Skip to content
View kismp123's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report kismp123

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
kismp123/README.md

Soon Chan Hwang

Web3 security researcher specializing in smart contract auditing, vulnerability research, and offensive tooling.

Ranked among the all-time top 10 whitehats on Immunefi, with critical findings across major protocols including Wormhole, Olympus, Tokemak, Inverse Finance, and Vest Exchange.

About

I focus on finding practical vulnerabilities in smart contracts and turning security research into measurable impact. My work spans direct bug bounty reports, smart contract security reviews, and offensive tooling for blockchain ecosystems.

Highlights

  • Ranked among the all-time top 10 whitehats on Immunefi
  • Reported critical vulnerabilities across major blockchain protocols
  • Built BugChainIndexer, a research tool for identifying fund-holding contracts and speeding up vulnerability triage
  • Focused on practical smart contract security research and offensive tooling

Experience

Role Organization Period Focus
Lead Security Researcher Hexens 2025.03 - 2026.04 Smart contract audits and vulnerability analysis
Chrome Exploit Development Stealien 2024.02 - 2025.02 Research tooling for Chrome sandbox escape 1-day analysis
Devirtualization Research Raon Whitehat 2021.04 - 2023.02 Themida v2/v3 devirtualization and original logic recovery
Security Researcher Orange Security 2020.05 - 2020.09 Web and Android vulnerability assessments
Security Operations Igloo Security Inc 2019.09 - 2020.04 Security event triage and incident analysis
Security Operations Air Force Information Security 2013.06 - 2015.06 Attack monitoring, malware analysis, firewall and IPS operations

Selected Security Impact

  • Inverse Finance: critical vulnerability reported directly in 2025.07
  • Monolith: critical logic bug reported directly in 2025.07
  • Vest Exchange: critical vulnerability reported directly in 2025.07, with potential drain impact of approximately $1.2M
  • Wormhole: critical vulnerability reported via Immunefi in 2022, with potential drain impact of approximately $1M
  • Olympus: critical finding via Immunefi in 2022
  • Tokemak: critical finding via Immunefi in 2022, with potential drain impact of approximately $51M
  • Optimism: medium severity finding via Immunefi in 2022
  • Delta Protocol: critical vulnerability reported via Immunefi in 2023
  • Erigon: high severity report to the Ethereum Foundation in 2023
  • BIFROST: critical vulnerability reported via Patchday in 2023

Projects

BugChainIndexer

GitHub: kismp123/BugChainIndexer

A lightweight indexing tool built to track Transfer events and isolate contracts that actually hold funds. The goal is to reduce noise during triage and surface high-value attack targets faster.

Research outcome:

  • Helped uncover a reentrancy issue in Vest Exchange
  • Helped uncover a drain vulnerability in Inverse Finance
  • Helped uncover a critical logic bug in Monolith
  • Helped uncover many additional vulnerabilities, with some unable to be responsibly disclosed because the contract owners could not be identified
  • Other researchers have also used the tool to discover critical vulnerabilities
  • Open-sourced for broader use in vulnerability discovery workflows

ACS (ASEAN Cyber Shield) CTF (2024)

Created blockchain challenges with attack-and-defense rules and operated the blockchain environment using Ganache.

Skills

  • Smart Contract Security: Solidity, Foundry, Hardhat
  • Programming: Python, JavaScript, C++
  • Security Research: vulnerability analysis, exploit development
  • Infra / Tooling: Docker

Links

Pinned Loading

  1. BugChainIndexer BugChainIndexer Public

    High-performance blockchain indexer for 12 EVM networks. Real-time contract analysis and portfolio tracking with sub-second API response.

    JavaScript 30 5

  2. DeFi-Security-Incident DeFi-Security-Incident Public

    real-world DeFi security incidents (2020–2026) with root cause analysis, attack flow, on-chain source code, and PoC exploits. Covers flash loans, reentrancy, oracle manipulation, access control, br…

    20 2

  3. smart-contract-review-reports smart-contract-review-reports Public

    A curated collection of smart contract security review reports derived from audit contests (Code4rena, Sherlock). Focused on real-world vulnerabilities, root cause analysis

    1