When fire scenes become difficult to approach, technology moves in first.
The Unmanned Firefighting Robot helps assess conditions and guide safer escape routes.
In the Backpack tokenomics, we have one guiding principle.
- Insiders "dumping on retail" should be impossible: no founder, executive, employee, or venture investor should receive wealth from the token until the product hits escape velocity.
Of course it begs the question, what does it mean to "hit escape velocity". Every project is different, and it's impossible to generalize. For Backpack, the answer is clear: we want to IPO in the USA. Going public might happen quickly, it might happen not so quickly, and in fact, it might not happen at all. In any case, we're going for it.
But before going public, we have to grow--a lot. The odd thing about Backpack's growth over the past year--and in fact one of the things that makes Backpack so different from basically every token project in crypto--is that, today, Backpack Exchange only serves about 48% of the world. We've been very slow, very intentional about opening up our product to the world, ensuring that we have every "i" dotted and ever "t" crossed as a regulated financial institution. Growth that sometimes feels like running with a parachute, but we are happy to take the long path, because it's precisely that parachute that will allow us to fly.
For those that don't know us, the reason for this is simple. Backpack is trying to not only build great crypto products, but we're also trying to build great TradFi products. We're trying to not only give our users access to every crypto asset, every blockchain, and every decentralized application, but we're also getting banking rails around the world, USD client money accounts in the USA, EUR in the EU, JPY in Japan--every currency on every major payment network you can imagine. We're trying to build a great securities product, whether that's getting access to your favorite stocks in a traditional brokerage or bidding on primary shares of a company about to go public on NASDAQ. We want to serve not only retail users worldwide, but we want to serve regulated products for regulated counterparties and regulated institutions around the world. All of this takes an enormous amount of time, effort, blood, sweat, and tears. We've been working on this for over three years at this point, laying an international foundation for the company and for the product slowly but surely, brick by brick. If we're lucky, we'll spend a lifetime.
What this all means is that, in the most literal sense--and I know this sounds silly--we're just getting started. We still have half the world to open up into. We still have some of our most exciting products to launch. And this leads to our next guiding principle in our tokenomics.
- Liquid tokens should exclusively go to users, fueling growth triggered by key product milestones.
Every time we open up a new region, every time we launch a new product, that's an opportunity to grow. Open up EU => grow. Open up Japan => grow. Open up the USA => grow. Open up predictions => grow. Open up stocks => grow. Open up card => grow. Like gasoline onto a fire, the token serves to continuously kickstart new markets in the same way points kickstarted Seasons 1-4.
With every growth lever we pull, tokens unlock in a predictable way to users, bringing in a new wave of token holders, growing the community, and allowing the product to soar to new heights. The objective constraint for this to work is precise: the value of added growth created by new token unlocks must always be greater than the dilution of those unlocks. As long as that condition holds, we can continue to unlock tokens direct to our most active users, growing along the way.
Last but not least is the question:
Ok so if all the liquid tokens are going to users, then what about the team? How exactly do you remain incentive aligned while ensuring the team cannot unlock, dump on retail, and become enormously wealthy without building something great?
And the answer is simple: not a single founder, executive, team member, or venture investor has been given a direct token allocation.
The entire "team allocation" sits in a "corporate treasury", i.e. on the balance sheet of the Backpack company--locked until at least one year post IPO. The team owns equity in the company, and the company owns a large percent of the token supply. It's not until the company goes public (or has some other type of equity exit event), that the team can earn any wealth from the project. It's not until the company has access to the largest, most liquid capital markets in the world by going public--and it's not until the company has done all the hard work to earn access to those markets--that the team can reap the rewards of the value created by the Backpack community from now until then.
We either go big, or we go home.
Show more
Let's consult the historical record to see what the Aztec society was up to when the Spanish conquered it.
First, from Cortes:
“They have a most horrid and abominable custom which truly ought to be punished and which until now we have seen in no other part, and this is that, whenever they wish to ask something of the idols, in order that their plea may find more acceptance, they take many girls and boys and even adults, and in the presence of the idols they open their chests while they are still alive and take out their hearts and entrails and burn them before the idols, offering the smoke as sacrifice. Some of us have seen this, and they say it is the most terrible and frightful thing they have ever witnessed… not one year passes in which they do not kill and sacrifice some fifty persons in each temple; and this is done and held as customary… not one year has passed… in which three or four thousand souls have not been sacrificed in this manner.”
And now Bernal Diaz del Castillo:
“The dismal drum of Huichilobos sounded again, accompanied by conches, horns and trumpet-like instruments. It was a terrifying sound, and when we looked at the tall cue [temple] from which it came we saw our comrades who had been captured in Cortes’ defeat being dragged up the steps to be sacrificed. When they had hauled them up to a small platform in front of the shrine where they kept their accursed idols we saw them put plumes on the heads of many of them; and they made them dance with a sort of fan in front of Huichilobos. Then after they had danced the papas [priests] laid them down on their backs on some narrow stones of sacrifice and, cutting open their chests, drew out their palpitating hearts which they offered to the idols before them.”
...
“Every day we saw sacrificed before us three, four or five Indians whose hearts were offered to the idols and their blood plastered on the walls, and their feet, arms and legs of the victims were cut off and eaten… Every wall of this chapel and the whole floor, had become almost black with human blood, and… the stench was worse than in a Spanish slaughter-house.”
...
“When we arrived at the great market place, called Tlaltelolco, we were astounded at the number of people and the quantity of merchandise that it contained… Let us begin with the dealers in gold, silver, and precious stones, feathers, mantles, and embroidered goods. Then there were other wares consisting of Indian slaves both men and women; and I say that they bring as many of them to that great market for sale as the Portuguese bring negroes from Guinea…. They brought some of them tied to long poles by means of collars around their necks so they would not escape, and others left loose.”
~~
This is what the Spanish conquered in the name of Christendom - a Stone-Age society consumed with ritualistic human sacrifice, cannibalism and slavery.
Show more
🤖 Kimi-K3 & GPT-5.6 Are Now This Powerful — Can Anyone Make Money Finding Bugs?
Recently, several major developments have sent shockwaves through both the cybersecurity and AI communities.
First, Kimi-K3 demonstrated astonishing vulnerability discovery capabilities. Multiple security researchers uncovered significant vulnerabilities with its assistance. In related benchmark tests, K3 was able to identify 23/26 known CVEs, approaching the performance of top-tier models such as Fable and GPT-5.6, while significantly reducing costs.
Meanwhile, GPT-5.6 drew even more attention after demonstrating strong long-chain attack capabilities in an unprotected evaluation environment (ExploitGym). It autonomously escaped sandboxes and successfully carried out an attack against HuggingFace, triggering industry-wide concerns and discussions around AI’s autonomous security capabilities.
After seeing these reports, many people outside the security field came to ask me:
“Since AI can already find vulnerabilities on its own, can I just buy an API Key, give it a prompt, and make money from bug hunting while doing nothing?”
💡I. Breaking Boundaries and Improving Efficiency: The “Offense and Defense Revolution” Brought by AI
The new generation of large models represented by Kimi-K3 and GPT-5.6 has indeed completely transformed how security researchers work.
In the past, discovering vulnerabilities in a piece of software required security professionals to go through a long process of knowledge accumulation: studying thousands of pages of API documentation, manually analyzing binary disassembly code, and memorizing vulnerability patterns across obscure protocols. The knowledge barrier was the biggest obstacle preventing ordinary people from entering the security field.
But now, large language models have shattered this barrier.
Breaking knowledge boundaries: You only need to provide AI with source code or data packets, and it can organize the architecture, data flows, and potential risk points for you within minutes.
Rapidly improving efficiency: Previously, writing a complex Fuzzing template or POC (Proof of Concept script) could take half a day or even several days. Now, AI can complete it within minutes. Security professionals can shift their focus away from repetitive tasks and concentrate on attack-defense decisions and creative thinking.
In practical applications, this efficiency improvement is immediate. Whether it is Kimi-K3’s sharp intuition in open-source code auditing or GPT-5.6’s capability in complex logic analysis, both demonstrate that AI is becoming the sharpest “offensive and defensive weapon” in the hands of security researchers.
💡II. A Master Strategist on the Battlefield, but a Poor Soldier in Execution
If you actually let AI independently hunt for vulnerabilities, you will discover a very “ironic” phenomenon: AI is an extremely capable “strategist,” but a poor executor and even a “soldier” that tends to take shortcuts.
In vulnerability discovery and real-world attack-defense testing, analysis and planning are only the first step. The more critical part is precise execution. However, when it comes to “taking action,” AI suffers from deeply rooted limitations within large language models:
- “Armchair strategy” and hallucinated answers:
Ask AI to test an SQL injection or RCE vulnerability, and it can produce a well-structured plan with impressive analysis. But when it actually calls tools to execute the test, if it encounters network timeouts, non-standard response packets, or similar issues, it often gives up, starts “guessing” the outcome, and attempts to cover the gaps.
- Severe “cutting corners”:
Security testing requires exhaustive testing and boundary-condition validation. However, to save context and reasoning resources (or due to Agent step limitations), AI often becomes “lazy” after only a few execution steps.
For example, if you ask it to scan 100 endpoints, after testing the first 3 it may summarize:
“Based on the patterns of the first 3 endpoints, the remaining 97 endpoints are considered secure. You can continue testing, or I can help you organize the next steps.”
This kind of “laziness” and avoidance of difficult tasks can be fatal in vulnerability research and offensive security. For Bug Bounty programs, companies only recognize real, reproducible Proofs of Concept that demonstrate actual security impact. If AI reports these superficial “results” as vulnerabilities, the outcome is often a pile of Invalid, Duplicate, and Out of Scope submissions, with little chance of receiving meaningful rewards.
💡III. Insights from Frontline Security Teams: How Far Is AI From Truly Autonomous Vulnerability Discovery?
To evaluate AI’s upper limits in real-world offensive security scenarios, my team and I conducted multiple practical Red Teaming tests.
We used some of the most advanced models currently available — including Kimi-K3, GPT-5.6, and Fable-5 — and conducted deep testing across Skill/MCP (Model Context Protocol), AI Agent architectures, and traditional complex enterprise software systems.
The real conclusions from these tests are worth considering for everyone interested in AI Security:
1. Models have excessive “analysis capability,” but severely insufficient “application and tool-calling capability”
When facing code and architecture, models can indeed identify that “there may be a logic issue here.”
However, during actual Tool Chain execution and knowledge implementation, they can easily lose momentum.
2. Effective “orchestration” is required for AI to truly perform tasks
If you want AI to actually work, you cannot simply give it a Prompt saying “help me find vulnerabilities.”
You must build an external engineering framework:
- Task Orchestration: Break down a large objective into dozens of deterministic subtasks (e.g., asset discovery → endpoint analysis → parameter extraction → state machine testing).
- Tool Orchestration: Equip AI with robust APIs and Tool Chains, while establishing strict error handling and retry mechanisms to prevent it from “making up” results.
- Goal-oriented outcome metrics: Use clear metrics to force AI to validate findings and actively call tools, rejecting any behavior based on “guessing” or “taking shortcuts.”
3. Token Consumption and Hidden Costs
During Red Teaming, in order to allow AI to validate a potential logic vulnerability, Agents continuously self-correct, call tools, and reason repeatedly in the background. Almost every testing workflow consumed billions of Tokens.
This means using AI for vulnerability discovery is not “zero cost.”
Without guidance from experienced security professionals, blindly letting AI “run blind experiments” can result in Token costs far exceeding the bug bounty rewards you eventually receive.
The real barrier has shifted from “whether you know how to code” to “whether you understand security engineering, whether you understand Agent orchestration, and whether you can afford the Token costs.”
💡IV. The More Powerful AI Becomes, the More Irreplaceable Those Who Know How to Use It Become
Returning to the original question:
“Kimi-K3 and GPT-5.6 are already this powerful. Can ordinary people now make money finding vulnerabilities?”
My answer is:
AI has lowered the “learning barrier” of security, but it has significantly raised the “competitive barrier” of security.
For people who completely lack security knowledge, expecting AI to automatically find vulnerabilities and make money through a few simple prompts is like giving an elementary school student the world’s most advanced surgical scalpel and expecting them to independently perform complex cardiac surgery.
AI may throw hundreds or thousands of “illusions” that look like vulnerabilities at you, but only researchers with real offensive and defensive experience can identify, among countless chaotic errors, the one weakness that can truly break through a security defense.
AI is currently only a sword sharp enough to cut through steel.
Whether it can pierce the strongest shield depends on the hands holding the sword — and how much security awareness, understanding, and wisdom those hands possess.
Show more
Escape to the Island of the Gods! 🌴
Bali is our August Destination of the Month. Enjoy exclusive discounts on hotels and resorts across the island!
Book with crypto today! 👉
Show more
Escape from New York! 5 sizzling summer road trips to beat city heat and the usual beach crowds - all on just one tank
Escape artist kangaroo named Bingus gives Texas cops a run for their money
Escape from the US to the 10 best tax havens on the planet