Skip to content
View Eras256's full-sized avatar

Block or report Eras256

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Eras256/README.md

Eras256

I build payment and trust infrastructure for AI agents — one product per network, each built for what that network does best, not one idea copy-pasted five times.

Product What it does Network Status
Nirium Autonomous treasury + machine-to-machine (x402/MPP) payments Stellar Mainnet (non-custodial roles), invite-only
Vouch402 x402-metered risk checks for agents, with on-chain attestations Base Mainnet, full flow settled
Kumply On-chain KYC/KYB/KYA compliance attestations Avalanche Fuji testnet (full) · mainnet (read-only beta)
Periplo x402 payment facilitator + discovery catalog for agents Stellar Testnet
Contextio Treasury/payroll agent for LatAm companies, bound to a signed legal-context document Stellar Testnet (full) · mainnet (invite-only, pre-audit)
Prova Signed on-chain receipts for AI agent actions Solana Devnet
Votalo Passkey-signed group voting, no wallet Monad Testnet

Built with my cofounder, Monserrat Mendoza — Dev Lead, five merged PRs in Nirium plus real fixes now shipped directly in Kumply and Vouch402 too; full detail on her own profile.

Each product stays on its own network until real demand says otherwise — Contextio's mainnet is narrower than its testnet build, Prova hasn't left devnet. That's a gate on evidence, not a roadmap slide.


Proof, not claims

Everything below is a link you can check yourself. Where something's still open or unmerged, it says so.

  • Found and fixed a crash in x402's own official conformance suite, merged upstream the same week — x402-foundation/x402#3228.
  • A skill PR survived ~16 real review rounds across 21 days before merging — stellar/stellar-dev-skill#97.
  • Found a security vulnerability in the exact library Vouch402 calls for every attestation it emits, fixed by the maintainer — eas-sdk#132.
  • A 32-day mainnet outage on a shared facilitator got fixed; verified it myself with a real $0.05 payment, not a 200 response — OpenZeppelin/relayer-plugin-x402-facilitator#47.
  • A protocol I'd never worked at merged 4 of my PRs in one sitting and thanked me by name — Trustless-Work/agentic-escrow-research#1–#4.
  • When I was wrong, I said so and closed my own issue against myself — OpenZeppelin/stellar-contracts#839 turned out to be my own construction bug, not a library gap.
  • Two Stellar Community Fund Instawards, delivered against real milestones — gated on being an active Stellar Ambassador, the program's own stated eligibility rule, not something I'm claiming on my own.
  • Every contract I ship is non-custodial by construction — the client's own wallet signs, or a role that by contract design can't move funds. Never a key of mine that can.
Full receipts — every PR, issue, and bounty, by project

Most of my public work is either a protocol implementation I maintain or a bug I found in something I depend on, then a patch for it. Where a fix landed as someone else's PR, that's named — the report was mine, not the patch.

Three Stellar products below (Periplo, Nirium, Contextio) share real upstream dependencies — same protocols, sometimes the literal same bug — so each fix is attributed to the specific project it came from, not merged into one pile.

Snapshot re-verified live against the GitHub API on 2026-10-09; the search links at the bottom always supersede it.

Kumply, Vouch402, Prova — upstream contributions

Kumply (Avalanche) — three open bug reports against a third-party community skills repo, Ayomisco/avaxskills, found while building on top of it: #2 (a subnet-deployment skill cites CLI commands that don't exist in the real ava-labs/avalanche-cli), #3 (a precompiles skill has the wrong genesis key name for TxAllowList), #4 (a wagmi skill cites an outdated version and a deprecated hook). All still open. I'm an official Team1 LatAm collaborator — an Avalanche-ecosystem-wide role, not tied to a single project. Also shipped AgentHub Protocol for Avalanche's Hack2Build: Payments x402 hackathon — real x402 micropayment code, on-chain agent reputation, and DeFi integration code for Trader Joe, Benqi, and Aave V3. SDK published on npm, contracts deployed to Fuji testnet — dormant since January 2026, stated plainly rather than presented as active.

Vouch402 (Base) — base/skills#152, an open PR adding a Vouch402 listing to Base's own community skills catalog. Also eas-sdk#132 (closed, fixed) and foundry-rs/foundry#16209 (cast wallet new <name> failed with a bare account name — closed 2026-09-09, fixed by @riba2534 in #16219), both found auditing tooling Vouch402 depends on. I hold the Based Developer Ambassador role in Base's own Discord — real and active.

Prova (Solana) — otter-sec/anchor#4960, bumping heck 0.3 → 0.5 to drop an unbounded edition2024 dependency landmine in the Anchor framework Prova's on-chain program is built on — merged 2026-09-30 by @jamie-osec.

Periplo — upstream contributions

Full first-hand narrative with transaction hashes and reproduction steps lives in Eras256/Periplo's own README.

Merged

PR Repo Merged
#3228 — scope EVM/SVM client signer derivation to the selected --families, fixing a crash in the official e2e conformance suite x402-foundation/x402 2026-08-31 — authored by me, merged by @phdargen. Closes #3187, which I also filed. An earlier attempt, #3219, was closed unmerged and superseded by this one.
#103 — point ECOSYSTEM_CARDS copyValue at raw content, not GitHub's blob HTML page stellar/stellar-dev-skill 2026-08-28, by @kaankacar
#3306 — add a dedicated extension_responses/extensionResponses field instead of leaking EXTENSION-RESPONSES data via the buyer-facing extensions field x402-foundation/x402 2026-08-31, by @phdargen. Closes #3270, which I filed. Not my code — full detail below.
#97 — production patterns for x402 + MPP stellar/stellar-dev-skill 2026-09-05, by @kaankacar — this one's Nirium's, not Periplo's

Open fix PRs

PR Repo Fixes
#3215 — derive one wildcard pattern per namespace, not one per registration x402-foundation/x402 #3172
#3138 — use the raw resource URL as canonical for opaque-origin schemes x402-foundation/x402 #3121
#3098 — upto scheme implementation spec for Stellar x402-foundation/x402 #3097

Bug reports that landed

  • x402#3171 — paymentRequirementsMatchAccepted threw on a missing/null payload.accepted. I found and reported it; fixed by @JasonColapietro in #3180, merged 2026-08-17.
  • x402#3169 — isValidRouteTemplate's traversal/scheme-injection checks decoded routeTemplate only once, so double percent-encoding bypassed both. Filed with full repro; fixed by @ygd58 in #3213, merged 2026-09-09.
  • x402#3270 — HTTPFacilitatorClient.settle()/verify() decoded the EXTENSION-RESPONSES header and discarded it. Fixed on Periplo's own side the same day; the actual upstream fix was the maintainer's own #3306 (Python, @phdargen), introducing a dedicated field instead of reusing extensions — rejecting the shape my own workaround used. My /settle still uses the old shape pending a migration to the new field, now available since @x402/core has moved to 2.28.0.
  • eas-sdk#132 — getUIDsFromAttestReceipt trusted log topic0 without checking the emitter address. Closed as completed by the maintainer 2026-08-27, fixed in eas-sdk 2.10.0.
  • OpenZeppelin/stellar-contracts#839 — hit UnreachableCodeReached combining Signer::Delegated with a CallContract rule. Closed 2026-09-02, resolution: ours — a construction bug in how the auth entries were built, not a library gap.
  • js-stellar-sdk#1655 — needsNonInvokerSigningBy()/signAuthEntries() only see the top-level node of a CAP-71 delegate credential. Filed with my own fix, #1672 (closed unmerged), superseded by the maintainer's own #1747 (merged 2026-09-28).

Still open, awaiting maintainer response: x402-foundation/x402 #3121, #3148.

Nirium — upstream contributions and GrantFox bounty program

Upstream, to repos Nirium doesn't own

Item Repo Status
#96 — add Nirium to community skills stellar/stellar-dev-skill Merged 2026-08-15
#97 — production patterns for x402 + MPP stellar/stellar-dev-skill Merged 2026-09-05, by @kaankacar, after ~16 real review rounds
#47 — mainnet sponsor/relayer account silent, then a stale-RPC outage OpenZeppelin/relayer-plugin-x402-facilitator Resolved by OZ 2026-09-11, confirmed by me with a real mainnet payment
#58 — allow an external SEP-43 signer instead of a raw secret key stellar/stellar-mpp-sdk Open
#30 — Nirium x402 adapter demo (apps/nirium) pollar-xyz/pollar-apps Merged 2026-08-31, by @aleregex
#1–#4 — bounded-authority milestone payouts, treasury rebalance via a missing destination parameter, direct x402 payment, agent-facing tool-schema evidence Trustless-Work/agentic-escrow-research Merged 2026-09-21, all four within 27 minutes — three by me, #3 by Monserrat
#9 — research note: fail-closed payment and delivery gates, two real production bugs found and fixed Trustless-Work/agentic-escrow-research Open, filed 2026-10-05

A real design collaboration, not a bounty: issue #96 (opened by me) was designed and tested by @CodeDeityX, who built the public reproducibility harness. Merged as #98 — nirium@0.16.0, now on npm, ships an optional policy hook on initX402().

GrantFox bounty program (nirium-protocol/nirium, Nirium's own repo — these are bounties Nirium posted). As of 2026-09-05: 44 issues across three campaigns, 42 real bounty asks — 20 delivered inside nirium itself, 2 delivered externally and awaiting that project's own review, 4 closed and administratively recreated, 16 closed without delivery.

Full bounty breakdown — every delivery, who opened it, and the five that are my cofounder's

A few of the stronger merged deliveries:

Bounty issue Delivering PR Author
#39 — harden the Python WebSocket signals client #47, merged @Simultech369 — external
#51 — GitHub Action to verify a Nirium audit-CID in CI #80, merged @Simultech369 — external
#65 — audit trail forensic export bridge #69, merged @Santia2004 — external

Five more are my cofounder's own first shipped code for this project, through the same GrantFox process: #50 via #58, #37 via #59, #45 via #61, #38 via #60, and #44 via #62 — all by Monserrat Mendoza.

One more worth naming because it isn't a bounty at all: #81 was a real fail-open vulnerability in the Next.js x402 example, reported by an outside party and fixed via a merged PR, #84. Separately, nirium#108 (pay no longer accepts a secret key as a CLI argument, fixing a shell-history/process-list leak) merged 2026-10-09.

Contextio

Moved from a personal repo to its own org — Eras256/Contextio now resolves to contextio/Contextio. Runs its own bounty-style program (not GrantFox-labeled): five open issues, none delivered yet, two with competing external PRs open and unreviewed. Upstream, three merged PRs added/refined its community-skill listing on stellar/stellar-dev-skill (#98, #101, #102). Beyond that, no upstream contribution from this account to any other external repo specifically for Contextio — said plainly, not padded.

Other dependency bug reports

Hackathons outside the portfolio

Separate weekend builds, no public repo for any of the three. Two have the event's own announcement naming the winner; the third only has my own tweet — disclosed as such, same standard as everywhere else here.


Stack

Avalanche Base Stellar Soroban Solana x402 Solidity Rust TypeScript Python

Protocols — x402, MPP, SEP-41/SAC, SEP-43, SEP-53, CAP-71 delegated auth, MCP, EAS

Commits, pull requests, merged PRs, reviews and issues for Eras256

Search these live yourself

All my PRs · all my issues · Nirium's bounty board · Contextio's open issues

Reach me — open an issue on any repo above, or periplo.xyz · nirium.xyz · contextio.xyz · X: @vaiossx · Discord: vaiossx

Pinned Loading

  1. kumplyprotocol/Kumply kumplyprotocol/Kumply Public

    KYC, KYB and KYA (AI agent verification) as on-chain attestations on Avalanche. Free reads, open-source SDK.

    TypeScript 1

  2. Prova-Solana/Prova Prova-Solana/Prova Public

    TypeScript

  3. Vouch402/Vouchx402 Vouch402/Vouchx402 Public

    x402-metered on-chain risk intelligence for AI agents on Base, with a built-in proof-of-fulfillment attestation layer

    TypeScript