About
I'm a computer scientist, security researcher, and CTF player based in Malta. My work focuses on blockchain security, smart contract auditing, and vulnerability research.
The Story
My journey into security has been... eventful. It includes getting arrested , charged , and subsequently pardoned for responsibly disclosing a security vulnerability in a popular student app. I told the whole story at 39C3 .
Current Work
Currently, I'm a Lead Security Researcher at OtterSec , where I lead audits of Solana validators (Firedancer, Agave and their derivatives) and run the Save CTFs Fund . Previously, I was a Senior Security Researcher at Dedaub , leading audits of the Ethereum protocol and EVM smart contracts, and before that I did R&D at ioLabs.
Talks & Research
- Save CTFs Fund , QuendCon 2026 closing keynote, with Robert Chen
- Hacking in the age of vibecoding , workshop at pwnEd 7 (2026)
- Precise Static Identification of Ethereum Storage Variables , ICSE 2026
- There is NO WAY we ended up getting arrested for this (Malta edition) , 39C3 (2025)
- Host more (Onsite) CTFs! , CSAW '25, with Robert Chen
- Transient Storage in the Wild: An Impact Study on EIP-1153 , Dedaub (2024)
CTF
I lead Friendly Maltese Citizens , which was #2 in the world on CTFtime in 2024 and won Google CTF 2025. In September 2025 we hosted MaltaCTF , Malta's first international CTF and mini-conference, in Valletta. I also won Malta's National Cybersecurity Challenge in 2024 and 2026, and write challenges for idekCTF and SekaiCTF.
Contact
You can reach me on Twitter , find my code on GitHub , or email me at mixy1@ctf.mt .