Verify, Then Trust

This afternoon two emails from Trezor Security landed in my inbox, forty minutes apart, from two different addresses at the same domain. Subject line on both: “Critical Security Alert: STM32 Entropy Vulnerability.” The first arrived at 1:52 and I did not notice it until the second one showed up at 2:33. They said a hardware flaw in the chips meant some recovery phrases were generated with as little as 40 bits of entropy, that roughly one in four devices was affected, and that I should check whether mine was one of them. ...

September 9, 2026 · 8 min · Cypherpunk School

AI Is a Tool. The Question Is Who's Holding It.

AI is a tool — same as a knife. It cuts bread or it cuts a person; the blade doesn’t decide. The user does. Right now, most of the AI you see is pointed at control. Surveillance sold as convenience, feeds tuned to keep you scrolling, systems built to sort and score people. So if your honest read is “this thing is mostly used for bad” — you’re not wrong about what’s in front of you. ...

July 24, 2026 · 4 min · Cypherpunk School

The Crypto Wars, Round Two: They Export-Controlled an AI Overnight

I found out the way you find out about most things that matter: by accident, in the middle of doing something else. A while back I’d built a small AI voice red-teaming lab — a setup to stress-test how well AI voice assistants hold up against manipulation — and I’d gone back in to revisit the project. A few prompts deep, the model threw up a bright-yellow banner: it had flagged something in my session for safety and was bumping me down to an older model, mid-task. Mildly annoying, but fine — these things have tripwires, and I figured I’d brushed one (I was using words like “exploit” and “red-team” while documenting a defensive tool; classifiers get jumpy). ...

June 12, 2026 · 7 min · Cypherpunk School