Thanks to visit codestin.com
Credit goes to github.com

Skip to content
View satoshi403's full-sized avatar

Block or report satoshi403

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
satoshi403/README.md

Hi, I'm Fredy Bahena (Satoshi) 👋

Web3 Security Researcher · Smart Contract Auditor · Bug Bounty Hunter


Fredy Bahena (Satoshi) 👋

Security Researcher · Bug Hunter · Web3 Security · Smart Contract Auditor

Security researcher focused on discovering, validating, and documenting vulnerabilities across Web3, smart contracts, APIs, and web applications.

I combine manual research with fuzzing, symbolic execution, automation, and offensive security techniques to identify security issues and understand their real-world impact.

📍 CDMX, Mexico


🔎 Research Focus

  • 🛡️ Web3 & Smart Contract Security
  • 💰 DeFi Security
  • 🌐 Web & API Security
  • 🔐 Authentication & Authorization
  • 🧠 Business Logic Vulnerabilities
  • 🧪 Fuzzing & Invariant Testing
  • ⚙️ Security Automation & Reconnaissance
  • 🔬 Vulnerability Research

🧰 Security Stack

Smart Contract Security

"Solidity" "Foundry" "Medusa" "Slither" "Halmos" "Echidna"

Web3

"EVM" "DeFi" "Arbitrum" "ERC-20" "ERC-721" "ERC-777"

Offensive Security

"Burp Suite" "Nuclei" "ffuf" "subfinder" "Nmap"

Programming

"Python" "Solidity" "Rust" "Bash"


🧪 What I'm Working On

Currently researching vulnerabilities in DeFi protocols and smart contracts, with a focus on:

  • Fund-extraction vulnerabilities
  • Access-control and authorization flaws
  • Minting & burning logic
  • Reentrancy
  • Oracle and price manipulation
  • Accounting inconsistencies
  • Protocol invariants
  • Attack-surface discovery

I also build security automation and reconnaissance tooling to improve vulnerability discovery and research workflows.


🛠️ Security Projects

🔬 Security Research Labs

Practical environments for studying vulnerabilities, exploitation paths, detection techniques, and mitigations.

🤖 Security Automation

Tools and experiments focused on automated reconnaissance, vulnerability discovery, and security research.

📚 Research & Writeups

Notes, methodologies, vulnerability analysis, and lessons learned from security research.


🏆 Bug Bounty

Active security researcher on:

  • HackerOne
  • Bugcrowd
  • Intigriti
  • HackenProof

My research follows responsible disclosure practices, program scope, and rules of engagement.


📜 Certifications

  • PentesterLab PRO — Deserialization RCE
  • PentesterLab PRO — Injection
  • PentesterLab PRO — Authentication & Authorization
  • PentesterLab Unix Blue

📫 Connect With Me

Bug bounty handle: "satoshi7"


«Find vulnerabilities. Understand the root cause. Build better security.»

Responsible disclosure only. No exploitation without authorization.

Pinned Loading

  1. satoshi403 satoshi403 Public

    Web3 Security Researcher | Smart Contract Auditor | Bug bounty hunter on HackerOne, Bugcrowd, Intigriti & HackenProof | Toluca, MX

    1

  2. web3-vulnerability-research-methodology web3-vulnerability-research-methodology Public

    1