Monday, August 31, 2026 Trend Press · Cloudflare Pages

The Trend Tribune

"All the trends that are fit to read" Morning Edition Free of Charge
TODAY'S LEAD STORY

The basis for claiming "a quarter of the world's GDP"—Anthropic's philosophical assertion of market size for investors.

This analysis examines Anthropic's strategy, revealed in news reports around August 25th, to claim a total addressable market (TAM) of $30 trillion for IPO investors. It covers the calculation method, which surpasses SpaceX's $28.5 trillion; the difference from traditional TAMs based on "all the work that AI can theoretically complete"; the scale comparison of being 12 times the combined sales of S&P 1500 tech companies; the discrepancy of less than 1% from the actual 2028 earnings forecast of $190-200 billion; Professor Aswath Damodaran's skeptical assessment; and the practical function of TAM claims in justifying valuations, all from a researcher's perspective.

The basis for claiming "a quarter of the world's GDP"—Anthropic's philosophical assertion of market size for investors.
(Photo: illustrative)

The Basis for Claiming "A Quarter of Global GDP"—Anthropic's Philosophical Claim of Market Size to Investors

Multiple reports have revealed that Anthropic is expected to explain to investors in its IPO (Initial Public Offering) briefing that its Total Addressable Market (TAM) exceeds $30 trillion. This would make it one of the largest TAM claims in IPO history, surpassing the $28.5 trillion figure presented by SpaceX, which went public in June. As a journalist with a background in AI research, I want to carefully examine the logic behind this enormous figure and what it signifies.

What Does the TAM Metric Measure?

First, let's clarify the nature of the TAM metric itself. TAM is a metric that shows the potential annual revenue that a product or service would theoretically achieve if it gained 100% market share. It does not represent a company's current sales, but rather is used as a means of discussing future potential to impress investors with the immense opportunity that lies before them.

Anthropic's methodology is distinctive in its calculation. According to reports, the company calculates TAM (Total Addressable Market) based on the entire scope of work that can theoretically be completed by AI models. This differs significantly from traditional TAM calculation methods that aggregate the market size of specific industries or software categories. Rather, it's based on a more ambitious idea of ​​viewing "all human cognitive labor" as a potential market.

Verifying the Scale of "12 Times the S&P 1500"

Let's verify the magnitude of this number through a concrete comparison. According to FactSet data cited by The Wall Street Journal, the total revenue of the 191 technology companies included in the S&P 1500 index was approximately $2.4 trillion last year. Anthropic's claimed figure of $30 trillion is more than 12 times the total revenue of the entire US technology sector.

In a broader context, this figure surpasses China's entire GDP, nearly rivals the US GDP, and represents approximately a quarter of the world's total GDP (around $120 trillion). For a single company to claim market opportunities of this magnitude is unprecedented in the history of corporate IPOs.

A Large "Gap" to Actual Earnings

On the other hand, there is a significant gap between this enormous TAM and Anthropic's actual financial performance. The company's second-quarter sales reportedly exceeded $11.5 billion, a phenomenal 14.6-fold increase year-on-year. Annualized Revenue (ARR) reached $65 billion as of July.

The company's 2028 earnings forecast for investors is approximately $190 billion to $200 billion. Even if the upper end of this forecast is achieved, it would still represent less than 1% of the company's claimed $30 trillion TAM. In other words, this enormous TAM figure does not suggest that Anthropic will acquire the majority of it in the near future; rather, it is merely an abstract indicator showing a "theoretical upper limit."

Skeptical Views from Experts

Financial experts have long expressed skepticism towards this type of massive TAM claim. Aswath Damodaran, a finance professor at NYU Stern School of Finance, commented on SpaceX's slightly smaller TAM claim of $28.5 trillion, stating that "TAM calculation in the age of AI has reached the limits of plausibility and is being pushed beyond them."

This criticism likely applies equally to Anthropic's even larger figure of $30 trillion. The TAM metric is essentially a tool for persuading investors in an IPO pitch deck, and there is considerable discretion in its calculation methodology.

The Practical Function of "Numerical Claims"

Apart from the debate surrounding the validity of these figures, we should also consider the practical role that the TAM claim itself plays. Such massive TAMs are not merely figures to attract investors; they simultaneously serve multiple functions: justifying the company's valuation, justifying the scale of infrastructure investment commensurate with that valuation, guiding product development priorities, and establishing a competitive framework.

As Reuters' analysis points out, the $30 trillion figure may be better understood not merely as a future prediction, but as a kind of statement of "what kind of business Anthropic sees itself as." It's an ambitious self-perception that goes beyond the framework of providing software, encompassing human labor itself.

What Researchers Should Consider

The debate surrounding this TAM claim leads to the larger question of how the valuations of AI companies are justified. The question of how investors will strike a balance between valuations based on verifiable metrics such as actual revenue and profits, and valuations based on the highly interpretable metric of "theoretical potential market," will be a recurring theme in the upcoming rush of AI company IPOs.

With Anthropic's prospectus (S-1) expected to be officially released within the next few weeks, it remains to be seen how this $30 trillion figure will be presented in the actual disclosure documents, and to what extent it will be explained. Furthermore, it will be crucial to closely monitor how seriously the market takes this claim.

AnthropicIPOTAMファイナンスAI投資

NVIDIA temporarily suspends its credit system for AI clouds, after only two months of criticism over "circular finance."

This article analyzes the circumstances surrounding NVIDIA's partial suspension of its "AI Compute Partnership" financing program, introduced in July, as reported by the Wall Street Journal on August 27. It provides an accounting analysis of the backlash caused by the revenue-sharing structure in which NVIDIA receives 50% of the amount exceeding the standard fee, the restrictions on cloud providers such as limiting the program to approved customers, antitrust concerns from within the company, Michael Burry's criticism that it was a "Wall Street spectacle," and the overall picture of the massive financial strategy that runs parallel to the mobilization of $500 billion in third-party capital and the $105 billion guarantee for OpenAI.

NVIDIA Temporarily Suspends AI Cloud Credit Mechanism After Criticism of "Circular Finance" Just Two Months

On August 27th, The Wall Street Journal reported that NVIDIA had temporarily suspended some of its new lending programs for AI cloud companies. This program, introduced in July, was forced to be reviewed in less than two months due to antitrust concerns. As an accountant, I would like to clarify the structure of this mechanism and the issues it raises.

The Credit Mechanism of "AI Compute Partnership"

First, let's examine the details of this program. This mechanism, called "AI Compute Partnership," aimed to provide funding support to relatively small AI cloud operators who needed to purchase large quantities of NVIDIA GPUs.

The specific mechanism is as follows: NVIDIA sets a standard hourly rate with the cloud operator. Then, if the operator is unable to sell the computing power of the purchased GPUs to other companies, NVIDIA provides a kind of "buyback guarantee," leasing the surplus. This guarantee makes it easier for cloud providers to secure more favorable terms when borrowing funds from financial institutions to purchase GPUs.

Furthermore, NVIDIA's revenue opportunities were structured in two ways. In addition to revenue from the sale of the GPUs themselves, a revenue-sharing mechanism was incorporated, where NVIDIA received 50% of the revenue earned by cloud providers above the standard fee.

Internal Warnings Regarding Antitrust Concerns

Reports indicate that the direct reason for the program's suspension was concerns raised within NVIDIA. Some employees reportedly informed existing and potential customers of concerns that the program could be subject to antitrust scrutiny. A particular concern was the extent to which NVIDIA could intervene in and control the business operations of its customer companies.

According to reports, in the initial stages of the program, NVIDIA required cloud providers to limit GPU lending to "approved customers," and also wanted to distribute computing power to as many small and medium-sized AI companies as possible. This type of control, extending even to the selection of downstream trading partners, is said to have displeased some potential partner companies.

The Broader Criticism of "Circular Financing"

This temporary suspension occurs within a broader context of criticism. Prominent investor Michael Burry (the subject of the film "The Big Short") described NVIDIA's AI-related financing practices this month as a "Wall Street stunt."

"Circular financing" is a critical term referring to a structure where a company provides funds to customers who purchase its products, and these customers then use those funds to purchase the company's products again, effectively creating a complete cycle of cash flow. An NVIDIA spokesperson countered this criticism by stating that the company's risks remain low. As justification, they cited the high liquidity of their assets, arguing that their computing resources (hardware) can always be redeployed to other customers.

The Big Picture of Massive Funding Mobilization, Including $50 Billion

The mechanism that has been temporarily suspended is only one part of a larger funding support strategy that NVIDIA has been building. This month, the company has already coordinated efforts to mobilize over $500 billion in third-party infrastructure capital from major US financial institutions such as Apollo Global Management, BlackRock, Blackstone, Brookfield Asset Management, Goldman Sachs, and KKR. Furthermore, it recently announced a guarantee of up to $105 billion for OpenAI to lease large-scale data centers.

In short, the "AI Compute Partnership" that has been temporarily suspended is just one of several different financial mechanisms that NVIDIA has been building, and as NVIDIA itself explains, this suspension does not represent a setback in its overall funding strategy.

What Accountants Should Consider

This temporary suspension demonstrates that the financial mechanisms supporting the rapid growth of the AI ​​industry are still in the trial-and-error stage. When a company with overwhelming market dominance, like NVIDIA, is in a position to not only fund its client companies but also influence their business operations, antitrust risks become a serious concern.

From an accounting and investment perspective, the key issue is the difficulty in accurately grasping the actual scale of this type of "cyclical" or "interdependent" financial structure accumulating on the balance sheets of the entire AI industry. While NVIDIA itself claims the risks are low, the extent to which independent regulators and investors can scrutinize the full picture of this complex financial arrangement will remain a crucial issue for the future governance of the AI ​​industry. We will be closely watching how this program is redesigned or integrated into a different framework in the future.

NVIDIA独占禁止法AIインフラファイナンス循環金融

"Simply being within Bluetooth range allows someone to hijack the robot"—a vulnerability in the $20,000 Unitree G1 that could be infected by worms.

This article explains the "UniBLEed" vulnerability (CVE-2026-76639/76640) disclosed on August 27th by security researcher Olivier Laflame. It provides a technical explanation of the BLE attack chain starting from the GATT characteristic 0xFFE2, which does not require pairing; AES key leakage due to the lack of ownership checks in the cloud API "/device/bindExtData"; the physical risk of root execution via bashrunner through path traversal via chat_go; the possibility of worm-like spread between multiple G1 devices; and the $6,700 bounty payment on August 6th and the uncertain release of a patch.

"Robots Can Be Taken Over Simply by Being Within Bluetooth Range"—A Vulnerable Vulnerability in the $20,000 Unitree G1

On August 27th, security researcher Olivier Laflame revealed details of a serious vulnerability in Unitree's humanoid robot, the G1 EDU. This series of vulnerabilities, dubbed "UniBLEed," allows attackers to completely take over the robot's control computer with root privileges simply by being within Bluetooth Low Energy (BLE, a type of short-range wireless communication standard) range, without prior authentication or pairing. As a software engineer, I want to carefully examine the technical chain of this vulnerability and its implications.

A Three-Month Investigation Reveals an Attack Chain Across Multiple Components

Laflame spent approximately three months investigating the G1 and discovered an attack vector that chains across multiple different components: Bluetooth, Unitree's cloud infrastructure, the mobile app, and the robot's firmware. Two different CVE numbers, CVE-2026-76639 and CVE-2026-76640, have been assigned to this vulnerability.

The technical starting point is the GATT characteristic "0xFFE2" (a unit of data exchange used in BLE communication). This characteristic is designed to accept only basic "write" permissions, allowing nearby devices to initiate communication with the robot without the authentication process normally required for Bluetooth pairing.

A critical design flaw: "Lack of ownership check" in the cloud API

Further problems, following this initial access, lay within Unitree's cloud infrastructure. The robot, in response to a plaintext "bootstrap command," returns its unique AES-128 encryption key in RSA encrypted form. This RSA encryption itself should normally protect the contents of the key.

However, according to Mr. Lafram's investigation, an API endpoint called "/device/bindExtData" on the Unitree cloud had the capability to decrypt this encrypted key, and moreover, it did not verify whether the Unitree account calling the API was actually the owner of the robot. In other words, anyone with a free Unitree account could obtain the AES encryption key of a G1 robot owned by someone else in plain text form.

Another Root Access Route via "Chatbot"

Another attack route, CVE-2026-76639, is via the AI ​​chat function "chat_go" installed on the G1. By exploiting a path traversal (a vulnerability that allows unauthorized writing of files to directories that should not be accessible) in the knowledge base upload process of this function, it was possible to send malicious files to a directory trusted by the "bashrunner" service.

The bashrunner was designed to process files in this directory based on shell execution rules that did not consider file extensions, resulting in the files being executed with root privileges.

The Severity of the "Locomotion PC" Being Hijacked

This vulnerability is particularly serious because the targeted "Locomotion PC (Locomotion PC)" is a core component of the G1. This computer runs on a Linux kernel that requires real-time performance and manages fundamental robot functions such as motors, cameras, audio output, and speech recognition with root privileges.

In other words, if this vulnerability is exploited, an attacker could potentially manipulate the robot's movements at will. For humanoid robots operating in industrial applications, this is a risk that directly impacts physical security, going beyond mere data leakage.

The Most Dangerous Feature: "Worm-like Ability"

Researchers are particularly alarmed by the fact that this Bluetooth-based attack chain is "worm-like." A compromised G1 robot could automatically propagate the same attack to other G1 robots within Bluetooth range.

Lafram states that in actual testing, this propagation test was limited to two G1 robots in a single room. However, theoretically, in environments such as factories or research facilities where multiple G1 robots are located in the same space, a compromise in one robot could potentially lead to a chain reaction to other robots.

Unitree's Response and Remaining Uncertainty

Unitree has already addressed some aspects of this vulnerability. In July, they implemented a "cloud-side account robot ownership binding check" and fixed the "cloud oracle" vulnerability discovered in May. On August 6th, a bug bounty of $6,700 ($4,000 for BLE RCE and $1,000 for chat_go RCE) was paid.

However, Laflam points out that there is no information available in the guidance published by Unitree regarding a confirmed release version of the patched firmware. While the current cloud-based attack vector requires either an account linked to the target robot or already obtained key information, the lack of a clear timeline for a fix for G1 EDU users leaves a practical frustration.

What Software Engineers Should Consider

The discovery of UniBLEed demonstrates that humanoid robots, a relatively new product category, suffer from the classic problem of weak security design, similar to, or even more so than, traditional IoT devices. Individual issues such as the omission of Bluetooth communication authentication, the lack of ownership verification in the cloud API, and inadequate extension checking during shell execution are by no means novel vulnerability patterns.

However, the combination of these factors, which resulted in a third party being able to seize control of a physically operating robot simply by being nearby, highlights once again how crucial such basic security design is in robotics products where hardware and software are closely intertwined. We will continue to monitor the release date of the finalized fix patch and the scope of its impact on other related products (Go2, B2, R1, etc.).

Unitreeヒューマノイドサイバーセキュリティ脆弱性Bluetooth
Advertisement300 × 250