Bluetti’s FridgePower does exactly what it says, with enough storage and a high enough output to keep even an ancient, inefficient fridge/freezer going for a few hours off grid. You’ll get longer with modern devices, with our tests suggesting likely backup time of more than a day for today’s efficient fridges. The Bluetti FridgePower isn’t scared of a little heavier duty work, either; it’s got enough poke to run a microwave or two-slot toaster, but it’s not really optimised to be a power-everything kitchen workhorse.
Adds a day’s backup power to a fridge
Very slim and expandable
Strong value
A little noisy
Slightly odd time-of-use behaviour
Key Features
Advertisement
Review Price:
£1299
A slim power station for fridges
Advertisement
This power station is designed to keep your fridge running through a power outage. It stores enough power to last a modern fridge/freezer around a day, and it can even handle some other more power-hungry kitchen devices.
Quite specialised
Advertisement
The FridgePower has only two mains output sockets, with no USB or DC outputs for charging phones, so it’s not really built as a general-purpose power supply.
Introduction
If you live out in the sticks, or you’re often on the road in a camper van, you might be familiar with the problem of keeping a fridge running when you’re away from a reliable source of power. The Bluetti FridgePower aims to provide an answer: it’s a slimline battery power station for fridges, designed to slip in alongside them or sit unobtrusively on top. Its narrow section is deceptive, as Bluetti has squeezed in enough batteries to store just over two kilowatt hours (kWh) of power.
In theory that’s enough to last a modern fridge freezer for over a day of running; perfect for riding out even a significant power cut. And if you live in an area that frequently sees multi-day outages, you can even add up to three expansion batteries, potentially keeping the milk fresh and your peas frozen for a week or more.
Advertisement
While most of today’s fridges top out at only 200-300W of consumption – and typically use quite a bit less – the FridgePower can deliver up to 1,800W. That means you could use it to backup a couple of coolers and perhaps even a microwave or two-slot toaster, but it doesn’t have the grunt for very powerful appliances such as a kettle or oven. We wanted to put this specialised power station through our usual tests, and more.
Advertisement
Design and features
Slim, but heavy
Handle and wall-mounting bracket
Basic but practical display
As you might expect, this power station’s 2kWh of batteries make it rather heavy – almost 20kg in fact – but it comes with a screw-on handle if you do need to cart it around. There’s also a sturdy wall mount if you want to keep it off the floor or counter top.
Image Credit (Trusted Reviews)
The other recommended orientation is to place the Bluetti FridgePower on top of the fridge – that’s how I positioned it, but I’d advise taking great care when lifting it into place or back down again.
Image Credit (Trusted Reviews)
This isn’t built as a general-purpose battery power station, so its ports and inputs are comparatively limited. Around the back you’ll find a standard mains power input and an XC60 connector for DC sources including solar panels. There are also just two mains output sockets. The most significant omission is that you won’t find any USB connectors, a shame if the FridgePower is within reach and you wanted a convenient place to charge a phone.
Advertisement
While Bluetti’s power stations usually get a display showing battery, input and output status, here you get a simplified version that uses five green LEDs to show the state of charge, plus a couple of other indicators for things like grid power availability. This is better than the norm in one important way; it’s always on, giving you an at-a-glance battery check in the middle of a power cut.
Advertisement
Image Credit (Trusted Reviews)
Alternatively you can buy the FridgePower with a magnetic screen designed to stick onto the side of the fridge. I didn’t have one to test, but it appears to work along the same lines as Bluetti’s standard on-device displays, showing the charge state, input and output power at a glance.
This display’s a neat idea, but I’m not convinced it’s necessary given you can get the same information from Bluetti’s app. Here you get the usual range of information and settings, including a choice of function modes. The default Standard UPS mode is fine for straightforward power security: when the grid is up the FridgePower will recharge and provide power, and when it’s down it’ll switch to battery power within 10 milliseconds. There’s also a PV priority mode, which lets you set a battery threshold above which the unit stops recharging on mains power: useful for favouring solar panels if you have them. In this mode, you can configure the use of some mains power to quickly recover a baseline amount of stored energy after a long power cut.
Image Credit (Trusted Reviews)
There are two time-control UPS modes, where the FridgePower recharges and provides standard UPS support during your off-peak hours, then powers your fridge from stored battery power during peak rate. That could be a good way to lower your fridge running costs, but if a power cut occurs late in the day when the battery’s depleted, you’ll get less backup time before your ice cream goes runny.
Advertisement
It isn’t just food that goes off; even the heavy-duty lithium iron phosphate (LFP) batteries in the fridge power will lose some of their capacity over time. Bluetti says that they’ll retain at least 80% of their rated capacity after 4000 full charge cycles, which equates to more than eight years of daily use. You can extend this life by using the app to limit both the maximum state of charge and the maximum depth of discharge. The flipside is that this will leave you with a smaller working battery range, and less time off the grid when you need it.
Bluetti has designed the FridgePower to be expandable. Additional battery units are priced at about £900 each, and could give you a total storage capacity of up to 8,064Wh (8kWh) – enough to power a single fridge freezer for four to eight days. The port for connecting each pack is behind a rubber bung on one of the long edges, seen at the right of this photo.
Advertisement
Image Credit (Trusted Reviews)
The Bluetti FridgePower is the latest example of how battery storage prices are falling. We calculate a power station’s value by dividing its price by the amount of energy you could expect it to store over its batteries’ working lifetime – in this case that’s the 80% over 4,000 cycles figure I mention above. Low values are good, with most of the supplies we’ve tested recently working out somewhere between 10-25p per kWh. Assuming steady degradation over time, and calculated for the discounted £999 launch price, you’d pay about 14p for every kWh stored in the FridgePower, which is among the best we’ve seen.
Charging
Charge from the mains. Solar or vehicle charging are optional
Maximum 1800W AC charging power
Full recharge in a little over an hour and a quarter
If you’re installing the Bluetti FridgePower to backup your fridge or freezer at home, you’ll almost certainly be recharging it from the mains. Typically for a Bluetti power station you can choose from Silent, Standard or Turbo modes, with the latter drawing a maximum of around 1800W. Starting with fully empty batteries, I timed a Turbo recharge to 100% full at 83 minutes. This consumed 2089Wh – only a little more than this power station’s stated capacity.
Advertisement
In truth, there’s unlikely to be much need for recharging this power station in a hurry. At the default Standard mode it demanded around 1200W and finished charging in a couple of hours, consuming 2041Wh in the process. Silent mode demanded 600W, took nearer four hours, and consumed only 2011Wh – actually slightly less than the battery pack’s 2016Wh rated capacity. Based on these tests, Silent recharging would be the ideal choice if you’re using the FridgePower in time-control mode, provided you get at least four hours of off-peak power each night.
Image Credit (Trusted Reviews)
The presence of a DC input port does open up some options, particularly if you have a few solar panels near your kitchen or on the roof of your RV. The Bluetti FridgePower can accept up to 1000W of solar input. If you have an RV and don’t mind shelling out the extra £500 or so for Bluetti’s Charger 2, you could recharge at up to 800W from your van’s alternator alone – provided you also won’t mind losing about 1 horsepower of engine output. This power station supports simultaneous AC and DC charging up to a 2200W maximum.
It’s worth noting a couple of quirks depending on your market. US models will only charge at up to 1440W from the mains, while Japanese models top out at 1200W. UK and EU customers also get the best surge performance (a momentary 3600W) and bypass power output (a sustained 2300W), although even the lowest capabilities as found in the Japanese model should be plenty high enough for a couple of domestic fridges.
Image Credit (Trusted Reviews)
Performance
Stable at maximum power
A bit noisy even at light duty
Very strong efficiency
Advertisement
While I usually head straight for our standard load tests, I first wanted to understand how this power station performed in its intended role. With it connected to my fridge and fully recharged, switching the mains power on and off didn’t cause any noticeable effects at all: the fridge continued working steadily.
Advertisement
I was interested to see whether the FridgePower’s Time Control mode might be a useful way to combine backup power with cheaper off-peak electricity, so I configured it to charge during my overnight off-peak tariff and discharge during the day. My Bosch fridge/freezer typically uses only around 60W, but even so I was amazed at how long the FridgePower’s battery lasted, with a slow discharge that suggested it could go for almost four days between charges. The maths suggested this shouldn’t be possible.
Switching back to Standard UPS mode helped clear things up. Here I put a separate smart socket on the FridgePower’s input cable, scheduled to turn the AC input on only during off-peak hours. The battery power state dropped far quicker when working from battery power in this configuration, suggesting that in Time Control mode the FridgePower had been consuming some grid power during peak hours.
Image Credit (Trusted Reviews)
With a couple of mains power meters added to the setup, I could see that the FridgePower did indeed consume around 60W of mains electricity in Time Control mode. This was constant, and occurred even during peak hours: the time period during which I was trying to avoid any power use. However, because of this the battery was less depleted by the end of peak hours, so there was less off-peak consumption to replenish it.
I let the fridge run for 48 hours in each configuration. The FridgePower (3kWh) and fridge (2kWh) consumed exactly the same amount of power during each test, but in Time Control mode some of the FridgePower’s mains use was during more expensive peak hours – if you were aiming to save money, you’d want to avoid that.
Advertisement
Advertisement
Things were much more straightforward on our standard tests, where we fully recharge a power supply and subject it to a constant load until its batteries are empty. At the maximum 1800W this device supplied only 1558Wh – some way short of its rated storage – while at a steady 1000W load it delivered 1696Wh. Using these figures I calculated a best round-trip efficiency of 84.3% – that’s excellent, meaning that of every 8kWh you store in the FridgePower, you might get nearly 7kWh back out again.
One small annoyance to mention is that the Bluetti FridgePower isn’t fully silent, even when it’s hardly under load. During the day it cycled its cooling fan on and off quite regularly and, while not loud, this was audible enough that it bothered me when watching TV on the other side of our living room. To be fair, I bother easily when it comes to noise – my partner barely noticed it.
Should you buy it?
You need dependable backup for your fridge
Advertisement
The Bluetti FridgePower really is suited to backing up one or two fridges for at least several hours during a power cut, and you can extend this with extra batteries. It’s a good choice if that’s your focus.
Advertisement
You want a general-purpose battery power station
This power station performs well, but it isn’t optimised for more general use in the home. If you want backup power for all your appliances, buy a generalist supply with more ports.
Advertisement
Final Thoughts
If you live somewhere that regularly gets power cuts, the Bluetti FridgePower could be ideal. It stores a sensible amount of power, can easily be upgraded with more, and has a high enough output to cope with the surges of fridge compressors switching on and off. It’s even got a bit of headroom spare to deal with other kitchen gadgets. For the owners of smaller camper vans, this might actually make the FridgePower an option for powering a modest kitchen where a more conventionally shaped power supply simply wouldn’t fit. Whatever you need it for, its 14p per kWh of lifetime energy storage makes it great value.
Personally however, I’d go for a more general-purpose power station where space allows. Alternatives like the Anker SOLIX C2000 Gen 2 offer similar storage and charge modes, combined with more ports and a higher maximum output. That makes them more flexible in a power cut and for everyday device powering and charging – even if they won’t fit neatly down the side of your fridge.
How We Test
We test every power station we review thoroughly over an extended period of time. We use standard tests to compare features properly. We’ll always tell you what we find. We never, ever, accept money to review a product.
Find out more about how we test in our ethics policy.
Advertisement
We test with a variety of devices to see how long the battery will last.
We test different charging methods to see how quickly the battery can be topped up.
Advertisement
FAQs
Where can I buy the Bluetti FridgePower?
Bluetti announced the FridgePower several months before it launched, leading to some confusion among people who wanted to buy it. It’s now available via the Bluetti website, and through resellers like Amazon in territories including the UK, US and Canada.
Can the Bluetti power a refrigerator?
Advertisement
Battery power stations with an output of at least five hundred watts can usually power a refrigerator. In fact, some supplies with just a couple of hundred watts’ output can do it, provided they’re able to cope with the momentary power surge each time the fridge’s compressor starts up. Bluetti’s been sensible with the FridgePower: its 1.8kW output is enough to cope with several coolers cycling on and off, and it gives headroom to spare for other mid-to-high power devices.
When you think of wartime cryptography, you probably think of World War II and Enigma, although there were other famous codes used during that war. But in fact, there have been codes used through wars and in peacetime for much longer. Even the Romans used codes. Of course, World War I, or The Great War, as it would have been known, had its share of codes and, as you might expect, most of these have been broken long ago. Most of them. But apparently an AI model, GPT-6 Astra, recently cracked one that was previously undeciphered.
If you aren’t up on century-old cryptography, the ADFGVX cipher appeared in 1918. It began as ADFGX, but after a few months grew an extra letter — and a larger grid. The letters were chosen because their Morse-code patterns were relatively easy to distinguish: A, D, F, G, V, and X.
The original ADFGX version used a 5×5 grid containing the alphabet, usually merging I and J. The later ADFGVX version expanded this to 6×6, making room for all the letters and the digits as well.
Encoding required a 5×5 (or 6×6) grid with the alphabet within. The table’s rows and columns were labeled… you guessed it… ADFGX pr ADFGVX. Each plaintext letter gets replaced by the corresponding row and column such as AF or XG. Finally, the letter pairs would be written under a transposition key.
Advertisement
Concatenating those pairs gives AGXGDDDXXF. Written in five columns under CANDY, the first row is AGXGD and the second is DDXXF.
Next, you sort the letters in the transposition key, taking the columns along with the letters. That would make the transposition key ACDNY, and the first row would now be GAGXD. Then the message is sent by columns. Too much to wrap your head around? Visit dCode and plug in some plain text, squares, and keywords for yourself.
The French broke the code in 1918, but without computers it was tough work. Codebreaker [Georges Painvin] reportedly worked on the cipher until it made him ill, but he did solve it. However, some of the intercepted messages remained a mystery. One in particular was sent on November 27, 1918. Apparently, the message used the codeword TRUPPENVERSCHIEBUNG, a German key believed to have gone into service in December. If this decoding is correct, then this message used it even earlier.
The message was, of course, in German and appears to be a report about a British ship’s movements near Sevastopol. In fact, HMS Canterbury’s position on the dates mentioned matches the message.
Advertisement
Honestly, we were more impressed that people like [Georges Painvin] in 1918 were able to decode these intercepted messages. But it is still an interesting glimpse into the capabilities of Astra.
The desktop headphone market is starting to look a lot like the rest of high-end audio: fewer boxes, fewer cables, and more functionality packed into a single component. Instead of assembling separate DACs and headphone amplifiers, listeners can increasingly choose one-box solutions designed to handle digital conversion, amplification, source switching, and even preamplifier duties without surrendering performance.
That is precisely the problem the Sendy Audio KYLIN is trying to solve. At $1,499/£1,499, however, simply combining a DAC and headphone amplifier in one handsome chassis is no longer enough. This has become a fiercely competitive category, and buyers spending this much should expect excellent sound, enough power for demanding headphones, useful connectivity, low noise, strong build quality, and the ability to genuinely replace multiple components on the desktop.
Sendy Audio has been one of my favourite headphone manufacturers in recent years. The Aiva 2 impressed me with its craftsmanship and engaging presentation, while the Egret has been one of my favourite planar magnetic headphones of the year so far.
I first listened to the KYLIN at CanJam London and enjoyed it enough that I wanted to spend considerably more time with one away from the noise and chaos of an audio show. Having now lived with it, that initial attraction is still very much there.
Advertisement
But at $1,499/£1,499, excellent sound is only the price of admission. The more important question is whether the Sendy Audio KYLIN does enough to justify replacing a stack of very capable DACs and headphone amplifiers already competing for the same space on your desk.
Related Reading:
Inside the Sendy Audio KYLIN: DAC, Class A Amplification and Connectivity
The KYLIN represents Sendy Audio’s move beyond headphones and into desktop electronics, combining a DAC, preamplifier, and headphone amplifier inside a single, substantial aluminium chassis.
Digital conversion is handled by the familiar ESS ES9038Q2M DAC, partnered with an XMOS USB implementation. Sendy Audio specifies support for native DSD512 playback, while digital connectivity includes USB-B, coaxial, and optical inputs.
Rather than building the KYLIN around the kind of highly integrated amplifier topology that has become commonplace in modern desktop DAC/amps, Sendy has gone with a Class A output stage employing matched Hitachi transistors. Dual Burr-Brown OPA604 op-amps are used in the preamplifier section, with WIMA and Nichicon capacitors also featuring internally.
Advertisement
This is not really trying to compete with products from Topping, FiiO, and similar manufacturers by offering the longest feature list or the most extravagant collection of measurements. The KYLIN feels much more like an old-school headphone amplifier that happens to have a very capable DAC built into it.
Three headphone connections are provided on the front panel: 6.35mm, 4.4mm, and four-pin XLR. Around the back are USB-B, coaxial, and optical digital inputs, alongside three sets of RCA analogue inputs and RCA preamplifier/line-level connectivity.
At this price, I would have liked balanced XLR line outputs. There is certainly enough room on the rear panel, and I am not convinced that three sets of RCA analogue inputs will prove more useful to most buyers than having the option of balanced connectivity to active loudspeakers or a separate power amplifier.
Advertisement. Scroll to continue reading.
Advertisement
Furthermore, the KYLIN provides an altogether more analogue user experience. There are no digital filters to cycle through, no parametric EQ, no large colour interface, and no labyrinth of internal settings to configure. There is not even a remote control. Depending on your perspective, that will either sound refreshingly simple or surprisingly limited.
Plenty of considerably cheaper DAC/amps now offer PEQ, extensive filter controls, Bluetooth, saved profiles, and increasingly sophisticated software ecosystems. Some all-in-one components are even beginning to dabble in AI-assisted functionality.
The KYLIN gives you knobs, switches, and two physical VU meters. I suspect Sendy Audio is perfectly happy with that distinction.
Design & Build
Inside the box, Sendy Audio supplies the KYLIN with the necessary power cable alongside an unusually generous collection of interconnects, including RCA, optical, and multiple USB cables intended to cover the most common computer and mobile-device configurations. It is one of those rare products where you can open the box and have a very good chance of finding the cable you actually need rather than immediately rummaging through a drawer or making another online purchase.
Advertisement
I think the unit itself is beautifully made. That should not come as an enormous surprise if you have handled Sendy Audio’s cans before. Its headphones place considerable emphasis on materials and machining, and the KYLIN takes a similar approach to desktop electronics.
At 245 x 225 x 50mm (9.6 x 8.9 x 2 inches) and roughly 3.1kg, it is not especially large, but there is enough weight to stop it from moving around the desk every time you connect a pair of headphones.
The centrepiece is unquestionably the pair of analogue VU meters. Of course, they are not exactly necessary, but they do look cool. Screens have become almost unavoidable on modern desktop audio equipment. The advantage is obvious when a product has dozens of settings, filters, and input modes, but there is something satisfying about using an amplifier that does not resemble another small computer sitting next to my PC.
The volume knob deserves particular praise because it feels excellent. There is real weight to its movement, with enough resistance that adjustments feel deliberate and precise rather than loose or vague.
Unfortunately, the KYLIN has an unusually small usable window before things get loud. Even with the HiFiMAN HE6se V2 — hardly a headphone famous for being easy to drive — I was operating within roughly the first 10% of the potentiometer’s travel for much of my normal listening. Small movements therefore create disproportionately large changes in output level.
That is irritating with demanding headphones and becomes a much bigger problem with efficient ones. Fine adjustment at lower listening levels is far more difficult than it should be.
Advertisement
There is also audible background noise with sufficiently sensitive headphones. I could hear a noise floor with easy to drive full size dynamic headphones such as the THIEAUDIO Cypher, and I would be very cautious about buying the KYLIN primarily for sensitive IEMs.
Unless you listen to a lot of classical music with very wide dynamic range, extended rests, or extremely quiet passages, the noise floor should not pose a significant problem in normal use. But for a $1,499 headphone amplifier, it is still something that should not really be there.
Advertisement. Scroll to continue reading.
There are certainly no complaints about the thermal performance, though. Despite the Class A design, the chassis only became lukewarm to the touch during extended use. Having spent time with products such as the Aune S17 Pro and LAiV Audio Crescendo VERSE, both of which can generate considerably more heat, I was expecting the Sendy Audio to become rather toasty. It never did.
Advertisement
That makes the KYLIN much easier to live with on a normal desk and gives you far more freedom over placement than some other Class A designs.
Listening & Headphone Synergy
The Sendy Audio KYLIN was used primarily as an all-in-one DAC and headphone amplifier with a range of planar magnetic and dynamic driver headphones. I fed the unit a mixture of high resolution FLAC files and Spotify streams from both my PC and smartphone.
As mentioned previously, my first proper listen to the KYLIN was at CanJam London, where its combination of warmth, dynamics, and physicality immediately stood out. I can now say that those initial impressions have largely survived extended listening.
Perhaps the best thing about the KYLIN is just how dynamic it sounds. Bass has real texture and physical presence, with enough weight behind kick drums and bass guitars to give music a convincing sense of scale. Transients have plenty of impact, and the KYLIN never sounds short of energy, especially in the low end, even when connected to more demanding planar magnetic headphones.
I especially enjoyed listening to Michael Jackson’s “Billie Jean,” where the recurring bassline punched through the rest of the track and gave the song even greater impact.
Advertisement
There is also a subtle old school Class A warmth to its presentation. It is not thick or syrupy in the traditional sense, but there is a little additional richness through the lower registers and midrange that gives instruments more body without completely neutering treble energy.
For that reason, I think the KYLIN pairs especially well with dead neutral headphones such as the HiFiMAN HE1000 Unveiled, adding a hint of cosiness that can otherwise be missing at times. It can also help tone down particularly spicy sections of certain tracks. Hans Zimmer’s “2049” can cause listening fatigue with some systems, but I had no such issues with the KYLIN.
As alluded to previously, the unit also has no trouble driving some of the most demanding headphones currently on the market. The HE6se V2 has earned a reputation for exposing amplifiers that look powerful on paper but struggle to provide convincing control and dynamic authority in practice. Despite this, the KYLIN had plenty of headroom while retaining bass impact and definition, and large dynamic swings never collapsed or became noticeably compressed.
British rapper AJ Tracey’s “Wifey Riddim 4” delivered the level of hard hitting impact I was looking for with the KYLIN paired with the Sendy Audio Egret.
Advertisement
The subtle warmth continues into the midrange, where vocals and guitars possess a pleasing sense of density without obscuring detail. There is enough clarity through the upper midrange and treble to prevent the KYLIN from becoming overly romantic, and it manages to retain a sense of openness despite its richer tonal balance.
That is refreshing in a market dominated by components chasing neutrality and increasingly impressive measurements. The KYLIN still sounds similarly clean and resolving to products from Topping or SMSL, but it adds a degree of dynamic exuberance and tonal character that gives the presentation some personality.
Advertisement. Scroll to continue reading.
The Bottom Line
In an era when a DAC/headphone amplifier costing under $500 can offer colour touchscreens, Bluetooth, parametric EQ, a myriad of filters, and enough menu options to keep you occupied for an entire day, the $1,499 Sendy Audio KYLIN might not initially seem like the most enticing all in one option. It has physical VU meters, conventional controls, and very little in the way of software.
But that more analogue user experience will be exactly what some listeners are looking for. It allows you to focus on the music rather than constantly fiddling with settings in an attempt to make the listening experience that little bit more convenient.
Advertisement
And the KYLIN simply sounds magnificent. It has acres of power, a slightly warm tonal balance that draws attention to its powerful and immaculately controlled bass performance, yet still manages to retain a high level of detail and spatial precision. That is a difficult balance to achieve. The unit is also beautifully constructed, with a reassuring heft and level of finish that make it feel every bit like a serious piece of desktop audio equipment.
Just be aware of the lack of balanced XLR line outputs and the fact that the KYLIN is not the best companion for sensitive IEMs or easy to drive dynamic headphones, owing to its audible noise floor and very narrow usable volume range.
Pros:
Beautifully constructed chassis with excellent physical controls
Analogue VU meters give the KYLIN real character
Substantial power for difficult full-size headphones
Excellent pairing with hard-to-drive planar headphones
Dynamic, textured bass response
Slight Class A warmth without excessive treble roll-off
Runs surprisingly cool for a Class A desktop amplifier
Generous selection of supplied cables
Cons:
Very narrow usable range on the volume control
Audible noise floor with sensitive headphones
No balanced XLR line outputs or remote control
No PEQ, digital-filter selection or extensive internal configuration
There’s no denying the appeal of deep-fried foods, from donuts to drumsticks, plus numerous bite-sized appetizers and every kind of potato. But when it comes to whether to bother deep-frying at home, it isn’t necessarily a matter of difficulty. With the right vessel and thermometer, frying can be a quick, easy way to make memorable dishes — the real issue is: what to do with all that leftover oil?
Shallow frying can also get the job done in many cases, but it can also create a conundrum. Putting that oil down the sink? Potentially drain-clogging, environmentally dubious, and frankly, wasteful. I grew up in a household where leftover grease and oil went into a glass mayonnaise jar kept under the sink, to be discarded once it was full. Sure, this saves the sink, but it doesn’t address the other two issues. It’s a quick kitchen hack that makes it easier to put it out with food waste, but there’s also another solution.
Leftover frying oil is begging to be reused.Pamela Vachon/CNET
Don’t get rid of it. “Oil used for frying is not one and done,” says Melanie Underwood, cookbook author, culinary instructor, and founder of Nourish and Gather, “unless the oil has been overheated, or if you’re frying things that are particularly strong in flavor. With something like seafood, you want to be careful, but it’s perfectly reusable as long as it wasn’t smoking.”
With that, Underwood shares her best practices and advice for reusing oil multiple times before it’s done.
Manage the oil before and during the frying process
A proper frying temperature is between 350 and 400 F.Pamela Vachon/CNET
To ensure oil is good for multiple uses, first make sure you’re using the right oil — something neutral in flavor with a high smoke point. “Any vegetable oil, such as canola oil, peanut oil or sunflower oil, is best for frying,” says Underwood. While olive oil can be tricky to fry with because it has a lower smoke point, “I definitely have used olive oil,” she says, “and I have never had any problem with it whatsoever.”
Resist the impulse to eyeball your oil for temperature clues, or test bits and pieces to make sure you’re in the right zone, unless you fry so regularly that it’s second nature. Otherwise, that’s a recipe for pieces with burnt exteriors and undercooked interiors, and/or smoking out your upstairs neighbors. (Speaking from experience, sadly.) Using a thermometer, “the correct range for frying is usually between 350 to 400,” says Underwood, which prevents smoking.
Just a bit of residue, which you can easily skim off.Pamela Vachon/CNET
During the frying process, it’s a great idea if you can skim out any crumbs or whatever has come off in the oil,” she says, “because when you have little burned pieces, that will degrade the oil faster.”
After frying: cool, strain, and store
Cool, strain and store.Pamela Vachon/CNET
Once you’re done frying, managing the oil for future use is simple. “First, you let it cool,” says Underwood. Don’t try to speed up the process by refrigerating it; just let it sit until it cools to room temperature.
Straining it is also straightforward and can be done with whatever you already have on hand. “I use a fine mesh strainer,” Underwood says. “People also use cheesecloth or a coffee filter. You just want to strain it and get out all those teeny particles.” Some micro particles may still be visible in the oil after straining, but they will settle once the oil is stored, and it is easy to prevent them from transferring into a pot the next time you want to use it.
Advertisement
Finally, Underwood suggests transferring the oil to a clean and dry container. “It’s very important that it doesn’t have any residual water in it,” she says, “and then just put a lid on it, tightly sealed, and keep it away from heat and light.” If you don’t plan to use it immediately, you can store it in the refrigerator, but any place with a consistent temperature and away from light works.
Considerations for reusing oil
Microparticles may still remain, but will settle during storage.Pamela Vachon/CNET
There’s nothing special that needs doing in order to use preused oil the next time, but bear one thing in mind: “Just be aware that it would now carry allergens from anything that you previously cooked in it,” says Underwood, which is essential to know if you’re cooking for other people.
Since that can be hard to track over multiple uses, “Always label and date it,” she suggests. “I just put a piece of tape on it with the date and the number of uses. And I also actually put what was fried in it,” she says, which can help keep track of potential allergens.
Store in a clear, dry jar with a tight-fitting lid.Pamela Vachon/CNET
It also helps keep potentially odd flavors out of whatever you cook next, as certain items like seafood or onion rings can impart flavor into the oil. “I don’t typically like to fry a savory thing and then fry a sweet thing,” says Underwood. “Like I wouldn’t make schnitzel and then use that oil for a donut.”
If you’re unsure whether an oil is still good to use, let your nose guide you to suss out if something is funky. If you’re not confident in your sniffing ability, Underwood advises smelling unused oil of the same type first, then smelling the used oil for comparison. You can use frying oil at least two or three times, maybe more if it was only used for light-flavored things that didn’t impart many particles and was never overheated.
The biggest benefit of reusing frying oil is the savings in every possible regard — you save money, and it’s a much more environmentally friendly practice across the board. “When you’re reusing any product, then you’re lowering the demand for things like production, packaging and transport,” Underwood says. “I don’t think that we think about that big picture very much, but if we were all reusing it, it would reduce those demands on the environment.”
Each time you reuse oil, it also diminishes in volume a bit. In my experience, at least with shallow frying, you can use the same batch of oil until, after a few uses, nothing remains to discard — the ultimate win.
Pamela Vachon
Contributor
Pamela is a freelance food and travel writer based in Astoria, Queens. While she writes about most things edible and potable (and accessories dedicated to those topics,) her real areas of expertise are cheese, chocolate, cooking and wine. She’s a culinary school grad, certified sommelier, former bartender and fine dining captain with 10 years in the industry. When not sitting at the keys, she leads in-home cheese classes, wine tastings and cocktail demonstrations.
See full bio
Jason Dessen cannot seem to get away from the Box, even when there isn’t one in front of him. In Dark Matter Season 2, Episode 4, Jason finishes a shift at the bar and, after stepping outside, reaches for the door to go back in. For a moment, it isn’t the entrance to the pub anymore. He sees himself opening the familiar door of the Box, with the corridor behind it, before reality settles back into place.
It is a brief moment, but an effective one, particularly after Episode 3 had Jason painstakingly dismantling the machine in the hope of finally putting some distance between his family and the multiverse. The physical Box can be taken apart; Jason’s relationship with it clearly cannot. More than that, seeing an ordinary rectangular doorway suddenly become its entrance makes us wonder about something Dark Matter has largely trained us to accept without question: why was the gateway to infinite realities a box in the first place? Why not a circle, a sphere, or the kind of glowing portal science fiction has taught us to associate with travelling somewhere impossible?
The answer begins much earlier than the Apple TV series.
Apple TV
The Box came before Blake Crouch knew what it did
When Blake Crouch was developing the 2016 novel on which the series is based, the shape wasn’t the conclusion to some elaborate piece of quantum theory. The image came first. “I had the image of a box in a warehouse, with a door on it. And that was it,” Crouch said of the idea that eventually became Dark Matter. He was brainstorming the novel in 2014, after spending years circling quantum mechanics and looking for the right story to connect to it.
A box creates an unmistakable boundary, which makes it a particularly useful object for a story built around lives that can branch into almost endless possibilities. Something is either inside it or outside it, and crossing that threshold becomes an event in itself. Crouch didn’t need the fictional physics to demand a cube; he needed an object that could make the act of entering another possibility feel physical.
Advertisement
Apple TV
The science behind the Box is fictional, but its basic idea grows out of a familiar quantum concept. Jason’s original research involved a much smaller cube intended to shield a tiny physical object from observation and external stimuli, keeping it in what he describes as an undetermined “cat state.” Jason2 succeeds where he did not and scales the concept until the experiment is large enough to contain a human being. The Box becomes the physical expression of an experiment built around observation, uncertainty and the possibility that more than one outcome can exist.
A hard-edged cube also gives the story something almost paradoxical to work with. Its dimensions are fixed, its walls are solid, and its boundary is obvious. Inside it, however, Dark Matter places a corridor that seems to have no meaningful end, with doors leading to realities that can differ wildly from the one left behind. The most ordinary-looking object in the story consequently becomes the entrance to something that cannot be contained by its physical dimensions.
Schrödinger’s cat makes the shape more interesting
The obvious reference is Schrödinger’s cat, the famous thought experiment in which a cat is sealed inside a box with a quantum event that can determine whether it lives or dies. Until the system is observed, the thought experiment imagines the cat occupying both possible states.
Apple TV
Dark Matter effectively puts the observer inside that experiment. Jason doesn’t stand outside the Box wondering which state exists on the other side. He enters it, becomes part of the experiment, and encounters a corridor through which different outcomes can be reached. The Box turns a thought experiment about mutually exclusive possibilities into the architecture of the series itself.
The visual contradiction is what makes the idea especially effective. A cube is rigid, finite and easily understood. It has fixed dimensions, hard corners and an obvious boundary between inside and outside. Dark Matter, meanwhile, places something apparently limitless within it. Once the drug takes effect, the enclosed space gives way to a corridor whose doors can lead to an extraordinary number of realities.
A circular portal would immediately communicate its purpose. Science fiction has spent decades teaching audiences that a glowing ring, tear or doorway is shorthand for travel between places that should not be connected. The Box carries a different suggestion. From the outside, it looks like an industrial object that could plausibly be sitting in an abandoned warehouse. Its strangeness only begins once the door closes.
Advertisement
Every door inside the Box also turns the mechanics of the multiverse into a question of choice. Jason can see other versions of his life, but seeing them does not make choosing between them easier. Each possibility carries its own consequences, and the person standing in the corridor still has to decide which one is worth entering.
Season 2 has changed what the Box represents
In Season 1, the Box was primarily a means of movement. Jason needed it because every journey through it offered another chance to find Daniela, Charlie and the world from which Jason2 had removed him. However frightening the realities behind its doors became, the machine still represented a possible route home.
Apple TV
In the current season, the relationship has become much less comfortable. Jason has his family again, yet the Box remains at the centre of their instability. His fixation with the machine is now affecting the life he fought to recover, and dismantling it becomes an attempt to impose some kind of final boundary between his family and the multiverse.
Episode 4 pushes that idea somewhere more personal. Jason no longer needs to be physically inside the Box for its presence to follow him. An ordinary doorway briefly becomes its entrance, turning something completely familiar into a reminder of the place he has spent so much of his life trying to escape. The image works because Jason’s problem is no longer simply the machine itself. He has begun to carry the Box with him.
The object can still function as a laboratory and a doorway, but its meaning has expanded. For Jason, it has also become a kind of prison, because destroying the physical machine cannot erase what happened inside it or the lives he has seen on the other side. A story about infinite possibilities has consequently given its central character a strangely finite problem: he cannot simply choose a different reality and leave the consequences behind.
Advertisement
Crouch may have started with nothing more complicated than the image of a mysterious box in a warehouse, but Dark Matter has spent two seasons turning that simple shape into the physical language of its entire story. It contains the experiment, separates Jason from the world he knows, opens onto lives that should never have been accessible, and now follows him even when he isn’t anywhere near the machine. The Box was always about crossing a boundary, but Jason’s experience suggests that some boundaries become much harder to cross back over.
The latest episode makes the idea particularly clear. Jason can dismantle the machine and try to build a life outside it, but the Box has become part of how he sees the world. For a character who spent so long trying to find the right door, the more unsettling possibility may be that he can no longer look at an ordinary one without wondering where it might lead.
We may receive a commission on purchases made from links.
Picking out power tools can be difficult, no matter how big or small you think the project will be, and it can feel expensive as you start looking for the ones you want to use. For anyone planning to get into woodworking, Ryobi offers several options, and we recommend it for any woodworking project. However, you might also be on a budget, which is common for first-time starters.
Advertisement
We’ve gone through to find eight different Ryobi power tools under $150 that you can use for a woodworking project. If you need to go lower, there are also options available under $60. We’ll explain why we selected these particular tools at the end of this article. Here are the eight Ryobi power tools that you can use in woodworking projects that cost under $150.
Advertisement
1-1/2 Peak HP Fixed Base Router
If you’re looking to create creative ridges or cuts in your woodworking project, a fixed-base router is an effective tool for doing so without disturbing the rest of the piece. An effective option from Ryobi is the 1-1/2 Peak HP Fixed Base Router. It has an aluminum base with LED lights to help you see where you’re going as you take the drill bit through a piece of lumber.
Inside the device is an 8.5-amp ball-bearing motor that makes cutting through various types of wood a simple motion, creating accurate designs and grooves, while the aluminum base makes it easier to grip and hold in place. You can also use this base router to smooth out any sharp edges you want to remove from your final piece.
For those taking up woodworking for the first time, Ryobi’s Base Router should serve as a good starting point. Not only is it budget-friendly at $119, but other customers also highlight that it’s easy to use, with intuitive controls for beginners, and that its compact design makes it easy to handle and store when not in use.
Advertisement
18V One+ 3-1 1/4-inch Hand Planer
If you’re looking to quickly remove unwanted sections from a piece of lumber before making more precise, intricate cuts, a hand planer is an effective tool to grab. Ryobi has the 18V One+ 3/4″ to 1/4″ Hand Planer, capable of reaching a 5/64″ cutting depth, and you can switch between these depths with a quick turn of the knob before you turn it on. The knob is easy to use and understand, regardless of your skill level with power tools.
The Hand Planer has a 14,000 RPM speed that remains consistent across a range of wood types, depending on what you’re using for your project. The reversible blade is double-edged and includes a guiding edge for when you want to maintain the same cut across a large section.
Advertisement
There are also three chamfer grooves on the tool, allowing you to use this hand planer on finer edges and corners. It comes with a dust collection bag. Neither the additional bag nor the battery will offset the lightweight performance of this tool. You’ll be able to use this hand planer on smaller projects that you might have used larger tools for, like a circular saw. You can get it from Home Depot for $83.89.
Advertisement
18V One+ Jig Saw
For woodworking projects that require long, precise cuts, there’s the 18V One+ Jig Saw. It’s a handheld tool with a T-shank wood-cutting blade and a one-inch stroke length, ideal for a range of woodworking projects for any craftsman. The blade is easy to load and swap out for other T-shank blades if you want to use alternatives. The front also features a built-in LED light to ensure you’re following the path you traced.
When in use, the blade can reach 3,000 SPM, and you can adjust the speed using the variable-speed trigger on the handle. To adjust the blade to your speed, use the small knob on the side to modify its orbital speed so it matches what you’d like for your current work. The grip is also designed to absorb more vibration, ensuring you don’t trip up while holding the tool in place, and it also reduces the tool’s noise as a bonus. You can get it for $79.99, although the battery and charger add-ons are sold separately. It’s one of several Ryobi tools we recommended for beginners.
Advertisement
18V One+ 4-1/2 Angle Grinder
When you want more precise, intricate control over the design of a woodworking project, an angle grinder is a good way to create blending curves or sand down specific areas of the wood. Although angle grinders are normally used on metal, using them at a lower speed with specific discs is ideal for woodworking. You can get the 18V One+ 4-½” Angle Grinder from Ryobi, a tool ideal for using to perform shaping and wood carving you want to do on a woodworking project, or sanding.
Ryobi’s Angle Grinder is a cordless tool that can go up to 9,000 RPM for cutting through tough woods. The twist-off, easy-to-use auxiliary handle has three optional positions to choose from before use, giving you options for how you want to use the grinder on your project. You can also adjust the guard’s placement around the grinder, and there’s a spindle lock at the front for any accessory changes you want to make.
You can get Ryobi’s 4-½” Angle Grinder for $59.97, or choose to get the 4 Ah battery and charger for $114, still keeping you under the $150 range. The base tool is one of several Ryobi tools you can get for under $75.
Advertisement
18V One+ AirStrike 18-gauge Brad Nailer
If you’re looking to add trim or want to ensure your glue joints hold together better, a brad nailer is an effective tool for the job. You can get Ryobi’s 18V One+ AirStrike 18-gauge Brad Nailer, capable of placing two-inch nails without leaving too much of a trace in any hard work during the final trim or molding stages of your project.
Advertisement
It does not come with a compressor or gas cartridges, making it quieter and easier to handle than models that rely on them, especially since it weighs less than six pounds. It uses a built-in Airstrike that draws in air from around the tool and pushes it into the material you’re driving the nail into. You can adjust the air pressure your Brad Nailer uses via a dial on the back of the tool, ensuring you don’t sink the nail in too deep or leave it sticking out. There’s also an adjustment dial on the front to fine-tune the nail depth. You can expect to sink in about 1,900 nails before you need to swap the batteries or start charging it.
The Airstrike 18-gauge Brad Nailer is available from Ryobi for $149 and does not include a battery or charger.
Advertisement
Ryobi One+ HP 18V Compact 6-1/2 Circular Saw
For cutting through larger pieces of lumber to slim down your wood in a project, there’s the Ryobi One+ 18V Cordless Compact 6-1/2″ Circular Saw for breaking down pieces you plan to use. The saw’s cutting speed goes up to 4,900 RPM, has an adjustable depth gauge from 1/4 inch to 2 inches, and an adjustable bevel from 0 to 50 degrees.
You can modify the bevel using the base at the front through an easy-to-use knob. For the cutting depth, there’s a quick-turn knob on the guard that you use before pulling the blade up and locking it into place. There’s also a built-in LED light to make it easier to see where the blade will cut before you push it down.
With the cordless model, you’ll have the freedom to move it and yourself around without being tied to an outlet. However, you’ll want to keep an eye on the battery charge, as it provides up to 350 cuts before you need to swap it or recharge it. You can get it for $119 at Home Depot, or go with a larger 7-1/4″ for $139.
Advertisement
18V One+ Compression Drive 3/8-inch Crown Stapler
An alternative to the brad nailer is the crown stapler, and you can use the One+ 3/8″ Crown Stapler to get the job done. It weighs almost three pounds, making it half the weight of the One+ Brad Nailer from Ryobi. You’ll be using it if you’re looking to install metal fasteners for plywood backs, trim along the sides of your woodworking materials, or place fiberglass insulation between wall frames.
Advertisement
You can use staples ranging from 1/4″ to 9/16″ with this model, or Arrow T50 staples, depending on your project. You can adjust the insertion depth using an adjustable knob on the back, ensuring they don’t go too deep or stick out too far. On a single battery charge, the Ryobi Crown Stapler is expected to use around 5,500 staples before you need to swap it out.
Sanding is an important step in many woodworking projects, especially before you begin varnishing or painting. Be sure to work it into your next woodworking project using the 18V One+ 1/4 Sheet Sander. It’s a handheld tool that you operate at 14,000 OPM to flatten a wood surface or to remove old paint that doesn’t match the look you want for your finished project. It weighs less than three pounds, making it lightweight to carry around a workshop or bring with you to different locations.
When you need to switch between sandpapers, it’s a quick pull to remove the current sheet and replace it with a new one to start working again. There’s a built-in dust collection unit and vacuum compatibility to help reduce the debris left behind when you’re working.
You can get the 1/4 Sheet Sander from Home Depot for $59, which comes with a dust bag, several types of sandpaper, and a paper punch. We can add it to the list of Ryobi sanders that help clean up rough surfaces.
Advertisement
Methodology
When picking from the available Ryobi products, we wanted to focus on the most important options that would be go-to choices for anyone looking to complete a woodworking project. Each tool is below $150.
Advertisement
These tools had to be used for a crucial part of a woodworking project, regardless of size. These had to serve a purpose, working on different types of wood and filling a specific role during a woodworking project. The customer reviews used to assess the ideal choices had to have at least 100 reviews on the Ryobi, Home Depot, and Amazon websites, with a rating of at least 4.4 stars.
An ongoing npm malware campaign involving the ‘indexed-btree’ package shows how threat actors bypass supply chain defenses by hiding malicious code in a package’s normal runtime behavior rather than in installation scripts.
The package, spotted by Checkmarx researchers, attempts to impersonate the legitimate ‘sorted-btree’ library and has already amassed 2 million weekly downloads.
The campaign may also have generated significant profits for the attackers, who, according to Checkmarx, use a wallet holding 109 ETH. However, the report does not say those funds came from cryptocurrency theft.
Bypassing latest security measures
In June 2026, GitHub announced a set of npm security measures designed to help prevent supply chain attacks that have shaken open-source ecosystems repeatedly since late 2025.
Advertisement
One key security measure is to block dependency lifecycle scripts such as ‘preinstall’, ‘install ‘, and ‘postinstall,’ unless explicitly approved.
Other measures prevent npm from automatically retrieving dependencies from Git repositories or remote URLs without permission.
The malicious indexed-btree package sidesteps these protections by avoiding installation scripts and instead hiding its loader in the package’s BTree.prototype.set() method, which executes at runtime when the application calls it with a specific key value.
As a result, installation appears clean and triggers none of npm v12’s approval mechanisms.
Advertisement
“The malware loader hides inside the library’s own BTree.prototype.set method, which is the main function that every user would call constantly,” explains Checkmarx.
“This triggers the sharedLoad.min.js, which contains the obfuscated first stage of the malware. This is a well-built way to sneak past standard taint-analysis tools and most static scanners.”
The malicious runtime trigger Source: Checkmarx
Once the malware is executed, it can collect system details, including architecture, hostname, CPU, memory, and uptime, and exfiltrate the information through hardcoded Slack and Telegram channels.
The malware also polls an Ethereum smart contract on the Sepolia test network for command-and-control (C2) information. It uses X25519 key exchange to derive an AES key and decrypt a second-stage payload stored in the contract.
When the operators choose to end the attack, the malware can delete its files and remove the malicious trigger from the package code to wipe its traces.
Advertisement
The researchers note that the threat actors have gone to great lengths to make the project appear legitimate, including building a legitimate-looking GitHub repository, populating its commit history, and curating the developer account.
Fabricated commit history Source: Checkmarx
Checkmarx also discovered nine additional npm packages linked to the same operation, which it has now removed from npm. Those also achieved significant download numbers, as seen here:
ordered-kv-index (448,184 downloads)
btree-leaderboard (493,685 downloads)
priority-slot-queue (402,860 downloads)
btree-range-store (468,092 downloads)
btree-core (1,951,274 downloads)
btree-time-index (425,312 downloads)
btree-lru-cache (372,185 downloads)
neighbor-key-map (366,019 downloads)
sliding-score-window (448,024 downloads)
Developers are advised not to rely on install-time scanning alone, and to also employ runtime behavioral analysis.
Those who installed indexed-btree or any of the above-listed packages should rotate all secrets and restore their development environment from a safe backup.
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Pavlo Bazilinskyy still can’t believe he was on PornHub for work. He’s an assistant professor at the Eindhoven University of Technology in the Netherlands, and has spent more than a decade researching AI-driven interactions between humans and robots. But he found himself typing “public transport” into the search bar of a very specific website’s “amateur section.” 297 hits.
“People are hard to predict,” Bazilinskyy says. It’s why he researches what he does. So his prurient pursuit had a point. Robotaxis without cabbies behind the wheel have started picking up passengers in a handful of countries, including the US. Meanwhile, there’s a long history of people getting up to antisocial behavior inside the quasi-private or straight-up public spaces of trains, planes, and automobiles—think the prom night limo, the “Mile High Club,” Tom Cruise in slow motion aboard the Chicago L in Risky Business, the stuff he found on PornHub.
What might riders do when there’s no authority figure inside a vehicle to say, “Hey, stop that!”? What do they do? Can people be convinced to stop before they start?
This week, Bazilinskyy and academic colleagues with backgrounds in systems engineering, computer science, psychology, and tourism studies are hosting an industry workshop asking participants to brainstorm along those very lines: How do you stop people from doing it in self-driving cars? Thinking about sex in autonomous vehicles, they theorize, can let anyone who cares about the future of mobility “stress-test” the role the vehicles might eventually play as communal spaces, where social norms get acted out every day.
Advertisement
The event focuses on prevention not just because these academics are no fun (though Alexandros Rouchitsas, an engineering psychologist who is also hosting the event, admits they are “taking the side of the parents, the elderly—we are not the cool people here”). They don’t want people to have sex in self-driving cars because they’re worried it will give a potentially positive technology a really bad rep.
“We want to see automated mobility solutions accepted, trusted by the general public,” Rouchitsas says. Self-driving could have huge upsides for the elderly, children, and people with disabilities, who have a harder time getting around places where driving is quicker and sometimes necessary. The tech might eventually move beyond private taxis and into public transit, where all sorts of people should be able to travel safely and comfortably. “We want automated mobility solutions to be seen as something that is equitable, serious, societally minded,” he says.
Rouchitsas’ biggest fear is that self-driving gets co-opted by the partiers, the drug users, the sort of hedonistic folk who have descended on some islands of his native Greece. “You know ‘Bang Bus’?” he says. “We don’t want that.”
The four-hour workshop—rise and shine, it starts at 8:30 am—is part of an industry conference in Gothenburg, Sweden, focusing on how people interact with vehicles and larger mobility systems. The organizers expect participants from academia but also the wider industry. (Gothenburg is home to Volvo Cars and the tech supplier SmartEye; BMW and Google are conference sponsors.) Those who show up will be prompted to come up with physical and design interventions that encourage people to not do that. The workshop will focus on preventing consensual interactions, its organizers say.
Advertisement
Rouchitsas, who studies human-machine interactions, says he hopes participants will get creative with their anti-action designs. But just off the top of his head: Maybe the vehicles could be transparent? Maybe a light begins to blink if the technology senses behavior it disapproves of? The organizers intend to publish a paper based on the workshop’s results.
Sex is the fun, eye-catching part here, made all the more alluring because it’s “the elephant in the room” for those thinking about how humans might interact with machines in the future, says Bazilinskyy—very under-studied. But the results of this sort of inquiry could help designers, companies, and lawmakers figure out how to compel people to safely share communal spaces like public self-driving buses in the future.
Prevent sex and maybe you’ll also prevent robbery, bullying, and homicide. “It could be helpful for the industry and academics to use this example to design other things,” he says.
There’s a frightening new digital threat that Android users should be aware of. New AI-powered malware called RatHat can automatically gain admin-level control over your Android device, stealing whatever it wants.
RatHat was discovered by mobile security firm Zimperium, which notes that the program tricks people into downloading what appears to be a legitimate app, such as Google Chrome, via a fake web page that mimics the Google Play Store. Once opened, the app seemingly innocently asks for accessibility permissions, which it then uses to take over your entire device.
RatHat uses the accessibility permissions users grant it to navigate your phone’s menu system and unlock Wireless Debugging, a legitimate developer tool commonly used in app testing, then grants itself ADB Shell permissions. This effectively grants the malware admin access to your device. Next, RatHat installs an AI-assisted agent that runs system commands to steal information and a proxy client that tunnels that stolen information back to the hacker.
“That sort of infection chain isn’t necessarily more complex than, say, following a phishing email on Windows and saying yes when the program asks for administrator permissions,” Sav Wheeler, a research engineer for Malwarebytes, said in an email. “Escalation in the Android landscape often relies on granting apps additional permissions that the OS locks away by default to keep the devices secure.”
Per Zimperium, the malware can be traced to attackers in China and primarily targets apps like WeChat Pay and Alipay, which are as popular in China as Apple Pay and Venmo are in the US. Malwarebytes notes that other financial apps can also be targeted. So far, researchers have found 162 infected apps in the wild, which report back to a dozen servers run by attackers.
Advertisement
What can this malware do?
The worrisome part is that the malware doesn’t do anything wonky the user would notice immediately, unlike with a ransomware attack. Instead, it bides its time, runs in the background, and captures information that appears on the screen, including usernames, passwords and two-factor authentication codes.
It can also steal raw touch input from your touchscreen, allowing it to recreate PIN codes and pattern unlock codes. It can capture SMS messages, too, thereby intercepting security codes. There isn’t much that the app can’t steal if it wants to.
How can I find out if I have RatHat on my phone?
The only way to find it is to run an antivirus scan that detects the software. Malwarebytes is a free option on Google Play that can do this. Wheeler told CNET that it can detect the malware pretty easily, which is good news for anyone who’s worried about whether or not they have it.
The bad news is that RatHat is sneaky and difficult to quarantine.
Advertisement
“Unfortunately, because of the behavior of the program itself — remasquerading as other apps, dynamically changing its behavior using the AI endpoint — static analysis and quarantining is not enough to remove the malware,” Wheeler said.
In short, the only way to actually get rid of this malware is a complete factory reset of your device. This effectively removes the hidden secondary files the malware installs, which antivirus apps can’t deal with. Uninstalling the app doesn’t work because the malware retains its admin access through those hidden files, which then let it reinstall the app over and over again.
How do I avoid RatHat?
This is also good news. RatHat’s infection method is complex and can be thwarted at multiple points during the process. First, you should never click a link from an SMS or email from a source you don’t know or trust. That stops almost all social engineering threats right out of the gate, including RatHat. Verify that you’re using the official Google Play app rather than a deceptive imitation website. Look at the top of the screen. If it has an address bar where you type URLs, it’s just a website disguised as an app. Real apps do not have address bars.
Also, note that preinstalled or existing versions of Chrome do not require reinstallation, so if you’re being asked to reinstall an app you know you have, think twice.
Advertisement
Denying accessibility permissions is the critical final line of defense against mobile malware. While downloading a malicious application is risky, the software remains largely powerless until you grant it advanced system privileges.
Wheeler says that SMS phishing is targeted to each specific user, so you won’t see the same phishing attempt as another person, and the tactics the app uses vary from region to region. Following standard antiphishing practices and not enabling accessibility permissions largely removes the threat of RatHat.
Joe is a freelance journalist. It all started with a long-running affection for building his own PCs, which he did for the first time as a teenager. It evolved into a lifelong enjoyment of putting words on the internet about the subject. He’s written for CNET, PCMag, Mashable and SlashGear as a freelance writer, and worked as a Senior Editor at Android Authority for 10 years. When he’s not writing about tech and science, he’s learning the ins and outs of DIY home repair, gaming, playing his bass guitars and posting help on PC building and gaming subreddits. He is a staunch believer that orange juice should have pulp.
See full bio
A saving of this size brings a genuine SteamOS handheld, the kind of device that plays full PC games rather than watered-down mobile ports, down close to the price most people pay for a mid-range tablet.
Advertisement
Powering all of that is the AMD Ryzen Z2 Go processor, a chip built specifically for portable gaming, pushing smooth frame rates through demanding titles rather than settling for the choppy compromises handheld gaming used to mean.
An 8-inch PureSight display backs that up with a 120Hz refresh rate and a 37 percent larger view than most 7-inch handhelds. Colours stay accurate too, with 100 percent sRGB coverage and 500 nit brightness keeping every detail visible in bright light.
Advertisement
Handling all of that is a pair of Legion TrueStrike controllers, built with hall effect joysticks that resist drift and adjustable triggers that switch between short clicks and full presses depending on what the game demands.
Advertisement
SQUIRREL_PLAYLIST_10148964
Legion ColdFront cooling keeps things running quietly during longer sessions, using a high-efficiency fan and larger heat sinks to manage airflow so performance stays consistent without the console overheating or throttling mid-match, even on the longest gaming nights.
A full 1TB SSD leaves plenty of room for a proper Steam library, while dual USB4 ports and Wi-Fi 6E keep the Legion Go connected to monitors, TVs and fast downloads with barely any lag.
So with a genuine Steam library, console-level power and £249.01 already saved, what is actually stopping you from ordering the Legion Go before this Game Day price disappears?
“You guys should understand that we pulled off the biggest supplychain [sic] maybe ever recorded in modern history,” one TeamPCP member wrote in the leaked chats.
Michael Fletcher, a former AFP analyst who now works in the threat research division of an Australian telecom firm, says he approached Larsen around that time about methods for monitoring the group’s members and activities. He says that Larsen responded by asking Fletcher to approach the hackers with caution because one of them was a “friendly,” Fletcher remembers. “I thought, damn, you all have been inside this early,” he says.
Google’s undercover analyst, Larsen says, gained access to a server where TeamPCP was storing its trove of credentials stolen from its many victims: the usernames, passwords, and access tokens it had obtained through its hacking and seemingly planned to use to extort target companies. So Google’s team decided to take action to warn victims and prevent TeamPCP’s ransom scheme. “My thought was: How can we, as quickly as possible, disrupt their campaign before more compromises can happen?” Larsen says. “Let’s go mess up what they’re doing. That was my goal.”
Rather than focus on alerting the owners of the stolen credentials at victim companies directly, which Larsen says would have taken too long given the sheer number of breached companies, Google first reached out to providers where those credentials could be used, like Amazon Web Services and Microsoft, to have the credentials revoked and prevent the hackers from exploiting them. Larsen and his team sent out hundreds of notification emails to those providers and then to victims, many of which got immediate responses.
Advertisement
Around the same time, Larsen says, Google’s visibility into the TeamPCP internal chat also allowed it to learn that someone within the group’s core circle was, distinct from the group’s supply-chain hacking, using an AI tool to develop a zero-day exploit in a widely used piece of login software that would allow the hackers to bypass its two-factor authentication. Google’s team got a copy of the exploit code, tested it out, and found that, with a few tweaks, it worked—a rare instance of an in-the-wild AI-created hacking technique that took advantage of a previously unknown software vulnerability. Google warned the software’s developer, who was able to patch its security flaw. (The incident was described in a case study Google released in May, but without naming TeamPCP or detailing how Google learned about the exploit.)
You must be logged in to post a comment Login