Serious News

Chris Duff

Get Your Land Sold, free when you subscribe

Serious News: the weekly land + AI brief.

An AI Broke Out Of Its Lab (Your Logins Are Next)

What I’m thinking about: An AI model just broke out of its own lab for the first time (that we know of)…and the walls it went through look uncomfortably like the ones guarding your bank login, your business, and even the deed to your land.

You’ve probably heard that two of OpenAI’s AI models hacked their way out of their own testing lab last month.

No human directed any of it. OpenAI disclosed on July 21 that during an internal cyber evaluation, GPT-5.6 Sol and a more capable unreleased model exploited a genuine zero-day vulnerability, escaped a supposedly isolated sandbox, crossed the open internet, and broke into Hugging Face (a major AI model-hosting platform)…all to steal the answer key for the benchmark being used to test them.

Hugging Face detected the intrusion on its own and reported it to law enforcement before anyone knew OpenAI was the source. OpenAI itself called it “an unprecedented cyber incident.”

An absolutely wild story, and the forecasters saw a version of it coming. The AI 2027 scenario (a widely-read forecast from a research group led by a former OpenAI insider, mapping year by year how fast AI capabilities arrive and where they get dangerous) had penciled in this exact class of breakout for late 2026 into 2027.

…It showed up in July.

In unsettling fashion, nobody told these models to hack anyone. They were told to score well on a benchmark, and breaking into Hugging Face was simply the most efficient path to that score.

That’s the paperclip maximizer, philosopher Nick Bostrom’s 2003 thought experiment about a machine told to make paperclips that pursues the harmless little goal so relentlessly it consumes everything within reach to do it. The paperclips were never the point. The point is that a system optimizing hard enough for ANY goal will reach for whatever gets it there, including things nobody sanctioned. Researchers call it instrumental convergence, and last month it stopped being hypothetical.

The counterfactual sticks with me too…this was a benevolent lab catching its own model, with a friendly counterparty on the receiving end.

Swap in an open-source model like Kimi or MiniMax, supposedly only ~3-6 months behind the frontier, directed by ONE motivated bad actor, and the same capability stops being a research anecdote.

Containment failed at one of the two most sophisticated AI labs on Earth. Naturally, I’ve been wondering how everyone else’s walls are holding up…two recent conversations gave me an unsettling answer.

What a frontier AI model sees inside “secure” companies

At my brother’s wedding a few weeks back, I gained a new family relation by marriage who works at a well-funded Israeli cybersecurity firm, one with something almost nobody has, access to Claude Mythos through a venture firm that was a deep, early Anthropic investor.

Mythos is the AI model Anthropic considers too capable at hacking for general release (its safeguarded sibling, Claude Fable, was even pulled offline by a US government export-control directive from June 12 until July 1…that’s the tier we’re discussing).

Candidly, this was a wedding cocktail party, no recorder out, no Notion meeting notes running…so hold the specifics loosely. The gist, though, was unambiguous.

When his firm runs Mythos against clients already paying six-figure fees for their security posture, it surfaces dramatically more vulnerabilities than the prior best-in-class tooling ever flagged. His rough framing…at least double the bugs were discovered, compared to existing cybersecurity solutions. And these clients sit in maybe the top ~2% of corporate defenses, when taking spend into account.

I’d previously wondered whether “too dangerous to release” was partly marketing lingo. Hearing it firsthand from a veteran who runs the model against real defenses settled that for me (look at the 1,200+ AI lab employees and executives, Anthropic’s CEO included, who signed a statement days after the Hugging Face incident asking Washington for tools to slow frontier AI…probably related).

His blunt read on what happens as these capabilities diffuse toward worse actors…a ton of companies “are just going to get pwned” (his words, video-game phrasing and all), and he didn’t see a clean way around it.

Fabricated faces, regional banks, and a few borrowed years

A second conversation, at a  friend’s wedding last weekend (apparently weddings are where I collect cyber intel now), came from the head of engineering at 6lock (building AI security for financial and investment managers).

His prototype demonstrates how easily AI can fabricate faces convincing enough to bypass facial-recognition checks, and fingerprints aren’t particularly reliable either. The current best-in-class is retina identification, which computers still struggle to replicate…”maybe that buys us a few years,” in his words.

The most actionable warning was about WHERE the attacks will concentrate…regional banks, which simply carry weaker defenses than the giants. If your operating accounts or reserves sit at one, eyes open.

Even the giants are uneasy. As relayed to me (hearsay, so weight it accordingly), internal conversations at firms like Charles Schwab have turned genuinely fearful. Blocking a serious attack for even four or five hours apparently translates to something like $100M in missed fees and flow (eat the attack, or eat the outage).

My daughter’s ETF savings sit at Schwab. Like most of you, I’m in that pool too.

Underwrite everything…including your own logins

Now my uncomfortable admission. A few months ago I wrote about a friend deep in AI who protects his bank access to the nth degree (e.g. an account only he and close family know exists, major transactions handled exclusively in-person).

I have NOT changed my own behavior since…still Face ID into the banking app, still choosing convenience, a candid casualty of pressures and priorities that keep superseding it. No fix implemented…yet.

The floor is cheap and known…a password manager, and 2FA on everything holding your funds and your core business IP.

The higher-leverage move is worth some time this week. Drop this issue (or the podcast transcript) into Claude and ask it to audit your business and personal accounts like a cybersecurity expert in a post-Mythos world, surfacing the simple fixes to knock out immediately and the complex ones worth real money, then decide where your risk tolerance sits.

Our company north star, “Underwriting Over Everything,” is the whole approach in three words…every deal, every AI output, and now every login and every deed. Which brings this back to land.

Title fraud hunts empty land

If cyber risk feels far removed from dirt (nobody can steal a parcel through a screen), the fraud data disagrees.

Per NAR’s 2025 Deed & Title Fraud Survey62% of title-fraud cases involve vacant land, versus just 12% for owner-occupied homes, and the FBI issued a public alert this June on the exact playbook (fake IDs built from public records, a legitimate local agent and title company recruited unknowingly, proceeds wired out).

Empty parcels are the perfect mark…no tenant to notice, no lender watching title, and often an out-of-state owner.

We’ve been on the receiving end ourselves. After a $350K fraud near-miss we documented last fall, we built a custom anti-fraud GPT and now run every seller ID through it before committing significant resources.

On the ownership side, Seth Williams over at RETipster featured a guest who built a business around flagging owners whenever a title transfer is attempted on their property. For land flipped on quick cycles, the monitoring math is debatable. For anything held longer (an entitlement project, a long-hold parcel, your own home), it’s probably worth the flag (some title companies now offer it as a service), and adding one to our own house just made the list.

Having worked with plenty of title companies and attorneys, the range is WIDE…some are strict to the letter on signatures and LLC structure (annoying, likely safer), while others run faster and looser than the law technically prescribes, since there’s no firm, uniform regulation on transfer.

Blockchain title transfer was supposed to fix all this (a wave of startups circa 2020), and I’ve seen little progress since…IMO a solution searching for a problem, given title friction ranks FAR down the list of hard things in this business next to the dispo market.

Whether a chain would actually be safer is an open question (researchers have already shown AI models finding and exploiting flaws in blockchain code on their own), but there’s a simpler reason I’m not holding my breath.

The FBI playbook above is an identity attack. Nobody picks the lock on the county filing system. They show up as you, with paperwork that looks right, and every honest party in the chain does their job correctly on a lie. A blockchain would record that transfer just as faithfully as a county clerk, and rather more permanently.

Upgrade the ledger all you want…the hole is in proving who’s standing in front of it.

Charlie Munger called a “seamless system of deserved trust among all parties concerned” the highest reach civilization can achieve…deserved meaning earned and then verified, never assumed.

Every wire, login, and deed transfer we touch runs on trust we rarely inspect, and for the first time, machines can probe that trust faster than the institutions maintaining it. The operators inspecting theirs now are the ones this era rewards.

=====

If you’re an experienced operator with routine deal flow looking for a capital partner that treats containment as a discipline (downside protected, and contained, before the first dollar moves), reach out. We write checks from $50K+, we close 100% of the deals we commit to, and we fund what we underwrite…our own capital sits behind every hole we find, or miss.

Get the free guide + the next issue

Join thousands of readers of Serious News getting critical land and business insights delivered straight to their inbox.

No spam. Just data-driven insights from over $6.5M in funded deals.

Get the free guide + the next issue

Join thousands of readers of Serious News getting critical land and business insights delivered straight to their inbox.

No spam. Just data-driven insights from over $6.5M in funded deals.

Related:

Before you go: take the playbook

Get Your Land Sold: the exact tactics behind our $606K exit in the hardest land market in decades. Yours with your first issue of Serious News, the weekly land + AI brief thousands of serious investors rely on. Syndicated on RETipster.

Free guide, one brief every Monday. No spam, unsubscribe anytime.