J4X

J4X

@J4X98

100

Spearbit

lsr

Public earnings

$161,539.70

12th


Public findings

103


Achievements


Worked with

Polystream
Ondo Finance
Berachain
Drips
n4nika
deadrosesxyz
Sujith S
Mario Poneder
xiaoming90
0xicingdeath

Biography

Auditor Profile

About

I am a smart contract security researcher with a strong focus on Solana / SVM Rust, Cairo / Starknet, and complex DeFi protocol security.

My core expertise is reviewing systems where correctness depends on protocol-specific logic rather than standard contract patterns. I have extensive experience with Solana programs, Rust-based blockchain code, Cairo/Starknet systems, AMMs, vaults, staking and rewards logic, governance systems, bridges, orderbooks, launchpads, smart wallets, and other DeFi protocols with non-trivial accounting and state transitions.

I have 5+ years of smart contract security experience, after studying Information Security / Cybersecurity and working as a penetration tester. In private audits, I have completed 38 Solana / Rust engagements totaling 197.5 audit days, including repeated work on Meteora, Jupiter, GMX Solana, Paladin, Ondo, Orderly, 1inch Solana, Ergonia, Dripster, Blendy, Token Mill, Bridge, Autonomous Finance, and other SVM / Rust protocols.

I am also highly experienced in Cairo / Starknet security, with 6 private Cairo audits totaling 67 audit days, including Ekubo, Vesu, Forge, Starknet Foundation Alexandria, and Starkware Cairo. My Cairo work includes AMM logic, Cairo libraries, Starknet protocol code, storage and serialization behavior, math-heavy code, and invariant-driven protocol review.

Across public contests, I have won six security contests, achieved four top-three placements, and placed top-10 four additional times. My Rust and non-EVM record includes 1st in Grass for Rust / Solana, 6th in Tensor for Rust / Solana, 7th in Solayer, 1st in Centrifuge for Rust / Substrate, 1st in HydraDx for Rust / Substrate, and 3rd in Andromeda for Rust / Cosmos.

I currently work as a Security Researcher with Spearbit, Zenith, and Blackthorn, and I also compete in contests on Code4rena, Cantina, and other audit platforms.

Core Expertise

Solana / SVM Rust

Solana / Rust is one of my strongest areas. I have reviewed a large number of production Solana protocols across AMMs, smart wallets, launchpads, vaults, bridges, staking systems, governance systems, payments, and token/accounting logic.

My Solana review work focuses on account validation, authority and signer checks, PDA derivation, initialization and reinitialization safety, CPI assumptions, token-account validation, protocol accounting, arithmetic precision, invariant preservation, and edge cases around user-controlled accounts and program state.

Representative Solana / Rust work includes Meteora, Jupiter, GMX Solana, Paladin, Ondo, Orderly, 1inch Solana, Ergonia, Dripster, Ego, Token Mill, Blendy, Bridge, Autonomous Finance, and multiple Accretion engagements.

Cairo / Starknet

I have strong Cairo / Starknet experience from both protocol and library audits. I have reviewed Cairo AMMs, Starknet protocol code, Cairo libraries, math-heavy components, storage and serialization behavior, and state-transition logic where small implementation errors can lead to broken accounting or invalid system states.

Representative Cairo / Starknet work includes Ekubo, Vesu, Forge, Starknet Foundation Alexandria, and Starkware Cairo.

DeFi Protocol Security

I have broad DeFi audit experience across AMMs, concentrated liquidity, bonding curves, orderbooks, vaults, staking, rewards, governance, lending, cross-chain systems, payment flows, and token standards.

My strongest reviews are usually on systems where the important bugs are not isolated to one function, but emerge from the interaction between accounting rules, user flows, state transitions, access control, and economic assumptions.

Rust-Based Blockchain Systems

Beyond Solana and Cairo, I have strong experience with Rust-based blockchain systems, including Rust / Substrate, Rust / Cosmos, and Rust backend protocol components. My public contest record includes first-place Rust/Substrate results and a top-three Rust/Cosmos result.

Solidity / EVM

Solidity / EVM remains a strong secondary area. I have audited and competed across ERC standards, lending, governance, staking, proxies, Gnosis Safe integrations, cross-chain protocols, and DeFi systems. My main edge in EVM work is on complex protocol logic rather than generic token or admin patterns.

Selected Experience Highlights

Solana / Rust Private Audits

38 private Solana / Rust audits, 197.5 audit days.

Representative work:

  • Meteora: 17 engagements across AMM, CP-AMM, bonding curve, fee sharing, zap program, and related Solana/Rust components.
  • Jupiter: 4 engagements across smart wallet and Solana/Rust protocol logic.
  • GMX Solana: 18-day Solana/Rust AMM audit.
  • Paladin: 18-day Solana/Rust staking / governance / rewards audit.
  • Ondo: 10-day Solana/Rust audit.
  • Orderly: Solana/Rust bridge audit.
  • 1inch Solana: Solana/Rust orderbook AMM audit.
  • Dripster, Ego, Token Mill: Solana/Rust launchpad audits.
  • Blendy, Autonomous Finance: Solana/Rust vault audits.
  • Ergonia: Solana/Rust AMM audit and vCISO/consulting engagement.
  • Bridge: Solana/Rust payment audit.
  • 4real: Solana/Rust staking audit.
  • Accretion engagements: Multiple Solana/Rust private audits across late 2025 and early 2026.

Cairo / Starknet Private Audits

6 private Cairo audits, 67 audit days.

Representative work:

  • Ekubo: 20-day Cairo AMM audit.
  • Vesu: 20 total Cairo audit days across two engagements.
  • Forge: Cairo audit.
  • Starknet Foundation Alexandria: Cairo bytes library audit.
  • Starkware Industries: 18-day Cairo language / Starkware codebase audit.

Selected Rust and Non-EVM Contest Results

  • Centrifuge: 1st / 231, Rust / Substrate.
  • HydraDx: 1st / 27, Rust / Substrate.
  • Grass: 1st / 197, Rust / Solana.
  • Tensor: 6th / 256, Rust / Solana.
  • Solayer: 7th / 306, Solana.
  • Andromeda: 3rd / 122, Rust / Cosmos.
  • Metrom: 1st, Rust / Backend.

Ecosystems and Languages

AreaLevelExperience
Solana / SVM RustExpert38 private audits, 197.5 audit days, multiple contest placements, and repeated production work across AMMs, smart wallets, launchpads, bridges, vaults, staking, governance, payments, and token/accounting systems.
Cairo / StarknetExpert6 private Cairo audits, 67 audit days, including AMMs, Cairo libraries, Starknet protocol code, math-heavy logic, storage behavior, serialization, and state-transition review.
Rust blockchain systemsExpertExperience across Solana / Rust, Rust / Substrate, Rust / Cosmos, Rust backend systems, and multiple high-ranking Rust contest results.
Solidity / EVMAdvancedPrivate audits and contest results across ERC standards, lending, governance, staking, proxies, Gnosis Safe integrations, cross-chain systems, and DeFi protocol logic.
Node / Go blockchain systemsExperiencedReviewed Berachain BeaconKit work involving blockchain node/protocol components.
Security backgroundStrongAcademic cybersecurity background, prior penetration-testing experience, and 3+ years of smart contract security work.

Protocol and Security Experience

AreaExperience
AMMs / DEXes / liquidity systemsExtensive experience across Meteora, GMX Solana, Ekubo, Ergonia, 1inch Solana, HydraDx, Morpho, Opal, Balancer-style systems, custom AMMs, bonding curves, orderbooks, and concentrated-liquidity designs.
Solana account and authority securityExtensive experience reviewing signer validation, account ownership, PDA derivation, initialization safety, authority checks, token-account validation, CPI assumptions, and user-controlled account edge cases.
DeFi accounting and invariantsExtensive experience with vault accounting, share accounting, fee accounting, reward accounting, staking logic, liquidity accounting, token accounting, precision issues, rounding behavior, and invariant violations.
Cairo / Starknet protocol logicStrong experience with Cairo AMMs, Starknet protocol code, Cairo libraries, storage/state-transition review, serialization, and math-heavy logic.
Staking / governance / rewardsExperience across Paladin, 4real, Ethena, Salty.io, Redacted, ENS, governance systems, reward distribution, and admin/role logic.
Launchpads and token lifecycle systemsExperience across Dripster, Ego, Token Mill, and related Solana/Rust launchpad and token lifecycle flows.
Vaults and asset-management logicExperience across Blendy, Autonomous Finance, Polystream, and other vault/accounting systems.
Bridges and cross-chain systemsExperience with Orderly, Wormhole, Axelar, Threshold tBTC bridge, Zetachain, and custom cross-chain implementations.
Smart wallets and account systemsExperience with Jupiter smart wallet work, Gnosis Safe integrations, reNFT, Redacted, and account/authorization-heavy systems.
Lending and collateral systemsExperience with Morpho, Wildcat Finance, Opal, Balancer-related systems, and lending/accounting logic.
ERC standards and token integrationsExperience with ERC20, ERC721, ERC4626, ERC4337, token accounting, token permissions, and integration assumptions.
Proxy and upgradeability patternsExperience with Transparent proxies, UUPS proxies, Diamond patterns, upgrade risks, and admin-control boundaries.

Full Track Record

The following tables contain the full contest, private audit, consulting, judging, and work-experience record.

Top Contest Performances

PlatformContestLanguagePositionPayoutReport
CantinaCentrifugeRust / Substrate🥇/231$70,209.75Private
CantinaWormholeSolidity🥇/13RedactedPrivate
Hats FinanceMetromRust / Backend🥇/X$28,000.00Private
C4HydraDxRust / Substrate🥇/27$23,597.20Report
CantinaGrassRust / Solana🥇/197$6,355.65Private
CantinaDecentSolidity🥇/193$1,250.00Private
CantinaMorphoSolidity🥉/22$17,919.95Private
SherlockAndromedaRust / Cosmos🥉/122$12,998.29Report
CantinaYOLO GamesSolidity🥉/250$2,238.22Private
C4ENSSolidity🥉/54$1,840.73Report
CantinaOptimismSolidity5/227$4,326.86Report
CantinaRoninSolidity6/61$16,809.33Private
CantinaTensorRust / Solana6/256$9,529.84Private
C4CentrifugeSolidity6/84$1,663.90Report
CantinaOpalSolidity6/42$1,780.65Private
CantinaSolayerSolana7/306$2,074.80Private

Private Audits

DateDurationAgencyNameLanguageProtocol typeReport
04/20245 daysThesis DefenseAcreSolidityGnosis SafeReport
04/202412.5 daysThesis DefenseMezoSolidity*Report
05/20245 daysThesis DefenseStars ArenaSolidity*Private
07/20243.5 daysSpearbitDripsSolidityReward distributionReport
09/20245 daysSpearbitBerachainSolidityBalancer forkPrivate
10/20242 daysZenithJupiterSolana / RustSmart walletPrivate
10/20244 daysZenith4realSolana / RustStakingReport
10/20241.5 daysZenithJupiter #2Solana / RustSmart walletPrivate
11/202418 daysBlackthornGMXSolana / RustAMMReport
11/20241 daysZenithJupiter #3Solana / RustSmart walletPrivate
12/20243 daysSpearbitBlendySolana / RustVaultPrivate
12/20243 daysZenithAutonomous FinanceSolana / RustVaultPrivate
12/20245 daysSpearbitBlendy #2Solana / RustVaultPrivate
01/202520 daysPlainshiftEkuboCairoAMMPrivate
02/202518 daysZenithPaladinSolana / RustStaking / Governance / RewardsPrivate
03/20255 daysZenithDripsterSolana / RustLaunchpadReport
03/20255 daysZenithOrderlySolana / RustBridgePrivate
03/20252 daysZenith1InchSolana / RustOrderbook AMMReport
03/202510 daysZenithMeteoraSolana / RustBonding CurvePrivate
04/20256 daysZenithEgoSolana / RustLaunchpadReport
04/20251 daysZenithBridgeSolana / RustPaymentPrivate
04/20253 daysBail SecurityToken MillSolana / RustLaunchpadPrivate
04/20253 daysZenithMeteora #2Solana / RustBonding CurvePrivate
04/202512.5 daysSpearbitBerachainNode / GoBeaconkitPrivate
05/20250.5 daysZenithMeteora #3Solana / RustAMMPrivate
05/202510 daysZenithMeteora #4Solana / RustAMMReport
06/20258 daysSpearbitErgoniaSolana / RustAMMPrivate
07/202522 daysZenithMeteora #5Solana / RustAMMPrivate
08/20251 daysZenithMeteora #6Solana / RustAMMPrivate
08/202515 daysZenithVesuCairoNAPrivate
08/20255 daysZenithVesu #2CairoNAPrivate
09/20254 daysZenithForgeCairoNAPrivate
09/20250.5 daysZenithMeteora #7Solana / RustAMMPrivate
09/20250.5 daysZenithMeteora #8Solana / RustAMMPrivate
09/20253 daysZenithMeteora #9Solana / RustAMMPrivate
10/20252 daysZenithMeteora #10Solana / RustFee SharingPrivate
10/20255 daysZenithStarknet FoundationCairoAlexandria Bytes LibraryPrivate
10/202518 daysZenithStarkware IndustriesCairoCairoPrivate
11/20255 daysSpearbitPolystreamEVMVaultPrivate
11/20254 daysZenithMeteora #11Solana / RustZap programPrivate
11/202510 daysSpearbitOndoSolana / RustNAPrivate
12/20253.5 daysAccretionTessertSolana / RustNAReport
12/20251.5 daysAccretionNASolana / RustNAPrivate
01/202615 daysAccretionNASolana / RustNAPrivate
02/20267 daysZenithMeteora #12Solana / RustNAPrivate
02/20263 daysZenithMeteora #13Solana / RustNAPrivate
03/20260.5 daysZenithMeteora #14Solana / RustNAPrivate
03/20263 daysZenithMeteora #15Solana / RustNAPrivate
05/20262 daysZenithMeteora #16Solana / RustNAPrivate
05/20264 daysZenithJupiter #4Solana / RustNAPrivate
05/20266 daysZenithMeteora #17Solana / RustNAPrivate

vCISO/Consulting

DateAgencyNameLanguageProtocol type
10/2024SpearbitZetachainSolidityBlockchain
06/2025SpearbitErgoniaSolana / RustAMM

Judging

DatePlatformNameLanguageProtocol type
06/2024CantinaUsualSolidityNA
08/2024CantinaZetachainSolana / RustNA
01/2025CantinaInclusive FinanceSolana / RustNA
03/2025CantinaReserveSolana / RustNA

Top competitions

View all
Contest
Position
Date
Payout
Centrifuge

Centrifuge

1

/ 14

August 2024$70,210
metamorpho-and-periphery

metamorpho-and-periphery

2

/ 33

November 2023$12,357
tensor-monorepo

tensor-monorepo

6

/ 10

October 2024$9,030
grass

grass

1

/ 15

June 2024$6,356
safe-extensions

safe-extensions

5

/ 59

May 2024$4,327

Private reviews

View all
Engagement
Project title
Timeframe
Researchers
Ondo Finance

Ondo Finance

Ondo: GM Solana

Nov 2025 - Dec 2025

n4nika
J4X
Mario Poneder
Polystream

Polystream

Polystream Vault

Nov 2025 - Nov 2025

rvierdiiev
J4X
Berachain

Berachain

Bera Bex

Sep 2024 - Oct 2024

J4X
xiaoming90
0xicingdeath
Drips

Drips

drips-monorepo

Jul 2024 - Jul 2024

Sujith S
J4X
deadrosesxyz