He Didn't Get Into YC. He Hacked His Way In.
What happened
A developer poking around YC's Startup School application process discovered that Paxel — the tool YC makes applicants run to auto-analyze their code and generate a "founder score" — had an unvalidated HMAC. That meant anyone could forge and push arbitrary scores straight into YC's ranking database. He disclosed it privately, got silence for 12 days, then went public.
Why this matters
Within hours of the public disclosure, YC's Jared Friedman personally replied, shipped a patch, and invited the hacker to Startup School. It's a rare real-world case study in responsible disclosure actually working — and a reminder that even Silicon Valley's top talent-sorting machine runs on breakable software.
The slightly cynical read
YC quietly outsourcing 1.2 million founders' code analysis to a third-party 'archetype quiz' tool was always going to end in someone finding the seams. The fact it took a public shaming post — not the private email — to get a same-day fix says plenty about where security sits on most companies' priority list.
What to watch next
Expect scrutiny on how many other startup-scoring or recruiting tools quietly run similar 'install this and we'll judge you' scripts, and whether YC audits Paxel's scoring logic more broadly now that its trust model just got publicly cracked.
