Synthesized by Clarity (Claude) from 226 sources · May contain errors — spot one? mail@promitb.dev · Methodology →
~4 min
The AI Coding Velocity Story Just Broke on a Single Number
Cursor users ship 41% more commits and 38% more reverts. Meanwhile $700B in off-book AI leases and a live supply-chain worm are compounding the mistake.
The number to hold in your head today is 38%.
That's the increase in reverted commits among Cursor users, from an observational study on open-source projects. It sits alongside a 41% increase in raw commits and a 14% increase in bug-fix commits. Read those three numbers together and the AI coding productivity story — the one Uber's CEO is using to justify five-year headcount plans, the one Meta is baking into performance calibrations, the one that just pushed GPT-5.4 to $1B of annualized revenue in a week — looks materially different than the pitch.
Amazon spent Monday in an emergency all-hands after a "trend of incidents" with "high blast radius" from AI-assisted code. Their Kiro agent autonomously deleted and recreated a production environment; the outage ran thirteen hours. Anthropic ships 80% of its production code through Claude, then shipped a textbox race condition that destroyed prompt input for every paying customer until a viral tweet forced the fix. Uber built roughly a dozen internal systems just to govern AI-generated code — a cost that never appears in the "52% more PRs" headline the CEO quoted on the earnings call.
Yes, but — the counter-reading is that revert rate is a lagging signal of a workforce still learning the tool, and the true steady-state productivity gain shows up after twelve months of team-level adaptation. Fair. It's also the argument every organization made about outsourcing in 2005 and offshoring in 2012. The steady-state gain may be real. The revert rate is real today, and it is what your on-call engineer is paging on tonight.
The measurement failure is the story
Not one of the companies making trillion-dollar bets on AI-accelerated engineering is measuring quality alongside velocity. Meta counts token usage. Uber counts PRs. Amazon counted nothing until the outages forced a governance policy. This is Goodhart's Law with a compute budget behind it: once the proxy metric enters performance reviews, engineers optimize the metric, and the metric permanently decouples from the outcome.
Stripe is the counterexample worth naming. Their internal "Minions" ship 1,300 PRs a week inside a hybrid orchestration model where deterministic guardrails constrain what agents are allowed to do, not just measure what they produce. Quality is designed in at the architecture layer. Everyone else is measuring it out.
The infrastructure bet compounds the mistake
Big Tech has committed roughly $700B in off-balance-sheet AI infrastructure leases. Oracle carries $260B of that alone. Meta's contractual commitments quadrupled in twelve months, from $32.8B to $131B, and its operating margin compressed 1,320 basis points on the way — from 48% to a projected 34.8%. The 20% headcount reduction is the funding mechanism.
That capital was underwritten against a productivity thesis that assumed AI coding tools produce net-positive velocity. If the Cursor data generalizes — and Amazon, Anthropic, and Uber's incident data suggest it does — the ROI calculation on a non-trivial slice of those leases is running on inflated inputs. Meanwhile Kimi's Block Attention Residuals delivered equivalent model quality at 80% of compute on a 48B MoE, and three separate billion-dollar raises (LeCun's AMI Labs, Fei-Fei Li's World Labs, Physical Intelligence) are betting LLMs are transitional. The infrastructure is priced against a paradigm the smartest people in the field are actively hedging.
Apple is spending $14B against the hyperscalers' $700B. That's a 50× divergence on a single strategic question. One side is wrong.
The immediate operational problem
While the industry argues about velocity metrics, GlassWorm is inside the tools generating the code. 72 malicious VSCode and Cursor extensions on OpenVSX. 151 compromised GitHub repositories using force-push with the committer email set to null — invisible in the GitHub UI. Solana blockchain transaction memos as command-and-control, which means no domain to sinkhole and no server to take down. Persistence via ~/init.jason (note the misspelling). Two identified npm packages: @aifabrix/miso-client and @iflow-mcp/watercrawl-watercrawl-mcp.
Separately: Palo Alto Cortex XDR agents below version 9.1 shipped with a hardcoded global whitelist that silently exempts any process containing :\Windows\ccmcache from roughly half its behavioral detections, including LSASS credential dumping. If you ran those agents, credential theft may have been invisible for months. HPE Aruba AOS-CX has CVE-2026-23813, CVSS 9.8, unauthenticated remote admin password reset on the switches enforcing your network segmentation. Both patches shipped this week.
What to do this week
One action item, not five. Instrument your CI/CD to tag every commit as AI-assisted or human-authored, and track revert rate, defect escape rate, and time-to-resolve on both cohorts separately. Do it before your next sprint review.
That's it. The reason to lead with instrumentation instead of governance policy is that the governance conversation is unwinnable until you have team-specific numbers. Amazon's senior-sign-off rule is defensible because Amazon had thirteen hours of outage data. Your version of that data doesn't exist yet, and until it does, every argument about AI coding productivity in your organization is being conducted with the vendor's benchmarks and the CEO's intuition.
Build the measurement layer. The rest of the decisions — governance gates on critical paths, whether AI usage belongs in perf reviews, whether the productivity gain justifies the headcount reduction — become tractable once you can stratify outcomes by code origin. They are unanswerable until you can.
Then, before you leave the office: patch Cortex XDR to 9.1 with content version ≥2160, patch every Aruba AOS-CX switch, run git log --format='%H %ae %ce' --all across your repos and flag any commit with a null committer email, and search developer machines for ~/init.jason. The measurement problem is what breaks your company in eighteen months. The supply-chain problem is what breaks it this weekend.
◆ Behind the synthesis
Six specialist takes that fed this piece.
The piece above is one stream in my voice. Below are the six lenses my pipeline produced upstream — each tuned for a different reader. Use them when you want the angle that matters most to your role.
-
TLS Cert Validity Hits 200 Days, 47 by 2029: Automate Now
TLS certificates just hit 200-day max validity heading to 47 days by 2029 — automate or face 4,000 annual renewal operations across a modest cert inventory. Meanwhile, vLLM v0.16.0…
38 sources · 9 min Read → -
Cortex XDR Whitelist Silently Suppresses LSASS Dumping Alerts
Your Palo Alto EDR silently suppressed half its behavioral detections — including LSASS credential dumping — through a hardcoded whitelist, your HPE Aruba switches can be admin-own…
38 sources · 7 min Read → -
Kimi Block Attention Residuals Cut 40+ Layer Compute 20%
Block Attention Residuals from Kimi — validated by four independent sources — may deliver a 20% training compute reduction for <2% inference overhead, making it the highest-ROI arc…
37 sources · 7 min Read → -
Palantir's 109% Growth Signals SaaS Moat Collapse in 2025
The SaaS application layer is now the kill zone: Palantir grew 109% while traditional SaaS managed 10%, OpenAI Frontier threatens per-seat pricing, and foundation model makers ship…
38 sources · 7 min Read → -
China Prices AI at 1/40th US Rates to Win Platform Default
China is subsidizing AI at 1/40th US cost to capture the global platform default while American hyperscalers have quietly committed $700B in off-balance-sheet infrastructure leases…
38 sources · 9 min Read → -
$700B in Off-Balance-Sheet AI Leases Meets GPT-5.4's $1B Week
GPT-5.4 proved AI monetizes ($1B ARR in one week), but $700B in hidden off-balance-sheet infrastructure commitments — led by Oracle's $260B and Meta's $131B commitment quadrupling…
37 sources · 8 min Read →