Writing

I write about smart contract security, audit methodologies, and the craft of building secure decentralized systems.

Five Chainlink Products. One Architecture. The DON+OCR Pattern Underneath Everything.

I Asked in a Chainlink Discord: "Is Chainlink Building Any AI?" The Answer Sent Me Down a Rabbit Hole for Three Days.

CCIP's Router Pattern: Why a Single Immutable Contract Per Chain Is the Entire Security Bet

Chainlink Staking Isn't a Yield Farm. It's Cryptoeconomic Security With Real Consequences.

TerraUSD Collapsed With $18B in Circulation. Chainlink Proof of Reserve Would Have Caught It Earlier

Chainlink Functions Is Serverless Compute With Oracle Guarantees. Here's the Full Request Lifecycle.

Chainlink Automation Isn't a Cron Job. It's a Consensus Decision

Why block.timestamp Is an NFT Mint Exploit Waiting to Happen (And What VRF Actually Does Instead)

Chainlink's Foundation Layer, Explained for Smart Contract Auditors

The latestRoundData() Footgun That Drained Two DeFi Protocols for $19.5M

Reading the OCR Protocol So You Don't Have To (But You Should Anyway)

DONs Are Not Multisigs - The Architecture Difference That Actually Matters for Security

Before OCR: How Chainlink Used to Work, and Why It Had to Change

The Oracle Problem Isn't About Data. It's About Trust Minimization.

SOC 2 Type I & Type II: A Complete Beginner-to-Expert Guide

INCIDENT REPORT: OPERATIONAL SECURITY FAILURE AND TREASURY COMPROMISE AT STEP FINANCE (JANUARY 2026)

Proof of Stake vs Proof of Work: A Look Through the Lens of Security

Trail of Bits: Raising the Standard for Blockchain Security

Ethereum vs. Solana: The Battle of Layer 1 Giants

Major DeFi Security Incidents in January 2025

Thala Protocol’s Recovery from a $25M Exploit

Unchecked External Calls and the Polter Finance Hack

How Governance Vulnerabilities Enabled the AquaDAO Exploit

How Mutation Testing Could Have Prevented the Penpie Reentrancy Attack

Trail of Bits: Leading the Way in Cybersecurity

Understanding EVM Opcodes: A Simple Guide