Aaaaaand it works for meme coins too!
https://t.co/MXuSKXHFuu
No ads. No API keys. No backroom deals.
Just outbid every other coin to rank #1 — every launchpad, every chain, one board 🚀
Aaaaaaand we're live!
https://t.co/ZElVA2hguv
No ads. No API keys. No revenue sharing.
Just outbid your competitors to rank #1 and consider marketing done for today 🚀
multi-exchange CVD imgui widget (perps + spot)
aggr was a big inspiration for this one. goal is to analyze divergence across all major exchanges in real-time next to all the other widgets
ofc binance spot and perps leading the dump at NY open while coinbase buying
Someone found an RCE on my website yesterday.
CVE-2025-55182.
React2Shell.
I don't have a bug bounty program.
I never asked for a security assessment.
I woke up to a DM: "Hey I found a critical vulnerability in your site. I only ran the exploit to verify it worked. Here's my PayPal for the bounty."
Bounty?
I checked my logs.
Forty-seven requests to my RSC endpoint.
Something, something ... Prototype pollution payloads.
They used the GitHub script.
The one with 2,000 stars.
The one that runs id automatically "for verification purposes."
They spawned a shell on my production server.
uid=1001(nextjs) gid=65533(nogroup)
They took a screenshot.
They posted it on Twitter.
"Popped a Shell on a Live Website 🚀💀 #BugBounty #CVE-2025-55182 #YOLO"
They got 84781 likes.
My customers' data was on that server.
I asked them to delete the screenshots.
They said "I removed the domain name, you should be thanking me."
Thanking them.
For unauthorized access to my production infrastructure.
For running arbitrary commands on systems I own.
For posting proof of exploitation for clout.
They called it "responsible disclosure."
I called my lawyer.
They called me "ungrateful."
I called the FBI.
Now they're in my DMs explaining that "this is how the industry works" and I "don't understand pen testing."
A pen what?
I understand it perfectly.
I understand that running https://t.co/C6kmBequB5 against random websites isn't research.
I understand that "I removed the identifying info" doesn't undo the unauthorized access.
I understand that #BugBounty doesn't apply when there's no bounty program.
I understand that finding my site on Shodan doesn't constitute authorization.
Their followers are defending them now.
"Presumption of innocence."
"You don't know if it was authorized."
"The screenshots were redacted."
Three hundred people are calling me a bootlicker for reporting a crime.
Someone said I should be grateful they didn't deploy a cryptominer.
The bar is underground.
I just wanted to run a small Next.js app.
I didn't ask to be someone's proof-of-concept.
I didn't consent to being their "first"
I didn't sign up for an unscheduled penetration test from a stranger with a GitHub account.
There is no safe harbor for spraying public exploits at random websites.
There is no legal protection for "I was just verifying the vulnerability."
There is no ethical framework where unauthorized prototype pollution is a favor.
But sure.
Thank you for your service.
You found a CVE that was already public.
Using a tool someone else wrote.
Against a target that never authorized you.
And you posted about it on main.
For likes.
Hero.
to S&P regarding your Tether rating:
We wear your loathing with pride.
The classical rating models built for legacy financial institutions, historically led private and institutional investors to invest their wealth into companies that despite being attributed investment grade ratings collapsed pushing worldwide regulators to challenge such models, the independence and objective assessment of all major rating agencies.
The traditional finance propaganda machine is growing worried when any company tries to defy the force of gravity of the broken financial system. No company should dare to decouple itself from it.
Tether instead built the first overcapitalized company in the financial industry, with no toxic reserves. And yet is and remains extremely profitable. Tether is living proof that the traditional financial system is so broken that it's becoming feared by the emperors with no clothes.
Mutluluğunu veya başarısını samimiyetle paylaşan kişilere haset etmenin büyük bir kişilik problemi olduğunu düşünüyorum. O algıya sahip insanları takmadan yoluna devam etmek gerekiyor. Altında bir sürü etmen var; psikolojik, sosyoekonomik statü, özgüven kıtlığı vs.
Oturup kafa yormaya değecek, laf anlatılacak insanlar değiller.
Benden naçizane bi tavsiye. Ben de ara ara ite kopuğa ders vermek için bu hataya düşüyordum eskiden. Siz yine de paranızı ve rızkınızı paylaşmayın. Nazarı var, manyağı var. İdiotun tekine kendini ispatlayacaksın diye dert sahibi olmayın.