Edition 57 | 2026 — Why Trust Doesn't Scale Automatically
✍️ by Amir Kabir | Founding Partner at Overlook VC
🧠 IN THIS ISSUE:
The Take: Why Trust Doesn’t Scale Automatically
The Signal: Claude Mythos || Cracks Post-Quantum Cipher
🔥 1. The Take — Why Trust Doesn’t Scale Automatically
Every time a new technology collapses the cost of creation and distribution, the same thing happens. We celebrate the democratization, then spend the next decade dealing with what the democratization destroyed.
The internet made publishing free and web content exploded, while context collapsed. By the time readers realized that volume without curation was worse than scarcity, they had already migrated to closed communities and human-curated feeds, places where friction was a feature, not a bug.
Social media made connection free; reach exploded and authenticity collapsed. Over 52% of social feed content is now synthetic or heavily automated. Social became the top channel for breaking news at the same moment it became the top distribution channel for synthetic content.
88% of consumers say AI-generated video tools have eroded their trust in the news they see on social media. 50% of Gen Z have blocked, muted, or unfollowed a creator because their content felt like AI slop. The audience for synthetic content is becoming hostile to it and hostile means inattentive.
The platforms optimized for engagement and got a trust deficit they haven’t recovered from. AI is making synthetic output free and generation has exploded, while verification is collapsing.
The problem is that these technologies scale faster than the mechanisms we use to trust what they produce.
Deepfakes now number approximately 8 million online, up from 500,000 two years ago. Video was the floor of credibility. The assumption that seeing meant believing ran through KYC processes, executive approval workflows, identity verification. That assumption no longer holds.
Only 24.5% of humans correctly identify high-quality deepfake videos. Across all types of AI-generated content and repeated testing, 0.1% can reliably tell the difference. 85% of organizations were hit by a deepfake incident in the past twelve months.
Trust has always been a product of friction. You call back on a known number before you wire money. You meet in person before you sign. You verify before you extend credit. The friction is the work that trust requires.
What’s emerging from this is a market for verified provenance. As synthetic output becomes infinite, the scarce thing is authenticity. The premium goes to the credential, the callback, the in-person check, the things that felt like bureaucratic overhead are now the signal that the identity, the content, the request is real.
📡 2. Signal Watch — This Week in Risk
Earlier last week, Anthropic published research showing Claude Mythos Preview broke HAWK, a digital signature scheme under active consideration by NIST for post-quantum cryptography standardization. HAWK had survived two rounds of expert human review over two years. Mythos found an exploitable symmetry in the underlying lattice structure that effectively cuts the key strength in half. The discovery took 60 hours and approximately $100,000 in API cost.
A second result in the same paper: Mythos autonomously developed the “Möbius Bridge,” an attack on 7-round AES that’s 200-800x faster than the previous best approach. The model ran for three days and output roughly one billion tokens. Two researchers then spent nearly a month verifying what Claude found in a week.
“In just one year, language models have gone from being unable to perform cryptanalysis of even the most basic ciphers to being capable of finding flaws in cryptographic designs that have escaped discovery despite years of human expert review.” — Anthropic
Neither result breaks production systems today.
HAWK isn’t deployed, and the AES attack is against a reduced 7-round variant, not the full 10-round cipher. Anthropic followed responsible disclosure, coordinated with NIST, and shared advance copies with government and industry partners.
Whether these specific ciphers failed matters less than what the capability trajectory means for everything downstream.
Post-quantum cryptography is the planned migration path away from algorithms vulnerable to quantum computers. Organizations are still mid-transition. NIST’s standardization process is the trust anchor for that migration.
One of the candidate schemes just got weakened by an AI running for 60 hours, after human experts missed the same flaw for two years. The standardization process caught it, which is how it was supposed to work. But the throughput asymmetry is the problem: AI is now discovering cryptographic weaknesses faster than the human review infrastructure can validate or respond to them. Anthropic said as much, noting they expect the cryptography field to face the same verification bottleneck that vulnerability triage is already experiencing.
The $100K cost to find a major cryptographic weakness is a number worth sitting with. That’s accessible to sophisticated threat actors, nation-state labs, and well-funded research teams that are not publishing what they find.
What to watch: whether NIST accelerates its PQC timeline in response, how other frontier labs disclose comparable capabilities, and whether the cyber insurance market starts pricing post-quantum migration risk differently now that AI-assisted cryptanalysis is a demonstrated capability at commercial API rates.
🔭 Coming Next Week
Topic: The Machine Risk Economy
We’ll explore:
Insurance Becomes Infrastructure
— Amir
Founder, Managing Partner – Overlook VC
Twitter: @AmirKabir99 | 🔗 LinkedIn
🔗 Sign Up Executive Risk Dinners



Good stuff I think NISTwill have to accelerate it's being at the forefront of a lot of these developments but needs to go faster otherwise it will basically soon be a kite Mark not worth holding.