Claude Found a 4-Year Zcash Bug. Now It Won't Audit DeFi: Uneasy Money artwork

Claude Found a 4-Year Zcash Bug. Now It Won't Audit DeFi: Uneasy Money

Unchained

June 12, 2026

Claude Fable 5 refuses security work, Kain Warwick pulls $5,000 of compute from a $200 plan, and Humanity Protocol loses its bridge, token, and treasury to one infected device. ======================================================== Thank you to our sponsors!
Speakers: Kain Warwick, Luca Netz, Taylor Monahan
**Kain Warwick** (0:00)
So, if you think about that, it's in the course of a couple of days, because I ran this overnight multiple times, $5,000 on the API for $200. And that was only my weekly limits for that week. I had three more weeks of that. So, it's very possible that I could have burned through like $20,000 worth of API credits on this account for $200.
And at that point, I was like, this is insanity. Like, this is, I knew it was subsidized, but like, it's subsidized to a level, it's 100x subsidized. It's crazy. Hey everyone, I'm Kain Warwick, and welcome to Uneaten Money, because what happens on Chained never stays on Chained. Before we begin, here is a word from the sponsors that make this show possible.

**SPEAKER_2** (0:57)
Multi-Chain Advisors is an emerging technology growth firm that has helped create $50-plus billion in enterprise value for 80-plus clients over the past four years.
They're the partner to help navigate markets. Build real traction today at multichainadv.com.

**Kain Warwick** (1:17)
All right, hey everyone, I'm here with my co-host, Taylor Monahan, Security Expert and Luca Netz, CEO of Pudgy Penguins.
So our first segment this week is something that I think we've all been waiting for, and then we all got rubbed. So that was exciting. They're like, Mythos is coming. It's going to kill everyone. It's the best thing ever and also incredibly dangerous. And then they're like, actually, just kidding. We're releasing a different model, Fable 5 And I think the first thing for me, like no one in my team, because I pointed this out on my team, was like, oh yeah, we've all become like so used to the insane naming conventions of AI. You cannot release a thing that has never existed before and call it 5
This is a crime of net.

**Luca Netz** (2:12)
You can't be like, oh, Fable 5

**Kain Warwick** (2:13)
Where's Fable 1 through 4? Like it's just Fable, bro. Like what the hell are you guys doing? They just make up these nonsensical names. It's almost as bad as open AI that went like, oh, three and then four and then back to three again. And then like crazy. Anyway, so we finally got Mythos, a Mythos class agent, Mythos class model, which was super cocked apparently in a bunch of ways. And they, I guess, have had Project Glasswing running now for like six weeks, and people have been slowly rolling out, whatever. So the new model hit, and of course, everyone immediately was like, let's see if we can hack some DeFi shit. And it refused to. So Joe DeLong, definitely a guy that would probably be happy to hack some DeFi stuff if he could get away with it, was like, yeah, it just outright refuses to do a smart contract audit.
And so I think like there's two things here. One, there are all of the safeguards. They've had now like six weeks, eight weeks or whatever, to put a bunch of safeguards, stop it from doing cybersecurity stuff, biology, weird chemistry shit, no life extension from Fable, unfortunately. We're not going to be biohacking ourselves.
But there is obviously, and I saw this this morning, when I woke up, the more you like constrain something, the more like excited everyone's going to be to jailbreak it.
So it looked like there is, I saw one tweet from someone who has a whole jailbreaking system using other agents like Jailbroken Opus 4.8 to try and jailbreak Fable and has been able to get it to provide info on bombs and stuff. So it feels a little futile to try and lock these things down and people always seem to be able to work around it. But here we are. That's the situation that we're in. Have you guys used Fable yet?

**Taylor Monahan** (4:38)
I tried.

**Kain Warwick** (4:41)
To act some stuff?

**Taylor Monahan** (4:43)
No, just do some 99 percent of the things that I use AI for these days is like incident response, finding stuff, doing reports on stuff, connecting stuff. If we have a huge amount of profiles or Githubs or whatever, just it'll go to town. It'll even feed a repos, you can feed it profiles, you can feed it a few different data sets, and they'll figure out all these other things that used to be super tedious. It's all security related, because ultimately these are usually threat actors or trying to find threat actors or report on the threat actors, et cetera.
It's not that it's like, well, yeah, it just immediately downgrades. The second, and like we've always dodged the safeguards that are in Opus, which are more feisty than all the others. Like you can ask like Haifu something and it'll try.

46 more minutes of transcript below

Feed this to your agent

Try it now — copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/1000772295351