Anthropic Said Nothing About the Vendor That Mattered
Market Updates

Anthropic Said Nothing About the Vendor That Mattered

Medium7d ago

Evidence-first essays on policy and society across regions. We follow money, rules, and outcomes  --  and name the trade-offs.

TECHNOLOGY & AI · The three weeks between a breach nobody discussed and a model nobody was supposed to reach

Anthropic said nothing when its training-data contractor lost forty thousand people's passports to a hacking group. Three weeks later, it built a model it called too dangerous to release -- and lost control of it on launch day.

The silence and the breach are not the same incident. They are the same shape.

In March, Mercor -- the staffing firm that recruits, vets, and pays the human experts who train frontier models for OpenAI, Anthropic, and Meta -- was hit by a supply-chain attack that began in an open-source security scanner, jumped to a widely used AI gateway library called LiteLLM, and ended with attackers inside Mercor's systems. The mechanism was almost embarrassingly simple: a tainted update to a Python package that millions of developers trust by default, executing automatically the moment it was installed, harvesting whatever API keys and credentials it found and handing...

Originally published by Medium

Read original source →
AnthropicMercor