Khalid Keshta Crypto & AI

London · Building in crypto and AI since 2020

I build the systems that trace, screen and trade on-chain.

On-chain forensics used in a live police investigation, autonomous trading and screening agents running on real capital, and AI products that turn expert judgement into something a stranger can use. Nine things I have designed, built and shipped.

6 yrs Full-time attention on crypto and AI, alongside an engineering and coaching career
$1.2M TVL reached by BullStake, the multi-chain DeFi yield protocol I founded, across 7,600 investors
2 cases On-chain investigations taken through to law-enforcement and exchange-level outcomes
68K Combined audience across X and Instagram, built and kept without paid reach

Selected work

Nine entries · Forensics, agents, products, GTM

Blockchain forensic investigations

Two full on-chain theft investigations taken from raw transaction data to an outcome a third party acted on. In the first, a 36 ETH theft, I produced a formal forensic report tracing the funds through the thief’s wallets to an exchange hot wallet, established that the wallet was a nested service rather than the exchange’s own, and Thames Valley Police used that report directly to obtain records from the platform behind it. In the second, I traced stolen funds across multiple hops and cross-chain swaps to their exit point and worked with exchange compliance teams to get roughly 11.5 ETH frozen on SwapUZ, a freeze that Hong Kong authorities were involved in.

What it proves
Evidence-grade work, not dashboard commentary. Consequential, verifiable and independent of any tooling. I can build a chain of custody, write it up so a non-technical investigator can act on it, and drive it through the institutions that actually freeze money.
How others use it
Victims of theft who need a report law enforcement will accept. Exchanges and compliance teams triaging inbound freeze requests. Funds and desks that need attribution on a counterparty before they touch it.
On the redactions
Counterparty identities and my own wallet addresses are blacked out in anything published here. The underlying reports are complete and available on request to anyone with a reason to see them.

Ethereum · Bitcoin · Solana · Cross-chain swap tracing · Nested-service identification · Address clustering · Exchange compliance liaison · Formal evidence reporting

Redacted page from the 36 ETH forensic report showing the transfer chain from the victim wallet through two thief-controlled wallets to an exchange deposit address
Case 01 · 36 ETH trace · report used by Thames Valley Police · redacted
Multi-hop fund flow graph showing SOL consolidating through intermediary wallets into FixedFloat, converting to BTC, splitting across THORSwap routes and terminating at the frozen address
Case 02 · cross-chain trace to the frozen exit point
CLUSTER A · 31% TOP 10TOP 70CEX FUNDED 66%85%32%
Holder clustering and concentration read-out

Token forensics and contract analysis bot

Send it a contract address, get back a full structured breakdown in seconds: sniper and insider wallets, team allocation, top 10 and top 70 holder concentration, bubblemap cluster detection, the share of holders funded straight from a centralised exchange, holder count and average bag, and a scam or legitimate verdict. Output is formatted to be posted publicly, so the analysis doubles as content.

What it proves
I systematised my own investigative method into something repeatable. The judgement came first, the automation second, which is the right order and the rarer one.
How others use it
Retail buyers screening before they enter. Analysts and KOLs producing breakdowns at speed. Desks and funds using it as first-pass triage before a human looks.

Python · Telegram Bot API · On-chain holder and transfer data · Cluster detection · Automated report formatting

EXIT RSI(2) 88.5BB UPPERMACD HIST + DLMM BINS · ONE-SIDED SOL · 15M CLOSE
Bin liquidity, price path, confluence exit

Meteora DLMM automated exit bot

An autonomous exit system for one-sided SOL liquidity positions on Solana. It auto-discovers every open position across pools, caches candles per pool with staggered fetches to stay inside free-tier rate limits, screens mint and freeze authority on-chain for rug risk, arms itself only after entry conditions settle, and closes on a strict signal confluence evaluated on closed candles. Priority fees are set dynamically from live network sampling. Every exit writes itself to a trade log with entry value, exit value, PnL, hold time, unclaimed fees and transaction signatures. A separate pre-entry scorer grades any pool before capital touches it.

What it proves
Engineering under real financial consequence, and the willingness to be wrong in public. I killed an exit signal mid-build after realising it fired at the start of every dump, which was structurally backwards for a strategy where the dump is the fee-earning event. Reasoning about mechanism beats pattern-matching indicators.
How others use it
Liquidity providers farming volatile pairs who need mechanical exits rather than nerve. The pre-entry scorer stands alone as a pool quality filter for anyone sizing a position.

Node.js · Solana · Meteora DLMM SDK · GeckoTerminal · DexScreener · pm2 · Telegram alerts · Supertrend, RSI, Bollinger, MACD

Crypto Battlefield running a token versus token match, with bull and bear units facing each other across a 3D battlefield and live buy and sell counts above
Token vs token mode, rendering a live market feed

Crypto Battlefield

A live 3D trading visualisation where market data becomes a fight rather than a candle chart. Buys and sells become units on the field, transaction volume sets the tempo, and the front line moves with price. Built as a single self-contained page on Netlify, rendering with Three.js against a live DexScreener feed, with real-time chat on Firebase, four visual themes, a Token vs Token versus mode, and an embeddable widget so any community can drop it into their own site. Seven major versions shipped so far, with distribution running through X, TikTok and YouTube Shorts.

What it proves
I take products from idea to a live URL with real users, then keep going. Seven versions is the signal, not the first one. It also covers the full stack of the job: build, host, instrument, distribute.
How others use it
Traders who want to feel market action rather than read it. Token communities embedding the widget for engagement. Platforms looking for a retention surface that is not another chart.

Three.js · WebGL · Firebase · DexScreener API · Netlify · GoatCounter · Embeddable iframe widget

15 WATCHED ACCOUNTS · 60s SCORE TELEGRAM TAP TO COPY EDIT SKIP HUMAN POSTS · ALWAYS 374 TESTS PASSING
Stream to score to one approved reply

X monitoring and reply agent

A Python system that watches around fifteen crypto influencer accounts on a push stream, scores each new post for whether it is worth engaging, analyses it with an LLM, and delivers one recommended reply to Telegram as a tap-to-copy block with a direct link to the exact post. Each watched account carries its own tone profile, analyst or sarcastic, switchable live from Telegram with no restart. Posting to X stays permanently manual by design. 374 tests passing. It exists to replace the cost of a social media manager.

What it proves
Production judgement, not just working code. I cut A/B reply candidates down to one because operator speed mattered more than the feature. I kept a human on the trigger to protect the account. And I cut polling from 5 seconds to 60 after a $10 lesson in API burn, then set a $0.50 a day ceiling. Agents die on unit economics, not on model quality.
How others use it
Any founder or creator replacing a social media hire. More broadly, the pattern generalises: watch a stream, have a model draft, let a human approve in one tap on their phone. That shape covers most agent work that survives contact with reality.

Python · TwitterAPI.io push stream · OpenAI · Telegram Bot API · Per-account prompt profiles · 374 tests

BILL OF QUANTITIES · NRM2 ITEMQTYUNIT RATEAMOUNT Rainscreen cladding1,240m2186.40231,136 SFS infill framing980m274.2572,765 Insulation, 120mm1,240m231.8039,432 Aluminium copings186m62.0011,532 TAKE-OFF AI RATING QA GATE LARGEST SOLO PACKAGE · £30M
Take-off to rated bill, with a QA gate

RapidQS AI estimating system

As a former senior cost manager with eight years across consultancy, main contracting and specialist subcontracting, the largest package I priced solo was around £30M. So I automated my own job. RapidQS is an AI-assisted estimating workflow: a structured take-off and bill template, a Claude-based rating and checking layer, Kreo integration for measurement, and a QA process that measurably cut client revisions. It is the reason I can turn around a bill of quantities in a fraction of the usual time without the accuracy loss that normally comes with speed.

What it proves
The thing most AI projects lack: a domain expert who knows exactly where the model is allowed to be trusted and where it must be checked. The QA gate is the product, not the generation step. This is the same discipline that makes an LLM deployment survive in any regulated or high-consequence industry.
How others use it
Contractors and consultancies pricing faster without adding headcount. More generally it is a template for applying AI inside any expert profession: encode the method, automate the mechanical part, gate the output, keep the expert accountable.

Claude API · Structured prompt workflow · Kreo · Excel estimating templates · NRM2 · Multi-stage QA review

19 CONDITIONAL QUESTIONS INTAKE CLAUDE API TRAINING · NUTRITION · MANAGEMENT PLAN
Conditional intake to generated plan

AI coaching intake and plan engine

A nineteen-question conditional intake form feeding an automation layer into the Claude API, which returns a complete personalised training programme, nutrition plan and diabetes management protocol, formatted and delivered to the client. Three subscription tiers sit behind it. The prompt is the product: it carries the coaching methodology, the safety boundaries, and the structure of the output, so the quality holds without me in the room.

What it proves
End-to-end AI product delivery with no engineering team, and the harder half of that job. Turning a professional's judgement into a prompt that holds up on inputs the author never anticipated is most of what commercial LLM deployment actually is.
How others use it
Coaches, clinics and any expert practice that needs to serve more people than hours allow. The architecture is domain-agnostic: conditional intake, automation middleware, LLM generation, branded document out.

Claude API · Typeform Pro · Make · Prompt engineering · MailerLite · Stripe · Tiered subscription delivery

EN MASTER → REVIEW → AR ADAPTATION DOCX BUILD HTML → PDF VALIDATE VISUAL QA · EVERY PAGE RENDERED NOTHING SHIPS UNSEEN. THE CHECK IS THE PIPELINE, NOT AN AFTERTHOUGHT.
Build, convert, validate, render, then ship

Coaching guides and publication pipeline

A library of branded guides and long-form drafts, produced through a repeatable pipeline rather than by hand: programmatic document generation, conversion to print-ready PDF, structural validation, and a visual check where every page is rendered to an image and inspected before anything reaches a client. English is always the locked master, reviewed before any Arabic adaptation begins, so the two versions never drift apart.

What it proves
The unglamorous discipline almost nobody applies to generated output. I built verification into the pipeline instead of trusting the generator. Bilingual delivery with a locked source of truth is the same problem as versioned content at scale.
How others use it
Creators and educators shipping premium digital products in more than one language. The toolchain itself is reusable for any documentation, report or template output that has to look correct, not just parse correctly.

Node.js · docx · WeasyPrint · LibreOffice conversion · Structural validation · Page-to-image QA · Arabic RTL typesetting

BONDING CURVE · GRADUATION 15–20 STAGGERED WALLETS 2,000 SOL ALLOCATED 5 TIERS · 1,000 NFTS TIER 1 TIER 2 TIER 3 TIER 4 TIER 5 30-DAY AVERAGE HOLDING SNAPSHOT · NOT BALANCE AT T
Graduation path and holding-weighted reward tiers

$DOODi and $REDOOD: relaunch strategy, incentive design and NFT collection

$DOODi was a token that reached roughly $19M market cap before a hack collapsed it in October 2024. $REDOOD is the rebuild, and I designed the whole thing: an eight-section go-to-market playbook, capital allocation modelled across 2,000 SOL, a four-tier Galxe rewards campaign for returning holders, and a five-tier NFT airdrop keyed to a thirty-day average holding snapshot rather than a balance at a single moment, so the reward goes to conviction and not to a wallet that appeared the hour before the cut. A 1,000-piece NFT collection with token-linked utility is in production to fund the relaunch.

What it proves
Incentive design under adversarial conditions. The thirty-day averaging is the whole idea: most airdrops reward whoever games the snapshot, so I priced time held rather than size held. Alongside it, recovery leadership after a failure I was personally on the wrong end of.
How others use it
Projects designing distribution that rewards holders instead of farmers. Teams rebuilding community trust after an exploit, where the incentive structure has to argue for itself.

Solana · pump.fun · Galxe campaign design · Tokenomics and capital modelling · NFT utility design · Community strategy

About

On paper I am two things: a civil engineer who became a senior cost manager, and a coach with a forty thousand strong following. What I actually am is a creator. For the past six years almost all of my attention has gone to crypto and AI, and the two earlier careers turned out to be the useful part rather than the thing I left behind.

Engineering taught me to measure before I commit, which is most of what on-chain forensics is. Surveying taught me to price risk on incomplete information and be accountable for the number, which is most of what running capital is. Coaching taught me to take something complicated and make a stranger able to use it, which is most of what building a product is.

So I build. Forensic investigations that ended with funds frozen and a police force holding exchange records. Agents that watch markets and social streams and act inside strict limits I set. AI systems that carry a professional's judgement into work they are not personally present for. Some of it is serious infrastructure and some of it is meme coins, and I have learned an uncomfortable amount from both.

Based in West London. I write up most of what I find in public, usually on X.