Skip to content
View DefiAudit0x's full-sized avatar
🏠
Working from home
🏠
Working from home

Block or report DefiAudit0x

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
DefiAudit0x/README.md

DefiAudit

Smart Contract Security Researcher · Solidity / EVM · DeFi Security

Building reproducible security tooling, researching smart-contract vulnerabilities, and contributing to the open-source infrastructure used by security researchers.

X Telegram GitHub


Core focus

  • Solidity / EVM security
  • DeFi & cross-chain attack surfaces
  • Protocol invariants, fuzzing & exploit reproduction
  • Static analysis and security automation
  • Sui Move security
  • Foundry, Echidna, Medusa & Slither

Selected security work

Project What it demonstrates
EVM Audit Lab Reproducible Solidity vulnerability labs — vulnerable vs. remediated, with exploit and regression tests.
Audit Reports Public security research, audit methodology, findings and sanitized case studies.
Smart Contract Auditor Multi-pass smart-contract analysis with static pre-scan, CVSS 4.0, SARIF and reproducible benchmarks.
DefiAudit Labs Research and tooling organization for security-focused projects.

Open-source security contributions

I don't just audit contracts. I contribute to the tools and test infrastructure security researchers use to audit them.

Crytic ecosystem

  • Echidna #1631 — cap generated msg.value at the sender's balance.

  • Echidna #1609 — isolate shrinking worker state.

  • Echidna #1610 — deterministic boolean corpus coverage counts. Merged

  • Echidna #1632 — document the JSON output schema accurately.

  • Medusa #845 — array structure mutations for ABI values.

  • Medusa #846 — separate ABI encoding/decoding helpers.

  • Medusa #844 — decouple value generation from mutation.

  • Medusa #839 — on-chain fuzzing / fork-mode documentation.

  • Medusa #838 — fail-fast fuzz test utilities. Merged

  • Slither #3094 — correctly merge inherited using-for directives.

  • Slither #3093 — quantum-vulnerable signature detector.

  • Foundry #16696 — preserve NatSpec characters inside fenced code blocks. Merged

  • Cross-chain payments #8 — boundary and fuzz tests for StreamEscrow and MilestoneEscrow, including conservation-of-value and accounting invariants. Open

Other merged open-source contributions include TermLens #158 and AudioBard #23.


Security methodology

My workflow is centered on reproducibility and narrow claims:

  1. Establish scope, trust boundaries and assumptions.
  2. Identify privileged flows, accounting, external calls, oracles and upgrade paths.
  3. Form explicit vulnerability hypotheses and test them against the code.
  4. Reproduce material findings with minimal PoCs.
  5. Argue impact and exploitability without overstating severity.
  6. Propose narrow remediation and verify it with regression tests.

Tool output is treated as evidence and a lead — not a substitute for protocol reasoning.


Research

Current research areas include:

  • Smart-contract vulnerability patterns
  • DeFi accounting and invariant failures
  • Cross-chain and bridge security
  • Fuzzing and property-based testing
  • Static-analysis tooling
  • Security automation and AI-assisted analysis

Responsible disclosure

Public work is labeled clearly as independent research, educational material, contest-based research, or client-approved material where applicable.

I do not publish private client details, credentials, or unauthorized weaponized exploit instructions.


Contact

Find the bug. Reproduce it. Explain the root cause. Make the fix testable.

Pinned Loading

  1. evm-audit-lab evm-audit-lab Public

    Reproducible Solidity and EVM security labs — vulnerable vs. remediated, side by side.

    Solidity

  2. Audit-Reports Audit-Reports Public

    Public smart-contract security research, educational case studies, and sanitized audit material by DefiAudit.

  3. DefiAudit0x DefiAudit0x Public

    DeFi Security Researcher · Solidity & EVM + Sui Move · Founder of @DefiAudit-Labs

  4. smart-contract-auditor smart-contract-auditor Public

    Enterprise-grade smart contract security auditor: multi-pass LLM analysis, 7 parallel static pre-scan modules, CVSS 4.0 scoring, Foundry-verified benchmarks, SARIF export, and a real-time streaming…

    Python

  5. wildfire-observatory wildfire-observatory Public

    Security-focused full-stack engineering showcase — geospatial early-warning platform with CI/CD, validation, and resilient data flows.

    TypeScript