👋 Hi, I am Moazzam Arif.
- 🔐 Security researcher and engineer, six years in blockchain across L1 core, cross-chain infrastructure, and zero-knowledge systems.
- 🛡️ 120+ security engagements, most of them with Oak Security since 2021, earlier with BlockApex, which I co-founded.
- 📃 Languages: Go, Rust, Solidity, Noir, C++ (read), TypeScript, Python.
- ⛓️ Ecosystems: Cosmos SDK and CosmWasm, Stellar and Soroban, Solana, Ethereum, NEAR, Fuel, Polkadot bridges, Gno.land, Aztec.
- 📂 Full audit portfolio with per-report findings: imxm/audits.
Domains I have secured:
- L1 core and consensus: Stellar Core state management and Soroban pipeline, GnoVM determinism and metering, Solana Agave fork choice, Cosmos SDK staking and migration logic
- Rollups and sequencers: shared sequencers, settlement layers, light clients, ABCI clients
- Cross-chain: messaging chains, orchestrators and relayers, gateways, asset bridges, BEEFY light-client verification
- ZK and cryptography: Noir circuits, Groth16 and R1CS, Fiat-Shamir soundness, EOTS, identity-based encryption
- Wallets and custody: multisig on CosmWasm and Soroban, account abstraction, MPC-backed custody services
- Regulated systems: custody, cross-border settlement and brokerage architecture for a large EMI wallet, with controls mapped for compliance review
🧪 Authored the Noir CTF challenges published by Oak Security.
🤖 AI-assisted security research
I build tooling to make review scale across large codebases and long-running engagements, and I use it on real audits:
- Obsidian: a root-cause-tagged corpus of ~5,000 Cosmos ecosystem vulnerabilities (taxonomy, domain tags, source reports),
- Diff-aware review across rounds: for multi-round programmes (Zigchain)
- A zk Circuit-bug detection: a harness over the corpus targeting under-constrained ZK circuits; example zkpassport bug was dicovered
Reach out on LinkedIn.



