Jay

Jay

Security Researcher w/ specialization in Formal Verification

@movejay
Spearbit

sr

Public earnings

$0


Public findings

0


Worked with

Eco Foundation
Sanctum
Coinbase
Sujith S
Rikard Hjort
0xicingdeath
Mustafa Hasan

Biography

Biography

Hey! J here! 👋🏾

I’m a security researcher with 5 years of experience in auditing and vulnerability research across EVM, SVM, and Move ecosystems.

I previously spent 3 years as a Solidity developer before transitioning fully into security, where I led the Security Department at Sixfoot as a Security Engineer.

I am also a founding contributor to the Sui Prover at Asymptotic, where I worked on formal verification tooling for Sui Move.

Today, I specialize in Move-based ecosystems, formal verification, and smart contract security. I’ve been actively triaging reports on Cantina for over a year, reviewing and validating real-world vulnerability submissions at scale.

Across my career, I’ve worked with protocols such as Aave, LayerZero, Coinbase, Flying Tulip, and Navi, among others. My audit experience spans cross-chain bridges, CLMMs, lending markets, staking systems, perpetuals, and DeFi infrastructure primitives, to name a few.

Solidity

Project NameTypeDescriptionReports
Coinbase SettlementRWA Token Sale Vesting Signatures Cross-chainSmart contract system for a regulated private investment platform. Investors fund deals with USDC and, after a raise completes, claim allocated tokens via Merkle proof and EIP-712 signature verification. Also handles carry fee withdrawals, time-based vesting, and cross-chain withdrawals.Coming Soon
Coinbase MultiproofL2/Rollup Dispute Game ZK Proofs TEE AttestationMultiproof dispute game system for Base (Optimism-based L2). AggregateVerifier.sol requires multiple independent proof types (TEE attestations and ZK proofs) to finalize L2 state proposals on L1, with bonded proposers, challenger disputes, a 7-day resolution delay, DEFENDER/CHALLENGER resolution, delayed WETH bond claims, and faulty-proof nullification.Coming Soon
SayferLendingDecentralized lending platform enabling users to supply assets to earn yield or borrow against holdings, with smart-contract risk management and collateralization mechanisms.View Report
FortephySecurity Tooling SimulationSmart contract auditing tool that deploys and simulates Solidity contracts to test for vulnerabilities and bugs; the audit focused on flaws and the tool's effectiveness.View Report
SturdyLending Yield Isolated PoolsLending protocol enabling interest-free borrowing using yield from deposited collateral, built around isolated lending pools with individual risk parameters.View Report
KelpStaking Liquid Restaking YieldLiquid restaking protocol letting users stake assets while keeping liquidity through derivative tokens usable across DeFi, combining staking rewards with broader composability.View Report
LayerZeroCross-chain/Bridge MessagingOmnichain interoperability protocol enabling blockchains to communicate and transfer data directly, supporting cross-chain token transfers, unified liquidity, and multi-chain DeFi.View Report
TopazLending YieldDeFi protocol for lending, borrowing, and yield generation; users supply assets to earn interest or use holdings as collateral to access liquidity.View Report
DragonSwapSwaps/DEX AMM Staking/FarmingAMM-based DEX enabling permissionless token swaps, liquidity provision, and yield generation, with staking, farming, and low-cost transactions.View Report
HyperCycleAI/Infrastructure Payments MarketplaceDecentralized network where AI agents interact, exchange services, and transact directly; infrastructure for an Internet of AI with machine-to-machine payments and scalable AI marketplaces.View Report
Flying TulipLending Soft Liquidations Yield OraclesSmart contract protocol on Sonic combining a cross-asset lending market with RFQ-style soft liquidations. Supports delta-neutral positions where idle assets deposit into external yield sources like Aave; pricing via Chainlink oracles and a kinked interest rate curve tuned per asset risk profile.Coming Soon
Flying Tulip V2Lending Soft Liquidations Yield OraclesSonic-based protocol combining cross-asset lending with optimized RFQ-style soft liquidations and delta-neutral positions deployable into Aave. Introduces refined debt flow mechanics and more efficient liquidation routing, with Chainlink oracle pricing and a kinked rate curve.Coming Soon
Flying Tulip V3Lending Soft Liquidations Vesting OraclesSonic-based protocol combining cross-asset lending with a refined liquidation engine and integrated vesting system. Supports delta-neutral positions deployable into Aave, with more precise liquidation mechanics, structured vesting flows, Chainlink oracle pricing, and a kinked rate curve.Coming Soon
Flying Tulip YieldClaimerOptions Yield Token Sale NFTCash-secured put option product by Flying Tulip. Users deposit collateral (e.g. USDC) during a public sale to buy put option NFTs; collateral is wrapped and deployed into yield strategies like Aave. Principal stays protected/redeemable while yield is harvested to the treasury. The YieldClaimer role deploys idle collateral, harvests, sweeps, and force-withdraws as needed.Coming Soon

Move

Project NameTypeDescriptionReports
Aave CoreLending Flash Loans LiquidationsFoundational lending layer of the Aave protocol handling supply, borrow, liquidations, flash loans, and interest rate logic, maintaining the protocol's liquidity pools and collateralization requirements.View Report
Aave Core v2Lending Flash Loans LiquidationsIteration of the Aave core lending layer (V3.1–V3.3) covering supply, borrow, liquidations, flash loans, and interest rate calculations.View Report
Aave PeripheralLending Rewards IntegrationsSupplementary modules extending Aave beyond core lending: reward distribution, UI data providers, debt swap adapters, and helper contracts that simplify user interactions and external integrations.View Report
AlphaLend Market LendingLending Interest-bearing Tokens Oracles Risk ManagementDecentralized lending and borrowing protocol on Sui where users supply assets into pooled liquidity markets to earn interest or borrow against collateral. Each market uses an interest-bearing xToken model with variable utilization-based rates, plus borrow limits, flow limiters, oracle price feeds, and spread/protocol fees ensuring safety and sustainability.Coming Soon
AlphaLend Position / PartnerLending Liquidations Account/Positions IntegrationsAccount layer tracking each user's cross-market portfolio of collateral, loans, and health status in USD, with continuous solvency evaluation and liquidation below threshold. The Partner system lets approved integrators create specialized positions with custom fee discounts and expanded collateral (e.g. Bluefin LP tokens) to build tailored DeFi products.Coming Soon
AlphaLend Rewards / StakingRewards Staking YieldIncentive layer distributing liquidity-mining rewards to depositors and borrowers by proportional share over scheduled windows, claimable directly or auto-compounded as collateral. Staking enables protocol-managed native SUI staking within the SUI market to earn validator yield for the pool.Coming Soon
EchoLending Yield GovernanceDeFi platform enabling users to lend, borrow, and earn yield on crypto assets. The audit focused specifically on the governance module, evaluating its smart contracts for vulnerabilities and proper functionality, with recommendations to strengthen governance processes and ensure secure, transparent decision-making.Coming Soon
KofiLendingDecentralized lending and borrowing platform letting users supply assets to earn interest or borrow against holdings, optimizing capital efficiency via flexible collateralization and automated interest accrual.View Report
PoelLendingDeFi lending and borrowing platform allowing users to deposit assets to earn yield or access liquidity using holdings as collateral, with smart-contract risk management and automated interest mechanisms.View Report
MatrixportRWA Lending Trading Asset ManagementCrypto financial platform for trading, lending, and asset management with support for real-world assets (RWA) such as digital gold. Users buy, sell, and earn yield on tokenized assets, access structured products, and participate in lending markets, bridging traditional and digital assets.Coming Soon
ZetachainCross-chain/Bridge Messaging InteroperabilityBlockchain interoperability protocol enabling seamless cross-chain communication and asset transfers between networks, supporting unified liquidity, token swaps, and multi-chain DeFi through secure, scalable cross-chain operations.Coming Soon
Studio MiraiNFT MarketplaceNFT project creating and distributing unique digital collectibles, enabling buying, selling, and trading of tokens with on-chain provenance and ownership in a secure marketplace.View Report
OL NetworkInfrastructure/L1 InteroperabilityBlockchain infrastructure platform supporting dApps and smart contracts with high scalability and low fees, focused on interoperability, performance, and developer-friendly tooling.View Report
Dexlyn BridgeCross-chain/Bridge InteroperabilityCross-chain bridge protocol enabling secure transfer of tokens and data between blockchain networks, maintaining security through cryptographic verification for fast, reliable cross-chain transactions.View Report
Project ZStakingSecurity audit of a staking-focused protocol.View Report
StakeSphereStakingSecurity audit of a stealth staking protocol.View Report
AquaSwapSwaps/DEX AMM LiquidityAMM-based decentralized exchange enabling permissionless token swaps and liquidity provision.View Report
ThalaLending YieldDeFi platform offering lending, borrowing, and yield optimization; users deposit assets to earn interest or use them as collateral, maximizing capital efficiency.View Report
NaviLending Staking YieldDeFi platform for managing assets, optimizing yield, and participating in liquidity markets via staking, lending, and borrowing with automation to improve capital efficiency.Coming Soon
LayerZero - AptosCross-chain/Bridge MessagingOmnichain interoperability protocol enabling Aptos applications to interact and transfer assets across chains through a verified messaging architecture.Coming Soon
LayerZero - SuiCross-chain/Bridge MessagingOmnichain interoperability protocol enabling Sui-based applications to communicate and transfer assets securely with other blockchains via messaging-based verification.Coming Soon
DecibelPerpetuals Orderbook Derivatives OraclesOn-chain perpetual futures protocol built around a central limit order book (CLOB). Traders open leveraged long/short positions on perpetual swap markets with orders matched directly on-chain for transparent price discovery. Manages margin accounts, funding rate payments, liquidations on maintenance-margin breaches, and oracle-based mark pricing — delivering a CEX-like experience with DeFi self-custody.Coming Soon

Rust

Project NameTypeDescriptionReports
Coinbase Settlement SaleToken Sale Access Control SignaturesCoinbase Sonar Solana program running permit-verified token sales. Participants commit an SPL token (e.g. USDC) against off-chain signed permits, tracked per entity and per wallet through a PreOpen → Commitment → Cancellation → Settlement → Done lifecycle. Built on Anchor 0.32 with Ed25519 precompile verification, a program-owned vault, and a bitmask-based RBAC model under a single admin authority.Coming Soon
Coinbase SunriseSwaps/DEX Stablecoin Liquidity Access ControlCoinbase SCaaS Solana smart contract (Anchor) implementing a protocol-managed liquidity pool for 1:1 stablecoin swapping. A single global pool supports up to 50 token types, each with a dedicated vault, with a configurable basis-point fee, dual-authority access control (operations vs pause), slippage protection, liquidity reservation limits, and PDA-derived account validation.Coming Soon
Coinbase Sunrise V2Swaps/DEX Stablecoin Liquidity WhitelistSolana smart contract (Anchor, Rust) for Coinbase's SCaaS stablecoin liquidity protocol. Implements a global liquidity pool enabling 1:1 swaps between supported stablecoins with configurable fees, slippage protection, decimal normalization, a dual authority model, and an address whitelist system.Coming Soon
SanctumStaking Liquid Staking Wrapped Assets Formal VerificationSOLS is a Sanctum Solana program implementing fractional reserve wrapped SOL. Users deposit SOL and receive SOLS, with careful tracking of supply vs lamports owed. Written in Rust (Solana BPF), split into core math/invariants, the Jiminy parsing layer, the deployed program with hot/cold routing, and a Mollusk test harness. Supports rebalancing, protocol fees, admin/manager roles, and Kani formal verification of core logic.Coming Soon
Wonderland Security AuditGameFi Randomness/VRF Rewards ReferralsSolana GameFi protocol (Anchor) where users buy keys, earn rewards from later purchases, and compete for mini and grand jackpots powered by verifiable randomness, with vaults, a game timer, and a merkle-backed referral system.View Report
Dreadnought Video Game Security AuditGameFi Security ToolingSecurity audit of the Dreadnought video game, evaluating vulnerabilities and integrity of the game's systems.View Report
Crossmint Audit ReportNFT Payments InfrastructureSecurity audit of Crossmint's NFT minting and payments infrastructure.View Report
Report on Suspected NFT Scam and Fake ProfilesNFT Investigation/FraudInvestigative report on a suspected NFT scam and the identification of fake profiles used to facilitate it.View Report
ElizaOSAI/Infrastructure Token Migration Whitelist/MerkleSolana smart contract (Anchor) for ElizaLabs handling a controlled token migration, allowing whitelisted wallets to swap one SPL token for another at a fixed rate, gated by a Merkle tree whitelist with per-wallet limits.View Report

Formal Verification

Project NameTypeDescriptionReports
OL NetworkInfrastructure/L1 Formal VerificationFormal verification of OL Network's blockchain infrastructure, proving correctness of core on-chain logic.View Report
ThalaLending Yield Formal VerificationFormal verification of Thala's lending and yield logic to prove invariants and ensure correctness.View Report
AaveLending Formal VerificationFormal verification overview for Aave Aptos V3, proving correctness of core lending and accounting logic.View Report
FullSailSwaps/DEX Formal VerificationFormal verification of FullSail's DEX/swap logic to validate core invariants.View Report

Private reviews

View all
Engagement
Project title
Timeframe
Researchers
Eco Foundation

Eco Foundation

Eco Routes SVM

Apr 2026 - Apr 2026

Jay
Rikard Hjort
Coinbase

Coinbase

Sunrisedotdev: Settlementsale

Apr 2026 - Apr 2026

Jay
Sujith S
Coinbase

Coinbase

Coinbase: Multiproof

Mar 2026 - Mar 2026

Jay
0xicingdeath
Sanctum

Sanctum

Sanctum: Sols

Feb 2026 - Mar 2026

Jay
Mustafa Hasan