Pinned Tweet
Announcing my rejected talk for @bsidespyongyang: Is that "web3 enthusiast" follower with the anime PFP acting suspicious? Find out if you have confirmed North Korean followers at dprkdetector.app.
8
8
50
18,880
Hmm maybe 50000 USDC is a little on the lower side compared to 100 MM...
Two BitGet bug bounty reports approved then ignored on BugRap for exposure on both the main exchange and wallet. I provided live evidence, showing 10k USDC lost via address substitution and provided PoC's... then..Nothing. @slowmist_team @peckshield @CertiK
1
48
I genuinely don't know how people get bored in this space You could work for a bank where your big security accomplishment is decommissioning a Windows XP machine Or fry your dopamine receptors with non stop 9 fig hacks I know which one I'm picking
Bitget and duelbits hacked on the same day. AI super cycle
1
45
208
4,411
66,448
1,633,749
Flo can I interest you in a job working Bug Bounty Triage?
Replying to @AQululu66418
We’ve already responded to you numerous times via DM on different social media platforms. The response isn’t going to magically change just because you’re asking the same question on X now. /Flo
1
3
71
It's still slop, just less of it to process mentally
Replying to @claudeai
Opus 5.5 communicates more naturally, addressing some of the most common feedback we heard on Opus 5. It puts the most important information up front and follows the writing rules you give it, which makes long sessions easier to follow.
1
54
One reason I know for a fact that OAI hasn't achieved AGI internally is exactly what @joshua_saxe points out - their security program is "cobbled together". If Daybreak is supposed to autonomously solve security, why hasn't it solved security for you?
It's true there's a sense in which you can't blame OpenAI's CISO for narrowly defending his company's corporate interests by pressuring the @HacktronAI guys to downplay having accessed the OpenAI monorepo and having positioned themselves to move laterally in pursuit of model weights, data sets, and training recipes. That seems to be @jachiam0's angle here. Respectfully, this misses the larger story -- that OAI is pursuing superintelligence, admits it's as dangerous and impactful as nuclear fuel rods, and yet seems to be at the cobbled together security maturity of a high velocity blitzscale-up. The public deserves to know all that and having us know that required exactly what the Hacktron guys did. The public -- and the government -- absolutely needs to know, and, really, in as dramatic and "stunt"-like a fashion as necessary to get people's attention, how permeable OpenAI appears to be, given the societal scale of its implications. It matters to all of us if we're on track for training recipes and weights for GPT-9 to get easily stolen, and it appears we are. While I'm on topic, it's in our interest to know whether some new model could escape a eval environment and self replicate across the Internet. We need way more transparency on that too as compared to what OpenAI has provided. For all those reasons we're lucky to have @HacktronAI and we're lucky to have Huggingface, and ultimately - and soon - we need policy enforced transparency and rules -- somehow -- on all of this, across all frontier AI development.
1
69
I don't expect any company to be bug free but there was a cascade of failures in both protection and detection. Many opportunities along the way, yet despite all the bluster the first sign something was amiss wasn't the PR - it was the report itself!
1
35
Like it or not, OAI needed @HacktronAI. They found multiple gaps in their security posture that led to real impact. But the most interesting to me is that internally OpenAI is still tool-assisted humans and not completely run by agents, despite the marketing promises.
1
23
Every crypto event with a DJ looks like this
Never forget the time Julian Assange, international fugitive on the run from the Feds, randomly turned up at a Reykjavík nightclub in Iceland & proceeded to torch the dance floor. Lithe as a lynx, gettin’ low & swangin’ them hips…
1
2
45
I have some regrets
15
a good example of why you need threat modeling: you prepare your detections for theoretical CPU-temp fluctuations the actual rogue AI is putting content on public wikis
OpenAI's Noam Brown says air-gapping the computers may not stop a misaligned AI, because two air-gapped machines can still talk by running a CPU hot and reading the temperature change "But I think the major takeaway from the incident is that people underestimated the AI. And we never want to be in a situation again where we underestimate the AI. It's a weird world, because AI progress is so fast that people are consistently underestimating the AI." "So to be in a situation where you don't underestimate it again, when it comes to safety and alignment, you have to have a very, very, very high bar." "You could even go as far as to say, "Well, we should air gap the computers." And I'm not convinced that that would be sufficient." "There are studies, and this is mostly academic, where you can have two computers next to each other that are air-gapped and they're still able to communicate with each other because they have temperature sensors." "One of them is able to run their CPU really hot, and then the other one can actually detect the temperature change, and then that actually gives them a mechanism to communicate." _________ Link and more key quotes from OpenAI's safety related conversations: firesidealpha.substack.com/p…
39
I'm beginning to think I may look a little dodgy while traveling with two @GrapheneOS phones
1
48
>he redeemed the gift cards
BREAKING: Travis Kelce has been named as a victim in a massive Ponzi scheme that pulled in more than $35 million from investors. Siddharth Jawahar, a 38-year-old illegal immigrant, pleaded guilty to three counts of wire fraud and has now been sentenced to 11 years in federal prison and ordered to pay more than $31 million in restitution. Prosecutors say Jawahar took in more than $35 million but invested only about $10 million, using new investor money to repay earlier clients and fund private jets, luxury hotels, and expensive outings. Kelce’s individual losses have not been publicly disclosed as this time, @Max_Gorden reports.
34
E-cart botters are some of the most cracked hackers in the business. If you're trying to break into cyber, skip bug bounties that are unfriendly to beginners and have been picked over with automation. Instead, try and build a bot to autobuy Supreme.
🧵 In 2021 I spent a few weeks trying to bypass Walmart's PerimeterX bot protection by poking at their edge infrastructure. What started as a Host header experiment in burp ended with me staring at a live internal metrics dump from a PCI-compliant Azure production server — completely unauthenticated And a very interesting PX bypass. ⚠️ Disclaimer: Some details are from memory so a few things may be slightly off — but the core findings are accurate.
47
The biggest Claude risk isn't superintelligent Terminators. It's using it in critical infrastructure engineering and having it say "You're exactly right! That calculation SHOULD have been in pound-seconds instead of Newton-seconds."
I am still confused by how AI would kill literally everyone on earth. What's the mechanism? A robot sets up a secret lab where it makes a deadly virus? What plausible scenario would result in every last human dying?
1
1
39
I view the cybersecurity risk as something similar to a better Metasploit - it makes exploitation way easier but least privileges / detection engineering wins every time. The pentest industry was already in the assumed breach mindset. This fundamentally changes nothing.
1
17
The most noteworthy cyber incidents so far had terrible detective controls. It was a smart escape but all parties were mostly blind. If you ran db_autopwn in a loop I suspect you would get a similar result and it would be your fault if it got loose.
7
day one of giving the fly unlimited white monster and cigs until its neurons are trained to win me bug bounties
39
297
4,360
97,675
This simple ragebait trick never fails to get threat actors to dox their wallets in a "band for band", take note and use it on Telegram
I know: I’ve been posting about this for 5 years. But no one in this thread—or with an anime avatar—is HNWI.
1
2
208
example:
Replying to @zachxbt
2/ Earlier today John got into a heated argument with another threat actor known as Dritan Kapplani Jr. in a group chat to see who had more funds in crypto wallets. In 'The Com' this is known as a band for band (b4b). However the entire interaction was fully recorded. nitter.net/zachxbt/status/1931216…
32