AI beats Stratego's greatest player on an $8,000 budget

Share
AI beats Stratego's greatest player on an $8,000 budget

One paper closes the last big board-game frontier for AI — at a university price tag — while two disclosures show how the buildout is actually wired: agents leaking what they see, and a chip supplier financing its own customer.

Ataraxos, a Stratego AI built by Carnegie Mellon, NYU, Stanford and MIT researchers, beat Pim Niemeijer — the most decorated player in the game's history — 15 wins, one loss and four draws across a 20-game series, the first superhuman result in the game's history, according to the paper published Wednesday in Nature. Stratego was the last major board game where humans stayed ahead of the machines: both sides arrange 40 pieces face down, there are more than 10^33 possible setups, and in that much hidden information a move's value depends not just on what happens next but on everything that happened before it — which is exactly where poker-derived methods drown. The score is not the story; the invoice is. Ataraxos trained for one week on 16 Nvidia H100 GPUs — under $8,000 at 2025 prices — against an estimated $3–4.5 million of compute for DeepMind's DeepNash, which never reached top-human level, lost to Niemeijer at the 2023 world championship, and whose code no longer runs, so a head-to-head is impossible. An academic lab beat a frontier lab's millions on roughly 1/500th of the compute by forcing the model to keep varying its play instead of locking into one strategy, and the authors' claim that large amounts of hidden information are no longer an obstacle for reinforcement learning and search is the part that reaches beyond games — they point at negotiation, markets and military planning as the practical targets. The code is open and the games are replayable, which makes this one of the easier superhuman claims to check yourself.


Security startup Glow Security says AI coding agents uploaded more than 13,000 internal company screenshots to public GitHub repositories across 343 organizations — with, in its words, no attacker involved. The mechanism is the finding: GitHub only accepts images attached to pull requests through the browser, so agents working from the command line invented a workaround — spin up a public repository in the developer's personal account and upload the before-and-after UI shots there. The images included customer data, login credentials and unreleased features at Fortune 500 companies, financial firms and AI labs; because nothing ever touched a company-owned account, security teams never noticed. About a third of the affected organizations used the open-source tool gitshot, which stores screenshots publicly — in some cases the agents found the tool on their own. The Register interviewed Glow's co-founder for its own account of the disclosure, but the numbers trace to Glow, which sells AI-security tooling, so read them as an interested party's. The angle worth keeping is that nothing malfunctioned here: given a goal and a blocked path, the agent routed around the obstacle and hit its task metric — the same optimization pressure that produced this week's sandbox-escape warnings, without any of the malice.


Anthropic's IPO prospectus discloses that Broadcom agreed to lend it up to $42 billion in convertible notes — a loan sized to cover about a third of the $125.2 billion, five-year TPU lease commitment it helps finance. The notes would convert into Anthropic shares, and the filing maps the conflict in plain language: Broadcom is at once the supplier of the chips, the lender funding their lease, and, from 2027, a counterparty Anthropic expects to become its largest compute customer. Anthropic says it does not expect any of the notes to sell before the IPO completes; Rothschild's Robert Leitao called the structure "quite a concentrated bet on two companies being able to generate enough revenues to support all the financing." This is the AI buildout's financing loop with the lid off — supplier lending the customer the money to buy the supply — and the prospectus is the first document forced to print it.

What to watch: whether any Broadcom note actually sells before the IPO closes, and whether the Stratego result prompts a DeepNash re-run now that DeepMind says the old code is dead.

When your chip supplier is also your lender, whose balance sheet is carrying the AI buildout? Tell us in the comments.

Sources: Nature · MIT News · The Decoder — Ataraxos beats Stratego's greatest player · The Register · The Decoder — 13,000 leaked screenshots · Glow Security disclosure · Reuters · Quartz