Contrary to popular belief, Anthropic’s hiring of a Google TPU lead is not about chip performance—it’s about control over the compute supply chain.
I don’t trust claims of impenetrable security when the infrastructure is a black box. The news that Anthropic recruited Amir Salek, the architect behind Google’s first seven TPU generations, is being framed as a strategic move to reduce dependency on NVIDIA and cloud vendors. But from my vantage point as a DeFi security auditor who has seen protocols collapse under the weight of centralized dependencies, this signals something far more concerning: the concentration of AI compute into the hands of a few labs, which will eventually trickle down into the crypto ecosystems that rely on that compute.

Let me be clear: Anthropic is not just building a chip. It is building a vertically integrated fortress. The company already sources from NVIDIA, Google, and Amazon. Now it wants its own silicon—likely a custom ASIC for training and inference tailored to Claude’s model architecture. This is reminiscent of the early days of DeFi when projects built proprietary oracles instead of using Chainlink. The result? Single points of failure, opaque upgrade mechanisms, and hidden vulnerabilities.
Context: The Compute Race in Web3
Web3’s AI narrative—think autonomous agents, decentralized compute marketplaces, and on-chain inference—depends on access to affordable, verifiable hardware. Projects like Akash, Render, and Bittensor build on the assumption that compute is a commodity. But if Anthropic, OpenAI, and Google start locking down their own chips, the cost of entry for decentralized alternatives skyrockets. The infrastructure becomes a gated community.
From my audits of yield aggregators and cross-chain bridges, I’ve learned that the most dangerous attacks are not flash loans but subtle privilege escalations. A custom chip with a closed-source microcode is the ultimate privilege escalation. It can’t be audited by the community. It can’t be forked. And if Anthropic decides to embed a kill switch—say, to comply with a future regulation—the entire Claude ecosystem, including any dApps that rely on it, becomes hostage.
Core: The Technical Blind Spots
Let’s dissect the architecture. Salek’s TPU experience is no joke. He oversaw massive scale-out interconnects, power-efficient matrix multiplication, and custom memory hierarchies. But TPUs are designed for Google’s internal workloads. Anthropic’s Claude models have different inference patterns, especially for long-context and multi-modal tasks.
My concern is not whether the chip works—it likely will. The concern is what happens to the rest of the industry. Every time a major AI lab builds its own silicon, the open-source and decentralized compute stacks lose another piece of the puzzle. We saw this with GPU scarcity during the NFT boom. Now imagine a world where the best inference hardware is only available to Anthropic, OpenAI, and Google. Decentralized AI becomes a second-class citizen.
Signature: “Code doesn’t lie. The chip microcode does.”
From my experience auditing smart contracts, I’ve learned to trust the code, not the whitepaper. But when the code is a physical chip with no public specification, trust is impossible. The only way to verify that a chip is not doing something malicious—like leaking data through a side-channel or prioritizing certain models over others—is through extensive testing and reverse engineering. Most Web3 projects don’t have the resources for that.

Contrarian: The Illusion of Decentralization
The contrarian take here is that Anthropic’s chip move could actually increase security for its own users, but decrease it for the broader ecosystem. Internal chips allow for more granular control: isolation of sensitive workloads, hardware-level access control, and optimized power profiles. For enterprises handling healthcare or finance, that’s a plus. But the network effect of AI is that the best models attract the most users. If Anthropic’s chip gives Claude a 10x cost advantage, then every crypto project that wants to integrate AI will naturally gravitate toward Anthropic’s walled garden.
This is the same trap that killed many DeFi platforms: they built on hype and short-term incentives, only to realize that the underlying infrastructure was controlled by a few gatekeepers. The Terra collapse was not just about algorithmic stablecoins—it was about the assumption that the market would always provide liquidity. Similarly, the assumption that compute will always be available and affordable is dangerous.
Signature: “Audits are opinions. Hacks are facts.”
Anthropic’s chip project is not yet a hack, but it’s an opinion that compute control is acceptable. The fact is that any centralized compute layer creates a single point of failure. Look at what happened when AWS went down in 2021—a huge chunk of the internet went dark. Now imagine if Anthropic’s chip factory has a fire, or if a trade war disrupts TSMC’s supply. The entire AI layer of Web3 could crumble.
Takeaway: A Call for Verifiable Infrastructure
The trend is clear: AI companies are becoming compute companies. For the crypto ecosystem, the only sustainable response is to demand verifiable, open hardware. Zero-knowledge proofs can verify that a computation was performed correctly, but they cannot verify that the chip itself didn’t leak your private data. That requires hardware-level attestation, side-channel resistance, and open-source RTL code.
Projects like Arbitrum and Optimism have shown that Layer 2 scaling can be transparent. Why can’t AI chips be the same? Until then, every protocol that integrates AI should treat the underlying compute as a third-party risk. Run adversarial simulations. Assume the chip vendor is malicious. And never, ever trust claims of impenetrable security.
Signature: “If you can’t audit it, you don’t own it.”
Anthropic’s move is a wake-up call. The AI-Web3 convergence is inevitable, but it must be built on decentralized, auditable hardware. Otherwise, we’re just trading one set of gatekeepers for another.