skip to content
Back to Home

Services

Independent security work for web2 and web3 systems. I find the bugs that automated scanners miss: logic flaws, deserialization issues, kernel weaknesses, and business logic that can be abused.

HONEST Trading Backtest Audits

Prop firm challenges like FTMO run you through one test trade, then let you risk real money on a strategy that was never honestly backtested. Most people fail. Not because the idea is bad, but because the chart they trusted was backtested without costs, without drawdown, and without randomness.

I run your strategy through an engine that does not flatter you. The report answers one question: is your backtest real, and can you actually trade it? It checks breakeven spread, how the strategy holds up when costs and parameters are worse than you assumed, and a Monte Carlo resample of your trades. Every run is locked to a data hash and code revision, so anyone can reproduce the verdict. You cannot argue with the numbers, and neither can I.

Public sample verdicts (real engine output)

Three real reports, generated live, and two of them come back rejected. That is the point. A service that only ever says "PASS" is not auditing, it is selling.

  • EMA Crossover 24/96 WEAK: 0.34% CAGR with a 17% drawdown. Survives every cost stress but quietly earns nothing.
  • EMA Crossover 4/20 REJECTED: loses money at every spread, even 0.00 pips. The day trading fantasy that dies at the counter.
  • RSI Mean-Reversion 14/30/55 REJECTED: unprofitable even at 0.00 pips, with a 15% Monte Carlo pass rate. "Buy the dip" has no edge here.

Receipts, every report is reproducible

No marketing screenshots. Each report pins its exact inputs, so anyone can re-run it and confirm the verdict. The three samples above all use the same 23.4-year daily EURUSD series:

data sha256: 04a4bbfda54fe12840075207501c9830f473d05f67f3e3376414d038c7df9dd5code revision: 8371edc0c384961666bdf45d264ce750fbcb554d

Application Security

Web and API penetration testing, auth logic review, SSRF, IDOR, XSS, business logic abuse, race conditions, the OWASP Top 10, and GraphQL, REST and gRPC APIs.

Blockchain Security

Smart contract audits for Solidity and EVM, DeFi protocol review, access control, reentrancy, oracle manipulation, and flash loan attacks.

Reverse Engineering & Malware

Binary analysis for x86 and x64, malware unpacking, IOC extraction, C2 analysis, Windows and Linux internals, kernel level debugging, and threat intel reports.

Infrastructure & Cloud

Docker and Kubernetes security review, cloud config assessment on AWS and GCP, network architecture review, and CI/CD pipeline hardening.

Code Audit & Tooling

Source code review in Go, Python, C, Rust and TypeScript, dependency analysis, custom scanner and fuzzer development, and security automation.

Vulnerability Research

Zero day discovery, CVE research and disclosure, exploit development, fuzzing campaigns, and proof of concept development.

Track Record

  • CVE-2026-31431 Kernel LPE (Copy Fail, CVSS 7.8)
  • CVE-2025-55182 React Server Components RCE (React2Shell, CVSS 10.0)
  • n8n CVE-2025-68613 Expression injection in an automation platform
  • Systems engineering and reverse engineering since 2024

Payment

I accept crypto. Contact me for current rates and availability.

USDC (Base)
0x4a0fcef66f73e978bc895139239dd9a0ca5cec4d
ETH / EVM tokens
0x4a0fcef66f73e978bc895139239dd9a0ca5cec4d