Protocol Security · Ethereum Foundation

Securing Ethereum at the protocol layer.

I'm Antoine James — a security researcher at the Ethereum Foundation, where I lead the Bug Bounty Program efforts and hunt vulnerabilities in the clients and specifications that run the network.

500+
Findings triaged
30+
Vulnerabilities disclosed

Findings

Responsibly disclosed vulnerabilities across Ethereum execution clients, consensus clients, and protocol specifications.

Critical

Chess.com

Payment System Bypass

Unauthorized premium subscription access via a payment-flow flaw.

Private
Low

Reth

EIP-2681 Nonce Validation

Missing nonce validation lets invalid transactions enter the pool.

Low

Reth

Gas Limit Misconfiguration

Gas limit config deviating from network consensus parameters.

Medium

Besu

P256 Curve Point Validation

Missing on-curve validation in P256Verify causes block import failures.

High

Reth

Network-Wide DoS

Prewarm workers keep executing a block the node has already rejected.

Low

Geth

EIP-2935 Constant Mismatch

Verkle testing constant doesn't match the hardcoded 0x1FFF bytecode value.

Low

Reth

Missing Malicious Peer Punishment

No penalty for peers spamming unwanted transaction hashes.

Medium

Teku

TOCTOU Race Condition

Attestation-validation race lets duplicates bypass detection.

High

go-libp2p-pubsub

Remote DoS

Affects all protocols built on it — Prysm, Optimism, Filecoin, and more.

High

jvm-libp2p

Remote DoS

Unbounded gossip control messages let four peers OOM a node in seconds.

High

Prysm

HTR Transaction Bomb

Max-transaction blocks are hashed before the slot check, OOM-killing the node.

High

Besu

Network-Wide DoS

Hash-colliding storage slots stall Besu for a minute on one block.

Medium

Prysm

TOCTOU Race Condition

Attestation-validation race lets duplicates reach the network.

High

Consensus Specs

Frozen Builder Withdrawals

Repeated 1 ETH deposits lock a builder's withdrawable balance.

Low

Teku

MatrixEntry Parameter Order

Swapped row/column indices when building the PeerDAS matrix.

Low

Lighthouse

Unsorted Data Columns in KZG

Columns not sorted before KZG, breaking cell-index ordering.

Info

Consensus Specs

Fulu DAS Parameter Ordering

Swapped parameter order in the DAS index functions.

High

Teku

Resource Exhaustion

Confidential
Low

Lighthouse

Memory Leak in Column Sidecars

Missing cache pruning leaks ~7MB/day on long-running beacon nodes.

Low

Lighthouse

Spec Deviation

Confidential

AI System Findings

Found by my KAT tool, an AI system that front-runs bug bounty submissions.

High

Grandine

Consensus Divergence

Confidential
High

Teku

Remote DoS

Confidential
Low

Erigon

ENR Poisoning

Unbonded discv4 pings make a node sign an attacker's address into its own ENR.

Low

Grandine

Consensus Divergence

Confidential
Low

rust-libp2p

Spec Deviation

Confidential
Low

Lodestar

Consensus Divergence

Confidential
Low

Nimbus

Spec Deviation

Confidential
Low

Nimbus

Validation Gap

Confidential
Low

Nimbus

Validator Risk

Confidential
Low

Teku

StrictNoSign Deviation

Teku relays a forbidden gossip field, so honest peers score it down and drop it.

Experience

TheDAO Security Fund

EthSecurity Badge Holder
April 2026 – Present5 mos

Selected as one of the 200 Top Security Minds of Ethereum, helping allocate 75,000 ETH to strengthen Ethereum security.

Ethereum SecurityFunding Allocation

Ethereum Foundation

Protocol Security Researcher
May 2025 – Present1 yr 4 mos

Auditing EIPs, consensus and execution specs, and all 11 clients in their own languages, with manual review, fuzzing and AI tooling. Leading the Bug Bounty Program end to end, from reviews to payouts. Rebuilt the submission process from the ground up: new UI, submission fee, AI triage.

GoRustJavaFuzzingBug Bounty

Spearbit

Rust Engineer
Jan 2025 – Apr 20254 mos

Backend work on Cantina, Spearbit's competitive audit platform — built profile features like auditors' findings display, optimized and fixed SQL queries, and shipped API and data-layer improvements in Rust.

RustPostgreSQLActix

Formal Land

Security Researcher
Sept 2024 – Jan 20255 mos

Formal verification of the Sui blockchain type-checker and Keccak implementation — translating Rust code to Coq proofs for critical blockchain components.

CoqRustFormal Verification

Contests

Findings from competitive audit platforms.

I only took part in one contest on Cantina and two on Code4rena before a non-compete put competitive auditing on hold — most of my work now happens at the Ethereum Foundation.

Cantina

1 vulnerability found
0 High 0 Medium 0 Low 1 Info

Code4rena

6 vulnerabilities found
0 High 2 Medium 4 Low 0 Info

Let's talk security

Open to protocol security research, audits, and collaboration.