CV

GodwinXbt

Security researcher · Protocol researcher · Engineer

Independent, deployment-aware security research on live financial protocols. Source to deployment. Economic analysis. Executable PoCs. Falsification when the path does not pay. Findings are disclosed and published.

Proof

17 documented findings · 11 protocols · Ethereum, Base, BSC, Robinhood Chain

3 Critical · 6 High · 7 Medium · 1 Informational

Security engagements

Independent research on deployed contracts. Not a retained audit roster. Type is the engagement model. Disclosure is public writeup after responsible handling.

ProtocolChainTypeFindingsDisclosure
lemon.funRobinhood ChainIndependent1 CriticalResponsible disclosure · public writeup
Noon (USN)EthereumIndependent2 CriticalResponsible disclosure · public writeup
Flex FinanceEthereumIndependent2 HighResponsible disclosure · public writeup
HydrexEthereumIndependent1 HighResponsible disclosure · public writeup
Ripe ProtocolBaseIndependent1 HighResponsible disclosure · public writeup
OrvexRobinhood ChainIndependent2 High · 3 MediumResponsible disclosure · public writeup
Ellipsis FinanceBSCIndependent1 MediumResponsible disclosure · public writeup
HyperFXEthereumIndependent1 MediumResponsible disclosure · public writeup
Monolith MarketEthereumIndependent1 MediumResponsible disclosure · public writeup
Panoptic V2EthereumIndependent1 MediumResponsible disclosure · public writeup
Ramses DLMMRobinhood ChainIndependent1 InformationalResponsible disclosure · public writeup

Selected investigations

All research · Full findings

Method

  • Source-to-deployment verification on live contracts
  • Economic analysis before severity is assigned
  • Executable Foundry PoCs against forked mainnet state
  • Falsification when the path does not pay
  • Responsible disclosure, then a public writeup

Engineering used in the research

Ragnarok — adversarial research harness. Themis — runtime invariant monitoring. Solidity, Foundry, TypeScript, Ethereum / Base / BSC / Solana.

Selected engineering work