Register and share your invite link to earn from video plays and referrals.

Rektoff
@rektoff_xyz
Rust-native security training for engineers, enterprises, and ecosystems.
286 Following    3.8K Followers
Superteam Talent came through loaded this fortnight. Real engineering seats, and some serious names attached. 1/ Want to build the backend behind $22B in trading volume? Trojan is the largest Telegram trading bot on Solana, 50,000+ daily users, and they need a backend engineer who lives in high-throughput, low-latency systems. 5+ years, Node/Bun, TypeScript. @TrojanOnSolana → 2/ Frontend at the home of onchain finance. Jupiter is one of the biggest names on Solana, and they're hiring a product-focused Frontend Engineer to shape how millions actually trade. React, real product instinct. @JupiterExchange → 3/ Two backend seats at Axiom, the trading platform doing $100M+ in daily volume. One backend, one fullstack. TypeScript, Rust, real-time systems at scale. @axiomexchange → 4/ Mobile and backend, from the ground up, at Arcade, the team behind the #1# DEX on HyperEVM ($5.4M revenue year one, two people). Staff-level React Native and backend seats, $180K+ plus equity. Not security, but a serious build role. @prjx_hl → 5/ Deep in Linux and validator infra? Staking Facilities run one of the strongest Solana setups and have a system engineer seat open. @StakingFac → The ecosystem is hiring. Go put your name in.
Show more
Superteam Talent showed up with a full board again, and there's real stuff here for our people. 1/ Want to write Rust in production on Solana, not in a sandbox? R3 is building Corda, an institutional RWA platform in partnership with the Solana Foundation. They want a Staff Engineer with 6+ years and real Solana production time behind them. @inside_r3 → 2/ Mobile trading from the ground up, spot and perps, owning the product. The team behind the #1# DEX on HyperEVM is building it. Staff-level React Native, $180K+ base plus equity. Not a security seat, but a serious build role for someone who's already shipped a consumer app solo. @prjx_hl → 3/ Live in Linux and validator infra? Staking Facilities run one of the strongest setups on Solana and just opened two seats, junior and senior, for a system engineer. @StakingFac → And straight up: there are 2 more roles on the @SuperteamTalent board: a Senior Full-Stack (TypeScript, frontend) and a product-focused Frontend Engineer. Both companies kept their names private, so the details only open up inside the application. If frontend's your lane, go see for yourself:
Show more
C5 certificates are going out today, which makes it official. This cohort is done. If you earned one, don't let it sit in your inbox. Post it. Tag @rektoff_xyz. Show the world you made it through. Every cert that goes up is one more name in a growing line of Solana security researchers who came through this program. We want to see how big the Rektoff army actually is, and so does everyone deciding whether to join the next one. C6 registration is already in the works, and it's coming soon. Follow us and turn on notifications so you catch the window when it opens. To C5: proud of every one of you. Go make some noise.
Show more
> Learn Rust and Solana development. > Learn Rust and Solana security (@rektoff_xyz is the best place to do so). > Learn how to use AI professionally. > Read as many security reports as you can. > Spend many hours working and contributing in the open source space. > Contact teams to improve the security of their protocols. > DM me with your results and portfolio, to see if I can help.
Show more
If you want to audit Solana for a living, this is the blueprint. Read the public audits @0xcastle_chain has shared. Then start contributing to open source, because the pattern recognition he's describing only comes from volume. Nobody reads their way to 250 findings.
Show more
70+ Rust audits 🧠🫡 50+ of them on Solana. 250+ critical and high severity findings I did not read my way there. I got there by going through the same account model over and over until the failure shapes stopped surprising me that is the only reason I can open an agentic payment program, and know exactly where to start looking
Show more
Superteam Talent showed up with a full board again, and there's real stuff here for our people. 1/ Want to write Rust in production on Solana, not in a sandbox? R3 is building Corda, an institutional RWA platform in partnership with the Solana Foundation. They want a Staff Engineer with 6+ years and real Solana production time behind them. @inside_r3 → 2/ Mobile trading from the ground up, spot and perps, owning the product. The team behind the #1# DEX on HyperEVM is building it. Staff-level React Native, $180K+ base plus equity. Not a security seat, but a serious build role for someone who's already shipped a consumer app solo. @prjx_hl → 3/ Live in Linux and validator infra? Staking Facilities run one of the strongest setups on Solana and just opened two seats, junior and senior, for a system engineer. @StakingFac → And straight up: there are 2 more roles on the @SuperteamTalent board: a Senior Full-Stack (TypeScript, frontend) and a product-focused Frontend Engineer. Both companies kept their names private, so the details only open up inside the application. If frontend's your lane, go see for yourself:
Show more
We went through the whole @SuperteamTalent board this week. These four earned a spot: 1/ Staff Engineer, Solana @inside_r3, building Corda, an institutional RWA platform on Solana in partnership with the Solana Foundation. 6+ years, 3+ in Rust with real Solana production time → 2/ Rust Engineer @Bulletxyz, perps and spot DEX on Solana with sub-1ms execution from the team behind Zeta Markets. Deep Rust, low-latency systems, no Solana background required → 3/ Developer Relations Engineer @Raydium, one of the largest AMMs on Solana. For someone who can build, break down, and explain Solana programs to other developers → 4/ Product Engineer, Consumer @gacha_game_, building consumer apps across Web and iOS. Not a security seat, but a real product build role for someone who ships. Up to $4k/month → Check the rest of the board here:
Show more
all weeks were absolutely bonkers, you get to know so much that things actually start making sense. ❤️ it doesnt matter what level of thinking you currently have, it is about how they make you think on many aspects would recommend 10/10 dont miss the next cohort!
Show more
wrapped up six intense weeks with the @rektoff_xyz bootcamp 🦀 learned a lot about rust and solana security, with even more left to explore. grateful for the experience and for the mentors who shared their knowledge and guided us throughout 💚
Show more
i officially graduated from @rektoff_xyz today 🥺🎊 when i started c5, my goal was simply to understand rust, solana programs, and security a little better i definitely didn’t expect the journey to stretch me this much there were moments when the code made absolutely no sense, moments where i had to go back and learn things i thought i already understood, and plenty of times where i wondered if i was actually cut out for this especially during my capstone 😭 but i kept showing up and now, i’m leaving c5 with a much better understanding of security research and, more importantly, a clearer idea of the kind of researcher i want to become huge thanks to our tutors for the mentorship, the pressure, for constantly pushing us to do better i am also grateful to @SolanaFndn for supporting the programme and making this opportunity possible there’s still so much to learn, so many protocols to read, and a lot more work to do but for now, i’m grateful for this milestone 🙏 fingers crossed for my capstone grades tho🤞
Show more
Just graduated from @rektoff_xyz Cohort 5 🦀 Six weeks deep in Solana, Rust, and security with an incredibly sharp group of builders. From ~4,000 applicants to 125 spots, and it delivered. I’m leaving a stronger Rust engineer with a much deeper security mindset. Big respect to the Rektoff team for building something special. ⚔️
Show more
C5 is officially complete. An hour ago, we held the graduation ceremony, where Rektoffians also showcased projects they've been working on. Thank you to all 125 students who put in the hours and made it to the finish. You came in writing Rust, and you're leaving as security researchers. Thank you to our mentors Jack Stodart, @m4rio_eth and @danielkcumming, who set the bar every week and held everyone to it. And thank you to the @SolanaFndn for backing this work and making it real, cohort after cohort. The Rust and Solana world just gained a new class of security researchers. We're already prepping C6. Details soon.
Show more
Yesterday's arrayref compromise was a build script that ran malware at compile time, and a crate with 244M downloads carried it. Anyone who compiled a project that pulled it in got hit, without ever calling the crate. So here's how you actually lower your odds of catching one of these. > Commit your Cargo.lock, and build from it. The lock file pins exact versions. If your CI resolves fresh dependencies on every build, you inherit whatever got published overnight. Build from the lock, not from the latest. > Don't auto-resolve new versions in CI. Use --locked in your build and test steps so cargo fails instead of silently pulling something new. A failed build is a signal. A silent upgrade is a liability. > Update dependencies on a schedule, not continuously. Bump deps deliberately, once a quarter or so, and review what changed. Most of these attacks get caught and patched within hours, so lagging slightly behind the bleeding edge is a feature, not a bug. > Treat build scripts as untrusted code. runs with your permissions at compile time. That's the whole attack surface here. Tools like cargo-vet and cargo-deny help you audit what's actually running. None of this makes you bulletproof. It makes you a harder, slower target, which for supply chain attacks is most of the battle. @m4rio_eth put together a diagnostic prompt for exactly this incident. Check his post and run it over your own system, it scans your repo and machine for the compromise indicators and reports back without touching anything. Stay paranoid about what you compile. Stay safe. Stay Rektoff.
Show more
Heads up for anyone writing Rust today. The Rust Security Response Team just disclosed a supply chain attack. The popular arrayref crate was republished to pull in a malicious dependency that downloaded a payload through its build script. arrayref isn't obscure. If you or your dependencies pulled it recently, you'll want to check now. The malicious versions to look for: > arrayref 0.3.10 > internment 0.8.7 > append-only-vec 0.1.9 > proc-macro1, plus typosquats: proc-macro-en, aovine, arone, aronenao, tinymember All deleted from and the maintainer's account is locked. The team believes the author's credentials were compromised rather than the author acting maliciously. Full advisory, including the one-line command to scan your local cargo cache:
Show more
Heads up for anyone writing Rust today. The Rust Security Response Team just disclosed a supply chain attack. The popular arrayref crate was republished to pull in a malicious dependency that downloaded a payload through its build script. arrayref isn't obscure. If you or your dependencies pulled it recently, you'll want to check now. The malicious versions to look for: > arrayref 0.3.10 > internment 0.8.7 > append-only-vec 0.1.9 > proc-macro1, plus typosquats: proc-macro-en, aovine, arone, aronenao, tinymember All deleted from and the maintainer's account is locked. The team believes the author's credentials were compromised rather than the author acting maliciously. Full advisory, including the one-line command to scan your local cargo cache:
Show more
We went through the whole @SuperteamTalent board this week. These four earned a spot: 1/ Staff Engineer, Solana @inside_r3, building Corda, an institutional RWA platform on Solana in partnership with the Solana Foundation. 6+ years, 3+ in Rust with real Solana production time → 2/ Rust Engineer @Bulletxyz, perps and spot DEX on Solana with sub-1ms execution from the team behind Zeta Markets. Deep Rust, low-latency systems, no Solana background required → 3/ Developer Relations Engineer @Raydium, one of the largest AMMs on Solana. For someone who can build, break down, and explain Solana programs to other developers → 4/ Product Engineer, Consumer @gacha_game_, building consumer apps across Web and iOS. Not a security seat, but a real product build role for someone who ships. Up to $4k/month → Check the rest of the board here:
Show more
Top 6 roles from this week's @SuperteamTalent board, filtered for the builders here: 1/ Staff Engineer, Solana @inside_r3, building Corda, an institutional RWA platform on Solana in partnership with the Solana Foundation. 6+ years, 3+ in Rust with real Solana production time. → 2/ Rust Engineer @Bulletxyz, perps and spot DEX on Solana with sub-1ms execution from the team behind Zeta Markets. Deep Rust, low-latency systems, no Solana background required. → 3/ Developer Relations Engineer @Raydium, one of the largest AMMs on Solana. For someone who can build, break down, and explain Solana programs to other developers. → 4/ Fullstack Engineer @veryai, fraud-resistant verification infra across fintech and crypto. Go and TypeScript, production scale. $120K - $150K, remote (US). → 5/ Soroban / Rust Smart Contract Specialist @TradeJanus, freight-fintech deploying lending contracts on Stellar. Expert Rust with hands-on Soroban, contracts already on testnet or mainnet. → 6/ Blockchain Engineer @TradeJanus, same team, moving from AI document intelligence into stablecoin rails, lending, and yield. Rust across payments and credit infra. → Everything we left out is still worth a look. Full board here:
Show more