Nicolas Carlini (67.2k citations on Google Scholar) says Claude is a better security researcher than him, made $3.7 million from exploiting smart contracts, and found vulnerabilities in Linux and Ghost

Reddit r/artificial / 3/30/2026

💬 OpinionDeveloper Stack & InfrastructureSignals & Early TrendsIdeas & Deep Analysis

Key Points

  • Nicolas Carlini says Claude is a better security researcher than he is, positioning LLM-assisted research as an increasingly capable security workflow.
  • He reports having earned $3.7M by exploiting smart contracts, underscoring how serious financial stakes still attach to contract and protocol security weaknesses.
  • Carlini claims a Linux vulnerability introduced in 2003 was not identified until now, attributing its severity to a buffer overflow that can enable attackers to steal an admin key.
  • He also notes LLMs should keep improving over time and suggests this may be accelerated if “Mythos” rumors are true.

Link: https://m.youtube.com/watch?v=1sd26pWhfmg

The Linux exploit is especially interesting because it was introduced in 2003 and was never found until now. It’s also a major security issue because it allows attackers to steal the admin key. It was a buffer overflow error, which are so hard to do that Carlini has never done it before.

He also says he expects LLMs to only get better overtime, which is likely true if Mythos lives up to the rumors.

here are his Wikipedia and Google Scholar pages in case you doubt his credibility: https://en.wikipedia.org/wiki/Nicholas_Carlini

https://scholar.google.com/citations?view_op=search_authors&hl=en&mauthors=carlini&btnG=

submitted by /u/Tolopono
[link] [comments]