🚨 Andrej Karpathy just explained the scariest thing happening in software right now..
someone poisoned a Python package that gets 97 million downloads a month.. and a simple pip install was enough to steal everything on your machine..
SSH keys.. AWS credentials.. crypto wallets.. database passwords.. git credentials.. shell history.. SSL private keys.. everything..
and here's the part that should terrify every developer alive..
the attack was only discovered because the attacker wrote sloppy code.. the malware used so much RAM that it crashed someone's computer.. if the attacker had been better at coding.. nobody would have noticed for weeks..
one developer.. using Cursor with an MCP plugin.. had litellm pulled in as a dependency they didn't even know about.. their machine crashed.. and that crash saved thousands of companies from getting their entire infrastructure stolen..
Karpathy's take is the real wake up call.. every time you install any package you're trusting every single dependency in its tree.. and any one of them could be poisoned..
vibe coding saved us this time.. the attacker vibe coded the attack and it was too sloppy to work quietly.. next time they won't make that mistake.
🚨 Someone just open sourced an AI hedge fund with 18 agents that think like Wall Street legends.
Warren Buffett. Charlie Munger. Michael Burry. Cathie Wood. Bill Ackman. All running on your laptop.
It's called AI Hedge Fund. You give it stock tickers. 18 AI agents analyze the company from every angle. Then they vote on whether to buy, sell, or hold.
Not a toy. Not a dashboard. A full multi-agent investment research system.
No Bloomberg Terminal. No $25K brokerage minimums. No financial advisor fees. Just AI agents doing what hedge funds charge 2-and-20 for.
Here's who's on your team:
→ Warren Buffett Agent. Only buys wonderful businesses at fair prices
→ Charlie Munger Agent. Demands a margin of safety on every pick
→ Michael Burry Agent. The Big Short contrarian hunting deep value
→ Cathie Wood Agent. Innovation and disruption. High conviction growth
→ Bill Ackman Agent. Activist investor. Takes bold positions
→ Ben Graham Agent. The godfather of value investing. Hidden gems only
→ Aswath Damodaran Agent. The Dean of Valuation. Story meets numbers
→ Plus 11 more specialized agents covering technicals, sentiment, risk, and fundamentals
Here's how it works:
→ You enter stock tickers (AAPL, NVDA, TSLA, whatever you want)
→ Agents pull real financial data. Earnings, balance sheets, insider trades, news
→ Each agent analyzes the data through their own investment philosophy
→ A Risk Manager agent checks position sizing and portfolio exposure
→ A Portfolio Manager agent takes all signals and makes the final call
→ You get a buy/sell/hold decision with full reasoning from every agent
Here's the wildest part:
You can turn on --show-reasoning and watch each agent explain their logic step by step. Warren Buffett agent breaks down the moat. Michael Burry agent flags the hidden risks. Cathie Wood agent finds the disruption angle. They literally argue with each other.
It has a full backtester. Run your strategy against historical data and see how it would have performed.
Full web UI included. Not just a terminal tool. A real dashboard.
Works with OpenAI, Claude, Groq, DeepSeek, or fully local with Ollama. Your data never has to leave your machine.
Data for AAPL, GOOGL, MSFT, NVDA, and TSLA is completely free. No API key needed.
46.7K GitHub stars. 8.1K forks. Actively maintained.
100% Open Source. MIT License.
Holy shit… Your anonymous internet identity can now be unmasked for $1 😳
Not by the FBI. By anyone with access to Claude or ChatGPT and a few of your Reddit comments.
ETH Zurich and Anthropic just dropped a paper called “Large-Scale Online Deanonymization with LLMs” and the results are the most alarming privacy research I’ve read this year.
They built an automated pipeline that takes your anonymous posts, extracts identity signals, searches the web, and figures out who you are.
No human investigator needed. Fully autonomous. Works on Hacker News, Reddit, LinkedIn, even redacted interview transcripts.
Here’s how bad the numbers are.
On Hacker News users: 67% identified correctly.
When the system made a guess, it was right 90% of the time.
On Reddit academics posting under pseudonyms: 52%.
On scientists whose interview transcripts were explicitly redacted for privacy: 9 out of 33 still got unmasked.
The pipeline works in four steps they call ESRC. Extract identity signals from your posts using LLMs.
Search for candidate matches using embeddings across thousands of profiles.
Reason over top candidates with models like GPT-5.2. Calibrate confidence so when it does guess, it’s almost never wrong.
The classical deanonymization method from the famous Netflix Prize attack? Nearly 0% recall across every test.
LLMs didn’t just improve on old techniques. They made old techniques look like toys.
When they scaled to temporally split Reddit profiles, matching a user’s old posts to their newer ones across a full year gap, the pipeline hit 67% recall at 90% precision and 38% recall at 99% precision.
Meaning even a year of changed interests and different conversations wasn’t enough to hide.
More reasoning compute = better deanonymization. High reasoning effort doubled recall at 99% precision in some tests. As frontier models get smarter, this attack strengthens automatically. Every model upgrade is a privacy downgrade.
What makes it nearly impossible to defend against: the pipeline splits into subtasks that all look benign. Summarize a profile.
Compute embeddings. Rank candidates. No single API call screams “deanonymization.” The researchers themselves say they’re pessimistic that safety guardrails or rate limits can stop it.
Their conclusion is blunt: “Users who post under persistent usernames should assume that adversaries can link their accounts to real identities.” And it extrapolates.
Log-linear projections suggest roughly 35% recall at 90% precision even at one million candidates.
Every throwaway account. Every anonymous forum post. Every “nobody will connect this to me” comment.
It’s all searchable micro-data now. And the cost to run the full agent on one target is less than a cup of coffee.
Practical anonymity on the internet just died. The paper killed it with math.
Game-Changing Companies to Mint New Millionaires
These disruptors are flipping industries, like $PLTR ’s data/AI dominance, $HOOD ’s trading revolution, and $SOFI ’s fintech overhaul.
1. $ASTS — Satellite-to-phone → true global coverage, no dead zones
2. $ZETA — AI marketing crushing legacy ad giants
3. $OSCR — Digital health insurance dismantling slow, opaque systems
4. $RKLB — Reusable rockets + Neutron launch owning medium-lift space
5. $NBIS — Full-stack AI cloud/GPU clusters
6. $ONDS — Drone networks redefining defense and logistics
7. $IREN — Mining-to-AI data center power pivot solving energy bottlenecks
8. $PATH — Agentic RPA/AI bots automating enterprise workflows at scale
9. $SNOW — Borderless data cloud powering the entire AI revolution
10. $OKLO — Advanced nuclear reactors fueling massive AI/data center demand
11. $TEM — AI precision medicine powerhouse personalizing care with the world’s largest clinical + molecular data engine
Who’d I miss?