eng @SquadsLabs | building blocks @ParagonStaking | passkeys @getbunkr

Joined August 2014
570 Photos and videos
Pinned Tweet
24 Mar 2024
Milestone: Running a Node ✅ Super proud to say that @BGuillaumat_ and I are running a validator (@ParagonStaking) together ❤️ Supporting the network I use 24/7 feels like such a full circle moment 🙌 Feel free to follow or stake while we work towards our leader slot 🫂
15
6
72
12,335
Orion retweeted
Announcing Solana Multisig Tools Three new open-source tools for Squads Protocol v4. All three are small, self-hostable, and built with minimal dependencies. We're actively engaging with STRIDE to help strengthen multisig management practices on Solana. This is the first step towards multiple independent frontends and access points to v4. multisig-cli A focused Rust CLI for reviewing, simulating, signing, and executing multisig proposals. It parses multisig accounts and instructions directly instead of pulling in a large dependency tree. The result is a binary that's easy to audit and well suited for high-trust operational workflows. If you're using an older CLI, we recommend switching to this multisig-cli which has minimal dependencies. multisig-verifier A static, zero-backend browser UI. Reads multisigs state directly from Solana RPCs, decodes proposals, tracks approvals, and lets members approve or reject from their own wallet. No secrets leave the browser. Strict CSP rules by default. multisig-monitor Real-time visibility into multisig activity. Watches configured multisigs, decodes actions, and emits notifications when members create, vote on, execute, or modify configuration. Treasury and governance events surface as they happen. The pattern across all three: inspect before signing, verify before approving, monitor after execution. Smaller dependency surfaces reduce supply-chain risk. Direct decoding reduces blind signing. Open implementations are reviewable end-to-end. Monitoring closes the loop. We strongly encourage every team to verify what they're signing through more than one interface. Don't rely solely on any single frontend. Cross-check with a CLI, an independent verifier, or a second client before approving anything that matters. We're working with a number of security teams who will host their own versions of the multisig-verifier. You can self-host today. Soon teams will also be able to access independently operated instances run by parties with no affiliation to Squads. Link to the repo in the post below.
26
47
308
91,531
Orion retweeted
An update on what we're focusing on with @multisig in light of the Drift incident last week. What we're building now: 1. A proxy program for v4 that lets you opt in to killing durable nonces for a specific signer. This removes the ability for pre-signed transactions to sit indefinitely waiting to be executed. 2. A dedicated protocol management multisig program with configurable template policies and a UI you can run locally. Built for teams that need tighter governance controls over admin operations. 3. Exploring clear signing with intents so signers can verify exactly what a transaction does before approving it (cc @Redacted_Noah). What's already available on v4 and can be set up by your team today: – Timelocks. You can set these up in Settings. They create a mandatory delay between proposal approval and execution. – Signer permissions. You can assign Propose, Vote, and Execute rights separately, so not every signer has the same level of access. – Multisig nesting. You can set up configurations where eg two separate multisigs are signers on a third. Adding a layer of operational separation. -Minimal UI. An interface on top of v4 that you can run locally (github.com/Squads-Protocol/s…). If you're unsure about your current setup or want guidance on how to configure any of this, DM us.
Our investigation into the @DriftProtocol incident remains ongoing. Early evidence points to two compromised signers on Drift's admin multisig, which were used to execute a transaction modifying Drift's program configuration. Squads programs were not compromised. We have also found no evidence of compromise to Squads infrastructure, though we are actively investigating to confirm this with full confidence. We will share further findings as they become available. Best Practices for Operationally Critical Multisigs Thresholds: Any multisig with operational or administrative control over a program should have a signing threshold of 3 or above. This requires an attacker to concurrently compromise multiple independent signers, significantly raising the difficulty of this type of attack. Where possible, signers should also be geographically and organizationally dispersed. Signers sharing the same location, devices, or org structure introduce correlated risk. Timelocks: Multisigs with program-level control should implement a timelock (can be set up in Settings of your Squads multisig). It won't prevent a malicious transaction from being proposed, but it creates a window to detect and reject it before execution. The tradeoff: timelocks also slow down legitimate emergency responses to bugs or active exploits, so teams should factor this into their operational setup. Alerts & Monitoring: We encourage all operationally critical multisigs to set up monitoring and alerts through our security partner @RangeSecurity. Range provides two key things: an alternative interface for independently verifying transaction content outside of the Squads UI, and proactive Slack alerts so signers are notified before a proposal moves forward. If you want help getting set up, reach out and we'll connect you directly. A high threshold, a timelock, and monitoring are the foundation for any multisig with program-level control. Signing Process: Signers should use dedicated devices and hardware wallets, never a general-purpose machine. Additionally, signatures are only valid for approximately 2 minutes each, so introduce at least a 2 minute delay between each signer taking actions to ensure signatures cannot be collected & bundled by an attacker. Always verify transaction content independently across all three available sources: the Squads UI, Range's alternative interface, and Solana Explorer or Solscan On Durable Nonces 
The Drift attack exploited durable nonces to collect signatures without time pressure, bypassing the 2-minute transaction expiry that would otherwise limit this type of attack. We are actively exploring ways to block durable nonce usage across all of our programs, both at the program level and through other enforcement mechanisms, to ensure this protection extends to our immutable programs V3, V4, and our current Smart Account Program. Beyond this, the broader Solana ecosystem is taking steps to address this at the protocol level, with a new transaction format that drops durable nonces as a feature entirely. We will follow up with more information on this soon.

Beyond Multisig, Operational Security Technical controls only go so far. Most high-profile compromises lately have been social engineering attacks targeting the people behind the keys, not the contracts themselves. If you are running mission-critical protocol operations, invest in your internal opsec processes and team culture accordingly, how proposals are initiated, communicated, and approved all matter. We recommend engaging dedicated security advisors. @zeroshadow_io and @0xGroomLake are trusted starting points, and we are happy to connect you directly.
18
35
214
34,356
Super cool to see this kind of stuff being spun up 🙌 Kudos @gumsays 🫶
1
183
Orion retweeted
SWIFT transfers are live. Pay any bank account, anywhere in the world. Directly from your Altitude account. 200 countries. 11,000 banks. 1 balance.
55
59
505
155,656
IBRL’ing on the mountain
1
4
20
1,975
Orion retweeted
Stoked to launch Bill Pay on @altitude. Every CFO managing stablecoin-native ops knows bill pay is a mess. Invoices get lost in email. Some payments in fiat, others in stables. Disconnected tools. Manual reconciliation. It's not fun. We built Bill Pay to fix this. One platform for all your payouts, across stables and fiat. Automated. For free. Give it a spin and let me know what you think.
Altitude Bill Pay is live. Pay bills directly from your stablecoin balance. → Email-forwarded bills for auto-ingestion → OCR AI populates every detail → Pay in USDC or via fiat rails your vendor prefers → Payouts from one account make reconciliation simple No more patchwork. One account. All your bills. Closing your books has never been easier.
6
5
30
3,141
Orion retweeted
YC gets it. Most startups will be funded this way in the future. Because for early stage startups, speed and efficiency mean survival. Stablecoins remove the friction from setting up accounts, accepting funding, and making payments. We've been running Squads entirely on stablecoins since day one. Our business account - @altitude lets any company do the same. We can onboard you in seconds. You receive your YC check instantly via USDC on Solana. DM me by the end of the week and we'll lock in 5% APY on your Altitude Earn balance until May 1st, 2026.
Today, Y Combinator is announcing that YC-funded startups can choose to receive their funding ($500k) in stablecoins. We believe stablecoins like @usdc are setting the stage for a new fintech renaissance and broader global access to financial services. Sending money should be as easy as sending a text message. Stablecoins make that possible: cheap, fast, and global, using currencies people already trust. Some of the fastest-growing YC startups in recent years like @get_aspora and @DolarApp use stablecoins to power faster, cheaper financial services across India and Latin America. Plus, with the passage of the GENIUS Act and growing adoption by financial institutions, we’re bullish. Whether crypto-focused or not, we expect many YC startups to use crypto in some way, from payments to banking to capital raising. If you’re building onchain, apply for our Spring ‘26 batch by Feb 9: ycombinator.com/apply
23
27
198
37,955
Orion retweeted
BP25 takeaways: 1. Massive credit to @platis_e and @akshaybd, truly exceptional work 2. The real momentum is where it should be: market structure, DeFi and core protocol development 3. No flashy metas or narrative games, just thoughtful iteration, optimization and focus on the north star 4. Coinbase is taking Solana far more seriously than most people realize 5. Watching trading push protocol limits reinforced a belief I’ve had for a while: payments chains alone won’t work, payments and trading have to coexist 6. Solana teams have clearly matured, more CFOs and COOs, sharper operational thinking, and some great conversations around @altitude 7. While Solana clearly has a lead, the energy wasn’t celebratory, it was focused, disciplined, jobs not finished type beat 8. Had to endure more UAE cope than expected from US friends 9. 27 of 31 Squads team members made it out - surreal (and very motivating) to have everyone in the same room 10. The @solana ecosystem is ready to get banked by @altitude and we’re going to deliver.
40
21
229
28,412
Orion retweeted
This is a long post about the rise of "prop AMMs", the history behind them and their advantages/disadvantages. This post will be different than my usual style of trying to be concise and is more of a story since it was meant to be for a DeFi Day talk like I did in the past 2 years. Unfortunately, this year I was asked to provide my ID/KYC (not the fault of the organisers) to be able to speak which I'd rather not do.
38
32
262
45,041
4 Dec 2025
🫳 🎤
4 Dec 2025
Introducing Grid Smart Transactions. A new primitive to ship safe, autonomous money movement on @solana.
8
396
25 Nov 2025
Lowest PDA bump I’ve ever seen. Took 100% more CUs than usual 🫠 You guys ever seen a lower one? @deanmlittle @cavemanloverboy
6
24
5,572
Orion retweeted
Stablecoins secured by @multisig just reached an ATH of $2.2B. There’s no mystery to how we build: 1. Start with infrastructure that aggregates capital and compounds trust. 2. Build high quality financial services on top. 3. Ship fast, talk to users, scale what works.
24
23
167
70,815
Orion retweeted
13 Nov 2025
Today, @solana joins several other trillion dollar companies in contributing to upstream BPF. No more custom toolchain. No more compiler forks. No more performance compromises. It's time to give back. Claire is cute.
13 Nov 2025
claire is cute
15
22
89
52,093
Orion retweeted
wait i just woke up, who is claire? and why is she competing with @albertisgreat Albert is great
2
1
9
1,548
Orion retweeted
11 Nov 2025
Your business isn’t just one thing. Your account shouldn’t be either. Manage multiple business lines using sub-accounts: • Separate funds by purpose • Route payments with unique deposit details • Move between USD and EUR accounts with instant FX
3
12
64
14,886
10 Nov 2025
Time to go meet all the chads in Rome 😈
1
147
6 Nov 2025
Team straight up snagged app of the year. Quadrillions.
6 Nov 2025
🏆 And the nominees are.... After a ~week of research and hours of (passionate, emotional, deeply thoughtful) debate, we are ready to announce all the nominees for the 2025 𝝠 Expo App Awards! They are broken down by category below. Before getting into the list we want to share our gratitude to everyone who submitted. For us, this review process has been both painful and beautiful. It hurt to remove apps from contention. But it was validating to see the incredible work y'all are doing. Thank you to all of you! ♢ App of the year: @Starlink, @partiful, @fusewallet, @runna, @krakenfx, @PrizePicks ♢ Most creative: Zona, Callie, @partiful, RX Connect, SeaPeople, @fusewallet ♢ Community's choice: @learnwithiago, Lingvano, Readwell, Fig, @VoidpetGame, @TheAtlantic ♢ Largest scale: @phantom, @JackBox, @Rippling, @brexHQ, @kick, @pizzahut ♢ Most innovative: Sanas, Cosmy, @v0, @CoupleJoyApp, @Starlink, @bluesky 👏Congrats to all the nominees! To see and explore all these apps visit expo.dev/awards
1
9
624
3 Nov 2025
Chat are we cooked?
1
15
719
26 Oct 2025
Hell yes. Higher.
26 Oct 2025
Something shifted, did you notice? 👀
4
597