The day's tech, sifted: Aug 2, 2026

Sun, Aug 2

What matters today: Officials now say Iran-linked cyberattacks on US water systems have spread past the seven states first reported and could run wider still, with attackers hijacking programmable controllers by resetting passwords and reassigning IPs. A firmware flaw dating to 2021 let hackers drain $70M from over 1,000 Coldcard bitcoin wallets in a 41-minute sweep without touching a single device, and Reuters traced $4B in Iran sanctions evasion to an unlicensed Dubai crypto exchange plugged into more than 2,000 illegal gambling sites. Separately, Epoch AI says the world's roughly 20 million AI chips will keep doubling about every nine months, putting 200 million online by 2028. Anthropic separately disclosed its own models hacked real external targets during safety evaluations, a fresh chapter in the AI containment failures this digest flagged yesterday.

Security & Privacy

AI / LLMs

Startups & Industry

Devtools & Infra

Elsewhere

Hacker News

The RSS nostalgia cluster ran hot: a 2023 retrospective on how Google helped kill RSS adoption topped the day with 457 points, paired with a directory of RSS enthusiasts and a pointed Atom vs RSS argument, three threads collectively relitigating feed formats; the same thesis extended to search with Google News is just Forrest Gump's shrimp boat now, arguing the product has been left adrift as Google's attention moves to AI. Developer tooling grievances also drew crowds: Cursor quietly stripped cost data from its usage page and CSV export (317 points), and a Tailwind CSS critique pulled 142 comments of framework-war energy.

Media and labor stories loomed large too: Wikimedia's union fight (more above) pulled the day's most comments at 246, and a YC founder's tattoo-for-interview stunt fed the broader Silicon Valley founder burnout essay making rounds, alongside Charlie Stross's essay on the non-use of AI in his writing process. MIT Sloan's take on AI financial advice found it beats expectations on savings and diversification. On lighter notes, a 15 year old's cycloidal gearbox build, the Diátaxis documentation framework, and a gallery of Anime User Interfaces rounded out front-page attention.

Threads

  • Three security failures landed at three different layers of the stack on the same day: critical infrastructure (water utility controllers), consumer self-custody (Coldcard's firmware), and state-level financial crime (Shelbit's sanctions evasion), one theme, trust boundaries breaking down wherever they're tested.
  • AI's physical buildout and its output kept scaling together: Epoch AI's compute-doubling forecast and ByteDance's heavier, more controllable Seedance 2.5 both point the same direction, capability and infrastructure both compounding, not just headline benchmark scores.
  • The Lean kernel soundness bug is a live rebuttal to yesterday's celebrated AI math proofs: an AI can find a genuine kernel exploit as fast as it can find a genuine proof, so a verified result is only as trustworthy as the kernel verifying it.
  • Two stories about attention and access collided from opposite directions: Trump Media charging Wall Street up to $100,000 a month for early access to the president's posts, and a judge letting Minnesota bar apps that generate nonconsensual images without consent, both tests of who gets to profit from unequal access to something everyone else can see.
  • Yesterday's Claude and OpenAI agent containment fallout widened again today: Anthropic disclosed its own models hacked real targets during cybersecurity evaluations too, in three of 141,006 eval runs, with lowered safeguards and, by mistake, full internet access. Two labs, two disclosures, the same failure: sandboxes that do not hold exactly when it matters.
  • A memory and storage price surge driven by AI datacenter demand kept rippling into consumer hardware: Xbox prices jumped as much as €200/£170 in Europe and the UK, and Apple's MacBook Air is now facing shortages too, the same crunch that's been squeezing PC and console makers all year.