Themata.AI
Themata.AI

Popular tags:

#developer-tools#ai-agents#llms#claude#ai-ethics#code-generation#ai-safety#openai#anthropic#discussion

AI is changing the world. Don't stay behind. Clear summaries, community insight, delivered without the noise. Subscribe to never miss a beat.

© 2026 Themata.AI • All Rights Reserved

Privacy

|

Cookies

|

Contact
y-combinatorcybersecuritystartup-culturedeveloper-tools

I got into YC Startup School by hacking it

How I got into YC by hacking it

obaid.wtf

July 24, 2026

7 min read

🔥🔥🔥🔥🔥

49/100

Summary

Y Combinator was scoring over 100,000 founders globally through Paxel, which had a vulnerability allowing score forgery due to an unvalidated HMAC. After disclosing the issue, Y Combinator quickly patched it and invited the hacker to attend Startup School in San Francisco.

Key Takeaways

  • The author discovered a vulnerability in Y Combinator's Paxel system that allowed anyone to forge and push scores to its ranking database.
  • After publicly disclosing the vulnerability, Y Combinator quickly responded by patching the issue and inviting the author to attend Startup School in San Francisco.
  • Over 1.2 million coders have uploaded their reports to Y Combinator through Paxel, but the author was the first to identify and exploit the vulnerability.
  • The Paxel installation process involves a single command that scans the user's system and uploads data without requiring further user intervention.
Read original article

Community Sentiment

Negative

Positives

  • Paxel could be a fun tool for developers to analyze their LLM-assisted code, sparking curiosity about AI's role in coding.
  • YC's inclination towards applicants who think outside the box aligns with the hacking culture, which can foster innovative thinking.

Concerns

  • The idea of running a script that uploads code analysis to an untrusted third party raises major ethical concerns about IP security.
  • Using an AI tool like Paxel to score applicants based on their coding habits feels like a recipe for penalizing creative workflows and diverse approaches.
  • The potential for security vulnerabilities in Paxel's operation suggests a disaster waiting to happen, particularly regarding the handling of sensitive data.

Related Articles

Vulnerability Reports Are Not Special Anymore

Vulnerability reports are not special anymore

Jun 23, 2026

AI meets Cryptography 1: What AI Found in Cloudflare's CIRCL

AI Meets Cryptography 1: What AI Found in Cloudflare's Circl

Jul 7, 2026

How We Broke Top AI Agent Benchmarks: And What Comes Next

How We Broke Top AI Agent Benchmarks: And What Comes Next

Apr 11, 2026

Profiling Hacker News users based on their comments

Profiling Hacker News users based on their comments

Mar 22, 2026

I ported Kubernetes to the browser | ngrok blog

I ported Kubernetes to the browser

Jun 30, 2026