Skip to content

Conversation

@LloydCoder
Copy link

Adds a high-confidence detector for hardcoded secrets common in Nigerian fintech and Web3 projects.

Detects:

  • Paystack secret keys
  • Flutterwave keys
  • Remita credentials
  • Interswitch MAC keys
  • Wallet mnemonic seeds (with entropy filter for accuracy)

Builds on my contributions to secret scanning tools:

Tested locally on Solidity samples—detects issues reliably without FPs. Follows Slither guidelines.

Author: @LloydCoder (Tinlance) — Advancing African blockchain security 🇳🇬

…ctor by @LloydCoder

New detector for hardcoded secrets in Solidity contracts targeting Nigerian fintech and crypto:
- Paystack live/test keys
- Flutterwave/Rave keys
- Remita merchant + hash
- Interswitch MAC keys
- 12-24 word wallet seeds

Includes entropy check to reduce FPs. Part of my African security series:
- Nuclei: #14253
- TruffleHog: #4588
- Semgrep: #3719
- Gitleaks: crytic#2001

Tested with `slither . --detect hardcoded-nigerian-secrets` on sample contracts—accurate hits, no noise.
Author: @LloydCoder (Tinlance) 🇳🇬
@LloydCoder LloydCoder requested a review from smonicas as a code owner December 6, 2025 13:47
@CLAassistant
Copy link

CLAassistant commented Dec 6, 2025

CLA assistant check
All committers have signed the CLA.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants