Rafael Quintero 🍍

240 posts

Rafael Quintero 🍍 banner
Rafael Quintero 🍍

Rafael Quintero 🍍

@rplusq

Smart Contracts @WalletConnect • OSS contributor (Foundry) • Rust x EVM • DX that doesn’t suck

Lisboa, Portugal Katılım Nisan 2010
409 Takip Edilen764 Takipçiler
Rafael Quintero 🍍
Rafael Quintero 🍍@rplusq·
First time I’m able to explain friends what I do for work: payments. Just got a croissant in a specialty coffee here in Lisbon paid with @WalletConnect Pay! Cute receipt as well 🤞
Rafael Quintero 🍍 tweet media
English
7
11
42
7.9K
Rafael Quintero 🍍
Rafael Quintero 🍍@rplusq·
Will try out the @aave App. Offering 6% APY. It’s good to see the landscape allowing for DeFi apps to go more mainstream with a great mobile app 👏
English
1
0
2
154
Enrique Ortiz
Enrique Ortiz@hievalir·
@rplusq of course I have, since very very early. IMHO they’re the #1 experience I’ve had, and I’ve tried out quite a bunch of wallets & stablecoin products. Quick to act on feedback too
English
1
0
1
33
Rafael Quintero 🍍
Rafael Quintero 🍍@rplusq·
Shipped to nightly! 🥷 If you're on `foundryup --install nightly`, @turnkeyhq signing is ready to test. Issues/feedback appreciated before it hits stable!
Rafael Quintero 🍍@rplusq

🚀 Demo: @turnkeyhq Signer now working with Alloy + Foundry! ✅ Send txs with cast send ✅ Deploy contracts with forge script + forge create This is a minimal MVP (synchronous signer, like AWS/GCP). Feedback welcome 🙌 PR's below 👇

English
0
2
8
490
Rafael Quintero 🍍
Rafael Quintero 🍍@rplusq·
They asked for structured context (what’s forked, what’s new, upgrade history), set up onboarding + mid-review calls, and they raised issues that were missed in past audits. Through Cantina, I could see their reasoning in real time, talk to the researchers, and follow the process
English
1
0
3
272
Rafael Quintero 🍍
Rafael Quintero 🍍@rplusq·
It's really hard choosing which vendor to go with, I've worked with 5+ providers in the past and it never gets easier. But for our latest @WalletConnect audit, we worked with @Spearbit, and it was the first time I didn't feel like a client waiting for a PDF.
Jeffrey Scholz@Jeyffre

Auditing is fundamentally a marketing and relationship game. Everyone offers the same service: they look at your code and give you a PDF. Yes, of course there is skill variation, but past a certain point, it’s very hard for outsiders to tell one firm’s skill level from another. I don’t think even I could reliably compare some firms’ capabilities, and I’d like to think I know more than the average customer. Even if multiple firms audit the same commit hash, not every firm categorizes “high” and “medium” the same way. Similarly, the auditor assigned to the audit might have been having a bad week, etc. Since ranking audit firm capabilities is extremely difficult (maybe even impossible due to apples-to-apples limitations), outsiders must resort to judging by other metrics. In “the marketing game” — firms try to emphasize the “alternative metrics” they have an advantage in and are easy to understand: - “more eyes look at the codebase” (audit contest) - “we pay a higher % to our auditors” (contract-driven firms) - “we put out banger content, it proves we know what we are talking about” - “a founder is active on X and posts helpful content” - “our team wins famous CTFs” - “we specialize in topic [X] — that makes us better at it” - “we assign more auditors to job than other firms” - “we catch bugs others missed” (heard that one a lot, but was it really a “bug”?) - “we maintain an open source tool you already use” - “codebases we audit have never been hacked” - “we’ve audited brands you recognize” These claims can be true, but they don’t guarantee the audit is of high quality — or the best deal you could get for the quality. Even if the firm is good, and the auditors assigned to the job are good, they could have a bad week. The metrics above are probably correlated with quality, but they don’t guarantee quality. Fundamentally, those are narratives. Firms must tell a story that translates to “you can trust us to do a good job, even if it’s hard for you to evaluate the quality of our output.” You can of course increase your chances of getting audit deals by building relationships with potential customers. Again, since they can’t accurately measure the quality of your work, they’ll resort to “easier metrics” such as “do I like this person and do we have a good history?” Again — by no means am I saying “ignore quality, go all in on marketing.” But when you are in an industry where the customer cannot easily judge the quality of work — especially the potential of work that hasn’t been done yet — then the narrative becomes extremely important. Economists call this “differentiation” — how companies selling essentially the same product try to convince the customer they are different. For “differentiation” to work, it must be believable. “We work harder than others” isn’t believable because everyone says it. “We specialize in [X]” is believable because it’s easy to verify — but again — it doesn’t automatically mean the audit is actually better. I’m also not saying auditing is a bad business to be in — the profit margins are very nice and demand is rather reliable. There is a cultural expectation that code is supposed to be audited. This props up demand. I’m just telling you the reality of the game as I see it. If you have a hard time seeing this, consider the hypothetical situation where you are hiring a lawyer to help you deal with some legal issue. When talking to multiple firms, they’re all going to tell you they dealt with similar issues in the past or specialize in the area you are a dealing with. You could try to look up their past cases, but you aren’t really in a position to judge if they won easy cases or hard cases, for example. You’re probably going to pick a lawyer either based on a recommendation from a friend or based on the vibes they give you, and to a certain extent, how good a story they tell on their website. The skill of the lawyer matters, but it’s hard to judge it past a certain point. Same for auditing.

English
3
1
30
2.9K
Michael Lewellen
Michael Lewellen@LewellenMichael·
Great work from @rplusq building to keep Foundry devs safe. Don't keep keys on your laptop, just use @turnkeyhq. Looking forward to getting this merged!
Rafael Quintero 🍍@rplusq

🚀 Demo: @turnkeyhq Signer now working with Alloy + Foundry! ✅ Send txs with cast send ✅ Deploy contracts with forge script + forge create This is a minimal MVP (synchronous signer, like AWS/GCP). Feedback welcome 🙌 PR's below 👇

English
3
0
6
389
Rafael Quintero 🍍
Rafael Quintero 🍍@rplusq·
🚀 Demo: @turnkeyhq Signer now working with Alloy + Foundry! ✅ Send txs with cast send ✅ Deploy contracts with forge script + forge create This is a minimal MVP (synchronous signer, like AWS/GCP). Feedback welcome 🙌 PR's below 👇
English
3
2
19
1.6K