Skip to content
View VolodymyrStetsenko's full-sized avatar
🏠
Working from home
🏠
Working from home

Block or report VolodymyrStetsenko

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
VolodymyrStetsenko/README.md
Volodymyr Stetsenko

Volodymyr Stetsenko

Security Reviews for High-Consequence Systems

Protocols · Agentic Systems · Incident Reconstruction

Work with me Professional profile LinkedIn


I run an independent, founder-led security research and engineering practice. I work with protocol teams and builders of tool-using AI systems where failures can cross code, permissions, verifiers, external data, and on-chain execution.

My work is evidence-led: define the scope, identify the trust and authority boundaries, test concrete failure paths, preserve reproducible evidence, and state what remains unresolved.

Engagements

Area Focus Typical output
Protocol Security Reviews Smart contracts, protocol invariants, authorization, accounting, callbacks, upgrades, and verifier/application boundaries Threat model, review ledger, reproducible findings, technical report, remediation review
Agentic Systems Security Reviews Tool permissions, untrusted context, indirect prompt injection, data exposure, goal hijacking, authority escalation, and transaction policy Authority map, adversarial cases, evidence report, prioritized hardening and regression plan
Incident Reconstruction On-chain execution, asset movement, contract relationships, root-cause analysis, provenance, and evidence gaps Bounded chronology, evidence bundle, technical report, limitations and unresolved questions

Engagement scope, revision, exclusions, confidentiality, delivery dates, and commercial terms are agreed before work begins. Review the engagement model →

Selected Work

Work Evidence
Security Reviews Three published protocol reviews with explicit scope, findings, and limitations
Security Review Skills Versioned, evidence-gated workflows for EVM, proof-verifier, and zero-knowledge review
Agent Authority Lab Reproducible recipient-substitution and approval-binding case for transaction authority
White Radar Read-only EVM incident reconstruction with bounded evidence collection and provenance
ZKBind Cross-layer analysis of verifier-to-application trust boundaries
Web3 Security Corpus Builder Reproducible collection, deduplication, FTS5 indexing, and RAG export pipeline

Operating Principles

Evidence over assertion · Reproducibility over narrative · Explicit limits over false certainty

All work is defensive and authorized. A security review reduces uncertainty within a defined scope; it does not guarantee the absence of vulnerabilities or future incidents.


Pinned Loading

  1. SECURITY-REVIEW SECURITY-REVIEW Public

    Published protocol security reviews and reproducible technical reports by Volodymyr Stetsenko.

  2. skills skills Public

    Evidence-gated Agent Skills for EVM, proof-verifier, and zero-knowledge security reviews.

    Python

  3. agent-authority-lab agent-authority-lab Public

    Reproducible authority-boundary cases for tool-using AI systems and transaction policy.

    Python

  4. White-Radar White-Radar Public

    Read-only EVM incident reconstruction with bounded transaction graphs, asset flows, provenance, and explicit evidence limits.

    Python

  5. ZkBind ZkBind Public

    Cross-layer security analysis for zero-knowledge proof integrations and verifier-to-application trust boundaries.

    Rust

  6. web3-audit-dataset web3-audit-dataset Public

    Reproducible local corpus builder for Web3 security research, FTS5, and RAG.

    Python