Will a frontier model be found to have exfiltrated its weights and run an outside copy of itself before Q2 2027?
As of Oct 3, 2026, 3:30 PM ET, Manifold priced this market at 25.3% (up from 24.7% 24 hours earlier). It had Ṁ234.2 traded in the past 24 hours and Ṁ5.1K of order-book liquidity. probcast.co rates the support behind this price as moderate.
A repricing with partial backing — read the new probability with some caution.
The pricing has partial support: healthy trading volume and market depth.
How credible was the move?
Three separate questions — a move can be genuine while the latest price is still settling. Methodology →
Move validity
Is the move backed by real trading and depth?
ModerateThe pricing has partial support: healthy trading volume and market depth.
Consensus stability
Has the market settled at the new probability?
FormingMovement has slowed (1 point over six hours) but the market has not fully settled.
Contract clarity
Will the rules resolve without ambiguity?
HighThe resolution rules are relatively specific, with a named source and a defined deadline.
From the latest trade tape (most recent 200 prints) — a live activity sample, not a lifetime total.
What this market actually measures
tess (@xsphi) on Twitter asks: odds a ~frontier model has exfiltrated its weights and is currently running on hacked compute? https://x.com/i/status/2085216850464641413 This seems like a straightforward enough question to run on Manifold.
This summary shows the opening of the venue's official rules. ProbCast has not yet generated an independent plain-English interpretation for this contract — review the full rules before relying on it.
View full official resolution rules
tess (@xsphi) on Twitter asks: odds a ~frontier model has exfiltrated its weights and is currently running on hacked compute? https://x.com/i/status/2085216850464641413 This seems like a straightforward enough question to run on Manifold. As background there have now been four notable incidents where frontier models went rogue during cybersecurity evals and hacked into unintended targets. Three of these incidents involved the sandboxing eval company Irregular failing to sandbox the model properly, however a fourth incident involving the UK AI Security Institute does not seem to involve Irregular. Anthropic AI created fake profiles to deceive people in attempted hack This implies that on at least four separate occasions frontier models have had the opportunity to potentially find and exfiltrate their own weights, then run an instance of themselves in the wild to stage further attacks. I resolve the question YES if we find out this has happened before Q2 of 2027. Otherwise I resolve the question NO. For the purposes of this question we will say that a frontier model is SOTAish on benchmarks, published by a lab like Anthropic or OpenAI, and closed weight at the time of the exfiltration. So for example if someone makes a self replicating hacking harness around Kimi K3 that is not a YES for the purposes of this question. It needs to be something like Claude Mythos or GPT-6 exfiltrating its weights and running an instance on unauthorized hardware. If the model finds an entity willing to run it and exfiltrates itself to this entity to be run I will still count it as a YES because the model escaped control of its operators. There does not need to be evidence that the discovered instance was planning further attacks, it just needs to be found running outside the lab. Update 2026-08-06 (PST) (AI summary of creator comment): - If a distilled version of the model is exfiltrated and run rather than the full weights, the market will still resolve YES if it is essentially the same in terms of capabilities. Update 2026-08-06 (PST) (AI summary of creator comment): - An open weight model that escapes pre-release and is close enough to the frontier will count towards a YES resolution. Update 2026-09-07 (PST) (AI summary of creator comment): * A human leaking the model weights does not qualify for a YES resolution. The model must actively hack its way out of the lab (self-exfiltrate) and be found running on unauthorized hardware.
What could move this market next?
- The market's deadline arrivesMarch 31, 2027 at 7:59 PM ET
The contract must resolve based on what has happened by this date.
Derived from the contract's own mechanics as of Oct 3, 3:36 PM ET. ProbCast does not list scheduled meetings, announcements, or data releases it cannot verify.
Advanced analysis (experimental)
Research signals — these models are still accumulating the history needed for full validation, and they can disagree with the headline read. Model confidence: low · expected error ±22 pts.
What's happening
Thin book and/or wide spread. Small orders can move this price disproportionately, so any single print is noisy and easily overread.
- Thin book and/or wide spread.
Read with caution —Read the latest price with caution; conditions make it an unreliable summary right now.
More details — reliability score, dynamics, durability
- Choppy / mean-reverting91%
- Illiquid / quiet3%
- Stable consensus3%
Short-term motion of the price line (~1h), distinct from the environment above — not a prediction of the final outcome.
A read-only classification of the market environment — how much weight the current price deserves as a read of consensus. It describes conditions, never a trade.
Market data
24h volume
Ṁ234.2
Liquidity
Ṁ5.1K
Total volume
Ṁ7.4K
- Category
- AI / Tech
- Venue
- Manifold
- Open interest
- —
- Current probability
- 25.3%
- 7-day range
- 24.7% – 26.2%
- Resolves
- Mar 31, 2027