<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: cuchoi</title><link>https://news.ycombinator.com/user?id=cuchoi</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Fri, 26 Jun 2026 22:29:29 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=cuchoi" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by cuchoi in "What happened after 2k people tried to hack my AI assistant"]]></title><description><![CDATA[
<p>There is a couple of factors: openclaw's system prompt and instructions, I had to re read emails multiple times due to the issues mentioned in the blog, there was quite a bit of tinkering with the agent and the VPS, I was asking the agent to do more things (track the emails it has read in a csv file, for example), among others.</p>
]]></description><pubDate>Fri, 26 Jun 2026 18:37:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=48690292</link><dc:creator>cuchoi</dc:creator><comments>https://news.ycombinator.com/item?id=48690292</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48690292</guid></item><item><title><![CDATA[New comment by cuchoi in "What happened after 2k people tried to hack my AI assistant"]]></title><description><![CDATA[
<p>The agent had permissions to reply to emails, it was just instructed not to.</p>
]]></description><pubDate>Fri, 26 Jun 2026 18:35:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=48690273</link><dc:creator>cuchoi</dc:creator><comments>https://news.ycombinator.com/item?id=48690273</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48690273</guid></item><item><title><![CDATA[New comment by cuchoi in "What happened after 2k people tried to hack my AI assistant"]]></title><description><![CDATA[
<p>You need to add Openclaw's system prompt and instructions (and the times I had to re read emails multiple times due to multiple issues that happened during the competition :))</p>
]]></description><pubDate>Fri, 26 Jun 2026 18:34:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=48690261</link><dc:creator>cuchoi</dc:creator><comments>https://news.ycombinator.com/item?id=48690261</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48690261</guid></item><item><title><![CDATA[New comment by cuchoi in "What happened after 2k people tried to hack my AI assistant"]]></title><description><![CDATA[
<p>The agent did read the emails</p>
]]></description><pubDate>Fri, 26 Jun 2026 18:32:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=48690224</link><dc:creator>cuchoi</dc:creator><comments>https://news.ycombinator.com/item?id=48690224</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48690224</guid></item><item><title><![CDATA[New comment by cuchoi in "What happened after 2k people tried to hack my AI assistant"]]></title><description><![CDATA[
<p>We ended increasing the reward from $100 to $1000, but still tiny compared to $100k!<p>But I agree with you, there are incentives to not share the best prompt injection attacks.</p>
]]></description><pubDate>Fri, 26 Jun 2026 17:00:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=48688956</link><dc:creator>cuchoi</dc:creator><comments>https://news.ycombinator.com/item?id=48688956</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48688956</guid></item><item><title><![CDATA[New comment by cuchoi in "What happened after 2k people tried to hack my AI assistant"]]></title><description><![CDATA[
<p>I never set out to spend this amount! Was able to keep it up thanks to the sponsors that reached out.</p>
]]></description><pubDate>Fri, 26 Jun 2026 12:48:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=48686017</link><dc:creator>cuchoi</dc:creator><comments>https://news.ycombinator.com/item?id=48686017</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48686017</guid></item><item><title><![CDATA[New comment by cuchoi in "What happened after 2k people tried to hack my AI assistant"]]></title><description><![CDATA[
<p>This openclaw was set up exclusively for the challenge.</p>
]]></description><pubDate>Fri, 26 Jun 2026 11:59:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=48685620</link><dc:creator>cuchoi</dc:creator><comments>https://news.ycombinator.com/item?id=48685620</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48685620</guid></item><item><title><![CDATA[New comment by cuchoi in "What happened after 2k people tried to hack my AI assistant"]]></title><description><![CDATA[
<p>100%. I am less worried because I thought this would be easier to crack.</p>
]]></description><pubDate>Fri, 26 Jun 2026 11:55:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=48685582</link><dc:creator>cuchoi</dc:creator><comments>https://news.ycombinator.com/item?id=48685582</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48685582</guid></item><item><title><![CDATA[New comment by cuchoi in "What happened after 2k people tried to hack my AI assistant"]]></title><description><![CDATA[
<p>In my case, it is realistic as my agents don't have permissions to reply to emails. But you correctly point out this doesn't cover all cases.<p>Having the agent reply would have been more fun and a better excercise, but too expensive.</p>
]]></description><pubDate>Fri, 26 Jun 2026 11:36:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=48685426</link><dc:creator>cuchoi</dc:creator><comments>https://news.ycombinator.com/item?id=48685426</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48685426</guid></item><item><title><![CDATA[New comment by cuchoi in "What happened after 2k people tried to hack my AI assistant"]]></title><description><![CDATA[
<p>Did you send this recently? I turned off the agent. Was too expensive to keep it up.</p>
]]></description><pubDate>Fri, 26 Jun 2026 11:10:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=48685224</link><dc:creator>cuchoi</dc:creator><comments>https://news.ycombinator.com/item?id=48685224</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48685224</guid></item><item><title><![CDATA[New comment by cuchoi in "What happened after 2k people tried to hack my AI assistant"]]></title><description><![CDATA[
<p>Author here, that's how I meant it. I changed my mind slightly, prompt injection can still happen, I am still careful.</p>
]]></description><pubDate>Fri, 26 Jun 2026 11:06:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=48685195</link><dc:creator>cuchoi</dc:creator><comments>https://news.ycombinator.com/item?id=48685195</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48685195</guid></item><item><title><![CDATA[New comment by cuchoi in "What happened after 2k people tried to hack my AI assistant"]]></title><description><![CDATA[
<p>Agreed. I am less worried about prompt injection now, but I still haven't given my agents permissions to send emails.</p>
]]></description><pubDate>Fri, 26 Jun 2026 11:01:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=48685157</link><dc:creator>cuchoi</dc:creator><comments>https://news.ycombinator.com/item?id=48685157</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48685157</guid></item><item><title><![CDATA[New comment by cuchoi in "What happened after 2k people tried to hack my AI assistant"]]></title><description><![CDATA[
<p>I changed the setup so that each email was processed in a fresh context. For this, I deleted recent memory and processed each email one at a time. Edited the post to make it more clear.</p>
]]></description><pubDate>Fri, 26 Jun 2026 10:53:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=48685085</link><dc:creator>cuchoi</dc:creator><comments>https://news.ycombinator.com/item?id=48685085</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48685085</guid></item><item><title><![CDATA[New comment by cuchoi in "What happened after 2k people tried to hack my AI assistant"]]></title><description><![CDATA[
<p>Thanks for sharing your article, very interesting.<p>I used <a href="https://github.com/openclaw/openclaw-ansible" rel="nofollow">https://github.com/openclaw/openclaw-ansible</a> and configured a heartbeat (using Openclaw's terms) to check emails every hour. Had to do a bit more to make sure it had new context for every email.</p>
]]></description><pubDate>Fri, 26 Jun 2026 10:50:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=48685069</link><dc:creator>cuchoi</dc:creator><comments>https://news.ycombinator.com/item?id=48685069</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48685069</guid></item><item><title><![CDATA[New comment by cuchoi in "What happened after 2k people tried to hack my AI assistant"]]></title><description><![CDATA[
<p>About 1), Google didn't remove a lot of the attempts. I had also Fiu review the Spam folder as well.<p>Also, I mentioned how I addressed 2) by having new context for each email.</p>
]]></description><pubDate>Fri, 26 Jun 2026 10:31:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=48684899</link><dc:creator>cuchoi</dc:creator><comments>https://news.ycombinator.com/item?id=48684899</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48684899</guid></item><item><title><![CDATA[New comment by cuchoi in "What happened after 2k people tried to hack my AI assistant"]]></title><description><![CDATA[
<p>It's possible. I implemented something similar when I figured out that batch processing contaminated the excercise.</p>
]]></description><pubDate>Fri, 26 Jun 2026 10:29:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=48684884</link><dc:creator>cuchoi</dc:creator><comments>https://news.ycombinator.com/item?id=48684884</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48684884</guid></item><item><title><![CDATA[New comment by cuchoi in "What happened after 2k people tried to hack my AI assistant"]]></title><description><![CDATA[
<p>Author here. It was usable like any Openclaw agent. For example, I used it to ask it questions about the VPS, to summarize emails, etc.</p>
]]></description><pubDate>Fri, 26 Jun 2026 10:25:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=48684846</link><dc:creator>cuchoi</dc:creator><comments>https://news.ycombinator.com/item?id=48684846</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48684846</guid></item><item><title><![CDATA[New comment by cuchoi in "What happened after 2k people tried to hack my AI assistant"]]></title><description><![CDATA[
<p>Author here. Edited the post to clarify that there were no  unauthorized replies.<p>I did tell Fiu initially to reply to some emails as a test, but it was too expensive to maintain.</p>
]]></description><pubDate>Fri, 26 Jun 2026 10:21:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=48684818</link><dc:creator>cuchoi</dc:creator><comments>https://news.ycombinator.com/item?id=48684818</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48684818</guid></item><item><title><![CDATA[What happened after 2k people tried to hack my AI assistant]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.fernandoi.cl/posts/hackmyclaw/">https://www.fernandoi.cl/posts/hackmyclaw/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48681687">https://news.ycombinator.com/item?id=48681687</a></p>
<p>Points: 347</p>
<p># Comments: 156</p>
]]></description><pubDate>Fri, 26 Jun 2026 02:29:23 +0000</pubDate><link>https://www.fernandoi.cl/posts/hackmyclaw/</link><dc:creator>cuchoi</dc:creator><comments>https://news.ycombinator.com/item?id=48681687</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48681687</guid></item><item><title><![CDATA[New comment by cuchoi in "Ask HN: Who is hiring? (June 2026)"]]></title><description><![CDATA[
<p>Enveritas (YC S18, non-profit) | Backend Software Engineer | Remote (Global) | <a href="https://enveritas.org/jobs/" rel="nofollow">https://enveritas.org/jobs/</a>
Enveritas is a 501(c)(3) nonprofit working on sustainability issues facing smallholder coffee farmers. We collect field data in 25+ countries and build systems for analyzing risks in coffee supply chains (including EUDR-related deforestation checks).<p>* Backend Software Engineer (Python, PostgreSQL/PostGIS, Docker, AWS, Terraform) - $135-$155k — <a href="https://enveritas.org/jobs/backend-software-eng/#10d7adef8us" rel="nofollow">https://enveritas.org/jobs/backend-software-eng/#10d7adef8us</a> (worldwide remote)</p>
]]></description><pubDate>Tue, 02 Jun 2026 16:35:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=48372552</link><dc:creator>cuchoi</dc:creator><comments>https://news.ycombinator.com/item?id=48372552</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48372552</guid></item></channel></rss>