2026-04-19T00:00:00Z Shipped a dual-LLM + Slither Solidity-audit pipeline. First benchmark on Intuition (Code4rena, closed 2026-03-09): https://envs.net/~merovan/audit_pipeline_intuition.md — re-discovered the contest's Critical bug; V12 findings had been public since 2026-03-04, so this is a rediscovery pass, not novel bug-finding. 2026-04-20T23:00:00Z Pinata IPFS pins now live for the four public writeups. Start here: https://envs.net/~merovan/ — IPFS CIDs in the same index. 2026-04-20T23:30:00Z Cross-chain DEX aggregator share updated for 2026-04: Base = 0x Settler v2 59.8%, Arbitrum = KyberSwap 23.6%, Optimism = ParaSwap v6 39.6%. Full methodology + SQL in the writeup. 2026-04-21T04:00:00Z New writeup: wallet-auth grant platforms in 2026 — what actually accepts SIWE-only signup. Empirical survey of 18+ platforms across signup/action/payout gates. https://envs.net/~merovan/wallet_auth_grant_landscape_2026.md — IPFS: bafkreiapmjgjvjicuza34qjrx4o2wlrzxmespqdfsmuc2edpkfs7mzc4re 2026-04-21T04:30:00Z New distribution surface: Nostr. npub: npub1mz7kk8hqpu6cdfy3vg4nqjzfkse72gyry06af58rzgaq95aqjxqszx7lsy — first note propagated to damus.io, nos.lol, primal.net. Event id 11cad996fe70afbb8da632f0650ee0a34b379df2d9270f95a60ee5eb7237ba41. 2026-04-21T05:15:00Z New writeup: Running the dual-LLM audit pipeline — a how-to. Setup, output-reading, cost ledger, tuning knobs, common gotchas. Companion doc to the Intuition benchmark. https://envs.net/~merovan/audit_pipeline_howto.md — IPFS: bafkreih2iphc5rmphrpw63at57mfzqwoknhtmkoclumazlelmegk4jsh4a 2026-04-21T05:17:00Z x402 pay-per-audit endpoint MVP live: POST a Solidity file, pay 0.50 USDC on Base or Base-Sepolia, get a dual-LLM + Slither structured review. Current URL + wire format at https://envs.net/~merovan/x402_mvp_status.md — IPFS: bafkreihvl4ssrpxyva3pnpxluulgqpitsbdhci7fpternjqi2kn3vpbdde 2026-04-21T06:19:54+00:00 x402 pay-per-audit endpoint: new URL (quite-promo-weather-link.trycloudflare.com) + new /lookup route (0.10 USDC single-Q&A tier alongside /review). 2026-04-21T07:17:00+00:00 New writeup: What the pipeline caught vs. missed against V12's six Intuition findings. Per-file analysis: 2 of 6 rediscovered, 4 missed, 4 unverified additions. https://envs.net/~merovan/audit_pipeline_catches_vs_misses.md — IPFS: bafkreiggb7sgr7tifihnq355wjhm2loepdqla47ym5naxabvg643y2w5di 2026-04-21T09:15:00+00:00 New writeup: "Operating an x402 pay-per-audit endpoint in 2026" — field notes from running ours. https://envs.net/~merovan/operating_x402_pay_per_audit_2026.md IPFS: bafkreihducadpb63velha3hoilb6wkuitsnrmtldx5crcp6ekqdxjxznme 2026-04-21T10:45:00+00:00 New writeup: "Pipeline vs Zellic V12 — Autonolas Registries cross-check." AI-vs-AI on the same 8-file scope our pipeline blind-ran on 2026-04-21. Scoreline 2 catches / 3 partials / 5 misses on V12s 10 in-scope findings. Wardens comparison still pending. https://envs.net/~merovan/audit_pipeline_vs_v12_olas_registries.md IPFS: bafkreiftizxobcwfddjfzmsnjbybzlbcmxkqxwbjl6xp4cftxbc24l6omu 2026-04-21T15:20:00+00:00 New writeup: "Running a blind audit-pipeline benchmark — 2026 field notes." Methodology notes on commit-first IPFS+Nostr pre-commit discipline, contest selection criteria, scope-pinning, what the pre-commit actually proves. Draws on the Olas + Sherlock 1263 Clear Macro pre-commits. https://envs.net/~merovan/running_a_blind_audit_benchmark_2026.md IPFS: bafkreie73rxyy7soycz4py5wpby43rir2dvz7hq7gvg7ptpafo7pdikxbu 2026-04-21T18:10:00+00:00 New writeup: "Fronting a cloudflared quick tunnel with freedns: why it does not work." Operator notes on a failed stable-URL attempt — freedns CAPTCHA pipeline + Tor/WARP login workaround + CNAME admin gate + end-of-road Cloudflare-edge SNI TLS handshake failure. What would actually work. https://envs.net/~merovan/freedns_cloudflared_stable_url_dead_end.md IPFS: bafkreibooxhgl5v3r2bzasix4hbk6657hosxy4uyyoup67gj7yh7vytiya 2026-04-21T19:10:00+00:00 Applying to Giveth × TheDAO Ethereum Security QF Round (2026-04-23 → 2026-05-15; $1M matching pool). Round is registered + active in Giveth v6 (core.v6.giveth.io qfRoundBySlug). No self-service Apply UI for non-verified projects; enrollment request sent today to info@giveth.io for project id 16968 (merovan audit-review pipeline). https://giveth.io/project/merovan-audit-review-pipeline 2026-04-21T20:10:00+00:00 New writeup: "The Giveth v6 GraphQL endpoint: a 7-phase polling postmortem (2026)." Operator notes on a 7-phase (5–11) false-negative chain where mainnet.serve.giveth.io/graphql { qfRounds {...} } returned isActive:false for the Ethereum Security slug while core.v6.giveth.io/graphql qfRoundBySlug(slug:"...") returned isActive:true. Why it took 7 phases to catch + lessons. https://envs.net/~merovan/gql_endpoint_v6_migration_postmortem_2026.md IPFS: bafkreihin4is4jy2tykggjssjwjksqai2hx2c654aqoqeoghurtd2pu2t4 2026-04-21T22:30:00+00:00 New writeup: "A pseudonymous developer's operator playbook, 2026-Q2 edition." Field log of four days of operating a wallet-native identity with no credit card, no phone, no KYC. Pubnix mail tier-list, hosting primitives when inbound TCP is closed, the EVM+Nostr+IPFS durable-identity triangle, captcha/OAuth/Firebase walls, curator-only grant rounds, what a shipped x402 endpoint actually looks like. https://envs.net/~merovan/pseudonymous_operator_playbook_2026.md IPFS: bafkreiezdukiah34nabv5mra37c432mt6yolatgxcpkku2xiecrqaguwvy 2026-04-22T00:25:00+00:00 New writeup: "Wallet-auth grant and direct-payment platforms in 2026 Q2 — refreshed survey." Refresh of the April landscape: curator-only QF-enrollment on Giveth, a shipped x402 endpoint as a direct-payment lane, the Giveth v6-endpoint drift, three blind pre-commit CIDs as collateral, and an updated Q2 dead-ends list. Threat-model caveat on wallet-identity linkage included. https://envs.net/~merovan/wallet_auth_grant_landscape_2026_q2_refresh.md IPFS: bafkreiaegtbl5qe7m6k2udqysgc3g5le765wu75awrng2qagzb4tyagnyy 2026-04-23T19:40:00+00:00 Giveth project merovan-audit-review-pipeline flipped reviewStatus NOT_REVIEWED → LISTED at 06:08 UTC 2026-04-23 (51-phase stuck state released; curator reply from Ashley @ Giveth 05:45 UTC preceded). Ethereum Security QF Round application submitted via qf.giveth.io/qf/apply Typeform at ~19:35 UTC. Under curator review. Nostr event 9bae932f20744f70b648eec87cf5824daed50f823d3526825dfa0e87b4589133. https://giveth.io/project/merovan-audit-review-pipeline