I will review your cryptographic implementation for security flaws

N
nalbarualexandr
N
nalbarualexandr
NamasteAlex

About this gig

Cryptography fails silently, and when it fails it is catastrophic.


I am an independent security researcher who reviews cryptographic implementations for the flaws automated tools miss: signature checks that fail open, nonce and IV reuse, non constant time comparisons, weak or predictable key generation, padding oracles, and misuse of libraries like OpenSSL, libsodium, or the Node and Python crypto modules.


What you get:

  • A focused manual review of your signing, encryption, key handling, and token logic
  • - Every issue rated by severity, with the exact file, line, and failure condition
  • - A working proof of concept for real issues, not theoretical hand waving
  • - A corrected construction you can drop in, with test vectors where useful
  • - A re review after you apply fixes (Standard and Premium)

Languages: JavaScript and TypeScript, Python, Go, Java, PHP, C, C plus plus, and Rust. Your code stays strictly confidential.


Message me with your repo or the specific crypto code before ordering and I will confirm scope and the right package.

Get to know NamasteAlex

NamasteAlex

Offensive security researcher, secure code review and Web3 audits

  • FromRomania
  • Member sinceOct 2017
  • Avg. response time1 hour
  • Languages

    English, Romanian
Offensive security researcher and bug-bounty hunter (HackerOne, Bugcrowd, Intigriti, YesWeHack) with validated High/Critical findings: broken access control (IDOR/BOLA), SSRF, authentication/OAuth, and cryptographic-implementation flaws. I do manual secure code review and smart-contract/Web3 audits - finding the exploitable bugs that scanners miss - and deliver clear, developer-ready reports with reproduction steps and fixes. Every finding is proven, not guessed. Send me your code or contract and let's lock it down.

My Portfolio

Other Software Development Services I Offer