Solo security researcher. I run Kairos Lab Security Research β Web3 smart contract audits, Web2 bug bounty, and the tooling that makes both faster.
I build the infrastructure I wish the ecosystem already had, then keep it running.
Focus β economic and cross-contract invariants Β· Uniswap v4 hooks Β· bridges and proxies Β· modern-web exploitation chains (postMessage/XSS, broken access control, SSRF, business logic).
| Project | What it is | |
|---|---|---|
| β | AsterScan | Community block explorer for Aster Chain. Live, growing DAU, v2 chart engine. |
| π‘ | Kairos Recon | Dual-spectrum passive recon SaaS. Amber phosphor design system. |
| π | KairosAuth | Passwordless auth β WebAuthn + ZK proofs. Base Sepolia β Aster Chain. |
| π¬ | StatShield | Scientific integrity scanner. 8 analysis modules, GRIM/SPRITE/statcheck, image forensics. |
| π | Covenant | Declarative smart contract language with native FHE, ZK and post-quantum primitives. |
Web3
Solidity Foundry Slither Aderyn Mythril Halmos Echidna EVM internals
Web2
Burp Suite Nuclei Semgrep ffuf mitmproxy SQLMap OWASP / PTES / NIST
Build
TypeScript Python React Next.js Vite Godot WeasyPrint
- Cantina β Morpho Midnight audit competition. Findings documented, full report shipped.
- Intigriti β Capture Our Flag. ~200h on a hardened Duende IdentityServer + BFF + Angular stack. Deep architectural intelligence, one collateral High severity finding, and an honest map of every dead end.
- Ongoing: measuring exploit-confirmation rates per vulnerability class against EVMbench, because a methodology you haven't benchmarked is a story you tell yourself.
Audits, bug bounty engagements, or Aster ecosystem work β kairos-lab.org Β· @Valisthea
the blade is sharpened in private, tested in public.



