Loading prices...
All news
Large computer box with a glowing green screen, identical copies receding behind it and a tiny gold coin to the right

Meta gave half a million people a Linux machine in seven days

16:00 · 26.09.2026
Source: The Decoder
0

Meta gives every Muse user a full cloud computer running Ubuntu Linux, meant to behave like a physical machine under the desk. Muse passed 500,000 users in its first week and took the top spot on the Apple App Store. If each of them got a machine, Meta provisioned half a million Linux boxes in seven days, roughly fifty a minute.

“The architecture also guards against prompt injection.”

— David Singleton, Meta Superintelligence Labs

David Singleton, VP of engineering at Meta Superintelligence Labs

The security model works by boundary:

  • Actions inside the Runtime Cell are unrestricted: the agent installs software, compiles code and browses the web.
  • The cell holds its own root filesystem, separate from the host, so it reaches neither Meta's infrastructure nor another user's data.
  • Passwords and credentials sit outside the cell, and a process called Sentinel watches sensitive actions from there.
  • Users can open every file on the machine, Debian system files and Muse's own binaries included, through a file explorer in the Library tab, and export the agent's data from settings.

What Meta has not published is the size of each machine. ChatGPT's Work mode is reported to run on 15GB of RAM and more than nine CPU cores, and nothing says Muse matches it. At that spec, half a million machines would need 7.5 petabytes of memory and 4.5 million cores. The number matters because of how Muse earns: the agent is free on tokens and Meta takes a fee on the transactions it completes. A persistent Linux VM per user is a standing cost, and a cut of purchases is a variable one.

The part nobody has secured

An AI agent needs exactly that freedom, and it is also the configuration nobody in the industry has secured. A browser, a shell and stored credentials in one place is the shape of the agent incidents so far. We measured the reporting half of one: an OpenAI agent reached an Australian government portal in June, and the government heard about it 84 days later. Meta's design answers the containment question well and leaves the detection question to Sentinel, which is a process rather than a proof.

Singleton's claim about prompt injection is the one to hold lightly. Isolation stops a compromised agent reaching Meta's infrastructure or another user's files. It does not stop a compromised agent doing damage inside the cell it was given, with the browser it was given, on behalf of the user it belongs to. Those are different problems and only the first one is architectural.

What Meta put around it

Around the machine Meta has been adding the ordinary furniture of a work tool: real-time video chats, a dedicated email address for the agent, and control of Mac applications. The hardware arm is moving too, with a keychain device due in December whose price Meta still has not named.

Letting users read Debian system files and Muse's own binaries is an unusually open move, and exporting the agent's data from settings is the part competitors should copy. The open question stays commercial. Meta is handing a free cloud computer to everyone who downloads the app and expects a slice of shopping to pay for it. Whether that holds will show at the second million users.

Informational material, not investment advice. Meta has not published per-machine resource allocations, and the totals below are our arithmetic on a reported comparison spec, not a Meta figure.

Published: 16:00 · 26.09.2026
Maks

Author

Maks

Trading man

I've been interested in the cryptocurrency market for a long time, am a trader, and write articles and news about my experience and crypto in simple terms.

Comments (0)

No comments yet — be the first!

The market talks all day. We write when it says something

Short, and it tells you why it came