Smart Contract Security Researcher · Solidity / EVM · DeFi Security
Building reproducible security tooling, researching smart-contract vulnerabilities, and contributing to the open-source infrastructure used by security researchers.
- Solidity / EVM security
- DeFi & cross-chain attack surfaces
- Protocol invariants, fuzzing & exploit reproduction
- Static analysis and security automation
- Sui Move security
- Foundry, Echidna, Medusa & Slither
| Project | What it demonstrates |
|---|---|
| EVM Audit Lab | Reproducible Solidity vulnerability labs — vulnerable vs. remediated, with exploit and regression tests. |
| Audit Reports | Public security research, audit methodology, findings and sanitized case studies. |
| Smart Contract Auditor | Multi-pass smart-contract analysis with static pre-scan, CVSS 4.0, SARIF and reproducible benchmarks. |
| DefiAudit Labs | Research and tooling organization for security-focused projects. |
I don't just audit contracts. I contribute to the tools and test infrastructure security researchers use to audit them.
-
Echidna #1631 — cap generated
msg.valueat the sender's balance. -
Echidna #1609 — isolate shrinking worker state.
-
Echidna #1610 — deterministic boolean corpus coverage counts. Merged
-
Echidna #1632 — document the JSON output schema accurately.
-
Medusa #845 — array structure mutations for ABI values.
-
Medusa #846 — separate ABI encoding/decoding helpers.
-
Medusa #844 — decouple value generation from mutation.
-
Medusa #839 — on-chain fuzzing / fork-mode documentation.
-
Medusa #838 — fail-fast fuzz test utilities. Merged
-
Slither #3094 — correctly merge inherited
using-fordirectives. -
Slither #3093 — quantum-vulnerable signature detector.
-
Foundry #16696 — preserve NatSpec characters inside fenced code blocks. Merged
-
Cross-chain payments #8 — boundary and fuzz tests for
StreamEscrowandMilestoneEscrow, including conservation-of-value and accounting invariants. Open
Other merged open-source contributions include TermLens #158 and AudioBard #23.
My workflow is centered on reproducibility and narrow claims:
- Establish scope, trust boundaries and assumptions.
- Identify privileged flows, accounting, external calls, oracles and upgrade paths.
- Form explicit vulnerability hypotheses and test them against the code.
- Reproduce material findings with minimal PoCs.
- Argue impact and exploitability without overstating severity.
- Propose narrow remediation and verify it with regression tests.
Tool output is treated as evidence and a lead — not a substitute for protocol reasoning.
Current research areas include:
- Smart-contract vulnerability patterns
- DeFi accounting and invariant failures
- Cross-chain and bridge security
- Fuzzing and property-based testing
- Static-analysis tooling
- Security automation and AI-assisted analysis
Public work is labeled clearly as independent research, educational material, contest-based research, or client-approved material where applicable.
I do not publish private client details, credentials, or unauthorized weaponized exploit instructions.
- X: @DeFiAudit
- Telegram: @DeFiAudit0x
- Email: defiaudit@gmail.com
Find the bug. Reproduce it. Explain the root cause. Make the fix testable.

