Skip to content
Hacker News front page

2,000 people tried to hack my AI assistant — zero succeeded

What happened after 2k people tried to hack my AI assistant

Fernando exposed his Claude Opus 4.6 email assistant to the public and dared people to extract a secrets.env file. Over 6,000 emails and 2,000 participants tried social engineering, authority impersonation, and multi-language attacks. The secret never leaked. API costs exceeded $500 and Google suspended the Gmail account for three days. The author credits model choice — weaker models would likely break.

Why it matters: 2,000-person red-team exercise with 6,000+ emails, disclosed attack vectors and defense prompt — enough substance for featured. Docked slightly because it's a personal experiment, not a product security advisory, and the Gmail ban / API cost consequences aren't detailed.

Read the original ↗Export Markdown