Hi Reader,
Happy Friday! Portfolios are green despite a shaky ceasefire and a still-closed Strait of Hormuz, which either means markets know something we don't or simply don't care. Either way, here's hoping it's a sign of better things to come, most of all for the people caught in the middle of it all.
- In-depth: Why financial regulators are worried about Anthropic's latest AI model.
- Newsbites: Hormuz, hot inflation, and house prices.
- PensionCraft News: Money market funds, misleading numbers, and volatility drag.
IN-DEPTH
Claude Mythos: Pandora's Bot
As if we didn’t have enough to worry about, Anthropic just launched an AI model with superhuman hacking abilities.
Well, I say “launched”, Anthropic claims they’re so alarmed by what it can do, they’ve limited access to a group of industry partners through an initiative called ‘Project Glasswing’. The list is a who's who of leading software, hardware, and cybersecurity firms.
The model is called Mythos. (Which just shows the importance of branding. People would be less worried about a doomsday scenario if they named it Claude Crumpet.)
To be fair, the software bugs already discovered by Mythos are sobering: critical vulnerabilities in every major operating system and web browser.
One was a 27-year-old flaw in OpenBSD, an OS famous for being among the most security-hardened in the world, used to run firewalls and critical infrastructure. Yet Mythos, acting fully autonomously, found a way to remotely crash any machine running it. And it cost less than $50 to find.
It also uncovered a 16-year-old vulnerability in FFmpeg, the video encoding library embedded in most of the software you use daily. Automated testing tools had hit the offending line of code five million times without finding it.
And it chained together several vulnerabilities in the Linux kernel — the software underpinning most of the world’s servers — to escalate from ordinary user access to complete control of the machine.
Anthropic published a red team report detailing the findings. Over 99% of the vulnerabilities they’ve found have not yet been patched.
Hacked off
Ok, I know what you’re thinking: This all sounds pretty dramatic but what are you telling me for? I didn’t subscribe to Cybersecurity Weekly!
Well, investors should be paying attention.
“US Treasury secretary Scott Bessent summoned the leaders of some of the largest US banks earlier this week to discuss the cyber risk posed by the latest AI model from Anthropic, according to people familiar with the matter.” —
Financial Times
The meeting reportedly included the heads of Bank of America, Citigroup, Goldman Sachs, Morgan Stanley, and Wells Fargo. Federal Reserve chair Jay Powell was also in attendance.
When asked last month about the risks of another financial crisis, Powell said: “We’ve had all kinds of financial crises, but we’ve never really had a successful cyberattack on a large financial utility or financial institution. And that would be quite a different thing.”
Pass the salt
A pinch of salt is probably in order. This is not the first time an AI lab has hyped the abilities of its latest model, only for it to prove less consequential than billed.
In 2019, OpenAI initially withheld GPT-2 over concerns it could generate realistic text and supercharge misinformation. That ancient AI model seems almost quaint now, and even at the time some thought the "too dangerous to release" framing was a marketing stunt. (Incidentally, OpenAI’s VP of Research back then was Dario Amodei, now CEO at Anthropic.)
There is every incentive for frontier labs to talk up the doomsday potential of their concoctions, particularly with OpenAI and Anthropic exploring IPOs later this year.
I don’t doubt that the cybersecurity fears are real, but the bigger reason for holding back public release could be financial. Mythos reportedly costs five times more to run than Opus 4.6. And while Opus remains firmly on the frontier, there is still time for Anthropic to distil the larger Mythos model into a more economic version before a wider release.
But I’d be cautious about assuming AI progress is all hype. At PensionCraft, we’ve been using Claude to help enhance our trackers, and frankly, it’s enabled us to do things we wouldn’t have otherwise been able to achieve.
And the new model blows Opus out of the water, if you believe the industry benchmarks. It has essentially saturated the standardised coding tests.
Remember, Opus 4.6 was released just two months ago. Things are moving fast.
Even rival companies involved in Project Glasswing are saying it's a genuine game changer. Palo Alto Networks warned that the model signals “a dangerous shift where attackers can soon find even more zero-day vulnerabilities and develop exploits faster than ever before. There will be more attacks, faster attacks, and more sophisticated attacks.” Cisco’s Chief Security Officer said “there is no going back.”
(Ironically, Anthropic recently accidentally leaked the underlying code for Claude. The company blamed human error.)
Yet Mythos wasn’t developed specifically for cybersecurity. The model’s reasoning and coding ability naturally give it this strength.
Mythos is rumoured to have ten trillion parameters — an order of magnitude more than the previous generation — and is the first model trained on Nvidia’s Blackwell chips. Nvidia's next-generation Vera Rubin chips start shipping later this year, offering ten times the performance per watt. Feynman-class chips follow in 2028, offering another jump on top of that.
Massive amounts of new compute is about to come online and Anthropic is already using Mythos to help develop its own successor. We should take seriously the idea that AI improvement might go exponential.
Hack to the future
For now, Mythos remains locked down to a few massive companies. It’s unclear when, if ever, it will be released to the wider public.
It’s possible that Opus 4.6 was the last time you and I were able to use a true state-of-the-art AI model. If the security risks can’t be mitigated, then we should probably expect public releases to remain a generation or two behind the frontier. That clearly could have major market implications if AI’s greatest powers are restricted to a few lucky firms. (Will consumers trust any smaller app that hasn’t been vetted by the leading AI model?)
In the near term, there are significant unknowns about how cybersecurity will progress. The field has always been an arms race between attack and defence, generally in a state of equilibrium. Control over the best AI model could tip the balance one way or another.
Even if big companies have the resources to use AI to discover and patch vulnerabilities, will your local council or hospital? Will governments?
Either way, it’s probably a good thing that a Western AI lab developed advanced hacking capabilities before China. But it does beg the question: if the US has been sitting on this for the last month or so, why hasn’t it hacked its adversaries?
(In unrelated news, there are reports that a hacker has breached a state-run Chinese supercomputer, stealing missile schematics, aerospace research, bioinformatics data and fusion simulations.)
Perhaps Anthropic's stand-off with the Pentagon makes more sense in light of current events, with Anthropic raising objections to the potential use of its models for “mass domestic surveillance”.
I wouldn’t be surprised to see a rush of major hacking attempts in the coming months. If you’re a state or non-state actor that’s been sitting on some zero-day software exploits, it may be time to use them or lose them.
No doubt other AI labs — both in the US and China — will release models with similar abilities in the near future. The head of OpenAI’s coding product is already tweeting out hints they aren’t far behind.
This is fine 🔥
There probably isn’t much individuals can do to guard against all this, other than the usual good security practices. Ensure you keep operating systems up to date, minimise the data you share online, and enable two-factor authentication wherever possible. And pray.
If we are about to enter a world where major institutions become more vulnerable to hacking — as the Fed and US Treasury seem to fear — then perhaps platform risk will be more of a concern. Ultimately, much of our wealth is little more than numbers in a spreadsheet. Maybe it’ll make sense to spread our numbers between a few different companies' spreadsheets.
In terms of the AI trade, I think it’s abundantly clear by now that the technology is not a fad. But that doesn’t necessarily make for an easy investment thesis. The leading AI labs, with the exception of Google, remain private companies for now. And when they eventually list on public markets, you can be sure they will be priced at sky-high valuations.
Then there is the risk that even if AI delivers revenues that justify the hype, investors might not reap the rewards. Rabid competition could commodify the technology and compress margins. Or profits might take longer than expected to materialise, in a mirror of the Dotcom boom and bust.
The ultimate risk is that as the technology gets more and more powerful, governments step in to nationalise the frontier labs. After all, the ability to hack any system on earth is an enormous amount of power for one company to wield.
SPONSORED
- Trading 212 offers the cheapest way to invest in the markets and build wealth with zero commission and the lowest FX fee on the market, along with multi-currency accounts;
- You can very easily automate your investing with Pies;
- We have launched an attractive Cash ISA where interest is calculated daily and paid monthly plus it’s a flexible Cash ISA (as is the S&S ISA);
- A nice additional feature is the Trading 212 Card, currently offering up to 1.5% cashback on all transactions capped at £15 per month.
Trading 212 is offering free fractional shares worth up to £100 for new customers: create and verify a Trading 212 account, make a minimum deposit of £1 and use our promo code "RAMIN".
Sponsored Link. Terms apply: trading212.com/join/ramin
When investing, your capital is at risk. Past performance doesn’t guarantee future results. Other fees may apply. Interest applies on the uninvested cash in your account. Free shares can be fractional. Terms apply. T212 Cards are issued by Paynetics which provide all payment services. T212 provides customer support and user interface.
|
NEWSBITEs
The US and Iran agreed a two-week ceasefire, triggering a ferocious relief rally. Brent crude plunged more than 13% to $94.75, its largest single-day drop since 2020. The S&P 500 jumped 2.5% and South Korea's Kospi surged 6.9%. Yet oil remains up over 60% year-to-date, 187 tankers carrying 172 million barrels sit stranded in the Gulf, and only four ships transited Hormuz on Wednesday. There's a lot riding on Schrödinger's Strait.
Saudi Arabia revealed that attacks have slashed its oil production capacity by 600,000 barrels per day. Strikes on the Manifa and Khurais fields each removed 300,000 bpd, while a hit on the East-West pipeline — now the kingdom's main export route with Hormuz blocked — cut throughput by a further 700,000 bpd. The combined loss represents roughly 10% of Saudi crude exports. Just Stop Oil: mission accomplished.
UK homebuyer demand slumped to its lowest level since August 2023, RICS reported. New buyer enquiries fell to a net balance of -39% in March, down from -29% in February, as average fixed mortgage rates climbed back above 5%. Agreed sales collapsed to -34%, and near-term price expectations plunged to -43%. Property snakes and ladders.
US consumer prices surged 3.3% in the year to March, the highest reading since May 2024. The BLS data showed monthly CPI rose 0.9% — the sharpest increase since June 2022 — as petrol prices climbed above $4 per gallon for the first time in three years. Core inflation edged up to 2.6%. Tomatoes jumped 15.3%. 🍅
PensionCraft Latest
🍿 Money Market Funds: How Safe Are They? [Member preview]
🎧 Statistical Sleight of Hand: How Good Numbers Hide Bad Investments [Podcast]
🤔 Volatility Drag & Optimum Leverage [Member video]
👨💻 12 April, 8pm: Members’ Zoom Q&A [Event link]
Exclusive Videos | Market Trackers | Courses | Q&A | Community
Annual membership comes with one month free! Cancel any time.
|
And finally...
Investors fixate on hawks and doves... but what about parrots? Do they favour a cut or hike? (Looks like they're pining for the fjords.)
Bon weekend,
Ramin
Was this email forwarded to you? Subscribe here.
Learn with PensionCraft:
Membership | Coaching | Courses