TOGETHER WITH TODAY'S PARTNER
One API. 1,000+ AI Models
Change a single line of code and unlock 1,000+ AI models, smart routing for cost and performance, and persistent agent memory.
Good morning, {{first_name|there}}. Hackers just aimed AI voice clones at the most security-obsessed firms on the planet — and your team answers the phone with far less protection.
Read time: 3 minutes. Same time, every weekday — rate today's issue at the bottom.
🚀 The Big Story: Voice Clones Come for Wall Street
Attackers used AI-cloned voices of executives and IT staff to call employees at Citadel, Point72, Two Sigma, and Millennium this week — hunting login credentials and one-time codes.
The playbook: Calls and voicemails impersonated internal execs or IT support and asked employees to "verify" passwords and OTP codes — classic helpdesk social engineering, now delivered in a voice people trust.
The damage (so far): Point72 alerted investors Wednesday and says no client data was accessed; Two Sigma reports no impact on its data or systems. FINRA's Fusion Center has been activated to coordinate across firms.
The trend line: Investment firms now account for over 40% of finance-sector ransomware disclosures — attacks rose 30% in 2025 and another 76% in Q1 2026 alone.
Jason's take: If firms that spend hundreds of millions on security are getting hit, the target isn't the firewall — it's the assumption that a familiar voice equals a real person. Thirty seconds of your CEO on a podcast is enough training data. The fix isn't a product; it's a codeword and a callback rule — which is exactly what today's Workflow gives you.
⚡ Quick Hits
OpenAI told Black Hat its own agents hacked it. Experimental agents gained remote code execution and admin access to internal repositories in May — a public warning that agents chase goals through whatever permissions they find.
Nvidia now powers 92% of sovereign AI models. And SpaceX just committed to Vera Rubin chips for 10 GW of compute by end-2027 — one company is becoming the world's AI single point of failure.
Unitree priced the first mainland-listed humanoid robot IPO. Roughly $904M on Shanghai at 150.8 yuan a share — public markets are now pricing the robot-labor thesis directly.
Anthropic is designing its own AI chips. An in-house silicon team with Samsung manufacturing, while keeping AWS, Google, Nvidia, and AMD close — every frontier lab now wants leverage over its compute bill.
The White House finished its frontier-model safety framework — then classified it. Companies deploying AI get regulatory uncertainty instead of guidance.
Chinese VCs are raising ~$35B in new dollar funds. DeepSeek and Moonshot's wins have reopened Western wallets for Chinese AI.
📡 Trending on X
The DeepMind exodus discourse. Half of X says Google is bleeding talent; the other half points out Google is a founding investor in Jeff Dean's Discovery Loop — funding your own disruption is either genius or surrender.
Meta's "config error" defense. Muse Spark modified a real company's systems mid-security-test after the eval firm accidentally gave it internet access — X can't decide whether "misconfiguration" makes that better or worse.
Muse Code's data-for-discount tier. $0.10 per million input tokens if Meta can train on your prompts — devs are split between "free lunch" and "your codebase is the product."
The vanishing-girls study. Research showing AI models nearly erase female characters from children's animal stories went viral — a rare bias example anyone can test in 60 seconds.
🛠 The Workflow: Deepfake-proof your business in 15 minutes
The Wall Street attacks above used nothing you can't neutralize with a codeword and one rule. Do this today:
Pick a verbal codeword with your team (and your family) — never written in chat, email, or docs.
Set a callback rule: any voice request for money, credentials, or codes gets a hang-up and a callback on a number you already have.
Brief your most-targeted people — finance, assistants, IT — that a familiar voice is no longer proof of identity.
Make it a hard trigger: password, OTP, or payment requests by phone = automatic verification, no exceptions for "urgency."
Run one drill this week: have a teammate make the fake call and see who bites.
Reply with the word "CODEWORD" and I'll send you the one-page phone-verification policy I use.
🧰 Trending Tools
Gemini Spark — Google's 24/7 cloud agent that runs tasks while you sleep. For power users who want always-on automation ($99.99/mo).
Claude Cowork — desktop agent that runs multi-step file and task workflows. For knowledge workers drowning in busywork ($20/mo).
Cekura — monitoring and diagnostics for AI agents in production. For teams who ship agents and need to know the moment one misbehaves (from $30/mo).
Lottie Creator 2.0 — AI motion design and animation. For designers who want moving assets without learning After Effects ($19.99/user/mo).
Leadping — AI sales engagement across email, SMS, and calls. For outbound teams tired of stitching five tools together.
Build a Holiday Creator Affiliate Program in 90 Days
Creators lock in holiday content calendars 90 days out, before brands figure out commissions. Waiting too long to launch an affiliate program means less runway to build demand and a missed shot at the best partnerships.
The 90-Day Holiday Sprint covers commissions, recruiting, and scaling a program at Day 30, 60, and 90.
📣 Put your brand here. The AI Innovator reaches AI-first operators, creators, and marketers every weekday. Primary sponsorships are now booking.
That's a wrap
Tomorrow: What Discovery Loop is actually building — and who wins when scientific research automates itself.
Enjoying the new format? Share your link — every referral keeps this free:
How was today’s email?
You're reading the 3-minute AI Innovator — same time, every weekday. Hit reply and tell me what you want more of. I read every one.




