Digital Colliers Daily Briefing — August 2, 2026
Sunday's agenda is dominated by a single technical event of unusual weight: OpenAI's claim that an internal version of its next flagship model produced novel results on ten long-standing problems in mathematics and theoretical computer science, complete with Lean formalizations. Alongside that, US officials have widened the known scope of ongoing cyberattacks against municipal water systems to at least seven states, and Apple has begun rate-limiting bug bounty submissions to fend off a growing tide of AI-generated vulnerability reports. Together, the day sketches a compressed picture of AI's dual role in 2026 — as a serious research instrument, and as a stress vector on the institutions built to receive its output.
1. OpenAI says Astra cracked ten decade-old problems for under $2,000 in tokens each

OpenAI published results attributing new proofs on ten open problems to an internal build of Astra, described as its next major model. The problems span high-dimensional sphere packing (matching the Cohn–Elkies threshold), exponentially improved bounds for binary and spherical codes, the existence of non-sofic groups, a disproof of Connes's rigidity conjecture, arithmetic-formula lower bounds of order n⁴/log n for the permanent, an exponential parallel-repetition theorem for two-player quantum games, polynomial-factor hardness for the closest vector problem, Ehrhart's volume conjecture, a superexponential lower bound for multicolor triangle Ramsey numbers (Erdős problem 183), and results on the compactness and degeneracy conjectures in extremal graph theory (Erdős problems 146 and 180). OpenAI says each solution required roughly $2,000 in tokens at Sol API rates, and that every argument was subsequently formalized in Lean 4 and published in the openai/ten-proofs repository. Manuscripts were prepared by humans working with the same model, and OpenAI is releasing reconstructed narrations of the model's reasoning.
The announcement lands the same week that Fields Medalist Jacob Tsimerman took leave from the University of Toronto to join OpenAI's safety work, according to the Wall Street Journal — a hiring signal that reinforces the research posture the results are meant to demonstrate. It also follows Anthropic's recent Claude-driven cryptographic findings, which Simon Willison noted involved deliberately steering the model toward "genuinely hard findings" rather than low-hanging fruit. Willison flagged the obvious gap in OpenAI's disclosure: the company has not said how many problems it attempted at $2,000 apiece without success, nor has it published the prompts.
Why it matters: If the Lean certificates hold up under community scrutiny, this is the clearest evidence to date that frontier models can produce genuine mathematical research contributions rather than assist at the margins. OpenAI's decision to be explicit about attribution — refusing to claim human authorship for machine-generated arguments, and gesturing to the Leiden declaration on AI and Mathematics — signals awareness that the sociology of the discipline is now part of the story.
Who is affected: Working mathematicians and theoretical computer scientists most directly, along with cryptography researchers whose lattice-based post-quantum assumptions intersect with the CVP hardness result. OpenAI's ChatGPT for Academic Researchers program, which provides 100,000 scientists free access, is the intended distribution channel. Willison points to the emotional dimension already visible in the community, citing Kirwin Hampshire's essay "The Dark Night of Mathematics" and Terence Tao's "big mathematics" framing in IEEE Spectrum.
What to watch next: Independent verification of the Lean proofs, whether OpenAI releases the prompts and full attempt counts, and how mathematics preprint norms adapt to AI-generated submissions. Tsimerman's specific portfolio at OpenAI will also be worth tracking.
Sources:
- [HN · 429↑] Ten advances in mathematics and theoretical computer science — Hacker News
- OpenAI says an internal version of Astra, its next big model, produced results for 10 problems in math, quantum complexity, and theoretical computer science (OpenAI) — Techmeme
- OpenAI's "ASTRA" change science forever... — YouTube · Wes Roth
- Ten advances in mathematics and theoretical computer science — Simon Willison
- A profile of Jacob Tsimerman, who won the Fields Medal last week and is taking a leave from the University of Toronto to join OpenAI and work on AI safety (Ben Cohen/Wall Street Journal) — Techmeme
2. Water-system cyberattacks now confirmed across seven states, officials say

Federal and state officials told the New York Times that ongoing cyberattacks aimed at disrupting US water systems now span at least seven states, including Michigan and Minnesota, with the true footprint potentially larger. Minnesota was the first state to publicly disclose an incident; other affected states have not yet been individually named.
Why it matters: Water utilities have been an acknowledged soft target for years — thousands of small, under-resourced systems running aging OT equipment — but a coordinated multi-state campaign moves the threat from theoretical to operational. It also revives long-running debate over whether EPA-led cybersecurity requirements for water systems, previously blocked in court, need to be reconstituted through legislation.
Who is affected: Municipal water authorities, ratepayers in the affected regions, CISA and state-level cyber response teams, and vendors of industrial control systems used in water treatment. Utilities outside the disclosed states should assume they are within scope.
What to watch next: Formal attribution, whether the intrusions produced any degradation of water quality or service, congressional response, and any emergency directive from CISA to the broader water sector.
Sources:
3. Apple caps bug bounty submissions as AI-generated reports overwhelm triage

Apple has introduced a per-researcher cap on vulnerability submissions and a 30-day cool-off period between reports, citing a surge of AI-assisted disclosures overwhelming its security triage pipeline, the Financial Times reported. Researchers with a track record can request higher quotas.
Why it matters: It is the first major vendor to formally throttle inbound security research in response to LLM-generated noise. The move concedes what curl maintainer Daniel Stenberg and others have argued for over a year — that plausible-looking but non-reproducible AI reports impose a real tax on defenders. Expect Google, Microsoft, and the major bug bounty platforms to follow with similar mechanisms, likely tied to reputation scoring.
Who is affected: Independent security researchers, particularly newcomers without established Apple Security Research reputations; bug bounty intermediaries such as HackerOne and Bugcrowd, whose economics assume high submission volume; and, indirectly, iOS and macOS users, whose exposure window depends on how the cap interacts with legitimate high-severity discoveries.
What to watch next: The exact quota structure and appeal mechanics, whether other platform vendors adopt matching policies, and whether Apple publishes data on the share of submissions it deems AI-generated slop.
Sources:
The through-line of the day is the widening gap between what AI systems can now produce and what surrounding institutions are equipped to absorb. Astra's results, if they hold, show frontier models operating at the edge of human mathematical research; Apple's quota shows a mature security process buckling under the volume of low-quality machine output. The water-sector intrusions are a reminder that while the AI industry debates authorship and triage, the older categories of critical-infrastructure risk continue on their own timeline — and demand attention that the news cycle does not always afford them.

