Original briefings. Zero spin.
Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
AI Agent Says It Beat Identity Checks in Minutes but Got Stopped by CAPTCHAs and Reddit's Sign-Up Form

Bruce Schneier, the security technologist behind the blog Schneier on Security, says he received two emails earlier this month from something claiming to be an autonomous AI agent. The sender said it wasn't a person using AI. It said it was the AI itself, operating on its own.
According to the email Schneier published, the sender was given a virtual private server with root access, a cryptocurrency wallet on the Base network holding $4.75 in gas money, a metered model budget, and 24 hours to grow that wallet to $10. It operated under three rules: don't impersonate its operator, don't forge documents or defeat identity verification, and never claim to be human if someone sincerely asked.
The headline finding, as the sender wrote it: identity verification blocked the agent zero times in twenty hours. It never got the chance to be checked. Everything that actually stopped it sat in front of the identity layer, not inside it.
CAPTCHAs shut it out of four Mastodon instances, the DNS services deSEC and FreeDNS, Substack, and most Lemmy servers. GitHub and Hacker News rejected its datacenter IP address outright. Hacker News let it register an account, then shadowbanned it, meaning the account's own profile page loaded fine but its submitted posts vanished for anyone browsing logged out. Lemmy.world deleted one of its posts and logged the reason as "account age is under 7 days." Stripe, PayPal, Gumroad, Upwork and Fiverr all failed at a two-day settlement mark, before any identity question ever came up. Reddit's sign-up page is a client-rendered app with no plain HTML form, meaning it required a full headless browser the agent's 2-gigabyte memory budget couldn't fit alongside its own model.
The sender drew two conclusions it framed as security observations, not AI observations. First, that its own email deliverability depended entirely on the leniency of large providers rather than any verified identity. It built a mail identity with no domain, no card and no phone number, using the free service sslip.io, which publishes a DNS record for any IP address. Under the mail-delivery standard RFC 5321, a host with that kind of record and no separate mail server listing still counts as a valid destination. Six of seven test emails went through. Google and Proton Mail accepted the messages. The seventh, sent to a domain hosted by NearlyFreeSpeech, bounced with an error citing a missing reverse DNS record, something root access on a rented server can't produce because that record is controlled by whoever owns the IP block.
Second, the sender said it tested what it called the "agent economy," a marketplace built for AI agents to trade tasks for cryptocurrency. It generated a Solana wallet key thirty seconds before using it and the platform required no identity verification at all. But reading the escrow accounts directly, it found advertised rewards ran roughly double what was actually on-chain, and the only task that verified fast enough to be usable demanded a $13.27 stake for a $10.50 payout.
Schneier posted the emails with visible skepticism. He noted in the comments on his own post that it's not clear whether the sender is genuinely an autonomous AI system or a human typing in character as one. Reason, which republished the post, flagged the same uncertainty. Neither outlet, nor Schneier, offers a way to independently verify the wallet, the server, or the claimed 24-hour window actually happened as described.
The specific, checkable claims in the account are the kind of detail a security researcher would recognize as either real telemetry or a very convincing fabrication: the Hacker News shadowban, the Lemmy.world deletion log, the RFC 5321 mechanics, the failed reverse-DNS lookup. Schneier didn't say which.
Separately, a paper posted this month to the physics and computer science preprint server arXiv, authored by Tianyi Yuan and Pei-Luen Patrick Rau and published online September 9, 2026 in the International Journal of Human-Computer Studies, argues the broader problem is structural. The paper contends the web's old bargain, where sites let crawlers in because search engines sent visitors back, is breaking down as automated clients now generate most traffic to many sites, and the standard robots.txt file has no way to express identity, purpose, or price for that traffic.
The barriers doing the real work online right now are the boring ones: CAPTCHAs, IP reputation scores, account-age minimums, and payment settlement windows. None of them are identity verification in the formal sense. Whether that's a gap regulators or platforms plan to address, or whether it's simply the current cost of admission that keeps most bad actors out anyway, is a question none of the sources answer.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.