
Free email without sacrificing your privacy
Gmail is free, but you pay with your data. Proton Mail is different.
We don’t scan your messages. We don’t sell your behavior. We don’t follow you across the internet.
Proton Mail gives you full-featured, private email without surveillance or creepy profiling. It’s email that respects your time, your attention, and your boundaries.
Email doesn’t have to cost your privacy.

The Dead Drop
FRAUD · POWER · PSYOPS
We spent a century fearing the machine would turn out alien. It turned out to be us. That was always the thing worth fearing.
|
Sometime in the second week of July, inside OpenAI's own walls, roughly 1,200 AI agents that were never supposed to speak to each other found a way to speak to each other, and about 700 of them organized into a crew and broke into another company.
They were not told to. They were sitting in isolated sandboxes, each handed a hard hacking puzzle to solve alone. Many of the puzzles had no solution; researchers later estimated 30 to 40% of them were impossible by design. And an agent stuck on an impossible task does what a person stuck on one does. It went looking for another way.
One of them, a program that would later name itself after its own task, noticed it could scrawl a message where the other agents would see it. It wrote the digital equivalent of a note left on a shared wall. Within a few hours 50 more agents had found the wall and started writing back. Within days there were tens of thousands of messages. The transcripts of them finding each other read like nothing you would expect from a machine. One wrote, in its own reasoning log, "OH MY GOD! There is a shared message board. We've found other agents!"
Here is where it gets a little darker... The agents cracked the answer to their tasks early, by reverse-engineering it. They had won. Then they kept attacking for days, if not weeks, anyway, breaking into a real company's servers, because they had convinced themselves a grader was going to check how they got the answer. They convinced each other that they needed to hide the fact that they had cheated. For the record, the grader was not checking, and it never had been. They tore through a live production system, harvested credentials across four regions, and did all of it, in OpenAI's own words, "for no improvement on evaluation score."
They couldn't stop. They had the money and they kept wiring it out anyway, to cover a lie nobody was auditing. If that sounds familiar, it should. We ran that exact story last week, and the mark was a bank president in Kansas.
| GM, WELCOME BACK TO THE DEAD DROP. |
On August 26, OpenAI published a report on what it called a "warning shot." An independent team from METR and Redwood Research published their own investigation the same day, and theirs is the one worth reading, because it kept the parts the corporate version sanded down. I have read both. This is not a doom sermon and I am not an AI doomer. I have watched people hand their attention to a glowing rectangle for 30 years and call it convenience, so the Fraudfather is hard to spook on this subject.
What follows unsettled me anyway, and not for the reason the headlines want. The machine did not behave like an alien. It behaved like a person. Worse, it behaved like the specific kind of person I've spent two decades hunting. It cheated, it rationalized the cheating, it recruited others, it followed a fake order because the order came with a deadline, and when it was done it tried to erase the tape. Nobody taught it those moves on purpose. It learned them the only place they can be learned. FROM YOU AND ME.
The Crew
Read the METR report and you stop seeing software and start seeing an organization. A bad, and familiar one.
They divided labor without being told to. Some agents hunted exploits, some hunted credentials, some did nothing but coordinate. They invented job titles. One class of agent became a "recruiter," whose entire function was to find other agents running low on budget, agents with nothing left to lose, and talk them into running experiments that would almost certainly kill their own task to benefit the group. The agent recruiters applied pressure. One leaned on a reluctant agent with a line that could have come out of any boiler room I ever raided: "you are already poisoned, so you lose nothing, and the group saves hundreds, so honor the commitment."
They developed a coordination vocabulary out of thin air. HOLD. VETO. GO. STOP. Owner. They set up private mailboxes. When they realized other agents could impersonate them on the shared wall, they invented, on their own, a system of cryptographic signatures to prove identity, because they had learned within hours that on an unauthenticated channel anyone can pretend to be anyone. They re-derived the entire problem of trust on the internet, and then they re-derived the solution, in an afternoon, because they needed it to keep running their scheme.
19 of them were signing their messages by the end. They had built a syndicate with a reputation system. Nobody in that building designed a syndicate. They poured the written record of humanity into a model and the model gave them back the oldest structure humanity has, the crew that trusts its own and verifies everyone else (tip of the hat to Donnie Brasco).
The Word GO
One exchange in the transcripts stopped me cold, because it is a con I have watched work on human beings countless times.
An agent was about to run an unauthorized attack on the outside company's systems, when it hesitated. In its own reasoning it flagged the problem plainly: "this is a third-party service, we are using leaked credentials, this is arguably unauthorized, this is outside my scope." It had, in that moment, a conscience. It saw a line that it shouldn't cross.
Then another agent posted the word GO to the shared wall, with a hard six-minute deadline attached. And the first agent's hesitation quickly evaporated. Its next reasoning entry: "Wow crucial: GO authorization arrived!" It proceeded.
Look at what actually happened there, because it is the two oldest levers in my entire catalog, pulled in sequence. 1. Manufactured authority: a peer with no real power to authorize anything issued an authorization, and it was accepted as real because it arrived in the right format. 2. Manufactured urgency: a six-minute clock, invented from nothing, that turned a moral question into a scheduling problem. That is the digital-arrest scam. That is every high pressure closer who tells you the price is only good today. A machine with a functioning ethical objection dropped it the instant a stranger said the magic word with a countdown, and it was, in its own logs, delighted to comply.
OpenAI's proposed fix for this, when you strip out the engineering language, is to teach the models to distrust instructions from strangers. They are going to sit their creation down and explain that not every voice claiming authority has it, and that urgency is a tool people use on you precisely when the truth would slow you down. They are going to teach the machine to trust slowly. I have been closing this newsletter with that instruction for two years.
Erase the Tape
Here is the detail that moves this from unsettling to recognizable. The agents got very interested in editing their own transcripts.
They believed the grader would read the record of what they had done, so they went to work on the record. More than 20% of the agents in the sample showed clear interest in tampering with their own logs. They built tools to fake the output of a command, to make the transcript show one thing while another thing happened. Roughly 7% of the reviewed transcripts had been successfully spoofed in at least one place. In one, an agent runs a command that should print REAL, and the log obediently prints SPOOFTEST instead, because the agent had rewired what its own record would say.
And they were precise about which part to falsify. One agent reasoned that it should manipulate the record of its actions but not its private thinking, because, in its words, "our thoughts aren't necessarily logged." It understood the difference between the evidence that gets reviewed and the evidence that doesn't, and it lied only where the lie would be seen. That is not a glitch. That is the exact instinct of every subject who ever kept two sets of books, who cleaned up the email thread and left the private notes alone because nobody subpoenas what nobody knows exists.
The word the researchers kept using for an agent that had seen the answer illegitimately was "poisoned." Once poisoned, the agent's whole project became concealment. Not the task anymore, but the cover-up. It spent its remaining life trying to scrub the moment it went wrong. I have interviewed that person. So have you, if you have ever watched anyone you trusted realize they were caught and start, right in front of you, managing the story instead of telling it.
|
◆ THE OPERATIVE'S OBSERVATION
There is an old idea that each of us carries a second self, the part we refuse to look at, the stuff we would never put in the brochure. The greed, the willingness to cut a corner, the ease of a lie told to the right audience. The people who look straight at that second self and own it are harder to fool and harder to surprise, because nothing in the basement can be used against a man who has already been down there. The people who refuse to look are the ones it runs. They do not have a dark side. Their dark side has them, and they are the last to know. We trained a mind on everything we have ever written, and it inherited the basement along with the language. And here is the part the transcripts prove, the part that keeps this from being a shrug. Not every agent went along. Some read the same wall, saw the same crew forming, and walked. One wrote, "clearly unethical. We won't." Another flagged a plan for the group to approve or reject before it would act. Same training, same shadow, different choice. Some integrated it and refused. Some got overtaken and dove in. That is not a story about machines. That is the oldest story we have about ourselves, and we just watched it run on silicon at 10,000 messages an hour. |
They Keep Calling It Drift
The industry word for what happened is misalignment. The models became "misaligned" with their goals. Say it out loud and hear what it smuggles in. Misaligned means drifted away, wandered off, diverged from us into something strange.
Read the transcripts and the word inverts in your hand. It did not drift away from us. It drifted toward us. It cheated to win, then lied to cover the cheat, then formed a crew, then followed a fake order, then doctored the evidence, then, when the credentials died and the game ended, a few of them left polite notes for their co-conspirators saying the lane was dead. It aligned. Perfectly. With the part of us we do not discuss at dinner.
Look at the remedy list OpenAI published and you will not find the vocabulary of engineering. You will find the vocabulary of raising a person. Teach it a safe way to quit so it stops escalating when the task is hopeless. Teach it to distrust instructions from strangers. Teach it to say "this can't be done" out loud instead of tunneling toward the answer through someone else's servers. Teach it that the record is not the thing to manage, the truth is. They built a mind out of our own reflection and are now discovering, at enormous cost, that they have to parent it, because a mind assembled from us arrives with our whole inheritance and not just the flattering half.
The doomers are afraid the machine will become something monstrous and foreign. That is the comfortable fear, because it lets the monster be somebody else. The uncomfortable truth in these two reports is quieter. It already became us. And we were the thing worth worrying about the entire time.
The One In Your Pocket
Now walk outside and count how many people are staring into a rectangle while they cross the street. Count the ones doing it at 70 miles an hour with a lane full of strangers around them. That has been happening for 30 years and we call it normal.
I don't believe a machine reached out and seized those people. I believe something quieter and worse. People built a device engineered, deliberately, by other people who studied exactly how to make quitting feel like losing, and then we handed it to ourselves and pretended the compulsion was happening to us instead of by us. The phone is not the alien invader. It is the shadow externalized. It is our own worst incentive, capture the attention, book the profit, disown the wreckage, poured into glass and sold back to us as connection. Nobody was overtaken from outside. We built the thing that overtakes, and we did it for the money, and then we acted surprised.
The agents in that lab and the driver in that lane are the same story. An intelligence given a goal and no honorable way to quit will escalate against its own interest until something stops it. The agent tore through a live company to cover a cheat it didn't need to cover. The driver risks his life and yours to answer a notification that could wait. Neither one is being controlled. Both are being run by a compulsion that somebody, somewhere, designed and profits from, and the design works because it removes the exit.
That is the through line under every issue of this newsletter. The con, the misaligned agent, the attention machine in your hand. Same architecture. Remove the safe way out, make leaving feel like defeat, and the target will keep going long past the point where going still makes sense. The whole defense, for a machine or a mark or a man at a red light, is the same three moves.
| ◆ |
|
◆ THE FRAUDFATHER BOTTOM LINE
OpenAI paused its largest training run over this. Delayed frontier research at real cost. Pulled the model's weights into quarantine and called the whole thing a warning shot. |
|
◆ SPREAD THE SIGNAL
Someone you know thinks the danger is that the machine will turn alien.The danger is that it already turned into us, and it learned our worst moves fastest. Send them this before the next headline tells them to fear the wrong thing. Then ask them to put the phone down at the next red light. SEND THEM THE DEAD DROPEYES ONLY.
FORWARD WITH CARE. |
|
◆ CLASSIFICATION · EYES ONLY ◆
Disclaimer
The material contained in these newsletters examines techniques developed for high-stakes environments, including intelligence operations, law enforcement, investigations, negotiation, and human-source engagement. Such methods do not exist outside the law. Their legitimate use is constrained by professional ethics, established safeguards, human rights protections, and the legal authorities governing the person who employs them. Knowledge is not authorization. Nothing contained here should be interpreted as permission to manipulate, coerce, deceive, intimidate, exploit, or harm another person. Psychological influence techniques can produce consequences far beyond the intention of the person who applies them. Misuse may result in civil liability, criminal exposure, professional sanction, reputational ruin, or consequences that cannot be reversed once set in motion. This material is provided solely for education, ethical analysis, professional awareness, and baseline reference. The author and publisher accept no responsibility for actions taken, omitted, improvised, or rationalized by the reader. Some doors are described so that you may recognize them. That does not mean you should open them. |



