0xRayaa/Audits
GitHub: 0xRayaa/Audits
资深安全研究员 0xRayaa 的审计作品集,汇集 130+ 次智能合约审计报告和 Web2 漏洞赏金成果。
Stars: 4 | Forks: 0
# 0xRayaa 的安全作品集
我是一名安全研究员,专注于 **Solidity**、**Rust** (Solana, CosmWasm)、**Cairo** (StarkNet) 和 **DAML** 的智能合约审计,同时也从事专业的 **Web2 漏洞赏金与渗透测试**。
**智能合约:** 130+ 私人审计 · 150+ 严重/高危漏洞 · 25+ Rust 审计 🦀
**Web2:** 3 个已发布的 CVE · 在 Stryker、Ivanti、BitGo、Decred、Tennessee Valley Authority 等平台发现严重/高危漏洞 · 活跃于 Bugcrowd、HackerOne 及政府平台
**审计覆盖的协议与机制:**
| 类别 | 覆盖范围 |
|----------|----------|
| 🏦 **DeFi** | AMM · 借贷 · 联合曲线 · 代币发行器 · 归属分发 · 再质押 |
| 🥩 **Staking** | 质押金库 · NFT 质押 · 流动性质押 · 验证节点系统 · 奖励机制 |
| 🎮 **GameFi** | 抽奖 · 骰子 · 老虎机 · 轮盘 · 预测市场 · NFT 市场 |
| 🪙 **代币** | ERC20 · SPL 代币 · 代币经济学 · 空投与分发 · 治理模块 |
| 🌉 **基础设施** | 跨链 · 链抽象 · 链间消息传递 · 浏览器钱包扩展 |
| ⛓️ **生态系统** | EVM (Solidity) · Solana (Rust) · CosmWasm (Rust) · StarkNet (Cairo) · DAML |
📩 有兴趣合作吗?
- Twitter/X: [@0xRayaa](https://x.com/0xRayaa)
- Telegram: [@0xRayaa](https://t.me/0xRayaa)
## 🔐 私人审计 — 公司委托审查
| 公司 | 报告 | 描述 | 发现 | 语言/生态系统| 📑 |
| ---- | ------ | ---------- | ------ | --------|----|
Pashov Audits | Nucleus | 金库合约 | - | ♦ EVM | **即将发布** |
|
Pashov Audits | Polygun | 预测市场交易机器人 | - | Typescript |**即将发布** |
|
Pashov Audits | Pump.Fun | AMM 与联合曲线 | 6 (1M, 5L) |🦀 Solana |**[🔗](audit-reports/pdfs/Pump-security-review_2026-02-09.pdf)** |
|
Pashov Audits | Nucleus | 金库合约 | 8 (8L) | ♦ EVM | **[🔗](audit-reports/pdfs/Nucleus-security-review_2026-02-03.pdf)** |
|
Pashov Audits | RAAC | 代币与铸造合约 | 10 (1M, 9L)| ♦ EVM | **[🔗](audit-reports/pdfs/RegnumAurum-security-review_2026-01-23.pdf)** |
|
Shieldify Audits | Springx | 金库与池子质押 | - | Solidity | **[🔗](audit-reports/pdfs/SpringX-Security-Review.pdf)** |
|
Pashov Audits | SpiceNet | 交易提交 API | - | Typescript |**[🔗](audit-reports/pdfs/Spicenet-security-review_2026-01-12.pdf)** |
|
Superteam | Prime Skills (草案) | GameFi | 4 (2H, 2L) | 🦀 Solana | **[🔗](audit-reports/pdfs/WAGER_PROGRAM_SMART_CONTRACT_AUDIT%20(1).pdf)** |
## 🔎 公开审计 — 竞赛与漏洞赏金
| 排名 | 报告 | 描述 | 严重/高危 | 中危 | 语言/生态系统 |
| ---- | ------ | ---------- | ------ | -----------| --------|
| 50 |
[Super DCA 流动性网络](https://audits.sherlock.xyz/contests/1171) | AMM, Uniswap V4 Hooks | 1 | 1 | ♦ EVM |
| 74 |
[Rain 智能合约审计竞赛](https://hackenproof.com/hackers/0xRayaa?tab=programs) | 去中心化预测市场协议 | 1 | 2 | ♦ EVM |
| 18 |
[Bid Beasts](https://codehawks.cyfrin.io/c/2025-09-bid-beasts/results?lt=contest&page=1&sc=xp&sj=reward&t=leaderboard) | NFT 市场 | 2 | 2 | ♦ EVM |
| 20 |
[Calyx 智能合约](https://hackenproof.com/hackers/0xRayaa?tab=programs) | 去中心化预测市场协议 | 0 | 1 | ♦ EVM |
## 🔐 私人审计 — CredShields
## 📆 2026 审计
协议 | 描述 | 生态系统 | 语言 | 发现 | 📑 |
|----------|-------------|-----------|----------|----------|----|
Mercuri Protocol | Uniswap V3 池金库 | ♦ EVM | Solidity | 4 (3C,0H,1M) | **[🔗](audit-reports/pdfs/MercuriFinance-MercuriProtocolContracts_Audit_Report.pdf)** |
Blockwill | DeFi 协议 | ♦ EVM | Solidity | 4 (0C,1H,3M) | **[🔗](audit-reports/pdfs/Blockwill_Final_Audit_Report.pdf)** |
Ardentis | 借贷 (Morpho 分叉) | ♦ EVM | Solidity | 7 (0C,1H,6M) | **[🔗](audit-reports/pdfs/Ardentis_Final_Audit_Report.pdf)** |
HeyElsa | Staking | ♦ EVM | Solidity | 5 (0C,2H,3M) | **[🔗](audit-reports/pdfs/HeyElsa_Staking_Final_Audit_Report.pdf)** |
## 📆 2025 审计
协议 | 描述 | 生态系统 | 语言 | 发现 | 📑 |
|----------|-------------|-----------|----------|----------|----|
Amgi Studios-2 | NFT 质押, 代币经济学 | ♦ EVM | Solidity | 30 (16C,7H,7M) | **即将发布** |
LERN360 | Staking | ♦ EVM | Solidity | 24 (6C,10H,8M) | **[🔗](audit-reports/pdfs/LERN360_ICO_Contracts_Final_Audit_Report.pdf)** |
Amgi Studios-1 | NFT 质押, L1<>L2 RollUp | ♦ EVM | Solidity | 9 (4C,3H,2M) | **即将发布** |
Power Couple Coin | Staking, 抽奖 | 🦀 Solana | Rust | 9 (6C,0H,3M) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/Lottery_Contracts_Final_Audit_Report.pdf)** |
Power Couple Coin: Selltax | DeFi | 🦀 Solana | Rust | 9 (6C,0H,3M) | **即将发布** |
Tarmiiz | 质押金库 | ♦ EVM | Solidity | 9 (2C,3H,4M) | **[🔗](https://github.com/Sanket-722/Audits/blob/main/audit-reports/pdfs/Tarmiiz_Final_Audit_Report.pdf)** |
DotLabs: Mushi | DeFi, 借贷 | 🦀 Solana | Rust | 8 (1C,3H,4M) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/Mushi_V2_0_Final_Audit_Report.pdf)** |
BRLA Digital | ERC20 代币兑换 | ♦ EVM | Solidity | 14 (2C,0H,3M,9L) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/BRLA_Final_Audit_Report.pdf)** |
| 协议 | 描述 | 生态系统 | 语言 | 发现 | 📑 | |----------|-------------|-----------|----------|----------|----| | Power Couple Coin: Staking | Staking | 🦀 Solana | Rust | 6 (4C,0H,2M) | **即将发布** | | Power Couple Coin: StakingPanelty | Staking | 🦀 Solana | Rust | 5 (4C,0H,1M) | **即将发布** | | Metaco Intelligence Corporation | 再质押 | ♦ EVM | Solidity | 13 (1C,2H,3M,7L) | **[🔗](http://github.com/Credshields/audit-reports/blob/master/Zoth_Final_Audit_Report.pdf)** | | Artulabs Limited | 归属分发, ERC20 | ♦ EVM | Solidity | 9 (0C,1H,2M,5L) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/Artu_Solidity_Final_Audit_Report.pdf)** | | mew.gg | AMM | ♦ EVM | Solidity | 11 (0C,1H,0M,10L) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/mew.gg_Contracts_Final_Audit_Report.pdf)** | | Manadotwin | 归属分发, 联合曲线 | ♦ EVM | Solidity | 5 (2C,1H,2M,0L) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/Manadotwin_Final_Audit_Report.pdf)** | | Zodor | Staking | ♦ EVM | Solidity | 7 (2C,0H,1M,4L) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/Zodor_Staking_Final_Audit_Report.pdf)** | | Avail | 链抽象 | ♦ EVM | Solidity | 4 (1C,0H,3M) | **[🔗](audit-reports/pdfs/Avail_Vault_Final_Audit_Report.pdf)** | | Safle Network | 跨链统一身份管理 | ♦ EVM | Solidity | 6 (2C,1H,3M) | **[🔗](audit-reports/pdfs/Safle_Final_Audit_Report.pdf)** | | LERN360 | ERC20 | ♦ EVM | Solidity | 4 (0C,2H,0M,2L) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/LERNToken_Final_Audit_Report.pdf)** | | Fomodotbiz | AMM, 联合曲线 | ♦ EVM | Solidity | 6 (3C,0H,3M) | **[🔗](audit-reports/pdfs/Fomodotbiz_Final_Audit_Report.pdf)** | | Vouch | 代币经济学 | ♦ EVM | Solidity | 7 (2C,0H,5M) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/Vouch_Token_and_Distribution_Final_Audit_Report.pdf)** | | Artulabs Limited | 空投, SPL 代币 | 🦀 Solana | Rust | 5 (1C,2H,3M) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/Artu_Rust_Final_Audit_Report.pdf)** | | Landslide | ICM (链间消息传递) | ♦ EVM | Solidity | 7 (2C,0H,5M) | **[🔗](https://github.com/Sanket-722/Audits/blob/main/audit-reports/pdfs/Landslide_Final_Audit_Report.pdf)** | | Save Planet Earth | Staking | ♦ EVM | Solidity | 5 (2C,1H,2M) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/SPE_Smart_Contract_Final_Audit_Report.pdf)** |
## 📆 2024 审计
协议 | 描述 | 生态系统 | 语言 | 发现 | 📑 |
|----------|-------------|-----------|----------|----------|----|
LogX | 验证节点 | ♦ EVM | Solidity | 11 (3C,2H,2M,4L) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/LogX_Token_Final_Report.pdf)** |
AllinGames: Bank | GameFi | 🦀 Cosmos (CosmWasm) | Rust | 9 (4C,0H,5M) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/AllInGames_Bank_Final_Audit_Report.pdf)** |
Plutope | 代币发行器 | ♦ EVM | Solidity | 12 (2C,0H,5M,5L) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/Plutope_Final_Audit_Report.pdf)** |
AllinGames: Lottery | GameFi | 🦀 Cosmos (CosmWasm) | Rust | 4 (2C,0H,1M,1L) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/AllInGames_Lottery_Final_Audit_Report.pdf)** |
AllinGames: Coin Flip | GameFi | 🦀 Cosmos (CosmWasm) | Rust | 2 (1C,1H,0M) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/AllInGames_Coin_Flip_Final_Audit_Report.pdf)** |
AllinGames: Hash Dice | GameFi |🦀 Cosmos (CosmWasm) | Rust | 2 (1C,1H,0M) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/AllInGames_Hash_Dice_Final_Audit_Report.pdf)** |
| 协议 | 描述 | 生态系统 | 语言 | 发现 | 📑 | |----------|-------------|-----------|----------|----------|----| | AllinGames: Classic | GameFi | 🦀 Cosmos (CosmWasm) | Rust | 7 (1C,0H,1M,5L) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/AllInGames_Classic_Dice_Final_Audit_Report.pdf)** | | Protop Vesting | 归属分发 | ♦ EVM | Solidity | 8 (1C,0H,0M,7L) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/Protop_Vesting_Contracts_Final_Report.pdf)** | | Arcana: Browser Extension | 钱包 | ♦ EVM | Solidity | 5 (0C,0H,1M,4L) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/Arcana_Wallet_Final_Audit_Report.pdf)** | | Arcana Staking | Staking | ♦ EVM | Solidity | 11 (0C,1H,0M,10L) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/Arcana_Staking_Contract_Final_Audit_Report.pdf)** | | AllinGames: Seven Up Seven Down | GameFi | 🦀 Cosmos (CosmWasm) | Rust | 5 (0C,0H,0M,5L) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/AllInGames_Seven_Up_Seven_Down_Final_Audit_Report.pdf)** | | AllinGames: Slot | GameFi | 🦀 Cosmos (CosmWasm) | Rust | 4 (0C,0H,0M,4L) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/AllInGames_Slots_Final_Audit_Report.pdf)** | | AllinGames: Roulette | GameFi | 🦀 Cosmos (CosmWasm) | Rust | 2 (0C,0H,0M,2L) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/AllInGames_Roulette_Final_Audit_Report.pdf)** | | Lara Protocol | Staking | ♦ EVM | Solidity | 13 (0C,0H,5M,8L) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/Lara_Liquid_Staking_Final_Audit_Report.pdf)** | | Tribally Games | GameFi | ♦ EVM | Solidity | 6 (0C,1H,0M,5L) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/Tribally_Games_Final_Report.pdf)** |
## 🕸️ Web2 漏洞赏金与 CVE
| 报告 | 漏洞描述 | 严重程度 |应用 |
|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | --------------------- | -----|-----------------|
|[Stryker](https://bugcrowd.com/h/Sanket_722) | 3 个漏洞 - 信息泄露 | 严重 | Web应用 |
|[Stryker](https://bugcrowd.com/h/Sanket_722) | 2 个漏洞 - 存储型和盲打 XSS | 严重 | Web应用 |
|Ivanti🔒 | 信息泄露 | 严重 | Web应用 |
| [BitGo 托管公开漏洞赏金委托](https://bugcrowd.com/h/Sanket_722) | 业务逻辑漏洞 | 高危 | Web应用 |
|[Decred](https://bounty.decred.org/hall-of-fame/) | 身份验证尝试的不当限制 | 高危 | Web应用 |
|ChargeOver 🔒 | SSRF | 高危 | Web应用 |
| E-GOI 🔒 | XSS | 中危 | Web应用 |
| [CVE-2023-3580 ](https://nvd.nist.gov/vuln/detail/CVE-2023-3580) | HTML 注入 | 中危 | Web应用 |
|[CVE-2023-0827 ](https://nvd.nist.gov/vuln/detail/CVE-2023-0827) | XSS | 中危 | Web应用 |
|[CVE-2023-1239 ](https://nvd.nist.gov/vuln/detail/CVE-2023-1239) | XSS | 中危 | Web应用 |
|[Drugs.com](https://hackerone.com/drugs_com/thanks#:~:text=17-,spiderweb7,-17) | 身份验证不当 - 通用 | 中危 | Web应用 |
|[Tennessee Valley Authority](https://hackerone.com/reports/1276559) | 身份验证尝试的不当限制 | 高危 | Web应用 |
|[特文特大学 ](https://www.utwente.nl/en/cyber-safety/responsible/hall-of-fame/#:~:text=1-,sanket%20salavi,-1) | 信息泄露 | 高危 | Web应用 |
| [澳大利亚国家银行](https://bugcrowd.com/engagements/nationalaustraliabankog/hall_of_fames#:~:text=sjv-,Sanket_722,-prok3z) | 信息泄露 | 低危 | Web应用 |
| [Kistler 公司](https://bugcrowd.com/engagements/kistler-vdp/hall_of_fames#:~:text=Private%20user-,Sanket_722,-nthuong95) | 尝试次数的不当限制 | 低危 | Web应用 |
| [汤森路透](https://hackerone.com/reports/1219922) | 信息泄露 | 低危 | Web应用 |
| Affinity 🔒 | 信息泄露 | 低危 | Web应用 |
**最后更新:2026 年 4 月**
显示另外 15 项 →
| 协议 | 描述 | 生态系统 | 语言 | 发现 | 📑 | |----------|-------------|-----------|----------|----------|----| | Power Couple Coin: Staking | Staking | 🦀 Solana | Rust | 6 (4C,0H,2M) | **即将发布** | | Power Couple Coin: StakingPanelty | Staking | 🦀 Solana | Rust | 5 (4C,0H,1M) | **即将发布** | | Metaco Intelligence Corporation | 再质押 | ♦ EVM | Solidity | 13 (1C,2H,3M,7L) | **[🔗](http://github.com/Credshields/audit-reports/blob/master/Zoth_Final_Audit_Report.pdf)** | | Artulabs Limited | 归属分发, ERC20 | ♦ EVM | Solidity | 9 (0C,1H,2M,5L) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/Artu_Solidity_Final_Audit_Report.pdf)** | | mew.gg | AMM | ♦ EVM | Solidity | 11 (0C,1H,0M,10L) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/mew.gg_Contracts_Final_Audit_Report.pdf)** | | Manadotwin | 归属分发, 联合曲线 | ♦ EVM | Solidity | 5 (2C,1H,2M,0L) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/Manadotwin_Final_Audit_Report.pdf)** | | Zodor | Staking | ♦ EVM | Solidity | 7 (2C,0H,1M,4L) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/Zodor_Staking_Final_Audit_Report.pdf)** | | Avail | 链抽象 | ♦ EVM | Solidity | 4 (1C,0H,3M) | **[🔗](audit-reports/pdfs/Avail_Vault_Final_Audit_Report.pdf)** | | Safle Network | 跨链统一身份管理 | ♦ EVM | Solidity | 6 (2C,1H,3M) | **[🔗](audit-reports/pdfs/Safle_Final_Audit_Report.pdf)** | | LERN360 | ERC20 | ♦ EVM | Solidity | 4 (0C,2H,0M,2L) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/LERNToken_Final_Audit_Report.pdf)** | | Fomodotbiz | AMM, 联合曲线 | ♦ EVM | Solidity | 6 (3C,0H,3M) | **[🔗](audit-reports/pdfs/Fomodotbiz_Final_Audit_Report.pdf)** | | Vouch | 代币经济学 | ♦ EVM | Solidity | 7 (2C,0H,5M) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/Vouch_Token_and_Distribution_Final_Audit_Report.pdf)** | | Artulabs Limited | 空投, SPL 代币 | 🦀 Solana | Rust | 5 (1C,2H,3M) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/Artu_Rust_Final_Audit_Report.pdf)** | | Landslide | ICM (链间消息传递) | ♦ EVM | Solidity | 7 (2C,0H,5M) | **[🔗](https://github.com/Sanket-722/Audits/blob/main/audit-reports/pdfs/Landslide_Final_Audit_Report.pdf)** | | Save Planet Earth | Staking | ♦ EVM | Solidity | 5 (2C,1H,2M) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/SPE_Smart_Contract_Final_Audit_Report.pdf)** |
显示另外 9 项 →
| 协议 | 描述 | 生态系统 | 语言 | 发现 | 📑 | |----------|-------------|-----------|----------|----------|----| | AllinGames: Classic | GameFi | 🦀 Cosmos (CosmWasm) | Rust | 7 (1C,0H,1M,5L) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/AllInGames_Classic_Dice_Final_Audit_Report.pdf)** | | Protop Vesting | 归属分发 | ♦ EVM | Solidity | 8 (1C,0H,0M,7L) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/Protop_Vesting_Contracts_Final_Report.pdf)** | | Arcana: Browser Extension | 钱包 | ♦ EVM | Solidity | 5 (0C,0H,1M,4L) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/Arcana_Wallet_Final_Audit_Report.pdf)** | | Arcana Staking | Staking | ♦ EVM | Solidity | 11 (0C,1H,0M,10L) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/Arcana_Staking_Contract_Final_Audit_Report.pdf)** | | AllinGames: Seven Up Seven Down | GameFi | 🦀 Cosmos (CosmWasm) | Rust | 5 (0C,0H,0M,5L) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/AllInGames_Seven_Up_Seven_Down_Final_Audit_Report.pdf)** | | AllinGames: Slot | GameFi | 🦀 Cosmos (CosmWasm) | Rust | 4 (0C,0H,0M,4L) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/AllInGames_Slots_Final_Audit_Report.pdf)** | | AllinGames: Roulette | GameFi | 🦀 Cosmos (CosmWasm) | Rust | 2 (0C,0H,0M,2L) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/AllInGames_Roulette_Final_Audit_Report.pdf)** | | Lara Protocol | Staking | ♦ EVM | Solidity | 13 (0C,0H,5M,8L) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/Lara_Liquid_Staking_Final_Audit_Report.pdf)** | | Tribally Games | GameFi | ♦ EVM | Solidity | 6 (0C,1H,0M,5L) | **[🔗](https://github.com/Credshields/audit-reports/blob/master/Tribally_Games_Final_Report.pdf)** |
标签:AMM机制, Bug Bounty, Cairo审计, CISA项目, CosmWasm安全, CVE, DAML审计, DeFi安全, EVM安全, GameFi安全, NFT安全, Rust审计, Solana安全, Solidity审计, StarkNet安全, Web2安全, Web3安全, 代币经济学, 借贷协议, 加密货币安全, 区块链安全, 去中心化金融安全, 可自定义解析器, 可视化界面, 安全研究员, 提示词注入, 数字签名, 智能合约审计, 治理模块, 流动性质押, 渗透测试工程师, 漏洞赏金猎人, 白帽黑客, 空投安全, 网络安全, 质押系统, 跨链安全, 钱包安全, 链抽象, 隐私保护