Posts
10 postsResearch, findings, and vulnerabilities along the way.
2026
Zero Day, Zero Click, Zero Balance
Draining Octra wallets
Minting Money from Nothing
Everybody dreams of turning a ZK verifier into a money printer
Crashing Anvil's OP Deposit Parser
Casting integers is easy to get wrong. One missing bounds check is all it takes
Unsafe Integer Casts in Anvil's JSON-RPC Handler
Five overflow panics across Anvil's RPC surface: gas limits, base fees, block counts etc
Opinions Are Not Vulnerabilities
My take on automated vulnerability research with AI
Starknet Is Zcash, Aztec Is Monero
The oldest debate in privacy coins is playing out again in L2s
2025
2024
Equinor CTF 2024
Writeups and first blood on two challenges at Equinor CTF 2024
The Cost of Complexity and Ownership
Two CodeHawks contests, two high-severity findings, both selected for the final report
Why You Should Care About Zero-Knowledge Proofs
Why ZKPs are important for data privacy and how they work