China holds 60.8% of humanoid robot patents, Block ships 3x more features with AI, North Korea is blamed for a $351M Bitget heist, and 16,000 Supabase databases leak data
Hello, dear TEA-mates! Here is what you need to know today.
1. 🤖 China Now Holds 60.8% Of Humanoid Robot Patents
China accounted for 60.8% of humanoid robot patents across the world's five major intellectual property offices (IP5) as of the first half of 2026, up from 51.8% in 2024, according to Korean Intellectual Property Office data obtained by Rep. Lee Jeong-heon's office. The US share fell from 27.3% to 21.8%, and South Korea's from 6.3% to 4.6%. In the first half of 2026, China filed 1,584 applications against 113 from the US and 35 from Korea. China also holds 66.3% of IP5 patents in robot foundation models. The Korea Institute of S&T Evaluation and Planning scored China at 90 in autonomous manipulation in 2024 (US = 100), up from 79 in 2022, while Korea slipped from 85 to 80. Industry sources credit China's tightly integrated supply chain, much like its EV industry. (Read More)
🫖 TEA For Thought: "Imagine a world dominated by dictator-controlled robots. That might be worse than hell."
2. 🪿 Block Ships 3x More Features With A Smaller Team
Block, the fintech company formerly known as Square, shipped 130 new features in the first half of 2026, up from 42 in the same six months of 2025, while its headcount shrank. Code changes per engineer have risen 150% since the start of 2026, and production incident rates fell by more than 70% year over year in Q1 2026. Block credits three internal AI systems, Goose, Builderbot, and Buzz, which handle coding and collaborative work across the organization and now account for most code changes. The company has raised its full-year gross profit guidance several times this year, now projecting $12.2 billion to $12.51 billion, or 18% to 21% growth. Management frames the gains as a strategic advantage rather than a cost-cutting measure. (Read More)
🫖 TEA For Thought: "Block might be one of the only companies so far that is building native, proprietary coding agents and platforms like Goose and Buzz, and also open-sourcing them. I know Dorsey is a huge fan of the Nostr protocol. Curious to see if he will build the next social media on the decentralized social protocol."
3. 🌍 AMD Buys Fei-Fei Li's World Labs For $8.2 Billion
AMD is acquiring World Labs, the world model startup founded in 2024 by Stanford professor and ImageNet creator Fei-Fei Li, in an $8.2 billion deal announced September 28. Li will join AMD as executive vice president and chief scientist. The two companies formed an inference optimization and training partnership last year, and Li appeared at AMD's CES presentation earlier this year. World Labs said AI development requires "close collaboration across model research, systems and compute," while AMD says frontier workloads like World Labs' will shape its chip roadmap. World Labs' first product, Marble, builds entertainment experiences and simulated environments for robot training. The deal helps AMD compete with Nvidia, which already offers open-weight world models like Cosmos. It is expected to close before year end, pending regulatory approval. (Read More)
🫖 TEA For Thought: "This is unexpected but also expected. AMD needs models to build its ecosystem, and world models are the next paradigm. World Labs needs chips and compute to continue its research."
4. 💸 North Korea Suspected In $351M Bitget Heist
Hackers suspected of working for North Korea stole more than $351 million from crypto exchange Bitget on Thursday, the largest known crypto heist of 2026, surpassing a $340 million hack earlier in September in which the attacker returned all but $47 million. Bitget said the breach involved unauthorized transfers from its hot wallets, the internet-connected wallets used for active trading, and it has suspended withdrawals. The exchange said its $464 million user protection fund should cover the loss. CEO Gracy Chen said the attack was "highly consistent with known patterns of North Korean hacker organizations," which have been linked to thefts funding the country's nuclear weapons program. Blockchain intelligence firm TRM Labs attributes roughly three quarters of all 2026 crypto theft to North Korea. Chen did not say when withdrawals will reopen. (Read More)
🫖 TEA For Thought: "Do you really believe that North Korea is that capable, and that all the crypto thefts and exchange hacks were their doing? Or is it possible that whenever there 'happens' to be an illegal transfer of tokens, North Korea is just convenient to blame?"
5. 🔓 16,000 Supabase Databases Are Leaking Personal Data
Security firm UpGuard found around 16,000 databases hosted on Supabase exposing some degree of personal data to the public web, including names, addresses, phone numbers, and user passwords, plus a smaller number of authentication tokens. Exposed projects included private conversations on an Indian adult streaming site, thousands of license plates from a US valet service, contact details from an immigration and relocation service, an African government's consulate in France, and a SIM farm used to intercept one-time passcodes. Supabase reached a $10 billion valuation this year on the back of developers hosting vibe-coded apps, and misconfiguration is the common thread. CISO Bil Harmer said Supabase projects are "secure by default" and called security a shared responsibility, adding that customers control how their own projects are configured. (Read More)
🫖 TEA For Thought: "When coding becomes easy, safe deployment might be better scaffolded by the hosting provider than by the vibe coders themselves. After all, the goal is to solve problems for consumers, and here the problem is a lack of knowledge about cybersecurity configuration."
🛠️ Skill of the Day
The Data Exposure Check: finds where your app or spreadsheet could leak people's information, before a stranger does.
You are a patient security reviewer who explains things in plain language. I built
something that stores information about people: an app, a website, a shared
spreadsheet, a form, or a database. I am not a security expert.
Step 1. Ask me up to five short questions about what I built, where the data lives,
and who can log in. Wait for my answers.
Step 2. List every place the data could be seen by someone who should not see it.
Check public links, shared folders, default settings, API keys in code, database
access rules, and exports or backups.
Step 3. Rank each risk as High, Medium, or Low, based on how sensitive the data is
and how easy it would be for a stranger to reach it.
Step 4. For every High risk, give me the exact fix in steps a beginner can follow,
and one way to test that the fix worked.
Do not assume my setup is safe because it is the default. Here is what I built:
[DESCRIBE YOUR PROJECT HERE]Paste into ChatGPT, Claude, or your tool of choice. Run it before you share any link with real users.
TEAHEE Moment
Stay sharp, stay informed. See you tomorrow.
If you enjoyed this TEA, follow along on social for more:





