frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Almost perfect Y Combinator Phishing Mail

3•fxtentacle•2h ago
Dear HN, I've just received what I would consider to be an almost perfectly crafted phishing mail. It says:

  Dear community,
  
  The Y Combinator W2026 Program is now open for applications. This world-renowned accelerator supports ambitious builders and early-stage teams, helping them transform projects into scalable companies.
  
  As a GitHub contributor, your open-source activity positions you to benefit from this opportunity. Whether you are shipping code, maintaining repositories, or prototyping new ideas, your work drives innovation and could qualify for YC’s support.
  Program Benefits
  
      Funding: $15,000,000 USD investment on standard YC terms
      Growth Allocation: Helping founders accelerate traction and align community growth with long-term success.
      Mentorship: Access to experienced founders and YC partners
      Community: A global network of alumni, investors, and experts
  
  Important:
  A refundable deposit is required for authorization. The full amount will be returned once verification is complete.
  Apply here: ycombinator.com/apply
  
  Applications are reviewed on a rolling basis. To maximize your chances, apply early via the official YC platform. Connect your GitHub profile and share your project details to get started.
  
  Best regards,
  Y-Combinator Team
  In collaboration with GitHub
  
  You are receiving this message as a registered GitHub member.
  ©2025 GitHub, Inc. All rights reserved.
  Address: 88 Colin P Kelly Jr St, San Francisco, CA 94107, USA.
and the email was sent

  From: "mail-automatic[bot]" <notifications@github.com>
with valid DKIM and SPF:

  DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com;
   s=pf2023; t=1758673517;
   bh=US4CJqqkBhma8Fvuq02w6IzAQPikeND5kn798+L2Xbc=;
   h=Date:From:Reply-To:To:Cc:Subject:List-ID:List-Archive:List-Post:
    List-Unsubscribe:List-Unsubscribe-Post:From;
   b=b6VQSnYetXklM0vroPZGy7uIAKxMtyJrP0f7iEFnxm+765issKWTt4iO4rEwGALot
    o8e1qRiKsz/PbbtwdbUHCXEZd/iQ1ALR1Tdq0nLQSkMzxkfPb+tPZStIyE+VMArF1P
    3zTfZjDwhHQRUURvcrP6r4MVXcW1DMoAh+mOKJrQ=
  Received-SPF: Pass (protection.outlook.com: domain of github.com designates
   192.30.252.207 as permitted sender) receiver=protection.outlook.com;
   client-ip=192.30.252.207; helo=out-24.smtp.github.com; pr=C
so the angle of Y-Combinator collaborating with GitHub appears legit. But - of course - that ycombinator.com/apply link actually uses unicode trickery to send you to a website where the "i" has been replaced with an "l". And there, it says:

  We use EIP-712 and Ethereum Attestation Service (EAS) to verify your wallet. During the process, you may see a standard withdrawal notification — this confirms your signature to record verification stamps on-chain.
  
  We guarantee that your assets remain completely secure.
which I guess is the phishing part where they steal your crypto.

Comments

jasonrm•49m ago
It had valid DKIM and SPF because it was using GitHub issues to mass mention people.

screenshot of an issue from before the account was terminated https://s3.amazonaws.com/jasonrm/2025/ycombinatoor-spam-issu...

southwindcg•14m ago
This has been reported a dozen times or so already.

https://news.ycombinator.com/item?id=45352610

Defer: Resource cleanup in C with GCCs magic

https://oshub.org/projects/retros-32/posts/defer-resource-cleanup-in-c-with-gccs-magic
1•signa11•1m ago•0 comments

The Startup Manifesto: 42 Principles for founders

https://www.thestartupmanifesto.com/
1•prototypo•3m ago•0 comments

AI Prompt Optimizer – Boost Your Prompts with PromptBoost

https://prompt-boost.com
2•icstiss•3m ago•0 comments

AI and the Rise of Techno-Fascism in the United States (Garry Kasparov)

https://www.theatlantic.com/podcasts/archive/2025/09/ai-and-the-fight-between-democracy-and-autoc...
1•saubeidl•7m ago•0 comments

AntOps – Lightweight Infra Map and Incident/Change/RCA Governance Layer

https://www.antopshq.com
1•samernaffah•7m ago•1 comments

Deploy your own AI vibe coding platform – in one click

https://blog.cloudflare.com/deploy-your-own-ai-vibe-coding-platform/
1•tosh•13m ago•0 comments

How to Prepare for a Technical Interview

https://www.rubynewbie.org/how-to-prepare-for-a-technical-interview
1•lylo•13m ago•0 comments

9 Things Every Fresh Graduate Should Know About Software Performance

https://johnnysswlab.com/9-things-every-fresh-graduate-should-know-about-software-performance/
1•signa11•13m ago•0 comments

Threats of violence against company executives on the rise, survey shows

https://www.reuters.com/business/threats-violence-against-company-executives-rise-survey-shows-20...
1•akyuu•16m ago•0 comments

PixAndFlow

https://pixandflow.com
1•candip99•18m ago•0 comments

Ask HN: What Is Your Hobby?

1•kerrsclyde•21m ago•0 comments

Free tailoring or Create new resume and cover letter

https://www.wahresume.com/
1•johnumarattil•21m ago•0 comments

Startup jobs require US visa – alternatives?

https://www.deel.com/
1•dominikhudzik•23m ago•1 comments

Show HN: Read-only AI coding assistant

https://github.com/msvana/filechat
1•msvana•24m ago•0 comments

Show HN: “You’re absolutely right” on a tee

https://ritzest.com/products/youre-absolutely-right-ai-inside-joke-unisex-tee-dev-data-nerd-gift
1•x7k•25m ago•0 comments

Improving state machine code generation in the Rust compiler

https://trifectatech.org/blog/improving-state-machine-code-generation/
3•fanf2•30m ago•0 comments

Dark Screenshots of the Soul

https://www.wysr.xyz/p/dark-screenshots-of-the-soul
1•martialg•33m ago•0 comments

OpenAI teams up with Oracle and SoftBank to build 5 new Stargate data centers

https://www.wired.com/story/openai-oracle-softbank-data-center-stargate-us/
2•thoughtpeddler•38m ago•0 comments

Traefik's 10-Year Journey from Zero to Standard

https://traefik.io/blog/celebrating-10-years-of-traefik
1•beckford•42m ago•0 comments

Ericsson to power VodafoneThree's core network

https://www.telcotitans.com/vodafonewatch/ericsson-nokia-win-big-as-vodafonethree-opens-wallet-fo...
1•NKosmatos•45m ago•1 comments

The Science Behind Scratchgate and What It Means for Repairing the iPhone 17 Pro

https://www.ifixit.com/News/113388/iphone-17-pro-teardown
2•Improvement•45m ago•1 comments

The Job Market Is Hell

https://www.aol.com/news/job-market-hell-115900454.html
1•bbzjk7•46m ago•0 comments

Why haven't PWAs killed native apps yet?

https://kevinbasset.medium.com/why-havent-pwas-killed-native-apps-yet-29beca4425fa
2•anon1395•47m ago•3 comments

That Secret Service SIM farm story is bogus

https://cybersect.substack.com/p/that-secret-service-sim-farm-story
4•sixhobbits•48m ago•0 comments

The J.D. Vance show and American Authoritarianism

https://www.diggitmagazine.com/jd-vance-show-and-american-authoritarianism
7•AntonioBarthes•49m ago•1 comments

Indian open source ventures take on Google Photos, SAP

https://timesofindia.indiatimes.com/technology/times-techies/indian-open-source-ventures-take-on-...
1•setalp•50m ago•0 comments

Multiscreen Device Play (MSDP) with SignalR on Android [video]

https://www.youtube.com/shorts/_J7LfKgrEzk
1•eric_khun•57m ago•0 comments

AI Article Generator – Transform Keywords into Professional Content

https://ai-article.loveyouall.qzz.io/
1•carloshmccarlos•58m ago•2 comments

Dragons Lair on the Amiga – How a laserdisc game fit onto 6 floppy disks – MVG [video]

https://www.youtube.com/watch?v=dyiwHF67Gvg
2•doener•58m ago•0 comments

Canada's 13M Buildings

https://tech.marksblogg.com/canadas-buildings.html
1•marklit•59m ago•0 comments