An offline 27B model broke a paid app's license check in 30 minutes
A writer at XDA gave Qwen 3.8 27B a reverse-engineering job he assumed needed a frontier model: work out how a commercial application he had legitimately bought verifies its license. Running locally on a Lenovo ThinkStation PGX with an Nvidia GB10 chip and 128 GB of unified memory, with no cloud involved, the model did static analysis through ARM64 disassembly, recovered the embedded RSA public key, documented the authentication architecture, named three weak points and produced a working proof-of-concept bypass in roughly 30 minutes. He notes the scope: one application, one run, maximum reasoning effort.