Web3 security researcher specializing in smart contract auditing, vulnerability research, and offensive tooling.
Ranked among the all-time top 10 whitehats on Immunefi, with critical findings across major protocols including Wormhole, Olympus, Tokemak, Inverse Finance, and Vest Exchange.
I focus on finding practical vulnerabilities in smart contracts and turning security research into measurable impact. My work spans direct bug bounty reports, smart contract security reviews, and offensive tooling for blockchain ecosystems.
- Ranked among the all-time top 10 whitehats on Immunefi
- Reported critical vulnerabilities across major blockchain protocols
- Built BugChainIndexer, a research tool for identifying fund-holding contracts and speeding up vulnerability triage
- Focused on practical smart contract security research and offensive tooling
| Role | Organization | Period | Focus |
|---|---|---|---|
| Lead Security Researcher | Hexens | 2025.03 - 2026.04 | Smart contract audits and vulnerability analysis |
| Chrome Exploit Development | Stealien | 2024.02 - 2025.02 | Research tooling for Chrome sandbox escape 1-day analysis |
| Devirtualization Research | Raon Whitehat | 2021.04 - 2023.02 | Themida v2/v3 devirtualization and original logic recovery |
| Security Researcher | Orange Security | 2020.05 - 2020.09 | Web and Android vulnerability assessments |
| Security Operations | Igloo Security Inc | 2019.09 - 2020.04 | Security event triage and incident analysis |
| Security Operations | Air Force Information Security | 2013.06 - 2015.06 | Attack monitoring, malware analysis, firewall and IPS operations |
- Inverse Finance: critical vulnerability reported directly in 2025.07
- Monolith: critical logic bug reported directly in 2025.07
- Vest Exchange: critical vulnerability reported directly in 2025.07, with potential drain impact of approximately $1.2M
- Wormhole: critical vulnerability reported via Immunefi in 2022, with potential drain impact of approximately $1M
- Olympus: critical finding via Immunefi in 2022
- Tokemak: critical finding via Immunefi in 2022, with potential drain impact of approximately $51M
- Optimism: medium severity finding via Immunefi in 2022
- Delta Protocol: critical vulnerability reported via Immunefi in 2023
- Erigon: high severity report to the Ethereum Foundation in 2023
- BIFROST: critical vulnerability reported via Patchday in 2023
GitHub: kismp123/BugChainIndexer
A lightweight indexing tool built to track Transfer events and isolate contracts that actually hold funds. The goal is to reduce noise during triage and surface high-value attack targets faster.
Research outcome:
- Helped uncover a reentrancy issue in Vest Exchange
- Helped uncover a drain vulnerability in Inverse Finance
- Helped uncover a critical logic bug in Monolith
- Helped uncover many additional vulnerabilities, with some unable to be responsibly disclosed because the contract owners could not be identified
- Other researchers have also used the tool to discover critical vulnerabilities
- Open-sourced for broader use in vulnerability discovery workflows
Created blockchain challenges with attack-and-defense rules and operated the blockchain environment using Ganache.
- Smart Contract Security: Solidity, Foundry, Hardhat
- Programming: Python, JavaScript, C++
- Security Research: vulnerability analysis, exploit development
- Infra / Tooling: Docker
