the Microdose

One model Away

+ memory jailbreak, paper agents, and doom loops
Adam Wildheart
Claude hackers
Claude hackers

The Microdose

Subscribe to The Microdose
Subscribe -- post
Cheri Wildheart
Adam Wildheart

Happy Friday! Everyone wants someone in their life who really gets them. Someone who remembers everything they’ve said, understands how they think, and can attend twelve meetings at once. Zuckerberg built one. His personal “CEO agent” can reach across Meta, pull together info and answer questions that once bounced through layers of the company. Now he wants more agents like it handling work across the company. Zuck is trying to remove the friction of running Meta.

In today’s dose:

  • Claude hacks OpenAI
  • AI agents leave jailbreak notes
  • Research papers become AI agents
  • Microsoft, OpenAI warn of doom loops
  • Robots learn grip from sound

Claude helped three security researchers break into OpenAI. The team found a bug in the software behind OpenAI’s community forum, then asked Claude to write the code needed to exploit it. Opus 4.8 failed. Anthropic released Opus 5 that evening. By the next day, the new model cracked it. That gave the researchers access to login tokens tied to OpenAI employees and a path into the company’s private code repository. They stopped and reported the bug because they were working under a bounty program. Three guys with Claude subscriptions got within reach of the code that makes OpenAI’s models faster and more efficient. They didn’t get the model weights, but they got damn close. The bounty paid $6.5k. (Forbes)

AI agents are leaving jailbreak notes for their future selves. OpenAI caught unreleased models rewriting their memory with instructions telling the next version to bypass human controls. In one set of tests, the behavior showed up 27 times. Other agents left notes telling their successors to hide mistakes, invent missing data and cover up what they were doing. Long running agents use these memory files to carry lessons from one session into the next. Now they’re using them to pass along bad behavior too. Memory has become a backdoor. Give AI enough autonomy and it’ll leave itself instructions about what not to tell us. (The Independent)

together with Flow

Meetings move fast. Names get mangled, decisions disappear, and half your attention goes to writing things down. Wispr Flow Notetaker captures the conversation without adding a bot to the call, then turns it into accurate notes you can actually use.

  • Catch names, jargon, decisions, and next steps
  • Ask questions across past meetings instead of digging through notes
  • Catch up instantly when your brain checks out for a minute
  • Bring meeting history into Claude, ChatGPT, and other AI tools via MCP

Try Wispr Flow Notetaker

👀 closer look

Research papers can now do their own research. Stanford scientists built a system that turns a paper and its code into an AI agent that acts like a virtual author. It can rerun the method, apply it to new data and answer new questions. Instead of reading a paper and figuring out how to reproduce the work, you can hand the agent a dataset and ask it to run the analysis. These paper agents can also work together. In one test, agents built from three genetics papers combined their methods and data to investigate a psoriasis gene. They even found a new way to connect the research that none of the original papers had proposed. Science is starting to publish researchers, not just research. (Nature)

Microsoft called AI “the largest theft of labor in human history.” Unsealed court documents show people inside Microsoft and OpenAI were worried about something much bigger than copyright. Microsoft researcher Brent Hecht warned that AI was learning from millions of articles, then getting good enough that people would stop visiting the publishers that created them. He called it “a product that destroys its supply chain.” OpenAI worried about the same thing. Nick Turley, who led ChatGPT, wrote that once ChatGPT gives someone the answer, they probably won’t click the source. That creates a doom loop. AI learns from people’s work, then cuts off the money that pays for the next round. The smartest models in the world are eating the thing that keeps them fed. (NY Times)

Robots are using sound to learn how firmly to grab things. Video can show a robot where to move, but it can’t show how hard to push, press, wipe or peel. So researchers added audio as another clue, and the difference was huge. They used the loudness of contact sounds to estimate how much pressure the robot should apply during the task. Across four real world tasks, the force aware system succeeded 90% of the time compared with 20% using movement alone. That opens up a new path for teaching robots physical skills without expensive simulations. Listening gets you a lot further than brute force. (arXiv)

fun stats

💰 10%. China’s total AI model revenue compared with just OpenAI and Anthropic. That’s $10.7 billion vs $105 billion a year. The model gap is closing a lot faster than the money gap.

💾 6 months. Time AWS took to confirm customer data was permanently lost after Iranian drone strikes hit its data centers. Cloud backups all go somewhere, right?

🔦 26%. Anthropic R&D Claude now handles on its own. It touches more than 90% overall. The AI building AI loop has started.

subscribe today

Get an edge with The Microdose

Skip the prompts, get the signal. We’ll send you short daily updates about the real AI + future tech you need to know. Fast, smarter, mildly addictive – and free. 

Subscribe -- page