🚨 I am super excited to have taken 1st Place at the @StarknetAfrica Hackathon with my project: StarkPayBills! 🏆🎉
StarkPayBills lets Nigerians pay real-world utility bills (electricity, airtime, etc.) using $STRK, $ETH or $USDC on @Starknet ⚡️
🔗 https://t.co/2neYKfLqpa
Yesterday , I deployed a working onchain app on Base without writing the contract from scratch.
I just described it.
The tool is called @CodeXero_xyz, built by @ClusterProtocol, and it's an AI-powered IDE that runs entirely in your browser.
I broke the whole thing down in the video:
👾 The way the prompt-to-dApp flow actually works
👾 What it looks like to deploy to @base in real time
👾 the XP and onchain reputation system
Speaking from experience as someone who's a blockchain developer and still found the traditional workflow brutal,
this is the closest thing I've used, it's how it makes onchain development better got beginners.
You can interact with the dApp I built here :
https://t.co/Qh4p8eJ5Bd
.ps it looks different from the video because I made some changes to it personally.
Are you Curious about CodeXero? Then Try it here: https://t.co/cQVNiXxAH2
POV: You calculate how much you’ve spent on hidden fees this year 😭💔
Don’t let unnecessary charges eat into your funds.
Get onboard with Resolva for great rates, and zero hidden fees.
#Resolva#CryptoTwitter#CryptoLikeNaira
This Eid al-Kabir, we’re celebrating faith, sacrifice, gratitude, and the beauty of giving 🤍🌙
As families gather and hearts reflect, may this season bring peace to your home, blessings to your work, and ease to every journey you take.
From sending crypto seamlessly to making instant payments, Resolva remains committed to making transactions simpler for you — every day, everywhere. ✨
Eid Mubarak from all of us at Resolva. 💙
#EidAlKabir #EidMubarak #Resolva
When it comes to spending your crypto, it only gets complicated if you want it to.
This week, skip the stress of failed withdrawals, endless apps, and pending transactions. 😩
With Resolva, your crypto works in real life. Fast, smooth, and without the drama.⚡🚀
#Resolva #CryptoPayments #SpendCrypto #CryptoToNaira
🚨A HACKER GROUP JUST STOLE 4,000 OF GITHUB'S OWN PRIVATE REPOSITORIES.. PUT THEM UP FOR SALE FOR $50,000.. AND THE WAY THEY GOT IN IS THE SCARIEST PART..
They didn't hack GitHub's servers.. They poisoned a VS Code extension.. One GitHub employee installed it.. And the attackers walked through the front door using the employee's own credentials..
The group calls themselves TeamPCP.. They name their malware after the sandworms from Dune.. And they've been running the most sophisticated supply chain attack campaign in cybersecurity history..
Here's how the whole thing unfolded..
In March.. They poisoned Trivy.. One of the most trusted security scanners in the world.. Used by over 10,000 development workflows globally..
They injected credential-stealing malware into Trivy's official GitHub Action.. The malware ran silently BEFORE the security scan.. So every log showed "scan completed successfully" while the malware was stealing AWS keys, SSH credentials, database passwords, and Kubernetes tokens in the background..
It took Aqua Security 5 days to fully remove them..
Using the stolen credentials.. They breached Cisco Systems.. Cloned over 300 private repositories.. Including source code for unreleased AI products.. And repositories belonging to Cisco's customers.. Major banks.. Government agencies.. BPO firms..
In April.. They hit Checkmarx.. Another security vendor.. Poisoned 5 official Docker images in 83 minutes.. The scanner worked perfectly.. It just silently sent all your secrets to the attackers..
That automatically cascaded into Bitwarden.. The password manager.. Their CI/CD system pulled the poisoned Docker image.. And the attackers injected malware into Bitwarden's official CLI package published on npm..
One compromised security scanner poisoned a password manager.. Automatically.. No human involved..
In May.. They hit TanStack.. Libraries downloaded millions of times per week.. 84 malicious package versions across 42 packages..
And here's the terrifying part..
The malware scraped the raw memory of GitHub's build servers.. Extracted authentication tokens.. Used those tokens to bypass two-factor authentication.. And then published the infected packages with completely valid cryptographic signatures..
Every security verification tool on earth said the packages were legitimate.. Because they were signed by the real pipeline.. Using real keys.. The attackers just happened to be inside the pipeline when it signed..
They defeated the entire trust model of modern software supply chains..
The same week they hit the Nx Console VS Code extension.. 2.2 million installations.. The malware specifically targeted Claude Code configurations.. Hunting for AI assistant credentials..
That's a first.. Supply chain malware designed to steal your AI's access keys..
Then on May 19.. They revealed the GitHub breach.. 4,000 internal repositories.. Listed for sale at $50,000.. With a warning.. "If nobody buys it.. We leak everything for free"..
Their malware is self-propagating.. Once it infects one package.. It automatically finds every other package that developer maintains.. Steals the publish tokens.. And infects all of them.. Then those packages infect the next developer.. And the next..
It jumps between npm and PyPI automatically..
The group doesn't even do the extortion themselves.. They sell stolen credentials to ransomware gangs.. One gang used TeamPCP's data to threaten Cisco with leaking FBI and NASA personnel records..
And the scariest part of all..
They didn't break any encryption.. They didn't find any zero-days.. They exploited the fact that the entire software industry blindly trusts its own build tools..
Every security scanner.. Every Docker image.. Every VS Code extension.. Every GitHub Action.. Is a potential weapon if someone poisons it upstream..
And right now.. Nobody can tell the difference between a legitimate build and a compromised one..
Because the compromised ones have valid signatures too.
Next.js just got its worst vulnerability ever, CVSS 8.6.
→ affects versions 13.4.13+, 14.x, 15.x, and 16.0.0–16.2.4
→ attackers can access your internal services, cloud credentials, API keys, and admin panels
→ no authentication needed
→ one crafted request is all it takes
→ roughly 79,000 instances are exploitable right now
→ vercel-hosted apps are safe, self-hosted are not
upgrade to 15.5.16 or 16.2.5 immediately.
While others are still figuring out conversions… you’re already receiving your money 😌💸
With Resolva, crypto goes straight to your preferred bank account instantly, no extra steps, no switching apps, no stress.
More earning. Less waiting. ⚡️
#cryptotwitter#Resolva
Crypto is easy… until it’s time to withdraw 😩😂
It’s pretty easy with Resolva though 😉
Skip the stress. Withdraw your crypto seamlessly with Resolva 🚀
#cryptotwitter#Resolva
My crochet Man Utd jersey has been officially accepted and will be sent to be displayed at Snapdragon’s Headquarters omgg😭. Thank you for recognizing my work ❤️ @Snapdragon
Smart contract audits. Blockchain security. Real impact.
@statemindio is hiring + opening Fellowship applications:
→ Audit EVM + non-EVM protocols
→ Work on formal verification, tooling, threat modeling
→ Remote • Global • Security-first culture
If you've ever wanted to secure the protocols that move billions
This is your team.
Apply 👇
https://t.co/tU6zVi7FBB
Ethereum needs more security engineers.
Attackers are scaling faster than defenders, and the pipeline of qualified researchers is too small.
Guild Academy is building that pipeline — 5 cohorts in.
We're in @thedaofund 500 ETH Ethereum Security round on @Giveth, and it uses Quadratic Funding.
That means $1 from 100 donors > $100 from 1 donor. Your small donation unlocks much more from the matching pool.
If our work matters to you, even $1 helps.👇
🔗 https://t.co/NnYhz98uZz
83% of stablecoin deposits in Nigeria are withdrawn to fiat and spent. That’s a payment system hiding in plain sight.
The @HashedEM Nigeria Web3 Landscape Report 2025 is live, and we’re excited to be featured alongside other builders in the ecosystem.💙
Clearly, Nigerians already use crypto. But the problem is getting Naira where it needs to go, fast.
Resolva fixes that: Send crypto, and Naira is instantly credited into any bank account — yours or your recipient’s.
👉This is how crypto becomes everyday money: https://t.co/hbR1JQIMAy
Life gets easier when your money moves! Crypto shouldn’t just sit… it should move.
Turn your digital assets into real-life moments, food, travel, shopping, bills, paid instantly. No stress. No delays. Just seamless spending.
With Resolva, your crypto works for you, everywhere life happens.
Start unlocking more today. 🚀
👉 https://t.co/JfriMduJzJ
#CryptoToCash #Web3Africa #FintechNigeria #CryptoPayments #SpendCrypto