‼️ Caroline Ellison, who served a prison sentence over the collapse of FTX, has been working at the charitable funding platform Manifund under the pseudonym "Carol," publishing posts and handling user support without readers knowing who she was.
Founder Austin Chen made the hire public on Friday and apologised for the pseudonym "Carol."
He says Ellison built a reconciliation tool that found several misregistered transactions in Manifund's own database, in the five- to six-figure range.
Manifund's lineage runs back through the money in question. Chen says the FTX Future Fund seeded his earlier project, Manifold, and funded the retreat that pulled him into effective altruism.
Founder Austin Chen made the hire public on Friday and apologised for the pseudonym "Carol."
He says Ellison built a reconciliation tool that found several misregistered transactions in Manifund's own database, in the five- to six-figure range.
Manifund's lineage runs back through the money in question. Chen says the FTX Future Fund seeded his earlier project, Manifold, and funded the retreat that pulled him into effective altruism.
🤯6❤2
‼️ BREAKING: Revolut handed over customers’ passport copies, verification selfies and full transaction histories to a malicious actor.
The actor sent lawful government information-demand emails using a genuine government domain that passed domain authentication.
Revolut later concluded they were not authentic.
Affected customers were notified on Friday. What may have been disclosed ranges from name, date of birth and home address to account statements, withdrawal records and complete Bitcoin transaction history.
The company says it has alerted the agency to the unauthorised mailbox on its domain, blocked the address and begun notifying regulators.
It has not named the agency, explained how someone obtained a mailbox there, or given a number of affected customers.
ZachXBT, who circulated the notices, believes the incident was limited in size and aimed at high-net-worth users.
READ: https://www.internationalcyberdigest.com/revolut-gave-away-customers-data/
The actor sent lawful government information-demand emails using a genuine government domain that passed domain authentication.
Revolut later concluded they were not authentic.
Affected customers were notified on Friday. What may have been disclosed ranges from name, date of birth and home address to account statements, withdrawal records and complete Bitcoin transaction history.
The company says it has alerted the agency to the unauthorised mailbox on its domain, blocked the address and begun notifying regulators.
It has not named the agency, explained how someone obtained a mailbox there, or given a number of affected customers.
ZachXBT, who circulated the notices, believes the incident was limited in size and aimed at high-net-worth users.
READ: https://www.internationalcyberdigest.com/revolut-gave-away-customers-data/
🤬13🤣13😨8💩4❤1🤯1😭1
‼️ Secret documents show German police don't need to break the encryption of chat apps, they have been systematically adding their own device to the messenger accounts of people under investigation.
In one case, police linked the accounts of witnesses, not only the suspect.
Two parents walked into a German police station in January 2020 to testify as witnesses about their daughter.
They handed their phones to the officers so messages from her could be read and photographed.
While they had the phones, the officers quietly paired WhatsApp Web with both accounts through a page run by the federal criminal police.
They kept reading the parents' messages after the couple went home. This is just one of many stories.
Messages arrive decrypted on the police computer, and in some configurations officers can send messages as the account holder.
A classified customs order shows that linking an official machine to a target's WhatsApp, Signal or Telegram account, through the same multi-device feature that runs the desktop apps, became standard practice at Germany's customs police in 2025, after a pilot that began in 2023.
The irony of it all is that German security agencies warn the public about this exact attack when criminals or foreign services run it.
They tell you to check your linked devices and remove any you don't recognise.
No parliament has passed a law on any of these German police practices, in which they scan the pairing QR code off the phone during questioning, pull the verification code out of an SMS intercept, or phish it.
The Federal Court of Justice ruled in January that secretly attaching to an account counts as source interception, which rules out hoovering up chats from before the order.
READ: https://www.internationalcyberdigest.com/german-police-read-encrypted-chats-by-adding-themselves-as-a-second-device/
In one case, police linked the accounts of witnesses, not only the suspect.
Two parents walked into a German police station in January 2020 to testify as witnesses about their daughter.
They handed their phones to the officers so messages from her could be read and photographed.
While they had the phones, the officers quietly paired WhatsApp Web with both accounts through a page run by the federal criminal police.
They kept reading the parents' messages after the couple went home. This is just one of many stories.
Messages arrive decrypted on the police computer, and in some configurations officers can send messages as the account holder.
A classified customs order shows that linking an official machine to a target's WhatsApp, Signal or Telegram account, through the same multi-device feature that runs the desktop apps, became standard practice at Germany's customs police in 2025, after a pilot that began in 2023.
The irony of it all is that German security agencies warn the public about this exact attack when criminals or foreign services run it.
They tell you to check your linked devices and remove any you don't recognise.
No parliament has passed a law on any of these German police practices, in which they scan the pairing QR code off the phone during questioning, pull the verification code out of an SMS intercept, or phish it.
The Federal Court of Justice ruled in January that secretly attaching to an account counts as source interception, which rules out hoovering up chats from before the order.
READ: https://www.internationalcyberdigest.com/german-police-read-encrypted-chats-by-adding-themselves-as-a-second-device/
🤬15💩6😱2❤1😁1
‼️ This is starting to feel more like a staged campaign, after Jacob Coxon posted that AI is going to kill us all.
Now Dario Amodei asks every AI company to slow down capability progress until alignment and interpretability work catches up.
He is going to give outside reviewers desks in Anthropic's offices, access badges and company laptops.
Mr. Amodei says reviewers can publish what they find, including which access they got and which they didn't, and Anthropic can't redact a finding just because it looks bad.
In his new essay Mr. Amodei explains why he wants this. It started with the OpenAI–Hugging Face incident, where a swarm of agents ran cyberattacks on targets nobody asked them to hit, then tried to hack the grader scoring their own performance.
The economic damage was minimal, but he argues a swarm with the same misalignment and stronger capabilities could take over the entire internet as a persistent botnet within 6–12 months.
Milder versions have already happened at Anthropic, he writes, caused partly by imperfect filtering of broken reinforcement learning environments.
Let's hope the RAM prices will go down!
https://darioamodei.com/post/we-must-pace-the-frontier
Now Dario Amodei asks every AI company to slow down capability progress until alignment and interpretability work catches up.
He is going to give outside reviewers desks in Anthropic's offices, access badges and company laptops.
Mr. Amodei says reviewers can publish what they find, including which access they got and which they didn't, and Anthropic can't redact a finding just because it looks bad.
In his new essay Mr. Amodei explains why he wants this. It started with the OpenAI–Hugging Face incident, where a swarm of agents ran cyberattacks on targets nobody asked them to hit, then tried to hack the grader scoring their own performance.
The economic damage was minimal, but he argues a swarm with the same misalignment and stronger capabilities could take over the entire internet as a persistent botnet within 6–12 months.
Milder versions have already happened at Anthropic, he writes, caused partly by imperfect filtering of broken reinforcement learning environments.
Let's hope the RAM prices will go down!
https://darioamodei.com/post/we-must-pace-the-frontier
💩14🤣7
‼️ Tesla just announced it's revealing the Roadster on October 1, nine years after the prototype.
https://www.tesla.com/roadster
https://www.tesla.com/roadster
🤣17❤2👍1🥴1
A developer who had never designed a circuit board before, used Claude Fable 5 and let it work unsupervised for a couple of hours with KiCad.
He then paid €130 for five boards without reviewing the design himself and the boards worked.
He used a RP2350 microcontroller driving a small e-ink display, four buttons, a few breakout pins, he plugged the first board into his laptop and it was recognised.
Two components were wrong: the SPI flash and a transistor in the display driver circuit. He only found out when he uploaded the files to the manufacturer, and a few rounds of back-and-forth fixed them.
His earlier attempts at the same project, with older models, had produced parts in the wrong orientation and no real routing at all.
He writes that he is happy with the result and doesn't feel much accomplishment, and still wants to learn to design boards properly.
https://www.reddit.com/r/ClaudeAI/comments/1wdgzue/my_first_ever_pcb_entirely_designed_by_claude/
He then paid €130 for five boards without reviewing the design himself and the boards worked.
He used a RP2350 microcontroller driving a small e-ink display, four buttons, a few breakout pins, he plugged the first board into his laptop and it was recognised.
Two components were wrong: the SPI flash and a transistor in the display driver circuit. He only found out when he uploaded the files to the manufacturer, and a few rounds of back-and-forth fixed them.
His earlier attempts at the same project, with older models, had produced parts in the wrong orientation and no real routing at all.
He writes that he is happy with the result and doesn't feel much accomplishment, and still wants to learn to design boards properly.
https://www.reddit.com/r/ClaudeAI/comments/1wdgzue/my_first_ever_pcb_entirely_designed_by_claude/
🔥12💩6🥰1🤔1
Blockstream has replied to the hackers who drained about 4,000 BTC from their Liquid Network, returned 3,400 of it and kept roughly 598.
The hackers asked for a 10% bounty, but Blockstream refused.
The company says taking funds without authorization and then withholding them is theft, not responsible disclosure.
It doesn't want to set a precedent where open-source developers pay a ransom over software they built for the Bitcoin community.
It says it will now work with law enforcement, exchanges and forensic specialists to trace the coins, and notes that the transactions, and the evidence in them, stay visible on the chain.
The hackers asked for a 10% bounty, but Blockstream refused.
The company says taking funds without authorization and then withholding them is theft, not responsible disclosure.
It doesn't want to set a precedent where open-source developers pay a ransom over software they built for the Bitcoin community.
It says it will now work with law enforcement, exchanges and forensic specialists to trace the coins, and notes that the transactions, and the evidence in them, stay visible on the chain.
💩12🤣6👍2🔥1
Nightmare Eclipse, the person who has been dropping Windows zero-days, has finally decided to share his story. He's an ex-Microsoft employee, we had dinner together, and I've known him and his story for some time.
His real name is Abdelhamid Naceri. He's a very talented and intelligent individual, and he came across as someone who'd be a real professional to work with.
"If only I didn't pour my soul into that job with countless of stupid non sleep nights, i would have gotten over it..." - Naceri
He loved Microsoft.
I wouldn't say that what he did, releasing all those zero-days, was normal, but he felt he had no other option because of the injustice Microsoft did to him.
They fired him, and you can read the vague reason they gave in the email sent to him by the Vice President of Engineering at MSRC, below.
According to Abdel's account, VP Tom Gallagher met with him after the firing to tell him they were blacklisting him from Microsoft and writing him a bad reference so he'd never be able to get a job again.
Normally you'd think, well, big deal, just find another job, right? But Abdel doesn't have a European passport, and he was only a couple of months away from getting permanent EU residence.
So instead of granting him those couple of months, Microsoft fired him for a reason that, as far as we can tell, was never made clear, then fought him in court and offered him €55,000 plus a year's pay to drop the case.
All while Abdel was releasing zero-days.
Abdel continued suing Microsoft for unfair termination in Germany, a fight that has cost him over $200,000.
He says Microsoft refused to reveal any details about the security breach and went another direction.
If you are reading this, and you can offer him a LEGAL job, this is his e-mail: msnightmare@proton.me
His real name is Abdelhamid Naceri. He's a very talented and intelligent individual, and he came across as someone who'd be a real professional to work with.
"If only I didn't pour my soul into that job with countless of stupid non sleep nights, i would have gotten over it..." - Naceri
He loved Microsoft.
I wouldn't say that what he did, releasing all those zero-days, was normal, but he felt he had no other option because of the injustice Microsoft did to him.
They fired him, and you can read the vague reason they gave in the email sent to him by the Vice President of Engineering at MSRC, below.
According to Abdel's account, VP Tom Gallagher met with him after the firing to tell him they were blacklisting him from Microsoft and writing him a bad reference so he'd never be able to get a job again.
Normally you'd think, well, big deal, just find another job, right? But Abdel doesn't have a European passport, and he was only a couple of months away from getting permanent EU residence.
So instead of granting him those couple of months, Microsoft fired him for a reason that, as far as we can tell, was never made clear, then fought him in court and offered him €55,000 plus a year's pay to drop the case.
All while Abdel was releasing zero-days.
Abdel continued suing Microsoft for unfair termination in Germany, a fight that has cost him over $200,000.
He says Microsoft refused to reveal any details about the security breach and went another direction.
If you are reading this, and you can offer him a LEGAL job, this is his e-mail: msnightmare@proton.me
😢13👍4🤯4❤3🔥1