Funkornaut

Independent smart contract security researcher. Specializing in Solidity, Noir, and Vyper, with a focus on DeFi, L2 infrastructure, and zk/privacy protocols. Previously spun up and led the AI Security department at Wonderland. Available for private audit engagements.

Funkornaut avatar: a red panda in a FUNKO visor on a links golf course at sunset

Professional Engagements

Wonderland — Solidity Developer → Security Researcher → AI Security Department Lead (Sept 2024 – July 2026). 13 audit engagements between May 2025 and April 2026.

13 engagements 5 High 6 Medium 20 Low

Findings are engagement totals for the review team. Client reports are not public.

Date Engagement H M L Ins Info
2025-05-05 EBO 2.5 1 2 5
2025-09-18 Optimism Fee Splitter 2 3
2025-09-30 Canon Guard 4 1 9
2025-10-20 Aztec Token Standard + 4626 2 1 2 3 11
2025-12-09 Aztec Escrow 1 1 7
2025-12-29 GEO 2 2 4 15
2026-01-15 Optimism OPCM V2 7 8
2026-01-30 Geo Token 5
2026-02-16 Optimism Staking 12
2026-03-04 Aztec BridgeFPC 1 4
2026-03-06 Aztec Token Separation 1 1 3 2
2026-03-18 Optimism L2CM 2 1 20
2026-04-06 0xBow Privacy Pools v2 2 3 7 11
  13 engagements 5 6 20 30 107

yAudit Fellowship — Published Reports

Selected for Block 7 of the yAudit fellowship (Summer 2025), a competitive audit program pairing fellows with senior researchers on live engagements. Both reviews below are public.

Protocol Scope Findings Report
Yield Basis DAO contracts — voting escrow, gauge controller, liquidity gauge, vesting (Vyper) 1 Critical
2 High
4 Medium
4 Low
Report →
Centrifuge V3 Vaults, spoke contracts, async request manager — multichain RWA tokenization (Solidity) 1 High
1 Medium
2 Low
Report →

Competitive Audits & Bug Bounties

4 High 16 Medium 4 Low

Across Sherlock, CodeHawks, Code4rena, Cantina, and Immunefi (2023 – present). One of three findings on the CodeHawks DSC audit selected for the final report.

Camillo

Camillo is my AI powered smart-contract security audit suite — a set of Claude Code plugins that run a structured audit pipeline: scoping, recon, static and invariant analysis, domain-specific review, and PoC building, with dedicated EVM and Aztec/Noir coverage.

The runner wraps it as a service. Point it at a public GitHub repo, set a scope, and it returns a Markdown audit report, with per-stage progress as it runs.

Building toward continuous offensive security — re-scanning deployed code against a growing library of exploit root-cause patterns, rather than one-off point-in-time audits.

Capture the Flag

Authored challenges for and helped run Wonderland's public CTF events — writing challenge contracts, operating the competition on the day, and publishing the solutions afterward.

Contact

funkornaut@gmail.com x.com/funkornaut github.com/Funkornaut