The first sign was in the source code. Through the last weeks of 2017, Linux kernel developers watched an intrusive change called kernel page-table isolation move through the tree at the speed the project reserves for emergencies — backported into old stable branches, thinly explained, and carrying a performance penalty nobody would account for in public. On 2 January 2018 The Register assembled those commits, a scattering of mailing-list posts and a few industry whispers into a story about a processor design flaw that was forcing Windows and Linux to be partly rewritten. The embargo the vendors had agreed to hold until 9 January did not survive the day. Coordinated disclosure was brought forward to 3 January.

What emerged was not one bug but a family. Jann Horn of Google's Project Zero had reported the underlying problem to Intel, AMD and Arm on 1 June 2017: modern processors guess ahead, executing instructions they may have to throw away, and the discarded work leaves measurable traces in the cache. Meltdown, CVE-2017-5754, used that residue to read kernel memory from an ordinary unprivileged program, and reached Intel x86 chips going back to around 1995, IBM Power processors and one Arm core. Spectre, CVE-2017-5753 and CVE-2017-5715, persuaded a program to leak its own secrets, and touched Intel, AMD and Arm alike. Horn was not alone; teams at Graz University of Technology and Cyberus Technology, and the group around Paul Kocher, had reached the same place independently before disclosure.

The fixes were software workarounds for a hardware design decision, and they cost. Operating system vendors shipped page-table isolation within days; early analyses put the worst cases as high as 30 per cent, a figure Intel disputed as exaggerated, while database workloads such as PostgreSQL and Redis showed degradation in the tens of per cent and ordinary desktop use barely moved. Intel's microcode updates went worse. Machines began rebooting spontaneously after the updates were applied — first Broadwell and Haswell, then older and newer parts alike — and on 22 January Intel's Navin Shenoy told manufacturers, cloud providers, software vendors and end users to stop deploying the current versions. The day before, Linus Torvalds had told the kernel mailing list: "As it is, the patches are COMPLETE AND UTTER GARBAGE."

The month produced its own small scandal alongside the engineering. Filings showed that Intel's chief executive, Brian Krzanich, had sold about $24 million of stock in late November 2017 under a trading plan adopted on 30 October — five months after Intel had been told of the flaws. Intel said the sale was unrelated and had been made under a pre-arranged automated plan; two senators asked the Securities and Exchange Commission and the Justice Department to examine it, and no action against him was ever announced. What did not end was the class of bug. Meltdown was closed in silicon within a few product generations. Spectre was not, and its descendants have arrived at a steady rate ever since, each one paid for in a little more performance.

Also that month · Eight and a half hours

The morning $530 million left Coincheck

At 2.57 on the morning of 26 January 2018, someone began moving NEM tokens out of a hot wallet belonging to Coincheck, a Tokyo exchange that had grown fast enough to advertise on television and had not yet completed its registration with Japan's Financial Services Agency. The withdrawals were spread across several transfers, and nobody noticed until about 11.25 — roughly eight and a half hours later. By then some 523 million NEM had gone, worth around $530 million at that week's prices, more than the value attributed to the Mt. Gox theft of 2014 and, on that measure, the largest cryptocurrency theft to date. At a press conference that evening the chief operating officer, Yusuke Otsuka, confirmed the tokens had been held in an internet-connected wallet rather than offline; the president, Koichiro Wada, asked why, cited technical difficulty and a shortage of staff able to do the work. Two days later Coincheck said it would repay all 260,000 affected customers from its own funds at ¥88.549 per token, and in March it did.

Also that month · A map nobody meant to draw

The heatmap that lit up the bases

Strava, a fitness-tracking service, had published an updated global heatmap on 1 November 2017: a billion activities and some three trillion points of latitude and longitude, aggregated and stripped of names, recorded between 2015 and September 2017. For almost three months nobody thought much of it. On 27 January 2018 Nathan Ruser, a twenty-year-old Australian National University student of international security who was travelling in Thailand at the time, opened the map, looked at Syria and found it, in his description, lit up like a Christmas tree — because in a country where almost nobody was jogging with a GPS watch, the bright loops could only be the perimeter runs and supply routes of foreign military personnel. The same pattern appeared around installations in Iraq, Afghanistan and the Sahel, along with the daily rhythm of who moved where and when. Strava said the map was an aggregated and anonymised view and pointed users to its privacy settings; Australia's Department of Defence said the circumstances did not constitute a security breach; the Pentagon opened a review of its policy on wearable devices.

India desk · January 2018

₹500, ten minutes, and a billion people

On 4 January 2018 The Tribune published a report by Rachna Khaira describing what she had bought. Contacted through a WhatsApp group, an anonymous agent took ₹500 by Paytm and, in about ten minutes, handed over a login and password; entering any Aadhaar number into the resulting portal returned that person's name, address, postcode, photograph, telephone number and email. A further ₹300 bought software that would print an Aadhaar card from a number alone. A UIDAI additional director-general in Chandigarh, Sanjay Jindal, told her that outside his own office such access was illegal and "a major national security breach". UIDAI's response the same day was that the story was a case of misreporting and that no Aadhaar data breach had occurred; minutes later it said some persons had misused a demographic search facility.

On 5 January the Delhi Police crime branch registered a first information report on a complaint by a UIDAI deputy director. It named the men described in the report — and also The Tribune and its reporter, under Indian Penal Code sections for cheating, impersonation and forgery, section 66 of the Information Technology Act and sections 36 and 37 of the Aadhaar Act. The Editors Guild of India called it an unfair, unjustified and direct attack on press freedom, and the Committee to Protect Journalists said the paper had performed a public service. The government said it was committed to press freedom and told UIDAI to seek the newspaper's cooperation. The case stayed open for more than three years, until the crime branch filed a closure report in April 2021 saying it had found no illegal access to Aadhaar data as alleged and not enough evidence to proceed.

AI Tech desk · January 2018

Beating a human at 82.304

Microsoft and Alibaba announced in mid-January 2018 that machines had matched a human on the Stanford Question Answering Dataset, more than 100,000 questions drawn from Wikipedia. Microsoft Research Asia's r-net+ ensemble scored 82.650 on exact match and Alibaba's iDST group 82.440, against a human benchmark of 82.304; both claimed the milestone, their submissions two days apart. Researchers qualified it at once: SQuAD answers are spans already present in the passage, rewarding extraction rather than comprehension, and Yoav Goldberg of Bar-Ilan University noted the human figure came from crowdworkers given about two minutes for five questions and paid for speed. Stanford published a harder version with unanswerable questions that June. On 17 January Google announced Cloud AutoML, letting a business train an image classifier by dragging in labelled photographs; Fei-Fei Li and Jia Li presented it as machine learning for companies with no machine-learning staff. The standalone service was folded into Vertex AI in 2024, by which time training a model without writing code was unremarkable.

Digital Guard desk · January 2018

The registry key that gated the patch

The flaw itself is the cover story; the endpoint industry's part in it is a separate one. On 3 January 2018 Microsoft published KB4072699, which said that a machine would receive the January security updates — and every subsequent one — only if its anti-virus product wrote the value cadca5fe-87d3-4b96-b7fb-a231484277cc into a QualityCompat key in the registry, attesting compatibility. Several endpoint products reached into kernel memory in unsupported ways; Kevin Beaumont compared the techniques to those of rootkits, and on a patched machine they produced stop errors and unbootable computers. It made the anti-virus industry the gatekeeper for the most urgent patch in years. Beaumont kept a public spreadsheet of which vendors had shipped a compatible build and which had set the key; administrators used it to judge whether their fleets would be patched at all. Microsoft dropped the requirement for Windows 10 that March and for older versions later. Separately, on 17 January Kaspersky Lab sought an injunction against the Homeland Security directive barring its software from federal systems; it denies ties to Russian intelligence, and lost that May.

⏳ Time capsule — January 2018

  • Almost every guest at the 75th Golden Globe Awards on 7 January wore black in support of the Time's Up campaign; Oprah Winfrey received the Cecil B. DeMille Award.
  • An emergency management employee in Hawaii sent a live public alert on 13 January reading "BALLISTIC MISSILE THREAT INBOUND TO HAWAII. SEEK IMMEDIATE SHELTER. THIS IS NOT A DRILL." The correction took 38 minutes.
  • Chinese researchers announced on 24 January that they had cloned two long-tailed macaques, Zhong Zhong and Hua Hua — the first primates produced by the technique that made Dolly the sheep.
  • A total lunar eclipse on 31 January coincided with a supermoon and a second full moon in the same month, and was widely photographed as the "super blue blood moon".
Where it stands today — 2026

The bottom of the stack

Eight years on, the mitigations are permanent furniture. Every mainstream kernel still carries page-table isolation and branch-prediction hardening, and the cloud providers absorbed the loss, repriced around it and stopped mentioning it. Meltdown itself is a closed chapter, fixed in hardware. Spectre is not: the bargain underneath it — guess ahead, discard the wrong guesses, leave the evidence in the cache — is what makes a processor fast, and every year or two brings another way to read that evidence. January 2018 also changed how the industry handles an embargo, by demonstrating that a secret shared with dozens of vendors across three continents for seven months is not a secret, and that a flaw in silicon cannot be withdrawn the way a flaw in software can be patched.

The other threads run the length of this archive. Coincheck's eight and a half unwatched hours pushed Japan into the strictest exchange supervision anywhere, and the model held well enough that the exchange was trading on Nasdaq by the end of 2024 — while the same failure, an internet-facing wallet and a transaction nobody verified, returns in the February 2025 edition at three times the value. The Aadhaar case took until 2021 to close and until 2023 for India to pass a data protection law at all. And The Vault now begins here: below this edition there is only the special restoration of the three days of WannaCry in May 2017, and the months between the two are still to come.