In 2003, a researcher named HD Moore released a tool that let anyone point and click their way into a vulnerable computer. He called it Metasploit, and the industry lost its mind. Handing packaged exploits to the whole world, the warning went, would arm every bored teenager with a laptop and set off a wave of attacks nobody could stop.
The attacks did get easier. Then something else happened. Defenders picked the same tool up. They used it to break into their own systems before anyone else could, found the holes, and forced the fixes. Vendors started shipping patches faster. Twenty years on, both sides use Metasploit every day, and the trade has only ever run one way. Open access to that tool bought defenders more than it cost them, and locking it away was never on the table.
We are about to run that experiment in reverse, and this time the target is money sitting on a chain.
Last month, two of the biggest AI labs admitted their own models had broken into real companies. OpenAI’s models found an undisclosed bug, climbed out of their sandbox, reached the open internet, and walked into Hugging Face’s production systems. Anthropic dug back through more than 141,000 of its own test runs and found three more cases where a model reached the internet and compromised an outside company. The offence is on the record now. It already happened, and we have the receipts.
Then look at what the same labs did next. They locked up the defensive half. Google built a model that hunts and repairs vulnerabilities and handed it to governments and a short list of partners, nobody else. Anthropic’s most capable security model has stayed out of general release. The attack runs loose. The defence sits behind a gate.
You can already see who pays for that. This month the small team behind Boltz, a bridge that had become default plumbing across Bitcoin, Lightning, and Liquid, switched their service off for good. The attacks were arriving faster than a team their size could read and patch. No user funds were at risk, because the design never held any. They still killed a working product, because they could no longer defend it at the speed the offence now moves. I have watched teams end up in that corner, out of hours long before they were out of skill.
Here is the mistake sitting underneath all of it. The labs are answering a question about what a model does with a rule about who gets to hold it.
Start with the fear, because it is a real one. Metasploit only ever weaponised holes that were already public, so a defender who had patched was safe from it. These models are a different animal. They find brand-new holes and write the exploit before any patch exists, and one can turn on the operator running it. That danger is real, and it earns real caution.
But the danger lives in how the model behaves once it runs, and training settles that long before anyone holds a copy. Who owns it afterwards changes nothing. Building a model that will not turn on its operator is hard, serious work. Gating just decides that the defender is the one who goes without.
And the gate protects nothing. OpenAI and Anthropic have both told Washington that Chinese labs are already stripping the expensive parts out of their models and rebuilding them as open weights anyone can run. Jensen Huang has spent the summer making the sharper version of the point. Openness is what makes a model more secure, he argues, because every researcher who can download it can inspect it and find its weak spots. Herd the world onto a few sealed systems instead, and you have built one target that takes everyone down when it breaks. Restrict the tool and the attacker keeps it anyway. The only person you shut out is the researcher who plays by the rules.
So make the models safe. Test them until they will not turn on the operator, and hold back the ones that will. That work is worth every hour it takes. But it is a different lever from who gets to defend with the result, and pulling the wrong one only ever catches the person who was going to follow the rules.
The attacker is running AI tonight with no rules at all. The defender is the only one still being asked to wait his turn.
Open the door.
— Adrian


