Proficiency bars are self-assessed and say so. The counts in the graph panel are not — those are rows in the database.
Select any technology to see how many projects, repositories and audits it appears in. Counts come from the database, so a technology with no work behind it reads zero.
Networks and on-chain primitives.
The settlement layer most of this stack targets — account-based state, EVM execution and the ERC standards every audited contract here is measured against.
A parallel-execution L1 with a rent-based account model. Programs are written in Rust and shipped through Anchor rather than the EVM toolchain.
The execution environment underneath Ethereum and its L2s. Reading it at the opcode and storage-slot level is what makes gas accounting and proxy collisions tractable.
On-chain programs treated as production systems: upgrade paths, access control and invariants specified before a line of implementation gets written.
Lending, staking and AMM mechanics — constant-function market makers, the Compound and Aave interest models, Set Protocol-style tokenised baskets — where economic design and contract design stop being separable and the oracle assumption decides solvency.
The client half of a protocol: wallet connection, transaction lifecycle and RPC handling that turn a deployed contract into something a browser can use.
The whole deliverable rather than the contract alone — a front end, an indexer and a wallet flow wrapped around on-chain state that no single party controls.
Representing an asset, a claim or a right as a token: supply policy, transfer restrictions and the accounting that has to survive a secondary market.
The asset layer itself — issuance, custody and the transfer semantics that every compliance and analytics question above it ultimately resolves to.
The property everything else is judged against: who can pause it, who can upgrade it, and how many keys have to agree before users lose a guarantee.
Consensus, finality and Byzantine fault tolerance underneath the application — the part that decides what a confirmation is actually worth.
Solana's payment request standard — QR-encoded transfer requests and reference-keyed confirmation, used for the Magento crypto-checkout plugin.
System design across the boundary: what lives on chain, what stays off it, how the two stay consistent, and which upgrade path the contracts leave open.
Frameworks, runtimes and toolchains.
The App Router build this site runs on — server components, server actions and incremental revalidation, with data fetched in the server tree rather than the client.
The component model behind every interface here: hooks, suspense boundaries, and a strict line between the server tree and what ships to the browser.
Solana's program framework — account validation, IDL generation, and the constraint macros that keep instruction handlers from trusting their inputs.
The JavaScript-side contract workflow: deployment scripts, mainnet forking for realistic tests, and custom tasks run against any EVM network.
Solidity-native testing — forge fuzzing and invariant runs, gas snapshots between commits, and cast for reading live contract state without leaving the terminal.
The older EVM toolchain — migrations, Ganache networks and its artifact format, still the thing an inherited 2021-era repository is built on.
The server runtime behind the indexers, webhook handlers and deployment scripts that sit between a contract and everything that talks to it.
The minimal HTTP layer used for API surfaces in front of chain data — routing, middleware and not much else, which is the point.
Cross-platform UI toolkit for mobile builds, where a single widget tree and one render pipeline cover both stores.
Infrastructure, data and delivery.
Reproducible environments for databases, chain nodes and CI jobs — the same image locally as in the pipeline, so a green run means the same thing in both places.
The database behind this site: relational modelling, indexes chosen for the queries that actually run, and migrations kept under version control beside the code.
The document store on the Node side of earlier builds — good for event and indexer output whose shape is still moving, and honest about what it gives up.
Schema-first data access — a typed client generated from the model, so a renamed column breaks the build instead of a page in production.
The deployment target underneath all of it — Ubuntu for servers and containers, Red Hat for the RH 124 system-administration track: shell, systemd, networking and the filesystem habits that keep a remote box debuggable at 2am.
Version control as an audit trail — small commits, readable history, and GitHub for the review surface on top of it.
CI and delivery — test matrices, contract compilation and lint gates on every pull request, and deploy workflows that trigger on merge.
The regulatory surface around a digital-asset product — the part that decides whether it can ship.
Mapping a token, a treasury or a platform onto the obligations that apply to it, and building the controls and evidence trail a supervisor will ask for.
Automating that surface: rule-driven screening, reporting and monitoring, so compliance is a system property rather than a quarterly scramble.
Typologies, sanctions and mixer exposure, and the ongoing monitoring that turns a one-off screen into a control someone can actually rely on.
Identity at the edge of the protocol — onboarding checks, wallet attestation and the awkward question of what a verified address is still allowed to do next.
Turning scattered signals — contract behaviour, counterparty exposure, incident history — into a position someone can make a decision from.
Where payment rails, custody and market structure meet the protocol — the constraints that decide what a digital-asset product is allowed to do.
The consulting half — scoping, architecture and the estimate someone has to sign.
Translating between founders, engineers and stakeholders who do not share a vocabulary, and writing down the decision so it survives the meeting.
Delivery inside an organisation that already has systems, procurement and an audit function — where integration constraints outrank the interesting problem.
The off-chain half of a protocol product: services, data flow, caching and the failure modes that decide what a user sees when an RPC is down.
Scope, cost and schedule stated with their assumptions attached — including the ones that would make the number wrong.
Choosing what not to build: the smallest thing that proves the protocol is worth having, and the order the rest of it arrives in.
Turning a business requirement into an architecture, a roadmap and an honest answer about whether a chain belongs in it at all.
System design across the boundary: what lives on chain, what stays off it, how the two stay consistent, and which upgrade path the contracts leave open.
The five headline skills. Each one is cross-listed into the category it belongs to further down the page.
Turning a business requirement into an architecture, a roadmap and an honest answer about whether a chain belongs in it at all.
System design across the boundary: what lives on chain, what stays off it, how the two stay consistent, and which upgrade path the contracts leave open.
Where payment rails, custody and market structure meet the protocol — the constraints that decide what a digital-asset product is allowed to do.
Reconstructing what happened on chain after the fact: fund flows, counterparties and the address clusters that connect them.
Scoring a protocol before it costs anything — contract-level exposure, centralisation, oracle assumptions and the operational risk around the keys.
Programming languages, on chain and off.
The primary contract language here — ERC-20/721/1155 implementations, proxy patterns, and the storage-layout discipline upgradeable contracts demand.
Used for Solana programs and off-chain tooling, where ownership rules and exhaustive matching remove a class of bugs before the compiler is finished.
The default language off-chain: application code, deployment scripts and test suites, with types carried end to end from database schema to component prop.
The runtime underneath the TypeScript, and still the shortest path to a one-off RPC script, a build hook or anything that has to run in a browser unbundled.
The language the security tooling is written in — Slither detectors, Mythril runs, and the analysis scripts that turn raw audit output into a readable table.
Roku's channel language, used for set-top application work: SceneGraph components, the observer model, and the event loop that drives them.
Android application work — coroutines for concurrency, null-safe models, and the Jetpack surface built around them.
The language behind the Flutter work: one typed codebase compiled ahead of time to both mobile targets.
The surface a person actually touches — Web3 clients, front ends and the design work around them.
The original Ethereum client library, and the one most of the earlier DApp work here connects through: provider setup, contract bindings and event subscriptions.
The leaner alternative — typed contract factories, signer abstraction and transaction handling that surfaces a revert reason instead of swallowing it.
The HTTP client in front of RPC endpoints, explorer APIs and indexers — interceptors for retries and rate limits, which chain data reliably needs.
Document structure taken seriously: landmarks, labels and headings that decide whether an interface is navigable without a mouse.
Utility-first styling with the design tokens kept in one place, so a theme change is a variable edit rather than a sweep through stylesheets.
Building the client: component structure, state, responsive layout and the interface design decisions that come with it.
Owning a feature from schema to screen — web development where the database, the API and the interface are one change, not three handoffs.
Theme and plugin work, design through to deployment — the pragmatic answer when a client needs a site they can edit themselves.
Avatar-driven 3D environments as a front end — used for the EtihadWE assistant, where the same bot answered in a browser and in-world.
Products with a model in the loop — voice and text prompting, retrieval against the site's own content, and a fallback for when the model is wrong.
Raster work for product and brand assets — the older craft underneath the handle, still useful when an interface needs artwork rather than a component.
Vector work: marks, diagrams and the icon sets that ship into an interface as SVG rather than as a screenshot.
Smart contract security — the practice and the tooling.
The threat classes themselves: reentrancy, access-control gaps, unchecked external calls, fund-handling and arithmetic errors, and the upgrade paths that quietly reintroduce all of them.
The engagement around that: scoping against a verified deployment, manual review, tool sweeps, and a written report with severity, impact and remediation for each finding.
Reading a contract without running it — control and data flow, inheritance linearisation and storage layout, which is where most findings start.
Static analysis over Solidity: detector sweeps as the first pass on any review, printers for call graphs and inheritance, and custom detectors when the built-ins miss.
Symbolic execution against EVM bytecode — used to reach states fuzzing has not, and to prove a suspected path is genuinely reachable before it goes in a report.
Property-based fuzzing: invariants written as Solidity assertions, then run until a counterexample turns up or the corpus stops finding new ground.
Specification annotations compiled into runtime assertions, so a property written in a comment becomes something the fuzzer can actually break.
Audited base contracts and the upgrade tooling around them, used as a reference implementation as much as a dependency — deviations from it are worth explaining.
A level below the contract: hash functions and cryptography, consensus and Byzantine fault tolerance, node and network attacks, and what layer-2 designs change about all of it.
The conventional half — information security, access control and least privilege, hardening and incident response — because most key compromises never touch a contract.
Solidity-native testing — forge fuzzing and invariant runs, gas snapshots between commits, and cast for reading live contract state without leaving the terminal.
Scoring a protocol before it costs anything — contract-level exposure, centralisation, oracle assumptions and the operational risk around the keys.
Reading the chain as evidence rather than as a feed.
Decoding transactions, events and contract calls into something with a shape — volumes, flows and behaviour that hold up when someone checks them.
Behaviour at the address level: funding patterns, holding periods, contract interactions, and the heuristics that group addresses into one actor.
Following funds hop by hop through bridges, mixers and exchange deposits until the trail either ends or reaches something with a name attached.
The same work continuously rather than retrospectively — thresholds, alerting and the tuning that keeps a rule useful instead of noisy.
The habit underneath the tooling: state the question, decide what would answer it, and say plainly how confident the answer is.
Reconstructing what happened on chain after the fact: fund flows, counterparties and the address clusters that connect them.
Scoring a protocol before it costs anything — contract-level exposure, centralisation, oracle assumptions and the operational risk around the keys.