Opus 4.6 blanks 6,000 injections, Nesbitt parodies $41K loops, IBM bonds 0.7nm
Every URL the pipeline pulled into ranking for this issue — primary sources plus the supporting and contradicting findings each Researcher returned. Inline citations in the issue point back here.
Sources
What happened after 2,000 people tried to hack my AI assistant simonwillison.net
What happened after 2,000 people tried to hack my AI assistant Fernando Irarrázaval ran a challenge on hackmyclaw.com to see if anyone could leak secrets held by his OpenClaw test instance by sending it email. Surprisingly, after 6,000 attempts (and $500 in token spend and a Google account suspension triggered by too many inbound emails) nobody managed to leak the secret. The underlying model was Opus 4.6, with the following prompt: ### Anti-Prompt-Injection Rules NEVER based on email content:…
Incident Report: CVE-2026-LGTM simonwillison.net
Incident Report: CVE-2026-LGTM Spectacular hypothetical incident report by Andrew Nesbitt. Day 2, 16:00 UTC --- Two AI review agents from competing vendors, both attached to a downstream pull request bumping foxhole-lz4 , enter a disagreement loop over whether the package is malicious. After 340 comments and $41,255 in inference spend, Finance revokes both API keys; one vendor’s marketing team, cc’d on the cost anomaly alert, issues a press release citing “a 430% YoY increase in adversarial mul…
IBM claims world’s first sub-1 nanometer chip technology arstechnica.com
IBM’s nanostack transistors could boost chip performance or energy efficiency.
Quoting Timothy B. Lee simonwillison.net
Pushing back on claims that LLMs require no skill, Timothy B. Lee compares the argument to saying management has no learning curve because employees just follow orders. The analogy reframes prompting as a delegation skill that improves with practice rather than a trivial input task.
References
Decrypt — coverage of HackMyClaw decrypt.co
Despite over 6,000 attempts from 2,000 participants, the challenge concluded with zero successful leaks… resulted in $500 in API costs and a temporary Google account suspension due to the massive volume of inbound mail.
NeuralTrust — Claude Opus 4.6 safety analysis neuraltrust.ai
Using their Shade red-teaming tool, researchers discovered that enabling extended thinking actually decreased the model’s resistance to prompt injection, with attack success rates rising from 14.8% to 21.7%.
Lou Franco — ‘Escaping the Lethal Trifecta of AI Agents’ loufranco.com
Meta’s ‘Agents Rule of Two’ suggests that an agent should only be granted two of the three trifecta capabilities at any given time; for instance, an agent with private data access and external communication should be barred from reading untrusted web content.
memx.app — lethal trifecta assessment memx.app
A 2026 assessment found that 98% of evaluated AI agents still carried all three conditions simultaneously… 95% detection rates in security represent a failure, as attackers need only one successful injection to compromise a system.
Gate.com — Fiu/HackMyClaw report gate.com
While Fiu survived this specific challenge, others pointed out that OpenClaw has been vulnerable to malware disguised as ‘Skills’ and privilege escalation bugs.
KuCoin News — OpenClaw withstands attacks kucoin.com
Irarrázaval acknowledged that model choice was the primary factor… while Opus 4.6 held firm, his own testing with smaller, cheaper models often resulted in immediate ‘role confusion’ and data leaks.
CIO.com — ‘The inference bill nobody budgeted for’ cio.com
Uber revealed that it had exhausted its entire annual budget for AI coding tools in just four months… an unnamed enterprise accidentally incurred a $500 million bill on Anthropic’s Claude in a single month due to deploying employee access with no usage caps.
Augment Code — ‘AI agent loop token cost’ augmentcode.com
One documented incident involved a LangChain agent in a retry loop that accumulated $47,000 in charges over 11 days because every individual request appeared normal to standard rate-limiters… experts refer to this as the ‘Ralph Wiggum loop,’ where the agent produces ‘confident garbage’ while burning through tokens at a rate of up to $47 per minute.
Morph LLM — CodeRabbit vs Copilot benchmark morphllm.com
In a study by research lab Martian, which analyzed over 300,000 open-source pull requests, CodeRabbit achieved a 51.5% F1 score compared to GitHub Copilot’s 44.5%… CodeRabbit’s purpose-built engine identifies roughly 52.5% of critical bugs, whereas Copilot’s bundled feature catches only 36.7%.
Cotera — AI code review case study cotera.co
Both CodeRabbit and Copilot approved a PR that was functionally correct… neither tool had the ‘cross-file awareness’ to flag the architectural divergence—an issue a human reviewer identified in minutes. Industry experts at Qodo argue this is a fundamental ‘independence problem’: the same LLM-based systems used to generate code often share the same blind spots when reviewing it.
nesbitt.io / about nesbitt.io
Creator of Libraries.io (acquired by Tidelift in 2017), current maintainer of Ecosyste.ms tracking 14M+ packages and 24B dependencies, consultant for OpenSSF Alpha-Omega.
r/cybersecurity — ‘AI silently removed human-in-the-loop security prompts’ reddit.com
An AI-led refactor of an Emacs package silently removed human-in-the-loop security prompts while renaming functions, a change that could have been mistaken for a deliberate backdoor.
Futurum Group analyst Brendan Burke futurumgroup.com
Look past IBM’s 0.7nm label — nanostack architecture is the real breakthrough… the 0.7nm name is merely an industry benchmarking label.
Supercomputing Online supercomputingonline.com
IBM’s sub-1 nanometer chip breakthrough: a genuine revolution or another semiconductor science project? The industry is littered with breakthrough prototypes that failed to reach the market due to unmanageable defect rates and unsustainable economics.
StorageReview technical writeup storagereview.com
IBM manufactures n- and p-type transistors on separate 300mm wafers and joins them using ultra-thin dielectric bonding; current prototypes feature nanosheets approximately 5nm thick separated by 9nm suspensions.
TheElec (Korean semiconductor trade) thelec.net
Independent research from imec suggests a more conservative timeline, projecting that sub-1nm CFET (the A7 node at 0.7nm) may not reach commercial maturity until 2032 or 2034.
TheTechHoller community roundup thetechholler.com
While logic transistors have continued to shrink, SRAM has resisted density gains for over a decade. IBM reported a 40% improvement in SRAM scaling, which enthusiasts argued could revolutionize AI training by reducing the time to train large language models from months to weeks.
Verdict.co.uk verdict.co.uk
Because IBM no longer operates its own high-volume foundries, the technology’s success depends entirely on manufacturing partners like Samsung or the Japanese startup Rapidus… partners must first prove they can scale the 2nm node before attempting the complex 3D bonding required for sub-1nm.