Welcome to the Gabal's Aura repository.
This repo contains my smart contract security reviews, findings, and reports across different protocols, challenges, and real-world scenarios.
All reports are written with a focus on clarity, impact, and practical exploitability.
I'm Gabal (Mahmoud Emad), a Web3 security researcher focused on:
- Smart contract auditing
- DeFi security & economic attacks
- Bug bounty hunting (HackerOne / Intigriti)
- Solidity & EVM internals
I aim to continuously improve by auditing real codebases and participating in competitive environments.
🔗 LinkedIn: https://www.linkedin.com/in/mahmoud-emad-695883261/
Each report typically includes:
- Protocol overview
- Threat modeling
- Vulnerability findings (High / Medium / Low)
- Proof of Concept (PoC)
- Recommendations
Some of the issues I commonly identify:
- ❗ Incorrect accounting leading to insolvency
- ⚖️ Share mispricing & inflation bugs
- 🔁 Reentrancy vulnerabilities
- 🔐 Access control issues
- 🧮 Logic flaws in DeFi mechanisms
My auditing approach focuses on:
- Understanding the protocol design deeply
- Identifying trust assumptions and invariants
- Testing edge cases (non-standard ERC20s, reentrancy, etc.)
- Writing PoCs to validate real exploitability
- Providing practical, developer-friendly fixes
- Contribute high-quality findings to Web3 security
- Participate in top audit contests (Sherlock, Code4rena)
- Build a strong track record of impactful vulnerabilities
All reports in this repository are for educational and research purposes only.
Some findings may already be known, fixed, or intentionally included in training challenges.
If you want to collaborate or discuss security:
⭐ If you find this repo useful, feel free to star it.