Fredy Bahena (Satoshi) 👋
Security Researcher · Bug Hunter · Web3 Security · Smart Contract Auditor
Security researcher focused on discovering, validating, and documenting vulnerabilities across Web3, smart contracts, APIs, and web applications.
I combine manual research with fuzzing, symbolic execution, automation, and offensive security techniques to identify security issues and understand their real-world impact.
📍 CDMX, Mexico
🔎 Research Focus
- 🛡️ Web3 & Smart Contract Security
- 💰 DeFi Security
- 🌐 Web & API Security
- 🔐 Authentication & Authorization
- 🧠 Business Logic Vulnerabilities
- 🧪 Fuzzing & Invariant Testing
- ⚙️ Security Automation & Reconnaissance
- 🔬 Vulnerability Research
🧰 Security Stack
Smart Contract Security
"Solidity" "Foundry" "Medusa" "Slither" "Halmos" "Echidna"
Web3
"EVM" "DeFi" "Arbitrum" "ERC-20" "ERC-721" "ERC-777"
Offensive Security
"Burp Suite" "Nuclei" "ffuf" "subfinder" "Nmap"
Programming
"Python" "Solidity" "Rust" "Bash"
🧪 What I'm Working On
Currently researching vulnerabilities in DeFi protocols and smart contracts, with a focus on:
- Fund-extraction vulnerabilities
- Access-control and authorization flaws
- Minting & burning logic
- Reentrancy
- Oracle and price manipulation
- Accounting inconsistencies
- Protocol invariants
- Attack-surface discovery
I also build security automation and reconnaissance tooling to improve vulnerability discovery and research workflows.
🛠️ Security Projects
🔬 Security Research Labs
Practical environments for studying vulnerabilities, exploitation paths, detection techniques, and mitigations.
🤖 Security Automation
Tools and experiments focused on automated reconnaissance, vulnerability discovery, and security research.
📚 Research & Writeups
Notes, methodologies, vulnerability analysis, and lessons learned from security research.
🏆 Bug Bounty
Active security researcher on:
- HackerOne
- Bugcrowd
- Intigriti
- HackenProof
My research follows responsible disclosure practices, program scope, and rules of engagement.
📜 Certifications
- PentesterLab PRO — Deserialization RCE
- PentesterLab PRO — Injection
- PentesterLab PRO — Authentication & Authorization
- PentesterLab Unix Blue
📫 Connect With Me
- 💻 GitHub: "@satoshi403" (https://github.com/satoshi403)
- 💼 LinkedIn: "Fredy Bahena Martinez" (https://www.linkedin.com/in/fredy-bahena-martinez-b3468a213/)
- 𝕏 X: "@FredyBahenaM" (https://x.com/FredyBahenaM)
- 📸 Instagram: "@satos_hi7443" (https://www.instagram.com/satos_hi7443/)
Bug bounty handle: "satoshi7"
«Find vulnerabilities. Understand the root cause. Build better security.»
Responsible disclosure only. No exploitation without authorization.