-
I am an independent security researcher and the Co-Founder and Lead Auditor at Enigma Dark, where I oversee smart contract security for large protocols such as Aave, Euler, Tapioca DAO, Silo, Credit Coop.
-
I am an in-house security researcher in TapiocaDAO and Hyperdrive
-
Additionally, I serve as a Security Researcher at Spearbit and Paladin Blockchain Security.
-
With over 100 reviews conducted across public, private, and firm engagements, I have audited a diverse range of DeFi protocols, including perpetuals, options, lending, and liquid staking platforms.
-
In 2024, I was the top 1 ranked solo auditor on Hyacinth, outperforming the second position by more than 2x and earning over six figures in bounties.
| Protocol | Protocol Type | High Risk | Medium Risk | Low Risk | NSLOC | Report | | ---- | ---------| ---------| -------| -------| --------| | Lexer Markets | Derivatives | 11 | 23 | 15 | 13000 | Report | Arrow Markets V2 | Options | 8 | 10 | 15 | 3000 | Report | Shezmu | CDP | 6 | 5 | 14 | 3000 | Report | Hyperdrive | Lending | 6 | 5 | 15 | 3000 | Report | Hyperstable | veEscrow | 6 | 5 | 15 | 3000 | Report | Ambit Finance | Lending | 0 | 7 | 10 | 4000 | Report | Tapioca DAO | Omnichain Lending/CDP | 10 | 16 | 15 | 7000 | Report | Fija Finance | Vault Strategies | 1 | 5 | 7 | 1500 | Report | Sybil Samurai | NFT | 1 | 0 | 100 | Report | Ceden Network | Nodes + NFTs | 3 | 5 | 800 | Coming soon | Arrow Markets Token | OFT Token | - | - | - | Coming soon | Arrow Markets Staking | Staking contracts | - | - | - | Coming soon | Arrow Markets Claim | Merkle contracts | - | - | - | Coming soon | Edgeless Network | Lido Strats | 2 | 2 | 400 | Coming soon | Fantasy Top | Card Game | - | - | - | Coming soon | Yeet | Staking | - | - | - | Coming soon | Champz | -- | - | - | - | Coming soon | Volmex | -- | - | - | - | Coming soon | Goldilocks | -- | - | - | - | Coming soon | W3GG | -- | - | - | - | Coming soon | Royco | -- | - | - | 300 | Coming soon | Pepino Casino | -- | - | - | - | Coming soon
| Protocol | Protocol Type | High Risk | Medium Risk | Low Risk | NSLOC | Report |
|---|---|---|---|---|---|---|
| Juicebox | Fundraising | 5 | 16 | 14 | 9000 | Report |
| Flaunch | Launchpad | 2 | 1 | 8 | 1700 | Report |
| Flaunch Extension | Launchpad | 1 | 0 | 4 | 500 | Report |
| Silo | Lending | 0 | 1 | 4 | 3000 | Report |
| Tapioca DAO | Lending | - | - | 5000 | Coming soon | |
| Tapioca DAO | Locking mechanism | - | - | 3500 | Coming soon |
| Protocol | Protocol Type | High Risk | Medium Risk | NSLOC | Report |
|---|---|---|---|---|---|
| Berachain | Perps & Validator Incentives | -- | - | - | Private |
| Protocol | Protocol Type | High Risk | Medium Risk | NSLOC | Report |
|---|---|---|---|---|---|
| Y2K | Migration | 4 | 6 | 1000 | Report |
| Meme Launchpad | Bonding Curve | 9 | 9 | 600 | Private |
| Protocol | Protocol Type | High Risk | Medium Risk | NSLOC | Report |
|---|---|---|---|---|---|
| Ambit Finance | Lending | 14 | 16 | 4000 | Report |
| Smardex | AMM | 5 | 11 | 2000 | Report |
| Wallchain | MEV Protection | 1 | 2 | 500 | Report |
| Davos Protocol I | VE/Governance | 2 | 1 | 1300 | Report |
| Davos Protocol II | Bribes/Gauges | 5 | 12 | 1300 | Report |
| Portal Fantasy | NFT marketplace | 4 | 6 | 1000 | Report |
| D2Quared | DPP/GMX/Camelot/Trader Joe | 8 | 12 | 5000 | Private |
| Protocol | Protocol Type | Link |
|---|---|---|
| GMX V1 I | Perpetuals | Link |
| GMX V1 II | Perpetuals | Link |
| GMX V1 III | Perpetuals | Link |
| GNS | Trading | Link |
| HOPR | Data Privacy | Link |
| Yield Yak | Vaults | Private |
| Pika Finance I | Perpetuals | Private |
| Pika Finance II | Perpetuals | Private |
| GLIF | Liquid Staking | Private |
| Union Finance I | Strats | Private |
| Union Finance II | Strats | Private |
Defi Security Summit 2023 security talk
-
https://medium.com/@mweiss.eth/rlp-encoding-and-zksync-era-library-review-part-i-4826a78f4677
-
https://medium.com/@mweiss.eth/send-ether-with-web3-py-python-bd0e8e85e93e
-
https://medium.com/@mweiss.eth/gas-saving-solidity-81cb5aa7b79b
-
https://medium.com/@mweiss.eth/defi-ii-basic-criptography-fd7c8048007d
-
https://medium.com/@mweiss.eth/defi-iii-liquidity-pools-impermanent-loss-560e9d567d52
-
https://medium.com/@mweiss.eth/amm-liquidity-pools-algorithm-f47f6486bbb1