Independent Security Research

I break things carefully
and write down exactly how.

Smart contract review, EVM internals, application and infrastructure testing. Evidence over adjectives: fork repro, live-state probes, and honest severity calls.

0chains probed for one finding
0deposit events scanned
0receipts cross-checked

01 Selected research

Disclosures and reviews, published only after vendor coordination.

EVM · SettlementLow

Cross-chain settlement depository — credit by claimed amount

A permissionless deposit path credited the amount advertised in the token transfer event instead of the balance actually received. Fee-on-transfer or rebasing tokens silently break per-asset solvency accounting. Verified with a mainnet-fork reproduction; severity downgraded after scanning 2.04M historical deposits across 3 chains found no affected asset in use.

Fork repro · 3-chain historical scan · coordinated disclosure

Mobile · AndroidPipeline

APK red-team pipeline

Automated acquisition, decompilation and finding triage for Android targets: exported-component audits, file-provider traversal, WebView bridges, pinning and root/emulator attestation gaps — with a reproducible harness instead of one-off manual pokes.

Tooling · repeatable methodology

DependenciesAudit

Vendored open-source deployments

When a vendor ships an upstream OSS project unchanged, the interesting bugs live in the deployment layer: configuration drift, exposed admin surfaces, version pinning, and the gap between upstream hardening and what actually runs in production.

Source review · live verification

Web · AuthChain

Account-takeover chains

Password-reset poisoning, host-header trust, token prediction and MFA-flow gaps chained from a low-severity reflection into full session takeover — proven by reading data as the victim, not by a redirect alone.

PoC-driven · impact first

02 Tools

Runs entirely in your browser. Nothing is uploaded.

EVM calldata decoder

paste calldata — get selector + arguments

Selector generator

keccak256 of a signature, computed locally

03 Contact

Security reports, triage questions, and coordinated disclosure:

audit@0xasuma.dev

Please include reproduction steps and affected asset/version. Encrypted or signed replies welcome.