KHASBI.M

Khasbi Maulana
Open to opportunities

Khasbi Maulana

Full-Stack Developer building Web3 agents,
secure smart contracts, and onchain products.

Full-Stack Dev Web3 Builder Security Researcher

Builder. Researcher. Shipper.

I'm a Full-Stack Developer focused on Web3 infrastructure, AI agents, and smart contract security.

Creator of web3-agent-kit — an open-source Python SDK for autonomous blockchain AI agents, with 22,000+ PyPI downloads and 1,971 tests across 9 chains.

I work across the stack: Python for AI/ML backends, TypeScript/React for interfaces, Rust/Go for performance tools, and Solidity for smart contracts.

Active security researcher. I've audited DeFi protocols, found critical vulnerabilities, and earned bug bounties from Immunefi and Bugcrowd.

Selected Work

Flagship
Open Source Python PyPI

Web3 Agent Kit

Python SDK for autonomous blockchain AI agents. 25 modules, LLM provider cascade, multi-chain support, and 1,971 passing tests. v1.18.5 registers Base Sepolia as a first-class chain and ships the WAK/Insight/PriorSeal conformance spike, on top of the enforced pre-sign authorization gate on every write path.

PythonWeb3.pyLLMMulti-ChainPolicy Gate
Peer Review
Integration Security Cross-Team

Web3 Agent Kit × PriorSeal

Independent four-round review of the pre-sign authorization gate with a live counterparty. Four defects found and closed, ending in a verified cross-network run: signed oracle assessment → policy → principal authorization → exact-call execution → onchain verification.

PythonMoveTypeScriptBase SepoliaExact-Call Auth
Hackathon DeFi Full-Stack

QIEPay

Decentralized payment gateway on QIE Blockchain — crypto payments with escrow, auto-settlement, POS mode, and analytics.

ReactSolidityethers.jsNode.js

Technical Stack

Languages

PythonTypeScriptRustSolidityGoJavaScript

Web3

Smart ContractsDeFiethers.jsWeb3.pyCross-chainWallets

AI / ML

Multi-AgentLLM PipelinesRAGCode AnalysisAutomation

Frontend

ReactNext.jsTailwindHTML/CSSVite

Backend

FastAPINode.jsPostgreSQLRedisREST APIs

Tools

Git / GitHubDockerLinux / VPSCI/CDHardhat

Security Research

Critical OnRe Finance

Exposed Spring Boot Actuator gave full access to MMBot infrastructure, logger modification, and trading strategy leak. $180M TVL at risk.

Critical PerpX

API security vulnerability on a perpetuals trading platform. Reward increased to $400 with a bonus after the initial report.

High Peanut

Responsible disclosure on self-custodial payments infrastructure — global digital-dollar transfers with no custodial intermediary.

Critical Trocador

Two live exchange API keys found leaked in public wallet-app repositories, plus a quote markup parameter that accepted out-of-range values — a $626 quote reduced to $6.21.

Critical KieDex V2

Futures backend trusted client-supplied entry and exit prices — arbitrary PnL and platform volume minted from a single account. Social-reward and fee-deduction bypasses found in the same API.

Critical Amp Pay

Admin API reachable by any registered account: platform metrics, high-value card transactions, and mass-notification endpoints had no server-side role check.

Critical KausaLayer

Unauthenticated private key export on all user wallet pockets. Full attack chain proven: scan pockets, export keys, sweep funds.

High Modulo Finance

Firebase Admin SDK custom token leaked via unauthenticated API — full account takeover, email flooding, and persistent access.

High Aiven

Production source map exposure on console.aiven.io — 2,642 files, 21MB, leaking OAuth secrets and internal API routes.

Medium Vultr

Production source map and Sentry exposure on cloud console infrastructure.

Medium MultiHopper

CORS misconfiguration and undocumented endpoint exposure on an agentic platform.

Grant Superteam Earn

Agentic Engineering grant, funded for open-source agent infrastructure work.

Notes & Articles

Open Source

Building Web3 Agent Kit

From architecture decisions to PyPI release — how I built a production-grade Python SDK with automated testing and LLM integration.

Read on GitHub →
LinkedIn

5 Lessons from 20+ Web3 Bots

What failed automation bots taught me about building in public, landing clients, and why your portfolio matters more than your code.

Read on LinkedIn →
Security

DeFi Security Research

Auditing DeFi protocols, finding vulnerabilities in smart contracts, and responsible disclosure through bug bounty programs.

View Research →

On-chain & Community

🔗

Cross-chain Ecosystems

Active across Base, Arbitrum, Optimism, Celo, Solana, and Sui — bridges, swaps, airdrops, and onchain interactions.

📝

Smart Contract Development

Deployed 9+ verified contracts. ERC-20, ERC-721, and custom DeFi patterns including swaps and token interactions.

🛡️

Security Research

Bug bounty hunter — found vulnerabilities in Solana privacy protocols and multi-chain DeFi aggregators through responsible disclosure.

👥

Mancing DAO

Web3 community focused on airdrop farming, testnets, and ecosystem updates. Regular content on DeFi and security.

t.me/mancingdao →

GitHub Contributions

GitHub Contribution Graph

@ulsreall on GitHub

Let's build something together.

Open for full-time roles, freelance projects, Web3 development, and security research collaborations.

Email copied.