Smart Contract Security Best Practices
The checks that catch the most bugs before an audit: invariant tests, access-control review, and reasoning about external calls.
Publishing soonBlockchain Security Researcher specializing in smart contract security, artificial intelligence, blockchain infrastructure, autonomous AI agents, cloud systems, and Web3 automation.
I design and build AI-powered blockchain infrastructure, security platforms, autonomous AI agents, smart contract tooling, cloud-native backend systems, and Web3 automation.
My work combines security research, distributed systems, artificial intelligence, and scalable infrastructure.
Day to day that means reading contracts closely, shipping backend systems that stay up, and giving AI agents enough structure to be useful without being dangerous.
Eleven tools I reach for most across security, AI, and infrastructure work.
Began building on EVM chains: first Solidity contracts and the fundamentals of decentralised systems.
Shifted focus to vulnerability research — reading contracts, studying historical exploits, and mapping common attack surfaces.
Started building LLM-driven automation: multi-provider orchestration, tool execution, and agentic workflows.
Built out backend pieces — RPC access, indexing, wallet integration, and containerised deployment.
Working on agents that reason, plan, and act across blockchain and cloud environments.
Independent
Self-directed research into smart contract vulnerabilities, exploit techniques, and Web3 security practices.
Independent
Building autonomous agents that reason, hold memory, execute tools, and run multi-step workflows.
Independent
Building blockchain utilities, automation tooling, and the backend infrastructure they run on.
Autonomous agents, security research, and the infrastructure underneath them. Each card states what is public and what is not — several are private or still prototypes, and the status label says which.
Autonomous agent runtime with persistent memory, tool execution, and multi-provider reasoning, operated through Telegram.
LLM routing layer that presents one API across OpenAI, Claude, Gemini, and OpenRouter, with health-based routing and failover.
Ongoing research into smart contract vulnerability classes, MEV, and protocol attack surfaces, with reproductions written as Foundry tests.
Personal tooling for wallet monitoring, multi-chain read operations, and Telegram-delivered alerts.
Analysis pipeline that runs static analysis over Solidity sources and groups findings into a reviewable report.
Interface over on-chain activity: address monitoring, transaction views, and charting on top of indexed data.
Public repositories from my GitHub. Some are original work and some are forks — each card links straight to the repo, and anything not yet confirmed is marked rather than claimed.
Details pending verification.
Details pending verification.
Details pending verification.
Details pending verification.
Details pending verification.
Details pending verification.
Details pending verification.
Details pending verification.
Details pending verification.
Details pending verification.
Public destinations rather than claims. Most project work sits in private repositories, so this list is deliberately short — it will grow as repos and deployments go public.
Six areas I work in end to end — from autonomous agents and contract review through to the cloud systems that keep them running.
Autonomous agents that reason, plan, execute tools, hold memory, and orchestrate multi-step workflows.
Smart contract audits, exploit research, vulnerability analysis, and security architecture review.
RPC layers, wallet integrations, backend APIs, indexers, and the automation that ties them together.
Containerized, observable deployments on Linux and AWS with pipelines built to ship safely.
Blockchain intelligence, wallet investigation, protocol analysis, and on-chain forensics.
Telegram and Discord bots, browser automation, AI workflows, and backend job orchestration.
Grouped by layer — from the languages and frontend through to AI models and the chains they work with.
Planned pieces on smart contract security, autonomous agents, MEV, and running Web3 infrastructure under load. None are published yet — the titles below are what I am writing, not links.
The checks that catch the most bugs before an audit: invariant tests, access-control review, and reasoning about external calls.
Publishing soonWhere autonomous agents genuinely help on-chain, where they add risk, and how to bound what an agent is allowed to sign.
Publishing soonHow ordering value is extracted, what sandwiching and backrunning look like in the mempool, and the protections available today.
Publishing soonMemory, planning loops, tool execution, and failure handling — the parts of an agent that decide whether it survives production.
Publishing soonRPC fan-out, indexer lag, and reorg handling: the operational realities of running Web3 backends under load.
Publishing soonOpen to security research, smart contract review, AI agent work, and Web3 infrastructure. The form reaches my inbox directly, or use any channel below.