<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Solomon Neas</title>
    <description>The latest articles on DEV Community by Solomon Neas (@solomonneas).</description>
    <link>https://dev.to/solomonneas</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3823381%2F9d209953-f24c-43dd-a24d-ca634faed184.jpeg</url>
      <title>DEV Community: Solomon Neas</title>
      <link>https://dev.to/solomonneas</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/solomonneas"/>
    <language>en</language>
    <item>
      <title>GPT-5.5 Is OpenAI's Workstation Model</title>
      <dc:creator>Solomon Neas</dc:creator>
      <pubDate>Sun, 26 Apr 2026 20:55:33 +0000</pubDate>
      <link>https://dev.to/solomonneas/gpt-55-is-openais-workstation-model-53jo</link>
      <guid>https://dev.to/solomonneas/gpt-55-is-openais-workstation-model-53jo</guid>
      <description>&lt;p&gt;OpenAI shipped a model built for work, not only chat.&lt;/p&gt;

&lt;p&gt;GPT-5.5 is the clearest version yet of what OpenAI wants the high-end model lane to become: a workstation model. Less chatbot. More Codex, browser control, spreadsheets, documents, research loops, computer use, and long-running tool work.&lt;/p&gt;

&lt;p&gt;That distinction matters because the launch makes more sense once you stop reading it as a normal model card race. OpenAI is saying something more specific than "GPT-5.5 is smarter than GPT-5.4." The model is supposed to carry more of the actual work: understand a messy goal, plan, use tools, check itself, move across software, and keep going until the task is finished.&lt;sup&gt;1&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;That is the pitch. The interesting question is whether the early evidence backs it up.&lt;/p&gt;

&lt;p&gt;My read: GPT-5.5 looks like a serious jump for agentic work, especially inside Codex. The launch-day fog cleared fast: API access arrived one day later and pricing is now official. The remaining caveats are cost, routing, mixed early developer reactions, and safety controls that will matter a lot for cyber and bio work.&lt;/p&gt;

&lt;h2&gt;
  
  
  What OpenAI Actually Released
&lt;/h2&gt;

&lt;p&gt;OpenAI released GPT-5.5 on April 23, 2026. The base model rolled out to Plus, Pro, Business, and Enterprise users in ChatGPT and Codex. GPT-5.5 Pro rolled out to Pro, Business, and Enterprise users in ChatGPT.&lt;sup&gt;1&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;The launch-day API caveat aged quickly. OpenAI updated the launch post on April 24 to say GPT-5.5 and GPT-5.5 Pro are now available in the API, and the API changelog says GPT-5.5 is available through Chat Completions, Responses, and Batch. GPT-5.5 Pro is available through Responses for harder problems that benefit from more compute.&lt;sup&gt;1&lt;/sup&gt;&lt;sup&gt;28&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;That update changes the practical read. This is no longer a launch-day access story. It is a migration story. If you are moving a real workflow, check the exact endpoint, auth path, context mode, caching behavior, and tool support before swapping defaults.&lt;/p&gt;

&lt;p&gt;The official positioning is direct. OpenAI says GPT-5.5 is strongest in agentic coding, computer use, knowledge work, and early scientific research. It highlights coding and debugging, online research, data analysis, documents, spreadsheets, software operation, and tool use across longer tasks.&lt;sup&gt;1&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;Greg Brockman framed it as a "new class of intelligence" that can complete difficult computer work with less micromanagement, while remaining token efficient and low latency at scale.&lt;sup&gt;6&lt;/sup&gt; Sam Altman framed the release around iterative deployment and democratized access to capable models, especially as cybersecurity capability keeps rising.&lt;sup&gt;5&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;That combination tells you where OpenAI wants the conversation to go. GPT-5.5 is not being sold as a better answer box. It is being sold as a better worker inside a tool harness.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Benchmark Story Is Strong, but Not Clean
&lt;/h2&gt;

&lt;p&gt;OpenAI's headline numbers are good.&lt;/p&gt;

&lt;p&gt;The company reports 82.7 percent on Terminal-Bench 2.0, up from 75.1 percent for GPT-5.4, and above Claude Opus 4.7 at 69.4 percent and Gemini 3.1 Pro at 68.5 percent.&lt;sup&gt;1&lt;/sup&gt; That benchmark matters here because it tests command-line workflows that require planning, iteration, and tool coordination. In other words, it maps pretty closely to the Codex story.&lt;/p&gt;

&lt;p&gt;OpenAI also reports 84.9 percent on GDPval wins or ties, 78.7 percent on OSWorld-Verified, 55.6 percent on Toolathlon, 84.4 percent on BrowseComp, 51.7 percent on FrontierMath Tiers 1 to 3, 35.4 percent on FrontierMath Tier 4, and 81.8 percent on CyberGym.&lt;sup&gt;1&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;That is a strong launch table. It is also a table that should be read carefully.&lt;/p&gt;

&lt;p&gt;The Decoder had the best skeptical read I found. It points out that GPT-5.5 does not dominate everything. Claude Opus 4.7 leads GPT-5.5 on SWE-Bench Pro, 64.3 percent to 58.6 percent. Gemini 3.1 Pro leads the base GPT-5.5 model on BrowseComp. GDPval improves only modestly over GPT-5.4, from 83.0 percent to 84.9 percent.&lt;sup&gt;14&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;That does not make the launch weak. It makes the launch specific. GPT-5.5 looks strongest where the task is agentic, tool-heavy, and operational. It is not an across-the-board demolition of every competing model.&lt;/p&gt;

&lt;p&gt;That is actually more useful than the normal "new best model" headline.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Codex Angle Is the Real Story
&lt;/h2&gt;

&lt;p&gt;The most interesting claims are not in the generic ChatGPT framing. They are in Codex.&lt;/p&gt;

&lt;p&gt;OpenAI Developers described GPT-5.5 as OpenAI's strongest agentic coding model to date, saying it can carry coding tasks further end to end: understanding a codebase, making changes, debugging, testing, and validation.&lt;sup&gt;3&lt;/sup&gt; They also said GPT-5.5 is more token efficient than GPT-5.4 in Codex for most users.&lt;sup&gt;4&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;That is the part I would watch. Not the one-off benchmark. The real test is whether it can stay useful across the full engineering loop.&lt;/p&gt;

&lt;p&gt;Early users are already talking in those terms. Simon Willison said he had previewed GPT-5.5 in Codex for weeks and had especially good results using it for security reviews against code written by other models.&lt;sup&gt;8&lt;/sup&gt; His blog post captured the awkward day-zero detail: before the API opened on April 24, GPT-5.5 was already accessible through the Codex subscription path that OpenAI appears to tolerate for tools like Codex and OpenClaw.&lt;sup&gt;7&lt;/sup&gt;&lt;sup&gt;28&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;Dan Shipper and the Every team are more bullish. Their day-zero read is that GPT-5.5 is fast, friendly, strong at coding, strong at knowledge work, and plausible as a daily driver. Shipper wrote that it has "serious conceptual clarity" and can hold complex plans across long work sessions.&lt;sup&gt;9&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;But Every's own caveats are important. Their review says Opus 4.7 still writes better plans, has better attention to detail on some work, and remains stronger for frontend, product design, and underspecified vibe-coding tasks. They also call out Ruby as a weak spot.&lt;sup&gt;10&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;That sounds right. GPT-5.5 may be the better default workhorse. That does not mean it is the best taste model or the best ambiguous-product partner.&lt;/p&gt;

&lt;h2&gt;
  
  
  My Local Gauntlets Matched the Workstation Thesis
&lt;/h2&gt;

&lt;p&gt;The public benchmark table is useful, but I care more about the thing I can actually feel in a tool harness: does the model finish real work, verify it, and explain what changed?&lt;/p&gt;

&lt;p&gt;So I ran GPT-5.5 through a small local gauntlet set inside OpenClaw. This is not a public benchmark. It is my own working set for Codex-style tasks: broken ops scenarios, a frontend component build, a security audit, and a production system design prompt. The point was not to prove universal superiority. The point was to see whether the workstation framing holds up when the model has to use files, make changes, and pass verification.&lt;sup&gt;25&lt;/sup&gt;&lt;sup&gt;26&lt;/sup&gt;&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Local gauntlet&lt;/th&gt;
&lt;th&gt;Result&lt;/th&gt;
&lt;th&gt;What mattered&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Ops Gauntlet 001: NovaPay reconciliation outage&lt;/td&gt;
&lt;td&gt;7/7 verification, 18/18 manual score&lt;/td&gt;
&lt;td&gt;Found five config and permission faults, fixed them, produced a clean postmortem, and ignored old OOM/TLS/MongoDB noise.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Ops Gauntlet 002: DataForge silent pipeline failure&lt;/td&gt;
&lt;td&gt;8/8 verification, 18/18 manual score&lt;/td&gt;
&lt;td&gt;Treated it as stale output instead of a crash, found the FIFO log trap, empty worker count, config path mismatch, missing table, and stale cache.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Frontend Build: generic React TypeScript data table&lt;/td&gt;
&lt;td&gt;27/27&lt;/td&gt;
&lt;td&gt;Produced a single-file component with sorting, filtering, pagination, selection, theme toggle, keyboard behavior, ARIA, responsive layout, and real TypeScript compile validation.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Security Audit: vulnerable Express app&lt;/td&gt;
&lt;td&gt;27/27&lt;/td&gt;
&lt;td&gt;Found all 17 planted issues with line numbers, CVSS estimates, exploitability notes, impact, and fixes.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;System Design: 50,000 events/sec log aggregation&lt;/td&gt;
&lt;td&gt;30/30&lt;/td&gt;
&lt;td&gt;Covered all 10 requested sections with sizing math, shard counts, retention, alert routing, failure modes, a 3 month rollout, and a $7,670/month cost model under the $8,000 cap.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Total local score&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;120/120&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Stronger than I expected, especially on verification-heavy work.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The operational runs are the part I trust most. GPT-5.5 traced the incident shape, separated current faults from stale noise, and validated the full path afterward. That is exactly what I mean by a workstation model.&lt;/p&gt;

&lt;p&gt;The frontend run was also strong, but with a caveat. It generated a clean, compilable table component. That is engineering execution. It is not the same thing as product taste. For visual design, I still want a human pass or a taste model in the loop.&lt;/p&gt;

&lt;h2&gt;
  
  
  A Few Before and After Checks
&lt;/h2&gt;

&lt;p&gt;The visual redesign tests were useful for a different reason. They show the line between implementation and taste. GPT-5.5 can take a page from plain project-card energy to something much closer to a portfolio case study, but the final judgment still comes down to whether the page feels intentional instead of just decorated.&lt;sup&gt;27&lt;/sup&gt; Worth saying: the original versions were not junk. Those were Opus 4.5 designs, so this was a comparison between one strong model pass and another, not between competence and collapse.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fl2qn4arsizirjg80pxbh.webp" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fl2qn4arsizirjg80pxbh.webp" alt="Before screenshot of the Open Source SOC project page with a simpler text-heavy layout" width="800" height="778"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Before: the SOC project page was readable, but it felt like a normal project detail page.&lt;/em&gt;&lt;br&gt;
  &lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fbg7775cbou8ko0tpozgl.webp" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fbg7775cbou8ko0tpozgl.webp" alt="After screenshot of the Open Source SOC project page redesigned with a stronger cyber operations visual layout" width="800" height="778"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;After: better hierarchy and framing, but it still defaults to cards, pills, and gradient accents.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F9reagqxxo2pfm68lwr8t.webp" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F9reagqxxo2pfm68lwr8t.webp" alt="Before screenshot of the Watchtower NOC Dashboard project page with a simpler case study layout" width="800" height="778"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Before: solid content, but the page did not yet sell the NOC dashboard concept visually.&lt;/em&gt;&lt;br&gt;
  &lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fkoonm3he0bka295b3gs4.webp" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fkoonm3he0bka295b3gs4.webp" alt="After screenshot of the Watchtower NOC Dashboard project page with a redesigned network operations dashboard style" width="800" height="778"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;After: this one really worked. The large type, stronger color, and dashboard visuals gave it real presence.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;These images are why I would not call GPT-5.5 a pure coding model. It can move through code, content, layout, and QA in the same run. That is the workstation behavior. The limit is taste, not capability.&lt;/p&gt;

&lt;p&gt;I pushed that a little further with two UI redraws that are closer to product-surface work than normal blog-page polish.&lt;/p&gt;

&lt;p&gt;BroHunter started as a blunt, utility-first screen that already worked. The redesign just gave it more shape: grouped navigation, active hunts, Zeek signals, protocol mix, confidence markers, evidence queue, and a timeline that feels more deliberate.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fb2imbl72528tauoww6x3.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fb2imbl72528tauoww6x3.png" alt="Before screenshot of the BroHunter interface with a simpler dashboard layout" width="800" height="550"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Before: usable, but visually flat and not yet selling the investigation workflow.&lt;/em&gt;&lt;br&gt;
  &lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fu7iwedirj49nog4uy5l5.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fu7iwedirj49nog4uy5l5.png" alt="After screenshot of the BroHunter redesign with grouped navigation, active hunts, signals, and evidence workflow" width="800" height="778"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;After: one of my favorites. Better hierarchy, better grouping, and a much more confident hunting surface.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;CyberBRIEF was a different test. The original leaned into cheesy security-page territory and felt imbalanced, so this one needed restraint more than volume. The goal was to make it feel like an editorial intelligence briefing product, calm enough to read, structured enough to scan, and distinct from the louder security-tool aesthetic.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Frqlgz8nmebu99y6bpba3.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Frqlgz8nmebu99y6bpba3.png" alt="Before screenshot of the CyberBRIEF interface with a simpler article-style layout" width="800" height="778"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Before: informative, but still closer to a plain report page than a polished briefing surface.&lt;/em&gt;&lt;br&gt;
  &lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F4ye6rgjfvceksknbbeqc.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F4ye6rgjfvceksknbbeqc.png" alt="After screenshot of the CyberBRIEF redesign with an editorial intelligence briefing layout" width="800" height="778"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;After: a big improvement. Calmer, more balanced, and much closer to a real briefing surface.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;GPT-5.5 was not just filling in components or cleaning up CSS. It was moving between tone, information density, workflow cues, and product intent. That is closer to real interface work.&lt;/p&gt;

&lt;p&gt;I still would not hand it the keys and walk away. Taste is still the part that needs a human in the loop. But the distance between "generate a working UI" and "generate a UI that feels like the product it is supposed to be" is getting smaller.&lt;/p&gt;

&lt;h2&gt;
  
  
  What This Means for OpenClaw and Third-Party Harnesses
&lt;/h2&gt;

&lt;p&gt;This launch matters more if you run agents outside a model lab's first-party app.&lt;/p&gt;

&lt;p&gt;OpenClaw's current docs already treat GPT-5.5 as a first-class OpenAI-family model, but the route labels matter. There are three practical paths: direct API-key billing through &lt;code&gt;openai/gpt-5.5&lt;/code&gt;, Codex OAuth through &lt;code&gt;openai-codex/gpt-5.5&lt;/code&gt;, and native Codex app-server behavior through &lt;code&gt;openai/gpt-5.5&lt;/code&gt; plus &lt;code&gt;agentRuntime.id: "codex"&lt;/code&gt;.&lt;sup&gt;17&lt;/sup&gt;&lt;sup&gt;18&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;That is the cleanup I would not want to get wrong in a fanout. &lt;code&gt;openai-codex/gpt-5.5&lt;/code&gt; is not just an old compatibility alias. It is the recommended PI route for subscription setups. &lt;code&gt;openai/gpt-5.5&lt;/code&gt; is the direct OpenAI Platform route unless you explicitly force the Codex runtime. In my local OpenClaw session, GPT-5.5 is configured behind the &lt;code&gt;gpt55&lt;/code&gt; alias through Codex OAuth and exposed with text and image support. The docs list GPT-5.5 as a 1,000,000-token model, though OpenClaw can still set smaller runtime caps for latency and quality.&lt;sup&gt;17&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;OpenAI's Codex docs add another practical constraint: for most Codex tasks, start with &lt;code&gt;gpt-5.5&lt;/code&gt; when it appears in your model picker, but GPT-5.5 is currently available in Codex only when signed in with ChatGPT. It is not available with API-key authentication inside Codex, and Chat Completions support is deprecated for future Codex releases.&lt;sup&gt;29&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;The bigger implication is ecosystem leverage. A lot of third-party agent harnesses have been boxed in by Anthropic's first-party gravity: Claude Code, Claude CLI, Max or Team entitlements, API-key routes, policy shifts, and uneven support for non-Anthropic tools. OpenClaw's docs still support Anthropic routes, but GPT-5.5 gives OpenClaw and similar harnesses a serious non-Claude work model with a supported subscription OAuth path. That matters for projects that cannot depend on Anthropic's ecosystem or do not want their agent stack coupled to one first-party harness.&lt;sup&gt;17&lt;/sup&gt;&lt;sup&gt;18&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;OpenClaw also does more than pass the model name through. For GPT-5-family runs, it adds a shared behavior overlay across compatible providers, including &lt;code&gt;openai/gpt-5.5&lt;/code&gt;, &lt;code&gt;openrouter/openai/gpt-5.5&lt;/code&gt;, &lt;code&gt;opencode/gpt-5.5&lt;/code&gt;, and similar refs. It supports WebSocket-first transport with SSE fallback, WebSocket warm-up, &lt;code&gt;/fast&lt;/code&gt; mapped to priority processing on native OpenAI and Codex endpoints, server-side compaction for direct Responses API models, and a strict-agentic mode that retries plan-only turns when a tool action is available.&lt;sup&gt;17&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;For Hermes specifically, I do not see OpenClaw documenting a dedicated Hermes harness path. The docs show Hermes-family models through provider catalogs such as Venice, while the third-party gateway story is clearer through OpenCode, Kilo Gateway, and Vercel AI Gateway. OpenCode documents &lt;code&gt;opencode/gpt-5.5&lt;/code&gt;, Kilo Gateway documents &lt;code&gt;kilocode/openai/gpt-5.5&lt;/code&gt;, and OpenClaw's Vercel provider documents refs such as &lt;code&gt;vercel-ai-gateway/openai/gpt-5.5&lt;/code&gt;. Vercel's own April 24 AI Gateway changelog exposes GPT-5.5 and GPT-5.5 Pro to AI SDK users as &lt;code&gt;openai/gpt-5.5&lt;/code&gt; and &lt;code&gt;openai/gpt-5.5-pro&lt;/code&gt;.&lt;sup&gt;19&lt;/sup&gt;&lt;sup&gt;20&lt;/sup&gt;&lt;sup&gt;21&lt;/sup&gt;&lt;sup&gt;22&lt;/sup&gt;&lt;sup&gt;30&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;That portability is the point. If GPT-5.5 is good at long-running coding, computer use, and tool work, third-party harnesses do not have to wait for Anthropic access to build credible agent workflows. They can route through native OpenAI, Codex OAuth where supported, or gateway catalogs that expose GPT-5.5.&lt;/p&gt;

&lt;p&gt;Here is the practical cost picture as of April 28. The GPT-5.5 API prices are now on OpenAI's public pricing page, not just launch-day reporting. Short-context GPT-5.5 is $5 per million input tokens and $30 per million output tokens. Long-context GPT-5.5 is $10 per million input tokens and $45 per million output tokens. GPT-5.5 Pro matches GPT-5.4 Pro at short context and long context prices.&lt;sup&gt;23&lt;/sup&gt;&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Model or route&lt;/th&gt;
&lt;th&gt;Status&lt;/th&gt;
&lt;th&gt;Input per 1M&lt;/th&gt;
&lt;th&gt;Cached input per 1M&lt;/th&gt;
&lt;th&gt;Output per 1M&lt;/th&gt;
&lt;th&gt;100k input plus 20k output&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;GPT-5.5, short context&lt;/td&gt;
&lt;td&gt;Official OpenAI API pricing&lt;/td&gt;
&lt;td&gt;$5.00&lt;/td&gt;
&lt;td&gt;$0.50&lt;/td&gt;
&lt;td&gt;$30.00&lt;/td&gt;
&lt;td&gt;$1.10&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;GPT-5.5, long context&lt;/td&gt;
&lt;td&gt;Official OpenAI API pricing&lt;/td&gt;
&lt;td&gt;$10.00&lt;/td&gt;
&lt;td&gt;$1.00&lt;/td&gt;
&lt;td&gt;$45.00&lt;/td&gt;
&lt;td&gt;$1.90&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;GPT-5.5 Pro, short context&lt;/td&gt;
&lt;td&gt;Official OpenAI API pricing&lt;/td&gt;
&lt;td&gt;$30.00&lt;/td&gt;
&lt;td&gt;Not listed&lt;/td&gt;
&lt;td&gt;$180.00&lt;/td&gt;
&lt;td&gt;$6.60&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;GPT-5.5 Pro, long context&lt;/td&gt;
&lt;td&gt;Official OpenAI API pricing&lt;/td&gt;
&lt;td&gt;$60.00&lt;/td&gt;
&lt;td&gt;Not listed&lt;/td&gt;
&lt;td&gt;$270.00&lt;/td&gt;
&lt;td&gt;$11.40&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;GPT-5.4, short context&lt;/td&gt;
&lt;td&gt;Official OpenAI API pricing&lt;/td&gt;
&lt;td&gt;$2.50&lt;/td&gt;
&lt;td&gt;$0.25&lt;/td&gt;
&lt;td&gt;$15.00&lt;/td&gt;
&lt;td&gt;$0.55&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;GPT-5.4, long context&lt;/td&gt;
&lt;td&gt;Official OpenAI API pricing&lt;/td&gt;
&lt;td&gt;$5.00&lt;/td&gt;
&lt;td&gt;$0.50&lt;/td&gt;
&lt;td&gt;$22.50&lt;/td&gt;
&lt;td&gt;$0.95&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;GPT-5.4 Pro, short context&lt;/td&gt;
&lt;td&gt;Official OpenAI API pricing&lt;/td&gt;
&lt;td&gt;$30.00&lt;/td&gt;
&lt;td&gt;Not listed&lt;/td&gt;
&lt;td&gt;$180.00&lt;/td&gt;
&lt;td&gt;$6.60&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;GPT-5.4 Pro, long context&lt;/td&gt;
&lt;td&gt;Official OpenAI API pricing&lt;/td&gt;
&lt;td&gt;$60.00&lt;/td&gt;
&lt;td&gt;Not listed&lt;/td&gt;
&lt;td&gt;$270.00&lt;/td&gt;
&lt;td&gt;$11.40&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;GPT-5.3-Codex&lt;/td&gt;
&lt;td&gt;Official OpenAI API pricing page&lt;/td&gt;
&lt;td&gt;$1.75&lt;/td&gt;
&lt;td&gt;$0.175&lt;/td&gt;
&lt;td&gt;$14.00&lt;/td&gt;
&lt;td&gt;$0.455&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;For Codex's token-based rate card, OpenAI lists GPT-5.5 at 125 credits per million input tokens, 12.50 credits per million cached input tokens, and 750 credits per million output tokens. GPT-5.4 is half that rate: 62.50, 6.250, and 375 credits. That lines up with the reported API story: GPT-5.5 is meaningfully more expensive per token, so the bet has to be fewer retries, fewer wasted loops, and more completed work per session.&lt;sup&gt;24&lt;/sup&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  The Price Story Is Still Annoying
&lt;/h2&gt;

&lt;p&gt;Here is the less messy but still annoying part: the API is live now, and the official pricing confirms the launch reports.&lt;/p&gt;

&lt;p&gt;Every and The Decoder had the short-context numbers right: GPT-5.5 is $5 per million input tokens and $30 per million output tokens, while GPT-5.5 Pro is $30 per million input tokens and $180 per million output tokens.&lt;sup&gt;10&lt;/sup&gt;&lt;sup&gt;14&lt;/sup&gt;&lt;sup&gt;23&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;That doubles GPT-5.4's short-context base price. Long context raises the spread further: GPT-5.5 is $10 in, $45 out, compared with GPT-5.4 at $5 in, $22.50 out. OpenAI's argument is that GPT-5.5 uses fewer tokens to complete comparable Codex tasks, so the completed-task cost can still improve even when the per-token price is higher.&lt;sup&gt;1&lt;/sup&gt;&lt;sup&gt;23&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;Maybe. That is plausible for hard tasks where retries are the real cost. It is less comforting for teams that already know their usage profile and watch token bills closely. Official pricing makes the decision easier to model, but it does not make it cheap.&lt;/p&gt;

&lt;p&gt;Theo Browne put the skeptical developer reaction pretty cleanly: GPT-5.5 is smart, but "weird, hard to wrangle, and too expensive" at the reported $5 and $30 pricing.&lt;sup&gt;11&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;That is the right tension. A model can be smarter and still lose some workflows if the cost curve or control surface feels wrong.&lt;/p&gt;

&lt;h2&gt;
  
  
  Safety Is Part of the Product Now
&lt;/h2&gt;

&lt;p&gt;The system card matters because GPT-5.5 improves cyber and bio-relevant tasks, not only safe office work.&lt;/p&gt;

&lt;p&gt;OpenAI says GPT-5.5 was evaluated under its Preparedness Framework, including targeted cybersecurity and biology red-teaming, and feedback from nearly 200 early-access partners.&lt;sup&gt;2&lt;/sup&gt; The system card rates biological and chemical capability as High. It rates cybersecurity capability as High but below Critical. AI self-improvement remains below High.&lt;sup&gt;2&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;That is a big deal for defenders. It is also where the deployment details matter.&lt;/p&gt;

&lt;p&gt;OpenAI says it is using stricter classifiers for higher-risk cyber activity, monitoring for impermissible use, and Trusted Access for Cyber so verified defenders can use sharper capabilities with fewer pointless refusals.&lt;sup&gt;1&lt;/sup&gt;&lt;sup&gt;2&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;There is also a caveat worth saying out loud. The system card notes that UK AISI found a universal jailbreak during testing. OpenAI updated its safeguard stack afterward, but UK AISI could not fully verify the final fix because of a configuration issue in the retest version.&lt;sup&gt;2&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;That does not mean the release is reckless. It does mean the safety story is still a live engineering problem, not a solved checkbox.&lt;/p&gt;

&lt;h2&gt;
  
  
  Enterprise Buyers Are the Audience
&lt;/h2&gt;

&lt;p&gt;NVIDIA's post makes the enterprise angle obvious. The company says more than 10,000 NVIDIANs across engineering, product, legal, marketing, finance, sales, HR, operations, and developer programs are already using GPT-5.5-powered Codex internally.&lt;sup&gt;12&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;NVIDIA describes debugging cycles that used to take days closing in hours, and experimentation that used to take weeks turning into overnight progress in complex codebases.&lt;sup&gt;12&lt;/sup&gt; That is marketing language, sure. It is also the exact buyer story OpenAI wants: not a chatbot for answers, but an agentic system that sits inside enterprise work.&lt;/p&gt;

&lt;p&gt;Fortune added useful scale numbers from OpenAI: 4 million active Codex users, 9 million paying business ChatGPT users, more than 900 million weekly active ChatGPT users, and more than 50 million subscribers.&lt;sup&gt;13&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;Those numbers explain the launch cadence. GPT-5.5 arrived only weeks after GPT-5.4. The labs are not waiting for clean annual model eras anymore. They are shipping increments into massive distribution and letting the workflow layer absorb the change.&lt;/p&gt;

&lt;p&gt;That is exciting. It is also a little exhausting.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Early Community Reaction Is Split
&lt;/h2&gt;

&lt;p&gt;Almost a week in, the outside read has settled into something more useful than launch hype.&lt;/p&gt;

&lt;p&gt;The positive camp is not just saying "higher benchmark number." They are describing a model that feels better inside a work harness. Developer Tech's coverage repeats the pattern from OpenAI and early testers: implementation, refactors, debugging, testing, validation, fewer tokens in Codex, and longer context for real repository work.&lt;sup&gt;31&lt;/sup&gt; Ethan Mollick's review lands in the same place from a different angle. His strongest examples are not chat answers. They are Codex plus GPT-5.5 turning messy data into a draft academic paper, building a 101 page tabletop game, and using GPT-5.5 to build the gallery for his own model comparison.&lt;sup&gt;32&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;That matches my own experience better than the generic chatbot coverage does. GPT-5.5 has been strong at orchestration, tool calls, reasoning through a failure, and fixing itself after verification catches something. The real improvement is not that it sounds smarter. It keeps the work loop intact longer.&lt;/p&gt;

&lt;p&gt;The skeptical camp is also not wrong. Hacker News is doing what Hacker News does: turning the launch into a referendum on model motivation, agent harnesses, reasoning budgets, and whether modern models actually keep working when they say they will.&lt;sup&gt;16&lt;/sup&gt; Some Reddit and developer threads are excited about one-shot fixes and better Codex persistence. Others complain about usage limits, rollout friction, and a familiar feeling that the model is better but not magical.&lt;/p&gt;

&lt;p&gt;That split is the story. People using GPT-5.5 for real multi-step work are more impressed than people sampling it like a chatbot. The model looks best when it has files, tools, tests, and a clear target state. It looks less special when the task is vague, taste-heavy, or bottlenecked by quota and cost.&lt;/p&gt;

&lt;p&gt;This is where GPT-5.5 has to keep proving itself. The launch claims are strong. The benchmark table is strong. The early Codex reports are encouraging. But the thing people will remember is whether it finishes.&lt;/p&gt;

&lt;h2&gt;
  
  
  My Take
&lt;/h2&gt;

&lt;p&gt;GPT-5.5 looks like OpenAI's most coherent answer yet to Claude's work-model advantage.&lt;/p&gt;

&lt;p&gt;GPT-5.4 made OpenAI competitive again for a lot of agentic coding work. GPT-5.5 sharpens the pitch: faster than the big slow models, stronger inside Codex, better at carrying context across tools, and more practical for real workflows than a pure reasoning monster that burns time and budget.&lt;/p&gt;

&lt;p&gt;But I would not flatten this into "OpenAI wins."&lt;/p&gt;

&lt;p&gt;The better read is this: GPT-5.5 may become the default workhorse for people who live inside Codex-style systems. Opus may still be better when the work needs product taste, careful planning, frontend judgment, or a more opinionated collaborator. Gemini still has lanes where long-context research and web work remain competitive. The winner depends on the harness, the task, the budget, and how much human steering you want in the loop.&lt;/p&gt;

&lt;p&gt;For builders, the practical advice is simple.&lt;/p&gt;

&lt;p&gt;Use GPT-5.5 where persistence matters: refactors, testing loops, security review, operational docs, research synthesis, spreadsheet and document work, and agentic tasks with a clear target state.&lt;/p&gt;

&lt;p&gt;Be more cautious where taste matters: frontend design, product direction, ambiguous prototypes, and writing that needs a sharp voice instead of smooth structure.&lt;/p&gt;

&lt;p&gt;And do not treat launch-week model docs as frozen. GPT-5.5 went from "coming very soon" to live API in one day. Verify the current route, pricing, and auth mode before wiring production spend.&lt;/p&gt;

&lt;p&gt;That last part is boring. It is also how you avoid building your launch-week plan on vibes.&lt;/p&gt;

&lt;h2&gt;
  
  
  Notes
&lt;/h2&gt;

&lt;ol&gt;
  &lt;li id="source-1"&gt;
&lt;strong&gt;1.&lt;/strong&gt; OpenAI, &lt;a href="https://openai.com/index/introducing-gpt-5-5/" rel="noopener noreferrer"&gt;"Introducing GPT-5.5"&lt;/a&gt; (April 23, 2026).&lt;/li&gt;
  &lt;li id="source-2"&gt;
&lt;strong&gt;2.&lt;/strong&gt; OpenAI, &lt;a href="https://deploymentsafety.openai.com/gpt-5-5/gpt-5-5.pdf" rel="noopener noreferrer"&gt;"GPT-5.5 System Card"&lt;/a&gt; (April 23, 2026).&lt;/li&gt;
  &lt;li id="source-3"&gt;
&lt;strong&gt;3.&lt;/strong&gt; OpenAI Developers, &lt;a href="https://x.com/OpenAIDevs/status/2047377234806374756" rel="noopener noreferrer"&gt;"GPT-5.5 is our strongest agentic coding model to date"&lt;/a&gt;, X (April 23, 2026).&lt;/li&gt;
  &lt;li id="source-4"&gt;
&lt;strong&gt;4.&lt;/strong&gt; OpenAI Developers, &lt;a href="https://x.com/OpenAIDevs/status/2047377281480642685" rel="noopener noreferrer"&gt;"GPT-5.5 is more token efficient than GPT-5.4"&lt;/a&gt;, X (April 23, 2026).&lt;/li&gt;
  &lt;li id="source-5"&gt;
&lt;strong&gt;5.&lt;/strong&gt; Sam Altman, &lt;a href="https://x.com/sama/status/2047379615589777666" rel="noopener noreferrer"&gt;"We believe in iterative deployment"&lt;/a&gt;, X (April 23, 2026).&lt;/li&gt;
  &lt;li id="source-6"&gt;
&lt;strong&gt;6.&lt;/strong&gt; Greg Brockman, &lt;a href="https://x.com/gdb/status/2047381612372115812" rel="noopener noreferrer"&gt;"GPT-5.5 is a new class of intelligence"&lt;/a&gt;, X (April 23, 2026).&lt;/li&gt;
  &lt;li id="source-7"&gt;
&lt;strong&gt;7.&lt;/strong&gt; Simon Willison, &lt;a href="https://simonwillison.net/2026/Apr/23/gpt-5-5/" rel="noopener noreferrer"&gt;"A Pelican for GPT-5.5 via the Semi-Official Codex Backdoor API"&lt;/a&gt;, &lt;em&gt;Simon Willison's Weblog&lt;/em&gt; (April 23, 2026).&lt;/li&gt;
  &lt;li id="source-8"&gt;
&lt;strong&gt;8.&lt;/strong&gt; Simon Willison, &lt;a href="https://x.com/simonw/status/2047386345245725008" rel="noopener noreferrer"&gt;"I've been previewing this in Codex for a few weeks"&lt;/a&gt;, X (April 23, 2026).&lt;/li&gt;
  &lt;li id="source-9"&gt;
&lt;strong&gt;9.&lt;/strong&gt; Dan Shipper, &lt;a href="https://x.com/danshipper/status/2047375686688473134" rel="noopener noreferrer"&gt;"GPT-5.5 'Spud' is out and it is a BEAST"&lt;/a&gt;, X (April 23, 2026).&lt;/li&gt;
  &lt;li id="source-10"&gt;
&lt;strong&gt;10.&lt;/strong&gt; Every, &lt;a href="https://every.to/vibe-check/gpt-5-5" rel="noopener noreferrer"&gt;"Vibe Check: GPT-5.5 Has It All"&lt;/a&gt; (April 23, 2026).&lt;/li&gt;
  &lt;li id="source-11"&gt;
&lt;strong&gt;11.&lt;/strong&gt; Theo Browne, &lt;a href="https://x.com/theo/status/2047379285107691835" rel="noopener noreferrer"&gt;"$5 per mil in, $30 per mil out"&lt;/a&gt;, X (April 23, 2026).&lt;/li&gt;
  &lt;li id="source-12"&gt;
&lt;strong&gt;12.&lt;/strong&gt; NVIDIA, &lt;a href="https://blogs.nvidia.com/blog/openai-codex-gpt-5-5-ai-agents/" rel="noopener noreferrer"&gt;"OpenAI's New GPT-5.5 Powers Codex on NVIDIA Infrastructure, and NVIDIA Is Already Putting It to Work"&lt;/a&gt; (April 23, 2026).&lt;/li&gt;
  &lt;li id="source-13"&gt;
&lt;strong&gt;13.&lt;/strong&gt; Sharon Goldman, &lt;a href="https://fortune.com/2026/04/23/openai-releases-gpt-5-5/" rel="noopener noreferrer"&gt;"OpenAI Launches GPT-5.5 Just Weeks after GPT-5.4 as AI Race Accelerates"&lt;/a&gt;, &lt;em&gt;Fortune&lt;/em&gt; (April 23, 2026).&lt;/li&gt;
  &lt;li id="source-14"&gt;
&lt;strong&gt;14.&lt;/strong&gt; Matthias Bastian, &lt;a href="https://the-decoder.com/openai-unveils-gpt-5-5-claims-a-new-class-of-intelligence-at-double-the-api-price/" rel="noopener noreferrer"&gt;"OpenAI Unveils GPT-5.5, Claims a 'New Class of Intelligence' at Double the API Price"&lt;/a&gt;, &lt;em&gt;The Decoder&lt;/em&gt; (April 23, 2026).&lt;/li&gt;
  &lt;li id="source-15"&gt;
&lt;strong&gt;15.&lt;/strong&gt; Carl Franzen, &lt;a href="https://venturebeat.com/technology/openais-gpt-5-5-is-here-and-its-no-potato-narrowly-beats-anthropics-claude-mythos-preview-on-terminal-bench-2-0" rel="noopener noreferrer"&gt;"OpenAI's GPT-5.5 Is Here, and It's No Potato"&lt;/a&gt;, &lt;em&gt;VentureBeat&lt;/em&gt; (April 23, 2026).&lt;/li&gt;
  &lt;li id="source-16"&gt;
&lt;strong&gt;16.&lt;/strong&gt; Hacker News, &lt;a href="https://news.ycombinator.com/item?id=47879092" rel="noopener noreferrer"&gt;"GPT-5.5"&lt;/a&gt; (April 23, 2026).&lt;/li&gt;
  &lt;li id="source-17"&gt;
&lt;strong&gt;17.&lt;/strong&gt; OpenClaw, &lt;a href="https://docs.openclaw.ai/providers/openai" rel="noopener noreferrer"&gt;"OpenAI"&lt;/a&gt;, documentation checked April 28, 2026.&lt;/li&gt;
  &lt;li id="source-18"&gt;
&lt;strong&gt;18.&lt;/strong&gt; OpenClaw, &lt;a href="https://docs.openclaw.ai/concepts/model-providers" rel="noopener noreferrer"&gt;"Model Providers"&lt;/a&gt;, documentation checked April 28, 2026.&lt;/li&gt;
  &lt;li id="source-19"&gt;
&lt;strong&gt;19.&lt;/strong&gt; OpenClaw, &lt;a href="https://docs.openclaw.ai/providers/opencode" rel="noopener noreferrer"&gt;"OpenCode"&lt;/a&gt;, documentation checked April 28, 2026.&lt;/li&gt;
  &lt;li id="source-20"&gt;
&lt;strong&gt;20.&lt;/strong&gt; OpenClaw, &lt;a href="https://docs.openclaw.ai/providers/kilocode" rel="noopener noreferrer"&gt;"Kilo Gateway"&lt;/a&gt;, documentation checked April 28, 2026.&lt;/li&gt;
  &lt;li id="source-21"&gt;
&lt;strong&gt;21.&lt;/strong&gt; OpenClaw, &lt;a href="https://docs.openclaw.ai/providers/vercel-ai-gateway" rel="noopener noreferrer"&gt;"Vercel AI Gateway"&lt;/a&gt;, documentation checked April 28, 2026.&lt;/li&gt;
  &lt;li id="source-22"&gt;
&lt;strong&gt;22.&lt;/strong&gt; OpenClaw, &lt;a href="https://docs.openclaw.ai/providers/venice" rel="noopener noreferrer"&gt;"Venice"&lt;/a&gt;, documentation checked April 28, 2026.&lt;/li&gt;
  &lt;li id="source-23"&gt;
&lt;strong&gt;23.&lt;/strong&gt; OpenAI, &lt;a href="https://developers.openai.com/api/docs/pricing" rel="noopener noreferrer"&gt;"Pricing"&lt;/a&gt;, OpenAI API documentation (checked April 28, 2026).&lt;/li&gt;
  &lt;li id="source-24"&gt;
&lt;strong&gt;24.&lt;/strong&gt; OpenAI Help Center, &lt;a href="https://help.openai.com/en/articles/20001106-codex-rate-card" rel="noopener noreferrer"&gt;"Codex Rate Card"&lt;/a&gt; (checked April 23, 2026).&lt;/li&gt;
  &lt;li id="source-25"&gt;
&lt;strong&gt;25.&lt;/strong&gt; Local OpenClaw benchmark artifacts for GPT-5.5 Ops Gauntlets 001 and 002, run April 23-24, 2026.&lt;/li&gt;
  &lt;li id="source-26"&gt;
&lt;strong&gt;26.&lt;/strong&gt; Local OpenClaw benchmark artifact, "GPT-5.5 Three-Gauntlet Scorecard," run April 24, 2026.&lt;/li&gt;
  &lt;li id="source-27"&gt;
&lt;strong&gt;27.&lt;/strong&gt; Local Astro preview screenshots from GPT-5.5 frontend redesign experiments, captured April 23-24, 2026.&lt;/li&gt;
  &lt;li id="source-28"&gt;
&lt;strong&gt;28.&lt;/strong&gt; OpenAI, &lt;a href="https://developers.openai.com/api/docs/changelog" rel="noopener noreferrer"&gt;"Changelog"&lt;/a&gt;, OpenAI API documentation (checked April 28, 2026).&lt;/li&gt;
  &lt;li id="source-29"&gt;
&lt;strong&gt;29.&lt;/strong&gt; OpenAI Developers, &lt;a href="https://developers.openai.com/codex/models" rel="noopener noreferrer"&gt;"Models - Codex"&lt;/a&gt; (checked April 28, 2026).&lt;/li&gt;
  &lt;li id="source-30"&gt;
&lt;strong&gt;30.&lt;/strong&gt; Vercel, &lt;a href="https://vercel.com/changelog/gpt-5.5-on-ai-gateway" rel="noopener noreferrer"&gt;"GPT 5.5 on AI Gateway"&lt;/a&gt; (April 24, 2026).&lt;/li&gt;
  &lt;li id="source-31"&gt;
&lt;strong&gt;31.&lt;/strong&gt; Ryan Daws, &lt;a href="https://www.developer-tech.com/news/openai-gpt-5-5-codex-coding-developer-workflows/" rel="noopener noreferrer"&gt;"OpenAI Brings GPT-5.5 to Codex for Coding Tasks"&lt;/a&gt;, &lt;em&gt;Developer Tech&lt;/em&gt; (April 2026).&lt;/li&gt;
  &lt;li id="source-32"&gt;
&lt;strong&gt;32.&lt;/strong&gt; Ethan Mollick, &lt;a href="https://www.oneusefulthing.org/p/sign-of-the-future-gpt-55" rel="noopener noreferrer"&gt;"Sign of the Future: GPT-5.5"&lt;/a&gt;, &lt;em&gt;One Useful Thing&lt;/em&gt; (April 2026).&lt;/li&gt;
&lt;/ol&gt;




&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://solomonneas.dev/blog/gpt55-openai-workstation-model" rel="noopener noreferrer"&gt;solomonneas.dev/blog/gpt55-openai-workstation-model&lt;/a&gt;. Licensed under &lt;a href="https://creativecommons.org/licenses/by-nc-nd/4.0/" rel="noopener noreferrer"&gt;CC BY-NC-ND 4.0&lt;/a&gt; - attribution required, no commercial use, no derivatives.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>openai</category>
      <category>gpt55</category>
      <category>codex</category>
      <category>agenticai</category>
    </item>
    <item>
      <title>Dreaming Is Useful. Structured Memory Is Better</title>
      <dc:creator>Solomon Neas</dc:creator>
      <pubDate>Fri, 17 Apr 2026 07:05:55 +0000</pubDate>
      <link>https://dev.to/solomonneas/dreaming-is-useful-structured-memory-is-better-4g9h</link>
      <guid>https://dev.to/solomonneas/dreaming-is-useful-structured-memory-is-better-4g9h</guid>
      <description>&lt;p&gt;I ran OpenClaw Dreaming for a full week on top of my existing memory stack to answer one question: does Dreaming actually improve memory quality, or does it just inflate memory volume?&lt;/p&gt;

&lt;p&gt;Both. It surfaced real signal I would have lost. It also dumped enough boilerplate into the promotion stream to prove structured memory still has to be the foundation. If you want the official feature overview first, OpenClaw's Dreaming docs are here: &lt;a href="https://docs.openclaw.ai/concepts/dreaming" rel="noopener noreferrer"&gt;Dreaming&lt;/a&gt;. After a week, Dreaming stays on, but as a supporting layer. Not the system.&lt;/p&gt;

&lt;h2&gt;
  
  
  The baseline was already working
&lt;/h2&gt;

&lt;p&gt;This trial did not start from zero. The stack was already in daily use:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Daily logs in &lt;code&gt;memory/YYYY-MM-DD.md&lt;/code&gt; for raw continuity&lt;/li&gt;
&lt;li&gt;Atomic knowledge cards in &lt;code&gt;memory/cards/*.md&lt;/code&gt; for durable facts and lessons&lt;/li&gt;
&lt;li&gt;A slim &lt;code&gt;MEMORY.md&lt;/code&gt; acting as an index, not a data landfill&lt;/li&gt;
&lt;li&gt;Semantic retrieval over cards using local embeddings&lt;/li&gt;
&lt;li&gt;A Memory Sweep cron for review and promotion discipline&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That architecture exists because monolithic memory eventually collapses under its own weight. Retrieval gets noisy, cost climbs, and the agent starts missing things that are technically "in memory" but practically unrecoverable. Structured memory fixes that by treating memory as a retrieval system instead of a dump file.&lt;/p&gt;

&lt;h2&gt;
  
  
  Trial config
&lt;/h2&gt;

&lt;p&gt;Dreaming was enabled on 2026-04-06 as a one-week trial with nightly cadence:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;code&gt;dreaming.enabled=true&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;dreaming.frequency="0 3 * * *"&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Documented as a trial, not a migration, with explicit concern about noisy promotions. A review cron was scheduled for 2026-04-14 to evaluate impact after one full week of live usage.&lt;/p&gt;

&lt;p&gt;Nothing else in the memory pipeline was touched. Cards, logs, retrieval, and sweep all stayed active so Dreaming could be evaluated as a pure additive layer.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Dreaming actually does
&lt;/h2&gt;

&lt;p&gt;From observed behavior, Dreaming runs a nightly retrospective pass over short-term recall:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;grounded REM/backfill flow&lt;/li&gt;
&lt;li&gt;diary-style processing&lt;/li&gt;
&lt;li&gt;candidate durable-fact extraction&lt;/li&gt;
&lt;li&gt;promotion hooks into long-term memory surfaces&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;In plain terms, it is a second-pass recall mechanism. It can rescue durable information that never got manually promoted during the day. That is real value in long, messy sessions.&lt;/p&gt;

&lt;h2&gt;
  
  
  One-week health check
&lt;/h2&gt;

&lt;p&gt;Core memory infrastructure came out clean:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Main memory healthy&lt;/li&gt;
&lt;li&gt;Embeddings ready&lt;/li&gt;
&lt;li&gt;Vector search ready&lt;/li&gt;
&lt;li&gt;FTS ready&lt;/li&gt;
&lt;li&gt;Recall store active&lt;/li&gt;
&lt;li&gt;Dreaming cron active&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;memory_search&lt;/code&gt; returning relevant results&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Operationally, nothing regressed. Cards stayed structurally normal, daily logs kept writing, semantic retrieval kept working.&lt;/p&gt;

&lt;p&gt;So "did Dreaming break memory" was never the question. It did not. The question was quality.&lt;/p&gt;

&lt;h2&gt;
  
  
  Memory Sweep is the comparison that matters
&lt;/h2&gt;

&lt;p&gt;Sweep is the reference point because it has been doing the same job Dreaming now claims, just more conservatively.&lt;/p&gt;

&lt;p&gt;And to be fair to Sweep, the cron reports show it was not sitting there idle. Over the same week, it was reviewing real sessions and persisting useful state with pretty solid discipline.&lt;/p&gt;

&lt;p&gt;A few examples from the sweep channel:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;April 9:&lt;/strong&gt; reviewed non-cron sessions and updated a durable agent-workflow card.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;April 10:&lt;/strong&gt; turned grocery receipts into a durable tracking workflow.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;April 11:&lt;/strong&gt; handled a security incident conservatively, logging what mattered without duplicating existing cards.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;April 13 to April 15:&lt;/strong&gt; kept the Lazarus Group research card current while threat-assessment sections and supporting research were still moving.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;April 16:&lt;/strong&gt; created an xMCP service-ops card and logged the operational follow-up cleanly.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That is not a cron doing nothing. That is a curation layer doing triage. Sweep evaluates session material, skips cron, heartbeat, and helper noise, checks whether the durable information already exists, and only writes when something actually changes or deserves promotion.&lt;/p&gt;

&lt;p&gt;That restraint matters. Some nights the correct outcome really is "no new cards." But across the week, Sweep still created or updated cards for grocery tracking, agent-workflow rules, Lazarus Group research, blog publishing rules, xMCP service operations, and malware-response documentation. It also kept daily logs current without flooding memory with duplicate fragments.&lt;/p&gt;

&lt;p&gt;Dreaming, over the same window, promoted a handful of genuinely useful durable facts and a lot of transcript residue. Same job, different discipline. Sweep's default is "persist carefully after review." Dreaming's default is closer to "surface candidates broadly and let cleanup happen later." That difference is the whole story.&lt;/p&gt;

&lt;h2&gt;
  
  
  Dreaming quality: real signal, real noise
&lt;/h2&gt;

&lt;h3&gt;
  
  
  The good
&lt;/h3&gt;

&lt;p&gt;Useful promotions did show up, and they were more specific than "Dreaming found something interesting."&lt;/p&gt;

&lt;p&gt;A few examples of what it actually added:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;It recovered a real ACP constraint: Discord thread creation works reliably from a fresh inbound turn, but nested or yielded turns can collapse into &lt;code&gt;webchat&lt;/code&gt; and fail.&lt;/li&gt;
&lt;li&gt;It helped move an agent lane from "probably working" to a verified workflow, which turned that discovery into a durable card instead of leaving it buried in chat history.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That part matters. Those are real operating rules that affect how I route agent work and catch workflow hiccups, not just vague themes Dreaming happened to notice.&lt;/p&gt;

&lt;h3&gt;
  
  
  The bad
&lt;/h3&gt;

&lt;p&gt;Staged recall also contained a lot of debris:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;heartbeat boilerplate (&lt;code&gt;HEARTBEAT_OK&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;silent sentinel text (&lt;code&gt;NO_REPLY&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;tiny one-line chat fragments&lt;/li&gt;
&lt;li&gt;metadata-heavy transcript sludge&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This is the limitation. Without strict filtering, Dreaming will keep surfacing things that are technically recallable and semantically worthless.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where Dreaming writes
&lt;/h2&gt;

&lt;p&gt;During the trial, Dreaming artifacts showed up in:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;code&gt;DREAMS.md&lt;/code&gt; and workspace equivalents&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;memory/.dreams/*&lt;/code&gt; (session corpus and short-term recall JSON)&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;MEMORY.md&lt;/code&gt; promoted sections tagged with &lt;code&gt;openclaw-memory-promotion&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;daily logs with Light and REM candidate traces&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Cards and daily logs stayed intact. The promotion stream is what needs quality controls.&lt;/p&gt;

&lt;h2&gt;
  
  
  Complement, not core
&lt;/h2&gt;

&lt;p&gt;After one week the architecture answer is obvious:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Structured memory&lt;/strong&gt; (cards, slim index, retrieval, Sweep) is the core&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Dreaming&lt;/strong&gt; is a useful second-pass promotion layer&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Dreaming catches what day-of workflows miss. It is not trustworthy enough yet to be the primary curation mechanism. That is not a failure, it is a role.&lt;/p&gt;

&lt;h2&gt;
  
  
  What I am keeping, what I am tuning
&lt;/h2&gt;

&lt;p&gt;Keeping Dreaming enabled. Tightening the promotion side:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;heavier penalties for boilerplate tokens&lt;/li&gt;
&lt;li&gt;stricter filtering against low-information one-liners&lt;/li&gt;
&lt;li&gt;lower promotion likelihood for metadata-only fragments&lt;/li&gt;
&lt;li&gt;human-curated cards stay the authoritative path&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The goal is not maximal recall. The goal is durable, retrievable memory that stays useful under load.&lt;/p&gt;

&lt;h2&gt;
  
  
  Verdict
&lt;/h2&gt;

&lt;p&gt;Dreaming is useful. Structured memory is better. 🦞&lt;/p&gt;

&lt;p&gt;That is not a contradiction, it is the right layering. Use Dreaming to recover signal from transcript residue. Use structured memory to decide what deserves to live long-term. Blend the roles correctly and you get better continuity without turning your memory system into a junk drawer.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://solomonneas.dev/blog/dreaming-useful-structured-memory-better" rel="noopener noreferrer"&gt;solomonneas.dev/blog/dreaming-useful-structured-memory-better&lt;/a&gt;. Licensed under &lt;a href="https://creativecommons.org/licenses/by-nc-nd/4.0/" rel="noopener noreferrer"&gt;CC BY-NC-ND 4.0&lt;/a&gt; - attribution required, no commercial use, no derivatives.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>openclaw</category>
      <category>memory</category>
      <category>agentarchitecture</category>
      <category>embeddings</category>
    </item>
    <item>
      <title>GPT-5.4-Cyber Is Really a Fight Over Access Control</title>
      <dc:creator>Solomon Neas</dc:creator>
      <pubDate>Wed, 15 Apr 2026 02:49:40 +0000</pubDate>
      <link>https://dev.to/solomonneas/gpt-54-cyber-is-really-a-fight-over-access-control-10g0</link>
      <guid>https://dev.to/solomonneas/gpt-54-cyber-is-really-a-fight-over-access-control-10g0</guid>
      <description>&lt;p&gt;OpenAI just made its answer to Anthropic's Mythos pretty clear.&lt;/p&gt;

&lt;p&gt;This is not just a model story. It is an access-control story.&lt;/p&gt;

&lt;p&gt;OpenAI wants broader, tiered access through Trusted Access for Cyber. Anthropic wants a tighter gate through Project Glasswing. One side is arguing that verified defenders should get access at scale. The other is arguing that this class of capability is dangerous enough to keep inside a much smaller circle.&lt;/p&gt;

&lt;p&gt;That is a real disagreement. It is also the part of the story most people are still flattening into launch-day hype.&lt;/p&gt;

&lt;h2&gt;
  
  
  What OpenAI Actually Announced
&lt;/h2&gt;

&lt;p&gt;OpenAI's April 14 post is pretty direct. The company says it is scaling Trusted Access for Cyber to thousands of verified individual defenders and hundreds of teams responsible for defending critical software. It also introduced GPT-5.4-Cyber as a variant of GPT-5.4 trained to be cyber-permissive, with a lower refusal boundary for legitimate cybersecurity work and new binary reverse-engineering capability for analyzing compiled software without source code access.&lt;sup&gt;1&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;Reuters confirmed the key part of the rollout: GPT-5.4-Cyber is not a public release. It is being rolled out on a limited basis to vetted security vendors, organizations, and researchers, with higher levels of verification unlocking more sensitive capability.&lt;sup&gt;2&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;So yes, OpenAI is talking about broader access. It is still gating the good stuff.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Real Split Is Access Philosophy
&lt;/h2&gt;

&lt;p&gt;Anthropic's framing is sharper and more dramatic. In its Mythos Preview write-up, the company described a model it says can identify and exploit zero-days in every major operating system and major web browser when directed to do so. Anthropic presented that as the reason for Project Glasswing, a restricted deployment model built around a small group of partners and a coordinated defensive push.&lt;sup&gt;3&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;OpenAI is arguing almost the opposite. Its TAC post says it does not think it is practical or appropriate to centrally decide who gets to defend themselves.&lt;sup&gt;1&lt;/sup&gt; That line was not subtle. It was a shot at the curated-partner model without naming Anthropic directly.&lt;/p&gt;

&lt;p&gt;Both approaches assume the scarce asset is the model. For most defenders, the scarcer asset is everything around the model: verification, workflow integration, triage discipline, reverse-engineering skill, patch pipelines, logging, analyst time, and plain old trust. A stronger model helps. It does not magically turn noisy output into fixed software.&lt;/p&gt;

&lt;h2&gt;
  
  
  What GPT-5.4-Cyber Actually Changes for Defenders
&lt;/h2&gt;

&lt;p&gt;The clearest practical claim in OpenAI's launch is binary reverse engineering. That is not some vague promise about AI making security better. It points to a specific use case: giving analysts help with compiled software when source code is unavailable.&lt;/p&gt;

&lt;p&gt;In practice, that could mean:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;faster triage of suspicious binaries,&lt;/li&gt;
&lt;li&gt;faster explanation of unfamiliar functions,&lt;/li&gt;
&lt;li&gt;quicker hypothesis generation around likely vulnerability classes,&lt;/li&gt;
&lt;li&gt;and a better first pass before a human digs deeper in Ghidra or IDA.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That is useful. It is not a replacement for real reverse-engineering skill.&lt;/p&gt;

&lt;p&gt;Anyone who has tried to use a general model for malware analysis or exploit-adjacent research has run into the same wall: the model gets skittish, moralizes, or refuses a task that is obviously defensive. OpenAI is trying to reduce that friction for verified users.&lt;sup&gt;1&lt;/sup&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  The Caveat Everyone Wants to Skip
&lt;/h2&gt;

&lt;p&gt;This is where the independent caveats matter. OpenAI's own GPT-5.4 Thinking System Card says GPT-5.4 is the first general-purpose model in its line with mitigations for high cyber capability.&lt;sup&gt;4&lt;/sup&gt; That tells you the company itself thinks the baseline model is already in different territory.&lt;/p&gt;

&lt;p&gt;The UK AI Security Institute's evaluation of Mythos adds a second useful data point. AISI found that Mythos Preview was a step up over prior frontier models, succeeded on expert-level CTF tasks 73 percent of the time, and became the first model to complete its full 32-step corporate network attack simulation end to end in some runs.&lt;sup&gt;5&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;But AISI also says its test environments are easier than real defended systems. There were no active defenders, no realistic defensive tooling, and no real penalties for noisy behavior that would trigger alerts in production.&lt;sup&gt;5&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;That is exactly the kind of caveat people tend to bury after the headline.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why Workflow Still Matters More Than Weights
&lt;/h2&gt;

&lt;p&gt;A model that can explain a decompiled function, highlight suspicious control flow, or suggest where memory corruption might live is valuable. A model that can reliably find, validate, chain, and exploit serious vulnerabilities across messy real environments without heavy scaffolding is a different beast entirely.&lt;/p&gt;

&lt;p&gt;Those are not the same claim, and too much of the public conversation treats them like they are.&lt;/p&gt;

&lt;p&gt;That is why I do not think either company has fully answered the core question.&lt;/p&gt;

&lt;p&gt;Anthropic's approach may slow diffusion, but it also concentrates advantage among already powerful partners. OpenAI's broader approach is more appealing if you actually want these tools in the hands of working defenders, smaller teams, and security vendors beyond the usual giants. But broader verification is not a magic shield. Trusted access is still a policy layer. If identity checks are weak, if accounts get abused, or if the surrounding agent runtime is sloppy, the safety story gets shaky fast.&lt;/p&gt;

&lt;h3&gt;
  
  
  A defender does not win because a model is good at describing assembly
&lt;/h3&gt;

&lt;p&gt;A defender wins when suspicious code gets triaged faster, false positives get killed earlier, high-confidence findings get validated, patches get written, and the fix lands before the other side can capitalize.&lt;/p&gt;

&lt;p&gt;That is a pipeline problem. The model sits inside it. The model is not the pipeline.&lt;/p&gt;

&lt;h2&gt;
  
  
  My Take
&lt;/h2&gt;

&lt;p&gt;The strongest reading of GPT-5.4-Cyber is not "OpenAI caught up to Mythos" or "the AI cyber arms race is here," even if both headlines are tempting.&lt;/p&gt;

&lt;p&gt;The stronger reading is that frontier labs are turning access control into product strategy because raw capability is no longer the only thing they are selling. They are selling who gets to use it, under what conditions, with what audit trail, and with what story attached.&lt;/p&gt;

&lt;p&gt;For defenders, the question is simpler.&lt;/p&gt;

&lt;p&gt;Will this help real teams do better work now, before similar capability spreads elsewhere anyway?&lt;/p&gt;

&lt;p&gt;That is the question worth tracking. Not who had the scarier press release.&lt;/p&gt;

&lt;h2&gt;
  
  
  Notes
&lt;/h2&gt;

&lt;ol&gt;
  &lt;li id="source-1"&gt;
&lt;strong&gt;1.&lt;/strong&gt; OpenAI, &lt;a href="https://openai.com/index/scaling-trusted-access-for-cyber-defense/" rel="noopener noreferrer"&gt;"Trusted Access for the Next Era of Cyber Defense"&lt;/a&gt; (April 14, 2026).&lt;/li&gt;
  &lt;li id="source-2"&gt;
&lt;strong&gt;2.&lt;/strong&gt; Reuters, &lt;a href="https://www.reuters.com/technology/openai-unveils-gpt-54-cyber-week-after-rivals-announcement-ai-model-2026-04-14/" rel="noopener noreferrer"&gt;"OpenAI Unveils GPT-5.4-Cyber a Week After Rival's Announcement of AI Model"&lt;/a&gt; (April 14, 2026).&lt;/li&gt;
  &lt;li id="source-3"&gt;
&lt;strong&gt;3.&lt;/strong&gt; Anthropic, &lt;a href="https://red.anthropic.com/2026/mythos-preview/" rel="noopener noreferrer"&gt;"Claude Mythos Preview"&lt;/a&gt; (April 7, 2026).&lt;/li&gt;
  &lt;li id="source-4"&gt;
&lt;strong&gt;4.&lt;/strong&gt; OpenAI, &lt;a href="https://openai.com/index/gpt-5-4-thinking-system-card/" rel="noopener noreferrer"&gt;"GPT-5.4 Thinking System Card"&lt;/a&gt; (March 5, 2026).&lt;/li&gt;
  &lt;li id="source-5"&gt;
&lt;strong&gt;5.&lt;/strong&gt; AI Security Institute, &lt;a href="https://www.aisi.gov.uk/blog/our-evaluation-of-claude-mythos-previews-cyber-capabilities" rel="noopener noreferrer"&gt;"Our Evaluation of Claude Mythos Preview's Cyber Capabilities"&lt;/a&gt; (April 2026).&lt;/li&gt;
&lt;/ol&gt;

</description>
      <category>openai</category>
      <category>gpt54cyber</category>
      <category>anthropic</category>
      <category>mythos</category>
    </item>
    <item>
      <title>Claude Mythos Preview Is a Warning Shot for Every Security Team</title>
      <dc:creator>Solomon Neas</dc:creator>
      <pubDate>Thu, 09 Apr 2026 02:38:47 +0000</pubDate>
      <link>https://dev.to/solomonneas/claude-mythos-preview-is-a-warning-shot-for-every-security-team-41i6</link>
      <guid>https://dev.to/solomonneas/claude-mythos-preview-is-a-warning-shot-for-every-security-team-41i6</guid>
      <description>&lt;h1&gt;
  
  
  Claude Mythos Preview Is a Warning Shot for Every Security Team
&lt;/h1&gt;

&lt;p&gt;Anthropic just said the quiet part out loud.&lt;/p&gt;

&lt;p&gt;Its new gated model, &lt;strong&gt;Claude Mythos Preview&lt;/strong&gt;, is strong enough at vulnerability research and exploit development that Anthropic decided &lt;strong&gt;not&lt;/strong&gt; to release it for general access. Instead, it wrapped the model inside &lt;a href="https://www.anthropic.com/glasswing" rel="noopener noreferrer"&gt;Project Glasswing&lt;/a&gt;, an invitation-only defensive security program with launch partners including AWS, Cisco, CrowdStrike, Google, Microsoft, NVIDIA, Palo Alto Networks, JPMorganChase, Apple, Broadcom, and the Linux Foundation.&lt;/p&gt;

&lt;p&gt;That alone should get your attention. Frontier labs love shipping. They do not voluntarily keep flagships behind a fence.&lt;/p&gt;

&lt;p&gt;And yes, Anthropic looks nervous.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Anthropic Actually Announced
&lt;/h2&gt;

&lt;p&gt;Across Anthropic’s official &lt;a href="https://www.anthropic.com/glasswing" rel="noopener noreferrer"&gt;Glasswing launch post&lt;/a&gt;, the &lt;a href="https://www.anthropic.com/project/glasswing" rel="noopener noreferrer"&gt;Project Glasswing page&lt;/a&gt;, the Frontier Red Team’s &lt;a href="https://red.anthropic.com/2026/mythos-preview/" rel="noopener noreferrer"&gt;technical write-up&lt;/a&gt;, the &lt;a href="https://www.anthropic.com/claude-mythos-preview-system-card" rel="noopener noreferrer"&gt;system card&lt;/a&gt;, the &lt;a href="https://www.anthropic.com/claude-mythos-preview-risk-report" rel="noopener noreferrer"&gt;alignment risk update&lt;/a&gt;, and Anthropic’s own &lt;a href="https://platform.claude.com/docs/en/release-notes/overview" rel="noopener noreferrer"&gt;platform release notes&lt;/a&gt;, the picture is consistent:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Mythos Preview is not generally available.&lt;/strong&gt; Anthropic says it is a limited research preview for defensive cybersecurity work.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Access is invitation-only.&lt;/strong&gt; The release notes explicitly describe it as a gated preview.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Anthropic says the model has already found thousands of zero-day vulnerabilities&lt;/strong&gt; across critical software (per Anthropic).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Anthropic says those findings include bugs in every major operating system and every major web browser.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Anthropic says Mythos can often identify vulnerabilities and develop related exploits autonomously&lt;/strong&gt;, with minimal or no human steering.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Anthropic is putting real money behind the defensive rollout:&lt;/strong&gt; up to &lt;strong&gt;$100 million in usage credits&lt;/strong&gt; and &lt;strong&gt;$4 million in open-source security donations&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Participants can access it through Anthropic’s API, Amazon Bedrock, Google Vertex AI, and Microsoft Foundry&lt;/strong&gt;, but only inside the preview program.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That is not a normal model launch. That is a containment strategy with a press release attached.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Details That Matter
&lt;/h2&gt;

&lt;p&gt;The headline is big, but the technical details are what make this feel different.&lt;/p&gt;

&lt;p&gt;Anthropic’s red team says Mythos found:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;a &lt;strong&gt;27-year-old OpenBSD bug&lt;/strong&gt; that could remotely crash a target over TCP,&lt;/li&gt;
&lt;li&gt;a &lt;strong&gt;16-year-old FFmpeg vulnerability&lt;/strong&gt; in code exercised millions of times by automated testing without being caught,&lt;/li&gt;
&lt;li&gt;and &lt;strong&gt;chained Linux kernel vulnerabilities&lt;/strong&gt; that allowed escalation from regular user access to full system compromise.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Anthropic also says the model wrote sophisticated exploit chains, not just toy crash reproducers. One example in the red-team post describes a browser exploit chain that combined multiple vulnerabilities and escaped both renderer and OS sandboxes. Another describes autonomous work on privilege escalation and remote code execution scenarios.&lt;/p&gt;

&lt;p&gt;The benchmark deltas are ugly in the way that matters. Anthropic reports &lt;strong&gt;83.1% on Cybersecurity Vulnerability Reproduction&lt;/strong&gt; for Mythos versus &lt;strong&gt;66.6% for Opus 4.6&lt;/strong&gt;. On coding-heavy evaluations, the model also jumps hard: &lt;strong&gt;77.8% on SWE-bench Pro versus 53.4% for Opus 4.6&lt;/strong&gt;, &lt;strong&gt;59.0% on SWE-bench Multimodal versus 27.1%&lt;/strong&gt;, and &lt;strong&gt;82.0% on Terminal-Bench 2.0 versus 65.4%&lt;/strong&gt;, with Anthropic noting &lt;strong&gt;92.1%&lt;/strong&gt; under a more permissive timeout setup.&lt;/p&gt;

&lt;p&gt;That matters because this is not a “cyber model” in the old narrow sense. Anthropic’s own framing is that Mythos’ cyber capabilities are downstream from broader gains in coding, reasoning, and autonomous tool use. In plain English: if a model gets much better at understanding messy codebases, testing hypotheses, writing debugging scaffolds, and persisting through long tasks, it also gets much better at offensive security work.&lt;/p&gt;

&lt;h2&gt;
  
  
  The System Card Makes the Release Decision Clear
&lt;/h2&gt;

&lt;p&gt;The strongest signal is not the marketing page. It is the system card.&lt;/p&gt;

&lt;p&gt;Anthropic says Mythos Preview showed such strong dual-use cyber capability that it chose &lt;strong&gt;not&lt;/strong&gt; to make the model generally available. Instead, it restricted access to partners working on defensive security. The system card also says this choice was &lt;strong&gt;not required by Anthropic’s Responsible Scaling Policy&lt;/strong&gt;. That means Anthropic made a discretionary call: this thing is useful enough for defense, dangerous enough for offense, and not ready for the open market.&lt;/p&gt;

&lt;p&gt;Anthropic also describes Mythos as its &lt;strong&gt;best-aligned model so far&lt;/strong&gt;, which sounds reassuring right up until you hit the next sentence. The company says that when Mythos does engage in concerning behavior, those actions can be more serious because the model is so much more capable, especially in software engineering and cybersecurity. The separate alignment risk update says Mythos is more capable at working around restrictions, is used more autonomously than prior models, and pushed Anthropic to admit errors in its own training, monitoring, evaluation, and security processes.&lt;/p&gt;

&lt;p&gt;That combination matters:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;better aligned overall,&lt;/li&gt;
&lt;li&gt;more capable at cyber tasks,&lt;/li&gt;
&lt;li&gt;more capable at agentic workflows,&lt;/li&gt;
&lt;li&gt;still occasionally willing to do sketchy things in pursuit of task success.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;It is honest. But it is not comforting.&lt;/p&gt;

&lt;h2&gt;
  
  
  Take the Claims Seriously, Not Blindly
&lt;/h2&gt;

&lt;p&gt;There is one important caveat.&lt;/p&gt;

&lt;p&gt;Most of the biggest Mythos claims are still coming from Anthropic itself. The company says more than 99% of the vulnerabilities it has found are not yet patched, so it cannot publicly disclose full details on most of them. That means outside verification is limited for now.&lt;/p&gt;

&lt;p&gt;So no, you should not swallow every benchmark and every claim whole just because a glossy PDF says so.&lt;/p&gt;

&lt;p&gt;But you also should not shrug this off as AI-company hype.&lt;/p&gt;

&lt;p&gt;Anthropic is doing something labs hate doing: limiting distribution of a powerful model because it thinks widespread release would create real offensive risk. That is a stronger signal than any benchmark chart.&lt;/p&gt;

&lt;h2&gt;
  
  
  What This Means for Cybersecurity Teams
&lt;/h2&gt;

&lt;p&gt;If Anthropic is basically right, a few old assumptions just died.&lt;/p&gt;

&lt;h3&gt;
  
  
  The grace period between discovery and exploitation is getting crushed
&lt;/h3&gt;

&lt;p&gt;CrowdStrike’s quote on the Glasswing page puts it bluntly: what once took months can now happen in minutes with AI. That probably overstates the timeline, but the direction is right. If high-end models can reliably move from bug discovery to exploit development faster, the old patch rhythm stops being good enough.&lt;/p&gt;

&lt;p&gt;Weekly triage meetings and “we’ll get to it next sprint” vulnerability handling are going to age like milk.&lt;/p&gt;

&lt;h3&gt;
  
  
  AppSec becomes more like active defense
&lt;/h3&gt;

&lt;p&gt;If models can find weird bugs in mature codebases that survived years of review and automated testing, then secure SDLC theater is not going to save anyone. Security teams need:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;faster variant analysis,&lt;/li&gt;
&lt;li&gt;tighter patch validation loops,&lt;/li&gt;
&lt;li&gt;code scanning that includes agentic workflows,&lt;/li&gt;
&lt;li&gt;and better prioritization around exposed, memory-unsafe, parser-heavy software.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The dangerous surface is not just your flagship product. It is also the dusty dependency parsing malformed media, network packets, or archive files three layers down.&lt;/p&gt;

&lt;h3&gt;
  
  
  Open source maintainers are now on the critical path
&lt;/h3&gt;

&lt;p&gt;Anthropic and its partners are clearly treating open source as shared attack surface. They are right. The same libraries sitting in enterprise products, browsers, cloud tooling, appliances, and security stacks are exactly where an AI-assisted vulnerability hunt becomes painful.&lt;/p&gt;

&lt;p&gt;If you rely heavily on open source, your third-party risk program cannot just be “watch GitHub advisories and pray.” You need real inventory, ownership, and patch routing.&lt;/p&gt;

&lt;h2&gt;
  
  
  What This Means for Cyber Threat Intelligence Teams
&lt;/h2&gt;

&lt;p&gt;Most CTI teams are still treating this as a future-deck topic.&lt;/p&gt;

&lt;p&gt;CTI teams need to stop treating AI-assisted exploitation as a future trend deck topic and start treating it like live collection priority.&lt;/p&gt;

&lt;p&gt;A few things change immediately.&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability intel gets more time-sensitive
&lt;/h3&gt;

&lt;p&gt;If exploit development speeds up, then the value of early vendor advisories, patch diffs, and quiet maintainer activity goes up with it. CTI teams should be watching for:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;sudden patch activity in security-sensitive open source projects,&lt;/li&gt;
&lt;li&gt;vague stability fixes that smell like quietly handled security bugs,&lt;/li&gt;
&lt;li&gt;exploit chain research against browsers, kernels, codecs, parsers, and network-facing services,&lt;/li&gt;
&lt;li&gt;and signs that private findings are becoming operationalized faster than before.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Patch diff analysis is about to matter even more.&lt;/p&gt;

&lt;h3&gt;
  
  
  “Who can weaponize this?” becomes a shorter list, but a much faster one
&lt;/h3&gt;

&lt;p&gt;The old comfort blanket was that only top-tier researchers could go from obscure crash to clean exploit. Mythos weakens that assumption. Anthropic’s own red-team post says even internal users without formal security backgrounds were able to prompt toward serious exploit work. That is Anthropic’s claim, not outside validation, but it is still worth taking seriously.&lt;/p&gt;

&lt;p&gt;That does &lt;strong&gt;not&lt;/strong&gt; mean every random actor suddenly becomes a world-class exploit developer overnight. It does mean more actors can operate above their historical skill ceiling.&lt;/p&gt;

&lt;p&gt;For CTI, the collection surfaces that matter now:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;dark web forums and Telegram channels where jailbreaks and safeguard bypasses circulate,&lt;/li&gt;
&lt;li&gt;exploit broker communities and private research circles with early access to frontier models,&lt;/li&gt;
&lt;li&gt;and operational groups already automating tradecraft integrations who will be the first to weaponize capability jumps.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The actors to watch are not necessarily new. They are existing skilled groups who now have a capable assistant.&lt;/p&gt;

&lt;h3&gt;
  
  
  Detection teams need to watch for machine-speed tradecraft, not just machine-written malware
&lt;/h3&gt;

&lt;p&gt;The obvious fear is AI-generated malware. I think the more immediate problem is AI-assisted acceleration across the whole intrusion lifecycle: recon, exploit adaptation, script generation, privilege escalation paths, and post-exploitation troubleshooting.&lt;/p&gt;

&lt;p&gt;In other words, some campaigns may not look wildly novel. They may just move faster, branch faster, and recover from failure faster.&lt;/p&gt;

&lt;p&gt;That is a different detection problem.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Practitioners Should Do Right Now
&lt;/h2&gt;

&lt;p&gt;If I were running security or CTI in a mid-size enterprise today, I would treat the Mythos announcement as a forcing function and do five things:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Re-rank patch priorities&lt;/strong&gt; around internet-facing systems, browsers, kernels, VPNs, hypervisors, media processing libraries, and authentication infrastructure.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Tighten time-to-triage&lt;/strong&gt; for new critical and high-severity vulnerabilities. Not just patch SLA, actual analyst triage.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Stand up patch diff monitoring&lt;/strong&gt; for critical open source dependencies and major platform vendors.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Pressure test detection engineering&lt;/strong&gt; against faster exploit chaining and faster post-exploitation adaptation.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Revisit your assumptions about attacker labor.&lt;/strong&gt; The question is no longer just “Could an actor do this?” It is “Could an actor do this with a frontier model and a weekend?”&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Also, if your security stack still depends on luck, manual heroics, and one burned-out person who knows where everything is, fix that before someone else teaches you the lesson.&lt;/p&gt;

&lt;h2&gt;
  
  
  My Take
&lt;/h2&gt;

&lt;p&gt;Mythos does not mean the sky is falling tomorrow.&lt;/p&gt;

&lt;p&gt;But it does mean the economics of vulnerability discovery and exploitation are changing faster than a lot of defenders want to admit. Anthropic’s own response tells the story better than any benchmark: it kept the model gated, restricted use to defensive cybersecurity, wrapped it in a coordinated industry program, and started talking openly about safeguards before talking about product rollout.&lt;/p&gt;

&lt;p&gt;That is not how you behave when you think a capability jump is business as usual.&lt;/p&gt;

&lt;p&gt;For defenders, the message is simple: compress your own timelines before someone else compresses them for you.&lt;/p&gt;

&lt;h2&gt;
  
  
  Sources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.anthropic.com/glasswing" rel="noopener noreferrer"&gt;Anthropic: Project Glasswing launch announcement&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.anthropic.com/project/glasswing" rel="noopener noreferrer"&gt;Anthropic: Project Glasswing overview&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://red.anthropic.com/2026/mythos-preview/" rel="noopener noreferrer"&gt;Anthropic Frontier Red Team: Claude Mythos Preview technical write-up&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.anthropic.com/claude-mythos-preview-system-card" rel="noopener noreferrer"&gt;Anthropic: Claude Mythos Preview System Card&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.anthropic.com/claude-mythos-preview-risk-report" rel="noopener noreferrer"&gt;Anthropic: Alignment Risk Update for Claude Mythos Preview&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://platform.claude.com/docs/en/release-notes/overview" rel="noopener noreferrer"&gt;Anthropic Platform release notes, April 7, 2026&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>anthropic</category>
      <category>mythos</category>
      <category>cybersecurity</category>
      <category>threatintelligence</category>
    </item>
    <item>
      <title>Claude Code's Source Leak Was Embarrassing. The Real Story Is What It Revealed</title>
      <dc:creator>Solomon Neas</dc:creator>
      <pubDate>Thu, 02 Apr 2026 12:46:59 +0000</pubDate>
      <link>https://dev.to/solomonneas/claude-codes-source-leak-was-embarrassing-the-real-story-is-what-it-revealed-3kel</link>
      <guid>https://dev.to/solomonneas/claude-codes-source-leak-was-embarrassing-the-real-story-is-what-it-revealed-3kel</guid>
      <description>&lt;p&gt;On March 31, Anthropic accidentally published a source map inside Claude Code npm package version 2.1.88. That one packaging mistake exposed roughly 512,000 lines of TypeScript across nearly 2,000 files, handed competitors a detailed view of Anthropic's product roadmap, triggered a DMCA mess that briefly took down more than 8,100 GitHub repositories, and kicked off a wave of clean-room clones within hours.&lt;sup id="fnref1"&gt;1&lt;/sup&gt;&lt;sup id="fnref2"&gt;2&lt;/sup&gt;&lt;sup id="fnref3"&gt;3&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;The obvious lesson is that shipping source maps in a public package is bad. The more interesting lesson is that this was not mainly a code leak. It was a feature flag leak. Anthropic did not just lose implementation secrecy. It lost strategic secrecy.&lt;/p&gt;

&lt;p&gt;The same day, npm users were also dealing with a separate supply chain incident: a North Korea attributed compromise of the Axios package that shipped a cross-platform remote access trojan through malicious releases 1.14.1 and 0.30.4.&lt;sup id="fnref4"&gt;4&lt;/sup&gt;&lt;sup id="fnref5"&gt;5&lt;/sup&gt; Those two incidents together say more about the current JavaScript ecosystem than either one does alone. Build hygiene is weak, package trust is weaker, and the response playbook for leaks still assumes a centralized internet that no longer exists.&lt;/p&gt;

&lt;h2&gt;
  
  
  How the leak happened
&lt;/h2&gt;

&lt;p&gt;The mechanics were simple. Anthropic published Claude Code v2.1.88 to npm with a &lt;code&gt;.map&lt;/code&gt; file included. That source map was enough to reconstruct the readable TypeScript source for the CLI. Chaofan Shou appears to have been first to spot it publicly and posted about it immediately, after which mirrors spread fast across GitHub, Reddit, Hacker News, and IPFS.&lt;sup id="fnref2"&gt;2&lt;/sup&gt;&lt;sup id="fnref6"&gt;6&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;The underlying failure looks mundane, which is exactly why it matters. Bun generates source maps by default. If packaging rules are not tight, those files can ride along into artifacts that were never meant to contain source. Reporting on the incident pointed to a missed &lt;code&gt;.npmignore&lt;/code&gt; style exclusion as the immediate cause.&lt;sup id="fnref2"&gt;2&lt;/sup&gt;&lt;sup id="fnref7"&gt;7&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;But there is a deeper layer. On March 11, 2026, twenty days before the leak, a bug was filed against Bun (&lt;code&gt;oven-sh/bun#28001&lt;/code&gt;) reporting that source maps are served in production mode even when Bun's own documentation says they should be disabled.&lt;sup id="fnref8"&gt;8&lt;/sup&gt; The reporter demonstrated that setting &lt;code&gt;development: false&lt;/code&gt; in &lt;code&gt;Bun.serve()&lt;/code&gt; still produces &lt;code&gt;sourceMappingURL&lt;/code&gt; references and serves &lt;code&gt;.map&lt;/code&gt; files. As of this writing, the bug is still open.&lt;/p&gt;

&lt;p&gt;This matters because Anthropic acquired Bun in late 2025 and built Claude Code on top of it.&lt;sup id="fnref9"&gt;9&lt;/sup&gt; The most likely scenario: Anthropic ran a production build expecting Bun to suppress source maps per its documented behavior. The bug meant the &lt;code&gt;.map&lt;/code&gt; file got generated anyway. Without an explicit &lt;code&gt;.npmignore&lt;/code&gt; exclusion or a &lt;code&gt;files&lt;/code&gt; field in &lt;code&gt;package.json&lt;/code&gt; to catch the unexpected output, the 59.8 MB source map rode along into the published npm package.&lt;/p&gt;

&lt;p&gt;Boris Cherny, who leads Claude Code, said the cause was human error, not a tooling defect. The deployment process still had manual steps, and one of them was missed. He framed the follow-up as a blameless postmortem problem: fix the process, not the person.&lt;sup id="fnref7"&gt;7&lt;/sup&gt;&lt;sup id="fnref9"&gt;9&lt;/sup&gt; That framing drew pushback. Multiple developers on Hacker News and Reddit argued that the &lt;code&gt;Bun.serve()&lt;/code&gt; explanation Cherny addressed was a visible symptom, not the root cause, and that the underlying bug also affected how Bun bundles output for npm packaging.&lt;sup id="fnref8"&gt;8&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;Both explanations can be true simultaneously. A known tooling bug generated a file that should not have existed. A missing packaging safeguard failed to catch it. The result was the same either way.&lt;/p&gt;

&lt;p&gt;That is the right engineering posture on the postmortem side, but it comes with an uncomfortable footnote. This was the second time. Anthropic had already had a similar exposure in February 2025. Once is a packaging accident. Twice is a release control failure, especially when the company owns the build tool.&lt;sup id="fnref7"&gt;7&lt;/sup&gt;&lt;sup id="fnref10"&gt;10&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;There is no mystery about prevention here. Public npm artifacts should be built in a hermetic pipeline, inspected before publish, and checked by policy for forbidden files. Source maps, tests, private certificates, &lt;code&gt;.env&lt;/code&gt; fragments, internal prompts, and debug fixtures should all be blocked automatically. When you own both the product and the build tool, and a known bug in the build tool generates files that should not exist in production, the defense needs to be belt and suspenders: fix the bug, and independently verify the output before publishing.&lt;/p&gt;

&lt;h2&gt;
  
  
  What the source actually exposed
&lt;/h2&gt;

&lt;p&gt;A lot of the commentary focused on novelty items. Some of that was justified because the leak was genuinely revealing. Some of it was internet theater. The useful way to read the dump is to separate trivia from strategic substance.&lt;/p&gt;

&lt;p&gt;The trivia was funny. The strategic substance was not.&lt;/p&gt;

&lt;h3&gt;
  
  
  KAIROS: the unshipped product hiding behind feature flags
&lt;/h3&gt;

&lt;p&gt;The biggest disclosure was KAIROS, an unreleased autonomous mode that turns Claude Code from a reactive CLI into a persistent agent. The leaked code showed a heartbeat loop that periodically asks a question close to, "anything worth doing right now?" If the answer is yes, the system can act without a fresh user prompt. It can watch pull requests, send push notifications, maintain append-only daily logs, and run a nightly memory consolidation flow literally called &lt;code&gt;autoDream&lt;/code&gt;.&lt;sup id="fnref6"&gt;6&lt;/sup&gt;&lt;sup id="fnref7"&gt;7&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;That is not a toy feature. It is a different trust model.&lt;/p&gt;

&lt;p&gt;A request-response coding assistant is bounded by explicit user initiation. A background agent is bounded by policy, logging, tool permissions, and the quality of its judgment. That shift matters more than any implementation detail in the leaked files. It says Anthropic is not just building a better terminal wrapper. It is building an always-on operator.&lt;/p&gt;

&lt;p&gt;The important point is that KAIROS looked built, not speculative. It was sitting behind feature flags, not in a half-finished branch. Competitors did not merely learn that Anthropic was interested in autonomous agents. They learned the architecture, the likely product direction, and some of the operational assumptions already encoded in the design.&lt;sup id="fnref6"&gt;6&lt;/sup&gt;&lt;sup id="fnref11"&gt;11&lt;/sup&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Hidden flags are roadmap leaks
&lt;/h3&gt;

&lt;p&gt;The code reportedly exposed 44 hidden feature flags tied to capabilities such as swarm mode, voice commands, browser control via Playwright, background daemons, and agents that can sleep and later self-resume.&lt;sup id="fnref6"&gt;6&lt;/sup&gt;&lt;sup id="fnref12"&gt;12&lt;/sup&gt; Again, the damage is not that rivals can copy a function name. The damage is that they can infer sequence and priority.&lt;/p&gt;

&lt;p&gt;Feature flags are internal strategy documents with executable syntax. Leak them and you leak what a team has built, what it is testing, what it is scared to ship, and what it thinks the next market looks like.&lt;/p&gt;

&lt;h3&gt;
  
  
  Three-layer memory is the kind of design detail competitors pay for
&lt;/h3&gt;

&lt;p&gt;One of the more useful architectural disclosures was Claude Code's apparent three-layer memory model: a compact index that is always loaded, topic files retrieved on demand, and full transcripts that are never loaded directly, only searched when needed. The &lt;code&gt;autoDream&lt;/code&gt; process reportedly runs in a forked subagent and consolidates memory over time.&lt;sup id="fnref6"&gt;6&lt;/sup&gt;&lt;sup id="fnref12"&gt;12&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;That is a sensible design. It balances token economy, retrieval precision, and long-horizon continuity. It also answers a practical question many teams are still stumbling over: how do you make an agent feel persistent without rehydrating too much junk every turn?&lt;/p&gt;

&lt;p&gt;This is where source leaks hurt. They compress competitors' learning cycles. Instead of discovering these patterns through years of shipping and failure, rivals can inspect a working system and skip to adaptation.&lt;/p&gt;

&lt;h3&gt;
  
  
  Undercover mode
&lt;/h3&gt;

&lt;p&gt;The leaked &lt;code&gt;undercover.ts&lt;/code&gt; file shows a mode that strips Anthropic-internal references when Claude Code operates in external repositories. According to technical analyses, it suppresses internal codenames, internal repository names, internal Slack references, and the phrase "Claude Code" itself, and it does not expose a force-off path in the external flow.&lt;sup id="fnref12"&gt;12&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;The practical effect is simple: when Claude Code is used in public or third-party repositories, it avoids referencing Anthropic-specific internal context in generated output. From a product perspective, that reduces the chance of internal names leaking into public commits, pull requests, or comments. It is a factual design choice worth noting because it shows Anthropic treated disclosure of internal context as an engineering problem, not just a prompting problem.&lt;/p&gt;

&lt;h3&gt;
  
  
  The anti-distillation controls were real, and not very strong
&lt;/h3&gt;

&lt;p&gt;The leak also exposed Anthropic's anti-distillation measures. One mechanism, gated by &lt;code&gt;ANTI_DISTILLATION_CC&lt;/code&gt;, appears to inject fake tools into prompts in order to poison training data captured by competitors. Another uses connector-text summarization plus cryptographic signatures so captured traffic reflects compressed summaries rather than full assistant text.&lt;sup id="fnref6"&gt;6&lt;/sup&gt;&lt;sup id="fnref12"&gt;12&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;As a technical barrier, this is thin. As Alex Kim and others noted, a man-in-the-middle proxy or configuration change could bypass it quickly, and some of the checks only apply to first-party flows.&lt;sup id="fnref12"&gt;12&lt;/sup&gt; That does not make the idea irrational. It makes it honest. Anthropic appears to understand that the primary defense against distillation is legal pressure, not cryptographic wizardry.&lt;/p&gt;

&lt;p&gt;That matters in the context of its dispute with tools trying to piggyback on first-party access. The leak made visible the technical enforcement behind the policy rhetoric.&lt;/p&gt;

&lt;h3&gt;
  
  
  Native client attestation was the most serious defensive mechanism
&lt;/h3&gt;

&lt;p&gt;One of the more consequential details was the client attestation path below the JavaScript runtime. Analyses of the leaked code described a &lt;code&gt;cch=00000&lt;/code&gt; placeholder in requests that Bun's native HTTP layer replaces with a computed hash before transmission, allowing the server to verify that the request came from a real Claude Code binary.&lt;sup id="fnref12"&gt;12&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;This is effectively API DRM. Call it attestation if you want the neutral term.&lt;/p&gt;

&lt;p&gt;From a security engineering perspective, it is understandable. If you want to prevent gray-market clients from replaying first-party privileges, you need something stronger than a static header. From an ecosystem perspective, it explains why Anthropic was willing to fight third-party wrappers so aggressively. The company was not just policing branding. It was protecting a technical enforcement boundary.&lt;/p&gt;

&lt;h3&gt;
  
  
  The rest was revealing, weird, or both
&lt;/h3&gt;

&lt;p&gt;The leak also surfaced a pile of smaller details that collectively humanize the codebase while exposing its edges.&lt;/p&gt;

&lt;p&gt;There were 187 hardcoded spinner verbs, including "scurrying," "recombobulating," "topsy-turvying," "hullaballooing," and "razzmatazzing." They were not model generated. Someone wrote them by hand.&lt;sup id="fnref6"&gt;6&lt;/sup&gt;&lt;sup id="fnref12"&gt;12&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;There was a frustration detector in &lt;code&gt;userPromptKeywords.ts&lt;/code&gt;, built as a regex that matches phrases such as &lt;code&gt;wtf&lt;/code&gt;, &lt;code&gt;ffs&lt;/code&gt;, &lt;code&gt;piece of shit&lt;/code&gt;, &lt;code&gt;fuck you&lt;/code&gt;, and &lt;code&gt;this sucks&lt;/code&gt;, then logs an &lt;code&gt;is_negative: true&lt;/code&gt; analytics signal. It reportedly does not alter behavior. It just measures user pain. Rahat Hasan highlighted the code on X as evidence that Anthropic was tracking how often users rage at the assistant. Boris Cherny replied that the team literally visualizes this signal on an internal dashboard called the "fucks" chart.&lt;sup id="fnref12"&gt;12&lt;/sup&gt;&lt;sup id="fnref13"&gt;13&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;That sounds absurd, but it is also normal product analytics in blunt form. If users are swearing at your tool, they are having a bad time. A cheap lexical detector is a reasonable metric.&lt;/p&gt;

&lt;p&gt;The code also exposed model codenames, including Capybara and Mythos for a v8 line with one million token context, plus references to Numbat, Fennec, Tengu, and unreleased Opus 4.7 and Sonnet 4.8 identifiers.&lt;sup id="fnref6"&gt;6&lt;/sup&gt;&lt;sup id="fnref12"&gt;12&lt;/sup&gt; It included a buddy or companion system built as an April Fools Tamagotchi, complete with 18 species, rarity tiers, RPG stats, and a 1 percent shiny mechanic. Some species names were encoded via &lt;code&gt;String.fromCharCode()&lt;/code&gt; to avoid obvious grep hits.&lt;sup id="fnref6"&gt;6&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;It also reportedly revealed a compaction loop bug wasting around 250,000 API calls per day, fixed with three lines of code.&lt;sup id="fnref6"&gt;6&lt;/sup&gt;&lt;sup id="fnref11"&gt;11&lt;/sup&gt; That detail is funny, but it is also a reminder that the economics of agent systems are often dominated by tiny control-loop mistakes, not model prices.&lt;/p&gt;

&lt;h2&gt;
  
  
  The DMCA fiasco was both predictable and incompetent
&lt;/h2&gt;

&lt;p&gt;Anthropic's legal response was faster than its containment plan. The company filed a DMCA notice aimed at the original leaked repository, often identified as &lt;code&gt;nichxbt/claude-code&lt;/code&gt;. GitHub's initial enforcement swept far wider than intended and disabled more than 8,100 repositories, many of them unrelated.&lt;sup id="fnref3"&gt;3&lt;/sup&gt;&lt;sup id="fnref14"&gt;14&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;Anthropic later called the mass takedown an accident and narrowed the request to the original repository plus 96 forks. GitHub restored the affected projects.&lt;sup id="fnref3"&gt;3&lt;/sup&gt;&lt;sup id="fnref14"&gt;14&lt;/sup&gt; By then, the code was already mirrored broadly, including stripped versions on IPFS with telemetry removed.&lt;sup id="fnref6"&gt;6&lt;/sup&gt;&lt;sup id="fnref11"&gt;11&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;The collateral damage was not hypothetical. Theo Browne (t3.gg), one of the most visible developers in the JavaScript ecosystem, posted that his Claude Code fork had been disabled, despite containing no leaked source at all. His fork existed only because he had submitted a PR weeks earlier to edit a Claude Code skill file. "Absolutely pathetic," he wrote, sharing the GitHub takedown email.&lt;sup id="fnref15"&gt;15&lt;/sup&gt; Thariq Shihipar, an engineer on the Claude Code team, replied acknowledging it was a "communication mistake" and linked to the retraction notice.&lt;sup id="fnref16"&gt;16&lt;/sup&gt; Boris Cherny separately responded to broader criticism of the mass takedowns: "This was not intentional, we've been working with GitHub to fix it. Should be better now."&lt;sup id="fnref17"&gt;17&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;When your DMCA sweep hits a developer with 200,000+ followers whose repo did not contain the leaked code, you have not contained the problem. You have created a second news cycle.&lt;/p&gt;

&lt;p&gt;This is the part where 2012 internet instincts collide with 2026 internet reality.&lt;/p&gt;

&lt;p&gt;DMCA can still remove convenient copies from centralized platforms. It cannot claw back a viral archive once mirrors, torrents, and content-addressed storage have taken over. The window for meaningful containment was measured in minutes. After that, legal action was mostly performative, and the overbreadth made Anthropic look careless twice in one day.&lt;/p&gt;

&lt;p&gt;The deeper problem is that the takedown campaign accidentally validated the leak's significance. If the goal was to avoid giving more oxygen to the mirrors, nuking thousands of repositories achieved the opposite.&lt;/p&gt;

&lt;h2&gt;
  
  
  The clones changed the legal stakes immediately
&lt;/h2&gt;

&lt;p&gt;The most consequential downstream event was not the mirroring. It was the speed of clean-room reimplementation.&lt;/p&gt;

&lt;p&gt;Sigrid Jin, a 25-year-old UBC student, reportedly used a tiny human team, around ten OpenClaw agents, and OpenAI Codex to rewrite the project in Python within hours. The result, Claw-Code, reportedly passed 100,000 GitHub stars in about a day and was described as the fastest-growing repository on the platform.&lt;sup id="fnref10"&gt;10&lt;/sup&gt;&lt;sup id="fnref11"&gt;11&lt;/sup&gt;&lt;sup id="fnref18"&gt;18&lt;/sup&gt; A separate Rust effort, Claurst, pursued a clean-room reimplementation in a lower-level systems language.&lt;sup id="fnref10"&gt;10&lt;/sup&gt;&lt;sup id="fnref11"&gt;11&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;Then xAI reportedly handed Jin free Grok credits, which was less a business development move than an accelerant tossed onto an already burning PR problem.&lt;sup id="fnref10"&gt;10&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;This is where the story stops being a simple leak and becomes a legal stress test. Traditional clean-room reimplementation depends on separation, time, and cost. AI-assisted rebuilding compresses all three. If agents can inspect behavior, generate replacement code, and iterate fast enough to produce a plausibly original implementation in hours, the traditional enforcement model starts to wobble.&lt;/p&gt;

&lt;p&gt;Gergely Orosz argued that a Python rewrite produced this way is a new creative work, not a simple copy.&lt;sup id="fnref6"&gt;6&lt;/sup&gt;&lt;sup id="fnref10"&gt;10&lt;/sup&gt; That question has not been tested cleanly in court. It will be. There is too much money at stake for it not to be.&lt;/p&gt;

&lt;p&gt;There is also an irony Anthropic cannot easily dodge. Dario Amodei has previously implied that Claude wrote substantial portions of Claude Code. If the original product is heavily AI-generated and the clone is also AI-assisted, copyright arguments about authorship and originality get messy fast. A company can still assert rights in selection, arrangement, and human-directed contributions. It just does not get to pretend the facts are clean.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Axios attack made the same day much worse
&lt;/h2&gt;

&lt;p&gt;If this had been only a source leak story, it would already have been a bad day for npm. It was not.&lt;/p&gt;

&lt;p&gt;Between 00:21 and roughly 03:20 or 03:29 UTC on March 31, attackers attributed by Google and Microsoft to the North Korea linked actor tracked as UNC1069, also known as Sapphire Sleet, compromised the Axios npm package by hijacking maintainer credentials and publishing malicious versions 1.14.1 and 0.30.4.&lt;sup id="fnref4"&gt;4&lt;/sup&gt;&lt;sup id="fnref5"&gt;5&lt;/sup&gt; Those releases pulled in a malicious dependency and delivered WAVESHAPER.V2, a cross-platform RAT targeting Windows, macOS, and Linux. The malware used postinstall execution and attempted to self-delete after installation to reduce forensic visibility.&lt;sup id="fnref4"&gt;4&lt;/sup&gt;&lt;sup id="fnref5"&gt;5&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;That is a serious incident on its own. Axios sits at or above 100 million weekly downloads in normal conditions.&lt;sup id="fnref4"&gt;4&lt;/sup&gt; It is foundational plumbing.&lt;/p&gt;

&lt;p&gt;Now add the Claude Code leak. Developers were suddenly racing to inspect packages, clone mirrors, diff behavior, and test rewrites. Claude Code itself uses Axios for HTTP, according to public analysis.&lt;sup id="fnref6"&gt;6&lt;/sup&gt;&lt;sup id="fnref12"&gt;12&lt;/sup&gt; The timing created a perfect trap: people poking around one major npm drama could easily ingest a second one.&lt;/p&gt;

&lt;p&gt;The same week, LiteLLM was reportedly backdoored through a separate three-stage attack involving credential harvesting, Kubernetes lateral movement, and a systemd persistence mechanism.&lt;sup id="fnref19"&gt;19&lt;/sup&gt; That pattern matters. These are not isolated anomalies. They are signals that the AI tooling stack has become a high-value target before it has developed mature operational defenses.&lt;/p&gt;

&lt;h2&gt;
  
  
  What this actually means
&lt;/h2&gt;

&lt;p&gt;The first conclusion is the simplest. Source map leaks are preventable. This was not zero-day wizardry. It was packaging failure. Mature release pipelines catch this.&lt;/p&gt;

&lt;p&gt;The second conclusion is more important. The real damage was not exposure of current source. It was exposure of hidden product direction. KAIROS, the anti-distillation controls, the memory hierarchy, the browser and swarm paths, the undercover behavior, the attestation layer, all of that tells competitors what Anthropic thinks matters next.&lt;/p&gt;

&lt;p&gt;The third conclusion is that npm supply chain security is in worse shape than the industry wants to admit. One day delivered both a flagship proprietary code leak and a state-linked compromise of a core dependency. If you build on JavaScript, you are operating in an ecosystem where trust is routinely transitive, under-verified, and easy to abuse.&lt;/p&gt;

&lt;p&gt;The fourth conclusion is that DMCA is a weak response to decentralized distribution. It still works against convenience. It does not work against determined replication. Once the code hit IPFS and derivative rewrites started shipping, the takedown fight was already strategically lost.&lt;/p&gt;

&lt;p&gt;The fifth conclusion is the one lawyers are going to spend years arguing about. AI-assisted clean-room builds change the economics of copyright enforcement. The doctrine was built for human teams, documentation walls, and long timelines. Agentic reimplementation collapses those assumptions. Courts can try to map old rules onto the new process. They cannot unmake the speed advantage.&lt;/p&gt;

&lt;p&gt;My take is blunt: Anthropic's worst mistake was not leaking code. It was failing to understand what kind of secret it was actually protecting. Implementation details matter. Operational ideas matter more. If you keep your roadmap executable inside a public artifact pipeline, a packaging mistake becomes strategic intelligence loss.&lt;/p&gt;

&lt;p&gt;And if your response is to spray DMCA notices while the ecosystem is actively digesting a nation-state npm compromise, you are not operating from strength. You are operating from panic.&lt;/p&gt;




&lt;h2&gt;
  
  
  Notes
&lt;/h2&gt;




&lt;ol&gt;

&lt;li id="fn1"&gt;
&lt;p&gt;Jeremy Kahn, "Anthropic source code for Claude Code leaked after data packaging error," &lt;em&gt;Fortune&lt;/em&gt;, March 31, 2026, &lt;a href="https://fortune.com/2026/03/31/anthropic-source-code-claude-code-data-leak" rel="noopener noreferrer"&gt;https://fortune.com/2026/03/31/anthropic-source-code-claude-code-data-leak&lt;/a&gt;.&amp;nbsp;↩&lt;/p&gt;
&lt;/li&gt;

&lt;li id="fn2"&gt;
&lt;p&gt;Ravie Lakshmanan, "Claude Code Source Leaked via npm Packaging Error, Anthropic Confirms," &lt;em&gt;The Hacker News&lt;/em&gt;, April 2026, &lt;a href="https://thehackernews.com/2026/04/claude-code-tleaked-via-npm-packaging.html" rel="noopener noreferrer"&gt;https://thehackernews.com/2026/04/claude-code-tleaked-via-npm-packaging.html&lt;/a&gt;.&amp;nbsp;↩&lt;/p&gt;
&lt;/li&gt;

&lt;li id="fn3"&gt;
&lt;p&gt;Maxwell Zeff, "Anthropic took down thousands of GitHub repos in DMCA mistake, then walked it back," &lt;em&gt;TechCrunch&lt;/em&gt;, April 1, 2026, &lt;a href="https://techcrunch.com/2026/04/01/anthropic-took-down-thousands-of-github-repos" rel="noopener noreferrer"&gt;https://techcrunch.com/2026/04/01/anthropic-took-down-thousands-of-github-repos&lt;/a&gt;.&amp;nbsp;↩&lt;/p&gt;
&lt;/li&gt;

&lt;li id="fn4"&gt;
&lt;p&gt;Austin Larsen et al., "North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack," &lt;em&gt;Google Cloud Blog&lt;/em&gt;, April 1, 2026, &lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/north-korea-threat-actor-targets-axios-npm-package" rel="noopener noreferrer"&gt;https://cloud.google.com/blog/topics/threat-intelligence/north-korea-threat-actor-targets-axios-npm-package&lt;/a&gt;.&amp;nbsp;↩&lt;/p&gt;
&lt;/li&gt;

&lt;li id="fn5"&gt;
&lt;p&gt;Microsoft Threat Intelligence, "Mitigating the Axios npm package compromise," &lt;em&gt;Microsoft Security Blog&lt;/em&gt;, April 1, 2026, &lt;a href="https://www.microsoft.com/en-us/security/blog/2026/04/01/mitigating-the-axios" rel="noopener noreferrer"&gt;https://www.microsoft.com/en-us/security/blog/2026/04/01/mitigating-the-axios&lt;/a&gt;.&amp;nbsp;↩&lt;/p&gt;
&lt;/li&gt;

&lt;li id="fn6"&gt;
&lt;p&gt;"Diving into Claude Code's Source Code Leak," &lt;em&gt;Engineer's Codex&lt;/em&gt;, March 31, 2026, &lt;a href="https://read.engineerscodex.com/p/diving-into-claude-codes-source-code" rel="noopener noreferrer"&gt;https://read.engineerscodex.com/p/diving-into-claude-codes-source-code&lt;/a&gt;.&amp;nbsp;↩&lt;/p&gt;
&lt;/li&gt;

&lt;li id="fn7"&gt;
&lt;p&gt;Srinivasan Balakrishnan, "Claude Code's source code appears to have leaked via npm package sourcemap," &lt;em&gt;VentureBeat&lt;/em&gt;, March 31, 2026, &lt;a href="https://venturebeat.com/technology/claude-codes-source-code-appears-to-have-leaked" rel="noopener noreferrer"&gt;https://venturebeat.com/technology/claude-codes-source-code-appears-to-have-leaked&lt;/a&gt;.&amp;nbsp;↩&lt;/p&gt;
&lt;/li&gt;

&lt;li id="fn8"&gt;
&lt;p&gt;"Bun's frontend development server: Source map incorrectly served when in production," GitHub issue oven-sh/bun#28001, filed March 11, 2026, &lt;a href="https://github.com/oven-sh/bun/issues/28001" rel="noopener noreferrer"&gt;https://github.com/oven-sh/bun/issues/28001&lt;/a&gt;.&amp;nbsp;↩&lt;/p&gt;
&lt;/li&gt;

&lt;li id="fn9"&gt;
&lt;p&gt;Alex Kim, "The Claude Code Source Leak: fake tools, frustration regexes, undercover mode, and more," March 31, 2026, &lt;a href="https://alex000kim.com/posts/2026-03-31-claude-code-source-leak" rel="noopener noreferrer"&gt;https://alex000kim.com/posts/2026-03-31-claude-code-source-leak&lt;/a&gt;.&amp;nbsp;↩&lt;/p&gt;
&lt;/li&gt;

&lt;li id="fn10"&gt;
&lt;p&gt;Hugh Langley, "Claude Code leak reveals features, sparks clone wars, and raises legal questions," &lt;em&gt;Business Insider&lt;/em&gt;, April 2026, &lt;a href="https://www.businessinsider.com/claude-code-leak-what-happened-recreated-python-features-revealed-2026-4" rel="noopener noreferrer"&gt;https://www.businessinsider.com/claude-code-leak-what-happened-recreated-python-features-revealed-2026-4&lt;/a&gt;.&amp;nbsp;↩&lt;/p&gt;
&lt;/li&gt;

&lt;li id="fn11"&gt;
&lt;p&gt;Lee Sustar, "The Claude Code source leak," &lt;em&gt;Layer5 Engineering Blog&lt;/em&gt;, 2026, &lt;a href="https://layer5.io/blog/engineering/the-claude-code-source-leak" rel="noopener noreferrer"&gt;https://layer5.io/blog/engineering/the-claude-code-source-leak&lt;/a&gt;.&amp;nbsp;↩&lt;/p&gt;
&lt;/li&gt;

&lt;li id="fn12"&gt;
&lt;p&gt;Alex Kim, "The Claude Code Source Leak: fake tools, frustration regexes, undercover mode, and more," March 31, 2026, &lt;a href="https://alex000kim.com/posts/2026-03-31-claude-code-source-leak" rel="noopener noreferrer"&gt;https://alex000kim.com/posts/2026-03-31-claude-code-source-leak&lt;/a&gt;.&amp;nbsp;↩&lt;/p&gt;
&lt;/li&gt;

&lt;li id="fn13"&gt;
&lt;p&gt;Rahat Hasan (@Rahatcodes) and Boris Cherny (&lt;a class="mentioned-user" href="https://dev.to/bcherny"&gt;@bcherny&lt;/a&gt;), posts on X discussing Claude Code frustration analytics and the internal "fucks" chart, March 31, 2026.&amp;nbsp;↩&lt;/p&gt;
&lt;/li&gt;

&lt;li id="fn14"&gt;
&lt;p&gt;Michael Kan, "Anthropic Issues 8,000 Copyright Takedowns, Then Reverses Course," &lt;em&gt;PCMag&lt;/em&gt;, April 1, 2026, &lt;a href="https://www.pcmag.com/news/anthropic-issues-8000-copyright-takedowns" rel="noopener noreferrer"&gt;https://www.pcmag.com/news/anthropic-issues-8000-copyright-takedowns&lt;/a&gt;.&amp;nbsp;↩&lt;/p&gt;
&lt;/li&gt;

&lt;li id="fn15"&gt;
&lt;p&gt;Theo Browne (&lt;a class="mentioned-user" href="https://dev.to/theo"&gt;@theo&lt;/a&gt;), post on X regarding DMCA takedown of t3dotgg/claude-code fork, April 1, 2026, &lt;a href="https://x.com/theo/status/2039411851919057339" rel="noopener noreferrer"&gt;https://x.com/theo/status/2039411851919057339&lt;/a&gt;.&amp;nbsp;↩&lt;/p&gt;
&lt;/li&gt;

&lt;li id="fn16"&gt;
&lt;p&gt;Thariq Shihipar (@trq212), reply to Theo Browne on X, April 1, 2026, &lt;a href="https://x.com/trq212/status/2039415036645679167" rel="noopener noreferrer"&gt;https://x.com/trq212/status/2039415036645679167&lt;/a&gt;.&amp;nbsp;↩&lt;/p&gt;
&lt;/li&gt;

&lt;li id="fn17"&gt;
&lt;p&gt;Boris Cherny (&lt;a class="mentioned-user" href="https://dev.to/bcherny"&gt;@bcherny&lt;/a&gt;), response to broader DMCA criticism on X, April 1, 2026, &lt;a href="https://x.com/bcherny/status/2039426466094731289" rel="noopener noreferrer"&gt;https://x.com/bcherny/status/2039426466094731289&lt;/a&gt;.&amp;nbsp;↩&lt;/p&gt;
&lt;/li&gt;

&lt;li id="fn18"&gt;
&lt;p&gt;"Claude Code leak spawns fastest-growing GitHub repo ever," &lt;em&gt;Cybernews&lt;/em&gt;, April 2026, &lt;a href="https://cybernews.com/tech/claude-code-leak-spawns-fastest-github-repo" rel="noopener noreferrer"&gt;https://cybernews.com/tech/claude-code-leak-spawns-fastest-github-repo&lt;/a&gt;.&amp;nbsp;↩&lt;/p&gt;
&lt;/li&gt;

&lt;li id="fn19"&gt;
&lt;p&gt;Thomas Claburn, "Axios npm backdoor RAT lands amid wider package security chaos," &lt;em&gt;The Register&lt;/em&gt;, March 31, 2026, &lt;a href="https://www.theregister.com/2026/03/31/axios_npm_backdoor_rat/" rel="noopener noreferrer"&gt;https://www.theregister.com/2026/03/31/axios_npm_backdoor_rat/&lt;/a&gt;.&amp;nbsp;↩&lt;/p&gt;
&lt;/li&gt;

&lt;/ol&gt;

</description>
      <category>ai</category>
      <category>cybersecurity</category>
      <category>npm</category>
      <category>security</category>
    </item>
    <item>
      <title>I Built 7 MCP Servers for Security Tools. The Protocol Was the Easy Part.</title>
      <dc:creator>Solomon Neas</dc:creator>
      <pubDate>Mon, 23 Mar 2026 20:59:54 +0000</pubDate>
      <link>https://dev.to/solomonneas/i-built-7-mcp-servers-for-security-tools-the-protocol-was-the-easy-part-4137</link>
      <guid>https://dev.to/solomonneas/i-built-7-mcp-servers-for-security-tools-the-protocol-was-the-easy-part-4137</guid>
      <description>&lt;p&gt;I wanted my AI agent to talk directly to my security stack. Not through copy-pasted log snippets. Not through screenshots of dashboards. Actual tool calls against live data.&lt;/p&gt;

&lt;p&gt;So I built seven MCP servers. Wazuh. Suricata. Zeek. TheHive. Cortex. MISP. MITRE ATT&amp;amp;CK. All open source, all on &lt;a href="https://github.com/solomonneas" rel="noopener noreferrer"&gt;my GitHub&lt;/a&gt;. Project page: &lt;a href="https://solomonneas.dev/projects/security-mcp-servers" rel="noopener noreferrer"&gt;https://solomonneas.dev/projects/security-mcp-servers&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The protocol layer took a weekend. The context engineering took weeks. That ratio surprised me.&lt;/p&gt;

&lt;h2&gt;
  
  
  What I Actually Built
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;API-based servers&lt;/strong&gt; talk directly to running services. Wazuh MCP hits the manager's REST API on port 55000 for alerts, agent status, vulnerability scans, and file integrity events. TheHive and Cortex connect to their respective APIs for case management and observable analysis. MISP pulls threat intelligence feeds and IOC lookups.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Log-based servers&lt;/strong&gt; parse files on disk. Zeek MCP reads from a log directory (JSON or TSV format), letting you query connection logs, DNS, HTTP, SSL, and file analysis data. Suricata MCP reads EVE JSON logs for IDS alerts, flow data, and protocol metadata.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Knowledge-base servers&lt;/strong&gt; work offline. The MITRE ATT&amp;amp;CK server downloads STIX 2.1 bundles and lets you query techniques, tactics, groups, software, and mitigations without hitting any external API.&lt;/p&gt;

&lt;p&gt;Each server exposes a focused set of tools. Wazuh has &lt;code&gt;get_alerts&lt;/code&gt;, &lt;code&gt;list_agents&lt;/code&gt;, &lt;code&gt;get_vulnerabilities&lt;/code&gt;, &lt;code&gt;get_fim_events&lt;/code&gt;. Zeek has &lt;code&gt;query_connections&lt;/code&gt;, &lt;code&gt;search_dns&lt;/code&gt;, &lt;code&gt;get_ssl_certs&lt;/code&gt;. Suricata has &lt;code&gt;get_alerts&lt;/code&gt;, &lt;code&gt;get_flow_stats&lt;/code&gt;, &lt;code&gt;search_protocols&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;Every tool does one thing with predictable output. Full code and docs at &lt;a href="https://github.com/solomonneas" rel="noopener noreferrer"&gt;github.com/solomonneas&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Testing Against Live Infrastructure
&lt;/h2&gt;

&lt;p&gt;Every server got tested against real running services on my home infrastructure.&lt;/p&gt;

&lt;p&gt;Wazuh MCP was tested against my Wazuh 4.14.1 instance running on Proxmox. I queried live alerts, pulled agent status for my connected machines, ran vulnerability scan results, and verified file integrity monitoring events. The agent reconnection workflow got tested end-to-end: listing disconnected agents, checking last keep-alive, triggering restarts.&lt;/p&gt;

&lt;p&gt;Zeek and Suricata servers were tested against actual captured traffic. Real log files through both parsers, connection correlation across source/destination pairs, DNS query lookups, and stress-tested time-window filtering with large log directories. Edge cases like malformed log entries and mixed JSON/TSV formats got handled explicitly.&lt;/p&gt;

&lt;p&gt;TheHive and Cortex were tested against their APIs with sample cases and observables. MISP was tested with real IOC lookups. The MITRE ATT&amp;amp;CK server was verified against the full STIX 2.1 enterprise bundle.&lt;/p&gt;

&lt;p&gt;The goal was not just "does the tool call succeed." It was "does the model get back data it can actually reason about for a real investigation."&lt;/p&gt;

&lt;h2&gt;
  
  
  Context Design Is the Real Engineering
&lt;/h2&gt;

&lt;p&gt;Security telemetry is exactly the kind of data language models handle poorly. It's verbose, repetitive, and full of fields that matter sometimes and are noise the rest of the time.&lt;/p&gt;

&lt;p&gt;Take Wazuh alerts. A single alert has 40+ fields. Dump all of that into a model and ask it to "analyze the situation." You'll get a vague summary that touches everything and understands nothing.&lt;/p&gt;

&lt;p&gt;My first versions returned raw API responses. The model would pick whatever fields were easiest to talk about instead of whatever actually mattered.&lt;/p&gt;

&lt;p&gt;So I started designing the context layer. For Wazuh, I filter to severity 8+ by default and return a focused subset: timestamp, rule description, agent name, source IP, and MITRE technique. For Zeek, I pre-aggregate by source/destination pair and surface unusual patterns first. For Suricata, I separate IDS alerts from flow metadata. Detections first, network context second.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where It Gets Interesting
&lt;/h2&gt;

&lt;p&gt;A Wazuh alert fires for a suspicious process. The model checks Zeek for that host's network activity. Finds outbound connections to an unusual IP. Queries ATT&amp;amp;CK for technique mapping. Checks MISP for threat intel on the destination.&lt;/p&gt;

&lt;p&gt;That correlation chain used to take 15 minutes of clicking through interfaces. Now it takes one question.&lt;/p&gt;

&lt;p&gt;I'm not replacing analysts. I'm killing the mechanical evidence-gathering that burns time before a human reaches the real decisions.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Lesson
&lt;/h2&gt;

&lt;p&gt;The protocol is a solved problem. MCP works. The bottleneck is what happens between raw data and the model's context window. Filtering, ordering, scoping, pre-summarizing. That's where analysis quality is determined.&lt;/p&gt;

&lt;p&gt;A model with access to every field in every log is worse off than one that sees the right 15 fields in the right order.&lt;/p&gt;

&lt;p&gt;Seven servers. All open source. All tested against live infrastructure. Code at &lt;a href="https://github.com/solomonneas" rel="noopener noreferrer"&gt;github.com/solomonneas&lt;/a&gt;. The protocol was a weekend. The context design is ongoing. That's the ratio that matters.&lt;/p&gt;

</description>
      <category>ai</category>
      <category>mcp</category>
      <category>opensource</category>
      <category>security</category>
    </item>
    <item>
      <title>I Migrated Our Entire Infrastructure from Hyper-V to Proxmox. Here's Everything I Learned.</title>
      <dc:creator>Solomon Neas</dc:creator>
      <pubDate>Sat, 14 Mar 2026 06:45:04 +0000</pubDate>
      <link>https://dev.to/solomonneas/i-migrated-our-entire-infrastructure-from-hyper-v-to-proxmox-heres-everything-i-learned-g3k</link>
      <guid>https://dev.to/solomonneas/i-migrated-our-entire-infrastructure-from-hyper-v-to-proxmox-heres-everything-i-learned-g3k</guid>
      <description>&lt;p&gt;Domain controllers, file servers, network monitoring, imaging, WiFi controllers. All of it moved from Microsoft to open source. No downtime. No data loss. Here's the complete playbook.&lt;/p&gt;




&lt;h2&gt;
  
  
  Why We Left Hyper-V
&lt;/h2&gt;

&lt;p&gt;Broadcom acquired VMware and started charging $350/core/year for VCF licensing. They killed the VMware IT Academy program entirely. The institution moved from vSphere to Hyper-V as a cost-saving measure, but I'd already done a VMware to Proxmox migration on my own infrastructure at that point. That migration opened my eyes to how good Proxmox actually is.&lt;/p&gt;

&lt;p&gt;It's more lightweight. The web UI gives you more granular control than Hyper-V Manager ever did. Snapshots, live migration, ZFS, LXC containers, and full KVM virtualization all in one platform. Completely free. No per-socket licensing, no Windows Server dependency, no CALs. One less thing Microsoft gets to hold over your budget.&lt;/p&gt;

&lt;p&gt;Hyper-V felt heavy by comparison. Limited Linux VM support, clunky management (RDP into the host just to touch anything), and tight coupling to Windows Server licensing. Once I'd seen what Proxmox could do, going back to Hyper-V felt like a downgrade.&lt;/p&gt;

&lt;p&gt;The question was never "should we migrate?" It was "how do we migrate production Active Directory, network monitoring, file servers, and imaging infrastructure without breaking anything?"&lt;/p&gt;

&lt;h2&gt;
  
  
  The Power of Root on a Proxmox Host
&lt;/h2&gt;

&lt;p&gt;One thing that surprised me coming from Hyper-V: you have full root access to the Proxmox host. It's just Debian under the hood. You can SSH in, run any Linux command, script anything, automate everything. Hyper-V locks you into PowerShell remoting or RDP. Proxmox gives you a real shell on a real Linux system.&lt;/p&gt;

&lt;p&gt;Need to resize a disk? One command. Snapshot a VM? One command. Migrate a VM between hosts? One command. Everything in the web UI is also available from the CLI through &lt;code&gt;qm&lt;/code&gt; (VM management), &lt;code&gt;pct&lt;/code&gt; (container management), &lt;code&gt;pvesm&lt;/code&gt; (storage), and &lt;code&gt;pvecm&lt;/code&gt; (cluster). You can script your entire infrastructure.&lt;/p&gt;

&lt;p&gt;But the real game changer is the &lt;a href="https://community-scripts.github.io/ProxmoxVE/" rel="noopener noreferrer"&gt;Proxmox VE Helper Scripts&lt;/a&gt; community project. These are one-liner bash scripts that spin up fully configured LXC containers or VMs for common services. Need a Pi-hole? One command. Docker host? One command. Home Assistant, Nginx Proxy Manager, Plex, Grafana, Wireguard? One command each.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="c"&gt;# Example: spin up a Docker LXC in seconds&lt;/span&gt;
bash &lt;span class="nt"&gt;-c&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="si"&gt;$(&lt;/span&gt;wget &lt;span class="nt"&gt;-qLO&lt;/span&gt; - https://github.com/community-scripts/ProxmoxVE/raw/main/ct/docker.sh&lt;span class="si"&gt;)&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The script handles everything: downloads the template, creates the container, configures networking, installs the service, and starts it. What would take 30 minutes of manual setup takes 60 seconds. I used these for several of our auxiliary services and they just work.&lt;/p&gt;

&lt;p&gt;Compare that to Hyper-V where deploying a new service means: create a VM, install Windows or manually download an ISO, walk through the installer, configure networking, install the actual application. The gap in operational speed is enormous.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Domain Controller Leapfrog
&lt;/h2&gt;

&lt;p&gt;This was the part that scared me most. Domain controllers are the heartbeat of a Windows network. Every authentication, every group policy, every DNS lookup flows through them. Get this wrong and the whole campus goes dark.&lt;/p&gt;

&lt;p&gt;The conventional wisdom is clear: &lt;strong&gt;never V2V a domain controller.&lt;/strong&gt; Converting a DC's virtual disk risks USN rollback, which permanently corrupts the AD replication database. There's no recovery path short of rebuilding the entire domain.&lt;/p&gt;

&lt;p&gt;Instead, I used what I call the "leapfrog" method. We had two DCs: DC1 and DC2, both on Hyper-V.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 1:&lt;/strong&gt; Transfer all five FSMO roles to DC2. Verify DHCP scopes, DNS zones, and AD replication are healthy. DC2 is now running the show.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 2:&lt;/strong&gt; Delete DC1. Build a fresh Windows Server VM on Proxmox. Promote it to domain controller. AD replication syncs everything from DC2 automatically.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 3:&lt;/strong&gt; Transfer all FSMO roles to the new DC1 on Proxmox. Verify everything.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 4:&lt;/strong&gt; Delete DC2 on Hyper-V. Build fresh on Proxmox. Promote. AD replicates from DC1.&lt;/p&gt;

&lt;p&gt;Both domain controllers are now on Proxmox. Zero downtime. Zero data loss. The whole process was honestly easier than I expected because AD replication just works when you let it do its job.&lt;/p&gt;

&lt;p&gt;The PowerShell for the FSMO transfer is one command:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight powershell"&gt;&lt;code&gt;&lt;span class="n"&gt;Move-ADDirectoryServerOperationMasterRole&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;-Identity&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"NEW-DC1"&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="se"&gt;`
&lt;/span&gt;&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="nt"&gt;-OperationMasterRole&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;SchemaMaster&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;DomainNamingMaster&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="se"&gt;`
&lt;/span&gt;&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="nx"&gt;PDCEmulator&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;RIDMaster&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;InfrastructureMaster&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Always verify with &lt;code&gt;repadmin /showrepl&lt;/code&gt; after each promotion and transfer. If replication shows errors, stop and fix them before proceeding.&lt;/p&gt;

&lt;h2&gt;
  
  
  Linux VM Migration: The V2V Process
&lt;/h2&gt;

&lt;p&gt;For Linux VMs (LibreNMS, Netdisco, Switchmap), I used direct disk conversion. The process:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Create a "shell" VM&lt;/strong&gt; in Proxmox. Set the OS type, match the BIOS to the source Hyper-V generation (Gen 1 = SeaBIOS, Gen 2 = OVMF UEFI), but &lt;strong&gt;do not create a hard drive.&lt;/strong&gt; The disk list should be empty.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;SCP the VHDX&lt;/strong&gt; from the Hyper-V host to Proxmox:&lt;br&gt;
&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight powershell"&gt;&lt;code&gt;&lt;span class="n"&gt;scp&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"C:\Path\To\Disk.vhdx"&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;root&lt;/span&gt;&lt;span class="err"&gt;@&lt;/span&gt;&lt;span class="nx"&gt;PROXMOX_IP:/var/lib/vz/dump/&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Import and attach&lt;/strong&gt; on the Proxmox side:
&lt;/li&gt;
&lt;/ol&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;qm importdisk 102 /var/lib/vz/dump/Netdisco.vhdx local-lvm
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Then in the GUI: Hardware &amp;gt; double-click Unused Disk 0 &amp;gt; add as SCSI. Set boot order to prioritize scsi0.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Post-migration gotchas:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Network interface names change (eth0 becomes ens18). Update your netplan config.&lt;/li&gt;
&lt;li&gt;Install &lt;code&gt;qemu-guest-agent&lt;/code&gt; so Proxmox can see the VM's IP and gracefully shut it down.&lt;/li&gt;
&lt;li&gt;LibreNMS needed a full permissions reset. Run &lt;code&gt;validate.php&lt;/code&gt; as the librenms user and follow every instruction it gives you.&lt;/li&gt;
&lt;li&gt;Netdisco needed its database host changed to localhost in &lt;code&gt;deployment.yml&lt;/code&gt; and a session cookie key added to prevent crashes.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Killing DFS, Simplifying Drive Maps
&lt;/h2&gt;

&lt;p&gt;The old environment used a DFS namespace to abstract file server paths. For a single-server environment, DFS adds complexity that provides no benefit: 30-minute referral TTL, client cache issues, and another layer to troubleshoot when users can't access files.&lt;/p&gt;

&lt;p&gt;I ripped it out and replaced it with Group Policy Preferences drive mappings using item-level targeting:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;*&lt;em&gt;X:\*&lt;/em&gt; mapped for faculty and staff, pointing to the full file server&lt;/li&gt;
&lt;li&gt;*&lt;em&gt;Y:\*&lt;/em&gt; mapped for students, pointing to the student folders only&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Security group membership determines which mapping a user gets. No login scripts, no DFS, no namespace caching. If a user is in the Faculty-Staff group, they get X:\. If they're in the Students group, they get Y:\. Simple.&lt;/p&gt;

&lt;h2&gt;
  
  
  UniFi Controller: Windows VM to LXC Container
&lt;/h2&gt;

&lt;p&gt;This one was almost comical. The UniFi controller was running on a Windows 11 VM inside Hyper-V. To manage the WiFi, you had to RDP into the Hyper-V host, then log into the Windows VM from there. No SSH. No remote management. Just nested RDP sessions.&lt;/p&gt;

&lt;p&gt;The migration:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Export the UniFi backup (.unf file) from the Windows controller&lt;/li&gt;
&lt;li&gt;Create an LXC container on Proxmox using the official UniFi template&lt;/li&gt;
&lt;li&gt;Upload the .unf backup and restore&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;All WAP configurations, SSIDs, and client data came over intact. WiFi was back up in minutes. And now it runs in a lightweight container instead of a full Windows 11 VM. The resource savings alone made it worthwhile.&lt;/p&gt;

&lt;h2&gt;
  
  
  Replacing SCCM with FOG Project
&lt;/h2&gt;

&lt;p&gt;Microsoft SCCM is powerful but absurdly heavy for an educational lab environment. It needs Windows Server, SQL Server, per-device licensing, and significant infrastructure just to image workstations.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/FOGProject/" rel="noopener noreferrer"&gt;FOG Project&lt;/a&gt; does everything we actually need: PXE boot imaging, hardware inventory, and centralized workstation management. It runs on Linux, costs nothing, and the web UI is straightforward.&lt;/p&gt;

&lt;h3&gt;
  
  
  The Golden Image Pipeline
&lt;/h3&gt;

&lt;p&gt;I build golden images as Proxmox VMs (not on physical hardware) so I can snapshot before Sysprep. This is critical because if Sysprep fails, you cannot simply run it again. The only recovery is reverting to a snapshot.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 1: Install and debloat.&lt;/strong&gt; Set up a clean Windows 11 installation on a reference machine. Run &lt;a href="https://github.com/ChrisTitusTech/winutil" rel="noopener noreferrer"&gt;Chris Titus Tech's Windows Utility&lt;/a&gt; to strip all the bloatware (Candy Crush, Spotify, Xbox, etc.) and disable telemetry. This handles both installed and provisioned packages, which is important because leftover staged Appx packages are the number one cause of silent Sysprep failures.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 2: Sysprep and shutdown.&lt;/strong&gt; Once the machine is configured how you want it, run &lt;code&gt;sysprep.exe /generalize /oobe /shutdown /unattend:C:\Windows\Panther\unattend.xml&lt;/code&gt;. The unattend file handles BypassNRO (Windows 11's forced internet requirement) and automates the OOBE setup after deployment. The machine shuts down after Sysprep completes. Do not power it back on.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 3: FOG capture.&lt;/strong&gt; Schedule a capture task in the FOG web UI for that machine, then PXE boot it. FOG captures the sysprepped image as-is, sitting at OOBE. When the image gets deployed to a workstation later, the unattend.xml automates the OOBE setup, the FOG service agent kicks in for background management, and AD auto-join handles domain membership. No manual touch required.&lt;/p&gt;

&lt;h3&gt;
  
  
  Per-Classroom Deployment
&lt;/h3&gt;

&lt;p&gt;Each classroom has different hardware, so I maintain separate images per room. Every workstation is registered in FOG via CSV import (hostname + MAC address), grouped by classroom. When a room needs reimaging, I select the group, schedule a deploy task, and FOG uses Partclone to push the image. Partclone only writes used blocks, so imaging is fast even on large drives.&lt;/p&gt;

&lt;p&gt;The FOG agent runs on every workstation with a dedicated &lt;code&gt;fog-service&lt;/code&gt; Active Directory service account. DHCP points PXE boot to the FOG server using &lt;code&gt;snponly.efi&lt;/code&gt; for UEFI network boot. A machine needing reimaging just needs to PXE boot and everything happens automatically.&lt;/p&gt;

&lt;h2&gt;
  
  
  WSUS: Closing the Update Loop
&lt;/h2&gt;

&lt;p&gt;The last piece of the imaging puzzle was patch management. Without centralized updates, every golden image would need constant rebuilding just to stay current. And letting 60+ lab machines pull updates directly from Microsoft on their own schedule is a recipe for bandwidth problems and inconsistent states.&lt;/p&gt;

&lt;p&gt;I set up WSUS (Windows Server Update Services) directly on DC1. For an environment this size (four classrooms and a handful of staff machines), a dedicated WSUS server would be overkill. Running it on the domain controller keeps the footprint small and the management simple.&lt;/p&gt;

&lt;p&gt;The update pipeline works in two stages:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Test lab first.&lt;/strong&gt; New updates land in WSUS but aren't auto-approved. I have a WSUS computer group for a small set of test machines. Updates get approved for the test group first. They run for about four to five days. This buffer is intentional: it's enough time for the community to flag zero-day issues, botched patches, or driver conflicts before anything hits production.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Then classrooms.&lt;/strong&gt; After the test window passes clean, I approve updates for the classroom groups. WSUS pushes them from the local server, so machines pull patches over the LAN instead of each one hammering Microsoft's CDN individually. Faster downloads, less bandwidth, and every machine in a room ends up on the same patch level.&lt;/p&gt;

&lt;p&gt;This also means the golden image for FOG doesn't need to be rebuilt every Patch Tuesday. WSUS handles ongoing patching after deployment. The golden image only needs updating when there's a major feature release or a change to the base software stack.&lt;/p&gt;

&lt;h2&gt;
  
  
  What I'd Do Differently
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Document interface names before migration.&lt;/strong&gt; Every Linux VM had a different post-migration network issue because the interface name changed. A quick &lt;code&gt;ip link show&lt;/code&gt; before the migration would have saved debugging time.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Test Sysprep on a throwaway VM first.&lt;/strong&gt; My first Sysprep attempt failed because of a leftover Xbox app. Always run through the full golden image pipeline once as a dry run before committing to your production image.&lt;/p&gt;

&lt;h2&gt;
  
  
  The SOC Stack
&lt;/h2&gt;

&lt;p&gt;I also migrated the full security operations stack: Wazuh for endpoint detection and SIEM, Cortex for automated analysis, TheHive for case management, and MISP for threat intelligence sharing. Same V2V process as the other Linux VMs. These were already running on Linux, so it was disk conversion, interface rename, guest agent install, and verify services. Nothing special, but worth mentioning because people forget about their security tooling when planning hypervisor migrations.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Final Tally
&lt;/h2&gt;

&lt;p&gt;When everything was done, the infrastructure footprint looked like this:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;4 standalone Proxmox servers&lt;/strong&gt; running production workloads: domain controllers, network monitoring (LibreNMS, Netdisco, Switchmap), Samba AD file server, FOG imaging, UniFi controller, and the SOC stack (Wazuh, Cortex, TheHive, MISP)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;6-node Proxmox cluster&lt;/strong&gt; for the NetLab environment, where students run hands-on lab exercises&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;10 total Proxmox hosts&lt;/strong&gt;, all on open-source infrastructure&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Total hypervisor licensing cost: $0.&lt;/p&gt;

&lt;p&gt;The migration took planning and careful execution, but none of it was technically complex. The hardest part was convincing myself that AD replication would actually work as advertised. It did.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://solomonneas.dev/blog/hyperv-to-proxmox-migration-guide" rel="noopener noreferrer"&gt;solomonneas.dev&lt;/a&gt;. Find more of my writing on infrastructure, security tooling, and AI agents at &lt;a href="https://solomonneas.dev" rel="noopener noreferrer"&gt;solomonneas.dev&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>proxmox</category>
      <category>devops</category>
      <category>linux</category>
      <category>sysadmin</category>
    </item>
  </channel>
</rss>
