The math is simple: $100 billion, two years, one competitor’s hardware. Meta wants to rent its surplus compute to Anthropic, the very team it competes with in the model wars. This isn’t a partnership. It’s a data leak waiting to happen.
Hook
Three sources close to the negotiations confirm what was first reported by The New York Times: Meta is in advanced talks to lease compute worth $100 billion to Anthropic over two years. The immediate narrative is a win-win—Meta monetizes its tanking infrastructure spend, and Anthropic gets the hardware it needs to scale Claude. But in the cold logic of a security audit, this deal is a catastrophic trust failure. The core question isn’t about revenue; it’s about asset isolation. When your model weights run on the same hardware as your competitor’s, the line between ‘tenant’ and ‘landlord’ becomes a single vulnerability away from exploitation.

Context
Meta has admitted overinvestment in data centers, with a 2025 AI budget of $145 billion—double the previous year. Zuckerberg himself said the spending hasn’t yet “borne fruit” and that external companies are willing to pay a premium for access. Meanwhile, Anthropic is on a $1.2 trillion valuation trajectory, targeting an IPO. It already has a $45 billion compute deal with SpaceX, but the Claude Code launch has spiked inference costs. The need for more capacity is existential.
The market, as usual, cheers. They see Metal becoming a “compute landlord”; they see Anthropic locking in supply. But they ignore the metadata problem. From my audit experience, every physical infrastructure handover creates attack surfaces. The 0x protocol vulnerability I discovered in 2018 wasn’t a logic error; it was a state mismatch between different systems. Here, the mismatch is between business incentives and security boundaries.
Core: The Systemic Teardown
Let’s break this down like a smart contract audit. We are analyzing a trustless environment: two competitors with opposite incentives. Meta’s success depends on its own Llama models; Anthropic’s success depends on Claude. Any data leakage or hardware-level tampering could tilt the competitive balance.
1. The Trust Variable
Trust is a variable you must solve. In this deal, Meta becomes the hardware oracle. All of Anthropic’s user queries, prompt data, and model weights will pass through Meta’s physical machines. Even with “hardware-level isolation,” the risk is structural. During my NFT metadata centralization exposure in 2021, I proved that 98% of BAYC visual traits were stored on centralized servers. The lesson: centralization hides in plain sight metadata. Here, the metadata is not images; it has inference patterns. Meta can see which sectors Anthropic is scaling, which types of prompts are most frequent, and potentially the computational fingerprint of new model features.
2. The Prompt Injection Vector
In my 2026 audit of an AI-agent integrated DeFi protocol, I found a critical prompt injection vulnerability where adversarial inputs could manipulate the agent’s trading logic. Now imagine Anthropic’s Claude running on Meta’s infrastructure. If Meta inserts a subtle latency shift or a packet-level modification, does it change the model’s behavior? This isn’t paranoia; it’s a gray-box threat model. The security community has long known that inference hardware can be coaxed into leaking weights through side-channel attacks. A $100 billion lease worth of compute provides a very tempting playground for such attacks.
3. The Lock-in Paradox
Anthropic gets flexibility with monthly payments and exit clauses. But the data gravity is real. Once the training data, inference pipelines, and optimization libraries are tied to Meta’s custom network topologies (InfiniBand + specific GPU clusters—likely B200), the cost of migrating becomes prohibitive. This is compute vendor lock-in. The contract’s “flexibility” is a facade; the technical lock-in is the real chain.
4. Financial Fragility
Liquidity is a mirror reflecting greed. Anthropic’s monthly compute cost hits $416 million from this deal alone. Combined with the SpaceX contract ($1.25 billion/month), the annual compute cost approaches $20 billion. Against that $1.2 trillion valuation, the ratio is high. If the AI market cools or if a new model emerges with 10x lower compute requirements, Anthropic is left holding a sunk cost contract. Meta, on the other hand, will have already booked the revenue. The asymmetry of risk is glaring.

Contrarian: What the Bulls Got Right
But I must give credit where it’s due. The bulls are not entirely wrong. Meta needs this deal. The $145 billion spend is a hemorrhage without a new revenue line. This deal turns a cost center into a profit center. It also prevents Anthropic from signing an exclusive deal with Microsoft or Google, which would be a much bigger strategic threat. By renting to Anthropic, Meta effectively subsidizes the development of a competitor while collecting the rent on the land. It’s a classic hedge.

Also, the mathematical model of compute-demand is real. Anthropic’s Claude Code has exploded in popularity; the raw demand for inference is not going down. The contract provides price certainty for two years. In a volatile token market, fixed compute costs are a form of collateral.
However, the bulls ignore the entropy of security. They see a contract; I see a surface area. They see revenue; I see a trust minimization failure.
Takeaway
Volatility exposes the architecture of fear. This deal is not about technical efficiency; it’s about capital efficiency at the expense of security efficiency. For the average AI company, this sends a chilling signal: the path to scaling is now locked behind the hardware of your biggest competitors. The next time a startup needs compute, it will have to ask Microsoft, Google, or Meta for permission—and pay for the privilege. The decentralization of AI compute is a promise, not a feature; the reality is that the largest players will own the hammers.
For investors: treat the deal as a binary option on trust. If Anthropic can maintain a perfect security perimeter, the deal is a stable income stream for Meta. If one leak happens—a single weight leak, a model behavior drift—the reputational damage will collapse both. The house always wins, but only if the walls don’t bleed.
Logic does not bleed; only code fails. And here, the code is not just the smart contract; it is the entire physical infrastructure. Auditors, start your engines.