A local open-weights model built a working license bypass in 30 minutes

Share
A local open-weights model built a working license bypass in 30 minutes

XDA's lead technical editor handed Qwen 3.8 27B — an open-weights model small enough to run on consumer-class hardware — a task he assumed needed a frontier model: reverse-engineering a commercial app's license check. It refused the initial jailbreak, then audited the authentication scheme, recovered a deliberately obscured cryptographic key, caught and corrected its own mistakes, and produced a working bypass — all in about half an hour, entirely offline.

The test ran on a single Lenovo ThinkStation desktop (128 GB of unified memory, no GPU cloud involved). The model worked purely through static analysis: it disassembled the binary, traced thousands of lines of ARM64 instructions, mapped the security functions to their call sites, and reverse-engineered the vendor's authentication architecture until it extracted the public verification key the app signs its licenses against. Since the editor held a legitimately purchased copy, he could confirm that a real license on his machine was signed by a private key matching the reconstructed one. After it located the gate, it turned the finding into a working proof of concept in a few lines of script.

What stood out to the tester was the model's self-correction. The first recovered key produced a passing signature check but a mismatched integrity hash — where most models would have stopped, Qwen flagged the discrepancy, went back to the drawing board, and iterated until the value matched byte for byte. That reliability, combined with the 17 GB V-RAM fit and the absence of any cloud dependency, is why the editor argues this marks a real shift in where this class of capability lives.

The caveats are honest and important: this was one application, one run, on a machine where the tester already owned a license, and a harder target might have stalled it entirely. But the underlying point — that a freely available model running wholly on hardware beside you can now tear apart a commercial authentication system and produce a working bypass — has clear double-edged implications. The same offline, no-governance properties that make local models appealing for analyzing proprietary code and malware also put the decision about their use with whoever sits at the keyboard, which is exactly what makes an unfettered capability like this a real input to threat models.

What to watch: whether labs and app vendors start hardening local-code license schemes the moment small open models turn static analysis into a commodity tool.

Do you think local open-weights models need any form of guardrails for use cases like this — or is fully offline capability the point? Tell us in the comments.

Read more

Australia plans to regulate AI like banks and airlines

Australia plans to regulate AI like banks and airlines

Canberra is putting teeth around model accountability this morning, Google just turned its AI-content detector into a public utility, and Nvidia's dealmaking reportedly reached all the way to OpenRouter. Australia wants AI companies supervised the way banks and airlines are — and it plans to legislate that by 2027. Assistant Minister for Science, Technology and the Digital Economy Andrew Charlton laid out a "systems-based" regime in a speech at the Sydney Trust and Safety Festival on October 8

GPT-6 safety report: fewer refusals, more regressions

GPT-6 safety report: fewer refusals, more regressions

GPT-6 reaches ChatGPT's free tier today, an open-source agent just found its price tag, and world models drew a high-profile new contestant. GPT-6 is rolling out to free ChatGPT users today — and OpenAI's 24-page deployment safety report shows exactly what the model traded to become chattier. Plus, Pro, Business and Enterprise tiers started getting GPT-6 Sol on October 7; free and Go users get GPT-6 Luna from October 8, replacing the GPT-5.6 line in ChatGPT's main chat (Work and Codex models a

Stuart Russell: current training may make AI alignment impossible

Stuart Russell: current training may make AI alignment impossible

A safety-obsessed week just found its second heavyweight: after Hinton asked for an FDA of AI, the man who gave the field the word "alignment" says the current road may not get there at all — while memory markets show exactly where the AI money is going. Stuart Russell says he regrets coining the word "alignment," because the field read it as an engineering target — and he now thinks the way models are trained today may make avoiding misalignment impossible. The Berkeley professor made the cas

Broadcom lines up over $50B to finance OpenAI's custom chip

Broadcom lines up over $50B to finance OpenAI's custom chip

The AI buildout is increasingly being paid for with borrowed money — and today's biggest example puts OpenAI's in-house silicon at the center of it. Also: Nous Research banks a $1.5 billion valuation, and an AI-built Adobe clone suite declares "software is over." Broadcom has been working to arrange more than $50 billion in financing for OpenAI's custom AI chip, with Oracle in separate talks on financing for a large chip purchase, the Wall Street Journal reported. Apollo, Blackstone and Goldma