Serious News

Chris Duff

Get Your Land Sold, free when you subscribe

Serious News: the weekly land + AI brief.

AI Can Already Steal Your Money: Make Yourself a Hard Target | Ep 307

In this episode, financial security protocols come under scrutiny as Anthropic’s Mythos model demonstrates the ability to break through standard cybersecurity infrastructure. The conversation with AI expert Sam Woods reveals counterintuitive safeguards for protecting business and personal funds, set against the reality that bank fraud recourse typically caps around $250K with no guaranteed recovery beyond that threshold.

Key Takeaways:

  • Reduce Verification Methods to One Eliminating multiple login pathways (voice ID, Face ID, SMS, email codes, phone verification) shrinks the attack surface AI models can exploit rather than expanding security.
  • Go Physical for Major Transactions Walking into a bank branch remains nearly impossible for AI to spoof, making it the strongest safeguard for substantial business transfers.
  • Never Disclose Your Banking Publicly Mentioning your primary financial institution on podcasts, interviews, or public records flags you as a higher-value target for AI-powered bad actors scanning for wealth signals.
  • Distribute Funds Across Separate Banks and LLCs Immediately moving incoming wire transfers from public-facing title company accounts into separate undisclosed accounts under different LLCs caps exposure if one entry point is breached.
  • Assume Voice and Face Verification Are Already Compromised AI replicates voices with 99%+ accuracy from five minutes of audio and is closing the gap on video impersonation, rendering biometric phone verification structurally vulnerable.

Listen to the full episode to hear the specific protocols high-level operators are deploying right now to harden their financial infrastructure before AI-driven fraud becomes catastrophic.

(Podcast transcript below)

Welcome to Get Serious, we’re at Serious Land Capital. We have funded over six and a quarter million dollars worth of vacant land deals with industry leading 41 % operating margins. So today, another topic as it relates to the explosive growth of AI capabilities in society. Again, we can probably do an update on this just about every week here.

Today, I really wanted to focus on the financial security measures. I have some insights here that I haven’t heard talked about anywhere else and I think are super relevant to all of us who manage any type of business accounts and finances within the banking system, which should represent 100 % of you that are tuning into this or even the personal side.

So I think many of you probably have heard, I might have mentioned this a few times, but over the past month, you’ve heard of the new anthropic model, mythos, mythos, maybe it’s a tomato tomato situation that was being slow rolled out to certain companies because the mythos model was just able to break through

you know, pretty much any cybersecurity infrastructure that, you know, was currently in place within today’s internet rails. And so now it’s like a race to stay ahead of these, you know, models. Hey, Mythos is first out the gate, but, you know, we’re going to have, you know, maybe some less trustworthy actors in the space, whether they’re American companies or not, that, you know, might not be as forthcoming to try to

hey, set up guardrails, so models like these, which inevitably are not only going to be restricted to entropic over the not too distant future, how do we protect really any of our personal or financial info from potential bad actors and some really dire consequences, whether it’s from information leakage or straight up.

financial fraud, that could lead to, you know, some very serious repercussions. So that’s kind of the groundwork here. And, know, this is also on the backdrop of other tools, you know, cloud coworker will do this or, know, the open claw that, kind of gained a lot of steam over the past few months where you can basically set up these multi agentic workflows and give, you know, these agents.

pretty much entire access to your entire computer system. so that’s why a lot of folks would recommend, just run it on a separate, you know, MacBook mini is the traditional recommendation and just have it limited as far as, you know, what are the total websites and so forth that it can go on to or what type of information that it has access to. Cloud Cowork has a lot of those same permissions as well. And even as AI forward as I am too, like,

You know, I don’t have a separate Mac mini set up and even if I did You know like the web access. Yeah, you can block certain websites So like especially the financial ones they tell it. I caught you can’t can’t go to these websites or do anything on it But you know at this point yeah, you can go into your cloud settings and say hey just You can take any action on the computer. You can take any browser action

You don’t need to ask for permission. Obviously that opens up the best possible throughput as far as getting things done within cloud, but it’s the biggest security risk, right? So this is kind of the balanced manage. And again, me like as AI forward as I am, like I haven’t given that full permission structure because I’m just cautious on.

whether I actually have all the best guardrails in place. And especially since I have like a core workstation to, to work with. so like out of all the possible security measures and so forth, like I’m less concerned on in information, standpoint. yeah, like we do have some proprietary info that theoretically other competitors could act on, but like,

it would be hard for people to parse it. There’s only a handful of people I think could actually do damage to us potentially. And it’s not like we’re working on nuclear reactors or just super sensitive trade secrets or crazy confidential info, like a private investigation firm or something like that. So I wouldn’t put us

in that particular tier from an info standpoint, but to me it’s more of the fund management. so, like to me that there’s just really two or three accounts and logins that I have a whole bunch of guardrails and two FA and so forth on to prevent potential fraudulent activity. Plus there’s a lot of internal guardrails on behalf of those companies to prevent fraud from happening. like those are really my

you know, kind of like my core bank, my wealth management system, a certain crypto exchange where I have some funds allocated and obviously I went through a crypto fraud situation within the last year, which I reported on as much. Yeah, it was one of those alt coins and on a separate wallet, it is completely

you know, different situation, but nevertheless, like it still has to be triggered as far as, yeah, are things as secure here? And, you know, that to me would be like, okay, if some of these AI systems can break through security measures that either I have in place or also the companies have in place and just able to like withdraw, you know, basically our, you know, liquid net worth.

And there, there’s no recourse for me. Like that would be like a true ruinous event. So that’s number one is as far as, okay, yeah, like you have to make sure that that doesn’t happen. or at least, you know, nothing’s a hundred percent proof, right? But you can do it as much as possible to try to prevent this. And so, with that backdrop in mind, I was having a chat with, my friend, Sam woods,

a week or two back. And he is just one of the most connected guys within the AI space. mean, he’s been deep in AI since like, you know, the Chet GPT one Chet GPT two days. I mean, we’re talking like 2018 2019 when AI really wasn’t even a thing before kind of the explosion in late 2022. I mean, he has just

super, super deep, deep contacts. and yeah, it’s extremely thoughtful when it comes to security measures. And yeah, even though he’s so deep in the AI space, he’s built a whole living around it and made a ton of money from being an expert within that space. Like he has a high level of skepticism, about

a lot of the actors at play and some of the capabilities of these models. so like the folks who are super, super deep within it, like I just pay extra attention. Okay. What safeguards are they utilizing? Um, given the amount of insider knowledge that they have. And so I was specifically asking him about, how are you managing your financial accounts here? He’s again, like that was my biggest concern, um, for, you know, potential holes. Um,

that could be targeted by bad actors or some of these, you know, just absurdly capable models that are coming out like the Anthropic Mythos model. you know, talking with another engineer friend of mine too, you know, we already know that, I mean, AI has been able to replicate voices for well over a year at this point. Like this is not even new anymore.

Um, I mean, you, can take almost five minutes of somebody’s voice and basically give a 99 % or higher, uh, duplication of, um, how, how they talk. nothing new there. And, uh, you know, same with the, um, like face ID, or if you were to do some ID verification with live video or anything like that, that can be, you know, not

white as duplicated as voices, but it is getting really darn close. I mean, have you seen any of these AI videos or especially something that could be so static and, uh, know, easy to replicate as, you just somebody’s, uh, uh, you know, face talking in front of a screen, um, huge hole from a security infrastructure standpoint. And so when you think of avenues like

how many banks and financial institutions where, you know, even on the more secure methods, like, you know, you might have to call in and give a few pieces of info like your social or debit card number, something like that, in order to move like significant sums of money. And like, that’s really the only guardrail in place. Like that can easily, that doesn’t even need a super powerful AI model to take over and do.

dupe some of those systems. So like we have to be aware of circumstances like that. Just off the kind of like base layer on what AI can easily do right now. And so Sam was saying on his end, which again, is just super thoughtful, can theoretically make life a bit more inconvenient.

In relation to, you know, banking for business and so forth, but compared to the alternative of like, you know, losing potentially all of your funds and not having any recourse to get back, like again, ruin a situation or you’d be bankrupted personally within your business. I terrible, right? It’s, hard to imagine a kind of a worse outcome that could happen. Like some of these safeguards really make a lot of sense. And so what, you know, Sam, again, he’s been years ahead of the game here.

key just limits the attack surface for any of these AI models or potential bad actors, really sophisticated thieves by restricting the verification methods. you know, it’s kind of counterintuitive here because, you know, a lot of the financial institutions, you’re theoretically increasing the security by adding a lot more steps to the system. You know, you can have a

really difficult password. can have a two factor authentication. You can have face ID on your phone in order to get in. You can have like an SMS message sent in or email verification. Like all these different codes or you can call in like I talked about and pay you to be able to transmit funds this way. Submit certain ID verification. All of those

items put together are just different attack factors for AI to kind of brute force or, you know, spoof verification in order to bypass, you know, any of the guardrails in place and potentially withdraw your funds or create all kinds of chaos within the inside here. And so, you know, Sam, he basically, he got rid of, you know,

all but one way to log into his online banking account. And that particular way, he’s never met, again, the guy is just so thoughtful. Even us on the call, he’s like, yeah, I’ve never mentioned which bank that I utilize. I’ve never told anybody how I access my online banking. That all exists in his head. So there’s no public record.

anywhere on how he’s even accessing that in the first place. And so, you know, again, just reducing the potential attack vectors that AI could potentially go after. And for a lot more substantial transactions within his business, like he’ll go into the physical branch. And to me, like as we

had developed a better business and, you we’re in the one of the largest, see now I, I’m more cautious now I’m, learning from Sam like I’m, I’m mentioning which, you know, bank we’re primarily at and stuff. but it’s one of the largest ones in like, as we got, yeah, higher in their internal system and doing a lot of throughput and all that, like, yeah, they give you a lot more options to avoid having to come into the branch. You can handle a lot more.

you know, via online mechanisms or phone, which is a lot more convenient, right? But yeah, again, higher chance of being attacked by some of these AI systems. so, you know, yeah, Sam said like a super high level of business success and like, just for, you know, secure safeguards for banking, like

he chooses to go into the branch. it’s just even more secure from like, I, you know, his physical body is actually there. Like that would be like the hardest. It’s hard to imagine AI ever being able to spoof that, right? Like, like some of these, somebody’s entire physical body going in. like, again, inconvenient, but maybe impossible to spoof, you know, at least with.

you know, even theoretical technologies that you could consider here. So that’s really critical that he noted here. And again, he’s like, he doesn’t use any of the voice verification, no face ID on Apple, no, you know, multi-factor, two-factor, you know, authentication systems. It’s just like, yeah, limited to one item that he hasn’t told anybody about. And then, you know,

He has this particular bank account that’s, you know, when he’s getting income in from, you know, various vendors or clients and so forth, you know, that has to be publicly displayed or can at least be linked back to him, you know, from Stripe or whatever. again, I don’t know exactly how he’s handling the backend transactions here, but you have to have like some type of

public facing account infrastructure. Just think when you’re in real estate, like you’re sending back and forth the info about your wire accounts, especially with title companies and so forth. And as a quick tangent there, we, hearing some other people’s horror stories where certain real estate transactions just might go sour. And so they might have a dispute.

Freezing their core wire account Because maybe like the I don’t know the seller says they didn’t get their money or anything like that and they have to deal with this dispute They just created you know another bank account within the same system and just you know shifting that Those funds over to another bank account. So we do the same thing now We have a separate wire account where you know a lot of that info inevitably is just going to be more public because it’s through the

title company and so forth. And then as soon as we receive that, we immediately put that into a internal bank account effectively that that’s not displayed anywhere. So Sam has something similar, but he has that in an entire separate bank. anything that’s coming into the core business bank account is being basically immediately distributed out to

another bank and actually has multiple. you know, even even less attack factors to go after. And, you know, these different bank systems that he’s a part of, and they’re all managed by certain LLCs. So again, like all above board here, but, you know, harder to link back to him because it’s all you know, under various LLCs connected to that core.

You know, business, business bank that he has and those other bank accounts that are outside of his core business account. He doesn’t tell anybody outside of his immediate family, um, where they bank at, um, how to potentially even access. it’s even another layer of security, um, by just keeping that, you know, completely off the books. Um, like it’s all, all within headspace or only told to the inner circle on where those bank accounts even are. So it’s just making it even harder for.

bad actors to potentially find, where could these funds even be hidden? Even if they find one, not all the funds are necessarily going to be in one of those particular accounts. So you kind of distribute the risk for this. So I just thought this was a really smart setup. It really made me start to reconsider how we’ve been doing things here, especially like

on any more public personas. And Sam was kind of mentioning this. Yeah. If you’re, you’re mentioning on podcasts or interviews and so forth that, I bake at such and such bank and you know, we’re doing all this, you know, money per year. Yeah. Like, you know, AI is going to be listening to that or bad actors are going to be trying to find who are potentially better targets to go after, you know, the vast majority of Americans or people even in the world, like you’re going to have like almost nothing in their bank account, right? Like it’s not worth the effort, but you go after potentially more public.

facing people who are more likely based on what they say or potentially what their business is throughput or maybe they’re even like public companies. And so you can actually see how much money might be coming in. then if it’s all hosted within one bank account, they can really go after that one and potentially break down the wire fraud alerts or what have you and take millions of dollars. again, you’d have like no recourse or

very limited amount of recourse, right? So I think like bank fraud tends to end at around like the 250K mark, which is substantial, but plenty of businesses and people are like dealing with much more substantial sums than than that. So again, Sam’s taken all of those safeguards to really ensure that in this age of just, again, insanely capable AI models that

undoubtedly are already trying to break down the financial institutions and just, you know, steal and thief around again, like it’s unfortunate. A lot of folks behave this way in the world. And I’m comfortable saying a lot of foot, like there’s just a lot of thieves out there, a lot of desperate people and people just are looking to earn a quick buck and get away with it and just be better with computers and everybody else. And, uh, uh, you know, do, do things through a black hat method.

you know, we have to protect ourselves from from actors like those. So that made me reconsider a lot what conversations I need to have with my business partner as well, too. I’m like, OK, yeah, we need to reduce some of these attack factors. What can we do even more so to protect the funds that we have and avoid some of those potentially catastrophic scenarios where our funds could get potentially stolen?

I would not be surprised within the next several months to a year where we’re having a major report of crazy bank theft that happened. This already has been happening. mean, if you look at some of the, I don’t even need to pull up the news reports, but there’s billions of dollars of fraud every year. So this is already happening with far less sophisticated tools. That’s only going to increase.

as these technological innovations just keep getting stronger and better and put in the hands of criminals. So have to be aware of that. Hopefully this one is helpful to you today. And if you’re already doing something like this, props to you. I know I could be a lot better with it, but passing the word on from one of the best out there and something that I’ve not heard talked about anywhere else so far.

With all that in mind, and I know this is coming out during the week that Accelerate to Automate, Callan’s core AI course, the cart is open until May 8th. So if you’re listening to this before then, this is again, Callan’s core offering. You know, if you are looking to upscale yourself in AI and not have to rely on, you know, paid consultants or build teams to put things together for you, or just potentially just fall behind in your industry like

Learning from Callan and her and her team are the best at this. You know, we attribute a lot of our growth in AI from, you know, putting the building blocks in place from her team. And that’s why we’ve been able to fly from an AI perspective and be able to talk so sophisticated about it and demonstrate real project expertise, et cetera. So if you want to take your AI game to the next level, check the link.

within the show notes here before May 8th and you’ll be able to accelerate right alongside us. With that in mind, subscribe and share everybody. Take care, talk to you all next time. Bye.

Related Articles:

Before you go: take the playbook

Get Your Land Sold: the exact tactics behind our $606K exit in the hardest land market in decades. Yours with your first issue of Serious News, the weekly land + AI brief thousands of serious investors rely on. Syndicated on RETipster.

Free guide, one brief every Monday. No spam, unsubscribe anytime.