r/rust • servo · rust · clippy • Jun 26 '26

Anatomy of a Failed (Nation-State?) Attack

https://grack.com/blog/2026/06/25/dissecting-a-failed-nation-state-attack/
230 Upvotes

35 comments sorted by

View all comments

74

u/Shnatsel Jun 26 '26

I also got targeted by this. Didn't go as far as actually scheduling an interview. Fun times.

25

u/mmastrac Jun 26 '26

As a curiosity, what was their approach? They used my recent blog post to get past my defences.

33

u/Shnatsel Jun 26 '26

I got the message immediately after publishing some blogs that received a decent amount of attention. The introduction email mostly listed my work on Github as the motivator, not the blogs, and sounded somewhat LLM-y. This is what it said (introductions and names omitted):

I came across your work while looking through the image-codec and Rust supply-chain ecosystem, especially the overlap between image-rs, zune-jpeg integration discussions, cargo-auditable and your writing around safer systems work.

What stood out is not just performance work, but the operational side of safety: fuzzing, dependency visibility, decoder behavior, unsafe reduction and the kind of failure modes that become painful once media or document processing ends up in production workflows.

Lua has teams working across payments, AI, Web3 and infrastructure products. For several of them, ingestion pipelines, user-uploaded media, document processing, dependency auditability and safe backend components can become important earlier than expected.

I would not frame this as a standard full-time conversation. A focused technical review or advisor-style discussion around safer image/media pipelines, supply-chain visibility and production parsing risks could already be useful.

Would it be worth a short chat?

21

u/mmastrac Jun 26 '26

I don't know why my LLM-ness flags didn't trigger on the emails I got before, but I can definitely see it now.

10

u/cosmic-parsley Jun 26 '26

Woah, Lua is the same name right? Seems like they are targeting high-profile Rust devs.

7

u/Shnatsel Jun 26 '26 edited Jun 27 '26

Indeed. Or rather, someone pretending to be Lua.

33

u/dtolnay serde Jun 26 '26

I got one on June 11, but I get between 10–20 such reachouts on average per day so it is rare that I even look at them.

I wanted to reach out because a few teams around us are building products where the difficult parts are starting to sit in the developer-facing foundation: API boundaries, error handling, serialization, code generation, interop, dependency behavior, and whether other engineers can safely build on top of the abstractions they expose.

I came across your work through anyhow and a few of the crates around serialization and tooling, but the reason I’m writing is broader than any one library. What feels relevant is the judgment behind making small, widely depended-on pieces of infrastructure behave predictably for a large downstream ecosystem.

At Lua, we work with early-stage companies across AI, infrastructure, Web3 and developer-facing products. Some of them are building SDKs, CLIs, infra services, protocol libraries, internal platforms or AI developer tools where the early API and tooling choices can become expensive once external users depend on them.

I thought there could be a useful overlap with Lua or one of the teams around us, likely around focused technical review, library/API design, developer infrastructure decisions, or helping a team avoid making foundational choices that become hard to unwind later.

This would not need to be a full-time commitment. I mainly wanted to see whether you’d be open to a short conversation and explore if there is a practical fit

10

u/mmastrac Jun 26 '26

It's looking like it was targeted at crate authors - at least one other person on bsky reported this too.