SIGNAL / NOISE

What We Were Supposed to Remember

I lived in New York City September 11th, 2001. That morning was crystal clear, literally the perfect NYC day, and as I argued with an insurance company over a charge, I saw a plane flying low and definitively in the wrong place (I was a bit of a plane spotter back then, and my 40th-story apartment gave me a view of the runways at both Kennedy and LaGuardia). With a dead-on view of the World Trade Center and a Leica spotting scope on my deck, I bore witness to the attacks. Not on a small TV, not in the newsreels afterward, but live, and with a scope good enough that in the minutes before the towers fell I could see the people standing in the openings, deciding how they wanted to die. I'll leave it at that. Twenty-five years later, and it's not the kind of memory that fades.

We tell each other the lesson of that day was the buildings. Taking down a symbol. It wasn't. It was the math. Nineteen men and about four hundred thousand dollars — the number the 9/11 Commission eventually landed on — took down the two tallest buildings in my city and remade the country for a generation. What broke that morning wasn't a skyline. It was the old assumption that to wound a nation you had to be a nation. Catastrophe came unbolted from scale, and we spent the next twenty-five years building a security state around that single fact. You can thank those 19 terrorists for the TSA.

Now look at what landed in my inbox this anniversary week, like the calendar was making a point. Anthropic published a report on people caught misusing its AI, and one line spoke clearly to me: "sophistication has stopped being a reliable signal of who is behind an operation." A lone hacktivist ran a campaign that read like Russian state intelligence. Two undergraduates in China stood up an exploit shop that produced a dozen possible zero-days in a month. Criminals dumped 2,100 cloud keys across 40 companies in 34 hours, and the AI did nearly all of it. The tradecraft that used to separate a government from a kid in a dorm is now a download.

And the price fell right on cue. Last week Cognition pointed its agents at RSA-260 — a cryptographic wall standing since 2020 — and cracked it for about $400,000 in compute. The same $400,000 that funded the plot now buys a public record for breaking encryption, and the same method puts the 1024-bit keys still guarding real systems near $30 million and dropping. In 2001 catastrophe came unbolted from scale. This week it came unbolted from skill.

In 2017 I was hacked. Badly. Like a state-sponsored type of hack. Took my Gmail, took my Apple ID, ransomed all of it for bitcoin. When I refused, they went deeper. They took over my home router, they attacked my Chase account, they took over my cell phone account. For a month I battled back and gained control without any financial loss. But I changed every account I owned, every password, every phone number — everything.

Here's what I can't shake, and it's why this isn't a cyber story. On 9/11 the ceiling was two buildings. In 2017 it was my personal accounts and data. I can only imagine what that would have looked like if Claude were running that exploit. This week Anthropic also disclosed that its safety classifier caught five attempts to use Claude for biological weapons work: gain-of-function on a chikungunya virus, tied to a military institute, built for transmissibility and immune evasion. A pathogen doesn't stop at the property line. The floor — cost, skill — is collapsing toward a rounding error. The ceiling, what one person can now reach for, went from a skyline to a genome. And that's one step from a pandemic.

The one grace is the same story: the classifier held. Anthropic caught them, banned them, told us. The wall was never what kept us safe — it was the other guy's incompetence, and that just went to zero. What's left is building the catch into the machine and moving the defender as fast as the attacker now moves. We managed to be one country for about six weeks after the towers fell. The defense this thing demands is that, made permanent and built in.

At COAI today: the full Signal/Noise — the arithmetic of asymmetric harm, the RSA math, and why the classifier is the only piece of this that scales — is live at getcoai.com.

If the price of catastrophe just fell again, the only question that matters is whether your defense got cheaper too, or just your attacker's.

ONE — A NUMBER THAT SUMMARIZES THE DAY

$400,000. The low end of what the 9/11 Commission says the entire attack cost to plan and carry out. It is also, almost to the dollar, what Cognition spent last week in GPU time to set a public record breaking encryption — a method that now prices the 1024-bit keys still in service at about $30 million and falling. The money that once bought a catastrophe now rents a skeleton key. Twenty-five years, and the terrible arithmetic of that morning didn't improve. It got cheaper.

THREE — ACTIONS TO TAKE TODAY

Assume capability parity between a bored teenager and a nation-state. Anthropic's own report says sophistication no longer tells you who's attacking. Stop scoping your security to "who would bother with us." Today, pull the one system whose breach would end you and ask what stops an automated adversary that never sleeps and rewrites its own malware — because this week's did exactly that.

Buy the catch, not just the wall. The only thing that worked this week was a classifier watching the model's own use. If you're deploying AI agents, the spend that matters isn't a bigger perimeter — it's automated detection on your own systems moving at the attacker's speed. Ask your vendor one question today: what watches the agent, and how fast does it flag?

Rotate off the encryption that's now on a clock. RSA-260 fell for $400K; 1024-bit keys are a $30M problem and cheapening. If anything you own still leans on legacy key lengths, today is the day to inventory it and start the migration to post-quantum-grade standards. The record that stood since 2020 fell in sixteen days. Assume your timeline is shorter than you think.

FIVE — STORIES TO KEEP YOU INFORMED

Friday, September 11

  • Anthropic caught people using Claude to build bioweapons — and it worked. Five attempts flagged by a safety classifier, including gain-of-function work on chikungunya tied to a military institute. Accounts banned. The scary part and the reassuring part are the same sentence: the model was asked, and the catch held. (Full analysis above.)

  • The lone operator now runs the state's playbook. Anthropic's threat report documents a single hacktivist mounting Russian-grade espionage and two students producing a dozen zero-days a month. The old tell — sophistication means a government — is dead. Price your risk accordingly. (Full analysis above.)

  • AI agents broke a public encryption record for $400K. Cognition rewrote the standard factoring toolchain to run on GPUs and cracked RSA-260 in sixteen days. Same method puts 1024-bit RSA near $30M. Your crypto has a shelf life now, and it's shorter than last year's. (Full analysis above.)

  • America named the model thieves. The NSA, CISA and FBI jointly accused six Chinese firms — DeepSeek, Alibaba, Moonshot and others — of industrial-scale "distillation" attacks on US frontier models, "likely" with government awareness. Anthropic clocked one campaign at ~3 million exchanges a day. The moat around a frontier model is leakier than the valuations assume.

  • Anthropic mapped three futures and refused to pick one. New research models AI as a gentle sidekick, a job-halving force by 2030, or a 15%-GDP boom with mass white-collar unemployment — and ships a tool to run your own assumptions. The honesty is the story: the people building it will not tell you which one they're building.

— Harry and Anthony

Sources:

  • CyberScoop, "AI lets small actors run state-level hacking campaigns, Anthropic report finds" (Sept 10, 2026)

  • Anthropic, "Detecting and countering misuse of AI: September 2026" threat intelligence report

  • CNBC / Forbes / Engadget, "Anthropic says it blocked misuse of Claude that could have supported biological weapons" (Sept 10, 2026)

  • The Implicator, "The One Number: $400,000" — Cognition factoring RSA-260 (Sept 10, 2026); Cognition primary write-up

  • Shelly Palmer, "America Names the Model Thieves"; NSA/CISA/FBI joint advisory AA26-251A (Sept 9, 2026)

  • Fortune, "Anthropic's new research maps three wildly different futures for the AI economy" (Sept 10, 2026)

  • The 9/11 Commission Report, Final Report of the National Commission on Terrorist Attacks Upon the United States (plot cost estimate, $400,000–$500,000)

Reply

Avatar

or to participate