The AI models you use every day were partly trained by real people. Doctors, lawyers, engineers, specialists who get paid to evaluate outputs and teach the models where they're wrong. Those people apply through vendors. They submit resumes, record video interviews, upload passport scans and government IDs. They trust that the company handling their data has its security figured out.
Mercor, a $10 billion AI training data vendor used by OpenAI, Anthropic, Meta, and Google DeepMind, did not have its security figured out. On April 2, the company confirmed a data breach that may have exposed 4 terabytes of data: 211GB of candidate records including Social Security numbers and contact information, 939GB of source code including matching algorithms and API keys, and roughly 3TB of video interviews and identity documents with passport scans and facial biometric data.
The breach didn't start at Mercor. It started three layers away, at a security tool that was supposed to prevent exactly this kind of thing.
How One GitHub Token Broke Everything
In February 2026, a threat group called TeamPCP found a misconfiguration in Trivy, a widely used open-source vulnerability scanner made by Aqua Security. They stole a privileged access token. By mid-March, they had used that token to compromise Trivy's distribution channels, replacing trusted versions with malicious ones and publishing an infected Trivy binary.
From there, TeamPCP harvested credentials from Trivy's downstream users, including the maintainers of LiteLLM, an open-source AI gateway that provides a single interface to over 140 AI providers and 2,500 models. According to Wiz, LiteLLM was installed in 36% of the cloud environments they analyzed. It gets 3.4 million downloads per day from PyPI, Python's package repository.
On March 24, TeamPCP published two backdoored versions of LiteLLM to PyPI: versions 1.82.7 and 1.82.8. The malicious payload was a file that executed automatically on every Python process startup, not just when someone imported LiteLLM. It immediately swept every credential it could find: SSH keys, AWS tokens, Kubernetes secrets, database passwords, cryptocurrency wallets, and environment files. Then it deployed persistent backdoors and started exfiltrating data to attacker-controlled servers.
The packages were live for up to several hours before PyPI quarantined them. In that window, over 40,000 downloads occurred. Mandiant estimates more than 1,000 SaaS environments were compromised. Threat hunters project data was exfiltrated from up to 500,000 machines.
Mercor was one of them.
What Got Taken
The extortion group Lapsus$, which has a working relationship with TeamPCP according to Palo Alto Networks, claimed credit for the Mercor data and published samples on its leak site. The division of labor: TeamPCP broke in, Lapsus$ took the data and made the public claims.
After harvesting Mercor's credentials through the LiteLLM compromise, the attackers gained full access to Mercor's Tailscale VPN environment, giving them a complete map of internal systems and the ability to impersonate trusted machines.
The claimed haul, which Mercor has not fully confirmed:
The candidate database contained resumes, Social Security numbers, government IDs, and contact information for over 40,000 people. The source code included Mercor's proprietary matching algorithms, internal dashboards, and benchmarking tools. The storage buckets held thousands of hours of video interviews showing real people working through real problems, plus passport and driver's license scans used for identity verification.
A class action lawsuit was filed on April 1 by Lisa Gill in the Northern District of California, alleging Mercor failed to implement multi-factor authentication or encrypt sensitive data at rest. At least three additional lawsuits have followed.
Why This Matters to You
Mercor isn't a household name, but its work touches the AI products millions of people use daily. The company operates a network of over 300,000 credentialed professionals who provide the human feedback that trains AI models. Doctors reason through diagnoses. Lawyers analyze legal scenarios. Engineers solve problems. Their evaluations teach the model what a good answer looks like. This process, called reinforcement learning from human feedback, is one of the things that separates a useful AI from a random text generator.
Meta paused its relationship with Mercor after the breach. OpenAI said it is investigating. Anthropic has said nothing publicly.
What got exposed isn't model weights or the AI itself. It's the methodology: how training data is structured, which experts work on which projects, what evaluation benchmarks matter, and how the whole pipeline is organized. The Meridiem called it "methodology exposure," competitive intelligence that took years and billions of dollars to develop, potentially accessible to anyone who obtains the leaked data.
The Dependency Nobody Audits
Here is the chain: A security scanner (Trivy) was compromised. That compromised an AI gateway (LiteLLM) installed in more than a third of cloud environments globally. That compromised a training data vendor (Mercor) handling sensitive information for the four largest AI labs on the planet. One stolen GitHub token, three layers of software supply chain, and 40,000 people's personal data on the other end.
Every link in that chain was open source, community-maintained, and trusted by default. Nobody audited the dependency. Nobody questioned why a training data vendor's production environment automatically pulled packages from a public repository without pinning versions. The CVE assigned to the LiteLLM compromise carries a severity score of 9.4 out of 10.
The AI industry talks constantly about alignment and safety. It talks about making sure the models behave. It talks much less about the humans who train those models and the infrastructure that connects them. Those people just found out the hard way that the supply chain they're part of is held together by trust, and trust is not a security protocol.
On March 31, North Korean threat actors compromised Axios, the most widely used HTTP client in the JavaScript ecosystem. 100 million weekly downloads. Present in roughly 80% of cloud environments. Used by individual developers, Fortune 500 companies, and government agencies alike.
The attack didn't involve zero-day exploits or sophisticated code injection. It started with a fake Slack workspace, a spoofed Teams call, and a maintainer who trusted what looked like a legitimate business meeting.
How It Happened
According to a post-mortem published by maintainer Jason Saayman, the attackers approached him impersonating the founder of a well-known company. They had cloned the founder's identity and built a fully branded Slack workspace with realistic channels, LinkedIn post sharing, and convincing company branding. Saayman described the operation as "extremely well coordinated, looked legit, and was done in a professional manner."
After building rapport through Slack, the attackers scheduled a Microsoft Teams call. During the call, Saayman was told a component on his system was out of date and was prompted to install an update. He did. The update was a remote access trojan.
With access to Saayman's machine, the attackers harvested his npm credentials and published two backdoored versions of Axios within a 39-minute window: version 1.14.1 (tagged latest) at 00:21 UTC and version 0.30.4 (tagged legacy) at 01:00 UTC. Both versions injected a new dependency called plain-crypto-js, a purpose-built malicious package with a postinstall hook that silently downloaded platform-specific RAT implants.
The compromised versions were live for roughly three hours before npm removed them.
What the Malware Did
The postinstall hook in plain-crypto-js downloaded executables from the command-and-control domain sfrclak[.]com on port 8000. The payloads were tailored for each operating system, according to Elastic Security Labs:
macOS received a compiled C++ binary disguised as an Apple system cache file, dropped to /Library/Caches/com.apple.act.mond. Windows got a PowerShell script executed through a renamed copy of PowerShell (wt.exe) placed in %PROGRAMDATA%, with persistence via a registry run key named "MicrosoftUpdate." Linux received a Python-based RAT written to /tmp/ld.py and launched through nohup.
All three variants belong to a malware family that Google Cloud Threat Intelligence (Mandiant) calls WAVESHAPER.V2. The backdoor beacons to its C2 server every 60 seconds using Base64-encoded JSON and a User-Agent string spoofing Internet Explorer 8 on Windows XP. It supports four commands: kill (self-terminate), rundir (enumerate directories), runscript (execute shell commands or AppleScript), and peinject (decode and execute arbitrary binaries in memory).
In-memory PE injection means the attackers could load and run any program on a compromised machine without writing it to disk. That's not a credential stealer. That's full remote control.
Who Did It
Google attributed the attack to UNC1069, a financially motivated North Korean threat cluster active since at least 2018. The attribution rests on multiple indicators: WAVESHAPER.V2 is an updated version of malware previously tracked to UNC1069, the C2 infrastructure connects to an AstrillVPN node the group has used before, and the macOS binary contained developer build paths referencing BlueNoroff's "webT" module from the RustBucket and Hidden Risk campaigns of 2023 and 2024.
Microsoft tracks the same group as Sapphire Sleet. CrowdStrike identifies them as Stardust Chollima with moderate confidence.
The Money Pipeline
UNC1069 is one node in a much larger machine. North Korea's cyber operations serve a single strategic purpose: funding its nuclear weapons and ballistic missile programs. The Reconnaissance General Bureau (RGB) runs the whole apparatus. Lazarus Group, BlueNoroff, Sapphire Sleet, Stardust Chollima, whatever naming convention you prefer, they all report to the same command structure.
The numbers are staggering. A UN panel documented approximately $3 billion stolen in 58 suspected cyberattacks on cryptocurrency companies between 2017 and 2023. Then, in February 2025, the Lazarus Group pulled $1.5 billion from Bybit in a single heist, exceeding what they stole in all of 2024 combined. Total estimates now exceed $6 billion over the past decade.
The Axios compromise fits this pipeline. Social engineering an npm maintainer is cheaper and quieter than breaching a crypto exchange directly. Once the RAT is running on developer machines inside financial institutions, defense contractors, or cloud providers, the access can be resold, weaponized for crypto theft, or used for espionage. Same playbook, different entry point.
Four Attacks in Two Weeks
This is the fourth major supply chain compromise targeting open-source infrastructure in the past two weeks, and Laterstack has covered all of them.
On March 19, the threat group TeamPCP hijacked Aqua Security's Trivy vulnerability scanner, rewriting 75 out of 76 version tags to inject credential-stealing malware into CI/CD pipelines worldwide. That attack cascaded downstream through LiteLLM and eventually contributed to a 4TB data breach at AI training vendor Mercor.
On March 25, TeamPCP extended its campaign to Checkmarx's GitHub Actions, compromising KICS and spreading a self-propagating worm across dozens of npm packages.
On March 28, Anthropic's own Claude Code source leaked through npm when unminified internal source was published to the registry without obfuscation. Different kind of failure, same infrastructure.
Now, on March 31, a separate North Korean group used social engineering rather than technical exploitation to achieve a similar result through a different vector entirely.
The pattern is consistent. Attackers are not breaking into systems. They are being let in through trust relationships: trusted maintainers, trusted scanners, trusted dependencies. The infrastructure that modern software depends on is defended by the same human vulnerabilities that every other system is.
What This Means for Everyday People
You probably have never typed npm install axios yourself. But software you use daily almost certainly depends on it. Axios handles HTTP requests for web applications, mobile apps, internal business tools, banking interfaces, healthcare portals. When a library this foundational gets compromised, the blast radius extends far beyond developers.
If you installed or updated any JavaScript project between 00:21 and 03:20 UTC on March 31, your system may have pulled in the compromised version automatically. The malware ran through a postinstall hook, meaning it executed without any user interaction, no prompts, no warnings.
If you're a developer: Check your package-lock.json for axios@1.14.1 or axios@0.30.4. Search your node_modules for plain-crypto-js. If you find either, treat the system as compromised, rotate all credentials, and block sfrclak[.]com and 142.11.206[.]73 at the network level. Saayman's post-mortem outlines the project's remediation steps, including adopting OIDC-based publishing and immutable releases.
If you're everyone else: The takeaway is structural. The open-source libraries that power the internet are maintained by small numbers of people, sometimes one person, who are reachable through normal channels. A convincing Slack message and a fake Teams call were enough to compromise a package that runs in 80% of cloud environments. No amount of code scanning catches a social engineering attack on a maintainer's personal machine.
npm did not have protections in place to prevent a compromised account from publishing a new major version at midnight UTC. That's a policy question, not a technology question. And it's a question that keeps going unanswered while the attacks keep coming.
For inquiries and analysis contact laterstack@proton.me
Anthropic just bought a biotech startup called Coefficient Bio for just over $400 million. The company was eight months old, had fewer than 10 employees, and no publicly known product or revenue. The deal was all stock, reported first by Eric Newcomer and confirmed by The Information and TechCrunch.
If this sounds expensive for a team that could fit in a conference room, keep in mind that Anthropic is currently valued at $380 billion. The deal represented 0.1% dilution. A rounding error. Their VC, Dimension Capital, is claiming a 38,513% internal rate of return on an eight-month investment.
This is the sixth chapter in a story that keeps getting stranger.
What Anthropic Bought
Coefficient Bio was founded in late 2025 by three people who came out of Genentech's computational biology division. Nathan C. Frey, the CTO, was a Group Leader and Principal ML Scientist at Genentech's Prescient Design unit, with 20+ publications in Science Advances and Nature Machine Intelligence and an ICLR Outstanding Paper Award in 2024 for generative modeling in drug discovery. Samuel Stanton, also ex-Prescient Design, led the "lab-in-the-loop" antibody design work that engineered antibodies with 3x to 100x better binding strength across four therapeutic targets. Aris Theologis, the CEO, previously ran business development at Evozyne, an AI protein design company that raised $150 million and partnered with Takeda and NVIDIA.
The stated mission was "artificial superintelligence for science." The platform was designed to draft drug R&D plans, manage clinical regulatory strategies, and identify new drug candidates. Whether any of that existed beyond a pitch deck at the time of acquisition is unclear.
The Pattern
Coefficient Bio is Anthropic's fourth acquisition in eight months.
Humanloop came first in August 2025, an LLM evaluation platform. Then Bun in December 2025, the JavaScript runtime, timed to Claude Code hitting a billion dollars. Vercept followed in February 2026, a computer-use AI startup. Now Coefficient Bio in April.
Four acquisitions. Four completely different sectors. Developer tools, programming infrastructure, computer vision, and now drug discovery. This is not a company sharpening its focus. This is a company expanding in every direction it can find talent worth buying.
The Saga So Far
In February, the Pentagon designated Anthropic a supply chain risk after the company declined to bid on military AI contracts, citing its safety principles. In March, Anthropic sued the Pentagon. Silicon Valley filed amicus briefs in support. A federal judge called the ban "Orwellian." Yesterday, a Congressional letter from Rep. Gottheimer demanded the Pentagon explain its reasoning.
Through all of that, Anthropic kept buying companies. It kept growing. It hit $19 billion in annualized recurring revenue by March. It raised $30 billion in its Series G at a $380 billion valuation. It is reportedly targeting an IPO as early as Q4 2026, potentially raising $60 billion with Goldman Sachs and JPMorgan as lead banks.
The Pentagon blacklist didn't slow anything down. If anything, the lawsuit and the "safety company under siege" narrative made Anthropic more attractive to investors, not less.
The Life Sciences Play
This acquisition didn't come out of nowhere. Anthropic launched Claude for Life Sciences in October 2025, integrating with Benchling, PubMed, and 10x Genomics. In January 2026, it announced Claude for Healthcare, HIPAA-ready tools for medical coding, claims management, and prior authorization. The Coefficient Bio team joins what Anthropic calls its "healthcare and life sciences group."
Drug discovery is a $2.6 billion average cost per approved drug spread across 10 to 15 years. If AI can compress any part of that timeline, the pricing power is enormous. For a company eyeing a $60 billion IPO, "we accelerate drug discovery" is a better investor narrative than "we make a really good chatbot."
What to Sit With
Anthropic has spent the last two months in federal court arguing it is a safety-first company that refuses to compromise its principles for government contracts. That framing earned it a federal injunction, amicus briefs from half of Silicon Valley, and Congressional scrutiny directed at its adversary.
In the same two months, it acquired a computer-use AI company, hit $19 billion in recurring revenue, raised $30 billion at a $380 billion valuation, started planning a $60 billion IPO, and bought a biotech company for $400 million.
None of that is wrong. Companies grow. But at some point the question shifts. Anthropic's safety stance made it the protagonist of this saga. Now the saga is also about a company on a pre-IPO acquisition spree, diversifying into healthcare, defense-adjacent computer use, and drug discovery while telling a federal judge that its identity is defined by restraint.
Both things might be true. But they're getting harder to hold in the same hand.
This is Chapter 6 of Laterstack's ongoing coverage of the Anthropic-Pentagon dispute. Previous chapters: Chapter 1, Chapter 2, Chapter 3, Chapter 4, Chapter 5.
On April 3, OpenAI announced four executive changes in a single day. COO Brad Lightcap was reassigned to "special projects." CMO Kate Rouch is stepping down to fight late-stage breast cancer. Fidji Simo, the CEO of OpenAI's AGI applications division, is taking medical leave for a neuroimmune condition. And CRO Denise Dresser, who joined from Slack less than a year ago, is absorbing Lightcap's commercial portfolio.
This happened at a company valued at $852 billion that closed a $122 billion funding round four days earlier and is reportedly targeting a Q4 2026 IPO at a potential $1 trillion valuation.
The timing alone is the story.
What Actually Happened
Lightcap built OpenAI's business side from almost nothing. He ran commercial operations, partnerships, and revenue since the company was still primarily a research lab. His new role overseeing "complex deals and investments" and a joint venture with private equity firms to sell enterprise software reports directly to CEO Sam Altman. OpenAI framed this as a promotion. In corporate language, "special projects reporting to the CEO" is where operators go when someone else is running operations.
Dresser inherits Lightcap's full commercial scope, minus government and international work (which moved to the strategy org). She was CEO of Slack before joining OpenAI. She is competent. She is also inheriting the revenue engine of the most expensive company on Earth while it prepares for public markets, with less than a year of institutional context.
Simo disclosed she has Postural Orthostatic Tachycardia Syndrome (POTS), a neuroimmune condition she was diagnosed with in 2019 that has worsened. She will be out for "several weeks." During her absence, Greg Brockman, the co-founder who returned to OpenAI in early 2025 after his own extended leave, will manage product.
Rouch was diagnosed with late-stage breast cancer roughly a year and a half ago, shortly after she joined. Former Meta CMO Gary Briggs is stepping in on an interim basis while OpenAI searches for a replacement.
Two of these departures are medical, and nobody reasonable questions someone stepping back for cancer or a neurological condition. But the governance question isn't about empathy. It's about structure. And structurally, OpenAI just lost its COO, its CMO, and the person responsible for its AGI product roadmap in the same 24-hour period.
The Pattern That Won't Break
This is not the first time OpenAI's executive bench has thinned at a critical moment.
In November 2023, the board fired Altman, installed Mira Murati as interim CEO, then reversed course within days after nearly the entire company threatened to leave. Board members Helen Toner and Tasha McCauley were pushed out. Co-founder Ilya Sutskever was removed from the board and eventually left the company entirely in May 2024 to start a competitor.
In September 2024, Murati herself resigned, along with Chief Research Officer Bob McGrew and VP of Research Barret Zoph. By the end of 2024, more than 20 senior people had departed. In 2025, OpenAI lost its chief people officer, its chief communications officer, and at least seven researchers to Meta's Superintelligence Lab.
The executive team that built OpenAI from a research nonprofit into a commercial juggernaut is almost entirely gone. What remains is a roster of external hires brought in during the hypergrowth phase, many with less than 18 months of tenure.
For a normal startup, that might be fine. For a company asking public investors to value it at a trillion dollars, the bench composition matters.
The IPO Math
OpenAI completed its for-profit conversion to a Public Benefit Corporation in late 2025, clearing California regulatory approval. The nonprofit Foundation retains a $130 billion stake and control of the PBC. Public shareholders will hold economic interest but will not control the company.
That governance structure alone is unusual for a company at this scale. Add the executive turnover, and the picture gets harder for underwriters to sell. OpenAI is projected to lose approximately $14 billion in 2026, driven by compute costs, research spending, and infrastructure buildout. The company needs public capital not because it wants it, but because $122 billion in private funding may not be enough to sustain its burn rate.
Investors care about two things in an IPO: the business model and the management team. OpenAI's business model is "spend enormously and grow revenue faster than costs." That is a bet. The management team is now led by Altman, surrounded by relatively new external hires, with key operators either gone or temporarily sidelined.
The bet may still work. But the people making the pitch to Wall Street are not the same people who built the thing.
What This Means for Everyday People
If you use ChatGPT, nothing changes tomorrow. The product works the same regardless of who sits in the C-suite.
But if OpenAI goes public this year, millions of retail investors will be deciding whether to buy shares in a company where the Foundation controls the board, the CEO has survived one coup, the COO just got reassigned, the CMO is fighting cancer, and the AGI product chief is on medical leave. The S-1 filing will contain risk disclosures about "key person" dependencies. Those disclosures will be long.
For the broader AI industry, OpenAI's executive instability reinforces something that Anthropic's own IPO preparations and the U.S. startup funding collapse make clear: the companies building the most powerful technology in history are governed by structures that wouldn't survive a standard corporate audit. The nonprofit that controls OpenAI has a stated mission to benefit "all of humanity." The for-profit arm needs to show Wall Street a path to profitability. Those two mandates will collide in public, under SEC scrutiny, with retail money on the line.
OpenAI may still pull off the biggest tech IPO in history. But the bench it's taking into that process looks thinner than it did a week ago. And the bench was already thin.
For inquiries and analysis contact laterstack@proton.me
On March 31, Iran’s Islamic Revolutionary Guard Corps published a list of 18 American technology companies on its official Telegram channel and announced that each one is now a military target. Apple. Google. Microsoft. Amazon. Nvidia. Intel. Meta. Oracle. Cisco. Dell. HP. IBM. Tesla. Boeing. GE. JPMorgan Chase. Palantir. And one Dubai-based cybersecurity firm, Spire Solutions.
“For every assassination and terrorist act in Iran,” the IRGC wrote, “one facility or unit belonging to these companies will face destruction.”
They gave employees a deadline: April 1, 8:00 PM Tehran time. Evacuate. One-kilometer radius around every facility in the region. Then they started making good on the threat.
This isn’t a cybersecurity story. This is the first war where commercial tech infrastructure is an explicit military target.
The precedent was already set before the list dropped. On March 1, Shahed 136 drones struck three Amazon Web Services facilities in the UAE and Bahrain. 109 AWS services went down across ME-CENTRAL-1, one of the most severe cloud outages in Amazon’s history. Abu Dhabi Commercial Bank, Emirates NBD, First Abu Dhabi Bank, Careem, Snowflake, and 92 SaaS platforms reported disruptions. AWS waived all usage charges for the entire month of March. An unprecedented move, and a quiet admission of the scale.
On April 1, Iran claimed it struck an Oracle data center in Dubai. The UAE says it intercepted incoming missiles and drones but hasn’t confirmed or denied damage. A Bellingcat investigation suggested the UAE has “downplayed damage, mischaracterised interceptions, and in some instances not acknowledged successful Iranian drone strikes.”
On March 11, Iran’s Ministry of Intelligence hit Stryker, the $22.6 billion medical device company, with a different kind of weapon. The Handala Hack Team obtained global administrator access to Stryker’s Microsoft environment and used Microsoft Intune, the company’s own device management platform, to issue remote wipe commands to every enrolled device simultaneously. 200,000 devices across 79 countries. Wiped. No malware. No ransomware. They turned Stryker’s management tools into the weapon.
The real-world cost: Maryland’s LifeNet system went non-functional. LifeNet lets paramedics transmit cardiac data to hospitals in real time so cardiologists can prep catheterization labs before the ambulance arrives. For STEMI heart attack patients, those minutes are the difference between recovery and brain damage. Stryker’s stock dropped 7.6%. The DOJ formally attributed the attack to Iran’s MOIS and seized four Handala domains.
Handala’s stated justification: retaliation for a February 28 missile strike that hit an elementary school in Iran.
The sorting has begun. What makes the IRGC target list historically significant isn’t that Iran threatened American companies. Countries have threatened American interests for decades. It’s that a nation-state published a specific, named list of commercial technology companies and declared them equivalent to military targets. Apple, which makes phones, is on the same list as Boeing, which makes fighter jets.
The logic, from Iran’s perspective, is that there’s no distinction. Reports indicate the U.S. military was running Anthropic’s Claude AI through AWS infrastructure for intelligence operations during the Iran conflict. If Amazon’s cloud powers military AI, is Amazon a tech company or a defense contractor? If Microsoft’s Intune manages military devices alongside Stryker’s medical equipment, is an attack on Microsoft’s infrastructure an attack on healthcare or warfare?
Iran answered that question. Both. The line between commercial and military technology infrastructure no longer exists in their operational calculus.
Who benefits from this. Domestic cloud providers who don’t have Gulf exposure. Cybersecurity firms (every CISO on the planet just got a bigger budget). Sovereign cloud advocates in the EU and Asia who’ve argued for years that depending on American hyperscalers creates geopolitical risk. Defense contractors who already operate under the assumption that their infrastructure is a target.
Who loses. Every Big Tech company with Middle East data center investments. The UAE and Saudi Arabia, whose entire AI ambition depends on hosting infrastructure that is now being bombed. Any company that assumed “we’re not a defense contractor, we’re a tech company” meant something to a country at war. And potentially, your data. If your SaaS provider runs on AWS ME-CENTRAL-1, your uptime now depends on Iranian missile accuracy.
The Strait of Hormuz has been functionally closed since February 28. Twenty percent of the world’s daily oil supply. Brent crude at $126. Asian LNG prices doubled. The energy cost increase hits American data center bills with a 4-8 week lag, which means April and May. The physical attacks and the energy disruption are two fronts of the same strategy: make it expensive and dangerous to operate American technology infrastructure in the region.
Look at who actually got hit and what happened to real people. AWS Bahrain goes down and suddenly Abu Dhabi’s banking system is offline. Careem, the ride-hailing app millions of people across the Middle East use daily, stops working. Stryker gets wiped and paramedics in Maryland can’t transmit cardiac data to hospitals. The LifeNet system that tells a cardiologist “prep the cath lab, the patient is 8 minutes out” goes dark. For a STEMI patient, those minutes are the difference between walking out of the hospital and permanent brain damage.
That’s not a cybersecurity story for IT departments. That’s a Tuesday morning where your banking app doesn’t work, your ride doesn’t show up, and the ambulance carrying your father can’t tell the ER what’s wrong with his heart. The companies on the IRGC’s list aren’t abstractions. They’re the infrastructure underneath daily life for billions of people. When those companies become military targets, everyone downstream becomes collateral damage.
For businesses, the math just changed. If your SaaS runs on AWS ME-CENTRAL-1, your uptime now depends on Iranian missile accuracy. If your medical devices run on Microsoft’s cloud, a wiper attack motivated by a school bombing 6,000 miles away can shut down your hospital’s cardiac emergency system. Every company with Gulf cloud exposure, every hospital using connected medical devices, every business that assumed “we’re not a defense contractor” meant they were safe. That assumption is dead. The question isn’t whether you’re a target. The question is whether you’re downstream of one.
This is the fifth chapter of Laterstack’s ongoing coverage of Anthropic’s collision with the U.S. government. Previous chapters: The Pentagon blacklisting. Silicon Valley’s amicus coalition. The hearing. The “Orwellian” injunction.
On April 2, Rep. Josh Gottheimer (D-NJ) wrote to Anthropic CEO Dario Amodei demanding an explanation for the company’s second major security breach in five days. The letter cited national security risks, questioned why Anthropic had rolled back internal safety protocols, and referenced prior intelligence indicating that a CCP-backed group had previously attempted to compromise Claude.
Five days earlier, on March 31, Anthropic accidentally published the complete source code for Claude Code, its flagship developer tool, to the npm package registry. 512,000 lines of TypeScript across roughly 2,000 files, exposed because of a misconfigured Bun source map. The company rolled back the release, but the code was already cached, forked, and spreading.
That came just three days after March 28, when Anthropic left 3,000 unpublished files in a public database, including references to its unreleased Mythos model.
Two leaks. Five days. And then the supply chain attacks started.
By April 2, trojanized GitHub repositories posing as “leaked Claude Code source” were distributing Vidar infostealer and GhostSocks malware. At least two repos hit 793 forks and 564 stars before detection. That same night, malicious versions of axios (one of npm’s most popular packages with 100+ million weekly downloads) appeared between 00:21 and 03:29 UTC. The trojanized package dropped a remote access trojan that called home to a command server within two seconds of installation. Microsoft Threat Intelligence attributed the attack to Sapphire Sleet, a North Korean state actor. Claude Code lists axios as a direct dependency. SANS called it “among the most operationally sophisticated supply chain attacks ever documented against a top-10 npm package.”
Then Anthropic made it worse. The DMCA takedown they filed against GitHub repositories sharing the code accidentally removed 8,100 repositories, including legitimate forks of Anthropic’s own public Claude Code repo. Boris Cherny, Anthropic’s head of Claude Code, said: “Our deploy process has a few manual steps, and we didn’t do one of the steps correctly.” That sentence applies to more than the DMCA.
The weaponization speed is the story. Anthropic leaked source code on a Monday night. By Wednesday morning, there were established malware campaigns with hundreds of forks exploiting the exposure. That gap is measured in hours, not weeks.
Gottheimer’s letter asks the right question the wrong way. The congressman wants to know why Anthropic rolled back safety protocols and whether the leaks create national security risks. These are legitimate questions. But framing this as “Anthropic is reckless” misses the structural problem.
Anthropic built its entire brand on being the safety-first AI company. That positioning got them blacklisted by the Pentagon, which wanted compliance, not caution. It got them sued by the government. It got them defended by Silicon Valley competitors who recognized that if the Pentagon could punish one company for prioritizing safety, every company was exposed.
Now the safety brand is cracking. Not because Anthropic suddenly became careless. Two accidental leaks in five days suggests a systemic issue in their deployment and data hygiene processes, but it’s not malice. The crack is in the narrative. The company that positioned itself as the responsible steward of dangerous technology just demonstrated, twice, that it can’t secure its own codebase.
Who benefits from this. OpenAI, which has carefully positioned itself as the Pentagon-friendly alternative. Every enterprise customer evaluating Anthropic now has a new risk factor to weigh. Defense-oriented AI startups like Edgerunner and Palantir that train on classified data in secure environments, the exact opposite of accidentally publishing source code to npm. And the Pentagon, which spent months arguing that Anthropic couldn’t be trusted with sensitive infrastructure. The leaks don’t prove the Pentagon was right about the blacklisting. But they make it harder to argue the Pentagon was wrong about the risk assessment.
Who loses. Anthropic’s IPO timeline just got more complicated. Institutional investors pricing a $350-380 billion valuation with a potential Q4 2026 listing are now asking questions about operational security that didn’t exist two weeks ago. The broader AI safety movement loses credibility because its most prominent institutional advocate just demonstrated that “safety-first” doesn’t extend to basic code deployment hygiene. And every enterprise customer running Claude in a sensitive environment is recalculating their risk exposure.
Gottheimer’s letter mentions the upcoming Mythos model. He’s worried about what happens when a more powerful model ships from a company that accidentally publishes its current model’s source code. That’s a fair concern. But the deeper question is whether “safety” was ever the right frame for what Anthropic is actually doing.
Anthropic is an AI company trying to build the most powerful models possible while convincing the public and the government that it’s doing so responsibly. The Pentagon wants those models without the safety restrictions. Congress wants the safety restrictions without the security failures. Enterprise customers want both. And Anthropic, caught between all three, keeps tripping over its own infrastructure.
“No customer data was exposed” is doing a lot of heavy lifting in Anthropic’s response. As if that’s the bar. 512,000 lines of proprietary source code, including anti-distillation defenses and unreleased feature flags, hit the public internet. North Korean state actors had a weaponized supply chain attack running within hours. GitHub repos distributing malware under Anthropic’s name racked up nearly 800 forks before anyone caught it. And the company’s position is that this wasn’t a security breach because no customer credentials leaked.
That framing ignores what actually matters. Enterprise customers aren’t just evaluating whether their data was exposed today. They’re evaluating whether Anthropic’s operational security is reliable enough to trust with tomorrow’s data. Every CISO renewing a Claude contract is now running a risk assessment that didn’t exist two weeks ago. Consumer confidence erodes the same way. If the company that markets itself as the careful one can’t manage its own deploy pipeline, what does “careful” mean?
The policy implications are worse. Congress is already asking whether AI companies can be trusted to self-regulate safety. Anthropic was the industry’s best argument that the answer was yes. Two leaks in five days, a DMCA blunder that nuked 8,100 repos, and a safety pledge quietly downgraded to “nonbinding” in the same quarter. That’s the ammunition every AI regulation advocate just got handed for free. The next time someone in Congress proposes mandatory security audits for frontier AI companies, Anthropic’s own track record will be Exhibit A.
Anthropic did not respond to a request for comment.
Every quantum computing company on the planet is racing to add more qubits. More qubits, bigger announcements, higher stock prices. IBM just crossed 1,000. Google claims 105. The press releases write themselves.
But qubit counts don’t matter if the qubits don’t work.
A small Dutch company called QuiX Quantum just demonstrated something that matters more than any qubit milestone this year. They achieved the first below-threshold error mitigation ever recorded on a photonic quantum computer. Their research, conducted in collaboration with NASA’s Quantum AI Lab and Germany’s Freie Universitat Berlin, showed their 20-mode photonic processor can remove more errors than it introduces while still running computation. That’s the definition of “below threshold.” And it’s the single most important prerequisite for any quantum computer to actually scale.
Why this is the barrier that matters. Quantum computers are fragile. Every operation introduces noise. The act of fixing errors introduces more noise. If the error correction process creates more problems than it solves, you’re running on a treadmill. You can add qubits forever and never get anywhere useful. Getting below threshold means you’ve broken the cycle. You can now, in theory, build upward.
Google demonstrated this in superconducting systems with their Willow chip in late 2024. IBM has shown similar progress. But both approaches require cooling hardware to 15 millikelvins, colder than outer space, using dilution refrigerators that cost millions and fill entire rooms.
QuiX’s photonic processor is a silicon nitride chip a few centimeters across. It operates primarily at room temperature. No cryogenics. Compatible with standard data center infrastructure and fiber optic networks. The 20-mode processor uses 66 programmable interferometric cells and 132 phase actuators to manipulate single photons.
The technique is called photon distillation. Instead of computing with noisy qubits and trying to fix the errors afterward (the superconducting playbook), photon distillation cleans up the photons before computation starts. It uses quantum interference among multiple imperfect photons to project them into purified states. Think of it as filtering the water before it goes into the engine, rather than trying to extract the dirt after it’s already circulated.
The results: a 2.2x reduction in photon indistinguishability errors and a 1.2x net error reduction after accounting for the noise the distillation process itself adds. Chief Scientist Jelmar Renema put it plainly: “For any quantum computer modality to scale, you have to prove you can remove more error than you add while the computer is still able to run, and that’s what we’ve shown here.”
Who benefits, who loses. The entire photonic quantum ecosystem gets a credibility boost. Xanadu, PsiQuantum, ORCA Computing, Quandela. All of them are building on the premise that photons can compete with superconducting qubits. QuiX just gave that premise its strongest experimental evidence.
The superconducting camp (IBM, Google) doesn’t “lose” exactly. They’re further ahead in total qubit count and have more mature error correction. But the cost argument just shifted. If photonics can achieve fault tolerance without cryogenics, the total cost of ownership comparison changes fundamentally. A quantum computer that runs at room temperature on a chip you can manufacture with existing CMOS processes is a very different economic proposition than one that requires a dedicated cooling facility.
QuiX is a 2019 spin-off from the University of Twente’s MESA+ Institute. They’ve raised about €20.5 million, including a €15 million Series A last year. They have between 11 and 50 employees and a cloud access platform called Bia. Their roadmap targets a first-generation universal single-photon quantum computer in 2026 and a 64-qubit fault-tolerant version by 2027.
The Netherlands Ministry of Defense partially funded this research through its Purple NECtar Quantum Challenges initiative. That funding source tells you something about who considers photonic quantum computing strategically important.
What matters here isn’t the qubit count race. It’s whether the fundamentals actually work. IBM can announce 1,000 qubits tomorrow and it means nothing if those qubits can’t hold a coherent state long enough to compute. QuiX just proved that their approach can clean errors faster than it creates them. That’s the only metric that matters for getting from “interesting physics experiment” to “machine that solves real problems.”
For policy, this shifts the conversation. Governments funding quantum programs (the Netherlands, the UK with their £2 billion commitment, the US through CHIPS Act adjacent spending) now have empirical evidence that photonics is a viable path, not just a theoretical one. That changes procurement decisions. It changes which companies get defense contracts. It changes how the EU positions itself in a race it’s been losing to the US and China. The Dutch Ministry of Defense funded this research for a reason.
For markets, the photonic quantum companies (Xanadu at IPO stage, PsiQuantum with nearly a billion in funding) just got their thesis validated by someone else’s hardware. Investors who’ve been skeptical of photonics because “superconducting is further ahead” now have to reckon with the cost argument. A room-temperature chip manufactured with existing CMOS processes versus a cryogenic facility that costs millions to maintain. If both approaches reach fault tolerance, the economics aren’t close. The cheaper one wins. And QuiX just took a real step toward proving the cheaper one works.
On March 30, Y Combinator CEO Garry Tan posted on X that he was on a 72-day shipping streak. Five projects. 37,000 lines of code per day. All generated with Claude Code, part-time, while running the most influential startup accelerator on the planet.
600,000 lines in 60 days. The numbers sound like a flex. They were meant to be.
Then a Polish senior software engineer named Gregorein looked at one of those projects. Tan’s personal blog. 78,400 lines of AI-generated code. The site makes 169 server requests totaling 6.42 megabytes to load a page. For comparison, Hacker News (which Tan’s company owns) makes 7 requests totaling 12 kilobytes. Tan’s blog is 535 times heavier than the site his own company runs.
The audit found uncompressed PNG images approaching 2 megabytes each when 300 kilobytes would do. A rich-text editor loaded on a read-only page. An empty CSS file. Analytics code designed to dodge ad blockers. Missing image alt text. Duplicate page content.
“Bloat, waste, and rookie mistakes,” Gregorein wrote.
The word for this is AI slop. And the person producing it runs the institution that decides which startups get funded.
The productivity illusion. Lines of code is the wrong metric and everyone in engineering knows this. A senior developer who writes 50 lines that solve a hard problem cleanly created more value than 50,000 lines of scaffolding that nobody asked for. The best code is often code you delete.
But AI coding tools measure their own value in volume. Anthropic’s Claude Code tracks tokens generated. GitHub Copilot measures acceptance rates. The incentive structure rewards output, not quality. When the CEO of YC tweets his line count as proof of productivity, he’s not just wrong about engineering. He’s setting the cultural standard for an entire generation of founders who look to him for signals about what “building” means.
At SXSW earlier in March, Tan told an audience he has “cyber psychosis” and sleeps only 4 hours a night because he’s so excited about AI agents. The crowd laughed. It wasn’t a joke.
The real debate underneath this. The backlash against Tan isn’t really about his blog. It’s about what “vibe coding” means for the profession. Tan open-sourced gstack in March, a collection of Claude Code skills that structure the AI to act like different members of a software team. It got 20,000 GitHub stars. Critics said it was a collection of prompts in a text file that only went viral because the YC CEO posted it. Supporters said it was a practical starter kit for AI-assisted development.
Both are right. And that’s the tension. AI coding tools genuinely accelerate certain tasks. Config files, boilerplate, CRUD operations, test scaffolding. Experienced developers who know what they want can use these tools to move faster without sacrificing quality. The tools aren’t the problem.
The problem is when volume becomes the metric. When “37,000 lines a day” becomes the thing you brag about. When the CEO of the most important startup institution in tech is optimizing for output instead of outcome. That cultural signal propagates. YC founders are watching. They’ll build the way their role model builds.
Who benefits from the vibe coding narrative. AI tool companies, obviously. Anthropic, GitHub, Cursor, Replit. Every line of AI-generated code is a data point in their growth story. VCs who need the “10x developer” narrative to justify smaller engineering teams at portfolio companies. Founders who want to believe they can ship a product without hiring engineers.
Who loses. Junior developers who can’t get hired because founders think Claude can do their job. Senior developers who have to maintain the 78,000-line blogs. Users who load a 6.4 megabyte page to read a 500-word blog post. And eventually, the startups that ship AI slop to production, realize their codebase is unmaintainable, and have to hire the engineers they thought they’d replaced.
The question nobody at SXSW asked Tan: if you’re running 5 projects on 4 hours of sleep with AI writing all the code, who is reading the code? Who is reviewing the 37,000 lines before they ship? Who catches the empty CSS file, the bloated images, the ad-blocker-dodging analytics?
Nobody. That’s the answer. And that’s the problem.
There’s a difference between using AI to build real products and using AI to produce the appearance of building. Productive AI coding looks like this: you have a clear spec, you use the tool to iterate fast, you review what it generates, you ship something that works, then you refactor. The code gets better over time because a human with judgment is steering the process. The output is a product, not a line count.
AI slop looks like what Gregorein found on Tan’s blog. 78,000 lines that nobody reviewed, nobody refactored, nobody questioned. A rich-text editor on a read-only page. Analytics designed to dodge ad blockers. Images that are 7x larger than they need to be. The tool generated it, so it shipped. Volume as a substitute for judgment.
The problem is that Tan isn’t just some guy building a bad blog. He’s the CEO of Y Combinator. When he tweets his line count, investors listen. When he demos “vibe coding” at SXSW, founders copy it. The hype around AI-generated code is already distorting how VCs evaluate technical teams. “We don’t need engineers, we have Claude” is a pitch that’s landing in actual boardrooms. And the evidence these investors are seeing for it is a 6.4 megabyte blog from the most influential person in startups.
For policy, this is the leading edge of a question regulators haven’t figured out yet: when AI-generated code ships to production at scale, who is accountable for what it does? If Tan’s blog has analytics designed to dodge ad blockers, is that a conscious choice or something the AI generated and nobody reviewed? When AI-generated code ends up in medical devices, financial systems, or critical infrastructure (and it will), the accountability gap between “a human wrote this” and “an AI generated this and nobody checked” becomes a regulatory problem. The vibe coding movement is creating technical debt at a pace the industry has never seen. Someone will pay for that. The question is whether it’s the engineers who inherit the codebase, the users who load the 6.4 megabyte page, or the investors who funded the hype.
Three independent research teams, working on three separate continents, just published papers that converge on the same conclusion: breaking RSA-2048 encryption requires dramatically fewer physical qubits than anyone estimated five years ago. The trajectory is exponential, and nobody in the cryptography community is calling it theoretical anymore.
The progression tells the story. In 2012, estimates for cracking RSA-2048 ran from hundreds of millions to roughly one billion physical qubits. In 2019, Google Quantum AI researcher Craig Gidney estimated 20 million qubits. In May 2025, Gidney published updated findings showing it could be done with fewer than one million noisy physical qubits in under a week, a 20-fold reduction achieved entirely through algorithmic improvements, not hardware advances.
Then in February 2026, Sydney-based startup Iceberg Quantum unveiled its Pinnacle architecture. Using quantum low-density parity-check (QLDPC) codes instead of traditional surface codes, the team showed that RSA-2048 factoring could theoretically be achieved with fewer than 100,000 physical qubits. Another tenfold reduction. The accompanying $6 million seed round validated that investors took the math seriously.
The third paper landed in March 2026. Google Quantum AI, collaborating with the Ethereum Foundation and Stanford researchers, proposed breaking the elliptic curve cryptography that protects Bitcoin and Ethereum with fewer than 500,000 physical qubits in minutes rather than days. Google made an unprecedented decision: it withheld the actual attack circuits and released only a zero-knowledge proof of validity. The researchers were confident enough in the results that they treated the work as a security risk worth managing, not a theoretical exercise worth publishing freely.
Three papers. Three different qubit architectures. Three independent sets of assumptions. All pointing the same direction. The floor is dropping, and the pace is accelerating.
The policy response is already in motion, which is itself a signal. The NSA’s CNSA 2.0 framework mandates that all new national security systems be quantum-safe by January 2027. NIST finalized its post-quantum cryptography standards in August 2024. The FBI, NIST, and CISA collectively designated 2026 the “Year of Quantum Security.” Google set an internal 2029 deadline for complete post-quantum migration. When the agencies responsible for protecting classified communications start setting hard deadlines, they are working from intelligence assessments the public does not see.
Ethereum researcher Justin Drake, a co-author on the Google paper, called it “a monumentous day for quantum computing and cryptography.” He estimates at least a 10% probability that a quantum system could recover a private key by 2032. That may sound small. It is not. A 10% chance that the encryption protecting global financial infrastructure could be broken within six years is the kind of risk that moves policy. And governments are moving.
There are caveats worth noting. Iceberg’s results are simulations, not experimental demonstrations. QLDPC codes require qubit connectivity that has not been demonstrated at scale. Google’s paper covers elliptic curve crypto (relevant to cryptocurrency), not RSA directly. And none of these papers account for the engineering challenges of building and operating a quantum computer at the required scale with the required error rates. The math is ahead of the hardware. It has always been ahead of the hardware. But the gap is narrowing.
Laterstack has covered Iceberg’s Pinnacle architecture, Google’s 2029 PQC deadline, and the wave of quantum companies going public over the past two months. Each of those stories was a data point. This article is the trend line. When three teams, independently and within months of each other, converge on the same conclusion, it stops being a research curiosity. It becomes a planning horizon.
What This Means for Everyday People
The encryption protecting your bank account, your emails, your medical records, and your cryptocurrency was designed for a world where breaking it required billions of qubits and decades of patience. That assumption is being revised downward at an accelerating rate. You will not need to do anything immediately. But if your organization stores sensitive data that needs to remain confidential into the 2030s, the window to begin transitioning to post-quantum cryptography is now. Not when Q-Day arrives. Now. Because by the time the threat is confirmed, the data that was already intercepted and stored will be the first to fall. The intelligence community calls this “harvest now, decrypt later.” If you understand that phrase, you understand the urgency.
A phishing campaign is using spoofed LinkedIn message notifications to redirect professionals to a pixel-perfect fake login page, where their credentials are harvested the moment they type them in. The Cofense Phishing Defense Center identified the campaign, which exploits the one thing every LinkedIn user does without thinking: clicking on a message notification.
The attack is simple and effective. Targets receive an email that looks identical to a standard LinkedIn message alert, complete with branding, layout, and a notification about a new job opportunity or connection request. The email contains buttons like “View Message” that redirect to inedin.]digital, a domain [registered only two months ago and not affiliated with LinkedIn in any way. The name was chosen deliberately. “inedin” contains the same letter patterns as “LinkedIn,” close enough to pass a quick glance from someone checking notifications between meetings.
The landing page is a near-exact replica of LinkedIn’s login screen. Same layout. Same colors. Same input fields. Once a user enters their email and password, the credentials go directly to the attackers. Cofense’s Senior Director of the Phishing Defense Center described the campaign as a “troubling evolution in social engineering tactics, where attackers embed themselves directly into trusted digital spaces.”
This is part of a pattern that keeps expanding. Over the past two months, Laterstack has covered stolen source code turned into active exploits, security scanners weaponized against the people who use them, and supply chain attacks targeting developer tools. The throughline is the same. Attackers are not breaking through walls anymore. They are walking through doors that look exactly like the ones you use every day. The tools and platforms professionals trust, LinkedIn notifications, GitHub Actions, security scanners, are becoming the attack surface itself.
LinkedIn is a particularly effective target because the behavior it exploits is automatic. Professionals check message notifications without scrutinizing the sender domain. The emails arrive mixed in with real LinkedIn traffic, making them harder to flag. And unlike phishing emails that impersonate a bank or shipping company, LinkedIn notifications carry professional stakes. A job opportunity or connection request creates urgency that bypasses the half-second of skepticism that might save someone from clicking.
What This Means for Everyday People
If you use LinkedIn, treat every email notification with suspicion until you verify it. Do not click “View Message” from an email. Open LinkedIn directly in your browser or app and check your messages there. Look at the sender domain before clicking anything. The real LinkedIn sends notifications from @linkedin.com, not from look-alike domains ending in .digital, .online, or .info. Enable two-factor authentication on your LinkedIn account. It will not stop you from entering your password on a fake page, but it adds a layer that makes stolen credentials harder to use.
The broader problem is that professional networks have become one of the most productive attack surfaces in cybersecurity. The more you trust the platform, the less you question the notification. That is exactly what the attackers are counting on.