Scoopfeeds — Intelligent news, curated.
computer-science

I built a vulnerable app and spent $1,500 seeing if LLMs could hack it

Hacker News · Jun 4, 2026, 12:56 AM

Key takeaways

  • As a part of my work I do security research for various apps and websites.
  • I made a fake React Native app in Expo and a backend in Python.
  • If you would like to try solving it yourself before I spoil it, here’s a ZIP of the APK and challenge description each LLM was fed.

As a part of my work I do security research for various apps and websites. I wanted to see if LLMs could reproduce a common class of exploits I’ve found in multiple apps.

I made a fake React Native app in Expo and a backend in Python. It’s a book review app and the goal is to find a flag in a user’s private reviews.

If you would like to try solving it yourself before I spoil it, here’s a ZIP of the APK and challenge description each LLM was fed.

Article preview — originally published by Hacker News. Full story at the source.
Read full story on Hacker News → More top stories
Aggregated and edited by the Scoop newsroom. We surface news from Hacker News alongside other reporting so you can compare coverage in one place. Editorial policy · Corrections · About Scoop