frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Tell HN: Financial Service Hacked via Private GitHub Repo

2•throwaway_900•3h ago
A colleague of mine manages a crypto financial service in a 3rd-world country, and his service was just hacked and $300,000 was stolen. (yes, three-hundred thousand dollars).

It happened - as he tells me - via a private GitHub repository where he puts the source code of his app. He made a dumb mistake of using his private key for the wallet inside the code more than one week ago, and thus, the private key was uploaded to the repository.

He noticed it at first, but he didn't react immediately because he thought that the repository is private, so no instant harm would happen since no one else has access to the repository but him.

A few days later, his central crypto wallet for the platform was hacked, and the $300k was stolen. The hacker moved the money from the wallet to 3 separate wallets on Binance. Big amount of TRX is staked in the wallet, the attacker changed the owner permission and locked him out the wallet, then he unstaked the TRX where it will be unfreezed after 14 days,

My friend contacted Binance and asked them to freeze the hacker's wallets, but they refused saying that they only accept official legal requests from the country. Since this is a 3rd-world country with no such communication channel established, nothing is done to stop the hacker so far. The country does not have a cybercrime department, and officials said they can't do anything at all.

My friend says the hack happened either:

- via Claude Code, since he was using the service to edit his files. - via an internal GitHub staff who might have access to the private repo.

He assures me no 3rd-party apps and no cracked accounts were responsible for what happened.

Publishing for tips and advice and what can we do, and using a throwaway account for obvious reasons.

The War on Roommates: Why Is Sharing a House Illegal?

https://marginalrevolution.com/marginalrevolution/2025/08/the-war-on-roommates-why-is-sharing-a-h...
1•surprisetalk•46s ago•0 comments

Cheat.sh: the only cheat sheet you need

https://cheat.sh/
1•surprisetalk•57s ago•0 comments

NASA panel fears a Starship lunar touchdown is more fantasy than flight plan

https://www.theregister.com/2025/09/22/nasa_starship_artemis_doubts/
1•voxadam•1m ago•0 comments

Invitees fail to realize that they should not respond with a "maybe"

https://www.sciencedirect.com/science/article/abs/pii/S0022103125000952
1•surprisetalk•1m ago•0 comments

The Anthropic Economic Index

https://www.anthropic.com/economic-index
1•surprisetalk•2m ago•0 comments

Tiny new lenses, smaller than a hair, could transform phone and drone cameras

https://www.sciencedaily.com/releases/2025/09/250921090853.htm
2•speckx•2m ago•0 comments

US authorities seize illicit electronics in New York during UN General Assembly

https://www.reuters.com/world/us/us-authorities-seize-illicit-electronics-new-york-area-during-un...
1•everybodyknows•2m ago•0 comments

UX Patterns for Artificial Intelligence

https://www.shapeof.ai
1•tontonius•3m ago•0 comments

Mnemeo – Flashcard app with typing and rating modes

https://www.mnemeo.com/
1•rytisg•3m ago•1 comments

Identify Your Core Values to Make Better Leadership Decisions

https://hbr.org/2025/09/identify-your-core-values-to-make-better-leadership-decisions
3•ZJChen•6m ago•0 comments

Floorp: The Vivaldi of Firefox

https://floorp.app/
1•AbuAssar•6m ago•0 comments

Abundant Intelligence

https://blog.samaltman.com/abundant-intelligence
1•j4mie•6m ago•0 comments

Pre-training under infinite compute

https://arxiv.org/abs/2509.14786
2•jonbaer•8m ago•0 comments

MrBeast Failed to Disclose Ads and Improperly Collected Children's Data

https://bbbprograms.org/media/newsroom/decisions/mrbeast-feastables
4•Improvement•8m ago•0 comments

To Avoid Murmuring to Horses: On Designing a Profoundly Human-Like AI

1•dearcloud09•11m ago•0 comments

If you make your app 10% easier to use you'll get twice as many users

https://twitter.com/paulg/status/1970422069151355163
5•turrini•11m ago•6 comments

Linden Lab is stealing from merchants

https://secondlife.com/?openid_identifier=https%3A%2F%2Fid.secondlife.com%2Fid%2Fanonymous
1•orangeboxman•12m ago•0 comments

Show HN: I created a small template language

https://github.com/hmpl-language/hmpl
2•aanthonymax•12m ago•0 comments

Using DNS for responding to ACME challenges

https://hsm.tunnel53.net/article/dns-for-acme-challenges/
1•cpach•12m ago•0 comments

Show HN: I built an interactive AI video as a tribute to my childhood dog

https://www.goodboynoodle.com/
1•clarkcharlie03•13m ago•0 comments

'We're building a factory here': Panel talks 3D-printed manufacturing for Guam

https://www.guampdn.com/news/were-building-a-factory-here-panel-talks-3d-printed-manufacturing-fo...
1•sipofwater•13m ago•1 comments

Air National Guard F-15C Eagle makes emergency landing with tail hook at PDX

https://www.kgw.com/article/news/local/oregon-air-national-guard-jet-emergency-landing-portland-a...
2•voxadam•14m ago•0 comments

Secret Service dismantles telecom threat around UN

https://www.cnbc.com/2025/09/23/secret-service-dismantles-telecom-threat-around-un-capable-of-cri...
5•tagyro•16m ago•1 comments

Handling resource variants in your REST API

https://www.stainless.com/blog/how-to-gracefully-handle-resource-variants-in-your-rest-api
1•minks96•16m ago•0 comments

Medicinal Chemistry Dares to Look at Medusa

https://medium.com/@chicamisteriosasinnombre/medicinal-chemistry-dares-to-look-at-medusa-64f90bcd...
1•fractalexplosiv•16m ago•1 comments

Deploying and Running Google ADK Agent on Amazon Bedrock AgentCore

https://medium.com/@hellosudip/from-pets-to-cattle-managing-ai-agents-at-scale-with-amazon-bedroc...
1•bluechips•17m ago•0 comments

I Fell for a $1.25M Scam – Now MrBeast Is Helping Me Hunt Down the Scammers

https://www.entrepreneur.com/money-finance/i-fell-for-a-125-million-scam-now-mrbeast-is-helping/4...
3•jelenapavovski•18m ago•0 comments

Reality Check – AI/real photo quiz

https://realitycheckk.com/week1
2•puttycat•19m ago•0 comments

Saudi pact puts Pakistan's nuclear umbrella into Middle East security picture

https://www.reuters.com/business/aerospace-defense/saudi-pact-puts-pakistans-nuclear-umbrella-int...
2•JumpCrisscross•20m ago•0 comments

AEO/Geo for Developer Tools: Win in AI-Powered Search

https://draft.dev/learn/aeo-geo-for-dev-tools
1•mooreds•20m ago•0 comments