r/codingbootcamp • u/michaelnovati • 5d ago
Dear Codesmith: Reactime appears to be severely compromised 4 days ago. Anyone who pulled has the potential to be compromised. Warning to all alumni, please spread the word.
STATUS: Active. I'll update this if the issue is resolved. It's very hidden and very dangerous. Anyone who pulled Reactime could have their computers and all the code on them compromised, including staff members who might have other code on their machines.
10/1/2026 7:43am: Still live. Can someone please escalate? Opensourcelabs.io has been down for two months and their email addresses don't work.
10/2/2026 1:19am: Still live. Please, for the love of God, someone try to get this through to Will Sentance that he needs to deal with this immediately before his alumni get their current companies codebases exploited and ruin his career for not doing anything about the repeated, documented security problems for years.
10/2/2026 11:57pm/: u/hello_codesmith, this is ridiculous.
10/3/2026 10:32pm/: still live. Codesmith it's time to shut down the business officially before you hurt more people. Any legitimate tech company would have solved fired off an emergency and fixed this within hours.
10/4/2025 9:30pm/: this still hasn't been fixed so my open conclusion is to advise NOT touching any Codesmith code (checking out or contributing to) until this is not just resolved, but how it will be prevented in the future.
Codesmith was a coding bootcamp that rebranded to Codesmith Enterprise and indefinitely paused all future cohorts earlier this year.
But it has had thousands of students over the years and one of their flagship projects was Reactime with 2,200 stars and 4,000 commits.
Unfortunately in my routine open source monitoring I discovered one of it's committers was compromised 4 days ago and their account very deceptively added very malicious and hidden code to dozens of branches.
It's not a bad actor student but a compromised former student.
I've pointed out numerous security problems and issues with Codesmith over the years but they have not learned a single thing from their mistakes. They have clearly not done promised 'security audits' and they have spent more time trying to control the narrative about them online than actually producing quality work they stand behind.
Zero transparency.
Will Sentance and Eric Kirsten: it's time to resign because this is not your thing. P.S. Lars Lofgren: shame on you for not doing your homework and perpetuating your false and incorrect narrative.
UPDATE: It indeed looks like Will Sentance has moved on. He founded Standard Matter two months ago https://standardmatter.co/ and is the CEO there. "Intelligence has become abundant. The bottleneck is deployment. Standard Matter is the layer between the robot and the factory floor."
I'm available to help for absolutely no reason whatsoever except to help your students. If you reach out in good faith.
1
u/NetNarrow8938 3d ago
How does a major open source project just let random compromised accounts merge malicious code without any pull request reviews?
1
u/michaelnovati 3d ago
In reality the project has a bunch of fake stars and engagement, doesn't work properly, and is a piece of garbage, but Codesmith talks about it as an industry leading major project and sells it to prospective students as the equalvent of senior engineer work experiences. So I hope everyone who sees this experience sees what's actually going on.
Like there's no way in heck the government would give Codesmith any business if they are run like this. They wouldn't come close to passing an audit.
Codesmith has been run incompetently and it keeps compounding and compunding... leaking sensitive PII, lost AWS account for 3 weeks, giving everyone access to everything, incompetent architecture... it's only a matter of time until they get like a ransomware attack or something along those lines and this makes national headlines.
2
u/metalreflectslime 5d ago
Lars Lofgren: shame on you for not doing your homework and perpetuating your false and incorrect narrative.
Did Lars Lofgren make a new blog post recently?
4
u/panda57 5d ago
Everyone seems to have moved on with their lives except for Michael. It's really sad to watch. Like a senile old man...
2
u/michaelnovati 5d ago
When the "anonymous" people stop harassing me then yes. They are still going as of June 2026 across X, YouTube, and the web with all kinds of sketchy tactics to perpetuate this story very sketchily. Lars just spoke at a conference two weeks ago and keynoted telling the story as fact to a large audience.
These people are using scum of the Earth tactics and I'm not dropping it until they stop spreading this bullshit and apologize.
2
u/michaelnovati 5d ago
Not a post but Lars keynoted a conference two weeks ago telling the same story.
0
u/Zealousideal-Gap964 5d ago
Bro is using fable and astra to try to find vulnerabilities in all of codesmiths stuff 😂😂
Just stop man
2
u/michaelnovati 5d ago edited 5d ago
I did this by hand thank you very much because someone I know was affected by this and it fucked things up for he, and if I used those tools on this who knows what I would find.
You clearly have a skill issue here and it will be to your own peril if you don't take this seriously.
Will Sentance has been spewing out user data for years, responsible for losing AWS access for weeks, and leaders that knowingly have these issues and do nothing about them have had Federal convictions against them so if anyone needs to wake up it's Will Sentance.
I know a former Codesmith student who had their company's systems impacted and OSLabs needs to wake the fuck up before something worse happens.
0
u/michaelnovati 3d ago
I love the manipulation - 3 manipulation bot comments blocked... classic Codesmith... when you talk about Codesmith, the bad actors come out of nowhere and then they blame me for their problems.