XFollowListPeople, ideas and original work on X
samczsun’s avatar

Security researcher and Security Alliance founder

samczsun

@samczsun on X

Exploit analysis and security strategy that connect smart-contract flaws with infrastructure, people and incident response.

Why read samczsun?

samczsun's price-oracle guide shows how a protocol can turn an apparently ordinary market price into an exploitable assumption. He walks through mechanisms and incident examples, making it useful for understanding what a contract trusts and how an attacker can influence that input. It is a concrete starting point for readers moving from using DeFi to examining how it works.

His later writing broadens the problem beyond a contract's source code. The North Korean threat article examines infrastructure and human access, while the bounty essay asks how to keep deployed systems under active review. These pieces connect exploit research to the work of Security Alliance, which he founded after his research role at Paradigm.

Start with the original

Selected work

  1. Technical guide ·

    So you want to use a price oracle

    When can a quoted market price become an attack vector? His incident examples explain how protocols consume prices and what happens when attackers can manipulate the source they trust.

  2. Security analysis ·

    Demystifying the North Korean Threat

    How does a security investigation extend beyond smart contracts? His account connects incident response with infrastructure, recruiting and access controls, showing how the threat model changes as evidence arrives.

  3. Security essay ·

    Higher Bug Bounties Won't Stop Hacks

    How do you keep a deployed system under review? His argument distinguishes a passive bounty offer from commissioning a new audit, including changes in dependencies and the resources needed for each approach.

Projects & roles

  • Security Alliance

    The nonprofit he founded, with incident-response, intelligence and security-preparation initiatives.

  • samczsun's research

    His archive of exploit research, technical explanations and security essays.

Community rating

92

Vote once every 24 hours. No account needed.

Sources & further reading