Independent Security Research

I study how systems fail across infrastructure, software, custody, and human-AI interaction. My public work includes security investigations, forensic analysis, research synthesis, and working papers.

Disclosures & Threat Research

Each record documents its own scope, evidence, publication history, and known outcome. Some summaries intentionally withhold technical details. A submission or publication does not establish vendor acceptance or remediation.

Bifrost Infrastructure

Infrastructure security

Infrastructure security research spanning Kubernetes, cloud systems, and the trust boundaries between connected services.

Submitted to Immunefi · February 2026.

Read public record

Coin98 Super Wallet

Wallet security

Cross-platform wallet security research covering browser, Android, and iOS, with a focus on wallet isolation and application trust boundaries.

Submitted to HackenProof · March 5, 2026.

Read public record

Bifrost XSS

Application security

Application security research examining backend data integrity and frontend content trust in a wallet-connected application.

Submitted to Immunefi · February 2026. A separate investigation from Bifrost Infrastructure.

Read public record

Universal Intent Validation Protocol

Human-AI interaction

Cross-model research on premature intent classification when user input is ambiguous.

Latest documented status: under disclosure review, December 2025. Technical materials remain withheld.

Read public record

ENS Metadata

Content integrity

Security research on metadata rendering and content sanitization across a shared web service.

Submission to Immunefi recorded.

Read public record

Interport

CPK-2026-003

Public record of a service-credential exposure finding in a production web application.

Vendor notified February 17, 2026. The summary records a May 18 disclosure deadline.

Read public record

Google Workspace Invitation Phishing

CPK-2026-005 · TLP:CLEAR

Threat research documenting a campaign targeting Web3 founders through trusted-brand impersonation, with analysis of variable page presentation and phishing indicators.

Latest documented observation: June 2, 2026. The repository preserves the original PDF and the corrected advisory identifier.

Read public record

Research & Case Studies

GemPad: Signing-Key Exposure & On-Chain Forensics

On-chain investigation · 2026

I traced an exposed GemPad signing key to a wallet with four successfully deployed Tron contracts, then linked its funding to a deployer with at least 49 recorded contract deployments.

The investigation classified 50 recorded transactions, separated 27 deployment attempts from four successful deployments, and documented the funding relationship connecting the exposed wallet to the wider deployment infrastructure.

Contract administrative privileges, downstream financial exposure, and remediation status remain unresolved in the published record.

Submitted February 7, 2026; published May 8.

Read public record

RevShare Ecosystem Compromise

Forensic case study · 2025

Analysis of a custodial architecture failure, examining centralized key storage, on-chain incident reconstruction, and the limits of attribution.

Separate wallet keys were concentrated on a shared backend. Public evidence does not resolve external compromise versus insider action.

The report estimates approximately $20,000–$25,000 in incident-time economic cost and, separately, $150,000–$250,000 in long-term economic impact.

Read public record

Probabilistic Identity Infrastructure

Research synthesis · 2025

Research synthesis on behavioral identity inference and the risks of treating probabilistic classifications as authoritative decisions.

Read public record

The Semantics of Collapse: Lawful Instability in Agentic Systems

Working paper · 2025

Proposes lawful instability and Safe-to-Exist Analysis to examine systemic harm arising from permitted behavior in agentic systems. Explores conservation-based invariants through control theory, distributed systems, and algorithmic game theory.

Read public record · DOI

Papers & Issue Briefs

They Lie, and We Lie About the Lying

Policy analysis / research translation · January 2026

Examines the terminology, testing, and deployment of unreliable language systems, drawing on published research on truthfulness, training incentives, and self-correction.

Read public record · DOI

On the Inability of Language Models to Stub Their Toe

Position paper · January 2026

Explores linguistic fluency, embodied grounding, and the incentives shaping academic language and model training data.

Read public record · DOI

The Pre-Articulation Observability Boundary

Position paper · December 2025

Examines the limits of language-based systems when relevant human cognition has not yet been articulated.

Read public record · DOI

Structural Vulnerability Assessment: Proxy Signals & Lawful Authority Extraction

Issue brief · December 2025

A generalized architectural assessment of authority decisions that depend on influenceable proxy signals.

Read public record · DOI

Tools in Practice

Community tools and software projects alongside the research portfolio.

Provably Fair Basketball

Coaching toolkit

Free, privacy-first coaching toolkit with fair tryout evaluation, season planning, and practice resources.

Read public record · Use the live tool

Lucky Pick Axe · Critters Quest

Community Mac app

Independent community Mac app for Critters Quest Lucky Pick, with round monitoring, simulated bids, and a separate local wallet signer.

Read public record

Auditr SDK

TypeScript SDK

TypeScript SDK for the Auditr x402 API, with typed audit results, monitoring, and payment integration.

Read public record

Research & Collaboration

Open to collaboration with researchers, institutions, and teams building systems where this work can inform design, evaluation, and risk decisions.

Get in touch · Full research portfolio · ORCID