Hello
Hello

Bokiru.

DevOps & Offensive Security · Indonesia

I run the infrastructure, then I try to break it. DevOps behind AuraNode, HexaNode, TropicalCrypto, SinceDAO, and Rektanalisis DAO by day, smart contract auditor and offensive researcher the rest of the time, and part of Airdropfinder. I trust systems only after I have attacked them myself.

Bokiru
recon.active● available
DevOps & infrastructure across
about me

The best defense is knowing exactly how you'd attack.

Running node infrastructure taught me where things break under pressure, and that made me a sharper attacker. I audit the smart contracts and protocols behind the networks I operate, then write the exploit before someone with worse intentions does.

I like the messy edges: reentrancy nobody noticed, an oracle that trusts the wrong price, a privileged function guarded by an assumption. If value flows through it, I want to know how it fails.

Smart Contract AuditSolidityFuzzingRed TeamThreat ModelingNode Hardening
60+Contracts audited
25+Critical findings
$4M+Value protected
4 yrAuditing since 2021
experience

Where I've been.

2023 — Present

Smart Contract Auditor · TropicalCrypto, SinceDAO, Rektanalisis DAO

Review Solidity protocols before and after launch. Combine manual reasoning with fuzzing to surface reentrancy, oracle manipulation, and access control bugs, then verify the fixes hold.

2022 — Present

DevSecOps · AuraNode & HexaNode

Run and harden validator infrastructure, then red team it. Threat model the deployment, lock down key custody, and keep an attacker's view of everything I ship.

2020 — 2022

CTF Player & Bug Hunter · Web & Web3

Cut my teeth on capture the flag and public bug bounty, moving from web exploitation into on chain security as the money moved there.

findings & projects

Things I broke.

audit

Reentrancy in a staking vault

Found a cross function reentrancy that let an attacker drain rewards before balances updated. Reported privately, patched with a reentrancy guard and checks effects interactions.

severity: criticalfixed
audit

Oracle price manipulation

Showed how a thinly traded pair could be pushed with a flash loan to mint against an inflated price. Recommended a time weighted feed and sanity bounds.

severity: highfixed
tooling

fuzz-forge

A Foundry based invariant fuzzing harness I reuse across audits to hammer protocol state and catch the bugs manual review misses.

open sourcesolidity
research

MEV in the mempool

A writeup on sandwich and backrun patterns observed on chain, and what protocol designers can do to make their users a smaller target.

blogongoing
achievements

By the numbers.

60+Contracts audited
25+Criticals
$4M+Value protected
9Protocols
contact

Got a system you want broken first?

Open to bug bounty engagements, security research, and appsec consulting. Let's talk.