About

I'm a cybersecurity leader who solves big problems at every level of the stack. I disclose critical vulnerabilities in software and smart contracts directly securing billions of dollars and I engage with non-technical leaders and stakeholders by meeting them where they are.

I founded SEAL, a non-profit, to solve cybersecurity challenges the cryptocurrency industry faces on a global scale. Previously, I was a Research Partner at Paradigm.

Writing

Findings

  • NFTTrader

    Reentrancy in legacy contracts allowing theft of NFTs from users with outstanding approvals

  • LayerZero

    Various critical vulnerabilities

  • Rari

    Reentrancy in cEther's use of `.call.value` across Fuse pools allowing theft of all borrowable assets

  • Etherscan

    Verification bypass allowing mismatched source code to pass contract verification

  • SushiSwap MISO

    `BoringBatchable` delegatecall preserved `msg.value` across batched `commitEth` calls, allowing reused ETH to drain ~$350M via refunds

  • ENS Name Wrapper

    ERC-1155 safe transfer callback enabled reentrancy during minting

  • Hashmasks

    ERC-721 safe transfer callback enabled reentrancy during minting

  • go-ethereum

    Bug in fast sync state downloader could be exploited to booby-trap the blockchain and trigger a hard fork

  • Ambisafe

    Four-year-old state corruption bug in contracts managing over a billion dollars in assets

  • 0x DAO

    Quadratic gas consumption in `getVotingPower()` enabled denial-of-service on treasury governance

  • go-ethereum

    Uncle validation didn't handle extreme timestamps, risking a fork between Geth and Parity

  • COTI

    Deposit/withdrawal pricing discrepancy allowed extracting ~630 ETH via LP token mispricing

  • Tokenlon

    Signature validation couldn't handle the zero address, allowing fee redirection

  • Opium Finance

    Malicious synthetic token could manipulate `getMargin()` return values to drain ~1M USDC during cancellation

  • ElasticDAO

    Bug in transfer function allowed minting duplicate tokens, threatening $5M+ in SushiSwap

  • NFTX

    Internal accounting error broke the 1:1 NFT-to-token minting invariant

  • ForTube

    Permission bypass allowing forged requests to bypass `seizeCheck` verification

  • Optimism

    State Manager remained callable after `applyTransaction()` completed, enabling post-execution state manipulation

  • Optimism

    `relayMessage` could be called on the L2-to-L1 Message Passer, enabling call spoofing on L2

  • Optimism

    Reentrancy in `relayMessage()` allowed recursive cross-domain message exploitation

  • Optimism

    `ovmSETNONCE` lacked a `notStatic` modifier, allowing nonce mutation during `ovmSTATICCALL`

  • Optimism

    `revertFlag` storage variable wasn't cleared before execution, causing stale state carryover

  • Frax Finance

    `withdraw()` failed to track locked vs unlocked LP tokens, allowing withdrawal from locked stake

  • Frax Finance

    Unnecessary `approve()` in redemption granted the redeemer a token allowance instead of transferring directly

  • 88mph

    Business logic error in DInterest allowed malicious minting of ~$100K in MPH tokens

  • Alpha Homora

    Price manipulation allowing attacker-triggered liquidation at 5% profit

  • Yield Protocol

    Unrestricted flash minting to arbitrary addresses allowed pool price manipulation

  • Aavegotchi Staking

    Flash loans could inflate pool balance to generate excessive rewards

  • Lien Finance

    Anyone could mint tokens for free, then burn them for all 25,000 ETH ($9.6M) in the contract

  • Incognito Chain

    Missing validation allowed a $2.69M double spend

  • xTokens

    Flash loans could manipulate SNX prices while minting xSNXa with negligible `minRate`

  • yVault

    Temporary Balancer pool imbalances could be exploited to inflate BPT valuation and drain vault assets

  • Atomic Loans

    Borrower could frontrun the lender agent's auto-cancel to extract both the USDC and the lender's secret, plus UTXO ordering bypass on collateral verification

  • Hegic

    Uniswap price manipulation allowed creating hedges at inflated strike prices to drain the options pool

  • Synthetix

    Variable reference error in `_closeLoan` broke liquidation by referencing `account` instead of `msg.sender`

  • Nexus Mutual

    Unprotected Oraclize callback lacking replay protection exploitable via Uniswap price manipulation

  • Authereum

    Order-of-operations flaw in meta transaction function allowed account takeover

  • Aragon Court

    Jurors could activate tokens while having a pending deactivation, corrupting the active balance tree

  • Curve Finance

    Critical bonding curve algorithm bug allowed draining the entire contract

  • Ethereum Name Service (CVE-2020-5232)

    Domain owner could set a backdoor to claw back ownership after transfer

  • Pillow (CVE-2019-19911)

    Unvalidated integers in FpxImagePlugin.py caused memory exhaustion

  • Cheese Wizards

    `resolveTimedOutDuel` lacked validation that two different wizard IDs were submitted

  • Kyber Network

    Reentrancy in bridge reserve trade process allowed draining of Kyber-operated reserves

  • Hydro Protocol

    DAI price manipulation on Uniswap/eth2dai allowed undercollateralized borrowing

  • bZx Network

    Oracle vulnerable to price manipulation through permissioned Kyber reserves

  • Livepeer

    Slashing function didn't validate that two submitted proofs were distinct, allowing false slashing of honest transcoders

  • 0x Exchange

    Signature verification treated `0x04` as valid for all non-contract accounts, allowing forged order fills

  • Meteor allow-deny

    Authentication bypass in Meteor's allow-deny package

  • mathjs

    Multiple methods to escape the sandboxed expression parser and achieve RCE

Talks

Press

Contact