One researcher. Every rejection logged.
I am KhomDev, an independent blockchain security researcher and agentic AI engineer. Not a team, not a firm. Everything on this site is my own work, in my own voice.
That is not a typo. One High-severity finding, split across 61 reporters, paid me two cents. Separately, 3 findings were confirmed valid by the teams, with working proofs of concept, and paid nothing, because the program's reward table had no tier at that severity.
I assumed my bottleneck was skill, so I built more tooling. The number did not move. Then I went back through all 97 rejections and asked one question per row: which check would have caught this before I spent the time?
73.2% of them were catchable before I read a line of code.
That changed the work. I now study why findings don't get paid, publish the data with its limitations first, and build open tools and an agentic audit pipeline that check the targeting before the analysis.
I am early, and the site says so. There is no client list here and no pricing, because I don't have the paid result that would justify one yet. When I do, it will be on this page with a link to the evidence.
Four rules I hold myself to.
Targeting before analysis
Payout floor, exclusions, scope and prior audits are checked before I read contract code.
Numbers from public repos
If I publish a number, it is generated by a script in a public repository, and CI fails when it drifts.
Hold, don't submit
A finding whose impact is unreachable under real conditions stays in my notes. I would rather submit nothing than submit noise.
Failures published
When a fix I proposed failed its test, I published the failure. The dataset contains rejections only, and says so first.