Anthropic's Cybersecurity Shock Wave + Farrow and Marantz on Altman
Summary
- Anthropic’s unreleased Claude Mythos Preview may mark a shift in the AI frontier toward autonomous vulnerability discovery. Anthropic claims it uncovered a 27-year-old OpenBSD flaw and an FFmpeg exploit missed by five million automated scans. Through Project Glasswing, it is giving Cisco, Broadcom, Microsoft, Apple, Amazon and others $100 million in Claude credits for defensive testing ahead of a potential cybersecurity “reckoning.”
- The immediate constraint may be remediation capacity, not vulnerability discovery. Kevin Roose thinks well-resourced companies could find and fix the top 1% of critical software, while the next roughly six months could bring a broad patching and rewriting cycle. Old code, limited human reviewers and slow customer updates create a “human bottleneck.” The unresolved fork is whether Mythos is exhausting a finite backlog of bugs or can continually invent exploit chains humans never imagined.
- The rollout exposes a sharp mismatch between private AI capability and public oversight. Kevin said his understanding was that the U.S. government had treated Anthropic as a supply-chain risk and ordered agencies to stop using Claude, leaving national-security institutions without straightforward access to technology they might urgently need. Casey Newton called it “really, really uncomfortable” that model development capable of forcing broad software rewrites remains essentially unregulated.
- Ronan Farrow and Andrew Marantz’s Altman investigation argues through accumulation rather than a single smoking gun. They found an extraordinary preponderance of people, including close, long-term contacts, alleging repeated deception, including an unnamed board member who called Altman “unconstrained by truth,” while also documenting legitimate defenders and a smear campaign featuring unsubstantiated material circulated by Elon Musk’s intermediaries.
- The governance bombshell is that the outside investigation used to legitimize Altman’s return produced no written report. Despite OpenAI’s nonprofit status and the public stakes of the 2023 firing, stakeholders received an approximately 800-word release describing a vague breakdown in trust. Farrow’s blunt finding: “There wasn’t a report,” because the work was kept out of writing.
- OpenAI’s key-person risk looks less absolute, but its governance risk remains live. Some pragmatic investors who supported Altman’s return told the reporters they might not have done so with today’s information; Farrow reported that senior executives have periodically discussed succession, with Fiji Simo mentioned as a possible candidate, though the company denies those discussions. Casey linked reported exclusion of CFO Sarah Friar from financial planning to the broader pattern of creating guardrails and then “skillfully navigating around them.”
- The episode’s counterweight to concentrated AI power is wonder at two very different scales. Artemis II carried four astronauts 252,756 miles from Earth, while the $25-a-year Acme Weather turns probabilistic forecasts and community reports into lightning, sunset, aurora and neighborhood-rainbow alerts. Its thesis is refreshingly modest: “What if there’s a rainbow in my neighborhood?”
Deep dive
1. Anthropic is withholding its frontier model to give defenders a head start
The hosts made an exception to the show’s “ship it or zip it” rule because Claude Mythos Preview was announced but deliberately not released. Project Glasswing takes its name from a butterfly whose transparent wings let it “hide in plain sight,” matching a model designed to reveal vulnerabilities embedded invisibly across the software stack.
Anthropic is instead giving defensive-testing access to a consortium including Cisco, Broadcom, Microsoft, Apple and Amazon — essentially every major technology company except OpenAI and Meta, in Kevin’s telling. The company is supplying $100 million in Claude credits so infrastructure providers, including Anthropic competitors, can patch systems before broader access becomes possible.
Casey’s explanation was rational liability avoidance: releasing a cyber weapon that lets nonexperts find a Linux-kernel exploit and seize machines would invite crimes and congressional hearings. He conceded that the safety stance might enhance Anthropic’s brand after its Pentagon fight, but Kevin argued that giving away access to a model it is not releasing for public sale is “a horrible marketing strategy.”
2. Mythos allegedly finds bugs that decades and millions of scans missed
Anthropic says Mythos found a 27-year-old flaw in OpenBSD, an open-source operating system used in firewalls and routers and expressly designed to resist hacking. The striking claim is not merely speed: the model identified something that nearly three decades of professional security research had left undiscovered.
Its second showcase was FFmpeg, popular open-source video software. Anthropic said automated security tools had scanned the code five million times without catching the critical exploit that Mythos found — an unusually clean demonstration of a reasoning system extracting signal where conventional automation had repeatedly failed.
Casey said cybersecurity professionals have spent 15 years warning him that the internet is held together with “spit and glue.” His outside gut check changed the weight of the claim: former Yahoo and Facebook security leader Alex Stamos said autonomous systems can now chain exploits that humans would miss, take too long to see or never have time to investigate.
3. The patching bottleneck could outlast the first six-month sprint
Stamos offered two scenarios. In the favorable one, the world faces a finite inventory of critical vulnerabilities that defenders can patch; in the darker one, Mythos-class systems can continually invent unfamiliar exploit chains, making the problem expand toward a possible superintelligence threshold. The hosts did not pretend to know which world is more likely.
Kevin said it seemed plausible that, over the next six months, every major piece of software might require patching, rewriting and rereleasing. Concentrated resources could plausibly secure the top 1% — Linux, major open-source libraries, routing gear and networking equipment — creating what he called a “forced reset for the entire cybersecurity industry.”
The long tail breaks that optimistic timetable. Maintainers may receive more proposed bugs and patches than humans can review, while countless machines run old code and depend on an owner eventually updating firmware. Kevin’s representative failure point was the person managing a router at a medium-sized Tulsa business who simply delays installing the fix.
Casey made the threat concrete by saying Iran was already attacking U.S. water and energy infrastructure without a Mythos-quality model. His concern was therefore not an abstract future adversary but the leverage existing hostile actors might gain if equivalent capabilities fell into their hands.
4. A private capability gap is colliding with weak public oversight
The government relationship is paradoxical: Kevin said his understanding was that the administration had tried to designate Anthropic a supply-chain risk and ordered federal agencies to stop using Claude, even as Anthropic held a model potentially valuable to national security. To Kevin’s knowledge, the U.S. government lacked access; Casey paired that with a regulatory regime the previous administration tried to put in place but the current one threw out over competitiveness concerns.
Kevin compared the moment with GPT-2 in 2019, when OpenAI withheld a model for months amid misinformation fears even though, as Casey joked, it “could barely write a limerick.” Since then, internal and public capabilities had remained relatively close. Mythos reopens that gap, and Kevin fears secrecy will amplify public paranoia even when withholding is responsible.
Casey saw Anthropic’s founding thesis operating as intended: build the best model, then use its frontier position to restrain domestic surveillance, autonomous weapons or exploit proliferation. His unresolved objection is circularity — “we have to build this frontier even though it’s dangerous” in order to guide it — while leakage could make that self-fulfilling prophecy impossible to contain.
For individuals, Casey resisted panic while defenders still have runway. His practical floor was conventional hygiene: use a password manager such as 1Password, generate a unique random password for every account, and protect email and banking with multifactor authentication through an authenticator app rather than relying on “eight letters.”
5. Farrow and Marantz build the Altman case through accumulation
Farrow described the profile of more than 16,000 words as deliberately “forensic and even.” Some readers concluded Altman poses an acute danger; Farrow’s mother finished it saying, “You know, I kinda like him.” The reporters consulted subjects extensively and carefully discussed whether to include material when counterarguments suggested it might be unfair or sensationalist.
Their central finding was nevertheless an “extraordinary preponderance” of people emerging from interactions with Altman, including close, years-long relationships, alleging that he lies about matters large and small. There is no single hand-in-the-cookie-jar moment. Even the comic detail — claiming to wear a gray sweater daily, then arriving in green — illustrates why the case works as narrative accumulation rather than a secret rap sheet.
The reporters separated evidence-based criticism from competitive warfare. Farrow said Musk’s intermediaries circulated “pretty spicy and pretty unsubstantiated material,” some inflated or apparently false. Andrew said the level of rivalry was consistent with a belief that whoever gets the ring first will control the world. That smear campaign does not erase the substantiated complaints, but it complicates every source’s incentives.
6. The missing investigation report is the governance bombshell
Andrew said their reporting indicates Altman did not simply choose to leave Y Combinator, contrary to the public account maintained by Altman and Paul Graham. It also suggested his relationships with Emirati and Saudi royals were deeper than previously understood, while revealing details from Ilya Sutskever’s memos and Dario Amodei’s notes.
When the OpenAI board members who moved against Altman agreed to depart, they insisted on an outside law-firm investigation. Because OpenAI was a 501(c)(3) emerging from a scandal of public consequence, executives and other stakeholders expected at least a detailed summary before the investigation was invoked to validate Altman’s return.
Instead, OpenAI issued an approximately 800-word release citing a vague breakdown in trust. Farrow resolved the long-running question directly: “There wasn’t a report,” because the investigation was kept out of writing. One board member whom Altman helped select and who oversaw the process now says a written document was unnecessary. Farrow noted that legal experts often view keeping such reports unwritten as a red flag.
The harshest testimony came from a Microsoft executive and an unnamed board member, not merely rivals. A Microsoft executive saw a “small but real chance” Altman might ultimately resemble Bernie Madoff or Sam Bankman-Fried; an unnamed board member called him “unconstrained by truth” and alleged “an almost sociopathic lack of concern for the consequences that may come from deceiving someone.”
7. Altman’s defenders force the argument back to OpenAI’s original promise
Altman’s network makes loyalties fluid: he estimated investments in roughly 400 technology companies, while founders and investors repeatedly served on one another’s boards. Andrew said the reporters encountered friends, enemies and, given Silicon Valley’s “mercenary nature,” people who had been both — helping explain why public positions move with power.
Farrow found a meaningful change among pragmatic, growth-oriented investors who supported Altman after the firing. With little clear information and obvious upside to restoring him, they granted the benefit of the doubt; several now say, “I don’t know that I would have” if they had known then what they know today.
Kevin’s pushback was that Altman has genuine, discerning supporters and an evident ability to rally talented people behind major projects. The positive case is often voiced privately or by people connected to him, but Andrew confirmed legitimate defenders exist, particularly those who regard telling different audiences different things as ordinary founder behavior.
Andrew’s rebuttal returned to the original contract: OpenAI presented itself as a nonprofit, safety-focused research lab that would aggressively comply with regulation. If today’s defense is simply that this is “a normal competitive business,” were early believers naive? Casey added that chronic truthfulness questions do not similarly define discussion of Satya Nadella, Sundar Pichai or Tim Cook.
8. OpenAI’s trust question is becoming governance and succession risk
Farrow agreed that structures matter more than any one personality. OpenAI’s founders themselves warned against an “AGI dictatorship,” making individual integrity part of their founding logic; yet the larger failure is a system that cedes consequential technology to private companies, their internal controls and their competitive “mud fight.”
Andrew noted that OpenAI acquired TBPN, a technology chat show, just after the profile closed, expanding its ability to tell its own story. The reporters also said safety-fellowship and governance announcements clustered around publication: Andrew called the governance plan “AI-y and ethereal,” while Farrow said the announcements were meant to occupy the same conversational territory as the investigation.
Economic incentives intensify the governance issue. Andrew recalled Altman acknowledging an AI bubble in which “someone’s gonna lose a phenomenal amount of money.” Whether the cycle becomes destructive is not independent of leadership rhetoric: its height partly reflects how aggressively pitchmen travel the world selling the future.
The recurring pattern, as one former colleague framed it, is building elaborate guardrails and then navigating around them. Casey connected that to reports that CFO Sarah Friar was excluded from some conversations about financial plans and some key meetings; the report said she doubted OpenAI would be ready for an IPO this year. Farrow added that senior executives had periodically discussed succession, with Fiji Simo mentioned as a potential candidate, though the company denies those discussions; Simo had subsequently gone on leave for medical reasons. Andrew now considers an OpenAI without Altman imaginable — a Steve Jobs-to-Tim Cook transition rather than corporate extinction.
9. Artemis II and Acme Weather restore a smaller kind of wonder
Kevin’s “one good thing” was Artemis II, whose four astronauts — Victor, Christina, Jeremy and Reid — traveled 252,756 miles from Earth, farther than any humans before them. The Times translated that into 2.37 billion Nathan’s Famous hot dogs, a comparison Casey sarcastically called easy to visualize.
Watching with his child taught Kevin the “terminator line,” separating the Moon’s illuminated and dark portions, and the preferred phrase “far side” rather than “dark side.” The mission restored “childlike glee and wonder” so powerfully that he argued NASA should receive whatever budget it needs to send people to the Moon annually.
Casey’s pick, Acme Weather, reunites Dark Sky’s team — Adam Grossman, Josh Reyes and Dan Bruton — after Apple bought the earlier app in 2020 and shut it down in 2022. Available on iOS with Android planned, it displays forecast ranges rather than false certainty, revealing when underlying signals imply genuine temperature volatility.
Its $25 annual subscription adds alerts for lightning, beautiful sunsets, precipitation within 12 hours, high UV, auroras and rainbows. Rainbow detection uses a Waze-like community reporting system: when enough neighbors submit sightings, Acme tells office-bound users to go outside and “behold the majesty of creation.”