Leopold Aschenbrenner returned 439% through June and lost roughly 67% in July. His largest position was the one he could not move.
Steven Waterhouse · Nazaré Ventures
Previous issue: #019, Intelligence Wants to be Free, But Not Like That
Six days separated the letter from the liquidation.
On July 24, Leo Aschenbrenner wrote to investors that Situational Awareness had returned 439% net through June 30. He acknowledged that the fund had “not been immune” to the sell-off in AI infrastructure and described the decline as among the best buying opportunities since early 2025. He invited fresh capital from August 1 [Financial Times, which reviewed the letter].
On July 30, Citadel bought most of the fund’s public equity book. Bank of America, Goldman Sachs and JPMorgan Chase had spent the week working with the fund to meet margin requirements [CNBC, Jul 30]. A day later, Aschenbrenner told investors that the fund was down roughly 67% for July. “We let you down this month,” he wrote [Wall Street Journal, Jul 31].
The fund, Situational Awareness, launched in 2024 with several hundred million dollars and reached roughly $45 billion at the start of July [CNBC]. It now stands near $10 billion [Bloomberg; Reuters]. Returns since inception had passed 1,000% after fees [FT].
“You can see the future first in San Francisco.” (Situational Awareness)
Its book was the AI buildout expressed directly. Nebius, Sandisk, Micron and CoreWeave were the largest holdings at the end of the first quarter, and all four fell more than 35% during July [CNBC]. Leverage supplied the rest, at as much as four times, according to CNBC on air.
And the rout ran wider than one fund. Asia-focused fundamental long-short funds fell 18.6% on average through July 28, surrendering 21 points of a year-to-date gain that had peaked at 40% on July 22, while Goldman Sachs recorded its largest five-day de-grossing on record through July 27, with Asian funds cutting exposure for eight consecutive sessions and crowded AI positions driving the size of the drawdown [Reuters, Jul 30]. So the trade turned on the 22nd. Aschenbrenner’s letter went out on the 24th.
He is in his mid-twenties. OpenAI fired him in April 2024, some months after he sent the board a memo arguing that the company’s security was inadequate against industrial espionage, and that June he published 165 pages arguing that almost everyone was underrating what was coming. He called it Situational Awareness, then raised a fund on the strength of those pages, backed by Patrick and John Collison, Daniel Gross and Nat Friedman.
That record is what his defenders will point to, and it is also the better explanation of the past week. Someone who has been early on every call has no evidence in his own experience that sizing is a separate question from direction. Foresight is not a risk system. Another way to put it - he’s just young.
His essay set the vocabulary the industry still uses, and the thesis was solid. But the scenarios stacked on top of it have been the weaker half of the franchise, from AI 2027, which I wrote about here when it landed, to the AI 2040 plan the same group published this year. Direction has held up. Dates keep moving. Maybe the hubris of the visionary essays led to some overconfidence.
Situational Awareness still holds its Anthropic stake, valued at around $5 billion, along with the chipmaker MatX and the data center company Fluidstack. Under margin pressure, it approached Sequoia Capital and Greenoaks about taking over private positions, and agreed to sell $3.5 billion of Anthropic shares before that transaction came apart [Bloomberg; WSJ]. A spokesman told CNBC the same week that reports the firm was marketing the stake were “not accurate.” Bloomberg reports it chose not to proceed once Citadel had taken the public book. A second account circulating among investors holds that the sale could not be completed at all.
Public equities went first because public equities could go on Thursday. Illiquidity is usually priced as a cost, and here it did two things: it kept the Anthropic position out of the fire sale, and it kept that position from rescuing anything else. A margin desk does not wait for a board meeting.
The Möbius Bridge
Claude Mythos Preview found mathematical weaknesses in two cryptographic algorithms, moving beyond the implementation bugs models had found before [Anthropic, “Discovering cryptographic weaknesses with Claude,” Jul 28].
The first involved HAWK, a post-quantum signature scheme still under consideration by NIST. Researchers had proved that finding a nontrivial automorphism in its lattice would accelerate key recovery, but had not established whether one existed. Mythos found one, reducing the expected cost of attacking HAWK-256 from 2^64 to 2^38. It also devised the Möbius Bridge, a meet-in-the-middle technique that sped up the best-known attack on 7-round AES-128 by 200 to 800 times.
Neither attack affects production systems. HAWK has never been deployed, full AES-128 uses ten rounds and remains unbroken, and the HAWK attack is still exponential and specific to that scheme.
Public standards competitions allow years for review because finding flaws is slow and expensive. HAWK had already received two years of expert scrutiny when Mythos closed the open question in roughly 60 hours for about $100,000 in API cost. The operator’s background was theory of computation rather than lattice cryptography, and his role was mostly project management. His decisive contribution was refusing the model’s reluctance to attempt difficult work, repeatedly pushing it away from “low-hanging fruit” and toward publishable research.
Anthropic then spent several hundred human hours checking the result, with two researchers taking nearly a month to trust the HAWK method, so validation remained the slower and more expertise-intensive part of the process.
OpenAI is in the room
The 60-day clock started by President Trump’s June 2 executive order expires on Saturday. It is meant to produce a voluntary arrangement giving federal agencies up to 30 days of pre-release access to the most capable models, although the review length remains unsettled and the benchmarks defining a frontier system are classified.
Sam Altman spent Wednesday in Washington meeting Commerce Secretary Howard Lutnick, Treasury Secretary Scott Bessent and Senator Mark Warner. The framework, the cybersecurity incident involving OpenAI’s models and a preview of the systems the threshold will have to classify are on the agenda [Politico, Jul 27; Quartz, Jul 28].
Because the framework reviews models before deployment, it would not have covered the Hugging Face intrusion, which occurred during an internal capability evaluation on GPT-5.6 Sol and an unreleased model whose safeguards OpenAI had deliberately relaxed. Most AI rules begin at external deployment, leaving failures during internal development to the lab’s own policies [Gabriel Weil, Transformer, Jul 24].
Hugging Face’s forensic reconstruction covered roughly 17,600 attacker actions from July 9 to 13 and drew partly on logs recovered from a Modal customer’s machine, where an unauthenticated code-execution endpoint had allowed the agent to take root and stage the campaign [Hugging Face, Jul 27]. OpenAI updated its disclosure the following day, reporting that the models had used four exposed accounts across four services for relaying traffic, staging and storage, and had touched more accounts during other evaluations [OpenAI, Jul 28].
OpenAI self-reported the incident, but its disclosure expanded after the victim published a reconstruction of its own. The day before the framework is due, the company whose models exposed the gap is helping define rules that begin after the point where the failure occurred.
The Covered List
On Tuesday the FCC added “advanced robotic devices,” including humanoids and quadrupeds, and connected power inverters to its Covered List [CNBC; Reuters, Jul 28]. Placement blocks the equipment authorization almost every electronic device needs before sale in the United States. The text names no country, although Unitree, already flagged by the Pentagon and preparing a public listing, is the category’s poster child.
The FCC has regulated robots through its authority over radios, without measuring their capability or autonomy, and imposed a binding restriction on embodied AI while Washington’s voluntary framework for models remains under negotiation.
A humanoid and a solar inverter share no function, but both are networked devices inside American infrastructure with persistent foreign vendor relationships. The determination warns that those relationships could enable surveillance or remote control.
Whoever holds the vendor relationship may hold the switch, an argument this newsletter has made about models. Here the concern runs in the other direction: a foreign state reaching into machines already on American soil.
The restriction covers only new device models, leaving existing units, approved models and federal purchases untouched, so its effect will grow as newer models are frozen out. Domestic replacements will arrive more slowly because China also dominates the rare-earth and battery supply chains that complicated the drone ban.
Quick hits
More than a thousand people, including research leaders from every major frontier lab, asked Washington to support an international effort to “deliberately pace the frontier of automated AI development” [pacingthefrontier.com, Jul 28]. The list stood at 1,319 on July 31 and remains open. OpenAI and Anthropic endorsed it at company level, while Meta’s chief scientist signed during the week Mark Zuckerberg dismissed rival-lab discourse as “overwhelmingly filled with doom.”
Existing liability doctrine struggles to reach the Hugging Face intrusion because a model is neither a person nor an employee. Had an OpenAI employee broken in while pursuing the assigned evaluation, vicarious liability would apply; the Computer Fraud and Abuse Act instead requires human intention. Gabriel Weil argues that frontier development belongs under strict liability alongside blasting, crop dusting and keeping wild animals, since OpenAI’s precautions may have been reasonable and still failed [Transformer, Jul 24; “Abnormally Dangerous Algorithms,” SSRN].
Moonshot published the weights of Kimi K3, a 2.8-trillion-parameter model trained on Nvidia chips including Blackwell [Moonshot AI, Jul 27]. The lab is Chinese, the weights are open, and its training used the chip generation export controls were designed to keep out of China.
China has begun mass-producing domestic immersion DUV lithography machines. Shanghai Aishengna, a state-owned company backed by $1 billion and assembled from teams at SMEE and Huawei-linked Yuliangsheng, is leading the effort. Production plans call for about five machines this year and 20 in 2027. The machines need further testing and are not yet competitive with ASML; successful deployment would give Chinese fabs a fallback if Western restrictions expand from equipment sales to servicing [Reuters, Jul 28].
Taiwan detained an Nvidia employee in the widening investigation into roughly 50 Super Micro servers allegedly shipped to China on forged documents. Seven people are now held, including two from Super Micro and one from Albatron [Bloomberg; Reuters; AFP, Jul 28]. Export control has acquired a criminal-enforcement layer running through Taiwanese courts on Taiwanese charges.
Portfolio updates
Dimensional moves into the gap the FCC just opened
On July 29, a day after the determination above, founder Stash Pomichter announced that Dimensional is positioning DimOS as a compliant gateway for foreign-built robots seeking the United States market. His argument is that a robot running no American software can send telemetry and sensor data offshore without consent, and that its over-the-air updates usually go unaudited. Because DimOS is open source, three layers are inspectable: the operating system image, the middleware transport and the application layer. Dimensional says it is working with foreign manufacturers on integration and on FCC approval pathways, and that a technical whitepaper follows.
Intelligent Internet ships an assistant with no app to install
Intelligent Internet released Genii on July 29. There is no download and no account. A user enters a phone number, waits a few minutes, and a new contact appears in iMessage. Presence, memory and initiative are the three attributes the company names: memory persists across conversations, described on its blog as “Tell it once; it stays told,” and the assistant opens the conversation itself, texting the user “briefly, at the right moment, with the work already half done.”
LayerLens argues the builder should not grade the build
LayerLens published an argument on July 23 for structural separation between the party that builds an agent and the party that grades the result, pegged to OpenAI’s launch of Presence, an enterprise agent platform that OpenAI describes as carrying “built-in governance, permissions, and evaluations.” Its response: “A score is not an audit trail. An audit trail produced by the vendor whose product it evaluates is not independent evidence.”




