{"id":425686,"date":"2026-10-09T07:40:56","date_gmt":"2026-10-09T07:40:56","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=425686"},"modified":"2026-10-09T12:52:14","modified_gmt":"2026-10-09T12:52:14","slug":"y-combinator-application-github-scam","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/y-combinator-application-github-scam\/","title":{"rendered":"Y Combinator Application Scam: Fake GitHub Invites and Wallet Theft Risks"},"content":{"rendered":"<p>A Y Combinator application invitation arrives through a GitHub notification. For someone building a startup, that combination can look relevant enough to investigate between coding tasks.<\/p><div id=\"mwtad3592963699\" class=\"gas_fallback-ad_309684--placement_406659\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The offer mentions a funding batch and a registration process. Before treating it as an opportunity, follow the invitation&#8217;s details more carefully than its familiar branding.<\/p>\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/yc-hero.png\" class=\"wp-image-425687\" alt=\"Illustrative fake startup application page using a fictional domain and wallet verification prompt\" width=\"1536\" height=\"1024\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/yc-hero.png 1536w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/yc-hero-300x200.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/yc-hero-1024x683.png 1024w\" sizes=\"auto, (max-width: 1536px) 100vw, 1536px\" \/><\/figure>\n<div id=\"mwtad1207525307\" class=\"gas_fallback-ad_309746-ad_309685-placement_406660\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<h3>A startup application becomes a wallet-verification pretext<\/h3>\n<p>The Y Combinator application scam uses a false funding invitation to bring developers to an imitation application page and persuade them to authorize dangerous wallet activity.<\/p><div id=\"mwtad3531093412\" class=\"gas_fallback-ad_381396-ad_309685-placement_406667\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The documented W2026 version refers to EIP-712 and Ethereum Attestation Service, then tries to explain a withdrawal warning as an ordinary signature confirmation.<\/p>\n<p>That explanation should stop the process. A warning about assets leaving your wallet cannot be dismissed merely because an application page calls it verification.<\/p>\n<h3>GitHub can deliver a message without endorsing its contents<\/h3>\n<p>The campaign reportedly abused GitHub notifications by mentioning users in repository activity. A legitimate delivery platform can carry text written by an unrelated person.<\/p><div id=\"mwtad3789506845\" class=\"gas_fallback-ad_309686-ad_309685-placement_406668\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>Neither GitHub nor the real Y Combinator becomes responsible for that person&#8217;s offer. Notification authenticity and the truth of its contents are separate questions.<\/p>\n<p>The recorded imitation domain, y-comblnator[.]com, resembles ycombinator.com but changes its spelling. Do not use the defanged address as an application route.<\/p>\n<h3>What we can verify, and what remains historical<\/h3>\n<p>This W2026 lure was documented in September 2025. Our October 9, 2026 check of YC&#8217;s real application page showed the Winter 2027 cycle.<\/p><div id=\"mwtad3431769492\" class=\"gas_fallback-ad_381401-ad_309685-placement_406669\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The suspect domain did not produce a usable fresh capture. We did not execute its wallet requests or verify a particular victim transaction.<\/p>\n<ul>\n<li>Reach YC applications through its independently opened official website.<\/li>\n<li>Treat issue mentions as user-generated conversation, not accelerator approval.<\/li>\n<li>Reject requests to reinterpret withdrawals as harmless identity checks.<\/li>\n<li>Review signatures and transactions in the wallet itself.<\/li>\n<\/ul>\n<p>The first image is an original illustration with a fictional address. It explains the application-to-wallet switch without presenting a recreated page as captured evidence.<\/p>\n<div id=\"mwtad4180386415\" class=\"gas_fallback-ad_309747-ad_309685-placement_406661\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How an Ordinary Development Notification Becomes Persuasive<\/h2>\n<div id=\"mwtad2377247544\" class=\"gas_fallback-ad_381404-ad_309685-placement_406670\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>Developers receive automated notifications throughout the day. Issues, pull requests, and mentions routinely arrive with links that are useful to their work.<\/p>\n<p>An invitation delivered in that setting benefits from the routine. The recipient may recognize the email infrastructure and spend less time questioning the underlying author.<\/p>\n<p>GitHub&#8217;s <a href=\"https:\/\/docs.github.com\/en\/subscriptions-and-notifications\/concepts\/about-notifications\" target=\"_blank\" rel=\"noopener\">notification documentation<\/a> explains that mentions and subscribed activity can trigger updates. These are communication features, not background checks on offers.<\/p>\n<p>Someone does not need to be your investor to mention your username. They also do not need authorization from an accelerator to write its name.<\/p>\n<p>A public repository can reveal enough about your interests to make an unsolicited startup invitation plausible. That relevance does not establish a personal relationship.<\/p>\n<p>The useful distinction is who authored the invitation. A mail service delivers it; a repository hosts it; a particular account supplies its content.<\/p>\n<p>Check those layers separately. Trust in one layer should not automatically extend to an external destination linked from another.<\/p>\n<div id=\"mwtad905561340\" class=\"gas_fallback-ad_309748-ad_309685-placement_406662\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the Y Combinator Application Scam Works<\/h2>\n<h3>Step 1: A GitHub mention introduces a funding opportunity<\/h3>\n<p>The reported campaign starts by using repository activity to get an invitation in front of people who build software. Its context makes the funding story relevant.<\/p>\n<p>The recipient may see a GitHub-generated email and assume the linked opportunity has been vetted. That assumption gives the attacker a credibility shortcut.<\/p>\n<p>Open your known GitHub notification page independently if you need to inspect the event. Look at the author, repository, and conversation before following external links.<\/p>\n<p>An unexpected mention in a repository you do not recognize deserves scrutiny. A real repository can also contain spam, so ownership alone does not settle it.<\/p>\n<p>Do not reply with company secrets or a pitch deck simply to ask whether the invitation is genuine. Verify the organization through a separate contact route.<\/p>\n<h3>Step 2: A lookalike address borrows the accelerator&#8217;s identity<\/h3>\n<p>The recorded domain inserts a hyphen and uses a lookalike letter. At a glance, a reader can recognize the brand without reading its spelling accurately.<\/p>\n<p>This is particularly easy on a small screen or when a button hides the full address. The visible invitation can say one thing while linking elsewhere.<\/p>\n<p>A polished logo does not repair a mismatched destination. Nor does HTTPS demonstrate that the organization named on a page operates that site.<\/p>\n<p>Rather than memorizing every possible lookalike, begin at YC&#8217;s established website. Follow the application link it publishes there.<\/p>\n<p>That method also avoids relying on an old campaign&#8217;s domain after it disappears. The spelling may change while the false application story remains recognizable.<\/p>\n<h3>Step 3: Registration introduces an unexpected crypto requirement<\/h3>\n<p>The imitation page changes the task from describing a startup to verifying a digital wallet. Its technical terms make the extra step appear procedural.<\/p>\n<p>A founder eager to complete an application may interpret an unfamiliar requirement as something the program recently introduced.<\/p>\n<p>Pause when the requested access has no clear relationship to the original task. Being considered for funding does not itself justify authorizing another party to move assets.<\/p>\n<p>If you have a legitimate reason to discuss crypto with an accelerator, confirm that process through its established contacts. The unexpected page cannot validate itself.<\/p>\n<p>You should not need to experiment with a valuable wallet to determine whether an application requirement makes sense.<\/p>\n<h3>Step 4: Technical vocabulary is used to dismiss the wallet&#8217;s warning<\/h3>\n<p>The documented page invokes EIP-712, a real standard for signing structured data. Using its name does not make the data safe to sign.<\/p>\n<p>The <a href=\"https:\/\/eips.ethereum.org\/EIPS\/eip-712\" target=\"_blank\" rel=\"noopener\">EIP-712 specification<\/a> describes a signing format. It is not a certification program for startup applications or the websites requesting signatures.<\/p>\n<p>Different signed messages have different effects. Some authenticate a session; others can authorize operations that become consequential when submitted to a compatible contract.<\/p>\n<p>The fraud&#8217;s particularly concerning move is its attempt to normalize a withdrawal notification. It tells the reader to disregard the meaning of a separate security prompt.<\/p>\n<p>When a webpage&#8217;s explanation conflicts with your wallet&#8217;s displayed effects, reject the request. Seek clarification through verified channels before signing anything.<\/p>\n<h3>Step 5: An authorization can expose assets while the applicant waits<\/h3>\n<p>If a person grants a harmful permission or signs a usable transfer authorization, an attacker may be able to move assets covered by that action.<\/p>\n<p>A routine connection is not the same as signing a malicious request. The exact transaction or signature determines what access was granted.<\/p>\n<p>For this historical case, no independently reproduced contract analysis is available here. We therefore do not claim a specific chain, spender, loss amount, or universal outcome.<\/p>\n<p>The practical warning remains firm: reject an imitation application that asks you to explain away withdrawal warnings.<\/p>\n<p>Any follow-up request to deposit more funds for verification should be investigated separately. Do not keep paying to complete a process whose identity is already wrong.<\/p>\n<div id=\"mwtad1525133042\" class=\"gas_fallback-ad_318930-ad_309685-placement_406663\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3818335085\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Checking the Real YC Application Route<\/h2>\n<p>The official <a href=\"https:\/\/www.ycombinator.com\/apply\" target=\"_blank\" rel=\"noopener\">Apply to YC page<\/a> links to the application system and describes the current process. Start there when assessing an invitation.<\/p>\n<p>On our review date, it described the Winter 2027 batch. That date matters because the fraudulent specimen&#8217;s W2026 language belongs to an earlier cycle.<\/p>\n<p>This screenshot shows the real application page, captured directly on October 9, 2026. It is a comparison reference, not the fraudulent invitation.<\/p>\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/capture-yc-real.png\" class=\"wp-image-425688\" alt=\"Official Y Combinator application page showing the Winter 2027 cycle\" width=\"1280\" height=\"900\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/capture-yc-real.png 1280w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/capture-yc-real-300x211.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/capture-yc-real-1024x720.png 1024w\" sizes=\"auto, (max-width: 1280px) 100vw, 1280px\" \/><\/figure>\n<p>An old label is not the sole evidence of fraud. Archived legitimate pages also exist. The stronger issues are the imitation identity and dangerous wallet-verification instructions.<\/p>\n<p>Look for consistency across the published process, application address, and contact information. Resolve an unexpected requirement through the organization&#8217;s own communication channels.<\/p>\n<p>A legitimate application can involve confidential business information. Verify the destination before uploading financial projections, customer details, unpublished code, or a pitch deck.<\/p>\n<p>Do not paste an application link containing private tokens into a public discussion. Share a redacted domain or ask support privately through the official route.<\/p>\n<h2>Reading a Wallet Prompt Without Being Rushed<\/h2>\n<h3>Check the action instead of the page&#8217;s label<\/h3>\n<p>The term verification is not a technical guarantee. Read whether the wallet is requesting a connection, signature, spending allowance, or transaction.<\/p>\n<p>If the request concerns token spending, inspect the asset, network, permitted amount, and spender. A broad allowance deserves scrutiny even when no funds move immediately.<\/p>\n<h3>Do not equate no gas fee with no risk<\/h3>\n<p>Some signatures do not immediately create a paid blockchain transaction. Depending on the protocol, they can still authorize something another party later submits.<\/p>\n<p>Judge the authority being granted, not just whether the wallet displays a gas charge. Free-to-sign is not another name for safe.<\/p>\n<h3>Keep business identity separate from signing authority<\/h3>\n<p>Owning a repository or applying with a company email does not require exposing a treasury wallet. Treat requests involving organizational funds as a separate approval decision.<\/p>\n<p>If colleagues share financial responsibilities, follow the team&#8217;s established signing process. A surprise application deadline should not bypass it.<\/p>\n<h2>What to Do if You Have Fallen Victim to This Scam<\/h2>\n<ol>\n<li>\n<p><strong>Stop the application flow.<\/strong> Reject any pending wallet requests and leave the imitation site. Record the domain and the GitHub issue or notification that introduced it.<\/p>\n<p>Do not revisit the page to reproduce the request. Screenshots, wallet activity, and existing transaction records are safer evidence than another interaction.<\/p>\n<\/li>\n<li>\n<p><strong>Determine what you authorized.<\/strong> Review recent wallet transactions and any saved signature information. Note the network, assets, spender, and transaction hashes where available.<\/p>\n<p>If you only connected without approving anything further, disconnect the site. Avoid treating that limited interaction as proof that your entire wallet was drained.<\/p>\n<\/li>\n<li>\n<p><strong>Address harmful permissions.<\/strong> Consult verified wallet guidance or <a href=\"https:\/\/revoke.cash\/learn\/security\/what-to-do-when-scammed\" target=\"_blank\" rel=\"noopener\">Revoke.cash&#8217;s incident guidance<\/a> to assess exposed approvals and remaining assets.<\/p>\n<p>Some signature risks require different handling from ordinary allowances. Revoking one approval cannot guarantee that every previously signed authorization has become unusable.<\/p>\n<\/li>\n<li>\n<p><strong>Replace exposed wallet secrets.<\/strong> If you entered recovery words or private keys during the journey, create a new wallet with a new secret on a trusted device.<\/p>\n<p>Protect assets across all accounts derived from the compromised secret. A new local unlock password does not invalidate another person&#8217;s copy of that secret.<\/p>\n<\/li>\n<li>\n<p><strong>Protect business information and accounts.<\/strong> If you uploaded private files or entered credentials, notify the appropriate team members and secure the affected services.<\/p>\n<p>Identify exactly which documents were disclosed. That supports a proportionate response to confidential plans or customer information without assuming unrelated systems were accessed.<\/p>\n<\/li>\n<li>\n<p><strong>Report the abused notification and any loss.<\/strong> Use GitHub&#8217;s reporting tools for the offending content. Include the issue URL and external destination.<\/p>\n<p>For stolen assets, contact any relevant exchange and law enforcement with transaction records. Blockchain visibility can support tracing, but does not guarantee return of funds.<\/p>\n<\/li>\n<li>\n<p><strong>Investigate software exposure when applicable.<\/strong> A wallet transaction and a malware infection are different incidents. Check the device if you installed an extension or ran a download.<\/p>\n<p>Malwarebytes can help inspect suspicious software. AdGuard may reduce deceptive advertising, but neither can invalidate a signature or restore assets transferred on-chain.<\/p>\n<\/li>\n<\/ol>\n<h2>For Repository Owners and Startup Teams<\/h2>\n<p>Public collaboration makes unsolicited contact easy. Have a simple internal route for suspicious funding invitations, especially when messages arrive through developer tools rather than investor contacts.<\/p>\n<p>Avoid reposting the malicious link in issue discussions while warning others. Use a defanged address and report the original content through the platform.<\/p>\n<p>Preserve enough context to explain what happened: the author&#8217;s account, issue location, timing, and claimed organization. A deleted notification alone may lose useful details.<\/p>\n<p>Review notification settings for noisy repositories without disabling important security alerts indiscriminately. The goal is to reduce abuse while keeping legitimate development communication useful.<\/p>\n<p>For treasuries, require independent review of unusual signing requests. A person researching an opportunity should not have to make a financial authorization decision in the same browser session.<\/p>\n<p>If a colleague interacted, focus on facts and recovery. Blame makes it harder to establish whether a signature, password, file upload, or transfer actually occurred.<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<h3>Is Y Combinator itself running this scam?<\/h3>\n<p>No. The warning concerns an imitation application and unauthorized use of YC&#8217;s identity. The legitimate accelerator&#8217;s application process should be reached through its official website.<\/p>\n<h3>Can a genuine GitHub email contain a scam invitation?<\/h3>\n<p>Yes. Notifications can deliver user-written issues or mentions. Authentic platform delivery does not mean GitHub verified an external offer included in that content.<\/p>\n<h3>Does mentioning EIP-712 make wallet verification safe?<\/h3>\n<p>No. EIP-712 specifies structured signing. Safety depends on the actual message, requested authority, and destination, not the presence of the standard&#8217;s name.<\/p>\n<h3>Should I ignore a withdrawal warning during registration?<\/h3>\n<p>No. Reject a request you do not understand. An application page&#8217;s reassurance cannot override the financial effects displayed by your wallet.<\/p>\n<h3>Is the W2026 application still the current batch?<\/h3>\n<p>The fraudulent specimen used that historical label. On October 9, 2026, YC&#8217;s official page advertised Winter 2027; check its current page for later changes.<\/p>\n<h3>What if I only visited the fake site?<\/h3>\n<p>Close it and report the invitation. Visiting alone does not establish asset loss. Investigate further if you signed, disclosed secrets, granted permissions, or installed something.<\/p>\n<h2>The Bottom Line<\/h2>\n<p>The Y Combinator application scam turns a promising invitation into a request for wallet authority. A real GitHub notification can deliver that false promise.<\/p>\n<p>Use YC&#8217;s official application route and refuse instructions that minimize withdrawal warnings. If you authorized something, investigate the exact action before trusting another proposed fix.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A Y Combinator application invitation arrives through a GitHub notification. For someone building a startup, that combination can look relevant enough to investigate between coding tasks. The offer mentions a funding batch and a registration &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"Y Combinator Application Scam: Fake GitHub Invites and Wallet Theft Risks\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/y-combinator-application-github-scam\/#more-425686\" aria-label=\"Read more about Y Combinator Application Scam: Fake GitHub Invites and Wallet Theft Risks\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":425687,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[],"class_list":["post-425686","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/425686","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=425686"}],"version-history":[{"count":1,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/425686\/revisions"}],"predecessor-version":[{"id":425689,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/425686\/revisions\/425689"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/425687"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=425686"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=425686"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=425686"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}