Available for Engagements  |  josephvasapolli.com

Joseph Vasapolli Security Researcher & Rail Architect

Web security hunter. Banking infrastructure builder. Finding critical vulnerabilities in financial systems, building next-gen payment rails under CryptoFreight LLC — federally registered, CAGE 17ZE9.

CVE+
Disclosures
$0→∞
Bounty Scale
CAGE:
17ZE9 / SAM.gov
3rdCir
Active Litigation

Core Expertise

Where adversarial security thinking meets financial infrastructure engineering.

🔍

Web Application Security

Deep-dive penetration testing and vulnerability research across web platforms, APIs, and financial portals. Specializing in authentication flaws, injection vectors, and logic bugs in high-value targets.

OWASP Top 10 API Security Auth Bypass SSRF
🏦

Banking & Payment Rail Research

Architectural analysis of ACH, SWIFT, RTP, and blockchain-native payment corridors. Identifying protocol weaknesses and designing resilient, compliant transaction infrastructure.

ACH/SWIFT RTP Stablecoin ISO 20022

Blockchain & Smart Contract Audit

Solidity smart contract security review, LayerZero cross-chain bridge analysis, and Solana account validation. Real-world exploit simulation on forked mainnet environments.

Solidity LayerZero Solana Foundry
🤖

AI-Augmented Security Research

Multi-agent AI frameworks deployed for automated vulnerability discovery, threat modeling, and IP forensics. Inventor of the ZZ Elite Swarm multi-agent architecture.

Multi-Agent AI Ollama Forensics Automation
🛡

Defense & Federal Systems

Inventor of defense concepts including Shield Swarm drone mesh for Golden Dome initiative. SAM.gov-registered federal vendor building advanced security and AI tooling for government applications.

CAGE 17ZE9 SAM.gov DoD Concepts Drone Swarm
⚖️

IP Protection & Legal Tech

Forensic code fingerprinting, SHA-256 hash manifests as legal chain-of-custody evidence, and active federal litigation experience. Third Circuit No. 26-1553 / E.D. Pa. No. 2:26-cv-00917.

IP Forensics 3rd Circuit Chain of Custody E.D. Pa.

Finding What
Others Miss

Financial platforms, fintech APIs, and banking portals carry the highest-value attack surfaces on the internet. I specialize in logic vulnerabilities, authentication chains, and transaction-layer exploits that automated scanners never catch.

Responsible disclosure to program operators. Full write-ups, PoC code, and remediation guidance delivered with every finding.

  • CRIT Authentication bypass via JWT algorithm confusion in banking API gateways
  • HIGH IDOR vulnerabilities exposing transaction history across account boundaries
  • HIGH Race condition exploits in payment processing allowing double-spend
  • MED SSRF in webhook validators enabling internal network reconnaissance
  • MED Solidity reentrancy vectors in cross-chain bridge liquidity pools
vasapolli@sec-node:~/recon
./recon.sh --target fintech-api.target --mode deep
[*] Initializing scan engine v4.2...
[*] Resolving subdomains... found 47
[*] Fingerprinting tech stack...
[+] Stack: Node.js/Express · JWT · PostgreSQL

./auth-probe.sh --endpoint /api/v2/auth
[*] Testing JWT algorithm confusion...
[*] Testing alg:none bypass...
[!] CRITICAL — alg confusion accepted!
[!] Admin token forged successfully

./report-gen.sh --severity CRITICAL --poc
[*] Generating disclosure report...
[*] Attaching PoC code...
[✓] Report ready — responsible disclosure initiated
[★] Estimated bounty range: $15,000 – $50,000

Payment Rail Architecture

Building and securing the infrastructure that moves money — from legacy ACH to real-time blockchain corridors.

Real-Time Payments (RTP)

ISO 20022-compliant instant payment rail design. Sub-second settlement architecture with fraud scoring at ingestion.

Active Research
🔗

ACH & Wire Security

Vulnerability mapping of Nacha rule edge cases, Reg E exposure analysis, and originator authentication hardening.

Active Research
🌐

SWIFT & Correspondent Banking

SWIFT gpi security posture review, correspondent network attack surface analysis, and sanctions screening bypass research.

In Progress
🪙

Stablecoin & CBDC Rails

On-chain payment corridor design using LayerZero v2 cross-chain messaging, stablecoin settlement, and programmable compliance.

Active Development
🔐

Rail Security Auditing

End-to-end penetration testing of payment processors, gateway APIs, and financial message brokers. Threat modeling for money movement systems.

Accepting Clients
📦

CryptoFreight Platform

Proprietary crypto logistics & exchange platform with custom price-time priority matching engine and AI-powered trading advisor.

In Development

Published Work & Active Cases

Litigation 2026 · Active

Third Circuit No. 26-1553
E.D. Pa. No. 2:26-cv-00917

Active federal litigation in the Third Circuit Court of Appeals and Eastern District of Pennsylvania. Civil rights and intellectual property matters.

IP Research 2025–2026

Logic DNA Extraction & Code Forensics Framework

Forensic fingerprinting system scanning 100,557+ files generating SHA-256 hash manifests as legal chain-of-custody proof for IP theft detection.

Defense Tech 2025

Shield Swarm — Golden Dome Layer 4/5 Concept

Laser-powered autonomous drone swarm mesh for close-in protection of cargo vessels and aircraft. 8-ring, 8,640-segment mesh schema proposed for Golden Dome initiative.

Blockchain 2025

LayerZero v2 Cross-Chain Security Research

Deep audit of LayerZero v2 smart contract stack including DVN validation, ReadLib1002 security, and MultiSig attack surface analysis on forked mainnet.

AI Systems 2025–2026

ZZ Elite Swarm — Multi-Agent AI Architecture v2.1

Nine specialized AI agents with confirmation-gated System Agent for PC-level access. Migrated to local Ollama inference for air-gapped security research applications.

Theoretical 2026

PLL Mass Stability Theory

Novel framework connecting Element 126 nuclear physics, phase-locked loop mechanics, biological signal stabilization, and dark matter detection protocol research.

Work With Me

Available for bug bounty program partnerships, payment rail security assessments, smart contract audits, and federal/defense security consulting. CryptoFreight LLC — SAM.gov registered federal vendor.

CAGE 17ZE9
UEI MACTBWLKHT13
SAM.gov Registered Federal Vendor