ali_shehab

Web3 Security Researcher, transitioning from Web2 bug bounty to smart contract audits across Solidity, Cosmos SDK, and Rust — https://custodiasecurity.xyz/.

Available
2 years experience
Vetted

Programming Languages

RustSolidityGoMove

Expertise & Skills

LendingStakingAMMInfrastructureNFT

Let Us Help You Connect

Our team can assist with project requirements, timeline coordination, and finding the perfect match

Portfolio & Experience

Detailed audit history and technical expertise

📜 Portfolio

Web3 Security Researchers — We come from 4 years of bug bounty experience working on major programs like Meta, GitHub, GitLab, and Deribit.
We also have a team member with 3+ years of software engineering experience, bringing strong backend and system architecture expertise to our audits. Since early 2024, We've focused on smart contract security — ranking Top 100 all-time on Code4rena with 100+ high/medium findings, over 10 Top-10 finishes, and multiple wins across Solidity, Cosmos SDK, Move and Rust.

🔍 Experience Highlights

  • Smart Contract Audits: Extensive experience across Solidity, Cosmos SDK, Move and Rust smart contracts.
  • Contest Success: Ranked Top 100 all-time on Code4rena with 100+ high/medium findings, over 10 Top-10 finishes, and multiple wins.
  • Private Audits: Performed audits at Custodia Security securing protocols with millions in TVL.
  • Audit Specialization: Focused on identifying high-impact vulnerabilities in DeFi protocols, including:
    • Logic flaws in protocol mechanics
    • Privilege escalation risks
    • Complex economic attack vectors

🛠️ Skills & Tools

  • Languages: Solidity, Rust, Go, JavaScript/TypeScript, Python , Move
  • Frameworks: Foundry, Hardhat, Anchor, Cosmos SDK
  • Methodologies: Manual review, invariant testing, fuzzing.

📎 See more of our work: https://custodiasecurity.xyz/