Justin Calmus

183 posts

Justin Calmus

Justin Calmus

@sumlac

Security dude

เข้าร่วม Ağustos 2016
643 กำลังติดตาม1.3K ผู้ติดตาม
zack0x01
zack0x01@zack0x01_·
i build an AI hacking agent that scan for bugs in an advanced level , trained from public reports and poc , and i was amazed what it found : 2 SSRF , 4 CVE's and encrypted password on a js file it decrypted the password made an api request and pulled 250 customers data 😅
English
12
7
162
9.4K
Justin Calmus
Justin Calmus@sumlac·
I have a theory... PSA for everyone who got hit with a full week's claude usage from one prompt this past week Claude Code has an agentic loop structure where token consumption is O(N²), not O(N). If call #1 sends 10K tokens, call #60 sends 500K. This is especially relevant if claude is having outages. status.claude.com When Opus (or equivalent) has an outage, and your prompt hits just at the right time, during that degraded service API calls will fail but still consume your input tokens. Claude will retry re-sending the context the entire time. That's why O(N²) is very relevant here, we're talking about killing your week's usage with one prompt. We see a lot of different responses because the outage wouldn't necessarily affect everyone equally. If you hit the bug at the wrong time, you are screwed. @claudeai please create a circuit breaker and alert users when API is failing. Silent failures are killing progress.
English
0
0
6
674
Alex Volkov
Alex Volkov@altryne·
This is Bonkers. Look at how many responses there are, most people are having the same experience, and yet, a complete silence from Anth dev rel folks. Sad this, folks love these tools but can't seem to be able to use them and no acknowledgement from the team that they are even looking into this . Yet every amazing release like /btw or computer use or Dispatch gets tons of engagement. This is exactly what @ryancarson was talking about btw. @alexalbert__ @trq212 @bcherny please take a look. I get that with the insane growth and shipping you guys are too busy, but this seems like a real thing that's happening to folks
Alex Volkov tweet media
Alex Volkov@altryne

My feed is showing me a bunch of folks who tapped out their whole usage limits on Mon/Tue. Is this your experience? Please comment, I want to understand how widespread this is

English
56
13
256
35.5K
Justin Calmus
Justin Calmus@sumlac·
PSA for everyone who got hit with a full week's claude usage from one prompt this past week Claude Code has an agentic loop structure where token consumption is O(N²), not O(N). If call #1 sends 10K tokens, call #60 sends 500K. This is especially relevant if claude is having outages. status.claude.com When Opus (or equivalent) has an outage, and your prompt hits just at the right time, during that degraded service API calls will fail but still consume your input tokens. Claude will retry re-sending the context the entire time. That's why O(N²) is very relevant here, we're talking about killing your week's usage with one prompt. We see a lot of different responses because the outage wouldn't necessarily affect everyone equally. If you hit the bug at the wrong time, you are screwed. @claudeai please create a circuit breaker and alert users when API is failing. Silent failures are killing progress.
English
0
0
0
286
dawgyg - WoH
dawgyg - WoH@thedawgyg·
@brockpierson yup this and 98 were the last windows i used lol switched to Redhat 5.0 and didnt turn back
English
2
0
6
810
⭕ Brock Pierson
⭕ Brock Pierson@brockpierson·
Be honest, did you use this when it was new?
⭕ Brock Pierson tweet media
English
566
33
1.4K
39.7K
Justin Calmus
Justin Calmus@sumlac·
@altryne 100%, hit the weeks limit immediately from a few prompts.
English
0
0
3
211
Justin Calmus
Justin Calmus@sumlac·
Will open source just be a great reference tool of the past?
English
0
0
1
82
Justin Calmus รีทวีตแล้ว
Rami McCarthy
Rami McCarthy@ramimacisabird·
TeamPCP got an infostealer into LiteLLM 1.82.7, 1.82.8litellm c2 is models[.]litellm.[]cloud Act fast. github.com/BerriAI/litell…
English
3
45
140
72.5K
Justin Calmus
Justin Calmus@sumlac·
@nervoir @stuxfdev @verialabs @BSidesSF I have the worst answer for you, because it really depends. MoE applies reasoning way beyond my model, but the model that I have has deep extensive security knowledge. If you wrap claude around it, it's pretty incredible.
English
0
0
0
118
nrv
nrv@nervoir·
@sumlac @stuxfdev @verialabs @BSidesSF Given the recruitment drive of both anthropic and OpenAI wrt offsec people, it seems likely the latest models will be trained on this and probably extensive synthetic data? Or does it feel like your model outperforms the latest frontier models?
English
2
0
0
142
stuxf
stuxf@stuxfdev·
We at @verialabs built an autonomous CTF agent in a weekend and won 1st place at @BSidesSF 2026, solving all 52/52 challenges. It races multiple AI models (Claude, GPT-5.4) in parallel, each in isolated Docker sandboxes with full CTF tooling. A coordinator LLM reads solver traces and sends targeted guidance to stuck agents. As AI gets better at finding and exploiting vulnerabilities, we think it's important to understand exactly how good it is and where it fails. github.com/verialabs/ctf-…
English
7
52
305
32.8K
JS0N Haddix
JS0N Haddix@Jhaddix·
Stacked content creator dinner last night. Was so fun!
JS0N Haddix tweet media
English
8
0
106
6.7K
Vadim
Vadim@VadimStrizheus·
i'm cooked maybe it's time to buy a second Claude Max subscription the week hasn't even started. 💀
Vadim tweet media
English
126
2
367
41.3K
Justin Calmus
Justin Calmus@sumlac·
Once I really nailed down what I was using OpenClaw for, I decided to just take some of the features and build it myself. Now I have exactly what I need with zero overhead.
English
0
0
1
67
Brad Groux
Brad Groux@BradGroux·
Something is up with Claude Code usage today. $200 Claude Max, 0%, 52% to 62%, then 68%, 76% and 84% in 5-hour rolling window in the time it took me to write this tweet. WTF, @AnthropicAI? I'm working on one GitHub PR for regression testing. Not folding proteins to cure cancer.
Brad Groux tweet mediaBrad Groux tweet mediaBrad Groux tweet mediaBrad Groux tweet media
English
390
56
1.3K
372.3K
Justin Calmus
Justin Calmus@sumlac·
2 Max Subscriptions... both maxed out. Sigh
English
0
0
1
78
Justin Calmus รีทวีตแล้ว
Chaofan Shou
Chaofan Shou@Fried_rice·
vibe coded a fuzzing ai agent last month and let it run for a week using my $200 claude max. it then found 21 high/critical vulnerabilities in Chrome.
Chaofan Shou tweet media
English
96
235
2.7K
473.4K