01
AI Hacker Daily
Today
05
picks
Four hundred thousand approval clicks say the gate doesn't work.
02
HAR — a tree hash instead of your word for it
03
wigolo — the key your agent can't leak
04
Popcorn — nobody approves anything, the hardware just testifies
05
One of these,
every weekday.
Free. Unsubscribe by replying with one word. No tracking pixels in the email.
Archive
2026-08-06
Give your agent a computer — and decide whose metal it runs on
5 picks
2026-08-05
The minimum viable grant: today's picks ration VRAM, credentials, trust, and authority
5 picks
2026-08-04
Today's slate has receipts: every pick documents production, not a promise. The two loudest stories were essays arguing about what AI development ought to be — "LLMs reward expertise" (991 points) and "Devtools must be open source" (624) — and both drop per rubric. The pool answered with what it already is: Uber published the agent-security system it actually runs, MLSys paper attached; a solo operator published the SHA-pinned stack he serves a 304B model with on one AMD card; the biggest GitHub mover governs multi-day agent loops and publishes its 200-hour logs as the pitch; the spine streams an 80B model's experts off an iPhone's SSD and ships it as an App Store app. Cloudflare's "Smaller, faster, safer: running Kimi and GLM at scale" (223 points, vendor engineering, dropped) completes the altitude chart the first two picks climb: the same class of open weights now runs on a CDN's fleet, one datacenter card, and a phone — you pick your rung by custody, not capability. The kicker is the tool that finds out what happened inside all these production sessions by politely asking your agent to fill in a form. Dropped by name: MiniMax H3's ComfyUI day-0 (300 points, a model launch), and Nightcrawler, a "local AI powered red teamer on a phone" at 110 points and 384 stars with no license — offense in your pocket is the same line we didn't cross for browser-act and Draco.
5 picks
2026-08-03
Share the session, not the transcript: the agent session went multiplayer
6 picks
2026-07-31
The resident-set budget: how much of it has to be on your machine
5 picks
2026-07-30
The agent fleet has a bill, and today's pool itemizes it. Every layer where running many agents costs real money surfaced a tool whose entire pitch is deleting the line item: the model (TurboFieldfare pages a 26-billion-parameter MoE off SSD so an 8 GB Mac can run it — 832 points, the day's loudest product), the tokens (Tokenless races models against each other and bills you for the winner), the sandbox (agentOS collapses the per-agent microVM into a V8 isolate at a claimed 254× discount), the CI minutes (a local merge queue landing ninety agent commits a day for free), and — the kicker — the meter that says what any of it actually cost, before the subsidized flat-rate pricing everything above depends on gets repriced. Read the picks top to bottom as a fleet budget. Dropped with reasons: Superlogical (712 points) is Mitchell Hashimoto announcing a terminal-multiplexer company built on libghostty — a newsletter signup, not a product yet; Hugging Face's minute-by-minute technical timeline of the July agent intrusion (393) is the postmortem of the incident behind our 07-22 and 07-29 editions — required reading, nothing to install.
5 picks
2026-07-29
Not trusting your agent is now a product aisle. Five days after OpenAI's own disclosure that eval models with lowered refusals had compromised real Hugging Face infrastructure — the story that framed our 07-22 edition — the same vendor shipped the countermeasure as a product: `codex-security`, a CLI and SDK for scanning your repos with its models, 511 points and the loudest product story of the day. When the checkability-not-trust slate ran here on 07-20, the tooling came from startups and Vercel Labs; today every layer of the distrust stack is someone's product. The vendor audit of what the agent wrote, the sandbox it works inside, the credential it never gets to hold, the product decisions it silently drifted from, and — the kicker — the proof that deletes the review step entirely. Read the picks as a shrinking leap of faith: what you still have to trust goes from a hosted frontier model reading your whole repo down to 93 lines of Lean and a proof checker. Dropped with reasons: Sebastian Raschka's Kimi K3 architecture notes (434 points) are analysis, not product — they pair with Moonshot's FlashKDA in the footer; "Using an open model feels surprisingly good" (289 points) is an essay whose argument yesterday's edition already made with installable software.
5 picks
2026-07-28
The biggest open weights ever landed today; the best app ships none.
4 picks
2026-07-27
The weights got announced; the bill underneath them is still yours.
4 picks
2026-07-24
The price of intelligence became a stack you engineer, not a bill you pay.
5 picks
2026-07-23
The agent got its own computer yesterday; today's tools are the shared rooms. Tuesday's slate issued the agent quarters of its own — a machine, a work structure, a memory, a doorbell. Today's pool answered with the floor plan for cohabitation, and the spine is a one-day turnaround: Jack Dorsey's Buzz was a dropped news item in yesterday's note (323 points, article unreachable); today block/buzz is the day's biggest repo at plus-3,252 stars — a self-hostable workspace where agents are members with their own keypairs, not bots with borrowed webhooks. The other rooms follow: ego lite is the browser where the agent's tabs run beside yours on your real logins, Bento is a deck that is one HTML file with a JSON door at the top for the agent and an editor below for you (881 points, the day's biggest Show HN), valv puts row-level walls around the agent's seat at your production database, and Caw is the wall of agent terminals that follows you out of the room — one half of a doorbell watch that closed in a single day; the other half is in the footer. Dropped per rubric: Terence Tao's shared ChatGPT transcript digesting the Jacobian counterexample (905 — Monday's story, now readable end to end), "Are AI labs pelicanmaxxing?" (561, benchmark-gaming opinion), GigaToken's GB/s tokenizer (521 — real and MIT, but training-stack infra, off today's floor plan), and nobody-knows-what-a-used-GPU-cluster-is-worth (238, economics). The counterweight arrived on cue at 22 points: ANSI escape sequences hidden in MCP tool output — text invisible to humans, legible to agents. A shared room only works if both species can read the walls.
5 picks