frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Almost perfect Y Combinator Phishing Mail

5•fxtentacle•4mo ago
Dear HN, I've just received what I would consider to be an almost perfectly crafted phishing mail. It says:

  Dear community,
  
  The Y Combinator W2026 Program is now open for applications. This world-renowned accelerator supports ambitious builders and early-stage teams, helping them transform projects into scalable companies.
  
  As a GitHub contributor, your open-source activity positions you to benefit from this opportunity. Whether you are shipping code, maintaining repositories, or prototyping new ideas, your work drives innovation and could qualify for YC’s support.
  Program Benefits
  
      Funding: $15,000,000 USD investment on standard YC terms
      Growth Allocation: Helping founders accelerate traction and align community growth with long-term success.
      Mentorship: Access to experienced founders and YC partners
      Community: A global network of alumni, investors, and experts
  
  Important:
  A refundable deposit is required for authorization. The full amount will be returned once verification is complete.
  Apply here: ycombinator.com/apply
  
  Applications are reviewed on a rolling basis. To maximize your chances, apply early via the official YC platform. Connect your GitHub profile and share your project details to get started.
  
  Best regards,
  Y-Combinator Team
  In collaboration with GitHub
  
  You are receiving this message as a registered GitHub member.
  ©2025 GitHub, Inc. All rights reserved.
  Address: 88 Colin P Kelly Jr St, San Francisco, CA 94107, USA.
and the email was sent

  From: "mail-automatic[bot]" <notifications@github.com>
with valid DKIM and SPF:

  DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com;
   s=pf2023; t=1758673517;
   bh=US4CJqqkBhma8Fvuq02w6IzAQPikeND5kn798+L2Xbc=;
   h=Date:From:Reply-To:To:Cc:Subject:List-ID:List-Archive:List-Post:
    List-Unsubscribe:List-Unsubscribe-Post:From;
   b=b6VQSnYetXklM0vroPZGy7uIAKxMtyJrP0f7iEFnxm+765issKWTt4iO4rEwGALot
    o8e1qRiKsz/PbbtwdbUHCXEZd/iQ1ALR1Tdq0nLQSkMzxkfPb+tPZStIyE+VMArF1P
    3zTfZjDwhHQRUURvcrP6r4MVXcW1DMoAh+mOKJrQ=
  Received-SPF: Pass (protection.outlook.com: domain of github.com designates
   192.30.252.207 as permitted sender) receiver=protection.outlook.com;
   client-ip=192.30.252.207; helo=out-24.smtp.github.com; pr=C
so the angle of Y-Combinator collaborating with GitHub appears legit. But - of course - that ycombinator.com/apply link actually uses unicode trickery to send you to a website where the "i" has been replaced with an "l". And there, it says:

  We use EIP-712 and Ethereum Attestation Service (EAS) to verify your wallet. During the process, you may see a standard withdrawal notification — this confirms your signature to record verification stamps on-chain.
  
  We guarantee that your assets remain completely secure.
which I guess is the phishing part where they steal your crypto.

Comments

jasonrm•4mo ago
It had valid DKIM and SPF because it was using GitHub issues to mass mention people.

screenshot of an issue from before the account was terminated https://s3.amazonaws.com/jasonrm/2025/ycombinatoor-spam-issu...

southwindcg•4mo ago
This has been reported a dozen times or so already.

https://news.ycombinator.com/item?id=45352610

Show HN: Verifiable server roundtrip demo for a decision interruption system

https://github.com/veeduzyl-hue/decision-assistant-roundtrip-demo
1•veeduzyl•1m ago•0 comments

Impl Rust – Avro IDL Tool in Rust via Antlr

https://www.youtube.com/watch?v=vmKvw73V394
1•todsacerdoti•1m ago•0 comments

Stories from 25 Years of Software Development

https://susam.net/twenty-five-years-of-computing.html
1•vinhnx•2m ago•0 comments

minikeyvalue

https://github.com/commaai/minikeyvalue/tree/prod
2•tosh•6m ago•0 comments

Neomacs: GPU-accelerated Emacs with inline video, WebKit, and terminal via wgpu

https://github.com/eval-exec/neomacs
1•evalexec•11m ago•0 comments

Show HN: Moli P2P – An ephemeral, serverless image gallery (Rust and WebRTC)

https://moli-green.is/
2•ShinyaKoyano•15m ago•1 comments

How I grow my X presence?

https://www.reddit.com/r/GrowthHacking/s/UEc8pAl61b
2•m00dy•17m ago•0 comments

What's the cost of the most expensive Super Bowl ad slot?

https://ballparkguess.com/?id=5b98b1d3-5887-47b9-8a92-43be2ced674b
1•bkls•17m ago•0 comments

What if you just did a startup instead?

https://alexaraki.substack.com/p/what-if-you-just-did-a-startup
3•okaywriting•24m ago•0 comments

Hacking up your own shell completion (2020)

https://www.feltrac.co/environment/2020/01/18/build-your-own-shell-completion.html
2•todsacerdoti•27m ago•0 comments

Show HN: Gorse 0.5 – Open-source recommender system with visual workflow editor

https://github.com/gorse-io/gorse
1•zhenghaoz•27m ago•0 comments

GLM-OCR: Accurate × Fast × Comprehensive

https://github.com/zai-org/GLM-OCR
1•ms7892•28m ago•0 comments

Local Agent Bench: Test 11 small LLMs on tool-calling judgment, on CPU, no GPU

https://github.com/MikeVeerman/tool-calling-benchmark
1•MikeVeerman•29m ago•0 comments

Show HN: AboutMyProject – A public log for developer proof-of-work

https://aboutmyproject.com/
1•Raiplus•29m ago•0 comments

Expertise, AI and Work of Future [video]

https://www.youtube.com/watch?v=wsxWl9iT1XU
1•indiantinker•30m ago•0 comments

So Long to Cheap Books You Could Fit in Your Pocket

https://www.nytimes.com/2026/02/06/books/mass-market-paperback-books.html
3•pseudolus•30m ago•1 comments

PID Controller

https://en.wikipedia.org/wiki/Proportional%E2%80%93integral%E2%80%93derivative_controller
1•tosh•35m ago•0 comments

SpaceX Rocket Generates 100GW of Power, or 20% of US Electricity

https://twitter.com/AlecStapp/status/2019932764515234159
2•bkls•35m ago•0 comments

Kubernetes MCP Server

https://github.com/yindia/rootcause
1•yindia•36m ago•0 comments

I Built a Movie Recommendation Agent to Solve Movie Nights with My Wife

https://rokn.io/posts/building-movie-recommendation-agent
4•roknovosel•36m ago•0 comments

What were the first animals? The fierce sponge–jelly battle that just won't end

https://www.nature.com/articles/d41586-026-00238-z
2•beardyw•44m ago•0 comments

Sidestepping Evaluation Awareness and Anticipating Misalignment

https://alignment.openai.com/prod-evals/
1•taubek•44m ago•0 comments

OldMapsOnline

https://www.oldmapsonline.org/en
2•surprisetalk•47m ago•0 comments

What It's Like to Be a Worm

https://www.asimov.press/p/sentience
2•surprisetalk•47m ago•0 comments

Don't go to physics grad school and other cautionary tales

https://scottlocklin.wordpress.com/2025/12/19/dont-go-to-physics-grad-school-and-other-cautionary...
2•surprisetalk•47m ago•0 comments

Lawyer sets new standard for abuse of AI; judge tosses case

https://arstechnica.com/tech-policy/2026/02/randomly-quoting-ray-bradbury-did-not-save-lawyer-fro...
5•pseudolus•47m ago•0 comments

AI anxiety batters software execs, costing them combined $62B: report

https://nypost.com/2026/02/04/business/ai-anxiety-batters-software-execs-costing-them-62b-report/
1•1vuio0pswjnm7•48m ago•0 comments

Bogus Pipeline

https://en.wikipedia.org/wiki/Bogus_pipeline
1•doener•49m ago•0 comments

Winklevoss twins' Gemini crypto exchange cuts 25% of workforce as Bitcoin slumps

https://nypost.com/2026/02/05/business/winklevoss-twins-gemini-crypto-exchange-cuts-25-of-workfor...
2•1vuio0pswjnm7•49m ago•0 comments

How AI Is Reshaping Human Reasoning and the Rise of Cognitive Surrender

https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6097646
3•obscurette•49m ago•0 comments