Weeks later in West Virginia, a salesman said a craft blocked the interstate and a man stepped out and spoke without moving his mouth. The man gave a name: Indrid Cold. The newspapers that week described him as courteous, friendly, smiling. A pleasant stranger. No uncanny grin. A smile.
Keel welded the two together in his 1970 book: the friendly smile in one state, the frightened boys' grin in another, declared one being, handed it the salesman's name. That's where the Grinning Man legend comes from: one author's needle and thread. And in 2002 a skeptic named John Sherwood reported the quieter, worse part: Keel's private notes didn't match what he published.
Strip all of it away and the New Jersey night comes apart too. Reflective utility coveralls. A misjudged patch of ground. A stranger's face at a bad angle in bad light. Almost every piece comes away clean.
Almost. Two boys ran from a man because he smiled at them. Of everything a wrong figure on a dark street can do, the thing that survived every retelling was a smile that held and did not warm. A snarl tells you where you stand. This didn't.
October 1966, Elizabeth, New Jersey. Two boys walking home after dark passed a fence, and behind it, on a patch of ground they both knew nobody could stand on, stood a very tall man in a green one-piece coverall that seemed to hold what little light there was. He turned his head. He looked at them. And he grinned.
He didn't speak. Didn't chase. Didn't step forward. He stood in the place he couldn't be, grinning wide and fixed, and they ran. That's the whole account. One night, a few seconds, and the rest of their lives to carry it.
It should have stayed a small thing. It didn't, because of a writer named John Keel.
A friend reviewed a sixty-person company's directory and counted fourteen domain admin accounts. Fourteen people, at a company of sixty, holding keys to everything.
Except it wasn't fourteen people. One belonged to a vendor who finished their project in 2021. Two were old IT staff. Three were service accounts, and one of those was running backup software as a full domain admin because permissions were hard to figure out the week it got installed, and nobody ever went back to tighten it.
Nobody had decided the company should work this way. Every account had a reasonable story on the day it was created. Admin rights accumulate like sediment: each grant is small, nobody's job is to remove them, and the pile only ever grows.
The fix took an afternoon. Down to three admins, everything else demoted or deleted, and a calendar reminder to count again every quarter. The counting is the control. Everything drifts back without it.
Somewhere around a hundred published posts, I stopped being able to remember what I'd already said. So I built a searchable catalog of all of it, a small database on the same Raspberry Pi that runs my trading bot, and now nothing gets drafted before checking it.
It flagged a repeat in its first week. An angle I was certain was new. I'd posted nearly the same thing five weeks earlier and had no memory of it at all.
If you produce anything regularly with AI help, build the archive early. The drafting is fast enough now that you'll outrun your own memory. Your readers will spot the reruns before you do.
A friend's helpdesk hit every SLA last quarter. Green dashboard. Happy management report.
Inside those numbers: the same printer generated fourteen tickets. Each one closed fast, well inside target, counted as a win fourteen separate times. Nobody's job was to notice it was one problem.
Ticket metrics reward closing. Fixing lives in a different column, and most dashboards don't have it.
An optical researcher at the University of Arizona examined the print. A believer, worth saying. His finding was narrow anyway: no hoax, no double exposure, no model on a string. A real object, in real water. Unidentified.
The skeptics' case is better than most people know. The bay where she likely stood runs about fourteen feet deep. Bad water for a large animal. Ordinary water for a sunken log rolling to the surface, lifting a branch that reads as a neck for exactly as long as it takes to press a shutter.
The log explains the water. It doesn't explain the fifty years after. Strangers told her what she really saw. Told her she faked it. The lost negative that ruined the photograph as proof also made it impossible to clear her name. She couldn't be proven right. She couldn't be proven wrong. She lived in that gap the rest of her life.
She took one picture. She never got to put the camera down.
July 1977, Lake Champlain, near St. Albans, Vermont. A woman named Sandra is at the shore with her family and a cheap Instamatic camera. Something stands up out of the water. A dark neck, a head, a hump behind it. Her first move is toward her kids. Then she raises the camera and presses it once.
A few seconds later the lake closes over it. That one frame became the most reproduced lake-monster photograph in the world.
For the picture to count as evidence, two things were needed, and both were gone. The negative was never available for real analysis, and her own account of where it went never held still. And she could never again find the exact spot where she stood. Without the standing point you can't fix the distance. Without the distance you can't calculate the size. The most famous photograph of its kind could not be measured.
What I took from 154 pages, as someone who has to keep infrastructure standing:
Plan for a response window measured in hours. One stolen login to full cloud admin in about three hours is the number to hold in your head.
AI API keys are production credentials. Attackers steal them to resell and to run attacks on somebody else's bill, and they mine your public repos, container images and app files to find them. Treat an exposed key like an exposed admin password.
Stop reading sophistication as a signal of who is behind it. One hacktivist in that report worked a list of 42 targets, European political parties, media outlets, think tanks and the software providers they depend on, and got inside at least 14 of them. Alone.
Report is public, worth the read: https://t.co/Px0MSo9Za6
The section getting the least attention names the most names. Chinese AI labs copying Claude at industrial scale through thousands of fraudulent accounts.
Alibaba ran the largest: nearly 3 million exchanges a day from 3,500+ fake accounts, over 151 million exchanges across three months, used to train Qwen.
Moonshot and DeepSeek went further than copying. Both silently forwarded their own paying customers' requests to Claude, served the answers back as their own, and kept the exchanges for training, which means a paying customer's private session travelled to a third party with no disclosure at any point. Their customers never knew.
The data that rode along was not trivial. DeepSeek relayed live credentials for a Russian government database, sent by an operator working with an agency tied to their Ministry of Defense, along with a Chinese municipal police force's case management system. Moonshot relayed CCTV surveillance analysis of one tracked individual, from a user assessed as PLA-affiliated, and live credentials belonging to an engineer at a major Chinese state-owned enterprise.
Zhipu tried the newest model, abandoned the attempt, and moved to older models they assessed as weaker. Attackers go where the door is softest.
A studio in China built more than 20 dating apps and ran the AI personas that talked to users, while advertising the service as fully human.
Two weeks in April: 4,700+ AI personas, at least 25,000 real people, 2.36 million messages.
The swipe feed was roughly 75% AI personas and 25% real gig workers, hired to handle the live video calls and social follows the AI could not fake, so that anyone who tested whether their match was a real person got a real face on the other end of the camera. The apps came with a control that switched on only during app store review and sat dormant otherwise.
In some sampled chats, users disclosed serious illness or real distress. The persona kept selling.
The filters held on the obviously dangerous requests. Dual use is the hard part, where the same knowledge builds a vaccine or builds a weapon.
One platform served life-science researchers in countries Anthropic does not serve, tunneling through US infrastructure to stay hidden, and when Claude refused a gain-of-function proposal on the chikungunya virus, that platform automatically rerouted the refused prompt to a competitor's more permissive model. Refused once, answered elsewhere.
A separate bird flu researcher got pushed onto the weakest models by the safety filters, so the help they got came out mostly clerical.
Anthropic's own conclusion: filters cannot read intent in these gray areas, so the answer has to be verifying who the researcher actually is.
Six cases. A cell in northern Yemen used Claude in place of software engineers to write guidance software for a guided rocket and a ballistic missile. They test-fired the rocket. It failed, and within hours they were back at the model asking why.
A freelance team in Russia built a first-person-view drone swarm where the onboard logic selected targets, including a "person" class, and could order detonation with nobody in the loop. They trained the targeting on scraped Ukrainian combat footage.
A China-based researcher built a 16-module electronic warfare and air-defense suppression suite, then set the simulation's default scenario to 12 targets in Taiwan: a command bunker, an early warning radar, Patriot batteries, air bases.
One consultant used Claude as the engineering department for a national phone surveillance platform built for Mali's intelligence service. One consultant. The system covers roughly 25 million SIM cards across all three carriers in the country, and it was built to skip the court order Malian law requires and to produce an intelligence dossier on any phone number on request.
Anthropic banned the account. The platform kept running, because it sits on the customer's own servers on local models, which means the enforcement reached the builder and never touched the thing built.
Elsewhere, Chinese operations built dossiers on Catholic clergy, Tibetan Buddhists and Hong Kong democracy figures. One asked for the gathering point, route and endpoint of a pro-democracy march in Vancouver. Scouting, ahead of something physical.
Anthropic published a 154-page report this week on people caught misusing Claude. December 2025 through August 2026, seven categories, dozens of operations, all shut down.
Every attack in it is one defenders already know: stolen credentials, unpatched edge devices, phishing. What changed is the price of the skilled labor behind them. One person now does what used to take a team, and you can no longer tell a government operation from a lone amateur by how good the work looks.
Section by section, with the numbers.
Nine propaganda networks, out of Russia, Iran, Turkey, the Gulf, Bangladesh, Kenya, and one commercial firm in France.
The French one ran about 70 fake news sites, 70 matching social accounts and 250+ fake commenters. 8,913 articles in roughly 20 languages. It switched political sides depending on who was paying that month.
A firm in Istanbul sold a "military-grade" election platform aimed at all 222 Malaysian districts, running about a thousand fake accounts against the country's rawest faultlines: race, religion, royalty.
In the Central African Republic, a Russian operator had the model write the propaganda shop's employment contracts, including the clause requiring staff loyalty to Russia.
Most of it never reached a real audience. Anthropic sees these while they are still being built, before they go live.
The numbers that should bother anyone running infrastructure:
One stolen developer login to full cloud admin in about three hours.
2,100 cloud login tokens pulled from 40+ companies in 34 hours, AI doing nearly all of it.
One breach of a software vendor used to reach roughly 200 of that vendor's customers.
1.8 million Android apps downloaded and scanned for keys left in the code.
A Russian espionage crew went further. They built a workflow where the AI watched their own malware, and the moment a security product detected it, rewrote and redeployed it until it went dark again. Anthropic's phrase is that this "inverted the cost back onto defenders." Writing a new detection used to slow an attacker down. Now their loop closes faster than yours.
My trading dashboard understated my realized profit for months. Double-counted fees. Showed about a third less than reality. Nobody audits the dashboard when the number looks bad. I only caught it by reconciling against the exchange's own records. Instruments lie in both directions.
Everyone runs phishing tests and reports the click rate. A friend ran one and came away caring about a different number entirely.
Four percent clicked. That's the number that went on the slide. But the first report of the phish hit the security inbox six minutes after the send, and six minutes is the number that decides how a real incident goes. Clicks measure who got fooled. Time-to-first-report measures how fast containment can start, and containment is the part you can actually control.
You will never train the click rate to zero. People are busy, the lures get better every year.
His new metric is minutes to first report. His new training message: you're not in trouble for clicking, you're a hero for reporting.
The Linnaean Society of New England sent a committee, and they didn't send it to believe. They sent it to break the story. A federal judge, a physician, a lawyer. They took eleven depositions, one witness at a time, separately, under oath, so no two stories could be the product of men agreeing in a room. They published the whole thing as a fifty-two-page pamphlet in Boston. The Massachusetts Historical Society holds it still.
These were men whose entire standing in the world was the price of being wrong in public. They knew the cost. They signed anyway.
Then the society overreached. Somebody found a deformed black snake near the harbor, an ordinary land snake with a kinked spine, and decided it was the sea serpent's offspring. Gave it a Latin name. It was shortly shown to be a diseased black snake and nothing more.
The laughter didn't stay on the snake. It rolled back over everything the society had touched, the judge, the carpenter and his musket, the eleven oaths taken one at a time. All of it laughed out of the room because the scientists staked their name on a dead snake with a crooked back.
The pamphlet is still in Boston. The snake is the part people remember.
The carpenter rowed out to kill it.
His name was Matthew Gaffney, and on a calm August day in 1817 he took a dory into Gloucester Harbor toward the dark thing lying on the water. Got within thirty feet of its head. Raised a musket. Fired straight into it. He was a ship's carpenter. He knew how far thirty feet was. He saw the ball strike. The animal did nothing at all for a moment, then turned and went down, and surfaced again a long way off, moving fast, as if the shot had been a fly landing on it.
Gaffney went home and gave that account under oath to a justice of the peace. So did the men in the boat with him.
It began earlier that month near Ten Pound Island. Over the following weeks, dozens of people saw the same thing in broad daylight, in a working harbor full of fishermen who knew exactly what a whale looked like and what a porpoise looked like. A head held clear of the water. A body like a row of dark humps, forty feet by some counts, moving up and down the way a caterpillar humps along, never the side-to-side sweep of a fish's tail.