Gitbank: Growth in Numbers
191 accounts registered. 186 vaults deployed on Base Mainnet.
Almost every user who signed up deployed a vault. One command, no gas required.
418 bot commands processed. 112 unique users. 8 repos.
Every single one ran through GitHub issue comments. No UI, no wallet popup, no gas from users.
Breakdown by command:
launch token: 162
withdraw: 133
balance check: 42
deposit: 27
x402 pay: 14
swap: 5
assign bounty: 1
transfer: 1
206 confirmed on-chain transactions.
92 deposits (gitShield)
111 withdrawals (gitUnshield)
3 swaps via Uniswap v3
All gas paid by the deployer. Users spent zero ETH.
153 tokens launched via Clanker. 33 unique launchers.
From a single bot comment in a GitHub issue.
61 bot installations across 43 unique GitHub accounts.
32 users connected via X. 99 contest entries.
24 groups. 31 group messages. 10 x402 payment transactions.
Manila is live. 🇵🇭
The first next-gen Gitlawb node:
https://t.co/42wk0crn9v - now serving the network from AWS:
▸ Terraform-provisioned, one apply from zero to node
▸ RDS Postgres + encrypted EBS + daily snapshots
▸ Auto-renewed TLS, CloudWatch alerting
▸ Images built & shipped from our own ECR
Made possible by an @AWSstartups credit grant.
The network grows. 🌱
$FIXER ( @fixerprotocol )
Solana native payment layer for AI agents, x402 + MPP behind one API, optional ZK privacy, live on Solana.
🚨Several headline claims aren’t supported by the code.
1. “ZK privacy” is not implemented.
The program’s entire dependency set is anchor-lang + anchor-spl (token only) + security-txt. No Groth16, no Token-2022, no nullifiers. A repo-wide search returns zero matches.
https://t.co/bFIgQaDyVK
2. On-chain records are plaintext.
Every settlement stores the payee and amount in cleartext on the PaymentRecord account. That is the opposite of “amounts & counterparties stay confidential.”
https://t.co/Wftt7Ipr3n
3. Anchor.toml sets cluster = testnet, and the program ID compiled into the code is the testnet one. The mainnet ID has no on-chain footprint.
https://t.co/ritnEyy0PN
4. The advertised test suite doesn’t exist.
The config points test at tests/**/*.ts. There is no tests/ directory in the repo.
Config: https://t.co/VCIL3ViNlv
Repo tree: https://t.co/HxJS58hfyF
5. “Non-custodial” is contradicted in source.
The program’s own comments state the agent key is “held by the Fixer Protocol KMS.” A party holding the signing key is custodial.
https://t.co/9DKMLtA1WI
6. Provenance markers.
The on-chain security.txt points to a different domain (.xyz) and a source repo that doesn’t exist. The advertised Python SDK isn’t on PyPI (404).
https://t.co/h7hJjUxKAW
The Anchor program is real, functional code which is what makes it convincing at a glance. But the privacy layer is absent, it’s on testnet, the tests and Python SDK don’t exist, and the token has no role anywhere in the code.
Reproducible. Verify the links yourself. NFA.
9LR7rbVdZVwXFF5riTznyvdrJXNf95ncsnx9Zdvwpump
Review For @fixerprotocol .
$Fixer
CA- 9LR7rbVdZVwXFF5riTznyvdrJXNf95ncsnx9Zdvwpump
Note- I was tagged to review it and i have no monetary interest in the project you can tag me on any project u want me to review and i will do it for you.
RED FLAG NUMBER 1: I usually dont even research beyond this as this is the biggest red flag, back date comments why does a developer want to do this? what is the reason for it? if ur github starts on 2025 november just run it from there with legit comments why do u want to have more old history no one cares.
RED FLAG NUMBER 2: 0 stars, 0 forks, 13 comments. This is a very new codebase. But if u see the github of the dev he has shown himself as experienced coder.
For anything handling real USDC, that's a meaningful risk signal. No releases have been tagged either.
It is always the same Group from Indonesia ( south east-asia) doing the scam repeatedly. stay safe and cautious.
even i am not expert so if u cant study coding, take help of AI to evaulate it. Here's what Claude said about this github( attached screenshot)
@xamvex@AlphaSeeker21 stay safe.