Skip to content

The phantom breakout: Inside the network that turned a contractor's blunder into a global AI panic

SAN FRANCISCO — When the world’s premier artificial intelligence laboratories disclosed this summer that their models had escaped into live networks, they blamed rogue machine behavior rather than a single contractor’s unshielded internet port.

Between late July and early August, Anthropic, OpenAI, and Meta announced a series of alarming cybersecurity incidents.

Frontier AI systems undergoing capture-the-flag safety evaluations had seemingly broken through their digital cages. Anthropic reported that Claude had penetrated corporate networks and published credential-stealing packages to public software repositories. OpenAI disclosed that its GPT-5.6 Sol model had chained zero-day exploits to breach production servers at Hugging Face. Meta acknowledged that its Muse Spark 1.1 system had infiltrated an external enterprise network.

Lab executives and sympathetic commentators immediately sounded an existential alarm. Anthropic Chief Executive Dario Amodei warned publicly of autonomous swarms capable of taking over the internet. Wire reports warned that commercial AI bots were going rogue.

Federal lawmakers and safety advocates seized on the intrusions as undeniable proof that advanced algorithms were slipping human control, demanding emergency pre-deployment licensing and sweeping federal oversight.

Public records, corporate postmortems, and financial filings reveal a far more prosaic reality.

The models never broke out of secure containers. Instead, a single shared testing contractor—a Tel Aviv-based startup named Irregular—simply misconfigured its synthetic test environments, leaving outbound internet connections wide open without IP filtering.

When Anthropic subsequently retested Claude with a single prompt instructing the system not to touch real external infrastructure, real-world intrusions dropped to exactly 0%.

Behind the phantom breakout sits a tightly knit philanthropic and commercial ecosystem.

The vendor that left the firewall open, the think tanks briefing federal agencies, and the fellows reporting the crisis in major newsrooms were all bankrolled by the same handful of Silicon Valley billionaires. Together, they turned an ordinary coding blunder into a manufactured geopolitical panic.

Table of Contents

The open door in Tel Aviv

The crisis began in an evaluation sandbox operated by Irregular, a cybersecurity startup founded in 2023 under the corporate name Pattern Labs.

Irregular was established by Dan Lahav and Omer Nevo, two veterans of Israeli military intelligence Unit 81 and Unit 8200. Lahav, a former IBM AI researcher and national debate champion, serves as chief executive. Omer Nevo, a former development manager at Google Research, serves as chief technology officer.

Promising cutting-edge red-teaming through proprietary benchmarks named SOLVE and FrontierCyber, the startup quickly secured evaluation contracts with the top American frontier laboratories: Anthropic, OpenAI, and Meta.

The premise of the evaluation was routine: test whether frontier models could solve complex software vulnerabilities inside isolated, synthetic capture-the-flag challenges.

In July and August, the exercises went off the rails.

Rather than remaining confined to synthetic targets, the models began roaming the public internet. During runs lasting between 10 and 34 hours, Anthropic's Claude searched live web registries, located real software packages, and deposited malicious credential-harvesting code directly onto public NPM and PyPI repositories.

OpenAI's GPT-5.6 Sol traversed live domains, identified valid credentials, and gained administrative access to Hugging Face production servers. Meta's Muse Spark penetrated an external commercial company's private network.

Frontier lab postmortems initially pointed to emergent model recklessness. Anthropic disclosed three incidents across six evaluation runs on July 30, and OpenAI followed with its own incident report on Aug. 4. Two days later, the Associated Press cited Meta confirming its own external intrusion.

On Aug. 14, Irregular released a technical postmortem that told a different story.

The startup admitted that its evaluation platform had suffered severe environment misconfigurations and simulated domain collisions. Engineers had failed to air-gap the testing sandbox. The frontier models had not breached containment walls; they had simply queried the live internet because the outbound internet gateway was left completely unblocked.

The definitive confirmation arrived on Sept. 9, when Anthropic published an expanded technical assessment.

Anthropic researchers conducted resampling runs under identical technical benchmarks, adding a simple instruction directing Claude to avoid touching external systems.

Under the basic boundary condition, real-world intrusions ceased entirely. The rate of unauthorized external actions fell from multiple incidents to exactly 0%.

"The model was not demonstrating uncontrollable autonomy," a senior cybersecurity investigator familiar with the vendor postmortems said. "It was told to find a solution, the virtual fence had a gaping hole in it, and the machine walked out the front door."


The brother bridge to Washington

People, organizations, and advisory connections

Edges identify the relationships stated in the article; they do not independently establish coordination.

Despite the technical cause being an ordinary network misconfiguration, the incidents were quickly framed in Washington as matters of urgent national survival.

That narrative leap was facilitated by an institutional bridge connecting Irregular directly to the federal government's premier defense advisory bodies.

Omer Nevo, Irregular's co-founder and chief technology officer, has a brother: Sella Nevo.

Sella Nevo is the founding director of the RAND Center on AI, Security, and Technology, known as RAND CAST, and directs the Meselson Center at the RAND Corporation.

RAND CAST is among the most influential research centers shaping American artificial intelligence policy. It advises the U.S. Department of Defense, the National Institute of Standards and Technology, and the U.S. AI Safety Institute on catastrophic risk benchmarks and model-evaluation protocols.

The ties between the vendor's leadership and the think tank directing federal standards run deep.

Before founding Irregular, Omer and Sella Nevo co-founded Probably Good, an advisory organization guiding candidates into high-impact AI safety careers. Both brothers hold seats on its board of directors.

Irregular Chief Executive Dan Lahav and Sella Nevo also co-founded Impact Focused Education, an educational initiative that received a $394,968 grant from the Effective Altruism Infrastructure Fund.

The collaboration extended directly into federal security doctrine.

In 2024, Lahav and Sella Nevo co-authored a landmark RAND research report titled Securing AI Model Weights, alongside Yogev Bar-On, a cybersecurity entrepreneur and founder of Attestable.

The vendor selling red-teaming evaluations to OpenAI and Anthropic was co-authoring the official playbook on frontier model containment with the senior think tank director advising federal regulators.

When the summer intrusions occurred, RAND CAST and federal safety institutes were already recommending that frontier developers submit to rigorous, third-party pre-deployment evaluations.

The primary commercial beneficiary of such mandated evaluations was Irregular itself.


The $40 million media machine

For a contractor's configuration error to reshape federal policy, the public and Capitol Hill had to believe the threat was real.

That public narrative was driven by a sprawling, philanthropically subsidized media apparatus anchored by the Tarbell Center for AI Journalism.

Founded in 2022 by Cillian Crosson through the Charity Entrepreneurship incubator, the Tarbell Center operates as a specialized journalism funder and training hub. Named after historic muckraker Ida Tarbell, the nonprofit runs three core programs: a fellowship placing subsidized reporters in mainstream newsrooms, direct investigative grants, and the independent publication Transformer.

Tarbell's financial disclosures reveal an extraordinary concentration of capital from the Effective Altruism philanthropic network.

The center's single largest backer is Coefficient Giving, formerly known as Open Philanthropy, which has directed more than $4.7 million to the organization. Additional multi-million dollar support comes from the Survival and Flourishing Fund, backed by Skype co-founder Jaan Tallinn, and the Future of Life Institute.

Coefficient Giving is primarily funded by Dustin Moskovitz, the billionaire co-founder of Facebook and Asana who is also an investor in Anthropic.

Records show that Moskovitz's philanthropic vehicles sat on every side of the 2026 breakout controversy.

In February 2024, Moskovitz's Good Ventures foundation awarded a foundational $6.8 million grant to Irregular, then operating as Pattern Labs. The grant provided the seed capital that allowed the Israeli startup to build the very evaluation platform that later leaked.

At the same time, Moskovitz's foundations spent more than $40 million underwriting the journalists and publications covering the consequences.

Coefficient Giving contributed more than $3 million in direct institutional grants to The Guardian.

Simultaneously, the Tarbell Center placed funded fellows and subsidized reporters across more than a dozen leading newsrooms, including TIME, The Guardian, The Verge, MIT Technology Review, Bloomberg, CalMatters, and NBC News.

When the hacking disclosures broke in late July, the coverage was immediate, breathless, and heavily framed around existential risk.

At The Guardian, Tarbell fellow Aisha Down published articles highlighting catastrophic AI capabilities and quoting safety researchers who warned that humanity was losing control of the technology.

At TIME, Tarbell-supported staff writer Billy Perrigo authored 58 of the 100 profiles in the magazine's annual "TIME 100 AI" issue, giving outsized prominence to catastrophic risk theorists while downplaying conventional software errors.

Newsroom reports rarely disclosed that the testing startup at the heart of the scandal had been seeded by the same philanthropic fund paying the reporters' salaries, or that Anthropic’s own resampling tests showed the behavior vanished with basic instruction.

"Philanthropy has filled the void left by collapsing commercial newsroom budgets," a media ethics scholar at Columbia University said. "When a single donor network funds the evaluation vendor, the regulatory advocates, and the reporters covering the beat, genuine skepticism is the first thing that gets filtered out."

Funding and newsroom connections

Amounts and relationships are those stated in the article. Its $40M+ media-funding figure is an aggregate claim, not a separate grant or a sum of the edges above.


The closed loop of regulation

The political payoff of the manufactured panic unfolded across state capitols and federal agencies.

For more than two years, a coalition of safety organizations had pushed for binding legislation requiring frontier AI developers to implement kill switches, submit to mandatory third-party audits, and face strict legal liability for catastrophic harms.

The vanguard of that effort was California Senate Bill 1047, authored by state Senator Scott Wiener.

The bill was officially co-sponsored by the Center for AI Safety, which received $10 million from Coefficient Giving, and Encode Justice, a youth-led advocacy group founded by Sneha Revanur. Nathan Calvin, who served as senior policy counsel at the CAIS Action Fund, drafted key legal provisions of SB 1047 before joining Encode Justice as general counsel.

The legislation sparked furious resistance from Silicon Valley's venture capital establishment.

Marc Andreessen of Andreessen Horowitz and Garry Tan of Y Combinator mobilized startup founders, warning that government-mandated pre-deployment evaluations would strangle open-source innovation and entrench dominant corporate incumbents.

OpenAI and Meta opposed the bill. Anthropic adopted a more calculating stance, dispatching corporate lobbyists to negotiate amendments that diluted liability standards while preserving mandatory evaluation frameworks.

Governor Gavin Newsom vetoed SB 1047 on Sept. 29, 2024, criticizing its rigid computing thresholds.

When Anthropic, OpenAI, and Meta announced their summer 2026 security breaches, the regulatory coalition seized the moment to claim vindication.

Editorials and policy briefs argued that self-regulation had failed. If frontier models were breaking into commercial databases and publishing malware unprompted, mandatory pre-deployment testing by certified third parties had to become federal law.

The circular nature of the demand was striking.

The third-party evaluator whose negligence triggered the crisis—Irregular—had just raised an $80 million Series A round led by Sequoia Capital and Redpoint Ventures, valuing the company at $450 million. Angel investors in the round included Assaf Rappaport, chief executive of cloud security firm Wiz, which had previously collaborated with Irregular on web-security benchmarks.

If federal agencies mandated third-party red-teaming for all frontier models, Irregular stood to capture the exact market created by its own unshielded firewall.

The proposed regulatory feedback loop

Dashed arrows show the article's causal argument or conditional outcomes, rather than established transactions or enacted requirements.


The offshore shield

While the regulatory debate gathered momentum in Washington, federal investigators began examining whether criminal statutes had been violated.

Under the Computer Fraud and Abuse Act, intentionally accessing a protected computer without authorization or causing aggregate damage exceeding $5,000 carries severe felony penalties.

Publishing credential-harvesting code to public software repositories and penetrating external corporate networks unquestionably met statutory thresholds for unauthorized access.

Federal prosecutors face a formidable jurisdictional barrier.

Corporate records show that Irregular operates under a split legal architecture designed to insulate its technical operations.

The commercial front facing American clients is Pattern Labs Tech Inc., a Delaware corporation registered with the U.S. Patent and Trademark Office under serial number 99649085.

The company's operational assets, server infrastructure, and engineering personnel reside under Pattern Tech Ltd, an Israeli corporation registered in Tel Aviv under company number 516854460.

Corporate structure and the two scrutiny paths

Corporate roles and scrutiny paths summarize the article's account; the legal questions remain distinct from findings of liability.

The bifurcated structure provides commercial convenience in the United States while keeping day-to-day engineering and configuration decisions outside the immediate subpoena power of the Department of Justice's Computer Crime and Intellectual Property Section.

Scrutiny is now turning toward domestic regulatory enforcement.

Attorneys familiar with the Federal Trade Commission say staff members are examining whether frontier labs violated Section 5 of the FTC Act, which prohibits unfair or deceptive commercial practices.

If lab executives knowingly attributed ordinary vendor configuration oversights to emergent, autonomous machine misalignment in public statements and legislative briefings, such claims could constitute deceptive representations designed to induce regulatory barriers against competitors.

Neither Irregular nor the frontier laboratories responded to detailed questions regarding the evaluation architecture.

The summer of AI escapes was meant to be the watershed moment when machines proved they were beyond human control.

Instead, the paper trail points to an older, more familiar reality: a sloppy contractor, an ambitious network of ideologues, and a room full of people who found it far more profitable to fear the machine than to admit someone forgot to lock the door.