Back to the network
Portrait of Souhail Mssassi, CCSSA, CBSP, CEE

Independent specialist · Wavect Expert Network

Souhail Mssassi, CCSSA, CBSP, CEE

11 years in offensive security. Smart contract and Solana audits at Quantstamp and Halborn, now Enya Labs Security. Brought in when a Wavect build needs an adversarial review before mainnet, or when the threat model has to clear a regulated buyer.

Specialty
Security
Based in
Casablanca, MA
Experience
11+ years
Status
Available · Selective mandates
01  ·  SIGNALS

Why we vouch for them

  • CCSSA, CryptoCurrency Security Standard Auditor (C4 · CryptoCurrency Certification Consortium, 2023)
  • CBSP, Certified Blockchain Security Professional (Blockchain Council, 2023)
  • CEE, Certified Ethereum Expert (Blockchain Council, 2023)
  • Security Researcher, Enya Labs Security (current)
  • Former Senior Security Researcher, Quantstamp (Jul 2021–Jan 2024). Led audit teams on large Solana programs and Solidity contracts. Reverse-engineered on-chain exploits at the assembly level. Built internal tooling for audit scoping and time estimation
  • Former Offensive Security Engineer, Halborn (May 2020–Jun 2021). Solidity smart contract audits, Solana program pentests, dApp and DEX/DeFi assessments, blockchain SDK and network infrastructure testing
  • Former Senior Security Consultant, Société Générale Morocco (Jun 2018–Apr 2020). DevSecOps integration across Nginx, Zuul, Keycloak, Jenkins. Mobile banking audits under EU and Moroccan compliance frames. 90% vulnerability reduction post-hardening
  • Prior consulting: IT6 Group (2017–2018) and Absec Cybersécurité (2014–2017). Vulnerability analysis and pentests for Moroccan banking (EURAFRIC), Ministry of Agriculture, Ministry of Health, trading platforms, and insurance
  • Blockchain security researcher, Cadi Ayyad University (Marrakech). Research in privacy-preserving smart contracts, EVM internals, cryptography-informed system design
  • 22+ keynote speaker engagements across Moroccan universities, Arab Security Conference, Arab EmTech & Startups, BlaBlaConf, and GDG
  • Peer-reviewed publications in Applied Sciences (MDPI), International Journal of Computer Networks and Applications, and a Springer book chapter
  • Blockchain mentor, MentorCruise (since 2021)
02  ·  BIOGRAPHY

In their own line of work

Souhail started in cybersecurity in 2014 at Absec Cybersécurité in Morocco. Trading platforms, insurance mobile apps, vulnerability analysis, reverse engineering. IT6 Group followed, with security testing of Moroccan banking infrastructure (EURAFRIC), the Ministry of Agriculture platform code review, and the Ministry of Health platform vulnerability program. By the time he joined Société Générale Morocco as Senior Security Consultant, he was running DevSecOps integration across the development cycle. Mobile banking audits, risk analysis, EU and Moroccan compliance. He authored the pentesting methodology reference for Société Générale Morocco, hardened Nginx, Zuul, Keycloak, and Jenkins, and cut roughly 90% of the vulnerabilities surfaced in pre-engagement testing.

In May 2020 he pivoted to Web3. Halborn brought him in as Offensive Security Engineer for Solidity smart contract audits, Solana program pentests, and DEX/DeFi assessments. Quantstamp hired him as Senior Security Researcher in 2021. There he led audit teams on large Solana programs and Solidity contracts, analyzed fraudulent transactions and reverse-engineered live exploits at the assembly level, and built internal tooling that helped auditors scope engagements and estimate time more accurately. He is now at Enya Labs on the security side, still in the same line of work: adversarial review of code that holds real value.

Parallel to that, Souhail runs an academic and public-education track. He is a blockchain security researcher at Cadi Ayyad University in Marrakech, with peer-reviewed publications on the blockchain trilemma in Applied Sciences (MDPI), on privacy-preserving application-layer frameworks in IJCNA, and a Springer book chapter on decentralized identity for the Web of Things. He has given 22+ keynotes and workshops across Moroccan universities, the Arab Security Conference, Arab EmTech, BlaBlaConf, and GDG. He has been a blockchain mentor on MentorCruise since 2021. He holds CCSSA, CBSP, and CEE charters across cryptocurrency custody, blockchain protocol security, and Ethereum.

When Wavect brings Souhail in, the work is straightforward. Adversarial review of code that is about to hold value. Threat-modelling of an architecture before it is locked in. Forensics when something has already gone wrong. He is not a generalist consultant. He is the auditor who has read the assembly.

03  ·  WHEN WE BRING THEM IN

Where Souhail Mssassi, CCSSA, CBSP, CEE plugs into a Wavect engagement

Wavect builds the product. When a build crosses into a domain that exceeds our own bench, we bring in the specialist who already lives there. This is the brief for this one.

  • Smart contract audit before mainnet

    Senior auditor at Quantstamp and Halborn. Solidity and Solana program audits, EVM-level review, threat modelling of dApps, DEXs, and DeFi protocols. When a Wavect build is going to mainnet and there is real value at stake, Souhail runs the adversarial pass before deployment. He has shipped enough audit reports to know which findings stop a launch and which can wait.

  • On-chain forensics and reverse-engineering

    At Quantstamp he analyzed fraudulent transactions and reverse-engineered live exploits on the blockchain, reading assembly to understand what actually happened. When a client gets hit and the team needs a post-mortem that holds up in front of investors, regulators, or insurers, Souhail does the forensic work.

  • DevSecOps for regulated buyers

    Société Générale Morocco: integrated DevSecOps into the development cycle, hardened Nginx, Zuul, Keycloak, and Jenkins, cut 90% of vulnerabilities, and authored the pentesting methodology reference. When a Wavect build needs to clear EU or Moroccan compliance, or sell into a regulated industry where audit trails matter, this is the depth we rent.

  • Cryptography-informed architecture review

    Academic researcher at Cadi Ayyad University with peer-reviewed work on the blockchain trilemma, privacy-preserving application layers, and decentralized identity for IoT. When a build needs cryptographic primitives sense-checked before the system is locked in, Souhail reads the spec the way an attacker reads it.

Brought in. Not introduced.We engage these specialists inside our own projects, when a brief calls for depth our bench does not carry.

04  ·  EXTERNAL ENGAGEMENTS

Selected work, delivered with their own clients

External engagement

GDG on Campus ENSAM Casablanca

2024

Keynote speaker · Introduction to Blockchain Security

Industry
Developer community · public webinar

A two-hour public webinar covering the threat surface of modern blockchain systems. Souhail walked through smart contract attack patterns, EVM-level pitfalls, and the disclosure workflow auditors use when a live protocol gets hit. The session is hosted as a publicly viewable artifact of his teaching depth.

Souhail Mssassi on Introduction to Blockchain Security, recorded live at GDG on Campus ENSAM Casablanca on 9 November 2024.
05  ·  PUBLICATIONS

Peer-reviewed work

Indexed academic publications. Full list on Google Scholar.

  1. 2024Journal paper

    The Blockchain Trilemma: A Formal Proof of the Inherent Trade-Offs Among Decentralization, Security, and Scalability

    Applied Sciences (MDPI)

    Read paper
  2. 2025Journal paper

    An Application-Layer Framework for Privacy-Preserving Blockchain Transactions and Smart Contracts

    International Journal of Computer Networks and Applications (IJCNA)

    Read paper
  3. 2026Book chapter

    Building Trust in the Web of Things: Decentralized Identity Management with Blockchain

    Signals and Communication Technology (Springer)

    Read paper
06  ·  TALKS & WORKSHOPS

On stage, in their own words

Public keynotes, workshops, and webinars delivered independently. Conference links and recordings where available.

  1. Nov 2024Webinar

    Introduction to Blockchain Security

    GDG on Campus ENSAM CasablancaOnline

  2. 2023Talk

    Blockchain technology and decentralized finance (DeFi)

    ENSA AgadirAgadir, MA

  3. 2022Conference talk

    Reverse engineering the EVM

    Arab EmTech & Startups ConferenceCasablanca, MA

  4. Oct 2021Conference talk

    Advanced attacks in decentralized applications

    BlaBlaConfOnline

  5. Sep 2020Workshop

    Advanced Attacks in dApps and Solidity

    Arab Security ConferenceOnline

  6. Sep 2019Workshop

    Side Channel Attack in Blockchain

    Arab Security ConferenceOnline

  7. Dec 2019Talk

    Application security: website security and pentester methodology

    EHTPCasablanca, MA

  8. Nov 2019Talk

    The security of mobile applications

    EST EssaouiraEssaouira, MA

  9. Oct 2019Talk

    Wireless network security: Cellular networks

    Netcom ENSA KhouribgaKhouribga, MA

  10. Oct 2019Talk

    Data exfiltration in an isolated information system

    Netcom ENSA FesFes, MA

  11. May 2019Talk

    Careers in the IT security industry

    ENSA BerrechidBerrechid, MA

  12. May 2019Talk

    Cybersecurity professions and blockchain

    EMIRabat, MA

  13. Apr 2019Talk

    Physical security: Internet of Things

    Netcom ENSA TangerTangier, MA

  14. Apr 2019Workshop

    Application security: Advanced attacks on Web applications

    ENSA AgadirAgadir, MA

  15. Mar 2019Talk

    Application security: Advanced attacks on Web applications

    FST MarrakechMarrakech, MA

  16. Feb 2019Talk

    Introduction to blockchain

    1337 KhouribgaKhouribga, MA

  17. Dec 2018Talk

    Security of wireless networks and decentralized applications

    ENCG MarrakechMarrakech, MA

  18. Dec 2018Talk

    Bitcoin and the professions of organizational security

    ENSA SafiSafi, MA

  19. Dec 2018Talk

    Physical security and the Internet of Things

    ENSA OujdaOujda, MA

  20. Dec 2018Talk

    Awareness on cyber security

    EMSI MarrakechMarrakech, MA

  21. Oct 2018Talk

    Protection of the confidentiality of the patient's personal data

    Faculty of Medicine AgadirAgadir, MA

  22. Oct 2018Talk

    Introduction to network and website security

    ENSA AgadirAgadir, MA

07  ·  LINKEDIN

Recent posts

Get to know how Souhail thinks. Recent posts, in their own words.

Not our domain?

If we lack the depth in-house, engage through Wavect (one contract) or directly with them. We take no referral cut.

Discuss a project