Pwnie Award / 2009
Best Research.
For From 0 to 0Day on Symbian, research into the attack surface of Nokia smartphones.
Founder / Pragma Research
I build tools for understanding complex systems. My work spans offensive security, mathematical models of physics and brains that learn from experience.
Pwnie Award / 2009
For From 0 to 0Day on Symbian, research into the attack surface of Nokia smartphones.
Pwnie nomination / 2018
For Smashing Ethereum Smart Contracts for Fun and ACTUAL Profit.
OWASP / Mobile security
The Mobile Application Security Testing Guide and Verification Standard, OWASP Flagship projects.
Research / Physics, mathematics and AI
A shared question runs through this work: how can local systems build a coherent account of a world?
Physics / OPH / 2025 onward
OPH studies bounded, self-reading patches with local state, ports, records and feedback. Patches compare shared records and repair disagreement. The research develops finite constructions and conditional routes toward quantum probability, spacetime, gravity and gauge structure.
The papers state the assumptions behind those routes. Establishing a physical account of nature requires measurements as well as mathematical consistency.
Mathematics / Formal verification
The OPH research repository develops machine-checked Lean proofs alongside executable models. Work includes finite agreement and refinement, event algebras, geometry and algebraic structure.
Formal verification establishes consequences of explicit hypotheses. The proofs, computational checks and physical interpretations can be examined separately.
AI / Cadence
Cadence turns the idea of cooperating local models into software. Flat, ordinary state-coupled and recursive observer layouts all settle through the same repair and qualification process; admitted experience changes their retained relations. Recursive observers add access to other populations' activity and exact prediction errors.
Code, bounded learning experiments and the research paper support an engineering program for embodied intelligence.
Career and selected work
From vulnerability research and mobile standards to symbolic execution, AI agents and the structure of learning.
2005–2013 / SEC Consult
Vulnerability research across enterprise software, embedded systems and mobile platforms.
2009 / Whitepaper / Pwnie Best Research
Applied low-level vulnerability analysis to Symbian smartphones, including Nokia multimedia codecs reachable through MMS. The research covered seven vulnerable codec DLLs and devices including the E61, E71 and N96.
2008 / Whitepaper
Research into DNS cache poisoning following the coordinated multi-vendor disclosure, using node re-delegation to improve the reliability of an attack.
2008 / With Peter Panholzer
A demonstration of the FireWire direct-memory-access attack against Windows Vista, with a proof of concept that disables password authentication in the login routine.
Disclosure ↗| Date | Research |
|---|---|
| Nov 2005 | Macromedia Flash Player: ActionDefineFunction memory corruption (SA-20051107-1). |
| Nov 2005 | toendaCMS: credential and session theft, directory traversal and arbitrary file upload (SA-20051107-0). |
| Apr 2006 | Opera Browser: CSS attribute integer wrap and buffer overflow (SA-20060413-0). |
| May 2006 | Symantec Enterprise Firewall: internal IP disclosure of NATted machines (SA-20060512-0). |
| Oct 2006 | PHP exec/system/popen: file descriptor bug demonstrated by overwriting an Apache log. |
| Mar 2007 | MySQL: information_schema denial of service through a null-pointer dereference, with S. Streichbier (SA-20070309-0). |
| Oct 2007 | Perdition IMAP Proxy: format string vulnerability (CVE-2007-5740; SA-20071031-0). |
| Nov 2007 | SonicWALL SSL-VPN: multiple ActiveX control vulnerabilities (SA-20071101-0). |
| Dec 2007 | SonicWALL Global VPN Client: format string through a crafted configuration file (SA-20071204-0). |
| Dec 2008 | Fujitsu-Siemens WebTransactions: remote command injection (SA-20081219-0). |
| Dec 2008 | Microsoft SQL Server: sp_replwritetovarbin memory overwrite (CVE-2008-5416; MS09-004). CERT/CC note. |
| Mar 2009 | IBM Director CIM Server: remote denial of service (SA-20090305-1). |
| Mar 2009 | IBM Director CIM Server: local privilege escalation (SA-20090305-2). |
| May 2009 | Nortel Contact Center Manager: authentication bypass (SA-20090525-0). |
| May 2009 | SonicWALL Global VPN Client: local privilege escalation through installation-directory permissions (SA-20090525-3). |
| Jul 2009 | Symbian S60 / Nokia firmware: media-codec memory corruption through MMS (SA-20090707-0). |
| Oct 2012 | ModSecurity: multipart parsing bypass (SA-20121017-0). Full Disclosure. |
| Nov 2012 | Applicure dotDefender WAF: format string vulnerability. |
| Dec 2012 | IBM System Director Agent: DLL injection through wmicimsv, with a Metasploit module; co-credited with Juan Vazquez and Kingcope. |
| Jul 2013 | Sybase EAServer: directory traversal, XML entity injection and OS command execution, with Gerhard Wagner (SA-20130719-0). |
2014–2018 / Vantage Point Security & OWASP
Security research became shared standards, testing methods and tools for reversing mobile applications.
Creator and lead author
The Mobile Application Security Testing Guide, including work on reverse engineering and tampering. Co-authors include Sven Schleier, Jeroen Willemsen and Carlos Holguera.
Creator and lead author
The Mobile Application Security Verification Standard defines requirements used to assess the security of mobile applications.
2016 / HITB GSEC, Singapore
Research on mobile two-factor and one-time-password tokens, from reverse engineering to kernel sandboxes and full-system emulation. Presented as Attacking Software Tokens.
Tools and training
2017–2020 / ConsenSys Diligence
As a security engineer, I worked on smart-contract auditing and tools that explore program behavior through symbolic execution.
Creator / Open-source analysis
A security analysis tool for EVM bytecode using symbolic execution, SMT solving and taint analysis. Created by Bernhard Mueller and transferred to ConsenSys.
2018 / HITB Amsterdam / Pwnie nomination
Paper and talk introducing Mythril's approach and the LASER symbolic execution engine.
August 2019 / DEF CON 27 / With Daniel Luca
A talk on Ethereum exploits, counter-exploits and honeypots, with a demonstration of Scrooge McEtherface. The tool uses symbolic execution and the Z3 solver to investigate exploitable contracts.
Research tools
2023 onward / AI & autonomous agents
Work on autonomous agents and an AI Research Lead role at Sherlock brought security analysis and machine learning together.
Creator / Research paper, October 2025
A language-agnostic code security auditor that builds relation-first knowledge graphs during an investigation. An exploring agent works with senior-model guidance. The paper is Hound: Relation-First Knowledge Graphs for Complex-System Reasoning in Security Audits.
Creator / Evaluation framework
A framework for evaluating AI smart-contract audit agents against real-world vulnerability datasets. Hound and ScaBench were transferred to scabench-org.
Source ↗Autonomous-agent experiments
MiniAGI explored a small autonomous agent built around the OpenAI API. Darwin GPT explored an agent that can spawn copies of itself.
AI-assisted security
A Web3 bug-bounty assistant that tracks bounties and uses autonomous agents to investigate code.
Source ↗Reinforcement learning
Deep Q-learning experiments with Mancala, including an OpenAI Gym environment, agent self-play and a PyGame interface.
Source ↗Music / TransformerXL
A polyphonic, multi-instrument music transformer trained on 3,604 metal, grunge and punk MIDI songs, augmented through pitch transposition. The project used a custom tokenizer and 200 hours on four Nvidia T4 GPUs.
Read the project story ↗Embodied learning / Cadence
Cadence extends this interest in machine intelligence to a persistent learner built from cooperating predictive patches. Explore the research or read the Cadence preprint.
2025 onward / Learning projects
Interactive explanations and reading paths for the mathematics and security of computational systems.
Interactive tutorial
A step-by-step exploration of STARK proofs, from execution traces and constraints to FRI.
Read about STARK Lab ↗Curated learning path
Reading paths through SNARKs, STARKs and Bulletproofs, with the mathematics and implementation ideas behind them.
Explore the project ↗Curated learning path
Resources on adversarial attacks, prompt injection and the use of AI in security testing.
Explore the project ↗Articles and essays
Research explanations, technical walkthroughs, malware analysis and occasional satire.
Keep in touch
For research conversations, robotics collaborations or an introduction to Pragma Research, get in touch.