293332
Francesco Piccoli

@francescop #293332

Co-Founder & CEO @almanax | Ex Head of Product @ AnChain AI | UC Berkeley engineering
1534 Follower 341 Following
Starting from this week, @almanax will offer offer $300 in security scan credits to the top 10 mini-apps on the leaderboard each week for the next 3 months.

In practice, this means multiple full scans of mini-apps’ repos + continuous monitoring of code changes for 3 months, to prevent security vulnerabilities from making it to production.

The product is self-service: https://app.almanax.ai/
To claim the prize, projects can DM me directly at the end of each cycle and I'll apply their credits.

We believe mini-apps will be instrumental to drive the growth of the ecosystem, and we're excited to support their builders!
This is incredible work by Kraken.

“Not all attackers break in, some try to walk through the front door”

https://x.com/coindesk/status/1918380370896073190?s=46&t=a16OBx1OV2RbvWl1HoCCGQ
Had a great time at Farcon.
Great to see the faces behind all the pfps I interacted with here :)

And here's an article on why you should never change it from @rrhoover
https://www.ryanhoover.me/post/why-i-never-change-my-profile-pic
Almanax was featured by PitchBook in their report on the top startups at Paris Blockchain Week.
Love their comparison with Datadog. 👇

"Almanax, one of the three Start in Block competition winners, sets out to become the AI “security engineer” that Web3 sorely lacks.

The team’s thesis is that nearly $9 billion has been stolen from crypto projects in just three years, and the attack surface is expanding faster than human auditors or rule-based scanners can cope.

Almanax applies large language model (LLM) agents to reason across entire codebases—smart contracts, traditional back-end services, and even software supply chain dependencies—and flags exploitable logic with far fewer false positives than legacy static analysis tools."
https://imagedelivery.net/BXluQx4ige9GuW0Ia56BHw/77b51173-6751-4ba6-8103-364eb92cce00/original
Just finished reading Chip War.
Great book on the history of the semiconductor industry and how it impacts the geopolitical landscape
something happening this week in nyc??
https://imagedelivery.net/BXluQx4ige9GuW0Ia56BHw/eda5591c-bc76-4e25-9571-2e2e1ecdbc00/original
Today I learned that Cursor writes almost 1 billion lines of accepted code a day.

To put it in perspective, the entire world supposedly produces just a few billion lines a day.
/dev
has anyone created a starter pack with farcon attendees?
@linda @ted
who will be at farcon this week?
let me know if you need a space to co-work before the conference
i just got a cold email from an english premier league soccer team asking to sponsor them

that would be something
Many products out there feel like “AI Horseless Carriages” —traditional interfaces with some AI sprinkled here and there.
Gmail’s AI assistant is a clear one.

Great essay by Pete Koomen

https://koomen.dev/essays/horseless-carriages/
/dev
Earlier this month, we were selected as one of the winners of the
Paris Blockchain Week startup competition.

You don’t often see security getting this level of recognition, but the tides are shifting.

Companies are beginning to recognize the growing cyber risk — and that AI will play a key role in addressing it.

Watch me share the Almanax vision for an AI Security Engineer.
https://x.com/AlmanaxAI/status/1915099579474719086
Today, @almanax transitions from beta to general availability (GA).

What happens when the number of lines of code engineers produce goes up 100x thanks for coding assistants like Cursor? How are security teams supposed to handle that?

We believe AI will change security the same way it’s changing software engineering.

Almanax is an AI security engineer designed to help security teams prevent hacks.

Sign up on app.almanax.ai and integrate LLMs in your security processes.
Celebrating our anniversary with champagne, Korean bbq, and great people
https://imagedelivery.net/BXluQx4ige9GuW0Ia56BHw/15dca926-4f7d-4e52-ae50-ff81ca7bff00/original
https://imagedelivery.net/BXluQx4ige9GuW0Ia56BHw/1ae44823-0042-4c6d-0f16-94a0a6cf1400/original
/Food
this is cool
875027
Almanax
@almanax·11:50 16/04/2025
We just got an upgrade
@almanax turns 1 today!

1 year ago, @mmwtsn and I began a journey to stop hacks.

He had spent years in cybersecurity and helped secure Coinbase.
I had spent 4 years investigating billion-dollar hacks.

Code vulnerabilities were often a major attack vector. We saw that code security was mainly done through third-party audits every 6-12 months, or through underperforming static analysis tools.

Compounding on top of that, coding assistant tools like Cursor and Github Copilot were changing the way engineers write code.

We asked ourselves, “What happens when companies produce 100x the number of lines of code they used to? How are security teams supposed to handle that?”. We needed a Cursor for Security teams.

We started Almanax to build an AI Security Engineer because we believe LLMs will change security the same way they’re changing software engineering.

On to year 2.
https://imagedelivery.net/BXluQx4ige9GuW0Ia56BHw/081f5139-cea0-4df0-ac72-9a352b7eaa00/original
Reality is nothing but a collective hunch
Any plans to introduce organization accounts and affiliation for users? Similar to what Twitter did
Proud to wake up and find myself on the Forbes under 30 list for the Technology track - alongside a great roster!

Great to see the work we’re doing at Almanax getting increasing recognition.
https://imagedelivery.net/BXluQx4ige9GuW0Ia56BHw/5a019ede-c793-4aac-234c-10c9b2d73100/original
and it made us go way over the weight limit at the airport
Loading...
Apparently I like to make weird faces when speaking
https://imagedelivery.net/BXluQx4ige9GuW0Ia56BHw/84b367dd-c07f-4eb4-7ded-7ea3252feb00/original
Fun to share the stage in Paris with these folks!
https://imagedelivery.net/BXluQx4ige9GuW0Ia56BHw/3b4d0625-5df1-4b6b-cd28-e00ca2d7a100/original
@almanax was just selected as the winner of the AI track at the Paris Blockchain Week startup competition among more than 1000 applicants
https://imagedelivery.net/BXluQx4ige9GuW0Ia56BHw/d73ec0b2-a984-4cce-b57e-6e8713bd6700/original
https://imagedelivery.net/BXluQx4ige9GuW0Ia56BHw/0cbed4ea-6a4a-4240-75ba-c3fb2b2b9000/original
I forgot to post this real photo
https://imagedelivery.net/BXluQx4ige9GuW0Ia56BHw/a333f9fb-b46f-4ec5-006d-edd55e697500/original
Loading...
can now claim @almanax has been featured both in Times Square and at the Louvre museum
https://imagedelivery.net/BXluQx4ige9GuW0Ia56BHw/d8dd07e9-57aa-49c7-0514-0e2f7f769d00/original
defense must be correct 100% of the time, attackers only have to be right once
by far the best sandwich in NYC
Loading...
/NYC
What are people’s favorite mini-apps?
I feel like I’m under-utilizing them
Ran a 10k in Governors island today.
We look much happier in the pre-race photos than the post ones
https://imagedelivery.net/BXluQx4ige9GuW0Ia56BHw/4ddd9ea1-d7df-4535-9e97-30b50a7fda00/original
/NYC
It sounds smarter to be a bear, but optimists are the ones who make things happen
"only the paranoid survive" lives rent free in my head
Back to FC after a few weeks heads down preparing for GA.

- we got selected by Paris Blockchain Week as one of the 12 top startups among 1000+ applicants so I'll be on stage in Paris next week

- we released a new AI model which can scan any type of code for security issues (not just solidity). We also rolled out CICD integration, so users are now scanning every time new code is pushed

- doing our official product launch on April 15th - if anybody wants to help us test the system before then hmu
Today we release ALMX-1.5, our new AI model, and the first version of the Web3 Security Atlas (W3SA), an open-source initiative led by Almanax aimed at improving Web3 security with AI.

ALMX-1.5 is designed to navigate large scale and complex repositories, to perform high effort reasoning across multi-file execution paths, while empowered with the ability to consult the project documentation and navigate the internet. It supports most commonly used programming languages.

This first W3SA release includes a benchmarking suite for blockchain code vulnerabilities. It initially focuses on EVM smart contracts written in Solidity and Solana programs written in Rust, with a second launch planned for Stellar and Aptos smart contracts.
https://imagedelivery.net/BXluQx4ige9GuW0Ia56BHw/942ae47e-b1d1-4d22-bdc2-bd31b7581d00/original
we saw a recent increase in scams inviting people to participate in podcasts.
pretty well structured, message is coming from accounts that seem legit.

both my cofounder and me have been targeted by multiple accounts already (good luck scammers).

be careful out there