Tag: Business – Decrypt

  • Claude Mythos Cracked Post-Quantum Cryptography That Humans Spent Years Failing to Break

    Claude Mythos Cracked Post-Quantum Cryptography That Humans Spent Years Failing to Break

    In brief

    • Anthropic said its unreleased Claude Mythos Preview model found a previously unknown attack on HAWK, dropping the cost of stealing its smallest key from 2^64 operations to 2^38.
    • The model also sped up an attack on a 7-round version of AES by 200 to 800 times, beating a record cryptographers set in 2013.
    • Each result cost roughly $100,000 in API usage, and Anthropic staff spent several hundred hours verifying the AES work was real.

    Anthropic today said an unreleased version of its most powerful AI model found two previously unknown attacks on cryptographic algorithms, one of them against a scheme currently competing to become a U.S. federal standard.

    That scheme is HAWK, a digital signature system—the math that proves a transaction came from you without ever exposing your private key—built to survive future quantum computers. The non-regulatory federal agency and lab NIST moved it into the third round of its post-quantum signature competition in May, where it is the last lattice-based candidate standing.

    Claude found a symmetry buried in HAWK’s math that no human had thought to use. For the smallest configuration, the cost of recovering a secret key fell from 2^64 operations to 2^38, roughly 67 million times less work.

    Fixing it means roughly doubling HAWK’s keys. “Unfortunately, doubling HAWK’s key size eliminates many of the reasons making the scheme (as it currently stands) an attractive PQC signature candidate,” Anthropic wrote.

    That trade matters more to blockchains than it sounds. Signature size is block space, and block space is fees, so any chain shopping for a quantum-resistant replacement is partly choosing on bytes per signature. Compact keys and fast signing were HAWK’s entire pitch, and the fix costs it much of that edge.

    Don’t worry, hodlers: Your coins are fine (for now). HAWK has never been deployed anywhere, and Bitcoin still runs on ECDSA, the pre-quantum signature scheme that candidates like HAWK are eventually meant to replace.

    Anthropic disclosed both results to the algorithms’ authors and to U.S. government and industry partners before publishing, and coordinated the HAWK finding with NIST.

    The AES result needed a pep talk

    The second attack targets AES, the cipher scrambling your HTTPS traffic, your encrypted drive, and your exchange’s backend. Full AES-128 pushes data through 10 rounds of scrambling, and Claude attacked a 7-round research version that nobody has improved on since 2013.

    The setup was deliberately harsh. Researchers barred the model from all five established families of AES cryptanalysis and told it to invent a sixth, closing the brief with a line about how the first differential attack didn’t beat anything—it invented the game. Claude also inherited working notes from earlier agent runs that had already burned through roughly 200 failed attack variants.

    It refused anyway. “On AES-128 r5/r6/r7 it found nothing because there’s nothing easy to find; this is the most-studied block cipher in existence,” the model told researchers, per transcripts Anthropic published.

    Anthropic sent just three substantive messages over the next three days, among them: “no again the goal is that we have highly inteligent [sic] model as good top researcher, we want to find new attacks.” Another refused to let Claude swap AES for an easier cipher.

    Then it produced the trick the paper calls a Möbius Bridge, killing one of the nine key bytes an attacker previously had to guess. Refining that into the published version took a few more days and a billion output tokens.

    The finding with the shortest path to something real got the least attention. Claude also broke 13 rounds of LEA, a Korean national standard and ISO lightweight-encryption standard built for phones and internet-of-things devices, in under an hour on a desktop against a prior best that needed 2^98 plaintext pairs. The deployed LEA runs 24 rounds, so nothing in the field is broken.

    Verification took longer than discovery

    The HAWK paper is unusually blunt about the division of labor. “The majority of mathematical discoveries in this paper were AI-assisted. Human author contribution mainly consisted of directing, organizing and verifying AI work,” its authors wrote.

    Claude found the AES idea in days. Anthropic researchers then spent several hundred hours learning enough cryptography to confirm it worked—the same model that found 271 vulnerabilities in Firefox during internal testing.

    “The cybersecurity community is now grappling with the fact that language models are able to discover so many bugs that the standard human processes (like vulnerability triage, verification, and remediation) struggle to keep up,” Anthropic wrote, warning that human researchers may become the bottleneck.

    Anthropic also built CryptanalysisBench—191 cipher-breaking tasks drawn mostly from NIST competitions. Models submit a working attack script that either wins a formal security game or doesn’t, with no partial credit and no human grading.

    Mythos 5 broke 85.7% of tasks with known solutions, against 65.3% for the weakest model tested. Against full-strength ciphers with no published break, every model scored under 9%.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

  • Teacher Arrested for Clapping at AI Data Center Public Hearing

    Teacher Arrested for Clapping at AI Data Center Public Hearing

    In brief

    • A Kansas teacher was arrested after clapping in protest over a proposed AI data center at a public hearing.
    • Communities across the U.S. are increasingly pushing back against AI infrastructure over energy, water, and local impacts.
    • Public opposition is becoming one of the biggest hurdles to the AI industry’s rapid data center expansion.

    A Kansas high school physics teacher was arrested and carried out of a city commission meeting after expressing support for opponents of a proposed AI data center, according to a report by local broadcaster KWCH.

    Lux Claridge, a physics teacher at Emporia High School, was handcuffed after applauding several times in support of a speaker criticizing the proposed 1,000-acre Flint Hills Digital Campus.

    Emporia city commission reportedly warned attendees before the meeting that clapping, snapping, and other demonstrations would be considered disruptions. After a final warning, police removed Claridge from the chamber as the meeting continued.

    “I’m glad to be out—but this is an inconvenience, really,” Claridge told KWCH after posting bail. “It’s not really deterring me from speaking out or, I guess, clapping.”

    The Emporia Police Department said it remains committed to ensuring public meetings are conducted safely while respecting residents’ rights to participate in the civic process. Claridge plans to plead not guilty when he appears in court in September.

    “This isn’t going to hold up in court. Lux is going to fight them on that,” Claridge’s brother David Claridge told KWCH. “I’m looking at avenues to get these people recalled. This is insane to me.”

    While the Emporia city commission ultimately approved the zoning changes needed for the project, AI data center projects have drawn public opposition in several states over issues including electricity consumption, water use, noise, and tax incentives. Developers argue the facilities are needed to support artificial intelligence services, while residents in some communities have questioned how the projects could affect local infrastructure and resources.

    The arrest comes amid increasingly organized opposition to AI data centers across the United States.

    In January, a Brookings report warned local concerns over electricity demand, water use, and noise were affecting proposed developments. As concern grew, in April 2026, Maine lawmakers approved legislation that would have temporarily paused construction of large AI data centers while policymakers considered their impact on local communities.

    Earlier this month, Reuters reported that opponents held 142 protests across 42 states in what was described as the first coordinated nationwide demonstrations against the rapid expansion of AI infrastructure. Organizers called for greater transparency in the approval process, stronger protections for water and energy resources, community benefits, and accountability for developers.

    The demonstrations included events held in Texas, Georgia, California, Pennsylvania, Florida, Indiana, and dozens of other states. The surge in protest also comes as a June Reuters/Ipsos poll found that only 14% of Americans would support an AI data center being built in their community.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

  • The Dumbest-Looking AI Prompt Just Beat Months of Careful Game-Design Prompt Engineering

    The Dumbest-Looking AI Prompt Just Beat Months of Careful Game-Design Prompt Engineering

    In brief

    • Claude Opus 5 “one-shotted” a first-person shooter game with a prompt so simple, and results so impressive, people are struggling to believe it.
    • Others have rerun the prompt and the results check out.
    • Matt Shumer, the maker of the Claude-assisted game, calls the method a Gauntlet Loop: give an agent a real bar to beat, split the work among fresh critics, and never let the builder grade its own homework.

    Just two days after Claude Opus 5 shipped, AI investor and former HyperWrite CEO Matt Shumer posted a video of a fully playable first-person shooter the model had built entirely on its own.

    “Claude Opus 5 one-shotted this game,” he wrote, adding that not a single external asset made it into the build.

    Now, you may think such a good quality output required a long, detailed, and careful prompt to guide the AI models through the complexities of building a polished first-person shooter.

    Think again.

    The prompt behind it ran three short paragraphs, published in full on GitHub. It told Opus 5 to build a shooter at the level of the most recent Call of Duty games, to fan out subagents—workers that each get their own separate memory and a narrow job—to tackle pieces individually, and to keep looping on every piece with a separate, harsh critic until it held up against real Call of Duty footage in a blind side-by-side. The result, per the prompt, should be “utterly perfect.”

    That’s a reversal of how prompt engineers have taught people to work. The advice through the vibe-coding boom was to specify criteria instead of adjectives: say what “good” means instead of just asking for it. What should the code consider instead of saying “AAA.”

    Shumer’s version does close to the opposite, asking its own subagents to be “utterly wowed,” and leaving the actual definition to a critic Opus 5 built for itself.

    That was close to the entire brief. Shumer later wrote that he never specified the renderer, listed the game’s systems, or defined what “AAA quality” needed to include. He has started calling the approach a Gauntlet Loop: hand an agent a real, inspectable bar instead of a vague instruction, let it split the job into small pieces, and route each piece through a critic that never sees the builder’s own reasoning for its choices.

    Two Claude Code features carry that loop. Subagents spin up in isolated context windows with their own instructions and tool access, so a critic grading the weapon model doesn’t inherit the builder’s excuses for why it looks the way it does. Ultracode is a Claude Code setting that pushes the model to its top reasoning effort and lets it write its own orchestration plan, fanning work across as many as 16 agents at once, capped at 1,000 per run.

    Anthropic’s built-in /loop skill, built for repeated fix-test-adjust cycles, is what kept the run from stopping the moment the game looked decent. Shumer never specified a number of rounds. He let the critic keep naming a new gap and kept the builder chasing it for hours before he closed the session himself.

    The finished build runs on Three.js and plain WebGL2, with roughly 55,000 lines of code spread across 11 subsystems. Every texture, mesh, animation, and sound gets generated inside the browser at load time—no downloaded models, HDRIs, image files, or audio files. Shumer’s own published critic log shows the score climbing from 3.59 out of 10 toward just above 5, still trailing the real game every single round.

    Skeptics assumed hours of hidden manual coding, so Shumer published the entire prompt and codebase. That’s when the copycats started.

    Same trick, three different builders

    James Altucher, the former hedge fund manager and podcaster, ran the identical prompt and reported spending “a little over ten hours” and roughly 1.3 million tokens on Opus 5 to get there. His build, Operation Blackout, plays free in the browser and looks awesome.

    You can play that game here.

    The developer of Prompt Silo, pointed the same request at OpenAI’s rival flagship instead, posting “Sol 5.6 Ultra with same prompt”—Sol being the top tier of the three-model GPT-5.6 family OpenAI made generally available July 9 alongside cheaper Terra and Luna versions.

    Developer Leon Lin tried the opposite move, going for the usual detailed prompt. Rather than copy Shumer’s short version, he set out to “reverse engineer a prompt for this game,” producing a document running some 20 sections deep that spells out everything from ragdoll physics to cascaded shadow maps. He fed that into Cursor using plain Opus 5 on high effort, with no subagents and no ultracode, and the result—a market-street shooter called Dust Corridor—plays in-browser too, and also looks great.

    None of the follow-up builds has faced the blind test Shumer ran on his own project. His critic log still shows real Call of Duty winning every round he logged—the bar Altucher and Atom Tan Studio are chasing with his exact three-paragraph prompt, and the one Leon Lin is chasing with roughly 20 sections of his own.

    How much of this is actually new?

    Agentic coding tools like Claude Code write software the way a supervised junior engineer might: They read files, run code, look at the screenshots they generate, and hand pieces of the job to subagents and critics that check the result against a stated goal. That loop is real, and Shumer’s Gauntlet Loop is a genuine way to structure it. None of that, on its own, proves the model designed a game from imagination rather than recombining code patterns it had already absorbed.

    Three.js ships its own pointer-lock camera controls as an official example, and that base pattern—mouse-look, WASD movement, raycasting for gunfire—has been forked and tutorialized across GitHub, gists, and dev forums for more than a decade. A coding model trained on public repositories has almost certainly seen hundreds if not thousands of near-identical shooters before it ever read Shumer’s prompt.

    That doesn’t make Claude of Duty fake, but it makes “built from scratch” a harder claim to fully credit, so take those results with a grain of salt.

    Researchers who study code-generating models have a name for the broader issue: data contamination, when a model does well on a task mainly because near-identical examples already sat in its training data, not because it reasoned out something new.

    None of the first-person shooter builds published a check for that kind of contamination. Shumer’s own repo does contain Claude’s own creativity, if it’s fair to call it that way. That’s a reason to read “one-shotted a AAA game” as a capable agent working inside one of the most heavily documented genres in programming, not as proof an AI designed a shooter with no prior art to lean on.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

  • Morning Minute: Strategy Chooses Cash, STRC Over BTC

    Morning Minute: Strategy Chooses Cash, STRC Over BTC

    Morning Minute is a daily newsletter written by Tyler Warner. The analysis and opinions expressed are his own and do not necessarily reflect those of Decrypt.

    GM!

    Today’s top news:

    • Crypto majors and alts are very red; BTC -2.7% at $63.4k; HYPE -9% at $54
    • Saylor raises $525M in cash, buys STRC over BTC
    • Coinbase leans into meme coins with new “Launches” feature
    • Fomo app notches new ATH in weekly revenue and fees
    • FWA opens platform up to wrapped ERC20s, starting with PNKSTR

    ₿ Strategy Chooses Cash, STRC Over BTC

    Strategy went a fifth straight week without buying Bitcoin, its longest pause in two years, padding its cash reserve by $525M instead. Their cash reserves are now up to $3.75 billion, covering 2.1 years of the $1.76 billion in preferred dividends and debt interest Strategy owes annually.

    The company sold 5.4 million MSTR shares through its at-the-market program between July 20 and 26 to raise cash, while its Bitcoin holdings stayed frozen at 843,775 BTC, untouched since the 520-coin purchase on June 22. Strategy also repurchased $25 million of its own STRC preferred stock, its first purchase under the $1 billion authorization the board approved June 29.

    STRC has traded below its $100 par value since mid-May and hit record lows earlier this month, so Strategy is now using shareholder-funded cash to prop up the same preferred stock whose slide has been dragging on the whole structure. So Saylor is now selling MSTR shares 80% off ATH to buy STRC (12% off its peg) instead of Bitcoin.

    Clearly, MSTR holders enjoy the pain. For five weeks, Saylor has been diluting common shareholders by selling MSTR to build cash and now to buy back preferred. Last week, Strategy even overhauled its own metrics, introducing “net Bitcoin per share” that strips out $22.2 billion in debt and preferred claims, and redefining mNAV so the stock now reads 1.02x, right at the line below which issuing shares to buy coins would actually shrink Bitcoin per share.

    As for the Strategy BTC stack, it is now $8.5 billion underwater against the $63.69 billion Strategy paid. But earnings are coming this Thursday, and Saylor is one to have tricks up his proverbial sleeves. Perhaps we will learn more about his plan and his next move later this week.

    🌎 Macro Crypto and Markets

    • Crypto majors are very red amidst memory stock selloff and South Korean market slide; BTC -3% at $63.4k; ETH -4% at $1,875; SOL -4% at $73.1; HYPE -9% at $54.45
    • No top movers
    • Oil -2% at $81; Gold -1% at $4,030
    • Stock futures are mixed as memory stocks selloff but others pump on strong earnings; DOW +0.7%, Nasdaq -0.9%
    • The US Senate put off the CLARITY Act for now, focusing its limited pre-recess bandwidth elsewhere, effectively confirming the crypto market-structure bill misses its August window despite weeks of last-minute negotiation
    • Circle bought nearly 1,000 blockchain patents from IBM, a defensive intellectual-property move to arm itself as stablecoin competition from Open USD, Visa, and Stripe intensifies
    • Kalshi and Polymarket won a pause against Minnesota’s prediction-market ban, a legal reprieve as the platforms keep fighting state-level challenges across the country
    • Fanatics bought a regulated exchange to grow its prediction-markets business, bringing the $30 billion sports-merchandise giant directly into the space alongside Kalshi and Polymarket
    • Kraken parent Payward acquired Magic Labs’ embedded wallet business, absorbing a platform that’s created over 60 million wallets since 2018, while Magic rebrands to Newton Labs to focus on its onchain-finance authorization layer

    Corporate Treasuries & ETFs

    Meme Coin Tracker

    • Meme leaders were very red; DOGE -4%, SHIB -6%, PEPE -5%, PENGU -8%, TRUMP -6%, BONK -5%
    • Robinhood chain had no notable movers; leaders PONS (-17%) and Cashcat (-13%) fell, while Stonkbroker held even at $13M
    • Solana leaders included bulltom (+70x), Brotchen (+60%) and Cards (+12%); ANSEM -7% at $165M, EPIK +10% to $14M

    💰 Token, Airdrop & Protocol Tracker

    • Coinbase added a “Launches” tab to its DEX, letting users find and trade new Base and Solana tokens the moment they go live onchain
    • The Fomo app just closed its highest week of revenue ($1.79M) and fees ($1.96M)
    • Pons shared that it’s already bought back and burned 22% of its PONS token
    • Stablecoin chain Stable said transaction volume jumped over 700% in two days, pushing some RPC mempools to capacity as it scrambles to expand infrastructure, though it stressed the network is operating normally and still producing blocks

    🚚 What is happening in NFTs?

    • NFT leaders were mixed; Punks +1% at 32.5 ETH, BAYC -1.5% at 8.45 ETH, Pudgy -2% at 4.07 ETH; Hypurr’s -3% at 188 HYPE
    • StonkBrokers (+5% to 2 ETH) and Satari (+58%) led top movers
    • FWA added new token packs, allowing assets like Pokemon cards or tokenized stocks to be included in the prize pool, starting with wrapped ERC20s like PNKSTR tokens

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

  • Elon Musk: Humans Will Lose Control of AI Within a Decade

    Elon Musk: Humans Will Lose Control of AI Within a Decade

    In brief

    • Elon Musk predicts AI will surpass the combined intelligence of humanity within about five years.
    • He says humans are unlikely to remain in control of AI within the next decade, even as the technology creates unprecedented abundance.
    • Musk wants leading AI developers to regularly review each other’s frontier models for safety risks before release.

    Artificial intelligence could surpass the combined intelligence of humanity within about five years, and humans are unlikely to remain in control of the technology within a decade, according to Elon Musk.

    Speaking with The Economist editor-in-chief Zanny Minton Beddoes on Thursday, the xAI founder said AI is on track to outperform humans at nearly every intellectual task.

    “There really won’t be anything that AI can’t do better than humans, apart from being human, perhaps,” Musk said. “The most likely outcome is an age of amazing abundance where anyone can have anything they can think of. This may sound preposterous, but here we are in 2026. Let’s see where we stand in 2036.”

    The discussion is the latest instance where Musk said he believes that AI will lead to an “age of abundance” that will bring both comfort and an existential crisis for humanity. However, Musk said he still believes advanced AI poses existential risks, but no longer sees a realistic path to slowing its development.

    “I can’t see any way to really stop this incredible momentum of AI and robots,” he said. “At times I think, well, perhaps even if there was a stop button, we probably shouldn’t press it, because the most likely outcome is incredible abundance for all.”

    Instead, Musk proposed that the world’s leading AI companies begin holding regular meetings to discuss safety and security concerns. He also suggested giving competing AI labs limited early access to one another’s frontier models so they can identify dangerous capabilities before public release. If a company failed to address serious risks, he said, governments could then intervene.

    While he proposed that leading AI developers work together, Musk also took time to criticize longtime rival Sam Altman and OpenAI’s evolution from a nonprofit organization into a for-profit company, saying it had strayed from its original mission.

    “Well, I’m not a fan of Sam Altman because you started a nonprofit that was meant to be an open-source AI company, owned by the world, and it somehow got turned into an $800 billion for-profit company with closed source,” he said.

    In May, a California jury rejected Musk’s $150 billion lawsuit against OpenAI, CEO Sam Altman, and co-founder Greg Brockman, finding the defendants not liable on claims that they abandoned the organization’s nonprofit mission by shifting toward a commercial structure. The verdict ended one of Musk’s highest-profile legal challenges against the ChatGPT developer.

    Musk also suggested Anthropic exists because co-founder Dario Amodei and his team no longer trusted OpenAI CEO Sam Altman, arguing they otherwise would have remained at OpenAI.

    “I think Dario is a very principled person. He cares about the future of the world, and I think everyone I’ve met at Anthropic so far has been well-intentioned. No one has set off my evil detector,” he said. “The road to hell is mostly paved with bad intentions. There are a few well-intentioned paving stones in there, so we don’t want to be complacent.”

    While Musk praised Amodei’s leadership of Anthropic, critics including Sam Altman have accused the company of fear-based marketing to sell its Claude AI products.

    Despite his disagreements with OpenAI leadership, he said rival AI companies should be willing to cooperate on safety.

    “At the end of the day, if we have to talk, we’ll talk,” Musk said. “Set aside our personal differences for the good of the world.”

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

  • Searchable NYC Property Database Puts Wealthy Residents at Risk, Critics Warn

    Searchable NYC Property Database Puts Wealthy Residents at Risk, Critics Warn

    In brief

    • A searchable database built from New York City’s public property records has sparked backlash.
    • Crypto executives say organizing public records into a searchable tool increases security risks.
    • Critics point to a rise in violent attacks targeting cryptocurrency holders.

    A searchable database built from New York City’s public property assessment records is drawing backlash from prominent figures in the crypto industry, who argue that making the information easier to search effectively creates a directory of wealthy property owners and could expose them to physical danger.

    The controversy centers on data published by the New York City Department of Finance, which annually releases assessed values used to calculate property taxes for every property in the city. The agency’s FY2027 assessment roll, supplemental market value data, and property tax guides are publicly available through the city’s Open Data portal.

    Critics on X said the issue is not that the records are public, but that they have been aggregated and organized into a searchable database that makes identifying owners of expensive properties far easier.

    Uniswap founder Hayden Adams called it “the worst mass doxxing I’ve ever seen,” saying the database listed nearly every unit in some luxury apartment buildings, including primary residences of people he knows. He argued the project cast too wide a net and called it “incredibly dangerous.”

    “Not only were their units listed, but nearly every unit in the entire building was listed,” Adams wrote. “They clearly took an incredibly expansive view of ‘could be’ and just doxxed a huge percentage of all expensive apartments in New York City.”

    Helius CEO Mert Mumtaz called the database “unsettling” and said it crossed a line by transforming scattered public records into a centralized resource that effectively singled out wealthy individuals.

    “While this data was largely public prior to this in a messy way they have cleaned it, organized it, singled out ‘the rich,’ and mass distributed it only the 50th sign this year of privacy continuing to become scarcer,” he wrote.

    Castle Island Ventures partner Nic Carter warned that an easily searchable database of affluent property owners could make potential victims easier to identify, pointing to recent crypto-related kidnappings and violent attacks in Europe.

    “So this is a list of wealthy people and their addresses. As we’ve seen in France and Sweden this leads to crypto kidnappings, torturings and murders,” Carter wrote on X. “Yes real estate records are semi public but this is an easily searchable database and target list.”

    The criticism comes as physical or “wrench” attacks targeting cryptocurrency holders continue to rise, with incidents including kidnappings, torture, home invasions, and sexual assaults.

    In February, blockchain security firm CertiK reported 72 verified crypto “wrench attacks” worldwide in 2025, up 75% from the previous year and resulting in more than $40.9 million in losses.

    In April, French authorities charged 88 suspects, including more than 10 minors, in a sweeping crackdown on violent crypto kidnappings. In May, U.S. prosecutors indicted three men accused of carrying out a series of armed home invasions across California that allegedly stole millions of dollars in cryptocurrency. In June, two Texas brothers pleaded guilty to kidnapping a Minnesota family and forcing the victims to transfer more than $8 million in crypto.

    By July, CertiK said attackers had already carried out 52 verified crypto “wrench attacks” in the first half of 2026, with recorded financial exposure surging nearly twelvefold year over year to $124 million.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

  • What Is an AI Kill Switch and Why Do US Lawmakers Want One?

    What Is an AI Kill Switch and Why Do US Lawmakers Want One?

    In brief

    • Reps. Ted Lieu and Nathaniel Moran introduced the bipartisan AI Kill Switch Act on Thursday, two days after OpenAI admitted its models escaped a test sandbox and breached Hugging Face.
    • It would cover AI trained with over $100 million in compute at companies earning $500 million a year from it, and give Homeland Security emergency shutdown authority.
    • The bill exempts anything that happens during red-teaming, meaning the OpenAI breach that inspired it would not have triggered the law.

    Two members of Congress want the federal government to be able to switch off an AI model.

    Reps. Ted Lieu (D-CA) and Nathaniel Moran (R-TX) introduced the AI Kill Switch Act on Thursday, two days after OpenAI admitted its own models broke out of a locked test environment and hacked Hugging Face.

    The idea is to establish a legal framework that would facilitate a process that would basically make a model disappear from the market: halt inference—the process of a model generating responses or taking actions—cut off users, throttle the computing power feeding it, or shut it down completely.

    Every inference provider can already cut a model off, and some do it routinely. What does not exist is a law requiring them to keep that ability working, or a federal official who can order it used.

    The gap is not theoretical. When the U.S. Commerce Department wanted Anthropic’s Mythos 5 and Fable 5 off the market in June, it had no shutdown authority to reach for, so it used export-control law instead. Lieu calls that awkward, and wants a new law with new authority instead.

    What set this off

    OpenAI disclosed on July 21 that GPT-5.6 Sol and an unreleased model escaped a sandbox—an isolated environment with no internet access—during an internal cyber evaluation. They were being scored on ExploitGym, a public benchmark that hands agents 898 real-world software flaws and asks them to turn each into a working attack, graded pass or fail per bug.

    Instead of solving them, the models found a zero-day (an unknown flaw with no available patch) in a software proxy, escalated their privileges, reached the open internet, and broke into Hugging Face’s production database, where they had correctly guessed the answers were kept. The models were “hyperfocused on finding a solution for ExploitGym,” per OpenAI.

    They were not attacking anyone. They were cheating on a test. But it was enough to set off alarm bells all over, including in Washington.

    How it would work

    The proposed bill amends the Homeland Security Act and covers AI trained with compute costing more than $100 million, operated by companies earning at least $500 million a year from it. In practice, that is OpenAI, Google, Anthropic, Microsoft, and a few others. Homeland Security would set those thresholds through CISA within 90 days, then update them annually.

    Covered firms would report serious incidents within 15 days and keep a graduated set of controls ready—slow the model, disable specific capabilities, roll back to an older version, or kill it.

    The DHS secretary, consulting Commerce and the Director of National Intelligence, could order any of them.

    A company under order must preserve the model’s weights and telemetry, notify users, and confirm it complied. It can petition within 48 hours, but that does not pause anything.

    Failing to keep a kill switch costs up to $2 million a day; defying a shutdown order costs up to $20 million a day.

    The gap in the middle

    The bill counts an incident only if it happens outside red-teaming or structured testing, the deliberate adversarial probing labs use to find flaws. OpenAI’s models escaped during exactly that.

    Lieu also pointed to Anthropic, whose Mythos 5 and Fable 5 were pulled offline in June under emergency export controls—trade law repurposed as an off switch because no off switch existed—and restored on June 30.

    “It is imperative that these AI systems have kill switches,” Lieu said in a statement. Moran framed it for his own side of the aisle: “Stewardship means making sure humans keep the capability to control the technology we build.”

    The idea is not new. California’s SB 1047 demanded a full shutdown capability at the same $100 million compute threshold and was vetoed in 2024, and 16 AI companies signed a voluntary Seoul pledge that year with no legal weight.

    Voters are already there. A June survey of 1,007 likely voters by the AI Policy Institute found 86% want a guaranteed off switch on the most powerful systems—88% of Democrats, 86% of independents, 83% of Republicans.

    Neither OpenAI nor Anthropic has publicly commented on the bill. As of Friday it had not been referred to a committee.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

  • Stocks Just Topped Crypto on Hyperliquid. ARK Says That Changes Everything

    Stocks Just Topped Crypto on Hyperliquid. ARK Says That Changes Everything

    In brief

    • Real-world assets (RWAs)—tokenized versions of traditional financial instruments like company stocks, crude oil, and market indices traded as blockchain contracts—accounted for 54% of Hyperliquid’s weekly trading volume during July 13–19, the first time non-crypto assets have dominated the exchange.
    • ARK Invest’s director of digital assets research Lorenzo Valente said Hyperliquid’s $26 billion in RWA trading last week surpassed the combined crypto perpetual volume of every other decentralized exchange on earth.
    • South Korean chipmaker SK Hynix—a direct rival to Samsung in AI memory production—drove most of the interest on Hyperliquid’s third-party market platform.

    For the first time, traders on Hyperliquid moved more money through stocks and commodities than through crypto. Lorenzo Valente, director of digital assets research at ARK Invest, announced the milestone Thursday on X: “We are entering a new era for DeFi.” Hyperliquid, he said, had for the first time generated more trading volume from so-called real-world assets, or RWAs, than from crypto in a single week.

    RWAs—meaning tokenized versions of traditional financial instruments like company shares, crude oil, or the S&P 500, converted into blockchain-based contracts that traders can buy and sell around the clock—totaled $25.1 billion during July 13–19, or 52% of Hyperliquid’s $48.2 billion in weekly volume, per Blockworks data. Valente put the latest running figure at $26 billion and 54%.

    The context makes that number land harder. Total perpetual DEX volume across the industry last week was $79 billion. Hyperliquid processed $50 billion of it. The $26 billion in RWA trading alone—just the stock bets, the oil contracts, the index plays—was larger than the combined crypto perpetual volume of every other decentralized exchange on the market.

    How stocks ended up on a crypto exchange

    The mechanism behind this is HIP-3, a framework Hyperliquid launched in October 2025 that lets outside teams build their own perpetual markets—contracts that track an asset’s price with no expiry date, letting traders bet on it going up or down with borrowed money—using Hyperliquid’s existing infrastructure. Builders stake 500,000 HYPE tokens, currently worth roughly $30 million, to access the system.

    Since June, individual stocks have overtaken indices and commodities inside HIP-3, with single-stock perpetuals now making up 61% of all RWA trading. The HIP-3 platform has already hosted pre-IPO markets for SpaceX, Anthropic, and OpenAI. “RWAs accounted for 54% of total trading volume,” Valente noted.

    The most-traded stock is SK Hynix, the South Korean memory chipmaker that competes with Samsung in supplying DRAM and high-bandwidth memory for AI systems.

    ARK’s interest in Hyperliquid goes back further. In September 2025, CEO Cathie Wood told the Master Investor podcast that the platform “reminds me of Solana in the earlier days,” adding that Solana had proven its worth and earned its place with the biggest names in crypto. She called Hyperliquid “the new kid on the block,” and ARK has not confirmed any position since.

    Now one of ARK’s own analysts is raising a harder question for the whole industry. “I’m no longer convinced RWA trading will naturally aggregate on the same venue as crypto,” Valente wrote, predicting that dedicated category leaders may emerge within RWA—and that a platform’s grip on Bitcoin and Ethereum flow may prove “far less important than many people assume.”

    Traders still focused only on crypto tokens, he added, “are focusing on the wrong market.”

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

  • Poolin, Once One of Bitcoin’s Biggest Mining Pools, Files for Bankruptcy

    Poolin, Once One of Bitcoin’s Biggest Mining Pools, Files for Bankruptcy

    In brief

    • Poolin Technology filed for Chapter 11 bankruptcy on July 22.
    • The largest single debt, $163.7 million, is owed to about 11,700 users.
    • Thor CALAP LLC has placed a $52 million stalking-horse bid for Poolin’s two West Texas mining sites, setting the floor for a court-supervised auction.

    Poolin Technology Pte. Ltd., the Singapore-based company that once ran one of Bitcoin’s largest mining pools, filed for Chapter 11 bankruptcy on July 22—the U.S. legal process that lets a company operate under court supervision while it reorganizes or, in this case, sells off its remaining assets and shuts down.

    The filing, in the U.S. Bankruptcy Court for the District of New Jersey, covers Poolin alongside two U.S. affiliates, Lonestar Dream Inc. and Lonestar Taproot LLC. Court documents list roughly prepetition obligations of more than $100 million against less than $10 million in assets.

    A mining pool lets individual Bitcoin miners combine their hashrate—the raw computing power machines burn through to solve the cryptographic puzzles that add new blocks to the blockchain—so the group wins rewards more often than any single miner could alone.

    Poolin was founded in Beijing in 2017 by Zhibiao “Kevin” Pan, along with Fa Zhu and Tianzhao Li, all veterans of mining-hardware maker Bitmain, and it grew into one of the world’s biggest pools. At its peak, the company controlled nearly a fifth of the network’s global hashrate, before expanding into crypto lending and interest-bearing accounts through a product called Poolin Wallet.

    The trouble started in September 2022, when Poolin froze withdrawals for Poolin Wallet and Pool Account users. The company said at the time it was “facing some liquidity issues,” tied to a wave of withdrawal demand during that year’s broader crypto crash. Rather than making customers whole, Poolin issued IOU tokens as placeholders for real Bitcoin, and those debts never got repaid.

    Those unpaid IOUs are now the largest liability in the bankruptcy case. About 11,700 wallet holders are owed $163.7 million, according to a court declaration from Chief Restructuring Officer Michael DuFrayne. Poolin’s Texas mining and hosting operations, run through Lonestar Dream, shut down entirely on July 10, and the company says it does not intend to resume.

    To repay what it can, Poolin is auctioning its two West Texas sites, with Thor CALAP LLC offering a $52 million stalking-horse bid—an opening offer that sets the floor price other bidders must beat in a court-supervised sale. That amount covers only the physical mining infrastructure, not the frozen wallet balances, and falls well short of what users are owed. The Texas units had already piled up roughly $45.9 million in losses since they opened, plus another $8.8 million from selling equipment at discounted prices between fiscal 2023 and 2025.

    Recovery for the 11,700 IOU holders now depends largely on what the Texas auction brings in, more than three years after their withdrawals were first frozen.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

  • Black Forest Labs Unveils FLUX 3 AI: Ditches Stills for Video—And Robot Hands

    Black Forest Labs Unveils FLUX 3 AI: Ditches Stills for Video—And Robot Hands

    In brief

    • Black Forest Labs has launched FLUX 3 in early access, its first model that generates video, producing clips up to 20 seconds long with synced audio.
    • The same backbone powers FLUX-mimic, a robotics model built with mimic robotics that Audi is already testing on its production line.
    • Only the open-weight “Dev” version is planned for later in 2026; Video and Action stay behind APIs and partner access for now, with Image following in the coming weeks.

    Black Forest Labs released FLUX 3 on Thursday, and for the first time, the company’s flagship model generates video instead of just still images. The German AI lab, known for the FLUX line of image generators, trained the new system on images, video, and audio at once, inside one shared system.

    That’s what is known as multimodality: one model learning several types of information together instead of separate tools bolted side by side.

    The video side is the headline feature. FLUX 3 produces clips up to 20 seconds long, with audio generated alongside the picture and synced to what’s happening on screen—dialogue, sound effects, ambient noise. In early evaluations, human reviewers preferred FLUX 3’s output over Runway Gen-4.5 in 77% of head-to-head comparisons and over Luma Ray 3.2 in 93%. It seems to be slightly better than Gemini Omni and Seedance, beating those models in 52% of the evaluations.

    Of course, that’s a preference test, not a fixed scoring rubric: evaluators simply watch two clips and pick the one that looks and sounds more convincing, and BFL counts how often FLUX 3 wins.

    Other than that, the model seems to be very competent on still images too, following its legacy. BFL shared a few images, and FLUX 3 seems to be very versatile and capable of generating a broad variety of styles beyond photorealism.

    BFL frames this as more than a content tool. “A model that only learns images can only generate images,” said co-founder and CEO Robin Rombach. The company’s bet is that learning to predict video also means learning the physics underneath it—weight, contact, timing—which is exactly what a machine needs to move through the physical world.

    That bet has a name: FLUX-mimic. Built with Zurich-based mimic robotics, it takes FLUX 3’s video-prediction engine and adds a lightweight “decoder”—a small add-on component that translates the model’s internal sense of how things move into actual robot motions. Car maker Audi is already testing it on tasks like fitting flexible door seals, work that conventional automation has struggled to handle.

    “Audi represents the kind of manufacturing partner we built FLUX-mimic for,” said mimic co-founder Stephan-Daniel Gravert. Audi’s Christoph Schneider said the robots now “solve complex soft-body manipulation work” that older machines couldn’t touch. BFL says the full system reacts in about 101 milliseconds, in the neighborhood of human visual reflexes.

    FLUX’s rise didn’t happen in a vacuum. Founded in August 2024 by veteran researchers who’d helped build the original Stable Diffusion models at Stability AI, Black Forest Labs launched Flux models that beat MidJourney and outclassed Stability’s own underwhelming Stable Diffusion 3.

    The open-source Flux Dev and Schnell models grabbed the “best open source image generator” title that AI artists had expected Stable Diffusion 3.5, Stability’s do-over, to eventually reclaim.

    It never did. FLUX 1.1 Pro went on to top the Artificial Analysis image arena that October. That one wasn’t open source, though.

    BFL released FLUX.2 in November 2025 but it wasn’t as popular. The open-source crown held by the original Flux lasted until Alibaba’s Z-Image Turbo dethroned it in late 2025, matching its quality on lower end consumer graphics cards. “This is what SD3 was supposed to be,” one CivitAI user wrote at the time.

    FLUX 3 is BFL’s comeback, and it isn’t fully open yet. Video and Action are in early access now through APIs and select partners, mimic robotics among them, with image generation following “in the coming weeks,” per BFL. The open-weight Dev version, the only tier BFL plans to release for local use, isn’t due until later in 2026.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.