Q2 booked · booking Q3 2026 audits · remote · global · replies < 24h
~/panther $

panther.audits — smart contract security auditor

smart_contract_security_researcher // move-first · multi-ecosystem

I find protocol-breaking bugs before mainnet. Deep expertise across Move, Rust/Solana, EVM, Cairo, and TON — plus active research in ZK and AI security. Aave, DeepBook, Decibel, Tensor, PancakeSwap, Venus — 50+ protocols reviewed across audits, contests, and bounty triage, securing $10B+ in combined TVL.

#01 trusted_by

Firms & platforms

// 20 engagements with Pashov Audit Group · 8 with Adevar Labs · repeat reviewer for multiple firms

// contracted by

Three Sigma Sherlock Cyfrin Pashov Audit Group Adevar Labs Zenith Accretion Vulsight ↗

// ranked on

Cantina Code4rena CodeHawks verify: cantina profile ↗
#02 what_people_say

Testimonials

// feedback from lead auditors and protocol teams

The auditor bonus goes to @theblackpantherhere for this one! Great performance by all others as well, thank you!
Pashov / Founder, Pashov Audit Group ★ bonus_award
Just wanted to drop a positive feedback, I really like both your skills and dedication. It's great working with you ser.
Nic / Security Audit Lead, Three Sigma ★ team_lead
I wanted to thank you for your insanely good work throughout the engagement, you submitted a lot of findings, and each one was of high quality. I would recommend you eyes closed.
Salah Ismail / Security Researcher, Adevar Labs ★ strong_recommend
#03 best_fit

Best fit for

// where I add the most value for protocols and audit firms

01direct

Direct protocol audits

Solo engagements scoped, executed, and reported by me end-to-end: threat model → review → report → fix-review. No firm overhead — direct access to the researcher reading your code.

02move-depth

Sui & Aptos Move depth

Object ownership, PTB composition, shared objects, abilities, resource accounts, and upgrade paths — the Move-specific bug classes that brick protocols, and that EVM-trained auditors walk past.

03defi-heavy

Complex DeFi reviews

Lending, credit systems, perps, CLOBs, DEXes, vaults, staking, RWA, and cross-chain systems where accounting and liquidation paths need deep review.

04firm-side

Audit firm reviewer capacity

Private engagements under NDA, second-review support, contest-style depth, report-ready findings, and fast ramp-up on unfamiliar codebases.

05triage-ops

Bounty triage & validation

Severity validation, deterministic PoC reproduction, and reviewer-ready handoff for live bounty programs — Move (Sui/Aptos core), Solana Token-2022/NFT marketplaces, EVM/Solidity DeFi, and OP Stack/Go scopes.

06proof-driven

Formal verification support

Invariant design, Certora CVL, Sui Prover, Move Prover, and property-driven review for protocol-critical accounting and access-control logic.

07emerging-risk

ZK and AI security review

Emerging focus — independently rediscovered a critical ZKsync Lite circuit issue. Constraint soundness, proof-system assumptions, AI model attack surfaces, output integrity, and ML supply-chain risk.

#04 workflow

How I work

// structured enough for firm workflows, deep enough for protocol-critical code

01

Build the threat model first

Map trust boundaries, assets at risk, privileged roles, user flows, external dependencies, upgrade paths, and protocol-specific failure modes before hunting isolated bugs.

02

Prove the core invariants

Stress the accounting, solvency, access-control, oracle, liquidation, settlement, and state-machine invariants that must hold for the protocol to stay safe.

03

Attack real execution paths

Trace adversarial flows across deposits, withdrawals, liquidations, upgrades, callbacks, cross-chain messages, keeper actions, and partial-failure scenarios.

04

Deliver findings teams can act on

Each report is written with clear impact, root cause, exploit path, affected code, mitigation guidance, and PoC or test direction where the engagement allows it.

#05 stack

Languages & ecosystems

// multi-chain coverage across the highest-value platforms

Movesui · primary
Moveaptos · primary
Solidityevm
Rustsolana
Cairostarknet
Vyperevm
Swayfuel
FunC / Tactton
Goop-stack

defi_protocols

lendingcreditdex_ammperps yieldclobasset_mgmt

nft_infra

marketplacesbonding_curves nft_bridgesnft_amms

staking_restaking

liquid_stakingrestaking staking_vaultsvalidators

xchain_infra

bridgeswormholexchain_msg rwaaccount_abstraction
#06 contest_wins

Top 3 finishes

// 6× top-3 placements in competitive audit contests · verify on my cantina profile ↗

2nd · silver
$16k+
Arcade.xyz
NFT-backed lending · Solidity
1 M
3rd · bronze
$24k+
Aave (Aptos)
Flagship lending protocol · Move
3rd · bronze
$13k+
Tensor
Solana NFT marketplace w/ AMM · Rust
3rd · bronze
$6.8k+
Velvet v4
Modular DeFi asset management · Solidity
6 H7 M
3rd · bronze
Juicebox
Programmable treasury · Solidity
2 M8 L
3rd · bronze
Venus
Governance contracts, BNB Chain · Solidity
9 L
#07 proof_points

Proof points

// short examples of the bug classes and review depth I bring to audits

#08 notable_findings

Critical & High severity

// selected protocol-breaking findings across ecosystems

Saffron Lido Vaults
Liquid Staking · Pashov
1 C1 H
Decibel
Perpetuals · Aptos · private bounty
1 C2 H
MightyFi
DeFi · Cantina
6 H
Velvet v4
Asset Management · Cantina
6 H
Rip.fun
NFT Marketplace · Pashov
2 H
HypurrFi
Leveraged Trading · Pashov
2 H
Tensor
NFT AMM · Solana · Cantina
2 H
StarVault
Crowdfunding · Solana · Adevar Labs
2 H
Chakra
Cross-chain · Cairo · Code4rena
2 H
Starknet Staking
Staking · Cairo · CodeHawks
1 H
Chorus One (TON)
Staking · FunC · Cantina
1 H
─── bug_bounties ─────────────────────────────────────────────────────

// independent vulnerability disclosures across L1/L2 protocols

Decibel
Move · Aptos
confirmed
1 C 2 H 5 M
Private program — the critical matched an issue the team was already tracking internally; both highs and all five mediums were confirmed and rewarded.
OpenZeppelin
Cairo Contracts
public
1 M
view advisory →
ZKsync Lite
ZK Circuits
acknowledged
1 C (known issue)
Independently discovered a critical ZK circuit vulnerability — classified as a known issue by the team.
3
programs
2
criticals*
2
highs
6
mediums
3
ecosystems

// *both criticals were independent rediscoveries of issues the teams were already tracking — found blind, without internal context

view full audit history
#09 recent_writing

From the blog

// deep dives into real vulnerabilities, audit war stories, and research

featured_post jun 5, 2026 · private work · bounty triage

Private Bug Bounty Triage — Validating and Reproducing Web3 Findings

Inside my firm-side triage workflow: validating live bounty submissions, writing deterministic PoCs after triage, and packaging clean impact evidence — without leaking client details.

read full post →
#10 faq

Engagement FAQ

// the practical answers before you reach out

01

How is pricing determined?

Per scope and complexity. Send the repo (or docs) with an estimated LoC and you'll get a quote within 24h. Scoping is always free.

02

How long does an audit take?

Focused reviews: under a week. Comprehensive audits: 1–3 weeks depending on size and complexity. The exact timeline comes with the quote.

03

What do I actually get?

A report with severity-classified findings — impact, root cause, exploit path, affected code, and PoCs where applicable — plus mitigation guidance and a fix-review pass on your remediations.

04

Do you work under NDA?

Yes — most of my portfolio is firm-side NDA work. I'll sign yours, or provide a standard mutual NDA.

05

How do I verify the private work?

References from the engaging firms — Pashov Audit Group, Adevar Labs, Three Sigma, Sherlock, Cyfrin, Zenith — and redacted findings summaries are available on request.

06

Direct audit or through a firm?

Both work. Hire me directly for a solo engagement, or through any of the firms I review for — whichever fits your procurement and budget.

#11 contact
~/panther $ ./contact --protocol=yours

Ready to secure your protocol?

Booking Q3 2026 audit slots — also available for security consulting, formal verification, firm-side reviewer capacity, and bounty triage support. Move / Rust / Solidity / Cairo / Vyper / TON / ZK / AI security. Reach out on X or Telegram — I reply within 24h. Scoping is free.

send a short brief
  • protocol name, ecosystem, and audit scope
  • repo/docs access, estimated LoC, and target dates
  • whether you need a solo review, firm-side reviewer capacity, formal verification, or bounty triage support

// official channels: x.com/thepantherplus (also known as @theblackpantherhere) · t.me/theblackpantherhere — any other handle is an impersonator