Available for selected reviews Independent. Worldwide.

Panther / Smart contract security

Independent
security researcher.

I’m Panther. I review Move systems on Sui and Aptos, plus complex DeFi across Rust, Solidity, and Cairo. From state transitions to solvency, I follow the assumptions that put funds at risk.

Case file 01 / Aave Aptos 1 H confirmed

One wrong address.
A protocol-wide failure.

  1. 01 / write move_to(@aave_data, Data) configuration resource stored
  2. 02 / read borrow_global<Data>(@aave_pool) getters point to a different address
  3. 03 / impact ERESOURCE_DNE core configuration reads abort
Storage-flow tracing plus a minimal PoC exposed a confirmed High in Aave's first non-EVM deployment. verify the public finding ↗ Cantina profile ↗
#01 selected_findings

The findings behind the work.

// public proof where disclosure allows; precise role labels everywhere

02
Cairoindependent disclosureCVE

OpenZeppelin Cairo — the pending owner that survived renunciation

Context
Review of OpenZeppelin's Cairo OwnableTwoStep state lifecycle.
Panther's role
Independent researcher; privately disclosed the issue to OpenZeppelin.
Risk & outcome
A stale pending owner could accept ownership after renunciation, restoring admin control to a contract users believed was ownerless. OpenZeppelin fixed the state cleanup in v0.16.0.
Evidence
Published as CVE-2024-45304 / GHSA-w2px-25pm-2cf9.
03
Sui Movefirm-sideNDA-safe

Sui lending — proving an eMode assignment cannot change mid-position

Context
A real Sui Move lending engagement delivered firm-side through Sherlock; sensitive protocol details remain private.
Panther's role
Security reviewer and formal-verification contributor using Certora's Sui Prover.
Risk & outcome
If an obligation could switch eMode groups, collateral and borrowing rules could cross risk tiers. The modeled immutability invariant passed across six target functions plus sanity checks.
Evidence
The report remains private; the property, methodology, limits, and verification result are documented publicly.
#02 language_register

Complex systems.
Concrete experience.

Grouped by language and ordered by indexed evidence views — not self-assessed skill. Multi-runtime engagements can appear in more than one stack. Every named codebase links to its evidence; nothing here is an endorsement.

25 named systems shown · the full record spans 79 distinct engagements and programs, including NDA work open the full work record →

#03 engagement_lanes

One researcher.
Two ways to work together.

// one specialty, adapted to protocol teams and audit firms

01for protocol teams

Direct protocol security review

Focused and comprehensive reviews for Move on Sui, Aptos and Movement, Solana Rust, and complex EVM DeFi, from threat model through remediation review.

  • Move-specific ownership, capability, object, resource, and PTB analysis
  • Accounting, solvency, oracle, liquidation, and cross-chain invariants
  • Prediction-market state machines: pricing, signed oracles, settlement, NAV, LP queues, and PTB composition
  • Report-ready findings with exploit paths and actionable mitigations
scope a protocol review
02for audit firms

Firm-side reviewer capacity

Dependable reviewer depth for private engagements, second passes, unfamiliar codebases, and deadlines that need another senior set of eyes.

  • NDA-ready, fast ramp-up, and compatible with established firm workflows
  • Independent attack-path review and clean, reviewer-ready submissions
  • Move-native depth backed by multi-ecosystem production experience
book reviewer capacity

Specialist add-ons

  • Bounty triage & validationseverity analysis, PoC reproduction, reviewer handoff
  • Formal verification supportinvariant design, Certora CVL, Sui and Move prover workflows
#04 review_protocol

I follow state, authority, and value—not just functions.

// state transitions over checklist scanning; evidence over intuition

  1. 01
    invariant model

    Model the promise

    Turn documentation, trust boundaries, privileged roles, and protocol economics into explicit properties the system must preserve.

  2. 02
    authority + asset flow

    Trace the whole system

    Follow capabilities, value, oracle data, and cross-module state through the real execution paths—including composed transactions.

  3. 03
    break + prove

    Challenge, reproduce, close

    Break the model at its boundaries, reduce material issues to reviewable evidence, then verify the fix against the original invariant.

#05 delivered_through

Ten security firms and platforms have carried my work.

The roster combines commissioned firm-side delivery and public contest platforms; those roles are labelled separately in the work record. The NDA-safe private ledger contains 34 engagements, with client names shown only where disclosure permits.

Pashov Audit Group private delivery · triage
Zenith triage · validation
Adevar Labs private delivery
Sherlock firm-side delivery
Cantina contest platform
Three Sigma private delivery
Zellic triage
Cyfrin private delivery
Accretion private delivery
BurraSec NDA delivery
“The auditor bonus goes to @theblackpantherhere for this one! Great performance by all others as well, thank you!”
Pashov / Founder, Pashov Audit Group repeat firm-side reviews
“Just wanted to drop a positive feedback, I really like both your skills and dedication. It's great working with you ser.”
Nic / Security Audit Lead, Three Sigma firm-side review work
“I wanted to thank you for your insanely good work throughout the engagement, you submitted a lot of findings, and each one was of high quality. I would recommend you eyes closed.”
Salah Ismail / Security Researcher, Adevar Labs firm-side engagement

// Private engagement feedback; names and roles are shown only where attribution is permitted. Publicly verifiable work remains linked separately in the ledger.

#06 field_notes

Recent technical writing

// the reasoning behind the review—not a generic vulnerability checklist

security_expertise

Security research by ecosystem and protocol

Explore review scope, relevant findings, and technical writing for your protocol.

#07 engagement_faq

Before you send the scope

What scopes are the strongest fit?

Move systems on Sui, Aptos, or Movement, and complex DeFi—especially lending, perps, DEX/CLOB, vault, staking, RWA, oracle, and cross-chain logic. Solana Rust and EVM Solidity scopes are regular work too; other ecosystems are considered when the protocol mechanics match the review depth.

How are timeline and pricing determined?

Per scope and complexity. Focused reviews can fit inside a week; comprehensive reviews commonly run one to three weeks. Share a scope summary, estimated LoC, repository or documentation, and target dates for a concrete quote.

Can the engagement stay private?

Yes. Most firm-side work is under NDA. A mutual NDA can be established before private code access, and public disclosure happens only where the engagement permits it.

Can audit firms reserve reviewer capacity?

Yes. Use the firm-side intake route and include ecosystem, approximate scope, delivery window, expected role, and your internal reporting workflow.

#08 open_channel

accepting selected review scopes

Give the protocol an adversarial review before users do.

Send the ecosystem, scope or estimated LoC, repository/docs, target dates, and the outcome you need. Start with a public link or scope summary; private repository access can move to an NDA-backed channel.

// verified channels: X / Twitter: @thepantherplus ↗ · Telegram: @theblackpantherhere ↗