README.md

Building security research that survives contact with the chain.

My work centers on the EVM / BSC ecosystem across three strands: independently reproducing real historical attacks end-to-end — from mathematical derivation to Foundry fork proof-of-concept, including a full reproduction of the ~$128M Balancer V2 ComposableStablePool precision-loss exploit — while maintaining a public DeFi attack PoC knowledge base with 50+ attack models and 120+ Foundry tests.

I also build security research at scale — a BSC real-time monitoring platform, static-analysis scanners, and a semi-automated detection pipeline (network-wide static scan → lending-protocol family fingerprinting → custom Slither detectors → Echidna invariant harnesses that extract pricing and accounting formulas straight from real contracts). I proactively discover and responsibly disclose live vulnerabilities to real protocol teams across chains from BSC and Base to emerging L2s like Robinhood Chain — not just reproduce history. I work daily with Foundry, Slither, and Echidna, and compete in audits through Code4rena.

Looking to join a team centered on on-chain security and exploit detection, turning attack-reproduction depth into defensive capability.

Selected work

4 repositories

Also reproduced: MAI / Moolah flash-loan callback reentrancy, and Valas Finance's oracle mispricing from deprecated TUSD collateral still priced via Chainlink.

Live mainnet findings

Independent vulnerability research

Self-directed research against already-deployed mainnet protocols, then responsibly disclosed.

Avalon Labs

BSC · Base
Disclosed & acknowledged

Unbounded flash-loan premium accrual on a near-zero-supply reserve lets a single flash loan inflate liquidityIndex by up to ~10^14x. The same Pool implementation had already been exploited once on a sibling reserve and was never patched. I confirmed and reproduced it on two live deployments — BSC UniBTC Market and Base SolvBTC Market — and disclosed directly to the security team, who reviewed with engineering and acknowledged both findings.

Robinhood Chain

Emerging L2
Reports written · disclosing

On an early, thinly-audited L2 I mapped the LayerZero OFT / bridge ecosystem, then deep-dived bespoke lending, vault, and trading contracts and reproduced several live bugs end-to-end on Foundry forks: a permissionless FeeConverter that sweeps a lending desk's entire ETH balance (Critical); a single-market liquidation that writes off cross-collateral bad debt for free (High); and a stale price-snapshot resurrection that falsely liquidates fully-healthy positions in a Uniswap V4-hook lending AMM. Full technical reports written; disclosure in progress.

DeltaPrime

Arbitrum
Submitted · HackenProof (self-assessed Medium)

A global 6h Chainlink staleness constant is applied to a 24h-heartbeat GLV oracle. A 31-day on-chain scan measured 14–21 normal-cause overages per month; during a feed's silent period the insolvency check reverts, blocking liquidation and shifting bad debt onto lending-pool LPs. Verified with a fork PoC against already-deployed bytecode.

Unitus V2

Base
Submitted · HackenProof

The Poster price feed had been stale for 853 days while USX had de-pegged to about $0.39, yet the oracle still reported $1.00 — the protocol is actually insolvent. Located roughly $759 of real on-chain bad debt, confirmed with 6/6 passing Foundry fork tests, and cross-checked against 6 prior audits.

Whitechain Bridge

Cross-chain
Analysis

Missing domain separation in bridgeTokens signatures lets a valid relayer signature be replayed against a second Bridge deployment — a cross-contract signature replay risk.

How I work

01

Model the invariant

Reduce a complex exploit to the accounting or state assumption that must always hold.

02

Reproduce the failure

Build a minimal test or PoC that separates the root cause from incidental protocol details.

03

Validate on-chain

Use source, bytecode, RPC state, and transaction history to confirm real-world reachability.

Technical focus

LanguagesSolidity, Python, Go, TypeScript / JavaScript
Dev & testingFoundry — fork testing, cheatcodes, invariant and custom fuzzing; Echidna property/invariant harnesses extracted from real contracts
Security toolingSlither (incl. custom detectors), Echidna, Mythril, Surya, plus a custom Python static-analysis scanner and protocol-family fingerprinting
On-chain & backendGo + PostgreSQL monitoring backend, event listening, REST (Gin) + WebSocket, tiered-cache RPC cost optimization, Sourcify/BscScan source backfill, Dune Analytics candidate sourcing
StandardsERC20 / 721 / 4626, EIP-2535, UUPS proxies, Uniswap V4 hooks, Olympus/OHM-fork vaults, LayerZero OFT
Attack surfacesReentrancy & read-only reentrancy, flash loans, oracle manipulation, share-inflation/donation attacks, precision/rounding loss, signature & stale-price replay, MEV, cross-chain bridges, access control & governance takeover, honeypot detection
EcosystemCode4rena, Sherlock, Immunefi, HackenProof · BSC, Ethereum, Base, Arbitrum, Sonic, Polygon, Optimism, zkSync Era, Robinhood Chain · Chainlink, LayerZero

Competitive audits & auditing experience

Independent Security Auditor (Freelance) · Jan 2025 – Present
  • Competed in real Code4rena contests: Chainlink Payment Abstraction V2; Moonwell (Compound V2 fork, first full diff audit).
  • In a Sherlock contest audit of Tare's lending and portfolio-vault contracts, found and dynamically confirmed with Foundry a Medium-severity issue: NAV calculation ignores in-custody borrower-payment clearing, letting vault shares be mispriced even against a freshly updated NAV.
  • Structured audits across MasterChef farms, rebasing tokens, vaults, lending protocols, and cross-chain bridge architectures, delivering severity-graded reports.
  • Designed invariant tests and custom fuzzing harnesses, finding real issues including zero-value deposits and state inconsistencies; built an automated invariant-test scaffolding pipeline.
  • Built a high-recall LLM audit-prompting system (a mandatory seven-category attack checklist) and a reusable DeFi audit report template with economic-model analysis.
  • Actively hunts on Immunefi against live protocols such as GammaSwap and Silo v2/v3, applying a strict four-question gate — attacker, failure mode, fund flow, in-scope — that discards weak leads rather than forcing a submission.

Education

B.S. Computer Science and Technology · Anhui Wenda University of Information Engineering, Class of 2024. Coursework: Blockchain, Data Structures, Operating Systems — smart contract auditing and EVM exploitation are self-taught.

Available for interviews

Interested in practical on-chain security and exploit-detection work.

Looking to join a team centered on on-chain security and exploit detection, where research quality, engineering, and adversarial thinking matter.

Get in touch