NEWS
The Brief
Tristan Buckmaster's short statement, posted on his NYU page, is the primary source. Read it before the coverage.
Top Story
Three Lean-verified proofs of finite-time blowup with smooth forcing went public today — for the incompressible porous media equation, for Boussinesq, and for 3D incompressible Euler — and the document announcing them is also the first serious public integrity dispute of the AI-for-mathematics era. Tristan Buckmaster’s short statement, posted on his NYU page, is the primary source. Read it before the coverage.
The mathematics is not in doubt at the level Buckmaster claims. He and Levent Alpöge obtained the Boussinesq and Euler results on August 15th and had them verified in Lean on August 22nd. The writeups, he says plainly, are poor: “The Euler writeup, in particular, can only be described as AI slop.” He names the tools — Anthropic’s Claude, OpenAI’s Codex with GPT-5.6 Sol, and more recently Astra, the last used only for writeups and auditing — and says the ideas are Diego Córdoba’s and Luis Martínez-Zoroa’s, whose forced-blowup program he and Alpöge extended from rough to smooth forcing and to Euler. He states that Martínez-Zoroa deserves a Fields Medal. He also holds back a fourth result: blowup for hypo-dissipative Navier-Stokes, withheld because Lean verification isn’t finished, and he flags it as suggestive of a path to unforced Euler. That ordering — certificate first, readable paper later — is the real methodological event here, and it is what makes the rest of the document checkable at all.
The rest of the document is an account of what OpenAI told him. On September 3rd, with a rumor circulating that Anthropic had solved a major open problem, Buckmaster emailed a mathematician at OpenAI to head it off; he quotes the email and the reply, which offered compute. On September 6th he and Sebastien Bubeck spoke twice by phone, without Alpöge. He was told an internal OpenAI model had proved finite-time blowup for forced Navier-Stokes in R³ and T³, smooth forcing, “option c and d in Fefferman,” roughly 100 pages. He has not seen it.
His interpretation is the crux. The smooth-forcing route into the Clay problem is precisely the one Córdoba and Martínez-Zoroa opened and that he and Alpöge had quietly chosen — “almost nobody else I know of was working on it,” he writes. It is not where you land by handing a model the problem statement. So when the word was “forced,” that was the tell. What emerged over the course of the calls was that a team had been working on it, that the unforced problem was tried first, that models were tried on easier problems including Euler, that the prompt shown to him had itself been written by prompting Codex, and that the first prompt was sent in the days after word of his and Alpöge’s work reached OpenAI. He asked twice whether their Codex sessions — where the whole project’s drafts lived — had been used for training. He says he did not get an answer.
Two proposals were put to him: post Euler and let OpenAI post Navier-Stokes the next day, or have him alone author the Navier-Stokes paper crediting the model, with Alpöge removed from authorship. He says Bubeck asked twice for Alpöge’s removal and called it annoying that Alpöge works at Anthropic. Buckmaster declined both, said he would go public, and reports the reply: “Why would you ruin your career?” followed by “If you don’t want me to be nice, then I don’t have to be nice.”
Be careful about what this establishes. Buckmaster says he is not accusing anyone of anything, and he is right to hedge: he has not seen the proof, does not know what the model did, and does not know whether his data was used. His own account is the only source for everything in the calls, and OpenAI has not responded in it. What is established is narrower and still serious — that a frontier lab described a result to a rival group’s author, in terms matching that group’s unpublished program, after the fact, and then proposed an authorship arrangement that would have removed that group’s other author.
The thing to watch is not the argument. It is two artifacts: the Lean certificate for hypo-dissipative Navier-Stokes, which is still running, and the 100-page proof plus the prompt, which OpenAI either publishes or does not. Navier-Stokes – Tristan Buckmaster [pdf]
Also Today
Google DeepMind Releases AlphaGenome Atlas · Source AlphaGenome Atlas turns DeepMind’s variant-effect model into an artifact: predicted regulatory impact for all 9 billion single-nucleotide variants of the human genome, precomputed into a 1-petabyte dataset and collapsed behind one number — the AVI score — queryable from a browser with no code. The cited wins are triage, not proof: Broad’s Laura Covill used a predicted DNM1 splice site as supporting evidence in an unsolved rare-disease case, and Gareth Hawkes found 22% more non-coding associations across 54,000-plus UK Biobank participants. A precomputed lookup table inherits every blind spot of the model that filled it, and the marketing offers no per-variant error bar. Worth watching whether anyone publishes one; without it, AVI is a ranking, not a measurement.
Mistral raises €3B to make sovereign, open-weight AI the technology frontier · Source Mistral closed a €3 billion Series D at a post-money valuation above €21 billion — the largest equity round a European tech company has raised — led by Samsung Electronics, with Scaleup Europe Fund (managed by EQT) and PSG Equity co-leading. That follows a Series C led by ASML: two capital-equipment giants buying a hedge against dependence on American model vendors. The sovereign pitch is concrete — open weights, private compute, auditable deployment, no vendor roadmap lock-in — and covers 125-plus enterprises including Airbus, ASML and HSBC. But €3 billion is nearer one hyperscaler’s quarterly capex than a frontier training budget, so it buys durability as Europe’s default stack, not parity at the frontier.
Automatic Key Exchange: faster, post-quantum secure origin handshakes for 45 billion daily connections (and counting) · Source Cloudflare replaced its static X25519 keyshare guess toward origins with a measurement: probe each origin for the key-agreement groups it actually supports, lead with the strongest it will accept — X25519MLKEM768 first where possible — and canary the preference per origin with automatic rollback if retries spike. HelloRetryRequests fell from roughly 52% to 3.7%, cutting more than 150 ms off p90 handshake latency, and hundreds of thousands of domains now negotiate post-quantum origin connections nobody configured. Origin PQ support is still only 12.8%, up from 0.5% in 2023. Harvest-now-decrypt-later is the reason it matters, and the only way to close it at scale is to stop asking every site operator to make a cryptographic decision themselves.
DHS ‘Predictive Policing’ Unit Is Analyzing Americans’ Financial Habits · Source 404 Media named a DHS program that had been operating largely out of sight: Predictive Intelligence Targeting Teams, run by Border Patrol, which analyze Americans’ financial activity and other data and feed it to local police for stops of people suspected of no specific crime. One documented case: a man driving through Montana, stopped under the pretense of an obstructed license plate, then charged with DUI. CBP declined to say what financial activity it monitors or whether it obtained a warrant, citing operational security; CDT’s Jake Laperruque calls the result parallel construction. When the stated reason for a stop is pretext, the real predicate never gets tested in court — and neither does the system that produced it.
I’ve factored the RSA keys of a Certificate Authority from the 90s · Source Root certificates shipped inside 1990s browsers had no minimum key size, so Matthew McPherrin went hunting for something factorable and found it: E-Certify’s 512-bit RSA roots, distributed with Netscape 4.51 in March 1999, removed in 2002, expired the following year. CADO-NFS on a Ryzen 9 5950X took 32 hours for the SSL root and 29 for the S/MIME one; he then wrote a Go TLS server archaic enough for Netscape 4.51 to talk to, and published the private keys. Nothing live is broken. What has changed is the cost curve: a research-lab result of 1999 is now a desktop overnight, and the argument for retiring keys before the arithmetic catches up.
In Brief
- OpenAI launched ChatGPT Images 2.5, citing more than 3 billion images generated across its image products — a usage figure rather than a capability claim. (Source)
- Gamers Nexus reports LG televisions continuing to emit network traffic for tracking even when powered off or in standby, the latest entry in a long-running smart-TV privacy genre. (Source)
- LibreOffice 26.8, released August 26, became the project’s most-downloaded update ever after the Document Foundation publicly advertised that it ships no AI features. (Source)
- A fork of deltafin runs the 2.8-trillion-parameter Kimi K3 at roughly one token per second on an Apple Silicon laptop by streaming weights from four SSDs, with benchmark manifests published. (Source)
- Weird Gloop finished migrating the Overwatch and Fortnite wikis off Fandom, framing the move around what it calls a ‘Google Jail’ that buries independent wikis in search. (Source)
- Among European companies that use a CDN at all, close to nine in ten are on Cloudflare — a concentration figure worth remembering the next time an edge provider has a bad day. (Source)
- Qualcomm signed Amazon as a data-center chip customer in an agreement spanning multiple generations, broadening the supply race as another reported deal in the same segment collapsed. (Source)
- Google will restructure Search in Europe — promoting comparison services like Expedia and Hotels.com and stripping some real-time features — to avoid EU Digital Markets Act fines rather than litigate them. (Source)
- Apple is preparing its largest product launch in years, expected to include the first foldable iPhone after roughly a decade of development. (Source)
- OpenAI’s GPT-6 Astra is now available on Amazon Bedrock, running on the cloud provider’s own inference stack — another frontier model arriving through a hyperscaler distribution channel. (Source)
- The NIH has reportedly agreed to route part of its budget into Department of Defense research, a transfer of biomedical money toward defense priorities with no public scientific rationale yet offered. (Source)
- Apple faces new UK obligations over nude imagery reaching children’s iPhones, adding regulatory pressure to a device-level content problem the company has preferred to handle by policy rather than technical control. (Source)
One Line
The bottom line is genuine probable cause cannot be synthetically generated.
— Jake Laperruque, deputy director of the Security and Surveillance Project at the Center for Democracy & Technology, to 404 Media