guest@0xurahara:~
guest@0xurahara:~$

> About Me

I'm Mehrdad (0xurahara), a full-stack blockchain developer moving deliberately into application security. Three years building decentralized applications — DEXs, NFT marketplaces — and REST APIs taught me how these systems are supposed to work. Now I'm learning how they actually fail.

My path runs from web application security into Web3-specific vulnerability classes, then toward deeper vulnerability research — with browser or IoT security as the long-term target. I run my own VPS infrastructure (WireGuard, VLESS, self-hosted Interactsh for OOB testing) and build a lean recon/attack toolkit. I also write my own offensive tooling from scratch when the job calls for it — most recently a Go implementation of the HTTP/2 single-packet attack

I document everything and disclose responsibly.

Development Exp
3+ Years
Current Focus
AppSec & Web3
Methodology
Build & Break

Core Stack

Solidity Golang JavaScript/React Hardhat Python Docker Burp Suite Nuclei

> Bug Bounty Writeups

Real vulnerabilities discovered and responsibly disclosed:

View All Writeups →

> Custom Tools & Scripts

Open-source tools I've built for bug bounty hunting:

myDex - Decentralized Exchange

📅 2026-08-07 | #Solidity #React #Web3 #DeFi

📋 Overview

myDex is a fully...

View Details GitHub Repo
View All Tools →

> Security Blog & Tutorials

Guides, how-tos, and security research:

Setting Up Private Interactsh Server

📅 2026-08-06 | ⏱️ 1 min read

Complete guide to deploying a...

Read Article →
View All Articles →

> Contact & Secure Comms

Prefer encrypted communication for vulnerability reports. Response time: 24-48h.

Email: [email protected]

PGP Fingerprint:

234C 1BE0 012D 804E F4A7 930A 77B3 9E1E 68A0 0601

Download Public Key (.asc) View on keys.openpgp.org

Bug Bounty Platforms

Social