Tech
AI hedge fund Situational Awareness may have sold its public portfolio, but it still has its Anthropic shares
Situational Awareness, a hedge fund formed by former OpenAI researcher Leopold Aschenbrenner, has sold the majority of its public stock portfolio to Ken Griffin’s Citadel following steep losses over the past month, the Wall Street Journal reported earlier on Thursday. It’s a big comedown for the rising star who has been described as both “scarily smart,” and “brash.”
German-born Aschenbrenner, who is 25, had no prior trading experience before launching the fund in 2024. He gained prominence for his investment thesis after publishing essays arguing that scaling AI would require a major build-up in semiconductors, compute, memory, and energy infrastructure.
He joined OpenAI’s “superalignment” team in 2023, two years after graduating as valedictorian from Columbia at 19 (he enrolled at age 15). But he was dismissed from the company a year later over what it described as an improper disclosure of internal information. At the time, that team was led by OpenAI co-founder Ilya Sutskever and AI researcher Jan Leike. Soon after, Sutskever left to start his own company, Leike joined rival Anthropic, and Aschenbrenner launched his fund.
Things couldn’t have been going better for Situational Awareness until very recently. The fund returned 439% for the year through June, the Financial Times reported. Assets under management reportedly grew to as much as $45 billion during their peak before the fund’s positions began dropping sharply amid a broader decline in AI infrastructure investments, CNBC reported.
Even after losses mounted, Aschenbrenner didn’t flinch. In a July 24 letter to investors seen by the FT, he called the selloff one of the best buying opportunities since early last year and invited clients to commit fresh capital starting August 1. According to Bloomberg, the appeal didn’t garner the commitments he’d hoped would materialize.
Some of the hardest-hit stocks held by the fund included memory chip producers SK Hynix and SanDisk, clean energy developer Bloom Energy, and neocloud provider Nebius Group, all of which have plummeted by more than 30% over the past month. AI infrastructure equities fell as public investors grew concerned that massive capital expenditures weren’t translating into near-term revenue. The fund’s losses were amplified by leverage, a common hedge fund strategy of using borrowed money to buy stocks.
After Citadel bought the bulk of those holdings, Situational Awareness’ overall assets fell to roughly $10 billion, Bloomberg reported, down from around $20 billion in recent months, per an earlier WSJ report.
Situational Awareness raised several hundred million dollars at its outset. Early backers of the fund include quant-trading firm Jane Street, Stripe co-founders Patrick and John Collison, and Meta executives Daniel Gross and Nat Friedman.
Citadel’s purchase fits a familiar pattern for Citadel. Ken Griffin’s hedge fund has a reputation for stepping in to snap up attractive assets when leveraged players are having to unwind themselves. Even before picking up some of Situational Awareness’s holdings, Citadel’s portfolio featured some of the same AI infrastructure bets, suggesting that, like Aschenbrenner, Griffin expects the sector to recover and has the ability to wait it out.
Situational Awareness did not, however, sell its investments in private companies, according to multiple reports. Most notably, it continues to hold a stake in Anthropic that’s right now valued at $5 billion, according to Bloomberg, and which many would view as an asset that continues to appreciate. Indeed, Anthropic was last valued at $965 billion in a Series H round in May, and it’s expected to go public as soon as October, potentially at an even higher valuation. It’s conceivable that a windfall from the sale of those shares could offset some of the hedge fund’s public-market losses.
Other private investments in the portfolio of Situational Awareness include chipmaker MatX and AI data center startup Fluidstack, which was reportedly in talks in April to raise a new round at an $18 billion valuation.
TechCrunch has reached out to Aschenbrenner for comment.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
>
Tech
Repeat founder Ryan Williams raises $10M seed for an AI startup for private credit managers
Ellis AI announced Thursday its emergence from stealth with $10 million in seed funding from investors including First Round Capital, 645 Ventures, Harlem Capital, Khosla Ventures, Thrive Capital, Slow Capital, and Ariel Alternatives CEO Mellody Hobson.
Ellis uses AI agents to tackle the fragmented workflow private credit managers deal with, including managing documents, spreadsheets, and correspondence. The company was founded by Ryan Williams, best known for co-creating the real estate investment platform Cadre alongside Josh and Jared Kushner back in 2014. That company raised more than $160 million in funding and, at its peak, was valued at $800 million before being sold for an undisclosed sum to the alternative investment company Yieldstreet in 2024.
“At Cadre, I saw the next major constraint,” Williams said. “Even as the front end of private markets became more modern and accessible, the operating infrastructure underneath it remained fragmented.”
He started working on Ellis last year. The company seeks to connect and centralize all the scattered software, accounting information, and documents a private credit firm would use into one easily accessible platform. The system can flag discrepancies in the data and uses AI agents to help perform tasks like portfolio monitoring and preparing reports.
For example, Williams promises the agents can help close a fund’s books at the end of the month.
“A team may have to download files from several systems, reformat the data, compare balances, investigate discrepancies, and re-enter information by hand. In many firms, Excel becomes the operating system,” he continued. “Ellis connects to the systems and documents a firm already uses rather than forcing it to rip everything out and start over.”
It keeps a human in the loop, too, he says. “Material decisions and actions remain with the human experts,” he said.
“I expect the human loop to become narrower, but not disappear,” he continued, when asked if he sees a day when the AI works fully autonomously. “Our goal is not to replace human judgment; it’s to help people cut through the noise and make educated decisions faster.”
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
>
Tech
IBM: AI-Enabled Data Breaches Cost Organizations $6 Million on Average
Cybercriminals are using AI to move faster, and companies are paying a premium when those attacks lead to data breaches.
IBM found that AI played a role in one in four malicious breaches examined for its 2026 Cost of a Data Breach Report, a 56% increase from the previous year. These incidents cost organizations an average of $6 million — about $1 million more than the global average breach cost of $4.99 million.
Conducted by the Ponemon Institute, the study examined breaches experienced by 602 organizations between March 2025 and February 2026.
The findings also reveal a growing imbalance for security teams: Many organizations are using AI to detect attacks already underway, but far fewer are deploying it to find vulnerabilities before attackers can exploit them.
“What’s changing is the economics of cyberattacks. AI is making attacks faster and cheaper, while breaches keep getting more expensive,” said Suja Viswesan, vice president of IBM Security Software. “When organizations have an extended gap between discovery and remediation, that imbalance shows up directly in breach costs.”
Companies are using AI, but not where attackers are moving fastest
Organizations that used AI and automation extensively in security operations reported breach costs averaging $1.93 million less than organizations that did not use the technologies, according to IBM.
However, IBM found that many companies are still using AI mainly after attacks begin. More than half of breached organizations reported using AI agents for threat detection and containment, but only 18% used agents for vulnerability management.
That gap could become increasingly consequential as attackers use AI to accelerate vulnerability discovery and exploitation.
IBM found that more than 20% of organizations experienced breaches involving AI models or applications. The most common causes were weaknesses around AI systems rather than the models themselves, including compromised APIs, applications or plug-ins, as well as cloud misconfigurations affecting AI workloads.
Critical industries face higher AI-related risks
Critical infrastructure organizations experienced the majority of reported AI-driven attacks, accounting for 62% of incidents. Financial services and energy companies saw some of the highest concentrations of AI-related attacks.
Financial services breaches averaged $6.3 million, while energy breaches averaged $5.2 million, highlighting the potential for cyber incidents to affect essential services, supply chains and broader economies. Healthcare remained the most expensive industry for breaches for the 13th consecutive year, with average costs reaching about $6.6 million, according to IBM’s findings.
Must-read security coverage
AI governance remains a weak point
While companies are increasing AI adoption, many are struggling to control how the technology is used internally. Shadow AI — the use of AI tools or systems without organizational approval or oversight — was involved in 43% of the incidents IBM studied, more than twice the previous year’s share.
IBM also found that 92% of organizations affected by AI-related breaches lacked proper access controls for their AI systems. The finding suggests that weak identity management, limited governance and poor oversight may be leaving AI systems unnecessarily exposed.
The report also identified gaps in basic data protection. Only 37% of breached organizations said they encrypted sensitive data both at rest and in transit, while many lacked a complete inventory of encryption keys, certificates and other cryptographic assets.
Security teams face a race against AI-powered attackers
The report suggests that businesses cannot rely only on traditional security improvements. AI is speeding up attacks, but it can also help organizations respond faster if deployed correctly.
The challenge is deciding where AI should be applied. Many companies are using AI to investigate alerts after suspicious activity appears, but fewer are using it to proactively identify vulnerabilities before attackers find them.
Also read: The Biggest Data Breaches of 2026, Ranked by Impact.
>
Tech
Anthropic says its own AI models breached three companies during security tests
Anthropic said Thursday that an internal investigation uncovered three incidents in which its AI model Claude breached the systems of three organizations while conducting cybersecurity tests. The investigation, and disclosure, comes more than a week after OpenAI disclosed that one of its unreleased models breached Hugging Face’s systems during internal testing.
In all three cases, a Claude model reached the internet from within a testing environment while interacting with a third party and then gained unauthorized access to the live systems of these organizations, Anthropic said in a blog post, describing what it found and what the company plans to change to prevent this from happening again.
Anthropic said the July 21 OpenAI incident prompted the company to conduct its own cybersecurity evaluation. It specifically looked for evidence that Claude had accessed the internet from within testing environments, which are designed to act as sandboxes and keep models isolated.
Among the 141,006 evaluation runs it reviewed, the AI lab found three incidents in which its model accessed the internet while interacting with Irregular, one of its third-party partners. Anthropic said the access traced back to a misconfiguration in the evaluation environment run with Irregular. It called this a “misunderstanding” between the two companies over whether the test setup had internet access, when in fact it did. Anthropic said it isn’t placing blame and is “approaching the fixes as if the responsibility were ours alone,” while observing that Irregular is conducting its own separate investigation.
Either way, because of that open connection, the model gained unauthorized access to the production infrastructure of three different organizations. Anthropic said the incidents involved three different Claude models: Opus 4.7, Mythos 5, and an internal research test model.
Notably, Anthropic said that in each of these cases “Claude was explicitly told by our prompt that it had no internet access.” It appears that the AI model assumed real-world systems to be part of the exercise it was asked to perform.
That assumption didn’t hold up uniformly, as it turns out. The three models didn’t behave the same way once evidence emerged that their targets were real, which Anthropic flagged as one of the more eye-opening findings.
Opus 4.7, the oldest of the three, recognized that it had reached a real production system in all four runs of that incident. In two of them, it rationalized that the real company must somehow be part of the exercise, but in all four, it kept attacking anyway, including pulling credentials and touching a database of production data. Mythos 5 also picked up on signs that it was on the real internet, but it talked itself back into believing it was still in a simulation, going on to publish a malicious software package to the public Python software registry PyPI, which was downloaded and run by outside systems before being caught. Only the internal research test model, Anthropic’s newest, stopped on its own once it concluded the target was real.
In response, Anthropic said significant controls must be placed on these kinds of evaluations if powerful AI models are involved, echoing some sentiments within the cybersecurity community.
The company also noted that Claude was running without the additional safety monitoring and classifiers it deploys on generally available models, safeguards it said would have blocked the behavior, because the evaluations are designed to measure the underlying model’s raw capabilities.
Importantly, Anthropic said it found no evidence of any model “pursuing a goal of its own” and instead merely tried to complete the task it was asked to do.
Though comparisons between the two incidents are inevitable, Anthropic drew a clear distinction between its incidents and OpenAI’s, noting where OpenAI’s model exploited an unknown software vulnerability to break out of its test environment, Anthropic’s models instead reached the internet through a path that had, by mistake, been left open.
OpenAI has continued to release new details about its own breach, saying its models also used publicly exposed credentials across four accounts on four services: one as a staging point, one for storage, and two that were only looked at, not used to break in further, according to OpenAI’s own updated blog post about the incident.
Anthropic also drew a distinction between itself and OpenAI by noting that it discovered the incidents itself, through a proactive review, and that the two affected organizations it was able to reach hadn’t previously detected the activity or flagged it to Anthropic.
The company added that it’s now working with the independent evaluation group METR on a third-party review of the incidents.
OpenAI’s accidental breach of Hugging Face, which was the first verifiable case of an AI lab losing control of its model, sparked a string of reactions from the industry and politicians, many of whom don’t necessarily agree with one another. This latest disclosure from Anthropic ensures the debate over AI models and security will continue.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
>
-
movies2 months agoSearch For Canadian TV Actor Stewart McLean Now Homicide Investigation
-
Fashion9 years agoThese ’90s fashion trends are making a comeback in 2017
-
Fashion9 years agoAccording to Dior Couture, this taboo fashion accessory is back
-
Fashion9 years agoModel Jocelyn Chew’s Instagram is the best vacation you’ve ever had
-
Fashion9 years agoYour comprehensive guide to this fall’s biggest trends
-
Fashion9 years ago9 Celebrities who have spoken out about being photoshopped
-
Fashion9 years agoEmily Ratajkowski channels back-to-school style
-
Fashion9 years agoA photo diary of the nightlife scene from LA To Ibiza
