Work
Two systems I built and ran in production, then hackathon and bounty projects. The code for the first two is private; I'm happy to walk through the architecture in an interview.
- Chain-Fi — OAuth server, backend API and vault infrastructure
CTO · May 2024 – February 2026 · company closed in 2026
Chain-Fi was building non-custodial accounts: users keep their key on their phone, and third-party applications sign them in and ask them to approve transactions. That needed an identity layer for developers, and a vault where users hold assets without paying gas.
I wrote the OAuth 2.0 authorization server from scratch: authorization code and refresh token grants, opaque access tokens, refresh token rotation, revocation, nine scopes and a consent screen. Around it, I built application registration with client credentials and secret regeneration, a developer portal with per-app usage statistics, and the main backend: 87 REST endpoints on Express and PostgreSQL with raw SQL, packaged with Docker, and a GitHub Actions pipeline running unit and integration tests against Postgres and Redis. I also wrote the JavaScript SDK that third-party apps embed for QR-code login and signing requests over Socket.IO, and the React Native app that holds the user's device key and approves those requests.
On-chain, I wrote the vault and its factory in Solidity: each user gets a minimal-proxy clone (EIP-1167), and every withdrawal or transfer requires an EIP-712 signature. A relayer service checks the user's signature plus a second-factor signature, then submits the transaction from a server wallet that pays the gas; Stripe handles subscription billing. A Node.js listener follows vault activity on the Base, Arbitrum and Optimism testnets and pushes it to clients over WebSocket. The constraint throughout was non-custody: the backend never held a user key. The product ran on testnets until the company closed in February 2026.
- Smarteaming — B2B scheduling SaaS
Founder and sole engineer · 2020 – present · in production since 2020
Companies with shift-based teams were planning in spreadsheets and group chats, then re-entering the same data for invoicing and payroll. Smarteaming handles the whole chain: availability, schedules, shifts, invoicing, payroll, and Dimona declarations (Belgian employment registration).
I built and operate every part of it. The backend is a Node.js/Express API on MySQL with hand-written SQL, Socket.IO for real-time schedule updates, and scheduled jobs for reminders and notifications. The web app is built in React and TypeScript and available in English, French and Dutch. The iOS and Android apps are a React Native shell around the web app, with push notifications. Everything runs on a DigitalOcean server behind Nginx, managed with PM2.
It is a multi-tenant system run by one person: payroll and social-security data leave no room for silent errors, and every incident lands on me. It has been in production since 2020, with around ten client companies and several hundred users. It is now stable and in light maintenance. Operations are documented in a deployment runbook, a decision log and a findings tracker.
Hackathons and bounties
- GigShield — winner, Conflux Global Hackfest 2026
Escrow for freelance work, paid in stablecoins (USDT0, AxCNH). The client deposits the full amount; funds are released milestone by milestone, automatically after 7 days of client silence, or through a dispute decided by a 3-arbitrator panel voting 2 out of 3. One Solidity contract (OpenZeppelin, Hardhat tests with coverage) is deployed on Conflux eSpace mainnet, with a Next.js and viem frontend.
- Conflux AI Smart Contract Auditor — bounty
A service that audits Solidity contracts by combining an LLM review (Claude or GPT-4) with static analysis. I didn't write the analyzers: I integrated Slither and Mythril, each in its own Docker container, with multiple Solidity compiler versions. What I built is the service around them: the job pipeline, mapping findings to the SWC and CWE vulnerability classifications, batch audits from CSV, HMAC-signed webhook notifications, rate limiting, PostgreSQL with Prisma, Redis, a Next.js interface, and a Jest test suite.
- FluxSub — winner, Conflux Summer Hackfest 2025
On-chain subscriptions: merchants create plans, users subscribe, fund, pause or cancel, and get refunded automatically. Two Solidity contracts (FluxSub and its factory, built on OpenZeppelin) are deployed on Conflux mainnet, with a Next.js frontend and no backend.
- FluxPad — second place, Conflux AI Agent Hackathon 2025
AI agents that carry out on-chain tasks: token and NFT creation, voting, market analysis, social posting. The agents run behind an Express API, with OpenAI models, Conflux contracts and market data from GeckoTerminal. They are also available as Discord, Telegram and X bots running as separate processes. The mainnet contract suite is a decentralized exchange following the Uniswap V2 design (factory, pair, router), plus factories for tokens, NFTs and token locks.
- On-chain forum — Conflux Summer Hackfest 2025
A forum with no backend: posts, replies, likes, moderation, pagination and rate limiting all live in a single gas-optimized contract on Conflux eSpace, with content that can be hosted on IPFS. The React frontend follows contract events for live updates.
How I deliver
On every project, whether a job or a contract, the work comes with:
- a repository with reviewable pull requests
- deployment notes and a runbook
- architecture notes explaining the main decisions
- tests for the parts that matter
- monitoring and alerting in production