$ whoami

Hi, welcome!

I am Karolina, a Ph.D. candidate in cybersecurity at Télécom Paris and Ledger Donjon. My research combines formal verification methods with practical security engineering to address vulnerabilities in production systems.

// warning: rabbit holes ahead

Research Interests

When things are beautifully done, there is usually a well thought out sort of abstraction layers.

Jim Keller

// it works on my machine

My Current Main Project

ZORYA logo active

ZORYA

I'm the main developer of ZORYA, a concolic execution framework for binary-level vulnerability analysis, with a strong focus on Go binaries. Written in Rust, it initializes execution from real runtime state (CPU + memory dumps), translates code to Ghidra's low-level P-Code, and explores paths with concrete and symbolic values using the Z3 SMT solver.

View on GitHub
karolina@donjon:~/zorya

$ zorya tests/programs/crashme-go/crashme-go \

      --lang go --compiler tinygo --mode main

[zorya] init state from CPU + memory dump

[zorya] lifting to Ghidra P-Code

[zorya] solving paths (concrete + symbolic) via Z3

[found] nil pointer dereference  @ crashme.crash

[done]  results written to results/

$

// ship first, sleep later

Innovation & Prototyping

Applied research requires iteration between theoretical frameworks and empirical validation. Through competitive hackathons and collaborative prototyping events, I develop proof-of-concept implementations that test security hypotheses in constrained timeframes. This rapid experimentation informs my doctoral research by exposing practical limitations of formal methods, revealing emergent attack vectors in Layer 2 systems, and fostering interdisciplinary collaboration. The projects below demonstrate how theoretical security analysis translates into functional tools and protocols.

OnchainGuard logo

ETH Global Brussels 2024, Belgium

An onchain static analyzer for blockchain smart contracts

  • Nethermind Price – Best Security Driven Development
ProofTranslate logo

ZK Hack 2023, Istanbul, Turkey

The conversion algorithm of ZK proofs between the Polygon zkEVM system and the Scroll system.

  • Price for Best Idea on Polygon
GENI logo

ETH Denver Hackathon 2023, USA

The specifications' generator for security tests

  • Price for Best Developer Infrastructure/tooling on Mantle
  • Price for Best Developer tooling solution for Filecoin Virtual Machine
  • Price for Open Aurora Bounty
Open Climate Collabathon

Open Climate Collabathon 2019, HEC Paris

"Consumer Disclosure Contracts for Sustainable Supply Chain", based on Hyperledger

  • Award for the Most Innovative Contribution
  • Award of the Most Collaborative Team

// pics or it didn't happen

Events

Black Hat Asia Arsenal 2026
Black Hat Asia Arsenal 2026
EthCC[8] 2025
EthCC[8] 2025
Telecom Paris INFRES – My Thesis in 3 Minutes 2025
Telecom Paris INFRES 3rd price for "My Thesis in 3 minutes" 2025
KRYPTOSPHERE Blockchain Summit 2024
KRYPTOSPHERE Blockchain Summit 2024
Jury for Ledger Hackathon 2024
Jury for Ledger Hackathon 2024
VivaTech 2023
VivaTech 2023
Security Workshop with Gendarmerie Nationale, 2023
Security Workshop with Gendarmerie Nationale, 2023
WalletCon 2023
WalletCon 2023
Web3 Security Conference 2022
Web3 Security Conference 2022
Viva Technology 2022
Viva Technology 2022 – J. Herscovici, K. Gorna, A. Stachtchenko and E. Larchevêque
Inauguration of The Big Whale, June 10 2022
Inauguration of The Big Whale – June 10, 2022
KRYPTOSPHERE Blockchain Summit 2022
KRYPTOSPHERE Blockchain Summit 2022
KRYPTOSPHERE Internal Seminar 2021
KRYPTOSPHERE Internal Seminar 2021
First Stablecoins Meetup in Paris, 2020
First Stablecoins' Meetup in Paris, 2020
Meetup Invest in Crypto
Meetup "Invest in Crypto"
Open Climate Collabathon 2019
Open Climate Collabathon 2019
Paris Blockchain Summit 2019
Paris Blockchain Summit 2019