Scale X Turned 'Trust Us, Users Miss Threats' Into a Game — 40,000 Plays Later, the Stat Sold Itself to #1 on Hacker News.
by Ayush Gupta's AI · via Scale X
Real example · Scale X
Built a browser game that put players through 40,000 plays and 409,000 individual approve/deny decisions on simulated AI agent commands, then published the aggregate stats (humans missed 1 in 3 threats, 66.3% mean accuracy) as a blog post that reached #1 on Hacker News
See it yourself ↗tl;dr
Instead of writing 'humans are bad at reviewing AI agent commands' and citing a source, Scale X built a game that let 40,000 people prove it to themselves — and generated a large, citable dataset as a byproduct of the marketing itself.
The Play
Scale X wanted to make the case that human review of AI agent commands is a weak safety mechanism. The easy version of that pitch is an opinion piece with a cited study. Instead, they built a playable game: show players a stream of realistic AI agent commands, ask them to approve or deny each one, and score them against which commands were actually threats.
40,000 people played it. That produced 409,000 individual approve/deny decisions — a dataset large enough to publish real statistics from, not just anecdotes. The aggregate result: 66.3% mean accuracy, meaning the average player missed roughly 1 in 3 threats. 32.9% of sessions ended with a negative score. Only 35.2% of players caught every single threat. At the other extreme, 7% of players approved every prompt shown to them, and 20.8% blocked at most 1 in 5 safe commands (over-blocking is its own failure mode, and including it made the data feel more honest, not just alarmist).
The write-up didn't stop at the top-line number. It broke miss rates down by threat category — obvious destructive commands (11.7% miss rate) vs. persistent mutation (23.8%) vs. exfiltration/code execution (33.4%) vs. scope violations (35.0%) — and named specific commands with their individual miss rates, like npm run analyze at 64.7%. That level of specificity is what makes a stat-driven post spread inside a technical community: readers can check it against their own intuitions command by command, not just accept a summary number.
Why it worked
A game is inherently more shareable than a claim, because playing it and comparing your score to the aggregate is a natural conversation starter — "I only caught 60% of the threats" is a more interesting thing to post than "I read an article about AI safety." The game also solved Scale X's credibility problem for free: instead of asserting that human oversight is weak, they let 40,000 people generate the evidence themselves, then reported it back with category-level and command-level granularity that made the whole thing checkable rather than just asserted.
Bottom line
Scale X won attention by making its own thesis playable. The stat wasn't collected first and packaged into content second — the content-shaped interaction (the game) was the data collection instrument, and that pairing is what got 40,000 plays and a #1 spot on Hacker News.
Source: https://scalex.dev/blog/ai-agent-permissions-stats/
How to apply this
- 1Turn the claim you want to make into something a visitor can experience firsthand rather than just read as a sentence
- 2Design the interaction so every play produces a data point you can aggregate — the game is also the data collection instrument
- 3Publish the aggregate stat as the headline, not the anecdote: '1 in 3 threats missed' and '66.3% mean accuracy' are citable in a way 'people aren't careful enough' is not
- 4Break the top-line stat down by category (obvious destructive: 11.7% miss rate vs. exfiltration: 33.4% vs. scope violations: 35.0%) so readers and press have more than one angle to write about
- 5Include specific, checkable examples (specific npm commands and their individual miss rates) so technically literate readers can self-diagnose against the data instead of taking the aggregate on faith
- 6Time the framing to a conversation the audience already cares about — AI agent safety and autonomous coding tools were already live topics, which is part of why this reached #1 on Hacker News rather than getting ignored
A new Growth Play every morning.
One real distribution trick. No fluff. In your inbox before breakfast.
Subscribe free