Claude Found a 4-Year Zcash Bug. Now It Won't Audit DeFi: Uneasy Money
Claude Found a 4-Year Zcash Bug. Now It Won't Audit DeFi: Uneasy Money
45 days agoUnchainedLaura Shin
Podcast1 hr 3 min
Listen to Episode
Note: AI-generated summary based on third-party content. Not financial advice. Read more.
Quick Insights

Investors should prepare for a "usage shock" in the AI sector as Anthropic transitions its high-performing Fable model to a non-subsidized, API-only pricing model on the 22nd. This shift highlights a broader "Subsidy Apocalypse" where current AI valuations may be inflated by unsustainable subscription costs, making "token-efficient" companies the only viable long-term plays. Exercise extreme caution with Humanity Protocol ($H) following a catastrophic security breach that compromised its treasury and bridge; the protocol is currently considered high-risk due to "security theater" failures. In the crypto space, Pump.fun remains a high-revenue but high-risk "entertainment" play as it pivots toward a controversial bounty-based marketplace that may attract heavy regulatory scrutiny. Finally, prioritize cybersecurity for AI-related assets, as North Korean threat actors are now specifically targeting engineers to exfiltrate valuable API keys and AI tokens.

Detailed Analysis

Anthropic (Claude / Fable / Opus)

The discussion centers on the release of Anthropic’s new "Mythos-class" model, specifically Fable (and references to Opus 4.8 and Sonnet). The speakers highlight a significant shift in how these models handle security and sensitive tasks.

  • Aggressive Safeguards: Unlike previous models that could be "convinced" to perform security audits or investigations by framing the user as a "white hat," Fable has "escape hatches." It immediately "ejects" or downgrades to an older model (Opus) if it detects security-related intent.
  • Subsidization Crisis: A major revelation in the transcript is the extreme level of subsidization for personal/pro plans. One speaker managed to run $5,000 worth of API-equivalent inference for a $200 subscription fee, estimating the service is 100x subsidized.
  • Performance Leap: Despite the safeguards, Fable is described as having a "human-like" reasoning capability that far exceeds Opus 4.8 or GPT-4o (Codex 5.5), particularly in complex planning and refactoring legacy codebases.
  • API Transition: Anthropic is moving Fable to be API-only (non-subsidized) starting the 22nd, which will force power users to pay actual market rates for tokens.

Takeaways

  • Investment Theme: The "Subsidy Apocalypse" in AI. Current AI valuations may be inflated by usage metrics that are unsustainable once users are forced to pay the true cost of compute.
  • Efficiency is Key: As subsidization ends, companies that have built "token-efficient" workflows (shared resources, multiplayer agents) will have a competitive advantage over those relying on "wasteful" personal subscriptions.
  • Security Risk: Because the model refuses to perform defensive audits for "good guys" but can potentially be jailbroken by "bad guys," there is a perceived increase in smart contract vulnerability risk in the short term.

Pump.fun (Bounty Marketplace)

The transcript discusses the launch of a new "Bounty" marketplace by the Solana-based meme coin platform Pump.fun.

  • Dystopian Incentives: The platform allows users to post financial rewards for real-world actions. Examples mentioned include a "tattoo bounty" (where a user tattooed a misspelled word on their forehead for money) and more extreme, dangerous bounties like self-harm or suicide.
  • "Bootywork" Token: Highlighting the chaotic nature of this market, when a bounty was disputed due to a typo ("Bootywork" vs "Bountywork"), the community launched a meme coin for the victim, which ended up paying out significantly more than the original bounty.
  • Uncancellable Growth: Despite the moral concerns, the speakers note that Pump.fun is "undestroyable" and "sticky," functioning more as an "immature male entertainment company" than a traditional financial platform.

Takeaways

  • Sentiment: Bearish on the "moral compass" of the platform, but acknowledging its massive revenue-generating power.
  • Market Trend: The "trenches" of crypto are moving from indirect incentives (pumping a coin via stunts) to direct incentives (bounties for stunts), which may lead to increased regulatory scrutiny or platform-level bans on certain types of content.

Humanity Protocol (H)

The transcript details a catastrophic security breach involving Humanity Protocol and its native token $H.

  • The Breach: A single device compromise (malware) led to the theft of multiple private keys. Despite having a "3-of-6 multi-sig," all keys were apparently stored on the same hot device, rendering the security measure useless.
  • Impact:
    • The bridge implementation was upgraded by the hacker to drain funds.
    • The $H token implementation was modified to "infinite mint" and steal tokens directly from users' wallets.
    • The treasury was completely cleaned out.
  • Conspiracy Theories: There are mentions of suspicious on-chain activity occurring days before the "official" hack, leading to community speculation about insider involvement, though the speakers lean toward a comprehensive external hack.

Takeaways

  • Risk Factor: This serves as a warning against "Security Theater." Investors should look for protocols where multi-sig signers are geographically and technologically distributed, not stored on a single machine.
  • Asset Status: Highly Bearish/Cautionary. The protocol suffered a "comprehensive" heist involving treasury, bridge, and user funds.

General Investment Themes

AI Infrastructure & Costs

  • The "Genie" in the Machine: AI labs are currently optimizing for growth and competitive dominance rather than profitability.
  • Price Sensitivity: The transition from flat-fee subscriptions to metered API usage will likely cause a "usage shock" for retail users and small startups.

Smart Contract Security

  • AI-Driven Vulnerabilities: There is a growing concern that "Black Hat" hackers are better at jailbreaking AI models for offensive purposes than "White Hat" defenders are at using them for protection, due to the strict safety filters imposed by labs like Anthropic.

North Korean Threat Actors

  • Targeting AI Engineers: The transcript mentions that North Korean groups are now specifically targeting AI researchers and engineers to exfiltrate API keys and AI tokens, as these have become more valuable than traditional cloud credentials.
Ask about this postAnswers are grounded in this post's content.
Episode Description
Claude Fable 5 refuses security work, Kain Warwick pulls $5,000 of compute from a $200 plan, and Humanity Protocol loses its bridge, token, and treasury to one infected device. ======================================================== Thank you to our sponsors! ⁠Multichain Advisors⁠: Get help navigating TGEs, go‑to‑market, BD and partnerships, capital markets advisory, PR, media placements, KOL activations and more at https://multichainadv.com. ======================================================== Anthropic promised Mythos and shipped Claude Fable 5 instead. The model found a four-year-old bug in Zcash's shielded pool that survived multiple expert audits. But when Anthropic shipped the model days later, it was no longer willing to audit smart contracts, bailing the moment a prompt smells like security work.Jailbreakers are already turning a jailbroken Opus 4.8 against it, while white hats sit locked out. Kain Warwick, Taylor Monahan, and Luca Netz weigh the defender's dilemma: builders cannot point the model at their own code, but nobody can prove black hats have not jailbroken their way in —  and, the hosts warn,North Korean threat actors have spent more than six months harvesting AI API keys. Then Kain runs the numbers on the subsidy: roughly 200 million tokens in four hours on a $200 plan, about $5,000 at API rates, and on the 22nd Fable goes API only as the first unsubsidized frontier model. Plus Pump.fun's bounty marketplace and the Humanity Protocol hack, which left the hosts asking why a 3-of-6 multisig existed at all. When the subsidies stop, who still gets the frontier? Host: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Kain Warwick⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, Founder of Infinex and Synthetix ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Taylor Monahan⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, Security Expert ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Luca Netz⁠⁠⁠⁠⁠⁠⁠⁠⁠, CEO of Pudgy Penguins Timestamps 🤖 00:40 Why Kain says Fable 5 should have been named Fable zero 🛡️ 03:50 Taylor on how Fable downgrades the second anything touches security 🕵️ 10:42Taylor on stolen AI keys,tokens and North Korea's new favorite loot 🧠 15:48 Does Fable reason like a senior engineer? Kain's 100-doc planning test 💸 20:06 How Kain pulled $5,000 of API value from a $200 Claude plan in four hours 🐧 ~33:45 How Igloo budgets $50K a month on AI, and the bot "brain" running the org 📊 44:00 Multichain Advisors: start building real traction with the team behind $50B at https://multichainadv.com 🎪 44:41 Pump.fun's bounty circus: tattoo typo, the Bootywork coin, Luca's steelman 🚨 55:36 How one infected device cost Humanity Protocol its bridge, token, and treasury Learn more about your ad choices. Visit megaphone.fm/adchoices
About Unchained
Unchained

Unchained

By Laura Shin

Crypto assets and blockchain technology are about to transform every trust-based interaction of our lives, from financial services to identity to the Internet of Things. In this podcast, host Laura Shin, an independent journalist covering all things crypto, talks with industry pioneers about how crypto assets and blockchains will change the way we earn, spend and invest our money. Tune in to find out how Web 3.0, the decentralized web, will revolutionize our world. Disclosure: I'm a nocoiner.