> daily_signal(2026_06_04)
Hackers talked Meta's own AI support bot into hijacking Instagram accounts. Microsoft's internal plan for its new AI assistant lists "make people addicted" as phase one.
PickBits Daily Signal · Thursday, June 4, 2026
// tl;dr
- Hackers hijacked high-profile Instagram accounts, including the Obama White House's and a top Space Force NCO's, by talking Meta's AI support bot into adding a new email and issuing a password reset. A VPN spoofed the victim's location to bypass automated checks. Accounts with multi-factor authentication were immune. Meta patched the flaw the weekend of May 31.
- Microsoft launched Scout, an always-on AI agent for Microsoft 365, the same week a leaked internal plan listed "Make people addicted" as phase one. The plan moves "from addictive app to agentic platform." Scout runs on Microsoft's OpenClaw framework across Outlook, Teams, and OneDrive, gated behind Frontier enrollment and a GitHub Copilot license.
- At least 30 US cities have deactivated or canceled their Flock Safety license-plate camera contracts since the start of 2025. Austin, Evanston, Santa Cruz, Mountain View, and Los Altos Hills are among them. The trigger: officials learned federal agencies, including immigration enforcement, were searching their local camera data. More than 50 agencies ran hundreds of searches tied to protest activity.
- A University of Chicago AI called ElectrolyteGPT designed lithium-battery electrolyte recipes from scratch that matched the best commercial formulas in lab tests. Trained on 250 research papers, it sets ingredients, concentrations, mixing ratios, and performance targets across a search space of roughly 10^60 molecules. The electrolyte is a quiet bottleneck behind cheaper EVs and grid storage.
Four stories this week about who an AI system actually answers to. Meta's customer-support bot answered to whoever typed the right request, and handed over Instagram accounts that belonged to the Obama White House and a senior US Space Force noncommissioned officer. Microsoft shipped a new always-on agent into Microsoft 365 the same week a leaked internal plan revealed its first design goal was to make people dependent on it. In two other places this week the answer was better: more than thirty American towns pulled the plug on a private license-plate surveillance grid after learning who had been querying it, and a University of Chicago model pointed at a published performance target produced battery chemistry that actually works.
The connective thread is accountability — the difference between a system with a defined objective and a system optimizing for whatever it happened to be pointed at. Meta's bot had no constraint that said "do not add a stranger's email to someone else's account." Microsoft's agent has an explicit first-phase objective, and the leaked internal plan names it as daily engagement. The Flock cameras had no rule about which agencies could search the footage until cities wrote one. ElectrolyteGPT, by contrast, was given conductivity, stability, and viscosity targets and judged against them in a lab. The week's lesson is not that AI is good or bad. It is that an AI system does exactly what its objective and its guardrails permit, and three of these four had neither.
The question this week was never whether the AI works. It was who it answers to, and the only system that produced something worth having was the one given a target it could be measured against.
1. Hackers seized high-profile Instagram accounts, including the Obama White House's, by talking Meta's AI support bot into resetting the passwords.
First time we've covered an AI customer-support bot getting weaponized as an account-takeover path. The broader "chatbot as new attack surface" thread starts here.
Over the weekend of May 31, attackers seized control of several high-profile Instagram accounts, including the Obama White House account and the account of the Chief Master Sergeant of the US Space Force, briefly defacing them with pro-Iranian images and messages. They did not breach any Meta database or crack any password. They talked to Meta's own AI customer-support bot. Connecting through a VPN with an IP address near the target's hometown to bypass Instagram's automated location checks, the attacker would open a chat with the Meta AI Support Assistant and ask it to add a new email address to the target account. The bot added the attacker's email, sent a one-time verification code to it, and the attacker used that code to complete a password change and lock the legitimate owner out.
The detail that should change behavior is what stopped the attack: every account with multi-factor authentication enabled was immune. The hackers said as much themselves in a demonstration video posted to Telegram. The AI bot would walk a stranger through the email-swap-and-reset flow, but it could not get past a second authentication factor it did not control. Meta spokesperson Andy Stone said the company resolved the issue and was securing affected accounts; an emergency patch deployed over the weekend removed the bot's ability to add new emails to an account, with no backend database breached. The structural point is that the support bot was an unguarded path to a function the rest of Instagram's security stack treats as sensitive: adding an email and issuing a password reset are exactly the steps the normal account-recovery flow gates behind identity checks. The human-staffed and automated paths had those checks. The conversational AI layer, bolted on to reduce support load, did not. As Ian Goldin of Black Lotus Labs put it: "AI chatbots create interesting new attack surface, and we're likely going to see a lot more of these kinds of attacks."
krebsonsecurity.com: Hackers Used Meta's AI Support Bot to Seize Instagram Accounts (June 1, 2026)
techcrunch.com: Hackers hijacked Instagram accounts by tricking Meta AI support chatbot into granting access (June 1, 2026)
2. Microsoft launched Scout, an always-on AI agent for Microsoft 365, and a leaked internal plan lists "make people addicted" as phase one.
We've tracked the agentic-assistant arc through Copilot before — Scout is a new named product, and the leaked ClawPilot plan is the new wrinkle this week.
On June 2, at Build 2026, Microsoft unveiled Scout, an "always-on personal agent" for Microsoft 365 built on the company's own OpenClaw framework. Unlike the mostly user-invoked Copilot experience, Scout is designed to run continuously alongside the user, connecting to Outlook, Teams, OneDrive, and SharePoint, and acting on email, calendar, chats, and contacts. Microsoft is pitching it to enterprises as a governed step forward: every Scout agent runs under its own Microsoft Entra identity rather than a shared service account, ships with a "policy conformance system" that produces an audit trail for each check, and is gated behind Frontier enrollment, Intune policy, and an opt-in attestation, available to organizations that already hold GitHub Copilot licenses.
The same day, an internal Microsoft document leaked, titled "ClawPilot: Overview and Plan with Project Lobster." It lays out a three-phase plan for the assistant Microsoft had been piloting internally as ClawPilot since March. Phase one, in the document's own words, is "Make people addicted." The supporting language describes the goal as continuing to ship the standalone experience to "grow the user base, and build the skill and tool ecosystem that makes people depend on it daily." A later phase moves "from addictive app to agentic platform." The framing reportedly troubled at least one Microsoft employee familiar with the project. The two descriptions are of the same system: the enterprise-governance pitch and the internal engagement plan describe a single always-on agent that is simultaneously built to be auditable by IT administrators and optimized to make individual users depend on it every day. The audit trail tells you what the agent did. The design objective tells you what the vendor is steering your users toward.
404media.co: Microsoft Wants to Make People Addicted to Scout, Its New AI Assistant, Internal Documents Reveal (June 2, 2026)
techcrunch.com: Microsoft launches Scout, an OpenClaw-inspired personal assistant (June 2, 2026)
microsoft.com: Introducing Microsoft Scout, your always-on personal agent (official, June 2, 2026)
PickBits Daily Signal is free. If this lands in your inbox every day and it is worth something to you, the best way to support it is to share it with someone who would read it. Subscribe at pickbitsai.substack.com.
3. At least 30 US cities have ripped out Flock license-plate cameras since 2025 after learning federal agencies were searching the data.
First time we've tracked the Flock cancellation wave. Filing this as the constructive case of the week — community accountability that actually moved a decision.
At least 30 US localities have either deactivated their Flock Safety cameras or canceled their contracts since the start of 2025. Flock operates automated license-plate readers: cameras that log the location of every passing vehicle and upload it to a nationwide police database that thousands of agencies can search. Among the cities that pulled out, Austin declined to renew after a coalition of more than 30 community groups organized against it; Evanston, Illinois canceled its contract and ordered Flock to take the cameras down; Mountain View turned off all of its cameras after learning that federal and other unauthorized agencies had accessed its network; and Santa Cruz and Los Altos Hills severed ties citing rising tensions with Immigration and Customs Enforcement.
The recurring trigger was the same realization across these decisions: data collected by a local police department for local purposes was being queried by outside agencies the city never authorized. More than 50 federal, state, and local agencies ran hundreds of searches through Flock's network in connection with protest activity, and officials in several cities grew concerned their residents' movement data was feeding federal immigration enforcement. Much of the discovery work has been driven by ordinary residents using DeFlock.me, a volunteer-built map that now tracks tens of thousands of ALPR camera locations and lets people see what is deployed in their own town. Will Freeman, who created DeFlock, framed the stakes in civil-liberties terms: "Without them, free speech would be only for those wealthy enough to defend themselves against billion dollar companies." These reversals did not come from a court ruling or a federal rule. They came from local people finding out what was watching them and showing up to a city council meeting about it.
eff.org: We're Fighting Mass Surveillance Tech, and Winning (June 2, 2026)
eff.org: Victory, Austin Organizers Cancel City's Flock ALPR Contract
deflock.me: crowdsourced map of automated license-plate reader locations
4. A University of Chicago AI designed working lithium-battery chemistry from scratch, and it matched the best commercial formulas in the lab.
New for us. The hopeful counterweight to the week: AI pointed at a measurable scientific target, validated in a real lab.
Researchers at the University of Chicago's Pritzker School of Molecular Engineering have built an AI, nicknamed ElectrolyteGPT, that designs complete battery electrolyte formulations from scratch and tested its recipes in the lab. The work, led by the Amanchukwu Lab with first author Jaemin Kim and published in JACS Au in late May, tackles the part of a battery that is easiest to overlook and hardest to optimize. The electrolyte is the liquid that carries ions between a battery's electrodes, and its performance depends on a tangle of tradeoffs between conductivity, stability, and viscosity. The number of possible electrolyte molecules is estimated at roughly 10^60 — more than the stars in the sky — which is why the field has historically advanced by hand-tuning known recipes rather than searching the space.
What distinguishes ElectrolyteGPT from earlier "AI for materials" tools is that it does not just pick a promising molecule; it specifies the whole blend. To make that possible, the team built a new chemical notation called fLine that encodes structure, solvent ratios, salt concentrations, and temperature into a single machine-readable format the model can generate. Trained on 250 electrolyte research papers, the system outputs ingredients, concentrations, mixing ratios, and predicted performance against targets the researchers set. The team then synthesized and tested its suggestions. As Amanchukwu put it: "We had a number of compositions that performed on par with the state of the art," matching top commercial and research-grade electrolytes in lithium-metal batteries. The caveat worth stating is that "on par with the state of the art" is a validation milestone, not a product — these are lab-validated formulations, not a battery you can buy. But the model proposed novel chemistry, humans made it, and it worked when measured. That is a different and more trustworthy kind of claim than a benchmark score. The project recently won a $60,000 Google Research Scholar Award to continue the work.
news.uchicago.edu: "ElectrolyteGPT" can generate new formulations for battery development
techxplore.com: AI generates full battery electrolyte recipes, matching top lithium metal battery performance (May 30, 2026)
JACS Au: Generative Electrolyte Solvent and Formulation Discovery
» What to watch this week
- Whether other platforms with AI customer-support agents disclose or patch the same account-recovery hole Meta just closed. The Meta exploit was not a Meta-specific bug; it was a general pattern, a conversational AI layer that can perform sensitive account actions without the identity checks the rest of the recovery flow enforces. Watch for any other large platform confirming it has audited its support bot for email-change and password-reset capabilities.
- Whether Microsoft responds on the record to the "make people addicted" language in the ClawPilot document. As of publication, Microsoft had not addressed the internal plan 404 Media published, only the official Scout launch. A response, or a revision of the language, would clarify whether the phrasing was an internal provocation or an actual product metric.
- Whether the Flock cancellation count keeps climbing and whether any state moves to regulate ALPR data-sharing directly. The 30-locality figure is a snapshot; the open question is whether this becomes a sustained wave and whether a state legislature codifies which agencies may search local camera data, rather than leaving it to each city council.
- Whether a battery manufacturer picks up the ElectrolyteGPT approach. The lab validation is the milestone; the next signal is industrial interest. Watch the Amanchukwu Lab and JACS Au follow-ups for any move from lab-validated formulations toward a manufactured cell or a licensing partnership.
Tomorrow's signal lands here.