Bhavya Jain
Smart Contract Security
Researcher.
Pre-final year BTech-MTech student at LNMIIT building audit-ready DeFi systems with Solidity, Foundry, fuzzing, and exploit-driven testing. Open to security internships, protocol engineering roles, and audit collaborations.
Security-minded builder
I'm a pre-final year BTech-MTech student at LNMIIT focused on smart contract security, DeFi protocol engineering, and research-heavy problem solving.
Over the last year I've shipped ERC-1155 marketplaces, Chainlink powered lotteries, crowdfunding contracts, over-collateralized lending protocols, and Uniswap/Curve style AMM clones tested with Foundry fuzzing and invariant suites.
My current focus is audit-ready security work: reproducing real exploit classes, studying reentrancy, access control, oracle manipulation, proxy upgrades, and signature replay, then turning the root cause into clear reports and fixes.
Outside Solidity, I'm a research intern at King's College London, applying YOLO/ViT object detection to surgical robotics. Different domain, same operating system: benchmark rigorously, test assumptions, and ship evidence.
CV ready for review
Fast recruiter overview: security focus, shipped Web3 systems, research work, and internship experience.
Open resumeSelected proof of work
Shipped repositories, security labs, and full-stack Web3 systems. Every card links straight to the source so the work is easy to verify.
My running audit-contest portfolio — findings, write-ups, and proof-of-concepts submitted through CodeHawks, organized by protocol and severity as the track record builds.
Tokenized real-estate investment platform. ERC-1155 property listings, a P2P marketplace, and a rent distributor — CEI pattern enforced across every state-changing function, verified on Sepolia.
Over-collateralized lending protocol — deposit ETH, borrow CORN tokens, 120% minimum collateralization enforced on-chain at all times, with liquidation logic built and stress-tested.
Trustless on-chain lottery using Chainlink VRF for provably fair randomness and Chainlink Automation for trustless draw scheduling — full edge-case and failure-mode test coverage.
Autonomous trading agent reading live Kraken market data, reasoning over RSI/EMA/volatility signals, and settling transparently on-chain via Solidity contracts on Sepolia.
ETH-denominated crowdfunding with a USD minimum enforced live via Chainlink price feeds. Access-controlled, gas-optimized storage reads, full Foundry unit coverage.
Security-first ERC-721 implementation. Static NFTs with fixed metadata alongside dynamic NFTs whose traits update from on-chain state — safe-transfer patterns throughout, IPFS + on-chain storage.
Security Lab - exploit reproductions
Alongside shipped protocols, I maintain a running lab where I rebuild historical DeFi exploits from scratch — reentrancy chains, flash-loan-funded oracle manipulation, governance attacks — and write them up like real findings: severity, proof of concept, root cause, recommended fix. This is where audit-contest readiness gets built.
Cardano ecosystem watch
I study Cardano native tokens, trade ADA pairs, and manage entries with the same risk-first mindset I bring to DeFi security work.
ADA thesis, CNT execution.
I'm bullish on ADA, and I study the Cardano DeFi stack closely to understand how it actually works — derivatives on Strike Finance, lending and borrowing on Surf, and privacy-focused execution on Midnight. That research feeds disciplined CNT pair trades like SURF/ADA, NIGHT/ADA, and STRIKE/ADA, where I watch liquidity and narratives before sizing a position.
ADA conviction
Cardano's base asset for fees, staking, governance, and ecosystem liquidity.
Surf
Open-source Cardano lending with isolated pools and one-click long/short exposure.
Midnight
NIGHT is Midnight's native governance token, tied to Cardano's programmable privacy layer.
Strike Finance
STRIKE powers utility, staking, fee benefits, and governance inside Strike Finance.
Verified capabilities
Battle-tested where it matters; leveling fast where the edge gets sharper.
Smart Contract Development
Security & Auditing
Full-Stack Web3
ML / Research
Internships & experience
Hands-on work across web3 systems, quantitative research, and applied computer vision.
- Benchmarking the full YOLO family (v1–v26) against transformer-based detectors (RF-DETR, Mask R-CNN) for robot detection in operating-theatre video
- Curating and labeling a custom surgical-scene dataset; evaluating on mAP, inference latency, and occlusion robustness
- Architected & deployed 3 ERC-1155 contracts with ReentrancyGuard + Ownable, verified on Sepolia via Etherscan
- Applied CEI pattern across all state-changing functions; wrote Foundry fuzz tests to surface reentrancy and edge cases before deployment
- Built the on-chain investment/sell/transfer UI with wagmi v3 + viem and live Etherscan transaction tracking
- Studied derivatives, order-book microstructure, and volatility modeling
- Assisted in designing and backtesting algorithmic trading strategies — directly applicable to AMM and liquidation mechanics
Current trajectory
From Web3 foundations to full-stack protocol builds, now focused on vulnerability research, audit-ready reports, wallet threat models, and public findings.
Web3 foundations
Started with blockchain fundamentals, Ethereum architecture, smart contracts, and the mindset of building in public.
Solidity + full-stack Web3
Writing Solidity, building frontend-to-contract flows, and studying real exploits through labs and protocol research.
Auditing + wallet security
Leveling up on vulnerability classes, secure wallet patterns, threat modeling, and audit-ready reporting.
Hackathons + open source
Targeting audit contests, security hackathons, open-source contributions, and a credible public findings trail.
Open to security internships and protocol roles.
Best fit: smart contract security, DeFi protocol engineering, Web3 full-stack work, or research-heavy engineering teams. Remote, Dubai, Singapore, or India.