Summary
Smart contract auditor and CTF player focused on finding vulnerabilities in DeFi protocols and on-chain systems. Experienced across the full audit workflow — reading codebases, tracing execution paths, and writing actionable reports. Active competitor on Sherlock, Code4rena, Cantina, and Codehawks with confirmed findings. Outside of audits, competing in CTFs with TCP1P across web, Web3, and cryptography categories.
Audit Results
Current Finance — Sherlock Contest
2025
Competitive smart contract audit
- 1 valid Medium severity finding confirmed
Codehawks First Flight #56
2025
Competitive audit · Codehawks
- Top #1 ranking out of all participants
Experience
Web3 Security Researcher
2025 – Present
Independent · Remote
- Participating in competitive smart contract audits on Sherlock, Code4rena, Cantina, and Codehawks.
- Analyzed DeFi protocol audit reports to identify vulnerability patterns and attack vectors.
- Studied EVM internals and common vulnerability classes including reentrancy, price oracle manipulation, flash loan attacks, and access control flaws.
CTF Player — TCP1P
2024 – Present
- Solved 100+ challenges across 30+ competitions spanning web, Web3, cryptography, forensics, and reverse engineering.
- Authored Web3 challenges for the TCP1P CTF Platform.
- Published writeups for 50+ challenges at blog.kudaliar.id.
Achievements
- Top #1 — Codehawks First Flight #56 (2025)
- 3rd Place — RITSEC CTF, team TCP1P (2026)
- Top 15 Pentester — CyberAcademy Helium Challenge (2026)
- Solved 100+ CTF challenges across 30+ competitions with 10+ categories
Projects
Constable
2025
Solana Colosseum Agent Hackathon 2025
- On-chain forensics and investigation toolkit for Solana — traces fund flows and identifies suspicious transaction patterns.
SHARK-Fin
2026
PIDI x Digdaya Hackathon 2026 · Bank Indonesia + OJK
- OSINT-based financial threat intelligence platform. Python backend, React frontend, Docker, 92 passing tests.
Skills
Languages
Solidity, Python, JavaScript, Bash
Audit Tools
Foundry, Hardhat, Slither, Echidna
Web3 Knowledge
EVM internals, DeFi protocol mechanics, common smart contract vulnerability classes, Uniswap V4
CTF / Web
Burp Suite, OSINT, XSS, CSRF, cryptography
Other
React, Docker, Git
Certifications
- Cyfrin Updraft: Smart Contract Security
- Cyfrin Updraft: Uniswap V4
- Cyfrin Updraft: Advanced Web3 Wallet Security