In short
Tech/business roundup focused on frontier AI releases and platform economics. Main segments: Meta’s new AI model Muse Spark (closed model) and how it fits Meta’s open-source strategy; Anthropic’s Mythos and its gated cybersecurity-focused rollout; market reaction and “token/vibe coding” implications; plus consumer robotics (Loom robot lamp) and a Bitcoin origin story.
Guests (backgrounds)
Luther Lowe, Head of Public Policy at Y Combinator (Washington, DC). Other names appear as hosts/participants in the episode title but the transcript only includes Lowe’s interview.
Key claims
- Meta launched Muse Spark, its first major model in over a year, and it is closed (not open-weight), powering Meta AI features.
- Meta’s open-source approach is strategic: open-source helps commoditize complements and accelerates product adoption, but Meta may stop when cost/safety/ROI thresholds are hit.
- Muse Spark shows strong benchmark highlights but also underperforms on some tests (e.g., ARC-AGI-2), raising “chart crime” concerns about model cards.
- Meta also shut down an internal employee “token dashboard” after data was shared externally (reported 60T tokens over 30 days).
- Anthropic’s Mythos is gated to ~50 critical-infrastructure companies due to strong zero-day/exploit-finding ability; skepticism exists about Anthropic’s safety messaging.
- Apple/Google app-store control is a bottleneck for “vibe coding” app distribution; Lowe argues for anti-self-preferencing policy (BASE Act).
Notable examples
- Muse Spark joke interaction (model suggested “Malibu surf puns” despite claims of no personal data access).
- Mythos partner list includes major tech and security firms (e.g., Microsoft, Google, CrowdStrike, Palo Alto Networks).
- Loom robot lamp demo: a humanoid robot that folds laundry and makes the bed.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VOMarket Overview and Ceasefire Impact
0:45 to 1:49
Discussion on the stock market performance influenced by recent geopolitical events.
“Alex Wang, the chief AI officer at Meta Platforms, announced a new large language model today, its first major new artificial intelligence model in more than a year.”
Meta's New AI Model Announcement
1:49 to 3:38
Explaining the launch of Meta's AI model Muse Spark and its market implications.
“He wrote this maybe three or four years ago.”
Open Source vs. Closed AI Models
3:38 to 6:20
A deep dive into Meta's shift from open-source to closed AI models and its strategic reasoning.
“a lagging edge model that requires just a few percent of Meta's 40 billion in CapEx is easy to open source.”
Future of AI Models and Cost Considerations
6:20 to 7:25
Discussion on the future of AI models and the financial considerations for Meta.
“There's plenty where it's underperforming.”
Meta's Model Development Insights
7:25 to 9:06
Insights into the development and benchmarks of Meta's AI models.
“Yeah, this also, I mean, that feels like...”
Benchmarking and Market Competition
9:06 to 11:35
Analyzing the performance of Muse Spark compared to competitors and the significance of benchmarks.
“Yeah, and of course, like, Meta is going to be hyper aware.”
Meta's Internal Dashboard and Token Usage
11:35 to 12:42
Updates on Meta's internal dashboard for tracking AI token usage and its implications.
“You kind of need to talk to these things for a long time before you can actually get the vibe.”
Muse Spark's Market Positioning
12:42 to 14:01
Evaluating Muse Spark's performance in the AI landscape and its competitive standing.
“I think Alexander Wang talked about they're going to train bigger models.”
Meta's MuseSpark Model Announcement
14:01 to 15:00
Discussion on Meta's new MuseSpark model and its performance metrics.
“but due to data from this dashboard, Being shared externally, we've made the decision to shutter it for now.”
Market Reactions to Meta's AI Release
15:01 to 17:10
Analysis of the stock market's response to Meta's performance claims and AI developments.
“I just saw the news that the Wall Street Journal is reporting that the straight-up-form moves might actually be closed again.”
Show all 61 chapters
Anthropic's Mythos Model Insights
17:11 to 19:30
Deep dive into the capabilities and implications of Anthropic's Mythos AI model.
“You know, There was a quick debunk on this.”
Cybersecurity Implications of AI Models
19:31 to 21:42
Exploration of how advanced AI models like Mythos could impact cybersecurity practices.
“and some stories about breaking out of a variety of, what do they call them, walled gardens or test environments?”
Debate Over AI Model Accessibility
21:43 to 24:00
Discussion on the decision-making process behind releasing powerful AI models and their societal impacts.
“that was something to the effect of like, okay then if it's so good go cure cancer.”
Future of AI in National Security
24:01 to 27:43
Considerations on the role of AI technology in national security and cybersecurity improvements.
“Anthropics has reasons to not make mythos widely available beyond a lack of compute.”
The Future of Mythos and National Security Models
28:00 to 29:50
Discussing the implications of Mythos on national security and model accessibility.
“And so hopefully if the war comes to an end and there's different discussions can happen and ice can thaw and there's a way for these companies to work together.”
Critique of Fundrise and Market Dynamics
29:50 to 31:20
Examining Fundrise's ad strategies and the implications for private tech investment.
“People, Tenebra says, people keep talking about this like it's not blatantly obvious.”
AI's Impact on Culture and Decision Making
31:20 to 32:50
Exploring AI's potential to enhance human creativity and decision-making.
“it depends how bullish you are on the names, but it's going to be very, very hard assuming that normalizes over time.”
CIA's Ghost Murmur Technology
32:50 to 34:00
Understanding the CIA's use of quantum magnetometry and AI for locating individuals.
“Players started developing moves that were distinct from both previous human moves and from the novel moves introduced by machine intelligence.”
Mystery of Satoshi Nakamoto Unraveled
34:00 to 36:08
A deep dive into the identity of Bitcoin's creator through recent investigations.
“The CIA used a secret tool called ghost murmur to find airmen in Iran.”
Luther Lowe on Vibe Coding and Tech Advocacy
41:33 to 42:00
Luther discusses his role in advocating for tech founders and the future of app stores.
“So, yeah, I'm the head of public policy for Y Combinator.”
Navigating the Vibe Coding Landscape
42:00 to 45:30
Exploration of the challenges and opportunities in vibe coding and app development.
“but little tech doesn't have a seat at the table.”
The Control Dilemma of Apple
45:30 to 48:50
Discussion on Apple's control over app submissions and its impact on developers.
“But just in terms of like, I want a special recipe app and I Vibe Code it and I want to get it on my phone and I want to send a link to the App Store page to a friend.”
The Future of AI Assistants
48:50 to 51:55
Debate on the potential for third-party AI assistants and the limitations of Siri.
“Because that feels like the logical analogy and what, as an Apple consumer, I would like.”
Policy and Entrepreneurship in Tech
51:55 to 56:00
Insights into the role of government policies in fostering tech entrepreneurship.
“Like, you know, something's got to give you.”
Thoughts on Tech Talent and AI Competition
56:00 to 56:49
Discussion on the importance of tech talent and AI competition in innovation.
“I think that that's where if I could change anything, I would say they could do a little bit better.”
Insights from Kalshi CEO Tariq Mansour
56:51 to 59:31
Exploring the differences between traditional sportsbooks and Kalshi's prediction markets.
“We have an exclusive clip from his interview with Kalshi CEO Tariq Mansour on the Axios show, which we will be discussing with Dan after we play it here.”
Legal Landscape for Prediction Markets
59:31 to 1:01:55
Discussion on the legal challenges and future of prediction markets in the US.
“It's the reason why they have elections on the platform.”
Congress and Prediction Market Regulations
1:01:55 to 1:04:15
Exploring potential legislative actions affecting prediction markets and gambling.
“I don't really care what the back end looks like.”
User Engagement and Sports Betting Dynamics
1:04:15 to 1:10:01
Analysis of user engagement in prediction markets versus traditional sports betting.
“bunch of different kind of rule sets around it, even in places where gambling is legal.”
Understanding Sports Betting vs. Prediction Markets
1:10:01 to 1:11:05
Learn about the differences in regulations and user experiences between sports betting and prediction markets.
“And specifically, every bet on Cal sheet goes to the CFTC and has to get approved, and CFTC has 24 hours to approve it.”
The Addictiveness of Gambling and Social Media
1:11:07 to 1:12:34
Explore the parallels between gambling addiction and social media's impact on behavior.
“Just so it feels like we all just agree that gambling is addictive.”
Legal Implications of Social Media Addiction
1:12:36 to 1:13:40
Discuss the recent legal proceedings regarding social media addiction and potential class actions.
“the actual fines for YouTube and Meta seemed very low, but it was the whole chain of more cases coming.”
Trends in Venture Capital Amid Economic Changes
1:13:42 to 1:14:56
Examine the current state of venture capital, especially in the context of AI and Middle Eastern investments.
“We were going back and forth on the impact of gold money.”
The Future of IPOs in the Tech Industry
1:14:58 to 1:16:06
Analyze the current landscape and challenges facing IPOs in the technology sector.
“The IPOs of SpaceX, Anthropic, and OpenAI this year, right?”
The Impact of Data Center Regulations on Investments
1:16:07 to 1:17:19
Investigate how proposed bans on data centers are affecting energy deal-making and investments.
“Yeah, I'm thinking like the Rippling and the Deals.”
Defense Tech Investment Strategies Amid Global Conflicts
1:17:20 to 1:20:03
Delve into the dynamics of defense tech investments and how global events influence funding.
“I mean, Sanders on the national level, you're not going to get anywhere nationally on this.”
The Evolution of AI and Investment Strategies
1:24:00 to 1:24:47
Explore the progression of AI technologies and investment approaches in tech.
“And naturally, when we made the investments in 2015, we didn't know AI will exist.”
High-Precision Metal Manufacturing at Vulcan Forms
1:24:47 to 1:25:56
Understand the innovative techniques being used in metal manufacturing.
“physics, start with physics in the case of Vulcan Forms, we are manufacturing high precision metal parts.”
Investment Philosophy and Company Involvement
1:25:56 to 1:27:19
Learn about the investment philosophy and operational involvement in startups.
“I imagine you take board seats, you lead rounds.”
The State of Robotics: Hype and Reality
1:27:19 to 1:28:56
Discuss the current landscape of robotics and its market perception.
“Where do you think robotics is overhyped and where do you think it's underhyped right now?”
Expectations for the Upcoming IPO Window
1:28:56 to 1:30:41
Delve into the expectations for IPOs and market trends in tech companies.
“And a lot of us did robotics much before in our operating life.”
The Future of the Space Economy
1:30:41 to 1:31:58
Examine the emerging opportunities within the space economy.
“Yeah, what are you tracking in terms of trends in the lunar economy?”
Building Companies in a Transformative Era
1:31:58 to 1:32:45
Discuss the excitement of building innovative companies during pivotal times.
“We are partnering with an amazing company called True Anomaly, the building space defense prime.”
Analyzing the Axios NPM Package Hack
1:33:02 to 1:35:46
Investigate the details and implications of the cybersecurity incident.
“NPM, of course, Axios NPM was downloaded 100 million times per week, and it was compromised by North Korean threat actors.”
The Mechanics of the Supply Chain Attack
1:35:46 to 1:38:06
Understand how the supply chain attack was executed and its broader effects.
“And, you know, by the way, they also developed a relationship over the course of weeks.”
Cybersecurity Breaches and Their Impact
1:38:06 to 1:42:30
Learn about recent cybersecurity breaches and the implications for companies.
“that has been happening really over the last six months in a really intense manner.”
The Role of Software Supply Chains
1:42:31 to 1:45:06
Understand the challenges posed by open-source software in security.
“I mean, it seems like you're getting a lot of calls from companies and boards.”
The Asymmetry of Security Efforts
1:45:07 to 1:47:44
Explore the advantages attackers have over defenders in cybersecurity.
“And, you know, it's finding vulnerabilities all across the software supply chain.”
Economic Impact of Cyber Attacks
1:47:45 to 1:50:14
Evaluate the economic consequences of cybersecurity incidents and industry responses.
“Because it felt like the number could have been very huge, but a lot of people were able to get to it fast enough that there wasn't necessarily a massive crypto breach or a massive PII breach.”
Building a Model for Software Security
1:52:00 to 1:54:07
Learn about the innovative approach to software security models and their importance in AI.
“We also work with really fast-growing startups, ranging from companies like Lovable, ClickUp, Superbase, the top names in tech.”
Mythos News and Its Implications
1:54:08 to 1:55:29
Discover the significance of Mythos news in the context of AI security advancements.
“It seems like really remarkable results in bug finding and vulnerability tracing, lots of partnerships.”
Vulnerability Detection Strategies
1:55:30 to 1:56:48
Explore different strategies for vulnerability detection in software applications.
“And it seems like they were able to find a lot of different stuff by just throwing every possible hacking technique at every possible open source repo.”
Partnerships and AI Development
1:56:49 to 1:57:46
Learn about the partnerships in AI security and their impact on software development.
“We need more white hat hackers than ever, very clearly.”
The Workflow of Closing Customers with Mutiny
1:58:12 to 1:59:48
Understand the workflow involved in closing sales and how Mutiny enhances this process.
“And yesterday we announced the new Mutiny, which is an AI agent that companies like Rippling and Snowflake use to create anything customer facing in order to get a deal from cold all the way to closed.”
The Origin of the Raccoon Mascot
1:59:49 to 2:01:08
Hear the fun story behind Mutiny's raccoon mascot and its significance.
“You know, the mission of Mutiny was all about killing the dependencies and go-to-market teams.”
The Challenges of Cold Email Outreach
2:01:09 to 2:05:14
Discuss the effectiveness of cold emails in modern sales strategies and alternatives.
“And the entire time we were there, we had six bottles of wine with us and basically no supplies.”
Mutiny's Recent Funding Success
2:05:15 to 2:05:47
Celebrate Mutiny's recent funding and its implications for the company's future.
“We hire people that are aligned with our values and we just let them be themselves.”
The Challenge of Cybersecurity and AI Scams
2:06:25 to 2:08:25
Jeremy discusses the evolution of cyber threats and the importance of AI in combating scams.
“you said he left meta to focus on ai scams which kind of sounds like you're scamming but i'm assuming it's the exact opposite.”
The Need for Proactive Defense in Cybersecurity
2:08:25 to 2:10:06
Jeremy emphasizes the importance of training and proactive measures to prevent cyber attacks.
“And so the core premise is that in an AI-powered world, all phishing becomes spear phishing.”
Innovative Tools for Cybersecurity Defense
2:10:06 to 2:12:30
Discussion on Jeremy's product, Agent Charlie, and its capabilities in real-time cybersecurity.
“Create the viruses, sell the anti-virus.”
Company Structure and Future Plans
2:12:30 to 2:14:28
Jeremy shares insights about his company's growth, funding, and future vision.
“and maybe an AI model could be listening in the background and sort of throw up a flag like, hey, it's actually there.”
Transcript
Automatic transcript. May contain errors.0:01You're watching TBPN. Today is Wednesday, April 8, 2026. We are live from the TBPN UltraDome, the temple of technology. The fortress of finance. The capital of capital. We got white suits on. You know what that means. The stock market is booming. The Dow Jones is up 2.68%. The S &P 500 is up 2.46%. The Nasdaq is up 2.9%. And there's a bunch of other stocks that are moving within that. Of course, this is on the back of the very good news that there has been a ceasefire, that the street might be opened. Of course, it's all back and forth. The front page of the Wall Street Journal is covering all of the geopolitical moves.
0:40But we're here to talk about tech and business, of course. And the big news today is that Meta Platforms has launched a new AI model. Alex Wang, the chief AI officer at Meta Platforms, announced a new large language model today, its first major new artificial intelligence model in more than a year. The rollout of the model, called Muse Spark, is a critical moment for Meta, which is up 7.5 % already, which has spent billions of dollars hiring AI talent in a bid to catch up to OpenAI. Anthropic and Google DeepMind, the leading labs have been putting out models at an accelerating pace. In a departure from its previous models, which were open source.
1:21Muse Spark is a closed model that will power Meta's AI chatbot and AI features within it. John Ludig has a very interesting post about open source AI and sort of predicted this. I can pull that up at some point. We can find. Predicted that Meta would eventually bail? Yeah. Let me find it. The future foundation models is closed source. Let me see if we have this here. He said, Given Meta is the primary deep-pocketed, large open-source model builder, open-source AI has become synonymous with Meta AI. He wrote this maybe three or four years ago. So the operative question for open-source AI is, what game is Meta playing?
1:59In a recent podcast, Zuckerberg explains Meta's open-source strategy. One, he was burned by Apple's closeness for the past two decades and doesn't want to suffer the same fate with the next platform shift. It's a safer bet to commoditize your compliments. He likes building cool products and cheap, performant AI enhances Facebook and Instagram. That's 100 % true. We've seen this in the ads product and the growth there. There's some call option value if AI assistants become the next platform. And that makes sense in Manus and the Meta AI app. He bought hundreds of thousands of H100s for improving social feed algorithms across products.
2:32And this seems like a good way to use the extras. That all makes sense and Llama has been great developer marketing for Facebook. But Zuck also suggests several times that there's some point at which open source AI no longer makes sense, either from a cost or safety perspective. When asked whether Meta will open source the future$10 billion cost model, the answer was as long as it's helping us. At some point, they'll shift their focus towards profit. And that's what John Ludig wrote. When did he write this? This was May 20... That was 2024. Man, time flies. Barely just under two years ago. He says, unlike the other model providers, Meta is not in the business of selling model access via API, so while they'll open source, as long as it's convenient for them, developers are on their own for model improvements thereafter.
3:16That begs the question, if Meta is only pursuing open source insofar as it benefits themselves, what is the tipping point at which Meta stops open sourcing their AI? Sooner than you think, he says. Exponential data frontier models trained on the corpus of the internet, but that data is a commodity. Model differentiation over the next decade will come from proprietary data, both via model usage and private sources. Exponential CapEx, he highlighted this two years ago, a lagging edge model that requires just a few percent of Meta's 40 billion in CapEx is easy to open source. No one will ask questions.
3:45But when you reach$10 billion or more in CapEx spend for model training, shareholders will want clear ROI on that spend. The metaverse raised some question marks at a certain scale too. Diminishing returns on model quality within Meta. There's a large upfront benefit for Meta building an open source AI model, even if it's worse than the frontier closed source counterpart. There are lots of small AI workloads. Think feed algorithms, recommendations, and image generation where meta doesn't want to rely on a third-party provider like they had to rely on Apple. And so the news has been back in December, there was a reporting that Alex Wang disclosed an internal company Q &A that his team was working on two new models.
4:26One was this text-based LLM codenamed Avocado, and then a separate model that was for image and video. Mango. Yeah. And so have they clarified if this is Avocado? This feels like what Avocado should be, this Muse Spark. Is that what it's called again? Yeah. Muse Spark. I see what it is. I don't know what else. So the image model should be coming soon. The question that I had was, will a code-focused Agenta coding harness be a separate model, a different train? It feels like it's not a coincidence that this news is dropping on the heels of Anthropix new model Mythos, which sort of was announced loosely and the model card dropped yesterday, even though the model is not available yet to play around with.
5:12Yeah, so going through, I think it's worth pulling up the actual model card here. Sure. so we can have it on the screen uh but they break out muse spark thinking against opus 4 6 max gemini 3.1 pro high gbd 5.4 x high and then grok 4.2 and uh the way that they position it it looks uh uh there was of course some people saying that it was a somewhat of a chart crime but if you look uh when you basically look at the top and you say that muse spark is gets an eight 86.4 yeah and it's in blue and then you look over and it's outperforming all the other models on that benchmark. You just sort of assume that the highlighted blue means that it's outperforming.
5:59Oh yeah, but it's not Frontier at MMLU. Because there's a bunch of them as you get further and further down. So like ARC AGI 2, Muse Spark dramatically underperforms the other leading models. And there's, you know, again, a number of others where it is, there's plenty where it's overperforming. There's plenty where it's underperforming. I, of course, we started asking it jokes right away. So I'll pull up the joke. I said, tell me a joke. And it said, gotcha, here's one for you. Why don't skeletons fight each other? they don't have the guts okay but then it doesn't even let me react it just says want a different vibe i've got dad jokes nerdy ones or malibu appropriate surf puns too and so i'm like wait why would you think i want malibu appropriate surf pun if you look in your previous chats i have i have no previous previous chats what about uh because meta ai and so instagram so when you search on Instagram, sometimes that prompts Lama or previous.
7:10Yeah. So I'm trying to get to the bottom of it. Right. Like this feels like an oddly specific type of joke to ask me. And so I said, why would you think I want Malibu appropriate surf funds? Haha, fair call. Toss that in without you asking for it. I try to mix in different flavors of jokes and surf puns just popped into my head as a random option. No special reason behind it. I just said, I don't believe it was random and it says you got me you got wasn't my smoothest moment but then it denies it again weird it says it's just like what kind of what kind of joke do you actually want no hidden motives here i said you gave a hyper specific example based on my life so i have to assume you were looking at my other account for inspiration instagram i get why i get why that felt weird i'm sorry it came off that way and then it denies it again i said you're clearly lying i mean you have talked about being in malibu on the internet for a full year it's possible it got baked in the pre-training or something.
8:06I don't know. Maybe. Yeah, this also, I mean, that feels like... But when I said, what can you tell me about myself? I said, I don't actually have access to personal details about you beyond what you share with me right here in this chat. That's very odd because the whole thesis of like personal super intelligence should be, hey, we're the best model that actually does plug into your entire life and your DMs and your Instagram and your likes and your preferences and everything that you have done across meta platforms for a very long time. We're gonna bring that in a really fun and delightful way and and telling a joke that is tailored I used to get jokes like that where I would ask for a joke and it would be so I've talked about this It would be something like oddly specific about my car And I was like, I don't that's that doesn't actually make the joke better But it's cool that you're remembering this whole personalization boom happened last year.
8:53I get those About like AWS really like specific services. Oh because you've been like querying asking questions when i was like debugging stuff yeah yeah but so i ran you know my favorite bench yes yes shrimp fried rice bench how do you do it by the way noah noah hirshfield said uh doesn't know your name i said what's my name i don't know your name unless you tell me smiley face it definitely knows your name but yeah i mean what is personal super intelligence if it doesn't even know your name like that that feels like they haven't dialed in the the the the harness or whatever the tuning is to actually tune responses.
9:32Yeah, and of course, like, Meta is going to be hyper aware. We don't want a PR cycle. Yeah, yeah, yeah. Like, they trained on your data, right? Everyone's been, oh, that ad was a little bit too close to home. And you remember every once in a while, one of those, like, things, a screenshot that's been screenshot, like, a thousand times, like, goes viral. And it's like, I do not give Mark Zuckerberg per... Oh, yeah. Yeah, yeah, yeah. Like, that works. Yeah. It's hilarious. This is, is this a rebuttal to the bench hacking allegations that happened last week, or last year? So where was the, so according to Meta's internal benchmark test, MuseSpark outscored Google Gemini on some tests and was competitive with models from OpenAI and Anthropic on others.
10:20It significantly outscored XAI's Grok on most tests. Alexander Wang's hiring followed the disappointing release of Meta's previous model called Llama 4. The company was accused of and later admitted to gaming a third party benchmark that it used to rank various models against each other on performance. It also delayed the rollout of its biggest model called Behemoth, which it never ultimately released. And so when I look at a model card like this, where you could call it a chart crime where, you know, it's highlighted in blue and it feels like it's the best, but it's actually, you know, doing better on some.
10:54It does well on Health Bench hard. It underperforms on ArcGIS2, as you mentioned. But this maybe is the bull case here is that they have at least moved on from the culture of like optimizing for the benchmarks. Right. Isn't that a good thing? Yeah. I mean, I remember there are rumors about them. like there was like extra bonuses if they if they got number one on Elam Arena. I think that was like something like the rumor. Yeah. But yeah, I mean, you've seen a lot of the labs kind of move away from benchmarks generally, because I think they're just not that meaningful anymore. Like a lot of them are like basically so saturated.
11:28They're all it's like they're competing between 89 and 91 percent. Yeah. And they're just like not very meaningful. Like you see. And you won't like actually feel that in the product necessarily. Yeah. You kind of need to talk to these things for a long time before you can actually get the vibe. Yeah. But I do think this news is very interesting in the context of the, you know, Claudeonomic stuff. The dashboard, yeah. Because like, okay, what does it mean if the entire company has been like maxing their Claude tokens over the past month? It means that they weren't using this model. Yeah. To me, it means they need to commoditize their complements, right?
11:59They need to bring down that cost potentially. And if they're, I mean, we sort of, you know, dug into, are they spending a billion a month seems like absolutely not, but they're clearly spending a lot, and if you can turn that OPEX into CAPEX and train your own model and then inference it much cheaper on your own hardware, that feels like just an economic opportunity that makes a ton of sense in the context of just 10 ,000, 20 ,000 engineers writing a lot of code Yeah, and I think there's basically two ways to square those two things happening. Either one, this model is not that good because the engineers aren't using it or your theory that they're just distilling cloth.
12:41That is not my theory. That is the schizo theory. I believe the 401, right, is true. This model still doesn't feel that big. I think Alexander Wang talked about they're going to train bigger models. They're training them right now. So I'm excited for those. I think I'm especially excited for the video models. They should have incredible training data. We've seen really good progress from VO3. This model is very competent. It's with the Frontier models. Maybe it's not the best one. It's like among the top five or whatever. And none of the other big labs have, I guess that's not true. Like Google right now is definitely ahead in images.
13:16OpenAI, I think is, they're releasing a new image model soon, it seems like there's been rumors of this. Yeah. The image two popped up on the arena? Yeah, on the arena. It's always like the code name coming out. The photos just looked photo real. It didn't look like AI imagery anymore. Yes. So if like a meta has like similar capabilities, but they have this incredible data set. Very excited to see what comes out there. The news this morning, meta platforms and the information. Meta platform has taken down internal employee-built leaderboard, tracking how many token staffers were using. Showed total usage over a recent 30-day period, amounted over 60 trillion tokens.
13:55The dashboard now displays a message that is offline. It says, we've really enjoyed building this app on Nest for everyone. It was meant to be a fun way for people to look at tokens, but due to data from this dashboard, Being shared externally, we've made the decision to shutter it for now. It seemed like a fun side project. Mike Isaac was reporting on it here. He said it's down. Unclear to me if this was a homespun one by employees or an official one. Employee projects come and go frequently. Conspicuous timing, though. But, yeah, you don't want to have, you want to measure the output, the impact, not necessarily the input and how much is going on there.
14:32What else is going on? Lisan Al-Ghaib says, Meta might actually be back with MuseSpark, still behind OpenAI, Anthropic, and Google, but ahead of XAI and Chinese Labs. MuseSpark stores 52 on the Artificial Intelligence Analysis Index, behind only Gemini 3.1 Pro, Gemini GPT 5.4, and Claude Opus 4.6. MuseSpark is the first new release since Llama 4 in April 2025, and also Meta's first release that's not open weight. So a huge jump up in performance across a variety of benchmarks. So all good stuff there. What else is? And the market is thrilled. Oh, thrilled. Absolutely thrilled. I just saw the news that the Wall Street Journal is reporting that the straight-up-form moves might actually be closed again.
15:19So I would imagine a kangaroo market for the near future. No, the market is thrilled that Meta has released a close to frontier level model, right? This is a new group. They've been at it for less than a year. The stock is up almost 8 % today. And again, so much of the pricing pressure, the downward pressure on Meta has just been kind of uncertainty on what all these tens of millions of dollars will actually go towards and what will be accomplished. And still unclear, like, you know, is this, are they going to go after Cogen at all? Are they just going to try to compete on the consumer LLM side?
16:03And can you economically go after Cogen if you're just using it for internal models? If you're not selling it externally, can you justify the CapEx just purely on the internal usage? Having this model be vended into all the different family of apps makes a lot of sense because they have billions of users that will wind up interacting with this in one way or another. The CodeGen thing, you have to wind up being more in this personal super intelligence. We've talked about Manus and what it might be able to do for you across Instagram, across Facebook, across WhatsApp. I don't know. Yeah, the question is, will they try to send MetaVibes?
16:42Again, with the new model? All the way up to the top of the App Store charts. Yeah. I mean, the previous, actual model was mid-journey under the hood, right? And so that was sort of a quick launch to demo what they were thinking, you know, mixing the music library, which was cool. Yeah, like that had nothing to do with the new like class of AI researchers. Mango, yeah. But yeah, I mean, there was a lot of weird back and forth and news about is Alex Wang getting kicked out? You know, There was a quick debunk on this. Andrew Bosworth came up and said, no, this is completely incorrect. We're very happy with the progress and the team and what we're building there.
17:23And so it seems like they got it out the door and it's been doing well. Meta's new family of AI models can reach the same performance as Kimi K2 with only 30 % of compute and only 10 % of the compute to reach Llama 4 Maverick, so a much more efficient computing frontier here. They completely rebuilt their pre-training stack with improvements to model architecture optimization and data curation. And so more facts. Metaspark is an early data point on our trajectory, and we have larger models in development. So the mythical 10 trillion parameter model. That is the 10T is what everyone's working on right now, 10 trillion.
18:05Yeah, probably in that range. Yeah, it's all rumored at this point. Yeah, rumored GPT-4 was something like a trillion, right? You remember those memes where it's like a small circle and then the big circle? And then the huge circle. GPT-4, GPT-5. Yeah. But yeah, lots of other work that went into it. And Martin Cassato has a little bit more context on what actually unlocks new capabilities in AI models. He says, Mythos appears to be the first class of models trained at scale on Blackwells. Then there will be Vera Rubens. Pre-training isn't saturated. narrative violation rl works and there's so much computing coming online soon buckle your chin straps it's going to be wild uh the scaling laws you know brad gerstner had to come in with a hundred hundred yep for sure uh yeah there's a there's a crazy bull case for nvidia in the information uh arguing it should be worth what 22 trillion dollars that is a wild move uh there's there's a lot going on uh the scaling laws holding is the most important articles from the information finance nvidia worth 22 trillion this old school financial model says yes uh so um uh yeah the big news on uh uh yesterday was um uh anthropics new model mythos some really impressive statistics and anecdotes yesterday both the model card the benchmarks and some stories about breaking out of a variety of, what do they call them, walled gardens or test environments?
19:44What are those called? Breaking out of the, I don't know, the simulation. Sandbox. The sandbox, yeah. Breaking out of the sandbox, sending emails, all sorts of stuff like that. The model preview is only available right now to about 50 companies that maintain critical infrastructure because the model is particularly good at finding zero days, bugs and exploits in technical systems. And if they leak that out before big companies have time to go and address all the bugs, there could be serious ramifications for cybersecurity. And so key partners include Apple, Google, Microsoft, Amazon, NVIDIA, JPMorgan Chase, Broadcom, the Linux Foundation, Cisco, CrowdStrike, and Palo Alto Networks.
20:28They're all listed on the cybersecurity focus page for Project Glasswing. Chris Bakke was having a little bit of fun because he noticed Anthropic put their own logo on the partner page, which is a little bit funny, but at the same time, it's kind of smart because a lot of people are just going to see the image quickly. And it's good to position yourself with the other companies. Yeah. So, yeah, it is interesting. I mean, people have predicted that AI models would be particularly good at cyber attacks. and this was one of the main sort of vectors of AI fears. It feels like this is what maybe what Dario was referring to when he was talking about the end of the exponential finding and exploiting software bugs.
21:08It's sort of perfectly in the sweet spot for coding agents and reinforcement learning. Combing through piles of code, tirelessly trying different exploits to find bugs, having a clear verifiable reward. Did you crash the system or not? did you break into the system or not. This is very, it's a very clear binary signal that you can send to the model to determine were you successful in breaking into that system? And it requires basically no time delay, there's no lag. So there was one snarky tweet I saw that was something to the effect of like, okay then if it's so good go cure cancer. But any application that requires a real world feedback cycle, even if it's just a few minutes of human interaction in the cancer example, you know, you're going to need to be testing the drugs in vitro in mice, in monkeys, in humans at some point.
22:03Or even if you're just sequencing DNA or doing anything in the lab, pipetting anything, if it's even just a few minutes, all of a sudden every iteration, every attempt is going to take a few minutes and that's going to put you on just a wildly different exponential as opposed to being able to spin up a virtual machine with basically every single piece of software out there and then try every single exploit against every single piece of software and you wind up with a ton of exploits. And very, very bullish for cybersecurity that this is being done preemptively. There's a whole bunch of different discussions.
22:39Ben Thompson has a good piece on the whole decision to release the model or not and stage it out and the go-to-market there. But it's even if the bio research, the other impacts are on sort of a slower exponential, there's still so much opportunity in even a software-only singularity. There's also risk in a software-only singularity. We've seen this story before, though, a model that's too powerful to release but then works its way out and has pretty moderate impact on the world. This was the story of GPT-2, the story of ChatGPT, the question of, you know, is this the model that's dangerous to put in the hands of people?
23:24Yeah, a headline from February 22, 2019 by Aaron Mack. OpenAI says its text-generating algorithm GPT-2 is too dangerous to replace. Yeah, so there is a, I think Van Thompson called it like the boy who cried wolf syndrome. But the mythos wolf, he says, there's a lot of skepticism about Anthropics announcement. This tweet was representative from Buco Capital bloke. Anthropics marketing strategy is so funny. Like, ah, the government is treading on me. Ah, our models are so good, we can't release them. It would be too dangerous. Ah, someone stop me. I'm going to destroy the economy. The rolling of the eyes is exacerbated by the fact that Anthropics has reasons to not make mythos widely available beyond a lack of compute.
24:08Another factor is surely trying to avoid having mythos distilled by Chinese model makers. So there's actually two good reasons to gate access. And when you're looking at those logos, when you're looking at the world's largest tech companies, there's much more ability to scale rollout, demand, set pricing. These companies might be able to pay more. The model is very expensive. But if you're justifying that against bug bounties for zero day exploits in your most critical system, when you look at like JP Morgan Chase, it's a bank. Like what is the price of finding an exploit in that system? It's pretty high.
24:49It's probably clears the token hurdle a lot. And if the rollout is paced evenly across all the different companies, they'll all sort of understand that they're getting inference allocation at the efficient price that clears the cost to actually serve the model. So I do think the systems, all of these 10 trillion parameter models will be released soon, broadly. And the main reason that an AI that's smart enough to find zero-day exploits should be able to recognize that it's being used by a bad actor to find zero-day exploits. And it's only been a few months since the last flurry of competing models for OpenAI Anthropoc and Google.
25:32And the next cycle is already off to an aggressive start. We had Meta. And then the other news is that Elon Musk announced that he is getting ready to do another larger model with XAI. He's got a few. He's doing seven models in training. Wow. That is a lot. Imagine V2, two variants of one trillion, two variants of 1.5 trillion, a six trillion model and a 10 trillion model. He says there's some catching up to do, but he says he will never give up, never. So he is continuing to grind and train more models. What else was in the reaction? There was a whole bunch of other back and forth. People seem split.
26:16Mike from also Capital, former guest, says, we've decided not to release our latest investment strategy. It's so powerful. Releasing it might end the entire venture asset class as we know it. Yeah. He says, you should release it to a handful of trusted partners so that we can harden ourselves. And George Hott says, Anthropics marketing strategy, it's amazing. It's so powerful. It's terrifying. And the best part is you can't come. By the way, if Anthropic had any way to ship this, they would. Trained AI models are the fastest depreciating asset in history. GPT-4 cost$100 million to train two years ago and is now worth less than Quen 3.527B, 1 million.
27:01Sending the FOMO back. Clock is ticking, boys. It needs something like an NBL 72 to run a decent speed, and even absurd API pricing doesn't cover it. There's more to be made on investor hype than API access. I just wish for honesty instead of a whole fake spiel about safety. Who remembers when GPT-2 1.5b was too dangerous? And so lots of back and forth. Dean Ball has some more thoughts on Mythos. It's a longer post, so we'll let you go and read it. But the main take is just this is technology that, whether it comes from Anthropic or another lab, clearly needs to go into the supply chain of the world and in the U.S.
27:41government and the U.S. economy because no one is doubting, even though some of the exploits were somewhat minor, no one disagrees that we need less cybersecurity. We want the most secure systems possible. And we probably want a lot of competition between different companies to provide that service to the government. And so hopefully if the war comes to an end and there's different discussions can happen and ice can thaw and there's a way for these companies to work together. Even if the supply chain thing doesn't go through and then Anthropoc can vend technology through Project Glasswing, through CrowdStrike, through Oracle and other partners to Cisco so that at least the systems are secure because everyone wants that.
28:33Dean Ball has been on an absolute tear. We should have him back on the show and talk more. He says, a lot of people, including people in positions of authority, told us recently that models of Mythos' capability wouldn't be a thing, that models with obvious national security implications would not be forthcoming. Those people were wrong. There's nothing to do about it, but you should remember it. Mythos is the first model where theft of the weights by an adversarial actor feels like it would be a major deal. You better believe they will try, and if they don't succeed with Mythos, they will eventually.
Read the full transcript
29:00We are thoroughly in the era of the lab's best models may well not be in public the way they used to. This is because of a combination of compute constraints, economic reality, competitive advantage and safety concerns. Three means the most relevant models may be decreasingly legible to the general public. And depending on the extent and duration of the coming compute squeeze, we could enter a market dynamic where the best models are only available to the highest bidder. And of course that makes sense from a KYC and security perspective. In other words, where compute is a seller's market rather than a buyer's market.
29:31Interesting. Imagine competing firms in the economy bidding against one another for access to the best and most tokens and the frontier labs as, in essence, kingmakers. The governance regime I have described above in four is not designed to stop that dynamic. And so there is plenty of more takes. This was a full current thing cycle. People, Tenebra says, people keep talking about this like it's not blatantly obvious. Anthropa clearly has a system that's auditing open source repos for vulnerabilities using their unreleased higher power models and sending fixes for them without revealing their current level of capabilities.
30:06So they've been going around on GitHub and contributing pull requests to patch any vulnerabilities without disclosing exactly what model was being used. um uh burn hobart yes is not excited about uh fundrise we had the founder on running ads for vcx the public ticker for private tech uh this is he says paying for an ad encouraging people to pay 6x net asset value for a closed-end fund where the cost of borrow is 400 is one of the things people will remember during the next bear market. Yeah, I asked the founder of Fundrise about this, like how you kind of like, is there another iteration of the product that can solve for this?
30:57Fundrise like very clearly made a bunch of really good bets a few years ago. And the fund has performed incredibly well. But the issue now is like, if you want access to these names, and the only way that you have is to go through VCX, you're paying 6x what the actual private market investors are paying. And that just is like, I mean, it's, I don't know, it depends how bullish you are on the names, but it's going to be very, very hard assuming that normalizes over time. It seems extremely unlikely that it trades at an insane premium forever. Interesting that they're running this ad on Axe. I haven't seen, I have X Premium, so I don't see a lot of ads.
31:41I don't see any ads, but that does seem like the reasonable place to go to advertise a product like this. But yeah, it is always odd. There's been a whole bunch of these like treasury companies that have traded above net asset value. And it was always just a weird supply and demand dynamic. People want them and they're willing to pay way above. Hopefully they know the net asset value multiple and they're doing that willingly. I think consumer education, investor education is more of the critical question here. Well, Tebow over at Codex is unreasonably excited about things. The next few weeks will be intense and fun.
32:23And yeah, Michael Greenish says weeks, years. you know it's going to be an ongoing model mayhem for vague maxing vague maxing and yesterday a lot of stuff going on it was about token maxing today is about vague maxing yes yes let's go mickey friedman says the current fear is that ai homogenizes culture and turns humans into passive consumers one counterpoint in go human play showed very little improvement from 1950 to 2016 until AlphaGo beat Lee Sedol. Then human decision quality jumped. Players started developing moves that were distinct from both previous human moves and from the novel moves introduced by machine intelligence.
33:02This seems more likely to me. Fun times ahead. Lee Sedol is now a professor at UNIST. He is a special professor on a three-year term to conduct artificial intelligence research on Go specifically. he yeah if you haven't seen the go alpha go documentary it is fantastic Lisa Dahl go to smoke yes Lisa Dahl it is it is such a wild ride watching the deep mind engineers like you know it seems like they're genuinely surprised by the performance like no one really expected it but yes this is a very interesting chart to see how much things changed in the post AI era as people discovered new and interesting ways to differentiate from the models effectively.
33:56Yeah. Scoop from Stephen Nelson. The CIA used a secret tool called ghost murmur to find airmen in Iran. Ghost murmur pairs long range quantum magneto magnetometry. How do you say that? sensors with AI to find human heartbeats. I was wondering this while they were, over the weekend, there was, you know, a search going on. It was like, how do you find someone? How does somebody like, you know, an airman that's down send a signal that can be picked up by one group, but not? This is very odd. So there are some community notes on this saying that quantum magnetometry, I'm probably, I imagine that's how you pronounce it.
34:43that detects heart magnetic fields. And I believe this technology works in labs, but only up to a few meters, not 40 miles as claimed. Fields decay with one over R cubed, making long-range detection implausible. So unclear if this is what worked, but there has to be some sort of device that you could carry on your person, like in your shoe, like an air tag that can talk to a satellite almost. You look at the Starlink receiver dish, it would fit in a backpack, but that's very high bandwidth. I imagine if you had something, I mean, there's sat phones that are the size of large cell phones. That was available in the 80s and 90s.
35:30You have to imagine that if you're just trying to put out a signal to GPS or a Starlink network, you must be able to shrink that down significantly to the place where it could be carried on your body. but it's probably classified, so I would be surprised if, it's just very hard to read into what's real and what's not here. There is a different community note pushing back saying, no note needed, this new technology is a classified system developed in secret by Lockheed Skunk Works and the CIA that was just used, revealed publicly for the first time. Naturally, it's reported capabilities far exceeding the known public state of the art.
36:07The note is relevant. So it's, yeah, it's very, very interesting. But good to see some comments. All right, let's go over to Aaron Tan's post. Okay. It says, introducing loom, a lamp that does your chores. Order now shipping this summer. Let's see the video.
36:38That bed already looks fully made. What chore is it going to do? Just drop some laundry off. Oh, okay, you have to drop the laundry first? Wait, it can do that? Wait, does it have fingers in that? Like, what is it put on the record? Yeah, what is in the... You can see it has a little claw. Oh, it has a claw inside? Oh, okay. That is so funny to have a humanoid robot play music on a physical record.
37:12The folding t-shirt is the touring test of humanoids for real. Pixar lamp quaking in its boots right now.
37:34Nice video. Good color grade. Nice warm tones. Friendly. Doesn't feel dystopian. Feels delightful. Would you get one of these? I think we should get one. Yeah, like I, not in my house. I think we should get one. I think we should get one as a team. I do have some clothes over there on the wardrobe rack. Rooting for Aaron and the Loom team. Very, very unique form factor. I mean, I just think an impressive timeline for shipping. Hopefully, yeah, shipping. I'm reading this as like actually shipping, not shipping another site to order because you can order already. But, yeah, it'll be very interesting.
38:18if it can reliably fold clothing. It could be enough, right? So the benefit here is like people already want lamps, I'm assuming, for their bedroom. If you can buy a lamp that's reasonably priced and then it also has the benefit of just a simple thing like folding clothes, there could be a market here. Yeah, I feel like, I don't know, even just putting pillows back on the bed, even just like really basic things. I mean, even there are probably applications Like the Roomba did so well with such a minimal scope. There must be something. I wouldn't be surprised if even in between this and fully folding the clothes, just remaking the bed properly feels like something that consumers might actually pay for and allow for the flywheel to start spinning.
39:10Obviously, lots of security considerations since there's a camera there and whatnot. they'll have to do a lot of cybersecurity and figure out that. But people already have cameras all over their homes from NANIT and child monitors, baby monitors and that type of stuff. So I'm optimistic about this. And I think they did a great job promoting it. There is a story in the New York Times from none other than John Kerry Rue, who blew the story wide open on Theranos. He says, the mystery of Satoshi Nakamoto, the pseudonymous inventor of Bitcoin has remained unsolved for 17 years, not anymore. Read my 18-month investigation to find out who Satoshi really is.
39:53And he says it's Adam Back who posted directly, I am not Satoshi, but I was early in laser focus on the positive societal implications of cryptography, online privacy, and electronic cash. Hence, my 1992 onwards active interest in applied research on e-cash, privacy, tech on cypherpunk lists, which led to hash cash and other ideas. John Kerry Rue in his New York Times research finds like Aaron Van in his Genesis block book, many interesting Bitcoin analogs in the early attempts to create decentralized e-cash, in effect prototype ideas, trying to figure out a Bitcoin-like thing, including P2P, BGP, and proof of work.
40:36For his quote, I'm not saying I'm good with the words. I'm not saying I'm good with words, but I sure did a lot of yakking on these lists, actually. The broader context was my observation that because I was talkative on the list and known to have an active interest in eCash, there is some confirmation bias in finding my comments frequently on eCash topics. So he has said, we are all Satoshi. I am not Satoshi. But it's a very interesting story that will happen. You just created a million Satoshis. Truthfully, High Yield Harry's joking, Steve Buscemi has been revealed as the Bitcoin founder, not Satoshi Nakamoto.
41:11Well, we have our first guest in the waiting room, Luther Lowe from Y Combinator. He's the head of public policy, and we are going to be talking to him about Vibe Cody Luther. How are you doing? Hey, guys. Great to see you. Congrats on the acquisition. Thank you. Thank you. Great to have you on. Can you kick us off with a little bit of an introduction on yourself and what you do day to day at Y Combinator? Sure. So, yeah, I'm the head of public policy for Y Combinator. I'm based in Washington. And Gary created the role when he started at YC. And really, his observation many years ago was Gary and I had actually met in Washington.
41:49We were sitting around the table at some kind of White House meeting. And he said, you know, you go to Brussels, you go to Washington, and the largest tech companies have lots of representation. but little tech doesn't have a seat at the table. And that was actually the first time I'd heard that phrase, little tech. And Gary actually kind of coined that phrase. You went back and you look on X Twitter. He has had said that a number of times years ago. And so, you know, my role is to really like help the founders navigate Washington, Brussels, the state capitals, advocate for pro little tech issues in the broader ecosystem.
42:27and yeah, just really do everything I can to help the founders. And what is your view on Vibe Coding, the app store, the boom? We were talking about it yesterday. There's a whole bunch of stories of where it feels like we're getting close to the one person, absolutely massive company, whether that's GMV or revenue or something. It's like it's starting to happen. But I was looking at my home screen. I mean, I don't have an app that is new or vibe coded. Maybe it'll come in a boom in video games. But how have you been tracking? I mean, I'm sure you see this at YC. Just the growth of broad app development.
43:10Yeah, I mean, I think I would almost kind of take a step back. It sort of reminds me of when I first started geeking out on the Internet like 25 years ago, where you saw the rise of sort of what you see is what you get HTML-based or browser-based HTML editors. And that allowed anybody, that kind of democratized the process so anybody could create a web page or a website. And now we have tools that allow anybody to create a web service or an app. And so the difference, though, between now and 20 years ago is that today we have basically these two bottlenecks in the form of Apple and Google that sit between the creation and the potential users of those services.
44:00The Apple App Store is basically like the worst DMV in the world. And so we're seeing not only sort of, you know, there's reports all over X about this, but if you just barely kind of look around for it, you're going to encounter lots of folks that are trying to develop apps and services that are not being accepted or getting kicked out. And then it's not only that kind of like app layer, it's sort of the layer up of the tools like Replit and Anywhere that are facing, you know, the inability to update their apps. And so it's a real problem. Yeah. When you say the worst DMV in the world, Are you actually referring to, we saw a chart where the number of App Store submissions is spiking.
44:46It's going exponential. And that feels very logical because people, I mean, we've been building vibe-coded web apps here. The next step was, hey, maybe we should actually get one of these in the App Store. But very quickly we realized, okay, well, it's at least a two-week review process. It could be a lot of back and forth. It's a new hurdle. We need to, you know, actually compile it to Swift or Objective-C. It's a whole different process, probably doable on a technical side, but we might be hung up there. But are you seeing an issue with actually getting just a one-off Vibe Coded app approved?
45:24And then I think we should talk about the apps that help you Vibe Code new apps because that's a whole separate thing. But just in terms of like, I want a special recipe app and I Vibe Code it and I want to get it on my phone and I want to send a link to the App Store page to a friend. Is that slowing down? What's slowing that down? Is that going to be a permanent thing, or do you think Apple can just adjust there? Well, I think the problem with Apple, I mean, this is a sort of perennial issue with Apple, is their culture is one of just absolute control. And I think that we have reached this inflection point where, you know, if I've got my MacBook in my lap, I can open it up, I can download any app I want, I can open terminal.
46:09I can do all kinds of crazy mods. But the second that that form factor fits in my pocket, all of that freedom goes away. And I'm living in sort of North Korea in terms of what I can do with my stuff, with my property. And so I think that, you know, this is, you know, sure, I could launch something in TestFlight if I want some kind of little bespoke, you know, training app or something. But God forbid if I want to share it with friends or I want to, you know, make some money because I've created sort of a differentiated product that's actually interesting that people want, I've got to pay this ridiculous VIG to Apple.
46:47So for them, it's actually about the reason they want control is because it's about app store revenue. And also, they have competing products. It's an anti-competitive thing because they've got Xcode and they've got their own dev tools that they're starting to kind of roll out their own sort of vibe coding services. So the longer that they can kind of delay and slow roll both the developers and the tools that allow the vibe coders to create stuff. Your theory is that they want to basically make their own version of Replet or anything that they have total control over. And they can make the argument, they can probably make the argument that this is better for users, it's more secure, it's better for privacy, less malware risk, whatever it is.
47:35but they yeah anyways they give you they give you pretty meaningful autonomy over shortcuts and other things like that it's not that unbelievable that they would want to actually make something here but it's like embarrassing Syria is embarrassingly stupid we've had sort of LLM consumer facing services Sam brought them down from the mountain whatever almost three years ago And Siri still can't do basic subtraction. The other day I asked it for what was 17 days from this particular date. And it was like, do you want Google to consummate that query? Do you want ChatGPT to do it? It's like, why can't Siri do it?
48:22And so you've got all these just lots of energy. There's lots of YC companies that are trying to take a crack at creating Siri alternatives. But until kind of this self-preferencing is addressed, I think, at the sort of policymaking level, and it's not just Apple self-preferencing, it's Google, it's all of them, then we're not going to really be able to see the fruits of this sort of LLM revolution diffused into the hands of consumers. Do you think the side button to trigger the helpful assistant that is currently mapped to Siri and can interface with ChatGPT and is reportedly going to interface with Gemini soon, do you think that there's any actual chance that that becomes remappable at a pick your browser search engine level in the OS, even if it's defaulting to Apple's stack?
49:23Do you think there's any motion there? Because that feels like the logical analogy and what, as an Apple consumer, I would like. I'd like to be able to pick my assistant, but be able to assign the hardware button. But where do you think that actually goes? look i there is no uh technical reason why we shouldn't have a flourishing ecosystem of third party uh ai assistant developers competing to do all kinds of interesting stuff you guys should check out a yc company called blue it's heyblue.com they have this amazing demo on their website and they talk about uh and basically the guy's sitting in his car yeah and he's driving he's driving up the 101 and he's saying, hey, go through my Slack messages from last night.
50:08Okay, cool. Jerry needs a document. Get into Google Docs and share that with Jerry, but make it read-only. I like my third button having perplexity and being able to cue that, but if I can't access those deeper OS API commands, then it stops being that interesting pretty quickly. Anyway, the blue guys, what you learn, you're like, God, this is magic. How'd they do this? How'd they figure this out? you realize it's a USB-C dongle that they've basically 70 % of the company is hardware. They're doing soldering irons. They're flying to China negotiating with distributors. It's like, why is this a hardware company?
50:46There should be 50 different companies like this duking it out to create something that's better than Siri because Siri clearly is not cutting it. And I think the antidote to this, frankly, is, you know, we just announced yesterday a coalition of 275 startups and VCs in support of the BASE Act. It's the Banning Anti-Competitive Self-Preferencing by Entrenched Dominant Platforms Act bill. And 1074 by Scott Wiener, not to be confused with Scott Wiener's ill-fated bill 1047 from a couple of years ago that had to do with AI regulation. This one we're really excited about because basically it calls upon companies that are a trillion in market cap or above 100 million U.S.
51:34users to end this type of egregious forms of self-preferencing. We're totally fine with innocuous forms of vertical integration. In fact, most of the time that's like a great thing in technology products. But, you know, when you've got, you know, the GitHub COO last week said that commit rates, if they stay linear, are on track to be 14x what they were last year. Wow. Like, you know, something's got to give you. Yeah, there's going to be more software. Everyone's building software. There's going to be a ton more software. How do you think the vibe coding apps, apps that go in the app store and allow you to build more apps with that particular app, how do you think that will shake out?
52:14because that is a place where it feels like Apple has spent a lot more time making the case. When I think about the Siri button, I feel like they haven't made a strong case for why that can't map to a different app that's already gone through approval. But when I think about the consumer protections and privacy that comes with knowing that the software that you download from the App Store has been audited, they've made a pretty strong case there. What's the counter argument for why Apple should open the floodgates of apps that allow anyone to vibe code an app and deliver it to anyone else's device sort of willy nilly?
52:53Look, I don't think that anything is going to in terms of creating consumer outcomes that maximize privacy competition, all the great things that you want. I don't think any mechanism is going to work better than good old competition. And so that means allowing for sideloading. It means allowing for alternative app stores. You know, we make fun of a lot of European regulation, but the Digital Markets Act has actually done a pretty solid job at that. And so, like in places like Japan and Europe, if you are just hitting a wall with the worst DMV in the world, you can just go to the alternative app stores.
53:29And I, as a consumer, can decide to download one of those and use that as a way to access a whole other ecosystem of services. And they have their own vetting processes. And I think, again, competition is going to be the mechanism that actually enables better privacy, better consumer protection. And I think what we found historically with Apple, and we saw this a lot a few years ago with Beeper, which was a YC company that had interoperable messaging. Eric Mijakovsky. Exactly. Eric Mijakovsky solved the blue bubble, green bubble thing, basically made it where it's not awkward for you to buy an Android and Kool-Aid man into your college.
54:07group chat and turn the whole thing green. He fixed that. And of course, what does Apple do? They said, no, Android users don't get that. We've got to basically reduce security to this lowest common denominator like SMS, RCS standards. It's pretextual. We can have choices. We can have nice things. And little tech's trying to build it. But I think policymakers have got to do a better job at ensuring that the biggest players are not kind of egregiously putting their thumb on the scale. Yeah. Last question. What else are you tracking in DC? It feels like with the AI boom, there's a lot of new company formation.
54:48I'm sure you're seeing that on the YC side, but we see it every day on the show. Are there policy initiatives to encourage entrepreneurship that you're tracking? Is there anything else on like the small business side that you find interesting these days? Yeah, I think, you know, there's I would say where I think the Trump administration is doing a good job is, you know, they've done a lot to sort of advocate for the American AI stack and sort of encourage entrepreneurs to like interface with government and become and they've, you know, put out sort of bids for where the government is a buyer of these tools.
55:31and they've been very proactive and have a great relationship. You see like lots of renewed interests in defense tech and dual use tech. I think where I wish that there was more work and I think they could probably be doing a better job is thinking about how do we make sure that the United States is brain draining the world and bringing in the top talent and making sure that the smartest people in the world are building companies here. I think that that's where if I could change anything, I would say they could do a little bit better. But I would say, you know, they have been they've been very thoughtful.
56:10The president's talked about little text in his tweets. Like and I think, you know, this is not a partisan issue. We want to have a thousand flowers flourish. but it is yeah I think getting the tech talent piece with the sort of being bullish on AI that I think is going to get and also the competition piece getting those things right I think that's going to put us in a position to be really amazing here I love it well thank you so much for coming on the show yeah great to meet you thanks for having me guys appreciate the hot takes alright you too cheers and before we bring in Dan Primack from Axios.
56:52We have an exclusive clip from his interview with Kalshi CEO Tariq Mansour on the Axios show, which we will be discussing with Dan after we play it here. It's about a minute and a half. So let's listen to this. For customers to lose. Actually, the proof of that is that, you know, when a customer wins on a traditional sportsbook, they block that customer.
57:16Dan Primack:And the CFTC chair who supports prediction markets being legal, supports federal framework, et cetera, said recently that one of the, when he was asked about this, he said, well, part of the difference is that when you walk into a casino, there's all sorts of entertainment, right? There might be shows, there's food, there's drink. So a casino, betting in a casino is different than betting in Calshi, but it's not necessarily different than betting on a sportsbook app on my couch. There's no entertainment difference. There's big fundamental differences. It goes back to the market mechanic. Like one of them is essentially a product that is designed for customers to lose.
57:46Actually, the proof of that is that, you know, when a customer wins on a traditional sports book, they block that customer because those winnings are coming from the business model, the business itself. If they win enough, yeah. If they win, really, if they win and consistently, if they do research, if they get informed. They're good. If they're good, exactly. And if they're not, actually you get them promos and you figure out how to bring them back and there's kind of a bit of this sort of like, I think we call like kind of marketing tactics to bring these people back. It could be like entertainment or promos and so on and so forth.
58:14That does not exist in prediction markets. It is a fundamental difference in structure where actually a lot of the people that win, the people that are doing research, that are getting informed, that are traders, do come to prediction markets. This is where the value profit is strongest because prediction markets do reward them for being right.
58:31Well, we have Dan Primack here with us today. Dan, how are you doing?
58:37Dan Primack:Doing well, guys. Not as well probably as you are, but I'm doing well. Thanks for being here. Good to see you. So give us an update on this interview, what you were looking to learn from it, what you think the conversation, where you think the conversation around prediction markets will go from here? I think it was interesting the day we did this, we did this on Monday in New York City, and it was really maybe an hour or two after New Jersey, a judge in New Jersey, and basically an appeals court judge, so kind of the highest judge so far that's dealt with this, basically gave Calci the green light to go forward.
59:09Dan Primack:I mean, I think ultimately prediction markets are going to go to the Supreme Court. I think both Polymarket and Kalshi thinks that. I also think they're probably going to win in the Supreme Court. The law really is on Kalshi's side. They have done a pretty good job kind of being in step with regulators. And granted, they were it was a little more complicated with the Biden administration, but they sued the CFTC. They won that lawsuit. It's the reason why they have elections on the platform. I think if something is going to stop or change the way prediction markets work, that's going to have to come out of Congress.
59:40So, yeah, what's the next step? Yeah, and they benefit from having their adversary are casinos and sportsbooks, which are not exactly the kind of groups that Americans want to stand up to defend. You know, in March, it's time to hit the streets and march for the legacy sportsbooks.
59:59Dan Primack:I mean, that's some of it, right? So obviously in Nevada, which is one of the few places where Calci is actually banned because the judge has upheld an injunction. Yeah, that's the casinos. That's maybe some regulatory capture. The other folks who are against this, though, are folks who are just anti-gambling in general. And I do think you are seeing a bit of a groundswell of that politically. And I think it's bipartisan. You know, some bills that have actually come out have been coming from Democrats. But, for example, the state of Utah doesn't want this and they don't want it to protect casinos.
1:00:26Dan Primack:They don't want it because they don't want people betting, period. And they sure don't want it on phones where it's so easy to do. And we did in this interview on the Axios show, which drops tomorrow, we did talk about the addiction piece of this and kind of the broader societal issues, which isn't to say what Calci is doing illegal. There are questions about is it promoting not immorality, but is it enabling addiction? And what are the proposals for, because this is not regulated as gambling, and it seems like it will continue on that path. Is there any motion to bring some of the restrictions that apply to traditional gambling over into this new regime?
1:01:06Dan Primack:no no and i mean that that's the the complicated thing here and i did ask them you know is this basically a loophole for example uh in california in texas the two biggest states in the country in terms of people right uh you can't oh you know try to open draft kings or fan duel it doesn't work for you because because it's not allowed there calci that will allow you to bet and you know um i think uh tarik or luana said about 70 percent of their volume last month in march was sports betting, which is lower than it had been in February, but you're still talking about$13 billion of volume last month.
1:01:37Dan Primack:So it's a big number. You know, it's a loophole. They have figured out a way to basically get around sports betting laws. And I appreciate that the back end is different. They make a very compelling argument for why legally they're allowed to do it. And I agree with them. But the reality in the end is, if I'm betting on the Celtics Knicks game tonight, I don't really care what the back end looks like. I care about my money if I win and the fact that I'm able to do it. So is federal preemption sort of baked in at this point? Or is there some sort of hybrid rule set where this could go back to the states and states could make their own rules?
1:02:17Because it does feel like there's a pretty wide set of opinions state by state on how different communities want to engage with this particular product.
1:02:28Dan Primack:Right now, it appears federal preemption is going to win the day. For starters, the Trump administration, specifically the CFTC, which is what regulates this, this isn't regulated by the SEC, it's the CFTC. They are all in on prediction markets. Mike Selig, who is the current commissioner, he is on the side of Calci, I assume will be on the side of Polymarket when they eventually really come to the US. And it does make a certain amount of sense and there is some historical precedence here a lot of commodities which are traded and that's kind of what they're arguing that these are kind of commodities in in a different name uh there were lawsuits a hundred years ago arguing the same thing this is crazy speculation the reason why i say this could go to congress there are two carve outs to that one is a weird one it is onion futures onions not pork bellies or something else onions because at one point a long time ago, there was a ridiculous speculatory, like a lot of people lost a lot of money on onions.
1:03:22Dan Primack:So Congress passed the law saying you can't trade onion futures. And I think I'm right in saying the other one is related to box office returns, which is why if you're on Cal sheet, you won't, you can't bet that a movie is going to make 20 million bucks, but you can bet on it's rotten tomatoes. That's so funny because I've never been like a sports better at all, but I did, I did participate in a fantasy movie league for a while that had no financial incentive whatsoever, but you would construct a hypothetical movie theater, pick, okay, Project Hail Mary is going in the first slot, and then they would have the box off returns, but it was all just for fun with a bunch of friends.
1:03:55Dan Primack:And maybe it still exists, but back in the early 2000s, there was something called the Hollywood Stock Exchange, which again, wasn't for real money, but people did that. It looked like a stock market. So other countries have created rules like, you know, you can't advertise gambling during, you know, these hours and there's a bunch of different kind of rule sets around it, even in places where gambling is legal. Do you expect any states to pass laws that say you can't advertise commodities trading platforms during? More like FCC as opposed to CFTC. Basically like not targeting like sports trading, which, you know, the Cal trees and the poly markets are doing, but effectively saying like, hey we know these are going to be the biggest spenders and we don't want to tolerate uh or encourage this type of activity i mean you you may see that and then that gets fought out in court you know i obviously again you know you on the federal side you know it's interesting it's not just calci fighting back against these lawsuits the cftc itself uh there's three states arizona i'm going to mess up the other two i think connecticut is one there were three states who have tried to ban calci and the cftc itself has come in to sue so i could see the fcc coming and to try to sue if such laws were passed.
1:05:08Dan Primack:It would be interesting. I mean, I do think part of, well, part of a lot of betting, despite what we saw several years ago with DraftKings and FanDuel, you know, on every billboard and every advertisement, an enormous amount of this is still word of mouth. You know, people talking about it. I will tell you, when we were doing this interview, most of the crew, you know, the camera folks and the sound folks, hadn't heard of CalSheet before we did this. And when it was over, I was in the corner kind of packing some stuff up, and I heard them at the table having lunch. They were all not making bets, but they were flipping through the app and they were talking about different bets that were on there and they were fascinated by it.
1:05:43Dan Primack:I don't forget addiction. It definitely fascinates people because people have always, you know, in our lifetimes, been able to buy stocks. You can trade on the price of oil, not on, you know, not on who's going to win an award or really events, you know, non non securities related events. Yeah. How do you think about that bifurcation between securities-related events and non-securities-related events? Has there been robust enough research on how much of prediction market activity is sports-related or sort of less like positive sum, more zero-sum situations? Because I would have to imagine that the level of engagement varies by category.
1:06:28Like there were a lot of people that were interested in tracking the presidential election, but that's not something that someone's doing every single day. Whereas there's always a sports game somewhere.
1:06:38Dan Primack:There is. So they said this again about said during the interview, they said about 70 percent of their volume last month was sports in February. That number was higher. There was obviously a Super Bowl in February that changed. So it was March Madness last month, but not as big a deal as the Super Bowl. 70 percent. That's a lot, right? That's the volume. They make the argument in the interview, you know, that one of the reasons why I mean, obviously, for CalShe, that's good, right? That's more users. That's more fees. That's how they do it. They also argued that the sports volume creates more liquidity on the platform for the more esoteric bets.
1:07:10Dan Primack:And thus, you need sports in order to have the other stuff. I will tell you, I do get the sense that if they could have the same valuation and the same revenue and have no sports, they'd be fine with that and probably thrilled with it. But it's not how it works. The last thing I'd say about this, the problem or where sports could become a little legally complicated for them is this issue of entertainment, right? Mike Selig, the CFTC commissioner, and I mentioned this during the interview, he on CNBC the other day made a comment about how, well, this is different than a casino because a casino is providing entertainment.
1:07:41Dan Primack:You know, it was in that clip, right? There's shows and all this stuff. Well, there's not a huge, but a sporting event is by definition just entertainment, right? Whoever wins that basketball game tonight, except for the players and the gamblers, it doesn't mean anything. No, no. Goldman Sachs isn't making trades based on if the Celtics win tonight. You know, nobody's wowed. I think, doesn't.72 have a desk or there's some hedge fund that I think does have a sports ring desk? Right. And that's kind of part of the argument they make. But in terms of this idea that the Cal sheet will put forth, which I agree with, that understanding events and events market can help people better understand the world.
1:08:21Dan Primack:There's 15, 18 baseball games tonight. None of those are going to change the world, even in a tiny way, except for the people who are in the ballpark, maybe be happier, sadder, buy a couple more dogs. Yeah, at the same time, yeah, I mean, I completely agree with you. But there is something about when you're about to turn on the Super Bowl and you want just a really clear read on who's more likely to win. Like, it is easier to understand just a straight percentage than, like, a line and points and all of that. Like, just for a complete novice. But that's a different question. It is. And they make the argument correctly that they are not, they're just taking a piece of all the action, right?
1:08:59Dan Primack:They're not betting against you. They don't care if you win. Cal, she doesn't care if you win or lose. They just care that you play. Sportsbooks obviously want you to lose. Yeah, yeah. Yeah, I had a very eye-opening conversation with the CEO of a unicorn company who I, of course, will not name. But I was shocked at how invested they were in sports gambling broadly. Like, we just had dinner. We were hanging out. And they had, like, tons of different parlays across every different app. Sure. And they and they would show me like, well, when I'm in this state, I use this app. And when I'm in this state, I do this app and this app.
1:09:37I have to take my funds off the platform every night because I don't trust that it's not going to get money doing this.
1:09:44Dan Primack:I don't know. I don't know. I was just like I was just like, wow, I'm bearish on this company because the CEO is spending all their time, you know, doing, you know, 10 leg parlays on all these different apps. and you guys haven't raised a round in years. Yep, what's going on. Can I say, though, one thing I learned in the research for this, and we talked about it a bit, and I should have probably known this, one kind of user difference between the prediction markets and the sportsbooks is that parlay issue. And specifically, every bet on Cal sheet goes to the CFTC and has to get approved, and CFTC has 24 hours to approve it.
1:10:19Dan Primack:What that means practically is while you can take a bet on the game tonight because you know there's going to be a game tonight. You can't do what you can do on DraftKings, say the next pitch is going to be a ball. The next pitch is going to be a strike because obviously you have that 24-hour. They don't know there'll be a next pitch necessarily. There's a little less real-time sports betting than there is on the sports books. But because they know the Super Bowl is going to happen and they get that contract approved in advance, you can live trade that contract up till the last second of the game.
1:10:50And so that does satisfy a little bit of that, which is, again, much higher frequency than, oh, I want to gamble on the Super Bowl. I'm going to fly to Las Vegas, place a bet at a counter, wait in line, sit down, watch the game, go and collect my winnings. It's a very, very different equation. How have you processed? Just so it feels like we all just agree that gambling is addictive. And I think that's reasonable. I don't know where that comes from, whether that comes from like science or law. But it all feels reasonable, but we're going through this again with social media whether social media is addictive How have you processed the social media addiction trials and then the the new gambling app addiction?
1:11:32Question like are these linked at all in your mind or how have you been processing the social media question?
1:11:36Dan Primack:I mean I'm obviously not a doctor. I don't think you guys are doctor I mean, there's definitely you we've all I think read about kind of the dopamine hits and look this only that you get from not posting on social media but when you get a like or when you get a reply on social media, uh, gambling, I mean, there's obviously a dopamine hit when you gamble, right? You know, your person hits the basket, you win the game, you get excited. I mean, obviously if you have a lot of money on it, you get excited for different reasons, but just even, you know, I, I'll admit I use some of these sports betting apps sometimes when I, if I'm watching like my hometown team play,
1:12:07Dan Primack:maybe, maybe, maybe a few times, but the leagues knew what they were doing, right? They knew that if there's a blowout, you generally turn it off. But if you're waiting for your guy to get 20 points, well, you might stick it out a little bit more. I didn't realize that. I didn't realize that. But so back to the social media question. Have you been tracking any of that and what that means for the venture community or startups or really any knock-on effects that you've tied to the trial? Because there was that decision in Los Angeles. the actual fines for YouTube and Meta seemed very low, but it was the whole chain of more cases coming.
1:12:45And it just felt like the first time we actually had a full decision that the judge said, yes, this is addictive.
1:12:52Dan Primack:Right. So, right. The lack of money is notable, right? Because it was also a single plaintiff, right? So, I mean, for theory, that's a lot of money for one person. The big question going forward is, can an attorney or can a group of attorneys get a class together? And You've seen a bunch of advertisements. I've seen a bunch of advertisements all over the place. You know, were you harmed? Were you under 18? They're clearly trying to put a class together. A judge would have to certify that class. That's, I think, what Meta, YouTube, et cetera, are worried about, understandably worried about, because it's one thing to have a single plaintiff.
1:13:21Dan Primack:But that sets a little bit of a precedent. If you can have that same case with 100 plaintiffs or 1 ,000 plaintiffs or 10 ,000 plaintiffs, that money then starts to become real. And I think that's kind of the next step here. And we have to see if lawyers can get that class together, if a judge will certify them, and then whether another jury and judge will go along with what we just saw. What are you tracking in the venture markets broadly? We were going back and forth on the impact of gold money. Yeah, we were asking you about potential impacts to fundraising outside of in the Middle East, even then you said, I believe like, well, We're in sort of a new cycle of like the AI is not a bubble thing, but how are venture funds processing and how are LPs thinking about it?
1:14:05Like, what are you tracking?
1:14:07Dan Primack:Yeah, on the Middle Eastern side, it does not seem that money flows have really stopped. It's been explained to me is calls sometimes take a few more days to come back than they were. Things aren't quite as instant. But there's been nobody who said, you know what, we're shutting off the spigots for a while. Call us in June. Like, that hasn't happened. And to be honest, even in the last week or two, you've seen some deals and agreements that have come like with Saudi PIF, not just partners into venture capital funds. There was a big private credit partnership that got announced yesterday, I think, with Saudi PIF.
1:14:37Dan Primack:So clearly deals are still happening. Venture fundraising as a whole, though, has become it's not even become it is still really bifurcated. Right. You still have the haps and the have nots and these massive multistage firms that are gobbling up most of the money. And on the AI bubble side, I mean, it's funny, almost every venture capitalist and certainly the industry as a whole is just looking at three things, right? The IPOs of SpaceX, Anthropic, and OpenAI this year, right? Because those, if successful, can solve all the problems that they've had for the last several years. And SpaceX goes first.
1:15:09Gambler's mindset. Make it all back in one trade.
1:15:12Dan Primack:Well, it used to be VCs used to talk about home runs. This is now like the grand slam in the bottom of the ninth to win the World Series, right? And then everything else. And that's what they're banking on. And there's not a huge IPO pipeline, for example, other than that. We had a story meeting this morning and somebody asked me, well, with the ceasefire, does that mean companies that were prepping IPOs are going to start back up again? I didn't see a huge number of companies that were prepping IPOs. There were some, but it's not like from Liberation Day last year when you had five or six companies that were ready to price and then stopped.
1:15:44Dan Primack:There's not that much out there right now, again, outside of those big three. Yeah, I mean, the ones that I can think of that are maybe more at the Figma scale are just looking at Figma's track record in the public markets and thinking like, I'm not as good of a business as Figma. And I don't expect to be treated any differently. And when the stock popped, a lot of founders were thinking, oh, if I can get that multiple, I should be public today. Yeah, I'm thinking like the Rippling and the Deals. Yeah, all those companies look amazing. The deal's got its own issues, I think, which might be separate.
1:16:19Dan Primack:But by the way, this isn't just a venture issue, though. Private equity firms, which are more mature, slower growth, but more mature companies, they haven't been taking their stuff out either. And they don't have anywhere else to go except sell to other private equity firms. It's just this broader, non-IPO issue right now. Yeah. How much are you spending time tracking the data center ban that Sanders has sort of proposed? It's also a bunch of different states. It's a bunch of different states. We had a big AI event in D.C. two weeks ago, and I wrote about this a little bit. And on the sidelines, I spoke to the CEO of Constellation, which is one of the big electricity providers, the data centers.
1:17:02Dan Primack:And I asked him, this was whatever, three weeks into the war and oil prices were spiking. And I said, how much, you know, what's this doing to energy deal making in the United States right now? Just the rise in oil prices. He said it's having a little impact. He said it's the data center ban proposals that are having the really big impact. That's what has people freaked out. I mean, Sanders on the national level, you're not going to get anywhere nationally on this. But on a state by state level, you don't need much. You need a couple of states to do it. It is something that opponents have done a really good job on the PR and the industry has done a very bad job on the PR on this.
1:17:38Dan Primack:And it doesn't help that everybody's gas prices and home heating oil prices and places where that's relevant and electricity prices are all going up. Iran is obviously exacerbating it. But if you're looking at your bill and this is something that is top of mind, well, the bills are only getting higher. What do you think the impact of the war in Iran will be on defense tech investing? I wrote about this today. We have to see what happens, right? It's a pretty fragile piece. It's unclear whether Hormuz is even open or not. Now it was. Maybe it's not. What I wrote this morning was, I mean, I thought a lot yesterday after Trump's civilization tweet, right?
1:18:12Dan Primack:That if he really went through with what he said, and I know some people are making some odd arguments that, oh, well, it's either a nuke or not a nuke. No, there's a lot in between, right? You bomb some major power plants that are for civilians or desalination plants or the power to desalination plants. And people don't get water anymore, let alone can't do crops or feed or feed animals, et cetera. I, you know, defense tech has boomed in terms of venture capital, which is such there was almost none of it, you know, seven or eight years ago. And there's so much of it now. I think it could have turned Silicon Valley again back against defense tech.
1:18:46Dan Primack:If the United States had done something that a lot of people viewed as a war crime or at least as inhumane. Sure. I think the fact that we have a ceasefire and Trump didn't go through with that, I think, is probably a bit of a save for defense tech in the midst of a boom. I think you've got this this huge upsurge in all sorts of defense companies that could have actually come to a halt pretty quickly. Not all firms and recent still would have invested. Founders Fund still would have. But that that broader swath of venture capital that fills out those rounds, I think, might have slowed down if the military had done something, the Pentagon had done something that that a lot of people viewed as morally indefensible.
1:19:21Yeah. Something I thought was notable is that the American version of the Shahed was a government program and they use some private contractors for it. But the smartest, the smartest defense tech play three years ago was just to make the Shahed and make a lot of them. And it seems like no company actually had the had the foresight to do that. And it ultimately had to be led from from the D.A.W. I guess. Yeah. Interesting.
1:19:52Dan Primack:And by the way, I haven't looked to see what's happened with the stocks, but I mean, something that is going to have to happen no matter what happens in Iran, ceasefire, no ceasefire. The standard munitions stockpiles are going to have to get refilled, right? We are using a lot of bombs and a lot of stuff that's going to have to all get refilled. And I know Palmer Luckey and all others have talked about how we don't have enough of that prior to all of this happening. And that stuff has to get done and there's going to be people who sell that. Yeah, that makes a lot of sense. Well, thank you so much for taking the time to come chat with us.
1:20:22The Axios show is live and available everywhere, I'm sure. Go check it out. And we will talk to you soon, Dan. Have a great rest of you, Dan. Thanks for giving us the scoop. Great to see you. Thank you. Up next, we have Lior Susan from Eclipse. He's the founder and CEO. We'll be talking to him about Eclipse's$1.3 billion raise as industrial tech shifts from innovation to scale production with companies like Cerebrous and Volting Forms. How are you doing? Doing well. Thanks for having me. Welcome to the show. Please kick us off with an introduction and some background. Yeah, it's great to be here.
1:21:00First of all, I love your show. Yeah, we started the film 11 years ago. We are all operators that left their job building companies in the physical world to build a film that we can build more than one company at a time. As you can guess, it was fairly controversial 11 years ago to talk about defense manufacturing, chips, mining, etc. It feels like a little bit less controversial right now. And yeah, we grow the firm roughly to a$10 billion AUM and we just announced our raised of$1.3 billion. Let's hit the gun. Good place to start. Congratulations. What was the prehistory of the firm? How did you get into investing?
1:21:44What was the first deal? How big was the first fund? Tell me some background. Yeah, first fund,$125 million. Feels like many moons ago. That's not bad though. How did you set that up? I feel like a lot of people start at 20 or 50. 125 is not bad. Yeah, the ignorance was the power. I never invested a dollar before Eclipse, so it might be that one. I grew up in the military. I went to the special forces. Then I did a company in the networking space, Cisco bought it. I moved to live here. I spent three years with McNamara while he was the CEO of Flextronics, fell in love in U.S. manufacturing, and felt all of my friends in Silicon Valley can only spell the word enterprise software.
1:22:24I know nothing about enterprise software. I don't like enterprise software. 85 % of the world's GDP is physical industries. I felt it's kind of weird that everyone is telling me you need to go after big markets, after big towns, but everyone is following their friends into the enterprise software a while, those 85 % of the world GDP don't have a platform, so I'm left to start that platform. Yeah. Talk to me about the Cerebris investment. How did you meet the founder? It was one of these companies that I'd heard of, and I'd seen a lot of negative takes saying that it was the wrong path, that it wouldn't apply to where the current models are going.
1:23:04And then I tried it, and it was really fast and it just felt like magical. And so I was all of a sudden converted to be very excited about the company where before I was sort of uncertain about how it would pencil out. It felt like there was a lot to be done, but you obviously invested early. How did that come together? Yeah, we've been around the company for not 10 years. So it's been a moment. Yeah, exactly. But you know, like a lot of our companies and I think a lot of those companies in that space. It starts by a fundamental view that wafer scale integration, basically the short version, you take the entire wafer and you interconnect between the core.
1:23:44You know, when we have an idea of a chip is essentially it's a square, but it don't come from the machine like that. It's actually come as a round thing and then we cut it into squares, into chips. The idea here is you take the entire wafer and you connect it to a lot of the chips and you create essentially one very large chip. And naturally, when we made the investments in 2015, we didn't know AI will exist. What we did know, because we built by ourselves as an operator's chips and factories and fabs, we knew that Moore's law is going to hit the limit from physics point of view. We're going to, we're in two nanometers already.
1:24:18You know, let's assume we can do one nanometer. That's about it. There is nothing after that. Yeah, that's true. And we were looking for a new physics. And a new physics mean, hey, should you, can you connect to a lot of those cores in order to create a one big chip? And we decided that we are going to take over companies like NVIDIA and others. And it was not easy, but I think now we're extremely excited about the company and the growth of the business. Yeah, yeah. It seems like it's in a fantastic position now. Talk to me about Vulcan Forms. What was the back history there? Yeah, in some way, same story.
1:24:53physics, start with physics in the case of Vulcan Forms, we are manufacturing high precision metal parts. Historically, a lot of those machines have been using one, two, three, maybe four lasers. We are using 160 laser fiber into a single head and we melt powder really, really fast. The hard part there was how to control something that is so powerful. We got a call from the US D.O.W. many years ago and asking ourselves, Bebesky started to investigate why we are buying all of these lasers, because it looks suspicious for them. We're like, no, no, we're just building metal parts, nothing too sketchy.
1:25:37And yeah, the company booked multi-billions of dollars deals last year and a billion dollar deal the year before. And Kevin Kaskill and the team there is doing a phenomenal job. We're building now four factories in the U.S., scaling the operation to build high-precision metal parts for medical devices, consumer electronics, aerospace and defense, et cetera. So, yeah, it's a big fund. You're using WE. I imagine you take board seats, you lead rounds. Is that roughly correct? How many companies do you want in the portfolio? How deeply do you want to be involved? Do you try and pick a single winner in a category, or do you look at more secular trends and try and get a broad exposure to the whole category?
1:26:16What's your thesis? Yeah, so our LPs put us in the venture bucket and then in the growth bucket when they're thinking about how they are allocating capital, those U.S. endowments and foundation. We call ourselves operators with capital. We are all operators and founders when we build those businesses alongside the management team. So we actually do very few deals every year, and we have actually a small amount of position in each fund. And I'll say roughly we incubate one third of the companies and two third who will lead seed series A, series B, series C, series D, whatever it is. We only lead.
1:26:57We always take a board seat and walk very, very closely to the management team. And to tell you the truth, I'm enjoying more building companies than investing in companies. So regardless if I end up investing and maybe it was not my idea to start the company, I want to feel like I'm part of the management team building those businesses. That's my passion. Jordy? Very cool. Where do you think robotics is overhyped and where do you think it's underhyped right now? Yeah, actually, I wrote something on my LinkedIn maybe last week that says it feels a little bit 2021 in Eclipse sectors. we'll start seeing some of the bad behavior that maybe wasn't the enterprise software in 2021 happening now in our sectors you see those companies raising a billion dollars out of the gate or some some crazy valuations yeah or doing doing i'm assuming there's instances where a company you guys may have backed a company in a category you know eight years ago and then a new company gets formed in the category and within you know six months they're valued at the same price, even though there's a wildly different from a kind of technical progress standpoint.
1:28:14There is some of that. I mainly, it goes back to first principles. As a company, as a person, as an entrepreneur that likes to build companies, I think, you know, there is a way to build companies. There is for sure a way to build companies in the physical world. You talk about building factories, you talk about supply chain, you talk about CapEx, you cannot all push a full max out of the gate, burn really fast because you believe the contracts will come and you believe that always the markets will be there to fundraise you. So we're just trying to bring some sort of a discipline of how to build those companies.
1:28:52But it goes back to your questions on robotics. We have been doing robotics for 11 years now as out of Eclipse. And a lot of us did robotics much before in our operating life. And I think we are now crossing the chasm with robotics, moving from a control-based PLC, very accustomed to a much more general purpose, much more using physical AI. And as a result of that, we'll start seeing adoption on the commercial side that is super exciting. From your position on boards, I don't know how much you can talk about this, but I'd love to know your view and expectations for the IPO window. We were just talking about it with Dan Primack.
1:29:35A lot of attention paid to the big three, SpaceX, OpenAI, and Anthropic. But what else are you seeing in terms of how companies are gearing up for the IPO window? I mean, I think it's interesting, right? Of course, SpaceX, I think arguably even OpenAI and Trinotropic have a much closer part of the business to what I built, to maybe the traditional software that kind of was leading the chart. I think real assets are going to have a great moment in the public market. I think people value, you forget it goes back to the 85 % of the world GDP. The reason SpaceX can have that type of an IPO is because they solve something that it's really, really hard.
1:30:20So it's really, really hard for the second person to solve it as well. I think the reason you are seeing the correction in the SaaS world is you have a lot of companies. The entry is very easy. The time is not too big. And as a result, the public market correct. So I do believe we're going to see quite a lot of companies in the semiconductor world, in the space, in the AI infrastructure, in the data centers world going public in the next 18 months or so. Yeah, what are you tracking in terms of trends in the lunar economy? It does feel like we're at a turning point moment with SpaceX and Starship coming online.
1:30:59There's lots of interesting... You mean space economy, right? The lunar economy doesn't quite exist yet. Orbital economy is the buzzword. It's fine. It's the eclipse name. Confused. Any variation from low Earth orbit to beyond. Some of this stuff, when you talk about mass driver on the moon, it starts to seem 10 years away, 20 years away. Harder to underwrite, harder to think about. But maybe as a venture capitalist, you can start thinking about it. What are you looking for in just space broadly? Yeah, I mean, I think when you think about Henry Ford, when we created cars, there is so much economy that is being developed and so much GDP that is being developed by the ability to move people much faster than you could move before.
1:31:44I think, you know, we are going to see something similar with the increase of our ability to travel to space and lowering the cost significantly. And as a result, we're just going to see a lot of new businesses being built. We are partnering with an amazing company called True Anomaly, the building space defense prime. So, you know, it's not only you're going to travel to space, you're also going to have conflict in space. We are seeing a live one, maybe a ceasefire, with Iran right now. But, you know, I think since I mentioned his name, I said on an interview yesterday, I used to say that this is the best time to build in this country from Henry Ford and Carnegie or post-World War II.
1:32:30and actually change it to this is the best time to build in this country pre-built and the companies that I'm passionate about. So I'm just extremely excited to have the capital and the relationships to go and build as many companies as we can. Well, congratulations on the fundraise. Congratulations on the progress. And thank you so much for taking the time to come chat with us. We'll talk to you soon. I really appreciate it. Great to hang. Thanks, folks. Have a good one. Cheers. Take care. Up next, we will be revisiting the Axios NPM package hack that happened to supply chain attack. NPM, of course, Axios NPM was downloaded 100 million times per week, and it was compromised by North Korean threat actors.
1:33:09We talked about it a little bit on the show last week, revisiting it with Firas Aboukadija. I hope I pronounced that correctly. Discovered the problem? Is that right? Yes. We can ask him. Yeah, we can ask him. Socket detected the malicious update within six minutes. And we are lucky to have Ferofs join us. What were you guys doing for the six minutes? So sleep at the wheel? No, I'm kidding. No, no, no. Definitely not asleep at the wheel. It takes time to download packages, scan them, put them through our battery of tests. So I think six minutes is actually pretty good. It's incredible. No, it's fantastic.
1:33:46I'm just the best of it. But yeah, maybe zoom out and tell us about the actual process that Socket runs, your business, how the system works, and how you're able to detect supply chain hacks and cybersecurity threats so quickly. Yeah, totally. So Socket was among the first to detect and report on this incident. We built a system that goes out and downloads every open source package in existence within a few seconds. So we support about 19 ecosystems, and this includes really all sorts of third-party code that might be used to build applications today. includes things like your AI models, your open source dependencies, even your editor extensions, your Chrome extensions, like really any code coming from third-party sources.
1:34:30And we put it through a battery of really intense static analysis, maintainer behavior analysis, and then, of course, a bunch of AI and then human researchers as well. And we try to help kind of make a determination. Is this something safe that you want to use within your application or within your organization? Yeah. So can you can you talk about the shape of the threat that was posed by the Axios supply chain attack? Like because there's a wide range of, you know, zero day exploit that gives you full access to someone's device or computer or system all the way to just something that, OK, it would crash if this was if this exploit was used.
1:35:11Right. Mm hmm. Yeah. I mean, maybe we just start from the beginning and summarize the attack for folks. There was a North Korean state actor that socially engineered the lead open source maintainer of the Axios package. And it was honestly quite a sophisticated and impressive effort. They posed as a founder of a fake company. They created a fake Slack workspace, invited the maintainer to join it. They staged a fake Microsoft Teams call. And the website was made just incredibly compelling. They use the official SDKs from Microsoft Teams to create really realistic components in the page. They join the call.
1:35:55And, you know, by the way, they also developed a relationship over the course of weeks. So this wasn't like a situation in which you would expect to be on guard or on defense. And at some point in the call, the call just cuts out. And the browser says, hey, you know, you've got to install an update. and it gives them a binary file that they're told to install. And so this maintainer thinks, okay, I guess I got to install this update real quick so I can get back into the call. And it turns out that's how they compromised their device. So it's not just like a phishing link or something like that.
1:36:31I mean, this was a targeted attack. They also targeted me and a bunch of people at our company as well. So they targeted a whole bunch of the top NPM maintainers who have access to a lot of packages. Interesting. Then in terms of once they get control over, they phish a particular credential, a particular device for a developer who has access to push changes to a package like Axios, what are they actually changing in Axios to create a vulnerability in the software supply chain? Yeah, so they publish poisoned versions of the package that silently install what's called remote access Trojan, which is basically a way for the attacker to just remotely control your device and basically do whatever the attacker wants.
1:37:15It's like they're sitting in front of your computer on the keyboard, typing whatever they want onto your system. And what they did with it was they kind of pulled all the most interesting files and credentials off the system. So things like if you have a crypto wallet, they're taking the keys for that. They're going to definitely want the crypto. If you're logged into NPM, they pull those credentials so they can spread like as a worm and kind of continue to infect the next set in the attack. Right. So it's it's actually like this self-replicating kind of cycle where they they get these credentials and then they use them to go on to the next stage.
1:37:52And, you know, yeah. And then, you know, this is I mean, the thing I think I want to emphasize here for people is this isn't just an isolated incident, because this has been kind of the most recent blow in this kind of series of of compromises and attacks against the software supply chain that has been happening really over the last six months in a really intense manner. And we've seen it really pick up in the last month with Team PCP compromising Aqua Security and the Trivi scanner, and then that cascaded into Light LLM being compromised. Another security company, Checkmarks, was compromised.
1:38:25What happened with Light LLM, and do you have a good sense of how that contributed to the breach at Mercore? So it's part of the campaign of Team PCP, so they dropped the same kind of self-propagating worm called Canister Worm into the package. And what you have to realize is once you run a compromised open source package on your system, you kind of have to rotate all your credentials, like all your tokens and keys and passwords. And it's a really hard thing to do very thoroughly and very completely. And so I think that we're going to see a long tail over the next, you know, probably 12 months of follow on attacks from this from this set of compromises, because the group claims Team PCP claims that they've stolen 300 gigabytes of compressed credentials.
1:39:22So that's, you know, that I mean, think about that 300 gigabytes of stolen passwords, API keys, GitHub action tokens. I mean, they they're sitting on so much, It's like a goldmine in terms of like, what's going to, what's going to follow on from this. So, um, I think it's, it's not surprising that, um, you know, that you're seeing companies affected, right? Yeah. So why, why the boom in the last six months is it feels like it must be tied to vibe coding or, or AI agents. Um, is this that they have more powerful tools so they're able to do more damage or is it because our systems are getting weaker because we're pushing more vibe code to production?
1:39:59Is it both? Like, what got us to this place where we see this takeoff in cybersecurity threats? Yeah, well, you're absolutely right. It's definitely become a top concern. I think we're hearing a lot of our customers and prospects that are contacting us that this has now become a board level concern. You know, everybody is asking, how are we not going to be affected by the next one? Yeah. So I would say that, you know, fundamentally, like if you really zoom out and ask, why is this a problem? like, why is this happening? It's because the whole software supply chain is built on blind trust. I mean, you're downloading code from random people on the internet that you've never met.
1:40:37You don't know who they are. And you're like, let's just run it, right? Like, let's just hit run. And like, I hope it's fine. You know, I hope it's good. You know, and I'm going to give it full access to my system, right? No permissions model, right? No review. And I mean, no one looks at the code, right? Before they run it. And unlike an iPhone app, or, you know, mobile phone app, where it has to ask for permission to do sensitive things like access your camera or your microphone or your location or your contacts or your files, right? Open source packages just get everything. You know, you just run them, they get everything.
1:41:07So, you know, also there's this asymmetry in security and this has always been true. So this is, you know, kind of more of the bigger picture, you know, part of the bigger picture here is that defenders have a much harder job than attackers because they have to guard against really all the ways that you can possibly get attacked. and the attacker has to just find one way in, right? So it's asymmetric. And so when attackers realize, hey, look, open source, the way that companies use it has changed in the last decade. We no longer use just a handful of components like WordPress, Apache, PHP, these kinds of big components.
1:41:46We actually pull in, in some cases, it's like a thousand open source libraries just to get Hello World to show up on the screen, right? Yeah, yeah. It's crazy, the diffusion in the number of these things. So, you know, they realize, look, I could just attack one of these things, one of these libraries, and I can get into a company. Like, that's so much easier than attacking head-on and trying to hack the company directly, right? I can find one of, you know, and we have customers, by the way, that have 500 ,000 plus open source components in their environment. So just think about that, right? Any one of those is a way into the company.
1:42:16Yeah. The funniest package is even. It just tells you if a number is an even number. And it has one dependency. is odd because it's a turtle stacked. Exactly. It's a great example. Tell me more about the shape of your business. I mean, it seems like you're getting a lot of calls from companies and boards. What does it look like to work with you? How are you plugging into companies? Do you have a business line around going and hunting bug bounties? How should I think about the business of Socket these days? Yeah. Well, look, people contact us when they want to get their software supply chains under control, right?
1:42:54So right now, what that looks like is companies that are deploying AI agents and AI coding assistants across their companies have one big question in their mind, which is, you know, how do I know what my agents are doing? How do I know what my developers are doing with those agents? And that is the problem that we help them get under control. So the way to think about Socket is we are a software supply chain defense company, right? We protect your software supply chain. So when an AI agent is making a decision to go and install something in order to accomplish the task that's been given to it, you know, it will go through socket first.
1:43:33So we are the guardrail to ensure that no malicious components get installed. And if you take a concrete example, Axios, the attack we've been talking about, that malicious package was live for about three hours, meaning, you know, anyone who was asking their agent, like, hey, go build me. whatever, right? Doesn't matter what. One of the first things, it's probably going to grab it because it needs to do HTTP requests. It's going to say, oh, Axios, right? And, you know, so the question is, how do we, how do we, before that gets taken down, right? Before the, or even before the community is aware, how do we defend our organizations and our applications from those, those packages that have had these implants, right?
1:44:11And, you know, and yeah, it's, it's really top of mind for people. I would, I would say it's, it's kind of become like a, you know, number one concern for CISOs and for boards. What is your view on cybersecurity as a category? I think a lot of, you know, we've talked to people on air, off air that were surprised about the sell-off in cyber due to LLMs just because LLMs themselves are creating all these new threat vectors. And so there was kind of a disconnect there. But what is your sort of more general outlook on the category? I think in the short term, security is going to get worse. It's going to get harder.
1:44:52So I think, actually, I think the answer is really the opposite. Like companies and products and, you know, things like Socket are actually more needed than ever before. Or, you know, with Mythos coming out yesterday, you know, that's going to find a ton of vulnerabilities. And, you know, it's finding vulnerabilities all across the software supply chain. And so, you know, I think, you know, more vulnerabilities discovered means there's more urgency to fix the ecosystem. And it goes from being, you know, a lower priority on people's lists to a higher priority. And so I think, you know, the short to medium term effect is going to be massive awareness.
1:45:25It's going to be supply chain security becoming more top of mind for everybody. That's obviously great for us as a business, great for the ecosystem, because I think it's hard to invest in things and get justification for budget if you're a security leader, if you don't have a fire or an emergency to point to. And so this really helps there. I think longer term, we have to see. I think, ultimately, I think AI solves the asymmetry problem that we were talking about earlier, because for the first time, defenders now have an infinitely scalable army of AI agents doing their bidding and doing continuous security analysis.
1:45:59and that's all work that would have been way too expensive or impractical for their humans to do before and so the attacker's advantage of only needing to find one way in starts to erode when the defender has the ability to kind of continuously audit everything and so i think longer term once we get through this rough period i actually am very optimistic about you know security improving but one thing i will say is you know with security one of the reasons i love the field and why it's such an exciting field to be in is that you know it's it's a cat and mouse game so you're it's a dynamic system.
1:46:27So it's not like, you know, architecture or bridge building where, you know, you learn the rules of physics and you know how to build a bridge that's going to, you know, withstand gravity and these forces that don't change. You know, in security, the minute you think you've got things under control, you know, the attacker evolves, the attacker switches their strategy, and they have access to the same AI tools that the defenders have. And so, you know, it's really a field that is, I think, always going to be growing and always going to be, a great business to be in. Has a cybersecurity company ever got caught sort of LARPing as a hacker group in order to drive demand?
1:47:02Sort of like hacking a popular company in order to drive demand for their product? Because you said CISOs oftentimes need to be able to point at a fire to justify budget. That's super funny you ask because that was always the conspiracy theory that folks had about the antivirus companies back in the 90s and in the 2000s was that they were the creators of the viruses so they could sell you the antiviruses you know but um you know create the problem sell the solution yeah i mean you know i i think i think that uh i'm not aware of any companies getting caught doing that i think there's enough bad guys out there that have realized the opportunity sitting there in plain sight that i don't think that you know it you got to go to the go to conspiracy theories to kind of explain why no tinfoil hat needed yeah no tinfoil hat needed yeah i mean uh how do you think about the uh these economic impact assessments uh when axios i feel like everyone jumped on it very quickly andre carpathy shared that he uh he didn't have the repo pinned but he hadn't updated so he was able to dodge it for that three or six hours right um so a lot of people got lucky but do we have an idea of like the actual toll that that particular attack had?
1:48:16Because it felt like the number could have been very huge, but a lot of people were able to get to it fast enough that there wasn't necessarily a massive crypto breach or a massive PII breach. But do you have an idea of like how the industry is thinking about the size of the scale of the economic impact? Yeah. Well, I don't have an economic dollar amount for you, but if you look at the number of downloads per week of this package. It's 100 million weekly downloads. You do the math on that and you figure out what does that mean across a three-hour window. I mean, you're talking hundreds of thousands of people who installed it.
1:48:53And that's across CICD environments, local laptops, that's stuff that's been shipped into production. Another metric would be how many folks have reached out to Socket in the 24 hours following that attack to become a customer and make sure that they could use our tools to assess whether they were affected and to protect themselves for future attacks. We had almost 2 ,000 organizations sign up for an account in 24 hours. Yeah, which, you know, to put in perspective, it's a, you know, it's a significant percentage of all, you know, our full user base. So, you know, I think this is very, very widespread.
1:49:33And this is the thing about the supply chain, right? It's like, it's really not a matter of if you're going to get hit. When you're talking about these very, very widely deployed dependencies, including even some of my own code, I know I have these, you picked on is even. I have some code that is similar to that, a little bit less outrageous of an example. And it's in probably almost every Node.js app, and that's just how the supply chain works today. It's really not surprising that everyone is going to get hit this eventually. Well, thank you for coming on the show and breaking it down for us.
1:50:09I really appreciate everything you're doing. This seems more important than ever. And so have a great rest of your week. Come back on soon. We'll talk to you soon. Thanks, guys. Goodbye. Up next, we have Kasim Mithani from Depth First announcing a big round. The company also launched its first in-house model, DFS Mini 1, focused on vulnerability detection and smart contracts. We'll bring Kasim into the DBP and UltraGum. How are you doing? Hey guys, thank you for having me. Of course, good to see you. Nice step and repeat behind you. Are you at an event or is this just your normal background? This is like my background.
1:50:44We had like an amazing event with the Mirror of San Francisco and we got this for that. That makes sense. Well, since it is your first time on the show, please introduce yourself and the company. Yeah, my name is Kasim Matani. I'm the co-founders of DevFirst. We are building intelligence to discover, triage and immediate vulnerabilities at scale in an enterprise environment. We just raised an$80 million Series B round from Veritech. Congratulations. When did you raise the last round before this? We raised in early January. It's been less than 90 days. The reason why we raised it was because we're seeing so much traction.
1:51:30Customers are seeing so much value from our product and we're doubling down on our research efforts like like you mentioned in the top of the segment so we are investing really heavily on training and fine-tuning our own models let's talk about the customer impact first what are the companies that are using your service and plugging in and getting value and sort of walk me through the user journey of actually working with you? Yeah, that's a very good question. We work with some of the largest companies in the world, Fortune 500 companies. We also work with really fast-growing startups, ranging from companies like Lovable, ClickUp, Superbase, the top names in tech.
1:52:10The way they use our product is that they connect their code repository and their environments, so their staging and their production environments. Then we go, our agents go and figure out how the application is supposed to run, and then deviations from the expected behavior. So they figure that out, they replicate it in production, and then they give remediation instructions to agents and developers. And on the research side, walk me through building an in-house model. What was special about that? Did you have to use, I imagine you didn't do a whole base pre-train yourself, but what is unique about the model and what were the keys to success?
1:52:52Yeah, so when we started a company almost two years ago, we really believed that software security is a very deep problem. Not everybody in the market seems to realize that, but back then people thought that the crowd strikes and the follow-all to a sort of monopoly in the market. But in the age of AI, as code is being written faster than ever before and attackers are already leveraging AI to exploit vulnerabilities, a new type of solution needs to exist. and that's what Depth First is. So we invested very heavily in building a world-class research team. My co-founder, Andrea Amici, comes from DeepMind.
1:53:25He spent seven years building reinforcement learning there before LMs were sexy. This is back in 2019. And my other co-founder, Daniele, was a co-founder of Fair Wholesale. And before that, he led security at Square and Cash App. So that's our background as a founding team. And then we also have some of the top researchers in the world working with us. In terms of building our own model, we used GPT-OSS. as our base model. And then we took vulnerability data, we planted flags, and then we had the model try to find those flags, and then use an RL loop to basically improve the model's performance.
1:54:00And we were able to do better than Opus 4.6 at$1.10 to cost in this particular benchmark. That's very cool. What was your reaction to the Mythos news yesterday? It seems like really remarkable results in bug finding and vulnerability tracing, lots of partnerships. How did you process the news? What are the key takeaways? Yeah, I mean, I think it's amazing news. It's like validation that security is such an important area in the age of AI, something that we believed for two years. The reason why I work 16 hours a day is because I believe that in the age of AI, software needs to be secure. So I'm really happy Anthropic is investing in this.
1:54:41And Anthropic is also one of our partners. So we work with Anthropic, we work with OpenAI, we work with DeepMind, we work with all the labs. And our product sits on top of that. So we use the best model for the use case that the model's good at. So we use 4.6 for code analysis, we use other models for capturing the flag type of vulnerability detection I mentioned. So it's good news overall. But in an enterprise environment, complex enterprise environment, you need to adjust all types of data. You need to figure out the cloud environment, how the software is deployed. You need to figure out if there's a firewall there, if there's a WAF there.
1:55:16Our product ingests all of that data and then gives actionable vulnerabilities, the ones that really matter, to our customers. Then with a click of a button, they can just fix it. We see that as being a significant value-add for product. Talk about the decision to plant the flags yourself versus what it appears Mythos did was just look across every single open source project and just sort of maybe brute force a bunch of vulnerabilities until they found bugs all over the place. And it seems like they were able to find a lot of different stuff by just throwing every possible hacking technique at every possible open source repo.
1:55:53Is that the correct way to think about that strategy? And then do you think you'll wind up doing something like that in the future? So we did both actually. So we run our product, our model on open source too. So we found hundreds of bugs. We're just responsibly disclosing them because we don't want to get them out there so attackers can exploit them. So we found vulnerabilities in Chrome. We found vulnerabilities in Linux, in really deep software that's existed. So not very heavily used products. No. Only the most used products. Only the most used, yeah. And that's helped us improve our product.
1:56:32and we have a team of world-class security researchers on staff. So people who hacked iPhones for a living, thankfully they're working for us. But like those types of folks who are going and evaluating the results and then helping us improve the model based on that and improve the product and the model. Well, thank you for everything that you do. We need more white hat hackers than ever, very clearly. We were just talking about the Axios hack. One final question Tyler on our team wanted us to ask. why not use are you fine tuning on any of the Chinese open source models or do those scare you? We are experimenting with some of them but we're an American company.
1:57:14We would love to use American models. I was actually, I met Jensen Huang yesterday and it was so amazing to see the investment that's going in in this area, especially in training open source models. He's going to do open source models too, right? Yeah, so we're very excited and we're partnering with NVIDIA and he loved our vision. He thinks that in the age of AI, I mean, as agents are everywhere, security is going to be extremely important. So he's completely bought in to our vision and he's really excited about it. Yeah. Very cool. Congratulations on the progress and the round. We will talk to you soon.
1:57:44Have a good day. Thank you. Talk to you again. Thanks for meeting you. Bye. Up next, we have the co-founder and CEO of Mutiny. Mutiny just raised$72 million from Sequoia Capital and Y Combinator reaching eight-figure ARR. Whoa! Bring in Jaleh Reze from the waiting room into the Ultradale. How are you doing? What's going on? Good. How are you? We're good. Thanks so much for joining the show. Please give us an introduction of yourself and the company. So I'm Jaleh. I'm the co-founder and CEO of Mutiny. And yesterday we announced the new Mutiny, which is an AI agent that companies like Rippling and Snowflake use to create anything customer facing in order to get a deal from cold all the way to closed.
1:58:33Okay. Yeah. Walk me through. I mean, what does that actually mean? Add assets to landing pages, battle cards, like walk me through the workflow of closing customers in the modern era. Yeah, absolutely. So starting out, you probably want to warm up the accounts in a particular vertical. And so our customers will create personalized vertical campaigns. And then from there, once the SDR is involved, they want to start prospecting and get meetings with the right people so they can make prospecting pages in Mutiny. The agent can even research the specific people that they want. They can pull in data from their CRM, any information that's available to them.
1:59:16the agent will access and create something really high quality that will stand out to that prospect. As the deal progresses, now we're looking at things like curated customer case studies. We're looking at business cases, ROI reports, pricing proposals. Even after the deal closes, there's a ton of expansion that the customer success team will drive. So they can create impact reports and mutiny for their customers and they can do look forward strategies. the whole works in order to maximize revenue. Okay. Bunch of questions. Where does the name come from? You know, the mission of Mutiny was all about killing the dependencies and go-to-market teams.
1:59:59I've led marketing teams, sales teams, and the biggest blocker to growth is always speed. And the blocker to speed is all of the little dependencies that exist inside of your team, outside of your team. And so it was really a mutiny against the status quo. That's where the name came from. And it just kind of stuck. And behind you, is that a raccoon mascot? Explain that. Yes, it is. This is our, this is our, our raccoon mascot. His name is Achoo. Achoo. Where, where did that come from? How'd you pick a raccoon? Do you want to know the real story? Absolutely. Yes. So we were all in a circle. This is when we were about four or five people.
2:00:42And we're like, what are we going to name the raccoon? And one of our early employees. How did you get to raccoon? You're just like jumping. That's just the default state. Of course, we're going to have raccoon. No, explain like, how did you pick raccoon? There's a million animals you could have picked. Yes. Okay. So we were designing our brand and the designers asked me, okay, is there an animal that you guys really identify with? And there wasn't really anything coming off the top of my head. And then we took the whole team to Angel Island on a camping trip. And the entire time we were there, we had six bottles of wine with us and basically no supplies.
2:01:20So it was just it was it was awesome. And every time we would turn around with our headlamps, we would see this gang of adorable raccoons just slowly approaching. And then they would see the light and they would start backing up. and so the next day the designer asked me that question again and I said raccoon and that's how we ended up with the raccoon there we go what's going on with email are you are you generating cold emails is it a waste of time now like what's the equilibrium I think a lot of people are getting more cold outreach than ever and it feels like we might be in this game theater yeah because I can imagine you guys helping somebody make a great a great cold email but at the same time you guys are also set up for the golf and stake GTM as well, which is you play a nice round of golf and afterwards you pass them a PDF or a little deck.
2:02:12It gives them some more context on the conversation. Exactly. So email is a really tricky one. I think we see this in our own data. We hear it from customers. The results are really bad. Most people don't really open emails anymore. Executives don't really open emails anymore. And so the engagement rate on email is really, really low, which is why I think having a really personalized approach that's going to stand out, that's going to be different, that's truly and genuinely tailored to that person is going to be really important. One of the things that I find really fascinating is if you look at an average sales person, they spend about 30 % of their time selling and 70 % of their time following up with customers getting ready for tomorrow's meetings, creating all of those materials, nurturing the old deals that are going to convert hopefully one day.
2:03:10And when you talk to CROs, for the most part, despite all the AI investment in data, they haven't really moved the needle in terms of increasing quota per rep. The rep is largely closing the same amount as the previous years. And I think the reason for that is that that 70%, that's really skilled custom work per customer that you're going after. I was on a call a couple of weeks ago where it was a great call, great enterprise brand, the right decision makers in the room. And at the end of the call, they're like, please send me, based on the challenges that we told you we have, send us the three metrics that you can move for our business.
2:03:55and relevant customer case studies for each of those. That would take a rep four hours to go create, right? You have to go look at hundreds of case studies, pull those things together. Whereas in the Mutiny Agent, they can just come in and it automatically will pull in the challenges from the Gong transcript. It will go through all of their case studies. It will sift and pull out the right stats. It will curate the assets in there. And then they can go ahead and send a really nice, beautiful, forwardable thing to their customer that's going to get shared with the whole buying committee. Yeah. The chat is asking for the name, where the name for the raccoon came from, because I think we glossed over that.
2:04:40So sorry to go back to the mascot. But the mascot is a raccoon named Achoo. They demand answers. Yes. So it was the same group of people that went camping. We said, what should we name the raccoon? And right as we were going to do that, someone sneezed and it just said, achoo. And we all went, achoo. That's actually a really good name. Let's go with that. I mean, in general, I would say the Mutiny brand, I think part of the reason people really like it is that it is raw. It's authentic. We don't really regulate what people can and cannot do. We hire people that are aligned with our values and we just let them be themselves.
2:05:22I love it. Well, thank you so much for taking the time to come chat with us. Congratulations. Did we hit the gong for you? You raised a$72 million round. Go for it. We got to smash it. That was it.
2:05:36That was a previous fundraise, but yes, you can hit the gong for that. We're still happy to celebrate it. We have the money, so that's all that matters. That's all that matters. We'll talk to you soon. Have a great rest of your day. Great to be here. Goodbye. And up next, we have Jeremy Gallen from Charlemagne Labs. He spent 12 years in Meta and Trust and Safety and left last year to focus on AI-powered scams and building defenses. We're doing a whole security-themed show. Look at this. Jeremy, welcome to the show. wow the matching suit you look fantastic wow you really like it is the mirror image of me this is crazy nailed it the memo came through i was hoping that i'd get that maybach right downstairs and i'm so glad you you're you're you're up to speed on the show uh but for those who aren't up to speed on you uh give us an introduction and explain a little bit of your background you said you said he left meta to focus on ai scams which kind of sounds like you're scamming but i'm assuming it's the exact opposite.
2:06:35No, it's the opposite. We're doing cyberspace. That would be too easy. It's much easier to be on the offense than it is to be on the defense today. I tell you, it's wild out there. So I left Met after 12 years to focus on... Over-night success. Right. And basically my vision is that every employee of every company would have a watchdog. So the company is named after my dog, Charlemagne. She goes by Charlie. So the product is called Agent Charlie. Yeah. The idea is you're using your computer and you're getting attacked now with novel kinds of threats that resemble legitimate communication. That could be on messaging apps.
2:07:14It could also be the standard phishing. We just heard about that with the Axios attack. It was a basically a fake Microsoft Teams, basically call that then cut out and triggered and suggested, hey, update Microsoft Teams. Whole thing wasn't Microsoft Teams, but the individual just was like, you know, confused because it just seemed like it was. I think the nastiest trick is when it's the unsubscribe button is itself link. I think that's like the thing. So what I, what I, we've built, you know, the startup has been selling a product that will try and stop you from clicking. So it's like bad, bad employee, do not click.
2:07:57But the research that we've done to inform this commercial product is into the capacity, the capability uplift that's happening with respect to offense. So it's important to remember that if you're an adversary that's a threat actor seeking financial gain or a state actor, you're availing yourselves of all this AI and agentic tooling that we are using, the sales tools, the automation. And so the core premise is that in an AI-powered world, all phishing becomes spear phishing. You're not going to get a Nigerian prince email much anymore. You're going to get an extremely realistic, utterly compelling request from your boss or your manager or your friends, and it's going to be catastrophic in consequences.
2:08:46How do you think about actual deployment? Because this sounds useful in a consumer context. I'm just thinking about the email that's from your bank and has the unsubscribe button for some marketing email. You click it, all of a sudden you're logging in, giving away details. Is there an important distinction? It feels like consumer and enterprise is blurring together in many places. How do you think this all plays out? I think as employees of companies, we are using personal email and personal messaging apps on our devices, for sure. I think as a business, we're a B2B SaaS company with a research arm.
2:09:21And I'm excited to tell you more about our research efforts. but yeah I mean my dream is that the AARP is listening right now and would give this you know for free I'd like to give our software for free to anyone who holds an AARP card because elder abuse is devastating and it has huge consequences but it's very difficult to market and sell to consumers you know a product like this people don't wake up and say today's the day I'm going to improve my security posture and sort of after their attack that they have a problem and a mess to clean up Well, you need to create the problem and solve the solution.
2:09:58Stop creating the problem. No one's creating the problem. We were just talking with Harris from Socket who was saying the old tinfoil hat theory with cyber security and malware products is that they would create the bugs and then sell the malware. Create the viruses, sell the anti-virus. I think that's unethical, but also we don't have to do that. Yeah, there's plenty of scammers out there. The bad guys are getting superpowers. And so all we have to do is wait. And like I said about this research arm, our team has done some work. Meta's model dropped this morning. We worked with them. I'm quite proud, actually, of what they're doing in the cybersecurity space because beyond infrastructure and coding attacks, what we all know and aren't really talking enough about is that humans are the weakest link.
2:10:51So when a company wants to secure its perimeter, it's critical that employees are trained. And today, you know, they're training exercises. But the social engineering attacks aren't studied as much. And so, yeah, I'm really excited that Meta has taken a lead in going beyond just infrastructure and code vulnerabilities to looking at the capabilities that models, frontier models might provide adversaries in the social engineering and scam space. Yeah. So explain a little bit more about the the eval suite for Muse Spark, because like, is it that the model is trying to is the model social engineering you or you're trying to social engineer the model?
2:11:36Like what are what are the two parties in this in this eval? Like, actually, how are they interacting? Yeah. So we use an industry practice called the LLM as a judge. So we don't test on human subjects and our eval suite takes a model and has it role play as an attacker And then we have a model that role plays as a victim and they're given instructions accordingly And then we have an LLM judge whether It's the specific attacker is succeeding and then we compare those Attack different models to each other in the in the role of attacker and that's how we measure the kind of uplift or capability Yeah.
2:12:15Do you think that, is there a world where these social engineers, like, I'm thinking of different vending points in where if someone's running like Granola and they're recording that particular, it wasn't a Zoom call, it was a Teams call for the Axios attack. and maybe an AI model could be listening in the background and sort of throw up a flag like, hey, it's actually there. I just checked. There's no update for Teams. You don't need to click on that binary. You don't need to install that. This person's trying to take advantage of you. That's exactly what the vision for our commercial B2B security product agent, Charlie.
2:12:54I want an agent that the technology that we use is small language models so that it is on device and thus it's limited in its capabilities. I see a future where you have a real-time AI for security exactly like you described. I think real-time audio analysis with an SLM is way too big an ask, but small language models are improving just like all of the large models. So yeah, we need real-time defense. I want it to be proactive too. I think the biggest issue is that when scammers succeed, it's because even intelligent and well-trained people, employees of companies that work in tech even are duped because it's a it's as old as the bible scamming is a is an ancient art and it has nothing to do with with preparation anymore it has to do with we you know we're being attacked by machine we need machine defense yeah no that makes a ton of sense um where how uh take me through the shape of the company how big are you have you raised money how long you've been doing this all this yeah so um i i've raised money last um from the three investors that I'm really excited to be working with.
2:14:00They're Kevin Carter of Knight Capital and Chris Howard of Ritual Capital and Rafael Corrales of Background Capital. Collectively, they've backed more than 30 unicorns from idea stage. And so, you know, I tell them that I want to be the 31st. I'm ready to go. We're going to go to the moon. Yeah. Love it. So we, you know, we were in a kind of stealth mode right now, working with design partners on the SLM's capabilities. And we're also, if you visit our site, you can actually self-serve for the real-time fishing defense. So you could sign up right now if you probably have a Centurion, but if you have a credit card that works, you could put that into our website right now.
2:14:43Don't get spear phished. Yeah. Well, thank you so much for coming on the show. Congratulations. Yeah, it was great to meet you. Good luck with the next phase. Thank you for suiting up as well. And we appreciate it. Yeah, I'm not wearing any pants, by the way. Well, have a great rest of your day. Great hanging, Jeremy. We'll talk to you soon, Jeremy. Goodbye. Bye-bye. And people were disappointed that we didn't go more into the story about Satoshi. There is a full deep dive in the New York Times, my quest to solve Bitcoin's great mystery. It is a long article, though, and so I think we'll have to touch on it another time.
2:15:22but you know we went through Adam Back's reaction his his disavowal of the accusations that he is Satoshi but there's a bunch of interesting little segments in here from the the forums and the message boards of the day analyzing the different writing styles trying to see do you did you dig into this at all anymore I didn't read the whole thing but I'm like people have speculated that's I'm back for a long time. It's like kind of like him and Hal Finney is the other one. These are kind of the two like main names. And there's one more, I think, that comes up all the time. There's Nick Szabo sometimes.
2:15:56Yeah, Nick Szabo, yeah. But yeah, I don't know if there was a lot of like new facts that came out with this, which I think is why it's like not like super, super crazy. Yeah. There was also an HBO documentary on Satoshi. I forget who the like who who did that Satoshi who did they accuse in the 2024 HBO documentary directed by Colin Hoback. The firm suggests the Canadian software developer Peter Todd is Satoshi and Todd denied that. And so you have that's got to be the worst kind of title in the world from a security standpoint is being accused of being Satoshi. Yeah, because you're just going to be attacked because you potentially have the keys to like$50 billion or something, maybe more.
2:16:43I forget exactly what the number is, but yeah, that wallet is big. I still think it's possible that like the Satoshi wallet, like the keys were just lost and the person, it's like sort of a lose-lose. Because if you admit that you lost the keys, then like everyone's like, oh, how do you even prove that? You can't prove that you lost something, but there's no movement. I don't know. Yeah. Also, there's like you could have someone could have created it and then had years and years and years and years to buy up, you know, an equivalent amount of supply. Yeah. A bunch of different ways. Yeah. And then you have the basically you can say like, well, I've never sold.
2:17:19Right. If Satoshi's wallet did start selling, it would probably. Yeah, from a lore perspective and the brand, you could potentially be making plenty of money from the other wallets. And then if that supply ever moves, the whole market's going to reevaluate basically the liquid supply and sort of tank what you have. And also just the aura around Bitcoin is that it has an anonymous founder. And if the founder was ever truly unmasked, it would be so much less of like a special project. And I think everyone involved wants to keep it that way. although these investigations will never cease to be interesting.
2:17:57And so you can go read it on the New York Times from John Kerry Rue. Anyway, thank you so much for tuning in today. A bit of a shorter show. We're experimenting with different things. Obviously, we don't have ad reads anymore, and so we are going to be mixing it up with more stories, more interviews, different timing, and more flexibility. And so we hope you enjoyed this show, and we will see you tomorrow at 11 a.m. Pacific. sharp goodbye we love you leave us five stars have a wonderful afternoon spotify sign up for our newsletter at tbpn.com thanks for hanging out goodbye cheers
From the publisher
- (00:44) - Meta Launches Muse Spark
- (18:24) - Anthropic's Mythos
- (30:19) - 𝕏 Timeline Reactions
- (36:12) - Robo-Lamp
- (41:13) - Luther Lowe, Head of Public Policy at Y Combinator, discusses the challenges small tech companies face due to the control exerted by major platforms like Apple and Google over app distribution. He highlights the restrictive nature of app stores, likening Apple's App Store to "the worst DMV in the world," and emphasizes the need for policy interventions to curb anti-competitive practices. Lowe also mentions Y Combinator's support for the BASE Act, aimed at preventing self-preferencing by dominant platforms, to foster a more competitive and innovative tech ecosystem.
- (58:30) - Dan Primack, a journalist specializing in business and finance, discusses the legal landscape of prediction markets, highlighting a recent New Jersey appeals court decision favoring Kalshi, a prediction market platform. He anticipates the issue may escalate to the Supreme Court, with potential congressional intervention being necessary for significant changes. Primack also notes the bipartisan nature of opposition to such markets, citing concerns from both casino interests and anti-gambling advocates.
- (01:20:42) - Lior Susan, founder and Managing Partner of Eclipse Ventures, discusses his firm's focus on investing in physical industries by supporting companies like Cerebras and VulcanForms. He highlights the importance of wafer-scale integration in chip design and the use of multiple lasers in metal part manufacturing to drive innovation and scalability. Additionally, Susan emphasizes the significance of disciplined company-building practices in capital-intensive sectors and expresses optimism about the future of real asset companies in public markets.
- (01:33:21) - Feross Aboukhadijeh, founder and CEO of Socket, a developer-first security platform, discusses how Socket rapidly detected a malicious update to the widely-used Axios npm package within six minutes. He explains that Socket's system downloads and analyzes every open-source package across 19 ecosystems, employing static analysis, maintainer behavior analysis, AI, and human researchers to identify supply chain attacks and cybersecurity threats. Aboukhadijeh also details the sophisticated social engineering tactics used by North Korean state actors to compromise the Axios maintainer's account, leading to the publication of poisoned package versions that installed Remote Access Trojans, enabling attackers to remotely control infected devices and exfiltrate sensitive data.
- (01:50:24) - Qasim Mithani, co-founder and CEO of DepthFirst, discusses the company's mission to build AI capable of detecting, triaging, and remediating software vulnerabilities at scale. He highlights their recent $80 million Series B funding, raised less than 90 days after a previous round, driven by significant customer traction and the need to enhance research efforts. Mithani also emphasizes the importance of security in the AI era, noting partnerships with major AI labs and the development of in-house models to address complex enterprise environments.
- (01:57:57) - Jaleh Rezaei, CEO and co-founder of Mutiny, discusses the company's AI agent that assists businesses like Rippling and Snowflake in creating personalized customer-facing materials to streamline the sales process from initial contact to deal closure. She explains how the agent generates tailored content such as landing pages, battle cards, and ROI proposals, enhancing efficiency and effectiveness in customer engagement. Additionally, Rezaei shares the origin of Mutiny's name, emphasizing its mission to challenge traditional go-to-market dependencies, and recounts the story behind their raccoon mascot, Achoo, highlighting the company's culture of authenticity and spontaneity.
- (02:05:53) - Jeremy Philip, after 12 years at Meta focusing on trust and safety, left to address AI-powered scams by founding Charlemagne Labs, which developed Agent Charley, an on-device AI agent for real-time threat detection. He discusses the increasing sophistication of phishing attacks, emphasizing that AI enables scammers to craft highly personalized and convincing messages, making traditional phishing indistinguishable from spear phishing. Philip highlights the necessity for proactive, real-time defenses like Agent Charley to protect users from these advanced threats.
Follow TBPN:
https://TBPN.com
https://x.com/tbpn
https://open.spotify.com/show/2L6WMqY3GUPCGBD0dX6p00?si=674252d53acf4231
https://podcasts.apple.com/us/podcast/technology-brothers/id1772360235
https://www.youtube.com/@TBPNLive


