Prof. @KU_Leuven | Ex-Postdoc NYU | Network Security & Crypto | FragAttacks & KRACK | bsky.app/profile/vanhoefm.bs…

Orion Arm
I found some design and implementation flaws in Wi-Fi again. All Wi-Fi devices are affected. It was a long ~9 months embargo, over this time a lot of info has been collected and that info now available at fragattacks.com
32
1,110
2,623
Mathy Vanhoef retweeted
At this point it’s absurd and embarrassing. How many hundreds of billions in funding do you need to hire a security team that understands basic sandboxing and network isolation?
I really need more big names in cybersecurity to come forward and state the obvious: cybersecurity is real and works and yes we absolutely can contain an AI even if it’s extremely good at finding zero days.
4
10
66
4,273
Mathy Vanhoef retweeted
Not a big name but this is very clearly true and we have strong evidence for it. Mythos failed to crack Firecracker. It has largely exploited systems that are not particularly hard targets. Existing tech can handle this when deployed properly.
I really need more big names in cybersecurity to come forward and state the obvious: cybersecurity is real and works and yes we absolutely can contain an AI even if it’s extremely good at finding zero days.
9
26
183
8,657
Mathy Vanhoef retweeted
ICLR 2027 has received more submissions than all previous years (2013–2026) combined
38
174
1,174
275,466
Interview with SecureW2, where we look back on various Wi-Fi attacks and give network security advice to handle future attacks, especially in the age of AI securew2.com/signal/sneaking… tl;dr: ensure a layered defense
2
4
481
Mathy Vanhoef retweeted
So one thing I’ve heard from multiple researchers in my field is that models seem to get *much* better at solving their specific problems over short periods, even asked in new contexts. Many of them have mentioned that they wonder if they’re training on their inputs.
21
21
389
39,958
Mathy Vanhoef retweeted
drama summary for those confused: - Aug 15th: Tristan Buckmaster & Levent Alpöge make progress on a few important math problems - they do NOT have a proof for the $1,000,000 Millenium Prize problem. BUT, they do claim to have a proof for a similar (non-Millenium) Navier Stokes problem that could help lead the way there - Levent works at Anthropic, but this research was independent of his work there, with a mix of GPT and Claude models. Tristan is not related to Anthropic. - Early Sep: Rumor spreads to OpenAI that Anthropic has solved a major problem. Tristan emails OpenAI to clarify. without revealing the problem they solved or how they did it. - After hearing of the rumor, OpenAI started researching Navier Stokes with a new internal model. - Sep 6th: OpenAI's Sebastien Bubeck tells Tristan that they solved the $1,000,000 Millenium Prize Navier Stokes problem. The approach is very similar to Tristan & Levent's approach to the non-Millenium problem. - Tristan is suspicious of the timing, as only few others were trying this approach. OpenAI says the model didn't access his user data directly, but leaves unanswered whether Tristan's chat conversations were part of the training. - OpenAI says they would partially credit Tristan for the $1,000,000 discovery (even though Tristan did not solve the $1,000,000 problem) — but only if they remove Levent as an author, as he works for Anthropic. - Sep 8th: Tristan refuses to remove Levent, and rushes to publish their results independently. Currently unclear is whether Anthropic had a separate solution for the $1,000,000 problem, or whether the rumor was about Tristan & Levent's independent research.
Wow Navier-Stokes thing is getting really ugly. But from the sounds of things it looks like both labs have actually solved Navier-Stokes independently and drama aside is massive
99
1,104
9,998
1,606,593
Mathy Vanhoef retweeted
You're missing the core drama of the story: Tristan is softly accusing OpenAI of having stolen their result from Codex chat logs. Tristan then claims OpenAI tried to threaten him to not publicly disclose this, and that they'd give him the Clay Prize ($1M) as the "closest humans to the problem" if he'd agree to disavow his co-author, @__alpoge__ , who is at Anthropic. This is HBO-level drama, but with math proofs.
SITUATION DETECTED: Mathematicians Tristan Buckmaster and Levent Alpöge have made major progress toward solving the Navier-Stokes existence and smoothness problem, one of the most important problems in mathematics, and say OpenAI may have solved it fully.
239
3,679
25,764
1,603,321
Mathy Vanhoef retweeted
We’re sharing a solution to the Navier-Stokes Millennium Prize Problem, one of the deepest problems at the frontier of mathematics. The proof was produced by a group of agents, using an OpenAI next-generation model significantly more capable than GPT-6 Astra. The problem concerns whether the description of smooth three-dimensional fluid motion modeled by the Navier-Stokes equations can break down. It has remained unresolved for roughly 90 years.
5,718
20,148
120,526
74,922,523
Mathy Vanhoef retweeted
Security Testing of WireGuard Implementations, from @vanhoefm et al. papers.mathyvanhoef.com/esor… [PDF]
1
4
21
1,954
Mathy Vanhoef retweeted
For most of history, surgery was done without anasthesia. Fruit was a luxury: people used to rent pineapples to show them off at parties. The sewing machine meant people no longer owned only 2-3 articles of clothing. Hand stitching clothing used to take 14 hours. Ordinary abundance lives all around us. My favorite quotes from people’s first reaction to these hidden marvels. Highly recommend checking out ordinaryabundance.org to see mundaneness in a new light.
Ordinary Abundance. This is the greatest thing I've read in weeks. No kidding. This should win a Pulitzer in a category not yet invented. ordinaryabundance.com/
23
377
3,594
251,503
Mathy Vanhoef retweeted
The Nearest Neighbor Attack: A Unicorn or an Iceberg? Revisiting the single public sighting of one of the most sophisticated Wi-Fi based APT attacks and why AI will make it worse CC: @RGB_Lights @ImposeCost @stevenadair medium.com/@TalBeerySec/the-…
1
13
32
10,441
This refers to repeatedly connecting using different passwords & optimizing the speed of connection attempts What's most interesting is that models can now do this kind of engineering. A while ago, they even struggled to answer details about the different types of WiFi frames
Yesterday night I left Kimi K3 with a monitor WiFi interface and root access. This morning I woke up to a new way to bruteforce WEP, WPA2-PSK and WPA3-SAE even if the card does not send ACKs in monitor mode. And found that WPA3 is much faster to bruteforce than WPA2 :D

ALT This Is Fine On Fire GIF

1
2
23
2,747
Mathy Vanhoef retweeted
human in the loop the loop: “you’re doing amazing sweetie”
We asked an unreleased research version of Claude to take a stab at the Riemann hypothesis. It didn’t solve it, but it did make strides on a related problem: it increased the lower bound for the fraction of zeros of the Riemann zeta function that satisfy the hypothesis from 41.6% to 67.2%. anthropic.com/research/riema…
51
406
7,122
371,282
Mathy Vanhoef retweeted
Why do Europeans not have AC everywhere? Asked Claude Code to run the numbers. Simple reason: Before 1980 it was very rare to have days above 32 degrees. The cities, the buildings, the public transport, the infrastructure as a whole isn't set up for it. But now it's extremely common to have ones above 38 degrees. Combine that with heatwaves, flashfloods, and draughts. Combine that with farming, river-logistics, river-cooling for power, cities not being built for heat, etc etc. Europe will be hit brutally by Climate Change.
184
208
1,067
85,541
Mathy Vanhoef retweeted
The work from @vanhoefm and friends showed that malicious channel switch announcements is a pretty good deauth primitive for management frame protection networks, so I added it to @aircrackng. Link below.
4
3
16
4,380
Mathy Vanhoef retweeted
i will say i am a fan of hostap, it's been a white whale of mine to find a good security bug because it's reasonably good c code that has reasonably good testing. jouni is also a top tier person in all regards
1
11
993
Mathy Vanhoef retweeted
It's BlackHat/DEF CON week so I'd like to interrupt your regularly scheduled chest drumming feed! Let's talk about a critical WiFi 7 memory corruption bug. The flaw was in Hostapd, the userland daemon which powers the world's WiFi on the majority of access points. I reported this in June and it's now patched upstream. My proof of concept shows that authenticated clients can bypass ASLR to leak pointers OTA and inject code execution. 802.1X Enterprise WiFi 7 is basically exploitable pre-auth because of the "outer tunnel". This bug was missed by LLM scans as well as human auditors, but found in the wifi gauntlet. If you're at BH/DC this week and interested in the memory safe wifi stack we're building please reach out
11
56
219
31,004
Mathy Vanhoef retweeted
Nomination announcements are now up! Thanks again to @SummerC0n for hosting as is tradition! Check out the nominations here: piped.video/live/uhOqo4Oz6I0…
2
4
10
10,092
Mathy Vanhoef retweeted
We beseffen onvoldoende hoe fantastisch onze universiteiten het doen. Er zijn ongeveer 20.000 universiteiten ter wereld. Dus wij zijn bij de beste 1%. Met open toegang voor studenten, tussen universiteiten met strenge selectie. Met 40% minder personeel dan elders in Europa. Met budgetten die slechts een veertigste (Hasselt, VUB), tiende (UGent) of vierde (KULeuven) zijn van pakweg Harvard (bijna 7 miljard). Kippen met gouden eieren verdienen maïs, niet de hongerdood nieuwsblad.be/binnenland/ku-…
19
28
170
13,297