Independent smart contract security researcher. Specializing in Solidity, Noir, and Vyper, with a focus on DeFi, L2 infrastructure, and zk/privacy protocols. Previously spun up and led the AI Security department at Wonderland. Available for private audit engagements.
Wonderland — Solidity Developer → Security Researcher → AI Security Department Lead (Sept 2024 – July 2026). 13 audit engagements between May 2025 and April 2026.
Findings are engagement totals for the review team. Client reports are not public.
| Date | Engagement | H | M | L | Ins | Info |
|---|---|---|---|---|---|---|
| 2025-05-05 | EBO 2.5 | 1 | 2 | 5 | — | — |
| 2025-09-18 | Optimism Fee Splitter | — | — | — | 2 | 3 |
| 2025-09-30 | Canon Guard | — | — | 4 | 1 | 9 |
| 2025-10-20 | Aztec Token Standard + 4626 | 2 | 1 | 2 | 3 | 11 |
| 2025-12-09 | Aztec Escrow | — | — | 1 | 1 | 7 |
| 2025-12-29 | GEO | 2 | — | 2 | 4 | 15 |
| 2026-01-15 | Optimism OPCM V2 | — | — | — | 7 | 8 |
| 2026-01-30 | Geo Token | — | — | — | — | 5 |
| 2026-02-16 | Optimism Staking | — | — | — | — | 12 |
| 2026-03-04 | Aztec BridgeFPC | — | — | — | 1 | 4 |
| 2026-03-06 | Aztec Token Separation | — | 1 | 1 | 3 | 2 |
| 2026-03-18 | Optimism L2CM | — | — | 2 | 1 | 20 |
| 2026-04-06 | 0xBow Privacy Pools v2 | — | 2 | 3 | 7 | 11 |
| 13 engagements | 5 | 6 | 20 | 30 | 107 |
Selected for Block 7 of the yAudit fellowship (Summer 2025), a competitive audit program pairing fellows with senior researchers on live engagements. Both reviews below are public.
| Protocol | Scope | Findings | Report |
|---|---|---|---|
| Yield Basis | DAO contracts — voting escrow, gauge controller, liquidity gauge, vesting (Vyper) | 1 Critical 2 High 4 Medium 4 Low |
Report → |
| Centrifuge V3 | Vaults, spoke contracts, async request manager — multichain RWA tokenization (Solidity) | 1 High 1 Medium 2 Low |
Report → |
Across Sherlock, CodeHawks, Code4rena, Cantina, and Immunefi (2023 – present). One of three findings on the CodeHawks DSC audit selected for the final report.
Camillo is my AI powered smart-contract security audit suite — a set of Claude Code plugins that run a structured audit pipeline: scoping, recon, static and invariant analysis, domain-specific review, and PoC building, with dedicated EVM and Aztec/Noir coverage.
The runner wraps it as a service. Point it at a public GitHub repo, set a scope, and it returns a Markdown audit report, with per-stage progress as it runs.
Building toward continuous offensive security — re-scanning deployed code against a growing library of exploit root-cause patterns, rather than one-off point-in-time audits.
Authored challenges for and helped run Wonderland's public CTF events — writing challenge contracts, operating the competition on the day, and publishing the solutions afterward.