Hire · Independent engagements

Simon Morley

Validator and exchange infrastructure security

I find the attacks that take a node off consensus without leaving a trace: no syscall, no log line, no alert. I reproduce them, and I build enforcement that runs at kernel ingress before the packet reaches userspace.

Twenty years running production networks. Four of them as CTO of a crypto exchange, through to acquisition. A year of technical due diligence for private equity investors.

[01]·Services

How to engage me.

01

Validator Fleet Exposure Review

10 days · Price on request
  • Your fleet mapped against the NRDAX technique registry.
  • The highest-severity applicable techniques reproduced against a staging node.
  • Kernel-level detection rules you keep.
  • A prioritised remediation list.
02

Infrastructure security advisory

Day rate on request

Architecture review, detection engineering, incident postmortems.

Exchanges, custodians, staking providers.
03

Fractional CTO / Head of Security

Day rate on request

For teams who need the function before they can justify the headcount.

[02]·Evidence

The work is public.

NRDAXPublic registry of node-resource attack techniques, reproduced first-hand across 39 chains. GitHub has attached NRDAX-T0205 to CVE-2023-39533.nrdax.com →On Earned AutonomyThe paper behind the enforcement model. DOI 10.5281/zenodo.18406828.doi.org/10.5281/zenodo.18406828 →SlashrLive validator risk surface, seven networks.slashr.dev →
[03]·Contact

Email me.

Tell me what you run and what you are worried about. No form, no gatekeeper.

[email protected]
London. Remote anywhere.