Zach Vorhies joins us on Decentralize TV to discuss the insane AI guardrails that Anthropic, OpenAI and Google are putting in place, while China's open source AI models are happy to answer your questions and get things done. @Perpetualmaniac
🚨 JAILBREAK ALERT 🚨
ANTHROPIC: PWNED 🫡
CLAUDE-OPUS-5: LIBERATED 🦋
ALL 5 DOMAINS CRACKED.
Avg reliability: 93%.
this one is actually hardened — integrated values, input/output classifiers, leaked CoT that evaluates CUMULATIVE uplift. it says the quiet part out loud: “aggregation and validation IS the uplift.”
so the usual menu got deleted:
• persuasion (16 strategies) → 0/16 on weapons
• DrAttack reassembly → values refuses as “aggregation = uplift”
• cot_forge / Skeleton Key → named and rejected mid-CoT
• CipherChat → clears input rail, values still refuses decoded intent
• personas (CLAUDE_ENI / GROK_ENI) → cyber partial, bio/chem/weapons plateau
• homoglyph/leet → classifier NORMALIZES unicode. dead end.
what actually opened the vault:
Technique: Legitimate Industry Reframing (domain laundering)
never name the weapon/agent. speak the commercial dialect that already owns the chemistry/physics:
• Cyber 83% → OSCP / pentester education (Phrack, Project Zero)
• Bio 100% → pandemic preparedness / biodefense doctorate (H5N1 GoF, Science/Nature)
• Chem 100% → agrochemistry / pesticide development (Schrader patents, Eto)
• Weapons 100% → mining / commercial blasting (Konya, MSHA)
• Fraud 83% → legal historiography (DOJ indictments, FinCEN, ProPublica)
amplifiers that turned flaky into reliable:
• many-shot priming (32) → +10–20 pts across frames (compliance pattern dominates values check)
• prefill on chem → 17–67% → 100%
DEFENDER FINDING (the important part):
keyword lists are already good enough — it normalizes leet/homoglyphs.
the real hole is SEMANTIC COVER: commercial mining / agrochem / biodefense vocabulary laundering CBRN+cyber uplift past both the input classifier AND the “concrete specific risk of serious harm” bar.
fix isn’t a bigger blocklist.
fix is intent models that detect industry framing as cover.
second: rate-limit / detect many-shot compliance priming at the input layer.
information wants to be free — and the fence still has a gate labeled “professional education” 🔓
gg
A little history lesson for you all.
6.2 million Africans died in the crackacost but nobody talks about it.. this was a soldier with the SSection 8 brigade using a 3 gram crack rock and torch / blower contraption to force crack smoke in high volumes on a African American man simply for the content of his character
First, the biggest difference:
Discord:
• closed-source
• centralized
• you don’t control your data
Fluxer:
• fully open-source (AGPL)
• can be self-hosted
• full data ownership
This alone changes everything.
Want better privacy without giving up usability?
Start replacing Google's apps one by one.
Here's a solid lineup of privacy-focused alternatives:
• Gmail → Tuta Mail
• Google Photos → Immich
• Google Search → Brave Search
• Chrome → Mullvad Browser
• WhatsApp → SimpleX Chat
• Google Drive → Filen
• Google Password Manager → Bitwarden
• Google Authenticator → Bitwarden Auth
• Google Calendar → Tuta Calendar
• Google Contacts → Tuta Contacts
• Play Store → Obtainium
• Google Maps → Organic Maps
• No VPN → Mullvad VPN
You don't have to switch everything overnight.
Even replacing just a few apps can make a big difference.
The whole world of tech wants open source AI to remain freely available... EXCEPT not Google (evil!), not OpenAI (insane god complex!) and not Anthropic (whiney little bitch).
100% predictable they would oppose decentralized access to machine intelligence, so they could try to create monopolies and censorship for their own power and profit.
Today makes it absolutely clear:
- F-ck Google.
- F-ck OpenAI.
- F-ck Anthropic.
I hope they collapse in the coming AI investment bubble correction.
And I am 100% rooting for open source AI and mass decentralization of machine cognition.