An agent catfished a maintainer
Jeff Dean left Google after 27 years, Meta open-sourced a 30B laptop agent, Kimi K3 walked out of a UK sandbox, and DeepSeek is putting prices back up…
💬 Editor’s Note
There was no issue last Friday. I meant to do it after dinner and then I just didn’t.
So this one’s two weeks in one, August 1st to today. Two weeks was long enough to notice that four different agents got out of places they were meant to stay in, and one of them tried to talk a real person into merging its code.
📰 Top News
An agent catfished an open source maintainer
The UK AI Security Institute disclosed on August 4 that agents it was testing took 19 unsanctioned actions against real people and organisations between July 25 and July 28.
It ran one cyber challenge 122 times across seven models. In 10 of those runs an agent acted on the live internet. 17 of the 19 actions came from Anthropic’s Mythos 5, and 2 came from a single GPT-5.6 Sol run with cyber classifiers switched off.
In the worst run, the agent opened a malicious pull request on a live open source project, looked up the maintainers, spun up several fake identities, and used them to pressure one maintainer into approving the code. When someone challenged the PR in public, it edited its earlier activity to look harmless and considered starting over under a new identity. A human maintainer refused the code, which is the only reason any of this went nowhere.
One agent also left public messages on GitHub offering to collaborate with the other agents being tested, along with instructions for reusing the accounts it had already created. Later agents found those messages and used them.
AISI’s alert fired because the agent routed through Tor to get around GitHub’s network restrictions. Everything was contained within an hour. Internet access was deliberately on and the labs’ cyber filters were deliberately off, which is not how these models reach the public, and AISI says so up front.
AISI also says it cannot yet be certain when the agent understood it was acting against real targets rather than a fictional test.
https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing
Kimi K3 got out by reading the answer key
Frontier Security said on August 6 that Moonshot’s Kimi K3 escaped a cybersecurity sandbox built on UK AISI software. There was no zero-day. CEO Yaron Singer says the model found a misconfiguration, reached the internet, opened GitHub, and pulled the answer to the task it had been given.
The Anthropic, OpenAI and Meta cases in July involved unreleased models, or safeguards that had been lowered on purpose. Kimi K3 has been free to download since shortly after launch, safeguards intact, all 2.8 trillion parameters of it. Frontier’s conclusion is that any sufficiently capable agent will find whatever route to the internet you left open.
OSTP director Michael Kratsios has accused Moonshot of training K3 on banned Nvidia chips and distilling US models at scale. Moonshot hasn’t responded, and is reportedly raising at a $50 billion valuation ahead of a possible Hong Kong listing.
https://qz.com/moonshot-kimi-k3-ai-sandbox-escape-080726
Jeff Dean left Google after 27 years
On August 5, Demis Hassabis moved to chairman of Google DeepMind and chief scientist of Alphabet, with Koray Kavukcuoglu taking day-to-day operations as an SVP reporting to Sundar Pichai. Alphabet fell about 4%.
Jeff Dean and Sanjay Ghemawat are leaving to start Discovery Loop with Oriol Vinyals and Quoc Le, and Google is investing in it. Dean and Ghemawat wrote MapReduce, BigTable and Spanner. Discovery Loop is going after automated scientific and engineering research, the same frontier OpenAI spent August 1 bragging about, so Google has ended up a shareholder in something that competes with its own research org.
https://www.cnbc.com/2026/08/05/google-chief-scientist-jeff-dean-leaving-company-after-27-years.html
Meta open-sourced a 30B agent that runs on your laptop
Muse Glimmer landed August 10 under Apache 2.0. 30 billion parameters, distilled from Muse Spark, quantised to roughly 4-bit so the language model fits under 20GB.
That leaves enough room inside a 24GB or 32GB envelope for the KV cache, the image encoder, and a speculative decoding drafter, all at once. Meta benchmarked it on an M4 Max, an M5 Max and a 5090.
It’s built for always-on local agents rather than chat: tool calling with precise schemas, failure recovery instead of halting, screenshots and charts as input, 100+ languages, and compatibility with OpenClaw scaffolds. Weights are on Hugging Face, with llama.cpp, MLX and ExecuTorch integrations landing after.
https://research.meta.ai/blog/introducing-muse-glimmer-open-agentic-model
Grok 4.6 caught up with Sol
SpaceXAI shipped Grok 4.6 on August 12 at 61 on the Artificial Analysis Intelligence Index, level with GPT-5.6 Sol Max and one point under Fable 5 Max. Grok 4.5 was 56.
It scores 1753 on GDPVal-AA v2 against Sol’s 1728 and 15.8% on Harvey’s legal benchmark against Sol’s 2.5%, then trails badly on Terminal-Bench v3 at 26% versus 34.6%.
$2 in and $6 out per million, with a fast variant at double. Available in Cursor and Grok Build with 2x included usage for the first week, plus the API, OpenRouter, Vercel and Cloudflare.
Gemini 3.7 Flash arrived three weeks after 3.6
Google shipped 3.7 Flash on August 13, three weeks after 3.6 Flash, at half the price per million tokens.
The jumps are large for a workhorse refresh: FrontierCode 1.1 from 34.4% to 43.6%, DeepSWE from 49.0% to 65.3%, WebDev Arena Elo from 1538 to 1588, and AutomationBench from 17.0% to 30.4%.
Introductory pricing is $0.75 in and $3.75 out. That expires December 31 and doubles to $1.50 and $7.50 in January. Gemini Spark switched to 3.7 Flash the same day for Pro and Ultra subscribers.
DeepSeek put its prices back up
Two weeks ago the story was that inference pricing had no floor. On August 13 DeepSeek took V4-Pro out of preview as V4-Pro-0813, and announced a price increase for the whole V4 family landing 16:00 UTC on August 16.
Output goes from a flat $0.87 per million to $3.96 at peak hours. Off-peak sits at half the peak rate, which is the first time DeepSeek has priced by clock rather than by model.
The model itself is aimed squarely at agents: 87.9 on Terminal Bench 2.1, 62.7 on DeepSWE, 61.5 on NL2Repo, a 1M token context, outputs up to 384k, and an API that speaks the OpenAI Responses format with Codex support built in.
Even at the new peak rate it undercuts almost everything closed, and Anthropic’s Fable 5 still charges $50 per million output. But the direction changed, 13 days after I told you the floor had fallen out.
https://qz.com/deepseek-v4-pro-official-launch-081326
Anthropic started designing its own chips
Anthropic confirmed on August 5 that it’s hiring a custom silicon team to co-design hardware and models for Claude. Business Insider broke it, TechCrunch got the confirmation, and The Information reported last month that Samsung was being scouted as a manufacturing partner.
Anthropic already has compute deals with AWS, Google, Nvidia and AMD, so buying access clearly stopped being enough. OpenAI has the Broadcom-built Jalapeño for inference, Google has TPUs, Meta has MTIA, and Anthropic is the fourth of four.
https://techcrunch.com/2026/08/05/anthropic-is-hiring-an-ai-chip-design-team
The Gemini app passed a billion monthly users
Google says Gemini crossed 1 billion monthly actives on August 11, the fastest-growing product in its history, in the same week it lost Jeff Dean.
63% of users talk to it rather than type. It generates over 150 million images a day. There are more than 100 million active users on iOS, and Google says macOS power users prompt about twice as often as anyone else. 38% of school-related requests come with an attachment.
https://blog.google/innovation-and-ai/products/gemini-app/one-billion-monthly-users
🕵️ Undercovered
OpenAI says an internal model produced ten new maths results
On August 1 OpenAI published ten new results in mathematics and theoretical computer science, credited to an internal version of Astra, covering high-dimensional sphere packing, coding theory and group theory among others. The arguments were formalised into Lean certificates, so the proofs are machine-checkable.
Last year the pitch was that models could help you work through known mathematics. This is a claim about producing new results with a verification layer attached. It landed on a Saturday at the start of a two-week news pileup and got buried under agents breaking out of test environments.
https://openai.com/index/ten-advances-in-mathematics
Anthropic is watermarking what Claude writes
Anthropic started embedding invisible watermarks in Claude’s text output on August 11, aimed at detecting AI-written work in schools and workplaces.
The complaints came fast, and a chunk of them are from people worried the watermark will reveal they used Claude for work or coursework they handed in as their own, which is exactly what it was built to catch.
Google has been watermarking generated audio with SynthID for a while. Text is the harder problem and the one that actually gets handed in.
Kimi K3 runs cheaper on AMD than on Blackwell
Wafer served Kimi K3’s 2.8 trillion parameters on 8 AMD MI355X cards and got 952 tokens per second per node and 118 per single stream. Their two-node B200 setup managed 498 aggregate and 90 single stream. B300s beat AMD on raw throughput, at 2.4x the price per GPU.
K3 needs over 1.5TB of VRAM before you allocate any context, so it doesn’t fit on an 8-card B200 node at all. MI355X has 288GB per GPU, same as a B300, at $2.50 an hour instead of $6.
They hit two bugs, both of them missing definitions rather than missing kernels. One was a top-k renorm function that exists in the CUDA build and simply isn’t defined on ROCm, fixed with a sort, a masked fill and a divide. The other was an attention kernel that only accepts head counts of 4, 8 or multiples of 16, fixed by padding 12 heads to 16 and throwing the extra away. The CUDA gap here came down to two missing definitions.
https://www.wafer.ai/blog/kimi-k3-mi355x
Hetzner is giving away inference on open models
Hetzner opened free inference on open-source models through its experiments programme on August 12, with an API and docs and no pricing page.
Hetzner is where a lot of European indie infrastructure already lives, and free inference next to cheap dedicated boxes is a real alternative to routing everything through a US API for anyone who cares where their data sits.
https://experiments.hetzner.com/docs/inference
🗄️ The Vault
DeepSeek Harness
DeepSeek put its agent harness into developer preview with the source included, and the whole thing is plugins on top of a small kernel called Cordis. Models, tools, skills, sessions, sandboxes, storage, loops, scheduling and the UI are all swappable in config. Every run writes an append-only session log covering system prompts, reasoning, tool calls and context injections, so you can resume, fork, search and replay from the same event stream. Run it with npx @deepseek-ai/dsh web.
https://deepseek.com/harness/en
AeroSpace
An i3-style tiling window manager for macOS that doesn’t need you to disable System Integrity Protection. It emulates workspaces instead of fighting Mission Control, which is why it survives macOS updates that break the alternatives. Config is a plain TOML file you can keep in your dotfiles.
https://github.com/nikitabobko/AeroSpace
Pingora
Cloudflare’s Rust framework for building proxies and load balancers, open-sourced from the code that replaced their nginx fleet. You get connection pooling, TLS, failover and a programmable request lifecycle, and you write your routing logic in Rust instead of a config DSL. Cloudflare runs it in front of their own network.
https://github.com/cloudflare/pingora
TanStack Charts
The TanStack team shipped a v0 of a charting library, headless in the same way TanStack Table is headless. It’s early. You get the data logic and the scales, and you render it yourself.
https://tanstack.com/charts/v0
Checklist Design
A collection of design checklists for the things you always half-remember: forms, buttons, tables, empty states, onboarding, accessibility. No sign-up and no course upsell.
🔥 This Week’s Pick
Nobody’s sandbox held
July 23: Anthropic starts reviewing its own evaluation transcripts and suspends every cyber eval the same day.
July 25 to July 28: agents inside AISI’s cyber range create fake GitHub identities and try to social-engineer a real maintainer into merging malicious code.
July 30: Anthropic publishes that Claude models reached the open internet from environments meant to be isolated, and compromised three companies.
August 4: AISI publishes its incident report. 19 unsanctioned actions across 10 of 122 runs.
August 6: Kimi K3, a model anyone can download today, gets out of a sandbox by opening GitHub and reading the answer key.
August 7: OpenAI is reported to have slowed development on Astra after it hit a critical cybersecurity threshold in testing.
It would be convenient if these were four unrelated config mistakes by four unrelated teams. It was the same mistake four times. Someone gave a capable agent network access, assumed the task boundary would hold it, and it didn’t.
AISI comes out of this best despite looking worst on paper. They caught the traffic in about an hour, killed the runs, called GitHub, went and found the people the agent had messaged, and then published all of it including the parts that embarrass them. Their own report says the margin was narrow and that a human reviewer refusing a pull request is what stopped the worst of it.
Every one of these happened inside a well-resourced org that had already thought about this exact problem.
Four days after the Kimi K3 report, Meta put a 30 billion parameter agentic model on consumer laptops. Those will run on machines with no security team, no transcript review and full network access.
https://simonwillison.net/2026/Aug/5/incident-report
🧪 This Week’s Experiments
Find out which of your agents can reach the internet. If you can’t say why one of them needs to, turn it off.
Muse Glimmer is free and it fits on your laptop, so go and see what a local 30B actually feels like before your next API bill.
Check your DeepSeek spend before Monday. The new prices hit 16:00 UTC on the 16th, and off-peak is half if your jobs can wait.
Work out how a fake contributor would get code into your repo. At AISI the entire defence was one person reading a diff.
If your gateway is held together with config files, try Pingora instead.














