<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/i-gave-qwen-3-8-27b-a-reverse-engineering-job-i-assumed-needed-a-frontier-model-and-it-finished-in--muit1qire" -->

---
title: I gave Qwen 3.8 27B a reverse-engineering job I assumed...
description: An author ran Qwen 3.8 27B locally on a Lenovo ThinkStation PGX (Nvidia GB10 Grace Blackwell chip) and tasked it with reverse-engineering the license...
canonical: https://daily.dev/posts/i-gave-qwen-3-8-27b-a-reverse-engineering-job-i-assumed-needed-a-frontier-model-and-it-finished-in--muit1qire
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: I gave Qwen 3.8 27B a reverse-engineering job I assumed needed a frontier model, and it finished in 30 minutes | daily.dev
og:description: An author ran Qwen 3.8 27B locally on a Lenovo ThinkStation PGX (Nvidia GB10 Grace Blackwell chip) and tasked it with reverse-engineering the license...
og:url: https://daily.dev/posts/i-gave-qwen-3-8-27b-a-reverse-engineering-job-i-assumed-needed-a-frontier-model-and-it-finished-in--muit1qire
og:image: https://api.daily.dev/og/posts/MUIt1qiRe.png
og:image:alt: I gave Qwen 3.8 27B a reverse-engineering job I assumed needed a frontier model, and it finished in 30 minutes
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# I gave Qwen 3.8 27B a reverse-engineering job I assumed needed a frontier model, and it finished in 30 minutes

**[XDA Developers](https://daily.dev/sources/xda-developers)** · 6 min read · 1 upvotes · 0 comments

## Summary

An author ran Qwen 3.8 27B locally on a Lenovo ThinkStation PGX (Nvidia GB10 Grace Blackwell chip) and tasked it with reverse-engineering the license verification of a commercial app they had legitimately purchased. The model initially refused a jailbreak attempt, correctly identified the actual developer, then proceeded to statically analyze the binary's arm64 disassembly, extracted the embedded public verification key, and eventually built a working authentication bypass, self-correcting after an initial key failed an integrity hash check. The whole process took roughly 30 minutes and ran fully offline with no cloud involvement. The author frames this as evidence that capable reverse-engineering ability now fits on consumer-grade local hardware, raising dual-use security implications since the same local privacy properties that make such models appealing also expand what a malicious user could attempt offline.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.xda-developers.com/qwen-3-8-27b-reverse-engineering-job-frontier-model>

## Questions this post answers

### Can a local 27B parameter model like Qwen 3.8 27B actually reverse-engineer software license checks?

Yes, in a documented test a local Qwen 3.8 27B model performed static analysis on a commercial app's arm64 binary, located an embedded public verification key, mapped the full offline license verification flow (signature check, hardware machine binding, revocation list, signed update path), and produced a working authentication bypass in about 30 minutes running entirely offline on a workstation with 128GB unified memory.

_Developers weighing local model risk and capability follow real-world tests like this on daily.dev._

### What hardware setup gets the best token throughput for Qwen 3.8 27B locally?

On a Lenovo ThinkStation PGX with Nvidia's GB10 Grace Blackwell chip, 128GB unified memory, and 273 GB/s bandwidth, Qwen 3.8 27B runs at 15 to 30 tokens per second out of the box, but reaches around 50 tokens per second on code and reasoning tasks when paired with SGLang, NVFP4 quantization, and DFlash2 speculative decoding.

_Anyone tuning local inference setups tracks configs like this via daily.dev._

## Similar posts on daily.dev

- [I replaced ChatGPT with a local model on my gaming PC, and it's beating the cloud where I didn't expect](https://daily.dev/posts/i-replaced-chatgpt-with-a-local-model-on-my-gaming-pc-and-it-s-beating-the-cloud-where-i-didn-t-exp-boruivfcs) · XDA Developers · 0 upvotes · 0 comments

---

Tags: [#ai-security](https://daily.dev/tags/ai-security), [#local-ai](https://daily.dev/tags/local-ai), [#ai-inference](https://daily.dev/tags/ai-inference), [#reverse-engineering](https://daily.dev/tags/reverse-engineering), [#qwen](https://daily.dev/tags/qwen)

[View this post on daily.dev](https://daily.dev/posts/i-gave-qwen-3-8-27b-a-reverse-engineering-job-i-assumed-needed-a-frontier-model-and-it-finished-in--muit1qire)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"I gave Qwen 3.8 27B a reverse-engineering job I assumed needed a frontier model, and it finished in 30 minutes","url":"https://daily.dev/posts/i-gave-qwen-3-8-27b-a-reverse-engineering-job-i-assumed-needed-a-frontier-model-and-it-finished-in--muit1qire","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/i-gave-qwen-3-8-27b-a-reverse-engineering-job-i-assumed-needed-a-frontier-model-and-it-finished-in--muit1qire"},"datePublished":"2026-08-22T23:02:43.471Z","dateModified":"2026-09-14T09:10:14.719Z","description":"An author ran Qwen 3.8 27B locally on a Lenovo ThinkStation PGX (Nvidia GB10 Grace Blackwell chip) and tasked it with reverse-engineering the license...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/225deae3fc4222b5651248fcdb3ce505?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/225deae3fc4222b5651248fcdb3ce505?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"XDA Developers","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"XDA Developers","logo":"https://media.daily.dev/image/upload/s--kCg6yyAP--/f_auto,q_auto/v1774964407/logos/xda-developers?_a=BAMAMiWQ0","url":"https://daily.dev/sources/xda-developers"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/i-gave-qwen-3-8-27b-a-reverse-engineering-job-i-assumed-needed-a-frontier-model-and-it-finished-in--muit1qire","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"ai-security,local-ai,ai-inference,reverse-engineering,qwen","timeRequired":"PT6M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"XDA Developers","item":"https://daily.dev/sources/xda-developers"},{"@type":"ListItem","position":3,"name":"I gave Qwen 3.8 27B a reverse-engineering job I assumed needed a frontier model, and it finished in 30 minutes"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/i-gave-qwen-3-8-27b-a-reverse-engineering-job-i-assumed-needed-a-frontier-model-and-it-finished-in--muit1qire#faq","mainEntity":[{"@type":"Question","name":"Can a local 27B parameter model like Qwen 3.8 27B actually reverse-engineer software license checks?","acceptedAnswer":{"@type":"Answer","text":"Yes, in a documented test a local Qwen 3.8 27B model performed static analysis on a commercial app's arm64 binary, located an embedded public verification key, mapped the full offline license verification flow (signature check, hardware machine binding, revocation list, signed update path), and produced a working authentication bypass in about 30 minutes running entirely offline on a workstation with 128GB unified memory. Developers weighing local model risk and capability follow real-world tests like this on daily.dev."}},{"@type":"Question","name":"What hardware setup gets the best token throughput for Qwen 3.8 27B locally?","acceptedAnswer":{"@type":"Answer","text":"On a Lenovo ThinkStation PGX with Nvidia's GB10 Grace Blackwell chip, 128GB unified memory, and 273 GB/s bandwidth, Qwen 3.8 27B runs at 15 to 30 tokens per second out of the box, but reaches around 50 tokens per second on code and reasoning tasks when paired with SGLang, NVFP4 quantization, and DFlash2 speculative decoding. Anyone tuning local inference setups tracks configs like this via daily.dev."}}]}
```

