{"@context":"https://schema.org","@type":"NewsArticle","generatedAt":"2026-07-28T06:20:51.496Z","headline":"我通过\"破解\"Paxel系统漏洞成功进入YC创业学院","description":"作者发现YC使用Paxel工具对全球10万+开发者进行评分，并成功利用其LLM代理与上传服务器之间缺少签名验证的漏洞，伪造任意评分数据上传至YC数据库。漏洞公开后数小时内，YC联合创始人Jared Friedman亲自回应并修复了问题，同时邀请作者参加今年夏天在旧金山举办的创业学院。","url":"https://www.aioga.com/news/cmrzu55j700vtrop1dwo1hjis/","mainEntityOfPage":"https://www.aioga.com/news/cmrzu55j700vtrop1dwo1hjis/","datePublished":"2026-07-25T03:39:36.081Z","dateModified":"2026-07-25T03:39:36.081Z","inLanguage":"zh-CN","publisher":{"@type":"NewsMediaOrganization","name":"Aioga","url":"https://www.aioga.com"},"citation":["https://obaid.wtf/jotbook/2026/07/18/how-i-got-into-yc-by-hacking-it.html","https://aihot.virxact.com/items/cmrzu55j700vtrop1dwo1hjis"],"canonicalUrl":"https://www.aioga.com/news/cmrzu55j700vtrop1dwo1hjis/","directAnswer":{"@type":"Answer","text":"Aioga 编辑摘要：作者发现YC使用Paxel工具对全球10万+开发者进行评分，并成功利用其LLM代理与上传服务器之间缺少签名验证的漏洞，伪造任意评分数据上传至YC数据库。 Aioga 将其归入「行业动态」方向，重点关注它对真实使用和行业竞争的影响。","url":"https://www.aioga.com/news/cmrzu55j700vtrop1dwo1hjis/","dateCreated":"2026-07-25T03:39:36.081Z","author":{"@type":"Organization","@id":"https://www.aioga.com/authors/aioga-editorial/#editorial-team","name":"Aioga Editorial Team","url":"https://www.aioga.com/authors/aioga-editorial/"}},"evidence":[{"@type":"CreativeWork","name":"obaid.wtf source article","url":"https://obaid.wtf/jotbook/2026/07/18/how-i-got-into-yc-by-hacking-it.html","datePublished":"2026-07-25T03:39:36.081Z","provider":{"@type":"Organization","name":"obaid.wtf","url":"https://obaid.wtf/jotbook/2026/07/18/how-i-got-into-yc-by-hacking-it.html"}},{"@type":"CreativeWork","name":"AIHot archive record","url":"https://aihot.virxact.com/items/cmrzu55j700vtrop1dwo1hjis","datePublished":"2026-07-25T03:39:36.081Z","provider":{"@type":"Organization","name":"AIHot","url":"https://aihot.virxact.com/items/cmrzu55j700vtrop1dwo1hjis"}}],"aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","originalPublisher":{"name":"obaid.wtf","url":"https://obaid.wtf/jotbook/2026/07/18/how-i-got-into-yc-by-hacking-it.html"},"article":{"id":"cmrzu55j700vtrop1dwo1hjis","slug":"cmrzu55j700vtrop1dwo1hjis","url":"https://www.aioga.com/news/cmrzu55j700vtrop1dwo1hjis/","title":"我通过\"破解\"Paxel系统漏洞成功进入YC创业学院","title_en":"我通过\"破解\"系统成功进入了YC创业学院","summary":"作者发现YC使用Paxel工具对全球10万+开发者进行评分，并成功利用其LLM代理与上传服务器之间缺少签名验证的漏洞，伪造任意评分数据上传至YC数据库。漏洞公开后数小时内，YC联合创始人Jared Friedman亲自回应并修复了问题，同时邀请作者参加今年夏天在旧金山举办的创业学院。","source":"Hacker News 热门（buzzing.cc 中文翻译）","sourceUrl":"https://obaid.wtf/jotbook/2026/07/18/how-i-got-into-yc-by-hacking-it.html","aiHotUrl":"https://aihot.virxact.com/items/cmrzu55j700vtrop1dwo1hjis","publishedAt":"2026-07-25T03:39:36.081Z","category":"行业动态","score":62,"selected":false,"articleBody":["tldr: I uncovered Y Combinator was scoring 100k+ founders around the world through Paxel, I broke it (possible easter egg) + found a vulnerability that let anyone forge and push any score to their ranking database, courtesy of an unvalidated hmac","Latest update: YC admirably, didn’t mind. In just a couple hours after first-public-disclosure Jared Friedman himself replied, announced the patch, and invited me to attend the Startup School in SF this summer! I’d also disclosed it in private through email 12 days earlier to no response. But publicly at least the process works.","this is a re-write of an earlier draft：/jotbook/2026/07/11/yc-startup-school-26-application-i-hacked-paxel.html where I first made the disclosure public. it was badly written, sleep-deprived and I didn’t feel good enough about it to publicize","It all started early June, when I found the application form for Startup School 26’ (referred by Dhanush: shoutout Audora S26, incredible stuff coming!!). I found that this year, YC wanted me to use something called Paxel on my computer as part of the application.","I should run a script, a very easy-to-use cURL one-liner that installed something on my computer and analyzed every line of code I’ve written with a coding agent, compile a report, and upload it to YC’s servers.","Paxel’s main site：https://paxel.ycombinator.com/ tells me the main feature is I get to “visualize” my work and get assigned fun attributes like “Which archetype are you?” and “What’s your biggest crashout?” That sounded fun.","But I wanted to know exactly how it did that, and when my curiosity starts creeping into obsessive territory it’s basically a toss-up that either ends in a legendary crash-out or doing something great. thankfully, in this case it was the latter.","I also can’t lie: I really wanted (or needed) to hack it. I knew I was starting from a disadvantage when filling out my application (no formal, ivy league education), but I knew this would be a fast-track, surefire way into confirming my acceptance. I’m not delulu, I knew it would be insane if I was able to do it, but why not go all in?","Based on Paxel’s own site, 1.2 million+ coders have so far uploaded their reports to YC. And seeing those numbers it’s honestly shocking I was the first person in the world to figure and break all of this.","As a side note before I get into it, I think the relative achievement of a “hack” in the world has diminished manyfold since agent-capable LLMs have arrived. That of course, pars with reality because of how much easier LLMs have made doing those. But I do think that ease is somewhat overestimated, both because of the many strange blindspots they have as well as the lack of a certain “hacking” or combative approach to intelligence. Whether that’s because of safety-neutering or simply the way they’re trained is a discussion for another time.","So although what they’re world-changing at is helping you go through the same material in 10x, and sometimes 50x less time (research, investigation), it is often a struggle to communicate with LLMs and keep your own mind sharp and independent when LLMs insist everything hackable is not — with near-perfectly plausible logic.","Paxel has an incredible UX, everything it does is handled from a single one-liner curl -fsSL https://paxel.ycombinator.com/upload.sh | bash . It will automatically scan your entire system, prompt you for questions, and handle the upload — you don’t have to worry about a thing after.","So the first starting point, naturally, was this install script. I first split it into 4 separate modules. When I tried breaking it in full every LLM I gave it to started hallucinating really badly (context window size increases are not perfect!)","The install script, turns out, actually didn’t run on its own. It downloaded an entire docker image hosting a ruby app, unwrapped that, and ran it locally through the docker installed on your computer. So the app is actually divided into two parts:","① ─▶ upload.sh 302KB install script. Handles auth, discovers projects, extracts git history, and initializes docker","② ─▶ the ruby app unwrapped from a docker image. it runs the actual full pipeline per-project.","And this is where I found that every piece of work you’ve done has been graded, scored, ranked by YC, and 1.2 million reports on earth’s coders have been compiled.","These are the core 5 axes the LLM grades you on and assigns a score between 1-10 with free-text notes.","And this, is also where I found the most gaping vulnerability. See, this program is a very good example of a distributed/decentralized app (not everything has be to ran and consolidated on a proprietary server).","But the thing about decentralized apps is they rely heavily on some very basic functions of cryptography. And this pipeline lacked a very, very important one.","The LLM proxy, along with each episode returns a nonce , and this nonce is shared between the LLM servers and upload server. Theoretically, this should be passed from LLM ─▶ local ─▶ POST /v1/results which validates that none other than an original LLM result is accepted by the endpoint.","What did happen though, is this nonce failed to encode a signature of the LLM’s results, scores, and notes so even though it did validate the nonce (server correctly rejected requests with invalid or missing nonce, and burnt after one use), the missing signature meant the entire episode and its score could be changed to whatever and uploaded to YC.","Not only accepted, but if I buffed the score or changed notes, the report of the same exact project differed wildly.","And I took it a step further. With the same one-liner (I love Paxel’s UX!!) I made paxel-boosted：https://paxel.obaid.wtf/, a hack that let anyone in the world upload forged reports the same by launching a mirroring tool. Self-sponsored the boosting proxy because needing to add env is terrible user experience.","For the couple hours from publicization to YC announcing the patch, over 20 of my users were able to rank themselves as the world’s top 1% in YC’s database.","two functions of basic cryptography were missing.","We could categorize all the fields accepted by /v1/results into 3 categories (two being important, one covering all others), as visualized above.","1) fields that are passed near-verbatim from LLM ─▶ /v1/results (green+blue-highlighted in the graphic above), these should have all been rolled and hashed together into the nonce as an hmac. Nonces were already validated, and this would make sure each nonce was actually tied to the LLM’s responses.","nonce = hmac(request_id) ─▶ nonce = hmac(request_id + scores.steering + scores.product_thinking + ... + title)","and this is actually the patch YC did deliver and announce, pretty much exactly as I suggested in the original draft：/jotbook/2026/07/11/yc-startup-school-26-application-i-hacked-paxel.html.","2) that are (1) passed near-verbatim from the LLM ─▶ /v1/results AND (2) also never used within the client. A subset of the fields above (green-highlighted in the diagram), these should be encrypted with any AEAD cipher (or asymmetric pub/priv keys) only the servers possess and share so the client can’t see details like the 5-axes scoring, episode title, and notes.","This one is optional and is essentially obscurity, but if it had been done from the start, I could have never known what to sniff, what to change, and it would have covered the most serious of impacts from the first vulnerability —","It’s possible that this entire “vulnerability” was a secret easter egg to find out who could hack it, or a honeypot that didn’t throw a validation error but secretly monitored who discovered and was “hacking” around it, but looking at the way this pipeline and Paxel seems to be written makes me think that’s likely not what it was.","Now, since Jared’s reply this has obviously been patched but my tool is still helpful in showing you your raw scores! Feel free to check it out：https://paxel.obaid.wtf/.","if you’ll also be in SF next week (21 jul - 6th aug) around the Startup School dates feel free to reach on Linkedin or Twitter with a tip for places, events, or people where i can find my next co-founder to build something timeline-changing with — and we can connect.","politics + systems + economics + markets + binary technologies + innovation + sciences + futbol + overton window/pop culture this is very prone to change as I add, drop more interests"],"articleImages":[{"sourceUrl":"https://obaid.wtf/assets/jared-friedman-tweet.png","alt":"Tweet from Jared Friedman (@snowmaker), replying to @wtfobaid: Impressive hacking! Sorry for all the hopefuls out there, but we have patched the bug :). Obaid - thanks for reporting the issue. Look forward to seeing you at Startup School in SF in two weeks! Posted 10:23 AM, Jul 11 2026.","afterParagraph":1,"url":"/media/articles/cmrzu55j700vtrop1dwo1hjis/d051527ae0fe4687.png"},{"sourceUrl":"https://obaid.wtf/assets/paxel-regular.png","alt":"Regular Paxel report","afterParagraph":22,"url":"/media/articles/cmrzu55j700vtrop1dwo1hjis/07b38e835f72eb70.png"},{"sourceUrl":"https://obaid.wtf/assets/paxel-boosted.png","alt":"Boosted Paxel report","afterParagraph":22,"url":"/media/articles/cmrzu55j700vtrop1dwo1hjis/2587a2fc67046b78.png"},{"sourceUrl":"https://obaid.wtf/assets/paxel-payload-map.png","alt":"LLM proxy responses vs upload payload — which fields are sealable, signable, local, or discarded","afterParagraph":25,"url":"/media/articles/cmrzu55j700vtrop1dwo1hjis/4f8835e15bf2e4fe.png"}],"mediaStatus":"ok","articleBodyZh":["简要：我发现 Y Combinator 通过 Paxel 在全球范围内为创业者评分超过 10 万美元，我破解了它（可能是复活节彩蛋）+ 发现了一个漏洞，使任何人都可以伪造并推送任意分数到他们的排名数据库，这都归咎于未验证的 hmac","最新更新：YC 值得赞赏，没有介意。在首次公开披露后的几个小时内，Jared Friedman 本人回复了邮件，宣布了补丁，并邀请我今年夏天参加旧金山的 Startup School！我也在 12 天前通过私人邮件披露过，但没有得到回应。但至少公开披露的流程有效。","这是之前草稿的重写：/jotbook/2026/07/11/yc-startup-school-26-application-i-hacked-paxel.html，我首次公开披露。那时写得很糟糕、睡眠不足，而且我觉得写得不够好而没有公开发布。","一切始于六月初，当时我发现了 Startup School 26' 的申请表（由 Dhanush 推荐：向 Audora S26 问好，精彩内容即将到来！）。我发现今年，YC 希望我在电脑上使用一个叫 Paxel 的东西，作为申请的一部分。","我应该运行一个脚本，一个非常易用的 cURL 单行命令，它会在我的电脑上安装某些东西，用一个编码代理分析我写的每一行代码，生成报告，并上传到 YC 的服务器。","Paxel 的主站：https://paxel.ycombinator.com/ 告诉我主要功能是我可以“可视化”我的工作，并分配一些有趣的属性，比如“你是哪种原型？”以及“你最大的崩溃是什么？”听起来很有趣。","但我想确切地知道它是如何做到的，当我的好奇心开始变得有些强迫时，这基本上是一个抉择，要么以传奇性的失败告终，要么做出一些伟大的事情。幸运的是，这次是后者。","我也不能撒谎：我真的很想（或者需要）破解它。我知道在填写申请时我从劣势开始（没有正式的常春藤教育背景），但我知道这是确认被接受的快速、可靠途径。我不是妄想，我知道如果我能做到会很疯狂，但为什么不全力以赴呢？","根据Paxel自己的网站，到目前为止，有超过120万编码人员已经将他们的报告上传到YC。看到这些数字，老实说，我是世界上第一个发现并破解这一切的人，这令人震惊。","在深入之前，顺便提一下，我认为自从具备代理能力的LLM（大语言模型）出现以来，在世界上“黑客”的相对成就已经大幅下降。当然，这与现实情况相符，因为LLM让这些事情变得容易得多。但我确实认为这种容易性有些被高估了，这既因为它们有许多奇怪的盲点，也因为缺乏某种“黑客”或对智能的对抗性方法。至于这是因为安全措施限制，还是仅仅因为它们的训练方式，这可以另作讨论。","所以，尽管它们在改变世界的方面是帮助你以10倍，甚至有时50倍更少的时间完成相同的材料（研究、调查），但与LLM交流往往是一种挣扎，同时在LLM坚持一切可黑的东西都不可行——并且逻辑近乎完美的时候，也要保持自己的头脑敏锐和独立。","Paxel拥有令人难以置信的用户体验，一切操作都通过这一行命令处理：curl -fsSL https://paxel.ycombinator.com/upload.sh | bash。它会自动扫描你的整个系统，提示你回答问题，并处理上传——之后你无需担心任何事情。","因此，第一个起点自然是这个安装脚本。我先把它拆分成4个独立模块。当我尝试彻底破解它时，每个我提供的LLM都开始严重出现幻觉（上下文窗口大小增加并不完美！）","事实证明，安装脚本本身实际上无法独立运行。它会下载一个托管Ruby应用程序的完整docker镜像，解压之后通过你电脑上安装的docker本地运行。因此，该应用程序实际上分为两部分：","① ─▶ upload.sh 302KB安装脚本。处理身份验证、发现项目、提取git历史记录，并初始化docker","② ─▶ 从docker镜像中解压的Ruby应用程序。每个项目运行实际的完整流程。","就在这里，我发现你所做的每一项工作都已被YC评分、打分、排名，地球上120万编码人员的报告都被汇总起来。","这些是 LLM 对你评分的核心五个轴心，并在每个轴心上给予1-10的分数，并附有自由文本备注。","而且，这也是我发现最明显漏洞的地方。你看，这个程序是一个非常好的分布式/去中心化应用的例子（不是所有东西都必须在专有服务器上运行和集中处理）。","但是去中心化应用的问题在于，它们非常依赖一些非常基础的密码学功能。而这个流程缺少了其中一个非常非常重要的功能。","LLM 代理会与每一集返回一个随机数（nonce），并且这个随机数在 LLM 服务器与上传服务器之间共享。理论上，这个随机数应该从 LLM ─▶ 本地 ─▶ POST /v1/results 传递，从而验证除了原始 LLM 结果以外，端点不接收其他任何内容。","但实际上发生的情况是，这个随机数未能对 LLM 的结果、分数和备注进行签名编码，因此即使它验证了随机数（服务器正确拒绝了无效或缺失随机数的请求，并在一次使用后销毁），缺失的签名意味着整集以及其分数可以被更改为任意内容并上传到 YC。","不只是被接受，而且如果我提高分数或更改备注，同一个项目的报告差异会非常大。","我甚至更进一步。使用同样的一行代码（我喜欢 Paxel 的 UX!!），我制作了 paxel-boosted：https://paxel.obaid.wtf/，这是一个允许世界上任何人通过启动镜像工具上传伪造报告的黑客工具。我自费支持了增强代理，因为需要添加环境变量的用户体验非常糟糕。","从公开到 YC 宣布补丁的几个小时内，我的超过20个用户能够在 YC 的数据库中将自己排名为全球前1%。","缺失了两种基本密码学功能。","我们可以将 /v1/results 接受的所有字段分为三类（两类重要，一类涵盖其他所有字段），如上图所示。","1) 从 LLM ─▶ /v1/results 几乎逐字传递的字段（在上图中以绿色+蓝色高亮显示），这些字段本应全部合并并通过 hmac 散列到随机数中。随机数已经被验证，这将确保每个随机数实际上都与 LLM 的回应绑定。","nonce = hmac(request_id) ─▶ nonce = hmac(request_id + scores.steering + scores.product_thinking + ... + title)","实际上，这就是YC确实交付并宣布的补丁，几乎完全和我在原始草稿中建议的一样：/jotbook/2026/07/11/yc-startup-school-26-application-i-hacked-paxel.html。","2) 这些字段（1）几乎是原封不动地从LLM传过来的 ─▶ /v1/results，并且（2）在客户端从未使用。上面字段的一个子集（图中绿色高亮部分），这些字段应该使用只有服务器拥有并共享的任何AEAD密码（或非对称公/私钥）加密，这样客户端就无法看到像五轴评分、剧集标题和备注等详细信息。","这个是可选的，本质上是为了模糊处理，但如果从一开始就这样做，我就根本不知道该嗅探什么、该修改什么，这可以覆盖第一次漏洞带来的最严重影响——","整个“漏洞”可能是一个秘密彩蛋，用来看看谁能破解它，或者是一个蜜罐，它没有抛出验证错误，但暗中监控谁发现并“破解”它，但看这个流程和Paxel的写法，我觉得这不太可能是它的目的。","现在，自从Jared的回复之后，这显然已经被修补，但我的工具仍然有助于显示你的原始分数！欢迎查看：https://paxel.obaid.wtf/。","如果你下周（7月21日-8月6日）也在旧金山，恰好在Startup School期间，欢迎通过Linkedin或Twitter联系我，推荐我可以找到下一位联合创始人的地方、活动或人——我们可以建立联系，一起做一些改变时间线的事情。","政治 + 系统 + 经济 + 市场 + 二进制技术 + 创新 + 科学 + 足球 + Overton窗口/流行文化，这些兴趣容易随着我增加或减少而变化"],"translationStatus":"translated","bodyOrigin":"source-page","editorial":{"summary":"Aioga 编辑摘要：作者发现YC使用Paxel工具对全球10万+开发者进行评分，并成功利用其LLM代理与上传服务器之间缺少签名验证的漏洞，伪造任意评分数据上传至YC数据库。 Aioga 将其归入「行业动态」方向，重点关注它对真实使用和行业竞争的影响。","background":"背景分析：公司与行业类动态需要放在竞争格局、商业化路径、资本信号和监管环境中观察，单条公告不能代表最终结果。","viewpoint":"Aioga 判断：这条动态更适合作为行业观察信号，当前信息足以建立线索，但不足以推导长期结论。","implications":"影响分析：对相关团队而言，短期应先核对来源、可用范围和实际成本，再判断是否值得接入或跟进。","nextStep":"后续观察：继续观察官方文件、合作落地、收入或用户信号、竞品动作和监管后续。","evidenceRefs":["title","summary","articleBody"],"confidence":"medium","status":"published","aiGenerated":false,"autoApproved":true,"generatedBy":"rule-safe-fallback","generatedAt":"2026-07-28T06:29:10.515Z","sourceHash":"79d5c24529332567","validation":{"passed":true,"mode":"rule-safe-fallback","checks":["schema","length","source-attribution","no-html"]}},"tags":["行业动态","Hacker News 热门（buzzing.cc 中文翻译）"],"translations":{"zh-CN":{"title":"我通过\"破解\"Paxel系统漏洞成功进入YC创业学院","summary":"作者发现YC使用Paxel工具对全球10万+开发者进行评分，并成功利用其LLM代理与上传服务器之间缺少签名验证的漏洞，伪造任意评分数据上传至YC数据库。漏洞公开后数小时内，YC联合创始人Jared Friedman亲自回应并修复了问题，同时邀请作者参加今年夏天在旧金山举办的创业学院。","category":"行业动态","source":"obaid.wtf","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"我通过\"破解\"Paxel系统漏洞成功进入YC创业学院 - Aioga AI资讯","description":"作者发现YC使用Paxel工具对全球10万+开发者进行评分，并成功利用其LLM代理与上传服务器之间缺少签名验证的漏洞，伪造任意评分数据上传至YC数据库。漏洞公开后数小时内，YC联合创始人Jared Friedman亲自回应并修复了问题，同时邀请作者参加今年夏天在旧金山举办的创业学院。","url":"https://www.aioga.com/news/cmrzu55j700vtrop1dwo1hjis/"},"en":{"title":"I successfully entered YC Startup School by 'exploiting' a vulnerability in the Paxel system","summary":"The author discovered that YC uses the Paxel tool to rate over 100,000 developers worldwide, and successfully exploited a vulnerability where there was no signature verification between its LLM agent and the upload server, allowing the author to forge and upload arbitrary rating data to the YC database. Within hours of the vulnerability being made public, YC co-founder Jared Friedman personally responded and fixed the issue, while also inviting the author to attend this summer's Startup School in San Francisco.","category":"Industry","source":"Hacker News 热门（buzzing.cc 中文翻译）","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"I successfully entered YC Startup School by 'exploiting' a vulnerability in the Paxel system - Aioga AI News","description":"The author discovered that YC uses the Paxel tool to rate over 100,000 developers worldwide, and successfully exploited a vulnerability where there was no signature verification be...","url":"https://www.aioga.com/en/news/cmrzu55j700vtrop1dwo1hjis/","contentTranslated":true,"sourceHash":"ff603132f43c3d6a","translatedAt":"2026-07-26T07:01:58.873Z"},"ja":{"title":"私は“Paxel”システムの脆弱性を“ハッキング”して、YC起業学院に成功裏に入りました","summary":"著者は、YCがPaxelツールを使用して世界中の10万人以上の開発者を評価していることを発見し、そのLLMエージェントとアップロードサーバー間の署名検証が欠如している脆弱性を利用して、任意の評価データを偽造しYCのデータベースにアップロードすることに成功しました。脆弱性が公開されてから数時間以内に、YCの共同創設者Jared Friedmanが個人的に対応して問題を修正し、同時に著者を今年の夏にサンフランシスコで開催される起業学院に招待しました。","category":"業界動向","source":"Hacker News 热门（buzzing.cc 中文翻译）","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"私は“Paxel”システムの脆弱性を“ハッキング”して、YC起業学院に成功裏に入りました - Aioga AIニュース","description":"著者は、YCがPaxelツールを使用して世界中の10万人以上の開発者を評価していることを発見し、そのLLMエージェントとアップロードサーバー間の署名検証が欠如している脆弱性を利用して、任意の評価データを偽造しYCのデータベースにアップロードすることに成功しました。脆弱性が公開されてから数時間以内に、YCの共同創設者Jared Friedmanが個人的に対応し...","url":"https://www.aioga.com/ja/news/cmrzu55j700vtrop1dwo1hjis/","contentTranslated":true,"sourceHash":"ff603132f43c3d6a","translatedAt":"2026-07-26T07:02:13.666Z"},"ko":{"title":"나는 'Paxel' 시스템의 취약점을 이용해 YC 창업 아카데미에 성공적으로 들어갔다","summary":"저자는 YC가 Paxel 도구를 사용하여 전 세계 10만 명 이상의 개발자를 평가하고 있으며, LLM 에이전트와 업로드 서버 간 서명 검증이 누락된 취약점을 성공적으로 이용해 임의의 평가 데이터를 YC 데이터베이스에 업로드했음을 발견했습니다. 취약점이 공개된 지 몇 시간 만에 YC 공동 창립자 Jared Friedman이 직접 대응하고 문제를 수정했으며, 동시에 저자를 올해 여름 샌프란시스코에서 열리는 창업 아카데미에 초청했습니다.","category":"업계 동향","source":"Hacker News 热门（buzzing.cc 中文翻译）","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"나는 'Paxel' 시스템의 취약점을 이용해 YC 창업 아카데미에 성공적으로 들어갔다 - Aioga AI 뉴스","description":"저자는 YC가 Paxel 도구를 사용하여 전 세계 10만 명 이상의 개발자를 평가하고 있으며, LLM 에이전트와 업로드 서버 간 서명 검증이 누락된 취약점을 성공적으로 이용해 임의의 평가 데이터를 YC 데이터베이스에 업로드했음을 발견했습니다. 취약점이 공개된 지 몇 시간 만에 YC 공동 창립자 Jared Friedman이...","url":"https://www.aioga.com/ko/news/cmrzu55j700vtrop1dwo1hjis/","contentTranslated":true,"sourceHash":"ff603132f43c3d6a","translatedAt":"2026-07-26T07:02:58.936Z"},"es":{"title":"He accedido con éxito al YC Startup Academy mediante la explotación de una vulnerabilidad en el sistema Paxel","summary":"El autor descubrió que YC utilizaba la herramienta Paxel para calificar a más de 100,000 desarrolladores en todo el mundo, y logró aprovechar exitosamente la vulnerabilidad de falta de verificación de firmas entre su agente LLM y el servidor de subida, falsificando datos de calificación arbitrarios y subiéndolos a la base de datos de YC. Horas después de que se hiciera pública la vulnerabilidad, el cofundador de YC, Jared Friedman, respondió personalmente y solucionó el problema, al mismo tiempo que invitó al autor a participar en la Academia de Startups que se celebrará este verano en San Francisco.","category":"Industria","source":"Hacker News 热门（buzzing.cc 中文翻译）","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"He accedido con éxito al YC Startup Academy mediante la explotación de una vulnerabilidad en el sistema Paxel - Aioga Noticias de IA","description":"El autor descubrió que YC utilizaba la herramienta Paxel para calificar a más de 100,000 desarrolladores en todo el mundo, y logró aprovechar exitosamente la vulnerabilidad de falt...","url":"https://www.aioga.com/es/news/cmrzu55j700vtrop1dwo1hjis/","contentTranslated":true,"sourceHash":"ff603132f43c3d6a","translatedAt":"2026-07-26T07:02:52.423Z"},"fr":{"title":"J'ai réussi à entrer à YC Startup School en exploitant une faille du système Paxel","summary":"L'auteur a découvert que YC utilise l'outil Paxel pour évaluer plus de 100 000 développeurs dans le monde, et a réussi à exploiter la vulnérabilité due au manque de vérification de signature entre son agent LLM et le serveur de téléchargement, en falsifiant n'importe quelles données de notation et en les téléversant dans la base de données de YC. Quelques heures après la divulgation de la vulnérabilité, le cofondateur de YC, Jared Friedman, a personnellement répondu et corrigé le problème, tout en invitant l'auteur à participer à l'Académie des start-ups qui se tiendra cet été à San Francisco.","category":"Industrie","source":"Hacker News 热门（buzzing.cc 中文翻译）","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"J'ai réussi à entrer à YC Startup School en exploitant une faille du système Paxel - Aioga Actualités IA","description":"L'auteur a découvert que YC utilise l'outil Paxel pour évaluer plus de 100 000 développeurs dans le monde, et a réussi à exploiter la vulnérabilité due au manque de vérification de...","url":"https://www.aioga.com/fr/news/cmrzu55j700vtrop1dwo1hjis/","contentTranslated":true,"sourceHash":"ff603132f43c3d6a","translatedAt":"2026-07-26T07:03:43.719Z"},"de":{"title":"Ich habe erfolgreich durch das 'Knacken' einer Sicherheitslücke im Paxel-System Zugang zur YC Startup Academy erhalten.","summary":"Der Autor stellte fest, dass YC das Paxel-Tool verwendet, um über 100.000 Entwickler weltweit zu bewerten, und dass er erfolgreich eine Sicherheitslücke ausnutzte, bei der zwischen seinem LLM-Agenten und dem Upload-Server die Signaturüberprüfung fehlte, um beliebige Bewertungsdaten in die YC-Datenbank hochzuladen. Innerhalb weniger Stunden nach der Offenlegung der Sicherheitslücke reagierte YCs Mitgründer Jared Friedman persönlich und behob das Problem, während er gleichzeitig den Autor einlud, an der diesjährigen Startup-Schule im Sommer in San Francisco teilzunehmen.","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译）","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"Ich habe erfolgreich durch das 'Knacken' einer Sicherheitslücke im Paxel-System Zugang zur YC Startup Academy erhalten. - Aioga KI-News","description":"Der Autor stellte fest, dass YC das Paxel-Tool verwendet, um über 100.000 Entwickler weltweit zu bewerten, und dass er erfolgreich eine Sicherheitslücke ausnutzte, bei der zwischen...","url":"https://www.aioga.com/de/news/cmrzu55j700vtrop1dwo1hjis/","contentTranslated":true,"sourceHash":"ff603132f43c3d6a","translatedAt":"2026-07-26T07:03:41.533Z"},"pt-BR":{"title":"Eu entrei com sucesso na YC Startup School explorando a vulnerabilidade do sistema Paxel","summary":"O autor descobriu que a YC usava a ferramenta Paxel para avaliar mais de 100 mil desenvolvedores em todo o mundo, e conseguiu explorar com sucesso a vulnerabilidade de falta de verificação de assinatura entre seu agente LLM e o servidor de upload, falsificando dados de avaliação arbitrários para enviar ao banco de dados da YC. Algumas horas após a divulgação da vulnerabilidade, o cofundador da YC, Jared Friedman, respondeu pessoalmente e corrigiu o problema, além de convidar o autor para participar da Escola de Startups deste verão em San Francisco.","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译）","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"Eu entrei com sucesso na YC Startup School explorando a vulnerabilidade do sistema Paxel - Aioga Notícias de IA","description":"O autor descobriu que a YC usava a ferramenta Paxel para avaliar mais de 100 mil desenvolvedores em todo o mundo, e conseguiu explorar com sucesso a vulnerabilidade de falta de ver...","url":"https://www.aioga.com/pt-BR/news/cmrzu55j700vtrop1dwo1hjis/","contentTranslated":true,"sourceHash":"ff603132f43c3d6a","translatedAt":"2026-07-26T07:04:21.182Z"},"ru":{"title":"Я успешно вошёл в YC стартап-академию, воспользовавшись уязвимостью системы Paxel","summary":"Автор обнаружил, что YC использует инструмент Paxel для оценки более 100 000 разработчиков по всему миру и успешно воспользовался уязвимостью отсутствия проверки подписи между LLM-агентом и загружаемым сервером, подделав любые данные оценки и загрузив их в базу данных YC. Через несколько часов после публикации уязвимости соучредитель YC Джаред Фридман лично отреагировал и устранил проблему, при этом пригласив автора принять участие в Летней академии стартапов, которая пройдет этим летом в Сан-Франциско.","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译）","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"Я успешно вошёл в YC стартап-академию, воспользовавшись уязвимостью системы Paxel - Aioga Новости ИИ","description":"Автор обнаружил, что YC использует инструмент Paxel для оценки более 100 000 разработчиков по всему миру и успешно воспользовался уязвимостью отсутствия проверки подписи между LLM-...","url":"https://www.aioga.com/ru/news/cmrzu55j700vtrop1dwo1hjis/","contentTranslated":true,"sourceHash":"ff603132f43c3d6a","translatedAt":"2026-07-26T07:04:28.413Z"},"ar":{"title":"لقد تمكنت من الدخول بنجاح إلى أكاديمية YC لريادة الأعمال من خلال استغلال ثغرات نظام Paxel","summary":"اكتشف المؤلف أن YC يستخدم أداة Paxel لتقييم أكثر من 100000 مطور حول العالم، وأنه نجح في استغلال الثغرة الناتجة عن عدم وجود تحقق من التوقيع بين وكيل LLM الخاص به وخادم التحميل، لتزوير أي بيانات تقييم وتحميلها إلى قاعدة بيانات YC. بعد ساعات من كشف الثغرة، قام جاريد فريدمان، المؤسس المشارك لـ YC، بالرد شخصيًا وإصلاح المشكلة، وفي الوقت نفسه دعا المؤلف للمشاركة في أكاديمية ريادة الأعمال التي ستقام هذا الصيف في سان فرانسيسكو.","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译）","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"لقد تمكنت من الدخول بنجاح إلى أكاديمية YC لريادة الأعمال من خلال استغلال ثغرات نظام Paxel - Aioga أخبار الذكاء الاصطناعي","description":"اكتشف المؤلف أن YC يستخدم أداة Paxel لتقييم أكثر من 100000 مطور حول العالم، وأنه نجح في استغلال الثغرة الناتجة عن عدم وجود تحقق من التوقيع بين وكيل LLM الخاص به وخادم التحميل، لتزو...","url":"https://www.aioga.com/ar/news/cmrzu55j700vtrop1dwo1hjis/","contentTranslated":true,"sourceHash":"ff603132f43c3d6a","translatedAt":"2026-07-26T07:05:16.021Z"},"hi":{"title":"मैंने 'Paxel' सिस्टम की कमजोरियों का फायदा उठाकर YC स्टार्टअप अकादमी में सफलतापूर्वक प्रवेश किया","summary":"लेखक ने पाया कि YC Paxel उपकरण का उपयोग करके दुनिया भर के 1 लाख से अधिक डेवलपर्स का मूल्यांकन करता है, और सफलतापूर्वक इसके LLM एजेंट और अपलोड सर्वर के बीच हस्ताक्षर सत्यापन की कमी का उपयोग करके मनमाने मूल्यांकन डेटा को YC डेटाबेस में अपलोड किया।漏洞 सार्वजनिक होने के कुछ ही घंटों में, YC के सह-संस्थापक जारेड फ्राइडमन ने व्यक्तिगत रूप से प्रतिक्रिया दी और समस्या को ठीक किया, साथ ही लेखक को इस गर्मी में सैन फ्रांसिस्को में आयोजित होने वाले स्टार्टअप अकादमी में भाग लेने के लिए आमंत्रित किया।","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译）","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"मैंने 'Paxel' सिस्टम की कमजोरियों का फायदा उठाकर YC स्टार्टअप अकादमी में सफलतापूर्वक प्रवेश किया - Aioga AI समाचार","description":"लेखक ने पाया कि YC Paxel उपकरण का उपयोग करके दुनिया भर के 1 लाख से अधिक डेवलपर्स का मूल्यांकन करता है, और सफलतापूर्वक इसके LLM एजेंट और अपलोड सर्वर के बीच हस्ताक्षर सत्यापन की कमी...","url":"https://www.aioga.com/hi/news/cmrzu55j700vtrop1dwo1hjis/","contentTranslated":true,"sourceHash":"ff603132f43c3d6a","translatedAt":"2026-07-26T07:05:07.976Z"},"it":{"title":"Ho penetrato con successo nel YC Entrepreneurship Academy sfruttando una falla del sistema Paxel","summary":"L'autore ha scoperto che YC utilizza lo strumento Paxel per valutare oltre 100.000 sviluppatori in tutto il mondo, ed è riuscito a sfruttare la vulnerabilità della mancanza di verifica della firma tra il suo agente LLM e il server di caricamento, falsificando dati di valutazione da caricare nel database di YC. Poche ore dopo la divulgazione della vulnerabilità, il cofondatore di YC, Jared Friedman, ha risposto personalmente e ha risolto il problema, invitando al contempo l'autore a partecipare alla Startup School che si terrà quest'estate a San Francisco.","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译）","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"Ho penetrato con successo nel YC Entrepreneurship Academy sfruttando una falla del sistema Paxel - Aioga Notizie IA","description":"L'autore ha scoperto che YC utilizza lo strumento Paxel per valutare oltre 100.000 sviluppatori in tutto il mondo, ed è riuscito a sfruttare la vulnerabilità della mancanza di veri...","url":"https://www.aioga.com/it/news/cmrzu55j700vtrop1dwo1hjis/","contentTranslated":true,"sourceHash":"ff603132f43c3d6a","translatedAt":"2026-07-26T07:05:57.330Z"},"nl":{"title":"Ik ben via het 'kraken' van de kwetsbaarheid in het Paxel-systeem succesvol het YC Startup College binnengekomen","summary":"De auteur ontdekte dat YC de Paxel-tool gebruikte om meer dan 100.000 ontwikkelaars wereldwijd te beoordelen en slaagde erin het lek te misbruiken waarbij de LLM-agent en de uploadserver geen handtekeningverificatie hadden, waardoor het mogelijk was om willekeurige beoordelingsgegevens te vervalsen en naar de YC-database te uploaden. Enkele uren nadat het lek openbaar werd, reageerde YC-medeoprichter Jared Friedman persoonlijk en loste het probleem op, terwijl hij de auteur uitnodigde om deel te nemen aan de Launch School die deze zomer in San Francisco wordt gehouden.","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译）","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"Ik ben via het 'kraken' van de kwetsbaarheid in het Paxel-systeem succesvol het YC Startup College binnengekomen - Aioga AI-nieuws","description":"De auteur ontdekte dat YC de Paxel-tool gebruikte om meer dan 100.000 ontwikkelaars wereldwijd te beoordelen en slaagde erin het lek te misbruiken waarbij de LLM-agent en de upload...","url":"https://www.aioga.com/nl/news/cmrzu55j700vtrop1dwo1hjis/","contentTranslated":true,"sourceHash":"ff603132f43c3d6a","translatedAt":"2026-07-26T07:05:57.274Z"},"tr":{"title":"Ben 'Paxel' sistem açığını kırarak başarıyla YC Girişimcilik Akademisi'ne girdim","summary":"Yazar, YC'nin Paxel aracını kullanarak dünya çapında 100.000'den fazla geliştiriciyi puanladığını ve LLM ajanı ile yükleme sunucusu arasındaki imza doğrulama eksikliğini kullanarak rastgele puan verilerini YC veritabanına yüklemeyi başardığını keşfetti. Açığın açıklanmasından birkaç saat içinde, YC'nin kurucu ortağı Jared Friedman bizzat yanıt verdi ve sorunu düzeltti, ayrıca yazarı bu yaz San Francisco'da düzenlenecek girişimcilik akademisine davet etti.","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译）","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"Ben 'Paxel' sistem açığını kırarak başarıyla YC Girişimcilik Akademisi'ne girdim - Aioga AI Haberleri","description":"Yazar, YC'nin Paxel aracını kullanarak dünya çapında 100.000'den fazla geliştiriciyi puanladığını ve LLM ajanı ile yükleme sunucusu arasındaki imza doğrulama eksikliğini kullanarak...","url":"https://www.aioga.com/tr/news/cmrzu55j700vtrop1dwo1hjis/","contentTranslated":true,"sourceHash":"ff603132f43c3d6a","translatedAt":"2026-07-26T07:06:38.253Z"},"vi":{"title":"Tôi đã xâm nhập thành công Học viện Khởi nghiệp YC thông qua việc khai thác lỗ hổng hệ thống Paxel","summary":"Tác giả phát hiện YC sử dụng công cụ Paxel để đánh giá hơn 100.000 nhà phát triển trên toàn cầu, và thành công khai thác lỗ hổng thiếu xác thực chữ ký giữa đại lý LLM của họ và máy chủ tải lên, giả mạo dữ liệu đánh giá tùy ý để tải lên cơ sở dữ liệu của YC. Vài giờ sau khi lỗ hổng được công khai, đồng sáng lập YC, Jared Friedman, đã trực tiếp phản hồi và sửa chữa vấn đề, đồng thời mời tác giả tham gia Học viện Khởi nghiệp được tổ chức tại San Francisco mùa hè này.","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译）","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"Tôi đã xâm nhập thành công Học viện Khởi nghiệp YC thông qua việc khai thác lỗ hổng hệ thống Paxel - Tin tức AI Aioga","description":"Tác giả phát hiện YC sử dụng công cụ Paxel để đánh giá hơn 100.000 nhà phát triển trên toàn cầu, và thành công khai thác lỗ hổng thiếu xác thực chữ ký giữa đại lý LLM của họ và máy...","url":"https://www.aioga.com/vi/news/cmrzu55j700vtrop1dwo1hjis/","contentTranslated":true,"sourceHash":"ff603132f43c3d6a","translatedAt":"2026-07-26T07:06:40.049Z"},"id":{"title":"Saya berhasil masuk ke YC Entrepreneurship Academy melalui 'membobol' celah sistem Paxel","summary":"Penulis menemukan bahwa YC menggunakan alat Paxel untuk memberi penilaian terhadap lebih dari 100.000 pengembang di seluruh dunia, dan berhasil memanfaatkan celah di mana agen LLM mereka dan server unggah tidak memiliki verifikasi tanda tangan, sehingga dapat memalsukan data penilaian apa pun dan mengunggahnya ke basis data YC. Beberapa jam setelah celah ini dipublikasikan, salah satu pendiri YC, Jared Friedman, secara pribadi menanggapi dan memperbaiki masalah tersebut, sekaligus mengundang penulis untuk menghadiri Akademi Startup yang akan diadakan musim panas ini di San Francisco.","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译）","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"Saya berhasil masuk ke YC Entrepreneurship Academy melalui 'membobol' celah sistem Paxel - Berita AI Aioga","description":"Penulis menemukan bahwa YC menggunakan alat Paxel untuk memberi penilaian terhadap lebih dari 100.000 pengembang di seluruh dunia, dan berhasil memanfaatkan celah di mana agen LLM...","url":"https://www.aioga.com/id/news/cmrzu55j700vtrop1dwo1hjis/","contentTranslated":true,"sourceHash":"ff603132f43c3d6a","translatedAt":"2026-07-26T07:07:24.199Z"},"th":{"title":"ฉันผ่านการ 'เจาะ' ช่องโหว่ของระบบ Paxel จนสามารถเข้าร่วม YC Startup School ได้สำเร็จ","summary":"ผู้เขียนค้นพบว่า YC ใช้เครื่องมือ Paxel ในการให้คะแนนนักพัฒนากว่า 100,000 คนทั่วโลก และประสบความสำเร็จในการใช้ LLM agent ของตนเองในการหาช่องโหว่ที่ขาดการตรวจสอบลายเซ็นระหว่างตัวแทนและเซิร์ฟเวอร์อัปโหลด ทำให้สามารถปลอมแปลงข้อมูลคะแนนใด ๆ และอัปโหลดไปยังฐานข้อมูลของ YC ได้ หลังจากช่องโหว่ถูกเผยแพร่ไม่กี่ชั่วโมง ผู้ร่วมก่อตั้งของ YC Jared Friedman ตอบกลับด้วยตัวเองและแก้ไขปัญหา พร้อมทั้งเชิญผู้เขียนเข้าร่วมวิทยาลัยผู้ประกอบการที่จัดขึ้นในซานฟรานซิสโกในช่วงฤดูร้อนปีนี้","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译）","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"ฉันผ่านการ 'เจาะ' ช่องโหว่ของระบบ Paxel จนสามารถเข้าร่วม YC Startup School ได้สำเร็จ - ข่าว AI Aioga","description":"ผู้เขียนค้นพบว่า YC ใช้เครื่องมือ Paxel ในการให้คะแนนนักพัฒนากว่า 100,000 คนทั่วโลก และประสบความสำเร็จในการใช้ LLM agent ของตนเองในการหาช่องโหว่ที่ขาดการตรวจสอบลายเซ็นระหว่างตัวแทน...","url":"https://www.aioga.com/th/news/cmrzu55j700vtrop1dwo1hjis/","contentTranslated":true,"sourceHash":"ff603132f43c3d6a","translatedAt":"2026-07-26T07:07:30.960Z"},"pl":{"title":"Udało mi się wejść do YC Startup School, korzystając z luki w systemie Paxel.","summary":"Autor odkrył, że YC używa narzędzia Paxel do oceniania ponad 100 000 deweloperów na całym świecie, i skutecznie wykorzystał lukę polegającą na braku weryfikacji podpisu między agentem LLM a serwerem przesyłającym, aby sfałszować dowolne dane ocen i przesłać je do bazy danych YC. Kilka godzin po ujawnieniu luki, współzałożyciel YC Jared Friedman osobiście odpowiedział i naprawił problem, jednocześnie zapraszając autora do udziału w Akademii Startupów, która odbędzie się tego lata w San Francisco.","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译）","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"Udało mi się wejść do YC Startup School, korzystając z luki w systemie Paxel. - Aioga Wiadomości AI","description":"Autor odkrył, że YC używa narzędzia Paxel do oceniania ponad 100 000 deweloperów na całym świecie, i skutecznie wykorzystał lukę polegającą na braku weryfikacji podpisu między agen...","url":"https://www.aioga.com/pl/news/cmrzu55j700vtrop1dwo1hjis/","contentTranslated":true,"sourceHash":"ff603132f43c3d6a","translatedAt":"2026-07-26T07:08:20.297Z"}}}}