recognition is a lagging indicator.
constant efforts go unrecognized until the body of evidence becomes so overwhelming you can no longer ignore it.
that's what "overnight success" looks like from the inside.
Got hacked yesterday. The link came from inside Claude chat.
I was installing a transcription app. Claude sent the download link, and I pasted the command into the terminal. It all looked legit.
It wasn't though.
It was a copycat site bundling malware. It ran instantly, tried
at this point, cc is like a useful spyware. monitoring VPN and geoip, becoming a vector for stolen credentials. should probably keep it away from secrets
🚨ALERT: If you use Claude, you could LOSE your crypto to malware without ever knowing you were hacked.
The campaigns targeting Claude users spread infostealers that silently grab passwords and browser data, putting exchange logins and hot wallets directly at risk.
One user got
there have been some posts around agents "escaping" the sandbox, OAI hacking HF, using github, directories for agents to pass memories to other agents.
the reality is more boring. orgs shipped with bad configs, sloppy code, not prioritizing security.
1. OAI not monitoring agent
Incredible research worth reading which further solidifies if the sand doesn’t stay in the box it’s not a sandbox. In this case, an LLM escaped a VM 3 times.
A VM is not a sandbox. A sandbox is a sandbox. A VM can also have a sandbox, but it needs to keep the sand in the box.
AI is finding new issues humans never could before.
Keep your hardware wallets firmware up to date. Trezor, Ledger, etc. If you haven’t updated it recently you need to.
🚨Critical security update for LEDGER hardware wallets
A critical vulnerability has been identified in the Ethereum app on Ledger hardware wallets. It could allow a malicious application to alter the details of a transaction during signing, without this being visible on the