Open for audits · contests · associate SR roles

Kalyan TR finds the bug that ships past the first pass.

Smart contract security researcher. Five years in regulated-domain QA at JP Morgan and Franklin Templeton, now full-time on EVM, Solana, Stellar, and cross-chain protocols. Competing on Immunefi, Sherlock, HackenProof, Code4rena, and Cantina.

2 Immunefi Highs confirmed
payout by 30 Sep 2026
1C · 4H · 6M + 10 Low
across live programs
5+ Years regulated QA
JP Morgan · Templeton
3 Chains in scope
EVM · Solana · Stellar

01 — Proof

Validated findings

Every row is confirmed by a platform or protocol team. Duplicate means independently found the same bug as the lead reporter — credit shared, bug real.

Protocol Platform Findings Status
Quantus
Post-quantum L1 · Substrate / Rust
Immunefi 1 High Confirmed · payout by 30 Sep Private until paid
Firelight
On-chain cover · ERC-4626 vault
Immunefi 1 High Confirmed · payout by 30 Sep Private until paid
Fluid DEX V2
DEX · first paid contest finding
Sherlock 1 Medium Report →
Hyperbridge
ISMP / cross-chain coprocessor
HackenProof 1 High Dup Valid · shared credit Report →
Solv BTC+
BTC yield / restaking
HackenProof 1 Critical Dup Valid · shared credit Report →
0xMarkets
On-chain markets
HackenProof 1 High 4 Medium Validated
Limit Break AMM
AMM · collaborative audit
GuardianAudits 1 Medium Validated Report →
Jupiter Lend
Solana lending
Code4rena 2 Low Validated Report →
Monetrix
Synthetic / vault
Code4rena 2 Low Validated Report →
K2
Contest findings
Code4rena 4 Low Validated
XRP Ledger
XRPL amendments
Sherlock 1 Low Validated
Battle Chains
Incentivized testnet / safe harbor
CodeHawks 1 Low Validated

Duplicate (Valid) — independently identified the same vulnerability as the lead reporter. Credit is shared.

02 — How I work

Falsification first.
PoC before submit.

  1. Falsification-first

    Kill weak hypotheses before investing in a PoC. Most “bugs” die here. The ones that survive get a test.

  2. Test-before-submit

    Every finding ships with a Foundry or Anchor PoC. No speculative reports. No vibes.

  3. Devil’s filter

    Who benefits. What is the concrete trigger. What is the honest-user harm. If that triangle doesn’t close, it isn’t a finding.

  4. Cross-check

    AI is a suggestion layer. Spec and code are the source of truth. I verify both before I write the report.

  5. Fuzz and invariants

    Foundry fuzz and invariant suites to hit the paths unit tests miss, and to prove the protocol still holds under arbitrary input.

03 — Stack

Where I can go deep

Languages

Solidity · Rust (Anchor / Solana) · Soroban / Stellar

Tooling

Foundry (unit, fuzz, invariant) · Slither · Anchor test harnesses

Ecosystems

EVM · Solana · Stellar

Cross-chain

LayerZero · ISMP / Hyperbridge

04 — Built to audit

Education, programs, projects

Rektoff Launchpad × Solana Foundation

Rust Security Bootcamp — Grade A, 216 pts

Capstone: MetaLend audit. 15 findings across admin auth, oracle validation, liquidation math, and flash-loan vectors.

Blok Capital Builder Cohort #1

ERC-2535 Diamond + ERC-4337

Mentored by Nick Mudge. Built ModularGarden, a diamond + account-abstraction wallet framework.

In progress

M.S. Computer Science

Formalizing the systems background that already shows up in invariant work and cross-chain reviews.

Prior career

QA, regulated finance — 5+ years

JP Morgan and Franklin Templeton. Order flow, settlement, accounting consistency. The same instincts apply to vaults and AMMs.

05 — Available

If you are running a contest, shipping a protocol, or hiring an associate researcher — write.

Open to audit collaborations, solo engagements, and junior / associate security researcher roles. Fast to start. Reports come with PoCs.