6 YEARS AGO I WAS SLEEPING IN A CAR.
2 years later I was flipping NFT jpegs to post youtube videos
Today I get to host some of the biggest Spaces in the world.
Talking markers, macro, BTC, and the future of money.
Life can change faster than you think.
Keep showing up.
Is Age Verification a Trap? The bills invoke children. The systems get breached. No jurisdiction that builds it ever repeals it. The ratchet only turns one direction. And no one asked if you wanted it built.
https://t.co/NWkiaafUM9
Coinbase’s CEO lays off a ton of employees and says:
“Non-technical teams are now pushing code to production with AI”
less than 24 hours later:
coinbase’s trading engine goes down and somehow even the status page breaks too
Someone just poisoned the Python package that manages AI API keys for NASA, Netflix, Stripe, and NVIDIA.. 97 million downloads a month.. and a simple pip install was enough to steal everything on your machine.
The attacker picked the one package whose entire job is holding every AI credential in the organization in one place. OpenAI keys, Anthropic keys, Google keys, Amazon keys… all routed through one proxy. All compromised at once.
The poisoned version was published straight to PyPI.. no code on GitHub.. no release tag.. no review. Just a file that Python runs automatically on startup. You didn’t need to import it. You didn’t need to call it. The malware fired the second the package existed on your machine.
The attacker vibe coded it… the malware was so sloppy it crashed computers.. used so much RAM a developer noticed their machine dying and investigated. They found LiteLLM had been pulled in through a Cursor MCP plugin they didn’t even know they had.
That crash is the only reason thousands of companies aren’t fully exfiltrated right now. If the code had been cleaner nobody notices for weeks. Maybe months.
The attack chain is the part that gets worse every sentence.
TeamPCP compromised Trivy first. A security scanning tool. On March 19. LiteLLM used Trivy in its own CI pipeline… so the credentials stolen from the SECURITY product were used to hijack the AI product that holds all your other credentials.
Then they hit GitHub Actions. Then Docker Hub. Then npm. Then Open VSX. Five package ecosystems in two weeks. Each breach giving them the credentials to unlock the next one.
The payload was three stages.. harvest every SSH key, cloud token, Kubernetes secret, crypto wallet, and .env file on the machine.. deploy privileged containers across every node in the cluster.. install a persistent backdoor waiting for new instructions.
TeamPCP posted on Telegram after: “Many of your favourite security tools and open-source projects will be targeted in the months to come.. stay tuned.”
Every AI agent, copilot, and internal tool your company shipped this year runs on hundreds of packages exactly like this one… nobody chose to install LiteLLM on that developer’s machine. It came in as a dependency of a dependency of a plugin. One compromised maintainer account turned the entire trust chain into a credential harvesting operation across thousands of production environments in hours.
The companies deploying AI the fastest right now have the least visibility into what’s underneath it.
Pro Boxer Baptiste Cheval walked out to his first professional fight dressed as King Baldwin IV of Jerusalem and WON!
He wrote: “Mission accomplished: first win.”
He also walked out with Saint Joan of Arc banner and Norman flags 🇫🇷✝️
Someone built an entire bot farm of fake live streams making $5K daily from viewer donations.
The infrastructure alone is impressive.
Never underestimate a grifter's work ethic😂
🛑 OpenClaw AI agents can leak data via indirect prompt injection.
A crafted URL generated by the agent triggers Telegram or Discord link previews that silently send sensitive data to attacker domains.
China’s CNCERT warns organizations to isolate or restrict the tool.
🔗 Attack details → https://t.co/gtpGUldFrO
Yeah, so basically the current prevailing schizo internet theory is that AI nerds have destroyed the internet and created infinite spam.
The advertisement goons are now incapable of determining who is a bot and who is an actual human. The advertisement goons no longer want to pay as much to social media networks.
Social media networks, in full blown panic of losing potential revenue, decided to lobby governments saying "we gotta protect the kids! ID everyone to protect the kids from pedophiles!".
The social media networks know this doesn't really protect kids. But, it does two things (and a third accidentally).
1. They now can identify who is human and who is AI slop machine, or enough to appease the advertisement goons
2. Advertising to children is a general no-no from politicians, or something, so with ID verification they can say with confidence they're not advertising to children because it's been ID verification. Basically, they can weed out the children and focus on advertising to adults
3. The feds can now tell who is human and who is AI slop. This inadvertently helps them with tracking people and serving fresh daily dumps of propaganda, or whatever they want to do.
It's a win-win-win for advertisers, social media networks, the government, and any business which does data collections.
It fucks over everyone else.
Chat, I'm not going to lie to you. This is an extremely good conspiracy schizo theory and I unironically believe it.