166,700 neurons do not amount to a trading edge
Stonkfly retains 166,700 neurons and about 25.6 million directed connections from the MaleCNS v1.0 fly dataset. It renders Coinbase price history as a 320 by 180 RGB chart, stimulates mapped visual cells, advances a spiking-network simulation, and converts activity in selected descending neurons into buy, sell, or hold. No language model picks trades, and no conventional price rule replaces the neural proposal. The fixed decoder is an engineered interface rather than a discovered biological trading circuit.
Profit and loss produce artificial reinforcement signals in 15 PAM11 cells or 2 PPL101 cells, which can alter selected mushroom-body connections through a candidate memory rule. The model documentation is explicit about what this fails to prove. Weight changes do not establish useful credit assignment, biological fidelity, or profitable learning. A persistent neural bias can simply cause repeated buying, which a rising market may reward without the network learning anything useful.
The $100 paper account is the right starting point
Paper mode is the default. It reads public BTC-USDC prices, starts with a simulated $100 balance, applies modeled fees, and stores its ledger, chart images, and resumable neural state locally. No Coinbase credential is required. An offline fixture mode can run faster for plumbing checks, while a frozen-memory control preserves the same setup without weight changes. These are useful experiment controls, but the project warns that accelerated fixture runs are not market backtests.
Live operation requires two independent opt-ins: an environment value and the --live flag. The operations guide calls for a separate Coinbase Advanced portfolio holding at most 100 USDC and a scoped ECDSA key with View and Trade permissions, while Transfer stays disabled. A preflight-only command checks permissions, balances, open orders, and portfolio scope without submitting an order. Those safeguards are thoughtful, although real funds remain exposed.
What happened when we ran it
Our sandbox installed commit 78ef3e0 in 51 seconds. The environment pulled 151 packages and occupied 489 MB before the separate connectome data download. The build completed in 5 seconds, then pytest succeeded in 35 seconds with 41 passed, 0 failed, and 1 skipped. The repository supplied one CI workflow and a tests directory. We used a fresh Debian container with 3 CPUs, 8 GB of RAM, no secrets, and no elevated privileges.
Pip-audit reported 20 known vulnerabilities. The supplied measurement does not name their packages, severities, or exploit paths, so assigning those details would be guesswork. Still, the count materially changes our recommendation because live mode reads a private trading key and can submit orders. A green 41-test run checks expected behavior; it does not cancel known dependency advisories. Paper mode keeps the experiment useful while maintainers identify and remediate the affected dependency chain.
Twenty known vulnerabilities block our live-mode recommendation
The installed dependency tree is large for a 3,374-line source project: 151 packages and 489 MB in our run. Direct pins include Coinbase AgentKit, Coinbase's Advanced client, NumPy, pandas, PyArrow, Pillow, Pydantic, and dotenv. Stonkfly itself is only v0.1.0, and GitHub has no tagged release. Before any live trial, we would require an updated audit with package names, fixed versions, and regression tests around authentication, previews, settlement, and restart recovery.
Credential scoping limits damage but does not make vulnerable code acceptable. A key without Transfer permission still has authority to trade within its portfolio. Keeping the JSON key outside the repository, setting file mode 600, and using a dedicated balance are good controls. They reduce exposure if something goes wrong; they do not repair the 20 findings. Until that audit is clean or each advisory is shown irrelevant, live execution is an avoidable risk.
A $20 drawdown stop does not cap total loss
Orders are tightly bounded. The default maximum buy commitment is $10 including a fee reserve, with no shorting, borrowing, transfers, or margin trading. Stonkfly allows at most 24 attempts per UTC day, enforces a 60-second interval, checks quote age and spread, previews fees, and uses price-bounded fill-or-kill orders. A unique client order ID is recorded before submission so an uncertain response triggers reconciliation rather than an automatic duplicate order.
The risk boundary still has a hard limit. A $20 drawdown stops future orders but does not sell existing holdings, and later market moves can deepen the loss. Stopping the process cannot cancel an order already submitted. The local lock protects one run directory, not copied ledgers on multiple computers. Anyone testing live mode would need a separate plan for holdings, uncertain exchange responses, machine sleep, backups, and human review after a STOP condition.
September 10 code with six open fixes is early software
The repository was created and last pushed on September 10, 2026. GitHub showed 862 stars and 8 open issues and pull requests on October 2, split into 2 issues and 6 pull requests. Proposed fixes cover missing data errors, absent ledgers, quote veto handling, fixture timing, negative sleep calculations, and Windows support. Recent discussion exists, but those fixes were still open and the main code had not moved in three weeks.
Use Stonkfly to ask a research question, not to answer whether a fly can beat crypto markets. A serious test would need chronological holdout data, multiple independent starts, frozen and shuffled-reinforcement controls, fees, exposure baselines, retention checks, and a reset of learned weights. The repository names those requirements itself. Until they are run and the 20 dependency findings are resolved, paper mode is both the scientifically honest choice and the safer one.

