Full Stack Security Researcher
- Smart Contract Security : EVM, Solana, SUI, Aptos, Stellar, Chromia
- Blockchain Infra Security : Nodes, Sequencers, Cosmos-SDK/golang/rust
- Web Application Security (Web2)
- API Security
- Cloud Security
- Supply Chain Security
- DevSecOps
- Cyfrin: https://cyfrin.io
- Pashov Audit Group: https://pashov.com
- AdevarLabs: https://adevarlabs.com
- HackenProof: https://hackenproof.com
- Valkyri Security: https://valkyrisec.com
| Protocol | Firm | Type |
|---|---|---|
| Synthetix Auto-compound | Guardian Audits | Private |
| Tradfi | Cyfrin | Private |
| Aztec | Cyfrin | Private |
| Uranium Digital | Immunefi / AdevarLabs | Private |
| Alvara | AdevarLabs | Private |
| Avon | Valkyri Security | Private |
| Metamask | Cyfrin | Report |
| Polygun | Pashov Audit Group | Report |
| Ostium | Pashov Audit Group | Private |
| Polygun | Pashov Audit Group | Report |
| Polygun | Pashov Audit Group | Report |
| Ostium | Pashov Audit Group | Private |
| Algoxen | Hackenproof | Report |
- CVE-2023-6747 : FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom attributes in all versions up to, and including, 2.3.3 due to insufficient input sanitization and output escaping.
- CVE-2023-41875 : Missing Authorization vulnerability in wpdirectorykit.com WP Directory Kit allows Exploiting Incorrectly Configured Access Control Security Levels.
- CVE-2023-40607 : The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10.0.
- CVE-2024-24715 : BookIt plugin for WordPress is vulnerable to Price Bypass in versions up to and including 2.4.0.
CVE Reversing and created nuclei templates for automated scanning: https://github.com/arpeetrathii/CVE-Reversing
- How to Hack a Web3 Wallet (Legally): A Full-Stack Pentesting Guide)
- x402 Integration Security: A Technical Deep Dive
- Top 10 Ways Soroban Contracts Get Hacked
- Your Code Is Audited, Your Keys Aren’t: Why Drains Keep Happening to Web3 Builders and Users
- NPM Malware Scanner : https://github.com/ValkyriSecurity/npm-malware-scanner
- Dependency Confusion Takeover : https://github.com/0xaudron/dependency-takeover
| Sl No. | Platform | Contest | Report | Submissions(H/M/L/G) |
|---|---|---|---|---|
| 1. | Code4rena | Lambo.win | 📄 | 1H |
| 2. | Code4rena | SecondSwap | 📄 | 1H |
| 3. | Codehawks | Aave DIVA Wrapper | 📄 | 1L |
| 4. | Cantina | daao-contracts | 📄 | 1H/1M/3L/3G |
| 5. | Code4rena | IQ AI | 📄 | 1M |
| 6. | Code4rena | Liquid Ron | 📄 | 1M |
| 7. | Sherlock | Crestal Network | 📄 | 1H |
| 8. | Codehawks | RAAC | 📄 | 4H/3M/4L |
| 9. | Cantina | Telcoin | 📄 | 1H/2M/4I |