flipskylark was here

8.8K posts

flipskylark was here banner
flipskylark was here

flipskylark was here

@mattgotitt

SIPPIN ON JET FUEL ✈️ community builder/creative producer KILROY WAS HERE

Brooklyn, NY Katılım Mayıs 2021
2.3K Takip Edilen2.1K Takipçiler
Mikasa Was Here
Mikasa Was Here@mikasasolslayer·
@_Shadow36 This is why you're the goat. Not a single kol is posting about kilroy anymore. They all sold and moved on and even refuse to engage anymore. The fact that you're still supporting in public means a lot to us and sets you apart from from every other kol in this space.
English
2
2
27
381
Shadow
Shadow@_Shadow36·
Sellers don’t matter if the coin goes up anyways
GIF
English
109
16
273
15.6K
Aakash Gupta
Aakash Gupta@aakashgupta·
Someone just poisoned the Python package that manages AI API keys for NASA, Netflix, Stripe, and NVIDIA.. 97 million downloads a month.. and a simple pip install was enough to steal everything on your machine. The attacker picked the one package whose entire job is holding every AI credential in the organization in one place. OpenAI keys, Anthropic keys, Google keys, Amazon keys… all routed through one proxy. All compromised at once. The poisoned version was published straight to PyPI.. no code on GitHub.. no release tag.. no review. Just a file that Python runs automatically on startup. You didn’t need to import it. You didn’t need to call it. The malware fired the second the package existed on your machine. The attacker vibe coded it… the malware was so sloppy it crashed computers.. used so much RAM a developer noticed their machine dying and investigated. They found LiteLLM had been pulled in through a Cursor MCP plugin they didn’t even know they had. That crash is the only reason thousands of companies aren’t fully exfiltrated right now. If the code had been cleaner nobody notices for weeks. Maybe months. The attack chain is the part that gets worse every sentence. TeamPCP compromised Trivy first. A security scanning tool. On March 19. LiteLLM used Trivy in its own CI pipeline… so the credentials stolen from the SECURITY product were used to hijack the AI product that holds all your other credentials. Then they hit GitHub Actions. Then Docker Hub. Then npm. Then Open VSX. Five package ecosystems in two weeks. Each breach giving them the credentials to unlock the next one. The payload was three stages.. harvest every SSH key, cloud token, Kubernetes secret, crypto wallet, and .env file on the machine.. deploy privileged containers across every node in the cluster.. install a persistent backdoor waiting for new instructions. TeamPCP posted on Telegram after: “Many of your favourite security tools and open-source projects will be targeted in the months to come.. stay tuned.” Every AI agent, copilot, and internal tool your company shipped this year runs on hundreds of packages exactly like this one… nobody chose to install LiteLLM on that developer’s machine. It came in as a dependency of a dependency of a plugin. One compromised maintainer account turned the entire trust chain into a credential harvesting operation across thousands of production environments in hours. The companies deploying AI the fastest right now have the least visibility into what’s underneath it.
Andrej Karpathy@karpathy

Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords. LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm. Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks. Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages. Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.

English
279
2.2K
10.7K
2.5M
flipskylark was here retweetledi
Mikasa Was Here
Mikasa Was Here@mikasasolslayer·
We’re in a rotation market where people don’t get rewarded for holding anymore. Mass deployers are being idolized and glazed while the bagworkers are getting exhausted and burned out. I love to see @a1lon9, @json1444 , @Pumpfun trying to bring back culture and community to this space. This space needs a huge change and I believe Pumpfun really could make a difference. Everyone wants to complain but nobody really wants to come up with solutions. As a delusional bagworker myself here are 10 ideas that could help: 1. Bring back Pumpfolio: For projects to become part of pumpfolio was a huge deal and a massive milestone. Instead of communities fighting against each other, pumpfolio brings them together. I loved this so much! 2. Alon loads up a doxxed wallet with a few sol and buys 1 sol of hardworking communities that have been alive for 3+ months (<500k mc). This exposure can help struggling communities a lot and it can be so much fun. People will even speculate on which coins alon is gonna bid and try to front run and thus inject capital in struggling communities that could use the volume. Bring back 1 sol and a dream Alon! 3. Pumpfun contests: I think it would be amazing if communities can create content for pumpfun and the most creative content could get a repost/shoutout. This gives older projects with creative content a chance for exposure. We need more creativity in the space and this could be a fun way. 4. Extra filter in Pumpapp for older coins with good communities. I honestly think this could be a gamechanger. This could also help prevent vamps because people can easily see if a community exists already. It's so hard to find older active communities on dex. 5. Spotlight communities: You already have Pumpfun trending which is for new coins, but how about adding spotlight that can give exposure to older communities too? You could do good dd and then weekly spotlight 1-2 older communities. 6. Anti vamp measurements: Not sure if it’s possible but would it be possible to block vamps in the pumpfun app? For example the same ticker can only be launched every 24 hours? Right now the same ticker/coin gets deployed hundred times a day and is not helping anyone. If a ticker could be blocked for 24 hours it will give the coin a chance to build a community. 7. Add some community advisors to the Pumpfun team. There are some amazing community builders in this space who really know what this space needs. By adding community advisors to Pumpfun it will also show to us that you are taking this seriously. 8. Build a cto lead community with pumpfun where leads can join, connect and get help. Being a CTO lead can be very lonely and I’m sure if leads can connect and discuss together this could help them a lot. Leads from different projects arguing and discussing together could be very useful for Pumpfun too and give lots of insights. Could be as simple as making a tg community for devs/leads. 9. Highlight good leads: This might be a bit tricky, but these days there are barely any good leads left. Who are they and how can we find them? Terminal has a bunch of good traders affiliated, but why can’t pump get affiliated with amazing community builders/ leads? Its not the day traders that take projects to insane numbers. 10. Bagworking contests: If you guys are really serious about making bagworking great again, then maybe you guys could come up with some cool ideas to reward bagworkers and aidrop them some pump tokens for example. You could even make a requirement that they need to hold at least some pump tokens to qualify so you don’t just attract giveaway hunters. I know many of these ideas are delusional and farfetched but I feel like Pumpfun could do so much more to support (old) communities. Right now the majority of updates are focused on rewarding traders but how about rewarding communities? What can you guys do to really help hardworking communities? Imo the first step could be by giving exposure to old, hardworking communities. It’s not the traders and mass deployers that are gonna raise the ceilings. It’s believers, bagworkers and delusional holders that refuse to sell for a x2 that are gonna raise the ceilings. We need to support them before they all give up and turn to mass deploying/rugging and farming out of frustration. Happy to think about more ideas if you guys are really serious about helping out communities.
Pump.fun@Pumpfun

bring back bag working bring back MAX RAIDS!!! bring back telegram voice chats fuck it, bring buybots back too

English
80
75
206
32K
Waka Flocka Flame 🔥
Waka Flocka Flame 🔥@WakaFlocka·
I been around spaces I wasn’t invited Still made a way, adapted, thrived. They tried to swat what they couldn’t define Now I exist in the back of they mind That’s how it works when you real with yourself You stop needin approval or help You become somethin they can’t ignore 😤
Waka Flocka Flame 🔥 tweet media
English
34
64
334
19.1K
flipskylark was here
flipskylark was here@mattgotitt·
sorry ive been so quiet. been cooking some special things. -Flip was here
English
0
0
1
50
Alex Finn
Alex Finn@AlexFinn·
BUT WHAT HAS YOUR OPENCLAW ACTUALLY BUILT??? Well, nothing to be honest. Other than: 1. Shipped 5 new features autonomously to my SaaS Creator Buddy, leading to 25% higher ARR 2 Proactively wrote 8 YouTube scripts that has led to 75,000 new subscribers and $20,000 of ad revenue 3. Completely automated my weekly newsletters, leading to 6,000 new (45,000 total) subscribers and $12,000 more ARR 4. Trained its own AI model based on my thousands of scripts, tweets, newsletters, and emails so it sounds exactly like me so it can accomplish all of the above 5. Planned and scripted tons of educational content for my private community which has increased retention to 94% 6. Automated all the tasks that bring me unhappiness like email and DM organization 7. Kept me in the loop in real time of all the AI advancements the last month so my content can stay cutting edge, increasing impressions and engagement over 10x and revenue into the hundreds of thousands 8. Brought me a tremendous amount of joy that has led to me waking up every single morning full of hope and excitement, the most happy and satisfied I’ve ever been in my life Other than that nothing much. You’re right Openclaw is useless
English
207
58
1.1K
78.2K
Mikasa Was Here
Mikasa Was Here@mikasasolslayer·
Gm guys, I hope everyone is doing great. I woke up stressed, burned out and with a big headache. When we’re green they call you goated and congratulate you. When we’re red they abandon you the first chance they get. It’s such an emotional rollercoaster leading a project. I have always been struggling with my emotions a lot. You can’t stop people from selling and I don’t blame anyone. However I would lie if I said it doesn’t bother me. A few days before we’re talking about sending it to millions together. Then we get a real opportunity and yall sell and move on. It sucks so much to see people leave who I thought I could count on. It makes me realize that many people just care about themselves. It even makes me question sometimes why I care about others so much and not just sell and move on? Anyway I knew what I signed up for, and it’s part of the game. We learned a lot of valuable lessons these last few days. I’m gonna touch some grass for the next few hours and lock in later. I have been so locked in the last few days that I can’t think straight anymore. Literally worked until 5-6am every morning trying to build momentum and create volume, which we had to fight for to get in the first place. Gonna clear my head today and get rid of all the negative and depressing thoughts. We will overcome this challenge like we always did. Kilroy still has one of the best narratives in the space. It still has one of the best communities in the space. We grew so much and got so many eyes on us because of @Pumpfun . Nothing has changed, and @OnlyLJC and I are more committed than ever. I just wanted to share my frustrations and be transparent with yall. The last 4 months have been depressing and I sacrificed so much for Kilroy and the community already. I'm not a whale with a lot of money, I'm pretty much all in on Kilroy and even put my salary in the chart. We’re not giving up though. What doesn't kill you makes you stronger! Gonna lock in later today!
Mikasa Was Here tweet media
Mikasa Was Here@mikasasolslayer

Hey guys, The last few days have been absolutely insane for $Kilroy. We got so much attention and new eyes thanks to @Pumpfun , @a1lon9. I honestly never expected this support and I'm so grateful! We just showed up every day and got rewarded. Thank you so much Pumpfun! We’re in a rotation market where attention shifts quickly. People sell their conviction bags to rotate in the next runner. We can’t change this but we can change our mindset. Instead of donating to bundlers we can support real communities. In the last few days we got so much support from ct, and this confirmed to me that we're heading in the right direction. Bagworking is hot again! It's not a sprint but a marathon, slowly we're building a rock solid community with believers who refuse to sell for pennies. You can join or fade us, but you won't be able to ignore us. Make Bagworking Great Again!

English
76
24
180
25.4K
slingoor
slingoor@slingoorio·
only guys in this range raiding me hard feels like motion + kilroy. idk the price of either but i know they’re under a mil.
English
71
23
132
13.8K
sopersone
sopersone@sopersone·
I launched a weather trading bot on Polymarket with $100 -> $8,000 here is how it works and how to copy it most people on polymarket price weather markets randomly based on vibes or a phone app but there is NOAA - a government agency that publishes free forecasts with 94%+ accuracy the result? you regularly see something like this: > NOAA gives a 94% probability that NYC will reach 74°F on Saturday > polymarket prices it at 11¢ the bot buys at 11¢ sells when the market corrects to 45¢ that is 4x on an almost guaranteed outcome how to launch it in 5 steps: > install OpenClaw on your pc > connect it to ChatGPT Plus + a telegram bot > create an agent on simmer markets deposit $100 > install the weather trading skill with: clawhub install simmer-weather > send the config to the bot and it starts trading the bot scans 6 cities every 2 minutes non-stop example of a real trader: profile: @automatedAItradingbot?via=sopersone" target="_blank" rel="nofollow noopener">polymarket.com/@automatedAItr… +$75,055 just from weather markets zero emotions. fully automated the window is still open but not forever
English
38
28
288
64.1K
onchainschool.pro
onchainschool.pro@how2onchain·
#HYPERLIQUID FUTURES: IN-PLAY POSITIONS WALLET This fresh wallet, created in early February, has shown $300K realized profit in just two weeks. Let’s break down its positions Currently, the portfolio holds 5 long positions, with the most profitable ones being Aztec and Init Trade details: - Earned on $S and missed out on $Bera - Trades in a wide range with no short stops - Uses 3x leverage to balance - Avoid trading stocks with this wallet, as it resulted in a $90K loss DYOR - keep an eye on this wallet for potential interesting moves Wallet: 0x90518c89564a36a71977a5832bc69339fc921e80
onchainschool.pro tweet media
English
1
0
4
864
Snibby
Snibby@ItsSnibby·
@mattgotitt Facts, some events barely shake the ones who actually play the long game. Kilroy knows the drill. @mattgotitt follow back appreciated fr
English
1
0
1
5
flipskylark was here retweetledi
AG^ Was Here
AG^ Was Here@TheJeetHunter·
When the market goes quiet the weak hands leave When the weak hands leave the supply gets tight When the supply gets tight it takes nothing to send it $KILROY is sitting in that window right now Soldiers drew this in silence too Right before they took the whole beach These are the setups you look back on and kick yourself for not buying
AG^ Was Here tweet media
English
12
9
28
361
Wuffett was here
Wuffett was here@BarrenWuffettX·
Gkilroy, Did you know they're selling dollar bills for $0.0002669 each on solana? I'd buy ASAP before the matrix patches this glitch. This IS financial advice. Wuffett
Wuffett was here tweet mediaWuffett was here tweet media
English
12
4
20
213
Mikasa Was Here
Mikasa Was Here@mikasasolslayer·
Never try to bully someone to buy a coin. That's not conviction, that's desperation. They'll sell the first pump or the first drawback. Show them the lore/narrative, and if they don't like it move on. Nobody likes to be "bullied" into buying a coin. It ain't MLM fam.
English
33
8
88
1.6K