Practice

Security research

Web and application security, smart contracts, ZK and applied cryptography, and agentic AI attack paths.

Scope

Applied capabilities

  • Web applications, APIs, access control, business logic, and integrations
  • Solidity and Vyper contracts with executable exploit proofs
  • Circuits, verifiers, proof systems, and formal verification
  • Indirect prompt injection, tool misuse, and adversarial evaluation
  • Reports that separate public evidence from private program details

In practice

Projects and contributions

  • Public reproducible review repositories and CI
  • Gray Swan Arena profile for indirect prompt injection research
  • HackerOne association with the Treasury Board of Canada Secretariat
  • Cantina associations with Reserve Protocol and Revert Finance
  • Code4rena associations with Chainlink Payment Abstraction V2 and K2

Public profiles

Attributable associations.

Platforms are presented without finding counts, severity, or non-public technical detail.