How I Hacked Y Combinator's Paxel to Forge Perfect Scores

I got into YC by hacking it

How I Hacked Y Combinator's Paxel to Forge Perfect Scores

I discovered a critical vulnerability in Y Combinator's Paxel application tool that allowed anyone to forge and upload fake performance scores. By exploiting an unvalidated HMAC in their decentralized pipeline, I manipulated the ranking database for over 100,000 founders. After publicly disclosing the bug, YC patched the issue within hours and invited me to attend Startup School in San Francisco.

I knew I was starting from a disadvantage when filling out my application, but I knew this would be a fast-track, surefire way into confirming my acceptance.
  1. a_t48

    Against better judgement, I ran it on my repo. Poking at the "Ask anything about the report" bot, it penalizes me heavily for not having "positive tracked outcomes", as I don't report back to Claude what the outcome is. It wanted me to do this:

    "At the end of research-heavy sessions, add a tiny closure note:

    Decision:

    Use CacheMountStore with registry/local/GHA backends.

    Why:

    GHA cannot expose the same content.Ingester path, local import has discovery issues, registry can resolve by tag.

    Proof / current artifact:

    See files X, Y, Z. Subagent found A, B, C.

    Next action:

    Implement interface in package N. Do not add new cache-mount flags yet. Use mode=cache-mount on existing cache flags."

    There's no need for this, Claude is not my task tracker.

    It also penalized me for:

    - Using Claude to introspect a codebase as throwaway work and ` not close with a crisp “acceptable / risky / copy this / avoid this” decision this session.`. No action was needed, it wasn't an actionable session!

    - Using Fable for code review. `Several BuildKit subagent sessions produced research reports, but the transcript does not show whether those findings became implementation choices.` Yes, Fable launches subagents to code review. Valid findings get turned into fixes or WONTFIX.

    - `The Cloudflare CI upload failure got narrowed well, especially after you supplied the exact timestamp and challenged the /v2 routing recommendation, but the session ended without a chosen next diagnostic owner or act […]

  2. Aurornis

    > Based on Paxel’s own site, 1.2 million+ coders have so far uploaded their reports to YC.

    I checked the Paxel website and it says this:

    > So far, 1,543,553 sessions have been uploaded and analyzed.

    The count is for sessions, not coders. I assume the tool uploads a lot of sessions from each person who uses it.

    That’s a large number, but it’s not a million different people. I am surprised that so many people think it’s a good idea to download a run a program which gathers up their coding sessions and submits information about them.

  3. jppope

    So let me get this straight... technical founders are providing limitless access to their IP, and this is supposed to be a positive indicator that they would be a good founder? Thats wild

  4. smcnc

    I could be mistaken, but isn't Paxel a tool that YC *itself* built to understand how founders/applicants apply AI? If so, this feels less scary than some of the comments (i.e. not 3rd party).

    Also, not trying to take shots, but should the title be "I got into YC Startup School by hacking it" instead? Isn't that different than the main YC program?

    All in all, you did them a solid by finding and responsibly disclosing. Nice job.

  5. jedberg

    For the longest time, the YC application included the question "What was your greatest (non-computer) hack?". They have always liked people who think of ways to work around existing systems. So it's no surprise that their response was positive. Also, all the principals are ex-founders, mostly engineers, who totally understand hacking culture.

    Sadly, it looks like they took that question off the application though.

More from this day

2026-07-24