Best placement
#32
One top-50 finish on Sherlock
Available for security reviews
Smart contract security / EVM · XRP Ledger · Solana / Banjarmasin, ID
I break assumptions in protocol logic — AMM invariant math, reserve accounting, deposit limits, cross-program trust boundaries. Seven accepted findings across Sherlock and Cantina.
Accepted findings
07
Best placement
#32
One top-50 finish on Sherlock
Earnings
$495
Across five paid competitions
Verified profiles
Findings
AMMDeposit
XRP Ledger
Low
AMMDeposit
XRP Ledger
Medium
5 competitions · 444.81 USDC on XRP Ledger (#75) · #32 Current Finance · #115 DRE App · #162 Clear Macro · Revert Finance on Cantina. Severity labels published by the hosting platform.
Tooling
Manifest-driven on-chain CTF infrastructure — Foundry templates, per-player Anvil launchers, Kubernetes deployment.
Recursively traces Solana token flows across wallets and exports transaction paths for investigation.
Sealed-bid auction infrastructure on Solana using Anchor and private ephemeral rollups.
Privacy-preserving medication eligibility with Midnight Compact contracts, nullifiers, and ZK credentials.
Threat-intelligence pipeline for Indonesian financial data leaks with risk scoring and PII masking.
An on-chain pet whose survival is tied to real leveraged perpetual positions and MagicBlock state.
Writing
30 May 2026 · Forensics
Five Git forensics challenges spanning hidden commits, odd authorship, deleted blobs, and replace refs.
30 May 2026 · Web
Beating an event-handler blocklist and a strict CSP with an autofocus payload and a navigation leak.
17 May 2026 · RF / SDR
Separating five overlapping 915 MHz transmissions across Morse, FM voice, AX.25/APRS, and DQPSK.
02 Mar 2026 · Blockchain
Exploiting missing program ID checks in Solana cross-program invocation verification.
About
I’m a medical doctor who audits smart contracts. Diagnosis and security review are the same discipline under different names: enumerate what could be true, rank by likelihood and consequence, then go find the evidence that separates them. Severity is likelihood times impact in both.
I go deepest on AMM and stableswap mathematics, reserve and sponsorship accounting, Uniswap v4 hooks, and Solana CPI verification. Every issue I report ships with a runnable Foundry proof and a recommended patch — if I can’t make a test fail, I don’t file it.
Outside audits I compete with TCP1P, currently ranked #1 in Indonesia on CTFTime’s 2026 leaderboard, with 100+ challenges solved across 30+ competitions.
Stack
Solidity, Rust and Anchor, Compact, Python, TypeScript, SQL, and Bash. Foundry for proofs, Anchor for Solana programs.
Certifications
Competition results
Contact
Private reviews, contest support, fix review, and proof-of-concept development.