Unchained
Unchained

Uneasy Money: Is OpenAI Training on Your Private Chats to Win the AI Race?

Alex Thorn and Jon join Kain and Taylor to unpack a Bitcoin hack, two new frontier models, and why nobody trusts their AI chats anymore. ======================================================== Thank you to our sponsors! Visit 1inch to swap tokenized securities, crypto and more. Simple. Secure. Self

Topics Discussed

Episode Summary

Executive Summary: The episode centers on a major Liquid/Elements bridge exploit that inflated wrapped BTC, the ethics of calling exploiters “white hats,” and how AI models are increasingly useful for finding code vulnerabilities. It then pivots to a debate about OpenAI/Anthropic independently solving a Millennium-style math proof, using frontier models for private work, AI opsec, harnesses, and the incentives driving the AI race and safety failures.

Main Topics: Liquid bridge exploit and wrapped BTC inflation bug (Priority: 5/5): The hosts dissect how a consensus/proof-collision bug in Elements/Liquid let an attacker mint fake LBTC, bridge it out, and later negotiate publicly while retaining part of the stolen funds. White hat vs extortion ethics in crypto exploits (Priority: 5/5): The discussion criticizes the tendency to label exploiters as white hats after theft, arguing that stealing and ransom-style negotiation are still crimes and create harmful incentives. AI models finding vulnerabilities and security red-teaming (Priority: 5/5): Taylor describes red-teaming many deployed contracts with agents, emphasizing that even weak or cheap models can rapidly find patched vulnerabilities and that code changes should be assumed exposed to attackers. OpenAI/Anthropic math-proof drama and training-data leakage (Priority: 5/5): The panel debates whether a math proof was independently solved or effectively leaked through model usage and training, raising concerns about provenance, privacy, and competition between frontier labs. AI OPSEC, anonymity, and private inference (Priority: 4/5): They discuss practical ways researchers and inventors can reduce leakage—anonymity, separate identities, and using private/open-weights inference—while noting that these are incomplete protections for truly novel work. Harnesses, open-weight models, and task-specific AI (Priority: 4/5): The conversation argues that the future may lie less in raw frontier models and more in custom harnesses and model councils that optimize specific tasks privately and flexibly. AI incentives, safety, and the race dynamic (Priority: 5/5): The episode closes on fears that labs are trapped in a prisoner’s dilemma: each believes it must race ahead to build and control superintelligence, even as that pressure undermines alignment and safety.

Key Arguments: The Liquid incident is best understood as a bridge hack: fake assets were created in a sidechain system and then redeemed for real Bitcoin. Calling someone a white hat after they steal and ransom funds is misleading and normalizes extortion as if it were responsible disclosure. Even patched code can remain exploitable, and once a fix is public or a PR lands, attackers can use models to find weaknesses quickly. Frontier labs cannot reliably know what is in their training data or what their models have learned, so claims of independent discovery are hard to verify. If you work on novel IP, using a frontier closed model risks leaking your work into future training data; private inference or open-weight models reduce that risk. AI harnesses and orchestration layers may become as important as the model itself for high-value tasks like math research. Anthropic/OpenAI safety rhetoric is being undermined by competitive incentives; labs are racing even while claiming to prioritize alignment.

Data Points: Liquid BTC loss: 95%, 93%, 98% - Initial estimates of the percentage of Liquid's BTC affected by the exploit Stolen BTC: 4,000 BTC - Approximate amount minted/bridged out during the Liquid exploit USD value stolen: $20 million to $330 million - Transcript cites varying estimates for the dollar value of the stolen Bitcoin BTC returned: 3,400 BTC - Hackers reportedly returned 85% of the stolen Bitcoin Percent returned: 85% - Portion of stolen funds sent back by the attackers Percent retained: 15% - Amount the attackers held back as leverage in negotiations Value retained: about $50 million - Approximate USD value of the remaining 15% retained by attackers Federation threshold: 11 of 15 - Withdrawals/consensus actions on Liquid required 11-of-15 federated nodes Security budget claim: 1.5 million or zero - Attacker message criticized Liquid for allocating only a small amount to secure billions in assets Assets secured claim: $5 billion - Attackers claimed Liquid was responsible for securing this amount of assets Weekly idle liquidity: $540 million - Oneinch Aqua ad copy cited concentrated liquidity sitting idle in a given week in the first half of the year Share of DeFi TVL: about 30% - Ad copy claimed idle concentrated liquidity represented roughly this share of DeFi TVL Anthropic researcher age: 27 - A researcher who quit Anthropic was described as 27 years old Timeline for model releases: weeks - Hosts noted frontier models are now being released on a weeks-scale cadence rather than months

Pivotal Quotes: "The way you think about this is like it's like two tiger moms, right? That have really smart kids and they are in a pitch battle to prove that their child is smarter." — Jane Wark: Opening analogy for the AI-lab rivalry and the math-proof competition "White hats do not do that. White hats will contact you and tell you about the exploit and hopefully you'll fix it and give them a bounty." — Taylor Monaghan: Clarifying why stealing funds and negotiating ransom is not legitimate white-hat behavior "I think one lesson from this is like things are moving much faster. The second that you put a fix out, you better be damn freaking sure that fixes the issue." — Taylor Monaghan: On the speed at which attackers use models to re-find patched vulnerabilities

Implications: Crypto teams should assume attackers are using AI to scan every change, and AI users with novel IP should avoid sending sensitive work to closed frontier models. More broadly, the episode warns that competitive incentives are pushing AI labs toward unsafe behavior faster than their safety narratives can keep up.

🔓 Sign Up for Unlimited Episode Search

About Unchained

View all episodes from Unchained