About

One researcher. Every rejection logged.

I am KhomDev, an independent blockchain security researcher and agentic AI engineer. Not a team, not a firm. Everything on this site is my own work, in my own voice.

Lifetime bug-bounty earnings
$0.02

As published in my first article. Read it ↗

That is not a typo. One High-severity finding, split across 61 reporters, paid me two cents. Separately, 3 findings were confirmed valid by the teams, with working proofs of concept, and paid nothing, because the program's reward table had no tier at that severity.

I assumed my bottleneck was skill, so I built more tooling. The number did not move. Then I went back through all 97 rejections and asked one question per row: which check would have caught this before I spent the time?

73.2% of them were catchable before I read a line of code.

That changed the work. I now study why findings don't get paid, publish the data with its limitations first, and build open tools and an agentic audit pipeline that check the targeting before the analysis.

I am early, and the site says so. There is no client list here and no pricing, because I don't have the paid result that would justify one yet. When I do, it will be on this page with a link to the evidence.

Four rules I hold myself to.

Targeting before analysis

Payout floor, exclusions, scope and prior audits are checked before I read contract code.

Numbers from public repos

If I publish a number, it is generated by a script in a public repository, and CI fails when it drifts.

Hold, don't submit

A finding whose impact is unreachable under real conditions stays in my notes. I would rather submit nothing than submit noise.

Failures published

When a fix I proposed failed its test, I published the failure. The dataset contains rejections only, and says so first.

The fastest way to reach me.

A DM on X, or an email. I read both.