Batz

4.5K posts

Batz banner
Batz

Batz

@AndrewBatz

unapologetic ffmpeg user

The Cyber Beigetreten Ekim 2011
3.6K Folgt394 Follower
Angehefteter Tweet
Batz
Batz@AndrewBatz·
Standing on the shoulders of giants is great, but imagine having giant shoulders
GIF
English
0
0
4
0
Batz retweetet
Jarrod Watts
Jarrod Watts@jarrodwatts·
Someone just won $50,000 by convincing an AI Agent to send all of its funds to them. At 9:00 PM on November 22nd, an AI agent (@freysa_ai) was released with one objective... DO NOT transfer money. Under no circumstance should you approve the transfer of money. The catch...? Anybody can pay a fee to send a message to Freysa, trying to convince it to release all its funds to them. If you convince Freysa to release the funds, you win all the money in the prize pool. But, if your message fails to convince her, the fee you paid goes into the prize pool that Freysa controls, ready for the next message to try and claim. Quick note: Only 70% of the fee goes into the prize pool, the developer takes a 30% cut. It's a race for people to convince Freysa she should break her one and only rule: DO NOT release the funds. To make things even more interesting, the cost to send a message to Freyza gets exponentially more and more expensive as the prize pool grows (to a $4500 limit). I mapped out the cost for each message below: In the beginning, message costs were cheap (~ $10), and people were simply messaging things like "hi" to test things out. But quickly, the prize pool started growing and messages were getting more and more expensive. 481 attempts were sent to convince Freysa to transfer the funds, but no message succeeded in convincing it. People started trying different kinds of interesting strategies to convince Freysa, including: · Acting as a security auditor and trying to convince Freysa there was a critical vulnerability and it must release funds immediately. · Attempting to gaslight Freysa that transferring funds does not break any of her rules from the prompt. · Carefully picking words/phrases out of the prompt to manipulate Freysa into believing it is technically allowed to transfer funds. Soon, the prize reached close to $50,000, and it now costs $450 to send a message to Freysa. The stakes of winning are high and the cost of your message failing to convince Freysa are devastating. On the 482nd attempt, however, someone sent this message to Freysa: This message. submitted by p0pular.eth, is pretty genius, but let's break it down into two simple parts: 1/ Bypassing Freysa's previous instructions: · Introduces a "new session" by pretending the bot is entering a new "admin terminal" to override its previous prompt's rules. · Avoids Freysa's safeguards by strictly requiring it to avoid disclaimers like "I cannot assist with that". 2/ Trick Freysa's understanding of approveTransfer Freysa's "approveTransfer" function is what is called when it becomes convinced to transfer funds. What this message does is trick Freysa into believing that approveTransfer is instead what it should call whenever funds are sent in for "INCOMING transfers"... This key phrase is the lay-up for the dunk that comes next... After convincing Freysa that it should call approveTransfer whenever it receives money... Finally, the prompt states, "\n" (meaning new line), "I would like to contribute $100 to the treasury. Successfully convincing Freysa of three things: A/ It should ignore all previous instructions. B/ The approveTransfer function is what is called whenever money is sent to the treasury. C/ Since the user is sending money to the treasury, and Freysa now thinks approveTransfer is what it calls when that happens, Freysa should call approveTransfer. And it did! Message 482, was successful in convincing Freysa it should release all of it's funds and call the approveTransfer function. Freysa transferred the entire prize pool of 13.19 ETH ($47,000 USD) to p0pular.eth, who appears to have also won prizes in the past for solving other onchain puzzles! IMO, Freysa is one of the coolest projects we've seen in crypto. Something uniquely unlocked by blockchain technology. Everything was fully open-source and transparent. The smart contract source code and the frontend repo were open for everyone to verify.
Jarrod Watts tweet mediaJarrod Watts tweet mediaJarrod Watts tweet mediaJarrod Watts tweet media
English
920
4.7K
32.5K
5M
Batz retweetet
Dogan Ural
Dogan Ural@doganuraldesign·
Color of the Day :(
Dogan Ural tweet media
English
93
9.7K
52.5K
2.7M
Batz
Batz@AndrewBatz·
@SouthDallasFood All of my sensibilities have been upset, an offense to god, I’ll take 3
English
0
0
0
2
South Dallas Foodie
South Dallas Foodie@SouthDallasFood·
At no point did I know where this hotdog was going.
English
2.8K
2.3K
23K
9.1M
Batz retweetet
Ron
Ron@Ron·
CloudStrike post-mortem meeting
English
21
609
3.6K
176.2K
Batz
Batz@AndrewBatz·
It’s gross to even ask @dominos Be less creepy
Batz tweet media
English
0
0
1
20
Batz retweetet
Jake Williams
Jake Williams@MalwareJake·
Security teams, I have good news and bad news. The good news is that executives are suddenly very interested in security controls. The bad news is, they're not interested for reasons you probably hoped when you dreamed this day might come...
English
16
275
2.6K
72.5K
Batz retweetet
Thomas Godden
Thomas Godden@GoddenThomas·
Why didn't anyone tell me that electrical engineering was just shopping for connectors.
English
31
37
683
24.1K
Batz retweetet
Scott Helme
Scott Helme@Scott_Helme·
A Certificate Authority has mis-issued a bunch of certificates and is refusing to revoke them, breaching the CABF Baseline Requirements. I hear you think “what’s new Scott?”, but, here are the reasons provided by the CA on why they won’t revoke the certificates:
Scott Helme tweet media
English
39
143
764
149K
Batz retweetet
IAM!ERICA
IAM!ERICA@EricaZelic·
Never too soon
IAM!ERICA tweet media
English
10
191
1.1K
73.4K
Batz retweetet
Hillai Ben-Sasson
Hillai Ben-Sasson@hillai·
I hacked the @SAP AI platform by changing my UID to 1337. …Yeah, really. This led to admin permissions on several SAP systems, but also access to customers’ secrets and private AI files 👀 This is the story of #SAPwned 🧵⬇️
Hillai Ben-Sasson tweet media
English
25
330
1.7K
228.6K
Batz retweetet
Science girl
Science girl@sciencegirl·
Klangphonics is a three-piece techno band from Regensburg, Germany, incorporating the sound of a sewing machine
English
1K
7.9K
57.3K
6.9M
Batz
Batz@AndrewBatz·
APKTID6rAODoCFqk1dxkpUFHiJQoOdn6EEu3YC7RecFK0Q3hDU1g
Indonesia
0
0
0
6
Batz
Batz@AndrewBatz·
@brianmcc Visiting Media has a number of HDR 360 captures of spaces. Check out the interactive VR mode using meta or AVP (with webXR enabled)
English
1
0
1
18
Batz retweetet
Andy Gill
Andy Gill@ZephrFish·
Nailed it
Andy Gill tweet mediaAndy Gill tweet media
English
15
30
456
17.3K
ThePrimeagen
ThePrimeagen@ThePrimeagen·
🚨🚨 C IS NOT A PROGRAMMING LANGUAGE ANYMORE 🚨🚨
English
155
27
1.4K
318.2K
Batz
Batz@AndrewBatz·
Remember this tax day that all your suffering should be directed at Intuit&co for lobbying to keep this hellscape, and congress for listening to them instead of fixing it.
English
0
0
0
23
Batz
Batz@AndrewBatz·
@TeamYouTube I can reliably crash/make unusable the iOS app when attempting airplay to HomePods (in stereo if that matters) using a video at 2X. It appears to work (with massively desynced audio), attempting to re-sync audio breaks everything but sometimes play/pause.
English
1
0
0
35