Hunting compiler miscompilations on smart-contract platforms with differential and metamorphic testing, using mutations proven equivalence-preserving in Lean4 — including real-world findings, some rewarded with bug bounties.
Coverage-guided grammar-aware fuzzing of smart-contract compilers — 100+ ICE bugs found in Sui Move, Cairo, Solang, Solidity, and Leo using AFL++ and LLMs.
Hybrid static analysis and LLM-based security tool for Sui Move — detects access control, governance, and centralization vulnerabilities in smart contracts.