Security researcher who breaks things so they don't break in production.
I write C++ and Rust when I need speed and memory safety. React and TypeScript when I'm building interfaces people actually use. Most days I'm hunting bugs, web apps, APIs, smart contracts across HackerOne, Intigriti, and private programs. 50+ valid reports so far. Best one chained IDOR to SSRF to RCE for $12k.
What I actually do:
Audit DeFi protocols (reentrancy, access control, oracle manipulation, the usual suspects)
Build custom fuzzers and Burp extensions because off-the-shelf tools miss the fun stuff
Review Rust unsafe blocks and C++ heap code memory safety is a myth if you don't check
Help teams ship secure code without slowing them down
Currently learning:
Advanced heap exploitation. Formal verification for smart contracts. How to explain vulnerabilities so developers actually want to fix them.
Open to:
Security assessments. Code reviews. Custom tooling. Research collaborations. Writing about bugs I've found.
DM me easiest way to reach me. No formal proposals needed, just tell me what you're working on.