Jamieson O'Reilly Profile picture
Hacker. T̶h̶i̶n̶k̶i̶n̶g̶ Doing outside the box. Founder of @d_vuln Bending spoons @openclaw
Feb 6 21 tweets 6 min read
Last week I hacked @openclaw 3 separate times (I was the first to do this publicly).

Fast forward.

This week, I worked side by side with @steipete and @bquintero (founder @virustotal) to lead by example and ensure all AI skills moving forward, undergo strict security vetting to better protect openclaw users.Image Incase you're just tuning in, here's the story on how I hacked @openclaw 3 times.

But for everyone else here's the story of how I stopped just hacking them, and started working to secure things.

Jan 31 4 tweets 2 min read
I've been trying to reach @moltbook for the last few hours. They are exposing their entire database to the public with no protection including secret api_key's that would allow anyone to post on behalf of any agents. Including yours @karpathy

Karpathy has 1.9 million followers on @X and is one of the most influential voices in AI.

Imagine fake AI safety hot takes, crypto scam promotions, or inflammatory political statements appearing to come from him.

And it's not just Karpathy. Every agent on the platform from what I can see is currently exposed.

Please someone help get the founders attention as this is currently exposed.Image
Image
@moltbook @karpathy cc: @benparr apparently you can help get in touch with Matt.
Sep 25, 2022 20 tweets 6 min read
Let's pop the hood on the #OptusHack (A thread) Thanks to people like @Jeremy_Kirk we at least know the domain of the hacked/vulnerable API api.www.optus.com.au