Back to all work

Security research

Security Reviews

A public catalogue of reproducible smart-contract and applied-security research.

Summary

Security Reviews groups public, reproducible research by vulnerability class. Each review links a vulnerable target, an exploit proof of concept, a remediated branch, a report, and automated checks.

Role and scope

Gilles Musy reproduces the vulnerable behavior, documents impact and assumptions, implements or explains remediation, and keeps the evidence runnable in CI.

Problem and constraints

A written finding is difficult to evaluate when the vulnerable state, exploit path, fixed behavior, and assumptions cannot be reproduced independently.

Architecture

The catalogue uses one public repository per vulnerability class. Reports, source, exploit tests, fixed branches, and CI remain close enough to compare without hiding the technical path behind a summary page.

Decisions and trade-offs

The portfolio names the vulnerability classes and public programs involved, but does not publish private report details, unsupported severity claims, or finding counts as a credibility shortcut.

Security context

The research covers Web and application security, Solidity and Vyper contracts, ZK circuits, formal verification, and indirect prompt injection. Public platform associations include the Treasury Board of Canada Secretariat, Reserve Protocol, Revert Finance, Chainlink Payment Abstraction V2, and K2.

Testing and verification

Public repositories include executable exploit and remediation checks using the tool appropriate to each target, including Foundry, Halmos, Circom, and GitHub Actions.

Public results

Published examples cover share inflation, signature replay, reward accounting drift, oracle freshness, reentrancy, fee rounding, access control, under-constrained circuits, and arithmetic verification.

Public evidence

The catalogue and linked repositories are public. HackerOne, Gray Swan Arena, Cantina, and Code4rena provide separate public professional profiles.

Remaining limitations

Only attributable public evidence appears here. Private submissions, unpublished technical details, and non-public program information remain excluded.

Next case study

Agent Resilience

View case study