Anthropic’s Cybersecurity Shock Wave + Ronan Farrow and Andrew Marantz on Their Sam Altman Investigation + One Good Thing
Episode
64 min
Read time
2 min
Topics
Productivity, Personal Finance, Relationships
AI-Generated Summary
Key Takeaways
- ✓AI Cybersecurity Gap: Anthropic's Claude Mythos found a 27-year-old security flaw in OpenBSD and a critical bug in FFmpeg that survived 5 million automated scans. Rather than releasing publicly, Anthropic granted access exclusively to a defensive consortium including Cisco, Microsoft, Apple, and Amazon, creating the first significant public-private AI capability gap since GPT-2 in 2019.
- ✓Software Rewrite Timeline: Security experts, including former Yahoo and Facebook security chief Alex Stamos, estimate the next six months will require patching, rewriting, and rereleasing virtually all major software. The primary bottleneck is human review capacity — not the AI's ability to find bugs — meaning medium and small businesses running legacy firmware face the longest exposure window.
- ✓Personal Cybersecurity Baseline: While defensive teams work through the vulnerability backlog, individuals should immediately adopt three practices: use a dedicated password manager such as 1Password with randomly generated unique passwords for every account, enable authenticator-app-based multifactor authentication on email and banking, and avoid reusing any passwords across services — the most exploitable single point of failure.
- ✓Missing OpenAI Investigation Report: The Farrow-Marantz investigation reveals that the law firm hired after Sam Altman's 2023 firing never produced a written report. The board members Altman helped select to oversee the process now state a written report was unnecessary, resulting in an 800-word press release citing a vague "breakdown in trust" — an outcome legal experts flag as a red flag for high-profile nonprofit governance.
- ✓Sam Altman's Gulf State Ties: Reporting documents that Altman's financial relationships with Emirati and Saudi royals run substantially deeper than OpenAI's public framing of routine business fundraising. This matters structurally: when a company pitches itself as a safety-focused nonprofit while cultivating opaque sovereign wealth relationships, the gap between stated mission and actual capital dependencies becomes a governance risk worth tracking.
What It Covers
Anthropic's unreleased Claude Mythos model discovers zero-day vulnerabilities in every major operating system and browser, prompting a controlled release to a defensive cybersecurity consortium. New Yorker journalists Ronan Farrow and Andrew Marantz discuss their Sam Altman investigation, revealing patterns of deception, the missing board investigation report, and deep Gulf state ties.
Key Questions Answered
- •AI Cybersecurity Gap: Anthropic's Claude Mythos found a 27-year-old security flaw in OpenBSD and a critical bug in FFmpeg that survived 5 million automated scans. Rather than releasing publicly, Anthropic granted access exclusively to a defensive consortium including Cisco, Microsoft, Apple, and Amazon, creating the first significant public-private AI capability gap since GPT-2 in 2019.
- •Software Rewrite Timeline: Security experts, including former Yahoo and Facebook security chief Alex Stamos, estimate the next six months will require patching, rewriting, and rereleasing virtually all major software. The primary bottleneck is human review capacity — not the AI's ability to find bugs — meaning medium and small businesses running legacy firmware face the longest exposure window.
- •Personal Cybersecurity Baseline: While defensive teams work through the vulnerability backlog, individuals should immediately adopt three practices: use a dedicated password manager such as 1Password with randomly generated unique passwords for every account, enable authenticator-app-based multifactor authentication on email and banking, and avoid reusing any passwords across services — the most exploitable single point of failure.
- •Missing OpenAI Investigation Report: The Farrow-Marantz investigation reveals that the law firm hired after Sam Altman's 2023 firing never produced a written report. The board members Altman helped select to oversee the process now state a written report was unnecessary, resulting in an 800-word press release citing a vague "breakdown in trust" — an outcome legal experts flag as a red flag for high-profile nonprofit governance.
- •Sam Altman's Gulf State Ties: Reporting documents that Altman's financial relationships with Emirati and Saudi royals run substantially deeper than OpenAI's public framing of routine business fundraising. This matters structurally: when a company pitches itself as a safety-focused nonprofit while cultivating opaque sovereign wealth relationships, the gap between stated mission and actual capital dependencies becomes a governance risk worth tracking.
- •AI Regulatory Vacuum: A private San Francisco company now holds technology capable of autonomously discovering critical vulnerabilities across all major operating systems, yet operates under no meaningful regulatory framework. The Biden-era executive order establishing AI oversight was rescinded on competitiveness grounds, leaving model development of this scale — with direct national security implications — entirely self-governed by the companies building it.
Notable Moment
Farrow reveals that periodic internal conversations about Altman succession have resumed at OpenAI, with one executive named as a potential replacement candidate — before that person subsequently went on medical leave. The detail underscores that what once seemed unthinkable, OpenAI without Altman, is now an active internal consideration.
Episode Transcript
Casey, I got a haircut yesterday. Thanks for noticing. Kevin, it looks extraordinary. Have has this ever happened to you? I went into the barber. I sat down on the chair. He did not ask me what I wanted. He just started cutting. Has this ever happened to you? No. Because they know I'm not straight. With a straight guy, you don't need to ask them. You just get the standard haircut that a man gets. He one shotted my hair. He said he said, yeah. I've seen this before. I know what I'm doing here. Whereas if I walk in, it's like, okay. Let me get out the schematics. And that's why I'm not a barber that I've been to a lot. Mhmm. So, like, it's not like he knew me. See, this is exactly it's like the fact that you just go to random barbers and will accept whoever happens to be this is why they can just start cutting your hair. Oh, who who is yeah. I know. I don't know this person. Yeah. Do whatever the hell you want. See if I care. Yeah. That is the straight approach to hair. But it's working great for you. Thank you. Yeah. Appreciate it. I'm Kevin Roose, a tech columnist at the New York Times. I'm Casey Noon from Platformer. And this is Hard Fork. This week, the dangerous new AI model that has cybersecurity experts on high alert. Then New Yorker writers Ronan Farrow and Andrew Morant join us to discuss their spicy new profile of Sam Altman. And finally, it's time for one good thing. Although, I guess, really, there are two things in the segment. Yeah. We should really rename the segment. Okay. Casey, we have a big announcement. Kevin, what is the announcement? We're ending the show. No. You're finally free, America. Yes. No. On June 10 in San Francisco, we are doing the second ever installment of Hard Fork Live. It's too fast. It's too furious, and it's happening. I tried to let them, get them to let me call it, Too Hard to Fork, but they decided that was not appropriate. Kevin, where can people get more information about Hard Fork Live two? Okay. It's happening on June 10 k. In San Francisco at the Blue Shield of California Theater. Bigger venue than last year. Mhmm. Tickets will be on sale at nytimes.com/events. Not today, but next Friday, April 17. So we're giving you a full week to get your act together, reach out to all your friends, use Meta AI to plan a trip to California, use cloud code to build your scraper bots to scoop up all the tickets. And on Friday, the seventeenth, you can buy tickets. Yes. And let and we will just say in advance, last year, the tickets did sell very quickly. They did. So get in there quickly if you wanna come. There would be more tickets available, but Kevin reserves 50 for, quote, his …
Get the full transcript (11,422 words) + summary by email — free
One-time email with the complete transcript and AI summary of this episode. No account needed.
One email, no spam. We’ll also show you what SignalCast does.
You just read a 3-minute summary of a 61-minute episode.
Get Hard Fork summarized like this every Monday — plus up to 2 more podcasts, free.
Pick Your Podcasts — FreeKeep Reading
More from Hard Fork
OpenAI’s Two-Week Pause + Jill Lepore on the Threat of the “Artificial State” + Train of Thought
Aug 21 · 63 min
This Week in Startups
Anthropic’s Mythos is a cyber-weapon, so you can’t have it | E2273
Apr 9
More from Hard Fork
Zuckerberg’s Anti-Doom Fantasy + Finally an A.I. Detector That Works + A.I. Math
Aug 14 · 63 min
The AI Breakdown
Should We Be Scared of Anthropic's Mythos?
Apr 8
Books, tools, and gear mentioned in this episode
SignalCast may earn commission on purchases via these links.
Tools
- 1PasswordRecommended
by AgileBits
“individuals should immediately adopt three practices: use a dedicated password manager such as 1Password with randomly generated unique passwords for every account”
More from Hard Fork
We summarize every new episode. Want them in your inbox?
OpenAI’s Two-Week Pause + Jill Lepore on the Threat of the “Artificial State” + Train of Thought
Zuckerberg’s Anti-Doom Fantasy + Finally an A.I. Detector That Works + A.I. Math
The White House’s Secret A.I. Rules + The State of Model Alignment With METR’s Chris Painter + The Final Hot Mess Express
Open Model Wars + Claire Stapleton's Dishy Google Memoir + Substack's Slop Fight
OpenAI Models Go Rogue + Kimi K3 Freakout + A.I. Superforecasting
Similar Episodes
Related episodes from other podcasts
This Week in Startups
Apr 9
Anthropic’s Mythos is a cyber-weapon, so you can’t have it | E2273
The AI Breakdown
Apr 8
Should We Be Scared of Anthropic's Mythos?
Software Engineering Daily
Aug 20
AI and the New Global Security Landscape
Software Engineering Daily
Aug 4
AI-Powered Threats to the Software Supply Chain
The AI Breakdown
Jun 29
Mythos Comes Back But Not for Everyone
Explore Related Topics
This podcast is featured in Best Tech Podcasts (2026) — ranked and reviewed with AI summaries.
You're clearly into Hard Fork.
Every Monday, we deliver AI summaries of the latest episodes from Hard Fork and 192+ other podcasts. Free for one show.
Start My Monday DigestNo credit card · Unsubscribe anytime