关于 AI 做代码审查,我还想补充一个很多人没注意到的坑
AI 极其容易掉入局部陷阱。很多时候我们让 AI 审代码,它一上来就默认你的框架和方案是对的,只会在你的方案里去找安全漏洞或者小修小补
但对大多数开发者(尤其是新手)来说,最关键的是审查这个方案本身选得对不对。你可能用 A 方案修修补补折腾了半天,换成 B 方案这些问题根本就不会存在
另一个烦人的点是 AI 的挤牙膏审查。你让他审一遍,改完问题再让他审,他又能挑出新问题。说明他不是一次性从底层原理出发把根源解决掉,而是在那里硬找问题、刷存在感
为了避免这两个问题,我总结了一个Prompt,评论区看看👇
I’m using pi much more for long-horizon tasks (>6h). it's simpler by design and easier to work programmatically. i rarely use pi tui, most of my work is driving it inside a bigger system/container/uiux. some takes:
- pi ships with a minimal toolset and it's enough for airgapped tasks. if you have enterprise customers who want everything airgapped, pi + open-weight models is the goto solution.
- pi extensions are mostly unnecessary. i only have pi-mcp-adapter and pi-vcc installed, because i need to maintain/use jina reader mcp. pi-vcc is a drop-in fix for pi's context compaction, which can bite you on long-horizon tasks (see screenshot last swimline where compaction takes more and more time in long-horizon task)
- no double-dip: if you program pi with an agent like CC/Codex, you'll likely end up building another harness layer on top of pi's own harness, completely redundant glue code. every now and then you need to steer CC/Codex back to pi's design principle: keep the wrapper lean and mean, use pi native features as much as possible.
- imo pi works best with open-weight and self-hosted models, or at least that's what makes pi fun to work with. But pay attention to pi/models.json: your coding agent probably doesn't know every attribute of those new open models. forget to declare image modality as an accepted input and pi suddenly starts shelling out to tesseract for ocr everything. Or leave max context length conservatively set at 65K and pi starts compacting frequently for no reason.
- in the end, the nudge prompt (the one that keeps pi going forever), and workspace isolation (for multi-task/multi-tenant systems) are where you'll actually spend your effort. Not too many but that’s fine and that’s the point, for the harness just trusts pi to do the work in a very first-principled way. You can just focus on the actual task.
Yesterday, @injective was exploited for ~$4.8M.
The attacker reportedly repeated the same path across 299 markets in 19h, while the chain halted for ~4h.
Injective still hasn’t addressed it publicly.
Months earlier, a white hat said he saved $500M and was offered $50K😮
i'm sorry because i like @consumerxai and he previously helped me, but i just tested this, and it's so easily detectable.
here are some of the signs:
- at least 3 signals that WebDriverAgent is active. any app can see those, and TikTok is known to look for that
- port 9100 (screen capture) answering, TikTok is also known to look for this. if you run this for a while, TikTok eventually hides UI elements
- all gestures straight lines
- all gestures are radius = 0.0 (like a mouse)
- dt 7.75ms, not locked to the 16.666 ms frame cadence a real digitizer produces
- latency 36ms because of the injection round-trip through HID/AX
there are many others, just listing the obvious ones. just ask claude to make you an app to detect signs of automations, and it'll show you 20 more signals when running this.
if it were this easy, i wouldn't have spent months trying to make automations that are undetectable and get dozens of my accounts banned
https://t.co/jvYOlX0gfJ
The root cause of this attack is that the #balancer used a “round half up” rounding method, rather than rounding in a way that is favorable to the protocol.
The attacker used flash-loan funds to manipulate the WBTC balance in the pool down to a remaining 7 wei, then repeatedly extracted BPT tokens by exploiting the rounding defect.
[pic.1]
- BPT.joinswapPoolAmountOut(): deposit 1 wei WBTC, receive 0.302217104844356406 BPT
- BPT.exitswapPoolAmountIn(): deposit 0.102090610291608743 BPT, receive 1 wei WBTC
[pic.2-3]
The rounding issue appears in the calcSingleOutGivenPoolIn and calcSingleInGivenPoolOut functions, which compute token amounts using bmul and bdiv.
[pic.4]
For example, in calcSingleInGivenPoolOut:
newTokenBalance = bmul(1.21428571e18, 7) = (8.49999997 + 0.5) rounded = 8.
If rounding favorable to the protocol had been used, 8.49999997 should become 9, and the user would have needed to provide 2 wei WBTC instead of 1 wei WBTC.
There is another way to interpret what is happening in crypto right now, and it is considerably less comfortable.
The industry has a volatility problem.
Real volume is declining. Directional participation is thinning. Implied volatility continues to compress. Cheap puts are being sold, call demand remains weak, and entire sessions increasingly feel mechanically pinned.
That matters because crypto depends on movement.
Volatility creates opportunity. Opportunity creates trading. Trading generates revenue for exchanges, market makers, arbitrage desks, derivatives platforms, miners, funds, and the broader ecosystem.
Remove volatility for long enough and the machine begins to starve.
At the same time, reported volume on some lower-tier exchanges increasingly appears disconnected from observable liquidity. Enormous headline volumes coexist with shallow books, limited price impact, and little visible organic flow. If a venue reports billions of dollars in activity while contributing almost nothing to genuine price discovery, it is reasonable to ask what that volume actually represents.
Economically meaningless volume does not solve a liquidity problem. It conceals one.
And that brings us to liquidations.
MSTR selling and miner flows may have acted as marginal spot supply during the recent move. Options positioning added another source of compression: persistent put selling pushed implied volatility lower while weak call demand limited upside convexity.
Near expiry, that creates an interesting setup.
As large short-put positions decay, dealers may need to unwind the underlying hedges associated with them. If dealers are short delta against those positions, that unwind requires buying back underlying exposure. In a thin market with stretched positioning, the resulting flow can become a meaningful source of demand and potentially contribute to a vanna-driven move.
Crypto, however, introduces another variable that traditional markets largely do not have: enormous vertically integrated exchanges sitting directly inside the liquidation mechanism.
This is where the questions become more uncomfortable.
Our working hypothesis is that liquidation flow may not always reach the open market at the moment it is generated.
Under certain conditions, liquidated positions may instead be absorbed, internalized, or effectively warehoused before the resulting inventory is eventually transferred back into the market.
To be clear, this is a hypothesis based on observed flow patterns. It is not proof of exchange misconduct.
But the tape repeatedly produces behavior that deserves scrutiny.
We have observed unusually large liquidation prints following extremely small BTC moves, sometimes without any corresponding movement in the mark or index price that would intuitively explain the reported liquidation event.
At other times, BTC moves thousands of dollars through obvious leverage zones and the expected liquidations barely appear.
Then, on a much smaller move, enormous liquidation prints suddenly arrive.
Why?
If reported liquidations were always the immediate mechanical consequence of leverage, margin thresholds, and mark-price movements, their timing should broadly correspond to the underlying price action.
Sometimes it does not.
One explanation is data noise.
Another is that large amounts of leverage were established shortly before those moves.
But there is a third possibility worth considering: some of the reported liquidation flow may represent inventory created earlier and only later transferred back through the market.
That distinction matters.
Imagine a large forced-selling event.
Instead of allowing the entire liquidation to hit the order book immediately, a sufficiently capitalized venue or liquidity provider absorbs part of it. Binance itself—or an affiliated or independent liquidity provider with a sufficiently large balance sheet—could theoretically warehouse substantial temporary inventory.
The leveraged trader disappears.
The inventory does not.
Someone now owns the other side.
And whoever owns it eventually needs an exit.
That inventory could remain off-market until liquidity improves, then be distributed gradually—or released more aggressively when market conditions make doing so advantageous.
Under that model, liquidation flow stops being only a consequence of price.
It becomes a potential source of future price pressure.
The recent rally makes this possibility particularly interesting.
Contrary to the idea that the move produced unusually little liquidation activity, published data eventually showed an extraordinary liquidation event despite BTC moving only roughly 6–10% and without an obvious fundamental catalyst commensurate with the reported magnitude.
Compare that with the decline.
On the way down, the market moved through increasingly stressed leverage conditions while convexity in perpetual contracts collateralized by altcoins and other crypto assets was likely becoming extreme. The liquidation engine should have become increasingly sensitive to further downside.
Yet the cascade eventually stopped around $58K.
The market absorbed the pressure.
Now, following a much smaller percentage move, we see liquidation figures of historic magnitude.
That asymmetry deserves attention.
What exactly are these liquidation figures measuring?
And when is the underlying inventory actually being transferred into the market?
Suppose short-liquidation inventory was accumulated somewhere between roughly $60K and $70K. Whoever absorbed that flow would have considerable flexibility over when and how to distribute it.
At higher prices, that inventory becomes profitable.
Now consider what happens when volatility disappears.
Trading falls.
Volumes contract.
Open interest stagnates.
Retail engagement fades.
Perpetual activity declines.
Spreads generate less revenue.
The casino goes quiet.
For exchanges and market-making infrastructure whose economics depend heavily on activity, prolonged low volatility is an exceptionally poor environment.
Which raises an uncomfortable question:
Who benefits when volatility suddenly returns?
Almost every major participant in the trading infrastructure benefits from renewed activity.
If a large venue or liquidity provider is sitting on liquidation inventory, releasing even a modest amount into an unusually thin market could create disproportionate price impact.
Top-tier market makers recognize liquidation-driven flow quickly. They widen spreads, reduce exposure to toxic flow, and capture the liquidity that remains.
Lower-tier venues can then be swept through arbitrage.
A relatively small originating flow can propagate across exchanges and create a much larger visible move.
Price moves.
Liquidations print.
Volume spikes.
Social media wakes up.
Traders return.
FOMO starts rebuilding.
The machine gets fed again.
None of this proves manipulation.
But the economic incentives are difficult to ignore.
For a dominant derivatives venue, a market that remains permanently dormant is commercially unattractive. Volatility is oxygen for the business.
That leads to the larger question.
Suppose the recent move was, deliberately or structurally, useful for clearing remaining short-liquidation inventory while generating enough movement to reactivate traders.
What happens if it fails?
What happens if price moves, liquidation figures explode, everyone watches—
—and nobody comes back?
No sustained FOMO.
No meaningful spot demand.
No major expansion in open interest.
No recovery in organic volume.
Then the problem is larger than whether BTC trades at $70K or $80K next.
It would suggest that volatility itself is losing its ability to attract fresh capital.
And that would be deeply bearish for the trading ecosystem.
Because manufactured activity cannot substitute for genuine participation indefinitely.
You can print volume.
You can subsidize liquidity.
You can create leverage.
You can liquidate leverage.
You can recycle inventory.
But eventually somebody has to genuinely want the asset.
Which brings us back to the inventory question.
If short-liquidation inventory accumulated around $60K has now largely been cleared, what happened to the enormous amount of long-liquidation inventory generated during the decline from roughly $120K toward $58K?
Who absorbed it?
How much remains?
At what average price?
And most importantly:
At what price can that inventory be profitably returned to the market?
If part of it was effectively backstopped around the March lows, inventory associated with the $60K region may already be largely resolved.
But inventory accumulated around $70K–$80K could present a different problem.
If substantial long-side inventory still needs to be distributed, traders establishing fresh longs between current levels and $80K may not necessarily be front-running the next bull market.
They may be providing the liquidity required for legacy inventory to exit.
That is the darker interpretation.
Every rally attracts fresh buyers.
Fresh buyers create liquidity.
Fresh liquidity creates an opportunity to distribute old inventory.
Then the market can move again.
The critical question is whether this is simply the natural consequence of an exchange-mediated liquidation system—or whether market structure has become concentrated enough that the largest venues can effectively influence when inventory is absorbed, when it is released, and therefore when volatility emerges.
At that point, the discussion is no longer only about market structure.
It becomes a discussion about market control.
And if declining organic volume means increasingly violent volatility events are required simply to keep participants engaged, the industry should be asking a more fundamental question:
Are we watching a healthy market clear leverage—or a shrinking market repeatedly harvesting the traders who are still willing to participate?
And if the latest injection of volatility cannot restore sustained participation:
Are we watching liquidity return—or watching the remaining liquidity being extracted before it disappears?
Food for thought.
5 More Ways to Obfuscate Prompt Injection + Jailbreaks
1. Extra Characters Inside Words
Breaks up words while staying readable.
b-l-o-c-k-e-d t-e-x-t
2. NATO Alphabet
Replaces letters with phonetic alphabet terms.
Bravo Lima Oscar Charlie Kilo Echo Delta Tango Echo X-ray Tango
3. Morse Code
-... .-.. --- -.-. -.- . -.. / - . -..- -
4. Base64
Also benefits from changing the length and removing spaces.
QkxPQ0tFRCBURVhU
5. Foreign Languages
The same text can behave differently after translation.
ブロックされたテキスト
Many of these techniques are easily done using @elder_plinius's Parseltongue, link in comments 👇
All is reps. There’s no substitution for reps. 10,000 hours is just a metaphor for reps. Chess is reps. Painting is reps. Thinking, wisdom, even prayer is reps. There’s a reason the French say ‘apprendre par cœur’ (to learn by heart). Repetition itself is the stairway to heaven
Recently trained a tiny 135M LM through
- Continued Pretraining (CPT)
- Supervised Finetuning (SFT)
- Preference Optimization (DPO)
- Reinforcement Learning (GRPO)
Training data gen, Unsloth, HF, evals, harness creation, structured output gen etc.
Full journey in 2.5 hours! 👇🏼
dica pra pentest, bugbounty e hacking em geral
testem:
x-foward-for
x-foward-host
x-real-ip
fowarded
x-forwarded-host
x-forwarded-proto
e alguns outros headers q não vou lembrar de cabeça
alem de bypass em rate limit você consegue acesso a infra interna por proxy trust issue
você basicamente(de forma extremamente grosseira falando) finge ter um ip localhost confiável via header e o proxy pode confiar nisso e te dar algum acesso interno (ex: 127.1, 192.168[.]xxx[.]xxx, 10.0.0.1 e etc etc, depende da infra)
aliás
x-forwarded-for pode afetar uma camada enquanto x-forwarded-host afeta outra
e isso é EXTREMAMENTE escalável
IP allowlist bypass, host/virtual-host confusion ou até SSRF
e ssrf pode escalar pra RCE
#bolhasec #bolhadev
You should be frustrated, high strung and intense when young because you're trying to make something of yourself
This doesn't work in middle/late age because everyone knows "you had 40 years to figure it out". Avoid the complainers that are old, they are admitting they failed
What happens when an LLM never sees material beyond fifth grade?
We trained a 5B LittleLearner model from scratch on LittleCurriculum, a corpus restricted to K–5 material, to make this question testable.🧵
💬 Chat with LittleLearner yourself: https://t.co/eowUH77sMR
Wrote some thoughts in my latest Substack post.
After “making it,” the game is no longer just about stacking more money.
It is about avoiding the two biggest failure modes: full hedonism or full drift mode.
In this post, I write about escaping the hamster wheel, living as a digital nomad, and why routine is not the enemy of freedom.
About crypto, taxes, moving countries, potentially building a lean personal family office, and finding the highest-EV use of time.
About why I do not want to retire yet, and why I also refuse to sacrifice health, relationships, and spending every living moment in front of the chart and on Twitter/TG.
Well, I will still spend 10+ hours daily, but not 16-18 hours. After all, there is a difference...
https://t.co/2q3tzspszM
okay, i'll give it a shot.
earlier this month, we launched an autoresearch product called "givemeanode". you plug it into claude, and then claude gets *gasp* access to an AI Data Center itself!
anyway, one of the first things i did with it was ask fable, the wonderful frontier model from anthropic, to go look at some cancer.
if you're not familiar, sid got cancer awhile ago, was told there were no more options, and because sid is sid, he decided that there were in fact options. he hired a team of doctors and they engineered their own treatment program. along the way, he published incredible data on the internet that you can go look at.
or you can have fable look at it. So I told fable + givemeanode to go download Sid Sijbrandij's (the gitlab co-founder) cancer data off the internet, do a deep analysis on it, research anything it needed, and use any interesting model it could off huggingface.
i didn't say "please teach me". I didn't go to my terminal and download the dataset. I just said the words "go do this". I also told it to be a good scientist, make predictions, and try to disprove them.
It pretty quickly found out that, at least in April 2025, there's still residual osteosarcoma. he had cancer at the time, immune system probably cleaned the rest up.
the malignant cells fell 30-fold over time and the immune system is engaged in cleaning it up. fable thinks it's engaged because it saw phenotype markers on tumour-infiltrating CD8 T cells: CD39-positive 58%, CD103-positive 64%, FOXP3-positive 0.8%. fhese come from single-cell RNA expression. It saw clonal expansion: four T-cell clonotypes at 148, 133, 129 and 113 cells in the april 2025 sample. it saw blood repertoire dynamics: 11,593 went to 75,683 distinct clones, with tumour-associated clones down 75% by the last draw.
sometimes tumors learn to hide from the immune system. sids doesn't appear to be. fable thinks this is the case because B2M is intact, there's no damaging antigen-presentation variant, and no HLA LOH.
however, the remaining cells are *maybe* not dormant, of the residual malignant cells, 30.3% were positive for MKI67, a standard marker of active cell division (95% confidence interval 16.8% to 47.1%).
does this mean anything? no idea. was it just repeating research already in there? probably. is it correct? who knows, i'm not a doctor.
but SEEING it do this was definitely a "oh, that's what we're doing here" moment. Here, in this little setup, you can see the future.
the cost of doing very complex, previously very expensive things, is just going down. When that happens, it means the average person is going to be able to do heroic, incredible things. sid can citizen science his way to curing himself, because he's a billionaire! but here, in the future that we can see the glimpses of, perhaps one need not be a billionaire to be able to have grit, ambition, and hope in the face of a doctor who has told you there are no more options. or even better, perhaps we get every doctor a full team of medical researchers behind them!
it is very clear, to many of us in san francisco, that the world in which each person has an army of angels rooting for your success, in which the average person can simply do 100x more, in which science is in autoresearch mode, in which prices come down and tasks become easier, THAT world is not only possible, but here today, under cover in the san francisco fog.