I am a full-stack Web3 engineer and independent security researcher working across TypeScript, React, Node.js, Rust, Soroban, blockchain infrastructure, wallets, and protocol integrations.
I ship narrow, reviewable changes with reproducible tests and clear documentation. Recent work spans agent tooling, CI, smart-contract behavior, data quality, and product QA.
- sh1pt CLI JSON output — merged TypeScript contribution adding safe machine-readable secret listings, focused local/cloud regression tests, and verification across 280 CLI tests, typecheck, and build.
- Mermail RFP Evaluator — a validated Codex-compatible agent skill for mailbox triage, requirement extraction, scoring, and draft-only responses.
- Chain-Love Algorand data contribution — merged open-source data work reviewed and accepted upstream.
- Trading terminal QA sample — reproducible findings covering market-data consistency, input validation, and accessibility.
- TypeScript, JavaScript, Node.js, React, Next.js, API integrations, and CI/CD
- Rust and Soroban smart contracts, deterministic tests, and contract-state invariants
- Manual QA, regression testing, accessibility, and evidence-driven debugging
My work is evidence-driven: I aim to turn a security hypothesis into a minimal, reproducible proof of concept with clear impact, negative controls, and a practical remediation path.
- Solidity and EVM protocol security
- DeFi accounting, rounding, access control, and state-machine invariants
- Cross-chain, bridge, wallet, and signing flows
- Rust- and Move-based blockchain ecosystems
- Web and API attack surfaces connected to Web3 products
- Map trust boundaries, privileged roles, and critical invariants.
- Trace candidate issues from attacker-controlled input to security impact.
- Reproduce the behavior with a minimal deterministic PoC.
- Add negative controls to rule out false positives and expected behavior.
- Document severity assumptions, affected conditions, and a regression test.
I follow program scope, safe-harbor terms, and coordinated disclosure requirements. I avoid harmful testing against live systems and keep unresolved findings private. Technical details are published only when the relevant disclosure policy permits it.
Active research and disclosure-stage artifacts may remain private until publication is authorized.
For non-sensitive questions or collaboration, open an issue in this repository. For a potential vulnerability, request a private communication channel first and do not post technical details publicly.
