🛡️Security Researcher | Co-founder @ValvesSec

Joined January 2022
15 Photos and videos
Pinned Tweet
Wrapped it in a valve 🫡
Wrapped up the @Panoptic_xyz contest on @code4rena 🏆 We secured 1st place🥇 with 5 valid findings (1 High / 4 Medium), including 1 solo submission. Really interesting system. Excited to see where Panoptic goes from here. Bright future ahead 🚀
1
21
1,583
Merulez retweeted
Jun 11
Been wanting this to exist for a while, so I built it. ProofOfRep, a reputation board for bug bounty programs and contests. Report your unfair or dishonest experiences, with proof, and I'll manually review everything. Hope it helps SRs focus on projects that actually take security seriously. Still early. Let me know if this sucks or if it's useful. All feedback welcome. proofofrep.xyz/

13
34
160
9,605
Merulez retweeted
Update to my roadmap -> We built the practice layer it was missing. training.valvessecurity.com 380 challenges derived from 50,000 real Solodit findings, clustered into 19 vulnerability patterns. Active pattern-recognition training on real code. The gap between reading findings and discovering them is huge. This is built specifically to close it. Still free. Still no fluff.
Smart Contract Security Roadmap 2026 Free resources only. If I had to start from zero today, this is the exact path I’d follow:🧵 Most people waste months jumping between random resources, tools, and contests. If I were starting again in 2026, I’d focus on 4 things in order: • Foundations • Security fundamentals • Competitive auditing • Specialization Here’s the roadmap I wish I had.👇
3
8
44
2,385
Merulez retweeted
5/5 Read our @ValvesSec v1.5 audit report here: docs.ezmanager.finance/audit… For more details on the changes: docs.ezmanager.finance More v1.5 changes rolling out in the UI over the next few weeks! Check out the docs and contracts for a sneak peek 👀
1
2
95
Merulez retweeted
We’ve got some exciting things coming to EZManger in the next few weeks with this audit! @ValvesSec has been incredible throughout the process, and we’re happy to trust them to make EZManager as secure as possible.
Valves 🤝 EZManager (@EZManagerCL ) EZManager tracks every position lifecycle. From opening and rebalancing to capital changes, compounding, and collections. We are going to ensure their contracts meet the highest security standards 🫡
6
15
574
Someone just made the first donation to our Valves Security Training Hub on Giveth. $18 from an anonymous contributor. It may look small, but honestly this means a lot. We spent countless hours building this because we wanted aspiring auditors to have a free place to train on real vulnerability patterns, not just random CTF puzzles. Just a resource we wish we had when we started. To whoever donated: thank you. And to everyone supporting, sharing, testing, or learning from the hub - you are the reason we keep building this. giveth.io/project/valves-sec…
1
2
28
885
The goal was never to look like the biggest audit firm. The goal is to be the team founders trust when they want honest, deep, no-BS security work before launch. That’s what we’re building with Valves Security.
We're on a mission to save millions (potentially billions) in exploits over the next 365 days. Big names in the space already trust us with their protocol security. Your codebase deserves the same level of protection🛡️ Book an audit now: valvessecurity.com/audit
2
1
16
867
Merulez retweeted
We're on a mission to save millions (potentially billions) in exploits over the next 365 days. Big names in the space already trust us with their protocol security. Your codebase deserves the same level of protection🛡️ Book an audit now: valvessecurity.com/audit
2
14
1,350
Code4rena winding down does not make contest results worthless. But it does change the lesson. For years, contest placement was one of the cleanest public signals that someone could find bugs under pressure. That still matters. But in private audits, the harder skill is different: - Can you explain the issue clearly enough that the team fixes it correctly the first time? A leaderboard proves speed. Client trust proves judgment. You need both.
24
1,103
Merulez retweeted
Not great for just one year... 😤 We should all do much better! At @ValvesSec we’re stepping up. We are going to save millions in exploits over the next 365 days. You should do the same. Let’s secure this whole space together. 🔥
1
4
10
803
Merulez retweeted
Valves 🤝 EZManager (@EZManagerCL ) EZManager tracks every position lifecycle. From opening and rebalancing to capital changes, compounding, and collections. We are going to ensure their contracts meet the highest security standards 🫡
4
18
1,532
Merulez retweeted
Can’t focus? Then force it. Talk to yourself like a psycho: “DO IT. NOW! RIGHT FUCKING NOW!” 😤 That’s what helps me snap back when I get distracted. Who else does this? 🔥
1
10
252
Merulez retweeted
Hands-off farming is here! Agent Max automatically opens positions on MaxFi, making it even easier than before. Get ready for the MaxFi seed round next week! #DeFi #AutomatedTrading
11
3
17
224
The first thing I check in any audit is not the complex math. It is every place the code converts between two units. Shares to assets. Tokens to wei. Seconds to blocks. That boundary between “what the user thinks” and “what the contract stores” is where a lot of serious bugs hide.
6
125
Merulez retweeted
"You're saying auditors are better than Opus 4.7 and GPT 5.5?" 🤡 Bro… YES!!! Auditors lead the AI, catch any misses, and actually stand behind the code that holds millions🔥 AI might be better in some casses, but if a non-auditor used it don't call it security...
2
1
10
399
Merulez retweeted
For the longest time node clients were gatekept and untouched by free AI auditing tools, but that is NO MORE! 🚀💫 Not only is your AI subscription auditing for you, but you can even choose which one! 🤯 More deterministic, more precise. BETTER 🏆 "Plamen" V2 is live 😈🤖
12
7
77
7,833
Merulez retweeted
May 13
Contests are dead, cantina killed them
20
11
243
15,385
The end of an era. Thank you for everything 🙏
Replying to @code4rena
After careful consideration, we’ve made the decision to wind down @code4rena. This community has meant a great deal to everyone who has been part of building it, and sharing this news is not easy.
2
109
Merulez retweeted
The Valves Security Training Hub is now listed on @Giveth A free pattern recognition platform for smart contract auditors. 380 challenges. 19 bug categories. 50K real audit findings. Train pattern recognition on real exploits, not textbook examples. Free forever. 100% goes to the project. giveth.io/project/valves-sec…
1
12
56
1,915
Merulez retweeted
Used @pashov's x-ray skill on day 1 of an audit (~8K nSLOC) and it saved me a solid half-day. The kickoff work I usually do by hand on day one: - Threat model - Architecture diagram - Subsystem breakdown - Invariant catalog x-ray produced all of it in one run, with derivations for each inferred invariant. That last part is what I'll keep coming back to. It surfaces invariants the protocol assumes but doesn't actually enforce in code, with citations to where each one breaks. Hit a couple of tooling glitches on macOS (BSD vs GNU grep flag in enumerate.[sh], forge coverage didn't finish in time) but nothing breaking. Will be running it on every audit going forward. Nice work @0xfirefist.
4
3
62
8,935
Merulez retweeted
BETA STARTING NOW! Reply to be among the first to get access
50
8
63
9,770