Q3 2026 availability limited review slots remote · global replies < 24h

Protocol-breaking bugs, found before mainnet.

move-first security researcher sui aptos movement prediction markets complex defi

I’m Panther. I review Move systems on Sui, Aptos, and Movement — including prediction markets — plus complex DeFi, backed by production work across Rust/Solana, EVM, Cairo, and Go for protocol teams and ten audit firms.

Need firm-side reviewer capacity?
verified_finding.trace 1 H confirmed

Aave Aptos: one address mismatch, protocol-wide configuration failure

  1. 01 / write move_to(@aave_data, Data) configuration resource stored
  2. 02 / read borrow_global<Data>(@aave_pool) getters point to a different address
  3. 03 / impact ERESOURCE_DNE core configuration reads abort
Storage-flow tracing plus a minimal PoC exposed a confirmed High in Aave's first non-EVM deployment. verify the public finding ↗ Cantina profile ↗
#01 the_record

Code reviewed at the protocols other protocols depend on.

// ten of the twenty-four · section 03 has the full record, severity counts, links

  • Aave
  • Lido
  • Optimism
  • OpenZeppelin
  • Polygon
  • ZKsync
  • Balancer v3
  • Sui Framework
  • DeepBook
  • Starknet
  1. 01 / disclosure CVE-2024-45304

    A published advisory in OpenZeppelin's Cairo library

    A stale pending owner survived renounce_ownership and could still claim a contract its users believed was ownerless. OpenZeppelin fixed the state cleanup in v0.16.0.

    security advisory ↗
  2. 02 / competition 24,293GHO

    Third place on Aave's first non-EVM deployment

    One accepted High and one accepted Medium on the Aptos Move port — configuration written to one address, read from another, aborting every core getter.

    leaderboard ↗
  3. 03 / formal methods 6/6functions

    An immutability invariant proved on a Sui Move lender

    Modelled and machine-checked with Certora's Sui Prover: an obligation's eMode assignment cannot change mid-position, verified across every target function plus sanity checks.

    verification notes →
#02 selected_findings

Three claims. Three evidence trails.

// public proof where disclosure allows; precise role labels everywhere

02
Cairoindependent disclosureCVE

OpenZeppelin Cairo — the pending owner that survived renunciation

Context
Review of OpenZeppelin's Cairo OwnableTwoStep state lifecycle.
Panther's role
Independent researcher; privately disclosed the issue to OpenZeppelin.
Risk & outcome
A stale pending owner could accept ownership after renunciation, restoring admin control to a contract users believed was ownerless. OpenZeppelin fixed the state cleanup in v0.16.0.
Evidence
Published as CVE-2024-45304 / GHSA-w2px-25pm-2cf9.
03
Sui Movefirm-sideNDA-safe

Sui lending — proving an eMode assignment cannot change mid-position

Context
A real Sui Move lending engagement delivered firm-side through Sherlock; sensitive protocol details remain private.
Panther's role
Security reviewer and formal-verification contributor using Certora's Sui Prover.
Risk & outcome
If an obligation could switch eMode groups, collateral and borrowing rules could cross risk tiers. The modeled immutability invariant passed across six target functions plus sanity checks.
Evidence
The report remains private; the property, methodology, limits, and verification result are documented publicly.
#03 language_register

The names on the wall are the argument.

Grouped by language, ordered by weight of record. Bar length is portfolio-record count — not self-assessed skill. Every named codebase links to its entry on the public work record; nothing here is an endorsement.

24 of 76 records shown · the rest include private firm-side engagements under NDA open the full work record →

#04 engagement_lanes

One specialty. Two ways to engage it.

// one specialty, adapted to protocol teams and audit firms

01for protocol teams

Direct protocol security review

Focused and comprehensive reviews for Move on Sui, Aptos and Movement, Solana Rust, and complex EVM DeFi, from threat model through remediation review.

  • Move-specific ownership, capability, object, resource, and PTB analysis
  • Accounting, solvency, oracle, liquidation, and cross-chain invariants
  • Prediction-market state machines: pricing, signed oracles, settlement, NAV, LP queues, and PTB composition
  • Report-ready findings with exploit paths and actionable mitigations
scope a protocol review
02for audit firms

Firm-side reviewer capacity

Dependable reviewer depth for private engagements, second passes, unfamiliar codebases, and deadlines that need another senior set of eyes.

  • NDA-ready, fast ramp-up, and compatible with established firm workflows
  • Independent attack-path review and clean, reviewer-ready submissions
  • Move-native depth backed by multi-ecosystem production experience
book reviewer capacity

Specialist add-ons

  • Bounty triage & validationseverity analysis, PoC reproduction, reviewer handoff
  • Formal verification supportinvariant design, Certora CVL, Sui and Move prover workflows
#05 review_protocol

I follow state, authority, and value—not just functions.

// state transitions over checklist scanning; evidence over intuition

  1. 01
    invariant model

    Model the promise

    Turn documentation, trust boundaries, privileged roles, and protocol economics into explicit properties the system must preserve.

  2. 02
    authority + asset flow

    Trace the whole system

    Follow capabilities, value, oracle data, and cross-module state through the real execution paths—including composed transactions.

  3. 03
    break + prove

    Challenge, reproduce, close

    Break the model at its boundaries, reduce material issues to reviewable evidence, then verify the fix against the original invariant.

#06 delivered_through

Ten firms have put my name on their reports.

Counts are entries on the public work record. A further 34 engagements sit in the NDA-safe private ledger, with client names shown only where disclosure permits.

Pashov Audit Group 14 public
Zenith 8 public
Adevar Labs 6 public
Sherlock 4 public
Cantina 3 public
Three Sigma 3 public
Zellic 2 public
Cyfrin 1 public
Accretion 1 public
BurraSec NDA ledger
“The auditor bonus goes to @theblackpantherhere for this one! Great performance by all others as well, thank you!”
Pashov / Founder, Pashov Audit Group repeat firm-side reviews
“Just wanted to drop a positive feedback, I really like both your skills and dedication. It's great working with you ser.”
Nic / Security Audit Lead, Three Sigma firm-side review work
“I wanted to thank you for your insanely good work throughout the engagement, you submitted a lot of findings, and each one was of high quality. I would recommend you eyes closed.”
Salah Ismail / Security Researcher, Adevar Labs firm-side engagement
#07 field_notes

Recent technical writing

// the reasoning behind the review—not a generic vulnerability checklist

#08 engagement_faq

Before you send the scope

What scopes are the strongest fit?

Move systems on Sui, Aptos, or Movement, and complex DeFi—especially lending, perps, DEX/CLOB, vault, staking, RWA, oracle, and cross-chain logic. Solana Rust and EVM Solidity scopes are regular work too; other ecosystems are considered when the protocol mechanics match the review depth.

How are timeline and pricing determined?

Per scope and complexity. Focused reviews can fit inside a week; comprehensive reviews commonly run one to three weeks. Share a scope summary, estimated LoC, repository or documentation, and target dates for a concrete quote.

Can the engagement stay private?

Yes. Most firm-side work is under NDA. A mutual NDA can be established before private code access, and public disclosure happens only where the engagement permits it.

Can audit firms reserve reviewer capacity?

Yes. Use the firm-side intake route and include ecosystem, approximate scope, delivery window, expected role, and your internal reporting workflow.

#09 open_channel

accepting Q3 2026 scopes

Give the protocol an adversarial review before users do.

Send the ecosystem, scope or estimated LoC, repository/docs, target dates, and the outcome you need. Start with a public link or scope summary; private repository access can move to an NDA-backed channel.

// official identity: Panther / 0xTheBlackPanther · @thepantherplus ↗ · Telegram ↗