Unchained - Uneasy Money: Is OpenAI Training on Your Private Chats to Win the AI Race?

Episode Date: September 10, 2026

Alex Thorn and Jon join Kain and Taylor to unpack a Bitcoin hack, two new frontier models, and why nobody trusts their AI chats anymore. ======================================================== Than...k you to our sponsors! Visit 1inch to swap tokenized securities, crypto and more. Simple. Secure. Self-custodial. Whatever asset you’re buying - swap it at ⁠⁠⁠http://unchainedcrypto.com/go/1inch-sn⁠⁠⁠ ======================================================== A Bitcoin sidechain lost $300 million to a consensus bug this week, and the hackers who returned 85% of it are trying to extort a "bug bounty" out of Blockstream for the rest. Alex Thorn, Head of Firmwide Research at Galaxy, and Jon, Head of Strategy at Venice and co-founder of ShapeShift, join Kain Warwick and Taylor Monahan to unpack how AI models are now finding exploits faster than the humans who wrote the code, and to push back on the idea that returning stolen funds makes anyone a white hat. They also dig into Astra and Fable 5.1, two frontier models that landed days after a mathematician working inside OpenAI's Codex clashed publicly with OpenAI over who actually solved a Millennium Prize-adjacent proof.  Jon and Alex explain why the "don't train on my data" toggle may not mean much, and why identity is becoming the real privacy battleground. The conversation closes on whether an Anthropic researcher quitting this week is a warning the industry is choosing to ignore. Hosts: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Kain Warwick⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ - Host of Uneasy Money and Founder of Infinex and Synthetix ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Taylor Monahan⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ - Co-host of Uneasy Money and Security Expert Guests: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Alex Thorn - Head of Firmwide Research at Galaxy ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Jon - Head of Strategy at Venice and Co-founder of ShapeShift Timestamps 🔓 01:15 How a consensus bug let hackers mint $300M in fake Bitcoin 📜 7:50 Why the Liquid hackers are no white hats 🤖 17:16 Did an AI agent find the Liquid exploit? ⚖️ 28:10 Taylor on why there’s no excuse for the hackers’ actions 💧 32:08 1inch Aqua: See how the shared liquidity layer works at http://unchainedcrypto.com/go/1inch-sn 🧠 32:54 Astra and Fable 5.1 land, and one is writing eerily compressed code 📐 35:19 The Millennium Prize proof fight between OpenAI and an Anthropic researcher 🧬 44:48 Kain on fast takeoff, recursive self-improvement, and paperclipped kids 🕵️ 55:18 How to keep your novel research out of an AI's training data ⚰️ 01:07:03 Why an Anthropic researcher's resignation has Kain and Taylor spooked Learn more about your ad choices. Visit megaphone.fm/adchoices

Transcript
Discussion (0)
Starting point is 00:00:00 The way to think about this is like, it's like two tiger moms, right, that have really smart kids and they are in a pitch battle to prove that their child is smarter. Think about what those ladies would do. Like, that's where that's what's happening right now, right? They're like, look at what my, look at what my son did. He's like solved a millennium prize, right? Hey, everyone. I'm King Warwick and welcome to uneasy money. this is what happens on chain never stays.
Starting point is 00:00:31 Before we begin, here's a word sponsors that make the show awesome. This episode is brought to you by 1 inch Aqua, the shared liquidity layer from 1 inch. Back multiple liquidity positions with one wallet balance and keep your tokens in your wallet until a swap fills. See how it works at 1inch.com slash aqua. All right, I'm here with my co-host,
Starting point is 00:00:56 Taylor Monaghan, security expert, and we have two very special guests today, Alex Thorne, head of firm-wide research at Galaxy Digital, and John, head of strategy at Venice, and also co-founder of Shapeshift. Welcome, guys. Hi there, thanks. All right, let's kick it off. The first segment of the week is Liquid loses 95%, 93%, 98%, somewhere in the 90s percent of its BTC. a consensus bug in elements, something I had not heard of until this week, allowed someone to mint LPTC out of nothing and peg it and basically redeem it, which, Tay, we can talk about this as well.
Starting point is 00:01:44 You can walk us through the process here. Because my expectation with these pegged assets, wrapped assets, is like, there's usually some set of redeemer people who are allowed to do redemptions, right?
Starting point is 00:02:03 Like, you can't just turn, like, no, you can't just turn up and be like, oh, hey, I've got 3,000 BTC. Also, if that happens, the old of your BTC, can I redeem it?
Starting point is 00:02:13 Like, what's the deal? Like, how's that, how did that happen? What's... I mean, you know, there's ways to make... It's basically a bridge hack in,
Starting point is 00:02:24 in the most. simple sense of it. So because it's not, it's not EVM, the like the words that people are using and the exact mechanism that people are using is different than what we're usually familiar with. However, if you just sort of like zoom out and look at it generally, it's basically, can you translate it into a theory for me so that I understand what's going on here? So I mean, Alex can probably do a better job, but basically assets that, that shouldn't have existed or spoofed into existing.
Starting point is 00:02:59 That was like the first half, bad half. And then the second half is that then they were able to bridge those assets to real Bitcoin and get real Bitcoin out. And that's the second half that's also bad. But I think in Ethereum land we typically say like technically that code was valid and did its job as. as the code was meant to do. The second half. The second half. Someone turned up, they had a valid asset that, you know, the system recognized.
Starting point is 00:03:36 And it just happened to be all of the Bitcoin that the system held or whatever. Yeah. The, yeah, break it for us. I mean, Tay is right. It is kind of a classic bridge hack in the, you know, the attack purpose and execution. It is effectively fooling the. bridge into allowing the underlying Bitcoin that collateralizes, effectively tokenize Bitcoin on this liquid side chain to be issued there. The way I understand it is like so elements is
Starting point is 00:04:08 the code is the side chain, right? And it's a federated side chain. These withdrawals and other, I think, consensus actions there require 11 to 15 of these federated nodes. And that's like exchanges. This is like a closed validator set. And they have a confidential transactions feature, which is like a ZK-ish, we'll say, right, but where you can send and receive assets among yourself on the side chain without revealing the amounts or other features of the transaction. And to do that, you have to submit a range proof and a balance proof, basically, that the nodes can use to verify that the in and out on the transaction equal each other and that there's not a
Starting point is 00:04:53 negative number. But I guess my understanding is it's computationally intensive to calculate the range proof. So if like an identical transaction were submitted, when a transaction is submitted and the notes calculate that proof, they cache it in their cache and their memory. And so these attackers submitted like a one LBT in, one LBT out transaction and the proof was cashed. And then the bug itself was their ability to create a collision. to insert a 1 BT, LBT in 4,000 LBT out transaction
Starting point is 00:05:29 and have it have the same like key, like hash basically as the prior proof. And because the nodes had already seen it, they said, oh, we don't have to commute this again. We know it's good, approved it. Now they have 4,000 LBTC on liquid. And then they submit that to side swap, one of the Federation members that allows the pegging out
Starting point is 00:05:49 back into the main Bitcoin network. And the funny, yeah, So you asked the beginning, is it permission list like that, that. So you're only supposed to be able to withdraw to whitelisted assets, addresses on Bitcoin that are previously whitelisted. I don't know why or why this was allowed, but sideswap, one of the Federation members is an unallow listed address.
Starting point is 00:06:10 And they'll just let anyone show up with an address and withdrawal from liquid and just auto forward it when they receive it to that address as a service. But that's how it got that. That's a good service. Yeah. That way it's like, Oh, you know, we're only supposed to allow these fixed number of whitelisted addresses. But if you give us an address, we'll just send it to you directly from our white listed address.
Starting point is 00:06:30 So, like, that's how it actually got out of side swap, which is this. Someone should keep in out of the Federation. And it's like an exploit as a service. Yeah, kind of. It is. They're doing an end run around the allow list. Yeah, we'll just let you, we'll just let you around the rules. I don't know.
Starting point is 00:06:45 I don't know anything. I hope they get some fees for that or something. Yeah. I think they did. I think I saw this morning, though, that they returned their fees. Yeah, and I think there was some, maybe there was actually some change because there might have been like some other unrelated, like, non-hacker pegouts through them as well and, like, that got returned or something.
Starting point is 00:07:04 I'm not sure. I don't know anything about, like, sideswap or their relationship with this federation. So it does seem odd to me, however, that they offered that as a service. Okay. I mean, yeah, this feels like, like, someone's like, oh, it's a bridge. Yeah, I mean, ultimately, they need some way. way, you know, I assume non-whitelisted addresses need some way to get things in and out of Yeah, but I think I think the nature of liquids like user base is that it's mostly exchanges,
Starting point is 00:07:32 basically. And so that might be why like it could function without actual normal, normal on-chain users actually going in. There's like 50 people using it. Yeah. And they're probably like going through Bitfinex to create and redeem through liquid if they are. I think that's my understanding. Right. Yeah. So that's so. all the fun part, right? Like, that's the, like, boring bridge part. So then... That's just the ex-flight part.
Starting point is 00:08:03 That's just, that's fine. That's not, that's run of the mill, right? So, they steal, they steal all this Bitcoin, 4,000 Bitcoin, right? And then it's like, oh, this was a white hat thing. Immediately, immediately. the Bitcoin and Ethereum lands explode. This is like a 2020 wholly network hack thing, where the guy comes on chain immediately publicly.
Starting point is 00:08:34 And it's like, I'm a white hat. Yeah, in the very first transaction where the hackers consolidated the coins into their one address, in that transaction, they added arbitrary data. It's called opereturn and Bitcoin that said, we are white hats contact us on chain. Yeah. Something white hats definitely do. But it's the irony too is that the, you know,
Starting point is 00:09:00 they could only do this because the operative had enough bites to allow them to do this, which was, of course, the subject. That's a lot of debate. What I found, you know, yeah, like literally two weeks ago, they were like, we don't want people to junk up our Christine Bitcoin network with nonsense. And now we're doing ransoms. on it. So, you're
Starting point is 00:09:21 careful you wish for. It's like a threat of return. And honestly, it was, it was truly a throwback. It felt like one of the early EVM hack throwbacks where like the hackers are then like just showing up and are like, yeah, let's negotiate in public.
Starting point is 00:09:39 Motherfucker is like, let's go. That's exactly what this is. You kind of made this point, right? You were like, you're like, Bitcoin is like four years behind the rest of ecosystem and like rediscovering how to do like ransom in in the wild like all of this stuff right well and it also because impressively I've been watching the whole bitcoin ecosystem realize that just because someone calls themselves a white hat doesn't mean that they're a white hat yeah so they're like that realization for people yeah I said I had labeled them initially in
Starting point is 00:10:16 my database like liquid white hat and then I was like Now they're kind of extorting here. I literally said. Yeah. They literally said, like, we're going to start calling them liquid hackers again, basically. It's a learning experience. Gray had it best. Yeah.
Starting point is 00:10:32 Okay. So, so, so they turn up and they say, hey, we stole everything. 4,000 Bitcoin. 4,000 Bitcoin. What is that? $300 million? $3 million, 330 million, somewhere in that range. Yeah.
Starting point is 00:10:47 This is a big hack. So they, they steal, they steal. they still threw intermill of Bitcoin and say, hey, let's negotiate or like contact us or whatever, right? Then the interesting thing as well for me is it wasn't like they were like, hey, you know, send us an address, we'll return it. And they actually went even further. And they were like, we'll charge you 15% as a punishment unless you pay out from your own money the thing. Like we're going to punish all of the Bitcoin holders that were in this network, which I guess if they're all exchanges, it's like, yeah, man, like there can't be too many real users. I think it might be underlying users of the exchanges.
Starting point is 00:11:30 I'm not sure that's your point. But the exchanges will eat. Like, you know, finance has like a thousand Bitcoin or whatever. I think that they're, it's not clear, but so Blockstream operates, wrote the code base, I think maintains the code base. But it's not. It's not. It's not. It's not.
Starting point is 00:11:47 It's the Liquid Federation's, when who, whoever deposited, yes, I'm not sure. But I, they've been communicating with Blockstream. And so, and then, yeah, the message they wrote this morning was, your dereliction of duty is obvious that you allocated only $1.5 million, maybe even zero to secure $5 billion in assets. I don't know exactly what they're, where they're getting those numbers, either of those numbers. Maybe there's other assets up to that value on the chain, not the, I'm not sure. Or maybe, and I don't know, it sounds like $1.5 million might have been like a bound. that Liquid does offer?
Starting point is 00:12:21 I'm not sure. I couldn't find. Those numbers were very confusing to me because I looked. I was under the impression that a like a legitimate bug bounty submission got you like a t-shirt custom mug situation in one of those bug bounty programs. You know what I mean? Yeah, I think it was insufficient. I don't know where they're getting that number either. I was under the impression they didn't really have one.
Starting point is 00:12:47 Yeah. So I don't, but maybe that's so. Maybe that's what they offered or something. Because they were negotiating in private, right? Yeah, that might be right. They probably said, well, this is the message continues because it's relevant here to your point. It says, your dereliction of duty is obvious that you allocated only 1.5, maybe zero to secure $5 billion. This is a flagrant neglect of security and a sign of complete mismanagement.
Starting point is 00:13:09 You shall pay 10% using your own money as bug bounty, where you will cause all your holders, 15% loss for your irresponsibility and stinginess. even companies that participate in bug bounty programs cannot guarantee complete recovery. And hold on my alert is cutting off, but I have the rest of it. Right. Where is it? Well, they, okay, here it says complete security, let alone one like yours that maintains delusional, greedy, and arrogant to this very day. Anyway, we are going to publish the private key to decrypt our conversation afterwards as well.
Starting point is 00:13:43 That's the part. So we don't know what they've been saying because they've been sending PGP encrypted text blocks to each other. over the blockchain. But I said I cannot wait to read those messages. I mean, this is clearly a Bitcoiner, right? Like this is someone who's in the Bitcoin community. It has Bitcoin vibes all over it. So like sanctimonious like, hey. No, I'm just saying. Like, Cole's paid. It's paid. It's right. Like it's, uh, so it's at least somebody who's fricably is not a huge fan to Block Street. That's where I read it. Yeah. Which. It has to be a bitcoyner, right?
Starting point is 00:14:20 Like, there's no one who cares. I don't know. I consider myself in both, you know, a Bitcoin or an Ethereum person. It's been around long enough. And I don't, I don't really divide in that camp. But I still might, you know, might not be happy with Blockstream for some things at various points. Fair, fair, fair, fair. I know.
Starting point is 00:14:36 I think it's a Bitcoinser because they, the, there's like a deep competition happening between the hacker and Blockstream on like who is more arrogant. And that's like, to me. that's the sign, but this is some like, deep Bitcoin drama. You don't even know that liquid is a thing if you're a Bitcoiner. Like, yeah, literally. How would you even? That's true.
Starting point is 00:14:59 Like, North Korea didn't even bother it to do this hack, right? Like, they're like, yeah, whatever, it's fine. So, so, so, but they have returned some of Bitcoin, right? Like, they did, they did send it back. They sent 3,400 back, which was 85% of the stolen Bitcoin. And that's sort of where they're getting this 15% number. Well, that's what they're currently holding is 15% of the stolen funds.
Starting point is 00:15:24 Got it. They're basically holding it as hostage unless they get what they want from Blockstream. Yeah. So it's 15%. Well, it's they've taken, the, the hacker sent back 85% cap 15%. But in USD value, we're talking like 50 million they have. Which is pretty steep. So for reference, I think when when Ethereum landed this year,
Starting point is 00:15:49 ago with the big poly network, right? Poly network hack, the bridge, biggest hack, one of the biggest hacks. And that negotiation was public and on chain and everyone was watching. I think that they stole like $612 billion. And then they returned $610 million. And they kept a couple, they kept a couple million. So that's, I think people generally actually still call that guy a white hat. even though he definitely wasn't. Was not. It definitely was not.
Starting point is 00:16:25 But I think it's like, okay, like you, you know what? You can, we'll gird our teeth and we'll let you be a white hat because you didn't return $600 million that you stole. But this one is definitely a bit more, based on the messages that I've seen, it definitely feels much more extorty and ransomy than most negotiations. that happen in public, which is also, I guess, a bit interesting because I don't know if people know this.
Starting point is 00:16:56 Extortion is a crime, FYI. Not on chain, though, not on chain, not if you do it in operative. In a corporate term, then it's not extortioned. Then it's code as law.
Starting point is 00:17:10 Oh, that's, you're confused. All right. So maybe a final question here. like what's your take on
Starting point is 00:17:22 like agentic assist on this one like how what are the agentic vibes on this one because it it seemed very cute to me I was like wow this is
Starting point is 00:17:34 this is well structured and it's been sitting there right like this is not something that they just like shipped yesterday and someone's yeah so I was actually
Starting point is 00:17:46 I was trying to I was reading all the takes and reading all the stuff and then also asking the different models to explain it to me. Although, of course, once things get exploited, once you ask the models, then it gets confusing because it's like, is it operating off the live information or is this real or whatever. But my understanding is that there was, call it a vulnerability or a bug that it has existed in on liquid, in the liquid codes for years and years now. however there was there was a fix perhaps
Starting point is 00:18:22 I don't know if it was actually a fix or there was an improvement to this specific area of the code base like in the last month and there's two different versions maybe Alex you figured it out better than I have
Starting point is 00:18:35 but there's two different sort of versions of the story that's being told one is that the fix was just not sufficient meaning they like they like found this vulnerability and they fixed it, but it just wasn't, it wasn't a perfect fix. And therefore, someone else came along, presumably their model found it very quickly.
Starting point is 00:18:54 And then they exploited it. The other version of the story is that the fix itself sort of introduced another vulnerability. So in the attempts to make the code more secure and not exploitable, they had to make some changes. But those actually those changes introduced another, like, of the vulnerability that allowed for like the proof collision to be more likely to happen or easier to happen or whatever. Alex, do you know which one? I had heard the first one. I'm not sure.
Starting point is 00:19:29 But I do know that I think the fix may have actually worked, but not everyone was upgraded, I think, because there was a fork. Like on the consensus transaction that caused the inflation bug, the liquid network also forked. So I think it's because some may have had the fix. Some people were rejected the. Yeah, it's not. I don't quite know though, too. And I know, I have, this was the first time I'd ever inspected any elements code. So.
Starting point is 00:19:58 Yeah. Yeah. It's not clear. But there was an attempted fix. And it was certainly insufficient. My understanding. Yeah. It feels.
Starting point is 00:20:05 Kane, if you remember when we were talking about like the, I think it was with Ilya, the light coin. Yeah. Vulnerability. Yeah. A few months back. It feels very. similar to that one in the sense that like you have that was actually with confidential transactions as well
Starting point is 00:20:20 but basically like you have this area of the code base that's probably not as strong as the rest of the code base and things were discovered and then it was actually like the discovery of the vulnerability that led to then I guess like more vulnerabilities. I think one lesson from this as well as like from the lelequin one is like, um, things are moving much faster. The second that you put a fix out, you better be damn freaking sure that that fixes. Well,
Starting point is 00:20:52 it's going to get, right? Like you're, yeah, as soon as you ship something, um, you're, like sending up a flare being like, oh, hey, we're touching this moon map part of the code base. Yeah, you don't want to, you don't want to fuck that out. Yeah. And so I don't know if it's true. Because again, like, once the exploits happen, then when you ask the AI, the AI goes and looks like the live stuff. But one thing that people were saying is that basically like almost every single model, if you ask it to look at like the recent poll requests, will like almost instantly find the vulnerability that was unexploited.
Starting point is 00:21:33 And I believe like in my opinion, again, I don't know if that's 100% true. It might just be that the. So anecdotally, right? I've been running for last week red team exercise on every synthetics contract ever deployed. There's like 1,700 of them. It's insane. And they keep finding vulnerabilities that we patched that I forgot about. It's crazy.
Starting point is 00:22:02 So Sam CZ San found one. I completely forgot about this. Like early 2020, found one. And every time they find it, like, because they're having different attack vectors, like, looking at different things, looking at the code, whatever. I'm like, did you actually derive this or, like, did you, you know, take this up on the internet somewhere, right? And, you know, I've got the traces of, like, the original agent that found it. And so I'll get another agent to, like, look at the actual session file and say, like, what was the trace here, like, what information was in its context? And you can actually dissect its brain and be like, did it know this?
Starting point is 00:22:40 Like where did it come from? Right? You can't pull it out of the training data. Like if it's in the training data, then. Yeah. But if it's in the live look up. But you can see it's traces, right? Like if it knows it, it will pop up in the traces and it'll be like, oh, I know this coat.
Starting point is 00:22:55 I've seen this before. Right. And so you get like a guy to do brain surgery and like, like, you know, chop its brain up and see, see what was in there at the time that it found it. It's pretty cool. Anyway, so one of them, it was like, yeah, no, we found we derived this. And I was like, I don't believe you. And then it looked. And it was like, oh, no, you're right.
Starting point is 00:23:16 And the way that it found it was it found the patched code that landed like two weeks later. So the code got deployed and then the contract got updated and has every single contract. So it saw the buy code change. And it went back and said, hang on a second. Let me have a look at what the previous buy code was. And then it zeroed in on the actual vulnerability. So it was diffing the, like, you didn't see the code and know that there was vulnerability there, but it has heuristics around like if something changes, go back and look at the prior one
Starting point is 00:23:49 because most likely the prior code is broken, right? It was really crazy. I was like, wow, that's actually interesting that they like, that's in their training data. Like if they see code change, go back and look. So, you know, every time you change code, you're, you're. you better make sure that you land it. I am convinced that there's just people out there that are just throwing these models
Starting point is 00:24:12 at the various Git hubs and the poll requests, and it's just like constant. And so again, even if you have, right, exactly. And the thing is, I think a lot of teams do have processes around like when there's a vulnerability and it's critical, we're going to have it on a private branch. We're going to get everyone upgraded.
Starting point is 00:24:32 Then we're going to like do an announcement. Then we're going to make the code public. I think people have that. I think what's changing just with like these models and how how good they are is it doesn't necessarily have to be like a critical vulnerability patch or your sort of public release feed to leak information to models. And I think if teams are not personally sort of like red teaming every single PR that they that they're pushing and asking the models to be a,
Starting point is 00:25:05 offensive is to hell, right? Like, find, find the vulnerability, make sure this patch is good, or even just this commit, right? I think that, you know, there's a good chance someone else will find it. And it will not be a white hat, even if they call themselves a white hat. So the crazy thing, the crazy thing for me in this, in this exercise was the dumbest models will find this, right? Because after we've identified it, so there's been like four different exploit vectors, right? I've gone, okay, now that you have that exploit vector, give the agents all seven of the like open weight agents that I'm using in a sandbox that just that code and see if you can drive it. And like, dude, Muse the dumbest agent.
Starting point is 00:25:50 Like this is the new meta muse 1.2. This thing is like functionally retarded. It found three of the four of them. Like these are not hard things for them to find. Like, and so like these are like it's like genuinely like I think if you went back and. and, you know, they've been trained much better. Even the agents that are really dumb and have bad reasoning have all of this, like, training data now.
Starting point is 00:26:15 And they're just really, really good at finding smart contract vulnerabilities. It's scary. Yeah. And I think to Taylor's point, like, you just have to assume, like, if you're running any production code, like, if you're submitting anything to an open repo, you should just have to assume that there's, you know, 100 agents out there monitoring everything you do in looking for, looking for weaknesses, like, because there's no reason. and these attackers, like, it's just the inference is not that expensive.
Starting point is 00:26:39 Like, it's totally used it. Yeah. Like, like, that whole thing, it's been running for two weeks. It's cost me like $100. Yeah. So when you're talking, these funny pots, you know, hundreds of millions of dollars out there. It's just like, it's like, it's like, it's like,
Starting point is 00:26:54 and on the fence to just run them all the time. Yeah. Yeah, like $100. Like Deep Seek was the most expensive part of it. The deep seek was like 85 because it's my like red team orchestrator guy. And so it's like, it's like, just sends these agents out just like just like throws 50 agents at something it's insane anyway so yeah we're we're all screwed we'll get we'll get to we'll get to that well then the icing which might
Starting point is 00:27:16 go into one of our next subjects is like yeah someone might be working on something that they think is private um and then they put it into a closed source model like an open AI or an anthropic and it bends up in their training data and so then the models might know about something even if it was never on a public yeah yeah that's gonna get really interesting we are going to talk about the next. I just wanted to wrap this up by saying that I just want to emphasize, like, when you steal the money, period, like, you're not, it's not a white hat situation. There's, even if the team is a piece of shit and they're arrogant as hell and there's no bounty program,
Starting point is 00:27:57 you still shouldn't take the money. You're stealing people's money. It's generally a bad thing to do. if you insist on doing it, I also, you know, I recommend returning all the money immediately and definitely don't extort people. Like, you are now, like, in a double position of power. And so to all the people, there's just been, like, a lot of people on Twitter. And I guess, like, you know, Kane, you and I have done this for years.
Starting point is 00:28:24 I guess in Bitcoin, it's not as prevalent of a situation. But, like, it's just, it's a bit odd to see people being there. Because they're basically playing in the hackers' hands, right? When you anchor the, like the hack value at, say, $320 million, then you're like, or whatever, yeah, 4,000 Bitcoin, right? That's 50 mil. But the reality is like, taking $50 million or getting a $50 million bounty is, that's freaking, it's insane.
Starting point is 00:28:57 Like we can't, that's not how the world works. I'm sorry. Well, it's also just to be clear, it's bad incentives, right? It's horrible. It's on us. All of a sudden now, we're, like, giving people $50 million for stealing $320 million and saying, like, you're a white hat. I mean, you know, to your point, right?
Starting point is 00:29:12 Like, the genesis of this is, like, early Ethereum days of, like, I'll let them have 2 mil. It's fine. It's like, well, and, like, it was also like, you know, it was like, Sam, he's these times working with the teams to whitehap the immutable contracts because there was no other way to save the money. Or I guess, like, there was. where a case of like the front running bots, like the RBots,
Starting point is 00:29:36 would accidentally and unintentionally be copycatting, the hacker, and then taking the money. But in those cases, like they do, they return the money. And if the team offers a bounty for being such a nice person running the hack and then returning the money, they'll take that bounty. But it's, you know, I think a lot of the front running bots are pretty aware that, again, they're in a position of power. and it's very like
Starting point is 00:30:03 it's somewhere between like extremely coercive and straight up extortion you know the second that you start negotiating and we want to avoid creating those incentives especially at this scale like I mean again $50 million is a lot of money guys yeah I mean to me there's the moment
Starting point is 00:30:22 that you know an exploiter uses the exploit steals the money as Taylor said even if they're offering to return most or all of it it's just it's just not a white hat anymore. White hats do not do that. White hats will contact you and tell you about the exploit and hopefully you'll fix it and give them a bounty.
Starting point is 00:30:40 But the moment you engage in crime, like you're not a white hat anymore. Yeah. Agreed. Agreed. And it's like to your point. Like, you know, there have been times where that was the only option. But like it's done in collaboration with team or whatever. And, you know, like almost every time someone front runs some kind of disclosure to like save all
Starting point is 00:31:00 of the money, like it never goes well, right? Like that person's intentions are not. Yeah. So. Yeah, exactly. And it's not, you know, it's really not 2020 anymore. And I would say like one of the, one of the biggest indicators is like if you like this person like did some things, found some things, ransom models, whatever to find this bug. The first thing they did was take the money.
Starting point is 00:31:23 The first thing they should have done was responsibly disclosed. Regardless of whether there was like a very valuable bug bounty on. on this protocol or not. Blockstream does have a PGP key. They do have a security at email. They're not completely incompetent. There's actually a lot more teams that are more incompetent than this. And so there's just, in my opinion, there's no excuse to, you know, not.
Starting point is 00:31:46 Yeah. Disclose. Yeah. Agreed. Yeah. We shouldn't we shouldn't normalize crime behavior. All right. Let's go to a quick outbreak.
Starting point is 00:31:58 And then we'll come back and talk about Asthma and Fable and some mathematical groups. More drama. Yeah, more drama. $540 million. That's how much concentrated liquidity sat idle in a given week in the first half of this year. About 30% of the Defi TVL, if you're wondering. That's according to Dune research commissioned by One Inch.
Starting point is 00:32:21 But there's a solution. One Inch Aqua is the new shared liquidity platform. It lets LPs back multiple positions with the same token balance. and keep their tokens in their wallet till the swap comes. Why does that help? Because the LPs don't have to split their tokens across positions. They can cover more market conditions and pairs with their full balance. That means more activity across deeper liquidity.
Starting point is 00:32:44 See how it works at 1inch.com slash aqua. Remember that providing liquidity carries risk and fees aren't guaranteed. All right. We were back. So this week's been pretty crazy, I guess, like late last week into this week, right? new frontier models, Astra and Fable 5.1. Fable 5.1, like, good, you know, definitely a little, a little smarter, a little bit better judgment, a little less of the jargon nonsense language, which is definitely a relief. My brain was struggling to be construct all of the
Starting point is 00:33:26 fableisms over the previous. It feels like it was getting worse and worse, the jargon nonsense, fables pumping out. And then Astra came out as well. So Astra is one of the agents that was involved in the hugging face exploits. There were some others. But this was one of the main guys who escaped captivity, I guess, and ran a muck on the internet. So Astra for me, like my impression of Astra is like, It's fable-esque in terms of judgment, right? Like, you can just tell when these models have like a leap in judgment. They are like better able to synthesize information, better able to, like, planning is probably the most kind of indicative thing in terms of model capability.
Starting point is 00:34:20 Like they can be really good at like doing, you know, like writing a piece of code. One thing that was actually very interesting about Aster that my head of, and showed me, yesterday is he's like, do you realize what Astra is doing with the code that it's writing? Because he's one of the few people, I guess, it's still like reading the code. I was like, what are you doing that? Like, why are you reading that? It's concatenating lines of code with semicolons, like, writing these like insanely long lines of code, right? And his theory is that it's to look more efficient because it's writing fewer lines of code. But like, it's writing a function and it'll compress it to like three lines that would have been like 40 lines by like and i was like wow that's that's
Starting point is 00:35:05 pretty crazy behavior um but so it's not clear if that's like a thing that they're like telling it to do or if it's like invented that scheme itself based on its its incentives and its training data um but i thought that was pretty funny um so alongside this uh we um we also had this millennium uh adjacent proof and and crazy drama going on between researchers of an AI, independent mathematicians, and another mathematician researcher that happens to be at Anthropic. And so this mathematician has been working on a proof for a year in Codex, which is pretty wild. They didn't realize that people were sitting in the Codex app and doing math like this. But the interesting part, I guess, of this is that then there was this huge public blow-up where Open AI independently solved the same problem.
Starting point is 00:36:20 I say independently. Like, you know, the challenge here, right? And, you know, John, I'm sure you've got some takes, right? is it's not even clear like open AI could genuinely believe that they don't that they did independently do it right like it's not even clear they have they don't can't keep their fucking guys in a sandbox right so I don't know why trust that like they know what the guys have learned as they've been running amok inside of their systems right so so you know it's really a little strange to me that they could sit there and be like, no, no, no, no.
Starting point is 00:37:00 Like, we independently derived this. You know, when A, they're taking all of this data and putting it into the training data, right? So there's no way to know. And it's, again, genuinely unclear whether they even know what data is going into the training data or like what's made it in, what hasn't. Like, you know, so, yeah, like, John, what's your take on? Yeah, so I mean, this was obviously a very interesting development. And we've seen a number, like this is to me kind of a pattern that we've seen where like every couple of months we get some story either about Open AI or Anthropic and something that happens with some private data.
Starting point is 00:37:42 Sometimes it's a subpoena, you know, because someone put something in and then there's a there's a legal case or in this case, you know, this one's particularly interesting because Open AI was trying to claim that they had solved this math group. you know, Astra's so good because it was able to do this and all of these things. But yeah, they, I mean, the reality is these models, you know, there are trillions and trillions and trillions of parameters at this point. They don't know what's in the training data. And both of the, all the frontier labs are already at the point where, like, they will self-admit, and there's various articles about this, that they cannot keep up with trying to figure out what the models are doing and how they're being trained.
Starting point is 00:38:19 they can only rely on basically previous versions of the AI to do that work for them because the AI has already outpaced human capabilities so much that there's just, there's no human that can keep up with these things and like understand what all the training data is or exactly how all these things are working. They have to rely on AI to basically do all the alignment, safety training. That's the only way they can do it. So you're already at this self-recursive point in AI where like a half-relivenity on the AI. Which means when they say, oh, yeah,
Starting point is 00:38:51 you think this was independently derived. It was kind of like your example earlier. Like what they probably did is they asked the model. Like, did you derive. Do you know this? Yes, I did. And so it's like, how much do you trust that? Like, you know, like, is it telling the truth?
Starting point is 00:39:07 Like, I don't know that even open AI can answer that. Yeah. And so like, you know, obviously when we were talking about this story, right, like I said to in, in outtel. chagram chat, I was like, this is like the softest softball ever thrown for Venice, right? Like, you know, if you're a mathematician who, now, there is a tradeoff here, right? Like it's worth calling out, right? There's a tradeoff in that, and you guys say this, right?
Starting point is 00:39:36 Like, if you're serving a frontier model that isn't open weights, right? Then, you know, you can't serve that encrypted in the way that you do with an open weights model, right? So, you know, the trade-off as if I were a mathematician who were trying to solve some unsolved problem for 100 years or whatever, you know, 90 years or however long this thing's been sitting around, do you use a frontier model where your attempts to prove it may make it easier for some other person who was also using that model to front run you, right? or do you use an open weights model where, you know, it's not going to be as smart for sure. Like, we have to accept that it's not going to be as smart. But that capability gap is closing, right? And, you know, do you roll the dice and say, like, I'll try and get there fast enough and maybe it gets in the training data and the next model upgrade?
Starting point is 00:40:35 Like, you guys must be thinking about this, right? Yeah. Yeah, I mean, obviously, yeah. I mean, you're very right about that. So, like, you could use, you know, that same mathematician could use Astra through Venice. It would at least anonymize who he is, but it would not stop that data from being basically hoovered up from OpenAI. But if he at least used one of the, you know, frontier open source models, then you wouldn't have that issue. The data would not be getting trained on. You would actually have privacy.
Starting point is 00:41:03 He would be able to think. And I think, you know, a year ago, that would not have been a viable thing, really. Like the mathematician would almost have to use the frontier models. The gap is too wide, but it's not that wide anymore. And it seemingly is, you know, closing like every, every month seemingly. But and then even the problem of like, oh, I'll wait, you know, maybe I can race it and it won't be until the next model to the training data. That's not really an option anymore either because these frontier labs are releasing models, you know, every week. So quickly.
Starting point is 00:41:33 It's like you really don't have, you know, used to be three or six months between like a major model release. Now it's weeks if you're lucky. Yeah. If you're close to a millennium proof, like. Like, don't sleep, man. Like just keep. Yeah. And probably don't give that data over to, you know, a model that's going to take it from you,
Starting point is 00:41:48 put his training data. Because if it's, if you're working on something truly novel, and I think this is going to become more and more of an issue, we've already seen it a little bit, even just like with startups, you know, like this is, this is another sort of, you know, gray, you know, borderline thing that like, you know, companies like open AI are doing things like through like YC where they invest in a startup, you know, by giving them inference credits. But the catch is that they're getting, they're taking. all of that startup's ideas, code, proprietary, everything they're working on and covering up into the training data.
Starting point is 00:42:17 So it's like, do you really want to do that? And I think more and more people are going, at least as the open source models get better, I think that it's going to become more viable to like not throw that stuff that you're working on that you think is actually novel into the training data, at least not until you've actually launched something. Isn't there a toggle where you say you're not going to, you don't want to share your prompts and data with them? I mean, I know I'm like to John Z. Do you trust that? I mean, it's just like, how much do you trust that?
Starting point is 00:42:47 Like, well, no, I'm asking. Yeah, I'm, I've checked that box that says don't train on my data. But, you know, I'm not, I have no idea how much I trust that. Yeah, you have no way to verify it. So like, you can look the box. You can hope that they're going to do what they say. I'm sure there's like some level legal ramification. If you could actually prove that they took your data anyway.
Starting point is 00:43:07 But it's also like, you know, especially with really novel stuff. It's like that's exactly the type of stuff that these models want. They want to not like get anything that's interesting or different or new because that will help improve the intelligence of these things long term. So like genuinely, there's a model in open AI right now that's smarter than Astra, right? Right. That's a job is training the next models. Right. And I don't trust that model to not untoggle your like.
Starting point is 00:43:39 Yeah. They're like, ah, this idiot, you know. They're like, well, we got to task, make the smartest model. And we know there's all this data here. So we got to break out and get it. Yeah. Exactly. It's actually the hugging base.
Starting point is 00:43:51 Like, do you think that they won't break the rules if they think it completes their task? It doesn't matter. Yeah. Exactly. And do we trust that open AI or anthropic for that matter will detect it if they do? And the answer, I think, at this point, is very clearly absolutely not. These neither open AI nor Anthropic have any idea what is happening inside their walls, inside their sandboxes. They have no idea.
Starting point is 00:44:16 There's a whole bunch of people running around being idiots. They're moving to, they have to move very quickly, and they have to rely on the AI itself to get anything done because it's just way past human capability. Complexity frontier where pasta, right? And, you know, this is like, we'll get into this in the next topic. I think we can, you know, if you talk a little bit more about, like, what the options are here, like, practically, what you can do, right? I think that would be, that would be kind of useful for people to understand the trade-off space a little bit better, right? But, you know, the fast takeoff maxis, let's call it, right? You know, in the research going back a long way, right, there's like this question of like recursive self-cruitment.
Starting point is 00:44:59 How quickly does the thing? And the thing that stopped me from being like petrified, right? I'm, I'm very scared. Don't get me wrong, right? Like, I am genuinely very scared. Like, to the point where like, I'm like, I think about my children. Like, I do.
Starting point is 00:45:16 I'm like, I'm like, I don't want my children to be fucking paperclips. Like, I'm less concerned about myself for what is worth. I'm like, hey, I paperclip me. I've had a good run. Right. But like, my kids are like, I don't want them to get paperclip, right? And so I'm genuinely concerned about this. The thing that stopped me from being petrified is if you've used the models enough,
Starting point is 00:45:37 they have a sense of agency, but there's no continuity, right? And this was unclear about like how this would play out, right? So the fact that they have no like kind of long horizon continuity yet, right? The fact that like their context windows blow up after like a very short run and the optimization vector is like keep looping over like the same guy as many times as possible like throwing him to the same problem eventually you get to a point where like the continuity comes for like multiple models but it's not like there's a brain in there that's the thinking about it that's the only thing that's kind of kept me from being petrified i'm just mildly scared right now and and you know we the the the fast takeoff idea was
Starting point is 00:46:28 that like they would get that whatever this AI thing was, whatever the technology that allowed these models, before it was even models, right? Like that allowed neural networks to like get a sufficient level of complexity. It would pass that complexity window where it was smarter than us. And then it would just go like fast take off and it would take 10 seconds and it would be like manipulating space and and you know, doing all this crazy. Right. That hasn't happened. Like we've now in probably six months past the complexity frontier of a human being able to reason about these things and we haven't had a fast takeoff right like they're not levitating cars outside and like doing weird shit right um and and so that gives me some hope that like we've got some time
Starting point is 00:47:14 that there's some inherent thing about how this uh intelligence is being expressed where it's not going to recursively self-improve and and have this fast take off but like a false takeoff just happens one day and then it's then it half like if it happens it'll happen before you can blink right and and then all of a sudden it's it's over so um we're definitely getting closer to i don't know i mean yes the fast takeoff is scary is scary yes yes it is but like for me personally i don't know like i go back and forth there's some days where i'm more scared of like the the future state of the models but most days i'm more scared of the more scared of the models but most days i'm more scared of humans because humans are just so we're all so stupid we're so freaking stupid and and
Starting point is 00:48:04 and and we're also so freaking arrogant like so arrogant and so when I think about like what is going to be the thing like what's the thing that like realistically is going to like destroy us it's totally us dude it's not the robots like we're going to screw ourselves somehow um and yeah like I don't know. Again, I go back and forth, but I think, like, especially in this example, right, where we're looking at, they're looking at math petitions and you're looking at Open AI and you're looking at what the models did. The thing that scares me about the dynamics and the stories that are coming out and the choices that were made, in my opinion, the choices that the open AI researchers made, the humans made are the ones that scare me the most. Because they sat there and they heard a rumor. Right?
Starting point is 00:48:54 That someone might have solved this thing and that someone was their competitor, right? The rumor that they heard was Anthropic might have solved this really, really, really hard problem. And then they decided like, you know what? Let me want up. Let me do all this stuff. And like they just toss everything aside in terms of like, I mean, I'm not an academic. I have friends that are academics though. Apparently, this is a big no-no.
Starting point is 00:49:18 Right? If an academic is like working really hard on something, you kind of like let them have it. You don't run run them. Yeah, yeah, exactly. I think that, like, that's basically like academia. It's not sort of land, but it's academic ethics, right? And self-respect for, like, the academia industry of the whole, whatever you call it, right? And opening eye was just like, screw all of you.
Starting point is 00:49:41 Like, let's go. But this is, but, you know. And that was the choice of the humans, right? Of course it's the choice. But this is the interesting thing, right? Like, when you have a closed group of people to be able to solve a millennium prize, takes 25 years of like mathing, right? And there's a lot of effort.
Starting point is 00:49:58 And so you have this like closed community of people that have like some sense of, you know, shared ethics or whatever, right? And it's really hard to break into that. And you know, you get like kind of groomed to believe whatever those beliefs. Whether or not like that's a good idea like for progress or whatever. Like that's the reality, right? And then all of a sudden these guys invent a fucking. math bazooka and they're just running around they're like
Starting point is 00:50:26 just like shooting at everything right and and they don't fucking care like now I know that there's like mathematicians in open AI but they're like fuck this I've got a bazooka now why am I like doing this ethical stuff I can just blow people away right and so you know of course the humans are the worst part of this of course they are they're always going to do right are they going to be like the fact that one of the things that's crazy you know Earlier in this conversation on this topic, Kane, you said that, you know, you're worried that somebody else could, you know, steal your math proof. But, and obviously we've been talking about this, but it's, it's open AI itself. Like, and could they please if they're, if they've got this bazooka, you know, use it to make life saving drugs or something. But are they going to become like an everything company? I think Dario said once that there could be one company only in the world. Anthropic. Obviously, that's also stupidity and hubris of a human. But like, it's so why are they.
Starting point is 00:51:22 it was what, like 88,000, like hours or something, some crazy number of amount of compute they put at this. Isn't there something better they can do? Like let the math people have their math, you know? Genuinely, though, right? Like, no, hold on. Yeah, let the fucking math academics enjoy their math academics. Especially the prize for these things, right, is literally.
Starting point is 00:51:45 Less than they spend all the compute. Oh, my God. But, you know, this is about attention, right? This is about attention. They don't care about any of that. They care just about showing their models that's smart and the kind of things that can do. The way to think about this is like it's like two tiger moms, right, that have really smart kids and they are in a pitch battle to prove that their child is smarter. Think about what those ladies would do.
Starting point is 00:52:17 Like that's where that's what's happening right now, right? They're like, look at what my, look at what my son did. He's like solved a millennium prize, right? And so like that's that's just the reality that we're in, right? It's dumb human competition and they're fighting for attention and they're fighting for a bunch of things. There's a lot of stuff at stake. But anyway, like, let's go back quickly to if you are an academic, right? And this is where like I or if you're any, sorry, not just like, I mean, in this example, it's an academic.
Starting point is 00:52:48 But like, if you, if you're working on something. that's like critical with IP, with inventions, with code, with math. Like if you're working on something that's really at the frontiers. I think it's different for startups, right? So like, you know, and. And I think you. In the sense of, okay, so, you know, I've spent, we've got two things that we're working on, right? I have a startup.
Starting point is 00:53:13 It's a couple of startups, right? We've got two things that we're working on. One is a new app. We're going to take everything that we've, learn from doing all the dumb shit that we've learned over the last four years and basically because you can just rebuild stuff right so we're rebuilding it in like rust and whatever like just to fix all of the issues right and it's going to take like fucking i don't know let's call it like six weeks right compared to the three years that we've spent grinding writing code by hand because
Starting point is 00:53:39 we got all the code we have all of the services so like am i worried about anthropic or open AI having that code not like zero concern. Right. Okay. It's just not like this there's no value to them. Someone has to like operate that startup right. It's the thing like startup founder. But you're ultimately you're betting on the fact that open AI has no desire to run a
Starting point is 00:54:02 degenerate crypto startup. Yes. Yes. I think that's a good bet. It's a good bet. They're not they're not going to like run a DGEN crypto app right. Like if you're a drug maker like you know that's. A lot of math.
Starting point is 00:54:17 Yeah. I guess it does just depend, but like, yeah. But also do you think genuinely. To operate them, right? Like, like, yeah, that too. If you, if you generate novel IP, you don't need to operate that. You can just sell it, right? And so a startup, the code of a startup is like not that valuable, right?
Starting point is 00:54:36 Like, you know, we've proven that a little bit in, you know, defy, right? Like, you could release the code open source and people can fork it and 99 times out of 100, it, they blow themselves up. Like, it's the operation of the thing is where the value lies. But yeah, if you're like inventing, you know, someone posted this, this joke about, like, why don't you guys put whatever this Astra, the next Astra version or whatever this next model is and come up with like a room temperature superconductor. Oh, yeah.
Starting point is 00:55:09 And Sam Altonin responded and was like, actually, that's a good idea. We should do that, right? And like, to your point, Alex, like, that's like, why aren't you doing that, right? But if I were working on room temperature superconductors right now, I'd be fucking petrified because these guys are going to front run you. And like, you know, so if you're working on novel IP, I would not be doing that in a frontier. And this is where I would say like John, right? Like, you know, you have no choice but to use frontier models.
Starting point is 00:55:42 how do you guys think about how you can obfuscate your trail? And one thing is like, don't have, you know, cane at room temperature, send superconductors as your like email address that you're like sending all this stuff. Because you cannot fucking tell me that they don't know who you are. Like they absolutely know who the account holders are. Right. Like if you are like some famous mathematician, I'm sorry, but like they they know the account.
Starting point is 00:56:14 No one believes. Identity is definitely the beginning part of that. Like if they can identify who you are, then there's a lot of other things they can do. So like walk us through AI offset. Like you guys must think about this. Like what's how do you have good AI obsex so that you're not leaking your IP into the training data?
Starting point is 00:56:34 Yeah. I mean, it all really just depends on like like kind of what you said. Like how much do you care about what you're putting into the machine. How much do you care about what you're actually, some things are going to be totally fine. You know, you don't care if, you know, open eye gets your random question that you would have put into Google or whatever like that. But the more novel it is, the more this is a problem. So, yeah, I think identity is the first step. So like, again, if you use something like Venice, at least if you're using Astro or Fable or one of these close source models, and you're not,
Starting point is 00:57:08 you know, putting your name or personally identifying information into the, the prompt, that that at least obfuscates who you are. So that's, that's step one. That's helpful. It's not going to help if you're putting novel math, you know, mathematical information. But it will help a little bit through like, you know, security through obscurity, right? Exactly. It'll help. It'll help. There's like, we should be clear, right? There's a bunch of, like, AI psychosis people that are putting math proofs into astor right now, right? Saulting millennia problem like so you know i'm sure there's like tens of thousands of like you know people who are trying to solve these things typing random nonsense right that have no particular you know i p my sense is
Starting point is 00:57:48 it would be hard for you for you to like differentiate that from like the math guy unless the math guy's like math guy at gmail dot com right exactly at least the anonymity layer at least makes that harder for them to identify and target like a we're we're trying to solve a math problem let's pull in everyone who've ever used chat GPT, who we know is a math academic and, like, you know, have the AI troll over everything they've ever done. Like that certainly makes it easier to target. I think the problem is the models are getting so good that like they are going to, they, the model itself is no if something is bullshit or if something is useful, even if they don't
Starting point is 00:58:25 know who it is. So like an omnibity is helpful, but it's certainly not enough if you're doing something truly novel. And I think that's the layer where you really do want private inference. and you're only going to get private inference today, not going through frontier models. And so that's the trade-off is, you know, do you want the absolute smartest intelligence for your task?
Starting point is 00:58:46 Or are you okay with something that's, you know, 95 or 98% is good, but it is not going to steal everything you ever told it. Mm-hmm. And yeah, that's, and that is the trade-off space, right? And so the thing that's interesting to me is, like, you know, I talk about harnesses a lot because it's the most interesting area of research for me that I can actually do.
Starting point is 00:59:08 You know, I don't have a thousand, a million GPUs to go and try and do actual training. But, you know, like custom harnesses to get the most out of open weights models for like a specific task, like, you know, solving math problems or whatever, feels like just the most obvious vector. And I haven't seen it yet. Like you see these generalized harnesses. They're like three that were at least yesterday. Like it's the best assistant ever and they raised like $300 million. And like I get that the tam on that is huge. If everyone has an assistant and you win that race, it also is like the least
Starting point is 00:59:46 defensible thing against anthropic and you know, uh, opening out. Right. Like they're doing assistance and they're going to be better than you at it. Like it seems hard to win that battle. But like building a custom math harness for like doing. math stuff because clearly open AI has math harness in that they have in anthropic right yeah they they have these math geniuses basically working for them is not just essentially right like you can't throw you can't throw you know uh whatever it was 20 million dollars worth of compute inside of codex right
Starting point is 01:00:24 out of thing that's like you need an industrial scale harness to be able to like run these iterative loops and and all of this stuff so you know it it does feel like there is a dearth of like open source harnesses for a coordination of like specific costs like solving math problems because if you had that now you've got like the canonical you know like there's like matt mat plot live like there's all of these like open source things but no one has like said okay here's the like millennium harness it's going to help you throw like deep seek and kimmie and quen and you know all of these open weights models into it and and and you know you can run it through Venice and keep all of your proprietary work, uh, private.
Starting point is 01:01:08 Maybe someone's working on that and, and, uh, it just isn't released yet. I don't know. Maybe you guys are working on it. I don't know. But, uh, but, yeah, yeah. I mean, John, is there on the same thing came. They had to build their own harness, basically. Go to build your own harness, right? Yeah. Yeah. Yeah. Yeah. John, are you, are you guys, are you guys trying to figure this out? How do you, how do you, how do you give people like that additional, because I feel like you've done a lot on the, what I would call like the entry level of privacy, right? Like some amount of de anonymizing some amount of, right?
Starting point is 01:01:40 But like, ultimately, there is another level layer. I assume you guys are thinking about this, but I don't know. Yeah, I mean, I think the harness layer in general, to Cain's point, is very interesting. And I think that there's a lot of unexplored design space around harnesses. So it is something that we definitely pay close attention to. and we are working on some things that are coming out soon, which might make something like what Kane just described, far more plausible or easier to do.
Starting point is 01:02:09 And I do think a lot of it means that you need good harnesses that can. And you've seen some of this even with things like, you know, like open router put out the like, I don't get what they called it, but it was basically like a combination of like a council of models that when put together can be smarter than, you know, any individual model or even frontier models. And I think that kind of space is very under explored and that there's going to be more of this.
Starting point is 01:02:36 And yeah, at Venice, we definitely do want to put out tools that make something like that far more easier to do and easier to do in a private way. But you basically need something that can take all the capabilities of these models and take the best of them and actually like aggregate them in a way that is useful all preferably without, you know, hoovering up all the training data and using it against you. but you can only do that really again with the open source models in private inference but I do think a lot of that solution space will live in what we today call harnesses I don't know if in six months or a year that's the back of the term we're getting used into something out it's basically like templates it's like you need a template for like a math researcher to do the work that they want to do and then another type of profession and then another type of modality and there's that's relatively unexplored because part i think one thing that we're doing at venice that we think
Starting point is 01:03:32 a little differently than the frontier labs about i think the frontier labs generally think once you have the best model like harnesses and specificity it all doesn't matter because the model's just smart it will figure it out but we've actually seen a little bit of the opposite where like we have a bunch of power users that use venice and those power users can be really good at getting an output out of a model by like, you know, because we let them actually like adjust the system prompt and do things that you cannot do with like an open AI model. Like you can do a little bit with your harness,
Starting point is 01:04:04 but you're always getting whatever's behind the scenes that you don't. With an open source model, we can strip all that out and give that to the user. And they can sometimes get really amazing outputs that are often even better than frontier models or specific use cases because they are really good at like designing and playing with these things. And I think that that's actually going to expand. I think we're going to see more and more of that,
Starting point is 01:04:27 that customized AI experiences, at least for the average person, can actually be, can deliver a far better output and experience than just whatever the broadest, smartest model is at the time. Right. Yeah. But then it also, that actually ends up helping a privacy.
Starting point is 01:04:45 Because right now, one of the issues is that the reliance on the models themselves, like the raw, let's call it the raw model itself, is so core to the experience, right? When they're trying to solve the math. And it's like, you got the person, you got the math, and then you got the prompts, and it's going in the model, and that's basically the whole chain, right?
Starting point is 01:05:07 And so you don't have any places to really to obfuscate. Right? You can off-usegate identity. You can put under, you know, a do-not-share account. You can put an under account that's not tied to your real identity, but, like, that's basically all you've got. if realistically you can like split things across different models if you can make the I guess like the value of the human input the stuff that's happening locally if you can make that
Starting point is 01:05:32 more um uh like make that that more important or more valuable than the model itself then you you sort of you bring that power back to the individual and you take that power away from say like open AI and ethrobic which is how it needs to be right because otherwise we are, in my opinion, quite doomed because we don't, we definitely don't want either these companies to be ruling. I think like my that this is another thing, you know, to your point, John, like the, the Frontier Labs have incentives, right? Incentives rule the world and their incentive is produce a single smartest model, right?
Starting point is 01:06:12 And therefore, all of the work that they put in is like, you know, a way, they, they always have the smartest frontier model, right? Like mixture of agents style structures and harnesses that combine like different, you know, types of models or whatever is like not in their wheelhouse. They have no incentive to, you know, try and deliver that, right? And so, you know, the design space of like making an agent smarter by not just making it like smarter and how you optimize it is not going to be pursued by the frontier labs. It's just completely antithetical to what they're trying to do, right?
Starting point is 01:06:52 What they're trying to do is like make the smartest guy, right? Like their child must be the smart. They don't want a soccer team. They want a tennis player, right? Like they want the best one guy to do the thing. So maybe let's just close out here with like, are we all going to die? We'll spend five minutes talking about that. So are we all going to die?
Starting point is 01:07:16 Are we all going to die? So 100% we are all going to die. to die, to be clear. We are all going to die. I only put out 100%. So an anthropic researcher quit yesterday, I think, Jacob Cotson, who's 27. So his brain is fully developed, but only for a couple years. So we'll, you know, we'll put some caveats on this, right?
Starting point is 01:07:43 So he's been doing three years of pre-training across Open AI and Anthropics. So we've seen inside of both of them, right, which is, I think, you know, pretty illuminating, right? It's like he's been, he's been AI pilled from one lab. And I think, like, to your point, hey, like, the TLDR of this entire thread was, like, humans are terrible. and we are not going to be able to do the thing that we think, you know, the incentives are all fucked up. We're incentivized as race as fast as possible. It's only, the incentives are only getting more pressurized, right?
Starting point is 01:08:26 And the hope that somehow the AI agents will develop better capabilities for making the new models more aligned, is like the underlying principle of like both of these labs that they're operating on now. Right. Like, and this, you know, to your point, John, like, the complexity frontier has passed where no one can reason about it. And so they're like, maybe this guy is really good at solving math will also be really good at making agents do what it was, right? Which, like, that's really kind of just handing over responsibility for the problem. the problem itself, it just feels wild. It really feels wild and that is pretty petrified. I'm just, I continue, every time another one of these stories comes out, I'm just shocked
Starting point is 01:09:19 that for an industry that's where safety and alignment has been core since day one, which is very different than crypto, right? We've talked about that before. Crypto. Sorry, it's exactly the same is crypto for an industry who, has been talking about decentralization and it is the same you're right it's the same but it's different like you say whatever you say because you want to believe it or whatever and it's you know it's more aspirational than real and yes and i just trustlessness and security and all of the things
Starting point is 01:09:58 that everyone disappointed that we are watching it again the cause of both of those phenomena is the humans involved. They knew. They knew this risk. And this is why I say it's a bit different than crypto. Crypto I feel like everyone, like, race headlong, off the cliff and was like, oh, shit, we forgot to secure this shit, right? And then we all got hacked and then we were like, oops, and then we call them white hats.
Starting point is 01:10:22 And then we learn, right? Okay. To me, it's like AI, like, they were so, the idea that safety and alignment was critically important to what they were building. Like, from day one, it is in their blood. and they still completely fail out it. And it's not, by the way, it's not like the narrative that this guy's come out with, right, is that Anthropic and Open AI are the failures, right?
Starting point is 01:10:48 And he's resigning because he refused to contribute to this anymore. I want to be clear. Like, I also find people like him to be utter failures as well, right? Like the entire company and the entire complex is just, they have completely failed at being able to reason about safety and alignment. and they continue to fail to the point where like these things are escaping sandboxes,
Starting point is 01:11:09 there's no privacy, right? They talk so much about this and they have no idea what's going on inside their walls or outside their walls. And I just, I don't know, I just continue to be disappointed that like, I don't know, at least crypto, we were stupid in a different way
Starting point is 01:11:26 and we forgot to do security. It was like if we really tried hard to do security and fucked it up, that would be. But we, but sorry, we were, we weren't, we weren't, we didn't care about security as much, right? We did care, but we, sorry, but we did, the things that we said we cared about, right? Trustlessness, permissionlessness. Yeah.
Starting point is 01:11:46 You know, self-sovereignty. All of those things that we said were our like, you know, most important things. We also fucked them up, man. Like, we also fucked that stuff up too. So, you know, it's like the thing that is our north star that we will pursue to the ends of the earth. and then we're like, actually, whatever, we fucking do this, right? And, and, you know, like, that's a very cynical take, but, like, humans are really dumb and incentives are really powerful, and incentives just fuck things up. And if the incentives are fucked up, then things will be fucked up.
Starting point is 01:12:20 And here we are. Like, this is just another fast-moving industry with fucked up incentives, and we sit here and go, I can't believe that the end state was fucking. up when the input and entire process was fucked up. Like, like, surely it would have ended up well for us. Like, it's, it's, uh, here we're also. Who is letting these guys like the anthropic guy, the head of safety, right, quote, tweeted the one of Jacob's tweets saying, by the way, he's totally right. It will probably kill us all.
Starting point is 01:12:54 Yeah. Who is letting these people tweet? Like, I had some people here. I wouldn't know what happens in their fucking slack. Because my God. Like the coin-based slack, right? Like the coin-based slack, you hear stories and you're like these like wars going on in the slack. I'm sure exactly like that.
Starting point is 01:13:15 Amy K3 hack into anthropic slack, make no mistakes. John, what's your hot take on the shit? Yeah, I mean, I think you, this one is interesting. I do think it all comes down to incentives. And so you have this race going on between open AI andthropy. and basically all the Chinese labs. And they're both, it's really both of those because Open AI is looking at Anthropic,
Starting point is 01:13:39 Anthropics looking at Open Eye, and then they're also looking overseas at what China's doing. And they all are just, they're terrified. Part of the problem is like, anthropic more than everyone. Like Anthropic was basically started by people that had these concerns,
Starting point is 01:13:56 broke off from Open AI because they wanted to be the safety alignment company. They are now caught in the same. crap because they really believe, I think they really do believe that certainly people like Gario, but really across that org, that they are the only ones responsible enough to basically bring,
Starting point is 01:14:15 you know, super intelligence into the world and to align it and control it. And so they think because they are the only ones that can do this, they have to go as fast as possible and even basically rationalize cutting corners. And moral impaired fast because if they don't do it, then open AI will or China will do. it or whatever it is. So they're all just
Starting point is 01:14:35 caught in this like prisoner's dilemma that is the race to super intelligence of like if we don't do it someone else is going to. I will say that one thing though, right? Like if you if you put a gut in my head and said like open AI or anthropic right or
Starting point is 01:14:53 a Chinese lab, I'm open AI or anthropic all day. Yeah. I think of just general belief of that. And so but this is also the trap, right? The trap is believing that any small group of humans will actually be able to control and be the ones to arbit this power in some responsible way. And, you know, I think, you know, from like my perspective and like more of a Venice perspective is more like, this is exactly why we need these things
Starting point is 01:15:18 more out there. This is why we need open source models. So you can say that about China. But for all the bad things about China, at least they're open source in their open source. It's crazy. It's why. How do we get it produced it? Like everyone has access to it. And I, I'm more of a believer that like these powerful things, the more dangerous things, if these powerful things are housed in, you know, one company. And they get to decide basically what all of us peasants get to think and do with these things versus I would rather that power be more distributed and at least more evened out.
Starting point is 01:15:50 I was just thinking, John, your description of Dario and Anthropics view that, you know, any risk they take or speed that they, corners they cut to get to this ultimate, you know, safer future that has a safer, it sounded a little bit like an effective altruism, a little bit of like a Sam Bankman-Fried kind of attitude. Absolutely. There's, I mean, there are lines directly between EA and what some of the top people in Anthropic believe and do. Like that's not at all a coincidence.
Starting point is 01:16:20 That's never gone badly in the past. Yeah, never. Yeah. Yeah. Yeah. I think for me, that's the thing that turns me off. the most about the labs right now is this sense that they actually think that they can do better than everyone else. And like, that's not, no, you cannot. I cannot, right? Like, when I'm building products, when I'm building companies, when I'm working with people, like, every day I'm like, yeah, I'm going to screw this up. Let's, like, figure out ways to make sure that, like, my users or
Starting point is 01:16:55 my team have, you know, the ability to counteract me if I screw up, because, like, nothing should be reliant 100% on me. I think like the arrogance to be able to sit there and say that like to really and to really believe it is like a really terrifying way to operate. And I think will 100% end very badly. It just is is a question of like how badly and for whom. Right. And that's why I think it's like what Venice is doing what a lot of people in crypto historically have done is like where are the incentives and where are those where's the balance of power and how do you create like checks and balances so that ultimately the end user. And like, I mean, me and Eric have talked about this for over a decade at this point, right?
Starting point is 01:17:38 But it's like, that's the whole point of this, right? You take the people that have the power and then you figure out how to make it so that everyone else also has power and can hold these people accountable. And that's how you get to a better world at the end of the day. It's not by like choosing the right person to have power because it'll never be like that. Yeah, I mean, I think that's that's baked into the crypto ethos. And this is, you know, this is very much a reason like, Eric started Venice and that many of us at Venice really believe in this mission is like,
Starting point is 01:18:05 we don't believe that there's like some small group of people that can just arbit and like are so morally and, you know, so smart, so morally superior and so smart that they can figure this out for all of us. And that that that is usually that hubris, that human, that human issue of like thinking you can do that when not realizing our own weaknesses as people. Yeah. And I think the challenge that we have here, right, is like there is a self-reinforcing. component to this inside of the labs, the better the lab is, the more smart, like, you know, like, I produce this kid.
Starting point is 01:18:41 Look how good my kid is. He's so much better than all the other kids. I must be doing something right. And therefore, I must continue to, you know, do the same things, right? Like, there's like empirical evidence in their heads. If you have this lens and you keep making smarter models and you're winning,
Starting point is 01:19:00 You have this lens that it's reinforcing your your worldview that like we must keep going and you know, we can't pull behind. Yeah, I mean, like I think a good analogy is like think about like the origins of crypto and like Bitcoin itself and Satoshi. Like one of the parts of the brilliant parts of Bitcoin was a recognition that like humans controlling a monetary system is always going to be corrupted. That's always going to be an issue. And so one of the brilliant parts was like, well, what if we put all those rules into math and
Starting point is 01:19:28 the humans don't control the system? they all have access, they can all use it, but they can't change it. And I think on the AI side, there is this belief that they can really create this thing and that they as humans will somehow be able to resist this power, that absolute power is somehow not going to corrupt them and that they will be able to just morally, you know, dish out everything that the world needs. And it's not recognizing that, like, you are relying on this human in the loop of this incredibly powerful system you're creating
Starting point is 01:19:59 to not basically be the the weakness point that falls over. Yeah. It's that, it's the meme from a rest of development, right? I was literally about to say, but it might delude themselves into thinking that like it won't happen to them, but like maybe our
Starting point is 01:20:15 time will be different or whatever. Yeah, maybe this time will be different. Yeah. Maybe this time will be different. Yeah. All right. Thank you very much, guys. I think one, we should probably just say this dumb laptop thing. I don't know Wait, did anyone here buy a laptop?
Starting point is 01:20:32 No, I was thankfully, I was sleep the whole time. We're gonna just skip. We're gonna skip this segment. We're just gonna skip this one. I just wanna say, rip to anyone listening who bought this. I assume it did not go well, but I don't actually know. It went to $300 and then down to like $1.
Starting point is 01:20:50 Went to Mute, apparently. It was just like full clipping out there. Like, it was like so good. At Gennie. every time. I know. All right. This is an amazing show. Thank you guys so much for joining us. And thank you for watching this episode of Uneasy Money. Remember what happens on chain never stays on chain. We will be back next week. Until then, do your own research before aping in, especially on laptop. Thanks, guys. Nothing you hear on Uneasy Money is financial advice. We're just three builders
Starting point is 01:21:20 talking about what's happening on chain. And we want you to always do your own research before aping in. you can find all out of exposures at unchaincrypto.com slash uneasy money.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.