Sujith Somraaj

Sujith Somraaj

Dev, who built a $170M protocol from zero, is now protecting hundreds of millions

@sujithsomraaj

100

Spearbit

sr

resident

Public earnings

$37,476

67th


Public findings

39


Achievements


Worked with

OP Labs
Puffer Finance
PaintSwap
Berachain
SatsBridge
Sweep n Flip
J4X
m4rio
deadrosesxyz
zigtur
phaze
dtheo

Biography

About

I'm Sujith, a security researcher at Spearbit and the CISO / security advisor of protocols, including Superform and LI.FI. I have over a decade of professional Web3 experience and 3 years in security, having worked with over 25 protocols in 2024. I am passionate about infrastructure security, from the consensus layer to message bridges. Before joining Spearbit full-time, I was the founding engineer of two startups, Superform ($180M+ in TVL) and Streams.

Audit clientele includes Berachain, Optimism Interop, Relay Protocol, Variational Finance, Monad, Blast, ZkSync, LI.FI, Decent, Drips, SuperSushi Samurai, DistrictOne, Omni-X, Centrifuge, Tea.xyz, Paintswap, Bitcorn, Sweep n' Flip, Byzantine Finance, Fantom and Angles.

CTF

  • Solved four problems during the Remedy 2025 CTF (placed 2nd).
  • Got FIRST BLOOD during the 2023 paradigm CTF solving the enterprise blockchains problem (placed 6th).
  • Broke Socket protocol's data layer during the surge competition in 2023 and bagged $27,000 from their CTF (placed 1st).

OSS + Bug Bounty

  • Major contributor to the Uniswap MMA (github.com/MultiMessageAggregation/multibridge) project, working alongside the Uniswap Foundation.
  • Major contributor to Pigeon, a cross-chain test suite. (github.com/exp-table/pigeon).
  • Wrote EIP-6170 (eips.ethereum.org/EIPS/eip-6170) to streamline the bridge interface.
  • Reported 4 vulnerabilities to Hyperlane via Immunefi from 2022 to 2024
  • Reported bugs in relay protocol (responsible disclosure, though the project has no bug bounty)

Hackathons

Audit contest

  • Achieved 1st place in the Cork Protocol competition on Cantina.

Top competitions

View all
Contest
Position
Date
Payout
incentive-contracts

incentive-contracts

5

/ 152

January 2024$5,468
curvance

curvance

24

/ 224

February 2024$2,724
opal-contracts

opal-contracts

15

/ 183

February 2024$1,018
zetachain-protocol

zetachain-protocol

36

/ 335

August 2024$492
Soon

Soon

15

/ 450

December 2024$438

Private reviews

View all
Engagement
Project title
Timeframe
Researchers
Centrifuge

Centrifuge

Centrifuge RWA Protocol Audit Summary

October 2023 - October 2023

Sujith Somraaj
Liam Eastwood
Drips

Drips

drips-monorepo

July 2024 - July 2024

Sujith Somraaj
J4X
deadrosesxyz
Omni X

Omni X

omnix-multisender

May 2024 - June 2024

Emile Baizel
Sujith Somraaj
Denis Miličević
Bitcorn

Bitcorn

bitcorn-oft[69d1ec]

December 2024 - December 2024

Sujith Somraaj
Denis Miličević
Bitcorn

Bitcorn

bitcorn-oft

November 2024 - November 2024

Sujith Somraaj
Denis Miličević

Security portfolio

Title
Description
Li.Fi ProtocolPrivate audit reports
Relay ProtocolInvalid message hash issue
HyperlanePermanent DoS
Hyperlane [Immunefi]Relayer overpaying gas
Hyperlane [Immunefi]Relayer ignoring acknowledgement cost
Hyperlane [Immunefi]32-length tree depth DoS issue
Socket.techPermanent DoS Of Data Layer
Socket.techRandom packet signing issue

Public earnings

$37,476

67th


Public findings

39


Achievements

Worked with

OP Labs
Puffer Finance
PaintSwap
Berachain
SatsBridge
Sweep n Flip
J4X
m4rio
deadrosesxyz
zigtur
phaze
dtheo