I develop program analysis, synthesis, and verification techniques to ensure the soundness and correctness of computation across diverse algebraic systems, including finite-field constraints in zero-knowledge proof systems (ZKP), nonlinear arithmetic in financial protocols, and cryptographic protocols.
I am also interested in the full lifecycle of LLM systems for coding tasks, viewing reliable coding capabilities as a foundation for increasingly general-purpose AI systems.
My work has been supported by Google Security, a16z crypto, and Ethereum Foundation.
Discovered 10 zero-day vulnerabilities on BNB Chain DeFi protocols using FORAY,
with verified exploit traces matching ≥$21M in historical loss patterns
(e.g., Discover).
ZKP
Discovered 14 zero-day vulnerabilities with BEAK (NDSS'27) while analyzing eight zkVMs:
Ceno,
Jolt,
Nexus,
OpenVM,
Pico,
Powdr,
RISC Zero, and
SP1,
as well as additional zero-day vulnerabilities in widely-used Circom projects using ZKAP,
including 0xPARC, Polygon-ZK, Axiom, iden3, and privacy-ethereum
(e.g., circom-pairing).
Invited Talks
Feb 2026
Tabby: A Synthesis-Aided Compiler for High-Performance Zero-Knowledge Proof Circuits
SoCalPLS, USC, Los Angeles, CA
Feb 2025
Tabby: Automated Programming of Efficient Zero-Knowledge Proof Circuits
ETHDenver, Denver, CO
Feb 2025
Practical Security Analysis of Zero-Knowledge Proof Circuits
SoCalPLS, UCSD, San Diego, CA
Oct 2024
FORAY: Towards Effective Attack Synthesis against Deep Logical Vulnerabilities in DeFi Protocols
ACM CCS '24, Salt Lake City, UT
Aug 2024
Practical Security Analysis of Zero-Knowledge Proof Circuits
USENIX Security '24, Philadelphia, PA
Grants & Awards
2024
Ethereum Foundation Academic Grant, Cybersecurity and Privacy Track Topic: Sentinel — Adaptive Counter-Attack Synthesis for Mitigating Onchain Exploits
Yu Feng, Hanzhi Liu, Hongbo Wen
2023
Ethereum Foundation Academic Grant, Formal Verification Track Topic: Financial Model-Driven Attack Synthesis for DeFi
Yu Feng, Yanju Chen, Hongbo Wen
This grant led to the development of FORAY (ACM CCS'24).
2022
Academic Excellence Fellowship, UC Santa Barbara
Experience
2024 – Present
Co-founder & Principal Architect, Riema Labs Led a 50-person engineering team through an AI-first development transformation,
shipping cross-chain bridges, Bitcoin-native ZK infrastructure, and user-custody wallet systems
serving 150K+ users.
2022
R&D Engineer, Veridise Inc. Smart contract and zero-knowledge proof security. Discovered 30+ critical vulnerabilities in widely-used ZK projects.