Reece

Principal Software Engineer, Cosmos-SDK, Ethereum, DevEx

My Open-Source Work Log

Past Experience

Full Development

Security Findings

Permission Bypass in Noble, Stride, Neutron, CosmosHub, and Sei Network

December 1st, 2023; I reported an issue to John @ Noble a security issue that allowed anyone to bypass their IsBlacklisted and IsPaused logic via nested authz messages. I further found this affected the Interchain security module as well for Stride and Neutron which was fixed as well after proper discloser to the Informal team. It further affected Sei Network (with their ACL admin priority of execution).

Packet-Forward DoS Halt

October 11th, 2023; I found a high-severity vulnerability affecting affecting the packet-forward-middleware v7.0.0 release I found, migrated, and distributed the patch to 6 networks within just 24 hours of discovery. The swift actions ensured no networks were able to be exploited accidentally or maliciously.

CosmWasm DoS Halt

Q1 2023; I identified a Security issue in the cosmwasm/wasmd blockchain repo, allowing bad actors to halt the chain of any cosmwasm network. If funds are removed from the distribution module without their special message, the chain's state machine throws an invariance if checked. CosmWasm failed to properly check if its governance instantiate & execute functions deny funds movement from this account, allowing attackers to submit valid proposals to move funds to their contract and use x/crisis module to halt the network after taking funds. This issue was patched in the Juno Network v12.0.0 mainnet upgrade, with other chains using my patch shortly following.

Robinhood Clearing House

2020; I decided to participate in Robinhood's Bug Bounty program. After learning how a clearing house works, I decided to come up with possible ways to break it for user benefit. With Robinhoods addition of Fractional shares trading, I was able to exploit their fractional rounding which lead to 33-66% discounts on all public stocks through their web platform. With this, I was awarded for finding the bug via their HackerOne.

Developer Content

Copyright © Reecepbcups 2025