frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Bitcoin trail, Google cookies and Uber Eats orders help tie man to Steam malware

https://www.theverge.com/games/967174/steam-game-malware-cryptostealer-arrest
20•rzk•2h ago

Comments

Cider9986•1h ago
Criminals should have used Monero.

Victims should have not keep crypto on desktops. They are much less secure than Mobile.

fsflover•1h ago
> Victims should have not keep crypto on desktops. They are much less secure than Mobile.

Unless it's Qubes OS.

Cider9986•55m ago
True. How viable is steam on Qubes?
LoganDark•23m ago
Modern macOS devices have a secure element just as good as iOS devices. Almost nobody makes use of it, though.

(I haven't seen anything yet that uses the secure element to control access to a wallet. Are there any technical obstacles to keeping the keys out of main memory?)

zuzululu•47m ago
He was smart/determined enough to risk it all. Why didn't he just try find a job that pays $200k/year ? Why play into the stereotypes ?
fhdkweig•34m ago
> He was smart/determined enough to risk it all.

Desperate people are willing to risk it all, and usually smart people aren't desperate.

r_lee•21m ago
> didn't he just try find a job that pays $200k/year ?

you really think it's that easy?

choilive•11m ago
Claude get me a job that pays $200k/yr. Make no mistakes.
idiotsecant•11m ago
Yeah, clearly risking it all wasn't the smart play here, as evidenced by the fact he got caught.

A lot of people are willing to tolerate risk, that hardly makes them useful. Frequently the opposite.

jjmarr•10m ago
> In the complaint, officials accuse 21-year-old... from the University of West Florida.[1]

And there's your answer. He's a student from a non-target school.

It's borderline impossible, especially now with AI and high interest rates, to crack one of these $200k/year jobs. Even if you are smart and determined it simply isn't possible because your resume goes into the garbage.

We should expect more sophisticated crime as we continue to graduate intelligent people into a job market that doesn't want them.

It's similar to how 44% of university-educated Islamic terrorists studied engineering.[2] Engineering is one of the most prestigious programs in the Middle East but there are not a lot of engineering jobs. As a result, a ton of smart, driven, people who would get well-paid jobs in a different economy, instead turn to violence in an attempt to gain power/money/status.

[1] https://www.local10.com/news/local/2026/07/15/feds-accuse-br...

[2] https://researchonline.lse.ac.uk/id/eprint/29836/1/Why_are_t...

LoganDark•25m ago
I heard Monero can help against blockchain analysis (though less so if you buy from adversaries). Unfortunately it looks like blockchain analysis was not the attack vector here, but rather buying gift cards through an incompetent intermediary
HDBaseT•5m ago
Not really an "incompetent intermediary", Bitrefill, the company used for buying gift cards with Bitcoin received legal requests to identify the user. Bitrefill doesn't proclaim insane privacy protections, they are based out of Sweden but aren't immune to being requested to provide the information.

Monero could of helped, although its not easy to transfer BTC to Monero without P2P trades, as effectively every exchange requires KYC. Those source and destination wallet addresses are tainted, you wouldn't be able to deposit on any mainstream exchange and if they do, its for a honey pot purpose.

drnick1•13m ago
This underscores a major issue with commercial software like Steam and games obtained therein. You cannot trust that software not to maliciously scan your device for secrets such as crypto wallets or other information. Ideally, you want to run apps like Steam, Discord, Zoom and whatever else does not come from a trusted distribution repo as a separate user. This is not always convenient however, and the compromise I adopted on my gaming PC is to bubblewrap Steam. Do not mount things like /home and devices games should not be using in the sandbox.
HDBaseT•9m ago
It is honestly much easier to spread malware or hack companies than it is to make 200k/year from a company.

Now with AI, you can accelerate this so much. The only thing holding back thousands of new threat actors from doing the same is Opsec, its hard.

robotnikman•5m ago
>Why didn't he just try find a job that pays $200k/year ?

Probably was not able to get into MIT or another prestigious school that many of those companies look for on a resume.

Our position on open-weights models

https://www.anthropic.com/news/position-open-weights-models
205•surprisetalk•1h ago•206 comments

Watching Go's new garbage collector move through the heap

https://theconsensus.dev/p/2026/07/19/observing-gos-garbage-collector-old-and-new.html
144•matheusmoreira•2d ago•16 comments

Launch HN: Rise Reforming (YC S26) – Turning Waste Gases into Valuable Chemicals

https://www.rise-reforming.com
53•george_rose25•3h ago•17 comments

Securing Services with Rootless Containers

https://blog.coderspirit.xyz/blog/2026/07/06/securing-services-with-rootless-containers/
35•speckx•4d ago•13 comments

Self-contained highly-portable Python distributions

https://gregoryszorc.com/docs/python-build-standalone/main/
86•jcbhmr•4h ago•20 comments

Glue bonds to nonstick surfaces and wipes clean with ethanol

https://cen.acs.org/materials/adhesives/glue-bonds-nonstick-surfaces-wipes-clean/104/web/2026/07
139•gmays•4d ago•72 comments

Ray tracing massive amounts of animated geometry using tetrahedral cages

https://gpuopen.com/learn/ray-tracing-massive-amounts-animated-geometry/
55•LorenDB•4d ago•6 comments

The computer that helped win World War II

https://spectrum.ieee.org/colossus-computer-ieee-milestone
163•baruchel•5d ago•66 comments

Judge Rejects Google's Attempt to DMCA Its Way Out of Being Scraped

https://www.techdirt.com/2026/07/27/judge-rejects-googles-attempt-to-dmca-its-way-out-of-being-sc...
216•cdrnsf•4h ago•80 comments

Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

https://eaton-works.com/2026/07/27/my-eicher-hack/
120•EatonZ•8h ago•39 comments

Show HN: FeyNoBg – Automatic background removal model and training library

https://usefeyn.com/blog/feynobg/
78•snyy•6h ago•21 comments

Bytecode-to-Source Mapping

https://tidefield.dev/bytecode-to-source-mapping/
29•evakhoury•4h ago•2 comments

Paged Out #9 [pdf]

https://pagedout.institute/download/PagedOut_009.pdf
156•laurensr•8h ago•20 comments

Removing React.js from the codebase and adapting Htmx for UI interactivity (2023)

https://misago-project.org/t/removing-reactjs-from-the-codebase-and-adapting-htmx-for-ui-interact...
208•Ralfp•13h ago•152 comments

A missing underscore sent innocent man to prison for 18 months

https://arstechnica.com/tech-policy/2026/07/police-missed-one-underscore-and-sent-the-wrong-man-t...
43•quantified•59m ago•17 comments

MAI-Cyber-1-Flash inside MDASH

https://microsoft.ai/news/introducing-mai-cyber-1-flash-inside-mdash/
205•migmartri•6h ago•107 comments

UpCodes (YC S17) is hiring remote AE's to help make buildings cheaper

https://up.codes/careers?utm_source=HN
1•Old_Thrashbarg•6h ago

Colorblind: Checking figure accessibility for colour blind people

https://quantixed.org/2022/05/19/colorblind-checking-figure-accessibility-for-colour-blind-people/
5•sebg•4d ago•0 comments

Libsm64: Mario 64 as a library for use in external game engines

https://github.com/libsm64/libsm64
172•klaussilveira•13h ago•21 comments

Forth

https://xkcd.com/3277/
54•beardyw•2h ago•10 comments

Building GCC 1.27 (2019)

http://kristerw.blogspot.com/2019/01/building-gcc-127.html
8•ciponi•5d ago•1 comments

How real are real numbers? (2004)

https://arxiv.org/abs/math/0411418
41•surprisetalk•7h ago•28 comments

VLC for Unity now supported on Linux

https://code.videolan.org/videolan/vlc-unity
147•martz•14h ago•44 comments

Tokio Gives Progress, Not Ordering: Scheduling 1M Tasks

https://pranitha.dev/posts/tokio-gives-progress-not-ordering/
34•pranitha_m•7h ago•2 comments

How is the Bun Rewrite in Rust going?

https://lockwood.dev/ai/2026/07/27/how-is-the-bun-rewrite-in-rust-going.html
438•tomlockwood•11h ago•333 comments

Bitcoin trail, Google cookies and Uber Eats orders help tie man to Steam malware

https://www.theverge.com/games/967174/steam-game-malware-cryptostealer-arrest
20•rzk•2h ago•14 comments

Modern email can be built from borrowed parts

https://en.andros.dev/blog/d7ed8b07/modern-email-can-be-built-from-borrowed-parts/
167•andros•14h ago•97 comments

The Artist Who Colored Ghibli

https://animationobsessive.substack.com/p/the-artist-who-colored-ghibli
94•herbertl•4h ago•8 comments

Towards a Theory of Bugs: The Ruliology of the Unexpected

https://writings.stephenwolfram.com/2026/07/towards-a-theory-of-bugs-the-ruliology-of-the-unexpec...
61•nsoonhui•3d ago•35 comments

Kimi-K3 on HuggingFace

https://huggingface.co/moonshotai/Kimi-K3
1294•nateb2022•16h ago•508 comments