I break systems so the people who own them don't have to find out the hard way.
I am Ndemafia Wilsmith, a cybersecurity researcher and full-stack developer working out of Nigeria. I reported a critical flaw in the national corporate registry, and I ship the production platforms that clients put their name on.
Two disciplines that only look separate
Most people pick a side. Builders learn to ship and treat security as somebody else’s checklist; breakers learn to exploit and never carry the weight of keeping something running in production. Doing both changed how I work.
My research came first in public: a critical flaw at Miva Open University in October 2025, which I disclosed to the university’s CTO and closed with a bounty. Two months later I found a broken access-control issue in the Corporate Affairs Commission’s document system, the registry behind more than 21 million Nigerian corporate entities. I reported it through ngCERT, and the national CERT validated it within 48 hours.
My engineering runs in parallel. I designed, built and deployed blordgroup.ng, the official B-Lord Group platform, end to end, and I treated the authorisation model as a design input rather than a launch-week afterthought. That is the whole argument for hiring one person to do both.
- FOCUS
- Access control, authorisation flaws, secure web apps
- DISCLOSED TO
- CAC · Miva Open University · BillPoint
- RECOGNISED BY
- ngCERT (NCCC / ONSA)
- SHIPPED
- blordgroup.ng
- STAGE
- MILSET ESI, Abu Dhabi
- BASED IN
- Nigeria · working remotely worldwide
MILSET Expo-Sciences International, Abu Dhabi
My secondary school selected me, and covered the full cost, to represent it at MILSET Expo-Sciences International in Abu Dhabi, one of the world’s largest gatherings of young scientists and technologists, where national delegations exhibit their strongest technical and scientific work to an international audience.
Being sent and funded to stand for my school on that stage says something about the work, not just the trip.
- EVENT
- MILSET ESI 2019
- HOST CITY
- Abu Dhabi, UAE
- SPONSORSHIP
- Fully funded
- ROLE
- Delegate & exhibitor
From the exhibition floor
ABU DHABI · UAE









The record so far
- OCT 2025
First responsible disclosure at Miva Open University
I escalated a critical flaw threatening student data privacy to the university's CTO. It was confirmed, remediated and rewarded with a bug bounty.
- DEC 2025
National CERT validation at the Corporate Affairs Commission
I reported a critical access-control flaw in the federal corporate registry to ngCERT, under the Office of the National Security Adviser. It was validated within 48 hours of my technical report.
- ONGOING
BillPoint fintech review
My application security review of the B-Lord Group payment platform, handled under coordinated disclosure with the product team.
- ONGOING
blordgroup.ng shipped
I designed, built and deployed the official B-Lord Group platform end to end as sole developer.
- MILESTONE
MILSET Expo-Sciences International, Abu Dhabi
My secondary school selected me and covered the full cost of representing it at one of the world's largest gatherings of young scientists and technologists.
How I work
Report, don't publish
The owner of the risk hears about it first. Every time, without exception.
Impact over cleverness
A boring authorisation bug that exposes millions of records matters more than an exotic one that exposes nothing.
Build what you defend
Writing production code keeps my research honest, and the research keeps my code paranoid.
Have a system worth protecting, or one worth building?
Security assessments, responsible disclosure and full-stack engineering.
Tell me what you are working on.