About
I'm a cybersecurity leader who solves big problems at every level of the stack. I disclose critical vulnerabilities in software and smart contracts directly securing billions of dollars and I engage with non-technical leaders and stakeholders by meeting them where they are.
I founded SEAL, a non-profit, to solve cybersecurity challenges the cryptocurrency industry faces on a global scale. Previously, I was a Research Partner at Paradigm.
Writing
- ★Higher Bug Bounties Won’t Stop Hacks
Bug bounties are passive, but security is an active process
- ★Demystifying the North Korean Threat
How the DPRK operates and what their tactics and procedures are
- ★Hiding in Plain Sight
Most people trust, but how many people verify?
- ★Two Rights Might Make A Wrong
Too much raw fish doesn’t make a better roll of sushi
- ★The Dangers of Surprising Code
The only thing worse than a bug in your code that breaks everything is a bug in your code that subtly breaks one thing
- ★Booby Trapping the Ethereum Blockchain
This is how an attacker could have hid a ticking time bomb on the Ethereum blockchain that, when triggered, would hard fork the entire network
- ★Uncovering a Four Year Old Bug
What does it take to find a bug? What about one in a contract that's survived the test of time?
- ★So you want to use a price oracle
Everything you need to know about price oracles and how to use them safely
- ★Escaping the Dark Forest
On September 15, 2020, a small group of people worked through the night to rescue over 9.6MM USD from a vulnerable smart contract. This is our story.
Findings
- ★RariMar 2022
Reentrancy in cEther's use of `.call.value` across Fuse pools allowing theft of all borrowable assets
- ★EtherscanNov 2021
Verification bypass allowing mismatched source code to pass contract verification
- ★SushiSwap MISOAug 2021
`BoringBatchable` delegatecall preserved `msg.value` across batched `commitEth` calls, allowing reused ETH to drain ~$350M via refunds
- ★ENS Name WrapperAug 2021
ERC-1155 safe transfer callback enabled reentrancy during minting
- ★go-ethereumMay 2021
Bug in fast sync state downloader could be exploited to booby-trap the blockchain and trigger a hard fork
- ★AmbisafeApr 2021
Four-year-old state corruption bug in contracts managing over a billion dollars in assets
- ★OptimismFeb 2021
`relayMessage` could be called on the L2-to-L1 Message Passer, enabling call spoofing on L2
- ★Lien FinanceSep 2020
Anyone could mint tokens for free, then burn them for all 25,000 ETH ($9.6M) in the contract
- ★AuthereumFeb 2020
Order-of-operations flaw in meta transaction function allowed account takeover
- ★Ethereum Name Service (CVE-2020-5232)Jan 2020
Domain owner could set a backdoor to claw back ownership after transfer
- ★Pillow (CVE-2019-19911)Dec 2019
Unvalidated integers in FpxImagePlugin.py caused memory exhaustion
- ★Kyber NetworkSep 2019
Reentrancy in bridge reserve trade process allowed draining of Kyber-operated reserves
- ★bZx NetworkJul 2019
Oracle vulnerable to price manipulation through permissioned Kyber reserves
- ★0x ExchangeJul 2019
Signature verification treated `0x04` as valid for all non-contract accounts, allowing forged order fills
- ★mathjsApr 2017
Multiple methods to escape the sandboxed expression parser and achieve RCE
Talks
- How to Fight the Lazarus GroupOct 2025
DC Privacy Summit
- How samczsun is bridging the old web to the dark forestMay 2025
Project Glitch
- Introduction to SEALDec 2024
DeFi Security Summit
- Mar 2024
- How to Improve Crypto SecurityFeb 2024
Unchained
- Top White Hat Hacker Samczsun Discusses the State of Crypto SecurityDec 2023
The Chopping Block
- How Do You Even Write Secure Code AnywaysOct 2022
DeFi Security Summit
- Finding VulnerabilitiesJan 2022
ECH Institute Podcast
Press
- How samczsun is bridging the old web to the dark forestMay 2025
Project Glitch
- Apr 2025
- Apr 2025
- Mar 2025
- Apr 2024
- Mar 2024
- Feb 2024
- Feb 2024
- Paradigm's white hat hacker Samczsun spearheads crypto security operation called Security AllianceFeb 2024
The Block
- Oct 2020
- Oct 2020
- Mar 2020