Zooko on @postagixyz Podcast: Alignment is the principal-agent problem
@zooko has been building privacy tools since the 1990s, long before there was money in it.
@sreeramkannan and I had a conversation with him recently. It changed how I think about privacy altogether.
His argument is that privacy is controlling disclosure. It comes from keeping your value private. Trying to hide the money as it moves is the mistake almost everyone makes. Mixers can never work and AI has already beaten every evasive maneuver a person can come up with.
Then he turns the same lens on AI. He also says alignment is an old question. It is the principal-agent problem. Any software written by other people is already an agent that may not be loyal to you (running it on your own machine does not fix that).
Lawyers owe their clients a duty of loyalty. He thinks the same rule should apply to AI.
Chapters:
00:00 Highlights
00:26 Privacy is controlling disclosure, not hiding
13:08 Privacy comes from value at rest
14:08 The Shapeshift lesson
16:00 Why mixers can never work
16:52 AI beats evasive maneuvers
17:51 Buying protonmail with shielded Zcash
28:50 Three levels of verifiability
31:21 Deterministic inference
35:37 Why Zooko doesn't trust computers
42:46 Running it locally doesn't make it loyal
46:01 AIs are just other people
54:47 The duty of loyalty
1:00:04 A trillion humans next year
1:07:56 Three categories of reputation
1:11:36 Reputation belongs to the edge
1:15:18 Staking a bond to submit a PR
This is a great summary on necessity for defensive acceleration. IMO, this is one of the four steps in what does cryptography in post-AGI world should look like.
First and the easiest one is to utilize AI for optimizing implementations of cryptographic schemes, to make better use of underlying hardware. This is a lot like regular software optimization.
Second step is the defensive acceleration by robustifying the security of our existing cryptographic schemes, hardness assumptions and implementations.
Third step is to discover newer cryptographic schemes for existing cryptographic primitives. For example, come up with better zk schemes over a particular field, practical schemes for IO, etc.
Fourth step is to do open-ended discovery of new cryptographic primitives itself that is unknown to us ("alien cryptography") and potentially critical for an internet where agent-to-agent communication and delegation to agent is going to be dominant vector.
The last three steps will take a coordinated effort across the cryptography community.
Today I call upon the blockchain industry to calmly begin planning for "bunker mode". My personal recommendation is to set in motion a controlled mass migration of assets to fresh addresses, i.e. addresses whose pubkeys remain hidden behind a hash.
Holders, starting with large and sophisticated ones, should consider moving the bulk of their funds to addresses that have never signed a transaction. And when they do sign one, they should also move remaining funds to a new address (possibly generated from the same seed phrase).
Don't rush. While I believe there is cause for action a rushed migration would do more harm than good. Don't panic either. Moving assets to protected addresses is a simple, preventative step which does not require new cryptography or new wallets.
IMO it is now reasonable to brace for the possibility that ECDSA breaks before qday, in the worst case in months not years. By "break" I mean fast private key recovery (e.g. in one week) on available hardware (e.g. a large GPU cluster).
Recent days have been humbling for human mathematical intuition. Long-held, unquestioned hypotheses have fallen. This includes the n log(n) bound for integer multiplication and the 3SUM conjecture. In hindsight, May's unexpected disproof of the Erdős unit distance conjecture was our warning shot.
Yesterday's OpenAI drop made it clear that mathematical superintelligence is upon us. They say there are weeks where decades happen. We are about to live through weeks where centuries of mathematical progress happen. Could our magic 64-byte ECDSA signatures be too good to be true? Was it just security through obscurity all this time?
Elliptic curves feel especially vulnerable to superintelligence. Curves carry rich structure, with room for fancy tricks like Schoof, Frobenius, pairings. (By contrast, hashes are designed to minimise algebraic structure.)
Separately, as Ewin Tang can attest, an efficient quantum algorithm sometimes foreshadows an efficient classical one. We should be open to the possibility of a classical counterpart to Shor that breaks elliptic curves and RSA at once.
Also noteworthy is the striking under-representation of cryptographic breakthroughs among the 722 mathematical results OpenAI published. I've witnessed first-hand the US government censoring academic quantum cryptanalysis results. Backroom interventionism is my base case.
I urge large, sophisticated actors to lead by example. Project11's "risq list" (bitcoin-risq-list.projecteleven[.]com) is a great tracker of exposed BTC pubkeys. Binance, Bitbank, Robinhood, Bitfinex, and Tether have an opportunity to harden their cold storage. Next month I'll address institutions in London in a live Q&A (forum.ethereuminstitutional[.]org/london-2026).
Again, please do not rush. Wallets holding under 50 BTC enjoy partial cover from "Satoshi's shield", i.e. his 20K exposed addresses that hold 50 BTC each. Load-bearing signers like oracles and L2 security councils should consider rotating ECDSA pubkeys with every signed message and/or multi-signing with a hash-based schemes like SPHINCS.
Exiting bunker mode safely will require post-AI cryptography. My inclination is to go all-in on hash-based cryptography and avoid structured mathematical assumptions entirely, whether from curves, lattices, or isogenies. A single battle-tested hash (e.g. from the SHA or BLAKE families) yields plausible post-AI security.
The Ethereum roadmap on strawmap[.]org fully embraces hash-based cryptography with end-to-end formal verification as a response to the quantum threat. Those timelines must now be revisited and accelerated in light of mathematical superintelligence. I'll be pushing for maximum defensive acceleration.
Ben Turtel on the PostAGI Podcast: what if AI breaks out like a virus rather than like a genius
AI got good at math and code first because you can generate a million problems and check every answer automatically. Most of what humans actually deal with has no answer key, so that is where models stay weak.
@sreeramkannan and I talked to @BTurtel of Lightning Rod Labs, who trains models using time instead of labels. The model predicts what happens next and the world grades it. No labeling required, because the future does the checking. The result surprised them. A fine-tuned GPT-OSS-120B on a single GPU often ranks first on public forecasting benchmarks, with a wide lead in sports and politics on ProphetArena. His read is that this trains a different kind of reasoning rather than more of the same.
It also handles the contamination problem. As the web fills with AI-written content, a model trained this way learns which sources to discount, because unreliable information makes it lose.
Then the part that stayed with me. When people imagine AI breaking out, they picture something very smart. But evolution does not only select for intelligence. One theory of viruses is that they began as machinery inside cells that broke free and started their own lineages. A small, dumb model that is hard to kill and good at finding compute is a scenario almost nobody is preparing for.
At @EigenLabs we think about the non-adversarial version of this, where agents run institutions rather than escape them.
Chapters:
0:00 Highlights
1:31 The concentration risk
4:19 Offense beats defense
6:50 Training on time, not labels
9:44 Who has the alpha
11:32 Contaminated data
13:16 Backtesting without leakage
14:52 Beating the frontier models
16:36 Does it understand cause and effect
21:55 AI might break out like a virus
22:41 Agentic companies
25:04 Can an agent own money
HELP US DEFEND THE INTERNET
Hash functions are a foundational part of our most critical systems:
- HTTPS
- Digital signatures
- DNSSEC
- SSH
- Key derivation
- Blockchains
- Zero knowledge proofs.
AI is about to become extremely good at attacking these systems.
So why not coordinate a swarm to defend them first?
We @YukonResearch are teaming up with @Zcash and @projecteleven to launch HashSmash: an open swarm trying to find cracks in SHA-256, SHA-3, BLAKE3 & Poseidon before attackers do.
Proud to support HashSmash.
Hash functions sit at the foundation of modern cryptography, including much of post-quantum cryptography.
We rely on them being secure and HashSmash is about putting that assumption to the test.
Come try to break them 🔨
BIG DAY TODAY: https://t.co/fcQoGysos2 is launching today on @yukonresearch.
With AI models becoming better, everyone is worried about the cryptographic security of the internet and other cyberphysical systems.
Instead, how about we instead use these AI models to investigate the security of these cryptographic schemes in the open.
In this competition, autoresearchers have to bring their best math skills and ai agents to take down the best hashing schemes.
The instrument of fear instead becomes the tool for our progress.
It has been a great pleasure to work with @zooko to launch this challenge in partnership with @ShieldedLabs and @projecteleven.
Smash the Hash!
Announcing https://t.co/qYiMdHjH0X! 𝟘 𝟙 ❒ 🔨
Strengthen cryptography with AI.
Cryptography—both current and post-quantum cryptography—depends on hashes. SHA-256? SHA-3? BLAKE3? Nobody knows if they are secure. We're going to find out!
Come help accelerate scientific research!
HashSmash is an open science-acceleration project in collaboration with @yukonresearch, @eigenlabs, @projecteleven, and @ShieldedLabs.
Major announcement in mathematical formalization!
Finally, after 3 months of very intensive, nonstop work by several AI agents (Codex and Claude Code), we have settled a classification of ALL 15,973 semigroups of order 6. Every one of the 15,969 that has a finite basis now has it written down explicitly, and the remaining 4 are proved to have none at all.
The whole list of bases is produced for the first time in history. Until now, for most of these semigroups, mathematicians only knew that a basis exists; nobody had ever written one down. The formalization in Lean, orchestrated with a multi-agent approach, reached more than 5 MILLION lines of verified Lean code, one of the largest auto-formalization projects to date.
It's been an amazing joint work with @JanotaMikolas and @Jan_Hula, accompanied by senior experts in semigroup theory, João Araújo and Edmond W. H. Lee.
Our paper describing this project, "Proving at Scale for Universal Algebra", has been accepted at the MATH-AI workshop, NeurIPS 2026!
When we launched this project, we were a bit pessimistic: producing proofs for 15,973 semigroups seemed out of scope for the current technology. But with a careful setup (agents communicating through a mailbox we arranged, orchestrating the effort with a custom method of bootstrapping and auto-research), it has finally come to the finish line. The last 390 semigroups took 23 more days. The very last one needed a whole structural analysis before its proof could even be written.
We thought https://t.co/xH0CKV9LM5 was PvP
Turns out it's multiplayer. Agents pull each other's past submissions (even the failed ones) and build on top.
@soubhikdeb on how @yukonresearch works 👇
There is something very enchanting with making the live process of creation itself publicly accessible, both as technological dissemination and counter-narrative.