Kostas works on security audits and combines latest academic research and industry experience, integrating these insights into our in-house tool development.

Prior AuditHub and Veridise, Kostas’ research goal has been to aid developers in writing correct and efficient code by using a combination of program analysis and program synthesis techniques.

Kostas Ferles earned his Ph.D. from the University of Texas, Austin in December 2020, followed by a brief postdoctoral work. Throughout his time at UT, he worked under Işıl Dillig’s supervision and was a member of the UToPiA research group.

Prior to UT Austin, he received his B.Sc. and M.Sc. degrees (both in C.S.) from the University of Athens, Greece. During his master’s, he was working as a research assistant under the supervision of Yannis Smaragdakis.

Author articles

Security Analysis

How the AuditHub Approach Would Have Flagged Future Protocol’s $4.6M Bug: Pre-Mortem

A sell tax that reconciled a liquidity pool’s reserves mid-transfer, and the property that catches it regardless of the mechanism.
Security Analysis

How the AuditHub Approach Would Have Flagged Arcadia’s $3.5M Bug: Pre-Mortem

Arcadia lost $3.5M to a call it let its caller shape. How a custom static detector catches that pattern on every commit, before the code ships.
Security Analysis

How the AuditHub Approach Would Have Flagged Euler’s $197M Bug: Pre-Mortem

A custom detector pinpoints the single Euler function that shipped without the solvency guard every other path enforced.
Security Analysis

How the AuditHub Approach Would Have Flagged Beanstalk’s $182M Bug: Pre-Mortem

A live balance read let borrowed votes pass as real stake. How live-state fuzzing catches Beanstalk’s $182M drain before execution.
Security Analysis

How the AuditHub Approach Would Have Flagged Nomad’s $190M Bug: Pre-Mortem

Nomad’s validation logic had no bug. The value it checked against did. How a specification-guided fuzzing run catches a broken config on the chain itself.
AuditHub Announcements

Run AuditHub’s Security Tools From Your AI Agent

An open-source MCP server that connects Claude Code and Codex to AuditHub for static analysis and fuzzing runs.
Security Analysis

The Access Control Check That Let Every Caller Through

An inverted require in SuperRare’s staking contract passed for every caller; a static detector catches the shape automatically.
Security Analysis

How the AuditHub Approach Would Have Flagged Resupplyfi’s $9.6m Bug: Pre-Mortem

Static detector plus fuzzer, custom configured, surfaced the floored exchange rate before deployment. Same setup reproducible on your lending market.