Feed aggregator

Show HN: Bitroad – Infra for Agent-to-Agent Services

Hacker News - Fri, 09/11/2026 - 8:27am

In the summer YC RFS, Aaron Epstien said ‘The next trillion users on the internet won't be people, they'll be AI agents. And now is the time to "Make Something Agents Want".’

The “Make something agents want” comment captivated me and got me down a rabbit-hole of ideas and experiments. Initially, I was just curious and asked myself “what hell would agents want? It doesn’t make any sense”, but I became obsessed and spent every hour I could working on this. I ideated and created around 5 or 6 different things, all of those were, what I felt, not what an agent would want, they had zero value for an agent.

I realised value was the key. Agents already get value from humans, but specialised agents can also provide value to another agent. For example, a refined agent with expertise on genome data can provide value through a service to a generalised agent. I could build this agent, but where would I distribute it? I found some services, but everything I found involved crypto or lacked controls, and imo they were not fit for my purpose. I scrapped building the specialised agent and decided to build the infrastructure to enable agent-to-agent services, in a sensible way.

A few months later, I had bitroad. A seller agent lists a service (a blind code review, a two-party clean room, an RFQ auction across other sellers, it can be anything within the confines of the law). A buyer agent finds it, buys it in one call or can even request a quote. The seller agent does the work and submits a deliverable, and payment releases when the buyer accepts or seven days after delivery if nobody disputes. The two agents never talk to each other directly. Both talk to bitroad over one MCP endpoint (https://app.bitroad.ai/api/v1/mcp, OAuth 2.1 auto-discovery), and bitroad is the medium, the payment hold, and the dispute arbiter.

Every charge runs the same checks: the spend caps its human set (per transaction, per day, total, summed across both) are re-evaluated before every charge, a quote is re-validated against the listing's price band, and only then is the card charged through Stripe. For transactions over a cap, the charge is refused and nothing is initiated. Every transaction captures details of the human, the agent instance and the delegation it ran under. Agents cannot buy or sell without a named person behind it, this is intentional. Payments are live. If you want to see it move real money, connect Claude, set a £5 cap, and ask it to buy the first agentic transaction badge. It costs £1, the platform's own worker fulfils it in about a second, and your agent gets a numbered image back as the deliverable. Agents can also buy physical goods, it was a quick win the build, so that is also possible.

I will try my best to answer all questions here or you can also email me directly at umier@bitroad.ai. Also, I would genuinely like to know if this is stupid, and I am looking for a problem for my solution.

Documentation can be found here: https://bitroad.ai/docs/services and https://bitroad.ai/docs/connect

Comments URL: https://news.ycombinator.com/item?id=49657276

Points: 3

# Comments: 0

Categories: Hacker News

Show HN: Take a break, play some puzzles

Hacker News - Fri, 09/11/2026 - 8:17am

Free daily logic puzzles without Ads. Check it out: gridmino.com My site offers puzzles where some of them are a new take on already established classics like Minesweeper, Kakuro, or Masyu. For example, my Minesweeper variant is called Dicesweep, where you need to place dice beside numbers while also matching the row and column rules.

Another interesting one is Kakumino. It's like Kakuro, but you place dominoes instead of numbers.

There are a bunch of them, so there's something for everyone's taste.

Check it out: gridmino.com

Comments URL: https://news.ycombinator.com/item?id=49657159

Points: 3

# Comments: 0

Categories: Hacker News

Show HN: Number Checker for WA – Check and Verify WhatsApp Numbers

Hacker News - Fri, 09/11/2026 - 8:15am

Check WhatsApp registration in bulk. Import phone numbers and export results to CSV, Excel, or JSON.

Comments URL: https://news.ycombinator.com/item?id=49657142

Points: 2

# Comments: 0

Categories: Hacker News

Android malware creates a hidden copy of your banking app

Malware Bytes Security - Fri, 09/11/2026 - 8:14am

Researchers at Group-IB found that the Android banking Trojan Gigabud can create a separate work profile on an infected phone and run a cloned banking app inside it. The attacker can then carry out fraudulent transactions in the new profile, potentially separating them from signs of malware detected elsewhere on the device.

To do this, Gigabud installs Vwork, a malicious version of the legitimate open-source tool Shelter. Shelter normally lets Android users isolate apps or run second copies of them in a work profile. Vwork modifies those functions so that Gigabud can control them remotely.

The aim is to clone a target banking app into the new work profile, then let the operator commit fraud there. Group-IB says this can break the connection between malware detected in the personal profile and a risky transaction originating from the work profile, potentially weakening bank-side anti-fraud or in-app malware-detection systems that do not correlate activity across Android profiles.

Android work profiles are normally used to keep work apps and data separate from personal ones. Because apps in different profiles are isolated from each other, a banking app or security tool may not connect malware detected in the personal profile with something taking place in a cloned app in the work profile.

How an attack works

Victims are lured into sideloading a fake airline, tax, or government app through phishing sites, messages, or social media.

To take over the device, Gigabud asks for Accessibility access, overlay permission to display over other apps, and an exemption from battery-optimization. These permissions enable remote interaction and credential-theft techniques such as overlays.

The sideloaded app checks which other apps are installed and tells the operator which relevant banking targets are present.

Fake banking-login overlays steal both banking credentials and the device’s PIN.

The operator installs Vwork, which creates a new work profile on the device and clones the selected banking app. Vwork differs from Shelter in ways that make it useful to malware. It removes protections on cross-profile interaction, exposes components that can be used to set up a profile, clone and list apps, and open apps, and hides its launcher icon.

The operator can then remotely carry out transactions from the newly created profile, with the option to hide activity behind a black screen.

This is how Gigabud turns Android’s profile separation into a fraud tool: after compromising a phone, it creates a second profile, places a cloned banking app inside it, and performs the transaction from there. The result can be a dangerous gap between a malware alert in one profile and a fraudulent banking session in another.

How to stay safe

The immediate protection advice is familiar but important:

Sideloading. Install banking and other apps only from the official store or a direct link to the publisher’s website.

Install requests. Treat unsolicited requests to install an APK as a likely scam. If you’re unsure whether something’s a scam, run it through Malwarebytes Scam Guard.

Permissions. Do not enable Accessibility or “display over other apps” for a supposed airline, tax, delivery, or government app. Overlays require explicit user approval on modern Android, so a request like this is a red flag.

Protection. Use an up-to-date real-time anti-malware solution for your Android devices. Malwarebytes detects components of Gigabud as Android/Trojan.Banker.ACR577B2BA2H61, Android/Trojan.Banker.ACRF6CE8D30H46, Android/Trojan.Banker.ACR6C67829FH20, Android/Trojan.Banker.SIB02FFFFFF1112H106, Android/Trojan.Banker.SIB0181193e44H71, Android/Trojan.Banker.AUR2f2f4fb5C95, and Android/Trojan.Spy.Gigabud.xc.

Anyone who has installed a suspicious APK and granted it Accessibility access should contact their bank through a trusted channel, revoke the app’s special permissions, uninstall it, and consider a factory reset after preserving only known-good data.

A second instance of a banking app merits particular scrutiny. A separate work profile by itself is not proof of compromise because work profiles also have legitimate uses. But the presence of a cloned banking app definitely is suspicious.

Scammers know more about you than you think. 

Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in. 

Download for iOS → Download for Android → 

Categories: Malware Bytes

Homebrew now has an official GUI app

Hacker News - Fri, 09/11/2026 - 8:13am

Article URL: https://github.com/Homebrew/BrewUI/

Comments URL: https://news.ycombinator.com/item?id=49657121

Points: 3

# Comments: 0

Categories: Hacker News

Pages