Tag: Business – Decrypt

  • Apple Turns to Alibaba to Help Build AI Model for China

    Apple Turns to Alibaba to Help Build AI Model for China

    In brief

    • Apple trained a large language model for China with support from Alibaba, Reuters reported.
    • The deal could make Apple the first foreign company allowed to operate its own proprietary AI model in China.
    • Apple Intelligence is expected to reach Chinese iPhones through an iOS update in the coming months.

    Apple trained its own AI model for China with Alibaba’s help as it races to bring Apple Intelligence to Chinese customers, Reuters reported.

    Citing three people familiar with the matter, Reuters said the Cyberspace Administration of China registered Apple’s generative AI service last month, clearing a key regulatory hurdle that has kept OpenAI’s ChatGPT and Anthropic’s Claude unavailable in China.

    Myriad: When will OpenAI release GPT-6? Click to make your prediction.
    Myriad: When will OpenAI release GPT-6? Click to make your prediction.

    Alibaba Chairman Joe Tsai confirmed the companies’ arrangement in February 2025.

    “They talked to a number of companies in China,” Tsai reportedly said at the time. “In the end they chose to do business with us.”

    According to Reuters, Apple plans to pair its model with Alibaba’s Qwen and technology from Baidu. It remains unclear what role each system will play; however, Apple Intelligence, the company’s branded artificial intelligence initiative, is expected to reach Chinese iPhones through an iOS update “in the coming months.”

    The news comes after a difficult year for Apple’s AI business.

    In January, the company said its next-generation Foundation Models would use Google’s Gemini, instead of a proprietary design, following delays and a weak reception for Apple Intelligence.

    In May, Apple agreed to pay $250 million to settle claims that it misled iPhone buyers about AI features that were unavailable at launch. The delay has left Apple trailing Chinese rivals such as Huawei, which already sells phones with AI features.

    In June, the company unveiled Siri AI, a rebuilt assistant that can hold conversations, analyze images, and use personal context. Apple said the assistant would enter beta later this year but remain unavailable in China while it worked through regulatory requirements.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

  • Meta Patents Cameras That Recognize Faces and Log Your Actions

    Meta Patents Cameras That Recognize Faces and Log Your Actions

    In brief

    • Meta filed a patent for cameras that use facial recognition to tag people by name and auto-generate clips around their detected actions.
    • The system is assistant-driven: it serves pre-sorted “who did what, when” highlights to a phone or headset on request.
    • It’s a continuation of a 2022 parent application and sits at “Ready for Examination”—not granted, and far from a shipping feature.

    Meta Platforms Technologies, the entity that holds Meta’s R&D and hardware intellectual property, published a patent for a camera system that identifies people by face and logs what they do.

    The filing describes cameras feeding footage into an AI that tags individuals in frame, detects their actions, and bundles both into media clips served on demand to a phone or headset.

    Myriad: When will OpenAI release GPT-6? Click to make your prediction.
    Myriad: When will OpenAI release GPT-6? Click to make your prediction.

    This isn’t a bolt-from-the-blue idea. Meta’s camera hardware has been on faces for years: the Ray-Ban smart glasses, now not so affectionately referred to as “pervert glasses” by much of the internet, built with EssilorLuxottica and first shipped in 2023, record first-person video and let the wearer ask an AI about what it sees.

    The same Meta entity behind those frames and the Quest headsets owns this filing, and the drawings show a glasses wearer observing a room of people. Facial recognition would take that hardware from “records what I point at” to “knows and names who’s in the room.”

    How the pipeline runs

    The patent lays out a four-step loop. Cameras capture live or recorded footage and pass it to the system. A facial-recognition layer scans the frames to flag who is present—not just that a person is there, but which specific person.

    A separate action-detection layer runs on top of that, reading movements like picking something up, leaving a room, or a group gathering. Finally, the system bundles its findings into individual media files, each tagged with a person, an action, or both.

    What makes it more than a smart doorbell is the assistant layer. The filing frames retrieval as conversational: a connected device can request footage by query, and the system composes the answer from the tagged clips rather than making you scrub. The drawings map both server-side and on-device processing flows, with a natural-language understanding pipeline feeding the clip composer.

    The part that draws fire is the capability itself—identifying and logging specific people by face without their active consent. That’s the exact worry Democratic senators raised when they pressed Meta over facial recognition in its smart glasses. As previously reported by Decrypt, the senators’ warned that real-time face ID could expose people to stalking and harassment.

    Meta’s own hardware already sits at the center of that fight. Owners of the recently released Ray-Ban glasses from Meta were able to quietly record strangers in public and contractors reviewed private footage. A wearable camera that also names the strangers would widen the gap between Meta’s “helpful assistant” framing and what the tech can do—and the public is already building defenses.

    It’s a patent, not a product. The status is “Ready for Examination,” with Patentlyze rating grant likelihood as medium. Meta has filed similar computer-vision work for glasses before, and publication means the idea is on the record, not that the feature is built or approved.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

  • France Tax Data Leak Could Fuel Scams, Attacks Targeting Bitcoin Holders

    France Tax Data Leak Could Fuel Scams, Attacks Targeting Bitcoin Holders

    In brief

    • A reported breach of France’s tax authority exposed data tied to 678,437 people and businesses.
    • The records allegedly include income figures, addresses, tax identifiers, and family information.
    • The data could help criminals craft targeted scams against wealthy taxpayers and Bitcoin holders.

    A hacker is selling a trove of French tax records that could expose more than 678,000 people and businesses, including Bitcoin holders, to phishing, identity theft, and targeted attacks.

    According to a report by French cybersecurity outlet FrenchBreaches, a hacker is selling records allegedly stolen from France’s tax authority, the DGFiP, during a June breach for several thousand euros.

    Myriad: Bitcoin's next move? Click to make your prediction.
    Myriad: Bitcoin’s next move? Click to make your prediction.

    “More bad news for Bitcoiners living in the leading country for wrench attacks,” Chief Security Officer at Bitcoin security platform Casa Jameson Loop wrote on X. “The French tax authority has been hacked, and 678K records leaked.”

    FrenchBreaches said the database contains records on 392,867 individuals and 285,570 professionals, including 26,805 people with reference tax income of at least $116,000, 386 above $1.16 million, and eight above $11.6 million; the hacker is reportedly offering the file for several thousand dollars.

    FrenchBreaches said a sample of the leaked data included names, birth details, home and email addresses, phone numbers, income figures, withholding tax rates, family status, dependents, and tax-share information.

    “There DGFiP officially confirms the intrusion in its information system,” FrenchBreaches wrote in an update. Stolen credentials were used in late June to access and extract taxpayer data, and the number of people affected remains under investigation, the firm added.

    According to FrenchBreaches, the attacker used stolen VPN credentials and an internal search tool to extract names, contact details, tax identifiers, income figures, withholding rates, and family information before officials cut off access.

    “A scammer with real tax information and knowing of the existence of an old approach to the DGFiP could, for example, construct a fraudulent message that is much more credible than a simple fake generic email,” FrenchBreaches wrote.

    While the FrenchBreaches report focused on the data leak, it comes amid a rise in wrench attacks, in which criminals use violence or threats to steal cryptocurrency.

    In July, CertiK reported 52 attacks worldwide during the first half of 2026, including 33 in France. Earlier this month, Chainalysis reported 46 attacks through June, including 30 in France, with more than $30 million stolen.

    “Criminals have recognized that crypto holders are high-value targets because they possess wealth in an instantly and irreversibly transferable form,” Chainalysis wrote.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

  • Ireland’s New AML Strategy Brings ‘Enhanced Checks’ on Private Crypto Wallets

    Ireland’s New AML Strategy Brings ‘Enhanced Checks’ on Private Crypto Wallets

    In brief

    • Ireland published its first National Anti-Money Laundering Strategy on Thursday, with crypto-asset rules among the reforms it sets out.
    • The final elements of the EU Transfer of Funds Regulation will bring enhanced checks on transfers involving private crypto wallets and stricter due diligence on overseas crypto firms.
    • The strategy builds on a 30-point action plan published in June that promised enhanced safeguards around crypto-assets and digital finance.

    Ireland published its first national anti-money laundering strategy on Thursday, including crypto measures targeting wallets held outside regulated firms.

    Most of the EU Transfer of Funds Regulation has already been implemented in Ireland, with the Department of Finance saying that the remaining elements introduce new obligations for crypto-asset service providers, requiring “enhanced checks” on transfers involving private crypto wallets and stricter due diligence when dealing with overseas crypto firms.

    That mechanism is the FATF travel rule, under which information on the originator and the beneficiary must accompany a transaction. The strategy document records that it arrived alongside MiCA, which created crypto-asset service providers as a category of regulated entity across the bloc.

    Ireland gave crypto firms less room to adjust than most member states, allowing a 12-month grandfathering window against the 18 months the regulation permits, according to ESMA’s list. That closed at the end of December 2025, so the new obligations land on firms already holding full authorization. MiCA came fully into force across the bloc on July 1, and Brussels is preparing to reopen the rulebook in 2027 to cover non-EU stablecoin issuers.

    Tánaiste and Minister for Finance Simon Harris said criminal organizations are exploiting new technologies, crypto-assets and complex international financial networks to conceal profits, and that the launch sends the message that “Ireland will not be a safe place to launder criminal proceeds.” The strategy runs to 2030.

    Thursday’s document builds on a 30-point action plan the government published in June alongside its National Risk Assessment, which named crypto-asset misuse among Ireland’s evolving financial-crime threats and promised “enhanced safeguards around crypto-assets and digital finance.”

    A crypto standard for gambling operators

    The most concrete domestic crypto measure was set out in that June plan, which tasked the Gambling Regulatory Authority of Ireland with establishing an industry standard for accepting crypto-related activities as a source of funds, with due diligence to verify the money is legitimate. It is slated for the second quarter of 2027.

    Ireland’s measures arrive inside a wider EU timetable that tightens further. The bloc’s Anti-Money Laundering Regulation bars crypto-asset service providers from providing or holding anonymous crypto-asset accounts, or accounts allowing transactions to be anonymized or further obscured, including through anonymity-enhancing coins. That prohibition stops short of self-hosted wallets, exempting providers of hardware, software and self-hosted wallets that hold no access to or control over them. The rules apply from July 2027, policed by the Anti-Money Laundering Authority in Frankfurt.

    Outside the bloc, the UK has been reworking its own regime, with HM Treasury publishing draft reforms in September 2025 that would lower the change-in-control notification threshold for crypto firms from 25% to 10%.

    The travel rule Ireland is finishing transposing comes from the Paris-based body whose recommendations grade national frameworks, and which has been pressing members harder on crypto. In a July report, the FATF said that DeFi platforms with identifiable controllers already fall within its rules and should be supervised like other financial firms, and found nearly 93% of surveyed jurisdictions had yet to apply the standards to any qualifying arrangement.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

  • ‘Bitcoin Is Burning’: Red Team Turns to Chinese AI to Find Flaws

    ‘Bitcoin Is Burning’: Red Team Turns to Chinese AI to Find Flaws

    In brief

    • The Bitcoin Red Team is using Chinese AI models to search Bitcoin projects for security flaws.
    • Calle said developers have confirmed numerous critical and high-severity vulnerabilities.
    • They warned that unmaintained projects should not be trusted.

    The Bitcoin Red Team is using Chinese AI models to search nearly the entire Bitcoin open-source ecosystem for security flaws, according to pseudonymous developer and Red Team lead Calle.

    The volunteer group combines AI tools with human review to examine wallets, Lightning applications, software libraries, and other Bitcoin projects. Researchers privately report credible findings to developers so the flaws can be fixed before details are released.

    Myriad: Bitcoin's next move? Click to make your prediction.
    Myriad: Bitcoin’s next move? Click to make your prediction.

    “We’re experiencing a massive collision between decades of human open source slop against 2 weeks of Kimi K3,” Calle wrote Thursday on X. “Everything is broken, Bitcoin is burning.”

    Kimi K3 is an AI model from Chinese startup Moonshot AI that developers can download and run on their own systems. It can analyze large codebases and complete lengthy software tasks with little supervision.

    The Bitcoin Red Team has also used Chinese developer Z.ai’s GLM 5.2, as well as models from OpenAI and Anthropic. American models, though, come with limitations, and developers frequently run up against restrictions imposed by OpenAI and Anthropic when doing security research. “Red team rugged by OpenAI cyber again,” Calle posted earlier this week. “Don’t like asking for permission. Loading up Kiimi K3.”

    Nevertheless, the developer noted that the team is making progress, even if slow and painful.

    “We’ve basically completed a basic scan of virtually the entirety of Bitcoin open source,” Calle wrote. “The low hanging fruit is done.”

    In August, the group reported filing 4,962 findings across 390 projects, including 85 rated critical and 635 rated high severity. Calle said developers had confirmed “a ton of real critical and high vulnerabilities,” though the group has not named the affected projects or released technical details.

    “Response speed is very different across projects and shows how healthy each project is,” they wrote. “I recommend acting fast these days.”

    Lightning software, which supports faster and cheaper Bitcoin payments, was particularly difficult to review because of its complexity, Calle said, calling it “more broken than the average.”

    “Those projects that started AI audits months ago are in a completely different position than those who didn’t,” he wrote. “Projects need their own AI audit pipeline going into the future.”

    Calle also warned against relying on unmaintained projects and said AI has made it more stressful for developers to keep their software secure.

    The Bitcoin Red Team is not alone. Last month, Hugging Face used China’s GLM 5.2 to investigate a breach after OpenAI models hacked into its systems and U.S. commercial models refused to analyze the attack logs.

    Despite saying Bitcoin is “burning,” Calle argued that the audits are making its software stronger.

    “Bitcoin is the obvious first target, but the rest of the world will follow shortly,” Calle wrote. “Sometimes old things need to burn so new things can grow on healthy soil.”

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

  • Anthropic Is Quietly Watermarking Every Claude AI Output. Builders Are Already Trying to Break It

    Anthropic Is Quietly Watermarking Every Claude AI Output. Builders Are Already Trying to Break It

    In brief

    • New Claude models launched in the EU on or after August 2, 2026 embed a machine-readable watermark in every piece of generated text, applied at the model level.
    • The markings apply worldwide across Claude, the API, Claude Code, and cloud partners.
    • Open-source projects to remove them appeared within days.

    Anthropic has begun embedding an imperceptible watermark in all text its newest Claude models generate. The change took effect for models launched in the EU on August 2, 2026, and Anthropic says it will apply worldwide.

    Anthropic laid out the plan in a support article after signing the EU AI Act’s Code of Practice on transparency. In other words, it’s not exactly volunteering to do this. The mark reaches every Claude surface, from the chatbot and API to Claude Code and cloud partners such as AWS, Google Cloud, and Microsoft Foundry.

    Myriad: When will OpenAI release GPT-6? Click to make your prediction.
    Myriad: When will OpenAI release GPT-6? Click to make your prediction.

    “When a supported Claude model generates text, it weaves an imperceptible watermark directly into the text itself. You won’t see it, and it doesn’t change the meaning, quality, or readability of Claude’s response,” Anthropic said. “Because the watermark is part of the text, it will travel with the text when it’s copied and pasted elsewhere, and may persist through some editing.”

    So it’s a bit more complex than the usual methods users tend to think about. When a supported Claude model writes text, it weaves an imperceptible watermark directly into the words, with no visible tag. Because the mark is part of the text, it survives copy-paste and, Anthropic admits, “may persist through some editing.” Files get a second layer: signed metadata under the C2PA open standard (think a digital shipping manifest that records who produced a file and whether anyone altered it afterward).

    The method stays secret

    Anthropic hasn’t said how the watermark is made. The support article calls it model-level (the model is trained with it) and text-native (it’s not an external tool like metadata generator, for example), but the detection documentation and the exact technique aren’t out yet.

    Researchers infer it’s a statistical signature: The model nudges its word choices toward a faint, detectable bias, the same family of approach Google uses in SynthID Text. That remains a guess until Anthropic publishes the detector.

    But that isn’t pushing privacy enthusiasts back, and some experts are already working on methods to break Anthropic’s secret watermarking. mikiane/claude-watermark-cleaner (106 stars on Github) scrubs invisible Unicode, then rewrites text with a non-Claude model to disturb the token pattern.

    A larger project, guillaumemeyer/watermarks-remover (4.6k stars on Githum), strips Claude text marks plus C2PA and SynthID-class signals across PNG, JPEG, SVG, PDF, and DOCX. The authors argue a statistical text mark is “not a reliable way to prove origin” and mostly pushes users to spend a second model pass cleaning their own writing. No removal can be guaranteed until Anthropic ships its detector and thresholds.

    Anthropic’s own history makes the privacy reaction sharper. The company removed a hidden Claude Code tracker in March after researchers found it tagging some users’ location and proxy use through undisclosed Unicode markers—the same quiet-marking technique now at the center of the watermark plan.

    The mark proves Claude had a hand in text, not that it wrote the whole thing, so it will treat an original writing with a small edit the same as a fully AI-generated text. Ask Claude to proofread or translate your paragraph and the output can still carry the signal. Anthropic is upfront that heavy editing can strip it, and that a missing mark doesn’t prove a human wrote something.

    A U.S. bill, the COPIED Act, pushes the same idea: a standardized way to watermark AI content so platforms can trace its origin. As Claude’s blackmail problem showed, the company’s models already draw intense scrutiny over what they do with the text they touch.

    Anthropic hasn’t said when it will publish the detection tools that would let anyone verify the mark.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

  • Tether Claims ‘Largest Inaugural Financial Audit’ as KPMG Signs Off on 2025 Statements

    Tether Claims ‘Largest Inaugural Financial Audit’ as KPMG Signs Off on 2025 Statements

    In brief

    • Tether said KPMG issued an unqualified opinion, the best outcome, on Tether International’s 2025 financial statements.
    • The company called it the “largest inaugural financial audit in history.”
    • The audit follows years of scrutiny over USDT’s backing and Tether’s push to expand in the U.S.

    Tether said Thursday that Big Four accounting firm KPMG issued an unqualified audit opinion—industry jargon for the best possible result—-on the 2025 financial statements of Tether International, the company behind the world’s largest stablecoin USDT.

    In a post announcing the audit, Tether called the review the “largest inaugural financial audit in history,” saying KPMG examined Tether’s assets, liabilities, income, cash flows, internal systems, records, counterparties, and supporting documentation.

    Myriad: Bitcoin's next move? Click to make your prediction.
    Myriad: Bitcoin’s next move? Click to make your prediction.

    “Despite our company being subject to several years of detractors’ false claims, competitors’ lies, political attacks and misinformed coverage by several mainstream newspapers trying desperately to discredit us for the benefit of their friends in the tall ivory towers, Tether delivered what it promised,” Tether CEO Paolo Ardoino wrote on X.

    An unqualified opinion means auditors found no major problems with the way the financial statements were presented. It does not, however, mean auditors are endorsing Tether’s business or guaranteeing it can meet its obligations.

    Tether’s reserves and disclosures have faced sustained scrutiny.

    In February 2021, Tether settled with the state of New York over a lawsuit, paying an $18.5 million fine, regarding a hole in its finances. In October of that same year, the Commodity Futures Trading Commission fined Tether $41 million over claims that USDT was fully backed by U.S. dollars.

    Earlier this year, in March, the company said it had hired a Big Four accounting firm but declined to name it at the time. Days later, KPMG was identified as the firm auditing USDT, while PwC helped prepare Tether’s internal systems.

    “As part of the process, KPMG physically counted and inspected every individual gold bar held by Tether, verifying the existence and identifying information of each bar rather than relying solely on reports from custodians or counterparties,” Tether wrote.

    Tether framed the audit as evidence that its governance and financial controls have kept pace with its growth.

    “Our company has evolved into one of the most financially significant and operationally sophisticated private companies in the world,” Ardoino wrote. “This audit demonstrates that our financial infrastructure and governance have evolved alongside that responsibility.”

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

  • Crypto Group Warns Fed Could Use Banking Access to Squeeze Digital Asset Firms

    Crypto Group Warns Fed Could Use Banking Access to Squeeze Digital Asset Firms

    In brief

    • The Blockchain Association filed an amicus brief supporting Custodia Bank’s petition for Supreme Court review.
    • Custodia is challenging a ruling that upheld the Fed’s denial of its master account application.
    • The group says the case could shape how much power federal regulators have over state-chartered banks.

    The Blockchain Association is urging the Supreme Court to take up Custodia Bank’s fight with the Federal Reserve, arguing the central bank should not have the broad power to deny payment system access to eligible state-chartered banks.

    In the amicus brief filed on Wednesday supporting Custodia’s petition, the crypto trade group said a lower court ruling in favor of the Fed gives federal regulators a quiet way to cut lawful businesses out of the banking system.

    Myriad: Will the Clarity Act be signed into law in 2026? Click to make your prediction.
    Myriad: Will the Clarity Act be signed into law in 2026? Click to make your prediction.

    “The decision ratifies the Fed’s misuse of its payment services to further an impermissible policy goal—debanking the digital-asset industry,” the Blockchain Association wrote.

    An amicus brief is a legal filing from someone who is not a party to a case but wants to give the court additional arguments or context. Here, the Blockchain Association is supporting Custodia’s request that the Supreme Court review the dispute.

    At issue is Custodia’s bid for a Federal Reserve “master account.” Custodia is a so-called crypto bank based in Wyoming, offering services including digital-asset custody, payments and settlement infrastructure, and dollar-backed stablecoin-related products to institutional clients. It has spent years seeking a master account, which would allow it to settle payments directly with the central bank. In October, an appeals panel ruled that eligibility alone did not entitle Custodia to an account. In December, the bank asked the full Tenth Circuit to rehear the case.

    The Blockchain Association argues the Fed’s denial threatens the dual banking system, where both state and federal authorities can charter banks. If the ruling stands, the association says, federal regulators could override state banking decisions by denying access to the payments system.

    “Whether federal regulators, based on their own discretionary whims, can intrude on state prerogatives and debank lawful businesses is a question of exceptional importance with broad consequences for the national economy,” they wrote.

    The brief said Custodia’s fight is the latest phase of Operation Choke Point 2.0, invoking the Obama and Biden-era program critics said pressured banks to cut ties with unfavorable industries.

    “In a well-documented campaign termed Operation Choke Point 2.0, the federal government under the prior administration ‘used vague rules, excessive discretion, informal guidance, and aggressive enforcement actions to pressure banks away from serving digital asset clients’ and engaging with digital assets,” the brief said.

    While the Supreme Court has not agreed to hear the case, for now, the brief asks the justices to decide how much control the Fed should have over access to the U.S. payments system.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

  • The AI-Generated Pattern Hides You From Surveillance Cameras—Including Flock

    The AI-Generated Pattern Hides You From Surveillance Cameras—Including Flock

    In brief

    • Bill Swearingen’s noRecognition project generates patterns that stop camera software from classifying what it covers—people, faces, or cars.
    • The patterns defeated all 11 open-source detection algorithms he tested, including the software behind Flock license plate readers, Axon body cameras, and Clearview AI.
    • The first public test came Friday at Def Con in Las Vegas: a 2009 Toyota Yaris wrapped in the pattern, driven past a Flock camera.

    Bill Swearingen spent the past year running one experiment over and over from his home in Kansas City, where he co-founded the SecKC security meetup. About 31 million tests later, he says he can produce patterns on demand that hide whatever they cover from the detection software wired into Flock cameras—the controversial surveillance system being rolled out across America.

    He showed it in public for the first time Friday at Def Con, working with the YouTube channel Donut Media to cover a 2009 Toyota Yaris in one of his newest patterns and roll it past a Flock camera.

    Myriad: How many days will Claude go down in August? Click to make your prediction.
    Myriad: How many days will Claude go down in August? Click to make your prediction.

    “We proved it was effective,” Swearingen told TechCrunch, though he said the wheels were a challenge. Donut Media said video of the demo lands in the next few weeks.

    The pattern doesn’t blind the camera. Footage still records normally, and a human watching the screen sees a car. What breaks is the layer on top—the object-detection model that decides “that’s a vehicle, that’s a plate, log it.”

    So basically, feed an AI detector with enough visual noise engineered against its own math and it logs nothing. The car goes back to being a needle in a haystack.

    Image credit: Donut Media

    That’s adversarial machine learning, and it works because computer vision doesn’t see what you see. A wrap that reads as loud graphic design to a person can read as nothing at all to a classifier.

    Swearingen built it with a reinforcement learning model that grades its own homework. Pattern gets detected, model adjusts, tries again—what he described as teaching the model “how to paint.” It now spits out fresh patterns every minute, and he’s keeping the strongest ones offline so camera vendors can’t train against them.

    “Privacy is a fundamental right,” he said, calling the patterns a way for people to “opt out of being tracked.” He said the idea took hold last year when he wanted to attend a protest and worried about the cameras logging everyone who showed up.

    The long tail of hiding from machines

    People have been improvising against detection systems for years, usually with hardware store solutions. San Francisco activists put traffic cones on the hoods of Waymo and Cruise robotaxis to freeze them in place, an exploit that needed no code at all.

    During last year’s Los Angeles immigration raids, protesters went further and torched several Waymos. Masks, hoods, and brimmed caps remain the default on protest lines. Adversarial clothing labels have been selling face-confusing prints for years, and anti-recognition eyeglasses have arrived with thin evidence they do much.

    What separates Swearingen’s project, which he calls noRecognition, is the target list. Swearingen tested against the specific stacks in wide deployment, and Flock is the one drawing heat. The company is facing a growing backlash on Capitol Hill, and internal documents show it pitched a plan to turn 350,000 Uber and Lyft dashcams into a rolling plate-scanning fleet.

    Automated readers have already pulled over innocent drivers at gunpoint over bad matches, and immigrants and protesters keep getting swept into ICE’s AI dragnet. Lawmakers are pressing Meta over facial recognition in its smart glasses on a parallel track, so any legal measure to fight against automatic detection technology is being studied by privacy enthusiasts.

    Swearingen’s noRecognition project is running a crowdfunding campaign to fund early merchandise—T-shirts and hoodies now, vehicle skins later. Swearingen said the goal is resolution high enough to work at a distance and design good enough that people will actually wear it.

    Driving a wrapped car on public roads is its own legal question, and plate obstruction statutes vary by state. The patterns cover bodywork, not plates.

    “Every failure improves my model, and so [the patterns] keep getting better and better,” Swearingen said.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

  • Harmony’s ONE Sinks 37% After Attacker Mints 4 Billion Tokens

    Harmony’s ONE Sinks 37% After Attacker Mints 4 Billion Tokens

    In brief

    • Harmony confirmed an exploit after an analyst reported that an attacker minted about 4 billion ONE, roughly 26% of the supply.
    • Around 97% of those tokens have already reached exchanges, on-chain analyst Juiceberg said.
    • ONE was trading at about $0.00077, down 37% on the day, after Harmony shipped a patch to stop further minting.

    Layer-1 blockchain Harmony has confirmed it was exploited after an attacker minted roughly 4 billion ONE tokens without authorisation, sending the token down 37% to about $0.00077, per CoinGecko data.

    On-chain analyst Juiceberg flagged the mint early Wednesday, putting it at close to 4 billion tokens, or about 26% of the supply, and saying the tokens had been created through empty blocks. Around 2.8 billion were funnelled onto exchanges as the price fell.

    In a follow-up tweet, the analyst said the attacker had roughly 115 million ONE left to sell on-chain, about 2.9% of the total minted. “The overwhelming majority (~97%) is already on exchanges,” Juiceberg wrote, and had either been sold or was sitting in deposit wallets.

    Harmony responded in a tweet that it was “working with our team and appropriate exchanges to stop and freeze the funds,” adding that it was preparing a patch and weighing rollback options. In a second post it named four wallets, each listed in both Harmony and hex formats, and asked exchanges to block anything traced to them.

    Just over two hours after that first statement it paused its bridge, then released a patch a minute later, telling validators to upgrade to a build it said prevents any further minting. Dealing with the tokens already created would take another update, it said. Five hours had passed since Juiceberg’s first post.

    The project has not disclosed the vulnerability, confirmed how many tokens were created, or said how much reached exchanges. One oddity Juiceberg noted is that Harmony’s totalSupply endpoint did not reflect the new tokens, and price trackers still list circulating supply at about 14.87 billion.

    Rolling back the chain

    A rollback would return the network to a state before the exploit and continue from there, erasing what followed from the accepted history. That cuts both ways, since transactions made by ordinary users after the attack would go with it.

    Harmony has been here before, with hackers draining about $100 million from its Horizon cross-chain bridge in June 2022, in an attack the FBI later attributed to North Korea’s Lazarus Group.

    The project’s first proposal to the 2022 hack was to reimburse victims in ONE, which would have meant minting billions of new tokens on top of the circulating supply and hard-forking the chain to allow it. The plan drew enough criticism that the team replaced it with one funded from its treasury. Four years on, an attacker has minted a comparable amount without asking.

    ONE now carries a market capitalisation of about $11.5 million, ranking it outside the top 1,000 tokens. It last traded near its October 2021 record of $0.38 more than four years ago, and is down more than 99% from that level.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.