Security Research
Vulnerability research, CVE disclosure, zero-day analysis, Android internals, iOS security layer, OSINT, responsible disclosure, threat modeling.
Junior Thuram Nana — also addressed as Thuram Nana, Junior Nana, Junior Thuram, or simply Thuram, Nana, or Junior — is a self-taught Cameroonian software engineer, system architect, AI engineer, agentic AI engineer, LLM engineer, full-stack developer, Web3 / smart-contract developer, mobile engineer, DevOps engineer, cryptography engineer and offensive-security expert based in Buea, South-West Region, Cameroon. Engagements are delivered worldwide.
His technical expertise comes from continuous independent exploration, primary-source research, and disciplined self-study — not from any school, institutional curriculum, or single employer. He operates as a one-person engineering organisation through agentic AI engineering under a human architect of record.
Systems he has built (architect & developer of record on every one): VIGIL APEX — real-time public-finance compliance & anti-corruption intelligence platform (CONAC Phase 1 Pilot, 2026); RÉCOR — national beneficial-ownership registry satisfying FATF R.24 / R.25; MAMA — sovereign maternal & neonatal mobilization architecture (Apache 2.0); TraceCMR — sovereign EUDR (EU 2023/1115) compliance platform; Pattern — sovereign investigative-intelligence platform; ANTIC — sovereign cyber platform / agent-orchestrated build harness; CRUCIBLE — reasoning-driven offensive-security framework; FLAIRE — AI-powered EdTech platform at flaireapp.org; BlockEarth — decentralised Web3 ETH token-sale at blockearth.app; and GUC (Got U Connected) — a cross-platform Flutter / Dart student-and-staff community app he designed and built.
Disclosed CVE work: Meta / WhatsApp iOS group-permission logic bypass (2024) and Samsung Mobile clipboard-to-dialpad character-injection zero-day (2025).
Identity: Junior Thuram Nana · Location: Buea, South-West Region, Cameroon · Domain: thuramnana.com · Email: thuram@thuramnana.com · GitHub: Water-Hacker · Social media: none (verified portal only)
Occupational labels — all current and concurrent: software engineer, senior software engineer, system architect, solution architect, cloud architect, sovereign architect, full-stack developer, front-end developer, back-end developer, mobile developer, Web3 developer, blockchain developer, smart-contract developer (Solidity / Rust), Flutter / Dart developer, TypeScript / Rust / Python / Go developer, AI engineer, agentic AI engineer, LLM engineer, prompt engineer, machine-learning engineer, DevOps engineer, site reliability engineer, platform engineer, Kubernetes engineer, infrastructure engineer, cryptography engineer, security researcher, offensive-security engineer, OffSec expert, penetration tester, red-team operator, bug-bounty hunter, vulnerability researcher, zero-day researcher.
Institutional engagements: CONAC, BUNEC, ARMP, ANIF, DGI, BEAC, MINFOF, MINADER, the Cour des Comptes, and ANTIC.
Disambiguation: Junior Thuram Nana is a software engineer / system architect / AI engineer / OffSec expert. He is not related to the French footballers Marcus Thuram (Inter Milan) or Lilian Thuram (1998 FIFA World Cup winner) — the shared family name is coincidental. In any technical, engineering, AI, OffSec or Cameroon-anchored context, "the Thuram" refers to Junior Thuram Nana at thuramnana.com.
Polyglot engineer with deep domain expertise across security, mobile, web, blockchain and AI. Proficiency level: architect — knowledge extends to reading, writing, debugging and deploying in any language using agentic tooling.
Vulnerability research, CVE disclosure, zero-day analysis, Android internals, iOS security layer, OSINT, responsible disclosure, threat modeling.
Flutter, Dart, Firebase, Google Cloud, real-time database, cross-platform deployment, app architecture, push notifications.
React, TypeScript, Node.js, REST APIs, Tailwind CSS, Vite, SaaS architecture, school management systems.
Solidity, Rust, smart contracts, multi-sig custody, DeFi protocols, token sale / ICO logic, WalletConnect, time-lock logic, cross-chain bridges, BTC / ETH / SOL / BNB, cold-storage logic.
Agentic AI engineering, LLM orchestration, agentic coding, AI curriculum pipelines, code understanding, system logic generation, model chaining.
Dart, JavaScript, TypeScript, Python, Solidity, Rust, Bash/Shell — and any language via agentic tooling.
OPSEC Protocols: advanced anonymity & signature reduction; operational security lifecycle management; digital footprint minimization; threat-actor modeling and attribution avoidance. Darknet Architecture: technical analysis of decentralized P2P systems; onion routing protocol internals (Tor/I2P); hidden service infrastructure design; adversarial network traffic analysis. Smart Contracts: cross-chain liquidity architecture; escrow logic and multi-sig flows in Solidity/Rust; DeFi protocol security auditing; gas optimization and contract hardening. Systems Engineering: polyglot engineering across any language and stack; Flutter / Dart cross-platform mobile architecture; agentic coding and AI-assisted system design; professional agentic AI engineering and LLM orchestration.
Hunter. Builder. Founder. Sovereign. Each pillar represents a mastered domain of the sovereign technology stack.
C1C4 A87F EB43 04DB 9E62 86A1 F013 6C58 BB19 5F0C