Skip to content
View imxm's full-sized avatar

Organizations

@BlockApex

Block or report imxm

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
imxm/README.md

👋 Hi, I am Moazzam Arif.

  • 🔐 Security researcher and engineer, six years in blockchain across L1 core, cross-chain infrastructure, and zero-knowledge systems.
  • 🛡️ 120+ security engagements, most of them with Oak Security since 2021, earlier with BlockApex, which I co-founded.
  • 📃 Languages: Go, Rust, Solidity, Noir, C++ (read), TypeScript, Python.
  • ⛓️ Ecosystems: Cosmos SDK and CosmWasm, Stellar and Soroban, Solana, Ethereum, NEAR, Fuel, Polkadot bridges, Gno.land, Aztec.
  • 📂 Full audit portfolio with per-report findings: imxm/audits.

Domains I have secured:

  • L1 core and consensus: Stellar Core state management and Soroban pipeline, GnoVM determinism and metering, Solana Agave fork choice, Cosmos SDK staking and migration logic
  • Rollups and sequencers: shared sequencers, settlement layers, light clients, ABCI clients
  • Cross-chain: messaging chains, orchestrators and relayers, gateways, asset bridges, BEEFY light-client verification
  • ZK and cryptography: Noir circuits, Groth16 and R1CS, Fiat-Shamir soundness, EOTS, identity-based encryption
  • Wallets and custody: multisig on CosmWasm and Soroban, account abstraction, MPC-backed custody services
  • Regulated systems: custody, cross-border settlement and brokerage architecture for a large EMI wallet, with controls mapped for compliance review

🧪 Authored the Noir CTF challenges published by Oak Security.

🤖 AI-assisted security research

I build tooling to make review scale across large codebases and long-running engagements, and I use it on real audits:

  • Obsidian: a root-cause-tagged corpus of ~5,000 Cosmos ecosystem vulnerabilities (taxonomy, domain tags, source reports),
  • Diff-aware review across rounds: for multi-round programmes (Zigchain)
  • A zk Circuit-bug detection: a harness over the corpus targeting under-constrained ZK circuits; example zkpassport bug was dicovered

Reach out on LinkedIn.

Pinned Loading

  1. Audit-Reports Audit-Reports Public

    Forked from BlockApex/Audit-Reports

  2. BlockApex/Audit-Reports BlockApex/Audit-Reports Public

    Security Audit reports by BlockApex

    39 6

  3. OakSecurity-audit-reports OakSecurity-audit-reports Public

    Forked from oak-security/audit-reports