0xabdullahx0

KYC
KYCed by Cantina

Web3 Security Researcher specializing in Solidity/Rust smart contract audits across Ethereum, Solana, and hybrid Web2/Web3 infrastructure security assessments.

Available
2 years experience
Vetted

Programming Languages

SolidityRust

Expertise & Skills

StakingNFTBonding-CurvesLendingPerpetuals

Let Us Help You Connect

Our team can assist with project requirements, timeline coordination, and finding the perfect match

Portfolio & Experience

Detailed audit history and technical expertise

Portfolio of Audits & Responsible Disclosures

About Me

I am a cybersecurity professional with over five years of experience, specializing in Web3 and blockchain security for the past two years. My expertise lies in auditing smart contracts and assessing the security of blockchain-related products.

I have extensive experience auditing Solidity and Rust-based contracts across both EVM and non-EVM blockchains, with a particular focus on Ethereum and Solana. In addition to smart contract audits, I am proficient in identifying Web2 threats affecting blockchain systems, auditing wallet extensions, backend infrastructures, and Web2/Web3 hybrid solutions.

Currently Working at Smart Contract Auditor at Blockapex

For private audits or security consulting, please reach out to me on:

Twitter - @0xabdullahx0 LinkedIn - Muhammad Abdullah

Team Audit Reports

ProtocolTypeAudit Report
Amet Finance - Zero Coupon Bonds Issuance ProtocolSolidity , EVMAudit Report
Adot Finance - Bridge and NFT Marketplace on LightlinkSolidity , EVMAudit Report
Axone Blockchain - AI orchestrationGOAudit Report
Ensofi - DeFi Lending/BorrowingRust , SolanaAudit Report
Lightlink BridgeBackendAudit Report
Popfi - DeFi Pepetual DexRust , SolanaAudit Report
ScriptTv - L1 BlockchainGeth (Golang)Audit Report
Stakera - Lottery ProtocolRust , SolanaAudit Report
Stashed Wallet Extension - Chrome Wallet ExtensionAudit Report
Pumpkin.funRust , SolanaAudit Report
Dorafactory (Dora Bridge)SolidityPrivate
Alethai.ai - pump.fun clone for AI agentsRust , SolanaPrivate
Livaat MetaverseSolidityPrivate
EnjoyoorsRust , SolanaPrivate
Toucan LightLink - Cross-Chain Governance & LayerZero OFTsSolidity
MetapoolRust , NearAudit Report
TokenMetrics (TMAI)Solidity, EthereumPrivate

Public Contest

DatePlatformProtocolPositionFindings
Mar 2025CantinaColorPool131H,3M

Hackathons

NameSubmissionPosition
REDACTED(2025)Overlooked web2 vulnerabilities in web3 RealmWinner :trophy: Announcement

Responsible Disclosures

IssueCompanyWriteup/HOF
s3 Bucket takeover leading to KYC informationMoneytokenhttps://medium.com/@mahitman1/i-own-your-customers-22e965761abd
Accessing to KYC information of a Crypto ExchangeBilaxyhttps://medium.com/@mahitman1/i-own-your-customers-22e965761abd
SQL Injection in a Plutus.ioPlutushttps://medium.com/@mahitman1/hacking-a-crypto-debit-card-service-730f287aaee7
Nacos Instance leading to Backend KeysH&Mhttps://medium.com/@mahitman1/how-i-found-a-goldmine-but-got-no-gold-e912a89fa522
Access to Air Conditioning PanelsH&Mhttps://medium.com/@mahitman1/how-attacker-could-have-suffocated-the-company-staff-37a6b7192f12
SSRF leading to BackendCargo.buildhttps://medium.com/@mahitman1/hacking-a-nft-platform-56fc59479d3b?source=user_profile---------1----------------------------
Free Wallet TopUpCJDropshippinghttps://medium.com/@mahitman1/free-wallet-topups-f814bb56640f
XSS In Apple's AcquisitionBeatsByDrehttp://exploiting365.blogspot.com/2016/03/xss-in-beatsbydrecom.html
XSS In SteamSteamhttp://exploiting365.blogspot.com/2016/03/xss-in-steamcommunity.html
XSS In ApptentiveApptentivehttp://exploiting365.blogspot.com/2016/03/cross-site-scripting-xss-in-apptentive.html
XSS In HackpadDropBoxhttp://exploiting365.blogspot.com/2015/09/cross-site-scripting-in-hackpad.html
XSS In EbayEbayhttps://pages.ebay.com/securitycenter/security_researchers_acknowledgements.html
Access to Redis InstanceSilvergoldbull
Subdomain TakeoverSilvergoldbull
Blind XSS In Crypto ExchangeBilaxy
Access to KYC File of CryptoExchangerekeningku
Stealing user funds via leveraging CSRFBilaxy
Blind XSS in admin panelDflow
CSRFs in Skypixel.comDJI
XXE in Solaredge.comSolaredgehttps://www.solaredge.com/bug-bounty-leaderboard
RCE in Cybozu.co.jpCybozu.co.jp
Access to Admin DashboardPlutus.it
Blind XSS in OneplusOneplus
Directory Traversal in OneplusOneplus
Misconfigured s3 BucketSphero
Account takeover using CSRFSphero
Subdomain TakeoverSphero
XSS in Opera.comOperahttps://blogs.opera.com/security/2014/01/thanks-researchers-2014/
XSS in Unity3d.comUnity
XSS in Vmware.comVmware
Log4j in tclTCL
Nacos panel Misconfiguration leading to CredentialsTCL
SQL Injection in TerravirtuaVirtua
Access to multiple instance of 204 netmanH&M