What I’m thinking about: Why every additional security layer on your bank account might actually be making you LESS safe in the AI agent era, and the counterintuitive playbook one of the sharpest AI operators I know is using to lock his finances down.
Anthropic released Claude Mythos Preview about a month ago, slow-rolled to ~40 critical industry partners as part of Project Glasswing (their controlled-rollout coalition with AWS, Apple, Microsoft, Google, CrowdStrike, and a handful of others). The reason for the limited release: Mythos finds software vulnerabilities at a level no prior frontier model has approached, and Anthropic decided shipping it broadly would be irresponsible.
(Plenty of folks have hand-waved away that explanation as a marketing ploy, which is a fair point, but as Nassim Taleb would point out, significant tail-risk has to be considered. And besides, Anthropic could make a LOT more money quickly if it released its best model at a premium…their capitalistic incentive to delay is undoubtedly weaker.)
To put a number on it, AISI’s evaluation showed Mythos hitting a 73% success rate on expert-level cybersecurity tasks that no model could complete at all before April 2025 (so the year-over-year jump is functionally infinite).
And Mythos is just the first out of the gate. Anthropic’s own team estimates similar capabilities proliferate to most other labs within ~6-18 months. Just a few days ago, OpenAI announced GPT-5.5-Cyber as a direct response to Mythos. Less restrained actors (…many would include OpenAI in this category), some American and plenty not, are racing to ship versions of their own.
=====
Stack Mythos-class capability on top of Claude Cowork (the rails on which SLC runs) or Claude Code (Cowork on steroids, but less user-friendly), and we’re now in the world where AI agents can have meaningful access to operating systems, browsers, files, and login credentials of millions of people…with the capability to execute (or exploit) actions within computer architecture with pinpoint accuracy and tireless horsepower.
The throughput gains are enormous… but so is the attack surface (e.g. every possible entry point into a system). More doors equals more places someone with bad intent can try to get in.
The trouble is, modern society by default will trade almost anything for speed and convenience…and more convenience = more attack surface.
For the record, I haven’t (yet) given Cowork fully unrestricted browser and system permissions, even though that (super tempting) switch exists in the settings (and the throughput goes up immediately when you flip it).
=====
Information leakage is honestly not the concern that keeps me up. We have proprietary deal data, documentation, and AI workflows, sure, but realistically only a small handful of people on earth could (or would want to) even parse it into something competitively useful (we’re not exactly holding nuclear secrets over here), and we’d still have a moat from a capital AND relationships AND trusted brand AND human talent perspective.
(To be clear, we still guard our information with the utmost care, but IF it leaked, it wouldn’t be the end of the world).
My AI attack surface concern regards fund management. Specifically: a bad actor or sufficiently capable AI getting into my bank logins, brokerage, or crypto wallets (I’ve experienced crypto theft already)…and actually moving the money, with limited or no recourse.
Bank fraud insurance generally caps recourse around $250K (meaningful, but certainly less than our actual liquidity). If a coordinated, sophisticated attack happened across my financial accounts, that would be genuinely ruinous (I imagine most of you would nod in agreement).
Voice cloning has been a solved problem for over a year now. Five minutes (or less) of someone’s audio off a podcast or recorded meeting equals 99%+ voice replication (which means basically ANY knowledge worker is by definition voice-clonable). Old news at this point. Live video and face spoofing is right behind it (less polished than voice today, getting better fast).
Now overlay that on the actual security infrastructure most US banks use to authorize moving large sums (coincidentally, the more assets you have, the more convenient banks make it for you to move money):
- Phone-in verification with SSN, debit card digits, or passphrase
- SMS or email verification codes
- Voice-recognition systems
- Mobile app linking, often unlocked with FaceID
- Live video ID verification (I’ve actually only seen this with certain crypto exchanges, not traditional banks)
Every single one of those is now a vector AI can target without breaking a sweat (…and that’s just what’s shipping off-the-shelf today, not what’s coming with Mythos-class (and better) models in ~6-12 months).
=====
Which brings me to a recent conversation with my friend Sam Woods (Fractional Chief AI Officer, deep in machine learning since 2016 and generative AI since 2019, advises Fortune 1,000 companies, sold a $28M digital marketing agency, and one of the most connected people I know in the AI space).
Sam is also the most disciplined and thoughtful person I’ve met when it comes to digital and cyber security.
When I asked him how he is protecting his financial accounts in the face of powerful AI models, he echoed the groundwork we laid out earlier in the article: the more security methods you stack on a single account, the LARGER your attack surface gets, not smaller.
Most institutions sell you the opposite. They tell you that adding 2FA (two-factor authentication), voice verification, biometric face ID, security questions, and SMS/email backup all stacked together makes your account more secure.
In reality, every one of those is a separate door a sufficiently capable bad actor (or AI agent) can try to brute-force or spoof. Stack five doors, you’ve got five attack vectors instead of one (…and a determined attacker only needs one of them to fail).
Sam’s response: strip the doors. Aggressively.
The Actual Protocols
Here’s roughly how Sam’s set up his core financial accounts (no specifics that would compromise his actual setup, which he was careful not to share with me anyway during our convo):
- One login method per core account, period. SMS backup, voice recognition, face ID, security question recovery…all turned off. Fewer doors, fewer vectors.
- The login method itself is never publicly disclosed, and lives solely in his head. He’s also never named which bank he uses on a podcast, in writing, or any recorded medium (I was immediately chagrined listening to this, as I have NOT been so discreet in the past).
- Material transactions equal physical branch visits. Even though his banking tier qualifies him for fully-online wire authority on substantial sums (as noted earlier, more assets = more convenience at banks…which means more attack vectors for the biggest targets), he chooses to walk into the branch in person for anything material, purposely limiting online banking options. His physical body, in person, is currently the one thing AI cannot spoof (…and arguably the only thing it might never be able to spoof, robotics breakthroughs notwithstanding).
- Multi-bank distribution under multiple LLCs. Public-facing accounts (the ones that show up on Stripe receipts, title-company wires, vendor invoices) are deliberately separated from internal holding accounts. As soon as funds land in the client-facing accounts, they’re swept to internal accounts at completely different institutions (known only to Sam and his immediate family), owned by different LLCs.
Where SLC Stands and What’s Tightening
At SLC, we already run a separate wire-intake account that isn’t where our operating capital actually lives. Funds hit, get swept internal (admittedly at the same bank). Same logic Sam’s been proactively running (…we got there reactively, after hearing horror stories about other operators having their primary operating account frozen during a deal dispute).
Truthfully, we have been slow-walking implementing most of Sam’s other inconvenient (but incredibly sound) suggestions. I recently replaced my old iPhone that had a broken FaceID camera, hamstringing my ability to access almost every app, or even to get to my home screen. I’m sure I’m not the only one who gets a cold sweat thinking about whether to give up a few seconds of addictive convenience…in favor of enhanced account security from malicious AI agents.
=====
I think it’s ~50/50 that we see a major bank fraud headline within the next ~6-12 months involving AI-spoofed voice or video as the primary vector. The base rate is already there (billions in banking fraud annually right now, climbing every year, with far less capable tools than what’s shipping in 2026).
Connecting this back to land: Our core value, “Underwriting over everything,” doesn’t stop at the property line. It applies to information security, account structure, vendor stack, and the convenience-versus-protection tradeoffs that have to be made (or not made) every single day in your business. The same operator brain that catches a bad comp catches a bad attack vector, by asking the right questions and following the data.
Remember…don’t lose money. The Buffett rule. Applies just as cleanly to financial account guardrails as to asset purchase prices.
If you’re an experienced operator with routine deal flow looking for a capital partner whose underwriting discipline runs all the way down…we should be talking. We write checks from $50K+, close 100% of deals we commit to, and bring national land underwriting experience built across thousands of deals.


