I work as a researcher at Trail of Bits, mainly focused on blockchain components. Special interests include fuzzing design, agentic tooling, blockchain components, and application security. I enjoy technical diversity, thus the variety in the experiences below. I am currently targeting the formal verification world, completely unknown to me but a fascinating world.
Experience
-
May 2025 – present
Senior Security Engineer, Trail of Bits
- Auditing applications, creating tools, researching techniques
- OpenAI’s Patch the Planet, Rust compiler bug hunting with Codex
- One of the external firms triaging and validating AI-discovered vulnerabilities for Anthropic’s coordinated vulnerability disclosure
-
Dec 2022 – May 2025
Senior Security Engineer, Security Research Labs
Rust-based blockchain nodes audits and fuzzing
-
Mar 2021 – Sep 2021
Penetration Tester, Vaadata
Web application penetration testing
-
Oct 2020 – Jan 2021
IoT Pentest, Ellcie Healthy
Bluetooth Low Energy implementation review
-
Jun 2020 – Sep 2020
Cybersecurity & Privacy Researcher, I3S / CNRS
Privacy and security analysis of COVID-19 contact-tracing Android apps
-
May 2019 – Sep 2019
Pentester & Internal Red Teaming, Fortil
Penetration testing and security governance across network, systems, and applications
-
2018
Software Developer, Calinda Software
Full-stack development (Vue, Angular, Java, Node) and electronic-signature workflows
Tooling
-
gosentry
Security-oriented Go toolchain, focused on state-of-the-art fuzzing capabilities repo blog
-
go-panikint
Go compiler fork that panics on silent integer overflows and truncations repo blog
-
phink
Coverage-guided, property-based fuzzer for ink! smart contracts repo talk
-
LibAFL-git-aware
LibAFL variant that biases fuzzing toward recently changed lines of code repo
-
gogotrace
Reverse call-graph: trace all callers of a function by its signature repo
-
aflpp-mcp
MCP server for AFL++ repo
-
rpc-fuzzer
WebSocket-based RPC fuzzer for node and service endpoints repo
-
coread
Voice-driven codebase Q&A for security engineers repo
Talks
-
Jul 2026
Building and shipping secure agent software event
-
Mar 2026
Merge Them All: How We Brought State-of-the-Art Tooling into a Single Go Toolchain program slides
-
Feb 2026
Finding Hidden Overflows in Go: Fuzzing Beyond the Compiler’s Limits video event slides
-
Mar 2025
Fuzzing Rust Smart Contracts: Writing a Bug Printer Engine from Scratch video slides
-
Jun 2023
Securing the Polkadot Ecosystem video
Writing & publications
Findings
Bug bounties
| Target | Severity | Reward |
|---|---|---|
| Snowbridge (Polkadot/Ethereum bridge) | Critical | $10,000 |
| Moonbeam | Medium | $2,000 |
| TradingView | Medium | $500 |
Bugs
-
rust
OpenAI’s Patch the Planet, Rust compiler bug hunting with Codex, see bugs #158078 #158033 #158028 #158017 #158016 #158008 #157969 #157965 #157964
and fix PRs
#158080 #158034 #158030 #158018 #157971 #157968 #157967
fun fact -
cvd
Anthropic coordinated vulnerability disclosure, triage and validation of AI-discovered bugs, see CVE-2026-44420 CVE-2026-44421 CVE-2026-45700 CVE-2026-41401
-
optimism
Found via gosentry differential fuzzing #19333 #19334 #19335
-
revm
Found via gosentry differential fuzzing #3458
-
cosmos-sdk
Found via go-panikint #25006
Education
-
2019 – 2020
MSc, Computer Science Engineering, City University of Hong Kong
-
2018 – 2021
Engineering degree, Polytech Nice Sophia
-
2016 – 2018
DUT, Computer Science, IUT d’Aix-Marseille