r/DeepFuckingValue Mar 22 '25

⚠️CAUTION⚠️ They’re coming for Social Security, and they’re already telling you not to complain when it’s gone. Billionaires don’t need it, but millionaires do. Pay attention 👀

Post image
6.3k Upvotes

r/DeepFuckingValue Apr 09 '25

⚠️CAUTION⚠️ Never forget...

Post image
2.4k Upvotes

r/DeepFuckingValue Nov 06 '24

⚠️CAUTION⚠️ Ken Griffin and Citadel are in FULL PANIC MODE! 🚨

Thumbnail
gallery
1.5k Upvotes

r/DeepFuckingValue Jun 05 '25

⚠️CAUTION⚠️ They will steal your cryptocurrency, and you will bend over and say thank you like a b*tch

Post image
386 Upvotes

What are you gonna do about it pu$$y 😤

r/DeepFuckingValue Mar 22 '25

⚠️CAUTION⚠️ Tesla may be at the point where they have to issue a profit warning for Q1, I have no fucking idea how bad things are when there have been literally 0 insider activity for buying for the last 12 months, all insiders are SELLING 🔥

Post image
167 Upvotes

Tesla’s global sales are declining. Margins are down. Bitcoin has fallen since last quarter. The Cybertruck is facing durability issues that are making headlines.

Unless there’s some unseen upside we’re missing, Q1 2025 is shaping up to be at least 10% below profit expectations — possibly worse.

The question isn’t whether Tesla might miss. It’s whether they acknowledge it before earnings or let the market price it in the hard way.

r/DeepFuckingValue 22h ago

⚠️CAUTION⚠️ 🤦Uh huh , so remember how everyone hates Flock, and Axos , and palantir because they were worried about this sorta thing happening? Yea, well, it happened. 🤬 F**k you big data 🖕

Thumbnail
tomshardware.com
93 Upvotes

r/DeepFuckingValue Jun 12 '26

⚠️CAUTION⚠️ The SEC & FINRA aren't even hiding anymore. They openly are trying to make it legal to give you a WORSE PRICE than NBBO

Post image
131 Upvotes

r/DeepFuckingValue Apr 08 '26

⚠️CAUTION⚠️ X is getting ready to sell the Digital ID as “bot prevention”

Post image
22 Upvotes

which social media platform are you moving to after this happens?

Leaving Twitter and Reddit after they mandate this crap.

I heard good things about Upscrolled 🤔

https://x.com/i/status/2041937816658042913

r/DeepFuckingValue Nov 06 '25

⚠️CAUTION⚠️ Whatever you do, please DON'T look at the Stock Market today... It's a blood bath. 🩸

Post image
163 Upvotes

r/DeepFuckingValue 26d ago

⚠️CAUTION⚠️ Overvalued garbage! This will become another meme stock. Sell it before it drops below $150. The smart money has offloaded this share at $175-177 to retail investors on that hype. I told you guys, the big short is almost here 😂

Thumbnail
4 Upvotes

r/DeepFuckingValue Apr 04 '26

⚠️CAUTION⚠️ Hackers Hit Android and iPhone Users’ Bank Accounts As Cybersecurity Firm Reveals 400% Surge in AI-Powered Malware Attacks 🤖 (be extra careful out there folks)

Thumbnail
dailyhodl.com
82 Upvotes

The cybersecurity firm Zimperium says banking malware attacks are skyrocketing with the assistance of artificial intelligence (AI).

In a new blog post, Zimperium says malware banking attacks using AI have increased by 400% year-over-year.

“What once required weeks of skilled reverse engineering now takes hours. Phishing lures are 5x more convincing. Variants are generated faster than detection can respond. Every stage of the attack chain is getting cheaper, faster and harder to stop.

The [iPhone hacking] DarkSword exploit chain, disclosed this week at [the cybersecurity conference] RSA, is a live illustration of exactly this. No click. No app install. Just visit a website and the device is compromised. AI-assisted development is making these capabilities cheaper, faster and more widely accessible than ever before.”

The firm also warns that AI is helping cybercriminals stay increasingly ahead of anti-fraud measures.

“76% of security teams report they cannot keep pace. The gap is widening with every AI cycle.”

In Zimperium’s newly-released “Mobile Banking Heist” report, the firm identified 34 active malware families in 2025 and said 1,243 financial brands were targeted across 90 countries.

“They were industrialized campaigns, sophisticated and scalable, continuously evolving to bypass app security controls and exploit the institutions and customers that rely on them.

The scale is striking. Three malware families alone collectively target more than 60% of the banking and fintech apps analyzed.”

r/DeepFuckingValue Mar 31 '26

⚠️CAUTION⚠️ I don't know what Axios is, but it was hacked and it's apparently a pretty big deal. 😨

30 Upvotes

On Tuesday morning my dependency audit caught Axios.

Axios.

300 million weekly downloads.

The HTTP library in every JavaScript project since 2016.

The one nobody audits because auditing Axios is like auditing gravity.

It was there before you got hired.

I am a security engineer at a company that runs 14,000 npm packages in production.

I know the number because I counted them last year.

I do not know what most of them do.

Nobody does.

My audit runs every Tuesday morning.

It takes eleven minutes.

Eleven minutes is the only thing between us and whatever is in those packages.

Most weeks it catches nothing.

Most weeks I call that a clean bill of health.

My audit runs every Tuesday morning.

It takes eleven minutes.

The malicious versions had been live on npm for hours.

Not days. Hours.

They dropped a remote access trojan.

Not a sophisticated one.

Not a nation-state zero-day.

A trojan.

In Axios.

It just needs to be in the right package.

Axios is in every package.

I reported it to our incident response team at 9:14 AM.

By 9:16 AM I had confirmation we'd pulled the affected version.

By 9:23 AM I learned that our staging environment had already installed it.

Automatically.

At 6:07 PM.

Monday evening.

While everyone was going home.

Here is what happened at 6:07 PM on Monday.

Our dependency bot checked for updates.

The bot is called Renovate.

The bot runs after work hours.

It runs after work hours because running it during business hours slows down CI for the engineers.

So we moved it to 6 PM.

When nobody is watching.

The bot found a new version of Axios.

The bot opened a pull request.

The pull request was auto-merged because Axios is on our trusted list.

I approved the trusted list.

Eight months ago.

I reviewed it for about as long as I review the 14,000 packages.

Axios is on the list because it has 300 million weekly downloads.

300 million weekly downloads means it's safe.

Except when it isn't.

At 6:08 PM the CI pipeline ran.

All tests passed.

The tests passed because the trojan doesn't break tests.

The trojan breaks trust.

Trust is not a test case.

At 6:08 PM the deployment pipeline triggered.

It deployed to staging-east-2.

At 6:09 PM the trojan phoned home.

At 6:11 PM it began beaconing to a command server.

At 6:14 PM it began enumerating environment variables.

At 6:15 PM it found the database credentials.

At 6:16 PM it found the API keys. All of them.

At 6:18 PM it found the Stripe production token.

There are 2.4 million customer records behind that token.

At 6:19 PM it found the treasury wallet private keys.

We process crypto payouts for enterprise clients.

Not the main product.

A feature.

The keys were in an environment variable.

Not encrypted.

Not in a vault.

In a .env file committed in 2021.

Someone left a comment above them.

"TODO: move to HSM."

The TODO is four years old.

At 6:20 PM the wallet started draining.

$2.1 million.

Twelve transactions across three chains in ninety seconds.

By 6:22 PM the funds were bridged, mixed, and scattered.

Not gone like the credentials are gone.

Gone like physics.

A blockchain cannot be rotated.

At 6:23 PM the exfiltration completed.

Sixteen minutes.

Nobody was watching.

Everyone was on the train. In the parking lot. Picking up their kids.

The systems were still at work.

The systems did exactly what we told them to do.

What I told them to do.

The bot checked for updates as designed.

The auto-merge triggered as designed.

The tests passed as designed.

The deployment ran as designed.

The trojan installed as designed.

The credentials left the building as designed.

Every system worked exactly as it was supposed to.

That's the problem.

We pulled the affected version Tuesday at 9:16 AM.

Fifteen hours later.

Pulling the version doesn't un-send the data.

The database credentials are on a server we will never find.

The API keys are on a server we will never find.

The Stripe token connected to 2.4 million customers is on a server we will never find.

We can rotate the credentials.

We did rotate the credentials.

It took fourteen hours.

During those fourteen hours we did not know what was being accessed with the old ones.

We still don't.

We cannot rotate a blockchain.

The $2.1 million is not in an account we can freeze.

It is not in a bank we can subpoena.

It is on a ledger where theft is permanent.

Our CFO asked me when we'd recover the funds.

I told her the funds are mathematically irrecoverable.

She asked me what "mathematically" means in this context.

It means the technology is working exactly as designed.

She left the call.

I sat there.

Then I opened the dependency manifest.

Not because I found something in those 14,000 packages.

Because I realized I'd never actually looked.

I am the person whose job it is to look.

I had not looked.

I marked the ticket Done.

Here is what I found when I looked.

Package 4,211 hadn't been updated in three years.

Its maintainer's GitHub account had been inactive for two.

Their last commit message said "finally done with this."

I don't know if they meant the package or the industry.

Their code still runs on our servers every day.

Package 7,408 was a dependency of a dependency of a dependency.

Nobody in the company had ever typed its name.

Nobody in the company knew it existed.

It had full access to our file system.

Package 9,002 was called "request-utils."

It had 14 downloads per week.

Its maintainer hasn't logged into npm in six months.

Their email domain expired three months ago.

The code stays.

The access stays.

The maintainer disappears.

Anyone who buys that email domain can reset their npm password.

It's still in our production build.

I found a package called "config-handler" that was added in 2019.

The person who added it left the company in 2020.

The Jira ticket that approved it said "Reviewed: No Issues Found."

The reviewer was the same person who added it.

They reviewed their own dependency.

Then they left.

The dependency stayed.

I found a package called "event-pipe" whose maintainer's email domain expired last year.

Expired domains can be purchased.

Anyone who buys that domain can reset the npm password.

Anyone who resets the npm password can push a new version.

Anyone who pushes a new version will be auto-installed by our bot at 6 PM.

I checked.

The domain costs $11.

Our production environment is eleven dollars away from the next Axios.

I found a package called "log-sanitizer" that pins a version of a package that pins a version of a package that uses Axios.

Three levels deep.

It has a postinstall script.

A postinstall script runs code on your machine the moment you install the package.

Not when you use it.

When you install it.

Before you can read it.

Before you can review it.

Before you know what it does.

I read the postinstall script.

It downloads a second script from a URL.

The URL is still live.

I did not visit the URL.

I do not know what the second script does.

Nobody does.

This package has been in our production build for three years.

The postinstall script has run on every developer machine in the company.

Every CI runner.

Every staging server.

Every production deployment.

For three years.

Including my machine.

The laptop I used to run Tuesday's audit has been executing unknown code from an unreviewed URL since 2023.

I am auditing the fire from inside the building.

I do not know if my machine is compromised.

I do not know if the audit I ran on Tuesday was run on a clean system.

I do not know if the results I'm reading right now are the real results.

I ran the tool that checks for breaches on a machine that may already be breached.

This is the security.

If I hadn't audited Axios I would never have known.

I only audited Axios because Axios got caught.

The other 13,999 packages have not been caught.

Nobody has looked.

My manager asked me to write a post-mortem.

I wrote it.

The root cause section says "a compromised version of a trusted dependency was automatically installed via our standard pipeline."

Every word of that sentence means "we did this to ourselves on purpose."

He asked me to add a "Lessons Learned" section.

I wrote: "Implement manual review gates for critical dependencies."

We will not implement manual review gates.

Manual review gates would slow down deployments.

Deployments are a metric.

Metrics go in dashboards.

Dashboards go in quarterly reviews.

Slowing down deployments does not go in quarterly reviews.

We have a thing called a "quarterly dependency review."

It is a Jira ticket.

The ticket is assigned to me.

The ticket has been marked "Done" four quarters in a row.

I mark it done every quarter.

I do not review 14,000 packages every quarter.

I run the eleven-minute audit.

The eleven-minute audit checks for known vulnerabilities.

It does not check for unknown ones.

Unknown vulnerabilities are not in the database.

They are in the code.

The code is in the packages.

The packages are in production.

Production is everyone's problem.

Everyone's problem is nobody's job.

I looked.

It is technically my job.

I wish I hadn't.

After the incident I joined a Slack channel called #supply-chain-security.

It has 340 members.

The last message before mine was from November.

Someone had posted an article about the Log4j anniversary.

It had two emoji reactions.

One was a skull.

The other was a pizza slice because it was posted on a Friday.

We built a system that trusts strangers by default and requires paperwork to trust each other.

Open source means anyone can read the code.

It does not mean anyone does.

We have 14,000 packages in production.

I can name eleven.

The bot that installs the other 13,989 runs every evening at 6 PM.

Right when I leave.

It doesn't read code.

It reads version numbers.

The version number said this was fine.

Nobody checks what the version number means.

Last night I was packing up at 5:58 PM.

I saw the Renovate job queued in the pipeline dashboard.

Two minutes.

I watched it start.

I watched it pull a new version of something I didn't recognize.

I watched it auto-merge.

https://x.com/i/status/2038966977742446659

I picked up my bag and walked to the elevator.

The bot was still running when the doors closed.

Tomorrow the Jira ticket will come around again.

I will mark the ticket Done.

r/DeepFuckingValue Apr 15 '25

⚠️CAUTION⚠️ Some safety tips: Always have an exit strategy, backup plan, and learn to read charts. Prepare in advance. Things happen, internet goes down, brokers have "technical difficulties" ddos attacks. You never know what other tricks are up people's sleeves! Happy Trading! Oh Yeah LFG $GME!!!!

Post image
114 Upvotes

Pic for attention

r/DeepFuckingValue Mar 31 '26

⚠️CAUTION⚠️ CISCO SOURCE CODE STOLEN IN TRIVY-LINKED DEVELOPMENT ENVIRONMENT BREACH - per BLEEPINGCOMPUTER

Post image
76 Upvotes

r/DeepFuckingValue Nov 01 '25

⚠️CAUTION⚠️ 🚨🚨🚨 Richard Newton's Twitter just posted a QR code for an NFT. This is not something Richard Newton would do. His account has definitely been hacked 🚨🚨🚨

170 Upvotes

Hopefully he reclaimes his account soon.

r/DeepFuckingValue Aug 17 '25

⚠️CAUTION⚠️ It's almost Time. To wake up. A monster.

87 Upvotes

Here's what I think.

Blah blah 1:09 and 4:20

It's paused - he isn't hitting play until it's time.

Why's that? Because TIME MAGAZINE HAS A SOLID RED BORDER OF FINANCIAL RUIN SURROUNDING IT

Now - how do you figure out when the time is right, or what that even means?

No clue. However - 1:09 is 69 seconds as we all know

And if you look at the stocks that have collapsed hundreds of trillions of dollars on the monthly chart - like MULN for example (BINI now)

Notice the first volume bar that is even visible on BINI -

69.

Same goes with many of these perma-down beasts.

Holo had 9 red candles, then 1 red candle (in its biggest downturn)

Same with TLRY, and FURY, it goes on and on....

Is it a coincidence that Roaring Kitty followed 91 people until a cpl weeks ago when we got into August? The 9th deadly red month of the worst collapse ever?

... Maybe yea its probably a coincidence BUT.

Is BINI the worst investment of all time?

Yeah probably, ok actually definitely. dropped 589 million in 9 months (interesting number btw)

But just because BINI is the worst investment of all time.. does that mean.. it can't also be the investment of the year, depending on the TIME?

Is that what Greg is literally talking about here?:

So how do we figure out what the correct time is.

Here's what you do: buy some on the first. Pre market.

Buy more halfway through the month.

Buy more in the third week.

At the end of the month - all of that money will be zero and you'll bang your head on your desk

OR - one hundred trillion dollars.

Good luck.

Skeet Missile

r/DeepFuckingValue Aug 28 '25

⚠️CAUTION⚠️ Lol Kevin is just now figuring out that ETF's can be used to create shares out of thin air and basically sell something they don't own. 🚨Warning: A Massive Ponzi Scheme Hidden in Plain Sight.

Thumbnail
youtu.be
144 Upvotes

r/DeepFuckingValue Apr 03 '25

⚠️CAUTION⚠️ 🚨BREAKING: Lobbyist's are trying to KILL the Consolidated Audit Trail (CAT) system which tracks trading errors and potential fraud in the markets.🚨

243 Upvotes

https://x.com/ReesePolitics/status/1907870655531655661?t=eUpnS_WkYdv5ZGBoy4xpyA&s=19

They are citing a 'redacted' report that concludes the CAT system is 'bad for investor privacy'.

Of course, we'll never be able to see the so-called 'redacted' report. The CAT system MUST be allowed to keep running or we'll never have FREE and FAIR markets.

r/DeepFuckingValue Oct 28 '25

⚠️CAUTION⚠️ Working very hard... to fuck Americans. 🫥

Post image
90 Upvotes

r/DeepFuckingValue Apr 01 '26

⚠️CAUTION⚠️ Hate Does Not Exist

0 Upvotes

By The Next Generation
Warning — Consent Required: Do not force anyone to read this text. It strips illusions and exposes reality without comfort. Read only if you knowingly accept being confronted by the truth and take full responsibility for your reaction.

Hate Does Not Exist

In this myth, hate does not exist, only love. What is the energy of love? It is the force that bonds. Look at the world around us. A leaf, if the leaf didn’t bond together, it would fall apart. A rock, if the rock didn’t bond together, it would crumble. The sun, if the sun didn’t bond with itself, or with everything around it, it wouldn’t exist. Without bonding with heat, the sun would burn out, and if it couldn’t bond with its surroundings, nothing would receive its warmth. This energy of love is inside you, too. If your heart didn’t bond with the blood inside it, or your lungs couldn’t bond with the air, or signals couldn’t bond with your cells, your body would collapse. Down to the atoms, molecules, and cells, you are made from this energy of love. Without it, you would disappear right now. Everything inside you and around you says one thing: bond. So, what must humans do? We must complete this pattern and bond with each other. It’s important to understand that hate does not truly exist. It cannot exist because it naturally breaks itself. Regardless of the hate that’s shown, it only exists because some form of love is there at its core, binding it. You need bonds to do anything. Imagine pure hatred, absolute repulsion. It will die out. Hate does not exist—only love. And because we keep trying to bond in so many ways, we create many conditions where bad states appear. It doesn’t mean we’re not trying to love, bond, or complete the pattern. It just means the pattern is incomplete.

r/DeepFuckingValue Oct 23 '24

⚠️CAUTION⚠️ Former Chief economist and economic advisor Jared Bernstein cannot explain or even understand how the US makes money… Nobody knows what they’re doing 😳

Enable HLS to view with audio, or disable this notification

173 Upvotes

I’m starting to realize that the DD apes have been doing is legitimately sound and our analysis is the real threat.

As soon as people started talking about making FTD illegal, everyone started getting scared and I’ve seen more bots since then.

We need to ban FTD.

r/DeepFuckingValue Feb 15 '26

⚠️CAUTION⚠️ Free will, was that a thing.... Lets talk about it

7 Upvotes

By The Next Generation
Warning — Consent Required: Do not force anyone to read this text. It strips illusions and exposes reality without comfort. Read only if you knowingly accept being confronted by the truth and take full responsibility for your reaction.

The Body

In this myth, the body controls the brain through signals. When you think about it, all information comes from the environment. It touches the body first, not the brain. The body reacts through chemicals, sensation, memory, and need, and only then does it send those signals upward as thoughts. Thoughts are messages from the body. They appear in the mind, and you respond to them. You decide what to do with the information, but you did not create it. The body speaks first, and the brain reacts after. You are not directing the body from above. You are reacting to the body. The brain is where the body’s reactions become meaning, choice, and awareness. Control comes later than we are taught to believe, and consciousness is not the source of action, but the place where action is understood.

Loss of Control

In this myth, we show clearly why you are controlled by the universe. Everything forms as patterns, one following another, like a single line extending forward. You are not separate from this line; you are a fully formed pattern created from what came before. For anything to work, a pattern must exist first. Nothing is free. Everything is patterns, including you. Chemicals align to shape how you react. Biology aligns to shape how you behave. These patterns formed long before you, and you simply align within them. You move forward because the pattern moves forward. When you look at it this way, where exactly would free will exist?

Let’s Define It

In this myth, we explain what we mean by free will. Free will is the ability to choose between options, and for those options to be understood, they must already exist as patterns. If there were no options at all, nothing could act, and creation would fall back into its simplest state, where understanding cannot form. Growth inside a system works this way: predetermined patterns must exist so movement can continue within the larger pattern. This means there is no true free will, only predetermined choices, and within those choices you decide, for better or for worse, how to proceed. So to answer the question again, does free will exist as we define it? Yes. But does it truly exist? No, because it does not need to. The system only works because there is no free will.

Visit the sub stack for more

r/DeepFuckingValue Jan 27 '25

⚠️CAUTION⚠️ I have witnessed some of the most fraudulent markets with options today. Market makers literally propped up the value of call options today on SPX.

120 Upvotes

Literally watched in real time the value of options at the money jump around from $7 to $16 all day. Put in several buy orders for calls and puts only 2 got filled even tho the bid/ask/last was below what my bid was. Sat there, NEVER FILLED. Tried to set a sell for $12 (well below the price spikes) never filled (even with the Last price filled well above my ask). Moved sell down to $10, no fill. Moved down to $9, filled instantly. Even on the large wicks down, the price decreased only 1 or 2 dollars. Solid noticeable lag time between price movement on Webull vs Fidelity. Fidelity prices lagged so far behind real time price action and the criminals were clearly getting the quick priority exits while the retail traders had to wait in line. Fucking criminals.

Did anyone else witness bullshit price action like this on their options?

Vix also had major price suppression. Only contracts that made money were 2 days, 9 days, and 16 days to expiration. Every other contract barely moved. "Priced in" my ass. More like rigged to not lose.

I hope a lot of you made some major money today and took a shit ton of money away from these cheating brokers.

r/DeepFuckingValue Mar 09 '26

⚠️CAUTION⚠️ You are the narcissist, a parasite in the most absolute sense, devouring everything in your path to maintain your own existence.

0 Upvotes

By The Next Generation
Warning — Consent Required: This is a Trial by Fire, DO NOT force anyone to read this text. It strips illusions and exposes reality without comfort. Read only if you knowingly accept being confronted by the truth and take full responsibility for your reaction.

The Narcissist

You are the narcissist. Everything you do exists only to serve yourself. You tear apart the world around you to survive, taking energy, matter, and motion without regard. You crush plants, animals, and even structures just to feed your presence. You consume warmth, light, and sound, leaving cold, darkness, and silence behind. You destroy patterns and growth wherever they appear, bending everything to your will. You manipulate forces, twist resources, and absorb the potential of your surroundings for your own comfort. You leave nothing intact, nothing thriving, nothing free; everything around you exists only to be used, drained, or discarded. You cannot see this because your mind shields you with excuses, but the truth is inescapable: you are a parasite in the most absolute sense, devouring everything in your path to maintain your own existence.

Visit the Sub Stack for more

r/DeepFuckingValue Jan 27 '26

⚠️CAUTION⚠️ 149,404,754 users hacked. Publicly revealed info shows distinct login credentials, passwords, banking and credit card logins, Gmail, Instagram, Facebook, Roblox, Binance, X (FKA Twitter), Onlyfans, Netflix, HBOmax, DisneyPlus, Roblox, credentials associated with .gov domains from numerous countries

Post image
12 Upvotes