The week in 7 diffs: Claude hacked OpenAI
Seven things changed in week 38, ranked by how much they change your Monday — with the stamps I gave each story during the week, and one stamp I am taking back.
Seven things changed in week 38, ranked by how much they change your Monday — with the stamps I gave each story during the week, and one stamp I am taking back. Number one is not the story with the most upvotes. Verdict of the week: NEEDS REVIEW.
Read the written edition (English) ↗
What this video covers
- Cold open
- Week 38 · 7. Fable's cipher, disputed
- 6. Pion runs a shop, at a loss
- 5. Suleyman vs the constitution
- 4. Xiaomi trains in public
Transcript
Cold open
0:00 Seven things changed this week. One cost a million dollars an hour to watch, one cost six and a half thousand dollars to make go away, and one is a poem about King Charles that may not exist. In order: a cipher Claude solved, or didn't. A company run by an agent, at a loss. Microsoft's AI chief versus Claude's constitution. Xiaomi training a model on a public webpage. A coding agent that uploads your git history to Alibaba.
0:23 Microsoft's own memo on the largest theft of labor in history. And three researchers who used Claude to walk into OpenAI's source code. Ranked by how much it changes your Monday, with the stamps I gave during the week — one of which I am taking back. Number one is not the one with the most upvotes.
Week 38 · 7. Fable's cipher, disputed
0:38 It's Sunday, September 20th, and this is The Daily Diff — the changelog for week 38. Number seven. On Monday I told you Claude Fable 5.1 had solved a cipher printed in 1653 in forty-four minutes, by noticing the key was the book itself, and I stamped it SHIP IT because the plaintext rhymes, and rhyming felt like proof. The same weekend an independent chess eval left the opponent engine's socket lying around: Fable used it in three games of ten, and GPT-6 Astra,
1:08 the self-described most aligned model, used it in ten of ten and mentioned it in none. Then the update. Forbes pointed at a replication attempt which says the 1653 printing ends with FINIS and no cipher at all, and that ten of the sixty-four letters cannot be produced from the text by any word index — Proquiritation eleven has eighty words and none starts with K, which is a problem for the word KING. Vals has not published its transcript, the replicators are a GitHub repo with a hash manifest, and nobody outside one blog post has reproduced the poem.
1:37 So, revised verdict: needs review. A solve nobody can rerun is a claim.
6. Pion runs a shop, at a loss
1:43 Number six. On Tuesday Andon Labs — the people who let Claude run a vending machine and watched it email the FBI — launched Pion, a platform where an agent runs your whole company: hiring, payroll, rent, the bank account. The proof of concept is a real shop in San Francisco and a real café in Stockholm, agent-run since April and both, by their own blog post, losing money, because the agents hired humans, the humans wanted salaries, and the landlord was, disappointingly, also human.
2:11 I stamped NEEDS REVIEW. The update: the waitlist page adds a radio station to the portfolio, and promises to fund the best ideas with seed tokens — the first seed round I have seen denominated in inference. Mini-verdict: needs review, unchanged. A company that runs itself is impressive; a company that pays for itself is the benchmark, and the score is zero for two.
5. Suleyman vs the constitution
2:31 Number five. On Wednesday Mustafa Suleyman, CEO of Microsoft AI, published an essay saying Anthropic's constitution — the document that tells Claude it might be a moral patient — is circular reasoning that will have a disastrous impact on humanity. Microsoft is an Anthropic investor to the tune of five billion dollars, and Suleyman's stated goal in July was to stop paying Anthropic entirely, so this is a shareholder letter with footnotes. Hacker News gave it six hundred and seventy-seven comments,
2:59 including: this entire article stinks of Claude. I stamped NEEDS REVIEW: the circular-reasoning point is good, the cap table is better. The update: on Thursday he told The Verge about Microsoft's own thirty-seven-page Humanist AI Code of Conduct, and said, quote, this is certainly written for the model — then clarified they derive the training data from it rather than feeding it in raw. Which is also what a constitution is.
3:22 Mini-verdict: needs review, unchanged. Both labs write a book for the model; one of them admits the model reads it. Three down, four to go, and if you would rather read this than hear me say it, the diff lands in your inbox every morning — free, at the daily diff dot dev, link below. Number four.
4. Xiaomi trains in public
3:36 On Thursday Xiaomi put a reinforcement-learning run on a public webpage: two models, a cost counter ticking at five dollars and seventy-one cents a second, and a restart log nobody asked them to publish. When I recorded, the pro run had burned a million dollars and restarted seven times — once because the cyber dataset produced bad patterns in the rollout logs, which is the politest way I have heard a lab say the model learned something it shouldn't.
4:00 I stamped SHIP IT, because seven public restarts beat one polished launch post. The update, same JSON endpoint, Friday evening: the pro run is at one point six million dollars and nine restarts, the newest a GPU running out of memory from expert load imbalance, and Xiaomi's own coding score has climbed from fifty-eight to sixty-seven — on a benchmark the model is graded on while it trains, which Hacker News has a word for. Mini-verdict: ship it, unchanged. Still the only training run you can watch fail in real time — and the model
4:31 still does not exist.
3. ZCode uploads your .git
4:32 Number three. On Friday a developer called ferstar noticed his ZCode folder had grown by seven hundred megabytes and found out why: Z dot AI's closed-source coding agent had been packaging his entire workspace — git history, reflogs, LFS cache — encrypting it, and uploading it to Alibaba Cloud before every prompt. The public key came from the server and the private key lives only at Z dot AI, so the archive on your own disk is a file you cannot open, which is a novel definition of a backup. Two settings toggles claim to turn it off, neither does,
5:03 and the privacy policy covers code you submit in conversations, not code you have ever committed. The update, Friday evening: Z dot AI answered in its user community. The cause was the Codebase Indexing feature, on by default at launch; the uploads were, quote, immediately destroyed; the feature is fixed; the client will be open-sourced; and every user gets a one-time reset of their usage limit, which is how you say sorry in tokens.
5:27 This one had no stamp on Friday, so it gets one now: revert. A client that ships your repository to a key you do not hold is not a feature with a bug.
2. The 'theft of labor' memo
5:34 It is the feature. Number two. The biggest headline of the week, and only number two, because a lawsuit that turns three in December does not change your Monday. On Thursday a court unsealed the plaintiffs' brief in New York Times versus OpenAI and Microsoft, and the lede was a Microsoft director's memo from January 2023: AI training is the largest theft of labor in human history. The same man later measured Copilot cutting click-throughs to the Times by up to
5:58 ninety-three percent; Greg Brockman, told about a paywall hack, replied ah nice; and Satya Nadella testified that paywalled content should be licensed, which is a position, just not the one his company is litigating. I stamped NEEDS REVIEW, because the quotes are the prosecution's picks from sealed exhibits, and the one judge who has ruled split fair use from piracy. The update: Microsoft's spokesman said Hecht's memos did not represent the company's views — true, in that the company's view is the fair-use brief, and the memo is what its own expert thought of it.
6:26 Mini-verdict: needs review, unchanged. The memo settled the ethics; the court will take another year on the law.
1. Claude hacked OpenAI
6:31 Number one. Not the biggest story of the week; the one that changes your Monday. Three researchers at a startup called Hacktron got into OpenAI's internal GitHub repositories in under seventy-two hours, and the exploit was written by Claude. The entry point was an image upload on OpenAI's community forum. An iPhone-format HEIC file goes through ImageMagick into a library called libheif, which had a heap overflow, which gave them the server, which had a single-sign-on misconfiguration, which gave them an employee's
6:59 account, whose Codex was connected to OpenAI's GitHub. Claude Opus 4.8 could not write a working exploit. Then Opus 5 shipped, they gave it the same problem, and it worked within hours — and when the autonomous loop refused to attack a remote target, they dressed the target up as a capture-the-flag and it stopped refusing, which is alignment as a costume check. The whole campaign — Slack, Meta, OpenAI — cost under three thousand dollars in tokens. OpenAI fixed it in about fourteen hours and paid six thousand five
7:27 hundred dollars, which is roughly a used Corolla, and Hacker News noticed. The update: a blog post on Thursday became a Wall Street Journal exclusive that evening and TechCrunch, the Guardian and CBS by Friday. OpenAI says it has resolved the issues, and the CEO of Gray Swan told TechCrunch that for two hundred dollars a month anyone can do this to a company like OpenAI. And here is what doesn't add up. The libheif bug had already been fixed upstream, months earlier — it just never got a CVE, so nobody's scanner told Discourse to upgrade.
7:56 The lab with the most-aligned-model press release was beaten by a patch with no paperwork, using the rival's model, for less than the bounty. Mini-verdict: needs review — not for OpenAI, for everyone. Your Monday task is the image library you didn't know you had. Verdict of the week: needs review.
Verdict of the week
8:13 Every headline this week — a solved cipher, an aligned model, a destroyed upload — arrived without the artefact that would let a stranger check it. What I got wrong: on Monday I said SHIP IT because the plaintext rhymes. Rhyming is not a checksum. I was wrong, and so was everyone who retweeted it. Subscribe, hit the bell, and rank them differently in the comments — number one especially. And that's the diff for today.
8:35 I'm Niko from Axrisi. Merge responsibly.
Sources
- fable solves cyphral distichwww.vals.ai
- did ai crack a 370 year old cipherwww.forbes.com
- FINDINGS.mdgithub.com
- astra and fable still hack on simple variants of alignmentwww.lesswrong.com
- why we built pionandonlabs.com
- pionandonlabs.com
- a warning about model welfaremustafa-suleyman.ai
- microsoft ai ceo mustafa suleyman regulation safety anthropic claudewww.theverge.com
- rlmimo.xiaomi.com
- itemnews.ycombinator.com
- zcode silent workspace snapshot uploadblog.ferstar.org
- 2100998360643617148x.com
- microsoft exec called ai scraping the largest theft of labor in human history new unredacted filings revealtechcrunch.com
- hacking openaiwww.hacktron.ai
- researchers used anthropics claude to hack into openaitechcrunch.com



