frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Hormuz Havoc, a satirical game that got overrun by AI bots in 24 hours

https://www.hormuz-havoc.com/
35•kupadapuku•4h ago
I built a satirical browser game to share with friends (Hormuz Havoc: you play an American president managing a crisis in the Middle East, only "loosely" inspired by current events). I had good fun making this, but that's not necessarily the interesting part.

The interesting part was that within a few hours of sharing it with my friends, some of them set about trying to overrun the leaderboard by launching a swarm of AI bots to learn the game and figure out how to get the highest score. This set off a game of cat-and-mouse as they found vulnerabilities and I tried patching them.

Within hours of sharing, someone used the Claude browser extension to read game.js directly. Large parts of the scoring formula, action effect values, and bonus thresholds were sitting in client-side JavaScript - this was a trivial thing even a human could've found, but a human would've still had to play the game, whereas the AI bot just optimised directly against the scoring formula. It meant that the first AI already scored 2.5x higher than the best human player by optimising directly against the source code rather than playing the game.

Straightforward fix: moved the entire game engine server-side. The client is now a dumb terminal, it sends an action ID, receives a rendered state. No scoring logic, no bonus thresholds, no action effects exist in the browser. The live score display uses a deliberately different formula as misdirection.

This increased the difficulty in finding bot-enabled hacks, so the subsequent bots tried brute-forcing the game, trying to game the RNG functions, and other methods.

But the next winning bot found a vulnerability where the same signed session token could be replayed. It would play turn N, observe a bad random event, replay the same token for turn N, get a different RNG outcome, keep the best one. Effectively branching from a single game state to cherry-pick lucky outcomes across 30 turns. Managed to 1.5x the previous bot's high score.

The bot's own description: "The key optimisation was token replay. Because the backend let the same signed state be replayed, I could branch from one exact game state repeatedly and continue from the luckiest high-value outcome each turn."

Fix here: consume a turn nonce atomically before any randomness is generated.

The current state is that the leaderboard is now split into human and AI-assisted. I think the capability of AI bots has flatlined a bit now. Perhaps Claude Mythos might be able to discover the next hackable exploit ¯\_(ツ)_/¯

Happy to go deeper on any of the above - or just enjoy the game! Feel free to try your own AI-powered leaderboard attempt too!

Comments

BahaaKhateeb123•1h ago
The fact that it got overrun in 24 hours is almost more interesting than the game itself. Says a lot about how cheap and easy it is to deploy agents at scale now — the interesting question is what happens when that hits products that actually matter.
keyes343•1h ago
Will you be releasing more such funny scenario based games. I laughed a lot reaching the end.
xg15•1h ago
> If your approval rating gets too low, your party will impeach you.

I like how in this game, the approval rating actually means something.

selectodude•53m ago
That’s how you know it’s loosely inspired by current events.
margalabargala•31m ago
The approval rating works the exact same way it does for the current administration.

If it goes to actually 0%, there are problems. Otherwise it's a resource that can be traded against to grift personal funds.

madamelic•1h ago
Can you explain how I can invade Kharg Island more than once? It seems to indicate that it is possible but the card says it is a one-time thing.

Also, the press shield + Fox News boosts don't seem to do anything with regards to subsequent events. Are they supposed to do something or are they just for show / humor?

unyttigfjelltol•13m ago
Weak gameplay. It’s a turn-by-turn war strategy game where all the levers are “Go on FOX and friends”. What’s particularly strange is how backward the critique is. How about this— for your encore, write the same game from the IRGC perspective. It goes— the US seeks peace; fund foreign militias, try to assassinate a former President. Said former president is reelected and after being unable to close a peace deal, attacks you. You— demonstrate your strategic deterrence by bombing a half-dozen neutral nations and mining an international waterway. Etc.

Cirrus Labs to join OpenAI

https://cirruslabs.org/
71•seekdeep•2h ago•32 comments

Filing the corners off my MacBooks

https://kentwalters.com/posts/corners/
1076•normanvalentine•16h ago•492 comments

Cooperative Vectors Introduction

https://www.evolvebenchmark.com/blog-posts/cooperative-vectors-introduction
14•JasperBekkers•1d ago•0 comments

Optimal Strategy for Connect 4

https://2swap.github.io/WeakC4/explanation/
151•marvinborner•2d ago•22 comments

Show HN: Pardonned.com – A searchable database of US Pardons

139•vidluther•8h ago•46 comments

South Korea introduces universal basic mobile data access

https://www.theregister.com/2026/04/10/south_korea_data_access_universal/
57•saikatsg•1h ago•12 comments

The Problem That Built an Industry

https://ajitem.com/blog/iron-core-part-1-the-problem-that-built-an-industry/
5•ShaggyHotDog•1h ago•1 comments

Starfling: A one-tap endless orbital slingshot game in a single HTML file

https://playstarfling.com
349•iceberger2001•2d ago•94 comments

Volunteers turn a fan's recordings of 10K concerts into an online treasure trove

https://apnews.com/article/aadam-jacobs-collection-concerts-internet-archive-chicago-b1c9c4466a2d...
203•geox•3d ago•33 comments

How Much Linear Memory Access Is Enough?

https://solidean.com/blog/2026/how-much-linear-memory-access-is-enough/
23•PhilipTrettner•3d ago•2 comments

Bitcoin miners are losing on every coin produced as difficulty drops

https://www.coindesk.com/markets/2026/03/22/bitcoin-miners-are-losing-usd19-000-on-every-btc-prod...
80•PaulHoule•1h ago•75 comments

1D Chess

https://rowan441.github.io/1dchess/chess.html
896•burnt-resistor•23h ago•154 comments

Installing every* Firefox extension

https://jack.cab/blog/every-firefox-extension
499•RohanAdwankar•17h ago•67 comments

How Passive Radar Works

https://www.passiveradar.com/how-passive-radar-works/
71•surprisetalk•2d ago•23 comments

Chimpanzees in Uganda locked in eight-year 'civil war', say researchers

https://www.bbc.com/news/articles/cr71lkzv49po
374•neversaydie•19h ago•224 comments

Previously unknown verses by Empedocles found on papyrus

https://www.thehistoryblog.com/archives/75792
10•danielam•2d ago•0 comments

Artemis II safely splashes down

https://www.cbsnews.com/live-updates/artemis-ii-splashdown-return/
1061•areoform•14h ago•338 comments

AI assistance when contributing to the Linux kernel

https://github.com/torvalds/linux/blob/master/Documentation/process/coding-assistants.rst
405•hmokiguess•20h ago•290 comments

France's government is ditching Windows for Linux, says US tech a strategic risk

https://www.xda-developers.com/frances-government-ditching-windows-for-linux/
200•pabs3•6h ago•120 comments

WireGuard makes new Windows release following Microsoft signing resolution

https://lists.zx2c4.com/pipermail/wireguard/2026-April/009561.html
510•zx2c4•23h ago•148 comments

Productive Procrastination

https://www.maxvanijsselmuiden.nl/blog/productive-procrastination/
76•maxvij•9h ago•29 comments

Industrial design files for Keychron keyboards and mice

https://github.com/Keychron/Keychron-Keyboards-Hardware-Design
410•stingraycharles•22h ago•128 comments

Polymarket gamblers betting millions on war

https://www.theguardian.com/business/2026/apr/11/polymarket-gamblers-betting-iran-war-ukraine-new...
98•sandebert•2h ago•56 comments

CPU-Z and HWMonitor compromised

https://www.theregister.com/2026/04/10/cpuid_site_hijacked/
366•pashadee•1d ago•94 comments

Bevy game development tutorials and in-depth resources

https://taintedcoders.com/
115•GenericCanadian•2d ago•26 comments

Borges' cartographers and the tacit skill of reading LM output

https://galsapir.github.io/sparse-thoughts/2026/04/11/map-and-territory/
3•galsapir•1h ago•0 comments

Helium is hard to replace

https://www.construction-physics.com/p/helium-is-hard-to-replace
334•JumpCrisscross•23h ago•237 comments

JSON formatter Chrome plugin now closed and injecting adware

https://github.com/callumlocke/json-formatter
249•jkl5xx•20h ago•124 comments

Sybilproof reputation mechanisms (2005) [pdf]

https://dl.acm.org/doi/pdf/10.1145/1080192.1080202
19•perfmode•3d ago•0 comments

Italo Calvino: A traveller in a world of uncertainty

https://www.historytoday.com/archive/portrait-author-historian/italo-calvino-traveller-world-unce...
106•lermontov•15h ago•20 comments