README.md
Building security research that survives contact with the chain.
My work centers on the EVM / BSC ecosystem across three strands: independently reproducing real historical attacks end-to-end — from mathematical derivation to Foundry fork proof-of-concept, including a full reproduction of the ~$128M Balancer V2 ComposableStablePool precision-loss exploit — while maintaining a public DeFi attack PoC knowledge base with 50+ attack models and 120+ Foundry tests.
I also build security research at scale — a BSC real-time monitoring platform, static-analysis scanners, and a semi-automated detection pipeline (network-wide static scan → lending-protocol family fingerprinting → custom Slither detectors → Echidna invariant harnesses that extract pricing and accounting formulas straight from real contracts). I proactively discover and responsibly disclose live vulnerabilities to real protocol teams across chains from BSC and Base to emerging L2s like Robinhood Chain — not just reproduce history. I work daily with Foundry, Slither, and Echidna, and compete in audits through Code4rena.
Looking to join a team centered on on-chain security and exploit detection, turning attack-reproduction depth into defensive capability.
Selected work
4 repositoriesdefi-poc-lab
PublicA public DeFi attack PoC knowledge base — 50+ attack models and 120+ Foundry tests across 12 vulnerability classes, each with a mathematical model and attack-flow diagram, including a full reproduction of the ~$128M Balancer V2 precision-loss exploit.
View repository →starkxun-crawlTool
PublicAn on-chain vault discovery and attack-surface scanner that identifies asset-holding contracts, proxy patterns, risky functions, and audit priorities.
View repository →MEV-LIFI
PublicA cross-chain arbitrage viability tool built on LI.FI quotes — nets real swap, bridge, gas, and slippage costs against a price gap in token terms, not USD-labeled spreads, before trusting a route. Feeds a broader long-tail-chain liquidation MEV and economic-vulnerability scanner that reuses the onChainListen data pipeline, currently in shadow-mode testing.
View repository →scan_danger_fun
PrivateA Python dangerous-function detector for Solidity: cross-function reachability analysis, false-positive masking, three-tier confidence scoring, and access-control tiering to separate permissionless attack surface from admin-only backdoors.
Not public yetAlso reproduced: MAI / Moolah flash-loan callback reentrancy, and Valas Finance's oracle mispricing from deprecated TUSD collateral still priced via Chainlink.
Live mainnet findings
Independent vulnerability research
Self-directed research against already-deployed mainnet protocols, then responsibly disclosed.
Avalon Labs
BSC · BaseUnbounded flash-loan premium accrual on a near-zero-supply reserve lets a single flash loan inflate liquidityIndex by up to ~10^14x. The same Pool implementation had already been exploited once on a sibling reserve and was never patched. I confirmed and reproduced it on two live deployments — BSC UniBTC Market and Base SolvBTC Market — and disclosed directly to the security team, who reviewed with engineering and acknowledged both findings.
Robinhood Chain
Emerging L2On an early, thinly-audited L2 I mapped the LayerZero OFT / bridge ecosystem, then deep-dived bespoke lending, vault, and trading contracts and reproduced several live bugs end-to-end on Foundry forks: a permissionless FeeConverter that sweeps a lending desk's entire ETH balance (Critical); a single-market liquidation that writes off cross-collateral bad debt for free (High); and a stale price-snapshot resurrection that falsely liquidates fully-healthy positions in a Uniswap V4-hook lending AMM. Full technical reports written; disclosure in progress.
DeltaPrime
ArbitrumA global 6h Chainlink staleness constant is applied to a 24h-heartbeat GLV oracle. A 31-day on-chain scan measured 14–21 normal-cause overages per month; during a feed's silent period the insolvency check reverts, blocking liquidation and shifting bad debt onto lending-pool LPs. Verified with a fork PoC against already-deployed bytecode.
Unitus V2
BaseThe Poster price feed had been stale for 853 days while USX had de-pegged to about $0.39, yet the oracle still reported $1.00 — the protocol is actually insolvent. Located roughly $759 of real on-chain bad debt, confirmed with 6/6 passing Foundry fork tests, and cross-checked against 6 prior audits.
Whitechain Bridge
Cross-chainMissing domain separation in bridgeTokens signatures lets a valid relayer signature be replayed against a second Bridge deployment — a cross-contract signature replay risk.
How I work
Model the invariant
Reduce a complex exploit to the accounting or state assumption that must always hold.
Reproduce the failure
Build a minimal test or PoC that separates the root cause from incidental protocol details.
Validate on-chain
Use source, bytecode, RPC state, and transaction history to confirm real-world reachability.
Technical focus
Competitive audits & auditing experience
Independent Security Auditor (Freelance) · Jan 2025 – Present- Competed in real Code4rena contests: Chainlink Payment Abstraction V2; Moonwell (Compound V2 fork, first full diff audit).
- In a Sherlock contest audit of Tare's lending and portfolio-vault contracts, found and dynamically confirmed with Foundry a Medium-severity issue: NAV calculation ignores in-custody borrower-payment clearing, letting vault shares be mispriced even against a freshly updated NAV.
- Structured audits across MasterChef farms, rebasing tokens, vaults, lending protocols, and cross-chain bridge architectures, delivering severity-graded reports.
- Designed invariant tests and custom fuzzing harnesses, finding real issues including zero-value deposits and state inconsistencies; built an automated invariant-test scaffolding pipeline.
- Built a high-recall LLM audit-prompting system (a mandatory seven-category attack checklist) and a reusable DeFi audit report template with economic-model analysis.
- Actively hunts on Immunefi against live protocols such as GammaSwap and Silo v2/v3, applying a strict four-question gate — attacker, failure mode, fund flow, in-scope — that discards weak leads rather than forcing a submission.
Education
B.S. Computer Science and Technology · Anhui Wenda University of Information Engineering, Class of 2024. Coursework: Blockchain, Data Structures, Operating Systems — smart contract auditing and EVM exploitation are self-taught.
Available for interviews
Interested in practical on-chain security and exploit-detection work.
Looking to join a team centered on on-chain security and exploit detection, where research quality, engineering, and adversarial thinking matter.