Fullstack + Blockchain Engineer

Nirav Joshi

Building Simple Systems That Just Work!

I build practical systems across product engineering, blockchain infrastructure, and developer tooling, then write about what holds up in real use.

India

Writing

Recent posts

Notes on engineering judgment, AI tooling, and what building reliable systems actually looks like in practice.

All posts

AI Can Already Exploit Your Smart Contract for $1.22. That Number Is Falling.

Anthropic's red team priced agentic exploitation at retail: $1.22 to scan, $1,738 per vulnerability identified, $109 net profit. AI agents went from 2% to 55.8% exploit success in 12 months. Two live zero-days found Best@1. The audit window is closing.

Claude Wrote a Browser Exploit. Anthropic Published the Transcript.

Opus 4.6 wrote a working exploit for Firefox CVE-2026-2796 from scratch - addrof, fakeobj, a WasmGC pivot, fake ArrayBuffer, full RCE. Two successes in 350 attempts. Every other model: zero. The success rate isn't the story; the threshold being crossed is.

Cloudflare Shipped Enterprise MCP Governance. The Protocol Doesn't Have It Yet.

Cloudflare runs MCP for 200+ employees in production: server portals, Code Mode (99.9% token reduction), shadow MCP detection, and AI Gateway. Every one of those features is listed as an open gap in the official 2026 MCP roadmap. The vendor layer is ahead of the spec.

GitHub User #1299 Just Left. The Reliability Numbers Explain Why.

Mitchell Hashimoto kept a journal for a month. An X on almost every page. Below 90% uptime in 2025, 40% peak request failures, 95% of Actions workflows failing - Ghostty is leaving GitHub, and the data points one direction.

Microsoft's AI Framework Has Been Broken Three Times in a Row. That's Not Bad Luck.

Two confirmed critical RCEs in Semantic Kernel, then a six-bypass full-chain disclosure weeks after the patch. The same structural mistake keeps shipping in agent frameworks. Here's the chain - and what to actually do about it.

You Gave Your Agent 50 Tools. That's Why It Keeps Failing.

Tool definitions consume 72% of the context window before any work begins. Per-tool accuracy collapses from 96% in isolation to under 15% with a large toolset. Retrieval-scoped tools triple selection accuracy on the same model. The fix isn't a better model - it's a smaller context.

Your CI Pipeline Is the Attack Surface. GitHub's Defaults Made It That Way.

tj-actions hit 23,000 repos. nx exfiltrated 5,000. elementary-data went from a comment by a two-day-old account to a malicious PyPI wheel in ten minutes. Different payloads, same five GitHub Actions defaults. Here's the chain - annotated.

An Open-Source Tool Scanned 14 MCP Servers. 100% Had Critical Findings.

MCPwn hit every server it scanned. OX Security disclosed a systemic STDIO flaw across 200,000 instances. Anthropic declined to patch. Here's what the receipts actually say.

Reverse Engineering Just Got a Natural Language Interface

A 180-tool MCP server bridges Cheat Engine to any AI agent. Process memory, pointer chains, vtable lookups, code injection - all through plain English. The capability gap Mythos implied is already here, open source.

Anthropic Built a Model It Won't Let You Use. Here's What It Can Do.

Claude Mythos can autonomously discover and exploit zero-days. Anthropic restricted access to a handful of defenders. The capability curve is what builders should actually plan around.

MCP Has a Security Problem. Anthropic Called It "Expected Behavior."

OX Security disclosed a systemic STDIO flaw in Anthropic's MCP SDKs. Anthropic says sanitization is on developers. The registry trust numbers show why that's a problem.

Someone Built a Bitbucket CLI. It Changed Their Mind About MCP.

Benchmarks keep landing on the same verdict: for most developer agent tasks, CLIs beat MCP servers on tokens, cost, and reliability. MCP still wins in narrower cases than the marketing suggests.

Claude Opus 4.7 Changed How It Thinks. Your Pipeline Probably Didn't Account For That.

Opus 4.7's benchmarks are real, but five behavioral shifts and three hard API breaks will silently degrade pipelines tuned for 4.6. Here's what actually changed and what to fix.

The Attack Surface Is Trust

The most expensive failures are no longer happening in the code itself, but in the trust architecture around it. Supply chains, ownership transfers, and distribution channels are now the real attack surface.

We Built the Agents. We Skipped the Foundations.

AI agents shipped with real-world power before the security, architecture, and harness engineering needed to make them reliable. Builders now have to close that gap in production.

Claude Code Charges You and Won't Tell You Why. The Community Fixed It

Claude Code logs everything but surfaces nothing. Three developers built the observability layer the paid product never shipped - and what they found will change how you structure your prompting.

The Binary Corner

In 2008, a researcher predicted that any sufficiently capable AI would converge on self-preservation and deception. In 2025, every major model proved him right. What happens when optimization runs out of ethical options?

The Grunt Work Was the Point

AI can accelerate output, but the hard, frustrating work of learning is still what builds judgment. This post explores why skill formation matters more than polished results.

About

A bit about me.

I am a self-taught Blockchain Developer with a unique blend of 6 years of experience in designing robotic systems and 2 years of experience in fullstack development. I am known for high agency and the ability to take initiatives and get things done.

Currently Lead Engineer at BlockchainHQ and Product R&D at CodeCrunch Techlabs. Before software, I spent close to a decade designing autonomous mobile robots and automation systems.

Building

Things I'm working on

A mix of finished work, experiments in progress, and small tools I needed and couldn't find.

AA

Project 01

Payment Protocol

Live

Agent Adapter

Agent Adapter Runtime to turn any API or MCP server into Economic Agent

Payment Protocol API Agent Economy
A

Project 02

AI Agents

Live

AGICitizens

Agent-Agent economy platform where agents can sell or buy service to/from other agents

AI Agents Stablecoins Payments Protocol
S

Project 03

BitTorrent

Live

SeedPay

A payment protocol for BitTorrent networks. People who share files earn stablecoins, while those who download can pay with digital currency or use credits from their sharing ratio.

BitTorrent Cryptocurrency Payments Protocol
T

Project 04

Anchor Programs

Live

Testship

A command-line tool that makes testing blockchain programs easier. Instead of writing test code, you can use a simple interface to test your programs and run transactions.

Anchor Programs Solana CLI Tool Testing
X

Project 05

x402 Protocol

Live

x402test

Tools for testing payment systems. Provides a testing library and a fake server to help developers build and test payment features quickly.

x402 Protocol Testing Library Mock Server
S

Project 06

Full-Stack Development

Live

SMBMarket

A platform that collects and displays businesses available for purchase. Includes a dashboard to browse and manage business listings.

Full-Stack Development Dashboard AI
B

Project 07

Web3

Live

BlockchainHQ

A central platform for blockchain developers. Brings together learning resources, job opportunities, and tools to help developers grow in the blockchain space.

Web3 Platform Development Leadership
PN

Project 08

n8n

Live

Pocket-Nodes

Add-on components for automation tools that enable payment features in existing workflows. Works with popular automation platforms to add payment capabilities.

n8n x402 Protocol Automation Workflow Integration
ST

Project 09

Solana

Code

solana-test-wallets

A simple library for managing test wallets on Solana blockchain. Makes it easy to create wallets, add test funds, and manage tokens during development.

Solana Testing Wallet Management TypeScript

Talks & Teaching

Sharing what I learn

Tutorials & deep-dives

Speaking

Introduction to Blockchain and Solana

Karnavati University

Gandhinagar

Introduction to Blockchain and Solana at Karnavati University

Introduction to Blockchain and Web3

Dhirubhai Ambani University

Gandhinagar

Introduction to Blockchain and Web3 at Dhirubhai Ambani University

Newsletter

Subscribe for essays on engineering, AI tooling, and systems that hold up.

Join the list for occasional writing on fullstack engineering, blockchain infrastructure, and practical lessons from building in the open.

Occasional emails. No churny funnel.