I work at the intersection of security, open source, Ethereum and AI, with a focus on technical product marketing and developer-facing products.
- Open-source contributions across Ethereum, security and developer tooling
- Finding and fixing high-impact technical issues
- Building visible proof of work through code, audits and documentation
Fixes accepted by the maintainers of these projects:
| Project | Change |
|---|---|
| ethereum/go-ethereum | Corrected the eth RPC endpoint documentation |
| google/skill-reach | Preserved query metadata across CSV and JSONL exchange formats |
| nasa/delta | Fixed cache eviction for files |
| Samsung/CredSweeper | Fixed CRX3 payload extraction, so credentials inside current Chrome extensions are no longer skipped |
| ethsystems/map | Clarified the ERC-3643 transfer and admin paths |
| Consensys/ask-o11y-plugin | Switched LLM requests from the deprecated max_tokens to max_completion_tokens, with tests. Shipped in v0.3.18 |
| NethermindEth/nethermind | Made engine_newPayloadV3+ reject null or missing withdrawals, blobGasUsed and excessBlobGas with -32602 instead of marking the payload INVALID. My fix and regression test, merged in a maintainer PR that extended the tests |
| DefiLlama/peggedassets-server | Corrected the EURR issuer attribution: Bridge Building S.A. issues it, Revolut distributes it |
Submitted upstream changes backed by reproducible regression evidence and broader checks. These pull requests are open for maintainer review; they are not presented as merged or accepted.
| Project | Change | Status |
|---|---|---|
| openai/codex-security #1020 | Required verification evidence before no_change remediation results are treated as resolved, with a regression proving evidence-free results fail closed |
|
| openai/codex-security #1021 | Added Solidity .sol files to diff scan inventories and rank inputs, with red/green coverage across repository, revision and local-patch modes |
|
| NethermindEth/nethermind #13755 | Rejected engine_getPayloadV5 at Amsterdam with -38005 Unsupported fork, while preserving Osaka V5 behaviour |
|
| NethermindEth/pluto #714 | Kept tracing topic labels visible to metrics at the default info log level, with an integration regression |
|
| NethermindEth/pluto #715 | Stopped ignored OTLP header values from leaking into WARN logs; the warning now records only the header count |
Open pull requests that maintainers are working through. The status badges update on their own when a PR is merged or closed.
| Project | Change | Status |
|---|---|---|
| centrifuge/api-v3 | Added the Pharos block explorer URL | |
| solana-foundation/solana-com | Slot-time block requests now accept v1 transactions |
Also:
-
Proposed re-exporting
@solana/codecsfrom Solana's web3.js v3 (#3943). Review dropped the re-export over maintenance cost and IIFE bundle size, but review of the PR surfaced a Rollup bug that made the v3 IIFE bundles throw in browsers; the PR merged with the maintainer's fix and runtime smoke test. -
proposed the fix for a reported Claude Code startup failure in Trail of Bits'
second-opinionplugin (#303). The maintainer shipped the same fix in #306.
| Area | Result |
|---|---|
| Security research | H1 2026 Digital Asset Security Review: 100+ incidents, $850M in losses |
| Exploit forensics | $287M+ in losses reconstructed |
| Organic reach | 2M+ impressions in 90 days, zero paid spend |
| Community | 2,300+ member security community |
| Disclosures | Acknowledged by the DoD (DARPA, Air Force, Navy), Toyota and Philips |
| Category | Created W3SPM (Web3 Security Posture Management) |
Plain-English case studies of verified open-source fixes, with each problem, change and proof recorded.
-
GTM-Teardowns: public, audit-first go-to-market teardowns of target companies.
-
Web3 Security Library
: Immunefi's library of Web3 security tutorials and tools. Second-largest contributor while at Immunefi
(commits).
-
Best-DeFi-Security-Practices
: a reference list of security practices for DeFi protocols.



