Skip to content
View TUPM96's full-sized avatar

    Block or report TUPM96

    Block user

    Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

    You must be logged in to block users.

    Content in all repositories owned by your account will be closed.
    Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
    Report abuse

    Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

    Report abuse
    TUPM96/readme.md

    Hi, I'm TUPM96

    Freelance full-stack engineer | OSS bounty hunter | Web3 security researcher

    Public repositoriesOpen PRsEmail

    I build production software, audit code for real-world impact, and turn bounty issues into PRs with tests, validation, docs, and a clear rollback path. My edge is getting productive inside unfamiliar codebases quickly, isolating risk, and shipping focused fixes that hit the root cause.

    Current focus

    • Security hardening for backends, webhooks, auth flows, queue runtimes, CI/CD, and deployment configuration.
    • Web3 review with Solidity/Vyper, Slither, Foundry, access control, oracle, accounting, and invariant testing.
    • Product engineering for real apps: Node.js, TypeScript, Python, Java/Spring, PostgreSQL, WPF/.NET, and mobile workflows.
    • Bounty workflow: reproduce, write failing test, patch, verify, submit PR, iterate with maintainers.

    Highlighted bounty & OSS PRs

    ProjectWorkStatus
    orchestration-agent/AgentOrchestrationReclaim abandoned scheduler reservationsPR #4222
    orchestration-agent/AgentOrchestrationHide disabled agents from capability discoveryPR #4219
    OriginProtocol/arm-oethHarden Lido withdrawal claimsPR #242
    ramimbo/mergeworkReject boolean bounty identifiersPR #245
    ramimbo/mergeworkHarden OAuth next path validationPR #243
    ramimbo/mergeworkReject non-global public base URL IPsPR #242
    ramimbo/mergeworkWebhook URL/body/issue-number hardening series#231, #235, #236
    ramimbo/mergeworkSender, payload, Postgres URL, wallet lookup and auth session fixesMerged #221, #223, #225, #226, #227
    crytic/slitherAdd exclude-test filter flag, docs fixes and trophy updates#3031, #3032, #3033
    BitgesellOfficialRPC debug namespace and EVM address validationjs-bitgesellcore-rpc #2, gobglbridge #7
    tscircuit/jlcsearchExtended promotional component filterPR #342
    pvium/github-appCentralized bounty issue discoveryPR #44

    Web3 security lab

    I review DeFi repos with static analysis, manual review, and exploit-path-oriented tests:

    AreaRepos
    Smart-contract auditsarm-oeth, moonwell-contracts-v2, mamo-contracts, sata-contracts-v1
    Protocol / oracle / tradingveriswap.io, sorosave-contracts, st0x.oracle
    Toolingslither, bounty-radar, awesome-bounties

    Toolkit

    PythonTypeScriptNode.jsSolidityPostgreSQLDockerGitHub ActionsFoundrySlither

    GitHub activity

    Public repositoriesBounty and security PRsGitHub followers

    Connect

    GitHubLinkedInFacebookEmail

    @TUPM96's activity is private