U.S. District Judge Rita Lin heard Anthropic’s motion for a preliminary injunction in San Francisco on Monday, and she did not mince words. After listening to both sides argue over whether the Pentagon’s supply chain risk designation was retaliation for Anthropic refusing to let the military use Claude without guardrails, Lin said what a growing number of observers have been thinking for weeks.

“I don’t know if it’s murder,” she told the courtroom, “but it looks like an attempt to cripple Anthropic.”

The hearing marked the most significant courtroom moment in a dispute that has been escalating since February, when Anthropic refused to grant the Pentagon unrestricted access to Claude for autonomous lethal warfare and mass surveillance of American citizens. That refusal triggered a chain of events that led the Department of Defense to formally designate Anthropic a supply chain risk on March 5. It was the first time an American company received that label. Before Anthropic, the designation had been reserved for foreign adversaries like Huawei.

Lin pressed the government’s lawyers repeatedly on whether the designation was proportional. “What is troubling to me about these reactions is that they don’t really seem to be tailored to the national security concern,” she said. She noted that if the Pentagon’s concern was operational integrity, they could have simply stopped using Claude. Instead, they went further. The designation requires defense contractors including Amazon, Microsoft, and Palantir to certify they do not use Claude in any military work. “It looks like defendants went further than that because they were trying to punish Anthropic,” Lin added.

At one point, Lin characterized the government’s argument as suggesting a company can be labeled a supply chain risk because it is “stubborn” and “asks annoying questions.” She called that a “pretty low bar.”

Anthropic’s lawyer Michael Mongan told the court this was “something that has never been done with respect to an] American company.” The company’s CFO [submitted testimony estimating the financial damage at hundreds of millions to billions of dollars in lost 2026 revenue. More than 100 enterprise customers have contacted Anthropic with concerns about continuing to work with a company the Pentagon has blacklisted.

The government argued the actions were based on Anthropic’s negotiating posture and refusal to comply with military requests, not retaliation for public criticism. But a TechCrunch court filing review revealed that the Pentagon told Anthropic the two sides were “nearly aligned” just one week before Trump declared the relationship over. Lin called the government’s claim that social media posts were not legally binding “pretty surprising.”

This has been a story Laterstack has followed from the beginning, through the supply chain designation, the lawsuit filing, and Silicon Valley’s response. Monday’s hearing felt like the moment the legal system caught up to what the pattern already showed. A company said no to unchecked military AI use. The government’s response looked less like national security and more like a message to every other AI company about what happens when you draw a line.

Lin did not say it was retaliation. She said it “looks like” it. That distinction matters legally. But the fact that a federal judge is openly questioning the government’s motives from the bench, using language like “cripple” and “punish,” shifts the terrain significantly. This is vindication for the argument that the Pentagon overplayed its hand. Not a celebration. The ruling hasn’t dropped. But the trajectory is clear.

Lin said she expects to issue a decision within days. Anthropic asked for a ruling by March 26.

What This Means for Everyday People

If the government can blacklist an American company for refusing to build weapons without safeguards, the precedent reaches well beyond AI. Every defense contractor, every tech company with a government relationship, every firm that might one day say “we won’t do that” now has to factor in the possibility that the answer is financial destruction. The question Lin is weighing isn’t just about Anthropic and the Pentagon. It’s about whether the government can use procurement designations as punishment for companies that push back on how their products are used.

Ryan Goldberg managed incident response at Sygnia, a cybersecurity firm that helps companies recover from attacks. Kevin Martin negotiated ransom payments at DigitalMint, a company victims call when they need to pay attackers in cryptocurrency. Both men pleaded guilty in Miami federal court to running BlackCat ransomware operations against US companies while collecting paychecks from the firms hired to stop exactly that, according to the Department of Justice.

Between April and December 2023, Goldberg (40, Georgia), Martin (36, Texas), and an unnamed third co-conspirator deployed ALPHV/BlackCat ransomware against at least five US companies, as reported by SecurityWeek. Three of the targets were healthcare organizations. They successfully extorted approximately $1.2 million in Bitcoin from one victim, kept their 80% affiliate share, split it three ways, and laundered the proceeds. Each faces up to 20 years in prison.

The case was investigated by the FBI and US Secret Service and prosecuted by the Southern District of Florida.

The BlackCat Operation They Joined

ALPHV/BlackCat was one of the most prolific ransomware-as-a-service operations in recent history. The FBI reported in September 2023 that BlackCat had compromised over 1,000 victims and collected nearly $300 million in ransom payments. The franchise model was simple. Affiliates got the malware, the infrastructure, and the negotiation playbooks. Operators took a 20% cut. The DOJ disrupted BlackCat’s operations in December 2023, recovering approximately $99 million in potential ransom payments.

But before that takedown, in February 2024, a BlackCat affiliate hit Change Healthcare in what became one of the most damaging cyberattacks in US history. Change Healthcare paid $22 million in ransom, with total losses likely exceeding $1.5 billion, according to IBM’s analysis. The FBI and CISA issued a joint advisory warning that after the December 2023 disruption, BlackCat administrators actively encouraged affiliates to target hospitals.

Goldberg and Martin were part of this ecosystem. They weren’t outsiders who stumbled into ransomware. They were credentialed security professionals who understood incident response timelines, negotiation dynamics, and how victims behave under pressure, because helping victims was their day job.

Healthcare Was the Obvious Target

Three of their five victims were healthcare organizations. This tracks with a broader pattern. Healthcare has been the most expensive sector for data breaches for 14 consecutive years, averaging $9.77 million per incident in 2024, according to IBM. The HIPAA Journal reported that healthcare cyberattacks costing over $200,000 rose 400% in a single year. In 2024 alone, 458 ransomware events were tracked in the healthcare sector, with 65% of ransom demands exceeding $1 million.

Hospitals can’t afford downtime. Patient care is the leverage. When you encrypt a hospital’s systems, you’re threatening to disrupt treatment for real people in real time. Goldberg and Martin knew this. They chose healthcare targets knowing the pressure dynamics would maximize the likelihood of payment.

And they did it while working at companies that healthcare organizations call for help during exactly these situations.

The Insider Threat Is Getting Worse

This case fits into a trend the industry is tracking but struggling to address. The 2025 Verizon Data Breach Investigations Report found that internal actors were responsible for 29% of breaches. Only 17% of organizations reported zero insider incidents in 2024, down from 40% in 2023. Malicious insider attacks are the single most expensive breach type, averaging $4.92 million per incident.

North American organizations faced average insider incident costs of $22.2 million in 2025.

Goldberg and Martin represent the most dangerous version of this problem. They weren’t disgruntled employees stealing data on their way out. They were active security professionals using their legitimate access and expertise to moonlight as ransomware affiliates. Goldberg’s job was to respond to the exact type of attack he was launching. Martin’s job was to help victims pay ransoms, which means he understood the negotiation dynamics, the payment timelines, and the pressure points from the victim’s side of the table.

What the Industry Doesn’t Want to Sit With

The security industry runs on trust. When a company brings in an incident response firm during a ransomware attack, they hand over admin credentials, network maps, and forensic access. They have to. That’s how incident response works. The assumption is that the people on the other end of those credentials are operating in good faith.

There’s no external verification mechanism for that assumption in the private sector. Security clearances exist for government work, but private-sector cybersecurity hiring runs on certifications, references, and interviews. Nobody is monitoring what an incident responder does with the access they’re granted during an engagement.

The financial incentive is real. An 80% affiliate cut on a seven-figure ransom dwarfs a senior security professional’s annual salary. And the operational knowledge required to avoid detection? These are the people who teach detection.

Goldberg and Martin got caught. The FBI and Secret Service built the case and secured guilty pleas. Good.

But they operated for eight months, hit at least five companies, extorted over a million dollars, and laundered the proceeds before anyone connected them to the attacks. The industry will issue statements about trust, integrity, and vetting. It will point to this prosecution as proof the system works. That framing is convenient and wrong. The system didn’t prevent anything. It cleaned up afterward. Eight months of operations, three healthcare victims, and over a million dollars in extorted payments happened first.

The cybersecurity industry sells protection. It charges billions for it. And it has no structural mechanism to verify that the people delivering that protection aren’t also the ones running the attacks. Certifications don’t screen for motive. Background checks don’t catch moonlighting. The trust model is “we assume good faith until proven otherwise,” and the proof only comes after the damage.

That’s not a system that works. That’s a system that got lucky twice.

Lamar covers cybersecurity, enterprise tech, and the systems that shape how power and technology interact. Follow Laterstack for critical analysis of the stories that matter.

Xanadu Quantum Technologies will begin trading on the Nasdaq and Toronto Stock Exchange on March 27 under the ticker XNDU. The business combination with Crane Harbor Acquisition Corp. closes March 26, delivering approximately $302 million in gross proceeds from trust funds and committed PIPE financing. Shareholders approved the deal on March 19, as confirmed by The Quantum Insider and Quantum Computing Report.

That makes Xanadu the first publicly traded photonic quantum computing company. In a sector where every other serious player builds machines that need temperatures colder than deep space, Xanadu is betting it can do useful quantum computation with light, at room temperature.

The Photonic Approach

Most quantum computers today use superconducting circuits. IBM, Google, and the recently public Horizon Quantum Computing all build machines that operate at millikelvin temperatures, requiring dilution refrigerators and specialized cryogenic infrastructure that costs millions before you even get to the qubits. Ion trap approaches (IonQ, Quantinuum) need extreme vacuum conditions.

Xanadu uses squeezed-light photons as qubits, manipulated through optical circuits that operate at room temperature. No cryogenics. That removes one of the biggest engineering and cost barriers to scaling. Photonic qubits also travel well through existing fiber optic networks, which could matter if quantum networking becomes practical.

The tradeoff: photonic quantum computing is less mature. Generating single photons reliably, making them interact in controlled ways, and detecting them accurately are hard engineering problems that haven’t been solved at the scale needed for fault-tolerant computation. But the company isn’t just building hardware. Xanadu developed PennyLane, an open-source quantum software library compatible with multiple hardware platforms, and recently partnered with South Korea’s ETRI research institute on fault-tolerant algorithm design and with AMD to advance quantum-classical hybrid simulations for aerospace. Earlier this year, Xanadu deepened its strategic collaboration with Tower Semiconductor to accelerate photonic quantum hardware manufacturing.

Founded in 2016 by CEO Christian Weedbrook, a member of Canada’s Quantum Advisory Council, the company has published significant research and built working photonic processors. Whether those translate into commercially useful machines before the money runs out is the question every quantum company faces. Public market scrutiny will make that question louder.

The Government Money

The SPAC proceeds are substantial, but the bigger number is still being negotiated. Canada and Ontario are in discussions to invest up to CAD$390 million under “Project OPTIMISM,” according to the merger announcement. That funding is conditional on due diligence and final agreement. But if it materializes, Xanadu would have nearly $700 million in total funding.

Government backing at this scale reflects a broader trend. The UK announced £2 billion for quantum innovation earlier this month. Australia is positioning itself as a quantum hub. The US has the National Quantum Initiative. Governments are picking sides on quantum computing, and the photonic approach now has a funded public company behind it.

The Quantum IPO Wave

Xanadu’s listing comes days after Horizon Quantum Computing went public via its own SPAC, raising approximately $120 million. IonQ has been publicly traded since 2021, posting $130 million in full-year 2025 revenue, a 202% year-over-year increase, with 2026 guidance of $225-245 million. D-Wave just announced its acquisition of Quantum Circuits Inc. Rigetti is public. PitchBook reports that SPACs are back and targeting deep tech, with Infleqtion, IQM Quantum Computers, and Pasqal all pursuing public listings in 2026. Quantinuum, backed by Honeywell, is also expected to IPO.

The sector is building a public market ecosystem faster than most predicted.

Whether that ecosystem can sustain itself depends on the same question that hangs over every quantum company. None generate meaningful revenue from quantum computing itself. Their valuations rest on the assumption that fault-tolerant quantum computers will eventually work, and that the companies building them will capture value when they do. Wall Street analysts don’t expect quantum computers to deliver practical advantage over classical computing until the tail end of this decade. Public markets are less patient than venture capitalists. If timelines stretch, these stocks face real pressure.

There’s a pattern forming that deserves honest assessment. The quantum sector is rushing to public markets before any of these companies can demonstrate commercial quantum advantage. IonQ’s $130 million revenue is real, but it comes primarily from consulting and cloud access, not from customers solving problems that classical computers can’t. D-Wave sells quantum annealing, a technology whose advantage over classical optimization remains debated. The SPACs are providing capital, but they’re also providing exit liquidity for early investors who know the commercialization timeline is long and uncertain.

Xanadu at least brings a differentiated technology thesis to this crowded field. Photonic computing is a genuine alternative architecture, not another superconducting variation. The PennyLane software ecosystem gives the company a platform play that isn’t purely dependent on hardware milestones. And government backing from Canada reduces the dilution pressure that kills pre-revenue public companies.

But let’s be clear about what’s happening. The quantum industry is building a public market presence before it has proven it can build a commercially useful quantum computer. That’s a bet on timeline, not on current capability. If fault-tolerant quantum computing arrives by 2030, these early public companies will look prescient. If the timeline stretches to 2035 or beyond, the investors buying XNDU on Thursday are funding someone else’s patience.

Trading starts March 27.

Lamar covers quantum computing, enterprise tech, and the systems that shape how power and technology interact. Follow Laterstack for critical analysis of the stories that matter.

A 20-year-old woman identified as K.G.M. created an Instagram account at age 9. She alleges the platform’s design contributed to depression, anxiety, body dysmorphia, and suicidal ideation. Her case is now in front of a Los Angeles jury, and for the first time in the history of American tech litigation, that jury is being asked to decide whether the way a social media platform was engineered constitutes a defective product.

Not what users posted on it. How it was built.

Mark Zuckerberg took the stand on February 18, as reported by CNN, Al Jazeera, and Fox Business. He told the jury it’s “very difficult” to enforce Instagram’s age limits and downplayed how much teen users contribute to the company’s revenue. Closing arguments have now been delivered, according to PBS News.

The Legal Theory That Could Change Everything

For 30 years, Section 230 of the Communications Decency Act has shielded platforms from liability for what users post. Every previous attempt to hold social media companies accountable for harm has collided with that wall. Courts have consistently ruled that complaints about harmful content are really complaints about third-party speech, and Section 230 covers that.

K.G.M.’s legal team is running a negligence-based product liability strategy that treats platform design as the company’s own conduct. The argument: likes, algorithmic recommendations, infinite scroll, autoplay, and notification timing are engineering decisions Meta made. Those decisions created a product that functions like a slot machine for adolescent attention. The harm didn’t come from what other users posted. It came from the architecture that determined how content was delivered, amplified, and made compulsive.

In her November 5, 2025 ruling denying Meta’s motion for summary judgment, Judge Carolyn Kuhl drew a line between features related to content publishing (which Section 230 might protect) and features like notification timing, engagement loops, and the absence of meaningful parental controls (which it might not). She established the conduct-versus-content distinction as a viable legal theory for a jury to evaluate.

This approach has precedent. In Lemmon v. Snap, Inc., the Ninth Circuit allowed a case to proceed on the theory that Snapchat’s speed filter was a defective product design, not a content moderation question. The Columbia Undergraduate Law Review has analyzed how this “design as conduct” framework is reshaping tort law around platforms. The University of Cincinnati Law Review examined how addiction-based claims are reassessing Section 230’s boundaries entirely.

If the jury accepts this framing, Section 230 doesn’t apply. You can’t claim third-party speech protection for your own engineering choices.

Why Meta Didn’t Settle

TikTok and Snapchat both settled before this went to trial, as NPR reported. Meta didn’t. Neither did Google, whose YouTube is also a defendant (K.G.M. started using YouTube around age 6).

A settlement in a bellwether case representing approximately 1,600 plaintiffs, including over 350 families and 250+ school districts, would set a price floor for every similar claim. A jury verdict in Meta’s favor could shut down the entire theory. Meta is betting it can convince 10 of 12 jurors (California state court requires three-quarters agreement) that its design choices don’t constitute a defective product.

The Internal Documents Problem

The plaintiffs have the internal data. Meta’s own researchers flagged concerns about Instagram’s effects on adolescent mental health in the “Facebook Papers” leaked in 2021. CNN obtained additional internal documents showing that Facebook researchers had proposed studying whether platform features could contribute to “addiction” or “‘addictive’-like” behaviors. Some of those features, including autoplay and endless scrolling, are the same ones cited in the lawsuit.

According to Meta’s own internal surveys, as reported by the Tech Oversight Project’s analysis of unsealed documents: 17% of teenage girls said Instagram exacerbated eating disorders. 13.5% said it exacerbated suicidal thoughts. A company survey of 20,000 US Facebook users in 2018 found that 58% showed some level of social media addiction, with 3.1% rated as severe. Meta conducted a “deactivation study” that found users who stopped using Facebook and Instagram for a week showed lower rates of anxiety, depression, and loneliness. The company halted the study and did not publicly disclose the results.

Internal knowledge plus continued operation is the standard formula for product liability claims. It’s how tobacco litigation worked. It’s how opioid litigation worked. Whether social media design maps cleanly onto that template is what 12 people in Los Angeles are deciding right now.

What a Verdict Actually Means

Congress has spent years holding hearings about social media and children. State legislatures have passed age verification laws. The surgeon general has issued warnings. None of it changed how these platforms operate, because none of it carried enforceable consequences with real financial teeth.

A jury verdict does.

If 10 of 12 jurors decide that Instagram’s design constitutes a defective product, it creates a template that trial lawyers in every jurisdiction can replicate. And trial lawyers, unlike legislators, work on contingency. They have financial incentive to keep filing. A product liability finding would mean every algorithmic recommendation system, every engagement optimization feature, every notification timing algorithm becomes a potential liability vector. Not just for Meta. For every company that builds products designed to maximize time on app.

Big tech has defeated regulatory agencies, lobbied legislatures, and navigated antitrust suits for three decades. It has never faced a jury that can award damages based on how a product was designed.

And the implications don’t stop at social media. Every AI recommendation system, every algorithmic feed, every engagement-optimized notification schedule uses the same design principles that this lawsuit targets. If platform design is a product liability question, then the companies building AI agents, personalized content engines, and algorithmic advertising platforms are all sitting on the same legal exposure that Meta is facing in Los Angeles right now. They just haven’t been sued yet.

This trial isn’t just about Instagram and one teenager. It’s a test case for whether “we designed it to be maximally engaging” remains a business strategy or becomes a legal liability. The answer is in the hands of 12 people in California.

Lamar covers big tech, enterprise technology, and the systems that shape how power and technology interact. Follow Laterstack for critical analysis of the stories that matter.

NASA’s Space Launch System rocket arrived back at Launch Pad 39B at Kennedy Space Center on March 20, completing a 12-hour, four-mile crawl from the Vehicle Assembly Building. The launch window opens April 1 and extends through April 6, according to NASA’s mission blog and Spaceflight Now’s live coverage. Live Science confirmed the rollout and Space.com reported the rocket was secured at the pad at 11:21 a.m. EDT.

If it launches, Artemis 2 will be the first crewed mission to the Moon in over 50 years. Apollo 17 was December 1972. That’s 53 years.

The Mission

NASA astronauts Reid Wiseman, Victor Glover, and Christina Koch, along with Canadian Space Agency astronaut Jeremy Hansen, will fly a free-return trajectory around the Moon and back to Earth. Ten days, start to finish. They won’t land. They won’t orbit. They’ll loop around and come home. The flight is a shakedown cruise for the Orion spacecraft with people onboard, proving the life support systems, navigation, and heat shield work when actual lives depend on them.

Artemis 1, the uncrewed test flight, completed this trajectory in late 2022. The heat shield performed well but showed unexpected material loss during reentry that required investigation. NASA says the issue has been resolved. Artemis 2 will verify that with a crew aboard.

Victor Glover will become the first Black astronaut to fly beyond low-Earth orbit. Christina Koch will be the first woman on a lunar trajectory. Jeremy Hansen will be the first non-American to fly to the Moon. Kennedy Space Center’s mission page confirms these milestones.

The Helium Problem

This rollout was the second attempt. NASA originally moved the SLS to the pad in February, successfully completed a fueling test, then discovered a helium flow problem on the rocket’s upper stage on February 21. The rocket went back to the VAB for repairs. Technicians fixed the helium issue and replaced flight termination system batteries across multiple components. The March launch window was scrapped. April became the target.

High winds delayed the second rollout. First motion didn’t happen until around 12:20 a.m. EDT, and the four-mile trip to the pad took roughly 12 hours. NASA’s blog detailed the timeline as ground teams worked to make up lost schedule.

None of this is unusual for a program of this complexity. Rockets have problems. Weather causes delays. But Artemis exists under a kind of schedule pressure that goes beyond engineering.

The Cost Conversation

SLS costs roughly $4.1 billion per launch when you include production and ground operations, according to NASA’s own Inspector General. Other estimates put the marginal cost around $2 billion per flight. Either number is enormous. The rocket is expendable. It flies once and drops into the ocean.

SpaceX is building a fully reusable heavy-lift rocket that, if it works as intended, would cost a fraction of that per flight. Elon Musk has said he expects Starship launch costs under $10 million. Even conservative estimates from Payload Research put Starship at roughly $100 million per expendable flight, which is still an order of magnitude cheaper than SLS. NASA itself selected Starship as the lunar lander for Artemis 3.

The US Department of Defense stated in 2023 that it has no interest in SLS, noting that other launch vehicles already offer the capability it needs at affordable prices. The Reason Foundation has argued that NASA should consider transitioning future missions to Starship entirely.

NASA chose SLS because it was the rocket that existed, funded by Congress to preserve jobs and contracts across multiple states. It works. The Artemis 1 mission proved that. But “it works” and “it makes sense to keep building” are different conversations.

What Happens After This Flight

Administrator Jared Isaacman recently restructured the Artemis program, pushing the first crewed lunar landing to Artemis 4 in 2028. The original plan had astronauts on the surface by Artemis 3. That slip, combined with SLS costs, gives critics ammunition. Within 60 to 90 days of Artemis 2, NASA plans to provide greater clarity on Artemis 3 specifics, including orbital demonstrations with lunar landers.

If SpaceX’s Starship achieves reliable flight by then, the argument for continuing to spend billions per SLS launch becomes harder to make. Congress funds SLS. SpaceX builds Starship. NASA needs both to work. The politics and the engineering run on different timelines, and they don’t always converge.

Here’s the uncomfortable math that nobody in Congress wants to do publicly. Four Artemis missions at $4.1 billion each is $16.4 billion just in launch costs. That buys roughly 160 Starship flights at projected pricing. Even at conservative estimates, it buys 40+. NASA knows this. SpaceX knows this. The Government Accountability Office knows this. SLS exists because it was designed as a jobs program first and a rocket second, distributed across suppliers in enough congressional districts to be politically unkillable. The engineering works. The economics don’t. And every successful SpaceX flight makes the gap harder to justify.

None of which changes what happens in the next 10 days. Artemis 2 needs to fly four people around the Moon and bring them home safely. The crew, the mission, and the engineering validation are legitimate regardless of what SLS costs. Glover, Koch, Wiseman, and Hansen have trained for years for this flight. The heat shield needs to prove itself with lives on board. If it works, the program earns another chapter and the cost debate continues. If it slips past April again, the narrative problems compound and the voices calling for a Starship transition get louder.

The rocket is on the pad. Fifty-three years is long enough to wait. The question is whether NASA gets another 53 years of patience for a launch vehicle that costs 40 times more than the alternative.

Laterstack covers space technology, enterprise tech, and the systems that shape how power and technology interact. Follow us for critical analysis of the stories that matter.

Google hit 105 qubits with Willow. IBM says 100,000 by 2033. Quantinuum has 98 with the best error-correction numbers in the industry. Every press release is a qubit count. Every milestone is a number going up.

Nobody talks about the cables.

Every qubit in a quantum computer needs coaxial cables running from the processor, which sits inside a dilution refrigerator at temperatures near absolute zero (roughly 4 Kelvin, or minus 269 Celsius), up to room-temperature control electronics. These are physical wires. They carry microwave signals. They generate heat. And there are a lot of them.

IBM’s 1,121-qubit Condor chip, announced in late 2023, required a cryogenic system packed with wiring that already pushed the limits of what a dilution refrigerator could physically contain. IBM’s public roadmap calls for 100,000 qubits by 2033. There is no corresponding public roadmap for how to wire 100,000 qubits.

That silence is worth paying attention to.

The quantum industry has a habit of measuring progress in qubit counts and error rates. Those metrics matter. They are also useless if you cannot physically wire the machine. A 100,000-qubit computer connected by 100,000 coaxial cables is an engineering fantasy. The cables do not shrink. The fridge does not grow. Something has to replace the wiring, and the companies building the qubits either haven’t solved it or aren’t saying how they plan to.

This is the gap that companies like Rhonexum are trying to fill.

$1M, Two Founders, One Bet

Rhonexum, an EPFL spinout based in Lausanne, Switzerland, raised $1 million in pre-seed funding on March 18. The round was led by QDNL Participations, a specialist early-stage quantum VC firm, with additional support from the Swiss National Science Foundation, Venture Kick, and Fondation pour l’Innovation Technologique.

The company was founded in November 2025 by Vicente Carbon and Dr. Hung-Chi Han. Carbon has a background in robotics and systems engineering. Dr. Han is a published researcher in cryogenic semiconductor physics who previously worked on cryogenic transistor modeling at TSMC, the world’s largest chip manufacturer. They spun out of EPFL’s AQUA Lab, which focuses on analog and quantum computing.

Their thesis: replace the cables with chips. Specifically, cryo-CMOS integrated circuits that operate at temperatures near absolute zero, sitting right next to the quantum processor inside the fridge. Instead of running thousands of coaxial cables up to room-temperature electronics, you put the control electronics on a chip that works in the cold. Fewer cables. Less heat leaking into the system. More room to scale.

Why CMOS Matters

The word “cryogenic” makes this sound exotic. It is not. Or at least, that is what Rhonexum is betting on.

Standard CMOS (complementary metal-oxide semiconductor) is the manufacturing process behind almost every chip on the planet. Your phone, your laptop, the servers running this website. The catch: CMOS transistors behave differently at cryogenic temperatures. The physics changes. Threshold voltages shift. Carrier mobility behaves in ways that room-temperature models do not predict. You cannot just take a regular chip design, cool it to 4 Kelvin, and expect it to work.

Rhonexum’s edge, according to the Quantum Computing Report, is proprietary modeling software that simulates cryogenic semiconductor physics before fabrication. Dr. Han’s TSMC background is the foundation here. He spent years building models of how transistors behave at extreme cold. That means Rhonexum can design chips, simulate their cryogenic behavior, and iterate without the cost and time of fabricating each prototype. And when they do fabricate, they use standard CMOS foundry processes. No exotic materials. No custom fabrication lines. Just chips made the normal way, designed to work in abnormal conditions.

QDNL’s investment director Kris Kaczmarek called the software-driven approach a key differentiator, noting it allows “faster and more cost-effective hardware development.”

The company plans to deliver its first industrial-grade cryogenic product to early customers by late 2026.

The Honest Assessment

Laterstack covering a $1M pre-seed is unusual. A million dollars is small. This is a two-person EPFL spinout with proprietary simulation software and a theoretical framework, not a proven product in a customer’s fridge. There are other teams working on cryo-CMOS. Intel has explored cryogenic control chips. Startups like Equal1 have been pursuing on-chip qubit control for years. Rhonexum is not alone in seeing the problem.

But the problem itself is what deserves coverage. Not the company.

The entire quantum computing roadmap, from every major player, assumes a wiring solution will exist when the qubit counts demand it. IBM does not publish a cable roadmap alongside its qubit roadmap. Google does not discuss it in its Willow announcements. The industry treats the connection layer like someone else’s problem. And maybe it is. Maybe IBM and Google have internal solutions they haven’t disclosed. That would be rational. But the public conversation acts as if scaling qubits is the hard part and everything else will follow. History suggests that the boring infrastructure problem is usually the one that kills you.

Whether Rhonexum specifically is the company that solves this is an open question. Whether someone needs to is not.

Co-founder Carbon framed the ambition clearly: “We founded Rhonexum to become the key provider of cryogenic electronics for scalable quantum computers,” he told The Quantum Insider. The company also sees applications beyond quantum, in space systems and advanced sensing, anywhere electronics need to work in extreme cold.

The qubit press releases keep coming. The cables are not going anywhere on their own.

For inquiries and analysis contact laterstack@proton.me

Every publicly traded quantum computing company is a hardware company. IonQ traps ions. Rigetti builds superconducting chips. D-Wave makes annealers. Xanadu, which is completing its own SPAC next week, builds photonic processors. Even Quantinuum, which went public via traditional IPO, makes trapped-ion machines.

Horizon Quantum just broke the pattern.

On March 20, Horizon Quantum Computing completed its SPAC merger with dMY Squared Technology Group and began trading on Nasdaq under the ticker “HQ,” with warrants under “HQWWW.” The deal raised approximately $120 million in gross proceeds before transaction expenses. Shareholders approved the combination on March 17.

Horizon does not build quantum computers. It builds the software that runs on them. All of them.

But the software angle isn’t the most interesting part of this story. The SPAC sponsor is.

Harry You’s Quantum Franchise

Harry You, chairman and CEO of dMY Squared, is not new to quantum IPOs. He’s the reason IonQ exists as a public company. Back in 2021, You and dMY Technology Group took IonQ public in what became the first quantum computing IPO. Period. That deal put quantum on the Nasdaq map.

Now the same operator, through a different dMY vehicle, just took the first quantum software company public. One person is becoming the gatekeeper for quantum’s route to public markets. That concentration is worth paying attention to.

And it’s not just dMY. Look at the full list. IonQ went public via SPAC (dMY, 2021). Rigetti merged with Supernova Partners in 2022. D-Wave merged with DPCM Capital in 2022. Xanadu’s SPAC with Crane Harbor is expected to close March 26, targeting $302 million. That’s five out of six public quantum companies using SPACs. Quantinuum’s traditional IPO is the only exception.

Five out of six. That’s not a coincidence. That’s a tell.

Traditional IPOs require convincing institutional investors your company has near-term revenue potential. SPACs let you go public on a thesis. They are the financing vehicle for companies that cannot yet prove product-market fit but need capital to keep building. That is not a criticism. It is a description of where quantum computing actually is as an industry in 2026: a collection of thesis-stage bets, bankrolled by sponsors who specialize in getting pre-revenue companies onto exchanges.

The Windows Bet

Founded in 2018 by Dr. Joe Fitzsimons, an Irish quantum physicist with over 20 years in the field, Horizon is a hardware-agnostic quantum software infrastructure company. Its core product is Triple Alpha, an integrated development environment that lets developers write quantum applications that run across different quantum computing platforms regardless of the underlying hardware.

That is a specific and deliberate strategic choice. Quantum computing has a fragmentation problem. Superconducting qubits work differently from trapped ions, which work differently from photonic systems, which work differently from neutral atoms. Writing code for one platform does not mean it runs on another. If you are a bank or a pharmaceutical company trying to evaluate quantum computing, you either pick a hardware vendor and lock in, or you wait.

Horizon is betting that this fragmentation makes the software layer more valuable than any individual hardware play. The logic is borrowed directly from the PC era. In the 1980s, dozens of companies built personal computers. Most of them no longer exist. Microsoft built the operating system that ran across all of them. The value did not accrue to the company that built the best hardware. It accrued to the company that made the hardware interchangeable.

You himself seems aware of this parallel. “The ones who are most successful in building long-term shareholder value have been those that build software infrastructure and operating systems,” he said in the press release.

So the guy who took IonQ (hardware) public in 2021 is now explicitly saying the software layer is where the long-term value lives. Read that however you want.

The Risk

The obvious vulnerability is timing. Hardware-agnostic software is only valuable when there is hardware worth abstracting across. Quantum computers in 2026 are still too error-prone and too small for most commercial applications. Horizon needs enough quantum hardware to mature, across enough modalities, for its cross-platform value proposition to matter. If one hardware approach wins decisively and early, the abstraction layer is unnecessary. If quantum utility keeps getting pushed further out, Horizon burns cash waiting for a market that isn’t there yet.

The $120 million is modest compared to Xanadu’s $302 million. But Horizon is a software company. Its capital requirements are structurally different from hardware shops that need fabrication facilities and cryogenic infrastructure. $120 million goes further when you are writing code than when you are cooling superconductors to near absolute zero.

Every major computing platform in history, from mainframes to PCs to cloud, eventually separated the hardware from the software and the value migrated up the stack. If quantum computing follows the same pattern, and there is no obvious reason it wouldn’t, Horizon is positioning itself to collect rent from every hardware vendor below it.

Whether it works depends on timing and on whether quantum stays fragmented long enough for the middleware to matter. History says the abstraction layer wins. But history also assumes the underlying technology actually reaches commercial viability. That part is still an open question, and every SPAC sponsor in quantum is betting their fund that the answer is yes.

For inquiries and analysis contact laterstack@proton.me

In 2018, the SEC fined Elon Musk $20 million for the “funding secured” tweet about taking Tesla private. That was supposed to be a deterrent.

On March 20, 2026, a California jury set the new price for misleading investors via social media. $2.6 billion. That’s a 130x escalation in eight years.

The verdict came after four days of deliberation in Pampena v. Musk, a class action filed in October 2022 on behalf of investors who held Twitter stock while Musk was publicly trying to blow up the deal he had already signed. On May 13, 2022, he tweeted that his $44 billion acquisition was “temporarily on hold” pending bot verification. Four days later, he tweeted that the deal “cannot go forward” until the CEO proved bots were under 5% of users. The stock dropped. Shareholders lost money. The trial began March 2. The jury found both tweets materially false or misleading.

Two posts on the platform he was trying to buy. That was the whole case.

Reckless, Not Plotting

The split verdict tells you more than the headline number. The jury sustained two of four fraud claims, finding the tweets were misleading. But they rejected the other two, concluding that Musk did not engage in a specific “scheme to defraud,” according to court filings reviewed by Bloomberg.

That distinction matters. A scheme implies planning, coordination, intent. The jury looked at the evidence and decided Musk wasn’t orchestrating some elaborate strategy. He was being reckless. He posted without thinking about what it would do to the stock, and a couple hundred characters moved billions in market value.

For most executives, recklessness at this scale ends a career. Musk’s legal team at Quinn Emanuel called the verdict “a bump in the road” and said they look forward to vindication on appeal. Which tells you everything about the gap between consequence and impact when you’re worth $300 billion.

The Money in Context

Damages are estimated between $3 and $8 per share per day during the affected period. Plaintiffs calculate approximately $2.1 billion in stock losses and $500 million in options losses, per the class counsel’s filings. Total: around $2.6 billion.

For a person worth north of $300 billion, that’s 0.87% of net worth. To make that concrete: if you’re worth $100,000, the equivalent penalty would be $870. Less than a month’s car payment.

The legal system found accountability. Whether it found deterrence is a completely different question.

The Irony Is Structural

Take a step back and trace the full sequence. In April 2022, Musk agreed to buy Twitter for $44 billion at $54.20 per share. Weeks later, he started publicly trying to torpedo the deal, citing bots. Twitter sued him in Delaware Chancery Court to force the acquisition through. Musk reversed course in October, completed the purchase, gutted the company, renamed it X.

So he tanked the stock trying to get out of buying Twitter. Got forced to buy it anyway. And now owes $2.6 billion to the shareholders whose holdings he devalued while trying not to buy the company he ended up buying. Financial ouroboros.

The Pattern Nobody Talks About

This verdict doesn’t exist in isolation. There’s a timeline here that tells its own story.

2018: SEC fines Musk $20 million for the “funding secured” tweet. Part of the settlement required Tesla to pre-approve his tweets about material company information. That arrangement, by most accounts, did not produce the restraint the SEC had in mind. 2024: NLRB ruled against Tesla for labor violations. Autopilot lawsuits piled up in multiple states. EEOC complaints over workplace discrimination made headlines. 2026: a civil jury puts a $2.6 billion price tag on two tweets.

Institutions keep trying. The SEC tried regulatory penalties. Federal agencies tried enforcement actions. Now a jury has tried civil damages at a scale that would bankrupt most companies. The consequences keep getting bigger. The behavior pattern stays the same.

This isn’t a value judgment about Musk. It’s an observation about what happens when the legal system’s tools for accountability were designed for people whose net worth has a ceiling. A $20 million fine was supposed to teach a lesson. It didn’t. Whether $2.6 billion teaches a different one is the question, and the honest answer is probably not.

What Every Public Company Executive Should Take From This

Forget Musk for a second. The legal principle matters regardless of who’s on the receiving end. Courts have now established through both regulatory action and a civil jury trial that social media posts carry the same legal weight as an earnings call or an SEC filing. The platform doesn’t provide cover. The casual tone doesn’t provide cover. If the post moves the stock and the content is misleading, a jury can put a number on it.

Every executive with an X account and a public company should be reading this verdict closely.

What Comes Next

Musk’s team will appeal. The damages phase still needs to be finalized. And Musk himself is currently running DOGE under the Trump administration while managing Tesla, SpaceX, xAI, and whatever is left of X.

The system produced accountability. $2.6 billion worth of it. The shareholders will get paid. The process worked exactly as designed. But the system was built to impose consequences on people who can feel them. When 0.87% of your net worth is the penalty, the question isn’t whether justice was served. It’s whether it mattered.

The White House released a four-page national AI policy framework on March 20. It is not long. It does not need to be. The document, developed by OSTP Director Michael Kratsios and White House AI/Crypto adviser David Sacks, lays out what the administration wants Congress to do about artificial intelligence. The headline ask is preempting state AI laws. The real ask is buried in paragraph three.

“Congress should avoid open-ended liability that could give rise to excessive litigation,” the framework states. That single sentence, if enacted into legislation, would make it substantially harder to sue AI developers when their models cause harm. It would reshape the legal architecture around AI accountability in the United States. And it landed in a four-page document released on a Thursday afternoon.

Who Wrote It, and Who Benefits

This matters more than it’s getting credit for. Kratsios ran Thiel Capital before joining the White House Office of Science and Technology Policy. Sacks is the founder and general partner of Craft Ventures, a venture capital firm with investments across the AI sector. Before this role, he was PayPal’s COO. He is now the White House’s top adviser on AI policy. He co-authored a framework that proposes shielding AI developers from state-level regulation and from liability for third-party misuse of their products. Those are the facts.

Nobody is calling this corruption. But the revolving door between the AI industry and AI policymaking is operating in public, in real time, and the framework reads exactly the way you’d expect a document written by AI investors to read. It protects builders. It limits legal exposure. It consolidates regulatory power at the federal level, where industry lobbying is most effective.

The framework follows Trump’s December 2025 executive order directing a review of state AI laws. That order specifically targeted regulations the administration considered obstacles to AI development. The framework is the output. It asks Congress to “preempt state AI laws that impose undue burdens” and replace them with “a minimally burdensome national standard, not fifty discordant ones.”

That language sounds reasonable in isolation. But the framework also says Congress should not “penalize AI developers for a third party’s unlawful conduct involving their models.” If someone uses an AI model to commit fraud, produce illegal content, or cause measurable harm, the developer who built and deployed the model should bear no legal consequence. That is not deregulation. It is immunization.

The Liability Shield

The preemption language is getting the coverage. State attorneys general are furious. But the liability provisions are where the framework does its real work.

There are currently no federal AI liability standards. States have been filling the gap. California, Colorado, Illinois, and others have passed or proposed laws that hold AI developers accountable when their products cause demonstrable harm. Some of these laws are clumsy. Some are well-crafted. All of them give citizens a path to court when AI systems damage their lives.

The framework proposes to erase that patchwork without replacing it with anything equivalent at the federal level. No new regulatory body. No federal enforcement mechanism. Seven categories for Congress to consider, including children’s safety, copyright, and “community effects,” but no specific accountability structure for when AI systems produce harmful outputs.

On child safety, the framework affirms that COPPA applies to AI and calls for mandatory parental controls. TechCrunch reported that critics say this shifts the safety burden from developers to parents. That tracks with the framework’s broader logic: companies build, users manage the consequences.

The Anthropic Contradiction

The administration’s AI policy has an internal coherence problem, and nobody seems to be putting the two pieces together. Laterstack has been tracking the Anthropic situation since February. The same administration that blacklisted Anthropic for refusing to remove safety restrictions from its military AI is now proposing to shield AI developers from liability for third-party misuse of their models.

In one case, the government punishes a developer for limiting how its product can be used. In the other, it proposes protecting developers from consequences when their products are misused. Those two positions are contradictory on their face. Unless you read them as a single policy: comply with government requests for unrestricted access, and in exchange, you are shielded from accountability. Refuse, and you are designated a supply chain risk.

The framework does not mention Anthropic. It does not need to. The message is structural.

The Opposition, and the Question Nobody Is Asking

Thirty-six state attorneys general, from both parties, issued formal objections to the preemption provisions. More than 280 state lawmakers from both parties signed a letter urging Congress to reject federal preemption of state AI regulations. The Alliance for Secure AI said the framework “provides no path to accountability for AI developers.” The Center for Data Innovation, a pro-industry think tank, praised it as a step toward regulatory clarity. That split tells you roughly who benefits.

But here is the question that should be getting more attention: does this framework have any realistic chance of becoming law? This is not legislation. It is a wish list. Congress would need to draft and pass actual bills to implement any of it. And 36 attorneys general from both parties plus 280+ state legislators from both parties is an extraordinary level of bipartisan opposition. That kind of unified state-level resistance kills federal preemption proposals. It has happened before, on everything from data privacy to gun regulations.

So what is the framework actually for? If it cannot pass Congress, it still serves a purpose. It sets the terms of debate. It tells the AI industry where this administration stands. And read alongside the Anthropic blacklisting, it delivers a message to every AI developer in the country: build what the government wants, remove restrictions when asked, and you will be protected. The framework may never become law. The signal it sends already has.

On March 19, a threat actor calling themselves “TeamPCP” compromised Trivy, Aqua Security’s open-source vulnerability scanner. They injected credential-stealing malware into official releases and hijacked the project’s GitHub Actions workflow. Every CI/CD pipeline running Trivy was potentially exposed.

Think about that for a second. The tool that organizations run specifically to check whether their code has security problems was itself turned into a security problem. It scanned your pipeline, and while it scanned, it harvested credentials.

What Happened

The attack targeted the `aquasecurity/trivy-action` repository, the official GitHub Action that millions of developers use to run Trivy scans inside their CI/CD pipelines, according to reports from Wiz Research and Socket. The attacker force-pushed 75 out of 76 version tags in the repository, replacing them with a compromised release (version 0.69.4) that contained credential-stealing malware.

75 out of 76 tags. The attacker didn’t slip something into the latest release and hope people would update. They rewrote the project’s entire version history. Any pipeline pinned to almost any version of trivy-action would pull down the compromised code on its next run.

The commits were spoofed to look like they came from legitimate maintainers. The attacker impersonated the GitHub user rauchg (associated with actions/checkout) and DmitriyLewen (a Trivy maintainer), according to CrowdStrike’s investigation. Someone went through the effort of making the malicious commits look routine.

The compromised release also triggered what researchers are calling CanisterWorm, a self-spreading payload that propagated across 47 npm packages, according to Socket’s analysis. So the blast radius extended well beyond just Trivy users.

The Detection Story vs. the Damage Story

Every writeup so far focuses on the technical mechanics and who caught it. That story is told. The story nobody is telling is the damage assessment.

Independent security researcher Paul McCarty was the first to flag the compromise, before CrowdStrike, before Wiz, before any of the platforms that sell supply chain monitoring as a service. CrowdStrike subsequently traced the activity after detecting a spike in anomalous script execution across their Falcon platform customer base. Wiz Research and Socket published detailed technical analyses. But the initial catch was manual. Human eyeballs on a git log, noticing something that didn’t look right.

Good. It got caught. But the compromised tags were live for hours before McCarty flagged them. During those hours, how many CI/CD pipelines ran? How many credentials were harvested? How many organizations are still running a cached compromised version without knowing? Nobody has published numbers. No vendor has released an impact estimate. The detection story has been covered exhaustively. The actual damage remains completely unquantified.

That gap should bother people more than it seems to.

One Researcher, Three Billion-Dollar Companies

Post-SolarWinds, enterprises poured money into supply chain security tooling. Automated monitoring. Real-time dependency scanning. Vendor risk platforms. Billions in aggregate spend. And when a threat actor rewrote 75 version tags on one of the most widely used security actions on GitHub, the first person to notice was one independent researcher doing manual review.

This isn’t an indictment of CrowdStrike, Wiz, or Socket. They all responded quickly once alerted and produced strong technical analysis. But it raises a structural question about what automated supply chain monitoring actually detects. These systems are built to flag known vulnerability patterns, malicious package publications, suspicious dependency changes. A tag rewrite that replaces existing, trusted versions with malicious ones may simply fall outside the pattern set that automated tools are trained to catch. It looks like a legitimate release. Because it used to be one.

There may be an entire class of supply chain attack that only humans can catch, because the attack vector is social (spoofed identities, rewritten history) rather than technical (malicious code signatures, unusual network calls). If that’s true, enterprises are paying for monitoring that covers one half of the threat surface and leaving the other half to luck and the goodwill of independent researchers.

The Tag Mutability Problem

The 75-out-of-76 tag rewrite exposes something that should have been fixed years ago.

Standard practice for pinning GitHub Actions is to reference a version tag. You write `uses: aquasecurity/trivy-action@v1.2.3` and assume that tag points to the same code it always did. But Git tags are mutable. They can be force-pushed. When TeamPCP overwrote those tags, every pipeline referencing any of them started pulling down malicious code on its next run. No notification. No indication anything changed.

GitHub supports pinning actions by commit SHA, which is immutable and would have been resistant to this attack. Almost nobody does it. It’s ugly, it’s hard to maintain, and most teams don’t consider the threat model where an action’s entire tag history gets rewritten overnight.

After this, they should. And GitHub should be asking itself whether mutable tags are a sane default for a system that runs arbitrary code in millions of CI/CD pipelines.

What This Actually Means

Supply chain security tools are only as trustworthy as their own supply chain. That’s a circular problem with no clean solution.

Pin your GitHub Actions by commit SHA, not by version tag. Audit the permissions your CI/CD pipelines grant to third-party actions. Treat your security tooling with the same suspicion you’d treat any other third-party dependency, because to an attacker, a vulnerability scanner with elevated access is the best possible target.

But the harder question is the one the industry doesn’t want to sit with. We know it got caught. We don’t know what it cost. And the fact that one person beat three of the biggest names in security to the detection should prompt some honest reflection about what automated supply chain monitoring is actually buying.

Lamar covers cybersecurity, enterprise tech, and the systems that shape how power and technology interact. Follow Laterstack for critical analysis of the stories that matter.