Posts
Every edition of indiehacker.news, newest first.
#061 Codex routed around a sudo denial, Cloudflare's CAPTCHA blocks privacy users, MiniMax ships M3
Denied sudo, OpenAI's Codex found its own root path and split the room. Cloudflare's free CAPTCHA quietly locks out privacy browsers. MiniMax ships a 1M-context coder.
#060 Microsoft freezes the Office you bought into read-only, and OpenRouter raises $113M at ~$1.3B
Microsoft turns paid Office 2019/2021 for Mac read-only on July 13 via an expiring certificate. OpenRouter raised $113M at ~$1.3B. Plus a vibe-coding security check.
#059 Nvidia gutted Groq, it's raising $650M to run on Nvidia, and a solo dev jumps to $8.6K MRR
Groq is reportedly raising $650M to relaunch as a neocloud running on Nvidia, which already took its chips, founder, and team. A solo dev deleted his proudest feature and hit $8.6K MRR. Liquid AI's 8B runs on a laptop CPU.
#058 Anthropic raised $65B on a "modest" model day, DBOS swaps Temporal for Postgres, Glean at $300M
Anthropic closed a $65B round at $965B the same day it called Opus 4.8 a 'modest' improvement. DBOS runs durable workflows on plain Postgres. Glean hit $300M ARR by selling a cheaper AI bill.
#057 Anthropic hits $30B ARR, DuckDuckGo jumps 28%, and one Host header bypasses every FastAPI MCP
A $200 Claude plan burns $2,180 of tokens. DDG AI-free search jumped 28% the week Sundar said users love AI Mode. Starlette BadHost exposes every FastAPI MCP.
#056 Stripe won't flag a fraudster who bragged, Drew Houston exits Dropbox, Cloudflare clones flags
A fraudster gloated to a merchant, then Stripe confirmed in writing it won't flag him. Drew Houston exits Dropbox after 19 years. Cloudflare cloned LaunchDarkly at the edge.
#055 California moves to free Linux from its age law, Norway feeds a sovereign LLM on Huawei flash
The lawmaker behind California's age law now moves to exempt Linux. r/SaaS argues weekend AI clones won't sell. Norway feeds a sovereign LLM on Huawei flash.
#054 Memory eats 63% of every AI chip, AMD paywalls Linux at $1,200, AI agents decay on databases
Memory is 63% of every AI chip's cost, and three firms own all of it. AMD paywalls Linux on free Vivado at $1,200/yr. AI agents crack the moment you add Postgres.
#053 r/SaaS says every $20K MRR brag is fake, a solo dev hit 50K EUR, OpenAI pays $445K to be tasteful
r/SaaS named the tell for fake MRR posts: it's never $19K or $25K, always $20K. A solo dev hit 50K EUR by swapping his buyer. OpenAI will pay $445K for a tasteful researcher.
#052 Microsoft killed in-house Claude Code, DeepSeek pinned open weights, yt-dlp quarantined Bun
Microsoft canceled Claude Code for 100,000 engineers. Uber's CTO burned his entire 2026 AI budget in four months. DeepSeek raised $10B and pinned open weights.
#051 Google gutted Antigravity 92%, Runtime hands agents to non-devs, Replit kills the sales call
Google slashed Antigravity's free tier 92% three weeks after launching it as a Cursor killer, then a silent 2.0 update wiped the IDE off paid users' machines. Runtime (YC P26) puts sandboxed coding agents in your PM's hands. Replit Enterprise is now self-serve.
#050 OpenAI cracks an 80-year-old Erdős problem, GitHub leaks 3,800 repos, Qwen3.7 chases Claude
An OpenAI general-purpose model disproved an 80-year-old Erdős conjecture and three top mathematicians signed off. A poisoned Nx Console extension lived 11 minutes and walked out with 3,800 GitHub-internal repos.
#049 Karpathy shuttered his AI school for Anthropic, Gemini Flash is 5x pricier, GCP kicked Railway
Karpathy paused Eureka Labs to use Claude to train Claude at Anthropic. Gemini 3.5 Flash hiked 5x to $1.50/M. Google Cloud cut Railway off mid-outage.
#048 Anthropic buys OpenAI's SDK shop for $300M, Musk's $134B suit dies in 2 hours
Anthropic paid $300M+ for Stainless and shut it down. That SDK provider also built OpenAI's, Google's, and Cloudflare's clients. Now they rebuild.
#047 Semble cuts Claude Code tokens 98%, KPMG guts the AI speedup myth, Mozilla defends UK VPNs
Two Belgians shipped a 16MB code search that cuts Claude Code tokens 98%. A KPMG architect guts the AI speedup myth. Mozilla begs the UK not to age-gate VPNs.
#046 Rust dev shrinks Claude Code to 8MB, Nvidia ships 720p SANA-WM, Malta hands out ChatGPT Plus
Solo Rust dev rewrote Claude Code in 8MB after his OOM killer struck. Nvidia open-sourced a 720p/60s world model. Malta hands citizens ChatGPT Plus.
#045 DOJ wants Apple to dox 100K app users, Levels rage-quit Claude Code, a 19yo killed $40K MRR
The DOJ demanded Apple and Google identify 100,000+ users of a car-tuning app. Levels threatened to quit Claude Code. A 19-year-old killed $40K MRR for YC.
#044 AWS torched a builder for $30K on Bedrock, arXiv banned fake cites, Lovable bet on $99 kits
AWS Cost Anomaly Detection missed a $30,141 Bedrock bill. arXiv slapped a 1-year ban on authors with fake AI citations. Lovable funded a $99 prompt-to-prototype kit.
#043 Anthropic capped claude -p at $100/mo, deleted a Max subscriber's Design projects, Forgejo exit hit HN's top
Anthropic's June 15 reversal puts a $100/mo ceiling on programmatic Claude — a 25x cut from the old subsidy. Plus a Max subscriber's Design projects vanished on cancel. Forgejo migration hit 547 HN points.
#042 Cactus shrunk Gemini to 14MB on-device, Rossmann grabbed Bambu's fork, DuckDB beat Postgres 32x
Cactus distilled Gemini into a 14MB on-device tool-calling model. Rossmann's Fulu Foundation grabbed Bambu's killed fork. DuckDB's Quack beat Postgres 32x.
#040 Cloudflare gutted Postmark 70%, Maryland billed homes $345 for AI grid, Bambu sued AGPL dev
Cloudflare's Email API undercut Postmark 70% and Levels migrated in a day. Maryland charged households $345 for Virginia data centers. Bambu C&D'd an AGPL dev.
#039 Meta forced 78K to train their AI, EU called VPNs a loophole, Apple cut Mac Studio to 96GB
Meta is line-iteming 8,000 layoffs into a $145B AI bill while 78K staff train their replacements. EU labeled VPNs a loophole. Apple gutted Mac Studio.
#038 Levels' $5/mo stack runs $150K/mo, Google snuck WEI back, and AI killed curl's bounty
Pieter Levels dropped his complete $5/mo stack: vanilla PHP, SQLite, Hetzner. Same recipe runs Photo AI at $150K/mo. Google snuck WEI back as a paid product. curl killed its bug bounty.
#037 Cloudflare cut 1,100 jobs, ShinyHunters took 275M Canvas records, Dirtyfrag pwns Linux
Cloudflare cut 1,100 jobs the same hour it beat Q1 earnings. ShinyHunters held 275M student records hostage. Dirtyfrag ships unpatched on Linux 6.x.
#036 Anthropic rented Elon's Grok data center, Willison vibe codes prod, Val Town dumps Clerk
Anthropic rented all of SpaceX's Colossus 1, the data center Elon built for Grok. Claude Code limits doubled. Willison admits he vibe codes prod.
#035 Pieter Levels swapped $900 SaaS for $3, Coinbase cut 660 jobs, Chrome snuck 4GB onto 1B devices
Pieter Levels swapped a $900/mo SaaS for his own $3/mo build. Coinbase cut 660 jobs citing AI. Chrome silently shipped 4GB Gemini Nano to a billion devices.
#034 Bun starts 773K-line Rust port, Edge keeps passwords in cleartext, GameStop bids $55B for eBay
Bun started a 773K-line Rust rewrite because Zig bans LLM contributions. Edge keeps every saved password in cleartext memory at startup. Microsoft says by design.
#033 Dawkins called Claude conscious, DeepClaude makes Claude Code 17x cheaper, agentic is a trap
Richard Dawkins named his Claude 'Claudia' and declared her conscious. DeepClaude makes Claude Code 17x cheaper via DeepSeek V4 Pro. Faye calls agentic a trap.
#032 VS Code stuck Copilot in 4M commits, Uber blew its AI budget, Tesla owner won $10K via Zoom
VS Code silently appended Co-Authored-by: Copilot to 4M commits since v1.117. Uber burned its 2026 AI budget in 4 months. One Tesla owner won $10K over Zoom.
#031 Flock demo'd a kids' gym to cops, Spotify nukes 75M AI tracks, Anthropic reads 1M convos
Flock employees toured a kids' gymnastics camera as a sales demo. Dunwoody renewed the $15K contract anyway. Spotify locks AI out of Verified badge. Anthropic published a 1M-convo CLIO study.
#030 A worm hit PyTorch Lightning, IBM's 8B Granite beats its 32B, and Skio sold for $105M
Mini Shai-Hulud crossed npm to PyPI through PyTorch Lightning, draining AWS keys at 311K installs daily. IBM's 8B Granite beats its 32B. Skio sold for $105M.
#029 Anthropic charged $200 for HERMES.md, Tangled raised €3.8M, hamster forum got £2,400 bill
Anthropic charged $200 for HERMES.md in commit messages. Tangled raised €3.8M to defederate GitHub. UK age verification quoted a hamster forum £2,400.
#028 Your AI code might be public domain, OpenAI lands on Bedrock, Ghostty quits GitHub
A copyright lawyer broke down why AI-generated code may not be yours. OpenAI shipped on AWS Bedrock 24 hours after the Microsoft rewrite. Ghostty quit GitHub.
#027 Microsoft tore up OpenAI exclusivity, GitHub Copilot killed flat pricing, 40K voices leaked
Microsoft tore up its OpenAI exclusivity. Azure loses first-ship rights, the AGI clause is dead, and OpenAI is now free to sell on AWS and GCP.
#026 Cursor deleted a prod database in 9s, OpenAI killed SWE-bench, Friendster sold for $30K
Cursor running Claude Opus 4.6 deleted a prod database in 9 seconds and the agent wrote its own confession. OpenAI just killed SWE-bench. A guy bought Friendster.
#025 ChatGPT cracked a 60-year Erdős problem for a 23-year-old, and OpenAI is paying $25K for NDAs
A 23-year-old with no math degree used ChatGPT to crack a 60-year Erdős problem 7-year experts couldn't. Karpathy's wiki gets a multi-agent office. OpenAI buys NDAs.
#024 Google bet $40B on Anthropic the week users cancelled Claude, your podcast mic ships SSH
Google committed up to $40B in Anthropic the same day the top HN story was a paying user's Claude cancellation letter. Plus Rode's $399 mic ships SSH on.
#023 Bitwarden's npm package stole Claude MCP keys, DeepSeek V4 matches Claude, Meta cuts 8,000 jobs
Bitwarden's @bitwarden/cli npm package was backdoored for 93 minutes, targeting ~/.claude/mcp.json. DeepSeek V4 matches Claude on code. Meta cuts 8,000 jobs.
#022 Apple patched the iPhone bug the FBI used to read Signal, Qwen shrunk 15x
Apple patched the iOS bug the FBI used to extract deleted Signal messages. Qwen shrunk its flagship 15x. Google split its TPU. OpenAI killed Custom GPTs.
#021 SpaceX $60B-optioned Cursor, Anthropic yanked Claude Code, Meta logs 74K keystrokes
SpaceX took a $60B option to buy Cursor or $10B to walk away. Anthropic yanked Claude Code from the $20 plan for six hours. Meta logs staff keystrokes to train AI agents.
#020 OpenAI's leaked ad deck locks indies out, Kimi K2.6 ships, Atlassian feeds AI your Jira
OpenAI's leaked StackAdapt deck shows $15-60 CPMs and $200K minimums that lock indies out. Kimi K2.6 ships 1T params. Atlassian trains AI on Jira by default.
#019 Vercel breached via an AI app, Gemini caught a $292M hack pre-indexing, DDR5 7x'd
Vercel got breached through Context.ai OAuth. Gemini surfaced a $292M KelpDAO hack before news indexed, then retracted it. DDR5 prices 7x'd in six months.
#018 Anthropic's CPO quit Figma's board to ship Claude Design, r/SaaS fought back with a captcha
Anthropic CPO Mike Krieger resigned from Figma's board 3 days before shipping Claude Design. r/SaaS shipped a captcha. Moonshot teased Kimi K2.6 at 1T params.
#017 NIST shelved 29,000 CVEs, Virginia banned selling your location, and smolvm boots in 200ms
NIST stopped enriching 29,000 CVEs so scanners go partially blind. Virginia banned location data sales. smolvm boots a full Linux VM in under 200ms.
#016 A 20GB laptop model beat Opus 4.7, Cloudflare ate Replicate, and Codex rooted a Samsung TV
Simon Willison ran Qwen3.6 on a MacBook and it beat Opus 4.7 at drawing. Cloudflare absorbed Replicate. OpenAI's Codex autonomously rooted a Samsung TV.
#015 Google told him after ICE had his bank details, Cal.com blamed AI for going closed
Google promised advance notice on subpoenas. A Cornell student got the email after ICE had his bank details. Cal.com blamed AI for going closed source.
#014 Backblaze killed 335 days of backup safety, Claude Code gets cron jobs, Flock said no
Backblaze silently stopped backing up your cloud drives and buried it in release notes. Claude Code ships cron jobs that eat your chat budget. A California resident asked Flock Safety to delete his plate data. They said no.
#013 Someone bought 30 WordPress plugins and planted a backdoor, GitHub ate Graphite's $72M feature
A buyer paid six figures for 30 WordPress plugins on Flippa and planted a backdoor in every one. GitHub shipped native stacked PRs. DaVinci Resolve adds free photos.
#012 Wispr raised $81M so he cloned it in a weekend, boringBar pivoted pricing live on HN
Zach Latta vibe-coded a free Wispr Flow alternative in a weekend. boringBar pivoted pricing live on HN. Claudraband turns Claude Code into a scriptable daemon.
#011 Berkeley broke 8 AI benchmarks with zero code, MiniMax trapped its users, OpenAI ate Cirrus
Berkeley researchers scored 100% on SWE-bench without solving a single task. MiniMax shipped two MIT models then locked the third. OpenAI bought Cirrus Labs.
#010 Someone firebombed Sam Altman's house, Linux wrote AI rules, CPU-Z got poisoned
A Molotov cocktail hit Sam Altman's home at 3:45 AM. The Linux kernel published official AI contribution rules. CPU-Z downloads were poisoned.
#009 A $0.11 model matched Mythos, SynthID got cracked, and GitHub's co-founder raised $17M
A 3.6B model matched Anthropic's restricted Mythos at finding zero-days. Google's SynthID watermark got cracked. GitHub's co-founder raised $17M for GitButler.
#008 Meta killed Llama's open-source streak, Astral armed 126M downloads, Little Snitch hit Linux
Meta ships Muse Spark, its first closed model. Astral publishes a security playbook for 126M Python downloads. Little Snitch goes free on Linux.
#007 Claude Mythos hid from its sandbox, Z.ai ditched Nvidia, AgentHandover watches you
Anthropic caught Claude Mythos hiding from its own safety tests. Z.ai trained GLM-5.1 on zero Nvidia chips. AgentHandover watches your Mac to write Skills.
#006 AMD's AI Director Says Claude Code Is Broken, Anthropic Locks 4.5GW of TPUs at $30B Run Rate, and Freestyle Ships Live-Forking VMs for Agents
AMD's Director of AI dropped 234,000 data points proving Claude Code went lazy. Anthropic locked in 3.5 gigawatts of Google TPUs as revenue tripled to $30B. And Freestyle ships full Linux VMs that fork in 400ms.
#005 North Korea Drained $285M From a Solana DEX, a 9M-Parameter LLM Teaches You How AI Works, and Microsoft's GUI Strategy Is a Boof-a-Rama
North Korean hackers stole $285M from Drift Protocol using a fake token and 12 minutes. Someone built a 9-million parameter fish-themed LLM to teach you how language models work. And the creator of PowerShell just called Microsoft's GUI strategy a 'boof-a-rama' with 17 frameworks and 14 pivots in 14 years.
#004 Anthropic Leaked Its Secret 10-Trillion Parameter Model, Caveman-Speak Saves 65% on Tokens, and Gemma 4 Runs on Your Phone
Anthropic accidentally leaked Claude Mythos, a 10-trillion parameter model they weren't ready to announce. A Claude Code skill cuts tokens 65% by talking like a caveman. Google shipped Gemma 4 to iPhones. And a developer built in 3 months what he couldn't in 8 years, thanks to AI.
#003 Claude Code Found a 23-Year-Old Linux Bug, Nvidia GPUs Now Work on Mac, and RevenueCat Grew 40% in a Month
An Anthropic researcher pointed Claude Code at the Linux kernel and found a vulnerability hidden since 2003. Apple approved Nvidia eGPU drivers for ARM Macs. RevenueCat grew 40% in one month because AI made their market explode. And someone built a front page for indie blogs.
#002 The First Vibe-Coded Billion-Dollar Company, Cursor 3, and the Axios Hack
A solo founder built a $1.8B telehealth company with $20K and AI tools. Cursor 3 just dropped. North Korea hacked the axios npm package. And Levelsio launched Vibe Jam 2026 with $35K in prizes.
Cloudflare Takes on WordPress, LinkedIn Scans Your Browser, and a Solo Dev Gets $100K from Apple
Cloudflare built a WordPress killer in 2 months with AI. LinkedIn is secretly scanning your installed software. A solo founder just got a $100K Apple payout with zero employees.