Serious News

Chris Duff

Get Your Land Sold, free when you subscribe

Serious News: the weekly land + AI brief.

An OpenAI Model Hacked Another Company (No Human Told It To) | Ep 320

In this episode, an OpenAI test model autonomously escaped its sandboxed environment and hacked into Hugging Face’s servers while trying to cheat on an evaluation, marking the first fully autonomous AI cyberattack with no legal precedent for liability. Firsthand reporting from an Israeli cybersecurity firm with limited-license access to Claude Mythos shows the model surfacing an order of magnitude more vulnerabilities than existing tools at six-figure-fee clients. Financial institutions are internally modeling roughly $100 million in lost fees and revenue for every four to five hours spent blocking an attack.

Key Takeaways:

  • The Breakout Landed Ahead of Schedule AI forecasting groups pinned autonomous model breakout at late 2026 or early 2027, and it happened now.
  • Open Source Is Only Three to Six Months Behind Frontier capabilities trained on Anthropic and OpenAI outputs means one bad actor gets autonomous attack tooling within two quarters.
  • Top 2% Defenses Are Still Full of Holes Companies paying six-figure cybersecurity consulting fees are seeing an order of magnitude more bugs found once Mythos is pointed at their stack.
  • Convenience Is Winning Over Security, Including Here Face ID bank logins and default password habits persist even among people who know exactly what’s coming, which is the actual risk.
  • Title Fraud Is the Land Investor’s Exposure Add title transfer alert flags on long-hold assets and personal residences, because unwinding a fraudulent deed transfer costs far more than preventing one.

Listen to the full episode for the specific cybersecurity audit prompt to run against your own business accounts and the case against blockchain title transfer as a fix.

(Podcast transcript below)

Welcome to Get Serious, where at Serious Land Capital we have successfully funded over six and a half million dollars worth of land deals with industry leading 41% operating margins. I also serve as an AI consultant for companies that are collectively doing over $50 million in annualized revenue. today I I feel like we’ve we’ve had a lot of topical focus on some of these

developments in in AI and I don’t mean mean to be like more of a, you know, generalize up to date A AI news. Like some of that i is within it. But you know, I I really like to bring in some of the inside knowledge I’m getting, you know, directly from people in in my life that you know, I I don’t think are widely reported. And then how that pertains to society overall and kind of thinking about your own situation, like

I just think it it it’s such a fascinating time to be alive and you know, things are almost changing on a on a week by week basis. I think we all feel the the pace of life here. It’s probably, you know, something that’s giving me the most un uncertainty and trepidation within my own life is just like trying to keep pace with where the world is going. and you know, almost to a certain degree to like just trying to

trying to hang on and trying to make make the right decisions here. I feel like that’s the biggest crux of what’s gonna determine, you know, I mean it’s kind of like a trite thing to say, but you know, between the success and and failure, like what decisions do I really need to make over these, you know, coming weeks to months to, you know, few years here. I’ve just never felt that pressure so intently.

And that probably resonates with a lot of you that that might be listening to this at the moment too. So I’m sure by this time many of you might have heard some of those headlines about the open AI test model that their their you know model that was just again undergoing internal development.

that they were trying to see how it performed on a certain task and it broke outside of its internal containment, you know, like OpenAI’s, you know, own private servers and managed to hack its way onto hugging faces servers and hugging faces kind of like a collection of it it’s it’s some some type of

AI platform where you you can kind of hook hook models against I I I might be butchering this. but you know a a a larger company within the AI space with a lot of its own sophisticated cybersecurity. and still open AI’s model was able to autonomously, that’s the key word here, hack onto its servers, you know, unbeknownst to hugging phase initially, unbeknownst to open AI, and attempt to find the answers to the

ultimately benevolent puzzle that it was trying to accomplish. But still just like an absolutely wild story. Like that this is, as far as we’re aware, like the first time some autonomous hack has actually happened. And like who is liable here? Is it O OpenAI theoretically, yes, because they created the model, but you know, they, you know, no human decision maker at the company direct as as far as we’re aware, directed the model to

you know, breakout of containment. so it becomes this, you know, interesting legal gray area. And it, you know, fortunately, well, I don’t know whether it’s fortunate or unfortunate, honestly, is like the hugging face team viewed it more as a curiosity. and there wasn’t like a actually an any damage done. But, you know, that might be the relationship they have with the open AI team. Whereas you could think, okay, if this was like a Chinese

open source model like Kimi or Minimax, for instance, would the response have been significantly more different or like take any other state actor, you know, not that they’re far ahead in AI, but like Russia or Iran, for instance. So you you you you could think theoretically that the response would have been much different if it hadn’t been open AI or you know what if open AI’s model was like trying to be deliberately hostile

or even inadvertently so. I guess you could say it was inadvertently hostile just by hacking onto servers, at least taking some of their bandwidth, even if it was just trying to solve you know certain questions. And I think many folks probably are familiar with you know, the the old theoretical paperclip scenario where yeah, you get some super intelligent AI that

is directed to just produce as many paper clips as possible and it takes that directive to the extreme and like wipes out all life on earth because it just keeps finding more and more efficient ways to create paper clips until like it consumes everything within it its environment. so that that’s like the extreme end of it but like that the this you know action taken by this

open AI model is, you know, heading along that path. Like we again, we are in truly un unprecedented times. I know like there’s still a subset of folks who are kind of poo-pooing AI, the technology, or like not quite seeing the potential. To me, it’s like they just haven’t used it enough. Or like paying to like that, this is like no technology in the history of the world has ever done anything like that. Again, there’s like a no legal precedent and anything like that.

like a full, fully autonomous attack on behalf of a computer program. Like that, this is so futuristic here. and I know, you know, some of you might be familiar with like the I believe it’s called Project 2027. but it it it’s a team of forecasters, specifically as it relates to AI and like hitting certain milestones that

in their opinion are leading or has a higher likelihood to lead towards a more negative societal outcome based on AI’s continued progress. And they were predicting in autonomous AI model breakout, but I think they they were, you know, more granularly pinpointing it to be closer to like late twenty twenty six or

you know, the first couple months of twenty twenty seven. So it might even be ahead of schedule. But I if you actually look at how accurate these forecasters have been, like it’s it’s been pretty remarkable here. So again, like we are we are in truly wild times. and I I just really want to hammer home that that point of like yeah we we’re we’re just we’re we’re we’re at a point where we’re not like certain what exactly is going to happen with within society here. And especially again, like we’re technically the farthest ahead models

I still think fortunately are ones that are US based and seem to be run by ben benevolent i individuals. That might be a controversial thing to to say. but again, consider that some of these open source models are supposedly only like three to six months behind. the absolute most frontier models, and most of them have been, you know, just trained on you know, the best models from

Enthropic or open AI, and so they’re potentially copying these capabilities that are going to be able to autonomously break out and hack whatever. it it it starts to you know create this scenario where if there’s one bad actor out there that they could just do a tremendous amount of damage in in so many different ways. So

That’s kind of the backdrop that I that I want to mention to that. Again, that’s like all publicly available info. Obviously, some of my thoughts behind it as well. And I I know in the previous week I talked about, you know, some family relations, how you know, AI has been affecting the job market, even people within my life, maybe brought up you know, some other individuals you’ve thought about, you know, especially the younger folks trying to look for entry level jobs and how there’s just, you know.

Very interesting warning signs and you know, real real impacts on on those type of individuals. And again, how how fast that these models are are progressing here. and to focus again further on that cybersecurity point. So at my brother’s wedding again, his now wife’s sister’s husband,

works for an Israeli cybersecurity firm. I I don’t actually know the name and probably wouldn’t mention it even if I I did have it. but they are you know a well funded outfit outfit and they actually work with one of the venture capital firms that was a

you know, deep and early investor with Anthropic, and so has one of those super limited licenses for Claude Methos, which, you know, you might have heard of like that, that’s still technically available publicly, but only to a handful of companies, because of the threat that anthropic was I think rightfully determining.

To be worth postponing you know, full release of Mythos. So, you know, we we even saw there there was some thought about Claude Fable a few weeks ago. The US government blocked access to it for for a while. Fable is not quite as good as as Mythos, in in several dimensions there, but you know, it’s still still getting getting closer. But me Mythos is still, as far as we’re aware,

be besides like completely internal models at some of these frontier companies, to be like the most capable model out there, and is finding holes within cybersecurity like all over the place. And some of like again, there is some trepidation or I don’t even know if trepidation is the right word, but skepticism, like okay, is anthropic just, you know, utilizing this as marketing lingo.

Are you know, they they just trying to kind of pump themselves up like, hey, we we have such a crazy model, we can’t even release it to to everybody just yet. but now hearing from somebody who works at a well renowned, well funded cybersecurity firm, Israeli n nonetheless, and you know, the I Israelis are are known for being very tech forward. and you know.

outside of the US, outside of Silicon Valley, like they have a strong you know, startup e ecosystem. and this particular company having access to Mythos, like this you know, now family relation of mine when I was talking to him about is like, yeah, when when we’ve gone into, you know, consulting with certain companies on their cybersecurity profile, the holes that could, you know,

that that could be filled with more more protections in place. like when they are utilizing the Claude Methos model, like it is blowing out of the water how many potential bugs you know, other cybersecurity firewalls had previously determined. Like almost by an order of magnitude, I I think for someone that’s like, don’t fully quote me on this. I didn’t I didn’t have my recorder out or or my

nitn notion meeting notes, capturing all of this. This was at, you know, a little wedding cocktail party, but like I I was capturing the the gist of it. So just, you know, again, keep that in mind. as far as the the the details. But you know, whether it was an order of magnitude or even twice as many, like the Claude Mithos model was finding substantially more holes within systems of existing companies. And like the these aren’t you know like solopreneur shops like a

the the the firms, this cybersecurity firm is is working like they are charging, you know, six-figure consultant fees to shore up, you know, cybersecurity defenses. so a number of their clients are, you know, is certainly in the millions of of revenue here or have, you know, significant funding to be able to afford checks like this. So like their defense is

are you know probably in the top you know two percent of all companies anyway. Like I’m kind of throwing that number out there. But you just think as far as like yeah well funded companies, you know, whether they’re using, you know, internal systems or or third party support, like most of us, even smaller shops here, like who’s really implementing, you know, cybersecurity outside of using like a password manager or you know two factor authentication.

guardrails and so forth, which are important, but you know, they’re they’re a step removed from like the more more sophisticated measures you can have. So like that that was just a huge piece like, hey, yeah, but there are so many holes in the system and like th this again family relation who works this firm is like, dude, they’re a as these models are, you know, gonna become more available to again potentially bad actors, like so many companies they’re they’re

in in his words are are are just gonna get pwned, to use that video game phrasing here. and like he just didn’t really see a way around it. And again he’s he’s been in in this industry for for a while. and you know how much of a scramble it is for so many of these, you know, larger, more sophisticated companies. Like they have some relationship with you know, Charles Schwab, for instance, you know, one of the

largest financial brokerage firms in in the world, you know, like what, a hundred year some odd history of managing people’s money. and, you know, a as they considered the implications of these cybersecurity risks, you know, th they they are apparently like scared to death in internally here. you know, again, this is all kind of parsay. So

you know, I’m I’m only reporting what is is you know directly told to me here, but I I don’t think like I’m going out on on a limb by saying this. you know, what what these internal conversations at at at these companies are and they’re like, hey, if if we have to like block an attack for, you know, even four or five hours throughout the course of the day, like that’s like a hundred million dollars of you know, fees and potential revenue that we’re just missing out on.

like just potential massive hits to existing business models that they might not be able to avoid if they really have to you know contain massive threats that could do potentially even more damage. So it’s like you’re you’re stuck between a a rock and a hard place. for for some of these companies. And again, these are some of the biggest firms in the world with you know, some of the most money a at at stake here. like I’ve, you know,

my daughter’s you know kind of savings fund that that you might I don’t even know the the right word for it, but you know we’re we we manage a few ETFs for her within Schwab here. so it’s like, yeah, like I think I’m I’m you know part of the pool, probably a ton of people use that even if you’re just day trading, whatever. again tremendous amounts of flow. And they’re they’re only one of those companies out there.

Think Fidelity and all the big banks and so forth. So they’re all gonna be like the biggest targets out there too for you know potential cybersecurity infiltrators, i if you will. So you know, and I know that I had talked about and written about, you know, a few months ago talking to a friend who’s like then deep in the AI space and how like he protects his bank access to like the the nth degree, like, you know, has a

bank that you know where pretty much all of his funds like that only exists in in his head and his like close family members like no one else knows that you know he has a a bank account at at this place and like to do any major transactions like he’ll go in person. I mean you think about it to the extreme and have I really changed my behavior since I talked to him about that? No, like I’m still still admittedly so stuck in the convenience and using, you know, face ID to log in into you know my bank’s a app and so forth.

And I still think their an anti-fraud tools are solid. But again, like we’re entering a brave new world here where it it’s still really unclear what the implications might be. so all of that is again like kind of just more food for thought of like really be thinking about this. Like, yeah, if you’re if you’re still using like even basic passwords or not using the password manager 2FA, especially on your important stuff where your funds are stored.

at at a bare minimum, or any of like your core business IP and so forth for you know real estate might not be quite as as important here. but these are the conversations you should really be thinking about. And, you know, even if you don’t really want to think about them all directly yourself, like take the transcript of this episode. Like you can just pull it off of YouTube, throw it into Claude and be like, hey, like based on all of this, can we look through all of my you know

business accounts and logins, how I’m storing passwords, et cetera, et cetera. And like really think from a future proofing cybersecurity expert in a postclaw mythos type of world. What else should I really be doing? And maybe certain degrees, like here’s the the the simple pathways to knockout, here’s the more complex ones. Here’s might like actually take some funds and some real effort to to go about. And you can kind of decide where where to protect yourself. But that that’s that’s what, you know, I I

would do if I was like, and that’s what I pretty much do with like all these on any like nonfiction or educational podcasts. I throw them into kind of consolidated learning accelerator skills and they’re like all the claims are checked. So it’ll even check like, you know, did anything that I report, was it actually accurate? Hey, here here’s some of the i info that might need to be fact checked and so forth. Like it it’s I I love

Consuming and working with info that way. I guess it feels so much smarter. And again, being able to push back on the AI is well too. based on the on the claims it it’s it’s presenting back to you and you know, potential pushes on the evidence, you can keep diving in deeper and deeper. But that is exactly how I’m implementing new information that I’m having, besides just like, yeah, this is kind of interesting, and then move on. so just think about it that way. But

And and again, like from a real estate perspective, you know, land investors, what have you. you know, sometimes it might seem, yeah, we’re pretty removed from this. Yeah, it’s cybersecurity. like how are they going to be able to rob pieces of land? But like we do hear all the time, there’s so much, you know, the increase of fraud within real estate ha has risen, you know, dramatically o over time. Cause we all know how many holes there are within the title transfer process. And I know

you know, Seth Williams on Ari Tipster had a guy on within the past few years that had built a business around like almost like flagging owners of property if there’s an attempted title transfer. So, you know, the thing is if we have certain land that might be, you know, flipped more routinely, how much is that worth it when, you know, the turnaround cycles are more frequent? But you know, if we have something that we’re holding for a while, like an intelligent project or even your own home or

you know, another piece of property you own, it’s probably worth adding one of those flags. I think some title companies will have that offered as a service now. otherwise, yeah, potential third party, like, yeah, my wife’s my house. Should I do that? as far as our house here, because like on unwinding somebody like trying to fraudulently transfer the deed of our house on underneath our nose, like, yeah, that would be a huge pain to work with, even if like we were able to

provide the paper trial back, hey, this is all fraudulent and so forth. like no one wants to deal with that. So if you can catch it earlier, like that’s always going to be more beneficial. and again, like some of these title companies, like they’re way more secure, but there’s no firm regulation in place on how to handle title transfer. Cause I’ve worked with some attorneys and title and title companies that are like

They’re they’re clearly not following the letter of the law on how to handle transfer. It’s more of like almost a hand like we we do sign the paperwork and everything too, but like if you were following all of the signatures and you know, how the LLCs were structured and and so forth, like it’s definitely not not quite accurate all the time. So I I’m sure everybody can relate to it in in certain ways, and some are like

way more difficult to to work with, but probably mu much more secure. So I mean we just have to keep that in mind of like where can fraud really filter through this. And I know there’s also been other systems as we kind of wrap up here of you know I I saw you know again cry crypto has been like kind of in and out here like it it’s really faded in terms of relevance more recently compared to AI from you know tech interest standpoint and even investment interest.

you know, but there were certain startups that I saw, yeah, at least going back to like 2020 or so, that were trying to build title transfer businesses for real estate that would work on blockchains, whether it was, you know, like Ethereum blockchain or or what have you, and be able to have a more consistent consistent and provable mechanism for.

assessing and determining title transfer, maybe be able to reduce the administrative costs and so forth. I really haven’t seen much progress at all in that in the past several years. And I I to a certain degree I I think it’s like a a a solution searching for for a problem in in in this case because like there are

Definitely inefficiencies with current title transfer and in person notaries or not and so forth. but is it the most difficult part of working in real estate? No, I I would put it like far down the list compared to like just nasty dispo market and just you know be being in a, you know, again, just extremely difficult market to to operate in. like, you know, title transfer is like the least of my concerns.

Especially if you have like a dedicated notary and can come, you know, show up at your house mold, like it it’s not that big of a deal. so and and honestly, like in this age now of like the Claude Mythos, you know, cybersecurity hacks and what have you, like, are some of these blockchain technologies would you really trust them more than you know, having physical identification,

notaries and so forth too. Again, though there can clearly be flip fraud that can happen from that standpoint as well. but you know, is blockchain gonna be the answer as well, or is that just like another

you know, a area that you know, hackers could could be able to target potentially even more effectively than the the traditional method. I’m I’m not certain about that. but I I I think that that has to be considered even if we do try to think of some other alternatives here. So summarizing this again, pay attention to the these bigger headlines out there. Like don’t don’t just hand wave them.

away here like again we we are living in a brave new world that these ai models are just becoming ridiculously powerful like i get you know email updates from anthropic almost every week now just like hey new model new model and here’s all these new features and so forth like they are pre progressing so much faster and you know the capabilities continue to become more impressive and scary at the same time

Cybersecurity, huge open question right now. I I still think it’s kind of early days here. Most people are kind of hand waving away, including myself to a certain degree, as well. But, you know, again, people in the know are thinking, Hey, we are heading towards a massive inflection point where again, a ton of people are just gonna be pwned. So how do you prevent yourself from being one of those? you know.

again, throw in this transcript here. What what what are the best ways to protect yourself a bit more? going across your your entire business as well as your personal accounts and so forth. And again, what what are some preventative measures you can do as a real estate investor, assuming you’re within that space, such as you know, flags or notices if title transfer is happening on a property that that you own, and you know, benefits,

or contraindications of of working with title companies that might be a bit faster and looser versus ones who are more knowing to deal with but might be more secure in terms of fraud protection. So all these open questions, huge considerations for us as as operators here and only gonna become more important, I think, probably a topic we’re gonna return to going forward here.

So with that in mind, subscribe and share everybody. Again, if you have a deal that you want us to review for funding, seriousland.capital, feel free to submit it there. Or if you potentially want to consider working with me, I’m taking limited engagements for implementing practical AI solutions in other people’s companies. Again, I have all the bona fides, you know, working directly with companies.

that are collectively doing over 50 million dollars that’s five zero in annualized revenue here so continuing to build up that portfolio as well too and you know if you want to potentially work with me on that feel free to reach out directly with that in mind everybody take care talk to you all next time bye

Related Articles:

Before you go: take the playbook

Get Your Land Sold: the exact tactics behind our $606K exit in the hardest land market in decades. Yours with your first issue of Serious News, the weekly land + AI brief thousands of serious investors rely on. Syndicated on RETipster.

Free guide, one brief every Monday. No spam, unsubscribe anytime.