Worrachatr Phoonbamphen
Worrachatr PhoonbamphenApp developer & independent penetration tester · Chiang Mai, Thailand · remote worldwide
App development · Penetration testing · Smart-contract audit · Security research

I build software and make it secure.

I build production mobile and web applications end to end: data model, backend, the apps themselves and the App Store and Google Play release. I also test web applications, APIs, smart contracts, blockchain infrastructure and AI/LLM features the way a real adversary would: manual, hypothesis-driven, and proven with a working proof-of-concept. Every security engagement ends in a report you can hand to engineers and auditors, so you can hire me to ship the product as well as to break it.

96
bug-bounty & audit programs engaged across 18 platforms
18
platforms — HackerOne, Bugcrowd, Immunefi, Cantina, Sherlock, HackenProof, CertIK, Google VRP, Meta…
19
public research summaries you can open on this page
5
target classes: web/API, EVM, Solana, Cosmos/Substrate, AI agents
Services

What I do

Two practices, one person. Hire me to test what you have built, to build something new, or both, since the cheapest security fix is the one designed in from the start.

01

Development

Mobile and web products shipped end to end, with the security basics built in rather than bolted on. Portfolio · Rates

Mobile apps

iOS and Android from one React Native / Expo codebase, through App Store and Google Play review.

  • Auth (phone OTP, Google, LINE), maps and live tracking
  • Chat, push notifications, payments, receipts
  • Camera, OCR and identity-verification flows
  • Bilingual UI, offline-tolerant data layer

Web apps & dashboards

Customer-facing web apps, admin consoles and marketing sites in Next.js / React and TypeScript.

  • Admin dashboards for approvals, bookings, KPIs
  • Static-exported sites for speed and low hosting cost
  • Route-based localisation (TH / EN)
  • Accessible, theme-aware, mobile-first UI

Backend & cloud

Serverless backends on Firebase / Google Cloud with least-privilege rules and secrets handled properly.

  • Firestore data models and security rules
  • Cloud Functions, scheduled jobs, webhooks
  • Stripe, SMS and email pipelines, AI assistants
  • CI/CD, release signing, monitoring
02

Security testing

Fixed-scope, fixed-price. Findings report with severity, reproduction, proof-of-concept and remediation, plus a free retest. Rates

Web application & API penetration test

Black-box or grey-box testing of production or staging systems against OWASP Top 10 and beyond.

  • Authentication, session, SSO / SAML / OAuth flows
  • Authorization: IDOR, multi-tenant boundaries, privilege escalation
  • Business-logic abuse, approval and payment workflows
  • REST, GraphQL, WebSocket and gRPC surfaces

Smart-contract security audit

Manual review with invariant-first analysis and fork-tested proofs-of-concept.

  • Solidity / EVM (lending, vaults, AMMs, bridges, staking)
  • Solana / Anchor (Rust), CosmWasm, Cadence, FunC
  • Economic attacks, rounding, reentrancy, signature replay
  • Upgradeability, proxies, diamonds, governance timelocks

Blockchain infrastructure review

The layer most audits skip: nodes, RPC namespaces, bridges, relayers and consensus code.

  • L1 / L2 clients, precompiles, custom RPC methods
  • Cross-chain bridges, message verification, DVN config
  • Validator signing services and key handling
  • ZK circuit soundness (Plonky2, recursion pinning)

AI / LLM application security

Assessment of assistants, agents and RAG pipelines that touch private data or take actions.

  • Prompt injection & data exfiltration (direct and indirect)
  • Tool / agent authorization scope and side-effects
  • MCP servers, OAuth 2.1 / DCR flows
  • Guardrail evasion and grounding-channel leaks
Development portfolio

Applications I have built

Security-minded full-stack development. I design the data model, write the backend rules and functions, build the apps, get them through App Store and Play review, and keep them running.

FixIt — on-demand home repair & services marketplace

Thailand · iOS, Android and web · 2026 · fixitth.com · first venture of Phenovative Co., Ltd.

Customers book identity-verified repairmen, technicians and service professionals at a fixed, published price, then follow the job live on a map from accepted to paid. Partners apply in-app, pass ID-card and background checks, and manage jobs, earnings and warranty from their own side of the same app. Built solo, from first commit to store submission, in about ten weeks.

  • One codebase, three platforms. React Native / Expo (Expo 57, React 19, TypeScript, expo-router) for customer and partner roles, exported to web and submitted to the App Store and Google Play. Bilingual Thai / English.
  • Serverless backend. Firebase Auth (phone OTP, Google, LINE), Firestore with 2,000+ lines of security rules, and 62 Cloud Functions modules: job pool and matching, scheduling, live tracking with shareable trip links, chat, receipts and PDF generation, warranty, referrals, Stripe fee handling, SMS follow-up drips.
  • Trust & safety pipeline. Thai ID-card OCR, selfie face-match, duplicate-identity detection, citizen-ID and phone reservation, criminal-record policy, App Check and device-trust for new-device sign-in.
  • AI features. "Fixie" assistant that triages a free-text problem into the right category, and an AI support bot backed by the same function layer.
  • Operations. Web admin dashboard for approvals, bookings, KPIs and SMS campaigns; Codemagic CI for iOS, local signed Android builds; automated store-screenshot capture; Playwright end-to-end tests against the auth flow.
React NativeExpoTypeScriptNext.jsFirebaseFirestore rulesCloud FunctionsStripeMapsOCR / face matchLLMApp Store / Play
FixIt home screen FixIt service categories FixIt live job tracking FixIt inbox and chat

Phenovative company site

Next.js 16 · React 19 · Tailwind v4 · static export · Firebase Hosting

Bilingual TH/EN venture-studio website with route-based localisation, typed copy dictionaries and a static build that survives without JavaScript. phenovative-web.web.app

This site

Hand-written HTML/CSS/JS · Firebase Hosting · in-page PDF viewer

Zero-framework, theme-aware, filterable portfolio with deep-linkable report viewer and strict response headers. Loads in one request.

Security tooling

Python · Node · Playwright · Foundry · Anchor

Custom recon and API-surface mappers, JS-bundle miners, fork-based exploit harnesses and PDF report generators used across the 96 engagements above.

Track record

Past recon & audit engagements

Every engagement below ran under an authorized bug-bounty or audit-competition program. Click a card to read the research summary. Reports were issued under my research label, Phoenix5981 Security. Engagements still under vendor review are listed without identifying detail.

Nothing matches that filter.

Outcome labels are the platform's verdict, not mine. "Duplicate" means the vendor confirmed the issue but another researcher reported it first; "Known issue" means the vendor already tracked it internally. Both are listed because the finding was real and demonstrated. Zero-finding engagements are published too: knowing what was tested and cleared is a deliverable.

Method

How a project runs

01

Development

From scope to store release, one person accountable end to end.

Discovery & scope

A short call, then a written scope: users, screens, data, integrations and what is out. You get a fixed price per milestone before any code is written.

Design the data model

Screens as a clickable prototype, with the database structure and security rules designed together, so permissions are built in rather than patched later.

Build in milestones

Working software at every milestone, deployed to a test link you can open on your phone. Code lives in your repository from day one.

Test & security review

Automated checks, real-device testing and a pentest of the finished product by the person who built it, before real users arrive.

Launch & handover

Production deploy, App Store and Google Play submission, admin access, documentation and a handover session. A maintenance retainer is optional.

What you receive

  • Source code in your own repository, with its commit history
  • A live web app and/or iOS and Android apps, including the store listings
  • An admin console for your team
  • Database security rules and a pentest report of the finished product
  • Documentation, credentials handover and a training session

Tooling & stack

  • React Native / Expo: iOS, Android and web from one codebase
  • Next.js, React, TypeScript, Node.js
  • Firebase: Auth, Firestore with security rules, Cloud Functions, Hosting
  • Stripe / PromptPay, Google Maps, Google Cloud Vision OCR, Anthropic Claude
  • Codemagic and signed store builds, Playwright end-to-end tests
02

Security testing

Authorised testing, proven findings, one free retest round.

Scope & threat model

Map every entry point, trust boundary and privileged role before touching a payload. Read prior audits and known issues first so effort goes to the un-audited delta.

Recon

Subdomain and host enumeration, JavaScript bundle mining, API surface extraction (typically 150 to 300 endpoints per target), commit-history analysis for code targets.

Manual testing

Hypothesis-driven, checklist-backed testing: auth and session, authorization boundaries with two independent tenants, business logic, economic invariants, signature schemes, boundary arithmetic.

Prove it

Every reported issue ships with a minimal proof-of-concept run from the attacker's position, on a fork or an isolated test tenant, that demonstrates the impact rather than the defect.

Report & retest

Severity with dollar or data impact, reproduction steps, root cause, specific remediation. One free retest round once fixes land.

What you receive

  • Executive summary for leadership and auditors (SOC 2, ISO 27001 evidence)
  • Technical findings with CVSS or platform-standard severity, CWE references
  • Working proofs-of-concept (scripts, requests, Foundry / Anchor tests)
  • Coverage statement: what was tested, what was cleared, what was out of reach
  • Retest letter confirming remediation

Tooling & stack

  • Burp Suite, custom Python tooling, headless-browser instrumentation
  • Foundry, Anchor, Solana CLI, Substrate, Sourcify bytecode-vs-source checks
  • Fork-based exploit simulation for EVM and Solana
  • Static + manual review of Solidity, Rust, Go, TypeScript, CosmWasm, Cadence, FunC
  • OWASP Top 10, OWASP Smart Contract Top 10, CWE Top 25 as baselines
Engagement & rates

Packages and hiring rates

Fixed price per job, agreed after a 30-minute scoping call. Prices are in USD; invoices can be issued in USD or THB.

01

Development

Priced per milestone, with the code in your repository from day one.

Discovery & prototype

from $2,500

1–2 weeks

Data model, the key screens as a clickable prototype, a backend plan and a fixed estimate for the build.

MVP

from $6,000

4–6 weeks

One platform (mobile or web) with its backend and admin basics, ready for real users.

Full product

from $15,000

8–12 weeks

iOS + Android + web + backend + admin console, including store submission and a security review of the result.

Maintenance retainer

from $1,200 / month

up to 4 days per month

Releases, monitoring, bug fixes and small features for an app you already run.

Development rate card
Hourly$45 / hour, 10-hour minimum block
Day rate$350 / day
Payment termsMilestone-based: 30% on kickoff, then per milestone. Bank transfer, Wise, or USDC. Code delivered in your repository from day one.

Every build ships with the security basics done properly: least-privilege database rules, server-side validation, secrets kept out of the client, and a pentest of the finished product at no extra charge.

02

Security testing

Fixed scope, fixed price, one free retest round.

Web / API pentest

from $2,500

5–10 days · typical $2,500–5,000

One application or API surface, grey-box with test accounts. Best for SaaS, fintech dashboards, exchanges and marketplaces before a launch or compliance audit.

Smart-contract audit

from $4,000

1–3 weeks · scoped by lines of code

Manual review with invariant definition, fork-tested PoCs and a fix-review round. Suitable as a second opinion after a primary audit. Indicative: $4k for up to ~1,000 lines, $8–15k for a full protocol.

Pre-launch security sprint

from $8,000

2–4 weeks

Contracts + backend + frontend + AI features together, since real attacks chain across them. Includes bug-bounty scope and policy drafting.

Retainer

from $2,000 / month

up to 5 days per month

Continuous review of releases, PR-level security review, incident triage and on-call reproduction of externally reported bugs.

Security rate card
Day rate (time & materials)$450 / day
Hourly (advisory, code review, triage)$60 / hour, 4-hour minimum
Retest of fixed findingsIncluded, one round within 60 days
Rush (start within 48 hours)+25%
Pay-per-finding optionBug-bounty style: no upfront fee, paid per validated finding by severity. Ask for the schedule.
Payment terms50% on kickoff, 50% on report delivery. Bank transfer, Wise, or USDC.

All testing happens only against systems you own or are authorized to have tested, under a signed statement of work and NDA. Prices exclude VAT where applicable.

About

How I got here

I spent eighteen years in industries where mistakes are expensive before I wrote software for a living. From 2004 to 2011 I was an engineer in precision electronics manufacturing: R&D engineer at Fujitsu (hard-disk drives, 2004–2005), process engineer at Delta Electronics (PCB assembly, 2005–2006) and Nidec (electric motors, 2006–2007), maintenance engineer at Rohm Integrated (semiconductors, 2007–2009), quality engineer at Sony (DSLR cameras, 2009–2011). From 2011 to October 2022 I was a flight dispatcher at Thai Airways International — planning and releasing commercial flights, and making time-critical calls inside a safety-critical regulatory framework. Both are worlds where a silent failure is the expensive kind and nothing counts until it is verified against the real article.

In 2022 I started teaching myself software, beginning with Java through Coursera, freeCodeCamp and open courseware, then JavaScript and TypeScript, React and React Native, Node.js, data structures and cloud architecture. By 2026 that had turned into shipped work: FixIt, a two-sided home-services marketplace I designed and built alone and released on iOS, Android and the web, and, since May 2025, a security practice running authorised engagements on 18 bug-bounty and audit platforms. The two feed each other — testing other people's systems changed how I build my own, and building production systems is why my reports come with remediation an engineering team can actually apply.

Timeline: BEng Electrical Engineering, KMUTNB (1999–2003) · electronics manufacturing engineering (2004–2011) · flight dispatch, Thai Airways International (2011–2022) · self-directed software study from 2022 · independent software and security practice since May 2025.

Worrachatr Phoonbamphen
Contact

Let's scope your test.

Send a short description of the system, the tech stack and your deadline. I reply within one business day (UTC+7).

willworachat@gmail.com
Chiang Mai, Thailand · remote engagements worldwide
Co-founder & CEO, Phenovative Co., Ltd.
Response within one business day