Polymarket's Rush to Grow Left a Door Wide Open for Fraudsters
Polymarket's rapid expansion has created vulnerabilities that fraudsters could exploit. Regulators have raised concerns about the platform's security and oversight practices. (wsj.com)
HellGates is a handcrafted gate-level challenge built around a custom 32-bit CPU described in VHDL, synthesized to a heavily obfuscated netlist with anti-tamper and timing checks and a bit-addressable, encrypted memory model. It was intended to be human-solvable but resistant to automation; teams and earlier LLMs spent weeks or months without success. In September 2026 GPT-6, run on SRE-Bench, recovered the CPU state and decrypted the system in under 30 minutes by exploiting a side-channel/differential analysis on the weak encryption protecting registers and memory, replaying runs after stripping obfuscation and ultimately dumping a full 1GB plaintext memory image.
Architecturally, the CPU has sixteen 32-bit general registers and special registers (overflow, condition, program counter, key modifiers, index for key modifiers, and a TEA-based pseudo-random state), a standard ALU instruction set, and memory words fixed at 64 bits so all code and data must be word-aligned. The encryption used simple, low-gate-count mixing - fake-value addition and XORs combined with a TEA state - left intentionally light to reduce logic cost; that lax design enabled differential recovery of key material. Tooling includes a custom ANTLR-based assembly (hgasm) and compiler and a CTF program with DMA and anti-tamper hooks. The takeaway: gate-level obfuscation without robust cryptography and side-channel resistance can be defeated, and powerful models can automate differential analysis.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.
Polymarket's rapid expansion has created vulnerabilities that fraudsters could exploit. Regulators have raised concerns about the platform's security and oversight practices. (wsj.com)
Windows product activation used a secret binary blob called 'Microsoft Bob' in volume licensing media to prevent unauthorized use. This key and media combination leaked early in 2001, leading to piracy and subsequent blacklisting by Microsoft. (twitter.com)
RSA-896, a challenge number, was factored on September 19, 2026, by Stephen A. Weis using Claude. The factorization reveals the prime factors p and q of the 896-bit RSA modulus. (saweis.net)
Twenty-five years after a proposed national ID system was rejected, the US has quietly moved toward a digital identity platform called Login.gov, which consolidates personal data without public debate. This system could eventually enable broad surveillance and access control across institutions without explicit legislation or public approval. (thedreydossier.substack.com)
Hugging Face experienced a security breach, but the impact was less severe than initially reported. The company clarified that the hack did not compromise sensitive data or major systems. (wsj.com)
Congress is investigating the diversion of F-35 aircraft parts to Hong Kong. The incident has raised concerns about potential security breaches involving military equipment. (politico.com)
Today's best Hacker News stories, summarized and screenshotted, one email a day.