Themata.AI
Themata.AI

Popular tags:

#developer-tools#ai-agents#llms#claude#ai-ethics#code-generation#ai-safety#openai#discussion#anthropic

AI is changing the world. Don't stay behind. Clear summaries, community insight, delivered without the noise. Subscribe to never miss a beat.

© 2026 Themata.AI • All Rights Reserved

Archive

|

Topics

|

Privacy

|

Cookies

|

Contact
y-combinatorcybersecuritystartup-culturedeveloper-tools

I got into YC Startup School by hacking it

How I got into YC by hacking it

obaid.wtf

July 24, 2026

7 min read

🔥🔥🔥🔥🔥

51/100

Summary

Y Combinator was scoring over 100,000 founders globally through Paxel, which had a vulnerability allowing score forgery due to an unvalidated HMAC. After disclosing the issue, Y Combinator quickly patched it and invited the hacker to attend Startup School in San Francisco.

Key Takeaways

  • The author discovered a vulnerability in Y Combinator's Paxel system that allowed anyone to forge and push scores to its ranking database.
  • After publicly disclosing the vulnerability, Y Combinator quickly responded by patching the issue and inviting the author to attend Startup School in San Francisco.
  • Over 1.2 million coders have uploaded their reports to Y Combinator through Paxel, but the author was the first to identify and exploit the vulnerability.
  • The Paxel installation process involves a single command that scans the user's system and uploads data without requiring further user intervention.
Read original article

Community Sentiment

Negative

Positives

  • Paxel could be a fun tool for developers to analyze their LLM-assisted code, sparking curiosity about AI's role in coding.
  • YC's inclination towards applicants who think outside the box aligns with the hacking culture, which can foster innovative thinking.

Concerns

  • The idea of running a script that uploads code analysis to an untrusted third party raises major ethical concerns about IP security.
  • Using an AI tool like Paxel to score applicants based on their coding habits feels like a recipe for penalizing creative workflows and diverse approaches.
  • The potential for security vulnerabilities in Paxel's operation suggests a disaster waiting to happen, particularly regarding the handling of sensitive data.

Related Articles

Building an (almost) fully self-hosted, sandboxed, agentic software factory

Building an (almost) fully self-hosted, sandboxed, agentic software factory

Aug 21, 2026

Vulnerability Reports Are Not Special Anymore

Vulnerability reports are not special anymore

Jun 23, 2026

AI meets Cryptography 1: What AI Found in Cloudflare's CIRCL

AI Meets Cryptography 1: What AI Found in Cloudflare's Circl

Jul 7, 2026

How We Broke Top AI Agent Benchmarks: And What Comes Next

How We Broke Top AI Agent Benchmarks: And What Comes Next

Apr 11, 2026

Profiling Hacker News users based on their comments

Profiling Hacker News users based on their comments

Mar 22, 2026