Most people think the future of RWA is tokenization. We don't. And that belief just earned us a grant from @solana.
Fractionax started with a simple idea:
Bring a tokenization standard to Solana similar to ERC-3643 on Ethereum.
Our goal was straightforward, we want to make real-world assets easier to bring on-chain. But the deeper we went, the more we realized something.
Tokenization isn't the end game. It's the starting point.
The next generation of financial infrastructure won't just put assets on-chain.
It will understand them, analyze them, monitor them and allocate capital around them, autonomously.
That's when Fractionax evolved, from just a tokenization platform into an agentic investment infrastructure for real-world assets.
A future where AI agents can help investors discover opportunities, evaluate risks, automate workflows, and interact with tokenized assets at scale.
The AI boom didn't change our vision. It accelerated it.
Today, we're grateful that Solana Foundation has backed that vision with a grant. And a huge thank you to @tuakdotsol and @hanstmy from @SuperteamMY for creating opportunities that help builders turn ambitious ideas into reality.
For us, this milestone means something else too. For months, we were building through the realities every founder knows:
- bootstrapping development
- managing infrastructure costs
- stretching every dollar as far as possible
Now we get to focus more of our energy on what matters most:
- building
- shipping
- learning
- iterating
To every founder reading this:
Your first idea doesn't need to be your final idea.
We started with tokenization and we're now building agentic infrastructure for the future of investing.
One pivot. One opportunity. One "yes". That's all it takes.
We pitched. We won. 🏆
Canopy just took home "The Frontier AI Award" in Builders Capital Night Official SEABW side event.
We're just getting started. The future of AI is being built right here.
@9CATGROUP@Xphere_official@LBank_Exchange
for all JS builders, @tan_stack just dropped a critical security advisory on a supply-chain attack that’s straight out of the Mini Shai-Hulud playbook (must-read + act NOW)
what happened:
1. 42 @tanstack/* npm packages (84 versions total) were compromised and published between ~19:20–19:26 UTC today. Two malicious versions per package.
2. how it works: attackers snuck in an optionalDependencies pointing to a git commit (@tanstack/setup": "github:tanstack/router#79ac49ee..."). On install, a prepare script pulls a ~2.3 MB obfuscated router_init.js that exfiltrates AWS, GCP, Kubernetes, Vault creds, GitHub tokens, ~/.npmrc files, and SSH keys from CI and dev machines.
3. new insane detail (dead-man’s switch): the payload also drops a persistent watcher (e.g. https://t.co/4UwyXKfXW1 as systemd/LaunchAgent). It pings GitHub every ~60s with the stolen token. If the token gets revoked (HTTP 40x), it triggers rm -rf ~/* (or equivalent wipe) on Linux/macOS. Do NOT revoke blindly.
4. bigger picture: Socket Security just confirmed 121 more compromised artifacts across 84 additional packages (including 64 UiPath ones). Total now at 205 affected packages spanning automation, AI, auth, and dev tooling.
5. detection: open your lockfile or package.json. Any version with that sneaky @tanstack/setup git dependency in optionalDependencies = compromised. Also hunt for ~/.local/bin/gh-token-monitor.sh.
6. immediate action if you installed anything @tanstack
/* in that window:
• First check for the monitor script and clean the infection (ignore-scripts + manual removal)
• Rotate ALL cloud, GitHub, and SSH credentials (but only after cleaning)
• Audit your cloud logs for the last several hours
• Pin to a pre-19:00 UTC known-good version
• Delete node_modules + lockfile and reinstall clean
7. prevention going forward: set minimumReleaseAge in Bun/pnpm/npm, use Socket or similar supply-chain scanners, and never trust fresh publishes without verification.
8. status: packages are deprecated with security warnings. npm security team is actively restricting the malicious tarballs (unpublishing blocked on most due to downstream dependents).
thanks @_weihup for alerting us on this matter, and keeping @SuperteamMY builders safe!
Day 3 at @ns
Pulled back slightly today — recovery matters if you want to sustain output.
Got some badminton in, cleared my head, and spent time thinking through what actually matters to build here.
Still moved things forward, just at a different pace.
Tomorrow: back to full execution.
Brekpast with @wanaokii
sorry i salah ambil your racquet, proof i didnt play so long i cant recognize my own one 😅 @hanstmy Great playing with @tuakdotsol and those from @SuperteamMY too! To more sessions 🏸🏸🏸