Services
Independent security work for web2 and web3 systems. I find the bugs that automated scanners miss: logic flaws, deserialization issues, kernel weaknesses, and business logic that can be abused.
HONEST Trading Backtest Audits
Prop firm challenges like FTMO run you through one test trade, then let you risk real money on a strategy that was never honestly backtested. Most people fail. Not because the idea is bad, but because the chart they trusted was backtested without costs, without drawdown, and without randomness.
I run your strategy through an engine that does not flatter you. The report answers one question: is your backtest real, and can you actually trade it? It checks breakeven spread, how the strategy holds up when costs and parameters are worse than you assumed, and a Monte Carlo resample of your trades. Every run is locked to a data hash and code revision, so anyone can reproduce the verdict. You cannot argue with the numbers, and neither can I.
Public sample verdicts (real engine output)
Three real reports, generated live, and two of them come back rejected. That is the point. A service that only ever says "PASS" is not auditing, it is selling.
- EMA Crossover 24/96 WEAK: 0.34% CAGR with a 17% drawdown. Survives every cost stress but quietly earns nothing.
- EMA Crossover 4/20 REJECTED: loses money at every spread, even 0.00 pips. The day trading fantasy that dies at the counter.
- RSI Mean-Reversion 14/30/55 REJECTED: unprofitable even at 0.00 pips, with a 15% Monte Carlo pass rate. "Buy the dip" has no edge here.
Receipts, every report is reproducible
No marketing screenshots. Each report pins its exact inputs, so anyone can re-run it and confirm the verdict. The three samples above all use the same 23.4-year daily EURUSD series:
data sha256: 04a4bbfda54fe12840075207501c9830f473d05f67f3e3376414d038c7df9dd5code revision: 8371edc0c384961666bdf45d264ce750fbcb554dApplication Security
Web and API penetration testing, auth logic review, SSRF, IDOR, XSS, business logic abuse, race conditions, the OWASP Top 10, and GraphQL, REST and gRPC APIs.
Blockchain Security
Smart contract audits for Solidity and EVM, DeFi protocol review, access control, reentrancy, oracle manipulation, and flash loan attacks.
Reverse Engineering & Malware
Binary analysis for x86 and x64, malware unpacking, IOC extraction, C2 analysis, Windows and Linux internals, kernel level debugging, and threat intel reports.
Infrastructure & Cloud
Docker and Kubernetes security review, cloud config assessment on AWS and GCP, network architecture review, and CI/CD pipeline hardening.
Code Audit & Tooling
Source code review in Go, Python, C, Rust and TypeScript, dependency analysis, custom scanner and fuzzer development, and security automation.
Vulnerability Research
Zero day discovery, CVE research and disclosure, exploit development, fuzzing campaigns, and proof of concept development.
Track Record
- CVE-2026-31431 Kernel LPE (Copy Fail, CVSS 7.8)
- CVE-2025-55182 React Server Components RCE (React2Shell, CVSS 10.0)
- n8n CVE-2025-68613 Expression injection in an automation platform
- Systems engineering and reverse engineering since 2024
Payment
I accept crypto. Contact me for current rates and availability.
0x4a0fcef66f73e978bc895139239dd9a0ca5cec4d0x4a0fcef66f73e978bc895139239dd9a0ca5cec4d