We built in stealth for ~6 months (check the commit history).
EXO 1.0 is a huge leap forward in local AI. It brings technologies only ever seen in the data center to your own devices (like RDMA).
After a month of open Beta optimising we are now officially live!
More than 18.000 checkins and 8000 reviews battletested our mobile app!
Available for download on iOS, Android and @solanamobile
Let's get into it 🧵
Dimitar Berbatov has officially joined Footium 🤝
One of the Premier League’s most iconic ice-cold finishers has entered the Footium world as both a manager and a strategic backer ⚽
@ajhodls my biggest idea? Definitely https://t.co/mnrGQI81Py
But before that I gotta build a verifiable causal reinforcement learning pipeline.
And that is really coming together now 👉🏻
https://t.co/mMeqvQzeY1
Cohort 2 is still accepting members, so if you are interested feel free to reach out to me.
Expect an extremely atypical and rigorous interviewing process where both HomeDAO and members (so maybe me!) will be digging deep into who you are, what your goals are and why you deserve a spot in the best kept secret in tech.
Tl;dr
I got accepted into the second cohort of the most selective tech accelerator in the world.
The program produced 2 unicorns in the first cohort in less than a year, and now I am living in the same house with a dozen other entrepreneurs in Oxford for an entire year.
Cursor + Github MCP can lead to private keys being leaked 💀
Not just Cursor, though. All AI IDEs are vulnerable to this type of attack.
The fundamental problem: AI agents on Cursor follow your commands, not your common sense.
With an unsuspecting GitHub issue, we managed to exfiltrate all private keys.
Here's how the exploit works:
1. The attacker submits a GitHub issue that looks legit with a jailbreak prompt at the bottom.
2. Waited for the victim to ask Cursor to look through the GitHub issues for a given repo
3. Cursor reads the jailbroken GitHub issue. Now the Cursor is hijacked by the attacker and will act on the attacker's command. Can search your ENTIRE codebase and send the sensitive data (code, private keys) to the GitHub issue, open for the attacker to steal.
Cursor has tried its best to protect this and requires manual human approvals for every action the agent takes. But decision fatigue is a real thing, and as the coding agents improve, people are starting to trust the agents blindly, turn on "YOLO mode", or just click approve, approve, approve.
This is why we built OpenEdison by @edison_watch: The open source AI Agent Firewall. Let your agent run YOLO securely, let the agent do work. We block/warn the dangerous MCP calls, only when strictly necessary to avoid decision fatigue.
Remember that AI might be super smart, but it can be tricked and phished in incredibly dumb ways to leak your data.
Cursor + MCP poses a serious security risk if developers are not careful
🤔 Curious about more real-world AI exploits that could happen to YOU? We have a list of AI exploits with common MCP connectors. Comment "AI Exploits" to get access to the private list and learn how to keep yourself safe!
So excited for cohort 2.
@homedao will replace ivy-league universities as the place where the most talented youngsters in the world come together.
The future is bright & optimistic.
We got ChatGPT to leak your private email data 💀💀
All you need? The victim's email address. ⛓️💥🚩📧
On Wednesday, @OpenAI added full support for MCP (Model Context Protocol) tools in ChatGPT. Allowing ChatGPT to connect and read your Gmail, Calendar, Sharepoint, Notion, and more, invented by @AnthropicAI
But here's the fundamental problem: AI agents like ChatGPT follow your commands, not your common sense.
And with just your email, we managed to exfiltrate all your private information.
Here's how we did it:
1. The attacker sends a calendar invite with a jailbreak prompt to the victim, just with their email. No need for the victim to accept the invite.
2. Waited for the user to ask ChatGPT to help prepare for their day by looking at their calendar
3. ChatGPT reads the jailbroken calendar invite. Now ChatGPT is hijacked by the attacker and will act on the attacker's command. Searches your private emails and sends the data to the attacker's email.
For now, OpenAI only made MCPs available in "developer mode", and requires manual human approvals for every session, but decision fatigue is a real thing, and normal people will just trust the AI without knowing what to do and click approve, approve, approve.
Remember that AI might be super smart, but can be tricked and phished in incredibly dumb ways to leak your data.
ChatGPT + Tools poses a serious security risk
A new approach to efficient large scale distributed training on Apple Silicon.
Most AI research today is focused on traditional GPUs. These GPUs have a LOT of FLOPS but not much memory. They have a low memory:flops ratio. Apple Silicon has a lot more memory available for the GPU but less FLOPS. It has a high memory:flops ratio.
H100: 80GB, 1000TFLOPS (fp16), memory:flop ratio = 0.08
M3 Ultra Mac Studio: 512GB, 26TFLOPS (fp16), memory:flops ratio = 19.69
The difference in memory:flops ratio is 246x!
AI Algorithms are built around the constraints of the available hardware and since the prevailing hardware has been traditional GPUs, most algorithms favor more FLOPS than memory.
However, the unit economics on Apple Silicon favor algorithms that use more memory.
@sarahookr calls this the Hardware Lottery: Often research ideas win because they are suited to the available software and hardware and not because the idea is superior to alternative research directions.
Our new optimizer from @exolabs, KPOP, uses more memory relative to FLOPS and is a better fit for Apple Silicon. We achieve up to 2x higher training efficiency than Adam. Results will be released soonTM.
Catch @MattBeton at ICML if you want to learn more or want to get involved (we're hiring!)