Jakub

Experienced Lead Blockchain Security Auditor, specialized in non-EVM chains and offchain penetration testing. Expert in MOVE, Rust and Golang.

Available
4 years experience
Vetted

Programming Languages

SolidityGoRustMoveClarity

Expertise & Skills

Cross-chainInfrastructureAMMWalletLending

Let Us Help You Connect

Our team can assist with project requirements, timeline coordination, and finding the perfect match

Portfolio & Experience

Detailed audit history and technical expertise

Portfolio of audits and certificates

About me

I am a cybersecurity expert with more than eight years of experience in the industry. For three years associated with blockchain technology as a Lead Smart Contract and Blockchain auditor. I conducted over 110 audits of various protocols, mostly related to Decentralized Finances. I am specializing in the security of contracts written in Rust, Golang and MOVE, in technologies such as CosmWasm, Sui/Aptos/Movement, NEAR, Ink!, Substrate and Solana, as well as i have a deep technical understanding of EVM and Solidity. I participated in assessments testing low-level aspects of blockchain technology, such as finality proof verifications, serialization libraries, rollups as well as implementations of bridges between many different ecosystems. I have an experience in auditing Layer 1 Blockchains written in Rust, Golang and MOVE. Additionally, i have an experience in testing offchain components such as wallets, infrastructures, oracles and Metamask Snaps. My experience covers also more niche languages, such as Pact, Noir and Rell. Before moving to Web3, I was a Lead Security Researcher and Penetration Tester managing a team of up to 10 engineers. I am also specialized in low-level binary exploitation in both UNIX and Windows environments. Holder of OSCP, OSCE and Lead ISO27001 Auditor certificates.

CEO & Cofounder at Monethic. Currently, I'm also an ASR at Spearbit, Lead Blockchain Security Auditor at Oak Security, Zenith, Sub7, Sayfer, Formal Verification Ambassador at Certora and Lead Smart Contract Security Auditor at Hacken. Additionally, i am a judge on Cantina.

For private audits or security consulting, please reach out to me on:

You can also request a quote on Monethic or Cantina.


Current public reports count: 86


Private & Solo Audits

ProtocolTypeReport
Legion Solana - Solana private Code4rena (Zenith) assessmentRust, Solana📄 Report.pdf
Medley Finance - Decentralized Exchange on SolanaRust, Solana📄 Report.pdf
Legion Solana - Solana second private Code4rena (Zenith) assessmentRust, Solana📄 Report.pdf
Succinct - Succinct SP1 Zero-Knowledge Virtual Machine (zkVM)Ethereum, ZK, Cryptography, Solidity📄 Report.pdf
Compass Wallet - Compass Wallet for SeiTypeScript, Extension, Wallet📄 Report.pdf
Leap Wallet - Leap Cosmos WalletTypeScript, Extension, Wallet📄 Report.pdf
Compass Wallet - Compass Mobile Wallet for SeiAndroid, iOS, Mobile Application, Wallet📄 Report.pdf
Leap Wallet - Leap Cosmos Mobile WalletAndroid, iOS, Mobile Application, Wallet📄 Report.pdf
Kinode OS - Kinode OS security & architecture reviewRust, OS, Architecture📄 Report.pdf
Eagle Finance - EagleFi XYK PoolAssemblyScript, AMM, Massa📄 Report.pdf
Razor DEX - Decentralized Exchange contractsMOVE, Aptos, Sui📄 Report.pdf
Wolf Game - Cave Game, ERC721Solidity, BLAST📄 Report.pdf
Magic Beans - Magic Beans, OTCSolana, Rust📄 Report.pdf
Orderly Network - Asset Manager Smart ContractRust, NEAR📄 Report.pdf
Cascadia Foundation - Liquidity Pools (Curve fork) ContractsSolidity, Vyper-
Holoride - Holoride Ethereum <> MultiversX bridgeRust, MultiversX/Elrond📄 Report.pdf
Uncharted - GangsterArena 5Solidity, BLAST, Gaming📄 Report.pdf
Tezos - Tezos Metamask SnapTypeScript, Metamask Snap📄 Report.pdf
Polkadot - Polkadot Metamask SnapTypeScript, Metamask Snap📄 Report.pdf
Sei - Sei Metamask SnapTypeScript, Metamask Snap📄 Report.pdf
Uncharted - ConfidentialSolidity, BLAST, Gamingsoon
Uncharted - ConfidentialSolidity, BLAST, Gamingsoon
Confidential - ConfidentialSolidity, MetaMorpho ERC4626 Vaultssoon

Audits in a team

ProtocolTypeReport
Unhosted Wallet - Unhosted Wallet Extension Core & Backend ServicesTypeScript, Extension, Wallet📄 Report.pdf
Aave - Aave on Aptos Core v3.0.2MOVE, Aptos, Aave v3📄 Report.pdf
Aave - Aave on Aptos Core v3.1-3.3MOVE, Aptos, Aave v3📄 Report.pdf
Aave - Aave on Aptos PeripheryMOVE, Aptos, Aave v3, Periphery📄 Report.pdf
Hydration - Hydration Peg Drift StableswapRust, Substrate, Polkadot📄 Report.pdf
SelfChain - SelfChain Cosmos SDK modulesGolang, Cosmos SDK📄 Report.pdf
Shogun Bot - Shogun Telegram Bot ApplicationTypeScript, Telegram, Wallet📄 Report.pdf
Landslide Network - Slide SDK, AvalancheGo Custom VMGolang, Cosmos, Avalanche, VM📄 Report.pdf
THORChain - Validator-scheduled Standard Cosmos Hard ForkGolang, Cosmos SDK📄 Report.pdf
Dusa - Dusa AMMAssemblyScript, AMM, Massa📄 Report.pdf
HadronLabs - Drop Initia Liquidity ProviderMOVE, MoveVM, CosmosSDK, Initia📄 Report.pdf
Amulet - Amulet Neutron PoS StretegyRust, CosmWasm📄 Report.pdf
Archisinal - Archisinal MarketplaceRust, NFT, Ink!, Polkadot📄 Report.pdf
Zeitgeist - Zeitgeist Combinatorial Betting and FutarchyRust, Substrate, Polkadot📄 Report.pdf
Jellyverse - Jellyverse Staking, Vesting, Governance, ERC20Solidity, ERC20📄 Report.pdf
Astroport - Astroport vxASTRORust, CosmWasm📄 Report.pdf
Manifest - Custom CosmosSDK implementationGolang, Cosmos SDK📄 Report.pdf
Manifest - Token Factory ModuleGolang, Cosmos SDK📄 Report.pdf
Manifest - POA ModuleGolang, Cosmos SDK📄 Report.pdf
Manifest - Ledger ChainGolang, Cosmos SDK📄 Report.pdf
Glue - EVM SC & L1 Relay chainsRust, Substrate, Polkadot📄 Report.pdf
5ire - Substrate Runtime and PalletsRust, Substrate, Polkadot📄 Report.pdf
Astroport - Astroport Fee SharingRust, CosmWasm📄 Report.pdf
Layer Zero - Layer Zero V2Solana, Anchor, Rust📄 Report.pdf
Mysten Labs - Sui - Adapter & VerifierMOVE, L1, Sui📄 Report.pdf
Volo Sui - VOLO Liquid StakingMOVE, Sui📄 Report.pdf
Satay Finance - Satay AptosMOVE, Aptos📄 Report.pdf
Bifrost - Laverage StakingRust, Substrate📄 Report.pdf
Starlay Finance - Starlay Protocol WASMRust, ink!📄 Report.pdf
Ociswap - Scrypto AVL Tree ImplementationRust, Scrypto, AVL Tree, Radix DLT📄 Report.pdf
Ociswap - Scrypto MathRust, Scrypto, Radix DLT📄 Report.pdf
Ociswap - Scrypto Precision PoolRust, Scrypto, Radix DLT📄 Report.pdf
Ociswap - Scrypto Flex PoolRust, Scrypto, Radix DLT📄 Report.pdf
Ociswap - Scrypto OracleRust, Scrypto, Radix DLT📄 Report.pdf
Hyperlane - cw-hyperlaneRust, CosmWasm📄 Report.pdf
Asteroid - Asteroid BridgeCFT-20, Rust, CosmWasm📄 Report.pdf
Dexlyn - Hyperlane on AptosSupra, MOVE, Bridge📄 Report.pdf
Zesh AI Layer - SUI coinSui, MOVE📄 Report.pdf
SUI Agents - SUI coin & ERC20Sui, Ethereum, MOVE, Solidity, ERC20📄 Report.pdf
Astroport - Tokenfactory LP TokensRust, CosmWasm📄 Report.pdf
Stader Labs - SD Token StakingRust, CosmWasm📄 Report.pdf
Astroport Concentrated Liq Pool - Injective Orderbook IntegrationRust, CosmWasm📄 Report.pdf
Astroport - Astral Assembly contractsRust, CosmWasm📄 Report.pdf
Astroport - Concentrated Liquidity PoolRust, CosmWasm📄 Report.pdf
Astroport - Astroport on OsmosisRust, CosmWasm📄 Report.pdf
Brokkr Protocol - Delta NeutralRust, CosmWasm📄 Report.pdf
Brokkr Protocol - Long Term BondingRust, CosmWasm📄 Report.pdf
Gable Finance - Gable Liquidity Market, StakingRust, Scrypto, Radix DLT📄 Report.pdf
Osmosis Labs - Osmosis TransmuterRust, CosmWasm📄 Report.pdf
Stargaze - Reserve AuctionsRust, CosmWasm📄 Report.pdf
Stargaze - Infinity PoolRust, CosmWasm📄 Report.pdf
Calculated Finance - ContractsRust, CosmWasm📄 Report.pdf
Hadron Labs - Lido SatelliteRust, CosmWasm📄 Report.pdf
Snowfork - SSZ serialization library - RustRust, library📄 Report.pdf
Membrane - ContractsRust, CosmWasm📄 Report.pdf
Coinhall - GenieRust, CosmWasm📄 Report.pdf
Snowbridge - Ethereum <=> Polkadot bridgeRust, Solidity, Polkadot, Ethereum📄 Report.pdf
Snowbridge - Extension, Ethereum <=> Polkadot bridgeRust, Solidity, Polkadot, Ethereum📄 Report.pdf
Snowbridge - Updates, Ethereum <=> Polkadot bridgeRust, Solidity, Polkadot, Ethereum📄 Report.pdf
Snowbridge - Updates 2, Ethereum <=> Polkadot bridgeRust, Solidity, Polkadot, Ethereum📄 Report.pdf
Snowbridge - Updates 3, Ethereum <=> Polkadot bridgeRust, Solidity, Polkadot, Ethereum📄 Report.pdf
Snowbridge - Updates 4, Ethereum <=> Polkadot bridgeRust, Solidity, Polkadot, Ethereum📄 Report.pdf
Ixo World - IXO SwapRust, CosmWasm📄 Report.pdf
Ninja Blaze - Ninja Blaze DoubleRust, CosmWasm📄 Report.pdf
Osmosis Labs - Osmosis Transmuter v3Rust, CosmWasm📄 Report.pdf
Astroport - Astroport Hub Neutron MigrationRust, CosmWasm📄 Report.pdf
Yieldmos - Outpost OsmosisRust, CosmWasm📄 Report.pdf

Certificates

0 day vulnerabilities found which were assigned CVE numbers - mostly web applications

  • CVE-2019-10070 - Apache Atlas, Stored Cross Site Scripting
  • CVE-2020-6856 - JOC Cockpit, Jobscheduler, XML External Entity
  • CVE-2020-6854 - JOC Cockpit, Jobscheduler, Multiple Stored Cross Site Scripting
  • CVE-2020-6855 - JOC Cockpit, Jobscheduler, Denial of Service
  • CVE-2021-3584 - Foreman, Authenticated Remote Code Execution via Sendmail configuration