frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Ask HN: Remember Fidonet?

72•ukkare•3h ago•50 comments

Ask HN: What Happened to xAI?

4•zof3•42m ago•3 comments

Ask HN: What Are You Working On? (March 2026)

277•david927•1d ago•1041 comments

The Architecture of an Exit Scam: A Technical Audit of Zszrun

3•cappyfjao•2h ago•0 comments

Ask HN: Let's rethink the architecture and future of Emacs

2•kurouna•27m ago•1 comments

Ask HN: Since a week HN keeps logging me off every few days, why?

5•epolanski•3h ago•0 comments

Ask HN: What AI content automation stack are you using in 2026?

2•jackcofounder•4h ago•2 comments

Ask HN: How to be alone?

661•sillysaurusx•2d ago•545 comments

Ask HN: Do you still run Redis and workers just for background jobs?

2•sergF•5h ago•6 comments

Ask HN: Can I repurpose a Bluetooth voice remote as input device for a PC?

15•albert_e•2d ago•20 comments

Ask HN: Please restrict new accounts from posting

699•Oras•1d ago•493 comments

Ask HN: Most beautiful personal blog UI you have ever seen?

132•ms7892•1d ago•53 comments

Why is GPT-5.4 obsessed with Goblins?

9•pants2•9h ago•5 comments

Why is email so resilient as a technology?

5•noemit•3h ago•4 comments

Tell HN: I'm 60 years old. Claude Code has re-ignited a passion

1063•shannoncc•3d ago•968 comments

Ask HN: Is GitHub getting less reliable, or is it just me?

7•_pdp_•16h ago•5 comments

Ask HN: Favorite Non-Spammy iPhone Games?

3•bix6•12h ago•3 comments

Ask HN: What game engine would you recommend for vibe coding?

5•general_reveal•12h ago•4 comments

Ask HN: Read‑only LLM tool for email triage and knowledge extraction?

2•maille•14h ago•3 comments

Ask HN: Any informed guesses on the actual size/architecture of GPT-5.4 etc.?

4•dsrtslnd23•14h ago•0 comments

Code-review-graph: persistent code graph that cuts Claude Code token usage

2•tirthkanani•19h ago•0 comments

Ask HN: Who Needs Help?

14•surprisetalk•22h ago•9 comments

A job ad for Agentic AI Advocate

4•greenpinia•23h ago•1 comments

Ask HN: Are showlang and thelang HN endpoints not being maintained?

4•freakynit•1d ago•1 comments

Ask HN: Which book are you reading these days?

6•chistev•17h ago•18 comments

OpenAI might end up on the right side of history

12•shoman3003•1d ago•10 comments

Ask HN: Anyone else feel this community has changed recently?

56•kypro•3d ago•29 comments

Ask HN: How are you handling persistent memory across local Ollama sessions

5•null-phnix•2d ago•0 comments

All tmux sessions as a single terminal

2•lygten•1d ago•1 comments

I replaced my freelance SaaS stack with 5 single-file HTML tools

5•AnnSri•1d ago•2 comments
Open in hackernews

The Architecture of an Exit Scam: A Technical Audit of Zszrun

3•cappyfjao•2h ago
I’m posting this here because the HN crowd understands the difference between a functional fintech backend and a high-fidelity simulation. Over the last few weeks, I’ve been tracking a surge in traffic toward a platform called ZSZRUN, and after performing a "sysadmin gut check" on their operational logic, I’m issuing a terminal warning.

For those who don't know me, I spent 20 years in enterprise IT systems administration—the kind of work where you learn to spot a single point of failure from a mile away—before moving into independent trading. I’ve survived the dot-com bubble, the 2008 collapse, and every "crypto disruptor" that turned out to be a hollow shell. My assessment of ZSZRUN is that it is a wrapper-based fraudulent operation designed to absorb capital under the guise of an AI-driven trading protocol.

Here is the technical breakdown of the ZSZRUN architecture.

1. The "Halo Effect" of the Web3 Frontend ZSZRUN utilizes a highly polished presentation layer. The UI/UX is built on modern frameworks (likely React or Vue) with seamless Web3 wallet integration. To the average retail user, the platform feels responsive and high-tech.

However, in my audit, I found that this frontend is a "halo facade." While the UI displays real-time price feeds and "profitable" trading activity, there is no verifiable evidence that these orders are hitting a live liquidity pool. If you can’t cross-reference a platform's trading volume with major global settlement layers or find their entity in the API endpoints of regulators like the NFA or FCA, you aren't looking at an exchange—you are looking at a closed-loop simulation.

2. The Database Logic Failure: The "Withdrawal Ransom" A functional backend simply updates the internal ledger and broadcasts the net amount to the blockchain or bank. ZSZRUN, however, employs a "ransom-based" logic. When a user attempts to withdraw significant capital, the backend triggers a manual "security freeze." The user is then instructed to deposit an additional 30% of their total balance as a "personal income tax" or "verification fee" via an external crypto wallet before the original funds can be released.

Why this is a technical smoking gun: From a systems integrity standpoint, requiring inbound liquidity to unlock an existing internal database entry is an absurdity. If the funds existed in the platform's liquidity pool, the tax would be deducted from the balance. The requirement for a new deposit proves that the numbers on the screen are disconnected from real assets. This is the terminal phase of a "pig-butchering" scam.

3. Social Engineering as an Operational Layer ZSZRUN does not operate in a vacuum; it relies on a sophisticated social engineering layer. Victims are funneled into the platform through "Investment Groups" on WhatsApp and Telegram, led by personas like "Professor" or "Investment Director."

These groups use coordinated shills and automated scripts to create a manufactured environment of success. They use psychological "proof" (fake screenshots and bot-driven praise) to override a user’s technical skepticism. By the time the user realizes the withdrawal logic is a trap, they have already been socially engineered into depositing multiple times.

Conclusion: Avoid ZSZRUN at All Costs My verdict as a veteran of both IT infrastructure and the markets is that ZSZRUN is a terminal threat to your capital. It is a simulation designed for one-way liquidity flow.

I’ve seen this script play out with platforms like SRQCGX and BTDUex. The names change, but the architecture of the fraud remains the same. If you have funds in this platform, do not send the "tax deposit"—that money will only follow your principal into the void. Stay sharp, stay cynical, and protect your principal.