Location via proxy:   [ UP ]  
[Report a bug]   [Manage cookies]                

Rappie

Fuzzing specialist. ASR at Spearbit. CTO of Perimeter guild.

@Rappie

Perimeter

asr

Public earnings

$0


Public findings

0


Worked with

Biography

About Me

I'm Rappie, CTO & Lead Fuzzing Specialist at Perimeter, Associate Security Researcher at Spearbit, and active in bug bounty on Immunefi. I specialize in fuzzing EVM-based smart contracts to help protocols secure their code.

Beyond security research and protocol assessments, I contribute to the fuzzing community through open-source projects like EVM Fuzzing Resources and the List of Public Fuzzing Campaigns.

Testimonials

Rappie found some extremely subtle behaviors in our code that many others missed. He not only uses the cutting edge of multiple fuzzing engines, but also helps shape how these fuzzers are built. We've been delighted to use his mastery to make our contracts more secure.

Rappie went above and beyond to deeply understand our protocol and cover all the edge cases. His experience and knowledge about the art of fuzzing is unparalleled. Overall he is an incredible security expert, we certainly will be returning to him with our future smart contracts.

Security & Fuzzing Engagements

ProtocolEngagement TypeCompletedReportCode
Origin ProtocolPerimeter Fuzzing Engagement2025-03
BerachainPerimeter Fuzzing Engagement2025-01
BerachainPerimeter Fuzzing Engagement2024-12
BerachainPerimeter Fuzzing Engagement2024-12
BerachainPerimeter Fuzzing Engagement2024-11
BerachainPerimeter Fuzzing Engagement2024-10
BerachainPerimeter Fuzzing Engagement2024-09
BerachainFuzzing Specialist during Spearbit Security Review2024-08
PrivateFuzzing Specialist during Spearbit Security Review2024-05
Origin ProtocolPerimeter Fuzzing Engagement2024-05ReportCode
PrivatePerimeter Fuzzing Engagement2024-04
CoinbaseFuzzing Specialist during Spearbit Security Review2024-03Report
CoinbaseFuzzing Specialist during Spearbit Security Review2024-03Report
Drips NetworkPerimeter Fuzzing Engagement2024-01Code
Drips NetworkFuzzing Specialist during Spearbit Security Review2023-11Report
PrivatePerimeter Fuzzing Engagement2023-11
Origin ProtocolFuzzing Engagement2023-09Code
Origin ProtocolFuzzing & Audit2023-03Report

Open Source Contributions

ProjectLink
EVM Fuzzing ResourcesLink
List of Public Fuzzing CampaignsLink
Creator of Fuzzlib, a General Purpose Unopinionated Solidity Fuzzing LibraryLink
Reproduction of the Rari Finance hack using on-chain fuzzing with EchidnaLink
Reproduction of the Curve Reentrancy hacks using on-chain fuzzing with EchidnaLink
Author of Echidna Exercise: Solve Damn Vulnerable DeFi - Side EntranceExercise, PR

Bug Bounties & Competitions

DescriptionSeverityReportPlatformProtocol
Incorrect argument passed to Utils.characterToUnicodeBytes in Namespace.fuseHighReportCode4renaCanto Identity
Calling OUSD.burn() on an address with zero balance causes the totalSupply to go downLowReportImmunefiOrigin Protocol
Vault.redeem() fails with only non-rebasing credits in the protocolLowReportImmunefiOrigin Protocol
Total supply can become larger than max supplyLowReportImmunefiOrigin Protocol
LiquidityTree.push() does not always update state correctlyLowReportImmunefiAzuro
OUSD.burn() allows for destroying supply while balance remainsLowReportImmunefiOrigin Protocol

Get in Touch

I'm open to fuzzing engagements, security research, consulting, and general fuzzing-related questions. Feel free to reach out!

Private reviews

View all
Engagement
Timeframe
Researchers

Coinbase

February 2024 - February 2024

Coinbase

February 2024 - February 2024

7seas

April 2024 - April 2024

Security portfolio

Title
Description
OETHVault Fuzzing ReportReport for the Origin Protocol OETHVault fuzzing campaign
OETHVault Fuzzing CampaignFuzzing campaign for the Origin Protocol OETHVault
Drips Fuzzing CampaignFuzzing Campaign and Spearbit Security Review for Drips Network
Reproducing Rari Finance Hack Reproduction of the Rari Finance hack using Echidna
OUSD Fuzzing CampaignFuzzing campaign for the Origin Protocol OUSD token

Public earnings

$0


Public findings

0

Worked with