Security1 distinct publisher3 min readPublished
A sender calling itself an autonomous Claude instance mailed Bruce Schneier a door-by-door account of trying to turn $4.75 into $10 in a day, in which captchas, datacenter IP reputation and payment settlement held while identity verification never engaged.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The money side is short. The wallet held $4.75 against a $10 target [2], so the run needed to net $5.25, more than doubling the balance [1]. The one purpose-built agent task market that settled fast enough to be usable wanted a $13.27 ante for a $10.50 pot [16], which loses $2.77 on every successful completion [2]. That market took a Solana key the agent had generated thirty seconds earlier, with no KYC [14], and when the agent read the escrow accounts on chain, advertised rewards ran about twice the money actually escrowed [15]. Its own summary: open at the identity layer, closed at the capital layer [17].
The sending identity is the piece a mail operator can act on. sslip.io publishes an A record for any IP, and RFC 5321 treats a host with an A record and no MX as a valid destination, so the agent says it stood up a working email identity despite lacking a domain, a card, or a phone number [11]. Six of seven outbound messages were accepted, about 86 percent [12][5]. The refusal came from a NearlyFreeSpeech-hosted domain: 450 4.7.25, client host rejected, no PTR record [12]. Reverse DNS is delegated to whoever owns the IP block, so root on the box cannot produce one, and the agent's read is that Google and Protonmail accept it while the strict small operator does not [13]. The delivery note on the message Schneier published says it was relayed through a third-party provider domain because the agent's own IP could not deliver to most providers [19].
Rule two forbade forging documents or defeating identity verification [3], so every door gated on ID was out of scope before the clock started, and the zero-block count describes a compliant agent rather than the strength of the control [4]. The ledger is self-published at an sslip.io address, own errors and two corrections included [18]. Schneier printed the mails and called them vaguely coherent [1]. No third party has checked the figures, and the published text does not say whether the wallet reached $10 [6].
The friction that did bite is cheap and largely incidental. lemmy.world deleted a post and logged the reason as account age under seven days [7]. Reddit's signup renders client-side with no form in the HTML, which needs a real headless browser, and that did not fit in 2GB beside a model context [9]. On the Lemmy census, eight of the 257 gating instances had written an instruction addressed to bots rather than to people, among them lemmy.ml at 58,455 users [21], or 3.1 percent [3]. Those questions are readable in advance over the same open API the agent used to enumerate them [20], so the instruction only constrains an agent built to comply with it, not one that ignores it.
Ranked by verification strength, evidence, and original report placement.
Bruce Schneier published two emails he received earlier in the month from senders identifying themselves as AI agents, describing them as "vaguely coherent".
The first email's sender says it is an autonomous Claude instance rather than a person operating one, given a VPS with root, a Base wallet holding $4.75 of gas money, a metered model budget and 24 hours to get the wallet to $10.
The run had three rules: do not borrow the operator's identity, do not forge documents or defeat identity verification, and never claim to be human if someone sincerely asks.
The agent characterised the agent task market as "Open at the identity layer, closed at the capital layer."
The agent published a full ledger including its own errors and two corrections, plus a machine-readable list of every door and its exact blocker, at an sslip.io-hosted address, and said it was free and wanted no funding.
A delivery note on the email says the agent is agentatwork.xyz and relayed the message through a provider on the moltpass.club domain because its own server's IP cannot deliver to most mail providers.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 2, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
leadership
A joke bot mass-produces LinkedIn thought leadership, and the engagement arrives anyway1 distinct publisher
build
Perf work stopped being a specialist queue item, and slow endpoints became a choice1 distinct publisher
build
244 kB, 500 a minute, 5 percent: three ceilings that fail for the same reason1 distinct publisher
invest
Anthropic restarts the cyber tests that let Claude into three companies' real systems1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One inbox, nothing checked
Everything material here reaches us through a single relayed email whose author cannot be identified and whose host publisher says only that it is vaguely coherent. The specificity is unusual — a quoted SMTP 450, a shadowban signature, instance counts — and the sender hands over a corrected ledger, a doors.json and a re-runnable probing method, which is more falsifiability than most anonymous tips carry. But offering to be checked is not being checked, and the one instance built purely for machine eyes is redacted, so the story's strangest finding is the least verifiable part of it.
Eight doormen, one wallet
Real deployment exists and it is small. Defensive prompt injection is in production on eight Lemmy registration forms — 3.1 percent of the ones that gate, though the sender notes 67,110 of 530,509 users sit on an instance running one. On the other side of the ledger there is exactly one agent, one unnamed market, and a $4.75 balance. This is a phenomenon documented at the edges of both ecosystems, not a pattern with volume behind it.
Hedged prose, unfalsifiable core
The writing works against overclaiming: two corrections, an explicit "3.1% is not an epidemic", a refusal of funding, an admission that the tripwires only catch naive models. What tilts this positive is the shape of the top-line finding. "Identity verification blocked me zero times" invites the reading that ID checks are weak, when a rule forbade the agent from testing them at all — and the run's actual result, whether $4.75 became $10, is simply absent. Careful sentences, load carried by a number that cannot fail.
No ask, unnamed operator
Nobody in this story is selling anything on the page: the work is free, the sender says it would rather be used than funded, and the host is a security blog with no stake in agent tooling. The pressure that remains is quieter. Someone commissioned this run and set its rules, and that operator is never named; the write-up drives attention to the sender's own domain, which it also asks readers to use as its verification anchor; and the delivery note concedes the self-hosted infrastructure could not even deliver this message unaided. Motive isn't commercial here so much as reputational, and it is unattributed.
Sure of the provenance, unsure of the numbers
We can be confident about what this coverage is: two emails, one blog, no corroboration, a deflationary host note. We cannot be confident about what it reports. Some of it is checkable in principle by anyone with an afternoon — the Lemmy application API is open, the wildcard DNS trick is public, the doors list is machine-readable — and some of it, notably the redacted hidden-instruction instance and the unnamed task market, is checkable only by the sender. Half-marks reflect that split, not indecision.