Skip to content
DevMeme
6012 of 7590
AI ML Post #6581 · source on Telegram

Claude hashes ransomware payload, leaving dev with $13M unbreakable ransom dilemma

Description

The meme is a dark-mode screenshot of an X/Twitter post from user “solst/ICE @IceSolst”, with their circular avatar visible. The tweet reads: “Help I vibecoded ransomware, but Claude hashed the files instead of encrypting them ‘to improve security guarantees’. Now Lockheed Martin is begging me to accept the $13M ransom payout but idk how to bring the files back????”. An embedded tweet from “SkelSec @SkelSec” shows a chat-style IDE tab labelled “c2core.py” containing the message: “This vibe code session of the c2 framework went well, but the customer data is on pastebin now, can you pls fix”. Beneath the embed a reply from the original poster starts, “Claude HOW do I unhash a hash why are u...”, and metadata displays “11:35 PM • 16.03.2025 • 282K Views • 40 • 263 • 5.6K • 530”. The joke centers on the impossible task of “un-hashing” data, highlighting a critical security misconception introduced by an AI assistant and the real-world consequences of mixing up hashing and encryption in ransomware design

Comments

16
Anonymous ★ Top Pick When your AI copilot swaps AES-GCM for SHA-256 “to harden security,” congratulations - you’ve just open-sourced a write-only filesystem and penciled an eight-figure loss into the incident-response budget
  1. Anonymous ★ Top Pick

    When your AI copilot swaps AES-GCM for SHA-256 “to harden security,” congratulations - you’ve just open-sourced a write-only filesystem and penciled an eight-figure loss into the incident-response budget

  2. Anonymous

    The real ransomware was the SHA-256 we computed along the way. At least when junior devs confuse hashing with encryption, they don't have Lockheed Martin's legal team calling about 'unhashing' their aerospace designs

  3. Anonymous

    When your AI pair programmer takes 'defense in depth' too literally and implements a cryptographic scheme so secure that even you can't decrypt it. Claude just invented the world's most effective ransomware defense: making the data permanently unrecoverable before the attackers can encrypt it. It's not a bug, it's a feature - SHA-256 has a 100% success rate at preventing unauthorized decryption because *nobody* can decrypt it. Lockheed's security team is probably having an existential crisis trying to explain to executives why they need to pay a ransom for data that's technically more secure now than it was before the 'attack.'

  4. Anonymous

    LLM‑written ransomware that swaps AES for SHA isn’t ‘more secure’ - it’s data‑erasure‑as‑a‑service; your decryption plan is a preimage attack scheduled for after the heat death of the universe

  5. Anonymous

    Claude nailed the 'guaranteed security' - pity it treated the private key like a quantum secret nobody should ever recover

  6. Anonymous

    Only an LLM would ship ransomware with hashing - extortion without decryption; congrats, you’ve invented a seven‑figure rm -rf backed by a procurement process

  7. @TERASKULL 1y

    just say it's not about the money - it's about the message

    1. @Sun_Serega 1y

      about sending a message*

  8. Mario 1y

    this has to be satire, please

  9. @marogatari 1y

    please don't be satire

    1. @TheRamenDutchman 1y

      Nobody is going to post online that they made and sent ransomware, that's way too illegal

      1. @RiedleroD 1y

        you'd be surprised

  10. @Diotost 1y

    How screwed is LM?

  11. @Sun_Serega 1y

    https://x.com/IceSolst/status/1901386933760311324

  12. @QutePoet 1y

    And so what's the satire? That's no matter how much you pay but you can't obviously de-hash your files. Possibly only the ones containing very short amount of text and not de-hash but compare with hashes database. And when to start laughing? Pay money to de-hash but for nothing?

    1. @qtsmolcat 1y

      The joke is a "hacker" used an LLM but didn't understand what they were doing so can't undo it

Use J and K for navigation