About
Simonluca Landi
I am co-founder and Chief Technology Officer of CryptoRefills, founded in Amsterdam in 2018 with Massimiliano Silenzi and Mats Veenman. We sell digital goods (gift cards, mobile top-ups, travel eSIMs) to people paying in cryptocurrency, across more than 180 countries, with a stablecoin-first checkout spanning 20+ assets on Ethereum, Solana, Base, Polygon, Arbitrum, Optimism and Tron.
The storefront is the easy half. Most of the engineering is in settlement: value arrives on a dozen chains that do not agree with each other, in assets whose price moves while the customer is still on the checkout page, and it has to become a delivered product in a few seconds with the accounting still correct a month later. Indexing, pricing, reconciliation, and a working definition of the moment a payment has actually happened.
CryptoRefills is the one I talk about publicly, and it is not the only one. Over the years I have started and run companies in mobile apps, mobile advertising, payments and crypto, and several are still going. They stay off this page because it is not a portfolio.
What I work on now
Whether a software agent can complete a purchase on its own. Find the product, get a quote, authorise, pay, take delivery, and deal with the refund when it goes wrong, with nobody watching.
CryptoRefills publishes agentic-commerce, a reference for that stack. Half of it is the protocol layer: ACP, AP2, x402, MCP, L402, UCP. The half I think is more useful is the operational one the specs skip, which in practice means refunds, delivery semantics, fraud signals and settling across several chains at once. We wrote it from what we run, so some of it is opinionated in ways a standards document would not be. The companion agent skills let an agent buy a gift card or top up a phone over MCP, or pay by itself over x402, with no account and no API key.
Why crypto, specifically
Not the trading. What keeps me here is that money became programmable and most of the consequences are still unexplored. A stablecoin transfer is a function call that settles. It can carry conditions and logic, and it leaves a receipt a machine can read without asking a bank whether the thing happened.
This is what makes agentic commerce workable. Agents can be given cards, and ACP and AP2 are largely about doing that properly with tokenised mandates, but a card drags along an issuer, a mandate and a dispute process. A key and a payment challenge answered in about a second drags along none of that. x402 does it over ordinary HTTP on status code 402, which the spec has kept reserved for future use since 1997. Lightning Labs got there first with L402, which is also on our list and also uses 402; x402 is the stablecoin version of the same idea.
On Lightning, since somebody always asks
In 2019 I wrote a piece called Why Lightning Network makes no sense. It is still in the archive and I have not put a correction on it, because I still think the core of it holds.
The argument was that payment channels fit retail money badly. Payments run one way, customer to merchant, and in a channel network receiving is the hard direction: a merchant needs inbound capacity and somebody else has to supply it. The industry's answer was to build a market for that liquidity, which to me confirmed the diagnosis rather than solving it. Node economics never worked either. The operator I quoted was running twenty nodes for $5.74 a month.
I got the title wrong, though. Routing improved more than I expected, and service providers made Lightning genuinely usable for ordinary people, even if that is not the peer-to-peer network it was sold as. The defensible claim was "this will not be the general payment rail", not "this makes no sense". And the thing that actually decided it is something I never mentioned: denomination. People wanted dollars. Public Lightning capacity today is around 4,900 BTC, roughly flat over three years, and most of the recent growth came from exchange integrations. Tron alone has moved trillions of dollars of USDT this year.
Which is why our own work went the other way. HTTP 402 was always the right idea, and Lightning Labs got there first with L402. x402 is the same idea on a rail with no inbound capacity to arrange, denominated in the thing people actually price goods in.
What I would like to see next is heavier things settled the same way. Smart contracts holding conditions and not only balances. Treasury that runs as a program. Real-world assets are the interesting hard case, and I would rather be honest about it than sell it: code enforces the ledger, not the ownership. The trust deed and the transfer agent and the jurisdiction are all still there, only now they sit underneath a token instead of beside it, and closing that gap is most of the actual work. None of it needs a token to go up, which is why I find it more interesting than most of what my industry talks about.
How the work gets done
The oldest thing on this site is a series about continuous deployment written in 2012, from inside a production system being moved off svn update /var/www. Tests first. One pipeline from development to production. Smoke tests on every deploy, automated rollback, and business metrics rather than a green build as the gate for calling a release good. My about page from that same year lists TDD and domain-driven design among the things I was working on, so the date is at least documented and not just something I am claiming here.
All of that is standard practice now. I keep the archive because the same approach has since carried through carrier billing, consumer crypto checkout and agents, which is three fairly different substrates for one habit.
These days most of my engineering happens through AI agents, dozens of them running against real repositories at once. They are very good at producing work that looks right, and that is the whole problem: a plausible diff is harder to catch than a broken one. What makes them usable is the same discipline as before. Tests that fail loudly, changes small enough to revert, a build that stops rather than shipping something broken. This site is built that way, which is why its content sits in data files that are validated at build time. A malformed one stops the release.
Before
Deputy CTO at Onebip, a mobile payments processor, where Massimiliano Silenzi was CEO. Carrier billing at the volume of large game publishers. Payments have been the job for about twenty years now: carrier billing, then consumer crypto checkout, now agents.
Degree in materials engineering, for electronics, at the Politecnico di Torino, with honours.
Photometry
I observe under AAVSO observer code LSIC and file variable-star photometry to the AAVSO International Database: multi-band Sloan work, including the recurrent nova T CrB. The record is open, so anyone who wants the raw points can pull them.
Flares on EV Lacertae
EV Lac is one of the best studied flare stars there is, and it still cannot be scheduled: you schedule the monitoring and hope the star cooperates. Catching a flare means sitting on it continuously and sampling fast enough that a few minutes of brightening does not average itself away.
I monitor it in Sloan g′ on a 30-second cadence, holding roughly 0.009 magnitudes of error per point. The run below, filed under LSIC, caught two obvious flares with a smaller excursion between them: the first rising 0.15 magnitudes and decaying over several minutes, the second sharper and reaching 0.207 magnitudes above the quiescent level, which is more than twenty times the error on a single point. The empty band in the middle is a break in the run, and the plot leaves it empty.
I submit these because EV Lac flares more often than any one observer can cover. On its own a single run is a curiosity. In a database alongside everyone else's it becomes one point in a duty cycle.
People ask what a small telescope adds now that surveys cover the whole sky. Less than it used to, honestly. Evryscope watches continuously at roughly two-minute cadence and has published EV Lac flare rates; NGTS goes down to thirteen seconds. The gap left over is narrower than people assume, and most of what remains is about colour.
TESS sees from about 600 to 1000 nm, a band chosen to favour cool stars. Flare emission is a hot continuum around 9,000 K, which peaks in the ultraviolet and falls off through the visible. What matters for detection is how far the flare stands above the star it sits on: against a 3,400 K photosphere the flux ratio is about 264 at Sloan g′ and about 35 at i′. Roughly eight times more contrast in the blue. The same event that is unmistakable in g′ is a small bump in a red band, which is why TESS is excellent for rotation and mediocre for flares.
TESS also leaves a sector after about 27 days, and its full-frame images arrive minutes apart, though selected targets do get 20-second sampling. So the remaining gap is narrow: continuous blue photometry of one star, at seconds, for as long as the star is up. A small telescope with a photometric filter set does that well enough.
All of this comes off a backyard under a Bortle 8–9 sky. Sloan i′ sits around 770 nm, far enough into the near-infrared that it is much less affected by urban light pollution and atmospheric scattering than the visible bands, which is what lets faint dust structure survive a city sky. Less true than it used to be, now that white LED street lighting spills further into the red.
The filters are why the pictures and the measurements are one activity. Sloan g′ r′ i′ is a photometric standard, so these are the passbands the survey catalogues are calibrated in and the ones the AAVSO record above lists as SG and SI. To be exact about it, the Baader set approximates the SDSS system rather than being it, and turning frames into measurements anyone else can use still takes standard stars and colour terms. Starting from the right passband is what makes that step possible at all.
Instrument
- GSO 8″ f/8 Ritchey-Chrétien, carbon tube
- RisingCam ATR3CMOS26000KPA
- ZWO AM5 mount
- Baader SLOAN/SDSS g′, r′, i′ 36 mm; Baader Hα ultra-narrowband 3.5 nm, CMOS-optimised, 36 mm
- PixInsight

Out of the same practice comes the asteroid work. I derive rotation periods for numbered main-belt asteroids from TESS full-frame-image moving-target photometry, deliberately picking objects with no reliable prior determination, so most entries in the catalogue are first determinations.
The published catalogue is at DOI 10.5281/zenodo.21446076, with per-object reasoning and ALCDEF light curves, as the open data companion to a paper submitted to the Minor Planet Bulletin. Work registered under ORCID 0009-0009-3410-8443.
The hard part is telling a real rotation from the spacecraft's own rhythms. TESS runs a 13.7-day orbit, which is 328.8 hours, and the things that vary on it, scattered light from Earth and Moon sweeping across the field and the thruster firings that bleed momentum off the reaction wheels, imprint not one spurious period but a comb of them at 328.8/n hours. At asteroid periods that comb is dense. My adopted 3.6640 h for Vigdis sits about 0.3% from the n=90 tooth, which is closer than I would like. tess-decomb tests a candidate against roughly two hundred ordinary field stars from the same sector: if they share the signal, it belongs to the spacecraft. The test has limits worth stating. A moving target crosses different pixels and different background stars than a fixed one, so its systematics resemble theirs without being identical, and nothing in the method separates a real period from one that happens to land on a tooth.
The catalogue ships the rejects as well, fifteen of them, each with the reason it did not survive. A 43-hour period on (637) fell when the sector turned out to be contaminated. A 144-hour period on (4876) went because the sectors disagreed and the fold came out single-humped. A 103.9-hour signal on (45502) was an artifact of a 69.8-hour gap in the data. One, (90866), was in the paper and came out during revision because the phase-connected fit would not hold. Long periods from a single sector are the easiest thing to get wrong here, and anyone reusing the catalogue needs to know which ones I threw away.
About this site
sll.it has been mine since 2012. It is a static site: nothing to log into, no database behind it. The archive keeps what was written back then, at the addresses it was written at.