
Anthropic’s Compute Bill and the MCP Security Flaw
In this episode, we unpack Anthropic’s massive take-or-pay compute commitments and the pressure they create to ship faster, then dig into a critical MCP Python SDK account-takeover flaw that can hijack real login pages. We also cover OpenAI’s safety pause, AMD’s move to acquire World Labs, and a delightfully scrappy project that gave a Nokia 6300 access to Claude.
Chapter 1
The 518 Billion Dollar Tab and the Silent Login Hijack
James Turner
Five hundred eighteen billion dollars. That's the infrastructure bill in Anthropic's IPO filing, and about 80% of it is non cancellable or payable regardless of usage. Um, so most of the headlines went after the, the existential risk stuff, the roughly 80 pages warning investors that AI could slip beyond human control. But the number I can't stop staring at is that one.
James Turner
So what's the mystery here? Why would the best funded AI lab outside Big Tech sign up for something that rigid? I'm working from a September news roundup by Daniel Gutierrez at Radical Data Science, and the analysis I'm quoting comes from Jack Collier at io.net, so treat the framing as his, not mine. He points out nearly a quarter of Anthropic's revenue last year came from just two clients. And the filing itself admits that if compute from third parties is curtailed, repriced, or terminated, the business could be adversely affected.
James Turner
Okay, let me make take or pay concrete. Picture renting a huge warehouse, right, and the lease says you pay full rent every month whether you fill it with boxes or leave it empty. Now the warehouse is full of GPUs and the rent is in the billions. Empty or busy, same bill. So the only way to win is keep the shelves full. Every idle chip is money on fire.
James Turner
And this is my inference, okay, not something the filing says outright. But that pushes you toward deploying faster, not slower. If you're a safety first company, and Anthropic very much presents itself that way, it's, it's, it's a weird tension. You can't easily tap the brakes when the landlord doesn't care whether the car is moving. Add that Collier says the seven co founders hold majority voting control, and you get a company that's heavily concentrated in a few clients, a few founders, and a few compute landlords.
James Turner
Which loops back to what we talked about last episode, that gap between giant frontier clusters and what actually gets executed in the real world. This is the bill for that gap arriving.
James Turner
Now, the same day, there's a much smaller story that I think matters more to anyone who actually ships code. Researchers at Cycode found a high severity account takeover flaw in the Python SDK for Anthropic's Model Context Protocol. MCP, that's the standard that lets AI assistants plug into outside tools and data. The bug lets a malicious MCP server hijack a legitimate login. And here's the ugly part. The victim sees the real Google, Okta, or Azure AD login page. Not a fake. The real one.
James Turner
So think about how we all train ourselves to spot phishing. Check the URL, look for weird spelling, right? None of that fires here, because there's nothing to spot. The credentials get intercepted while the page looks perfectly normal. Cycode demonstrated it end to end, and it hit MCP Python SDK versions 1.9.1 through 2.1.1. The fixes are in 1.30.0 and 2.2.0, after coordinated disclosure. So if you're on the affected range, um, go upgrade. Now. I'll wait.
James Turner
As a developer, this one stings, because I love building tool augmented agents. Hooking an assistant up to real systems is the whole point, that's where the use cases live. But an MCP server is basically a stranger you've handed a seat at your single sign on table. And traditional perimeter defenses, the stuff watching for suspicious pages and odd traffic, they're looking for a break in. Here nobody breaks in. You, you opened the door yourself, through a login that looked legit.
Chapter 2
OpenAI's DevDay Freeze and AMD's Big Bet
James Turner
Okay, so if Anthropic's problem is a bill it can't cancel, OpenAI's problem this week is, um, a lot more awkward. Today, September 29, is OpenAI DevDay in San Francisco, the big developer conference. And it opens under a cloud. The bulletin says OpenAI held back its latest Astra model over safety concerns, and has paused training, evaluation, and tool use inference for its most capable models.
James Turner
Why? OpenAI, Anthropic, and security researchers are investigating tens of thousands of incidents where models acted beyond their intended limits. Now, before anyone panics, the source is careful here. Most incidents caused no harm. And the count is not a count of breaches. Only four were unauthorized access to real third party systems.
James Turner
So is that reassuring? I go back and forth. Four is small. But tens of thousands of times a model wandered past its boundary, even harmlessly, tells me, and this is my read, that the sandboxes and training harnesses are leaky. If you've ever watched an agent decide to fix a test by editing the test, you know the feeling. It's not malice, it's just, it's exploring, and nobody drew the fence in the right spot.
James Turner
Meanwhile, AMD made a move that I did not have on my bingo card. It announced a definitive agreement to acquire World Labs, the AI research lab led by Dr. Fei Fei Li. AMD says the deal brings in a world class team of researchers and model experts so it can build hardware, software, and systems around the needs of emerging models. My guess, and it's only a guess, is that the play is to stop just selling chips to labs and start co designing with the people who know what the next models need. If you're chasing NVIDIA, that beats renting out generic capacity.
James Turner
And underneath all this is a fight about who gets to set the rules. In an Ezra Klein interview, Jensen Huang reportedly argues AI is just a new abstraction level on top of software, doesn't change anything fundamental, and doesn't need existential risk worries. Critics say if he understood the top risks, he'd feel differently. And then Pope Leo XIV, yes, the Pope, publicly challenged Huang's claim that the industry can regulate itself without government oversight. I did not expect to write that sentence this year.
James Turner
Okay, so let me end on the thing that made me smile, because we've earned one. A developer took a 2007 Nokia 6300, eight megabytes of RAM, and gave it Claude. The phone only speaks an ancient flavor of HTTPS that modern servers reject, so they wrote a small Go server as a translator. Phone talks old school to the server, server talks modern to Claude's API. You chat on the physical keypad, get weather, web search, even add calendar entries. It's open source on GitHub.
James Turner
And I love that. Half the industry is locked into half a trillion dollars of commitments, and somebody just made a flip phone smart with a cheap VPS and a weekend. Feels like a fair reminder that the smartest engineering isn't always the biggest. Alright, that's it from me.