frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

I Was Trapped in Chinese Mafia Crypto Slavery [video]

https://www.youtube.com/watch?v=zOcNaWmmn0A
1•mgh2•42s ago•0 comments

U.S. CBP Reported Employee Arrests (FY2020 – FYTD)

https://www.cbp.gov/newsroom/stats/reported-employee-arrests
1•ludicrousdispla•2m ago•0 comments

Show HN: I built a free UCP checker – see if AI agents can find your store

https://ucphub.ai/ucp-store-check/
1•vladeta•7m ago•1 comments

Show HN: SVGV – A Real-Time Vector Video Format for Budget Hardware

https://github.com/thealidev/VectorVision-SVGV
1•thealidev•9m ago•0 comments

Study of 150 developers shows AI generated code no harder to maintain long term

https://www.youtube.com/watch?v=b9EbCb5A408
1•lifeisstillgood•9m ago•0 comments

Spotify now requires premium accounts for developer mode API access

https://www.neowin.net/news/spotify-now-requires-premium-accounts-for-developer-mode-api-access/
1•bundie•12m ago•0 comments

When Albert Einstein Moved to Princeton

https://twitter.com/Math_files/status/2020017485815456224
1•keepamovin•13m ago•0 comments

Agents.md as a Dark Signal

https://joshmock.com/post/2026-agents-md-as-a-dark-signal/
1•birdculture•15m ago•0 comments

System time, clocks, and their syncing in macOS

https://eclecticlight.co/2025/05/21/system-time-clocks-and-their-syncing-in-macos/
1•fanf2•17m ago•0 comments

McCLIM and 7GUIs – Part 1: The Counter

https://turtleware.eu/posts/McCLIM-and-7GUIs---Part-1-The-Counter.html
1•ramenbytes•19m ago•0 comments

So whats the next word, then? Almost-no-math intro to transformer models

https://matthias-kainer.de/blog/posts/so-whats-the-next-word-then-/
1•oesimania•20m ago•0 comments

Ed Zitron: The Hater's Guide to Microsoft

https://bsky.app/profile/edzitron.com/post/3me7ibeym2c2n
2•vintagedave•23m ago•1 comments

UK infants ill after drinking contaminated baby formula of Nestle and Danone

https://www.bbc.com/news/articles/c931rxnwn3lo
1•__natty__•24m ago•0 comments

Show HN: Android-based audio player for seniors – Homer Audio Player

https://homeraudioplayer.app
2•cinusek•24m ago•0 comments

Starter Template for Ory Kratos

https://github.com/Samuelk0nrad/docker-ory
1•samuel_0xK•26m ago•0 comments

LLMs are powerful, but enterprises are deterministic by nature

2•prateekdalal•29m ago•0 comments

Make your iPad 3 a touchscreen for your computer

https://github.com/lemonjesus/ipad-touch-screen
2•0y•35m ago•1 comments

Internationalization and Localization in the Age of Agents

https://myblog.ru/internationalization-and-localization-in-the-age-of-agents
1•xenator•35m ago•0 comments

Building a Custom Clawdbot Workflow to Automate Website Creation

https://seedance2api.org/
1•pekingzcc•38m ago•1 comments

Why the "Taiwan Dome" won't survive a Chinese attack

https://www.lowyinstitute.org/the-interpreter/why-taiwan-dome-won-t-survive-chinese-attack
2•ryan_j_naughton•38m ago•0 comments

Xkcd: Game AIs

https://xkcd.com/1002/
1•ravenical•39m ago•0 comments

Windows 11 is finally killing off legacy printer drivers in 2026

https://www.windowscentral.com/microsoft/windows-11/windows-11-finally-pulls-the-plug-on-legacy-p...
1•ValdikSS•40m ago•0 comments

From Offloading to Engagement (Study on Generative AI)

https://www.mdpi.com/2306-5729/10/11/172
1•boshomi•42m ago•1 comments

AI for People

https://justsitandgrin.im/posts/ai-for-people/
1•dive•43m ago•0 comments

Rome is studded with cannon balls (2022)

https://essenceofrome.com/rome-is-studded-with-cannon-balls
1•thomassmith65•48m ago•0 comments

8-piece tablebase development on Lichess (op1 partial)

https://lichess.org/@/Lichess/blog/op1-partial-8-piece-tablebase-available/1ptPBDpC
2•somethingp•50m ago•0 comments

US to bankroll far-right think tanks in Europe against digital laws

https://www.brusselstimes.com/1957195/us-to-fund-far-right-forces-in-europe-tbtb
4•saubeidl•51m ago•0 comments

Ask HN: Have AI companies replaced their own SaaS usage with agents?

1•tuxpenguine•53m ago•0 comments

pi-nes

https://twitter.com/thomasmustier/status/2018362041506132205
1•tosh•56m ago•0 comments

Show HN: Crew – Multi-agent orchestration tool for AI-assisted development

https://github.com/garnetliu/crew
1•gl2334•56m ago•0 comments
Open in hackernews

The Evolution of Technical Scams: Why Developer Knowledge Isn't Enough

2•idrj•5mo ago
The Evolution of Technical Scams: Why Developer Knowledge Isn't Enough As developers, we assume our technical knowledge protects us from scams. We can read smart contract code, verify certificates, spot phishing. But modern scammers exploit the very complexity built into systems we create and use daily. The Smart Contract Trojan Horse Consider fake airdrop tokens appearing in your wallet: Scammer deploys token with malicious approval function Tokens sent to thousands of wallets (free advertising) Users attempt to claim/swap, unknowingly approve unlimited spending Contract drains wallet of valuable tokens This exploits our mental model of wallets. We see tokens, assume they're benign assets we can interact with safely. The approval mechanism—designed for legitimate DeFi—becomes the attack surface. Most wallet UIs don't make contract approvals visible or manageable. How many of us audit approved contracts regularly? Authentication That Isn't Scammers create pixel-perfect DeFi platform clones with working functionality—except withdrawals. Technical sophistication is remarkable: Valid SSL certificates Responsive design matching originals Working deposits (building confidence) UI elements querying real blockchain data Only difference? Withdrawal functions route to scammer addresses. These aren't "fake" sites—they're fully functional applications with malicious business logic. Social Engineering Meets Technical Attack The concerning trend: layering social engineering on technical attacks. Attack chain: Research target via LinkedIn, GitHub, Twitter Build relationship over weeks/months Share valuable information/opportunities Send legitimate-looking contract interaction Use established trust to bypass technical skepticism Technical component might be simple—just wallet-draining contract—but wrapped in social proof that makes developers ignore red flags. Why Technical Knowledge Creates Blind Spots Our expertise works against us: Over-confidence: "I understand this, so it's safe" Analysis paralysis: Focus on complex vectors, miss simple ones False assumptions: Assume others are as careful as we are I've seen developers who'd never click suspicious emails happily approve contracts because they "verified the address" (using attacker-provided information). The Gift Card Evolution Gift cards now target B2B contexts: Fake CEO emails requesting emergency purchases Compromised Slack accounts requesting cards for events "Vendor" payment requests via cards due to "banking issues" Low technical sophistication, high process exploitation. They target business logic flaws in human organizations. Lessons for System Design Default Deny: Make dangerous operations (unlimited approvals) require explicit consent Revocation UX: Why is granting permissions easier than revoking them? Trust Indicators: Help users distinguish legitimate vs malicious interactions Social Context: Detect relationship-based manipulation The Meta-Problem Every protocol, DeFi innovation, convenience feature creates exploitation opportunities. We build complex systems assuming users navigate them safely. But complexity is security's enemy. Our Responsibility Audit your assumptions: What security practices do you skip? Design for exploitation: Assume bad actors will misuse every feature Educate your network: Your connections make others targets Stay humble: "That would never work on me" is dangerous Scammers are professionalizing. They study our systems, assumptions, behaviors. They're patient, funded, sophisticated. The question isn't whether we're smart enough to avoid traps—it's whether we build systems that make traps ineffective.

Comments

gus_massa•5mo ago
Remember to use double enter to jump to a new paragraph.

Like this.