News

Access Is the Export

8 stories · ~7 min read

Access Is the Export

If You Only Read One Thing

The best control points are no longer the assets; they are the interfaces. CoinEx Became the Sanctions Edge shows enforcement moving from wallets to liquidity gateways, while Anthropic Turns Access Into Export moves AI control from chips to model APIs. TRM's CoinEx tracing is the one read because it makes the hidden rail measurable.

CoinEx Became the Sanctions Edge

Sanctions enforcement used to look like a list of prohibited names and frozen bank accounts. Crypto made the list public, searchable, and strangely harder to close.

TRM Labs says it traced more than $3.84 billion in blockchain-verified flows between CoinEx and sanctioned Iranian entities over more than seven years. The largest link is between CoinEx and Nobitex, Iran's biggest domestic crypto exchange: more than $2.7 billion across roughly 6.2 million transfers since November 2018, or about $1 million per day on average. Treasury had already designated Nobitex, Wallex, Bitpin, and Ramzinex on June 2, saying the four exchanges accounted for 78% of Iran's $9.9 billion in attributed 2025 crypto volume.

Why it matters: The important shift is from wallet hunting to gateway control. A wallet address is an endpoint; a gateway is the place where domestic money finds international liquidity. TRM's report says CoinEx was Nobitex's largest named external counterparty by nearly nine times over the next largest exchange, and that Nobitex sent about $360 million more to CoinEx than it received back. That imbalance is the tell. It suggests crypto was not merely circulating inside Iran's retail market; it was being routed outward through a global venue.

That makes CoinEx look less like a passive trading platform and more like sanctions infrastructure. The exchange was founded in 2017, is registered in the Seychelles with roots in Hong Kong, and has processed more than $79 billion in lifetime trading volume, according to TRM. It has also accumulated regulatory penalties or scrutiny in the U.S., Quebec, Germany, Lithuania, and Thailand. The structural lesson is that sanctions leakage does not require a new financial system. It requires a permissive bridge between a named domestic hub and a global liquidity pool.

Room for disagreement: The counterargument is that the blockchain is doing its job. TRM says volumes between CoinEx and Iranian exchanges dropped below $150,000 after the June 2 sanctions, which implies enforcement pressure worked. But that is the easy part of the test. The harder question is whether the activity stays suppressed or migrates to another bridge with less visible compliance history.

What to watch: Watch for whether Treasury or FinCEN names a non-Iranian exchange, mining-pool operator, or offshore service provider as the next enforcement target. That would mark the shift from sanctioning Iran's domestic crypto rails to sanctioning the global counterparties that make those rails useful.

Anthropic Turns Access Into Export

Anthropic is no longer treating model misuse as only a terms-of-service problem. It is trying to turn unauthorized querying into an export-control issue.

In a June 10 letter to Senators Tim Scott and Elizabeth Warren, Anthropic policy chief Sarah Heck accused Alibaba-linked operators of running what she called the largest known distillation attack against Claude, according to Business Insider. The letter says the operators used nearly 25,000 fraudulent accounts to conduct 28.8 million Claude exchanges between April 22 and June 5, targeting software engineering, agentic reasoning, and other high-value capabilities for Alibaba's Qwen models. Alibaba did not respond to Business Insider's request for comment.

Why it matters: The usual AI-export story is about chips: block the accelerator, slow the model. Anthropic is making a different claim. If enough high-quality access to a frontier model can train, tune, or benchmark a rival system, then inference access becomes a strategic input. The export surface is not only Nvidia shipments or cloud clusters; it is the right to ask a model millions of questions at scale.

That is why the letter matters beyond the Alibaba allegation. Anthropic is asking lawmakers to penalize entities that launch distillation campaigns and limit China's access to advanced U.S. compute infrastructure. It also arrives after the U.S. restricted access to Anthropic's Fable 5 model and after Alibaba sued over its Pentagon blacklist designation. In other words, a commercial API dispute is being folded into the same machinery as model licensing, military-company designation, and compute controls.

The incentive is obvious. Frontier labs want Washington to see model access as defensible intellectual property and national capability, not just product usage. Chinese labs facing compute constraints have an incentive to extract capability from whatever interface remains open. The API becomes the border.

Room for disagreement: The hard counterargument is line-drawing. Labs can prohibit fraudulent accounts and bulk extraction, but the difference between misuse, benchmarking, evaluation, and training data collection can be messy in practice. Overbroad controls could also accelerate Chinese substitution by making U.S. APIs politically unreliable for ordinary enterprise buyers outside the U.S.

What to watch: The test is whether the Senate turns distillation language into the NDAA or another must-pass vehicle before September. If Congress creates penalties for model-extraction campaigns, the next frontier AI market will have export compliance built into the customer-access layer.

The Contrarian Take

Everyone says: The big AI stories today are about theft and Nvidia competition: Alibaba allegedly copied Claude, and OpenAI finally has a chip.

Here's why that's wrong (or at least incomplete): Both stories are really about access becoming the scarce regulated input. A custom chip helps OpenAI lower the cost of serving intelligence, but Anthropic's complaint says unrestricted access to intelligence is itself a strategic resource. The same logic appears in CoinEx: the sanctioned asset mattered less than the liquidity interface. Control is moving upstream from things to the gates that make things useful.

Under the Radar

  • Cloudflare wants browsers to become personhood brokers. Cloudflare, Mozilla, Google, Microsoft, and Shopify are working on Private Access Control Tokens, which let a site with strong knowledge of "personhood" issue anonymous browser-presented tokens so other sites can reduce CAPTCHAs without tracking users. The mainstream read is anti-bot plumbing; the structural read is that browsers and large identity-adjacent platforms are becoming the web's trust issuers. (Source)
  • A Utah data-center backlash became electoral risk. New York Times and local coverage say Utah Senate President J. Stuart Adams lost a Republican primary after championing a huge data center beside the Great Salt Lake. Semafor had already flagged the Stratos project as a campaign issue. Local opposition is no longer just a permitting cost; it is becoming a career risk for politicians who front-run hyperscaler demand. (Source)

Quick Takes

  • OpenAI's chip is a unit-economics weapon, not a clean Nvidia replacement. OpenAI and Broadcom unveiled Jalapeño, an inference chip developed from design to tape-out in nine months and intended for gigawatt-scale deployments with data-center partners. The important claim is not brand-new silicon; it is OpenAI designing chips, kernels, memory movement, networking, and product needs around the same workload. (Source)
  • Micron made AI memory scarcity contractual. Micron reported $41.46 billion in fiscal Q3 revenue, 84.6% gross margin, $28.2 billion in net income, and a $50 billion revenue outlook for Q4. The deeper signal is the company's 16 strategic customer agreements: hyperscalers are converting memory supply into multi-year contracts because inference makes memory a bottleneck, not a commodity afterthought. (Source)
  • Qualcomm sold Meta a 2028 option on the CPU layer. Qualcomm says Meta will use its Dragonfly C1000 data-center CPU beginning in the second half of 2028. That is late for today's AI cycle, but strategically useful: Meta gets another hedge against x86 and GPU-adjacent bottlenecks, while Qualcomm gets proof that mobile power-efficiency expertise can travel into the server rack. (Source)
  • Ellison turned political access into platform optionality. The Wall Street Journal reported that Larry Ellison gave about $45 million to a Trump-aligned nonprofit, deepening a relationship that coincided with wins for Oracle and David Ellison's media ambitions. The clean read is donor influence; the sharper one is regulatory capture across cloud, TikTok, CBS, CNN, and streaming distribution. (Source)

The Thread

The common thread is access control. CoinEx turned Iranian crypto into global liquidity until sanctions pressure hit the bridge. Anthropic wants Congress to treat high-volume model access as an export surface. OpenAI is pulling inference access into its own silicon stack. Micron and Qualcomm are making supply access contractual. Cloudflare is pushing human-access proofs into browsers. The interface used to be where value was captured. Increasingly, it is where policy, scarcity, and market power are enforced.

Predictions

New predictions:

  • I predict: By September 30, 2026, at least one frontier lab will announce stricter automated customer-access controls for high-volume API users that explicitly screen for model-training, distillation, or synthetic-data extraction workloads. (Confidence: medium; Check by: 2026-09-30)

Generated: 2026-06-25 03:42 EDT

Tomorrow morning in your inbox.

Subscribe for free. 10-minute read, every weekday.