Research & findings

Evidence that stays useful.

Contest records, responsible disclosures, and the report format behind the work. Private findings stay private: publishing is gated by disclosure terms.

On record

Contest submissions & disclosures.

Contest record

01

Sherlock · Contest submission

Metric & Tare

Audit-contest submission, validated and submitted. The supporting repository stays private, so the finding detail is summarized here without a link until disclosure terms permit.

Jul 2026 · Sherlock
02

SolanaBR · Skill bounty

Audit-tooling skill bounty

Open contribution to the SolanaBR skill-bounty effort, submitted as PR #35 and visible on the public repository.

Bounty PR ↗
03

Contest record

Onward contest submissions

Further audit-contest findings are validated and submitted, with supporting repositories kept private and the record summarized without platform or date detail.

Contest record

Responsible disclosures

01

Responsible disclosure

Sheriff Exchange: protocol configuration review

Findings from a protocol configuration review, shared privately with the team. Details are withheld until disclosure terms permit.

Contact ↘
02

Responsible disclosure

Private findings stay private

Four private disclosures are recorded without publishing exploit details. Evidence is shared only when disclosure terms permit it.

Contact ↘

Authorized testing only. I do not publish active exploit paths, private reports, or sensitive protocol details before a responsible-disclosure process is complete. Where a severity is shown, it reflects what was validated, not the worst case that can be imagined, and nothing goes public until disclosure terms permit it.

Sample finding

A finding that a developer can act on.

Redacted / illustrative formatReport excerpt 01

Clear enough to fix.
Careful enough to trust.

Interactive sample: pick a severity and copy the report. This is the ErrorLens output format.

Severity
HIGH: material risk to funds or protocol invariants under realistic conditions, validated by a fork-based PoC.
Evidence
Reproduction steps, test output, and the affected trust boundary.
Remediation
A concrete fix path with the assumptions it must preserve.
Verification
Retest notes that confirm the proposed change closes the risk.

This is a reporting-format sample, not a published client finding. Protocol details and exploit paths remain private until disclosure terms permit publication.

Have a finding to verify?

Bring the context, I'll bring the evidence.

01

Scope

Share the repository, program list, and the exact systems or flows under review.

02

Risk context

Point to trusted roles, asset movement, integrations, and assumptions that cannot fail.

03

Report

Get severity, impact, reproduction, remediation, and verification in one usable format.

Appearance