[ 01 ]Available for builds, audits, conversations

Nicklas Reiersen

I build the boring infrastructure decentralized storage networks need to survive. I find the bugs everything else trips over. Protocol engineer and security researcher, founder of two products, designer and marketer by training. Eight years inside Filecoin, 200+ vulnerabilities disclosed last year, 5 PiB of storage in production today.

BasedNorway · Denmark
DatacenterMiami, FL
Tax-IDTSE Reiersen · 929074912
Nicklas Reiersen
Vol. MMXXVI · Oslo → Miami
8+ years
In Filecoin
since pre-launch
200+
Vulnerabilities
disclosed (last 12mo)
22 envs
Calibration test
environments operated
5 PiB
Storage managed
on Filecoin today
"

Every decentralized storage network dies the same way: someone has to own the unglamorous middle. The sealing pipeline at 3 AM. The faucet nobody funds. The migration when the protocol changes under your feet. The stability work that's only visible when it breaks. I own the unglamorous middle. The flashy parts ship themselves.

About

A design degree, a marketing master's, an early Ethereum bag, a sunglasses brand, and somewhere along the way a deep specialty in Filecoin protocol work.

Skills

What I actually do

Filecoin protocol depth. Lotus, Boost, Curio internals. SNARK / PoRep math. Sealing pipeline, GPU proving (CUDA), FEVM, calibration network operations, IPLD / CBOR / FRC encodings, libp2p, on-chain state.

Engineering. Go and Rust at protocol level. TypeScript and Node for product. Solidity and viem on the EVM side. Python for ops glue. Distributed systems, control-plane design, multi-machine cluster architecture.

Infrastructure. Linux, systemd, nginx, Caddy, SSH tunneling, Cloudflare (Pages, Workers, Turnstile, DNS), Hetzner, datacenter hardware. Hardened deploys, observability, on-call ops.

Security research. Web, API, mobile, and crypto-stack auditing. RNG / provably-fair, ATO chains, IDOR and auth-flow analysis, wire-protocol reversing, responsible disclosure. Comfortable with both attacker and defender posture.

Design and brand. Graphic design (NKF) plus marketing master's (BI). Brand systems, landing pages, dashboards, technical writing. Things that ship look like things that ship.

AI fluency. Working expert across Claude, GPT, Gemini, Llama, Mistral, DeepSeek. Agent orchestration as a real discipline, not a demo. AI woven into research, code, security tooling, and operational decision-making.

2025+

CC Security & independent products

Founded CC Security to do the iGaming and crypto-stack security research the existing audit shops weren't doing well. Started Nøytral and Swopa on the side because Norway needs better civic-tech and better local-community infrastructure than the marketplace template every other Nordic startup ships.

2020

Started shipping code

Pandemic gave me the time. Always had the interest in compute, finally had the runway to learn the engineering side properly. From hobbyist scripts to protocol-level contributions in roughly four years.

2016

First Ethereum position

Started paying attention to crypto early. Got the entrepreneurial side and the protocol side at the same time, which is part of why I work where I work now.

2013 – 2017

ShadyFruits

Solo e-commerce brand selling sunglasses. Sold over 30,000 pairs before closing it down. Lessons in sourcing, brand voice, paid social before paid social was easy. @shadyfruits

2009 – 2015

Graphic Design (NKF), Master in Marketing (BI)

Norges Kreative Fagskole for the design fundamentals, BI Norwegian Business School for the master's. Two languages of the same problem: how to make people care about something on purpose.

Now

One flagship inside the Filecoin protocol, one independent security firm, two products of my own. Each one is here because I'd rather build it than wait for someone else to.

Curio Storage
Core contributor · 2024 → 2026

The next-generation storage stack for Filecoin storage providers. A complete rewrite of the legacy Lotus and Boost pipeline as a multi-machine cluster architecture. I work on protocol internals, sealing pipeline performance, GPU-accelerated PoRep, and the operational tooling that keeps multi-PiB storage providers running in production.

Network raw1.87 EiB
Real operators73
Status active
GoSNARK / PoRepDistributed SystemsCUDA
curiostorage.org
CC Security
Founder · 2025 → present

Independent security research firm. Web, API, mobile, and crypto-stack auditing. Paid retainers, scoped engagements, and responsible disclosure.

Vulns200+
Platforms40+
capriaudits.com
Nøytral
Solo founder · in beta

Norwegian news intelligence platform. Multi-source clustering, framing analysis across the 8-party political spectrum, blindspot detection, transparent methodology.

nøytral.no
Swopa
Solo founder · closed beta

Norwegian neighborhood-help platform (Nabohjelp). Built for real local-community use cases, not the marketplace template every other Nordic startup ships.

swopa.no

Selected Work

A handful of pieces from 2026 that I can show without breaking an NDA.

May 2026 · Open infrastructure · live

Calix · Calibration Stability Console

Real-time stability console for the Filecoin calibration network. Tracks tipset cadence and chain health, surfaces upgrade-readiness state with manifest and migration audits, monitors top miners and rich-list movement, and publishes the result publicly so SPs can self-diagnose without DMing me on Slack. Built and shipped during the nv28 Fire Horse upgrade. Live at calix.reiers.io.

calix.reiers.io · live NETWORK VERSION nv28 · Fire Horse ● ACTIVE TIPSET CADENCE MIGRATION ✓ 41 / 41 MANIFEST ✓ match STATE ✓ integrity post-upgrade audit · nv28 activation epoch 3,694,534
April 2026 · Curio · Stack Leads

Filecoin Network Intelligence

Operator-level census of the entire Filecoin storage network. The 728 reported "SPs" deduplicate to 73 unique operators after analyzing shared control, worker, and beneficiary addresses. 37 entities run 90% of physical storage. Includes IP geolocation showing China and Hong Kong account for ~60% of resolved infrastructure. Methodology and raw data delivered for governance review. Live public version at filcensus.reiers.io with continuously refreshed snapshots.

Network Power · 2020 → 2026 Raw: 1.87 EiB QAP: 16.2 EiB 2020 2026
2025 – 2026 · Open infrastructure

Plumbline · Filecoin Calibration Stability

Lead the Calibration Stability initiative for Filecoin. Operate faucet.reiers.io (public tFIL + USDFC faucet), maintain 10+ dedicated test environments, and build the broader stability tooling the Calibration network needs. Public-good infrastructure that's invisible until it breaks.

faucet.reiers.io · live tFIL 5,000.00 delivered USDFC 5,000.00 delivered $ curl https://faucet.reiers.io/drip ✓ tx submitted ✓ 100 tFIL → t1xxx...
May 2026 · undisclosed client · NDA

Pre-launch security audit, high-stakes platform

23 findings across 10 audit phases on a pre-launch product. Headline finding was a multi-step attack chain combining authentication weaknesses, account-recovery gaps, and fulfillment-side IDOR that would have allowed attacker-controlled rerouting of $5K to $125K shipments per incident at launch. Customer report delivered with prioritized remediation; client patched before going live.

CHAIN-1 · Critical at launch enumeration cred-stuffing email-swap password-reset → reroute physical asset $125,000 max value per incident · validated against live data
March 2026 · coordinated disclosure

Multi-tenant SDK credential leak

Found hardcoded SDK credentials in a major operator's production Android app. Confirmed cross-brand impact across 14 production tenants, 4 brands, and 7 jurisdictions. CVSS 7.3. Reported through public bug bounty.

14 tenants · 4 brands · 7 jurisdictions 4 BRANDS 14 TENANTS 7 JURISDICTIONS CVSS 7.3 · CWE-798
2025 · Filecoin Improvement Proposal

FIP-Daybreak · Economic Rebalancing

Co-author on a comprehensive economic-rebalancing proposal for Filecoin. Modeling and policy-design work on pledge dynamics, supply emission, and verified-deal incentives. github.com/Reiers/fip-daybreak

FIP-Daybreak · pledge curve modeling current proposed network growth →
2021 – 2024 · Protocol Labs

Technical Support Engineer · Lotus, Boost, Saturn

Three years inside Protocol Labs as the engineer SPs called when production broke. Triaged failure modes across the Lotus consensus and storage pipeline, the Boost deal stack, and the Saturn CDN. Tested bleeding-edge releases in production environments before they shipped to the network. Every weird sealing failure, every chain-sync edge case, every libp2p quirk eventually came through this seat. The kind of role where you see every failure mode the protocol can produce, which is why I keep finding bugs nobody else does.

Protocol Labs · 2021 → 2024 Protocol Labs Lotus · Boost · Saturn

Open Source

Selected from github.com/Reiers. 24 public repos, mostly Filecoin storage tooling.

Contact

If you're shipping decentralized storage, auditing a launch-critical product, or just want to talk about why most public-good infrastructure dies of neglect: write.