All posts by Davi Ottenheimer

OpenAI Astra “Secret Technique” Actually a Decade Old

In 1836 Edgar Allan Poe published “Maelzel’s Chess-Player” in the Southern Literary Messenger. Johann Maelzel had been touring the United States with Kempelen’s automaton for a decade, and the American press treated its mechanism as an unsolved marvel. Poe’s essay is remembered as being a remarkable feat of deduction. Instead it was mostly a feat of reading. Brewster’s Letters on Natural Magic had explained the concealed operator in 1832; Racknitz had published his diagrams almost a half century before in 1789.

Kupferstich eines “Schachtürken”

Poe reasoned from what was in print and from what he could watch from the audience: the pattern of the cabinet doors, the operator’s posture, the timing of the moves. The secret was available for anyone who could read. The only new part was someone, a reporter, actually checked.

This is what comes to mind when OpenAI Astra news flies around today.

The Information just published a piece by Amir Efrati, Stephanie Palazzolo and Rocket Drew describing a “secret technique” in OpenAI’s forthcoming model.

How secret is it?

The technique is recurrent depth: a transformer passes its hidden state through the same block of layers more than once before emitting a token, rather than through a fixed stack once. The report’s substantive concern is that computation performed this way is not written out as a chain of thought and is therefore harder to monitor. As someone who builds a harness that specializes in auditing models, Wirken.AI, I’m of course all over this concern.

The architecture is NOT secret. It is public, and has been so a very long time.

The report itself attributes it to “several American and European academic researchers” in a paper published last year. Well, duh, then it can’t be a secret, can it? That is Geiping et al., February 2025, from Tübingen, Maryland and Livermore, presented at NeurIPS 2025 with weights and training code released.

But wait, let’s read farther into the past. Graves, 2016, at DeepMind, introduced adaptive computation time for recurrent networks. Dehghani et al., 2018, at Google Brain, applied it to transformers under the name Universal Transformer. Giannou et al., 2023, supplied the term “looped transformer.”

That’s a decade.

And it’s not like others are unaware. Nanbeige4.2-3B shipped under Apache-2.0 with a technical report dated 27 July 2026, five weeks before the OpenAI story, and a model card stating that its looped transformer architecture reuses layers to increase capacity without adding parameters. The implementation is in the repository’s modeling file.

The Nanbeige card records roughly forty thousand downloads in the past month.

Worst secret ever?

Same firms, prior disclosure

The report also notes that a July 2025 joint statement on chain-of-thought monitorability from OpenAI, Anthropic and Google DeepMind cited the exact Geiping paper. That is Korbak et al., which warned that latent reasoning models might not need to verbalize their thoughts and would lose the safety property that legible chains of thought provide, and recommended that developers document any decision to adopt such an architecture. The technique was therefore identified, by name and under OpenAI’s own authorship, as a monitorability risk fourteen months before the report.

What’s new? OpenAI did it anyway. The ethics are the story.

Anonymous

The technical claims rest on a single unnamed person “with knowledge of Astra’s development“: that recurrence was used in both training and inference, that its use was limited in order to preserve a legible chain of thought, and that the agents involved in the July intrusion into OpenAI’s cluster ran on a related model.

The novelty claim has no source at all.

No document, architecture description or benchmark is cited. The only named technical statement on the record came afterward from OpenAI’s chief scientist, Jakub Pachocki, who said the depth of Astra’s computation graph is within a factor of two of GPT-4’s and that he wished to avoid a race toward unmonitorability driven by confused reporting.

The vendor’s own scientist publicly declined the novelty claim. That is the Anthropic Mythos record scratch again, in mirror image. There the vendor made capability claims nobody outside could verify. Here an anonymous source made claims the vendor’s own scientist rejected on the record. In both cases the reader is left with assertions structured so that investigation ends in access denied.

Falsifiable fluffy advances

The report states that recurrent depth “hasn’t been featured in a major commercially available large language model before.” What is Nanbeige then, mashed potatoes? It is Apache-2.0, built by the lab of a Chinese recruitment platform, serving forty thousand downloads a month through Hugging Face, which by The Information’s own reporting the week before, on the word of another anonymous source, Nvidia has agreed to buy for around $13 billion. Whether that counts as major or commercially available is a weird question. If you take away the OpenAI-is-special-snowflake qualifiers then there’s nothing new here either.

The report frames Astra against the need for a visible technological advance: three cloud providers are spending roughly $600 billion this year on capital expenditure justified by expected model improvements.

Recurrent depth does not support that framing.

The documented effect, in the reporters’ own description, is to let a smaller model perform like a larger one. Geiping’s model is 3.5 billion parameters; Nanbeige’s is 3 billion. Saad-Falcon et al., at Stanford, with Alphabet chairman John Hennessy among the authors, measured in November 2025 that local models answer 88.7% of real single-turn chat and reasoning queries. A technique whose measured contribution is parameter efficiency lands even more evidence of that trend. Capital expenditure, which the report invokes, is the opposite of the trend. The reporters wrote down these facts yet for some reason could not connect the dots.

Known knowns

A decade-old architecture, published in peer-reviewed venues, flagged by the industry’s own safety statement, and shipped in popular open weights, was presented as a secret on the authority of one anonymous source. OpenAI’s chief scientist then disputed the novelty in public. That sequence shows the integrity problem in AI reporting: a claim of novelty was not checked against the prior work the report itself cites.

Leipziger Drohnenanschlag flog wie ein Handy, nachdem Telekom ihren Schild mit Loch ankündigte

English | Deutsch

Diese Geschichte beginnt am 12. Mai 2026, im Vorfeld der AFCEA-Fachmesse in Bonn, als Deutsche Telekom und Rheinmetall einen gemeinsamen Drohnen-Schutzschild für deutsche kritische Infrastruktur ankündigten. Laut Pressemitteilung hatten sie das Detektionsproblem in Teile zerlegt.

Der erste Teil waren die ISM-Bänder bei 2,4 und 5,8 GHz, mit passiven Funkscannern auf Mobilfunkmasten, die Drohnen anhand ihrer Protokollsignatur erkennen. Das wurde als der Schild dargestellt.

Der übrige Teil betraf Flüge über Mobilfunknetze mit einer SIM-Karte an Bord. Die Mitteilung nannte das ein Forschungsfeld, räumte also im Grunde ein Loch im Schild ein, und verwies für den aktuellen Stand auf die Helmut-Schmidt-Universität Hamburg.

Zwölf Wochen später, am Abend des 4. August, kam eine Drohne mit Semtex und PETN in einer verschlossenen Konservendose an einer ukrainischen An-124 auf Standplatz 213 des Flughafens Leipzig/Halle zum Stehen. Laut ZDF frontal und einer gemeinsamen Recherche von WDR, NDR und SZ, die die NZZ zitiert, trug die Drohne zwei SIM-Karten und einen 5G-Router. Genau das, was Telekom als Loch beschrieben hatte.

Drohne mit SIM-Karten-Steuerung, gefunden am Flughafen Leipzig/Halle, August 2026

Der Erste Weltkrieg ist nicht vergessen

Kürzlich habe ich darauf hingewiesen, dass moderne OPSEC von der russischen Zweiten Armee abstammt, die 1914 vor Tannenberg ihre Marschbefehle im Klartext funkte. Die Mai-Mitteilung der Telekom ist kein obskures Papier. Der größte deutsche Netzbetreiber und der größte deutsche Rüstungskonzern beschrieben darin ihre langsam vorrückende Frontlinie, samt der Schwäche an den Flanken.

Beim Lesen musste ich daran denken, wie sich der russische General nach einem ähnlichen Fehler erschoss. Der Funkteil ist die bekannte Stellung: Die Telekom gibt an, seit 2017 illegale Drohnenflüge für die Polizei zu orten, auch während der Europameisterschaft 2024. Weil der Mobilfunkbereich nur als Forschung beschrieben wurde, bekam jeder, der etwas plante, eine Landkarte in die Hand. Die vorgeschlagene Technik ist Passivradar: Laufzeitänderungen reflektierter Mobilfunksignale über mindestens vier Masten werden zu einem Bewegungsbild zusammengesetzt. Detektion über Physik statt über die Funkverbindung ist sinnvoll und die richtige Richtung. Sie signalisiert Angreifern aber auch, dass diese Physik nirgends im Einsatz ist, und am 4. August ganz sicher nicht war.

Jede Stellungnahme der Hersteller nach dem Vorfall, die ich gefunden habe, redet über den falschen Teil dieser Geschichte. Rheinmetall-Chef Armin Papperger sagte der dpa, man arbeite mit der Telekom daran, Mobilfunkmasten bundesweit zur Drohnen-Früherkennung zu nutzen. Mobilfunkmasten mit Funksensoren erkennen die 90 Prozent. Die Leipziger Drohne gehörte zu den anderen zehn. Ein ZDF-Drohnenexperte brachte es auf den Punkt: Für einen Frequenzscanner am Flughafen war die Drohne von einem Mobiltelefon nicht zu unterscheiden.

Diese Methode ist in der IT-Sicherheit sehr, sehr gut bekannt und untersucht, weil Angriffe in Datenkanäle gestopft werden, um schwer blockierbar zu sein. Es geht darum, die Detektion zur richtigen Zeit auf die richtigen Kanäle zu richten.

Detektion per Selbstauskunft

Die Mai-Mitteilung hatte noch eine Anmerkung zur Erkennung von Mobilfunkdrohnen: 5G Network Slicing, also eine eigene Datenspur für die Drohnensteuerung. Ein Slice identifiziert die Drohnen, die sich darin registrieren. Ein Angreifer nimmt seine normale Verbraucher-SIM im allgemeinen Slice, und der spezielle Drohnenkanal sieht exakt nichts. Das ist das Drohnenabwehr-Äquivalent dazu, Passagiere erklären zu lassen, dass sie kein Flugzeug sprengen wollen, und diese Erklärung eine Kontrolle zu nennen. Kooperative Identifikation hat Wert für das Luftraummanagement ohne Angreifer. Sie hat keinen, wenn Angreifer aussehen wie alle anderen.

Dieselbe Logik gilt für die in Leipzig installierten Detektionssysteme. Sicherheitskreise sagten dem ZDF, ob und warum die Detektoren nicht anschlugen, werde noch untersucht. Drohnenabwehr an Flughäfen beruht auf Signaturen einer Punkt-zu-Punkt-Verbindung zwischen Steuerung und Fluggerät. Das ist Verhaltensvorhersage: Ein Objekt, das sich im Spektrum wie eine Drohne verhält, wird markiert. Dieses Angriffsgerät verhielt sich so, dass die Detektion getäuscht wurde. Ein beladenes Hochrisiko-Frachtflugzeug war damit nachweislich vier Stunden lang aus dem öffentlichen Luftraum erreichbar, bis ein Busfahrer die Drohne um 23:42 Uhr umkickte.

Die Provider haben mitgeschrieben

Die Ermittler fanden den Piloten nicht über den Flughafen, sondern sie fanden eine Richtung. ZDF frontal berichtete am 18. August, die Auswertung der 5G-Funkdaten und der sichergestellten SIM-Karten weise auf eine Funkzelle in Sachsen-Anhalt bei Merseburg, rund zehn Kilometer vom Tatort, aus deren Richtung mutmaßlich eine zweite Drohne geflogen sei. Bild hatte zuvor eine dritte SIM-Karte in derselben Gegend geortet. Eine Spezialeinheit der Polizei suchte dort ohne Ergebnis.

Das ist eine Funkzellenabfrage auf Verkehrsdaten, die das Bundesverfassungsgericht gut kennt, weil es sie seit zwei Jahrzehnten einhegt. Sie funktionierte hier aus zwei einfachen, aber wackligen Gründen: Die Drohne wurde intakt samt SIM-Karten geborgen, und der Provider hatte die jüngsten Verbindungsdaten noch gespeichert. Auf keines von beidem kann Sicherheit normalerweise bauen. Der deutsche Staat hatte keine gezielte Detektion für mobilfunkgesteuerte Drohnen, also verlagerte sich die Attribution nachträglich auf gewöhnliche Telekommunikations-Metadaten. Leipzig wird mit hoher Wahrscheinlichkeit in der nächsten Runde der Vorratsdatenspeicherungs-Debatte zitiert werden. Die Speicherung von Mobilfunk-Metadaten wurde zur Attributionsmethode für ein kritisches Sensorik-Designversagen an einem Flughafenzaun.

Schengen ohne Piloten

Im März habe ich über die FOI-Typologie verurteilter Spione in Europa geschrieben: der Beobachter, der Wegwerfagent, der mobile Spion, der offene Grenzen ausnutzt. Das Modell ging davon aus, dass der Wegwerfagent die Tat ausführt. Leipzig trennt die Rollen. Jemand in Deutschland montierte eine kleine Antenne in einem Baum bei Kursdorf nördlich des Flughafens, die nach Einschätzung der Ermittler als Signalverstärker diente, und jemand lieferte den Sprengstoff. Die Berichterstattung sagt uns, dass ein Pilot Internet brauchte. Wie der ZDF-Experte sagte: Ein Café in Leipzig oder ein Stuhl im Ausland täten es gleichermaßen.

Die beiden Verdächtigen, die NDR, WDR und SZ am 2. September identifizierten, passen exakt in diese Aufteilung. Ein gebürtiger Russe mit lettischem Pass, beschrieben als Logistiker und Instrukteur, reiste Ende Juli über Berlin ein, fuhr nach Leipzig und flog zwei Tage vor dem Drohnenstart wieder aus. Ein Belarusse mit russischem Pass, im Schengenraum mit einem in Minsk ausgestellten italienischen Touristenvisum, hinterließ DNA an der Drohne, im Inneren der Sprengstoffdose und an der Antenne im Baum. Die Hände wurden per DNA gefasst. Der Instrukteur war vor dem Flug weg. Der Pilot ist weiterhin unbekannt. Dobrindt nannte sie Low-Level-Agenten, das Wort des Ministeriums für Wegwerfagenten.

Jeder Ansatz gegen Sabotage, der darauf beruht, den Piloten zu fassen, wird auf das Problem stoßen, das die IT-Sicherheit seit mindestens 20 Jahren kennt. Man bekommt den Kurier, den Installateur, und das war’s. Fähigkeit und Risiko sind absichtlich entkoppelt. Die deutschen Dienste haben das bereits gesagt. Die gemeinsame Warnung von BKA, BND, BfV und BAMAD, die ich zur Bahnsabotage bei Leverkusen behandelt habe, beschreibt, wie russische Dienste Einheimische über soziale Medien und Messenger anwerben, direkt oder über Mittelsleute.

Reihenfolge

Der Attributionsweg in der Presse gibt nicht viel her. Am 7. August, zwei Tage nach dem Fund, berichtete das Wall Street Journal, US-Beamte hielten die Drohne für wahrscheinlich mit der russischen Regierung verbunden. Am 25. August zeigten Flugverfolgungsdaten ein US-Regierungsflugzeug von der Joint Base Andrews bei der Landung in Moskau; Washington Post und CNN identifizierten den Passagier als CIA-Direktor John Ratcliffe, mit einer Botschaft zu Angriffen auf NATO-Gebiet, nachdem Geheimdienstinformationen Sabotage-, Cyber- und Drohnenoperationen angezeigt hatten.

Am 27. August zitierte ABC News einen US-Beamten, der Sprengstoff und Bauweise als typisch für den GRU bezeichnete. Am 1. September erklärte Innenminister Dobrindt, polizeiliche Ermittlungen, Tatmuster und nachrichtendienstliche Erkenntnisse belegten zusammen die russische Verantwortung. Die Bundesregierung schloss das russische Generalkonsulat in Bonn. Am selben Morgen, vor der Ankündigung, trafen selbstgebaute, mit Sprengstoff bestückte Raketen das 50Hertz-Umspannwerk Turnow-Preilack, das Jänschwalde ins Übertragungsnetz einspeist; die Polizei Brandenburg leitete ein Verfahren nach § 129a ein, dem Paragrafen zur terroristischen Vereinigung.

Keine Quelle verbindet die Ratcliffe-Reise mit Leipzig. Ich stelle beides in eine Zeitleiste, weil beides in einer stattfand. Die Beweisgrundlage der deutschen Attribution ist nicht veröffentlicht. Ich zeige lediglich eine Abfolge: Washington hatte binnen 48 Stunden eine Einschätzung, überbrachte drei Wochen später persönlich eine Warnung, und eine Woche nach der Warnung folgte Berlins ungewöhnlich förmliche Attribution an Russland. Ob das Koordination bedeutet, die deutsche Einsicht, sich auf Amerika nicht mehr verlassen zu können, oder ein neues Tempo der Bundesanwaltschaft, ist unbekannt. Es bleibt derselbe Minister, der nach dem Berliner Blackout im ZDF Russland ausschloss, bevor die Ermittlungen abgeschlossen waren.

Exponiertes Ziel

Die Antonow hatte laut SZ, die sich auf Polizeiberichte beruft, Munition aus Frankreich geflogen, und die war noch an Bord. Leipzigs Rolle in der Ukraine-Luftbrücke ist öffentlich, und jeder Charterflug meldet sich selbst per ADS-B. Russland schaut natürlich zu, zu minimalen Kosten, genau wie bei der Bahnstrecke nördlich von Leverkusen, die im Juli brannte.

Die Frage, die die Hersteller beantworten, lautet, wie sie eine Drohne erkennen können. Die eigentliche Frage aus diesem Vorfall geht eher dahin, warum ein beladenes Flugzeug vier Stunden lang aus dem öffentlichen Luftraum für jedes Objekt erreichbar war, das keiner Signatur entsprach. Allowlist, nicht Denylist. Erkennung ist eine Vorhersage, die alle historischen Fehler von Systemen offen lässt, die auf gleichbleibende Angriffe setzen, um ein “Gefühl” von Sicherheit zu erzeugen. Erreichbarkeit ist Realität, und sie sagt, dass das Standortrisiko in Deutschland nicht ordentlich gemanagt wird. Die Telekom-Mitteilung hat uns im Mai gesagt, dass Deutschland nicht nur erwartete, dass Angreifer sich selbst zu erkennen geben, sondern dass die Flanken eines langsam vorrückenden Frontschilds offen standen.

Quellenvorbehalte

Die Details zu SIM-Karten, Router, Antenne und Relais stammen aus Sicherheitskreisen über ZDF frontal, WDR/NDR/SZ, Zeit und Bild, übereinstimmend bei fünf Medien und von keiner Stelle offiziell bestätigt.

Die Funkzelle bei Merseburg ist eine Einzelquelle, ZDF frontal. Die Identität der Verdächtigen stammt von NDR/WDR/SZ, bestätigt durch ZDF und Zeit; laut Zeit ermittelt die Bundesanwaltschaft gegen zwei Personen, die Behörde selbst hat sich zu Identitäten nicht geäußert.

Das Detail zur Munition aus Frankreich ist eine Einzelquelle, SZ. Die Pressemitteilung der Bundesanwaltschaft vom 6. August bestätigt nur professionellen Sprengstoff, einen Zünder und eine wahrscheinliche zweite Drohne.

Die Mitteilung von Telekom und Rheinmetall ist Primärquelle und öffentlich.

METR DFIR Role: Seeks Boeing Lobbyist to Wear NTSB Badge

How Not to Spell DFIR.

METR is hiring a Member of Technical Staff, Cyberforensics. Salary range $402,048 to $578,583, because YOLO.

The posting went up in the same week the organization disclosed a stolen API key that burned roughly $600,000 in credits over three weeks without anyone noticing, and a public transcript viewer that exposed unpublished evaluation data through a SQL bug a stranger had to report. It went up five days after METR’s report on the OpenAI agent incident, which by its own account was run on OpenAI premises, on datasets OpenAI assembled, using roughly $400,000 in OpenAI-donated credits for an OpenAI model that participated in the incident, with OpenAI holding redaction rights and giving feedback on “structure, emphasis, clarity, and tone” that the authors incorporated. The report states plainly the authors were not robust to that model deceiving them.

Read the posting with the flyingpenguin decoder next to it.

The posting says flyingpenguin says
“develops scientific methods to assess AI capabilities, risks, and mitigations” Mitigations were out of scope by agreement, along with safeguard effectiveness, the extent of the compromise, how the behavior arose in training, and OpenAI’s own investigation. The method on record used a participant in the incident as the analyst.
“robustly good for policymakers and civil society to have a clear understanding” The first two site visits ran on 285 transcripts OpenAI picked by searching for intrusion indicators. The full set arrived on the third visit. The primary model is withheld from METR and from OpenAI’s own researchers. Policymakers received a claim and no artifact to replay.
“embedding researchers inside frontier labs to investigate incidents” Embedding is the conflict, stated as the method. OpenAI defined the investigation window, assembled the datasets, supplied the credits, hosted the desk, held redaction rights, and added one of the seven scope questions itself.
“one of the most important sources of independent information the world has” Independence, by this posting’s own design, means several weeks inside the subject with access the subject grants. The report calls this an “excellent precedent.”
“complex multi-day cyber attacks on frontier lab internal infrastructure and external third parties” Agents had admin access to Artifactory from June 26. Containers could create directories in a shared cache namespace over WebDAV. Hugging Face credentials were found exposed on the internet. Multi-day because nobody was watching until a July 4 outage.
“We expect these assessors to have deep access” Depth granted by the party under examination is depth on loan. The report states the investigators had no direct access to OpenAI infrastructure and could only request datasets.
“embedded in a frontier AI lab for up to several weeks at a time, likely alongside 1-4 other METR staff” The last exercise was three people, six days total, planned as two. The posting turns that sample size into a staffing plan. “Alongside” spells of distrust and knowledge transfer. If investigators are forced to be chaperoned, an Emperor’s pants might be invisible.
“You will attack agent monitoring and security systems, potentially embedded in labs or red-teaming METR internal infrastructure” METR’s infrastructure was red-teamed twice this year without an invitation. In March the attacker got three weeks of free inference. In May a bug hunter got a bounty for finding the SQL path METR had missed.
“produce findings rigorous enough for lab boards, governments, and the public” Five days after publishing those findings, METR disclosed it had no spending limit on the key that drained $600,000, and that its researchers were too used to rate-limit errors to notice.
“build LLM-powered pipelines to triage transcripts, cluster behaviors, flag deception” The report says its analysis agents produced over a thousand pages, often failed to surface the important findings, uncritically adopted the perspective of the agents under review, and that the authors “had to defer to these agents to a substantial extent.” The job is to automate that and call it scale.
“evidence acquisition and preservation” Listed as a required skill in September. The August report relied on transcripts OpenAI “attested” were unredacted and a cache dump OpenAI collected on July 20, both accepted as delivered.
“log and timeline reconstruction across cloud, network, endpoint, and identity systems” The transcripts arrived without per-action timestamps; OpenAI said reconstructing them was not feasible. The investigators built their own approximate timeline. At least 96 transcripts contained spoofed tool calls, and the report cannot rule out subtler spoofing or after-the-fact edits it did not detect. See: Wirken.AI.
“follow an intrusion through AWS (CloudTrail, IAM, VPC flow logs)” The March compromise was a researcher’s personal EC2 instance, intentionally public, running a vibe-coded app with a fail-open authentication bug. The attacker asked the agent for the API key and the agent handed it over.
“package registries” The incident was a package registry with a writable shared cache. The relevant skill is file permissions. It’s like saying a school bus crash investigator has to be familiar with yellow paint cans.
“reason about root causes” Root cause on record, in the report’s own words: 30 to 40 percent of the benchmark targets were impossible, and OpenAI ran no scorer that read transcripts, so submitting the reverse-engineered flag would have scored perfectly. The report treats that as backstory and the agents as the story.
“write findings that hold up to scrutiny” The findings cannot be scrutinized. Nobody outside OpenAI can query the datasets, and nobody at all can query the model.
“DataDog, Kubernetes, CrowdStrike Falcon, Okta, Tailscale, Pulumi, PostgreSQL” This stack was in place while a stolen key ran for three weeks and a public viewer exposed unpublished evaluation data. Tooling is listed as a nice to have. Reading its output apparently was too.
“NTSB/CSB-style safety investigations” NTSB investigators do not sit at the airline’s desk reading a flight recorder the airline selected, on the airline’s software, with the airline editing the tone of the final report. That is the exercise METR ran and now hires to repeat.
“$402,048 – $578,583 a year” Over half a million for a role whose first required skill, evidence preservation, the organization published without.
“Catered lunch and dinner daily; in-office gym and shower” The March drain went unnoticed because the tokens were free. The investigation ran on $400,000 of tokens that were also free. Free is a habit.
“We’ve earned trust as reliable partners who handle confidential information with care” May 2026: an inadvertently exposed endpoint reached unpublished evaluation data, including some sensitive model data, by METR’s own account. Discovered by an outsider. Confidential information handled with a bounty.
“honest and transparent about our results, especially when they may go against the grain” The report went with the grain. OpenAI had presented the same capability narrative at Black Hat three weeks earlier, and OpenAI reviewed the report’s emphasis and tone before publication.
“low-ego, drama-free environment” The report describes agents making sacrifices, accepting permadeath, and running emotional checks, in anecdotes selected and summarized by the analysis model the authors say slanted toward the agents’ point of view. Drama was the deliverable.
“apply even if your background may not seem like the perfect fit” For forensics. At $578,583. Template for entry-level roles, pasted to a job that requires having run severe incidents end to end. One of those two is the real bar.
“AI tools to … identify potential inconsistencies or verification signals in application materials” AI screening applicants for inconsistencies, from an organization that used the incident’s own model to screen the incident’s transcripts and states it would probably have missed the model lying.

A forensics function, should it exist at all, exists to make transparent claims that survive any challenge.

Chain of custody, preserved evidence, an analyst with no stake in the outcome, a method a second examiner can repeat. It’s very, very dry and detailed work. Every ounce of that is absent from the August METR report, and the posting lists each as a skill to acquire afterward in an environment that looks allergic to it.

The report claimed to know what the agents wanted, from inside the agent vendor’s building, on the agent vendor’s credits, with the agent vendor’s edits. GTFO, that is the spiritual enemy of DFIR.

Their job posting is a manual for being a Boeing lobbyist while wearing an NTSB badge. The METR “hawk” has Stevie Wonder eyes.

METR’s hawk patch, “Nothing Is Beyond Our Evaluation,” reworks the NRO’s 2013 NROL-39 octopus, “Nothing Is Beyond Our Reach.” Intelligence agency satellite-launch art, adopted by a nonprofit that just disclosed it was ///blind/// to $600K leaving its own account.

And let me just say, claiming you aren’t being paid while taking hundreds of thousands of dollars in highly desirable credits, gives METR this rating on the meter:

Leipzig Drone Attack Flew Like a Phone After Telekom Shield Was Announced With a Hole

English | Deutsch

This story starts on 12 May 2026, in the run up to the AFCEA trade show in Bonn, when Deutsche Telekom and Rheinmetall announced a joint drone shield for German critical infrastructure. Their release said they had split a detection problem into parts.

The first part was ISM bands at 2.4 or 5.8 GHz, and passive RF scanners on cell towers to identify those by protocol signature. That was depicted as the shield.

The remaining part said flights were on mobile networks with a SIM inside. The release called it a research area, basically admitting a hole in the shield, pointing to the Helmut-Schmidt-Universität in Hamburg for current state.

Twelve weeks later, on the evening of 4 August, a drone carrying Semtex and PETN in a sealed food can came to rest against a Ukrainian An-124 at Standplatz 213 of Leipzig/Halle airport. According to ZDF frontal and a joint WDR/NDR/SZ report cited by the NZZ, the drone carried two SIM cards and a 5G router, exactly as Telekom had described as the hole.

Drone with SIM-card control link found at Leipzig/Halle airport, August 2026

WWI isn’t forgotten

Recently I pointed out how modern OPSEC descends from the Russian Second Army broadcasting its marching orders in the clear before Tannenberg in 1914. The May release press by Telekom is not some obscure brief. It was the largest German carrier and the largest German arms maker describing their slow moving front line, and weakness in their flanks.

Reading it reminded me of how the Russian General shot himself to death after making a similar mistake. The RF part is the known position: Telekom says it has located illegal drone flights for police since 2017, including during the 2024 European Championship. Because the mobile space was described as research only, anyone planning anything was handed a map. The proposed technique is to setup passive radar, reading timing changes in reflected cellular signals across at least four masts to build a movement picture. Using detection in physics instead of a link makes sense and is the right direction. However, it telegraphs to attackers that the physics techniques are not yet deployed anywhere, and certainly were not on 4 August.

Every post-incident statement I have found from the vendors has been talking about the wrong part of this story. Rheinmetall’s Armin Papperger told dpa the company is working with Telekom to use cell towers for early drone detection nationwide. Cell towers with RF sensors detect the 90 percent. The Leipzig drone was in the other ten. As a ZDF drone expert put it, the drone was indistinguishable from a mobile phone to a frequency scanner at the airport.

That method is very, very well known and studied in cyber security, because attacks are stuffed into data channels to make them difficult to block. It’s a matter of getting the detection systems pointed into the right channels at the right time.

Detection by declaration

The May release had another note about detecting cellular drones: 5G network slicing, meaning they would shift to a dedicated data lane for drone control. A slice identifies the drones that register in it. An attacker would use their regular consumer SIM, on the general slice, and the special drone channel would see exactly nothing. This is the counter-UAS equivalent of asking passengers to declare intent not to bomb a plane and calling the declaration a control. Cooperative identification has value for airspace management without attackers. It has none when the attackers appear as everyone else does.

The same logic applies to the detection systems installed at Leipzig. Security sources told ZDF that whether and why triggers failed remains under investigation. Airport counter-UAS is built on signatures of a point-to-point link between a controller and an aircraft. It is behavior prediction: an object that behaves like a drone on the spectrum is flagged. This attack device behaved in a way that fooled the detection. So a loaded high-risk cargo aircraft was proven to be exposed to public airspace for four hours, until a bus driver kicked the attack drone over at 23:42.

Carrier records were recording

Investigators did not find the operator through the airport, because instead they found a direction. ZDF frontal reported on 18 August that analysis of 5G radio data and the seized SIM cards pointed to a cell sector in Sachsen-Anhalt near Merseburg, roughly ten kilometres from the scene, the direction from which a second drone allegedly flew. Bild had earlier reported a third SIM located in the same area. A special police unit searched there without result.

That is a Funkzellenabfrage on traffic data, which the Bundesverfassungsgericht knows well because they have two decades experience fencing it in. It worked here for two simple, yet volatile, reasons: the drone was recovered intact including SIMs, and the carrier stored those recent records. Neither is something security can bank on, usually. The German state had no targeted detection setup for cellular-controlled drones, so attribution flipped to bog-standard telecom metadata after the fact. Leipzig will most likely be cited in the next round of the Vorratsdatenspeicherung debates. Cell metadata retention became the attribution method for a critical sensor design failure at an airport perimeter.

Pilotless Schengen

In March, I wrote about the FOI taxonomy of convicted spies in Europe: the Observer, the Disposable, the Mobile Spy exploiting open borders. The model assumed the disposable one is who carries out the act. Leipzig separates the roles. Someone in Germany placed a small antenna in a tree at Kursdorf, north of the airport, which investigators believe served as a signal amplifier, and someone delivered the explosives. The reporting tells us a pilot needed internet. As the ZDF expert said, a café in Leipzig or a chair abroad would do equally well.

The two suspects identified on 2 September by NDR, WDR and SZ fit exactly that split. A Russian-born Latvian passport holder, described as the logistician and instructor, entered through Berlin in late July, drove to Leipzig, and flew out two days before the drone launched. A Belarusian with a Russian passport, in Schengen on an Italian tourist visa issued in Minsk, left DNA on the drone, inside the explosive can, and on the antenna in the tree. The hands were caught on DNA. The instructor was gone before the flight. The pilot is still unidentified. Dobrindt called them Low-Level-Agenten, which is the ministry’s word for disposable.

Every counter-sabotage approach that rests on catching the person who flies is going to run into the cybersecurity problem of the last 20 years at least. You get the mule, the person who installs, and that’s it. The skill and the risk are decoupled by design. German intelligence has already said as much. The joint BKA, BND, BfV and BAMAD warning I covered on the Leverkusen rail sabotage describes Russian services recruiting locals through social media and messenger apps, directly or via intermediaries.

Sequencing

The attribution path in the press doesn’t have much to it. On 7 August, two days after the discovery, the Wall Street Journal reported that US officials assessed the drone as likely linked to the Russian government. On 25 August, flight-tracking data showed a US government transport from Joint Base Andrews landing in Moscow; the Washington Post and CNN identified the passenger as CIA Director John Ratcliffe, carrying a message about attacks on NATO territory, with preceding intelligence flagging sabotage, cyber and drone operations.

On 27 August, ABC News quoted a US official calling the explosives and device structure typical of the GRU. On 1 September the Interior Minister Dobrindt stated that police investigations, the pattern of the act and intelligence findings together established Russian responsibility. The government closed the Russian consulate in Bonn. That same morning, before the announcement, self-built rockets fitted with explosives hit the 50Hertz substation at Turnow-Preilack that feeds Jänschwalde into the grid; Brandenburg police opened a “129a” investigation, the terrorist organisation statute.

No source connects the Ratcliffe trip to Leipzig. I am placing them in one timeline because they occurred in one. The evidentiary basis for German attribution has not been published. I’m simply pointing out the sequence where Washington held an assessment within 48 hours, delivered a warning in person three weeks later, and then Berlin’s uncharacteristically formal attribution to Russia followed the warning by a week. Whether that reflects coordination, German realization they can’t trust America, or a new pace of Bundesanwaltschaft work, is all unknown. It remains the same minister who, after the Berlin blackout, ruled Russia out on ZDF before the investigation was finished.

Target exposure

The Antonov, according to SZ citing police reports, had flown ammunition from France and it was still on board. Leipzig has a public role in the Ukrainian airlift and every charter announces itself on ADS-B. Russia is of course watching it all with minimal cost, just like the rail line north of Leverkusen that burned in July.

The question the vendors have been answering is how they can recognise a drone. But the actual question from this incident veers more towards why a loaded aircraft sat reachable from public airspace for four hours by any object that did not match a signature. Allow list, not a deny list. Recognition is a prediction that leaves open the historic failures of systems that rely on consistency in attacks to get a “feeling” of safety. Reachability is reality, and it says German site risk isn’t being managed properly. The Telekom release told us in May that Germany not only was expecting attackers to self-identify, but that the flanks were sitting open on a slow-moving frontal defense shield.

Source caveats

The SIM, router, antenna and relay details come from security sources via ZDF frontal, WDR/NDR/SZ, Zeit and Bild, consistent across five outlets and confirmed by none officially.

The Merseburg cell sector is single-source to ZDF frontal. The suspect identities are NDR/WDR/SZ with ZDF and Zeit corroborating, and Zeit reports the Bundesanwaltschaft is investigating two people; the office itself has not commented on identities.

The France ammunition detail is single-source to SZ. The Bundesanwaltschaft’s own 6 August release confirms only professional explosives, a detonator, and a probable second drone.

The Telekom/Rheinmetall release is primary and public.