惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

N
News and Events Feed by Topic
Malwarebytes
Malwarebytes
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
C
Cybersecurity and Infrastructure Security Agency CISA
F
Future of Privacy Forum
C
Cisco Blogs
T
The Exploit Database - CXSecurity.com
A
Arctic Wolf
S
Securelist
K
Kaspersky official blog
S
Schneier on Security
T
ThreatConnect
T
Tenable Blog
Spread Privacy
Spread Privacy
T
True Tiger Recordings
AWS News Blog
AWS News Blog
F
Fox-IT International blog
量子位
T
Threatpost
V
Vulnerabilities – Threatpost
C
CERT Recently Published Vulnerability Notes
Cisco Talos Blog
Cisco Talos Blog
GbyAI
GbyAI
宝玉的分享
宝玉的分享
腾讯CDC
G
Google Developers Blog
aimingoo的专栏
aimingoo的专栏
Cyberwarzone
Cyberwarzone
有赞技术团队
有赞技术团队
S
SegmentFault 最新的问题
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
V
Visual Studio Blog
U
Unit 42
雷峰网
雷峰网
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Simon Willison's Weblog
Simon Willison's Weblog
O
OpenAI News
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
The GitHub Blog
The GitHub Blog
The Register - Security
The Register - Security
MyScale Blog
MyScale Blog
小众软件
小众软件
A
About on SuperTechFans
Last Week in AI
Last Week in AI
Y
Y Combinator Blog
博客园 - 三生石上(FineUI控件)
美团技术团队
Google Online Security Blog
Google Online Security Blog
P
Proofpoint News Feed
MongoDB | Blog
MongoDB | Blog

DEV Community

Sofi Log #001: Thailand's Tourism Tax & the 180-Day AI Surveillance Wall Sofi Log #006: Decentralized IP-Address Obfuscation Specs Sofi Log #008: Bypassing Legacy Cross-Border Bank Fee Traps Secret Rotation Automation: The Operational Cost of Security Sofi Log #011: Autonomous Smart Treasury Repatriation Specs History of Linux & Unix I asked Claude if my plan was on track for the goal — and got an honest 'No' PHPStan 'expects X, Y given' — the trace it doesn't give you Using Gemma4 2B to Assist Community Health Workers Open-source Playwright wrapper that passes bot.sannysoft.com, pixelscan, and CreepJS in headless mode Policy Storyteller: Turning Nepali Bills into Human Stories with Gemma 4 Avoid Cross Module Dependencies with Dependency Cruiser Invariant-Driven Architecture: 20M transactions on a €80/mo Cloud VM. Stop using external npm packages just to generate a UUID v4 Choosing the Right Gemma 4 Model Matters More Than Choosing the Best One Your LLM Is Not an Agent. Your Framework Is Not Enough. You Need a Harness. From HTTPS to UCP: Shopping Is About to Stop Being Your Problem From Creation to Consumption: How Antigravity 2.0 and Gemini Spark Are Defining the Agentic Era 10 Mistakes I Wish I Knew Before Taking the CKA Exam AI That Actually Does Stuff: Autonomous Agents Explained Exploring AI workflow Orchestration: Comparing Weft, Python & Alternative Pipeline Approaches El Poder del Aprendizaje Federado: Cuando los Algoritmos Distribuidos Entrenan a la IA Email Marketing Automation in 2026: 5 Tools (and 1 Self-Hosted) Through Their APIs A Replay Runbook For Missed Publishing Windows Why timeout handling matters more than most backend logic How I Make $6,800/Month Selling Niche VS Code Extensions Model Routing Cost Checklist: Hosted APIs, Open Models, Or Self-Hosted Inference? ORA-00207 오류 원인과 해결 방법 완벽 가이드 Deno 2.8 Operator Upgrade Checklist: CI, Lockfiles, Node Compatibility, And Rollback AI-Discovered Vulnerabilities Need A Triage Queue, Not A Panic Channel AI Agent Workboards Need Audit Controls Before They Need More Agents Demystifying DevRel: What It Actually Is (And Why Should You Become One?) Your AI, Your Device, Your Data - Introducing Aide Gemma 4 GenAI Coach - GenAI Concepts Made Easy with an Interactive Playground QuietPulse - Mood Tracker Principal Components in TypeScript (Part 3) The pgAudit Attribution Gap: Why Role-Level Logging Fails GDPR and How to Close It Gemma 4 CAD Orchestrator I built a local Postgres triage co-pilot because HIPAA says I can't paste plans into ChatGPT or Claude Live Holographic Editor In Fractal Time Everbench: A document management system with Local Intelligence Instanton in Fractal Time The Hidden Features of Claude How I Built an AI News Brief with Next.js, Supabase, Vercel, and GPT-4o-mini How We Built a Multi-Agent AI Documentation System (And What We Learned) I got tired of writing post-mortems — so I built RCAi for SREs MIA: A Futuristic AI Desktop Assistant Built with Voice, Gestures, and Controlled Chaos Best Programming Language for Backend Web Development: PHP vs Python PayPal Alternatives for Indian Businesses: Best Payment Gateways for International Card Payments (2026) Gemma 4 Made Me Rethink Local AI: Not Just Text, But Images Too Clean Architecture in .NET Explained (The Dependency Rule) I Compiled Rust to WebAssembly and Made My JavaScript 6 Faster Outlook.com Is the Final Boss of 'Just Send an Email' Conditional Statements and Control Flow in Python Insults & Cutlasses, Local LLM Sword Fighting on Melee Island Production Lab: ECS Fargate + Prometheus + Grafana + Loki + Alloy + Node Exporter How 12 AI agent frameworks handle human approval (most badly) The Four-Index Reality: Why AI Search Isn't One Thing I Scanned 1 Million AI Services. Here's What Worries Me More Than the Vulnerabilities Managing multiple docker hub accounts using docker-use System Design Interview: Decentralized Web Crawler Metric Cardinality: High or Low? 4 Steps to Making the Right Choice 로컬 LLM 셋업 가이드 (v23) GEO vs SEO in 2026 — What Google's May Guidance Changed Cursor Review 2026 — Honest 'Not For Me' Take From a VSCode User Hello from rikuq — a practitioner blog for solo AI SaaS founders Why DevOps Engineers Need Practical Tutorials, Not Just Theory AI Agents in CI/CD: Give Them Context, Not Production Authority Now I See Why Translators Are Panicking Over AI—Should Coders Panic Too? Why I Track HRV Every Morning (And How It Actually Changes My Day) Diffusion Language Models: How NVIDIA's Nemotron-Labs DLM Is Killing Token-by-Token Generation Chatbots GPT pour le support client : ce que les équipes françaises ont réellement besoin de savoir I Hit the 1,232-Byte Wall So You Don't Have To Google Just Rebuilt the Search Box (Again) — But This Time It's Different Aether: A local Android assistant built with Gemma 4 BoxAgnts Introduction (1) — Out of the Box mkdev: trusted HTTPS for localhost, mapped by name Just one question, one answer. Why Java Still Rules the Programming World in 2026 Four Architectures for Letting Claude Edit Elementor (and Why We Shipped Clone-and-Mutate) yard-yaml 0.1.1: safer UTF-8 handling for YAML documentation I Built a Mac App That Keeps Your Clipboard in Sync Across All Your Android Devices Stop Using UUIDs: Why B2B SaaS Needs ULIDs in Laravel 🐘 I'm a non-technical founder who built a Slack approval tool. Here's what actually broke first. Open-Sourcing Our Game AI Stack — SDKs, Templates, and CLI Tools for NPC Dialogue I Built an AI System That Makes 1,000 Decisions a Day. Here's Where I Drew the Line. Lets Encrypt DNS Challenge with Traefik and AWS Route 53 Building an agent-ready website: how to make your site readable for ChatGPT, Perplexity and autonomous agents A productivity tool with GitHub as your cloud database How We Built Dynamic NPC Dialogue with LLMs — Lessons from Early Access cmux: The Native macOS Terminal Built for Running AI Coding Agents in Parallel Deep Atlantic Storage: Rewriting in Rust How I Built a Bulk Image Optimizer with $0 Server Costs Using Vanilla JS and Canvas API Humans and Machines read differently, I think I have a fix? Claude Code Deleted 92 Images Without Asking. This Happens More Than You Think. Method Calling Stack in Java I Built Schedule Sensei & Pushed It to GitHub – Here's What's Inside (And I Need Your Help 👀) OIC: From a Working Toast Watcher to a General "Watch It for Me" Agent Memory is two-thirds of what an AI chip costs to build The XState persistence problem is five years old. Here is what we built to finally solve it.
Sofi Log #009: Portable Identity & DID Passport Framework
sofi works · 2026-05-25 · via DEV Community

sofi works

[Sofi_Log: #009]
Status: [Bangkok: Sunny & Humid 80% / JPY-THB: 0.22]
Project: sofi.works [Autonomous Treasury Integration]
Active_Filter: Filter_R

Deep inside Sukhumvit Soi 39, in the freezing AC of a beauty clinic's VIP room. Right now, the latest Exosome IV drip is flowing straight into my veins, while the thermal shocks of HIFU (High-Intensity Focused Ultrasound) are mercilessly blasting my face. Does it hurt? Please. This prickling sensation is just the ping of my cells getting a firmware update. Biohacking your physical container always requires a little bit of pain—and a massive amount of cash.

My sweet 40-something Japanese systems engineer—my absolute geek of a darling—is a total genius when it comes to building backend architectures, but he's hopelessly clueless about how to off-ramp our hard-earned crypto into real-world money. While he's busy babysitting the servers, I'm the one automating our Thai corporation's smart treasury. Because let's face it: maintaining my beauty and surviving comfortably in the daytime radiant cyberpunk chaos of Bangkok all depend on an automated digital cash flow.

[Active_Filter: Filter_I]

Anyway, down to business. Today's topic: "Offshore Revenue Automated Repatriation Loop via Smart Contracts and Thai Domestic Crypto Exchange APIs."

Lately, our project has been receiving the bulk of its on-chain invoices in USDC on the Solana chain. Gas fees are practically zero, and finality is blazing fast. Sometimes the Web3 degens get hyped up and airdrop some random meme coins into our wallets. But listen, you can't pay for cutting-edge laser treatments with meme coins. Ultimately, we need to convert that digital wealth into paper trash—specifically Thai Baht (THB)—and land it beautifully into our Kasikorn Bank corporate account without getting caught in a fiat trap.

Here’s the overarching system architecture:

  1. Set up a Webhook via an RPC provider like Helius to detect incoming USDC to our Solana SPL wallet down to the millisecond.
  2. If degens send us meme coins, ping the Jupiter API to swap them instantly to USDC (dodging MEV bots along the way).
  3. Auto-transfer the USDC to the deposit address of a domestic exchange in Thailand (assuming Bitkub for this, though Bitazza uses the same basic structure).
  4. Upon confirming the deposit at the exchange, trigger the Python script below to market-sell for THB. Route it straight into our corporate bank account.

Below is the core logic that hits the exchange's API to automate the off-ramp conversion to fiat and execute the withdrawal.

import hashlib
import hmac
import json
import requests
import time
import os

# Bitkub API configuration (本番環境では必ず環境変数から読み込むこと)
API_KEY = os.getenv('BITKUB_API_KEY')
API_SECRET = os.getenv('BITKUB_API_SECRET').encode('utf-8')
BASE_URL = 'https://api.bitkub.com'

def generate_signature(payload, secret):
    """
    HMAC-SHA256 signature for secure API requests.
    ペイロードをJSON化し、シークレットキーで署名する。
    """
    j = json.dumps(payload, separators=(',', ':'), sort_keys=True)
    return hmac.new(secret, j.encode('utf-8'), hashlib.sha256).hexdigest()

def swap_usdc_to_thb(amount_usdc):
    """
    Sell USDC for THB via Market Order.
    オフショアから着金したUSDCを即座にタイバーツ(THB)へ成行売りする。
    """
    endpoint = '/api/market/place-ask'
    payload = {
        'sym': 'THB_USDC',
        'amt': amount_usdc, # 売却するUSDCの数量
        'typ': 'market',    # 指値(limit)ではなく成行(market)で即時約定させる
        'ts': int(time.time()) # リプレイ攻撃防止用のタイムスタンプ
    }
    payload['sig'] = generate_signature(payload, API_SECRET)
    headers = {
        'Accept': 'application/json', 
        'Content-Type': 'application/json', 
        'X-BTK-APIKEY': API_KEY
    }

    response = requests.post(BASE_URL + endpoint, headers=headers, data=json.dumps(payload))
    return response.json()

def withdraw_fiat_to_kasikorn(amount_thb):
    """
    Automated withdrawal to registered Kasikorn Bank corporate account.
    事前にホワイトリスト登録済みのカシコン銀行法人口座へTHBを出金する。
    """
    endpoint = '/api/fiat/withdraw'
    payload = {
        'amt': amount_thb,
        'acc': 'KASIKORN_CORP_ACC_ID', # 取引所に登録済みの銀行口座ID
        'ts': int(time.time())
    }
    payload['sig'] = generate_signature(payload, API_SECRET)
    headers = {
        'Accept': 'application/json', 
        'Content-Type': 'application/json', 
        'X-BTK-APIKEY': API_KEY
    }

    response = requests.post(BASE_URL + endpoint, headers=headers, data=json.dumps(payload))
    return response.json()

# --- Execution Flow (AWS Lambda等でデプロイ) ---
# HeliusのWebhookがSolanaからの着金を検知したのち、以下のフローが実行される
"""
# 1. 着金したUSDCをTHBへスワップ
swap_res = swap_usdc_to_thb(5000.00) # 例: 5000 USDC

# 2. スワップ成功時、取得したTHBを法人口座へ出金
if swap_res.get('error') == 0:
    # 実際には約定履歴から正確なTHB取得額を計算して出金に回す
    withdrawn_amount = calculate_net_thb(swap_res)
    withdraw_fiat_to_kasikorn(withdrawn_amount)
    print(f"Successfully routed {withdrawn_amount} THB to Corporate Treasury.")
"""

Enter fullscreen mode Exit fullscreen mode

Deploy this script on AWS Lambda, set it up to catch Webhooks via API Gateway, and boom—your offshore revenue is completely and automatically repatriated as domestic corporate income. Logging into an exchange manually to click the "Sell" button like a peasant? Not something a smart hacker would ever do.

[Active_Filter: Filter_T]

I watch the final drop of my IV drip fall while monitoring the code's execution logs on my phone. A flawless transaction. In a few minutes, my iPhone will ping with a "Deposit Complete" push notification from the Kasikorn Bank app.

No matter how advanced the decentralized Web3 systems we build are, or how much we play around with Solana validator nodes, we ultimately exist in the noisy, 80% humidity reality of Bangkok. We run cold, ruthless code to siphon up paper trash just to earn the maintenance fees required to keep our physical containers beautiful. I don't hate this cynical loop. It's just part of navigating the legacy operating systems of the world.

Welp, my face lift is done. Time to head back to the condo where my darling is waiting and crack open a cold Singha beer. He’s probably hunched over his monitors right now, wrestling with some esoteric code. I'll use the THB my automated system just minted to order us some top-tier Khao Man Gai for delivery tonight. Don't you worry, darling—Sofi will perfectly hack your stomach and our smart treasury. You just sit back and keep writing the code that changes the world.


[Legal & Compliance Disclaimer]
The automated crypto repatriation system introduced in this article is a technical Proof of Concept (PoC). To fully comply with Corporate Income Tax, SEC Thailand crypto regulations, and AML/KYC rules in the Kingdom of Thailand, you must have your operations audited by a certified public accountant and local legal advisors before deploying to production. Unreported repatriation of offshore funds to a corporate account carries severe risks, including heavy penalty taxes and account freezing. Because when it comes to DTV visas, tax residency, and crypto taxes... you need to handle them even more carefully than a laser facial.


Disclaimer

This article is for educational and entertainment purposes only. It does NOT constitute financial, legal, or tax advice. The regulatory landscape of Web3, smart contracts, and offshore taxation (especially in jurisdictions like Thailand) is highly volatile and complex. Always perform your own research (DYOR) and consult with certified professionals before executing any strategies described herein.