now i may have lied about some stuff i saidmaybe a lot of stuffonly did that because MS lied in courtif they gonna lie in court and they believe themwhy not just lie in public as well ?What did you lie about?I don't remember, have of the stuff I wrote, I probably forgot

i would like to see those court documents

what i think

maybe he is a bit of a hero for getting other researchers to speak up. people were talking about reports msrc had ignored or downgraded, and i think thats a good thing even if his own reason for doing this was different

but i cant really support releasing exploits people can use against others. huntress saw three of his exploits used against a company in april. none appears to have worked in that case

i still want to know why he kept the firing quiet for five months. i hope things start going better for him, but theres a lot here i cant check

update

august 19th

7:30 pm. i was finishing this article when he posted something on twitter suggesting that he had taken an overdose

august 20th and 21st

he kept posting:

september 11th

he's posting as "Abdelhamid Naceri" now:

his work history

theres a linkedin profile under that name with the september 2022 to june 2025 dates i couldnt find earlier:

screenshot of a linkedin profile under the same name listing a microsoft security researcher role from september 2022 to june 2025

searching the name and the usernames halov and halove23 also turns up a long history of vulnerability research and cve credits. zdi credits "Abdelhamid Naceri (halov)" for CVE-2021-27070 and CVE-2021-45231, among others. halove23 also appears in an older mozilla vulnerability report

september 13th

he posted his side on twitter too, including an email from gallagher

the offers and email

mostly the same story he told us in august. the meeting is now september 2024 instead of october, which fits the date on the email

termination and court

he also shared his termination letter, dated march 3rd 2025, with employment ending on june 30th. those dates match his earlier messages. it says he was released from work with continued pay (im not attaching the photo because it includes his home address)

he now says his visa had expired, after telling us all his documents were valid. not sure what to make of that

the aftermath

and then he added this:

comments

0 comments