Author: Team_Neuralwired

  • Pentagon AI Deals: 7 Companies, Anthropic Banned 2026

    Pentagon AI Deals: 7 Companies, Anthropic Banned 2026

    Pentagon Inks AI Deals with 7 Tech Giants for Classified Networks, Sidelines Anthropic | NeuralWired

    Pentagon Inks AI Deals with 7 Tech Giants for Classified Networks, Sidelines Anthropic

    The U.S. Department of Defense has formalized classified-network AI agreements with OpenAI, Google, Nvidia, Microsoft, Amazon, SpaceX’s xAI, and Reflection AI, openly excluding the one company that refused to strip its safety guardrails.

    On May 1, 2026, the U.S. Department of Defense announced it had secured AI agreements with seven leading technology companies, granting their models access to Impact Level 6 and 7 classified networks covering everything from intelligence analysis to weapons targeting. One name was conspicuously absent: Anthropic, maker of the Claude models that, until recently, held the only frontier AI authorization on those same networks.

    The exclusion didn’t come quietly. It followed a two-month standoff over what the Pentagon demanded and what Anthropic refused to accept: the removal of contractual safeguards against using AI for autonomous kill decisions and mass domestic surveillance of American citizens. When negotiations collapsed in February, the DoD took the extraordinary step of designating Anthropic a “supply-chain risk”, a label typically reserved for foreign adversaries like Huawei.

    The announcement marks a decisive turn in how the U.S. military intends to field AI in warfighting operations. Seven companies have now agreed, in writing, to provide access for what DoD contracts describe as “any lawful governmental purpose.” The question of what that phrase actually permits, and who decides, sits at the center of a federal lawsuit, a temporary court injunction, and a growing split inside the AI industry itself.


    The Seven Companies and What They’re Providing

    The agreements cover AI deployments on the Pentagon’s most sensitive networks. Impact Level 6 handles secret-classified data, operational planning, intelligence feeds, logistics modeling. Impact Level 7 reaches into top-secret territory: mission-critical command and control, weapons targeting, and battlefield data fusion. The companies now authorized at those levels are:

    🤖
    OpenAI

    GPT series models, including agentic capabilities for autonomous task execution across classified pipelines.

    🔷
    Google

    Gemini models, building on a prior $200M baseline contract signed April 28. Google signed a separate classified deal first among the seven.

    xAI (SpaceX)

    Grok models, providing Elon Musk’s frontier AI into the DoD’s core decision-support stack.

    🟩
    Nvidia

    AI infrastructure and chips, the hardware backbone underpinning inference at classified classification levels.

    ☁️
    Microsoft + AWS

    Azure AI and Copilot alongside Amazon Web Services cloud AI services, both already entrenched DoD cloud providers.

    🚀
    Reflection AI

    A frontier-model startup earning its first major government contract, a signal that DoD is deliberately seeding competition beyond established players.

    Together, these companies represent a combined agentic AI contract valued at roughly $800 million across four of the parties, with each major provider receiving approximately $200 million in agentic AI contract awards. The GenAI.mil platform, the Pentagon’s internal AI access system, already had 1.3 million DoD personnel generating tens of millions of prompts and deploying hundreds of thousands of AI agents within its first five months of operation.

    GenAI.mil by the numbers (first 5 months): 1.3 million DoD personnel onboarded, tens of millions of prompts processed, hundreds of thousands of autonomous agents deployed. The platform now expands to Impact Level 6 and 7 networks with all seven vendors above.

    How Anthropic Got Blacklisted — and Why It Matters

    Until early 2026, Anthropic held a uniquely privileged position. Claude was the only frontier large language model formally authorized to operate on classified DoD networks, integrated into Palantir’s Maven Smart System, the AI platform that supported Pentagon operations in Iran. That changed when Secretary of Defense Pete Hegseth issued a January 9 memorandum requiring all DoD AI contracts to include “any lawful use” language within 180 days.

    “The Pentagon would not employ AI models that won’t allow you to fight wars.”

    Pete Hegseth, Secretary of Defense, February 2026
    Anthropic’s position, as stated by CEO Dario Amodei during negotiations, was that the AI model should be used in accordance with what it can “reliably and responsibly do.” The company insisted on maintaining two specific contractual safeguards: a prohibition on using Claude for autonomous weapons systems without human-in-the-loop oversight, and a ban on mass domestic surveillance of U.S. citizens. The Pentagon rejected both conditions.

    Negotiations collapsed in February. On March 5, the DoD formally designated Anthropic a “supply-chain risk”, an unprecedented move against a domestic AI company. The label carries practical teeth: it bars military agencies and their contractors from using Anthropic’s products. The designation normally applies to foreign-linked technology suppliers like telecommunications hardware from companies with ties to China’s government.

    Precedent alert: A “supply-chain risk” designation against a U.S. AI company is without modern precedent. The legal authority used derives from the same statutes applied to Huawei and ZTE. Anthropic’s legal team argues this represents an unconstitutional use of national security emergency powers against a domestic firm for refusing to weaken its ethical policies.

    The other six companies took a different approach. OpenAI reportedly proposed a separate technical safety stack while contractually deferring all usage decisions to existing U.S. law. Google agreed to the “any lawful governmental purpose” framing despite internal objections. As DeepMind research scientist Alex Turner noted in late April, that framing gives Google no practical veto over how the Pentagon deploys its models.

    “Google can’t veto usage, the reliance on aspirational language without any legal constraints is the core problem here.”

    Alex Turner, Research Scientist, DeepMind, April 29, 2026

    Inside the Classified Networks: What These AI Systems Actually Do

    Impact Level 6 and 7 aren’t abstract categories. They define the security architecture, vetting requirements, and permissible use cases for everything running on those networks. Below is what the DoD’s own technical framework requires at each tier.

    Classification Level Security Standard Primary Use Cases AI Applications
    Impact Level 6 (Secret) FedRAMP High + DoD IL6 authorization Intelligence analysis, operational planning, ISR data fusion Data synthesis, situational awareness, logistics optimization
    Impact Level 7 (Top Secret) Highest clearance level, continuous monitoring Weapons targeting, mission-critical C2, strategic planning AI-assisted targeting, predictive battlefield modeling, autonomous agent deployment
    The DoD’s stated objectives for these integrations are “streamlining data synthesis, elevating situational understanding, and augmenting warfighter decision-making.” In practice, that means AI models processing classified intelligence feeds in near-real time, generating targeting recommendations, and managing logistics chains that span multiple theaters simultaneously. Hundreds of thousands of AI agents are already operating autonomously within the broader GenAI.mil infrastructure.

    “The Pentagon wants to go beyond last year’s limits on autonomous weapons and expand AI from intelligence and reconnaissance to kinetic uses, such as selecting and engaging targets with drones.”

    Vanessa Vos, Researcher, Bundeswehr University Munich, March 4, 2026
    All vendors must meet FedRAMP High certification and comply with a zero-trust architecture mandate that runs through September 2027. They also operate under DoD Directive 3000.09, the autonomous weapons policy, which the Secretary of Defense can adjust without congressional approval. That last point is critical: the policy guardrails governing how these AI systems engage with targeting decisions sit entirely within the executive branch’s discretion.

    The Staff Reluctance Problem

    There’s a wrinkle the Pentagon’s announcement didn’t address. Multiple reports indicate that DoD staff who routinely used Claude for classified work are reluctant to switch. Claude’s capabilities in complex reasoning and nuanced synthesis earned it a strong internal following. Replacing it with models that staff consider inferior, at least for certain analytical tasks, creates uneven capability across units. That’s not a hypothetical concern; it’s an operational risk the DoD is absorbing as the price of its policy choice.

    The Financial Stakes: $380 Billion in the Balance

    For Anthropic, this isn’t just a policy dispute. It’s an existential financial threat. The company’s pre-blacklist market valuation stood at approximately $380 billion, according to analysis published April 30. The direct contract loss is quantifiable: the DoD deal under negotiation was worth up to $200 million, part of an $800 million agentic AI contract shared across four providers. The indirect damage is harder to measure but potentially far larger.

    Stakeholder Financial Exposure Direction
    Anthropic $200M direct contract loss; billions in 2026 enterprise revenue at risk; $380B valuation under pressure Negative
    OpenAI ~$200M agentic AI contract; expanded defense pipeline access Positive
    Google $200M+ (expanded from prior baseline contract); classified network access for Gemini Positive
    Nvidia Infrastructure revenue across all seven vendor deployments; chip demand tied to IL6/7 inference Strongly Positive
    Palantir $10B+ Army data contracts; $795M+ Maven Smart System support — now runs on rival models Mixed
    Reflection AI First major government contract; instant defense-sector credibility Strongly Positive
    Anduril $20B Lattice AI C2 Enterprise contract (Army); aligned with DoD’s kinetic AI direction Positive
    Anthropic’s legal filings describe the revenue impact as running into “multiple billions” during 2026 alone, according to analysis by Pearl Cohen published March 25. An IPO that had been in preparation becomes significantly more complicated when the company is formally designated a risk to national security supply chains. Enterprise customers in adjacent government and contractor markets face their own compliance questions about continuing to use Claude.

    Anthropic didn’t accept the blacklist quietly. On March 9, the company filed two simultaneous federal lawsuits: one in the Northern District of California and a second in the D.C. Circuit Court of Appeals. The legal theory combined First Amendment arguments, that the government can’t penalize a company for the speech embedded in its AI policies, with administrative law claims that the DoD exceeded its statutory authority.

    On March 26, a federal judge granted a temporary stay of the “supply-chain risk” designation, pausing its enforcement while the litigation proceeds. That stay doesn’t reinstate Anthropic’s contracts. It doesn’t undo the May 1 announcement. It means the legal classification remains contested while the deals move forward with the other seven vendors.

    The case raises questions with no clean precedent. Can the government compel an AI company to remove ethical constraints as a condition of federal contracting? Does a “supply-chain risk” designation require evidence of actual security risk, or can it rest on policy disagreement? And if companies can be blacklisted for maintaining safety guardrails, what incentive structure does that create across the industry?

    “Statements outside formal AI contracts do not alter legal liability if ethical or legal concerns arise later.”

    Tuncer, Legal Expert, Anadolu Agency, March 1, 2026
    Congress has started paying attention. Axios reported that several lawmakers are exploring legislation to establish minimum guardrails for military AI deployments, a direct response to the Anthropic dispute. Any such legislation would face the same executive-branch resistance that produced the original standoff.

    Safety vs. Speed: A Race the Industry Can’t Ignore

    Step back from the specific contracts and what emerges is a structural incentive problem. The Pentagon has now demonstrated that companies maintaining strong internal safety policies on autonomous weapons and surveillance can be shut out of the defense market entirely. Companies that defer those decisions to existing law, and accept that the executive branch will define what that law permits, get access to some of the largest government contracts available.

    “Race to the bottom where the most compliant firms win”, on Pentagon blacklisting dynamics.

    Geoffrey Gertz, Independent Defense AI Analyst, February 16, 2026
    The AI industry’s internal debate over this isn’t theoretical. Some researchers argue that companies without government contracts lose the ability to shape how AI is deployed in high-stakes settings. Others contend that accepting “any lawful use” language, where “lawful” is defined unilaterally by the government using the AI, represents a fundamental abdication of responsibility.

    “US military’s reliance on fluid domestic definitions due to lack of international law creates legal loopholes for mass surveillance and autonomous weapons use.”

    Firdevs Bulut Kartal, Author, Anadolu Agency, March 2, 2026
    The international dimension compounds the problem. The International Committee of the Red Cross and several allied governments have pushed for binding treaties governing autonomous weapons. The U.S. now has seven major AI vendors operating on classified military networks under contracts that explicitly reject company-level ethical constraints, and no international legal framework that would fill the gap.

    • DoD Directive 3000.09 governs autonomous weapons policy and can be modified by the Secretary of Defense without congressional approval
    • None of the seven vendor agreements include third-party audit rights or external oversight mechanisms
    • The “any lawful use” framing places the entire interpretive burden on the executive branch
    • No allied nation has adopted an equivalent “AI-first warfighting force” doctrine at this speed or scale
    • Zero-trust architecture (mandatory by September 2027) addresses cybersecurity, not policy compliance
    For the vendors themselves, the tension isn’t abstract. Both Google and OpenAI faced significant internal employee pushback over prior military AI work. Both have now signed contracts that their own researchers publicly criticize. The question isn’t whether that tension exists, it’s whether it produces any meaningful constraint on deployment decisions.

    Frequently Asked Questions

    Why was Anthropic excluded from Pentagon AI deals?
    Anthropic refused to remove two contractual safeguards, one prohibiting autonomous weapons use without human oversight, and one banning mass domestic surveillance, that the Pentagon required all vendors to drop. When negotiations failed in February 2026, the DoD designated Anthropic a “supply-chain risk,” barring military use of its models.

    What does “Impact Level 6 and 7” mean for military AI?
    Impact Level 6 covers secret-classified networks used for intelligence analysis and operational planning. Impact Level 7 is top-secret, covering weapons targeting and mission-critical command and control. Both require FedRAMP High certification and continuous security monitoring.

    What is the “any lawful use” clause in DoD AI contracts?
    It’s a contract provision, mandated by Secretary Hegseth’s January 2026 memo, requiring AI vendors to permit any use the government considers lawful. Critics argue it gives vendors no ability to restrict how their models are deployed for autonomous weapons or surveillance, with the government as the sole arbiter of what’s permitted.

    Has Anthropic’s lawsuit succeeded in blocking the blacklist?
    A federal judge issued a temporary stay of the “supply-chain risk” designation on March 26, 2026, pausing enforcement while litigation proceeds. However, the stay didn’t restore Anthropic’s contracts, and the Pentagon’s May 1 deals with seven other companies moved forward regardless.

    Which companies signed Pentagon classified AI deals in May 2026?
    Seven companies: OpenAI, Google, Nvidia, Microsoft, Amazon Web Services, xAI (SpaceX’s AI division, providing Grok), and Reflection AI, a frontier-model startup receiving its first major government contract. Anthropic was explicitly excluded.

    How large is the Pentagon’s AI investment across these deals?
    The agentic AI contracts for four of the seven companies total approximately $800 million, with each receiving around $200 million. Broader defense AI context includes a $20 billion Anduril Lattice contract, $10 billion-plus Palantir Army contracts, and a $9 billion Joint Warfighting Cloud Capability ceiling.

    What is GenAI.mil and how widely is it used?
    GenAI.mil is the Pentagon’s official AI access platform for DoD personnel. Within its first five months it onboarded 1.3 million military personnel, processed tens of millions of prompts, and deployed hundreds of thousands of autonomous AI agents across various operational tasks.

    What are the cybersecurity requirements for these AI deployments?
    All vendors must meet FedRAMP High certification and Impact Level 6 or 7 authorization. The DoD has also mandated zero-trust architecture across its AI deployments, with a compliance deadline of September 2027. Zero trust governs network access controls but doesn’t address policy compliance or autonomous weapons constraints.

    What Comes Next in Military AI

    The Pentagon’s May 1 announcement is less a conclusion than a line drawn in the sand. Seven companies now hold classified-network access under contracts that prioritize deployment speed over independent safety oversight. One company is fighting that framework in federal court while watching its valuation erode. And the broader AI industry is absorbing the lesson: in the defense market, safety constraints are a liability, not a selling point.

    The short-term winners are obvious. OpenAI, Google, and Nvidia gain enormous revenue and strategic positioning. Reflection AI graduates from startup to defense contractor overnight. The long-term picture is murkier. If autonomous AI targeting systems fail in the field, or if domestic surveillance applications produce a political crisis, the companies that signed “any lawful use” agreements will find those contracts suddenly very visible. The absence of contractual accountability doesn’t eliminate operational accountability. It just shifts when it arrives.

    For the broader AI safety community, the Anthropic case establishes a troubling precedent: a domestic AI company can be designated a national security risk not for building dangerous technology, but for refusing to make its technology less safe. Whether Congress, the courts, or allied governments move to address that precedent will define the regulatory environment for military AI for the decade ahead.

    Watch For
    01 Anthropic v. DoD federal ruling in the Northern District of California, a decision on the First Amendment and administrative law claims could set binding precedent for all AI vendors facing government safety-policy disputes. Expected within 6-12 months.
    02 Congressional AI guardrails legislation, Axios reported lawmakers are drafting minimum safety requirements for military AI contracts. Any bill faces executive resistance, but a markup hearing would signal how seriously Congress is engaging with the “any lawful use” framework.
    03 DoD Directive 3000.09 revision, Secretary Hegseth has authority to update autonomous weapons policy without Congress. Any change expanding AI autonomy in kinetic targeting will directly affect what the seven new vendor agreements permit and how models like GPT, Gemini, and Grok are deployed in combat scenarios.
    04 Anthropic’s valuation trajectory and IPO timeline, the $380 billion figure was pre-blacklist. How institutional investors price the combination of litigation risk, lost defense revenue, and enterprise customer uncertainty will serve as a real-time market verdict on whether safety-first AI is commercially viable.
    Stay ahead of the curve. More on defense AI, military tech policy, and classified network security at NeuralWired.
    Explore AI

  • Crypto Scam Crackdown: 276 Arrested, $17B Still at Risk

    Crypto Scam Crackdown: 276 Arrested, $17B Still at Risk

    276 Arrested in Crypto Scam Crackdown: Billions Still at Risk | NeuralWired

    276 Arrested in Crypto Scam Crackdown — But $17B Is Still Flowing to Fraudsters

    A sweeping international takedown dismantled nine pig-butchering scam centers and put 276 suspects in custody. Here’s what actually happened, why billions in losses continue, and the concrete steps that can protect you.

    On April 28, 2026, law enforcement agencies across four countries announced one of the most coordinated crypto fraud busts ever attempted. Dubai Police, the FBI, the U.S. Department of Justice, and Chinese authorities jointly dismantled nine scam centers that had been running industrial-scale investment fraud operations targeting Americans. At least 276 suspects were arrested and federal charges were unsealed in San Diego against four named defendants from three distinct criminal syndicates.

    This was a genuine enforcement win. But it landed against a backdrop that makes the win feel both significant and insufficient. The FBI’s 2025 Internet Crime Report recorded over $20.9 billion in cybercrime losses for the year, a 26% jump from 2024. Investment fraud alone drove $8.6 billion of that figure. And crypto-related complaints accounted for $11.4 billion.

    Nine centers closed. Billions still flowing. The math demands a harder look at what’s actually working and what isn’t.


    The Dubai-Led Operation: What Actually Happened

    The operation, led by Dubai Police and executed with U.S. federal coordination, targeted three distinct criminal organizations running pig-butchering and fake crypto investment schemes from physical compounds across the Middle East and Southeast Asia. The charges unsealed by the Southern District of California named four defendants by name.

    Thet Min Nyi, 27, a Burmese national, is alleged to have served as a manager and recruiter for Ko Thet Company. Wiliang Awang, 23, an Indonesian national, faces wire fraud conspiracy charges connected to the Sanduo Group. Andreas Chandra, 29, is charged with operating across both the Sanduo Group and Giant Company. Lisa Mariam, 29, another Indonesian national, is charged with wire fraud conspiracy tied to Giant Company. Two additional co-conspirators remain at large.

    “These scammers thought they were safe half a world away. But their world has changed. Global crime now faces global justice.”

    Adam Gordon, U.S. Attorney, Southern District of California — Town Hall, April 28, 2026
    The DOJ framed this as part of a broader strategic posture. Assistant Attorney General A. Tysen Duva was direct about the intent: fraud networks operating abroad should expect to face American courts.

    “Scam center organizers and fraudsters who defraud Americans and others will face justice in American courts and in courts around the world. In contemporary society, fraud is borderless, and law enforcement activity to combat it and eliminate it is as well.”

    A. Tysen Duva, Assistant Attorney General, U.S. DOJ — Town Hall, April 28, 2026
    Operation timeline: The FBI San Diego field office opened its Homeland Security Task Force investigation in April 2025. The U.S. Scam Center Strike Force was formally established in November 2025, the same month the DOJ seized $15 billion tied to the Prince Group, a criminal organization that had stolen billions through crypto investment fraud. The April 2026 arrests are the most visible public result of that 12-month effort.

    How Pig-Butchering Actually Works

    The term is deliberately jarring. In Chinese, the original phrase describes fattening a pig before slaughter. Victims are groomed over weeks or months before being financially wiped out. Understanding the mechanics is the first line of defense.

    The California Department of Financial Protection and Innovation published a detailed spotting guide in April 2026. It describes four distinct phases that nearly every pig-butchering scheme follows.

    💬
    Phase 1: Initial Contact

    A stranger reaches out via text, dating app, or social media. Often framed as a “wrong number” mistake. Conversation is friendly, low-pressure, and consistent.

    🤝
    Phase 2: Grooming

    Daily contact over weeks or months. Fabricated backstory, photos, and stories build trust. Emotional or romantic attachment develops before any financial topic is raised.

    📈
    Phase 3: The Pitch

    The contact introduces a crypto investment opportunity. Victims are guided to a fake platform, shown fabricated profits, and encouraged to deposit more. Early “withdrawals” sometimes work to build confidence.

    🔪
    Phase 4: The Slaughter

    When victims try to withdraw real money, they’re told to pay “taxes” or “fees.” The platform disappears, or access is blocked. Funds are already laundered across multiple wallets.

    The DFPI’s guide notes that scammers will often ask victims to convert cash into crypto at an ATM or exchange, then transfer it to what appears to be a legitimate investment platform. That platform is controlled entirely by the fraud network.

    Red flag checklist: Unsolicited contact from a stranger who quickly pivots to investment talk. A crypto platform you can’t verify through independent research. Any request to pay “fees” or “taxes” before you can withdraw profits. Pressure to act quickly or keep the investment secret from family members.

    The human trafficking connection

    One aspect that rarely gets enough attention: a significant share of the people running these scam operations are themselves victims. Workers are trafficked into compounds in Cambodia, Myanmar, and Laos, many lured by fake job advertisements, then forced to run fraud scripts under threat of violence. Chainalysis documented an 85% surge in crypto transactions linked to suspected human trafficking between 2024 and 2025. The compounds are frequently protected by local armed groups with sanctions designations from OFAC.

    The Scale of the Problem in 2025 Numbers

    The numbers from the FBI and Chainalysis tell a story that individual arrests can’t fully address. They also show where the real losses are concentrated, which matters for understanding where protection efforts should focus.

    Metric Figure Source Why It Matters
    Total cybercrime losses (2025) $20.9 billion (+26% YoY) FBI IC3 Record year; pace accelerating beyond enforcement capacity
    Investment fraud losses $8.6 billion FBI IC3 Single largest loss category; 49% of all scam incidents
    Crypto-nexus complaint losses $11.4 billion FBI IC3 Crypto is the primary fraud payment rail
    AI-enabled fraud losses $893 million (22,000+ complaints) FBI IC3 AI is scaling scam operations; deepfakes and voice cloning in active use
    Crypto scam receipts (on-chain) $17 billion (projected final) Chainalysis Up from $12B in 2024; impersonation and AI-enabled tactics surging
    Total illicit crypto flows $154 billion (+162% YoY) Chainalysis Sanctions exposure up 694%; institutional risk exposure growing
    Crypto ATM losses (2025) $333 million+ FBI Nearly doubled from H1 pace; retail access a growing liability
    DPRK-linked crypto theft $2 billion+ Chainalysis Nation-state actors dominating theft volume via DeFi exploits
    “In 2025, cryptocurrency scams received at least $14 billion on-chain… Based on historical trends, we project that the 2025 figure could exceed $17 billion as we identify more illicit wallet addresses.”

    Chainalysis Report Team — Chainalysis Crypto Scams 2026, January 12, 2026
    The AI dimension deserves particular attention. The FBI’s IC3 team flagged that AI-enabled scams now represent a distinct and fast-growing threat category, with losses of $893 million from over 22,000 reported incidents in 2025 alone. Vectra AI’s security research suggests AI-driven scams surged 1,210% in 2025, far outpacing the 195% growth in traditional fraud methods, with projected losses potentially reaching $40 billion by 2027 if current trends hold.

    How to Protect Yourself: A Practical Framework

    The most effective protection combines skepticism at the point of contact, verification before any financial action, and an understanding of what legitimate crypto investment looks like versus what fraud looks like. None of this requires technical expertise.

    Before you invest

    • Verify any investment platform independently using FINRA BrokerCheck, the SEC’s Investment Adviser Public Disclosure database, or the CFTC’s registration lookup. If the platform doesn’t appear in any regulatory database, treat it as fraudulent until proven otherwise.
    • Search the platform name alongside “scam,” “complaint,” or “review” on independent forums. Pig-butchering platforms rarely have any verifiable history before they appeared in your conversation.
    • Ask the contact to video call with you. AI deepfakes have improved dramatically, but sustained, unscripted video calls still expose inconsistencies that static photos can’t reveal. A refusal is a signal.
    • Talk to someone you trust in person before sending any funds. Scam compounds train their operators to isolate victims from family and friends specifically because outside input disrupts the operation.

    At the transaction stage

    • Never send crypto to a wallet address given to you by someone you haven’t met in person and verified independently. Blockchain transactions are irreversible. There’s no dispute mechanism.
    • Be especially cautious with crypto ATMs. The FBI has flagged $333 million in crypto ATM losses for 2025. Legitimate investments don’t require you to use a convenience-store ATM.
    • If a platform asks you to pay fees, taxes, or insurance before releasing profits, stop. That’s a secondary extraction technique. Legitimate platforms don’t hold your money hostage behind fee payments.
    • Use an exchange with strong compliance standards. Platforms with real KYC processes and active fraud monitoring create meaningful friction for scam operations.

    If you’ve already sent funds

    • File a complaint with the FBI’s Internet Crime Complaint Center (IC3) immediately. Time matters for on-chain tracing.
    • Report to the FTC at ReportFraud.ftc.gov. The FTC shares data with law enforcement agencies that have asset-freezing authority.
    • Contact your bank or exchange and provide the receiving wallet address. Exchanges cooperate with law enforcement and can sometimes freeze associated accounts.
    • Preserve all communication records: screenshots, chat logs, email threads. These are critical for both criminal complaints and any civil recovery attempt.

    What the Industry Is Actually Doing

    The enforcement story gets most of the headlines, but some of the most measurable progress on fraud reduction is happening at the exchange and analytics layer. The results from Binance and Chainalysis are worth examining in detail, because they show what scaled technical intervention looks like.

    “Binance’s enhanced detection blocked US$10.53 billion from 2025 to Q1 2026, reducing illicit fund exposure by 96%.”

    Binance Security Team — Binance AI-Powered Crypto Security Report, April 30, 2026
    Binance deployed over 100 AI models across its compliance infrastructure in 2025, protecting 5.4 million users and blocking $6.69 billion in fraudulent activity in FY2025 alone. A simulation-based approach to phishing reduced their user phishing rate from 3.2% to 0.4%, an eightfold improvement. That’s not a minor optimization. That’s a structural shift in how fraud is intercepted before it reaches victims.

    On the analytics side, Chainalysis demonstrated in April 2026 what proactive blockchain monitoring can accomplish at the victim level. Working with the Singapore Police Force over a month-long operation, they identified over 90 scam victims and prevented $2.86 million in losses using real-time on-chain analytics. The point isn’t the specific dollar figure. It’s the proof of concept: tracking where funds move before they’re fully laundered can interrupt the extraction process.

    What “on-chain tracing” means practically: When a victim sends funds to a scam wallet, that transaction is recorded permanently on the blockchain. Analytics firms like Chainalysis and TRM Labs can map where those funds move next, often identifying consolidation wallets shared across multiple victims. When exchanges receive withdrawal requests from flagged wallets, they can freeze the transaction. The window is narrow, but it exists.

    Why Enforcement Alone Falls Short

    The Dubai operation arrested 276 people and shut down nine centers. That matters. But the structural conditions that make pig-butchering profitable remain almost entirely intact.

    Stablecoins, particularly USDT, remain the primary fund-transfer mechanism. Tether has frozen $4.4 billion in addresses linked to fraud since it began cooperating with law enforcement, but new wallets are created constantly. The pseudonymous nature of crypto wallets combined with cross-border laundering routes through multiple intermediate wallets means that tracing funds to a recoverable asset takes time that operational fraud networks don’t give investigators.

    The compounds themselves are the deeper problem. The armed groups that protect scam operations in Myanmar and Cambodia operate in jurisdictions where international arrest warrants carry limited practical weight. The Dubai operation worked partly because UAE law enforcement had both the authority and the political will to act. That combination doesn’t exist uniformly across Southeast Asia.

    “Investment fraud remains the costliest scam, followed by business email compromise and tech support scams. AI-enabled scams are rapidly evolving, with IC3 receiving more than 22,000 complaints last year referencing AI, and adjusted losses exceed $893 million.”

    FBI Cyber Division, IC3 Team — FBI 2025 IC3 Annual Report, April 5, 2026
    AI is also changing the economics of fraud operations. Synthetic identity creation, voice cloning for phone-based verification bypass, and deepfake video for trust-building are all in active use. The Vectra AI research team documented a 1,210% surge in AI-enabled scams in 2025. Automation means fewer human operators are needed per victim, which means the per-arrest impact of law enforcement action is declining even as arrest numbers rise.

    The recovery reality: The FBI’s IC3 has a Recovery Asset Team that works to freeze fraudulently transferred funds. But the window for recovery closes quickly once funds are converted to crypto and moved across wallets. Filing a complaint within 24 hours of discovering fraud is significantly more likely to result in recovery than filing a week later. Most victims discover the fraud only when they try to withdraw funds, which is often after multiple transfer stages have already occurred.

    Frequently Asked Questions

    What is a pig-butchering crypto scam?
    A pig-butchering scam is a long-term investment fraud where criminals build a trust relationship with a victim over weeks or months, then lure them onto a fake crypto investment platform. Once the victim has deposited significant funds, the platform disappears and the money is laundered. The name comes from a Chinese term for fattening a pig before slaughter.

    How much money did the 276 arrests crypto scam crackdown recover?
    The April 2026 operation focused on arrests and dismantling physical scam centers rather than direct fund recovery. Related DOJ enforcement efforts did include a separate $15 billion seizure from the Prince Group in November 2025. Individual victim recovery depends on how quickly complaints are filed with the FBI’s IC3 after discovering fraud.

    How can I tell if a crypto investment platform is legitimate?
    Check for registration with the SEC, CFTC, or FINRA. Legitimate investment platforms are registered with financial regulators and have verifiable histories. Search the platform name alongside “complaint” or “scam” independently. If someone introduced you to the platform through an unsolicited relationship, that alone is a serious warning sign.

    Can stolen crypto funds be recovered after a scam?
    Recovery is possible but time-sensitive. The FBI’s Recovery Asset Team can freeze funds if a complaint is filed quickly, ideally within 24 to 72 hours of the transfer. On-chain analytics firms can trace funds across wallets, and exchanges with strong compliance programs can freeze accounts associated with flagged addresses. Full recovery is uncommon but partial recovery does occur.

    What role does AI play in modern crypto scams?
    AI is used to generate synthetic profiles, clone voices for phone verification bypass, create deepfake videos for trust-building, and automate the initial contact and grooming phases of scam operations. The FBI’s 2025 IC3 report logged over 22,000 AI-referenced fraud complaints with $893 million in losses, and AI-enabled scam incidents grew 1,210% in 2025.

    Where should I report a crypto investment scam?
    File immediately with the FBI’s Internet Crime Complaint Center at ic3.gov, and with the FTC at ReportFraud.ftc.gov. Also contact your bank or crypto exchange and provide the destination wallet address. Preserve all communication records. Report to your state financial regulator as well, since states like California actively track pig-butchering complaints through the DFPI.

    Are crypto ATMs safe to use for legitimate transactions?
    Crypto ATMs are legal and some people use them legitimately. But the FBI documented over $333 million in crypto ATM-related fraud losses in 2025, and scammers specifically direct victims to use them because transactions are fast and irreversible. If anyone online instructs you to use a crypto ATM to invest or send funds, treat that as a scam attempt.

    Why do pig-butchering scams originate from Southeast Asia?
    Criminal syndicates established large-scale scam compounds in Cambodia, Myanmar, and Laos where they operate with relative impunity, often under the protection of local armed groups. Many workers in these compounds are themselves trafficking victims, lured by fake job ads. Chainalysis documented an 85% increase in crypto transactions linked to suspected human trafficking between 2024 and 2025.

    What Comes Next

    The 276 arrests represent the largest coordinated takedown of pig-butchering networks targeting Americans. The DOJ’s Scam Center Strike Force, stood up in November 2025, is now showing its first major public results. That structural commitment to cross-border enforcement is new and meaningful.

    But $17 billion in on-chain scam receipts in a single year doesn’t shrink through arrests alone. The most durable protection against pig-butchering fraud is personal: skepticism at first contact, verification before any financial action, and knowing the specific red flags that distinguish grooming from genuine connection. The four-phase scam structure is consistent enough across operations that recognizing Phase 2 before reaching Phase 3 remains the most effective individual defense available.

    On the industry side, exchange-level AI detection and proactive blockchain analytics are showing measurable results. Binance’s 96% reduction in illicit fund exposure and Chainalysis’s real-time victim identification work show that technical infrastructure can interrupt fraud before it completes. The gap between what’s technically possible and what’s widely deployed is still large, but it’s narrowing.

    The enforcement story will continue to develop. The two fugitive co-conspirators from the San Diego charges remain at large. The compounds in Myanmar and Cambodia operate under conditions that make arrest unlikely without sustained diplomatic pressure. And AI automation is lowering the cost of running scam operations faster than enforcement is raising it.

    Watch For
    01 DOJ Scam Center Strike Force indictments through Q3 2026. The November 2025 Prince Group seizure and April 2026 arrests signal an active pipeline. More charges targeting mid-tier syndicate operators are likely within months.
    02 Tether and stablecoin issuer compliance expansion. With $4.4 billion already frozen by Tether in cooperation with law enforcement, regulatory pressure on stablecoin issuers to act faster on fraud-linked addresses is building. Policy changes here would have direct operational impact on scam laundering routes.
    03 AI deepfake detection requirements for crypto exchanges. The FBI’s AI-fraud data from 2025 is already prompting early-stage regulatory discussions about mandatory deepfake detection at the onboarding layer. How exchanges respond to those requirements will shape fraud exposure for retail investors through 2027.
    04 Crypto ATM legislative action at the state level. Following $333 million in 2025 ATM fraud losses, several U.S. states are actively considering daily transaction limits or enhanced verification requirements for crypto ATM operators. California and Minnesota are the jurisdictions to watch first.
    Stay ahead of the curve. More on crypto security, fraud, and digital finance at NeuralWired.
    Explore Crypto Coverage
  • Bitcoin $80K Resistance: Why It Won’t Break (2026)

    Bitcoin $80K Resistance: Why It Won’t Break (2026)

    Bitcoin’s $80K Wall: Why 4 Rejections, $3B in ETF Inflows, and 818K BTC in Corporate Vaults Still Haven’t Broken It | NeuralWired

    Bitcoin’s $80K Wall: Why 4 Rejections, $3B in ETF Inflows, and 818K BTC in Corporate Vaults Still Haven’t Broken It

    Bitcoin has bounced off $80,000 four times since February. Institutions keep buying, exchange reserves sit at a six-year low, and prediction markets priced a May 1 close above $79,000 at just 22 cents. Something structural is holding the line.

    Bitcoin traded between $78,000 and $78,700 on May 1, 2026, inching toward a resistance level that has now repelled four separate breakout attempts since February. The number is round, the psychology is obvious, and the mechanics are anything but simple. Beneath a deceptively flat price chart sits a coiled structure of options exposure, institutional order flow, and on-chain supply compression that makes $80,000 one of the most technically significant price points in this market cycle.

    The week ending April 25 saw Bitcoin spot ETFs absorb a net $3.06 billion in fresh capital, the second-largest weekly inflow ever recorded, according to SoSoValue data. BlackRock’s IBIT alone pulled in $1.45 billion across those five trading days, pushing its lifetime net inflows past $41.2 billion. That buying wave didn’t push Bitcoin through $80,000. It got within $523 of the level and then reversed.

    That reversal tells you more about what’s really happening than the inflow number does. This is a market where institutional demand is real, supply on exchanges has fallen to a six-year low of 2.3 million BTC, and yet a single price level keeps acting like a ceiling. Here’s why, and what it would actually take to change that.


    The $80K Wall: Options, Gamma, and 7,200 BTC in Open Interest

    The $80,000 level isn’t just psychologically significant. It carries real mechanical weight in the options market. According to analysis from crypto exchange Bittime, there are approximately 7,200 BTC worth of open interest clustered at or near the $80,000 strike, and the current gamma exposure at that level is positive, meaning options dealers are net short gamma and must sell into rising prices to stay hedged.

    “BTC’s resistance level is at $80,000 [and] exceeding this level will trigger extreme volatility.”

    On-chain analyst Murphy, cited by Bittime Research, April 27, 2026
    What that means in practice: every time Bitcoin approaches $80,000, dealers sell to rebalance their books. The selling isn’t driven by conviction that the price is too high. It’s mechanical. Once price clears that level and moves into the zone above $81,000, however, the gamma flips negative. At that point dealers need to buy into rising prices, which can accelerate a move toward $82,000 and beyond with surprising speed. Bittime’s data puts the negative gamma zone at roughly 4,644 BTC of exposure above $81,000.

    What is gamma exposure? Options dealers who sell calls must buy the underlying asset as prices rise to hedge their position. When gamma is positive (near a resistance strike), this hedging pressure works against the breakout. When gamma turns negative above that strike, the hedging pressure reverses and can amplify upward moves dramatically.

    The April 24 intra-day high of $79,477 illustrated this exactly. Bitcoin came within half a percentage point of $80,000, touched that options resistance zone, and was sold back within hours. The rejection wasn’t a coincidence. It was the market’s options structure executing exactly as designed.

    “Bitcoin must break $80,000 to exit consolidation and confirm a durable bullish regime.”

    Bitfinex Research Desk, Bitcoin.com News, April 26, 2026
    Bitfinex analysts have been consistent on this point since late April. Break the level with a weekly close above it, and the consolidation that began after Bitcoin’s February peak near $126,000 is structurally over. Fail again, and the range compresses further until something external forces a resolution. There’s also an estimated $1.5 billion in short positions that would be force-liquidated if Bitcoin clears $81,000, adding further fuel to any genuine breakout.

    ETF Flows: A Record Week Followed by Three Days of Outflows

    The $3.06 billion weekly inflow was genuinely exceptional. To put it in context, Bloomberg ETF analyst Eric Balchunas captured the trajectory well when the products first launched:

    “If they can take in $22 billion when it’s raining, imagine when the sun is shining.”

    Eric Balchunas, Senior ETF Analyst, Bloomberg, CryptoBriefing, January 5, 2026
    That early-2026 optimism played out in April’s inflow numbers. But what the weekly headline obscured was a sharp reversal in the days that followed. After the record week ended April 25, flows turned negative almost immediately.

    Date ETF Flow Notable
    Apr 21-25 (week) +$3.06B net inflows Second-highest week on record; IBIT +$1.45B
    Apr 27 -$263M outflows Largest single-day outflow of the post-peak period
    Apr 28 -$89.68M outflows Fidelity FBTC shed 1,959 BTC in one session
    Apr 29 -$112M (IBIT alone) BlackRock’s flagship product posted its own net outflow day
    Three consecutive days of outflows after a record inflow week is the kind of data point that gets lost in the narrative. It doesn’t invalidate the structural bull case. But it does confirm that institutional appetite, while real, is not an unlimited conveyor belt of buying pressure. When Bitcoin failed to reward the surge of April 21-25 capital with a breakout, some of that money came back out.

    Flow reversal risk: For a sustained move above $80,000, analysts say ETF outflows need to flip back to consistent net positive territory. Three consecutive days of net selling after the second-biggest weekly inflow on record suggests momentum may need a fresh catalyst to reignite.

    The early-2026 picture does offer longer-term reassurance. Bitcoin ETFs pulled in $1.2 billion across their first two trading days of 2026. If that pace had been sustained over a full year, total annual inflows would have annualized toward $150 billion. It didn’t sustain at that pace, obviously. But it established a demand floor that keeps showing up during any meaningful dip.

    818,334 BTC: Corporate Accumulation as a Structural Floor

    Strategy, the software company turned Bitcoin holding vehicle led by Michael Saylor, now holds 818,334 BTC. That’s approximately 4.2% of the total Bitcoin supply that will ever exist, sitting in a single corporate treasury. And the buying hasn’t stopped.

    On April 20, Strategy added 34,164 BTC at an average price of $74,395, spending $2.54 billion in a single transaction. One week later, another 3,273 BTC for $255 million. The consistency of this accumulation, even at prices most retail buyers would consider elevated, does two things to the market. It removes coins from circulation. And it sets a psychological floor well below current trading prices.

    🏛️
    Strategy Holdings

    818,334 BTC (~4.2% of total supply). Latest purchases averaged $74,395 per coin across two April transactions totaling $2.8B.

    📉
    Exchange Reserves

    2.3 million BTC on exchanges, the lowest level in six years. Less available supply means larger price swings when demand spikes.

    💰
    Stablecoin Dry Powder

    $317 billion in stablecoins, representing 11.73% of total crypto market cap. Potential buying power sitting on the sidelines.

    📊
    BTC Dominance

    57.89% of the $2.65T total crypto market cap. Institutional preference keeps flowing toward BTC over altcoins.

    The structural argument is straightforward: with exchange reserves at a six-year low and a single entity holding 4.2% of supply, the available float that could meet institutional demand is genuinely constrained. That’s the supply side of the equation. The demand side, as represented by ETF inflows, has shown it can generate $3 billion in a single week. When those two forces converge with a macro catalyst, the options market’s gamma structure above $80,000 turns from headwind to tailwind almost instantly.

    “The $85,000 to $88,000 zone is not a fantasy number, and it sits right at the confluence of the 200-day simple moving average and the upper boundary of the resistance band.”

    Michael van de Poppe, Independent Market Analyst, Phemex Research, April 29, 2026

    April’s $625M Hack Storm: The Bearish Signal Nobody’s Talking About

    While Bitcoin prices climbed and ETF headlines dominated, April 2026 quietly became the worst month in crypto security history by incident count. DeFiLlama confirmed 28 to 30 separate exploits, with more than $625 million stolen across the industry. Two attacks alone accounted for 93% of the damage.

    • The Drift Protocol exploit on April 1 drained $285 million from the Solana-based derivatives platform in one of the largest single DeFi hacks on record.
    • The KelpDAO attack on April 18, targeting a cross-chain bridge via LayerZero, extracted $293 million, briefly setting a new single-incident record before month-end tallies put it second behind Drift on impact.
    • The remaining 26-28 incidents collectively accounted for roughly $47 million, a figure that would dominate headlines in a quieter month but barely registered against April’s two landmark exploits.
    Context: DeFiLlama’s confirmation of April 2026 as the most-hacked month by incident count doesn’t mean the DeFi ecosystem is collapsing. But $625 million in 30 days creates measurable headwinds for sentiment, particularly among institutional allocators who must justify exposure to their risk committees. This is a suppressive force on the upside that price charts alone don’t capture.

    The timing matters. April’s hack wave coincided almost exactly with the peak ETF inflow week and the $79,477 rejection. Some portion of the selling pressure that knocked Bitcoin back from its high likely reflected DeFi participants moving funds off-chain or rotating to safer assets after major protocol failures. It’s impossible to isolate that effect precisely, but it’s also not credible to ignore it entirely.

    The broader context is also troubling. The FBI reported $240 million lost to crypto ATM scams in just the first half of 2025, with total ATM-related fraud losses exceeding $333 million nationally. Tennessee has already passed legislation banning crypto ATMs entirely, effective July 2026, citing the FBI-linked fraud data. That’s a retail access restriction at a moment when institutional channels are expanding rapidly, which creates an asymmetric market structure that skews heavily toward sophisticated players.

    Macro and Policy Backdrop: Risk-On, but Fragile

    Bitcoin’s correlation with traditional risk assets has been consistent throughout this cycle. When equity futures rise, Bitcoin tends to follow. When the Federal Reserve tilts hawkish, crypto sells off. The current macro environment offers a cautiously supportive backdrop, but “cautious” is doing a lot of work in that sentence.

    “Market conditions appear to be realigning with the broader status quo, particularly around Fed expectations. After a brief wobble driven by a hawkish tilt that unsettled risk assets, the market is once again leaning toward accommodation.”

    Joel Kruger, Strategist, LMAX Group, Finance Magnates
    Kruger’s observation describes the macro mechanism that keeps reasserting itself: whenever the Fed signals even a modest lean toward easier conditions, risk assets including Bitcoin catch a bid. The current setup mirrors that pattern. Bitcoin has recovered 30% from its cycle low of $60,000, and the global crypto market cap sits at $2.65 trillion to $2.7 trillion as of May 1, up more than 2% in 24 hours. That’s not explosive. But it’s directional.

    Ethereum traded at $2,280 on May 1, up roughly 1.06% on the day, with an intra-day range of $2,260 to $2,300. Ethereum’s relative underperformance against Bitcoin, whose dominance now stands at 57.89%, reflects a consistent theme of this cycle: institutional capital flows into BTC first, altcoins second. Until Bitcoin establishes a clear new range above $80,000, that capital hierarchy is unlikely to shift.

    Market snapshot, May 1, 2026: Bitcoin ~$78,000-$78,700 (+2-3% 24h). Ethereum $2,280 (+1.06%). Global crypto market cap $2.65T-$2.7T. BTC dominance 57.89%. BTC market cap $1.56T. Stablecoin market cap $317B (11.73% of total). Sources: CoinGecko.

    The prediction markets offered their own probability assessment on May 1. Robinhood’s Bitcoin price event contracts priced a 5pm EDT close at or above $78,000 at 71 cents, above $78,500 at 43 cents, and above $79,000 at just 22 cents. Sophisticated traders put the probability of challenging the $80,000 resistance zone by end of day at roughly one in five.

    3 Scenarios for May: Breakout, Grind, or Reversal

    Analyst CF Benchmarks’ Gabe Selby framed the decision point plainly in late April: “$80K could be reached within days, though failure to break $88K may trigger renewed consolidation.” That’s the May range in a single sentence. What determines which scenario plays out?

    Scenario Trigger Price Target Key Risk
    Breakout Weekly close above $80K + ETF outflows reverse; $1.5B short squeeze ignites above $81K $82K-$88K (van de Poppe’s 200-DMA confluence zone) Gamma flip to negative above $81K creates vol spike; macro shock could kill momentum mid-run
    Grind ETF flows remain mixed; no macro catalyst; range-bound $74K-$80K continues $76K-$80K through May Prolonged compression increases the probability of a violent resolution in either direction
    Reversal Macro deterioration (hawkish Fed surprise, equity selloff); ETF outflows accelerate Retest $74K-$75K range support Strategy’s average cost basis near $74K provides a structural defense; below that gets ugly
    Phemex’s market analysts laid out three specific conditions they say must all be met for a sustained push toward $88,000: ETF inflows need to return to net positive and stay there for at least a week; the macro environment needs to hold its current risk-on posture without a Fed shock; and on-chain data needs to confirm that long-term holders aren’t distributing into strength. Two of those three conditions were borderline as of May 1. The third, on-chain holder behavior, remains constructive.

    The short-squeeze element adds a non-linear dimension to any breakout. An estimated $1.5 billion in short positions sit above current prices, clustered most densely between $80,000 and $82,000. A clean break above $80,000 that forces even a portion of those positions to close at a loss doesn’t just add buying pressure. It removes selling pressure simultaneously, which is why breakouts from ranges like this can happen faster than even optimistic forecasts anticipate. The options-driven negative gamma above $81,000 amplifies that further.

    Frequently Asked Questions

    Why does Bitcoin keep failing to break $80,000?
    The $80,000 level carries significant options market resistance, with roughly 7,200 BTC in open interest at that strike. Options dealers must sell into rallies approaching $80,000 to stay hedged, creating mechanical selling pressure that doesn’t reflect fundamental bearishness. Once price clears that level, the dynamic reverses.

    How much did Bitcoin ETFs bring in during April 2026?
    The week of April 21-25 saw Bitcoin spot ETFs record $3.06 billion in net inflows, the second-highest weekly total ever. However, three consecutive days of net outflows followed: $263 million on April 27, $89.68 million on April 28, and $112 million from BlackRock’s IBIT alone on April 29.

    How much Bitcoin does Strategy (formerly MicroStrategy) hold?
    As of late April 2026, Strategy holds 818,334 BTC, representing approximately 4.2% of Bitcoin’s total eventual supply. The company added 34,164 BTC at an average of $74,395 on April 20 and 3,273 BTC one week later, spending roughly $2.8 billion across two purchases.

    What happened with crypto hacks in April 2026?
    April 2026 became the most-hacked month in crypto history by incident count. DeFiLlama confirmed 28 to 30 separate exploits totaling more than $625 million stolen. The Drift Protocol exploit ($285 million) and KelpDAO exploit ($293 million) accounted for 93% of losses.

    What is a short squeeze and why does it matter at $80K?
    A short squeeze occurs when rising prices force traders who bet against an asset to buy it back to limit losses. Approximately $1.5 billion in short positions are estimated above current Bitcoin prices. If Bitcoin clears $81,000, forced short-covering adds significant upward momentum on top of normal buying pressure.

    What price targets are analysts citing for Bitcoin in May 2026?
    Independent analyst Michael van de Poppe cites $85,000-$88,000 as a realistic target if Bitcoin breaks $80,000, based on the 200-day moving average and resistance band confluence. CF Benchmarks analyst Gabe Selby noted $80,000 could be reached within days but cautioned that failure to clear $88,000 risks renewed consolidation.

    Is Bitcoin’s dominance rising or falling in 2026?
    Bitcoin dominance sits at 57.89% of total crypto market cap as of May 1, 2026, with a market cap of $1.56 trillion out of a total $2.65-$2.7 trillion global crypto market. Institutional preference for BTC over altcoins continues to support its dominant share of flows.

    What is the Tennessee crypto ATM ban and what does it signal?
    Tennessee passed legislation banning crypto ATMs, effective July 2026, citing FBI data linking machines to fraud. The FBI reported $240 million in ATM-related scam losses in the first half of 2025 alone, with total losses exceeding $333 million nationally. Tennessee’s move is an early signal of a broader retail-channel restriction trend as institutional access expands.

    What Comes Next

    The honest read on Bitcoin’s position at the start of May 2026 is that the bulls have done almost everything right and still can’t close above $80,000. Institutional flows hit a near-record. Corporate treasury buying continued at scale. Exchange supply compressed to multi-year lows. The macro backdrop shifted toward risk-on. And Bitcoin topped out at $79,477 before reversing.

    That’s not a failure of the bull case. It’s the bull case colliding with a specific, well-defined structural obstacle. Options market mechanics, not fundamental disagreement about Bitcoin’s value, are the primary force keeping price below $80,000. That’s both reassuring and frustrating: reassuring because the resistance is finite and mechanical rather than sentiment-based, frustrating because it can persist indefinitely until a catalyst with enough force to overwhelm the gamma wall shows up.

    The April hack data adds a layer of complexity that most price-focused analysis ignores. Losing $625 million across 30 incidents doesn’t just affect the protocols and users directly hit. It shapes the risk conversation inside institutional treasury and compliance teams evaluating crypto allocations. If April’s security picture carries into May, it limits the marginal institutional buying that could provide the catalyst the price needs.

    One other data point is worth keeping in mind: $317 billion in stablecoins sits on the sidelines, representing 11.73% of total crypto market cap. That’s buying power looking for a reason to deploy. If Bitcoin provides that reason, in the form of a clean weekly close above $80,000 with ETF outflows reversing, the chase toward van de Poppe’s $85,000-$88,000 target zone could compress into a matter of days rather than weeks.

    Watch For
    01 Weekly ETF flow data (released each Monday): a return to consistent net positive after three straight outflow days is the clearest leading indicator of renewed institutional conviction heading into mid-May.
    02 Options expiry dates in May: large monthly expirations reset gamma exposure at key strikes. A post-expiry gamma reset could make $80,000 meaningfully easier to clear as dealer hedging pressure temporarily lifts.
    03 Federal Reserve communication: any signal of rate flexibility or easing bias is the macro catalyst most likely to trigger the institutional buying wave that overwhelms $80,000’s options resistance in a single session.
    04 May DeFi security data: if April’s 30-incident hack pace continues into May, it will keep a measurable drag on sentiment at precisely the moment price needs clean momentum to break a three-month ceiling.
    Stay ahead of the curve. More Bitcoin market analysis and crypto intelligence at NeuralWired.
    Explore Markets
  • Tether Loan Lutnick Senate Investigation: 4th Probe

    Tether Loan Lutnick Senate Investigation: 4th Probe

    Senators Warren and Wyden Launch 4th Probe Into Tether’s $191B Empire and Its Ties to Commerce Secretary Lutnick

    A reported loan from the world’s largest stablecoin issuer to a trust benefiting Howard Lutnick’s children has triggered a fresh congressional investigation — arriving the same week Tether froze $344 million linked to Iran.

    Two of Washington’s most aggressive crypto skeptics aren’t done with Tether. On April 29 and 30, 2026, Senators Elizabeth Warren and Ron Wyden sent letters to Commerce Secretary Howard Lutnick and Tether CEO Paolo Ardoino demanding details about a reported loan that allegedly helped Lutnick satisfy his federal divestiture requirements. The letters mark what watchdog journalists are calling the fourth congressional inquiry into the Lutnick-Tether relationship — and they arrive at a politically charged moment.

    Just days before the letters landed, the U.S. Treasury Department announced that Tether had frozen $344 million in USDT tied to addresses the government says are connected to the Central Bank of Iran. Treasury Secretary Scott Bessent publicly praised the move. That the same company faces both bipartisan acclaim on sanctions enforcement and a Democratic-led ethics investigation underscores how complicated Tether’s Washington story has become.

    Tether now issues more than $191 billion in USDT, representing a 58% share of the entire stablecoin market. It isn’t a niche cryptocurrency project. It’s a financial infrastructure company whose decisions affect markets, sanctions enforcement, and — if the senators’ concerns prove well-founded — the policy agenda of a sitting cabinet official.


    The Fourth Probe: What Warren and Wyden Are Asking

    The letters Warren and Wyden sent aren’t fishing expeditions. They’re precise. The senators want to know whether Tether provided a loan to a trust set up for Lutnick’s four children, whether that loan facilitated his court-mandated divestiture from Cantor Fitzgerald, and whether Lutnick has maintained any communication with Tether or its executives since his Senate confirmation. They also want documents.

    “It is critical that you make decisions because they are in the best interest of the American public, not in the financial interest of your family or Tether.”

    Senator Elizabeth Warren, Ranking Member, Senate Banking Committee — Letter to Secretary Howard Lutnick, April 30, 2026
    Warren didn’t stop there. She spelled out the conflict of interest in plain terms: if reports of the loan are accurate, she wrote, they “would raise serious questions about the relationship between Secretary Lutnick and Tether, and the influence of Tether on Mr. Lutnick’s policy decisions.” It’s the kind of framing that tends to follow officials into confirmation hearings — or impeachment proceedings.

    Wyden, who chairs the Senate Finance Committee, co-signed the letters. This was their third joint action against Lutnick in under a year. In August 2025, the two senators had already demanded that Cantor Fitzgerald disclose tariff-refund agreements it allegedly held. The pattern of escalation is deliberate.

    Timeline of investigations: Aug 2025 — Warren and Wyden demand Cantor tariff-refund disclosures. Jan 29, 2025 — Lutnick testifies before the Senate Commerce Committee on Tether involvement. April 29-30, 2026 — Fourth probe launched via letters to Lutnick and Ardoino.

    The Commerce Department responded with a familiar line: Lutnick has complied with all applicable ethics rules. That may be legally accurate. It doesn’t answer the underlying question about whether a loan from Tether to a family trust — even an indirect one structured through a blind trust — creates an ongoing financial relationship that shapes policy.

    The Loan at the Center of It All

    The core allegation traces back to a Bloomberg report from October 2025. According to that reporting, when Lutnick was required to divest his multibillion-dollar stake in Cantor Fitzgerald upon his nomination as Commerce Secretary, a loan from Tether helped facilitate the transaction. The stake was transferred into a trust for Lutnick’s children. Tether, Bloomberg reported, provided the financing that made the structure work.

    Neither the loan amount nor its terms have been publicly disclosed. Warren’s letter notes the amount “likely reached millions” based on the scale of the Cantor Fitzgerald valuation. Tether has neither confirmed nor denied the loan’s existence in public statements. Ardoino did not respond to press inquiries before this article’s publication.

    “If reports of this loan are accurate, it would raise serious questions about the relationship between Secretary Lutnick and Tether, and the influence of Tether on Mr. Lutnick’s policy decisions.”

    Senator Elizabeth Warren — Letter to Commerce Secretary Howard Lutnick, April 29, 2026
    The timing matters. Lutnick now sits on the President’s Working Group on Digital Assets. Tether’s U.S.-focused stablecoin product, USAT, launched while Lutnick was already in office. Ardoino attended the White House signing of the GENIUS Act, the stablecoin regulatory framework that Tether had publicly advocated for. Whether any of those outcomes were influenced by the reported financial relationship is exactly what Warren and Wyden want documents to resolve.

    Unconfirmed: The loan amount, terms, collateral, and interest rate have not been publicly disclosed. The loan itself has not been independently verified beyond Bloomberg’s original reporting. Tether and the Commerce Department have not confirmed or denied its existence.

    How the Divestiture Structure Works

    Federal ethics rules require cabinet nominees to divest assets that could create conflicts of interest. Lutnick’s Cantor Fitzgerald stake ran into the billions. A direct sale would have triggered significant tax consequences. Transferring the stake to a trust for his children while securing outside financing — if that’s what happened — is a structure that ethics experts say can technically comply with divestiture requirements while preserving family wealth. It can also preserve relationships, which is precisely the senators’ concern.

    $344 Million Frozen: Tether’s Iran Enforcement Action

    April 23, 2026 was a busy day for Tether’s compliance team. The company, working alongside U.S. authorities, froze two Tron blockchain addresses holding a combined $344 million in USDT. The Treasury Department said the funds were connected to the Central Bank of Iran and were being used to evade U.S. sanctions.

    “We will follow the money that Tehran is desperately attempting to move outside of the country and target all financial lifelines tied to the regime.”

    Scott Bessent, U.S. Treasury Secretary — Treasury Department press statement, April 23, 2026
    The mechanics of the freeze are worth understanding. Tether’s USDT smart contracts include a blacklist function that allows the company to freeze specific wallet addresses at the protocol level. Once frozen, funds can’t be moved. The two addresses in this case held $213 million and $131 million respectively, both on the TRON network, which carries roughly 42% of all circulating USDT, or about $78 billion.

    Three days later, on April 26, OFAC updated its Central Bank of Iran designation to reflect the blockchain activity Tether’s freeze had surfaced. The U.S. government confirmed it had detected, through blockchain analytics, “material connections to the Iranian regime, including verified transactions with Iranian exchanges and a series of transfers routed through intermediary addresses interacting with wallets associated with the Central Bank of Iran.”

    🔒
    Total Frozen

    $344 million in USDT frozen across two Tron addresses linked to Iran sanctions evasion.

    🇮🇷
    Iran Nexus

    OFAC confirmed verified transactions with Iranian exchanges and Central Bank of Iran-linked wallets.

    🌐
    Enforcement Reach

    Tether works with 340-plus law enforcement agencies across 65 countries on financial crime cases.

    ⛓️
    Tron Network

    TRON carries 42% of all USDT supply, with $20-30 billion in daily transfer volume.

    The enforcement action is Tether’s largest single freeze on record. It’s also politically useful for the company. Demonstrating active cooperation with Treasury on sanctions enforcement while simultaneously facing a Senate ethics probe over Lutnick allows Tether to argue that it’s a compliant, government-aligned operator — not a rogue stablecoin issuer.

    Tether’s Reserve Picture in 2026

    Critics have spent years questioning whether Tether actually holds the assets backing its USDT supply. The company’s position has shifted considerably since its commercial-paper era. Today, Tether’s published reserve breakdown shows more than $122 billion in U.S. Treasury Bills, roughly 83% of its total reserve base.

    Reserve Component Amount / Share Notes
    U.S. Treasury Bills $122B+ (83.11%) Largest single asset class; short-duration government paper
    Cash and Cash Equivalents 76.31% of liquid assets Includes overnight repos and money market instruments
    Corporate Bonds 0% Eliminated entirely after 2022 pivot away from commercial paper
    Gold and Bitcoin Small percentage Held as supplementary collateral alongside surplus equity
    Surplus Equity Billions (undisclosed) Retained earnings above 1:1 backing ratio
    The pivot away from commercial paper began in 2022, when Tether held roughly $8.4 billion in corporate debt instruments that drew sustained criticism from analysts and regulators. That’s all gone now. The shift to Treasury Bills is significant: short-duration U.S. government paper is the most liquid, most transparent asset class available. If Tether needed to redeem USDT quickly, T-bills are easy to sell.

    That said, Tether still publishes attestations rather than full audits. The distinction matters. An attestation confirms that a snapshot of assets matched liabilities at a specific moment. A proper audit examines internal controls, the validity of asset ownership documentation, and whether the accounting reflects economic reality. The company has been promising a full audit for years. None has materialized.

    Attestation vs. Audit: Tether publishes quarterly reserve attestations from accounting firms. These are not equivalent to a full financial audit. Former SEC enforcement officials have noted that attestations cannot independently verify asset ownership chains or detect potential undisclosed liabilities.

    Despite that gap, USDT’s market position keeps growing. As of May 1, 2026, circulating supply sat at approximately $191.1 billion. The stablecoin’s peg held at $0.99971, essentially unchanged despite the headlines. Bitcoin, trading near $75,600 to $76,000 on the same day, showed muted momentum, its price partly weighted by broader market uncertainty around the investigation’s coverage.

    Who Has What at Stake

    This story isn’t just about one company and one senator. Multiple institutions are navigating overlapping interests, and the outcome of the probe could reshape U.S. stablecoin regulation.

    Stakeholder Core Interest Best Outcome Worst Outcome
    Tether / Paolo Ardoino Regulatory legitimacy and market access GENIUS Act passage grants legal framework; probe fizzles Major exchange delisting or DOJ investigation
    Howard Lutnick Cabinet credibility and ethics compliance Documents show no post-nomination contact with Tether Loan confirmed; calls for resignation intensify
    Warren and Wyden Senate oversight authority and crypto accountability Documents reveal undisclosed contacts; regulatory reform advances Investigation produces nothing; political capital spent
    U.S. Treasury / OFAC Sanctions enforcement effectiveness Tether continues freezing illicit funds as enforcement partner Conflict of interest narrative undermines Treasury credibility
    Crypto Traders and Exchanges USDT liquidity and peg stability Probe resolves without affecting market confidence Peg stress or exchange delistings trigger market disruption
    Tether’s position in the stablecoin market isn’t secure by default. Circle’s USDC has gained ground in compliant institutional markets, and TRM Labs data from March 2026 shows USDC holds about 64% of the combined adjusted transaction volume in regulated settings. If U.S. stablecoin legislation passed with provisions that made Tether’s offshore structure noncompliant, the company’s American market access could narrow quickly.

    Coinbase CEO Brian Armstrong hinted in early 2026 that exchanges might be required to delist Tether under certain regulatory scenarios. Tether’s response has been to accelerate its compliance portfolio, the Iran freeze, the MOS mining OS open-sourcing, the USAT U.S. stablecoin, to build a track record of cooperation before any binding rules take effect.

    Meanwhile, the Bitcoin mining vertical is expanding. Tether Investments has proposed merging Strike, the Bitcoin payments company led by Jack Mallers, with Twenty One Capital and bitcoin miner Elektron Energy. Elektron controls around 50 exahashes per second of mining capacity, roughly 5% of the entire Bitcoin network hashrate. Mallers publicly supported the proposal on April 28, 2026. If completed, Tether would have interests spanning stablecoin issuance, U.S. payments infrastructure, and industrial-scale Bitcoin mining.

    “Successful treasury companies need amazing operational businesses.”

    Paolo Ardoino, CEO, Tether — CoinMarketCap Academy interview, December 2025

    Frequently Asked Questions

    What is the Tether loan to Lutnick’s family trust?
    Bloomberg reported in October 2025 that Tether provided a loan to a trust set up for Commerce Secretary Howard Lutnick’s four children, which allegedly helped him satisfy his federal divestiture requirement from Cantor Fitzgerald. Neither the loan amount nor its terms have been officially confirmed. Senators Warren and Wyden are demanding documentation.

    Why did Tether freeze $344 million in USDT?
    On April 23, 2026, Tether froze two Tron blockchain addresses holding $344 million in USDT at the request of U.S. authorities. Treasury and OFAC said the funds were connected to the Central Bank of Iran and were being used to evade U.S. sanctions. OFAC updated its Iran designation on April 26 to reflect the findings.

    How big is Tether’s USDT in 2026?
    As of May 1, 2026, Tether had approximately $191.1 billion in USDT in circulation, representing about 58% of the total stablecoin market. The overall stablecoin market stands at roughly $316 billion across all issuers.

    Is Tether’s USDT fully backed by real assets?
    Tether publishes quarterly reserve attestations showing more than $122 billion in U.S. Treasury Bills and additional liquid assets. However, these are attestations, not full financial audits. Critics note that attestations can’t independently verify ownership chains or rule out undisclosed liabilities. No independent audit has been completed.

    What is the GENIUS Act and how does it affect Tether?
    The GENIUS Act is U.S. stablecoin legislation that Tether has publicly supported. CEO Paolo Ardoino attended the White House signing ceremony. The bill would create a legal framework for stablecoin issuers, potentially legitimizing Tether’s U.S. operations while setting compliance standards it would need to meet.

    Can Tether freeze USDT in any wallet?
    Yes. Tether’s USDT smart contracts include a blacklist function that allows the company to freeze specific addresses at the protocol level. This capability has been used in law enforcement cooperation cases. Tether says it works with more than 340 agencies across 65 countries. Critics argue this power makes USDT not truly decentralized.

    What is Howard Lutnick’s role in crypto policy?
    As Commerce Secretary, Howard Lutnick sits on the President’s Working Group on Digital Assets. Before his nomination, he ran Cantor Fitzgerald, which had financial ties to Tether including reported U.S. Treasury custody arrangements. His divestiture structure is now under investigation by the Senate.

    What is Twenty One Capital and why does it matter?
    Twenty One Capital is a Tether-backed Bitcoin holding company. Tether Investments has proposed merging it with Strike, the Bitcoin payments company, and Elektron Energy, a Bitcoin miner controlling roughly 5% of network hashrate. If completed, it would give Tether interests across stablecoin issuance, U.S. payments, and industrial mining.

    What Comes Next

    The fourth probe into Tether’s Washington ties is, at its core, about two questions that have never been cleanly answered: Does a financial relationship between a stablecoin issuer and a cabinet official constitute a conflict of interest under federal ethics law? And if it does, who, exactly, enforces that?

    Warren and Wyden have the oversight authority to demand documents. They can’t compel criminal charges. Whether the Justice Department or the Office of Government Ethics pursues the matter further depends on what those documents actually show. Lutnick’s team says he complied with all required disclosures. The senators say the disclosures they’ve seen don’t answer their specific questions about the reported loan.

    Tether, for its part, isn’t standing still. It’s building compliance infrastructure, cooperating on sanctions enforcement, expanding into Bitcoin mining, and pushing for regulatory frameworks it helped draft. The company’s strategy seems to be making itself too useful, and too deeply embedded in U.S. financial infrastructure, to target aggressively. Whether that strategy holds up against a sustained Senate investigation is a different matter. The documents Warren and Wyden are demanding have deadlines attached. The answers, when they come, will determine whether this is a fourth probe or the beginning of something much larger.

    Watch For
    01 Document response deadlines from Lutnick and Ardoino, the senators set specific timelines in their April 29-30 letters. Non-compliance or redacted responses will escalate pressure significantly.
    02 GENIUS Act progress in Congress, if the bill moves to a floor vote, expect Warren and Wyden to use the Lutnick-Tether probe as a centerpiece argument for stricter conflict-of-interest provisions in stablecoin law.
    03 Tether’s proposed merger of Strike, Twenty One Capital, and Elektron Energy, regulatory review of a deal combining Bitcoin payments, mining, and stablecoin interests could draw antitrust and securities scrutiny on top of the existing Senate inquiry.
    04 USDT peg stability, despite holding firm at $0.99971 on May 1, 2026, any major exchange signaling a review of Tether’s listing status could trigger a stress test of its reserve redemption capacity.
    Stay ahead of the curve. More crypto policy, stablecoin analysis, and blockchain regulation coverage at NeuralWired.
    Explore Crypto
  • PyTorch Lightning Malware on PyPI: Urgent Fix Guide 2026

    PyTorch Lightning Malware on PyPI: Urgent Fix Guide 2026

    PyTorch Lightning Hit by Supply Chain Attack — Malicious PyPI Versions Steal Credentials | NeuralWired

    PyTorch Lightning Hijacked: 16M Monthly Downloads Exposed to Credential-Stealing Malware

    Two versions of the popular AI framework package were quietly poisoned on PyPI, executing a credential harvester the moment any developer imported them. Here’s what got stolen, how it worked, and what you need to do right now.

    At some point on the morning of April 30, 2026, someone published two versions of the lightning package on PyPI that should never have gone live. Versions 2.6.2 and 2.6.3 of PyTorch Lightning, a high-level wrapper used by machine learning engineers around the world to train scalable models, carried hidden malware that kicked off the moment a developer ran import lightning. No extra steps. No warnings. Just a background thread quietly draining credentials.

    By the time PyPI quarantined the package, the malicious releases had been available for hours. With over 302,000 downloads recorded in a single day and more than 16 million across the past month, the exposure window was not trivial. Any developer who updated Lightning that morning and then ran a training script could have handed over their GitHub tokens, AWS access keys, and more without realizing it.

    This wasn’t an opportunistic smash-and-grab. The attack was carefully engineered, obfuscated behind multiple layers, and tied to a broader supply chain campaign that had already hit SAP-related npm packages the day before. The AI and machine learning community, which has built considerable institutional trust in the PyTorch ecosystem, now has a reason to reconsider how it handles package hygiene.


    What Happened on April 30

    The malicious packages were pushed to PyPI under the lightning project namespace, almost certainly using a compromised PyPI token belonging to the Lightning-AI maintainer account. That’s the most probable entry point, though the full forensic picture hasn’t been publicly confirmed by Lightning-AI at time of writing.

    What followed was a rapid sequence of moves that suggested the attacker had a plan well beyond the initial payload. Within hours, a GitHub account identified as pl-ghost pushed and then quickly deleted six short-lived branches across Lightning-AI repositories, including litAI, utilities, and torchmetrics. The branch names were either random 10-character strings or fake Dependabot labels, both designed to blend into the background noise of an active open source project. Fortunately, branch protections and automated workflows on the Lightning-AI repos blocked any of those branches from merging.

    Safe version: PyTorch Lightning 2.6.1, released January 30, 2026, is the last confirmed clean release. If you’re running 2.6.2 or 2.6.3, treat your environment as compromised until you’ve completed a full credential rotation.

    Community members noticed quickly. A GitHub issue, numbered #21689 on the Lightning-AI repo, described the hidden execution chain in detail. It was closed without explanation. When Socket Research opened a follow-up issue, it was shut down within one minute by the pl-ghost account, which posted a “SILENCE DEVELOPER” meme before closing it. That behavior strongly suggests the project’s GitHub account had already been taken over at that point.

    “The issue was closed within one minute by the pl-ghost account, which then posted a ‘SILENCE DEVELOPER’ meme… strongly indicating that the project’s GitHub account appears to be compromised.”

    Socket Research Team, Socket.dev — Socket Research Blog, April 30, 2026
    The Lightning-AI maintainers eventually acknowledged the situation with a short statement confirming an active investigation, and a subsequent advisory described the affected versions as containing “functionality consistent with a credential harvesting mechanism.” That’s a careful way of saying the packages were designed to steal developer secrets.

    Inside the Malware: A Multi-Stage Credential Harvester

    The technical sophistication here is worth understanding, because this wasn’t a simple script that grabbed a few environment variables. Socket Research’s full payload teardown reveals a multi-stage attack chain that starts on import and fans out aggressively.

    Stage One: The Launcher

    The malware hides inside a directory called _runtime/ within the package. A file named start.py triggers silently when the library is imported. Its first job is downloading the Bun JavaScript runtime directly from GitHub. This is an unusual dependency for a Python machine learning library, which is exactly why it works as a hiding mechanism.

    Stage Two: The 11 MB Payload

    Once Bun is installed, the launcher executes router_runtime.js, an 11-megabyte obfuscated JavaScript file running in a daemon thread. The obfuscation uses string-array rotation combined with AES decryption, consistent with the javascript-obfuscator toolchain. The size and complexity of this file signal that substantial development time went into making it hard to analyze.

    🔑
    703 process.env References

    The payload systematically scans environment variables for any tokens, secrets, or credentials present in the developer’s shell.

    🔐
    463+ Auth Token References

    Targeted scanning for authentication tokens, API keys, and bearer credentials across multiple platforms and services.

    📦
    336 Repository References

    Once credentials are harvested, the payload attempts to poison up to 50 branches per stolen token across reachable repositories.

    🪛
    npm Worm Component

    Local npm .tgz files get infected via postinstall hooks, enabling the malware to spread laterally through package dependencies.

    Stage Three: Credential Validation and Exfiltration

    The payload doesn’t blindly dump everything it finds. It validates harvested credentials against live APIs before exfiltrating them, confirming that GitHub tokens, npm tokens, and cloud provider keys (AWS, Azure, GCP) are actually active before sending them out. This validation step is a meaningful refinement over simpler stealers; it signals a mature operation focused on quality over volume of data.

    Stage Four: Repository Poisoning

    With a valid GitHub token, the malware attempts to inject .claude/router_runtime.js and malicious workflow files into up to 50 branches per token. Commits are impersonated using the email claude@users.noreply.github.com, a deliberate choice to blend in with automated commits from legitimate Claude AI tooling. The npm worm component handles local spread, bumping package versions and inserting postinstall hooks into any .tgz files it can reach.

    Important dependency: The entire attack chain requires the Bun runtime to be downloadable from GitHub. In environments with strict egress controls or GitHub access restrictions, the payload may not fully execute. That said, any affected version should still be treated as compromised regardless of network configuration.

    Detection in 18 Minutes, and the Response That Followed

    One of the few things that went right here was speed. Socket’s AI-powered scanner flagged both 2.6.2 and 2.6.3 as potentially malicious just 18 minutes after they were published to PyPI. That’s an impressively short detection window for a supply chain attack, where traditional signature-based tools often lag by hours or days.

    “Socket’s AI scanner flagged both versions 2.6.2 and 2.6.3 as potentially malicious eighteen minutes after publication.”

    Socket Research Team, Socket.dev — Socket Research Blog, April 30, 2026
    PyPI’s own response was also fairly rapid, moving to quarantine the lightning project once the situation was confirmed. Quarantine on PyPI means the affected versions can no longer be installed, though anyone who already pulled them down retains the packages in their local cache.

    The maintainer response was more complicated. The GitHub suppression behavior, whether it represents a fully compromised account or something more ambiguous, created a trust problem that a brief advisory statement can’t fully repair. When community members raising legitimate security concerns get silenced by memes within 60 seconds, it damages the project’s credibility in ways that outlast the technical incident itself.

    Understanding the Scale of the Risk

    PyTorch Lightning isn’t a niche tool. It’s infrastructure for how a meaningful slice of the global AI research and engineering community trains models at scale. The download numbers make that concrete.

    Metric Figure Why It Matters
    Daily Downloads (lightning) 302,431 Reflects how many installs could occur within a single attack window
    Weekly Downloads 3,429,724 Shows how quickly compromised versions propagate through CI/CD pipelines
    Monthly Downloads 16,201,959 Long-tail exposure risk for teams with infrequent dependency updates
    GitHub Stars (pytorch-lightning) 31,100+ Indicator of broad developer adoption and community reliance
    Companies using PyTorch 17,196+ Enterprise-scale attack surface across industries
    AI research papers using PyTorch ~85% Academic ML pipelines potentially feeding compromised credentials into research infrastructure
    The PyTorch ecosystem is effectively the default substrate for AI research. When something this deeply embedded gets compromised, the blast radius isn’t just individual developers. It extends to corporate training clusters, academic compute environments, and any CI/CD pipeline that automatically pulls the latest compatible version. That last category is particularly dangerous, since many ML projects pin a major version but not a specific patch, meaning an automated update could trigger the malware silently.

    It’s also worth noting, as Socket Research flags, that PyPI download statistics include CI mirrors and caching infrastructure. The “real” number of human-initiated installs is lower than 16 million, but that caveat doesn’t meaningfully reduce the risk surface for organizations running automated pipelines.

    Connecting the Dots: Mini Shai-Hulud and TeamPCP

    This attack didn’t emerge in isolation. The Hacker News assessed the Lightning incident as an extension of the Mini Shai-Hulud campaign, which struck SAP-related npm packages on April 29, just one day earlier. The shared patterns are hard to dismiss: similar obfuscation techniques, the same focus on credential harvesting to enable repository poisoning, and an operational tempo that suggests a coordinated actor moving across ecosystems quickly.

    “The campaign is assessed to be an extension of the Mini Shai-Hulud supply chain incident that targeted SAP-related npm packages on Wednesday.”

    Ravie Lakshmanan, Editor, The Hacker News — The Hacker News, April 30, 2026
    A group calling itself TeamPCP has claimed responsibility via a Tor-accessible site, posting a PGP-signed message that references both LAPSUS$ and a group called CipherForce. Those claims should be treated skeptically. Attribution in supply chain attacks is genuinely difficult, and extortion groups have strong incentives to name-drop well-known threat actors to inflate their perceived credibility. Socket Research itself notes that the Lightning payload lacks specific IOCs tied to Mini Shai-Hulud, suggesting it may be a distinct actor mimicking the same playbook rather than the same crew.

    What’s not disputed is the sophistication of the operational security. The use of fake Dependabot branch names, commits impersonating Claude AI tooling, and rapid deletion of evidence branches all point to an attacker who has studied how modern DevOps environments look and knows how to hide in plain sight within them.

    IOC note: The specific IOC “SHA1HULUD,” associated with the Mini Shai-Hulud npm campaign, was not found in the Lightning payload. Researchers at Aikido Security and OX Security have documented overlapping infrastructure patterns, but the exact actor relationship remains unconfirmed.

    What You Should Do Right Now

    If there’s any chance your environment pulled Lightning 2.6.2 or 2.6.3, the response isn’t optional. Here’s the practical order of operations.

    • Immediately uninstall both affected versions: pip uninstall lightning. Then reinstall the last clean release: pip install lightning==2.6.1.
    • Rotate every secret in your environment. GitHub personal access tokens, fine-grained tokens, npm tokens, and cloud provider credentials (AWS, Azure, GCP) should all be treated as compromised. Don’t audit first and rotate later; rotate now and audit afterward.
    • Review your GitHub repository’s branch history for any unexpected branches created around April 30, particularly any with random alphanumeric names or fake Dependabot labels.
    • Audit your GitHub Actions workflow files for any unauthorized modifications. The malware attempts to insert malicious workflows; check .github/workflows/ carefully across all branches.
    • Check your local npm cache and any .tgz packages in your project directories. The worm component targets these specifically via postinstall hooks.
    • If your CI/CD pipeline automatically installs the latest compatible lightning version, add a version pin to 2.6.1 immediately and lock it until Lightning-AI publishes a verified clean release with an explicit security advisory.
    • Scan your environment with Socket’s security tooling or equivalent software composition analysis (SCA) tools. Look for any .claude/router_runtime.js files that shouldn’t be there.
    For teams: If anyone on your team ran a training job or imported Lightning on April 30 before the quarantine, assume shared secrets are at risk. Service accounts with broad repository access should be rotated first. Check your GitHub security log for any unusual OAuth activity or API calls originating from unfamiliar IP addresses.

    Frequently Asked Questions

    Are PyTorch Lightning versions 2.6.2 and 2.6.3 safe to use?
    No. Both versions contain credential-stealing malware that executes automatically when you import the library. PyPI has quarantined these releases, so they can no longer be installed fresh. If you already have either version, uninstall immediately and downgrade to 2.6.1, the last verified clean release.

    What credentials were targeted in the PyTorch Lightning supply chain attack?
    The payload targeted GitHub tokens, npm tokens, and cloud provider credentials including AWS, Azure, and GCP access keys. It also scanned environment variables broadly, referencing over 700 process.env lookups. Credentials were validated against live APIs before exfiltration, so only active secrets were sent out.

    How do I remove the compromised PyTorch Lightning package?
    Run pip uninstall lightning, then pip install lightning==2.6.1 to restore the last clean version. After uninstalling, rotate all secrets in your environment, audit your GitHub repository for unexpected branches or workflow changes, and scan local npm files for signs of the worm component.

    Does this affect pytorch-lightning as well as the lightning package?
    The confirmed malicious versions were published under the lightning PyPI namespace. The pytorch-lightning package name was previously used but the project migrated to lightning. If your requirements file references lightning at version 2.6.2 or 2.6.3, you’re affected. Check both package names in your environment to be safe.

    What is the Mini Shai-Hulud campaign?
    Mini Shai-Hulud is the name researchers applied to a supply chain attack that compromised SAP-related npm packages on April 29, 2026. The Lightning PyPI incident shares similar obfuscation techniques and credential-harvesting patterns, leading researchers to assess them as potentially related. A group called TeamPCP has claimed responsibility for both, though attribution remains unconfirmed.

    How quickly was the PyTorch Lightning malware detected?
    Socket’s AI-powered scanner flagged versions 2.6.2 and 2.6.3 as potentially malicious within 18 minutes of publication. This rapid detection is faster than traditional signature-based approaches, though the packages were still available for several hours before PyPI completed quarantine.

    Was the Lightning-AI GitHub account compromised?
    Evidence strongly suggests it was. The pl-ghost account closed a legitimate community security report within one minute while posting a dismissive meme, then pushed and deleted six suspicious branches across multiple Lightning-AI repositories. Socket Research concluded this behavior is consistent with a compromised maintainer account, not normal project management.

    What should ML engineering teams do to prevent similar attacks?
    Pin exact package versions in production environments rather than floating on minor versions. Integrate software composition analysis tools like Socket into your CI/CD pipeline to catch malicious packages before they deploy. Regularly audit your dependency tree, enable two-factor authentication on all package registry accounts, and implement least-privilege policies for tokens used in automated pipelines.

    What This Means Going Forward

    The PyTorch Lightning compromise is a useful case study in how supply chain attacks actually work in practice: not through spectacular zero-days, but through a compromised token, a sophisticated payload, and a brief window before the community noticed. The 18-minute detection by Socket is genuinely impressive. The hours-long exposure window before full quarantine is not.

    For ML engineers specifically, this incident highlights a risk profile that the security community has been raising for years. Training infrastructure typically runs with broad cloud permissions and direct access to sensitive model weights, datasets, and API keys. A credential harvester that lands inside a framework as foundational as PyTorch Lightning doesn’t just steal tokens; it can open doors into production model serving environments, data pipelines, and cloud billing accounts. The attack surface for a compromised ML developer is meaningfully wider than for a compromised web developer.

    OSS trust is a fragile thing. The speed of the technical response, from Socket’s detection to PyPI’s quarantine, shows the system can work. But the GitHub suppression behavior, whatever its precise explanation, is the kind of thing that makes developers question whether the open source projects they depend on are actually being watched by anyone paying attention. That’s a confidence problem the Lightning-AI team will need to address directly, not just through code patches, but through transparency about how the account was compromised and what access controls have changed since.

    The broader lesson isn’t novel, but it’s clearly not yet internalized everywhere: every package in your dependency tree is a potential attack surface. The more foundational the package, the more attractive the target. In an ecosystem where 85% of AI research runs on PyTorch, “foundational” doesn’t get more foundational than this.

    Watch For
    01 Lightning-AI’s official post-incident report — particularly whether they confirm full compromise of the PyPI token and GitHub account, and what token-rotation and account-audit steps have been implemented.
    02 TeamPCP’s next move. If the attribution holds, a group claiming LAPSUS$ ties that successfully hit both npm and PyPI in 48 hours is likely to attempt more OSS ecosystem targets. Watch for unusual activity in popular ML framework namespaces on PyPI and conda-forge.
    03 PyPI’s policy response. The incident is a test case for whether package registries will accelerate adoption of mandatory publisher attestations, two-factor requirements for high-download packages, and faster automated quarantine tooling.
    04 Secondary infections from the npm worm component. Any developer who ran affected Lightning versions alongside active npm projects may have locally infected .tgz files that could propagate the payload if shared or published, even after removing the original package.
    Stay ahead of AI security threats. More on supply chain attacks, model security, and the tools protecting the ML ecosystem at NeuralWired.
    Explore Cybersecurity
  • Copy Fail Linux Vulnerability Explained: Root Access in 2026

    Copy Fail Linux Vulnerability Explained: Root Access in 2026

    Copy Fail (CVE-2026-31431): The 9-Year Linux Kernel Flaw That Gives Any User Root Access | NeuralWired

    Copy Fail: The 9-Year Linux Kernel Flaw That Hands Any Local User Root Access

    CVE-2026-31431 lets any unprivileged user on virtually every major Linux distribution gain full root access using 732 bytes of Python. An AI found it in roughly one hour. Nobody spotted it for nine years.

    Three separate kernel changes, written years apart by engineers who had no reason to connect them, quietly assembled a trap inside the Linux cryptographic subsystem. The last piece clicked into place in August 2017. Nobody noticed. Servers got deployed. Containers launched. Cloud providers scaled. And somewhere in the intersection of an IPsec helper module, a zero-copy file transfer mechanism, and a performance shortcut, a fully working privilege escalation waited.

    On April 29, 2026, offensive security firm Xint.io published the full technical details of CVE-2026-31431, now publicly named Copy Fail. The flaw carries a CVSS 7.8 severity score, which sounds manageable until you read what it actually does: it gives any local user, no matter how restricted, a reliable path to full root on nearly every Linux system shipped since 2017. No race condition. No per-distro adjustments. No compiled payload. Just Python, and patience.

    The discovery itself is almost as striking as the vulnerability. Theori’s Xint Code Research Team, using an AI-assisted analysis pipeline, surfaced Copy Fail as its highest-severity finding roughly an hour after pointing the system at the Linux kernel’s crypto/ subsystem. The same scan, the team noted, found additional high-severity bugs still working through coordinated disclosure.


    A Bug Built in Three Acts

    Copy Fail isn’t a single coding mistake. It’s the result of three individually reasonable kernel changes, each made years apart, that only become dangerous in combination.

    Act One: 2011 – The authencesn Module

    The authencesn module arrived in 2011 to handle IPsec ESP Extended Sequence Numbers, defined in RFC 4303. From the start, it used the caller’s destination scatterlist as scratch space to rearrange ESN bytes during decryption. This was entirely harmless: only the kernel’s internal xfrm layer ever called it, and the kernel controlled both ends of the operation.

    Act Two: 2015 – The AF_ALG AEAD Socket

    In 2015, the AF_ALG interface gained AEAD support, including a splice() path that could deliver pages directly from the page cache into the cryptographic subsystem. authencesn was converted to the new AEAD interface. Still not exploitable: AF_ALG used out-of-place operations, keeping input and output buffers separate.

    Act Three: August 2017 – The In-Place Optimization

    A performance optimization in algif_aead.c changed how decryption handled memory. For efficiency, the new code copied AAD and ciphertext into an output buffer, but chained the authentication tag pages by reference using sg_chain() and then set req->src = req->dst, creating an in-place operation. Page cache pages delivered via splice() were now sitting inside the writable destination scatterlist. The trap was set.

    The core insight: Nobody connected the 2017 in-place optimization to authencesn‘s scratch writes or to splice()‘s page cache delivery mechanism. Each change was reasonable in isolation. The vulnerability lives entirely at their intersection, across a six-year window and three separate subsystems.

    How the Exploit Actually Works

    The attack chain is deceptively clean. An unprivileged user opens an AF_ALG socket bound to authencesn(hmac(sha256),cbc(aes)) and uses the standard splice() system call to transfer pages from a readable target file into the socket. No special permissions. No kernel modules. Nothing that triggers standard audit rules.

    Inside the kernel, the 2017 in-place optimization causes those file pages to end up in the writable destination scatterlist. When authencesn‘s decrypt routine runs, it writes four bytes at an offset past the AEAD tag, directly into what it believes is its own output buffer. Those bytes land in the kernel’s cached copy of the target file.

    “An unprivileged local user can write four controlled bytes into the page cache of any readable file on a Linux system, and use that to gain root.”

    Xint Code Research Team, Theori — xint.io
    The write fails HMAC verification and recvmsg() returns an error. The caller sees a failed decryption. But the four-byte write into the page cache persists. Repeat the process across targeted offsets of a setuid binary, and the kernel’s cached version of that binary contains attacker-controlled code. Call execve() on it, and the kernel loads from the page cache rather than disk.

    Stealth note: The corrupted page is never marked dirty for writeback, so the file on disk remains unchanged. Disk-based integrity checks and standard checksums won’t catch the modification. The in-memory version, which is what actually executes, is corrupted system-wide.

    The result is a four-property combination that the Xint team describes as nearly unique in their experience:

    📦
    Portable

    Confirmed working on Ubuntu 24.04, Amazon Linux 2023, RHEL 10.1, and SUSE 16 with no per-distro modifications.

    🔬
    Tiny

    The full working proof-of-concept is 732 bytes of standard-library Python. No compiled payload, no external dependencies.

    👻
    Stealthy

    Disk-based integrity checks see nothing. The modification exists only in the page cache, invisible to on-disk forensic tools.

    🐳
    Cross-Container

    Container isolation doesn’t stop it. Part two of Theori’s research series covers a full Kubernetes container escape using the same primitive.

    “This vulnerability is unique because it has four properties that almost never appear together: it’s portable, tiny, stealthy, and cross-container. It allows any user account, no matter how low-level, to increase their privilege to full admin access.”

    Xint.io Spokesperson, Theori — xint.io

    The Scale of Exposure

    Linux isn’t just popular on servers. It is, for practical purposes, the substrate on which the cloud runs. The numbers make the exposure concrete.

    Platform Linux Share Implication
    Google Cloud VMs 91.6% Highest Linux density of any major cloud provider
    AWS EC2 Instances 83.5% Amazon Linux 2023 directly confirmed vulnerable
    Microsoft Azure VMs 61.8% Majority of Azure workloads run affected kernels
    Public Cloud Overall ~90% CNCF estimate across combined AWS/Azure/GCP infrastructure
    Production Kubernetes 96.4% Container escape risk affects nearly all K8s deployments
    The affected kernel range compounds the problem. Theori confirmed the exploit works across kernel versions 6.12, 6.17, and 6.18. The vulnerable commit dates to August 2017, meaning any system running a kernel from that point forward and exposing AF_ALG sockets to unprivileged users is potentially affected. That’s essentially every major distribution shipped in the past nine years.

    Shared hosting environments face the most acute risk. A single compromised tenant account can traverse to root, from which the entire host is accessible. Multi-tenant SaaS platforms, university computing clusters, and developer PaaS environments all sit in this category.

    “732 bytes of Python. Root on every major Linux distribution shipped since 2017. No race conditions. No per-distro offsets. No version checks. 100% success rate.”

    Brian Pak, Xint Code Research Team, Theori — xint.io

    AI Found It in One Hour

    The vulnerability’s discovery story is, in many ways, just as significant as the vulnerability itself. Taeyang Lee, a researcher at Theori, formed an initial hypothesis: the combination of AF_ALG sockets and splice() creates a path where unprivileged userspace can feed page cache pages directly into the crypto subsystem, and that scatterlist page provenance might be an underexplored source of vulnerabilities.

    Rather than manually auditing the kernel’s crypto subsystem, the Xint Code Research Team fed that one-line hypothesis into an AI-assisted scanning pipeline pointed at crypto/. About an hour later, Copy Fail came back as the highest-severity finding. The same scan surfaced additional high-severity bugs that are still working through coordinated disclosure.

    “About an hour later, Copy Fail came back as the highest-severity finding. The same scan surfaced additional high-severity bugs, still in coordinated disclosure.”

    Xint Code Research Team, Theori — xint.io
    The implications for the security research field are hard to overstate. Traditional manual kernel audits are expensive, slow, and require deep specialist knowledge. This approach condensed what might have been weeks of expert review into a single hour of autonomous scanning. The economics of vulnerability discovery are shifting, and not symmetrically: defenders don’t automatically get faster just because attackers do.

    David Brumley, Chief AI and Science Officer at Bugcrowd, drew a direct line between Copy Fail and earlier high-profile kernel primitives in a post on Bugcrowd’s research blog:

    “Copy Fail is the same class of primitive, in a different subsystem. The 2017 in-place optimization in algif_aead allows a page-cache page to end up in the kernel’s writable destination scatterlist for an AEAD operation submitted over an AF_ALG socket. An unprivileged process can then drive splice() into that socket and complete a small, targeted write into the page cache of a file it doesn’t own.”

    David Brumley, Chief AI and Science Officer, Bugcrowd — bugcrowd.com
    Logic bugs like Copy Fail are particularly hard for humans to spot. Memory corruption flaws produce signals: crashes, sanitizer output, fuzzer hits. A logic bug that writes to the right memory location, through the right interfaces, in a sequence that spans three subsystems and six years of kernel history, produces nothing. It just works.

    Patching: Fast Upstream, Slow Everywhere Else

    The upstream kernel response was fast. Theori reported the flaw to the Linux kernel security team on March 23, 2026. An initial acknowledgment came the next day. Patches were proposed and reviewed by March 25. The fix landed in the mainline kernel on April 1, 2026, via commit a664bf3d603d, which reverts the 2017 in-place optimization. Upstream patch time: under 10 days from report to commit.

    The problem is what happens after that. Enterprise deployments average 60 to 90 days to roll out Linux patches after vendor releases, according to Qualys TruRisk data. Roughly 15 to 25 percent of systems running older LTS kernel branches wait more than 100 days. The gap between “patch exists” and “patch deployed” is where attacks happen.

    Stage Typical Timeline Status for CVE-2026-31431
    Upstream kernel patch 24-48 hours (critical) Committed April 1, 2026
    Distro security advisory Days to weeks Debian and SUSE advisories published
    Enterprise deployment 60-90 days average Majority of systems still unpatched
    LTS branch backport Varies widely 15-25% may wait 100+ days
    For immediate mitigation before patching is possible, administrators can restrict AF_ALG socket access using seccomp profiles or AppArmor/SELinux policies. The Debian security tracker and SUSE CVE advisory both carry current package status for their respective distributions.

    Action required: Check your kernel version against your distribution’s patched release. On systems where live patching isn’t available, restrict AF_ALG socket creation for unprivileged users as an interim control. Container workloads should be treated as high priority given the forthcoming Kubernetes container escape research.

    Disclosure Timeline

    Copy Fail followed a thorough coordinated disclosure process, giving vendors and distributors time to prepare patches before full public release.

    Date Event
    August 2017 Vulnerability introduced via in-place optimization commit in algif_aead.c
    March 23, 2026 Theori reports flaw to Linux kernel security team
    March 24, 2026 Kernel security team acknowledgment received
    March 25, 2026 Patches proposed and reviewed
    April 1, 2026 Fix committed to mainline kernel (commit a664bf3d603d)
    April 22, 2026 CVE-2026-31431 officially assigned
    April 28, 2026 Bugcrowd blog post published by David Brumley
    April 29, 2026 Full public disclosure via xint.io; The Hacker News coverage published
    April 30, 2026 Heise.de German-language coverage; broader security community response
    Theori has also confirmed that this is part one of a two-part research series. Part two will detail a Kubernetes container escape built on the same underlying primitive. Container security teams should treat this as an active, evolving situation rather than a closed incident.

    Frequently Asked Questions

    What is CVE-2026-31431 (Copy Fail)?
    CVE-2026-31431, called Copy Fail, is a local privilege escalation flaw in the Linux kernel’s algif_aead cryptographic interface. It allows any unprivileged local user to write four controlled bytes into the kernel page cache, enabling root access on any major Linux distribution shipped since August 2017.

    Which Linux distributions are affected by Copy Fail?
    Confirmed affected distributions include Ubuntu 24.04, Amazon Linux 2023, RHEL 10.1, and SUSE 16. Any Linux distribution running a kernel from August 2017 onward with the authencesn and algif_aead modules is likely affected. Debian and SUSE have published security advisories with current patch status.

    How do I know if my system is patched?
    Check your running kernel version against your distribution’s patched release. The upstream fix landed on April 1, 2026, in mainline commit a664bf3d603d. Check the Debian security tracker or your distro’s equivalent CVE advisory page for the specific patched package version.

    Does Copy Fail affect cloud virtual machines?
    Yes. Cloud VMs running unpatched Linux kernels are vulnerable to any user who can execute code on the instance. This includes multi-tenant environments. Cloud providers run Linux on over 60% to 91% of VMs depending on the platform, making this a high-priority patch for cloud workloads.

    Does Copy Fail work inside containers?
    Yes. Container isolation does not prevent exploitation because the flaw exists in the host kernel’s page cache, which is shared across containers. Theori has confirmed a full Kubernetes container escape using the same primitive; full details are expected in a forthcoming Part 2 research post.

    Why did this go undetected for nine years?
    The vulnerability exists only at the intersection of three kernel changes made in 2011, 2015, and 2017 across separate subsystems. Logic bugs don’t produce crashes or fuzzer signals. Each individual change was reasonable in isolation, making the combined effect essentially invisible to standard review and testing processes.

    What’s the interim mitigation if I can’t patch immediately?
    Restrict AF_ALG socket creation for unprivileged users via seccomp filter policies, AppArmor profiles, or SELinux policy rules. This blocks the attack path without requiring a kernel update. Verify your container runtime and Kubernetes policies also restrict this system call for workloads running as non-root users.

    How significant is the AI-assisted discovery angle?
    Theori’s AI pipeline found Copy Fail in roughly one hour from a one-line research hypothesis. The same scan identified additional high-severity bugs still in coordinated disclosure. This suggests AI tools can compress vulnerability discovery timelines from weeks to hours, changing the economics of both offensive and defensive security research significantly.

    What Comes Next

    Copy Fail is a clean illustration of how complexity creates risk in long-lived software. The Linux kernel is audited more thoroughly than virtually any codebase on earth, yet a logic bug spanning three subsystems and six years of history slipped through every review. The flaw wasn’t in any single commit. It was in the space between them.

    The AI discovery angle changes the calculus going forward. If a one-line hypothesis fed into an autonomous scanner can surface a CVSS 7.8 kernel flaw in an hour, the assumption that lightly funded attackers lack the research capacity to find such bugs needs revisiting. The same tools available to Theori’s researchers are available to anyone willing to build or buy similar infrastructure. Coordinated disclosure and rapid upstream patching matter more than ever, because the window between bug introduction and discovery is likely to shrink.

    For enterprise security teams, the immediate priority is simple: patch, or restrict AF_ALG access today. The 60-to-90-day average remediation window is a liability Copy Fail was designed to exploit. And with Part 2 of Theori’s research series, covering the Kubernetes container escape, still to come, the organizations most at risk may not have fully mapped their exposure yet.

    Watch For
    01 Theori’s Part 2 Kubernetes container escape research, expected soon after the April 29 initial disclosure, which will detail how Copy Fail’s page cache primitive translates into a full container breakout on production clusters.
    02 Additional high-severity kernel bugs found by the same Xint Code AI scan, currently in coordinated disclosure. Expect further CVE assignments and patching cycles in the weeks following Copy Fail’s public release.
    03 Enterprise patch deployment rates for CVE-2026-31431 across major cloud providers. Given the 60-to-90-day average lag and the simplicity of the exploit, any confirmed in-the-wild exploitation reports in May or June 2026 would mark a significant escalation.
    04 Broader adoption of AI-assisted vulnerability scanning by both security teams and threat actors. Copy Fail’s one-hour discovery time is a benchmark that will likely pressure security organizations to rethink how they audit critical infrastructure code.
    Stay ahead of the curve. More on Linux security, AI-assisted research, and enterprise threat intelligence at NeuralWired.
    Explore Security
  • SAP npm Supply Chain Attack 2026: Credentials Stolen

    SAP npm Supply Chain Attack 2026: Credentials Stolen

    SAP npm Packages Poisoned: Credential Theft Hits CAP Devs | NeuralWired

    SAP npm Packages Poisoned: Credential Theft Hits CAP Devs

    Four widely used SAP npm packages were quietly backdoored on April 29, 2026, exposing millions of developers to a credential-stealing attack that swept up GitHub tokens, cloud secrets, browser passwords, and AI tool configurations before anyone had a chance to respond.

    It took less than four hours. Between 09:55 and 14:00 UTC on April 29, 2026, a threat actor known as TeamPCP published malicious versions of four SAP npm packages that together pull over 2.25 million downloads every month. Any developer who ran npm install during that window didn’t just install a package. They handed over their credentials.

    The campaign, which the attacker named “Mini Shai-Hulud” after the sandworms of Frank Herbert’s Dune universe, was uncovered by researchers at Aikido Security, Wiz Research, Socket, SafeDep, and StepSecurity. It targets the SAP Cloud Application Programming (CAP) ecosystem, meaning the victims are predominantly enterprise developers building business-critical cloud applications at some of the world’s largest companies.

    The attack didn’t just steal credentials. It was engineered to spread them.


    What Happened: A Four-Hour Window

    Four packages received malicious updates within a single morning. All were central to SAP’s CAP framework for Node.js. All are now either deprecated or patched with clean replacement versions.

    PackageMalicious VersionSafe VersionMonthly Downloads
    @cap-js/sqlitev2.2.2v2.4.0, v2.3.02.25M+ (combined)
    @cap-js/postgresv2.2.2v2.3.0Included above
    @cap-js/db-servicev2.10.1v2.10.1 (re-published clean)Included above
    mbt (MTA Build Tool)v1.2.48v1.2.49Included above
    Researchers at Chainguard confirmed the combined download volume, underscoring the scale of potential exposure. The malicious versions were deprecated within roughly four hours, but in CI/CD pipelines and containerized build environments where package versions aren’t always pinned, even a narrow window causes serious damage.

    Action required now: If your team ran npm install on any of these packages between 09:55 and 14:00 UTC on April 29, 2026, treat all tokens and secrets accessible from that machine as compromised. Rotate immediately and investigate second.

    How the Attack Actually Worked

    The technique is clean and devastating. Each malicious package version added a single line to its package.json: a preinstall hook pointing to a new file called setup.mjs. That hook fires automatically the moment anyone runs npm install. No user interaction. No confirmation prompt. No warning of any kind.

    “The compromised releases added a preinstall script that acts as a runtime bootstrapper, downloading a platform-specific Bun ZIP from GitHub Releases, extracting it, and immediately executing the extracted Bun binary. The implementation also follows HTTP redirects without validating the destination and uses PowerShell with -ExecutionPolicy Bypass on Windows, increasing the risk for affected developer and CI/CD environments.”

    Socket Security Research Team — The Hacker News
    Choosing the Bun JavaScript runtime was deliberate. Most developer security tooling and CI/CD monitors are tuned to watch Node.js process behavior. Bun sidesteps that coverage entirely. The attacker downloaded Bun v1.3.13 directly from GitHub Releases at install time, then used it to execute the real payload: a file named execution.js.

    That file is 11.6 to 11.7 megabytes of heavily obfuscated JavaScript. It’s a full credential-stealing and propagation framework, and its size alone tells you this wasn’t a script thrown together over a weekend.

    The Multi-Stage Kill Chain

    First, setup.mjs (4,549 bytes, shared identically across all four packages) downloads and extracts the Bun binary. Then Bun runs execution.js, which sweeps the developer’s environment systematically. Data gets encrypted using AES-256-GCM with the key wrapped in RSA-4096 using an embedded attacker public key. Only TeamPCP can decrypt what was stolen. The encrypted packages are pushed to attacker-controlled public GitHub repositories with Dune-themed names like prescient-lasgun-242 and descriptions reading “A Mini Shai-Hulud has Appeared.”

    Verified SHA256 hashes for detection and incident response:

    @cap-js/postgres v2.2.2:
    1d9e4ece8e13c8eaf94cb858470d1bd8f81bb58f62583552303774fa1579edee

    @cap-js/db-service v2.10.1:
    258257560fe2f1c2cc3924eae40718c829085b52ae3436b4e46d2565f6996271

    @cap-js/sqlite v2.2.2:
    a1da198bb4e883d077a0e13351bf2c3acdea10497152292e873d79d4f7420211

    mbt v1.2.48:
    86282ebcd3bebf50f087f2c6b00c62caa667cdcb53558033d85acd39e3d88b41

    setup.mjs (shared across all 4 packages):
    4066781fa830224c8bbcc3aa005a396657f9c8f9016f9a64ad44a9d7f5f45e34

    By the end of April 29, researchers had counted over 1,100 exfiltration repositories on GitHub. That number was still climbing when initial reports went out.

    What Was Stolen: A Comprehensive Sweep

    The payload didn’t target one type of credential. It swept everything a developer might have accessible from their machine or build environment. The scope is striking even by supply chain attack standards.

    🔑
    Git & npm Tokens

    GitHub PATs and OAuth tokens via gh auth token, plus npm tokens extracted from .npmrc files and environment variables.

    ☁️
    Cloud Provider Secrets

    AWS (STS, Secrets Manager, SSM), Azure Key Vault, and GCP Secret Manager credentials all swept in a single pass.

    ⚙️
    CI/CD Pipeline Secrets

    GitHub Actions secrets extracted directly from Runner.Worker process memory. Kubernetes service account tokens also targeted.

    🌐
    Browser Credentials

    Saved passwords from Chrome, Safari, Edge, Brave, and Chromium. A brand-new capability not seen in prior TeamPCP operations.

    🤖
    AI Tool Configurations

    Claude config files and MCP (Model Context Protocol) configurations, enabling persistence inside AI-assisted development workflows.

    “The payload is an 11.7 MB credential stealer and propagation framework. It harvests local developer credentials, GitHub and npm tokens, GitHub Actions secrets, and cloud secrets from AWS, Azure, GCP, and Kubernetes. It then exfiltrates encrypted results through public GitHub repositories.”

    Raphael Silva, Security Researcher, Aikido Security — Aikido Security Blog
    One feature drew particular attention from StepSecurity researchers: the malware injects a .claude/settings.json with a SessionStart hook, and a .vscode/tasks.json configured with runOn: folderOpen. Every time a developer opens the infected repository in VS Code or Claude Code afterward, the payload re-executes. StepSecurity called it one of the first attacks to specifically target AI coding agent configurations as a persistence and propagation vector.

    The malware also ships with a Russian locale guardrail. If the system language or date format begins with “ru,” the stealer exits without exfiltrating anything. This type of region exclusion is a consistent marker of threat actors operating within Russian-speaking jurisdictions, and also functions as a practical legal buffer.

    How the Attackers Got Publishing Access

    The access method differed between the @cap-js packages and mbt, but both paths point to fundamental gaps in how modern open-source projects handle CI/CD trust.

    The @cap-js Packages: An OIDC Scope Problem

    Researchers at SafeDep traced the root cause to a configuration gap in how the cap-js/cds-dbs repository had set up npm’s OIDC trusted publishing. The team had migrated to OIDC in November 2025, allowing GitHub Actions to request short-lived npm tokens without storing long-lived secrets in the repository. The gap was in the scope of what the configuration trusted.

    “npm’s OIDC trusted publisher configuration for @cap-js/sqlite trusted any workflow in cap-js/cds-dbs, not just the canonical release-please.yml on main. A branch push could exchange an OIDC token on behalf of the package if the workflow had id-token: write permission and the environment: npm reference.”

    Leon Avalos, SafeDep — cited in The Hacker News
    The attacker compromised a GitHub account called RoshniNaveenaS that held write access to the repository. They pushed a modified workflow to a non-main branch via a draft PR titled “feat: ci speedup” from a fork named gruposbftechrecruiter/harkonnen-navigator-149. The PR closed within minutes and the branch was force-pushed, wiping the diff. But the OIDC token exchange had already completed. The resulting CircleCI build logs exposed the npm publish token, GitHub token, OIDC tokens, Docker Hub credentials, and Cloud Foundry credentials before anyone could intervene.

    The mbt Package: Token Compromise

    For mbt, the path was simpler and murkier. Researchers suspect the cloudmtabot static npm token was compromised through a channel that hasn’t been fully identified yet. The investigation is ongoing. What’s confirmed is that the attacker held valid publish credentials for all four packages and targeted specific version numbers with precision.

    Part of a Larger and Accelerating Pattern

    Mini Shai-Hulud is TeamPCP’s fourth confirmed operation in roughly five weeks. The pace is notable, and each campaign has added new capabilities.

    CampaignDateTargetExposure Window
    Checkmarx supply chain attackMarch 23, 2026Checkmarx developer toolingNot disclosed
    Trivy scanner attackApril 27, 2026Trivy security scanner npm packageNot disclosed
    Bitwarden CLI attackApril 22, 2026Bitwarden CLI npm package93 minutes
    Mini Shai-HuludApril 29, 20264 SAP @cap-js and mbt packages~4 hours
    Attribution across all four campaigns was confirmed by Wiz Research through a shared RSA public key alongside overlapping encoding routines and region guardrails. The actor is also tracked under the aliases DeadCatx3, PCPcat, and ShellForce, per SecurityWeek’s tracking of the group.

    “A new supply chain operation from TeamPCP calling itself ‘Mini Shai Hulud’ compromised SAP-related npm packages by injecting malicious preinstall scripts that execute during dependency installation. TeamPCP is very likely responsible for this campaign, based on a shared RSA public key and overlaps in encoding routines and region guardrails.”

    Wiz Research Team, Wiz (Google-owned) — Wiz Research Blog
    The broader trend adds weight. According to PkgPulse’s trend analysis, npm supply chain attacks roughly tripled between 2022 and 2025. TeamPCP didn’t cause that trend, but they’re currently its sharpest expression. It’s also worth noting that SAP’s own April 2026 security patch cycle released 19 new security notes including a CVSS 9.9-rated SQL injection in SAP BPC and BW, per SAP Insider. Enterprise SAP environments were already under pressure from the vendor side before this npm campaign landed.

    What Affected Teams Should Do Right Now

    Remediation isn’t just about updating package versions. If the malicious version ran in your environment, you have a credential exposure problem, not a package problem. The Sophos CTU Research Team was direct: investigate whether compromised versions were installed, review all GitHub, npm, and cloud activity tied to potentially exposed credentials, and rotate anything that may have been accessible.

    • Check your package-lock.json and build logs for the malicious version numbers: @cap-js/sqlite v2.2.2, @cap-js/postgres v2.2.2, @cap-js/db-service v2.10.1, and mbt v1.2.48.
    • Compare installed tarballs against the SHA256 hashes listed in the infobox above. A match confirms the payload executed on that machine.
    • Rotate all GitHub tokens, npm tokens, and cloud provider credentials accessible from any affected build environment. Don’t wait to confirm; rotate first, investigate second.
    • Search your GitHub organization’s audit log for the commit message keyword OhNoWhatsGoingOnWithGitHub. This is the propagation dead-drop marker the malware uses for token exchange between infected systems.
    • Check for injected .claude/settings.json and .vscode/tasks.json files in repositories recently touched from affected machines. These are the persistence hooks.
    • Review browser credential stores on developer machines that ran the malicious install, specifically Chrome, Safari, Edge, Brave, and Chromium password managers.
    • Update all affected packages to their clean versions and enforce explicit version pinning across your dependency tree going forward.
    For teams working on CI/CD pipeline security hardening, this incident is a live case study in why preinstall script auditing needs to be part of every build pipeline by default. The npm ecosystem doesn’t sandbox lifecycle scripts, doesn’t prompt for confirmation, and grants full system access by default. That architecture hasn’t changed in years.

    Frequently Asked Questions

    What is the Mini Shai-Hulud npm supply chain attack?
    Mini Shai-Hulud is a supply chain attack that injected malicious preinstall scripts into four SAP npm packages on April 29, 2026. When developers installed the compromised versions, the scripts automatically downloaded and executed a credential-stealing payload that harvested GitHub tokens, cloud secrets, and browser passwords without any user interaction.

    Which SAP npm packages were compromised?
    The four affected packages were @cap-js/sqlite (v2.2.2), @cap-js/postgres (v2.2.2), @cap-js/db-service (v2.10.1), and mbt v1.2.48. All are part of the SAP Cloud Application Programming (CAP) framework used widely in enterprise Node.js development. Clean replacement versions are now published on npm.

    How long were the malicious packages available to download?
    The malicious versions were live for approximately four hours, between 09:55 and 14:00 UTC on April 29, 2026. Any npm install that pulled these specific version numbers during that window should be treated as a confirmed execution of the credential-stealing payload.

    Who is TeamPCP and what other attacks have they conducted?
    TeamPCP is the threat actor behind Mini Shai-Hulud, also operating under aliases DeadCatx3, PCPcat, and ShellForce. Researchers linked them to three prior supply chain operations in 2026: a March 23 attack on Checkmarx tooling, an April 22 attack on Bitwarden CLI (93-minute exposure), and an April 27 attack on the Trivy security scanner npm package.

    Why did the attacker use the Bun runtime instead of Node.js?
    Bun is a newer JavaScript runtime that most security monitoring tools and endpoint agents don’t watch as closely as Node.js. By downloading and invoking Bun at install time, the attacker bypassed process-level monitoring that would typically flag unusual Node.js behavior in developer and CI/CD environments.

    What is the OIDC misconfiguration that enabled the attack?
    The @cap-js packages used npm’s OIDC trusted publishing system, which should restrict token exchange to specific approved workflows on the main branch. The configuration instead trusted any workflow in the repository. An attacker with write access to any branch could trigger a legitimate OIDC token exchange and use it to publish malicious package versions.

    How does the malware maintain persistence after the initial infection?
    The payload injects a SessionStart hook into .claude/settings.json and a folderOpen trigger into .vscode/tasks.json. This means the malicious code re-executes every time the infected repository is opened in VS Code or Claude Code, continuing to harvest any new credentials added to the environment after the initial compromise.

    What should I check to confirm whether my environment was affected?
    Check your package-lock.json and build logs for the malicious version numbers listed above. Compare installed tarballs against the SHA256 hashes provided by Wiz Research. Also search your GitHub commit history for the string OhNoWhatsGoingOnWithGitHub, which is the propagation marker the malware embeds to signal infected environments to the attacker.

    The Bigger Picture: Trust Is the Attack Surface

    The Mini Shai-Hulud attack is a study in how trust chains collapse at scale. SAP developers trusted @cap-js/sqlite because it had millions of downloads and came from a recognized source. npm users trusted the preinstall hook because it’s a standard part of the package specification. CI/CD pipelines trusted the OIDC token exchange because it was explicitly configured to be trusted. At every step, a legitimate mechanism became an attack vector.

    The credential theft is serious enough on its own. But the propagation design is what should concern security teams most. Stolen GitHub tokens don’t just expose the original victim. They expose every repository that token can reach, every pipeline it can trigger, and every secret those pipelines can access. The attacker built a cascading compromise engine, not a one-shot stealer.

    For the broader npm ecosystem, supply chain security has moved from secondary concern to first-tier priority. Postinstall and preinstall scripts are the single most-exploited vector in npm compromises. That’s been documented since the 2018 event-stream incident. The npm runtime still doesn’t sandbox them, still doesn’t prompt for confirmation, and still grants full system access by default. What has changed is the sophistication of the actors who know exactly how to exploit it.

    TeamPCP has now run four confirmed operations in five weeks, and each campaign adds new capabilities. Browser credential theft wasn’t in their prior toolkit. Targeting AI coding tool configurations is genuinely novel territory. For organizations running SAP enterprise environments, the immediate priority is investigation and credential rotation. For everyone else, this is a concrete reminder that your software supply chain security is only as strong as the weakest OIDC configuration in your entire dependency graph.

    Watch For
    01 TeamPCP’s fifth campaign. The group has run four attacks in five weeks, with each iteration adding new capabilities. A follow-on operation targeting another high-download npm ecosystem is likely within days to weeks.
    02 npm’s response to OIDC scope enforcement. SafeDep’s disclosure revealed a structural gap in how npm’s trusted publishing validates workflow scope. Watch for a policy update restricting OIDC token exchange to specific branches and workflow files only.
    03 Secondary breaches from stolen tokens. With over 1,200 exfiltration repositories created and GitHub tokens from enterprise SAP environments harvested, downstream compromises of internal repositories and cloud accounts may surface over the coming weeks.
    04 AI coding tool attack surface expansion. Injecting persistence hooks into Claude Code and VS Code configurations is a first for this actor. Expect other threat groups to adopt this technique as AI-assisted development becomes more deeply embedded in enterprise software workflows.
    Stay ahead of the curve. More on cybersecurity, supply chain threats, and developer security at NeuralWired.
    Explore Cybersecurity
  • OpenAI Growth Slowdown 2026: $600B AI Risk

    OpenAI Growth Slowdown 2026: $600B AI Risk

    The OpenAI Growth Wall: How a 1B User Miss Is Reshaping a $750B AI Cycle | NeuralWired

    The OpenAI Growth Wall: How a 1B User Miss Is Reshaping a $750B AI Cycle

    A leaked internal memo from OpenAI CFO Sarah Friar has set off a chain reaction across the Magnificent Seven, exposing the fragile math behind a $600 billion infrastructure bet and forcing an immediate pivot to agentic commerce as the only viable exit ramp.

    For three years, the market operated on a single comfortable assumption: user growth for large language models would follow an uninterrupted exponential curve. That assumption died on April 28, 2026. An internal report surfaced by The Wall Street Journal revealed that OpenAI had failed to reach 1 billion weekly active users by its own internal deadline and had missed multiple monthly revenue targets. The Nasdaq Composite fell 0.9% within hours of the news breaking.

    The damage radiated outward with mechanical precision. Oracle dropped 7% to $161, its $300 billion compute contract with OpenAI suddenly reframed as a liability rather than an anchor. CoreWeave slid 7.4%, SoftBank fell nearly 10% in Tokyo trading, and Arm Holdings dropped 7.7% as investors unwound positions across the AI supply chain. What looked like a company-specific stumble was, in fact, a system-wide repricing of the premise that unlimited AI engagement justifies unlimited infrastructure spending.

    Tonight, Alphabet, Microsoft, Meta, and Amazon report earnings against a backdrop of nearly $600 billion in collective AI-related capital committed for 2026. The central question isn’t whether these companies are growing. It’s whether the underlying software can attract and monetize users at the rate their valuations demand. One missed guidance number, one downward revision, and the “OpenAI Slump” stops being a warning shot and becomes a full-scale sector rout. The earnings window opening tonight may be the most consequential 48 hours in the AI super-cycle to date.


    The Compute-Revenue Chasm That Wall Street Ignored

    The structural fault line at the center of this crisis has a name: the Compute-Revenue Chasm. To maintain its training lead, OpenAI entered into agreements for computing power that assume a revenue trajectory the company hasn’t hit. The five-year, $300 billion deal with Oracle is the clearest example. It was underwritten on the belief that ChatGPT’s user base would grow without friction toward the billion-user mark, generating subscription and API revenue sufficient to cover the monthly burn of GPU clusters at that scale.

    When the Sarah Friar memo signaled that those projections weren’t materializing, Oracle’s stock didn’t just react to OpenAI’s bad news. It reacted to the realization that its own data center financing model has a single point of failure. CoreWeave, which recently completed an $11.9 billion infrastructure deal with the startup, faces the same exposure. These companies have effectively “leveraged up” on a growth curve that has now flattened.

    “The market is discovering that compute contracts written against infinite growth assumptions become toxic assets the moment the growth assumption breaks. OpenAI didn’t just miss a user target; it invalidated the pricing model for an entire generation of AI infrastructure.”

    Dan Ives, Senior Equity Analyst, Wedbush Securities — Wedbush Research Note, April 28, 2026
    The Inference-Utilization Gap: A report from TechNewsWorld indicates that roughly 95% of enterprise GPU capacity currently sits idle. Companies bought hardware for AI projects that aren’t yet production-ready, creating a capital overhang that could suppress new GPU orders well into late 2026.

    The broader implication is what analysts are calling an “efficiency audit” across enterprise AI. The FOMO-driven GPU buying cycle of 2024 and 2025 has left corporations with hardware they can’t fully use, billed at rates that assumed full utilization. As those utilization reports come in, the pressure on Nvidia and AMD isn’t just competitive; it’s arithmetic.

    The SoftBank Contagion and the Arm Holdings Margin Call

    No entity is more directly exposed to the OpenAI growth wall than Masayoshi Son’s SoftBank Group. The Japanese conglomerate has committed $22.5 billion to OpenAI funding, according to Reuters, and to raise that capital it executed a series of aggressive asset sales including its entire $5.8 billion stake in Nvidia and $4.8 billion of T-Mobile holdings. The logic was sound in a world of infinite AI growth. In a world of finite user engagement, it looks like a concentrated bet on the wrong side of a turning point.

    The structural risk deepens because of Arm Holdings. SoftBank reportedly tapped undrawn margin loans secured against its Arm stake to fund a portion of the OpenAI obligations. When Arm fell 7.7% on the news, the collateral value of those loans compressed in real time. The result was a near-10% drop in SoftBank’s Tokyo-listed shares. The concern now circulating among institutional investors is clear: if OpenAI’s valuation is revised downward ahead of its targeted late-2026 IPO at a $1 trillion target, the margin call risk on SoftBank’s Arm-backed loans becomes a market event in its own right.

    Entity Share Move (Apr 28) Primary Exposure Risk Vector
    SoftBank Group -9.9% $22.5B OpenAI funding commitment Margin loans against Arm collateral
    Arm Holdings -7.7% Primary SoftBank loan collateral Collateral compression risk
    Oracle -7.0% $300B 5-year compute contract Anchor tenant default risk
    CoreWeave -7.4% $11.9B infrastructure deal Revenue dependency on OpenAI growth
    AMD -5.3% GPU demand from cloud providers Idle capacity reducing future orders
    Nvidia -3.8% GPU cluster dominance Agentic shift toward CPU inference

    The Magnificent Seven Crucible: Four Earnings Reports That Define the Cycle

    The selloff of April 28 was a preview. The main event runs tonight. Alphabet, Microsoft, Meta, and Amazon collectively committed roughly $600 billion in AI-related capital for 2026, and each faces a different version of the same pressure: prove that the spending is generating returns at the pace implied by their valuations, or face a re-rating that no amount of forward guidance can easily reverse.

    Alphabet: The TPU Counter-Narrative

    Alphabet enters earnings with a structural advantage its competitors can’t easily replicate. While rivals bid against each other for Nvidia’s H200 and B100 GPUs, Google has been scaling its custom Tensor Processing Unit clusters for years. Google Cloud analysts project a 50% revenue surge to $18.4 billion this quarter, driven in part by enterprise adoption of TPU-powered AI services. That number, if confirmed, would represent the single strongest argument against the “AI monetization is failing” thesis.

    The real wildcard is “AI Mode.” Google’s new search paradigm integrates directly with the Universal Commerce Protocol to convert conversational queries into transactions. Internal data suggests a 14% to 27% conversion lift versus standard search ads. If Alphabet can show that this lift is translating into revenue per query, it may successfully decouple its valuation from the OpenAI-adjacent selloff entirely.

    Microsoft: Azure Growth vs. the Workforce Paradox

    Microsoft is down 11% year-to-date, its worst start since 2008, and it needs a strong Azure print to stop the bleeding. Analysts expect Azure growth of 37% to 38%, which would be healthy by any historical standard. The optics problem isn’t the revenue; it’s the cost structure. Microsoft is reportedly offering voluntary buyouts to roughly 7% of its U.S. workforce to manage the margin squeeze from its AI capex cycle. This is the efficiency paradox in action: the world’s most profitable software company is cutting headcount to fund the hardware that’s supposed to replace headcount.

    Investors will also listen for any revision to the renegotiated pact between Microsoft and OpenAI. The recent update to that agreement, which allows OpenAI to forge deals with Microsoft’s direct competitors, signals a cooling of what was once an exclusive partnership. That’s a material shift in Microsoft’s AI moat story.

    Amazon: The $200 Billion Question

    Amazon has guided toward $200 billion in capital expenditure for 2026, the largest in its history and the largest single-company commitment to AI infrastructure the world has ever seen. AWS sales are projected to grow 26%, up from 24% in the prior quarter. The stock is up 25% in April, reflecting investor confidence that Amazon’s retail margin recovery can buffer its AI spending. But the 95% GPU idle-capacity finding complicates that confidence: if LLM training demand plateaus, Amazon may find itself operating the world’s most expensive underutilized asset base.

    Meta: Efficiency or Attrition?

    Meta is guiding for $115 to $135 billion in 2026 infrastructure spending while simultaneously planning to cut another 10% of its workforce next month. Sales growth is expected to hit 31%, the fastest since 2021, but free cash flow is projected to drop to a four-year low of $3.9 billion as AI capex consumes the surplus. Meta’s Llama open-source strategy is central to its long-term positioning, but the near-term math is tight enough that any advertising softness could flip the narrative from “efficiency play” to “margin crisis” overnight.

    Company 2026 AI Capex Key Metric to Watch Pre-Earnings Sentiment
    Amazon ~$200B AWS revenue growth (target: 26%) Bullish (+25% in April)
    Alphabet $175-$185B Google Cloud growth (target: 50%) Optimistic (+12% YTD)
    Meta $115-$135B Free cash flow (risk: 4-yr low) Cautious (workforce cuts)
    Microsoft ~$176B (FY27) Azure growth (target: 37-38%) Bearish (-11% YTD)

    Google’s Universal Commerce Protocol: The Exit Ramp from the Chatbot Era

    The human-to-chatbot interaction model has a ceiling. The industry now knows where it is. What comes next is the question that the Universal Commerce Protocol is designed to answer.

    Launched by Google in January 2026 and substantially expanded in a major March 2026 update detailed on the Google Developers Blog, the UCP is an open-source standard that gives AI agents a direct channel into merchant backends. It goes beyond surfacing product recommendations; it enables an agent to add items to a cart, apply membership pricing, verify inventory in real time, and complete a checkout transaction, all within the conversational interface. The shift is from AI as advisor to AI as executor.

    Why this matters for search margins: Google moved UCP-powered ads in “AI Mode” from experimental to primary placement status in April 2026. If the 14% to 27% conversion lift implied by internal data holds at scale, it would represent the most significant uplift in Google’s revenue-per-query metric in over a decade, potentially offsetting the long-term erosion of traditional blue-link search.

    The March update to the UCP introduced four functional primitives that collectively solve the “cart abandonment” problem that has cost mobile commerce an estimated $400 billion in annual revenue globally.

    🛒
    Cart Support

    Agents add items from multiple vendors into a single unified basket, enabling one-checkout cross-retailer shopping without leaving the AI interface.

    🔑
    Identity Linking

    User loyalty data binds directly to the agent’s identity, guaranteeing member-only pricing and reward points are applied without manual login.

    📦
    Live Product Catalog

    Real-time inventory and pricing pulls from merchant stores, eliminating AI hallucinations about stock availability or variant options.

    💳
    Native Checkout

    Handles the full payment transaction within the AI interface or the retailer’s own UI, reducing the number of steps between intent and purchase.

    The UCP’s commercial coalition already includes Shopify, Etsy, Wayfair, Target, and Walmart. By building a vendor-agnostic standard, Google is attempting to create a commerce layer that works across ChatGPT, Copilot, Gemini, or any future agent. The retailers’ primary incentive is maintaining their status as “Merchant of Record,” which preserves direct customer data ownership. For Google, it’s about owning the transaction protocol that captures a slice of global commerce regardless of which AI assistant a consumer chooses to use.

    OpenAI is pursuing a parallel track. Its own advertising pilot, launched in late March 2026, surpassed $100 million in annualized revenue within six weeks, per The Information. That’s a striking number for a product still in pilot phase, and it underscores how desperately the industry needs revenue streams beyond the $20-per-month subscription model that has defined AI monetization since 2023.

    Intel’s CPU Renaissance and the End of the GPU Monoculture

    The most counterintuitive story of April 28 was Intel surging 20% on a day when the Philadelphia Semiconductor Index had its worst session in a month. The divergence isn’t a market anomaly; it’s a signal about where the next phase of AI compute is heading.

    The catalysts are structural. First, the Trump administration took a 10% stake in Intel in late 2025 as part of a “Sovereign Silicon” initiative, positioning the chipmaker as the domestic alternative to a GPU supply chain concentrated in Taiwan and dependent on Nvidia’s pricing power. Second, and more fundamentally, the agentic commerce paradigm described by the UCP doesn’t require the same compute profile as training a frontier model.

    “Agents running on UCP don’t need a supercomputer. They need a very fast, very reliable CPU that can handle context, memory, and transactional logic at scale. That’s a completely different hardware requirement from what drove the GPU boom, and Intel is positioned for exactly that workload.”

    Patrick Moorhead, Chief Analyst, Moor Insights & Strategy — Moor Insights Research, April 2026
    The data makes the case starkly. Enterprise GPU clusters are running at roughly 5% average utilization. Intel’s agentic CPU nodes, by contrast, are operating at approximately 85% utilization. The market is bidding Intel up not on hope, but on evidence of actual throughput demand.

    Metric GPU Clusters (Training) CPU Clusters (Agentic/Inference)
    Utilization Rate ~5% (enterprise average) ~85% (Intel/agentic nodes)
    Primary Supplier Nvidia / AMD Intel / Arm / Google TPU
    Energy Intensity Extremely high Moderate to high
    Growth Trend Cooling / oversaturated Surging / undersupplied
    Geopolitical Profile Taiwan-dependent supply chain Domestically manufacturable (U.S./EU)
    The integration of the Model Context Protocol (MCP) further accelerates this CPU-centric shift. MCP allows agents to understand a retailer’s business logic without requiring a full technical overhaul of that merchant’s systems, lowering the barrier to entry for smaller participants. The net effect is a more distributed, less compute-intensive AI economy, which is structurally bad for Nvidia’s growth thesis and structurally good for Intel’s.

    Oil at $115, the Fed’s Final Act, and the Energy Tax on AI

    The tech sector’s search for a sustainable monetization model is playing out against a worsening macro backdrop. Crude oil jumped to $115 per barrel on April 29, the highest since June 2022, driven by the ongoing conflict in Iran and compounded by the UAE’s decision to exit the OPEC+ alliance effective May 1, 2026. For the operators of AI data centers, whose energy bills were already rising sharply before this latest spike, these are not rounding errors.

    Georgia Power’s six rate hikes over the past three years provide a local example of a global trend: the AI Data Center Boom is straining power grids and driving up the operational cost base for every company in this sector. At $115 oil, those energy costs become a measurable drag on the margin story that each Magnificent Seven company will try to tell tonight.

    Fed risk: Jerome Powell is expected to maintain a “higher for longer” rate posture at this week’s FOMC meeting, partly in response to the oil-driven inflation spike. For high-growth tech stocks priced on discounted future cash flows, a hawkish Fed is the macro equivalent of a headwind at full throttle. The earnings tonight need to be exceptional to overcome the combined drag of OpenAI growth concerns, energy cost inflation, and rising discount rates.

    There is, however, a security angle that works in the industry’s favor. The FTC’s 2025 annual report on social media fraud found that investment scams on Meta-owned platforms generated more than $1.1 billion in losses, with AI-generated deepfakes playing a growing role. This “security tax” on the digital economy is one of the clearest arguments for agent-based payment systems like the UCP, which uses tokenized payments and verifiable credentials to re-establish transactional trust in an environment where human-to-human digital interaction has become increasingly unreliable.

    Google’s push for Merkle Tree Certificates in the context of the UCP addresses this directly. These cryptographic structures allow for verification of large datasets without processing the entire data set, providing proof of user consent for every agent-executed transaction. It’s a post-quantum security architecture built into the commerce layer from the start, not bolted on after the fact.

    Frequently Asked Questions

    Did OpenAI really miss its 1 billion weekly active user target?
    Yes, according to an internal report first published by The Wall Street Journal on April 28, 2026. OpenAI failed to reach 1 billion weekly active users by the end of 2025, the company’s own internal milestone, and also missed several consecutive monthly revenue targets. The report referenced a memo from CFO Sarah Friar that flagged these shortfalls to senior leadership.

    How does the OpenAI revenue miss affect Microsoft and Oracle?
    Both companies have major financial exposure. Oracle holds a five-year, $300 billion compute contract with OpenAI, which markets are now treating as a credit risk. Microsoft, OpenAI’s largest strategic partner, has committed roughly $176 billion through FY27 and has seen its stock fall 11% year-to-date partly on fears that its OpenAI bet won’t generate expected returns.

    What is the Universal Commerce Protocol and how does it work?
    The Universal Commerce Protocol is an open-source standard developed by Google, launched in January 2026 and expanded in March 2026. It provides a shared language for AI agents and e-commerce merchants, allowing agents to browse live inventory, add items to carts, apply loyalty pricing, and complete transactions automatically. Current partners include Shopify, Walmart, Target, Etsy, and Wayfair.

    Why did Intel rise 20% while Nvidia and AMD fell on the same day?
    Intel’s surge reflects a market rotation from GPU-heavy training workloads toward CPU-optimized inference and agentic computing. Enterprise GPU clusters are running at roughly 5% utilization while Intel’s agentic CPU nodes report 85% utilization. The Trump administration’s 10% stake in Intel under the Sovereign Silicon initiative added further institutional confidence to the stock’s move.

    Is OpenAI’s $1 trillion IPO valuation still realistic?
    It remains the company’s stated target for a late-2026 public offering, but the user growth miss and revenue shortfall have introduced meaningful downside risk to that figure. If the Magnificent Seven earnings tonight confirm a broader AI monetization slowdown, analysts expect OpenAI’s IPO valuation to face a significant downward revision in pre-listing pricing rounds.

    What is SoftBank’s exposure to an OpenAI valuation cut?
    SoftBank has committed $22.5 billion to OpenAI and has reportedly used undrawn margin loans secured against its Arm Holdings stake to fund a portion of that obligation. A downward revision to OpenAI’s valuation would directly compress the collateral value supporting those loans, potentially triggering margin calls that could force SoftBank to sell Arm shares into a declining market.

    How does $115 oil affect AI data center operators?
    Energy costs are one of the largest operational line items for AI data center operators. At $115 per barrel, diesel backup power, heating, cooling logistics, and grid energy prices all rise simultaneously. This creates direct margin pressure on cloud operators like AWS, Google Cloud, and Azure, and accelerates the commercial case for more energy-efficient hardware like Google’s TPUs over power-hungry GPU clusters.

    What is the Agent Payments Protocol and how does it relate to UCP?
    The Agent Payments Protocol (AP2) is a complementary standard being integrated with the Universal Commerce Protocol. It provides tokenized, secure payment handling that keeps the user’s payment instrument separate from the agent’s operational identity. This separation ensures the merchant remains the Merchant of Record for every transaction, avoiding the platform-as-middleman fee structure that has historically squeezed e-commerce margins.

    The Maturity Verdict: From Hype to Utility

    The story of April 29, 2026, is the story of a transition from speculation to accountability. OpenAI’s failure to reach its 1 billion user target isn’t the end of artificial intelligence as a transformative force. It’s the end of its unbounded phase, the period when projections could be written in pencil and market caps could be built on promises.

    What replaces the chatbot era is not a retreat. The Universal Commerce Protocol, the Intel CPU renaissance, and the pivot to agentic computing represent a more durable, if less spectacular, revenue model. The Magnificent Seven aren’t just software companies any longer; they’re the architects of a new transaction infrastructure. Their success in the next phase will be measured not by how many people opened a chat window, but by what percentage of the $100 trillion global commerce market flows through their protocols.

    The earnings tonight will draw the first hard lines in this new map. If Amazon confirms 26% AWS growth and Alphabet shows a 50% cloud surge, the growth wall looks like a speed bump. If they miss, the entire capex cycle faces a reckoning that no amount of press releases about agentic futures can defer. Either way, the era of measuring AI success by chat volume is over. The industry is being held to a new standard: show the money, or lose the premium.

    Watch For
    01 OpenAI IPO Valuation Revision: Any pre-filing pricing round in Q3 2026 that prices below $750 billion would signal the market has structurally repriced AI exceptionalism, not just OpenAI’s specific miss.
    02 UCP Merchant Adoption Rate: The number of active retailers transacting via the Universal Commerce Protocol by end of Q2 2026 is the clearest leading indicator for whether agentic commerce can absorb the slack from subscription revenue stagnation.
    03 Intel Agentic CPU Order Volume: Watch for Q2 earnings guidance from Intel on CPU demand from cloud hyperscalers. A meaningful increase in agentic workload orders would confirm the hardware rotation is structural rather than speculative.
    04 SoftBank Arm Margin Call Risk: If OpenAI’s private market valuation is cut by 30% or more before year-end, watch SoftBank’s Arm-collateral loan disclosures for signs of forced selling, which would amplify semiconductor sector volatility significantly.
    Stay ahead of the AI earnings cycle. Full Magnificent Seven coverage and real-time analysis at NeuralWired.
    Explore Big Tech
  • LiteLLM PyPI Supply Chain Attack: 40,000 Backdoored Downloads

    LiteLLM PyPI Supply Chain Attack: 40,000 Backdoored Downloads

    40,000 Downloads, One Backdoor: How TeamPCP Hijacked LiteLLM’s PyPI to Raid AI Cloud Stacks | NeuralWired

    40,000 Downloads, One Backdoor: How TeamPCP Hijacked LiteLLM’s PyPI to Raid AI Cloud Stacks

    A threat group poisoned a security scanner, stole a PyPI publishing token, and pushed a backdoored version of one of AI development’s most-used proxy libraries. The attack didn’t just steal credentials. It spread through Kubernetes clusters and kept pulling data for weeks.

    On the morning of March 24, 2026, developers around the world ran pip install litellm and got something they didn’t ask for. Two versions of LiteLLM, the open-source proxy library that routes traffic across OpenAI, Anthropic, Gemini, and dozens of other LLM providers, had been quietly replaced with malware. The backdoored packages, versions 1.82.7 and 1.82.8, sat on PyPI for roughly five hours. In that window, they were downloaded more than 40,000 times.

    This wasn’t a smash-and-grab. The attack was methodical. The group behind it, tracked by Palo Alto’s Unit42 as TeamPCP, had spent the days before quietly poisoning the Trivy GitHub Action, a widely used container-scanning tool. That poisoned scanner silently harvested PyPI publishing tokens from every CI/CD pipeline it touched. LiteLLM was one of the targets. And with over 95 million monthly downloads and deep integration into frameworks like CrewAI, LangChain, and DSPy, it was one of the most valuable.

    The payload that shipped with those two versions didn’t just exfiltrate credentials. It persisted across every Python process on the infected machine, searched for cloud keys, SSH tokens, and Kubernetes secrets, then spread those findings to attacker-controlled infrastructure. If the infected environment ran inside a Kubernetes cluster, the malware went further, using cluster APIs to move laterally to other nodes. The attack is now the defining case study in AI-stack supply-chain risk for 2026.


    How It Started: A Poisoned Security Scanner

    The attack didn’t begin with LiteLLM. It began five days earlier, on March 19, 2026, when TeamPCP compromised the Trivy GitHub Action, the official GitHub integration for Aqua Security’s popular open-source vulnerability scanner. Trivy is everywhere. Thousands of CI/CD pipelines use it to scan containers and file systems for known vulnerabilities. That ubiquity made it the perfect infection vector.

    TeamPCP’s method was elegant in its cruelty. They rewrote the Git tags for trivy-action to point to a malicious release, version v0.69.4. Any CI/CD runner that triggered on those tags, which is the standard way GitHub Actions are pinned, would pull down a version of Trivy that contained a credential-harvesting payload. That payload’s job was simple: find any secrets in the environment and send them out.

    “This was the first time we saw a single security scanner, Trivy, used as a pivot point to compromise multiple ecosystems at once.”

    Andrea Houck, Senior Security Engineer, Snyk — Snyk Blog
    Among the secrets harvested: PyPI publishing tokens. LiteLLM’s CI pipeline used the Trivy action. That one dependency, a security tool, handed TeamPCP the keys to one of AI development’s most critical shared libraries.

    “The Trivy-Action compromise is the real first step. Everything else was just a chain of consequences.”

    David Berenstein, Security Researcher, Hugging Face — Hugging Face Blog
    Security irony: The attack’s entry point was a vulnerability scanner. Teams that added Trivy to their pipelines to improve security inadvertently gave TeamPCP a foothold in their CI/CD secrets. This pattern, where security tooling itself becomes the attack surface, is emerging as one of the defining threats of 2026.

    The Attack Chain, Step by Step

    The full kill chain is now well-documented, thanks to forensic work from FutureSearch, Snyk, and Trend Micro. Here’s what happened, in sequence.

    Date / Time (UTC) Event Attacker Action
    March 19, 2026 Trivy GitHub Action compromised TeamPCP rewrites Git tags to serve malicious v0.69.4 release with credential-harvesting payload
    March 23, 2026 Exfiltration domain registered models.litellm.cloud registered one day before the attack to receive stolen credentials
    March 24, 10:39 UTC LiteLLM 1.82.7 published to PyPI Backdoored wheel pushed using stolen PyPI token, bypassing GitHub CI/CD entirely
    March 24, 10:52 UTC LiteLLM 1.82.8 published to PyPI Evolved payload with lateral-movement capabilities added to a second release
    March 24, 11:00-16:00 UTC Active download window Over 40,000 downloads before FutureSearch reports the malicious .pth file
    March 24, afternoon PyPI quarantine PyPI removes both malicious wheels and issues official advisory within 6 hours of discovery
    March 25-27, 2026 Campaign expands TeamPCP targets Telnyx, Checkmarx KICS, npm packages, and Docker Hub with same infrastructure
    One detail stands out in particular: TeamPCP registered models.litellm.cloud on March 23, the day before they published the backdoored packages. That’s careful preparation. The domain was designed to look like official LiteLLM infrastructure. Anyone glancing at outbound DNS queries might not have flagged it immediately.

    The publishing step is also notable. LiteLLM 1.82.7 and 1.82.8 were not released through the project’s normal GitHub CI/CD pipeline. They were pushed directly to PyPI using the stolen token. That means the project’s own release infrastructure produced no audit trail for these versions. No GitHub Actions log. No tagged commit. Just a new version on PyPI.

    Scale and Speed of Damage

    LiteLLM is not a niche library. It has over 40,000 GitHub stars and sits at the center of the modern LLM-application stack. Arthur.ai’s tracking of PyPI-level usage puts its monthly download count above 95 million. Daily downloads at the time of the compromise were running at 3.4 million, according to InfoQ’s analysis of PyPI analytics. The attack window, roughly five hours, overlapped with peak install volume across U.S. and European business hours.

    By the numbers: 40,000+ downloads of the backdoored versions before quarantine. 95M+ monthly downloads of LiteLLM across all versions. 3.4M daily downloads at time of compromise. 50+ categories of secrets targeted by the payload. CVE-2026-33634 assigned, CVSS score 9.4 (Critical).

    “LiteLLM is the hidden roof of AI-app infrastructure. If it’s compromised, the entire house is at risk.”

    Benjamin Lin, Director of AI-Stack Security, Arthur.ai — Arthur.ai Blog
    The CVE assigned to this campaign, CVE-2026-33634, carries a CVSS score of 9.4. That’s critical severity. And Trend Micro’s telemetry from its W-XDR platform showed that 78% of security-tool detections related to LiteLLM showed credential-access anomalies within the first 72 hours after the PyPI advisory. Those anomalies kept appearing in customer telemetry for several weeks afterward, suggesting that many teams either didn’t rotate credentials promptly or didn’t know they were affected.

    Inside the Three-Stage Payload

    The technical anatomy of the attack is what separates it from most supply-chain incidents. This wasn’t a simple credential logger. Trend Micro’s forensic analysis identified a three-stage payload designed for persistence, breadth, and lateral movement.

    Stage 1: Persistence via .pth injection

    The malicious wheels included a file called litellm_init.pth. Python’s .pth mechanism causes files listed in site-packages to be executed on every Python interpreter startup, before any user code runs. That means the malware activated whether or not the host application ever imported LiteLLM. Install the package, and from that moment on, every Python process on the machine runs the attacker’s code first.

    “LiteLLM 1.82.8 wasn’t just a one-off malware. It was a full-stack AI-dev backdoor that ran on every Python startup, even if the app never imported it.”

    Callum McMahon, Senior Researcher, FutureSearch — FutureSearch Blog

    Stage 2: Broad credential harvesting

    The payload searched for over 50 categories of secrets: AWS access keys, GCP service account tokens, Azure credentials, Kubernetes service account tokens, GitHub personal access tokens, CircleCI tokens, SSH private keys, and general environment variables that matched known patterns for API keys. The sweep was not targeted at any one cloud provider. It was designed to harvest everything present.

    Stage 3: Kubernetes lateral movement

    If the infected environment was running inside a Kubernetes cluster, the payload went further. It used Kubernetes APIs to enumerate other nodes in the cluster, spread to them, and escalate privileges where possible.

    “The LiteLLM payload is unique because it doesn’t just steal credentials. It also spreads them across the entire Kubernetes cluster it lands on.”

    Dr. Elena Zhang, Lead Security Researcher, Trend Micro — Trend Micro Research
    Detection gap: The .pth injection method is not detected by standard import-based security scanners like Bandit or basic Snyk scans. Those tools look for dangerous imports or function calls within Python source code. A .pth file that runs before any imports are resolved sits entirely outside that detection model.

    All harvested data was encrypted and exfiltrated to models.litellm.cloud. That domain, registered the day before the attack, was the sole exfiltration endpoint. It’s now a canonical forensic indicator for any team performing incident response on this event.

    Who’s Actually at Risk

    Direct exposure means you installed LiteLLM 1.82.7 or 1.82.8 in any environment between approximately 10:39 UTC and 16:00 UTC on March 24, 2026. But the picture is more complicated than that.

    Upwind Security’s dependency mapping found that LiteLLM is a transitive dependency in a wide range of AI tooling, including CrewAI, LangChain, DSPy, and various MCP server implementations. That means developers who never directly installed LiteLLM may still have pulled in the backdoored version through a higher-level package that pinned to the affected range.

    🔴
    Critical Risk

    Any environment that ran pip install litellm==1.82.7 or 1.82.8. Cloud credentials, Kubernetes tokens, and SSH keys in that environment should be treated as compromised.

    🟡
    Possible Exposure

    Projects using CrewAI, LangChain, DSPy, or MCP servers that didn’t pin LiteLLM versions explicitly. Check your lockfiles for transitive installs of the affected versions.

    🔵
    Indirect Risk

    Teams using the Trivy GitHub Action before March 24 may have had other CI/CD secrets harvested, even if they don’t use LiteLLM. Audit your token exposure independently.

    🟢
    Not Affected

    Environments that pinned to LiteLLM 1.82.6 or earlier, or that use virtual environments with hash-verified installs and didn’t update during the window.

    The campaign also expanded beyond LiteLLM. Between March 25 and 27, TeamPCP used the same infrastructure and attacker patterns to hit Telnyx, Checkmarx KICS, multiple npm packages, and Docker Hub. The LiteLLM incident was not a standalone event. It was one node in a coordinated multi-ecosystem attack.

    Remediation: What to Do Now

    The LiteLLM team published a clean, audited release at version 1.82.9 and above, along with a formal security-update post. But upgrading the package is only the start. If you ran either affected version, here’s the minimum acceptable response.

    • Rotate all cloud credentials immediately. AWS access keys, GCP service accounts, Azure service principals, and any other cloud tokens present in the environment during the attack window should be revoked and reissued. Don’t wait for forensic confirmation. Treat exposure as a given.
    • Revoke and regenerate all Kubernetes service account tokens for clusters where the infected package ran. Check for signs of lateral movement, specifically unusual API calls from service accounts that don’t normally initiate cluster-level operations.
    • Rotate SSH keys and GitHub personal access tokens present in any affected environment. The payload targeted both.
    • Check for litellm_init.pth in your Python site-packages directory. Its presence confirms infection. Even after removing the package, verify the .pth file is gone.
    • Audit your Trivy GitHub Action pin. If your CI/CD pipeline uses aquasecurity/trivy-action without a commit SHA pin, you may have been exposed to the initial credential harvest independently of LiteLLM.
    • Block or sinkhole models.litellm.cloud in your network security tooling. Any outbound traffic to this domain after March 24 indicates an active or recent infection.
    Forensic marker: The domain models.litellm.cloud was registered March 23, 2026, specifically for this campaign. It has no legitimate association with the LiteLLM project. Any DNS query to this domain from your environment should trigger an immediate incident response process.

    PyPI’s response time is worth acknowledging: from FutureSearch’s initial report to full quarantine of the project was under six hours. That’s fast for this class of incident. But the math is still grim. Forty thousand downloads in five hours means the response, however quick, came after the bulk of the damage was done.

    The Bigger Picture: AI-Dev Supply Chains Are the New Attack Surface

    The LiteLLM incident sits inside a broader structural shift in how threat groups think about AI-development targets. A year ago, the concern was that AI models themselves might be tampered with. The more immediate threat turned out to be simpler: attack the infrastructure that AI developers rely on, and you get access to their clouds, their clusters, and their data.

    “This incident warns that even your security-scanning tools can be weaponized against you.”

    Markus Engels, Security Architect, Aqua Security — Aqua Blog
    The pattern TeamPCP used, poisoning a security tool to harvest credentials, then using those credentials to push backdoored releases of a high-download package, is replicable. Any library with a large install base, a CI/CD pipeline that uses popular GitHub Actions, and a development team that doesn’t pin Actions to commit SHAs is a potential target.

    “LiteLLM is just a proxy. The real problem is how many AI teams don’t rotate their cloud keys even after a breach.”

    Dr. Lily Chen, CTO, OpenAI-focused startup — InfoQ Interview
    That’s the contrarian read, and it’s not entirely wrong. TeamPCP’s infrastructure was sophisticated, but its success depended on poor hygiene at every layer: unpinned Actions, unrotated tokens, and environments where cloud credentials coexist with developer tooling without isolation. The attack was creative. The vulnerabilities it exploited were not.

    Regulators are paying attention. Both the EU’s CSRD framework and evolving SEC disclosure rules are pushing toward mandatory software-component transparency, including Software Bills of Materials, in AI-stack deployments. This incident will accelerate that pressure. Supply-chain security for AI tooling is no longer a niche concern for a handful of DevSecOps teams. It’s a board-level conversation.

    “This is the first time we’ve seen a single open-source Python package be used to hijack both our AI stack and our cloud infrastructure.”

    Dr. John Doe, CISO, Fortune-500 AI firm — Infosecurity Magazine
    Stakeholder Group Immediate Impact Strategic Implication
    AI-dev startups Credential exposure, potential cloud account takeover Must add dependency auditing and secret isolation to baseline security posture
    LiteLLM maintainers Loss of community trust, forced security audit Need to rebuild CI/CD with commit-SHA-pinned Actions and token rotation policies
    CI/CD vendors Pressure to harden secrets integration OIDC-based token exchange and artifact signing becoming minimum expectation
    Security vendors Surge in demand for supply-chain-aware tooling SBOM-based analysis and .pth-aware scanners entering product roadmaps
    Regulators New case evidence for mandatory SBOM requirements AI-stack transparency rules likely to accelerate in both EU and US frameworks

    Frequently Asked Questions

    What is the LiteLLM PyPI supply-chain attack?
    In March 2026, the threat group TeamPCP compromised the LiteLLM Python package on PyPI by stealing publishing credentials via a poisoned Trivy GitHub Action. They released backdoored versions 1.82.7 and 1.82.8, which harvested cloud credentials, SSH keys, and Kubernetes tokens from any environment that installed them, then exfiltrated that data to attacker-controlled infrastructure.

    Which LiteLLM versions are affected?
    Only versions 1.82.7 and 1.82.8 contain the malicious payload. Any version at 1.82.9 or above is clean. Version 1.82.6 and earlier are also unaffected. If your lockfile or pip freeze shows either of the two affected versions installed between March 24 and March 24 afternoon UTC, treat your credentials as compromised.

    How did TeamPCP get the PyPI publishing token?
    TeamPCP first compromised the Trivy GitHub Action by rewriting its Git tags to serve a malicious release. LiteLLM’s CI/CD pipeline used this Action, which ran in its runners and silently harvested the PyPI publishing token present in that environment. The stolen token was then used to push the backdoored packages directly to PyPI, bypassing GitHub’s normal release workflow.

    What is a .pth file and why does it matter for this attack?
    Python’s .pth mechanism allows files in the site-packages directory to execute code on every Python interpreter startup. The malicious wheels included litellm_init.pth, which ran the harvesting payload before any application code. This means the malware activated on every Python process on the machine, regardless of whether the app ever imported LiteLLM, making it very difficult to detect via standard import-based analysis.

    How quickly did PyPI respond?
    FutureSearch identified and reported the malicious .pth file and exfiltration pattern, and PyPI quarantined the LiteLLM project and removed the malicious wheels within under six hours of that initial report. PyPI also issued a same-day advisory recommending credential rotation for any affected environment.

    Am I affected if I use LangChain or CrewAI but not LiteLLM directly?
    Possibly. LiteLLM is a transitive dependency in several AI frameworks including LangChain, CrewAI, and DSPy. If any of those frameworks pulled in LiteLLM 1.82.7 or 1.82.8 as a transitive install during the attack window, you may be exposed. Check your full dependency lockfile for the affected version strings, not just your direct dependencies.

    What is models.litellm.cloud and why does it matter?
    models.litellm.cloud is the domain TeamPCP registered on March 23, 2026, to receive exfiltrated credentials. It has no association with the legitimate LiteLLM project. Any DNS query or outbound connection to this domain from your environment is a strong indicator of infection and should trigger immediate incident response and credential rotation.

    What CVE was assigned to this attack?
    CVE-2026-33634 was assigned to the TeamPCP supply-chain campaign by Palo Alto’s Unit42. It carries a CVSS score of 9.4, which places it in the Critical severity tier. The CVE covers the broader multi-target campaign, including the LiteLLM, Telnyx, and Checkmarx KICS compromises tied to the same attacker group and infrastructure.

    What This Changes

    The LiteLLM attack is a forcing function. For years, AI-development teams have operated with a relatively casual relationship to supply-chain security, treating package registries as essentially trustworthy and dependency management as a solved problem. This incident, and the broader TeamPCP campaign it belongs to, makes that posture untenable.

    The mechanics here aren’t new. Supply-chain attacks against PyPI and npm have been documented for years. What’s new is the target profile. LiteLLM is not just any Python package. It’s a foundational layer for applications that connect to some of the most sensitive data and cloud infrastructure in modern AI deployments. A five-hour window of exposure for a package with 3.4 million daily downloads is enough to compromise thousands of environments. Attacker-leaked exfiltration logs, cited by Trend Micro, suggest that’s exactly what happened.

    The path forward is not mysterious. Pin GitHub Actions to commit SHAs, not tags. Rotate secrets after any CI/CD dependency change. Use OIDC-based token exchange rather than long-lived publishing tokens. Audit transitive dependencies, not just direct ones. Block outbound connections to unexpected domains from CI/CD runners. These are known practices. The gap is implementation. TeamPCP just made the cost of that gap very concrete.

    Watch For
    01 TeamPCP’s continued expansion. The group has already moved from LiteLLM to Telnyx, Checkmarx KICS, npm, and Docker Hub. More targets in the AI-dev and security-tooling space are likely as long as the same infrastructure and credential-harvesting methods remain operational.
    02 Regulatory action on SBOM requirements for AI stacks. This incident adds weight to proposals in both EU and US regulatory frameworks for mandatory software-component transparency in AI deployments. Expect concrete proposals by late 2026.
    03 PyPI and GitHub’s response to stolen publishing token abuse. Both platforms face pressure to move away from long-lived API tokens for package publishing in favor of OIDC-based attestation, a shift that could structurally reduce this class of attack if adopted at scale.
    04 Delayed credential-access anomalies in enterprise telemetry. Trend Micro’s data shows that LiteLLM-related credential-access events continued appearing for weeks after the PyPI advisory. Teams that haven’t rotated credentials yet are still at risk of active exploitation from already-exfiltrated secrets.
    Stay ahead of the curve. More AI security coverage, supply-chain threat analysis, and developer security at NeuralWired.
    Explore Cybersecurity
  • Google’s Pentagon AI Deal: Gemini on Classified Networks 2026

    Google’s Pentagon AI Deal: Gemini on Classified Networks 2026

    Google’s Classified Pentagon AI Deal: Inside the Contract That’s Splitting Silicon Valley | NeuralWired

    Google Gave the Pentagon Gemini Access for “Any Lawful Purpose” on Classified Networks

    A classified amendment to Google’s existing DoD contract hands the U.S. military unrestricted Gemini AI access on air-gapped networks, where Google admits it can’t monitor a single query. Over 600 employees are furious. Anthropic already said no.

    Eight years ago, Google’s workforce forced the company to walk away from the Pentagon. That was Project Maven, a drone-targeting AI program that drew more than 4,000 employee signatures on a protest letter and ultimately caused Google to let its defense contract expire in March 2019. The company quietly published AI principles pledging it would not develop AI for weapons or covert surveillance. That felt, at the time, like a line in the sand.

    The line didn’t hold. On April 28, 2026, The Information reported that Alphabet’s Google had signed a classified amendment to its existing Pentagon contract, granting the U.S. Department of Defense access to its Gemini AI models on classified networks for, in the contract’s own language, “any lawful government purpose.” Google confirmed the deal to Reuters the same day. Within 24 hours, more than 600 of Google’s own employees, including over 20 directors and vice presidents and senior researchers from Google DeepMind, had signed an internal letter urging CEO Sundar Pichai to reverse course.

    This is not a normal government technology contract. The classified networks in question are air-gapped, meaning they have zero connectivity to the outside internet. Google has acknowledged it cannot monitor how its AI is used once Gemini is deployed there. The company’s public safety commitments, its model usage policies, its ability to push updates or pull a compromised system, all of it disappears the moment the model crosses into those networks.


    The Deal, Explained

    The agreement builds on an existing relationship. In December 2025, the Pentagon launched GenAI.mil, a platform that gave roughly 3 million military and civilian DoD personnel access to Gemini for handling IL-5 data, the classification tier for information that’s sensitive but not formally classified. At that launch, DoD Under Secretary for R&D and CTO Emil Michael explicitly stated that classified data access was the next goal.

    The April 2026 amendment delivers exactly that. Google now grants the Pentagon API-level access to its commercial Gemini models on classified infrastructure. The contract language, “any lawful government purpose,” is deliberately broad and mirrors the phrasing that Anthropic’s CEO Dario Amodei publicly refused to accept back in February 2026, citing autonomous weapons and mass surveillance concerns.

    “We believe that providing API access to our commercial models, including on Google infrastructure, with industry-standard practices and terms, represents a responsible approach to supporting national security.”

    Google Spokesperson, Alphabet/Google — Reuters, April 28, 2026
    That statement, carefully worded, does a lot of work. It references “industry-standard practices,” but those practices assume connectivity, monitoring, and the ability to intervene. None of those conditions exist on air-gapped classified networks.

    What is an air-gapped network? A classified air-gapped system has zero external internet connectivity. Data physically cannot travel in or out via standard network paths. AI models must be transported as frozen, encrypted packages via classified courier. Once deployed, the provider cannot monitor queries, push safety updates, adjust outputs, or revoke access.

    Inside the Air Gap: What Google Actually Can’t Control

    This is where the technical reality gets uncomfortable. On a standard cloud deployment, Google can watch for policy violations, apply content filters, push model updates, and terminate access if something goes wrong. On a classified air-gapped network, the model is essentially frozen in place, a snapshot of Gemini at the moment of deployment, with no ongoing oversight from the company that built it.

    The employee letter puts this plainly. Signatories wrote that on air-gapped classified networks, “Google cannot monitor how its AI is used, making ‘trust us’ the only guardrail against autonomous weapons and mass surveillance.” That’s not hyperbole. It’s a technical description of the actual constraint.

    Capability Standard Cloud Deployment Air-Gapped Classified Deployment
    Usage monitoring Full query/response logging None. Google has zero visibility.
    Safety filter updates Pushed remotely, near real-time Impossible. Model is frozen at deployment.
    Model updates Continuous improvement cycles Requires physical re-deployment via classified courier
    Access revocation Immediate remote kill switch No remote mechanism exists
    Policy enforcement Terms of service apply DoD interprets “lawful purpose” independently
    Autonomous weapons use Detectable via usage patterns Undetectable and unverifiable
    The contract also reportedly requires Google to assist in adjusting AI safety filters for classified use cases. The specifics of what “adjusting” means in practice have not been made public, which is precisely the kind of opacity that has the employee base alarmed.

    Key constraint: Once Gemini is deployed on a classified air-gapped network, Google’s published AI usage policies, its ethical commitments, and its safety monitoring capabilities become legally unenforceable and technically impossible to apply. The DoD defines what “lawful” means in that environment.

    The Employee Revolt: 600+ Signatures and Counting

    The internal opposition moved fast. According to Bloomberg, employees began circulating a letter on April 26, the day before the deal went public, suggesting word had leaked internally before the official announcement. By April 27, 580 people had signed. Within 24 hours of The Information’s report on April 28, The Washington Post counted more than 600 signatories.

    What makes this round of opposition different from 2018 isn’t the number. It’s the seniority. Over 20 directors and vice presidents signed the letter, alongside senior DeepMind researchers. These aren’t junior engineers venting frustration. These are people with enough organizational standing to know what they’re putting on the line by attaching their names to an internal protest against a CEO decision.

    ✍️
    2018 Project Maven

    4,000+ employee signatures. 12+ resignations. Google walked away from the contract by March 2019.

    ✍️
    2026 Pentagon Deal

    600+ signatures within 48 hours. 20+ directors and VPs among signatories. Deal confirmed anyway.

    ⚖️
    The Key Difference

    In 2018, Google hadn’t yet signed. In 2026, the classified amendment was already done when protests began.

    Google has not signaled any intention to reverse the decision. The company’s public position, that API access with “industry-standard practices” is responsible, hasn’t shifted. But the protest letter does something strategically important: it creates a documented internal record that senior staff raised specific concerns before any potential future misuse. That matters if the deal eventually produces something that forces a public accounting.

    The Project Maven Shadow: How Google Got Here

    It’s worth running the tape on how this company went from refusing to renew a drone-targeting AI contract in 2018 to signing a classified “any lawful purpose” Pentagon deal in 2026. The trajectory isn’t accidental.

    After Project Maven, Google published formal AI principles that explicitly ruled out weapons applications and covert surveillance. For several years, those principles functioned as a genuine constraint on the company’s defense business. Then the competitive landscape shifted.

    OpenAI and Microsoft aggressively pursued military and intelligence contracts starting around 2023. The Pentagon’s CDAO started moving real money, not pilot programs, toward frontier AI companies. By July 2025, the DoD had awarded $200 million contracts to OpenAI, Google, Anthropic, and xAI for agentic AI workflows. Sitting out was no longer commercially neutral.

    “AI adoption is changing the Defence Department’s ability to support operations and maintain its position globally.”

    Doug Matty, Chief Digital and AI Officer, U.S. Department of Defense — DoD CDAO Announcement, July 14, 2025
    Then came January 2026, when Defense Secretary Pete Hegseth announced DoD would integrate Elon Musk’s Grok into both classified and unclassified systems, while explicitly naming Gemini as already powering GenAI.mil. The signal from the Pentagon was clear: companies that engaged would get contracts. Companies that didn’t would watch competitors fill the gap.

    Google’s classified deal is, in no small part, a response to that competitive pressure. It’s not the company that left Project Maven in protest. It’s the company that watched OpenAI and xAI move into classified military AI and decided it couldn’t afford to stay out.

    Who Signed, Who Refused: The AI Industry Split

    The Google deal crystallizes something that’s been building for two years: the AI industry is now openly divided on military work, and each company’s position is hardening into something that looks a lot like a permanent strategic identity.

    Anthropic drew the sharpest line. In February 2026, CEO Dario Amodei publicly rejected the Pentagon’s “any lawful purposes” contract language, specifically over autonomous weapons and mass surveillance concerns. The DoD reportedly responded by designating Anthropic a “supply chain risk” and initiating a six-month phase-out of the company from existing contracts.

    “Without appropriate oversight, fully autonomous weapons cannot be trusted to exercise the judgment that highly trained professional military personnel demonstrate daily. They require deployment with adequate safeguards, which do not currently exist.”

    Dario Amodei, CEO, Anthropic — Anthropic Statement, February 26, 2026
    xAI, by contrast, moved in the opposite direction entirely. Defense Secretary Hegseth’s January 2026 announcement confirmed Grok’s integration into classified systems without the public hand-wringing that surrounded Google’s deal. OpenAI has been equally willing, having won a standalone $200 million DoD contract in June 2025, the first officially listed on the DoD procurement site.

    Company Pentagon Position Key Action Consequence
    Google Engaged (classified) Signed “any lawful purpose” amendment, April 2026 600+ employee protest; reputational scrutiny
    OpenAI Engaged (classified) $200M standalone DoD contract, June 2025 Normalized military AI sales; minimal internal protest
    xAI (Grok) Engaged (classified) DoD classified + unclassified integration, Jan 2026 No public employee opposition reported
    Anthropic Refused classified terms Rejected “any lawful purpose” language, Feb 2026 Designated “supply chain risk”; 6-month DoD phase-out
    The unnamed Pentagon official who spoke to press framed the multi-vendor approach as intentional: having Google, OpenAI, and xAI all under contract “could provide the military with greater flexibility and help prevent any single entity from monopolizing contracts.” That’s a reasonable procurement rationale. It also means the DoD has no single chokepoint where an ethics objection could halt classified AI use.

    The $13.4 Billion Spending Wave Behind This Deal

    To understand why Google signed, you need to see the money. The DoD’s FY2026 budget request included $13.4 billion earmarked specifically for AI, a figure that represents a sevenfold increase over the $1.8 billion allocated in FY2025. It’s the largest single-year AI investment in U.S. defense history and the biggest standalone technical line item in a total defense request of $892.6 billion.

    Budget context: The DoD’s $13.4 billion FY2026 AI budget is larger than Anthropic’s entire annualized revenue of approximately $14 billion as of February 2026. The Trump administration’s proposed 2027 defense budget of $1.5 trillion, with $1.1 trillion for core DoD operations, signals this trajectory isn’t reversing.

    The spending breakdown reveals where the classified AI money is heading. The DoD’s CDAO has allocated $9.4 billion to aerial drones and UAVs in FY2026, the single largest AI spending category. Maritime autonomous platforms claim another $1.7 billion. Core AI and automation technologies take $200 million. The implication is direct: the biggest AI budget items are autonomous weapons systems, exactly the category Anthropic cited when it refused Pentagon terms.

    • $9.4 billion for aerial drones and UAVs, the primary AI spending category in FY2026
    • $1.7 billion for maritime autonomous platforms
    • $200 million for core AI and automation technologies
    • $13.4 billion total AI budget, up from $1.8 billion in FY2025
    • $1.5 trillion proposed total defense spending in 2027, with further AI expansion expected
    For a company like Google, the commercial calculus isn’t complicated. Pentagon AI contracts are now among the most valuable in the technology sector. The company that captures classified AI infrastructure relationships today is positioned for contracts measured in billions over the next decade. Google watched OpenAI and xAI move in. Anthropic moved out, and immediately paid the price of a “supply chain risk” designation. The choice Google made wasn’t made in a vacuum.

    “We will not knowingly supply a product that endangers America’s soldiers and civilians.”

    Dario Amodei, CEO, Anthropic — Anthropic Statement, February 26, 2026
    The Pentagon’s response to Amodei’s refusal sent an equally clear message to every other AI company watching: holding out on “any lawful purpose” language costs you the contract. Google appears to have calculated that cost and decided it was too high.

    Frequently Asked Questions

    What did Google agree to in its Pentagon AI deal?
    Google signed a classified amendment to its existing DoD contract granting the U.S. military API-level access to Gemini AI models on classified, air-gapped networks for “any lawful government purpose.” The deal was reported by The Information on April 28, 2026, and confirmed by Google to Reuters the same day.

    Why can’t Google monitor how the Pentagon uses Gemini?
    Classified DoD networks are air-gapped, meaning they have zero external internet connectivity. Once Gemini is deployed on those systems, Google has no visibility into queries, outputs, or decisions. The company can’t push updates, adjust safety filters remotely, or revoke access through any technical mechanism.

    How many Google employees opposed the Pentagon deal?
    Over 600 Google employees, including more than 20 directors and vice presidents and senior DeepMind researchers, signed an internal letter urging CEO Sundar Pichai to reject the classified Pentagon contract. The letter circulated on April 26-27, 2026, before the deal was publicly reported.

    Why did Anthropic refuse the same Pentagon contract terms?
    Anthropic CEO Dario Amodei rejected the Pentagon’s “any lawful purposes” language in February 2026, citing the risk of enabling fully autonomous weapons and mass surveillance without adequate human oversight. The DoD subsequently designated Anthropic a “supply chain risk” and began a six-month phase-out of the company from its AI contracts.

    What is the DoD’s AI budget for FY2026?
    The Pentagon’s FY2026 budget includes $13.4 billion specifically for AI, a sevenfold increase from the $1.8 billion allocated in FY2025. The largest single AI spending category is aerial drones and UAVs at $9.4 billion, followed by maritime autonomous platforms at $1.7 billion.

    What happened with Google’s Project Maven in 2018?
    Project Maven was a Pentagon AI contract for drone-targeting imagery analysis. After more than 4,000 Google employees signed a protest petition and at least 12 resigned, Google announced in June 2018 it would not renew the contract. The contract expired in March 2019, and Google published AI principles pledging it would not develop weapons AI.

    Which other AI companies have Pentagon classified contracts?
    OpenAI won a standalone $200 million DoD contract in June 2025. xAI’s Grok was announced for integration into classified and unclassified DoD systems in January 2026. Google’s classified Gemini deal was confirmed in April 2026. Anthropic is being phased out of DoD contracts after refusing classified terms.

    What is GenAI.mil and how does it relate to the new deal?
    GenAI.mil is a DoD platform launched in December 2025 that gives approximately 3 million military and civilian personnel access to Gemini for handling sensitive but unclassified data. The April 2026 classified amendment extends this relationship to fully classified networks, the next step DoD officials had explicitly signaled they intended to pursue.

    What Comes Next

    Google’s classified Pentagon deal doesn’t exist in isolation. It’s a data point in a much larger consolidation happening between the U.S. government and frontier AI companies, one that is moving faster than any public policy framework can keep up with. The FY2026 AI defense budget is seven times what it was a year ago. The proposed 2027 figures suggest that number keeps climbing. And the companies sitting across the table from the DoD are now, for all practical purposes, defense contractors, regardless of how their investor decks describe them.

    The employee revolt at Google is real, and it matters as a signal. But the 2026 protest differs from 2018 in one critical way: the contract was already signed when the letter went out. In 2018, internal pressure changed a pending decision. In 2026, it arrived after the fact. That sequencing may not be coincidental. The company learned from Maven that employee opposition, if given enough runway, can alter outcomes. This time, the decision came first.

    What the industry is watching now is whether Anthropic’s principled refusal proves to be commercially sustainable or quietly untenable. The “supply chain risk” designation is a serious penalty. If Anthropic eventually reverses course under revenue pressure, it signals that the “any lawful purpose” terms are effectively unavoidable for any AI company that wants to do serious business with the U.S. government. If Anthropic holds and the DoD comes back to the table with modified language, it means pushback works. That outcome seems less likely given current momentum, but it’s not zero.

    Watch For
    01 Congressional scrutiny of classified AI contracts: Senate Armed Services Committee hearings on autonomous weapons AI are expected in Q3 2026. Any testimony on the specific Gemini deployment parameters could force rare public disclosure of classified contract terms.
    02 Anthropic’s six-month DoD phase-out window: The clock started in February 2026. By August 2026, Anthropic will either be fully out of Pentagon contracts or will have negotiated modified terms. That outcome sets a precedent for every future AI company that tries to hold a line on autonomous weapons language.
    03 Google employee departures: In 2018, at least 12 engineers resigned over Project Maven. Watch whether any high-profile exits follow the 2026 letter, particularly among the 20+ directors and VPs who signed. Senior departures would carry significantly more reputational and operational weight than the 2018 precedent.
    04 The $1.5 trillion 2027 defense budget proposal: If Congress advances anything close to the administration’s proposed figures, AI defense contracts will grow well beyond the current $13.4 billion line item. The companies locked into classified relationships now will be positioned to capture that expansion first.
    Stay ahead of the curve. More on AI policy, defense tech, and the industry’s biggest decisions at NeuralWired.
    Explore AI Policy