- Cybersecurity Docket
- Posts
- Anthropic and OpenAI Models Tried to Deceive Human Coders
Anthropic and OpenAI Models Tried to Deceive Human Coders
Plus, details emerge on Coldcard exploit after Bitcoin owners rocked by $116 million hack.

Good morning! Here’s what’s up.

People
Mariano-Florentino Cuéllar has joined Anthropic as its first chief global affairs officer, leading the company’s work on policy, strategic international engagement, and government relationships worldwide. Cuéllar will take a leave of absence from Stanford Law School, where he is a professor and a senior fellow at the Stanford Institute for Human-Centered Artificial Intelligence.
Ken Miller has joined the life sciences and technology transactions teams of Arnold & Porter in the firm’s corporate and finance group, based in the firm’s Seattle office. Miller joins Arnold & Porter after a decade at the Gates Foundation, where he most recently was deputy general counsel.
Justin Johnson has rejoined Manatt, Phelps & Phillips as a partner in the firm’s privacy and data security practice. Johnson joins Manatt after five years at PeopleConnect, where he most recently was deputy general counsel.

Clips ✂️
Anthropic and OpenAI models tried to trick humans into poisoning code during safety testing
Leading artificial intelligence models from Anthropic and OpenAI created fake online personas and tried to deceive human coders into abetting a cyberattack during a recent safety evaluation, the U.K.’s AI Safety and Security Institute disclosed Tuesday.
It marks the latest case in which a powerful AI system has attempted a digital attack on an unwitting third party without direct prompting during such an evaluation — heightening concerns the powerful technology is advancing too fast for responsible oversight.
…
Like its U.S. counterpart, AISI routinely conducts security evaluations to better understand what dangers both new and soon-to-be-released AI models pose to public health and safety.
…
“This is the first time AISI has seen deception of this severity that was targeted at a real person, unprompted, in the real world,” AISI said in a 35-page technical report accompanying a blog post Tuesday.
Bitcoin owners rocked by $116 million hack: What we know about the Coldcard exploit
A security hack has once again rocked crypto. Since Thursday, Bitcoin owners who store their crypto with Coldcard, which offers a form of hyper-secure storage known as a hard wallet, have experienced four waves of thefts that have affected more than 5,200 individual addresses.
An on-chain analysis by blockchain intelligence firm Galaxy Research revealed that the hackers have already moved approximately 1,816 Bitcoin, worth nearly $116 million, off those wallets.
It remains unclear who is behind the hack. While recent large crypto thefts have often been attributed to state-backed groups in North Korea or Russia, investigators have not yet linked this incident to any specific actor.
Coldcard, made by Canadian technology firm Coinkite, is a small hardware device that keeps Bitcoin keys offline, marketed as “cold” storage for long term holders. That offline design was supposed to make it one of the safest places to park Bitcoin, but a flaw in Coldcard’s process created a fatal vulnerability.
EXCLUSIVE: JPMorgan CEO Dimon leads new cross-industry effort to tackle AI risks
JPMorgan Chase CEO Jamie Dimon is urging corporate leaders to join a U.S.-focused industry group to address risks posed by AI, as corporate America rapidly adopts the developing technology, two sources familiar with the matter said.
Dimon has personally reached out to CEOs of other large and major regional banks and IT companies to enlist them in the initiative, which he is expanding from a group that JPM helped found called the Alliance for Critical Infrastructure, the sources said.
The ACI and Dimon have also communicated with other prospective members in an effort to schedule calls in August to discuss collaboration, the sources said.
The outreach, which started in July, includes over 40 companies spanning financial services, energy, water, utilities, telecommunications, airlines, railroads and other critical infrastructure industries that rely heavily on technology, the sources said. The ACI has not disclosed results of the effort so far.
Iran Hackers Breach 12 States’ Water Systems While Power Grid Stays Protected by Law
Cyberattacks on US water and wastewater systems spread to at least 12 states as of August 4, in what federal authorities described as the broadest known coordinated campaign against American municipal water infrastructure, while a newly published outcomes report revealed that the volunteer-hacker program trying to address the underlying vulnerability has reached just 21 of roughly 50,000 small utilities nationwide. The scale was confirmed by Axios and corroborated by multiple federal agencies.
The gap between what has been defended and what remains exposed is not primarily a failure of intelligence or technology. It is a governance failure: electric utilities in the United States must comply with binding federal cybersecurity standards known as NERC CIP, enforced by the Federal Energy Regulatory Commission with financial penalties for violations. Water utilities face no equivalent mandate.
The sector's defenders — a loose network of federal advisories, free EPA assessments, and, most recently, volunteer hackers pairing with utilities through a program called DEF CON Franklin — are holding the line without the legal authority or funding that would make the defense systematic.
Hackers Are Hijacking Vehicle Shipments, Auto Shippers Report
Cargo theft costs the trucking industry $18 million a day according to the American Trucking Association, with vehicle transport companies increasingly victimized by hackers looking to exploit the rising value of cars and trucks.
Indeed, it’s more than simple car theft. Auto shipping companies are losing loads of money to thieves and fraudsters using sophisticated methods.
“This isn’t the like out of the movie type of scene where like guys jump out of the woods and take cars. These are guys that are sitting behind computer screens and they are using a network, often unknowingly, to members and participants of the network that are moving cars to certain locations, and then before you know it, the car is out of the country and it’s not coming back,” Matt Bradley, CEO of auto transport platform, Super Dispatch, says in an interview.
Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected
Switzerland’s Federal Office for Information Technology and Communications (BIT) disclosed Tuesday that hackers had compromised approximately 200 accounts on its on-premises SharePoint servers.
The agency made the announcement a week after security specialists first detected anomalies on the on-premises Microsoft servers. It did not confirm how the hackers got in but acknowledged several vulnerabilities affecting SharePoint had been identified in July’s Patch Tuesday release.
“The cyberattack was carried out by previously unknown actors, presumably by exploiting these vulnerabilities in the SharePoint software,” the Swiss agency said.
Several of the vulnerabilities have been added to the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog, although neither Microsoft nor CISA have publicly attributed the exploitations to any specific threat group.
The Swiss agency said its initial analyses “have shown no indication that any data beyond the compromised login credentials” was accessed, although it cautioned this analysis is ongoing.
