frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

OpenAI Google Play billing flaw allows receipt replay attacks

2•Agoodgirl3232•1h ago
I am writing to report a critical logical flaw in the payment verification flow between OpenAI and Google Play, which is currently being exploited at an industrial scale.

The Vulnerability: Receipt Replay / Lack of Binding Based on analysis of grey market operations, attackers have automated the following workflow:

Create fresh Google Play accounts to trigger introductory offers (Free Trials/Discounts).

Intercept the purchaseToken / receipt data returned by Google's Billing API.

The Exploit: The backend validation endpoint appears to accept valid Play Store receipts without strictly verifying if the obfuscatedAccountId (or internal user ID binding) matches the OpenAI account requesting the upgrade.

This allows attackers to "inject" or "transfer" a legitimate trial receipt onto unrelated OpenAI accounts, effectively cloning the subscription status.

Current Impact This is not a theoretical bug. It has spawned a massive reselling market. Telemetry from reseller communities suggests a throughput of 8,000 to 10,000 accounts per day.

Evidence / Attribution Several large-scale unauthorized resellers are openly utilizing this method. These platforms claim to have distributed hundreds of thousands of accounts. Examples of domains involved in this distribution include:

bewildcard . com (Widely known for virtual cards, now allegedly distributing these subs)

nf . video

Technical Mitigation If any OpenAI engineers are reading this: You must enforce strict 1:1 binding verification on the server side. The developerPayload in the purchase request must be cryptographically signed and matched against the user ID during the verifyPurchase callback.

This post is intended to bring attention to the flaw so it can be patched, as standard support channels have been unresponsive.

An Open Letter to Jony Ives AI Companion

1•daly•55s ago•0 comments

JavaScript Bin Down in 2026

https://remysharp.com/2026/02/02/js-bin-down-in-2026
1•robin_reala•58s ago•0 comments

Glass Battery

https://en.wikipedia.org/wiki/Glass_battery
1•RGamma•4m ago•0 comments

Grounded Agency: The Type System Your Agent Framework Forgot to Build

https://github.com/synaptiai/agent-capability-standard
1•fornbogi•5m ago•1 comments

Long-term memory for OpenClaw agents with the mem0/OpenClaw-mem0 plugin

https://docs.mem0.ai/integrations/openclaw
1•ninadwrites•5m ago•0 comments

Show HN: Swiss army knife for SpiderWeb Router

https://github.com/knitprong/Devilfileprong-/commit/549364cb64afc348cfd60b18b95af71096a5cd12
1•devilfileprong•8m ago•0 comments

Stardew Valley Turns 10: The Big ConcernedApe Interview

https://www.ign.com/articles/stardew-valley-turns-10-the-big-concernedape-interview
1•thm•10m ago•0 comments

Trump's Profiteering Hits $4B

https://www.newyorker.com/news/a-reporter-at-large/trumps-profiteering-hits-four-billion-dollars
2•tromp•11m ago•0 comments

Skill Issues: An OpenClaw Malware Campaign

https://cantpwn.com/posts/skill-issues
1•djood•11m ago•0 comments

What Do You Get When You Put a Mummy Through a CT Scan?

https://www.nytimes.com/2026/02/03/health/mummy-virtual-autopsy.html
1•mitchbob•11m ago•1 comments

Ask HN: Why not just running OpenClaw in Docker?

1•fdeage•12m ago•1 comments

Show HN: AI Blocker by Kiddokraft

https://kiddokraft.org/wiki?name=ai-blocker
1•Rezhe•12m ago•0 comments

We built what Canva AI should have been

https://markup.one
2•cyrus_kelly•13m ago•1 comments

Proposal to Illion-Ise the Byte System

https://billibyte.site/
1•permo-w•14m ago•0 comments

TfL Status Page

https://tfl.luischav.es/
3•lucharo•14m ago•2 comments

Did we just see a black hole explode? Physicists think so

https://phys.org/news/2026-02-black-hole-physicists.html
1•pseudolus•16m ago•1 comments

Show HN: Yapwise, an ios app to map your yaps

https://yapwise.xyz
1•Kapilverma29•17m ago•1 comments

Show HN: Output.md – Import sitemap, export all pages as Markdown

https://output.md
1•glennhv•19m ago•0 comments

Free AI video clipper using scene and speech-based segmentation

https://www.crabcut.ai/
3•vah7id•20m ago•5 comments

Man in Business Suit Levitating

https://en.wikipedia.org/wiki/Man_in_Business_Suit_Levitating_emoji
1•tosh•22m ago•0 comments

Peter Attia 'Ashamed' After Epstein Emails Become Public

https://www.nytimes.com/2026/02/02/well/peter-attia-epstein.html
2•anonnon•23m ago•1 comments

What Is Claude Code's Plan Mode?

https://lucumr.pocoo.org/2025/12/17/what-is-plan-mode/
1•nebben64•24m ago•0 comments

Speculative Sampling Explained

https://saibo-creator.github.io/post/2024_03_08_speculative_sampling/
2•teleforce•27m ago•0 comments

Pinterest sacks two engineers for creating software to identify fired workers

https://www.theguardian.com/technology/2026/feb/04/pinterest-sacks-two-engineers-for-software-ide...
1•marcosscriven•28m ago•1 comments

Free Unlimited Custom QR Code Generator: Design, Edit and Download

https://www.qrexpress.org/#en
1•levario_studio•32m ago•1 comments

The engineering behind GitHub Copilot CLI's animated ASCII banner

https://github.blog/engineering/from-pixels-to-characters-the-engineering-behind-github-copilot-c...
1•tosh•32m ago•0 comments

Show HN: Glintlog – Self-hosted log aggregation in a single binary

https://glintlog.com
4•caioricciuti•35m ago•0 comments

Reuse of Public Keys Across UTXO and Account-Based Cryptocurrencies

https://arxiv.org/abs/2601.19500
1•Anon84•37m ago•0 comments

The Relocation-Friendly Tech Jobs Report (2026)

https://relocateme.substack.com/p/the-relocation-friendly-tech-jobs-38c
1•hunglee2•37m ago•0 comments

What's New in Peergos in 2025

https://peergos.org/posts/2025
1•ianopolous•43m ago•0 comments