Skip to content
View dimin4241-svg's full-sized avatar

Block or report dimin4241-svg

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
dimin4241-svg/README.md

Web3 Engineering & Security Research

I am a full-stack Web3 engineer and independent security researcher working across TypeScript, React, Node.js, Rust, Soroban, blockchain infrastructure, wallets, and protocol integrations.

I ship narrow, reviewable changes with reproducible tests and clear documentation. Recent work spans agent tooling, CI, smart-contract behavior, data quality, and product QA.

Selected engineering work

  • sh1pt CLI JSON output — merged TypeScript contribution adding safe machine-readable secret listings, focused local/cloud regression tests, and verification across 280 CLI tests, typecheck, and build.
  • Mermail RFP Evaluator — a validated Codex-compatible agent skill for mailbox triage, requirement extraction, scoring, and draft-only responses.
  • Chain-Love Algorand data contribution — merged open-source data work reviewed and accepted upstream.
  • Trading terminal QA sample — reproducible findings covering market-data consistency, input validation, and accessibility.

Engineering stack

  • TypeScript, JavaScript, Node.js, React, Next.js, API integrations, and CI/CD
  • Rust and Soroban smart contracts, deterministic tests, and contract-state invariants
  • Manual QA, regression testing, accessibility, and evidence-driven debugging

My work is evidence-driven: I aim to turn a security hypothesis into a minimal, reproducible proof of concept with clear impact, negative controls, and a practical remediation path.

Research focus

  • Solidity and EVM protocol security
  • DeFi accounting, rounding, access control, and state-machine invariants
  • Cross-chain, bridge, wallet, and signing flows
  • Rust- and Move-based blockchain ecosystems
  • Web and API attack surfaces connected to Web3 products

How I work

  1. Map trust boundaries, privileged roles, and critical invariants.
  2. Trace candidate issues from attacker-controlled input to security impact.
  3. Reproduce the behavior with a minimal deterministic PoC.
  4. Add negative controls to rule out false positives and expected behavior.
  5. Document severity assumptions, affected conditions, and a regression test.

Responsible disclosure

I follow program scope, safe-harbor terms, and coordinated disclosure requirements. I avoid harmful testing against live systems and keep unresolved findings private. Technical details are published only when the relevant disclosure policy permits it.

Active research and disclosure-stage artifacts may remain private until publication is authorized.

Contact

For non-sensitive questions or collaboration, open an issue in this repository. For a potential vulnerability, request a private communication channel first and do not post technical details publicly.

Popular repositories Loading

  1. alephium alephium Public

    Forked from alephium/alephium

    Reference client for Alephium protocol

    Scala

  2. ton ton Public

    Forked from ton-blockchain/ton

    Main TON monorepo

    C++

  3. ckb ckb Public

    Forked from nervosnetwork/ckb

    The Nervos CKB is a public permissionless blockchain, and the layer 1 of Nervos network.

    Rust

  4. pump-public-docs pump-public-docs Public

    Forked from pump-fun/pump-public-docs

    Pump public docs

    TypeScript

  5. monero monero Public

    Forked from monero-project/monero

    Monero: the secure, private, untraceable cryptocurrency

    C++

  6. polkadot-sdk polkadot-sdk Public

    Forked from paritytech/polkadot-sdk

    The Parity Polkadot Blockchain SDK

    Rust