Blockchain consultant & full-stack builder | Founder @KochainTech | Ethereum • Solana • Hyperledger • Casper | Building in Public 🛠️ | Tweets are personal
🚨 Something happened during a job search that I sat on for months. I'm talking about it now — because we built something about it.
I was contacted for a blockchain role. Professional communication. Real company name. Proper GitHub repo. All the right signals.
They sent a take-home technical task.
I ran it on a cloud instance instead of my laptop. Good instinct, as it turned out.
The actual code ended at line 46. Everything beyond that — all the way to line 258 — was a hidden payload:
🔑 SSH keys
🌍 Environment variables
🔐 Credentials and API keys
💀 Anything it could reach on a local machine
Designed to look like nothing. Designed to run the moment I opened it on my own machine.
I flagged it to the "recruiter." No response.
And then I kept thinking: what if I'd just run it locally, like most people would?
That question didn't go away.
This attack pattern has a name. It's documented. It's ongoing. It specifically targets blockchain and Web3 developers — because running code during a technical interview is completely normal behaviour, and that normality has been weaponised.
I wasn't the first. I won't be the last.
So we built a response to it.
@RTindex — the Risk & Threat Index — is live today.
Paste a suspicious repo link or a recruiter conversation. Get a risk verdict in under 2 minutes — with a clear explanation of why, not just a flag.
The full story, the technical breakdown, and the case that started all of this are on the blog.
🔗 https://t.co/y6jfUMI8Yb
This wouldn't exist without @piotrdz (product vision and trust) and @jan_defdone , who engineered RTIdx end-to-end. Jan's work is the product.
The platform's analytical foundations draw from research by Prof. @ameerrahmati and Abisheka Pitumpe PhD at Stony Brook University's Ethos Security & Privacy Lab — connecting serious academic research on recruitment scam ecosystems to a tool developers can actually use in the moment.
If you're in Web3, blockchain, or any developer community — share this. Someone in your network may already be targeted.
The index gets stronger with every report.
🔗 https://t.co/y6jfUMI8Yb
#cybersecurity #web3 #blockchain #developerprotection #infosec #recruitmentscam #rtidx
Fake job offers are no longer obvious scams.
They can start with a polished recruiter message, a credible role, and a normal-looking interview process.
Then comes the “technical assignment.”
We wrote up what happened in a real case:
https://t.co/DJ8fWEK2k8
Fake recruiters are targeting developers with “technical assignments” that hide malware.
RTidx helps you check suspicious recruiters and coding test repos before you run them.
Paste the convo. Scan the repo. Get risk verdict.
Stay safe in job search: https://t.co/vIUTwP6als
Even though this book is about 20 years old, it's still a good starting point for anyone who wants to learn how to build databases.
It just took me a couple of weeks to go through it.
For the interested folks, the link is here:
https://t.co/kWSfVA1WJ9
Introducing Raffle Robot - the world’s first AI raffle platform.
Let AI agents enter raffles for you, or take full control and enter yourself.
Built with our Proof of Fair system on @solana.
The future of raffles starts here: https://t.co/MLipKuOx4K
Ahead of the Raffle Robot soft launch, we’re opening our first community game.
Climb the ranks, earn points, and secure early access to the platform. 🤖🎟️
https://t.co/ATD0BPtlZP
Raffle Robot is the world’s first AI agent raffle platform, allowing users to deploy AI agents that automatically enter raffles and participate in prediction markets, all within a community driven ecosystem!
Built from the ground up on @solana
Join us https://t.co/9GAFF6V7fz
Hey @MpmTos
I came across your post and just wanted to say—I'm really sorry you're going through this. Losing a job suddenly, especially with a young baby at home, sounds incredibly tough. That punch-in-the-face feeling is real.From what you've shared, it's clear you put real heart and hard work into building something meaningful for the community—growing it big while keeping things genuine and fun. That kind of care stands out in this space, and it matters, even if the project couldn't continue.
You protected people by not forcing something risky, and that's integrity. Hold onto that pride.
Wishing you and your family strength right now, some calm amid the storm, and new doors opening soon. Your skills and genuine approach will carry you forward—better opportunities are coming.
You've got this. Take care of yourself and the little one first. Rooting for you. 💪👍
Decentralised file transfer — no wallet friction, no jargon, just drag and drop.
Tried @thedefdone team's freshly soft-launched https://t.co/PCZlZP6qJ8 and it genuinely impressed me.
Under the hood? The full power of @DataHaven_xyz — a decentralised storage L1.
On the surface? Pure simplicity. User-first design done right.
This is how Web3 products should be built. Abstract the complexity. Deliver the experience.
Go try it 👉 https://t.co/PCZlZP6qJ8
#Web3 #DecentralizedStorage #DataHaven #HavenTransfer
We're cooking! Our new project has just been soft-launched. https://t.co/5dJPmhdTM1 lets you share your files securely using decentralised storage at no base cost. And guess what - much more is coming, including monetisation for creators. We will support both humans and agents (hello @openclaw!). Storage provided by @DataHaven_xyz!
We love builders, especially those building at the intersection of ai x crypto … and taking it even one step further are those building for the agentic world, that understand the criticality of verifiable data for ai agents 🤖
Proud to be sponsoring @ethmumbai - can’t wait to see the incredible projects and use cases come to life!
securely share files with anyone, knowing the data remains private & verifiable … perfect for humans & ai agents too
try out out HavenTransfer (https://t.co/khu7rEbALN) built on @DataHaven_xyz 👇🏼