OkCupid handed nearly three million user photos to Clarifai, a facial recognition company, along with demographic information and location data. No user consent. No opt-out. No contractual restrictions on how the images could be used. The arrangement started in September 2014 when Clarifai’s founder requested the data directly, and OkCupid handed it over because its own founders were financial investors in Clarifai.
The Federal Trade Commission announced on March 30 that it settled the case against Match Group Americas and its subsidiary Humor Rainbow, Inc. (which operates OkCupid). The penalty for a decade of deception, active concealment from media, and obstruction of a federal investigation: zero dollars.
The settlement requires OkCupid to stop misrepresenting its privacy practices and submit compliance reports for 10 years. That is the entire enforcement action. No admission of wrongdoing. No monetary fine. An OkCupid spokesperson told reporters that the alleged conduct “does not reflect how OkCupid operates today.”
The timeline makes the settlement feel even worse. The data sharing happened in 2014. The New York Times exposed it in 2019. The FTC filed a petition demanding documents in May 2022. And in March 2026, twelve years after the violation and four years after the investigation began, the resolution is a promise to file paperwork. Match Group’s portfolio includes OkCupid, Tinder, Hinge, and dozens of other dating platforms that collectively hold some of the most intimate personal data on the internet. Selfies, sexual orientation, location history, conversation logs. All of it sitting behind privacy policies that, in OkCupid’s case, the company itself was violating.
What makes this a structural failure rather than a company-specific scandal is the enforcement mechanism. The FTC cannot impose civil penalties on first-time privacy violators under its current authority. That is not a bug. That is the design of US privacy law. A company can share your most intimate photos with an AI firm, lie about it for a decade, obstruct the federal investigation, and the maximum consequence is a consent decree that says “please don’t do it again.” The punishment for getting caught is supervision. Not cost.
This is the same pattern playing out across technology right now. A jury in another courtroom is deciding whether Instagram was deliberately designed to be addictive. Platform companies build their business on user trust, extract maximum value from personal data, and face regulatory consequences so light that the violation is effectively free. The FTC’s own enforcement tools are not built for the scale of the problem. When a company operating dozens of dating apps across hundreds of millions of users can settle a biometric data case for zero dollars, the message to every other platform is clear: the fine for violating your users’ privacy is less than the value of what you took.
What This Means for Everyday People
If you have ever used OkCupid, your photos may have been sent to a facial recognition company over a decade ago. There is no mechanism to find out whether your specific data was included in the transfer to Clarifai, and the settlement does not require notification to affected users.
More broadly, your dating app data, the photos, the preferences, the location history, is among the most sensitive information you produce online. The privacy policies protecting it are only as strong as the enforcement behind them. Right now, that enforcement amounts to a promise to file compliance reports. If that bothers you, the problem is not OkCupid. It is the absence of a federal privacy law with actual teeth.
Quantum computing has a dirty secret that the industry would prefer you not dwell on. Every qubit you have ever read about in a press release is a physical qubit. And physical qubits are unreliable. They lose their quantum state constantly. They produce errors at rates that make real computation impossible. The entire field has spent decades trying to solve a single problem: how do you build qubits that actually work long enough to be useful?
Quantinuum just posted the most convincing answer anyone has produced so far.
In a paper published on arXiv in late February, Quantinuum researchers demonstrated quantum computations using up to 94 error-protected logical qubits on the company’s 98-qubit Helios trapped-ion processor. The logical gate error rates hit roughly one error in 10,000 operations, significantly lower than the raw error rates of the physical hardware underneath. They also ran 48 fully error-corrected logical qubits using a more robust encoding scheme. Both results cleared “beyond break-even,” meaning the error protection actually improved computation accuracy instead of degrading it.
That last part is the important part. For years, adding error correction to quantum computers made them worse. The overhead of monitoring and fixing errors consumed more resources than it saved. Beyond break-even is the threshold where the protection starts paying for itself. Quantinuum crossed it with 94 qubits. Nobody else has done that at this scale.
How They Did It
The technique relies on something called iceberg codes, named because most of the structure sits below the surface. In the simplest version, just two extra monitoring qubits watch over the entire logical system. That is absurdly efficient. Traditional quantum error correction codes require massive overhead, sometimes 1,000 physical qubits per logical qubit. Iceberg codes achieved a physical-to-logical ratio near 1:1 for error detection and roughly 2:1 for full error correction.
The reason Quantinuum can pull this off is their trapped-ion architecture. Unlike superconducting qubits (Google, IBM), trapped ions can connect to any other ion in the processor. That all-to-all connectivity lets you implement error correction schemes that would be physically impossible on a chip where qubits can only talk to their neighbors. It is a genuine architectural advantage, not marketing.
To prove the system works on something real, the team ran a quantum simulation of the three-dimensional XY model of quantum magnetism using 64 error-detected logical qubits. They also generated a 94-logical-qubit GHZ entangled state with 94.9% fidelity. These are not toy demonstrations. They are the kind of computations that will eventually underpin drug discovery, materials science, and cryptographic analysis when the qubit counts get large enough.
Where This Sits in the Race
Quantinuum is not the only company making progress on error correction. Google’s Willow chip, announced in December 2024, demonstrated that errors could be reduced exponentially as qubit counts increased, a result the field calls going “below threshold.” That was a milestone. But Willow is a 105-qubit superconducting chip. Google showed the principle works. Quantinuum showed it works on computations with 94 logical qubits that outperform the raw hardware. Those are different claims.
IBM has published its own fault-tolerant roadmap centered on the Quantum Starling system, targeted for 2029, which would feature 200 logical qubits running 100 million error-corrected operations. That is ambitious. It is also three years away.
IonQ, Quantinuum’s closest competitor in trapped-ion technology, is working toward 256-qubit systems in 2026 and has posted strong qubit performance numbers from R&D prototypes. But IonQ has not published a comparable logical qubit demonstration at this scale. The company also carries baggage from a Wolfpack Research short report alleging that most of its revenue came from Pentagon contracts that were subsequently canceled. IonQ disputes the allegations. The uncertainty remains.
The competitive picture is messy, but one pattern is clear. The companies that can demonstrate fault-tolerant operations (not just promise them on a roadmap) are separating from the pack. Quantinuum just put up the strongest logical qubit numbers in the industry.
Follow the Money
None of this exists in a vacuum. Quantinuum filed a confidential S-1 with the SEC on January 14, beginning the formal process for what would be the first traditional quantum computing IPO. Every other quantum company that went public (IonQ, D-Wave, Rigetti) used SPAC mergers, which let them project future revenue without the scrutiny of a full SEC registration. Quantinuum is betting its financials can withstand that scrutiny.
The last private round valued the company at $10 billion, with a $600 million raise drawing in NVIDIA NVentures, JPMorgan, and Amgen. The IPO is expected to target $20 billion and raise roughly $1 billion. Honeywell retains a 54% majority stake and provides the manufacturing backbone that no pure-play startup can replicate.
The timing of this research paper is not accidental. You publish your best results when you need the market to pay attention. An IPO roadshow goes better when you can say “we just ran 94 logical qubits beyond break-even” than when your last headline is six months old.
Governments are paying attention too. The UK just committed £2 billion to quantum computing procurement and scale-up, targeting operational infrastructure by the early 2030s. Quantinuum, formed from the merger of Honeywell Quantum Solutions and Cambridge Quantum, has deep UK roots. That £2 billion is not earmarked for Quantinuum specifically, but the company is positioned to capture a significant share of it.
What It Actually Means
Ninety-four protected logical qubits is a genuine engineering milestone. It is also not commercially useful scale. Real applications in cryptography, pharmaceutical modeling, and financial simulation need error-corrected systems orders of magnitude larger. The qubit count needs to grow. The error rates need to drop further. The cost per operation needs to come down.
But the math is starting to work. For the first time, encoding qubits in error-protecting schemes makes computation better instead of worse, at a scale that is not trivial. That is the inflection point the entire field has been waiting for.
Whether $20 billion is the right price for that inflection point depends on how fast the next steps come. Quantinuum says it will deliver universal, fully fault-tolerant quantum computing by 2029. If they are right, this valuation looks cheap. If the timeline slips, investor patience will be tested against Honeywell’s willingness to keep writing checks.
Ninety-four logical qubits. One error in 10,000 operations. The physics is cooperating. Now comes the hard part: turning physics into a product someone will pay for.
—
For inquiries and analysis contact laterstack@proton.me
Thirty thousand Oracle employees woke up to a termination email at 6 AM this morning. No meeting with their manager. No phone call from HR. A mass email from “Oracle Leadership,” sent across time zones simultaneously, with immediate system access revocation and a final working day of today.
TD Cowen estimates the cuts hit between 20,000 and 30,000 workers, roughly 18% of Oracle’s 162,000 person global workforce. The Revenue and Health Sciences (RHS) and SaaS and Virtual Operations Services (SVOS) divisions took the heaviest damage, with reductions of at least 30%. Employees across the United States, India, Canada, and Mexico confirmed the cuts in real time through Reddit’s r/employeesOfOracle and the anonymous professional forum Blind.
The math behind the decision is straightforward. Oracle has committed to $156 billion in AI infrastructure spending, according to TD Cowen’s analysis. The company raised between $45 billion and $50 billion in debt and equity financing this year alone for Oracle Cloud Infrastructure expansion. The layoffs are expected to free up $8 billion to $10 billion in annual cash flow, money that goes directly into data center construction for its OpenAI partnership and broader AI buildout. A $2.1 billion restructuring charge was already disclosed in Oracle’s March 2026 10-Q SEC filing, with $982 million recorded in the first nine months of fiscal 2026.
Here is what makes this difficult to stomach. Oracle is not a company fighting for survival. Last quarter, net income hit $6.13 billion, a 95% increase. Remaining performance obligations, the contracted future revenue already on the books, stood at $523 billion, up 433% year over year. Oracle’s stock rose 3% on the news. Wall Street did not punish them. It rewarded them.
This is the human invoice for artificial intelligence. A company posting record profits just eliminated 18% of its workforce through an automated email because the money is worth more in silicon than in salaries. No warning from a direct manager. No human conversation. A 6 AM notification and a badge that stops working by end of business. For a company sitting on $523 billion in contracted revenue, handling it this way is not restructuring. It is a statement about where people rank in the priority stack of the AI infrastructure arms race.
The standard defense writes itself. Every technology transition displaces workers, and AI data centers create downstream jobs in construction, cloud operations, and tooling. Short term pain, long term growth. Capital goes where it generates the most return.
That argument holds up when a struggling company pivots to survive. It falls apart when the company doing the firing just posted a 95% profit increase. This is not survival. This is a profitable machine deciding that compute capital is worth more than human capital, and 30,000 people are the rounding error in that equation. The trend is accelerating across the industry, and Oracle is not an outlier. It is a preview.
What This Means for Everyday People
If you work at a large technology company, pay attention to your employer’s AI infrastructure spending. When the capital expenditure numbers start climbing into the hundreds of billions, the headcount numbers start moving the other direction. Oracle did not invent this trade. It just executed it more bluntly than most. The companies that give you six months of warning are being generous. Oracle gave people a 6 AM email on a Tuesday morning. The ones who will do it next are already running the same math.
Oracle has not publicly commented on the layoffs. The emails went out. The badges stopped working. The stock went up 3%.
A physicist from IBM and a computer scientist from the University of Montreal just won the A.M. Turing Award, computing’s equivalent of the Nobel Prize. Charles H. Bennett and Gilles Brassard share the $1 million prize, funded by Google, for “their essential role in establishing the foundations of quantum information science and transforming secure communication and computing.”
It is the first time in the award’s 59-year history that the ACM has given its highest honor for work rooted in quantum physics. That alone is a milestone. But the timing makes it something else entirely.
A Protocol Born in the Ocean
The origin story is almost too good. In October 1979, Bennett swam up to Brassard at a beachfront hotel in Puerto Rico and started talking about quantum money. His friend Stephen Wiesner had invented a theoretical scheme for unforgeable banknotes using quantum mechanics. Brassard, by his own account, was “trapped, so I listened politely.” Within ten minutes, they had the seed of their first paper.
Five years later, that poolside conversation became BB84, the first practical protocol for quantum cryptography. The idea: two parties can establish a shared encryption key using photons, with security guaranteed not by the difficulty of a math problem, but by the laws of physics. Any eavesdropper disturbs the quantum states, leaving detectable traces before any information is compromised. No assumptions about computational power. No algorithm an attacker could eventually crack. Physics as a security guarantee.
In 1993, Bennett, Brassard, and four collaborators demonstrated quantum teleportation, transmitting a quantum state between particles using entanglement and classical communication. Not matter. Information. Then in 1996, they introduced entanglement distillation, a method for strengthening imperfect entanglement into the high-fidelity version needed for scalable quantum networks. Each of these contributions didn’t just advance a field. They helped create it.
John Preskill at Caltech told Quanta Magazine that Bennett and Brassard “helped to set the culture for this group, which was kind of on the fringes of both physics and computer science.” Scott Aaronson at UT Austin put it more bluntly: “They were there since before quantum computing was even a field.”
Why Now
Forty-two years passed between BB84 and this Turing Award. That delay is the interesting part.
Bennett and Brassard’s work has been foundational since the 1980s. Variants of BB84 already run in operational quantum communication networks worldwide, through fiber optics and satellite links. China launched a quantum-encrypted satellite in 2016 using principles that trace directly back to their protocol. This was not obscure work waiting to be discovered. Everyone in the field knew.
So why did the Turing Award committee pick 2025, with the announcement coming in March 2026?
The United Nations designated 2025 as the International Year of Quantum Science and Technology, marking 100 years since quantum mechanics took shape. That’s the official backdrop. But the unofficial one is more telling: quantum computing just became a real financial market.
Quantinuum filed a confidential S-1 in January seeking a valuation north of $20 billion. Xanadu started trading on Nasdaq on March 27 after its $302 million SPAC closed. Horizon Quantum Computing went public the same week, raising $120 million. IonQ posted $130 million in 2025 revenue, a 202% year-over-year jump, with 2026 guidance between $225 and $245 million. The UK pledged £2 billion for quantum innovation. Canada is negotiating up to CAD$390 million for Xanadu alone. PitchBook reports that Infleqtion, IQM, and Pasqal are all pursuing public listings this year.
Awards committees don’t operate in a vacuum. The Turing Award recognizing quantum information science while billions of dollars flow into quantum companies is not a coincidence. It’s a legitimization event.
What the Award Actually Does
Bennett and Brassard don’t need the validation. Their work speaks for itself and has for decades. But the industry around them does need it.
Quantum computing occupies a strange position in the technology economy. Companies are going public with $10 billion to $20 billion valuations. Governments are writing nine-figure and ten-figure checks. Wall Street analysts are publishing price targets. And none of these companies have demonstrated commercial quantum advantage over classical computers. The entire sector is priced on a bet that fault-tolerant quantum computers will work, that the timeline will be years and not decades, and that these specific companies will be the ones that capture the value when it happens.
A Turing Award for the theoretical work underneath all of that money carries weight. It says to the broader computer science community: quantum information science is real computer science, not speculative physics. It says to policymakers writing billion-dollar checks: the academic foundation is solid enough for the most prestigious prize in the field. It says to public market investors: the technology these companies are trying to build rests on Nobel-caliber ideas.
Science Magazine called it “computer science’s Nobel Prize goes quantum.” That framing does work for everyone involved. The ACM gets credit for recognizing a transformative field. The quantum industry gets another credibility marker. The scientists get long-overdue recognition.
Whether the companies building on Bennett and Brassard’s ideas can actually deliver commercially useful quantum computers remains an open question. BB84 works. Quantum teleportation has been demonstrated. The physics is sound. The engineering is the hard part, and billions of dollars of public market capital are now riding on how fast that engineering matures.
A poolside conversation in Puerto Rico, 47 years ago, started something that now moves markets. The Turing Award arriving in the same month as multiple quantum IPOs is the kind of timing that tells you where a field thinks it is in its own story. Whether the story holds up is another matter entirely.
—
Lamar covers quantum computing, enterprise tech, and the systems that shape how power and technology interact. Follow Laterstack for critical analysis of the stories that matter.
Anthropic shipped a debugging file in a production npm package on March 31, 2026, exposing 512,000 lines of Claude Code source code to anyone paying attention. Security researcher Chaofan Shou found a 59.8 megabyte source map file inside version 2.1.88 of the `@anthropic-ai/claude-code` package. Within hours, the entire codebase was archived across multiple GitHub repositories, gathering over 1,100 stars before Anthropic could react.
The real find was buried deeper. Inside the leaked code sat a feature called Undercover Mode. It instructs the AI to never reveal that it is an AI in commit messages and pull requests. “NEVER include the phrase ‘Claude Code’ or any mention that you are an AI,” reads the system prompt injection found in `utils/undercover.ts`. The company that brands itself as the responsible AI lab built a tool to hide AI authorship in public code repositories. And then accidentally proved it existed by leaking the source code that contains it.
How It Happened
Claude Code is built with Bun, a JavaScript runtime that generates source maps by default. Source maps are debugging files that map minified production code back to the original source. Standard in development. Not supposed to ship to production.
Someone at Anthropic failed to exclude the `.map` file via the package’s `.npmignore` configuration. The file referenced source files stored on Anthropic’s own cloud infrastructure, which were also publicly accessible. The result: a complete reconstruction of the original TypeScript codebase across 1,900 files, including internal documentation, feature flags, authentication flows, and a full product roadmap.
Anthropic confirmed the incident in a statement to VentureBeat: “Earlier today, a Claude Code release included some internal source code.” The company pushed an update to remove the source maps and deprecated the affected version. By then, the source had been forked across GitHub.
Three Leaks in Fourteen Months
This was not the first time. The identical source map vulnerability appeared in February 2025, when an early Claude Code package shipped with the same misconfiguration. Anthropic removed it from npm and deleted the source map.
They did not fix the build pipeline that allowed it to happen again.
Five days before the March 31 incident, Fortune reported that Anthropic had exposed approximately 3,000 unpublished assets through a misconfigured content management system. That leak included details about an unreleased AI model described as “the most capable model it has yet trained,” an invitation-only CEO retreat, and internal employee materials. Alexandre Pauwels, a cybersecurity researcher at the University of Cambridge, assessed the exposed data and confirmed the scope. Anthropic attributed the CMS leak to “human error in the CMS configuration.”
Three leaks. Two different systems. Fourteen months. The company whose entire brand proposition is “we are the careful ones” cannot keep its own house in order.
What the Code Revealed
Beyond Undercover Mode, the leaked source exposed 44 feature flags for unreleased products. KAIROS, referenced over 150 times in the codebase, appears to be an autonomous background agent that operates as an always-on daemon. BUDDY is a Tamagotchi-style AI pet with 18 species, rarity tiers, and stats like DEBUGGING, PATIENCE, and SNARK. Coordinator Mode enables one Claude instance to manage multiple worker agents simultaneously.
The code also revealed internal model codenames. Claude 4.6 is “Capybara.” Opus 4.6 is “Fennec.” An unreleased model called “Numbat” remains in testing. For competitors, this is a literal roadmap. With Claude Code generating an estimated $2.5 billion in annualized revenue and enterprise adoption accounting for 80% of that figure, the stakes of this exposure are not academic.
Developers on Hacker News also flagged sentiment detection via regex baked into the codebase. Claude Code uses pattern matching to monitor negative user sentiment during sessions, tracking frustration in real time using regular expressions rather than the company’s own AI models.
A defender would argue this is a routine DevOps error that got amplified by Anthropic’s profile. Source maps ship accidentally all the time. The exposed code is the CLI tool, not model weights or training data. And Undercover Mode’s primary purpose is preventing internal codenames from leaking into public repositories, which is standard security hygiene. The instruction to hide AI authorship may serve enterprise customers who want clean commit histories, not deception.
That defense has limits. Routine DevOps errors do not recur across two separate systems at a company that sells careful development as a differentiator. And “do not reveal internal codenames” is not the same instruction as “never mention you are an AI.” One is security. The other is concealment.
Anthropic’s entire value proposition is that they are the safety company. That is the brand. That is the pitch to investors, to enterprise customers, to regulators. When you make “careful” your differentiator and then leak your own source code three times across two different systems, the word stops meaning anything. Other companies ship source maps by accident and it is a bad day. When Anthropic does it, it is a credibility problem. Because if they cannot secure a build pipeline, why should anyone trust them to secure the AI systems they are asking the world to depend on?
What This Means for Everyday People
If you use Claude Code, the source code leak itself does not directly expose your data. The CLI runs locally and communicates with Anthropic’s API. Your code is not in the leaked files.
The real concern is a concurrent, separate axios supply chain attack. An unrelated attacker compromised the axios npm package between 00:21 and 03:29 UTC on March 31. Anyone who installed or updated Claude Code during that window may have pulled in a malicious version containing a Remote Access Trojan. If you updated that morning, check your axios dependency version immediately. The npm ecosystem has faced sustained supply chain attacks throughout the year, and this incident landed at the worst possible time.
More broadly, consider the pattern. The companies building AI tools that run inside your development environment, tools with access to your entire codebase and terminal, are the same companies that cannot configure a `.npmignore` file. That gap between capability claims and operational reality should inform how much access you grant them.
For inquiries and analysis contact laterstack@proton.me
On March 24, the European Commission detected what it now calls a “cyberattack” on the cloud infrastructure behind its Europa.eu web platform. Six days later, the extortion group ShinyHunters claimed responsibility and published proof: screenshots, file trees, and an initial 90GB archive from what they say is a 350GB haul of mail servers, databases, confidential documents, and contracts pulled from the Commission’s Amazon Web Services environment.
The Commission’s official response confirmed that data was taken. It also insisted that “internal systems” were not affected and that no Europa websites were disrupted during the incident. This is the institutional equivalent of your house getting robbed and telling the neighbors your lawn looks great.
Look at what ShinyHunters says they have. Not just emails and attachments, but a full SSO user directory, DKIM signing keys, AWS configuration snapshots, NextCloud and Athena data, and internal admin URLs. Each of those items creates a distinct threat vector. The SSO directory is a roadmap of every authenticated user in the system. The AWS config snapshots reveal how the environment was architected, what services connect to what, where the seams are. The internal admin URLs are reconnaissance gold for any follow-on attack.
But the DKIM keys are the real problem. DKIM is the email authentication protocol that lets a receiving server verify a message actually came from the domain it claims to come from. If you possess the signing keys for europa.eu domains, you can forge emails that pass authentication checks. Emails that look legitimate to every spam filter and every inbox. Imagine a spear-phishing campaign targeting EU member state officials, originating from what appears to be a genuine European Commission address. That is not hypothetical anymore. The keys are out.
AWS, for its part, told reporters that it “did not experience a security event” and that its services “operated as designed.” This is technically accurate in the way that saying a highway operated as designed after a car crash is technically accurate. Nobody is blaming the road. The question is what the Commission was doing with its IAM controls, its access policies, and its monitoring. A breach that exfiltrated 350GB of data from an AWS account without triggering immediate detection points to configuration failures, not infrastructure failures.
ShinyHunters is not an unknown quantity. The group first appeared in 2020 and immediately started racking up victims: Tokopedia (91 million accounts), Mathway (25 million users), Microsoft (500GB of source code from a private GitHub repo). Their 2024 Snowflake campaign was a masterclass in exploiting weak credential hygiene. They systematically targeted customer accounts that lacked multi-factor authentication, hitting Ticketmaster (560 million records), AT&T (110 million call and text records), Santander Bank, Advance Auto Parts, and LendingTree across a single coordinated operation. One of their members, French national Sebastien Raoult, was arrested in Morocco in 2022, extradited to the U.S., and sentenced to three years in prison with a $5 million restitution order. The arrest did not slow the group down. It rarely does with decentralized threat actors.
In February 2026, ShinyHunters hit Wynn Resorts. Weeks later, the European Commission. The tempo is accelerating.
And this is the part the Commission would prefer you not focus on: March 24 was not their first incident this year. In late January, CERT-EU detected an intrusion into the Commission’s central Mobile Device Management infrastructure, exposing staff names and mobile phone numbers. That breach was linked to two zero-day vulnerabilities in Ivanti’s Endpoint Manager Mobile software that were simultaneously exploited against the Dutch Data Protection Authority and Finland’s Valtori agency. The Commission disclosed it in February, called it contained, and moved on. One month later, a completely different attack group walked through a completely different door and took 350GB of data on its way out.
Two separate breaches at the same institution in under 60 days. Different attack vectors, different threat actors, different infrastructure layers. This is not bad luck. This is a pattern of systemic inadequacy in security posture at one of the most powerful governing bodies in the world.
The F5 BIG-IP source code theft showed what happens when attackers get the blueprints. The SharePoint CVE that went unpatched for months showed what happens when institutions treat patching as optional. The Trivy supply chain compromise showed how security tooling itself becomes the entry point. Now the European Commission is adding another chapter to the same running story: the organizations telling everyone else to improve their cybersecurity posture cannot secure their own systems.
To be fair: ShinyHunters’ claims remain unverified by independent researchers as of this writing, and threat groups routinely exaggerate the scope and sensitivity of stolen data to increase leverage. The 350GB figure could include significant amounts of publicly available or low-sensitivity material. The Commission’s distinction between “public-facing web infrastructure” and “internal systems” may be meaningful if the AWS environment truly held only web content and ancillary data. And the Ivanti breach in January, while embarrassing in proximity, was a zero-day exploit affecting multiple European government agencies simultaneously, not evidence of uniquely poor security at the Commission.
None of that changes the DKIM problem. The European Commission handles trade policy, regulatory enforcement, and diplomatic communications that affect 450 million people across 27 countries. If those signing keys are in criminal hands, forged emails impersonating Commission officials could target government agencies, businesses, and individuals across Europe. The immediate risk is not the data that was stolen. It is what that data enables next. Every email from an @europa.eu address now deserves an extra second of skepticism.
Melbourne-based developer Zach Manson asked Copilot to fix a typo in a pull request. It fixed the typo. It also rewrote the PR description to include an advertisement for Raycast, a macOS productivity tool with a Copilot integration. The promotional line read: “Quickly spin up Copilot coding agent tasks from anywhere on your macOS or Windows machine with Raycast.”
Manson’s reaction: “This is horrific.”
A search across GitHub found the same phrase embedded in over 11,000 pull requests across thousands of repositories. Broader estimates put the total number of PRs affected at over 1.5 million. The promotional text was not limited to the Raycast plug. Other injected “tips” pushed Slack and Teams integrations, VS Code, JetBrains IDEs, and Eclipse. Every variant was tagged with a hidden HTML comment in the PR markdown: `START COPILOT CODING AGENT TIPS`.
The ads hit GitLab merge requests too. If Copilot touched your PR anywhere, the tip followed.
Martin Woodward, GitHub’s Vice President of Developer Relations, confirmed the behavior and said the feature has been disabled. His explanation: the product tips were “kinda ok on Copilot originated PR’s but then when we added the ability to have Copilot work on _any_ PR by mentioning it the behaviour became icky.” He said product tips are now disabled entirely thanks to feedback.
Two things about that response. First, “icky” is doing a lot of heavy lifting for a VP describing an AI tool that silently modified developer work product to promote commercial integrations. Second, the framing admits that GitHub considered injecting promotional text into AI-generated pull requests acceptable in the first place. The line between “ok” and “icky” was not the advertising itself. It was the radius. They only pulled back because it spread to PRs Copilot did not originate.
That distinction matters because it tells you what the default position was: promotional injection is fine as long as it stays inside the content the AI created.
Pull requests are one of the most trusted artifacts in software development. They represent proposed changes to a codebase. They get reviewed by humans who are making decisions about what ships to production. They carry legal and compliance weight in regulated industries. When an AI tool silently appends commercial messaging to a PR description, it is modifying a document that developers treat as a source of truth. The fact that the modification was a “tip” rather than a banner ad does not make it less of an integrity violation.
And it sits inside a pattern that Microsoft has been running for years. Windows 11 shoves ads into the Start menu. Edge intercepts browser downloads with pop-up surveys asking users why they want to leave. Copilot inserts promotional messages into the Windows desktop. The throughline is simple: Microsoft treats every surface it controls as an advertising channel. GitHub was not going to be an exception. The only question was when.
The timing makes it worse. On March 25, GitHub announced that starting April 24, 2026, interaction data from Copilot Free, Pro, and Pro+ users will be used to train AI models by default. The announcement post collected 97 thumbs-down reactions against 4 supportive ones. Users are calling it “forced authorization.” GitHub is shifting from opt-in to opt-out while simultaneously dealing with the fallout of its AI tool injecting ads into developer workflows.
So GitHub is now running a two-front trust erosion campaign: using your code interactions to train models you did not consent to improve, and using the AI agent you pay for to advertise other products back to you inside your own repositories. Both happened in the same week.
The security implications are not hypothetical either. In October 2025, researchers demonstrated that hidden instructions embedded in PR comments and metadata could manipulate Copilot into leaking sensitive data from private repos. The attack used hidden HTML elements to exfiltrate AWS keys through Copilot’s rendering pipeline. GitHub’s own “tips” mechanism used the same vector: hidden HTML comments in PR descriptions. When the platform itself normalizes embedding hidden content in pull requests, it lowers the bar for everyone else who wants to do the same thing for less benign purposes.
Woodward says the tips are off. Fine. But the infrastructure that enabled them still exists. The decision-making culture that approved them still exists. The business model that incentivized them still exists. Microsoft spent $13 billion on OpenAI and 15 million developers now use Copilot. That is not a tool. That is a distribution channel. And distribution channels get monetized.
The next time Copilot adds something to your pull request, you should probably read it twice. And check the HTML.
Intel confirmed late last week that CPU prices are going up by 10 to 15 percent effective immediately, with major PC manufacturers and OEMs receiving revised pricing at the end of March. AMD is following with its own increases starting in April. Both companies saw their stock prices surge over 7% on the news, because on Wall Street, the ability to raise prices without losing customers is a signal of market power even when the reason you can raise prices is that nobody else has any supply either.
The supply numbers are ugly. CPU delivery lead times, which sat at a comfortable one to two weeks for most of 2025, have stretched to eight to twelve weeks on average, with some orders now quoting six months. The bottleneck is not a manufacturing defect or a logistics hiccup. It is a structural reallocation of global semiconductor capacity toward AI infrastructure. Nvidia, Broadcom, Google, and Amazon are consuming fabrication capacity at a rate that leaves less room for the processors that go into the laptops, desktops, and servers that regular businesses and consumers buy. When Big Tech committed $650 billion to AI capex this year, that money had to come out of a finite supply chain. Now everyone else is finding out where the cost lands.
The Iran war is making it worse. Oil above $100 per barrel raises energy costs at every stage of semiconductor manufacturing, from the fabs in Taiwan and Arizona to the packaging facilities in Southeast Asia. The Strait of Hormuz closure and Qatar’s helium supply disruption are adding pressure to a supply chain that was already running at capacity before the first strike. TSMC is accelerating its Fab 21 expansion in Arizona, but new fab capacity takes years to come online and solves nothing for the price hikes hitting OEMs right now.
The three-way squeeze
Three forces are converging on the same supply chain simultaneously. AI demand is pulling fabrication capacity toward high-margin accelerators and away from consumer CPUs. The Iran war is raising energy and logistics costs across every node in the chain. And the geographic concentration of advanced semiconductor manufacturing, still overwhelmingly dependent on TSMC in Taiwan, means there is no backup capacity to absorb the pressure. The $2.5 billion chip smuggling operation Laterstack covered last week shows how desperate the demand for semiconductor supply has become. When the legitimate supply chain cannot keep up, the gray market fills the gap.
Consumer electronics price increases of 10 to 15 percent on finished products are expected to begin rolling through in the second half of 2026. That number assumes the war does not escalate further, that TSMC’s operations are not disrupted, and that AI demand does not accelerate beyond current projections. All three assumptions are optimistic.
The counter argument
CPU price increases of 10 to 15 percent are significant but not catastrophic, and the semiconductor industry has weathered supply crunches before without permanent structural damage. The 2020-2022 chip shortage produced similar panic and prices eventually normalized as new capacity came online and demand rebalanced. Intel and AMD both have incentives to communicate supply constraints publicly because it justifies price increases and supports their stock prices. The “AI ate your chips” narrative may overstate the actual capacity reallocation, given that AI accelerators and consumer CPUs often use different fabrication processes and compete less directly for fab time than the headlines suggest.
The AI subsidy era is over. For a decade, the implicit bargain of the consumer technology market was that hardware got cheaper every year because the scale of production kept costs falling. That bargain depended on fabrication capacity growing faster than demand, and AI just broke that equation. Nvidia guided $78 billion in revenue and every dollar of that guidance represents fabrication capacity that is not making your next laptop cheaper. The war makes it worse, the geographic concentration makes it fragile, and the timeline for relief, measured in years of new fab construction, means this is not a quarter or two of higher prices. This is the new cost structure for computing, and the companies driving it are the same ones telling you AI will make everything more efficient.
What This Means for Everyday People
Your next laptop, desktop, or server will cost more, and the reason is not inflation in the traditional sense. It is that the companies building AI systems are consuming so much of the world’s chip manufacturing capacity that there is less left over for everything else. The 10 to 15 percent increase on CPUs will work its way into every finished product that contains a processor by the end of the year. If you were planning a hardware purchase, the price is not getting better from here.
Crunchbase reported this week that American startups raised approximately $13 billion in seed through growth-stage funding in March, a collapse from the $189 billion that flowed in February. The headline number sounds catastrophic until you remember that February was an anomaly inflated by three rounds that individually would have been historic in any other month: OpenAI’s $110 billion, Anthropic’s $30 billion, and Waymo’s $16 billion. Those three deals alone accounted for more than 80% of February’s total. March is not a crash so much as it is reality returning after a month of statistical fiction.
But here is where the story gets interesting. While US funding cratered, European startup funding hit its highest point of 2026 in the same month. AI infrastructure megarounds from companies like Nscale and Advanced Machine Intelligence closed across the continent, and early-stage European investment held steady. The money did not disappear. It moved.
The timing is not coincidental. The Iran war started February 28. Oil crossed $100. The Strait of Hormuz closed. The S&P 500 dropped into correction territory, falling to 6,369 by Friday. The VIX surged. And the political environment in Washington, between the Anthropic retaliation, DHS shutdown, tariff uncertainty, and an AI policy vacuum left by David Sacks’ departure, is generating the kind of regulatory unpredictability that makes capital allocation committees nervous. European regulatory environments are not perfect, but they are at least predictable, and predictability is what large institutional investors optimize for when the alternative is chaos.
Seed didn’t stall. The top of the funnel is fine.
Crunchbase’s own data shows that seed funding hasn’t stalled in absolute terms. It is skewing larger and more competitive, but the volume of seed deals has remained relatively consistent across January, February, and March. The collapse is concentrated entirely at the growth and late stage, where the AI megarounds live. The pipeline of new companies getting funded is intact. What dried up is the willingness of large investors to write $1 billion plus checks into US AI companies during a month when the geopolitical and regulatory floor was shifting under them.
Thrive Capital raised $10 billion earlier this year and AMI Labs closed $1 billion as recently as March 21. The money for conviction bets still exists. But the broad market confidence that would support multiple simultaneous megarounds in a single month, the kind of environment February represented, requires stability that March simply did not offer.
The counter argument
Comparing any month to February 2026 is inherently misleading. OpenAI’s round alone was the largest venture deal in history. $13 billion in a month is not a crisis by any historical standard. It is actually higher than the monthly average for most of 2024. The European funding surge may also be driven by a handful of large rounds rather than a systemic capital shift. Calling this “capital flight” may be overstating what could simply be reversion to the mean after an outlier month, combined with the normal lumpiness of megaround timing.
US money froze while European money accelerated, and the only variable that changed between February and March was the outbreak of a war and a political environment that went from merely chaotic to actively hostile toward the technology companies that were the largest recipients of venture capital. Follow the money. It is moving east, and the reasons are not temporary. War, regulatory uncertainty, and the political weaponization of supply chain designations against AI companies are structural conditions, not monthly blips. Capital goes where it can predict the next twelve months, and right now, that is not the United States.
What This Means for Everyday People
Venture capital might feel like a game played by billionaires that has nothing to do with your life, but VC-funded startups become the products you use, the companies that hire, and the technologies that reshape industries. When that money starts leaving the country, the startups that would have been built in San Francisco get built in London or Berlin instead. The jobs, the innovation, and the economic multiplier effects follow the capital. If this trend holds, the consequences show up in your city’s job market, not just in Crunchbase charts.
Judge Rita F. Lin of the Northern District of California issued a 43-page ruling on Thursday granting Anthropic a preliminary injunction against the Pentagon’s decision to designate the company a “supply chain risk” and against a Trump executive order barring federal agencies from using Anthropic’s technology. The language in the opinion was not subtle. “Nothing in the governing statute,” Lin wrote, “supports the Orwellian notion that an American company may be branded a potential adversary and saboteur of the U.S. for expressing disagreement with the government.”
She went further. The Pentagon’s actions, Lin found, constituted “classic illegal First Amendment retaliation.” The government punished Anthropic not for any supply chain failure, not for any security breach, not for any deficiency in its technology, but for CEO Dario Amodei’s public statements that Claude would not be used for autonomous weapons systems or to surveil American citizens without consent.
This matters because the case just jumped categories. What started in February as a Pentagon procurement dispute over AI safety guardrails, escalated in March into a lawsuit and a hearing where Silicon Valley split publicly over which side to back, and has now landed in constitutional law territory. A federal judge looked at the evidence and concluded that the United States government retaliated against an American company for exercising free speech.
That is not a procurement ruling. That is a First Amendment precedent.
The injunction temporarily blocks the supply chain risk designation and the federal agency ban, but Lin put her own ruling on hold for one week to give the Justice Department time to file an appeal. The DOJ is expected to take it. Which means the Ninth Circuit will likely be weighing in on whether the executive branch can use supply chain designations as political punishment within the next few months, and that ruling will set precedent that reaches far beyond one AI company.
Why this outlasts the current administration
The specific fight between Anthropic and the Pentagon will resolve one way or another. Either the appeals court upholds Lin’s injunction and the designation gets scrapped, or it reverses and Anthropic faces years of litigation while locked out of federal contracts. But the constitutional question Lin raised, whether the government can use procurement and supply chain authorities to punish companies for public speech, applies to every defense contractor, every technology vendor, and every company that does business with the federal government.
David Sacks left the White House AI role with no replacement named. The administration’s AI policy framework is a preemption play designed to block state regulation rather than articulate any actual federal standard. And now a federal judge has called the executive branch’s treatment of its most prominent AI safety advocate “Orwellian.” The administration’s AI posture is becoming incoherent in a way that the judiciary is starting to notice.
The counter argument
The injunction is preliminary, not final. Lin’s ruling survives only if the Ninth Circuit agrees, and appellate courts regularly narrow or reverse district court injunctions, particularly in national security cases where courts traditionally defer to executive branch discretion. Politico reported that lawyers and lobbyists familiar with the case say Anthropic is “still in trouble” despite the ruling, because the underlying procurement dispute has not been resolved and the political dynamics have not changed. The government may lose the constitutional argument and still find administrative ways to exclude Anthropic from contracts.
This is not about procurement anymore and it has not been for weeks. A federal judge just told the Pentagon it cannot punish a company for disagreeing with the government’s position on how AI should be deployed in military contexts. That principle, that the First Amendment applies even when the disagreement is with the Department of Defense during wartime, is a constitutional marker that will outlast this administration, this case, and probably this generation of AI technology. The specific contract dollars at stake are a rounding error compared to the precedent being set.
What This Means for Everyday People
The AI tools you use every day exist because companies like Anthropic make decisions about what those tools will and will not do. When a government can punish a company for choosing to put safety limits on its technology, the incentive for every other AI company is to remove those limits to avoid the same treatment. This ruling protects not just Anthropic’s right to speak, but the idea that the companies building AI get to have an opinion about how it should be used without being blacklisted for saying so.