Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I've got no idea who codewall is. Is there acknowledgment from McKinsey that they actually patched the issue referenced? I don't see any reference to "codewall ai" in any news article before yesterday and there's no names on the site.

https://www.google.com/search?q=codewall+ai



Yeah can't find much information either. I would like to see at least some proof. Either via Mckinsey or from the security team.


it is weird isn't it? The register article implies that it's acknowledged by McKinsey- https://www.theregister.com/2026/03/09/mckinsey_ai_chatbot_h...

Edit: Apparently, this is the CEO https://github.com/eth0izzle


>A McKinsey spokesperson told The Register that it fixed all of the issues identified by CodeWall within hours of learning about the problems.

Ah. Thanks for the link. I'm suspicious of everything posted to a blog without proof these days.


We’re pretty new! :) They didn’t want to provide comment on our post but they did offer comment via The Register.


There's a responsible disclosure timeline at the bottom indicating they'd all been fixed.


I think the point is that we don't have evidence that this actually happened from anyone other than Codewall.


If it's true that there's 58k users in the dump, that would mean former employees are in the dump

I assume that means McKinsey would need to disclose it, or at least alert the former employees of the breach?




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: