Available for security reviews
Banjarmasin, ID · UTC+8
Muhammad Rifqi Haikal @kudaliar
Finding the flaws.
Before they
find you.
Independent smart contract security researcher. I turn protocol assumptions into reproducible findings — and help teams build with confidence.
EVM XRP Ledger Solana
Question. Reproduce. Verify.
Better questions. Stronger protocols.
- Accepted findings
- 07↗
- Chain ecosystems
- 03
- Open-source repositories
- 30+
- Published writeups
- 60+
01 / Security research
Proof, not promises.
Public findings. Reproducible impact. A record you can verify.
Preclaim reserve check double-charges a base reserve, blocking single-asset XRP
Low
Lender-initiated LoanSet with a pre-funded sponsor
returns tecINTERNAL
Low
Vault sponsorship cannot be transferred, reassigned, or ended
Medium
Minimally-funded reserve sponsor rejects a legitimate sponsored
AMMDeposit
Medium
A depositor can exceed the protocol deposit caps
MediumExact-output swaps round required input to zero for low-decimal tokens
Medium
Lopsided first deposits overflow getInvariant,
bricking every swap
Medium
5 medium · 2 low — severity classifications published by Sherlock and Cantina.
Competition record & earnings
Best placement: #32 on Sherlock · $495 across five paid competitions. 444.81 USDC on XRP Ledger (#75) · #32 Current Finance · #115 DRE App · #162 Clear Macro · Revert Finance on Cantina.
02 / Selected projects
Built out of curiosity.
Tools, experiments, and infrastructure. Open source by default.
03 / Field notes
Down the rabbit hole.
What I break, what I learn, and how I got there.
BYU CTF 2026: Gitastic 1–5
Five Git forensics challenges spanning hidden commits, odd authorship, deleted blobs, and replace refs.
BYU CTF 2026: on point
Beating an event-handler blocklist and a strict CSP with an autofocus payload and a navigation leak.
NDIAS 2026: D’s Signpost
Separating five overlapping 915 MHz transmissions across Morse, FM voice, AX.25/APRS, and DQPSK.
BITSCTF 2026: Bank Heist
Exploiting missing program ID checks in Solana cross-program invocation verification.
04 / The person behind the proofs
A different kind of diagnosis.
Medical doctor. Security researcher.
I’m a medical doctor who audits smart contracts. Both disciplines start with the same instinct: question what looks normal, find the hidden failure, and follow the evidence.
I go deepest on AMM and stableswap mathematics, reserve accounting, Uniswap v4 hooks, and Solana CPI verification. Every issue I report comes with a runnable proof and a recommended patch. If I can’t make a test fail, I don’t file it.
Outside audits, I compete in CTFs with TCP1P — with 100+ challenges solved across 30+ competitions — and build tools that scratch my own itch.
Tools of the trade
Continually learning / Cyfrin Updraft
- Cyfrin Updraft — Smart Contract Security
- Cyfrin Updraft — Uniswap V4
- Cyfrin Updraft — Advanced Web3 Wallet Security
A few milestones along the wayCompetition results
Hackathons
- 1stMidnight Network Hackathon — Healthcare Track (2026)
- 1stAgents Assemble — The Healthcare AI Endgame
- 2ndDevNetwork AI + ML Hackathon — TrueFoundry Track (2026)
- 3rdSolana MagicBlock Hackathon (2026)
- 3rdWeb Data Unlocked Hackathon
- 3rdHackerRank Orchestrate Hackathon — August 2026
- Top 5HackerRank Orchestrate Hackathon — May 2026
- Top 10Paradigm Optimization Hackathon
- HMMind The Products Hackathon — Honorable Mentions
- HMQuran Foundations Hackathon — Honorable Mentions
Security
- #1CodeHawks First Flight #56 (2025)
Capture the flag
- 3rdRITSEC CTF — TCP1P (2026)
- FinalistWaskita Manunggal Siber CTF (2026)
- Top 15CyberAcademy Helium Challenge (2026)
05 / Let’s work together
Let’s make it
harder to break.
Building something that needs a second set of eyes? Let’s talk security reviews, proofs of concept, and getting the details right.
rhaikal91@gmail.com