Audit portfolio from my time at Quantstamp, where I led 26 and contributed to 98 audits securing over $1B in TVL across Ethereum, Solana, Cosmos, and Flow. Background in pure mathematics (MSc, University of Toronto) and web2 security training at the Fields Institute. Cross-ecosystem fluency in Solidity, Rust, Cadence, CosmWasm, and Go.
Quantstamp research developed with Kacper Bąk and Alex Murashkin, presented at ETHAustin 2023. Analyzes the security and performance impact of chain forks and reorgs across the full cross-chain bridge design space, varying by decentralization level, settlement speed, and whether the bridge connects two L1s or an L1 to an L2. Introduces a novel deposit-hash mitigation for L1-L2 bridges.
Hytham Farah (@HythamFarah), Auditing Engineer at Quantstamp, discussing “The Impact of Chain Forks and Reorgs on Cross-chain Bridges” at ETHAustin! ⛓️🌉 pic.twitter.com/K7KPzB7pUc
— Quantstamp (@Quantstamp) April 25, 2023
Six findings selected for range rather than volume: account abstraction, oracle manipulation, cross-protocol composability, DeFi math, accounting invariants, and MEV.
_withdraws, letting an attacker transfer zero, reset withdrawal history, and repeatedly reclaim yield until the contract was drained.