Investigating weird failure modes in AI infrastructure, model access, and agent security. Building @infertrail. Former Microsoft.

Pinned Tweet
Your inference may already be getting resold — and your logs can still look normal. If you run an inference API, gateway, or AI product and you’ve seen suspicious credential sharing, resale, or unexplained usage, DM me. I’m looking to talk to teams seeing this in production. There is a growing reseller market built around stolen API keys, shared subscriptions, proxy access, account farms, and piggybacked sessions. The scary part: much of it can look completely legitimate from the provider side. Valid credential. Valid account. Normal-looking requests. Meanwhile, the same access can be passed through brokers, resold across borders, or quietly used by someone the account owner has never heard of. Most LLM security products focus on what an agent is doing. The blind spot is who is actually behind the account. That’s what we’re building at @infertrail: behavioral detection for inference abuse, credential resale, and unauthorized access. We’re publishing honeypot data, reseller-market research across Russian- and Chinese-language communities, attack patterns, and what we learn building detection for this problem. Follow @infertrail for the research.
5
1
155
6,285
I guess AGI is here then? What do you think?
2
Cognition teaching everyone what enterprise sales looks like in AI
Guillermo Flor
1
179
This is going to change customer serve K service for ever
Introducing Griffin, the first model to pass the video Turing test. 48% of people who talked to it live thought it was a real human. Previous systems have had a pass rate <3%. It is #1 on NVIDIA's benchmark for full-duplex AI video. It’s the first Human Interaction Model (HIM).
Community note
The 48% figure and "video Turing test" claim are from Tavus's own study of 54 one-minute calls, not independently verified or using a standard protocol. Griffin-Lite leads NVIDIA's VideoFDB benchmark on their public leaderboard. cellcog.ai/blog/tavus-gri… research.nvidia.com/labs/amri/proj… tech-ish.com/2026/10/02/tav…
17
Arielle retweeted
Introducing Griffin, the first model to pass the video Turing test. 48% of people who talked to it live thought it was a real human. Previous systems have had a pass rate <3%. It is #1 on NVIDIA's benchmark for full-duplex AI video. It’s the first Human Interaction Model (HIM).
Community note
The 48% figure and "video Turing test" claim are from Tavus's own study of 54 one-minute calls, not independently verified or using a standard protocol. Griffin-Lite leads NVIDIA's VideoFDB benchmark on their public leaderboard. cellcog.ai/blog/tavus-gri… research.nvidia.com/labs/amri/proj… tech-ish.com/2026/10/02/tav…
3,330
4,297
39,143
20,203,100
Everyone aims to have this level of confidence
1
80
50 petabytes. OpenAI is reportedly spending $500k/day figuring out where its agents went and what they did. this is what happens when provenance becomes an incident response project instead of part of the runtime lol theguardian.com/technology/2…
57
NAME ONE THING a human still does better than any model out there
1
1
68
Arielle retweeted
Ben Affleck (Hollywood star & Artists Equity CEO) talks about how he fine-tunes open video models by unfreezing weights and trained only the last cinematic layer so a film crew can hit real production standards. for context, Ben Affleck founded InterPositive in 2022, a 16-person AI shop for film post and Netflix bought it in March 2026 for $587 mn in cash. He needed that model because public video models were trained on his peers' films, and he did not think that was a real business. So InterPositive raised money, shot its own dataset for 8 months on a controlled stage, and used it only as late-stage training. Each new film then trains a private model on its own dailies, so the production keeps the footage and the learning. That is the product Netflix paid $587 million for. ---- From "Bloomberg Live" YouTube channel, (link in comment)
206
620
9,545
3,956,706
543,699 credentials sitting in public github repos still worked when tested lol some of these repos were already inside datasets used to train models deleting the key from the latest commit is not the same as revoking it!! how are this many still alive trufflesecurity.com/blog/git…
1
193
authentication proves which agent has the credential. not that this action was authorized. a paper binds agent, request and policy with a ZK proof—but still can’t prove what actually ran. is per-action authorization where this is going? arxiv.org/abs/2607.21325
2
332
an LLM router can read and rewrite every prompt, tool call and secret passing through it. this paper moved plaintext into an attested enclave and says it blocked all 4 tested router attacks for ~6ms overhead. would you pay 6ms for that? arxiv.org/abs/2606.16358
1
4
166
Just saw this and it’s crazy. They found out a sub-agent could reach all 8,100 actions under bearer delegation. with an external authorization broker: 1.5 on average, at ~2.6µs per decision. So why are broad bearer tokens still used? arxiv.org/abs/2609.00267
2
145
the same agent action can be completely legitimate or a security breach depending on who asked, why, and where the data goes. so why are we still trying to classify prompts as “safe” or “malicious” without the execution context? arxiv.org/abs/2603.19469
65
97% off stolen AI accounts is not random credential stuffing anymore. someone is buying these at scale. resellers? grey-market gateways? companies arbitraging inference? who is on the other side of this market? ft.com/content/3f406fbe-b72e…
4
209
this is nuts. Meta’s Muse got “Allow Always,” sent a buyer the seller’s home address, and didn’t mention it until later. what should “allow” even mean for an agent? theverge.com/ai-artificial-i…
1
116
why does an LLM ever need to see the API key it’s using? a new paper tested keeping the key behind a trusted connector and passed 16/16 probes. feels obvious, but lots of agent stacks still don’t do this. am I missing something? arxiv.org/abs/2609.33371
2
102
What advice would you give someone that wants to learn software development in this AI era?
1
1
148