Open-source project
ErrorLens
An AI-assisted audit and report compiler for EVM and Solana projects, turning security observations into clear developer-ready findings.
Independent Web3 security researcher
I build and test Web3 security workflows across EVM and Solana. The aim is simple: turn meaningful risk into evidence developers can act on.
Contest & platform record
Capabilities
Contract and program review across both runtimes, with the same evidence discipline.
dApp, API, and integration surfaces checked for the assumptions that break in production.
Transaction, signing, and approval flows traced for user-facing risk.
Trust boundaries, roles, and invariants mapped before code is read for bugs.
Credible findings validated with fork-only proof-of-concept work.
Severity, impact, reproduction, remediation — structured for the team that has to fix it.
Selected work
Public tools, audits, and research that show how I approach Web3 risk across interfaces, transaction flows, contracts, and developer reporting.
Open-source project
An AI-assisted audit and report compiler for EVM and Solana projects, turning security observations into clear developer-ready findings.
Security monitoring demo
A security-focused product demo exploring audit trails, transaction monitoring, verification controls, and operational visibility.
Research workflow
A growing research workflow for reviewing dApp surfaces, wallet and transaction flows, API assumptions, contracts, and Solana programs.
Case study snapshot
ErrorLens turns EVM and Solana security observations into a structured, developer-ready finding format.
Record the affected surface and the security assumption under review.
Frame severity, impact, and reproduction around evidence that can be checked.
Pair the finding with a clear fix path and the behavior it must preserve.
Keep retest notes alongside the original evidence for a complete record.
Start a review
Share the repository, program list, and the exact systems or flows that need attention.
Point to trusted roles, asset movement, integrations, and assumptions that cannot fail.
Provide authorized local or fork-based testing details. Production testing is never assumed.
Have a protocol to secure?
Available for audit contests, authorized fork-based PoC collaboration, research support, and developer-ready report compilation.
Elsewhere