Arbaz Hussain
Lead Web & Smart Contract Security Triager at Immunefi
About Me
I'm Arbaz Hussain from India 🇮🇳 working as a Lead Smart Contract Security Triager at Immunefi. With a strong passion for blockchain and web security, I focus on safeguarding the decentralized ecosystem. My role involves conducting in-depth security research and proactively identifying vulnerabilities to mitigate risks before they can be exploited.
When I'm not diving into code, you'll find me exploring new cultures, chasing travel adventures, or getting lost in deep thoughts about philosophy, self-awareness, and human behaviors.
From trekking in the Himalayas to reflecting on life's big questions, I believe every experience adds a new layer to how we see the world & ourselves.
Experience
Skills
- 🛡️ Ethereum-based Blockchain Security (Smart Contracts & DApp Auditing)
- 🔒 Web Application Security Testing
- 📱 Mobile Application Security (iOS & Android)
- ☁️ Cloud Security (AWS, Azure, GCP)
- 🛠️ DevSecOps & Web Security
- 🌐 Onchain Threat Monitoring Solutions
- 🎥 Motion Graphics & Video Editing (Adobe Premiere)
- 💻 Scripting Languages: Python, JavaScript, Bash
- 💻 Programming Languages: Golang, Rust, Solidity
Acknowledgements
- Top 100 hackers on HackerOne (2020)
- Synack Red Team Member for VAPT
- 250+ valid vulnerability reports via HackerOne (impact score of 20)
- 500+ overall valid reports across multiple platforms
- Acknowledged by 300+ companies, including Microsoft, Google, PayPal, etc.
Speaker @ Conferences
-
BSides Ahmedabad 24:
Web3 Bug Bounties: Why & How to Get
Started
Slides Video -
DeFi Security Summit 24:
The Bug Hunter's Guide to High-Quality
Reporting
Slides Video -
BSides Ahmedabad 22:
The Dark Side of DeFi
Slides Video -
Web3Conf Goa 23:
Navigating EVM Chain Security: Smart Contract
Vulnerabilities
Video - NULL-HYD 22: Introduction to Web3 & Security Pitfalls
- ThreatCon 22: Tour of Common Web3 Vulnerabilities
Open Source Projects
Maintaining open-source projects in Web3 security.
-
EVM Vulnerabilities PoC Templates
Creating reusable, easily modifiable PoC examples for various EVM-based vulnerabilities.
-
Immunefi CLI Tool
A Rust-based CLI tool that automates white-hat bug hunting processes.
Work Projects
Contributions to the Web3 community at Immunefi.
- Immunefi - Bounty Boosts Bug Reports
- Immunefi - Internal Audit of the Vault System & Arbitration
- Immunefi Community Challenges
- Wormhole Uninitialized Proxy Bugfix Review
- How ERC Standards Work - Part 1
- Synthetix Logic Error Bugfix Review
- Polygon Consensus Bypass Bugfix Review
- Moonbeam Missing Call Check Bugfix Review
- Sense Finance Access Control Issue Bugfix Review
- Aurora Withdrawal Logic Error Bugfix Review
- Immunefi POC Templates
- Beanstalk Logic Error Bugfix Review
- DFX Finance Rounding Error Bugfix Review
Personal Projects
CIMEX CONTINUOUS SECURITY RECON FRAMEWORK
Cimex automates security monitoring and reconnaissance, streamlining bug bounty workflows. Utilizes AWS Lambda, Celery tasks, Redis queues, and Django for efficient scaling.
Video OverviewMar 5, 2020
LINK DUMPER BURP PLUGIN
Extracts links from JS/CSS files intercepted by Burp Proxy using multiple regex patterns. Features auto-link building to accelerate deeper analysis.
GitHub RepositoryAug 27, 2019
BROKEN LINK HIJACKING BURP PLUGIN
Automates detection of broken links from Burp Proxy responses. Performs DNS resolution to identify potential hijackable domains.
GitHub RepositorySep 13, 2019
HACK BOT - TELEGRAM
My first initiative to run penetration testing and bug bounty tasks seamlessly via a Telegram bot system.
GitHub RepositoryMedium Post 1
Medium Post 2
Aug 29, 2017
Web3 Security Research
Collection of articles covering various aspects of Web3 security, smart contract vulnerabilities, and blockchain security best practices.
Understanding Smart Contract VulnerabilitiesDeFi Security Best Practices 2024
Blockchain Security Fundamentals
2023-2024
Bug Bounty Writeups
Detailed writeups of critical vulnerabilities found in various bug bounty programs, including methodology and impact analysis.
From XSS to RCE: A Complete WalkthroughChainlink Oracle Manipulation Vulnerability
DeFi Protocol Exploit Analysis
2022-2024
Security Tools & Automation
Articles about security automation tools, custom scripts, and workflow optimizations for security researchers.
Automating Security Research with PythonBuilding Custom Security Tools
Security Workflow Automation
2021-2023
More from My Medium
Additional articles and content covering various aspects of security, blockchain, and technology.
Twitter Timeline
We are releasing weekly community challenges for beginners to learn about the common security pitfalls... https://t.co/u2Fpi91G1H @immunefi
— Arbaz Hussain (@ArbazKiraak) March 2, 2022
Brilliant piece of postmortem written by @sherlockdefi on a complex cross-protocol reentrancy... https://t.co/8SooOJycNl
— Arbaz Hussain (@ArbazKiraak) August 17, 2022
Book Recommendations

Thus Spoke Zarathustra
By Friedrich Nietzsche
An epic philosophical work that challenges and empowers readers to explore the depths of individual purpose.

Man's Search for Meaning
By Viktor E. Frankl
A profound reflection on surviving the Holocaust and discovering life's ultimate purpose.

The Forty Rules of Love
By Elif Shafak
A mesmerizing story that interweaves the lives of a modern woman and the legendary poet Rumi.
Limitless
By Jim Kwik
Techniques and mindsets for unleashing your brain's full capacity and achieving high-performance goals.

Be Here Now
By Ram Dass
An inspirational guide bridging Eastern spirituality and Western consciousness, urging us to live mindfully.
Personal Blog
Bucket List
- 🤿 PADI Open Water Diver certification in Koh Tao 🇹🇭 Completed!
- 🏕️ Camping at Chandrataal Lake, Spiti Valley 🇮🇳 Completed!
- 🛣️ Road trip across Northern Himalayas 🇮🇳 Completed!
- 🪂 Paramotoring around Annapurna Ranges 🇳🇵 Completed!
- 🌉 Bungee Jumping 🇳🇵 Completed!
- 🎶 Attend Boris Brejcha Music Event 🇩🇪 Coming Soon
- 🚴♀️ Complete a 150km cycling route on Al Qudra track 🇦🇪 Training
- 🏃♂️ Participate in a 50km+ Ultra Hell Race 🇮🇳 Planning
- 🏄♂️ Master surfing in Bali 🇮🇩 Completed!
- ⛷️ Learn to ski at Shymbulak Ski Resort 🇰🇿 Completed!
- 🏔️ Hike in Pahalgam town, Kashmir 🇮🇳 Completed!
- 🧗♀️ Become a certified rock climber 🇹🇷 Researching
- 🤿 Molchanovs Wave 1 Freediving certification in Nusa Penida 🇮🇩 Completed!
- 🗻 Climb Mt. Fuji 🇯🇵 Completed!