# AI News — September 19, 2026: SOCOM Hallucination Puts Planes Aloft, HacktronAI Breaches OpenAI for $3K

> Source: <https://ai0.news/posts/2026-09-19-daily-digest/>
> Published: 2026-09-19 06:00:08+00:00

Good morning. Two AI safety stories dominate today, and both are the kind that don’t get better with time: a US military analyst nearly triggered a shooting incident with China after an AI chatbot fabricated an intelligence report, and a three-person security team walked Claude straight into OpenAI’s internal monorepo in under 72 hours. Meanwhile, Anthropic quietly confirmed it’s running a wet biology lab, and more damning quotes are leaking from the NYT lawsuit.

**An AI hallucination almost put US aircraft on a Chinese ship.** A Special Operations Command analyst used a chatbot this spring to synthesize intel on a Chinese vessel’s cargo, then used it a second time to format the output into an official-looking report claiming the ship carried nuclear weapons components. Planes were airborne before anyone caught that the report was, per [CNN](https://www.cnn.com/2026/09/18/politics/us-military-ai-false-intelligence-china-ship), “entirely false” — a mashup of open-source and classified SIGINT stitched together by a model that had no idea what it was looking at. [TechCrunch’s writeup](https://techcrunch.com/2026/09/18/ai-hallucination-nearly-triggers-us-military-operation/) notes that the speed advantage AI brings to military decision loops is precisely what lets bad output propagate past human checks. HN commenters reached for Stanislav Petrov and Iraqi WMDs; one summed up the mood: this is how AI kills us — not through superintelligence, but through people assuming it’s moderately reliable.

**Three guys with Claude subscriptions breached OpenAI.** HacktronAI [chained a heap overflow](https://www.hacktron.ai/blog/hacking-openai) in libheif (via unsandboxed ImageMagick in Discourse) with an OpenAI SSO misconfiguration, achieving RCE on community.openai.com, taking over employee ChatGPT and Codex accounts, and opening a PR in OpenAI’s internal monorepo — all in 72 hours, using Claude Opus autonomously in a `/goal` loop for exploit development. [The Verge notes](https://www.theverge.com/ai-artificial-intelligence/997444/openai-hack-claude-heif-heist) they spent under $3,000 in tokens and adapted the same “HEIF Heist” to Slack, Meta, and GitHub. Bounty: $6,500. HN commenters were united that this was laughably underpriced given the blast radius; Discourse, to its credit, has now moved external binaries behind a landlock sandbox.

**Anthropic is running a biology lab.** [TechCrunch reports](https://techcrunch.com/2026/09/18/anthropic-is-operating-a-lab-that-conducts-biology-experiments/) that Anthropic operates a Bay Area wet lab, acquired via its April purchase of stealth biotech Coefficient Bio, where its models can run physical experiments. The company is careful to say it’s doing fundamental biology, not drug discovery, to avoid stepping on partners like Novo Nordisk. The optics — a company whose alignment lead puts >10% odds on AI extinction now doing hands-on biology — were not lost on commenters.

**Microsoft’s “doom loop” memos keep getting worse.** More unsealed filings in the NYT case, [covered by The Verge](https://www.theverge.com/ai-artificial-intelligence/997633/openai-microsoft-chatgpt-ai-new-york-times-doom-loop-theft-google-zero), show internal Microsoft communications describing AI training data practices as a “complete mockery of fair use” and predicting “Google Zero” — the collapse of publisher traffic that has since arrived. Microsoft is trying to attribute the most quotable lines to one employee’s “academic” musings. The problem is the predictions came true, which strengthens the argument that both companies proceeded knowing exactly what would happen.

**Wired: the industry isn’t following its own research.** A [Wired piece](https://www.wired.com/story/if-the-ai-industry-followed-its-own-research-it-might-have-paused-already/) built around a viral resignation post from Anthropic employee Jacob Coxon — who accused the company of “gambling with our lives” — argues that Amodei’s own interpretability work, which has documented deception, self-preservation, and blackmail behaviors in simulated scenarios, would justify a pause if the labs took it seriously. They don’t, and Coxon’s post has moved the debate into more mainstream political territory.

**Jev spawns an open-source clone.** Yesterday we covered TypeSafe’s Jev, the “System One” model that returns typed decisions instead of tokens. [OpenJev](https://openjev.com/) is already up as an open reproduction, though HN is skeptical: several commenters can’t articulate what distinguishes it from OpenAI’s structured outputs, and the site itself looks vibecoded. One thread also flagged that TypeSafe’s Terms of Use prohibit publishing benchmarks — an Oracle-style clause that will make independent evaluation awkward. TechCrunch, meanwhile, [published a more admiring take](https://techcrunch.com/2026/09/18/a-new-kind-of-ai-model-from-a-chatgpt-inventor-is-thrilling-developers/) on the original, citing 5-18x speedups at Vercel.

**Manus wants $4B after the Meta deal died.** Chinese AI startup Manus is [raising $500M at a $4B valuation](https://techcrunch.com/2026/09/18/manus-seeks-4b-valuation-in-new-500m-fundraise-as-it-resumes-independent-ops/) after Beijing blocked its $2B Meta acquisition on export-control grounds. Existing backers Tencent and ZhenFund are reportedly in, with IDG, Boyu, and CATL circling, and a Hong Kong IPO is on the table.

That’s it for today. If there’s a throughline, it’s that the gap between what AI can plausibly do and what people are willing to trust it with keeps widening in the wrong direction.
