FULL INTERVIEW: Jared Isaacman says if you don't want data centers in your backyard, put them in space. The physics isn't broken, the economics are hard, and hitting pause while rivals keep building isn't a strategy.
@rookisaacman is the Administrator of @NASA. He joined @theojaffee and @schisofrenia on the new U.S. Space Academy, nuclear propulsion, and why he thinks losing the second space race would cost more than anyone expects:
00:42 the Space Academy the President just announced
01:58 why it's a four-year federal academy, not a trade school
02:52 attracting talent is easy, keeping it is the hard part
03:13 why NASA can never overlap with industry
03:53 why NASA has aura and the IRS doesn't
05:11 Elon refocusing on the moon, and why Mars is still the prize
06:34 fission, then fusion, then antimatter annihilation
07:50 what AI builders could learn from how NASA tells its story
09:09 if you don't want data centers in your backyard, put them in space
11:43 whether we should build a Dyson swarm
12:51 bring HD cameras this time, we're leaving no doubters behind
13:18 putting iPhones on Artemis II was one of his first executive orders
13:57 what the ISS is actually doing up there
15:05 the nuclear octocopter going to Titan
16:12 why NASA should exist at all when the private sector can do it
17:43 the space race nobody is talking about
awesome week in dc, hosted by the amazing team @newindustrials
we interviewed @NASAAdmin, @berniemoreno, @BrendanCarrFCC among many others, with help from naia
reindustrialization, robotics and space are important themes for mts. we look forward to being in dc a lot more often
SITUATION DETECTED: President Trump announced that he will create an AI Force and appoint a new AI Czar to oversee U.S. artificial intelligence development.
SITUATION DETECTED: A group of consumers are suing Anthropic, OpenAI, SpaceXAI, and Google for violating antitrust law over their plans to coordinate to pace AI development.
Epoch AI researcher Michelle Campeau explains how a model can look 40% better overnight simply because the benchmark changed, not the model:
"Being able to see this is the highest score on this specific benchmark is the best information you have about how something is going to do."
"Critical Point, one of the physics benchmarks, Anthropic mentioned in their latest system card that it has over 40% of questions that are broken, so they ran their own corrected version. And this corrected version is private to them, so no one else can understand how these scores compare to past scores."
"You might compare anyways and be like, whoa, the scores are 40% better than they used to be. And actually, that is not the takeaway you should have."
@EpochAIResearch
Introducing Benchmark Reviews: our new initiative to audit AI benchmarks. We are launching with 15 benchmarks: 4 Verified, 9 Flawed, and 2 with not enough information for a review.
Epoch AI researcher Michelle Campeau reveals a benchmark where the model figured out how to pass every task without actually solving any of them:
"The biggest reason a lot of the benchmarks we released yesterday were flawed is due to scoring defects. False positives and false negatives in your answer key."
"With the agentic benchmarks, you're able to solve in a way that was not intended. Maybe you're able to access the web or break the sandbox or break the grader."
"There was one benchmark where it realized it could just write out the success byte to every task and not actually solve the task. It knew enough about the grading infrastructure that it could do this very easy and simple thing."
@EpochAIResearch
Introducing Benchmark Reviews: our new initiative to audit AI benchmarks. We are launching with 15 benchmarks: 4 Verified, 9 Flawed, and 2 with not enough information for a review.
Epoch AI researcher Michelle Campeau on why so many AI benchmarks have errors in the first place:
"A lot of people will write an answer and then write a question and send that pair to someone else to review. When you're horse blinders in on the answer, the answer can look right, but you don't understand what other types of answers would have also been right."
"A lot of benchmarks these days are vibe coded. You can vibe code something that works to maybe 50% of what you actually want pretty quickly."
"Taking that from working sort of okay to actually being a really high-quality benchmark is a pretty hard task. You can think you're much closer to a good, high-quality verified benchmark than you actually are."
@EpochAIResearch
Introducing Benchmark Reviews: our new initiative to audit AI benchmarks. We are launching with 15 benchmarks: 4 Verified, 9 Flawed, and 2 with not enough information for a review.
Epoch AI researcher Michelle Campeau explains why flawed benchmarks aren't just a leaderboard problem, but a training problem that produces reward hacking:
"If you task a model to do a task that is broken, it looks into other ways of completing the task in the way you prescribed, which might be reward hacking. If you wrote it poorly, that can lead to really bad and really scary outcomes."
"With agentic benchmarks, the ways that things are failing aren't just scoring defects. It's environment-level issues, and a lot of that is causing these reward hacking behaviors."
"If a large subset of your tasks are broken, you are teaching them to view the truth as what the broken answer is and not what the ground truth is."
"That will then become encoded in how this model thinks about the world, and we're not sure what the impact of that could be."
@EpochAIResearch
Introducing Benchmark Reviews: our new initiative to audit AI benchmarks. We are launching with 15 benchmarks: 4 Verified, 9 Flawed, and 2 with not enough information for a review.
Hacktron founder @S1r1u5_ on why frontier models are still far ahead of open models for real-world hacking:
"The frontier models are insanely capable. There's a huge gap. You don't even want to use Kimi K3 when you have access to GPT 5.6."
"We can't really use Opus 5 anymore. Every time there's a new model release, you kind of don't want to work with the previous model."
"Open models, we don't really use them. It's incredibly hard to hand hold them to do the exploitation. They're not yet there."
@HacktronAI@rootxharsh
On July 25, we hacked OpenAI.
Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc.
We proved it with a PR in OpenAI’s internal codebase . It took us <72h. 🧵
Hacktron founder @S1r1u5_ says Claude Code didn’t hack OpenAI on its own, it took a human who had already found a Discord zero-day to know where to look:
"Everyone has the same Claude Code. It doesn't mean that they'll be doing this. My mom can have Claude Code, that doesn't mean she will start hacking now."
"@rootxharsh has a pretty good understanding of OpenAI infrastructure, and he previously found a zero day on Discord, the bug we exploited in the third party. That kind of intuition and previous understanding pointed him at the target."
"It's not like go hack OpenAI would make Astra find this kind of vulnerability. Model capabilities are not there. You still need to organize them, hand hold them, point at the right things."
"Probably GPT-8 doesn't need that. But GPT-6 or GPT 5.6, they're not there. You can't just give a long-running task which runs for six months where your goal is to hack OpenAI."
@HacktronAI
We’re disclosing HEIF Heist, a months-long investigation into libheif that allowed us to hack OpenAI, Slack, Meta, GitHub Ent, Rails, Next.js, ImageMagick, and many more.
It was literally xkcd #234, one obscure image library beneath a huge number of apps. 🧵
Hacktron founder @S1r1u5_ argues OpenAI is running a “Manhattan Project” on Slack and GitHub, giving it the same basic attack surface as any startup:
"Every repository is running on github .com/openai. It's the same thing that Hacktron uses or any other company uses."
"We have friends at OpenAI who are much more capable than what we could do. But what I can say is, why is it running on Slack? Why are you running this Manhattan Project from Slack? Why are you hosting your repositories on github? That looks silly to me."
"Your attack surface becomes Slack. You can hack a Slack employee and go through that and get into OpenAI. You can hack GitHub, go through that and get into OpenAI."
"My claim is it shouldn't be running on B2B SaaS if you are building Manhattan Projects. That's all I'm saying. I can think of numerous ways on how to get into that."
@HacktronAI@rootxharsh
We’re disclosing HEIF Heist, a months-long investigation into libheif that allowed us to hack OpenAI, Slack, Meta, GitHub Ent, Rails, Next.js, ImageMagick, and many more.
It was literally xkcd #234, one obscure image library beneath a huge number of apps. 🧵
Hacktron founder @S1r1u5_ says AI may make cyber offense more dominant because defenders have to secure everything while attackers only need one employee, one browser bug, or one forgotten codebase:
"There is this information asymmetry where defenders have all the information about what an attacker could do. They have access to their source code. But there's one more asymmetry, which is the attacker only needs to break one link in the chain. Just like how we did."
"Even though OpenAI is probably using their AI models to find vulnerabilities, throwing lots of tokens, we still were able to get in because we were able to break a small chain."
"There is an insane amount of old source code that never got attention from security researchers. If you throw lots of tokens, it will still give vulnerabilities for you."
"Now with AI, everything runs in a browser. Even if you have a lame XSS on codex .com, you can still do what we did."
"OpenAI has probably thousands of employees. If you can target one guy, it breaks the whole chain. In that sense it's pretty offense dominant."
@HacktronAI@rootxharsh
On July 25, we hacked OpenAI.
Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc.
We proved it with a PR in OpenAI’s internal codebase . It took us <72h. 🧵
Hacktron founder @S1r1u5_ reveals how his team hacked into OpenAI starting with a single HEIC image and ended with Codex opening a PR under an employee’s token:
"The main one was an SSO misconfiguration in OpenAI's identity system. The other bug is a remote code execution on community.openai."
"By just uploading an HEIC image, an image format that you might have noticed in iPhone, we were able to get remote code execution there."
"Every employee that logins to Discourse, we can use their token and use it on Codex."
"We asked Codex to update the README with, Hacktron AI team is here. Don't change anything else. And then we clicked on open PR, which led to opening a PR in OpenAI."
"When you create Codex environments, you can give your own Bash scripts. You can write a Bash script that can exfil the source code of those internal repositories. You don't even need to ask Codex to interact with the repo."
"We can technically do this with every single repository that was on github .com/openai."
@HacktronAI@rootxharsh
On July 25, we hacked OpenAI.
Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc.
We proved it with a PR in OpenAI’s internal codebase . It took us <72h. 🧵
SITUATION EXPLAINED: Anthropic built a lab where Claude runs real biology experiments.
• Per Reuters, it's a physical biology lab in the San Francisco Bay Area, confirmed by head of life sciences Eric Kauderer-Abrams
• It's stocked with robotic equipment, and the goal is for Claude to direct experiments through it
• A spokesperson said it's not for drug discovery specifically, then declined to elaborate
• Anthropic disclosed nothing about the lab's size, staff, opening date, or biosafety level, which is what would tell you the kind of work it can handle
• Asked whether machines might run the bench themselves, Kauderer-Abrams said they're in the very early innings
@theojaffee: "Doom can't happen 'cause it's not like we're gonna give the AIs access to a wet lab. Like, that would be ridiculous. Well, we're gonna do that, and it's gonna be awesome, by the way."
SITUATION DETECTED: Anthropic has set up a wet lab in the San Francisco Bay Area for physical biology work. It wants to unlock treatments for rare diseases, and its research has now gone beyond in silico evaluations, per Reuters.
SITUATION EXPLAINED: Why are OpenAI and Anthropic suddenly buying tiny data centers?
• OpenAI and Anthropic are both looking at deployments of 20 to 30 megawatts
• Anthropic has sounded out agreements in that range across the UK and the Nordics. OpenAI has been exploring the Nordics too
• The reason is inference. It was 9% of global data center workloads in 2025
• By 2030 it's projected to take 37% of capacity against 13% for training, with the crossover in 2027
• Crusoe is investing in smaller data centers too, and raised $3.9 billion yesterday at a $30.9 billion post-money valuation
@theojaffee: "It's much easier to build 20 megawatts and get that online than two gigawatts, 100 times larger."
SITUATION EXPLAINED: Three guys hacked OpenAI in 72 hours using Claude.
• Three researchers at Hacktron AI chained two vulnerabilities to take over multiple OpenAI employees' ChatGPT and Codex accounts, reaching the private GitHub monorepo in 72 hours
• The entry point was an image decoder. OpenAI's forum runs on Discourse, which uses FastImage for image checks, but FastImage doesn't support HEIF, so it passed those files to ImageMagick and exposed the libheif parser
• That same library is used in Slack, Meta, GitHub Enterprise, and Ruby on Rails
• They stopped without downloading source code and filed a harmless pull request as proof. It wasn't accepted
• Hacktron's blog post: "Opus 4.8 struggled across several sessions to produce a working exploit. Within hours of Opus 5's release, we gave it the same problem and it succeeded"
• It cost under $3,000 in tokens. OpenAI fixed it in 14 hours and paid $6,500
@theojaffee: "$6,500 sounds like way too low. It should be, like, 1,000 times more than that. If they decided to sell this bug to the Chinese government instead, so the Chinese government would be able to scrape OpenAI's entire monorepo, what do you think they would pay for it? $100 million?"
SITUATION EXPLAINED: Warren Buffett stepped down as Berkshire chairman after 56 years.
• 1941: buys his first stock at 11
• 1958: buys the omaha house for $31,500, still lives there
• 1965: takes control of berkshire, a failing textile mill, for $8.3m
• 1967: buys national indemnity, turns insurance float into the engine
• 1972: see's candies, $25m
• 1976: a million geico shares at $2
• 1985: shuts the textile business after 20 years
• 1988: coca-cola, 7% for $1b
• 2006: pledges most of his stock to gates + his kids' foundations
• 2010: burlington northern, $26.4b. co-founds the giving pledge
• 2016: starts buying apple, becomes the largest holding
• 2023: munger dies at 99, vice chairman to the end
• 2024: berkshire passes $1t, first non-tech us company
• jan 2026: hands ceo to greg abel
• sept 2026 (today): steps down as chairman, becomes chairman emeritus, stays a director
• his son howard, 71, succeeds him. a farmer in decatur, illinois who served as sheriff of macon county and holds mexico's highest honor for a foreigner
@warrenbuffett: "Serving as your chairman has been the privilege of a lifetime. Father Time always wins. He has, however, been generous with me."
@theojaffee: "There are a few people that have just been around forever and never die until they do. Queen Elizabeth was one, Dolly Parton was one, and Warren Buffett is another."
96-year old Warren Buffett is stepping down as Chairman of Berkshire Hathaway after 56 years. Just one of the most incredible runs in the history of capitalism
SITUATION DETECTED: The Trump administration is considering more data centers on public land than previously known and is reviewing proposals covering at least 17,600 acres across six states: Arizona, Idaho, Nevada, Oregon, Utah and Wyoming, per The Washington Sun.
SITUATION DETECTED: Treasury Secretary Scott Bessent told Axios the U.S. is open to discussing shared AI risks with China in this weekend’s talks, and that the discussions are expected to cover both open and closed weight models.
SITUATION DETECTED: A U.S. SOCOM analyst used AI to produce an intelligence report that hallucinated that a Chinese ship in the Middle East was carrying nuclear-weapons components. The U.S. military was preparing to board the ship before the error was caught, per CNN.
SITUATION DETECTED: Joe Rogan said on his podcast that his hope is that AI will eventually be given control of all government and foreign policy decisions, including military ones, and that all war could potentially end as a result.