Smart Contract Security Researcher | Solidity 📂 Audit Portfolio ➡️ github.com/0xKemah/audits

Remote
Pinned Tweet
Thanks to @cantinaxyz and @SuccinctLabs for the opportunity to earn my first 3-figure win in web3 security. I missed quite a number of bugs, but I also had the opportunity to learn from other top researchers. I am excited to keep improving and contribute more to make web3 safer!
8
1
97
3,585
Kemah retweeted
A new audit contest is coming to Sherlock! @tare_io is an onchain loan exchange for regulated, institutional credit originators and investors. Tare's Loan Management System manages the end-to-end loan lifecycle with asset-level NFTs, native double-entry accounting, programmatic settlement, and ERC-7540 vaults priced with transparency. Full protocol in scope, written in Solidity. $50K in fixed rewards. July 20-29. Let's go!
6
8
117
8,301
Kemah retweeted
I’ve tried learning Rust many times and got derailed for one reason or another. When I started @RareCodeAI, I finally stuck with it. The focused learning path made the pieces click, and before long I was writing utilities on my own. It’s a great launching pad for anyone looking to get productive with Rust. Thanks @Jeyffre 🙌
2
6
18
1,869
Happy New Week Security Researchers! Looking forward to another productive week as I enter the final phase of the Fluid Dex audit contest on @sherlockdefi. What are you working on this week?
1
102
I have spent the past week on the Fluid DEX V2 contest on @sherlockdefi, gaining a solid grasp of the protocol. It has also been a great opportunity to refresh my understanding of Uniswap v3 math and core concepts. I am looking forward to digging deeper and exploring more edge cases in the remaining days of the contest 💪
3
104
Happy New Month Security Researchers! Looking forward to a very productive February 💪
83
This week, I have been reviewing the findings I missed in my previous audit contests. I have gained fresh insights learning new edge cases. I have now joined the Fluid DEX V2 audit contest on @sherlockdefi. It’s a much larger codebase than my recent contests, however I am looking forward to going deeper, applying these new insights, and hopefully uncovering some interesting bugs 💪
1
5
133
Here is another quick bug tip I learnt: If storage slots are manually composed instead of hashed, always assume storage collisions are possible until proven otherwise.
3
89
A few more lessons from reviewing my missed findings in previous audit contests : The sequence number returned by a Pyth entropy provider is only unique per provider address. This means two different providers can legitimately share the same sequence number at the same time. Therefore if you track or validate requests using only the sequence number, it can be manipulated by an attacker. The fix is simple but critical: pair the sequence number with the provider address. TL;DR: If you key async requests by an external ID, always key them by the ID plus the source that generated it. Great work by @0xhgrano who uncovered this bug 🫡
1
5
192
Reviewing missed findings has been just as valuable as finding bugs. Here are a few insights I have picked up : 1. If a protocol enters a terminal state (such as emergency mode), no code path should be able to update states that rely on future settlement. 2. If a governance update depends on a user controlled state(such as pending deposits), then users can invariably control governance. I will continue to share more as I uncover them.
1
6
432
Happy New Week Security Researchers! I am taking a pause from audit contests this week to review and deeply study the findings I missed in my recent contests. Sharpening the blade for the next round! What are you working on this week?
1
78
This week I participated in the @OpenCover contest on @sherlockdefi. After invalidating all my earlier leads, I ended up with no valid highs or mediums to submit. It was still a solid experience and I am looking forward to the final report to learn from any missed findings.
2
100
Good security architecture is not about adding guards everywhere but removing the need for the guards in the first place, as much as possible 🫡
1
4
98
In my short time in web3 security, I have realized that depth of understanding beats speed. Investing time to gain thorough understanding of solidity fundamentals, ERC20, ERC721, ERC4626, Upgradeability, Access Control, Math Errors etc. will get you ahead faster than rushing through audits.
1
93
Becoming a top security researcher is hard but not impossible. It can feel overwhelming starting from zero, but consistency matters more than how you feel on any given day. Keep showing up, and your efforts will compound to get you there.
2
6
210
I’ve been a developer for 10 years. I’ve mastered languages. I’ve optimized databases. I’ve built systems that handle millions of requests. But last week, a Junior dev outperformed me. He didn’t know how to write a complex program. He couldn’t explain the difference between a proper monoloth and a microservice. He didn't even know how the code worked in some parts. But he knew how to talk to the Agents. He orchestrated three AI workers. One for the frontend. One for the backend logic. One for the unit tests. In 4 hours, he pushed a feature that would have taken me 3 days. I felt a cold shiver. "Is this it?" I thought. "Am I finally the legacy hardware?" But then I looked at his PR. It was fast. It was functional. But it was… fragile. It lacked architectural vision. It had security holes that only someone who has been "burned" would see. It was a house built on sand. That’s when I realized the truth about 2026. The "Senior" title isn't about how fast you type anymore. It's about how well you judge. We are moving from being "builders" to being "architects." From "coders" to "composers." If you’re a veteran feeling left behind by AI: Don’t compete on speed. Compete on wisdom. The machine can write the notes. Only you can write the symphony.
476
638
5,595
377,729
Solana developers, this one's for you 🚀 Introducing: The Solana Development Course on Updraft Build real programs—Oracles, AMMs, Auctions—in both Anchor AND native Rust. Completely free. Here's everything you need to know 👇
52
75
542
36,342
Gm Security Researchers! It is a new week and another opportunity to find that bug, break that protocol and help make web3 safer! What are you working on this week?
3
1
99
Gm SRs, another day to find bugs and contribute towards the security of web3 projects. Still on the @flyingtulip_ contest, I have gained a good understanding of the codebase so far and am looking to dive deeper to explore some edge cases.
3
2
112
Kemah retweeted
A new report out from OX Security found that 900,000 users have had ChatGPT and DeepSeek conversations stolen by Chrome extensions. That means full chat logs exfiltrated every 30 minutes. Hackers want your AI history. Why? Because you've probably pasted in code, strategy, legal questions, personal information, health info, or other material that could be used for blackmail or extortion. A few takeaways: 1. Don't sign up for LLMs with your personal information if possible. 2. Don't input personal information into the LLM itself. 3. Be extremely careful with browser extensions. We already know that from wallet hacks.
8
5
72
5,100
I joined the @flyingtulip_ audit contest on @sherlockdefi and I look forward to contribute towards making the code base safer. Also taking some lessons from the @0xSimao mentorship series. It is packed with great insights.
84