382 Upvotes Peel Back the Optical Disguise
In September 2026, Bastardica, a lightweight tool running entirely within the browser, climbed to the number two spot on Hacker News, picking up 382 points. Sidestepping complex distributed systems and heavy infrastructure, it offered a clean web interface dedicated to a deceptively simple task: taking two common body typefaces, tearing them apart, and stitching them back together. Readers scan tens of thousands of characters across screens every day, yet virtually no one fixates on individual glyph geometries. The tool struck directly at this modern visual blind spot.
The web application provides a streamlined, automated workflow. Anyone can select a base typeface, pick a mix-in font, choose a blending cadence, and instantly generate a disruptive font file with real-time in-browser rendering. The system exports directly to TTF, OTF, and WOFF2 formats. What began as a typography prank has been refined into an industrial-grade pipeline.
Interface engineers and designers are well aware of a foundational reality: when it comes to visual deception, swapping glyph mappings at the font level is vastly cheaper and stealthier than altering plain text. Modifying actual textual content readily trips content moderation filters and data-loss prevention alarms. Swapping the font’s visual skin, by contrast, slips right past automated inspection while remaining virtually imperceptible to human eyes. On-screen typographic authority is divorced from the craftsmanship of font design; it relies almost entirely on the human habit of never looking twice.
Zero Server Footprint, Zero Attack Cost
The architecture behind Bastardica systematically closes off external telemetry and server-side tracking. It dispenses with traditional backend rendering infrastructure entirely, using Pyodide to compile and run a full Python execution environment directly inside the browser via WebAssembly. Powered by fontTools, glyph parsing, permutation rules, and binary font repackaging take place silently inside local client memory. This client-only design eliminates hosting bills—and introduces a threat model that is exceedingly difficult to defend against.
Running strictly on the client means that generated font binaries never cross the network. There are no server access logs to audit, no external API calls to monitor, and no trail left behind. Creating an optically weaponized font is completely invisible from an infrastructure standpoint, with the time from tuning parameters to downloading a functional font binary compressed to a few seconds.
Altering typefaces historically demanded specialized typography software like Glyphs or FontForge, paired with deep domain knowledge. That barrier has now been flattened by a client-side web script. Anyone with a browser link can produce optical chaos without leaving a forensic trace. The moment low-level font manipulation is democratized into a static web page, defensive models rooted in technical friction begin to unravel.
From a Seven-Year-Old Meme to Six Weaponized Presets
The lineage of the project traces back to a casual 2019 joke posted by Tumblr user ommanyte. The throwaway concept was captured in a screenshot that remains archived in the project repository’s root documentation. Developer weiweihuanghuang seized on the idea and turned it into Times New Bastard, an open-source project published under the AGPLv3 license.
Figure: The 2019 Tumblr joke that started it all. Source: Tumblr, archived via project README
The original project’s mechanics were straightforward. Inside the classic Times New Roman serif typeface, it forcefully injected an incongruous sans-serif character every seven glyphs. Using the open-source Nimbus Roman No. 9 L and Nimbus Sans as foundational assets, its jarring geometric transitions shattered the visual rhythm of long-form reading.
Figure: Official font specimen for Times New Bastard. Source: GitHub repository Times-New-Bastard, by weiweihuanghuang
Bastardica took this comedic premise and turned it into an automated suite, shipping with six fully articulated presets. Among them, SNEAKY BASTARD injects Arial into Times New Roman on every seventh glyph, scaling the injected characters to 90% to match the base font’s x-height. That subtle proportion tweak makes reading subtly uncomfortable, leaving readers unable to articulate why the text feels wrong.
The remaining five presets showcase equal disruptive versatility. IMPACTER stretches every second glyph in the already dense Impact typeface; CARTOON PAPYRUS introduces jitter parameters to emulate low-budget cartoon lettering; and NERVOUS SANS layers five instances of Arial to produce pseudo-random positional jitter. Another preset, ROYAL RANSOM NOTE, combines six radically different typefaces to evoke a classic cut-and-paste ransom letter, while TEMU SANS captures the chaotic typographical sensibility of budget consumer electronics packaging.
Figure: Meme featured on the Bastardica website. Source: bastardica.mitpit.com
55 Comments Expose the Vulnerability of Multimodal LLMs
Community reaction to the release reached far beyond typography pranks, quickly surfacing significant engineering and security implications. Across 55 comments on Hacker News, practitioners discussed real-world attack surfaces and optical deception techniques. Several developers recounted experiments aligning the x-height and baseline of Papyrus to Comic Sans to subtly torment colleagues. When such microscopic alterations are introduced into production documents, standard editorial workflows are powerless to detect them.
Other participants pointed to more covert applications. One proposal involved taking standard Helvetica and silently swapping every two or three characters for structural twins in Arial. In typical paragraphs of a few hundred words, this substitution is imperceptible to the naked eye. Yet it introduces unique layout perturbations and character spacing signatures that can act as a forensic canary or invisible digital watermark to identify the source of leaked documents.
The most technically sophisticated discussions centered on content moderation and adversarial machine vision. Developers highlighted the use of OpenType ligature features to construct self-censoring typefaces that dynamically pixelate or redact sensitive keywords directly in the font renderer. Another engineer proposed dynamically synthesized fonts as next-generation CAPTCHAs: once underlying Unicode-to-glyph mappings are randomized on the fly, the visual parsing and optical character recognition capabilities of multimodal large language models are rendered entirely ineffective.
Cheap Deception Shatters On-Screen Typographic Trust
In progressing from a social media gag to an adversarial tool, Bastardica traversed the gap using nothing more than an open-source repository and an unhosted static webpage. When the cost of dismantling typographic norms drops to zero, the natural authority we assign to screen text begins to falter. Our sense of security, built on clean and uniform typography, stands exposed.
Historically, human readers have relied on typographical consistency as a proxy for rigor and authenticity. Official government documents, journalistic reporting, and corporate correspondence command immediate respect partly through their visual polish. Yet that optical lens, developed over centuries of print and digital design, offers no defense against a handful of Python scripts compiled to WebAssembly. Anyone can assemble a plausible, professionally formatted typeface embedded with subtle optical traps in seconds.
Typography represents the final layer of implicit trust on our displays, and Bastardica dismantled that assumption with a few thousand lines of code. Visual authority has detached from typographic craftsmanship; it persists only through our cognitive habit of never questioning what we see. Once that veneer is stripped away, the premise that “seeing is believing” on digital screens collapses.
Reference Links:
- Hacker News Discussion (item?id=49823738)
- Times-New-Bastard GitHub Repository
- Bastardica Project Homepage