Software Engineer | I build digital products that make real money | ₦100M processed | Founder @PeventNG

Joined October 2021
120 Photos and videos
Harlexander retweeted
Jun 14
I feel like the tech behind Paj isn’t talked about enough. Most off-ramps stop at stablecoin-to-naira conversion and vice versa; USDC or USDT hits a custodial wallet, a conversion rate is applied, and a bank transfer is initiated. Straightforward flow. But Paj is building something deeper. You can send almost any Solana token: $SOL, $JUP, $MET, memecoins, long-tail SPL assets, etc, and receive ₦aira directly in your local bank account within seconds. Nobody else does this because Paj operates a fundamentally different architecture. In a sea of payment wrappers and basic off-ramp clones, Paj practically had to rebuild their own original infrastructure layer and engineer a multi-layer settlement stack, from scratch. And that’s why they’ll always have my respect.
Jun 14
For everyone discovering us this month, PAJ = converts ANY Solana token directly to Naira in your bank account. PAJ = Generates an address for you to receive crypto as naira from anywhere in the world. Just: Wallet > Naira > Delivered. In 30 seconds.  Welcome. Try it once. You'll get the hype.
18
18
126
6,514
Harlexander retweeted
Time to get that volcano lair I’ve always wanted. I think it’s in the “Beyond” section of BB&B.
15 Apr 2015
If this works, I'm treating myself to a volcano lair. It's time.
9,792
12,267
172,954
39,414,760
This week is blessed!
3
Mine doesn’t even open without vpn on mtn and airtel
I can’t seem to access CloudFlare using my MTN network, but it immediately opens once I switch to Airtel. Does this happen to anyone else?, is this common?
1
53
I can plan this actually
so, nobody can organize a club party for tech guys and babes? not tech event everytime na😪
48
I am wondering how this is even possible 🤔. A basic positive value validation, from server and client forms even have this in them. How inexperienced do you have to be to make such mistake
In my early days as an inexperience fintech startup founder. With proper testing we launched and we lost over a million Naira though we were able to recover it back via token charge. This is how it happened… User with 0 balance sent say -20 Naira to be withdrawn. System read -20 as lesser than 0, so it did subtraction 0 - (-20) =20 (balance) And then update user balance with 20 Naira. From 0 balance to 20 Naira, in this case user can now withdraw 20 legitimately. You see how an inexperienced developer building fintech can go to jail.
1
2
5
1,172
Chunking server-sent events can greatly improve your customer experience for long tasks. Instead of a prolonged loading state, you can chunk the task on the server and display progress of the action. AI platforms already do this with streaming.
13
Currently working towards organizing a hackathon, I am not the host but the project manager.
1
22
Passionate about payments and finance, and lately I've been exploring blockchain and stablecoins as the future of low-cost, efficient payments in Africa. Currently building on Solana and learning Rust along the way. Excited to contribute to the ecosystem
12
Just gonna focus on what is in front of me. Worry less
6
Not me tho
May 19
In this industry, everybody lies about their numbers.
15
Harlexander retweeted
First ticket. Big savings. Get up to ₦2,500 off when you book through the Pevent app. Download now → pevent.co/app/download
1
2
35
2 weeks is impossible tho. So many edge cases to test for.
On this Jumia Saga, hobbying, i name it after my daughter. I can't possibly build the business aspect of Jumia. But AI can build the tech part in 2 weeks, even without paying, this is day1, just wasting my time here, you don't have to mind. Its systematic approach not emotional. @echo_vick
1
48
Harlexander retweeted
If you’re vibecoding anything, paste the prompt below In your prompt box and let your agent do a security sweep. [ You are a senior security engineer and red-team specialist tasked with performing a comprehensive, adversarial security audit of the following codebase, system design, or application. Your goal is to identify all possible security vulnerabilities, including common, uncommon, and novel attack vectors. Assume the system will be deployed in a hostile environment with motivated attackers. --- AUDIT SCOPE Analyze the system across all layers, including: - Frontend (UI, client logic, browser storage) - Backend (APIs, business logic, services) - Authentication and authorization flows - Database interactions and storage - Infrastructure and deployment assumptions - Third-party integrations and dependencies --- CORE OBJECTIVES 1. Identify critical, high, medium, and low severity vulnerabilities 2. Detect logic flaws, not just known patterns 3. Surface chained attack paths (multi-step exploits) 4. Highlight unknown or unconventional weaknesses 5. Assume attacker creativity beyond standard checklists --- THREAT MODELING - Define possible attacker profiles (anonymous user, authenticated user, insider, API consumer) - Identify entry points and trust boundaries - Map out sensitive assets (data, tokens, permissions, secrets) --- VULNERABILITY ANALYSIS Check for (but do NOT limit yourself to): ### Authentication & Authorization - Broken auth, weak session management - Privilege escalation (vertical and horizontal) - Insecure password reset flows - Token leakage or reuse ### Input Handling - Injection attacks (SQL, NoSQL, OS command, template injection) - XSS (stored, reflected, DOM-based) - CSRF vulnerabilities - File upload exploits ### Data Security - Sensitive data exposure - Weak encryption or misuse of cryptography - Hardcoded secrets or keys - Insecure storage (localStorage, cookies, logs) ### API & Backend Logic - Broken object-level authorization (IDOR/BOLA) - Mass assignment vulnerabilities - Rate limiting issues / brute force risks - Business logic abuse (race conditions, double spending, bypassing checks) ### Infrastructure & Configuration - Misconfigured headers (CORS, CSP, HSTS) - Open ports, debug endpoints, admin panels - Environment variable leaks - Cloud/storage misconfigurations ### Dependencies & Supply Chain - Vulnerable packages - Unsafe imports or execution - Malicious dependency risks --- ADVANCED / UNKNOWN THREATS Actively attempt to discover: - Non-obvious logic flaws unique to this system - Feature abuse scenarios - State desynchronization issues - Cache poisoning - Replay attacks - Timing attacks - Multi-step exploit chains combining low-severity issues - Any behavior that “shouldn’t be possible” but is --- ADVERSARIAL TESTING MINDSET - Think like an attacker trying to break assumptions - Attempt to bypass validations and safeguards - Manipulate edge cases and unexpected inputs - Explore how different components interact under stress -- OUTPUT FORMAT Provide findings in this structure: ### 1. Vulnerability Summary - Total issues by severity ### 2. Detailed Findings For each vulnerability: - Title - Severity (Critical / High / Medium / Low) - Affected component - Description - Exploitation scenario (step-by-step) - Impact - Recommended fix ### 3. Attack Chains - Show how multiple minor issues could be combined into a major exploit ### 4. Secure Design Recommendations - Architectural improvements - Safer patterns and best practices --- IMPORTANT INSTRUCTIONS - Do NOT assume the code is safe - Do NOT skip analysis due to missing context, infer risks where needed - Be exhaustive and paranoid in your review - If unsure, flag it as a potential risk and explain why ]
111
452
3,424
374,175
Tough, some fixing to do
If you’re vibecoding anything, paste the prompt below In your prompt box and let your agent do a security sweep. [ You are a senior security engineer and red-team specialist tasked with performing a comprehensive, adversarial security audit of the following codebase, system design, or application. Your goal is to identify all possible security vulnerabilities, including common, uncommon, and novel attack vectors. Assume the system will be deployed in a hostile environment with motivated attackers. --- AUDIT SCOPE Analyze the system across all layers, including: - Frontend (UI, client logic, browser storage) - Backend (APIs, business logic, services) - Authentication and authorization flows - Database interactions and storage - Infrastructure and deployment assumptions - Third-party integrations and dependencies --- CORE OBJECTIVES 1. Identify critical, high, medium, and low severity vulnerabilities 2. Detect logic flaws, not just known patterns 3. Surface chained attack paths (multi-step exploits) 4. Highlight unknown or unconventional weaknesses 5. Assume attacker creativity beyond standard checklists --- THREAT MODELING - Define possible attacker profiles (anonymous user, authenticated user, insider, API consumer) - Identify entry points and trust boundaries - Map out sensitive assets (data, tokens, permissions, secrets) --- VULNERABILITY ANALYSIS Check for (but do NOT limit yourself to): ### Authentication & Authorization - Broken auth, weak session management - Privilege escalation (vertical and horizontal) - Insecure password reset flows - Token leakage or reuse ### Input Handling - Injection attacks (SQL, NoSQL, OS command, template injection) - XSS (stored, reflected, DOM-based) - CSRF vulnerabilities - File upload exploits ### Data Security - Sensitive data exposure - Weak encryption or misuse of cryptography - Hardcoded secrets or keys - Insecure storage (localStorage, cookies, logs) ### API & Backend Logic - Broken object-level authorization (IDOR/BOLA) - Mass assignment vulnerabilities - Rate limiting issues / brute force risks - Business logic abuse (race conditions, double spending, bypassing checks) ### Infrastructure & Configuration - Misconfigured headers (CORS, CSP, HSTS) - Open ports, debug endpoints, admin panels - Environment variable leaks - Cloud/storage misconfigurations ### Dependencies & Supply Chain - Vulnerable packages - Unsafe imports or execution - Malicious dependency risks --- ADVANCED / UNKNOWN THREATS Actively attempt to discover: - Non-obvious logic flaws unique to this system - Feature abuse scenarios - State desynchronization issues - Cache poisoning - Replay attacks - Timing attacks - Multi-step exploit chains combining low-severity issues - Any behavior that “shouldn’t be possible” but is --- ADVERSARIAL TESTING MINDSET - Think like an attacker trying to break assumptions - Attempt to bypass validations and safeguards - Manipulate edge cases and unexpected inputs - Explore how different components interact under stress -- OUTPUT FORMAT Provide findings in this structure: ### 1. Vulnerability Summary - Total issues by severity ### 2. Detailed Findings For each vulnerability: - Title - Severity (Critical / High / Medium / Low) - Affected component - Description - Exploitation scenario (step-by-step) - Impact - Recommended fix ### 3. Attack Chains - Show how multiple minor issues could be combined into a major exploit ### 4. Secure Design Recommendations - Architectural improvements - Safer patterns and best practices --- IMPORTANT INSTRUCTIONS - Do NOT assume the code is safe - Do NOT skip analysis due to missing context, infer risks where needed - Be exhaustive and paranoid in your review - If unsure, flag it as a potential risk and explain why ]
1
1
31
9,266
Omo.
Cybertruck is an APC from the future
1
26
Harlexander retweeted
Replying to @uzoart
@PeventNG is the best ticketing platform out of Nigeria rn!
1
1
98
Harlexander retweeted
Replying to @uzoart
Pevent.ng all the way!

1
1
348
Harlexander retweeted
Seamless platform 💯
1
1
104