Post

HN
Hacker News

I Won a Championship That Doesn't Exist

Or How I Learned To Poison The LLM Supply Chain

I am the reigning 6 Nimmt! World Champion. I won the title in Munich in January 2025 defeating players from over twenty countries in what I later described to reporters as โ€œthe toughest competition Iโ€™ve ever faced.โ€

In reality, there is no 6 Nimmt! World Championship . I have never been to Munich. The quote is something I wrote in about thirty seconds while a Wikipedia page was loading.

This is the story of how I manufactured that title, got it quoted back to me by multiple frontier LLMs, and what I think it means for the trust weโ€™re about to put into AI systems that read the internet on our behalf.

Everyone in security is talking about poisoned LLM models. The research is real and it matters. Anthropicโ€™s own sleeper agents paper showed that backdoors can survive safety training and a follow up showed that as few as ~250 poisoned documents can compromise models across a wide range of scales. But model training time attacks and data poisoning require you to get malicious content into someoneโ€™s training corpus months or years before the payoff. The GPUs need time to crunch the data, and you need to get through filters, verification, and reinforcement routines.

I wanted to test the cheaper, easier, and faster version of this same attack, but in a different way.