Stackframe MARKET | web3/crypto (dApp, DeFI, DAO, etc)
17.7K subscribers
11 photos
6 videos
8 links
Occasional posting on web3/crypto-related tools & vulnerabilities. If something is not listed on-market you can pay for research. Ask: Goal, Deadline, Coin.
Download Telegram
@stackframe MARKET 💼 · 2026

vulnerability research & exploit code targeting Web3, DeFi
and dApp
surfaces. each release ships as working source.
pay for my research with exclusive private use of whatever I find.

if a "MM" is wanted that's completely reasonable.

for paid research requests (e.g., VMs, vulns, contracts, etc) / purchase inquiries | @moschata
Please open Telegram to view this post
VIEW IN TELEGRAM
This media is not supported in your browser
VIEW IN TELEGRAM
Tonkeeper Extension · TonConnect Origin Spoof

Wallet popup renders the chosen dApp's real branding over an
attacker-chosen recipient, amount and payload. Single Confirm
against any pre-existing connection. Mainnet-confirmed: Fragment,
DeDust.

Source delivered — 1:1 Fragment auction
phishing clone (if needed), supporting on-chain artefacts.


500 USD · @moschata

-- PATCHED (for now). I'll be looking into this soon.
if you need a VM or another tool for a specific platform/service for example and want to pay for my research (if not already listed on-market) and use privately, you can reach out between my work times. if what you're asking for peaks my interest i'll invest as much time as possible to satisfy outcome. ensure you're good at communicating.

DISCLAIMER: if something is not currently exploitable and nothing is found either due to "incompetence" or no possible way, then refunds (50%) are eligible!
if you need a VM or another tool for a specific platform/service for example and want to pay for my research (if not already listed on-market) and use privately, you can reach out between my work times. if what you're asking for peaks my interest i'll invest as much time as possible to satisfy outcome. ensure you're good at communicating.

DISCLAIMER: if something is not currently exploitable and nothing is found either due to "incompetence" or no possible way, then refunds (50%) are eligible!
Media is too big
VIEW IN TELEGRAM
Google Voice Autodialer | t.me/stackframe 😀

Processes Google Voice (or SIP trunk) calls sequentially, one at a time.
Categorises each call within 1.5 seconds as ringback, pickup, human, voicemail, or silent, acting on each instance with maximum efficiency.

Upon human response, the selected prompt is activated (e.g., Ledger, Trezor, Coinbase, Kraken, etc.).
Upon voicemail detection, the call is terminated (configurable).
The microphone remains silent by default; no audio is transmitted unless explicitly scripted. As per the standard process.

* Ringback and voicemail beep detection utilizing Goertzel algorithm plus streaming whisper transcripts.
* Press-1 detection via dual-band Goertzel algorithm with a minimum 40 ms tone duration.
* Per-call WAV recording with webhook notification upon outcome.
* Live transcripts available in the web console.
* Interfaces include Telegram bot, command-line interface, and operator console (bot/CLI/web).
* Stealth configuration via Patchright and residential proxy rotation (if required).
* SIP trunk capability: Twilio, Telnyx, Signalwire, Asterisk, etc.
* Deployment on a domain behind basic authentication and Caddy.
* Cross-platform compatibility: macOS, Linux, Windows.
* No voicemail is left; operator audio is never leaked.
* On average you can expect ~3-6 calls per total on-line minute, depending on connection, call status, and vic (data quality in general). Nothing special as it's heavily dependant on you and your data.

Sorry for the cut-off in the video too (both video time and the CLI & Web interface windows). I don't know why OBS decided to ignore the rest of the content.

$1,000 for source |
@moschata

I'm not running any P1 myself. You will have to manage/buy routes yourself. I will only ever respond to inquiries for purchase, feature requests, bugs, or usage. Because of this there is no "$$-$$$ or % per 1k lines". Most people seem to prefer outright purchasing the source anyways based on the previous poll. MM is ALWAYS accepted if needed!
Please open Telegram to view this post
VIEW IN TELEGRAM
This media is not supported in your browser
VIEW IN TELEGRAM
Bitstamp VM | t.me/stackframe

VM for Bitstamp. Feed email address list; precisely identifies real VS fake accounts at volume, no inbox access and nothing ever sent to the addresses themselves.

Every address resolves to a definite registered / unregistered verdict, written straight to a clean results file (results.txt by default). Already-checked addresses are skipped automatically with caching, so any run can be stopped and resumed with zero duplicate work or wasted spend.

Throughput scales with your setup, roughly 200 to 2,000+ verifications per minute, sustained, depending on hCaptcha solver quality and proxy pool (CaptchaSonic was used in demonstration). CapSolver will not work as it doesn't support hCaptcha anymore.

* Definite registered / unregistered verdict per address, written to a clean, readable results file.
* Parallel solver pool, run multiple captcha services and keys at once; every key you add scales throughput.
* Built-in sticky residential-IP rotation, budgeted per IP to keep high-volume runs clean.
* Pluggable from a single config file: any hCaptcha-capable solver service, any rotating-proxy provider. Solvers that can't handle hCaptcha are rejected before a run begins (let me know otherwise).
* Self-healing under load. Such as automatic retries, rate-limit-aware IP rotation, and accuracy safeguards so verdicts never degrade when pushed.
* Resume + dedupe cache, same address is never checked twice, across runs.
* Live TUI console for watching verdicts land in real time.
* One config file (config.toml) for all credentials; no account logins required.
* Cross-platform: macOS, Linux, Windows.

$1,650 | @moschata