Skip to content
View arunimshukla's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report arunimshukla

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
arunimshukla/README.md

Arunim Shukla

AI Security Technical PMM Open Source Ethereum Developer Tooling AI Tooling GTM Strategy

I work at the intersection of security, open source, Ethereum and AI, with a focus on technical product marketing and developer-facing products.

📊 GitHub Stats

🚀 Current Focus

  • Open-source contributions across Ethereum, security and developer tooling
  • Finding and fixing high-impact technical issues
  • Building visible proof of work through code, audits and documentation

🛠 Tech

Python GitHub Ethereum Solidity

Merged upstream

Fixes accepted by the maintainers of these projects:

Project Change
ethereum/go-ethereum Corrected the eth RPC endpoint documentation
google/skill-reach Preserved query metadata across CSV and JSONL exchange formats
nasa/delta Fixed cache eviction for files
Samsung/CredSweeper Fixed CRX3 payload extraction, so credentials inside current Chrome extensions are no longer skipped
ethsystems/map Clarified the ERC-3643 transfer and admin paths
Consensys/ask-o11y-plugin Switched LLM requests from the deprecated max_tokens to max_completion_tokens, with tests. Shipped in v0.3.18
NethermindEth/nethermind Made engine_newPayloadV3+ reject null or missing withdrawals, blobGasUsed and excessBlobGas with -32602 instead of marking the payload INVALID. My fix and regression test, merged in a maintainer PR that extended the tests
DefiLlama/peggedassets-server Corrected the EURR issuer attribution: Bridge Building S.A. issues it, Revolut distributes it

Recent validated contributions

Submitted upstream changes backed by reproducible regression evidence and broader checks. These pull requests are open for maintainer review; they are not presented as merged or accepted.

Project Change Status
openai/codex-security #1020 Required verification evidence before no_change remediation results are treated as resolved, with a regression proving evidence-free results fail closed state
openai/codex-security #1021 Added Solidity .sol files to diff scan inventories and rank inputs, with red/green coverage across repository, revision and local-patch modes state
NethermindEth/nethermind #13755 Rejected engine_getPayloadV5 at Amsterdam with -38005 Unsupported fork, while preserving Osaka V5 behaviour state
NethermindEth/pluto #714 Kept tracing topic labels visible to metrics at the default info log level, with an integration regression state
NethermindEth/pluto #715 Stopped ignored OTLP header values from leaking into WARN logs; the warning now records only the header count state

In review

Open pull requests that maintainers are working through. The status badges update on their own when a PR is merged or closed.

Project Change Status
centrifuge/api-v3 Added the Pharos block explorer URL state Approved
solana-foundation/solana-com Slot-time block requests now accept v1 transactions state Awaiting review

Also:

  • Proposed re-exporting @solana/codecs from Solana's web3.js v3 (#3943). Review dropped the re-export over maintenance cost and IIFE bundle size, but review of the PR surfaced a Rollup bug that made the v3 IIFE bundles throw in browsers; the PR merged with the maintainer's fix and runtime smoke test.

  • proposed the fix for a reported Claude Code startup failure in Trail of Bits' second-opinion plugin (#303). The maintainer shipped the same fix in #306.

Numbers behind the work

Area Result
Security research H1 2026 Digital Asset Security Review: 100+ incidents, $850M in losses
Exploit forensics $287M+ in losses reconstructed
Organic reach 2M+ impressions in 90 days, zero paid spend
Community 2,300+ member security community
Disclosures Acknowledged by the DoD (DARPA, Air Force, Navy), Toyota and Philips
Category Created W3SPM (Web3 Security Posture Management)

Selected work

Open Source Fix Analysis

Plain-English case studies of verified open-source fixes, with each problem, change and proof recorded.

Contact

LinkedIn or Twitter (X)

Pinned Loading

  1. Best-DeFi-Security-Practices Best-DeFi-Security-Practices Public

    A comprehensive list of security practices for DeFi protocols.

    88 19

  2. GTM-Teardowns GTM-Teardowns Public

    An independent collection of Go-To-Market (GTM) strategy assessments, positioning teardowns, and messaging audits for high-growth platforms.

  3. immunefi-team/Web3-Security-Library immunefi-team/Web3-Security-Library Public

    Information about web3 security and programming tutorials/tools

    2.2k 343

  4. nasa/delta nasa/delta Public

    Deep Learning for Satellite Imagery

    Python 232 69

  5. Samsung/CredSweeper Samsung/CredSweeper Public

    CredSweeper is a tool to detect credentials in any directories or files. CredSweeper could help users to detect unwanted exposure of credentials (such as token, passwords, api keys etc.) in advance…

    Python 224 53

  6. Consensys/ask-o11y-plugin Consensys/ask-o11y-plugin Public

    AI-powered observability assistant for Grafana that helps you query data, investigate issues, and manage dashboards through natural language.

    Go 42 13