blockchain security researcher, solana and evm
@deviykee · @deviykee · @deviykee
i find vulnerabilities in smart contracts and DeFi protocols across Solana and EVM chains. my work covers initialization races, front-running, MEV, custody bugs, and access control flaws. i have shipped open-source security tooling for address poisoning detection, trade validation, and multi-chain key management.
- initialization and migration race conditions
- front-running and MEV exploitation paths
- address poisoning and signature validation
- custody and key management
- access control and privilege escalation
- bonding curves and AMM design flaws
| target | chain | vulnerability class | severity | status | date | report |
|---|---|---|---|---|---|---|
| TollyPad | Arc | pool initialization race (TOCTOU) | critical | under review | aug 2026 | report |
| Solana Mobile | Solana | SGT zero-balance ATA bypass | critical | bounty submitted | aug 2026 | report |
| Aumo | EVM | dust redeem full liquidation (O(TVL) loss) | high (critical-class) | disclosed, private | aug 2026 | report |
| Aumo | EVM | unrealizable NAV allows preferential drain | high | disclosed, private | aug 2026 | report |
| SunPump | TRON | graduation migration MEV/flash arbitrage | critical | research | aug 2026 | report |
| JustLend | TRON | multiple critical MEV paths ($100M+ exposure) | critical | research | aug 2026 | report |
| RadarDEX | EVM | pool squat attack | critical | research | 2026 | report |
| Sheriff | Robinhood Chain | burn-path DoS when registry zero | medium | disclosed, private | aug 2026 | report |
| Ellipse | Arc | comprehensive Uniswap v4 hook analysis | none found | complete | sep 2026 | report |
AddressGuard
address poisoning and ENS typosquat detector. scans transaction history for zero-value transfers and look-alike addresses.
TradeGuard
pre-flight trade validator for AI trading agents. ships as an MCP proxy and hook. validates slippage, liquidity depth, and counterparty risk before execution.
MCW (@deviykee/mcw)
multi-chain CLI wallet and MCP server. manages BTC, ETH, SOL, and TRON from one BIP-39 seed with AES-256-GCM encryption. human-in-the-loop approval flow for agent transactions.
- aug 2026: disclosed critical pool initialization race in TollyPad on Arc.
- aug 2026: submitted Solana Mobile SGT verification bypass to official bug bounty program.
- aug 2026: disclosed 1 critical-class and 5 high-severity findings in Aumo DeFi vault (private audit, pre-mainnet).
- aug 2026: disclosed burn-path DoS in Sheriff.money AMM on Robinhood Chain.
- background in wallet custody and key management from the builder side.
languages: rust, solidity, typescript, javascript
chains: solana (anchor, token-2022), ethereum, arbitrum, base, TRON, arc, robinhood chain
security: smart contract auditing, race condition analysis, MEV research, threat modeling, key management, fork testing (foundry)
tools: foundry, slither, anchor, web3.js, solana-web3.js, ethers.js
i disclose responsibly to project teams without preconditions. i provide PoC code, reproduction steps, and mitigation guidance. i discuss compensation after the vulnerability is understood and validated. i never exploit mainnet. all verification is fork-based or read-only.
github: @deviykee
twitter: @deviykee
telegram: @deviykee
bug hunting methodology: iykes-evm-bughunt-skill
full findings archive: hunts/