Metric & Tare
Audit-contest submission, validated and submitted. The supporting repository stays private, so the finding detail is summarized here without a link until disclosure terms permit.
Research & findings
Contest records, responsible disclosures, and the report format behind the work. Private findings stay private: publishing is gated by disclosure terms.
On record
Contest record
Audit-contest submission, validated and submitted. The supporting repository stays private, so the finding detail is summarized here without a link until disclosure terms permit.
Open contribution to the SolanaBR skill-bounty effort, submitted as PR #35 and visible on the public repository.
Further audit-contest findings are validated and submitted, with supporting repositories kept private and the record summarized without platform or date detail.
Responsible disclosures
Findings from a protocol configuration review, shared privately with the team. Details are withheld until disclosure terms permit.
Four private disclosures are recorded without publishing exploit details. Evidence is shared only when disclosure terms permit it.
Authorized testing only. I do not publish active exploit paths, private reports, or sensitive protocol details before a responsible-disclosure process is complete. Where a severity is shown, it reflects what was validated, not the worst case that can be imagined, and nothing goes public until disclosure terms permit it.
Sample finding
Interactive sample: pick a severity and copy the report. This is the ErrorLens output format.
This is a reporting-format sample, not a published client finding. Protocol details and exploit paths remain private until disclosure terms permit publication.
Have a finding to verify?
Share the repository, program list, and the exact systems or flows under review.
Point to trusted roles, asset movement, integrations, and assumptions that cannot fail.
Get severity, impact, reproduction, remediation, and verification in one usable format.