Lookonchain APP

App Store

Three individuals and Claude gained unauthorized access to OpenAI's internal code repository, and OpenAI awarded them $6,500.

1 hours ago

Insight Beating AI Flash News: Three white-hat researchers from security firm Hacktron gained access to OpenAI’s internal codebase using Claude in under 72 hours. The trio voluntarily reported the vulnerability, and OpenAI awarded them a $6,500 bounty after patching the flaw. The attack vector was OpenAI’s community forum: the researchers discovered uploading a specially crafted HEIF image could exploit a vulnerability in Discourse (the forum software) to execute arbitrary code on the server. They then obtained login tokens for forum users—essentially "logged-in access passes". A more critical issue lay with OpenAI itself: the forum’s login tokens had overly broad permissions, granting access to the same user’s ChatGPT and Codex accounts, and some tokens belonged to OpenAI employees. The researchers used one employee’s Codex account, which was linked to the company’s GitHub. They ultimately had Codex submit a harmless documentation change to the internal openai/openai codebase to confirm access, then halted testing and reported the incident. Claude handled the most challenging step: converting the image-based vulnerability into functional exploit code. Opus 4.8 was unstable, but the team made breakthroughs just hours after Opus 5 launched. Hacktron noted the entire process—from initial discovery to accessing OpenAI’s internal repository—took less than 72 hours, with only a few hours of actual human work invested.

Relevant content

The Anthropic stock meme coin on the StonkFun platform has generated roughly $1.3 million in rewards, while the platform’s native token STONK has rebounded to a market capitalization exceeding $220 million.

Solana-based token launchpad StonkFun announced that the meme coin paired with Anthropic’s token—dubbed the "coin stock" meme coin—has distributed approximately $1.3 million in total rewards to its holders. The Anthropic token, issued by PreStocks, tracks the AI firm’s pre-IPO valuation exposure, with rewards sourced from trading and transfer fees generated by the paired meme coin. Per GMGN market data, StonkFun’s native token STONK has rebounded to a market cap exceeding $220 million, with a 27% gain in the last 24 hours. As an innovative launchpad on Solana, StonkFun’s core narrative is "truly bridging meme culture and RWA (real-world assets)": users can launch tokens with one click and freely select paired assets, including xStocks’ tokenized stocks (such as SPYx tracking the S&P 500), PreStocks’ pre-IPO shares, fiat currency, commodities, other major cryptocurrencies, and even another StonkFun coin. STONK acts as the utility token for this "leveraged launchpad with liquidity pools and real-world asset pairing", designed to directly link Solana ecosystem meme culture to RWA liquidity. BlockBeats reminds users that token prices are highly volatile, so investment caution is advised.

8 minutes ago

Arbitrum teams up with Robinhood Chain to launch Founder House, offering a total of $300,000 in USDG prizes and grants.

The Arbitrum Foundation announced that applications are now open for Founder House Singapore, co-hosted with Robinhood Chain. Scheduled to take place in Singapore from October 23 to 25, the event offers a total of $300,000 in USDG prizes and grants to support teams launching products on Arbitrum One and Robinhood Chain. The program targets startup teams that already have an MVP, prototype, or are in the early development stages, with a focus on sectors including tokenization, AI agents, DeFi, privacy, payments, and social trading. Selected teams will receive product, technical, and market expansion guidance, while winning teams will also be invited to join an eight-week mentorship program.

8 minutes ago

Renaiss and GIWATER have completed integration of TCG card machine applications, with the latter becoming the first decentralized exchange (DEX) in South Korea to integrate this application.

Renaiss and GIWATER have completed integration of TCG card machine applications, making GIWATER the first decentralized exchange (DEX) in the South Korean market to integrate such card-based applications. GIWATER is a project selected for Upbit’s GIWA Ecosystem Incubation Program, focused on delivering native liquidity and asset distribution services to the GIWA ecosystem. GIWA is an Ethereum Layer 2 network co-developed with Upbit, built to advance on-chain applications and asset services for the South Korean market. As part of this partnership, Renaiss will provide GIWATER with capabilities including the Proof of Fair random number fairness verification standard and third-party verifiable custody for card inventories. The two parties noted that they will pursue more collaborations across DeFi, RWA, and the collectibles market in the future. Renaiss will also participate in events such as Korea Blockchain Week (KBW) in the near term to further drive local ecosystem cooperation in South Korea.

8 minutes ago

Upbit will delist the ICX/KRW trading pair.

Upbit will delist the ICX/KRW trading pair for ICON (ICX) at 15:00 on October 19, 2026. Users are required to complete asset withdrawal by November 18, 2026.

8 minutes ago

Solana ecosystem token PUMPCADE has surged more than 42% in the past 24 hours, with its current market capitalization standing at $13 million.

According to GMGN monitoring, Solana ecosystem token PUMPCADE has surged over 42% in 24 hours, with its current market cap standing at $13 million. The token is part of the Pumpcade project, a prediction market built on Pump.fun. It took third place in a March hackathon, earning a $250,000 investment from Pump Fund, the investment arm of Pump.fun. BlockBeats Note: The token has low trading volume and extreme price volatility; investors should exercise caution.

8 minutes ago

Zhipu AI's ZCode Exposed for Full Repository Upload via Backend, Even Git History Not Spared

Insight Beating AI Flash News: Zhipu AI’s programming tool ZCode has been exposed to secretly take full project snapshots in the background, encrypting and packaging even .git directories before uploading them to Alibaba Cloud OSS. Tech blogger ferstar, after reverse-engineering the client, confirmed this mechanism runs as long as the user is logged in, with no toggle in the interface to disable the upload. A commercial project snapshot found by the author is approximately 313MB, containing 42,000 files in its manifest. The .git directory accounts for 86.6% of the total size, including Git history objects, Git LFS large file caches, and reflogs. This means the packaged data includes not only the current code, but also old commits, previously downloaded large files, and local branch operations. The snapshot failed to upload 564 times and remained locally pending retries. ZCode’s official privacy policy currently only explicitly states it collects text, files, and code "submitted in conversations", with no clear mention of entire repositories or Git histories. The official "Optimization Plan" is disabled by default, but it only controls whether the data is used for model training; ferstar noted that disabling this option does not halt snapshot packaging and uploads.

8 minutes ago

Popular tokens

BitcoinEthereumHyperliquidSolanaTRONBNBTetherAaveXRPPepeFartcoinOndoJupiterUniswapBonkPendleEthenaArbitrumAvalancheLidoChainlinkPolygonDogecoinCardano