> About Me
I'm Mehrdad (0xurahara), a full-stack blockchain developer moving deliberately into application security. Three years building decentralized applications — DEXs, NFT marketplaces — and REST APIs taught me how these systems are supposed to work. Now I'm learning how they actually fail.
My path runs from web application security into Web3-specific vulnerability classes, then toward deeper vulnerability research — with browser or IoT security as the long-term target. I run my own VPS infrastructure (WireGuard, VLESS, self-hosted Interactsh for OOB testing) and build a lean recon/attack toolkit. I also write my own offensive tooling from scratch when the job calls for it — most recently a Go implementation of the HTTP/2 single-packet attack
I document everything and disclose responsibly.
Core Stack
> Bug Bounty Writeups
Real vulnerabilities discovered and responsibly disclosed:
> Custom Tools & Scripts
Open-source tools I've built for bug bounty hunting:
myDex - Decentralized Exchange
📅 2026-08-07 | #Solidity #React #Web3 #DeFi
📋 Overview
myDex is a fully...
View Details GitHub Repo> Security Blog & Tutorials
Guides, how-tos, and security research:
Setting Up Private Interactsh Server
📅 2026-08-06 | ⏱️ 1 min read
Complete guide to deploying a...
Read Article →> Contact & Secure Comms
Prefer encrypted communication for vulnerability reports. Response time: 24-48h.