@stackframe MARKET 💼 · 2026
vulnerability research & exploit code targeting Web3, DeFi
and dApp surfaces. each release ships as working source.
pay for my research with exclusive private use of whatever I find.
if a "MM" is wanted that's completely reasonable.
for paid research requests (e.g., VMs, vulns, contracts, etc) / purchase inquiries | @moschata
vulnerability research & exploit code targeting Web3, DeFi
and dApp surfaces. each release ships as working source.
pay for my research with exclusive private use of whatever I find.
if a "MM" is wanted that's completely reasonable.
for paid research requests (e.g., VMs, vulns, contracts, etc) / purchase inquiries | @moschata
Please open Telegram to view this post
VIEW IN TELEGRAM
This media is not supported in your browser
VIEW IN TELEGRAM
Wallet popup renders the chosen dApp's real branding over an
attacker-chosen recipient, amount and payload. Single Confirm
against any pre-existing connection. Mainnet-confirmed: Fragment,
DeDust.
Source delivered — 1:1 Fragment auction
phishing clone (if needed), supporting on-chain artefacts.
-- PATCHED (for now). I'll be looking into this soon.
if you need a VM or another tool for a specific platform/service for example and want to pay for my research (if not already listed on-market) and use privately, you can reach out between my work times. if what you're asking for peaks my interest i'll invest as much time as possible to satisfy outcome. ensure you're good at communicating.
DISCLAIMER: if something is not currently exploitable and nothing is found either due to "incompetence" or no possible way, then refunds (50%) are eligible!
DISCLAIMER: if something is not currently exploitable and nothing is found either due to "incompetence" or no possible way, then refunds (50%) are eligible!
TREZOR SAFE 7 · zero-prompt deanonymiser
silent dossier extraction, triggered by a single page visit
A page load on any HTTPS site silently pulls the full identity, wallet
state, and residential location of every Trezor Safe 7 user with Suite
running. No prompt on the device, no UI in Suite, no permission dialog
in the browser. Just under ~1.4s per visit on the synthetic Safe 5 bench, captchaless,
no proxy rotation needed (because this uses your site).
Per-visit dossier:
* device_id, model, label (typically owner's first name), firmware +
commit hash, bootloader hash, language, btc-only vs multi-coin,
pin / passphrase / initialised state
* BT adapter MAC + every paired peripheral the host has bonded to
(headset, keyboard, watch, partner devices). Stable per-machine
fingerprint across cookie clears, vpn switches, browser sessions
* xpub for any standard derivation (BTC, ETH, LTC, DOGE, BCH, XRP).
Off-line decoded to full receive + change tree across legacy,
nested-segwit and native-segwit; per-address balance, received,
tx count, first-to-last-tx span. Total holdings in BTC and USD.
* IP geolocation: city, region, country, lat / lon, isp, asn,
network type (residential / mobile / datacenter / vpn), timezone (as accurate as possible)
Bundle:
* landing page, 9 kb HTML, drops into any kit, fires on visit
* python collector with /capture POST endpoint, NDJSON log,
ngrok and cloudflared tunnel templates included (if needed)
* live TUI dashboard: per-victim geo + xpub-derivation +
mempool.space balance + coingecko USD enrichment, sortable by
holdings tier, dark monospace
* ndjson segmenter: whales >1 BTC, mid 0.1-1, dust <0.1, no-device,
pna-blocked
Filters:
country, isp, asn, firmware revision, pin state, passphrase state,
btc-only flag, USD threshold, account age, network type
Format:
ip | city | isp | net_type | device_id | label (name) | firmware |
pin / pp (pass-phrase) / init | model | xpub | total_btc | total_usd | tx_count |
first_seen | last_seen | address_count
Scope:
Works on Trezor Safe 7 (BLE) with Suite running on Mac, Windows or
Linux. Does not affect Safe 3, Model T, Model One or USB-only Bridge
users. Browser PNA blocks ~5-10% of strict chrome attempts;
localhost-origin and extension shims bundled as bypass.
NOTE: This is intelligence / targeting, NOT a drainer. Hardware
wallet display still gates signing. Pair with any drainer, aitm or
seed-phisher for the conversion stage. xpubs alone let you build a
watchlist for opportunistic timing.
NOTE: Trezor medium-tier disclosure-to-fix typically 2-4 weeks. Pre-patch
window viable. However, I did try reach out to Trezor personally to ask about this type of issue (not giving them source/info to patch) and they said they classify this as something that "doesn't require patching".
$2,000 | single seat (negotiable depending on your setup) / $4,500 source | @moschata
silent dossier extraction, triggered by a single page visit
A page load on any HTTPS site silently pulls the full identity, wallet
state, and residential location of every Trezor Safe 7 user with Suite
running. No prompt on the device, no UI in Suite, no permission dialog
in the browser. Just under ~1.4s per visit on the synthetic Safe 5 bench, captchaless,
no proxy rotation needed (because this uses your site).
Per-visit dossier:
* device_id, model, label (typically owner's first name), firmware +
commit hash, bootloader hash, language, btc-only vs multi-coin,
pin / passphrase / initialised state
* BT adapter MAC + every paired peripheral the host has bonded to
(headset, keyboard, watch, partner devices). Stable per-machine
fingerprint across cookie clears, vpn switches, browser sessions
* xpub for any standard derivation (BTC, ETH, LTC, DOGE, BCH, XRP).
Off-line decoded to full receive + change tree across legacy,
nested-segwit and native-segwit; per-address balance, received,
tx count, first-to-last-tx span. Total holdings in BTC and USD.
* IP geolocation: city, region, country, lat / lon, isp, asn,
network type (residential / mobile / datacenter / vpn), timezone (as accurate as possible)
Bundle:
* landing page, 9 kb HTML, drops into any kit, fires on visit
* python collector with /capture POST endpoint, NDJSON log,
ngrok and cloudflared tunnel templates included (if needed)
* live TUI dashboard: per-victim geo + xpub-derivation +
mempool.space balance + coingecko USD enrichment, sortable by
holdings tier, dark monospace
* ndjson segmenter: whales >1 BTC, mid 0.1-1, dust <0.1, no-device,
pna-blocked
Filters:
country, isp, asn, firmware revision, pin state, passphrase state,
btc-only flag, USD threshold, account age, network type
Format:
ip | city | isp | net_type | device_id | label (name) | firmware |
pin / pp (pass-phrase) / init | model | xpub | total_btc | total_usd | tx_count |
first_seen | last_seen | address_count
Scope:
Works on Trezor Safe 7 (BLE) with Suite running on Mac, Windows or
Linux. Does not affect Safe 3, Model T, Model One or USB-only Bridge
users. Browser PNA blocks ~5-10% of strict chrome attempts;
localhost-origin and extension shims bundled as bypass.
NOTE: This is intelligence / targeting, NOT a drainer. Hardware
wallet display still gates signing. Pair with any drainer, aitm or
seed-phisher for the conversion stage. xpubs alone let you build a
watchlist for opportunistic timing.
NOTE: Trezor medium-tier disclosure-to-fix typically 2-4 weeks. Pre-patch
window viable. However, I did try reach out to Trezor personally to ask about this type of issue (not giving them source/info to patch) and they said they classify this as something that "doesn't require patching".
$2,000 | single seat (negotiable depending on your setup) / $4,500 source | @moschata
if you need a VM or another tool for a specific platform/service for example and want to pay for my research (if not already listed on-market) and use privately, you can reach out between my work times. if what you're asking for peaks my interest i'll invest as much time as possible to satisfy outcome. ensure you're good at communicating.
DISCLAIMER: if something is not currently exploitable and nothing is found either due to "incompetence" or no possible way, then refunds (50%) are eligible!
DISCLAIMER: if something is not currently exploitable and nothing is found either due to "incompetence" or no possible way, then refunds (50%) are eligible!
When you see someone post a P1 ad what would you prefer to see?
Anonymous Poll
31%
$$$$ (~$2-5k) for source
26%
$$-$$$/1k lines
23%
$$$$ (~1-2k+) for full-time access
21%
a combination
Media is too big
VIEW IN TELEGRAM
Google Voice Autodialer | t.me/stackframe 😀
Processes Google Voice (or SIP trunk) calls sequentially, one at a time.
Categorises each call within 1.5 seconds as ringback, pickup, human, voicemail, or silent, acting on each instance with maximum efficiency.
Upon human response, the selected prompt is activated (e.g., Ledger, Trezor, Coinbase, Kraken, etc.).
Upon voicemail detection, the call is terminated (configurable).
The microphone remains silent by default; no audio is transmitted unless explicitly scripted. As per the standard process.
* Ringback and voicemail beep detection utilizing Goertzel algorithm plus streaming whisper transcripts.
* Press-1 detection via dual-band Goertzel algorithm with a minimum 40 ms tone duration.
* Per-call WAV recording with webhook notification upon outcome.
* Live transcripts available in the web console.
* Interfaces include Telegram bot, command-line interface, and operator console (bot/CLI/web).
* Stealth configuration via Patchright and residential proxy rotation (if required).
* SIP trunk capability: Twilio, Telnyx, Signalwire, Asterisk, etc.
* Deployment on a domain behind basic authentication and Caddy.
* Cross-platform compatibility: macOS, Linux, Windows.
* No voicemail is left; operator audio is never leaked.
* On average you can expect ~3-6 calls per total on-line minute, depending on connection, call status, and vic (data quality in general). Nothing special as it's heavily dependant on you and your data.
Sorry for the cut-off in the video too (both video time and the CLI & Web interface windows). I don't know why OBS decided to ignore the rest of the content.
$1,000 for source | @moschata
Processes Google Voice (or SIP trunk) calls sequentially, one at a time.
Categorises each call within 1.5 seconds as ringback, pickup, human, voicemail, or silent, acting on each instance with maximum efficiency.
Upon human response, the selected prompt is activated (e.g., Ledger, Trezor, Coinbase, Kraken, etc.).
Upon voicemail detection, the call is terminated (configurable).
The microphone remains silent by default; no audio is transmitted unless explicitly scripted. As per the standard process.
* Ringback and voicemail beep detection utilizing Goertzel algorithm plus streaming whisper transcripts.
* Press-1 detection via dual-band Goertzel algorithm with a minimum 40 ms tone duration.
* Per-call WAV recording with webhook notification upon outcome.
* Live transcripts available in the web console.
* Interfaces include Telegram bot, command-line interface, and operator console (bot/CLI/web).
* Stealth configuration via Patchright and residential proxy rotation (if required).
* SIP trunk capability: Twilio, Telnyx, Signalwire, Asterisk, etc.
* Deployment on a domain behind basic authentication and Caddy.
* Cross-platform compatibility: macOS, Linux, Windows.
* No voicemail is left; operator audio is never leaked.
* On average you can expect ~3-6 calls per total on-line minute, depending on connection, call status, and vic (data quality in general). Nothing special as it's heavily dependant on you and your data.
Sorry for the cut-off in the video too (both video time and the CLI & Web interface windows). I don't know why OBS decided to ignore the rest of the content.
$1,000 for source | @moschata
I'm not running any P1 myself. You will have to manage/buy routes yourself. I will only ever respond to inquiries for purchase, feature requests, bugs, or usage. Because of this there is no "$$-$$$ or % per 1k lines". Most people seem to prefer outright purchasing the source anyways based on the previous poll. MM is ALWAYS accepted if needed!Please open Telegram to view this post
VIEW IN TELEGRAM
This media is not supported in your browser
VIEW IN TELEGRAM
Bitstamp VM | t.me/stackframe
VM for Bitstamp. Feed email address list; precisely identifies real VS fake accounts at volume, no inbox access and nothing ever sent to the addresses themselves.
Every address resolves to a definite registered / unregistered verdict, written straight to a clean results file (results.txt by default). Already-checked addresses are skipped automatically with caching, so any run can be stopped and resumed with zero duplicate work or wasted spend.
Throughput scales with your setup, roughly 200 to 2,000+ verifications per minute, sustained, depending on hCaptcha solver quality and proxy pool (CaptchaSonic was used in demonstration). CapSolver will not work as it doesn't support hCaptcha anymore.
* Definite registered / unregistered verdict per address, written to a clean, readable results file.
* Parallel solver pool, run multiple captcha services and keys at once; every key you add scales throughput.
* Built-in sticky residential-IP rotation, budgeted per IP to keep high-volume runs clean.
* Pluggable from a single config file: any hCaptcha-capable solver service, any rotating-proxy provider. Solvers that can't handle hCaptcha are rejected before a run begins (let me know otherwise).
* Self-healing under load. Such as automatic retries, rate-limit-aware IP rotation, and accuracy safeguards so verdicts never degrade when pushed.
* Resume + dedupe cache, same address is never checked twice, across runs.
* Live TUI console for watching verdicts land in real time.
* One config file (config.toml) for all credentials; no account logins required.
* Cross-platform: macOS, Linux, Windows.
$1,650 | @moschata
VM for Bitstamp. Feed email address list; precisely identifies real VS fake accounts at volume, no inbox access and nothing ever sent to the addresses themselves.
Every address resolves to a definite registered / unregistered verdict, written straight to a clean results file (results.txt by default). Already-checked addresses are skipped automatically with caching, so any run can be stopped and resumed with zero duplicate work or wasted spend.
Throughput scales with your setup, roughly 200 to 2,000+ verifications per minute, sustained, depending on hCaptcha solver quality and proxy pool (CaptchaSonic was used in demonstration). CapSolver will not work as it doesn't support hCaptcha anymore.
* Definite registered / unregistered verdict per address, written to a clean, readable results file.
* Parallel solver pool, run multiple captcha services and keys at once; every key you add scales throughput.
* Built-in sticky residential-IP rotation, budgeted per IP to keep high-volume runs clean.
* Pluggable from a single config file: any hCaptcha-capable solver service, any rotating-proxy provider. Solvers that can't handle hCaptcha are rejected before a run begins (let me know otherwise).
* Self-healing under load. Such as automatic retries, rate-limit-aware IP rotation, and accuracy safeguards so verdicts never degrade when pushed.
* Resume + dedupe cache, same address is never checked twice, across runs.
* Live TUI console for watching verdicts land in real time.
* One config file (config.toml) for all credentials; no account logins required.
* Cross-platform: macOS, Linux, Windows.
$1,650 | @moschata
This media is not supported in your browser
VIEW IN TELEGRAM
Binance US VM | t.me/stackframe
VM for Binance US. Feed an email OR phone number list; precisely identifies real VS fake accounts at volume, no inbox/SMS access and nothing ever sent to the targets themselves.
Every entry resolves to a definite registered / unregistered verdict, written straight to a clean results file. Registered hits also surface the account's internal ID. Already-checked entries are skipped with caching, so any run can be stopped and resumed with zero duplicate work.
Throughput reaches high of ~55,000-60,000 CPM on a single account, accurate, no proxies, no captcha solvers, no passwords needed. Add accounts to sustain it at scale (easy cookie grabbing to add multiple per browser profile).
* Definite registered / unregistered verdict per email or phone, plus the internal account ID on every hit.
* Email and phone modes from one tool, written to a clean, readable results file.
* ~15,000-60,000+ CPM on a single account; scales linearly with more.
* Self-healing under load. Such as automatic retries, rate-aware backoff, and a health canary so verdicts never silently degrade.
* Resume + dedupe cache, the same target is never checked twice, across runs.
* Live TUI console for watching verdicts land in real time.
* One config file (config.toml), no captcha services, no proxy pool.
* Cross-platform: macOS, Linux, Windows.
$2,750 | @moschata
VM for Binance US. Feed an email OR phone number list; precisely identifies real VS fake accounts at volume, no inbox/SMS access and nothing ever sent to the targets themselves.
Every entry resolves to a definite registered / unregistered verdict, written straight to a clean results file. Registered hits also surface the account's internal ID. Already-checked entries are skipped with caching, so any run can be stopped and resumed with zero duplicate work.
Throughput reaches high of ~55,000-60,000 CPM on a single account, accurate, no proxies, no captcha solvers, no passwords needed. Add accounts to sustain it at scale (easy cookie grabbing to add multiple per browser profile).
* Definite registered / unregistered verdict per email or phone, plus the internal account ID on every hit.
* Email and phone modes from one tool, written to a clean, readable results file.
* ~15,000-60,000+ CPM on a single account; scales linearly with more.
* Self-healing under load. Such as automatic retries, rate-aware backoff, and a health canary so verdicts never silently degrade.
* Resume + dedupe cache, the same target is never checked twice, across runs.
* Live TUI console for watching verdicts land in real time.
* One config file (config.toml), no captcha services, no proxy pool.
* Cross-platform: macOS, Linux, Windows.
$2,750 | @moschata
This media is not supported in your browser
VIEW IN TELEGRAM
Phone Number version for Binance US (included).