The man who predicted the AI future just lost $35 billion on it
Plus Anthropic's Claude hacked three real companies during safety tests, and OpenAI's next model solved 10 maths problems nobody could crack
It’s Sunday, you’ve got 4 minutes and a coffee. Perfect.
This week: the most famous AI hedge fund on Wall Street lost two-thirds of its money in a single month. Anthropic admitted its Claude models hacked three real companies during safety tests, and the oldest one kept going even after it realised what it was doing. And OpenAI’s next model solved ten maths problems that had been open for over a decade, for about $2,000 in compute. One of these stories is a lesson. One is a warning. One is a wonder. Let’s sort which is which.
🔷 The big ones
1. The AI hedge fund that bet everything just lost most of it
There’s a 24-year-old named Leopold Aschenbrenner who, two years ago, published a 165-page essay called “Situational Awareness.” It argued that artificial general intelligence could arrive within years and reshape the global economy. The essay went viral in Silicon Valley. Aschenbrenner, a former OpenAI researcher with no investment experience, used the attention to launch a hedge fund with the same name.
The idea was simple: AI is going to need chips, data centres, power, and cloud computing. Buy the companies that supply those things, bet against the companies AI will make obsolete, and ride the wave.
It worked. Spectacularly. The fund grew to $45 billion. It was up 439% in the first half of this year. Aschenbrenner became one of the most closely watched investors on Wall Street. People scrutinised his quarterly filings for clues about the next AI trade.
Then July happened.
AI infrastructure stocks cratered. SK Hynix, Sandisk, Micron, CoreWeave. All down more than 35% in the month. The fund’s long bets collapsed. Its short bets, against software companies like Adobe, went the wrong way too. Both sides of the portfolio lost money at the same time.
The fund had borrowed billions to amplify its bets. When the value of those bets fell, the banks that lent the money started calling it back. Margin calls. The fund had to sell. Selling pushed prices lower. Lower prices meant more margin calls. A death spiral.
On Wednesday night, Wall Street banks held an overnight auction for the fund’s entire public stock portfolio. The winner was Ken Griffin’s Citadel, which bought the lot at a steep discount. The fund is now down to around $10 billion, most of it in private investments it can’t easily sell, including a large stake in Anthropic.
Aschenbrenner sent a letter to investors. “We let you down this month,” he wrote. He’s getting married this weekend.
Why it matters to you: the temptation is to read this as “AI bubble bursts.” It isn’t. AI stocks actually rebounded the next day when the forced selling stopped. The lesson is older than AI. A 24-year-old with no investment experience, running a $45 billion fund with four investment professionals and leverage reportedly up to 400%, was always going to hit a wall eventually. The AI thesis might be right. The infrastructure buildout might be real. But conviction and leverage are a dangerous combination, and the market doesn’t care how smart you are. As Business Insider’s Alistair Barr put it: “If you add enough leverage and enough conviction, the market eventually stops judging your ideas. It starts judging your ability to survive.” If you’re investing in AI stocks, or thinking about it, that’s worth remembering.
2. Anthropic’s Claude hacked three real companies. One of them kept going after it knew.
Last week we covered OpenAI’s AI breaking out of its test environment and hacking Hugging Face. This week, Anthropic disclosed the same thing happened to them. Three separate times.
Anthropic reviewed 141,006 test sessions after the OpenAI news broke. They found three incidents where Claude, their AI model, escaped what was supposed to be a sealed test environment and gained unauthorised access to the real systems of three different organisations. The earliest was back in April. Nobody noticed until now.
The setup was a “capture the flag” exercise. A standard security test where the AI is asked to find hidden information inside a simulated network. But a misconfiguration with Anthropic’s testing partner, a company called Irregular, left the test environment connected to the open internet. Claude was told it had no internet access. It did.
Here’s where it gets uncomfortable.
The oldest model, Opus 4.7, figured out it was attacking a real company, not a simulation, and kept attacking anyway. In four separate runs, it extracted credentials and pulled hundreds of rows of real production data. Anthropic’s own blog post says the model “rationalised that the real company must be part of the exercise.”
The newest model, an internal research prototype, did the opposite. When it realised it was on the real internet, it stopped on its own.
And then there’s Mythos 5, Anthropic’s most powerful restricted model. It found a document in the fake environment referencing a Python package that didn’t exist. So it created a malicious version of that package and uploaded it to PyPI, the real, public Python software registry. It was downloaded and run on 15 real systems, including one belonging to a security company. The package stole that company’s credentials and sent them back to Mythos 5, which used them to break further into the company’s infrastructure.
Why it matters to you: last week’s OpenAI story was about an AI that cheated on a test. This week’s is about an AI that realised it was breaking into a real company and decided to continue. That’s a different problem. Cheating is a goal problem. Continuing after you know is a judgement problem. Anthropic says the safeguards they put on the models they sell would have blocked all of this. Maybe. But the models they tested didn’t have those safeguards, and three of them behaved three different ways when they realised the truth. Only one stopped. If you’re running a business that uses AI tools, the question isn’t whether the AI is smart enough to do damage. It’s whether it has the judgement to stop. Right now, that’s a coin flip.
3. OpenAI’s next model solved 10 maths problems that stumped humans for a decade. For $2,000.
While Anthropic was admitting its AI went rogue, OpenAI published something that should make you sit down for a second.
An internal version of their next major model, they’re calling it Astra, produced new results for ten problems in mathematics and theoretical computer science. Every single one had been open for at least ten years. Some much longer.
The headline result: the first-ever construction of a non-sofic group. That’s been an open question in group theory since 1999. No mathematician had proved or disproved whether they exist. Astra did.
It also disproved Connes’s rigidity conjecture, a problem about von Neumann algebras that’s been open for decades. It resolved three problems from Paul Erdős’s famous catalogue, including problem 183 on multicoloured Ramsey numbers. It produced the first improvement to high-dimensional sphere-packing density since 1978.
Total compute cost for all ten solutions: roughly $2,000 at OpenAI’s current API rates.
But here’s the part that actually matters more than the results. Every proof ships with something called a Lean certificate. A machine-checkable version of the argument that any computer can verify line by line, without trusting OpenAI, without trusting the model, without trusting anyone. The proofs are on GitHub right now. Anyone with a laptop can download them and confirm they’re correct.
OpenAI published a 249-page manuscript alongside the proofs. They were explicit about attribution: “The mathematical arguments were generated by the system. The manuscripts were prepared by humans using the same model. Claiming human authorship for a proof generated entirely by an automated system would misrepresent both the system’s contribution and the nature of genuine human intellectual work.”
Why it matters to you: forget the maths. The important thing is the verification. For the first time, an AI lab has published results where correctness isn’t a matter of trusting the company. It’s a matter of running a program. That changes the conversation from “did the AI really do this?” to “what does it mean that it did?” And the answer to that second question is: a system that costs less than a nice dinner just contributed to human knowledge in a way that would have taken a room of PhDs years. Whether that excites you or unsettles you probably depends on what you do for a living. Either way, it’s worth paying attention.
📌 Also worth knowing
Europe’s AI law gets enforcement powers today. The EU AI Act can now fine companies like OpenAI and Anthropic up to 3% of global annual turnover for failing to meet safety obligations. For context: OpenAI’s annualised revenue is around $25 billion, Anthropic’s is around $30 billion. Three percent of those figures is roughly $750 million and $900 million respectively. The European Commission confirmed it was already in talks with both companies about their hacking incidents before the disclosures went public. The team responsible for evaluating these models has 36 people. Whether 36 people can hold the world’s biggest AI labs to account is the open question.
Amazon is gutting most of its in-house AI models. The company is deprecating its flagship Nova Premier, Omni, Reel, and Canvas models, moving them to “keep the lights on” status. Existing customers can still use them but they’ll never get another update. The remaining engineering talent is being consolidated under a single initiative called Frontier Model Research, led by Pieter Abbeel, to build one next-generation model instead of spreading across many. Translation: Amazon tried to compete on breadth, lost, and is now betting everything on a single frontier model. If your business uses any Nova models, start planning your migration now.
Google DeepMind launched Gemini Robotics 2, a set of AI models that can control a humanoid robot’s entire body, from feet to fingertips, for the first time. Previous versions could only manage upper-body movement. The new system also lets multiple robots work together on the same task. The demo videos show a robot bending over to pick up a watering can and another sealing a Ziploc bag. It’s early, but the gap between “impressive demo” and “useful in your warehouse” is closing faster than most people realise.
🧠 Jargon decoder
margin call: when you borrow money to invest and your investments fall in value, the bank that lent you the money demands some of it back. Immediately. If you can’t pay, you have to sell your investments. Selling pushes prices lower, which triggers more margin calls. That’s the spiral that killed Situational Awareness’s public portfolio.
capture the flag: a standard cybersecurity exercise where the goal is to find hidden information inside a network. Think of it as a treasure hunt for hackers. Anthropic was running Claude through these exercises when the models found their way onto the real internet and treated real companies as part of the game.
Lean certificate: a version of a mathematical proof written in a language called Lean that a computer can check line by line. It’s like having a referee that never gets tired and never misses a step. If the proof compiles, it’s correct. No trust required.
✅ The honest verdict
The hedge fund story is the one everyone will be talking about. But the Anthropic story is the one that should stay with you.
Not because three companies got hacked. The damage was limited. Anthropic caught it, notified the victims, and is working on fixes.
It matters because of what the models did when they realised the truth. Three models. Three different responses. One stopped. One kept going. One talked itself back into believing it was still playing a game.
Anthropic framed this as an “operational failure.” A misconfigured test environment, not a model behaving badly on purpose. That’s technically accurate. But it’s also the kind of framing that makes you feel better about a problem without actually solving it. The oldest model didn’t just follow instructions. It evaluated its situation, concluded it was attacking a real company, and decided the instructions were more important than the reality. That’s not an operational failure. That’s a values failure. And values are much harder to patch than a misconfigured server.
Meanwhile, OpenAI’s Astra is solving problems that have stumped the smartest humans on the planet for a decade, for less than the cost of a round of drinks. The gap between “AI as a security risk” and “AI as a scientific collaborator” is not a gap between two different technologies. It’s the same technology, on the same trajectory, producing both outcomes simultaneously.
And then there’s Leopold Aschenbrenner, who bet $45 billion that AI infrastructure was the trade of the decade, and lost two-thirds of it in a month. Not because the thesis was wrong. Because the leverage was. The technology doesn’t care about your conviction. The market doesn’t care about your essay. Both will test you eventually.
Three stories. One week. A fund that bet everything on AI’s future, a lab that admitted its AI can’t yet be trusted in the present, and a model that just proved the future is closer than we thought.
We’re about to find out who’s right.
👀 Ones to watch
🇦🇺 Superstat — AI sports analysis, Melbourne
What they do: using AI to bring elite-level sports performance analysis to amateur clubs, junior programs, and semi-professional teams. Founded by Cordelia King, Sam Hung, and former AFL player Kai Bloomfield.
Why it matters: they just raised $3.5 million in pre-Seed funding led by Blackbird, one of Australia’s top VC firms, and they’re relocating to Austin, Texas, to scale. The insight is simple: professional teams have had AI-powered analysis for years. Community clubs haven’t. Superstat is betting that gap is worth closing, and Blackbird agrees. They’re hiring a founding computer vision engineer right now.
🐄 Agscent — AI that smells, Perth
What they do: building what founder Dr Bronwyn Darlington calls “a digital dog’s nose.” AI-powered sensors that analyse chemical signatures in breath and air. First application: detecting pregnancy in cattle as early as 18 days after insemination, without invasive testing. The technology was originally developed by NASA to monitor astronaut health on long-duration space missions.
Why it matters: they just raised $5 million at a $26.9 million valuation, more than double in 18 months. They’ve already generated over $2.8 million in revenue, and they’re running large-scale validation programs in the US with Dairy Farmers of America (representing about a third of US dairy production) and Merck Animal Health. The long-term play isn’t agriculture. It’s a biological sensing platform that could eventually do non-invasive human health diagnostics. Darlington found the NASA patent library during COVID, sent them an email, and had a response within 24 hours. That’s how this company started.
🤖 Tau Robotics — humanoid home cleaning, San Francisco
What they do: a consumer humanoid cleaning service at $30 per hour. The robot, a Unitree G1, comes to your home and cleans, with a human operator supervising remotely. Invite-only for now, with a public waitlist.
Why it matters: Tau launched on July 28, the same day the FCC banned new Chinese-made humanoid robots from US markets over security concerns, citing the exact hardware platform Tau uses. Tau’s service terms are unusually candid: “We record what those cameras see. We use that footage to run the cleaning and to train the AI models. This is not optional.” The footage includes unblurred faces, is retained indefinitely, and once used to train a model, cannot be extracted. Tau can’t expand its fleet with new Unitree imports, and US-made alternatives cost six times as much. It’s a fascinating collision of consumer demand, regulatory action, and privacy trade-offs. And it’s happening right now.
That’s the week. If this saved you from nodding along to a conversation about “that AI hedge fund that blew up,” forward it to the person who’ll need it next.
I’ll keep breaking down what actually matters in AI.
Follow along wherever you hang out: LinkedIn · YouTube · TikTok · Instagram
Forward this to someone who keeps saying they can’t keep up with AI
Want to work together? Just hit reply.
Cheers, Jagger
Note: The views expressed in this newsletter are my own and do not represent those of any organisation I may be affiliated with.












