I want to share more context on our findings yesterday and our reasoning for delaying Meme Madness.
Myself and the team care much more about the integrity of the platform and our brand than we do about shipping something as quickly as we can.
Yesterday evening, a few hours before we were set to open the tournament, we noticed millions of inbound requests on cloudflare targeting our market API routes. These are known routes, as we previously ran a tournament during the Cade Cup, and anyone was able to see public facing API routes in their network requests.
The millions of inbound requests originating from clearly identified VPN sources clearly do not line up as organic individual users being that we have roughly 128k pre-registrations for the tournament.
Let's be real for a second, the prize pool for Meme Madness is large. One of the largest that we've seen in recent times in a zero-risk-tournament. Our team is fully aware that this will bring people that are in it for the wrong reasons.
We're not dumb, our goal is not to juice metrics as high as possible and give money away for meaningless traffic to potentially malicious users.
During the Cade Cup, we were extremely proactive in identifying cheaters, and promptly revoked their prizes. Additionally, we sanitized metrics prior to posting them. We know it was a testnet tournament, and we gain no benefit from flexing 1 user trying to run hundreds of active wallets.
This is no different here for Meme Madness, but the scale is much, MUCH larger. We are expecting between a 5-10x increase in active players from Cade Cup.
In this tournament however, there are 102 winners per day (up from 5 in the last tournament) and prizes payouts are triggered automatically.
Now that i've given context, why the delay?
There's 2 reasons really:
1. We've done load testing simulating 50,000 concurrent users on the website. We are taking extra time now to significantly ramp this number up in our testing environment, to account for the event where we do see millions of spam predictions on the platform. Ensuring zero degradation under ANY load is incredibly important for us.
2. After seeing what we saw last night, we want to ensure that we add a few additional preventative measures to the automatically triggered prize payouts. We already have a number of processes that run prior to the prize payouts executing, but we now have more information to make this significantly more fault tolerant.
I know people are excited for Meme Madness, and seeing a delay is potentially hindering that excitement...
If waiting a little bit more time means we can ensure that we're doing things FAIR, and not rewarding the wrong users, then that's the path i'll chose every single time.
Even though Meme Madness is a testnet tournament, it's still part of our overall go to market strategy. The tournaments we do stress test our REAL money go to market where we are focused on activating retail. We want to ship an incredible and fault tolerant product when mainnet comes, and pushing back test tournaments like this is incredibly important and part of the process to do so.
We'll have further updates for you all shortly.
Cade on.
Possible data breach on X. Seeing dozens of password reset requests on the timeline
Me, the @CadeMarket account, and a few of our employees are all getting spammed with password reset requests.
PSA: Myself & the team will NEVER advertise tokens other than our own. Stay safe.
We're selling ad space on the Solana logo.
9 spots, with 100% of proceeds donated to Nepal flood relief. Win and your logo or artwork sits on our PFP and pinned post for a week.
24 hours to bid and donate: https://t.co/Y76WemJtVX
Powered by @mallowdotart
Video call froze during my meeting with the team today and now everyone is guessing what point I was making.
I'm sending $100 bucks to the funniest caption.
At 11:15 AM, a malicious post was made from our business account.
They added CadeDotCash (now deleted) as an affiliate to our business account.
At 11:16 AM, 1 minute after their post, I logged into the business account, deleted the post, and removed the affiliate.
At 11:18 AM, I confirmed the business account nor associated email were compromised, and changed the password to be safe.
At the same time, they posted 1 more time, which I deleted less than 1 minute after.
At 11:19 AM, our employee alerted us that it was HIS account that was compromised, which had delegate access to the business account. This gave us the full picture as to what was going on.
At 11:20 AM, I removed the affected employee account as a delegate as well as their badge.
It's really scary that even with the best account safety practices, these things can still happen. All of our employees use non-SMS 2FA, and this particular employee even used a biometric passkey.
Not how I wanted to spend my Sunday morning, but i'm just relieved we were able to action this as quickly as we did.
A few minutes ago we noticed some malicious posts from this account.
We acted instantly. The account was not compromised.
An employee account with delegate access to this account was briefly compromised. This should now be resolved.
Please stay safe if you see anything else.
@Po_rThos@CadeMarket Sorry we're not gonna waste money to artificially pump the token for you. We care about sustainable approaches.
Consider pivoting to other projects pal.
I've been building @CadeMarket in public with a live token for almost a year now and I want to share some of my thoughts, specifically in regards to the many hundreds of DMs I get every week.
The token is not THE SOLE product, and it never will be. By this, I mean that we won't bend the knee and just mindlessly dump raised capital into the token when it's not sustainable to do so. That's how you create exit liquidity and just dig yourself into a hole.
Our product is the product, and that is where 100% of our efforts are as we gear up for our mainnet go to market.
Why does this matter? The best tokens in our space are driven by successful revenue generating products. There's a reason why the lifespan of memecoins, even the hottest runner of the day, are typically short, and even the most successful ones always capitulate.
The core focus for myself and my company is building a product that will attract users and generate revenue, which in turn ultimately benefits the token & ecosystem through our tokenomics (encourage you to read them if you're unfamiliar, as we spent significant time on these to ensure that ALL activity, especially from retail users that don't even know that the token exists benefit the value engine: https://t.co/4a3wEAKbd1)
Cade, the product, is currently at the best point that it's ever been. In July we ran a tournament with thousands upon thousands of weekly active users, and we're about to launch another tournament where we expect to 5x this user count as a baseline. We spent months obtaining the proper licensing to launch the product, and now HAVE that license.
These tournaments do not serve to simply hand out money. We are getting users familiar with the product, and most importantly stress testing our app and infrastructure for when we do go live on mainnet.
We are in a VERY good place as a company. We raised quite a significant amount of capital, and we plan on deploying that strategically to make the product as successful as it can be.
Without getting into deep specifics, we already have 7 figures in capital allocated to user acquisition plans. (inside web3, but mostly OUTSIDE of web3).
By attracting the right users, and a lot of them, we set ourselves up to meaningfully contribute to the token and the ecosystem.
It's been nearly a year, and i've been as transparent as I possibly can with sharing the process of building this company. It should be evident that we are never going to make a quick rash decision to put a bandaid on something. Every step we take is for the long haul. I will never think in the short term.
The product is everything, and the key to everything succeeding around it.
@0liverVera@CadeMarket we'll have an announcement in the coming days. it's not very far away, like some people are thinking.
we just intentionally decided to not set the date until we were ultimately certain what the correct day would be