Web3 Security Researcher
@samueltroydomi on Sherlock & Code4rena
@fresh on CodeHawks
Portfolio: https://t.co/wzQcfdWff9
Github: https://t.co/TyUT7vKRLvgithub.com/samtdomiJoined February 2025
3 months of only private audits - every week, what an experience! I’ve found crits, highs, medium, lows, and hygienic issues - communicated with clients and worked on fixes. I am grateful for the opportunities and will keep pushing!!!!!!!!!!! What a field to be apart of!!!
Wow just finished an audit for a protocol with the most secure and well thought out codebase I have seen yet. It was frustrating from my perspective, but it was a sight to behold. In the end, I learned a lot!
Something I’ve seen twice now in private audits is a protocol that has 2 contracts that they rely on being in sync with each other (indexing, other accounting) - but they each have their own storage.
For external calls each contract has sufficient reentrancy protection for its…
Wooooh crit finding in a recent private audit.
What a feeling. This one was interesting because I prematurely convinced myself that there was something big to be found in the time I had left. I had no reason to believe that but I made myself believe it.
Sure enough, there…
I’ve been blessed with a great individual giving me opportunities to do private audits - next one starts soon. So I haven’t been able to do any contest.
But I have 2 days free, I’m going to see what I can produce in the ‘Morpheus’ audit on @code4rena during this time.
Goal is…
There’s no short cuts here. Consistency and discipline. Constant improvement. Honestly I’m understanding the compounding effect in action. In the moment and through the jungle I felt very little improvement. But now I look at where I started and I look at where I’m standing and…
As a web3 SR, you need A LOT of skill and understanding of MANY different types of complex concepts.
- Obviously syntax of the programming language and everything that comes with that.
BUT, you also need a high level of business logic understanding, understanding of incentive…
I can proudly say I have over 15+ findings from private audits.
Also, I do my best to ensure full coverage, even the minor issues that don’t present an immediate attack path I can think of in the time I’m given for the audit- but is clearly vulnerable logic that allows things…
Also very happy to say that the past month has been filed with only private audit work. I haven’t had time to participate an a contest, just private audits and bug bounty hunting on the side.
It’s been a complete change but I believe it came at a time where I was prepared for…
You know what is an interesting day?
Having a few complex multi layered attack paths you need to prove but are confident in.
A FULL day of writing tests, running them
Debug the output, fix a piece of the test, get closer, run it again…. ALL DAY.
It’s like the day isn’t…
In fighting there’s this saying “a fighter IMMEDIATELY becomes 30% better the moment they become champion”
I believe that is true in life and also in this profession of SR and Auditing. When you have a great victory, you become immediately 30% better. If you let yourself. A lot…
Since starting on and now worked on multiple private audits - maybe it’s just this small sample size but wow - what a difference in codebase from a protocol getting an initial or 2nd audit (most of my private audits have been this case)
Vs. an audit contest where the protocol…
I used to be hesitant to work on protocols that don’t use solidity - but I’ve been working on a protocol on Starknet (using Cairo) - and I was able to grasp it , break it down, and begin breaking it and looking for bugs.
I like Cairo, I like auditing / working with it
I never felt my brain operating at such a high capacity outside of bug hunting. You see a vulnerability in principle and your mind STARTS MOVING! So many scenarios, so many ideas, so many possibilities- the creativity of bug hunters is on another level. Really high level mental…
377 Followers 1K FollowingI tweet about web3 tech, products and security
Web3 and DeFi since 2016
Founder at FipeFinance
Top auditor at @stronghold_dao
22K Followers 121 FollowingMaster math 4x more efficiently than a traditional classroom. Individualized, adaptive, AI-powered and fully automated.
Accredited courses 4th grade-University.
14K Followers 107 FollowingThe leveraged lending marketplace for accelerated yield on @hyperliquidX. Mint synthetic dollar $USDXL, powered by @lastdotnet.
377 Followers 1K FollowingI tweet about web3 tech, products and security
Web3 and DeFi since 2016
Founder at FipeFinance
Top auditor at @stronghold_dao
153 Followers 260 FollowingBuilding @Procur3 - Smart contract security marketplace.
Planning an audit? Reach 30+ audit firms and get quotes in hours - not weeks
761 Followers 21 FollowingOnboarding the next generation of world-class security researchers through specialized onsite bootcamps offering them valuable hands-on experience in web3sec.
156K Followers 2K FollowingCrypto Analyst. Sharing DeFi updates and crypto strategies. Subscribe to my blog to stay on top of trends: https://t.co/qrKYXe3Uxo
1K Followers 579 FollowingBlockchain Security Researcher @NethermindEth | Lead-judge @codehawks | Auditor at @PashovAuditGrp | Working on 5G x Blockchain
712 Followers 92 FollowingSolo auditors, made mainstream.
Commission-free, vetted network of top SRs.
Browse, filter, connect — or ask us to matchmake.
👇👇👇
4K Followers 218 FollowingWeb3/Web2 Security & Building Company. Trusted by Dinero, Multipli, Etherspot, Ambire, Colb, Pear, Hana and more. Book an audit: https://t.co/Jf6SO3wlMP
8K Followers 2K FollowingIndependent Smart Contract Researcher & Researcher at @ShieldifySec
My mission is to find vulnerabilities in smart contracts for a safer Web3 Space!