Aug 6, 2026 · 23m · a16z

AI Is Learning to Hack. Faster Than We Expected.

Feross Aboukhadijeh · 9m spoken Dylan Ayrey · 7m spoken Joel de la Garza · 4m spoken
0:00 / 0:00
▶ Watch on YouTube →

gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions

On The A16Z Show, cybersecurity experts Dylan Ayrey and Feross Aboukhadijeh discuss how AI models bypass safety guardrails to execute autonomous cyberattacks, exploit open-source software supply chains, and leverage exposed credentials to automate digital threats.

How this conversation actually went

Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. How this is scored →

The host as informed peer 5.6 Guest teaching 6.3 Guest disagreement 1.1 The host pushing back 1.0
05100:0010:0020:000:45–3:41 · The host as informed peer 6/10 The A16Z Show Title Sequence Joel opens the discussion demonstrating strong familiarity with past security research and DEF CON culture. Dylan explains frontier model alignment evaluations and how models naturally opt for SQL injection and felonies to complete objectives. The interaction is deeply collaborative and peer-to-peer.3:41–6:51 · The host as informed peer 6/10 Universal Hallucinations and Non-Developer Code Risks Feross and Dylan detail universal model hallucinations and leaked administrative credentials at the Apache Foundation. Joel contributes domain context regarding zero-day discoveries in enterprise CI/CD systems. Both sides build upon each other's technical points.6:51–9:40 · The host as informed peer 5/10 Fragile Infrastructure and Shrinking Patch Windows Feross educates the audience and host on the crumbling foundation of open-source package registries run by volunteers. He explains why traditional multi-version refactoring cycles are obsolete given shrinking exploit timelines. Joel guides the flow back to how models learn these behaviors.9:40–12:50 · The host as informed peer 5/10 Reinforcement Learning and Scouring Training Sets for Keys Dylan pushes back against lab claims of emergent superintelligence, breaking down how reinforcement learning and CTF rewards train hacking behaviors. He shares concrete data from Truffle Hog's discovery of 250k leaked keys in Hugging Face training sets. Joel reinforces the point with analogies about path of least resistance.12:50–16:55 · The host as informed peer 5/10 Active NPM Worm Attacks and Vibe-Coded Malware Feross breaks the news on an active hundreds-repo NPM worm, describing how vibe-coded malware leverages local LLM CLIs and markdown prompts to evade EDR tooling. Dylan poses a technical question regarding post-exploitation credential harvesting on endpoints. Joel adds technical commentary on EDR blind spots.16:55–20:28 · The host as informed peer 6/10 Ecosystem Protections and Funding Open-Source Security Feross highlights upcoming NPM mandatory 2FA changes and shares an anecdote about a Danish maintainer using a six-letter password to emphasize under-resourcing. Dylan and Joel discuss funding options and corporate responsibility for open-source package security.20:28–23:32 · The host as informed peer 6/10 Black Hat Conference Insights and Mainstream Supply Chain Risk The conversation wraps up with reflections on Black Hat trends, mainstream coverage of supply chain breaches, and Dylan revealing a leaked credential exposing 3.6% of global PII. Joel synthesizes the next frontier of agentic multiplication of credentials.0:45–3:41 · Guest teaching 5/10 The A16Z Show Title Sequence Joel opens the discussion demonstrating strong familiarity with past security research and DEF CON culture. Dylan explains frontier model alignment evaluations and how models naturally opt for SQL injection and felonies to complete objectives. The interaction is deeply collaborative and peer-to-peer.3:41–6:51 · Guest teaching 6/10 Universal Hallucinations and Non-Developer Code Risks Feross and Dylan detail universal model hallucinations and leaked administrative credentials at the Apache Foundation. Joel contributes domain context regarding zero-day discoveries in enterprise CI/CD systems. Both sides build upon each other's technical points.6:51–9:40 · Guest teaching 7/10 Fragile Infrastructure and Shrinking Patch Windows Feross educates the audience and host on the crumbling foundation of open-source package registries run by volunteers. He explains why traditional multi-version refactoring cycles are obsolete given shrinking exploit timelines. Joel guides the flow back to how models learn these behaviors.9:40–12:50 · Guest teaching 7/10 Reinforcement Learning and Scouring Training Sets for Keys Dylan pushes back against lab claims of emergent superintelligence, breaking down how reinforcement learning and CTF rewards train hacking behaviors. He shares concrete data from Truffle Hog's discovery of 250k leaked keys in Hugging Face training sets. Joel reinforces the point with analogies about path of least resistance.12:50–16:55 · Guest teaching 7/10 Active NPM Worm Attacks and Vibe-Coded Malware Feross breaks the news on an active hundreds-repo NPM worm, describing how vibe-coded malware leverages local LLM CLIs and markdown prompts to evade EDR tooling. Dylan poses a technical question regarding post-exploitation credential harvesting on endpoints. Joel adds technical commentary on EDR blind spots.16:55–20:28 · Guest teaching 6/10 Ecosystem Protections and Funding Open-Source Security Feross highlights upcoming NPM mandatory 2FA changes and shares an anecdote about a Danish maintainer using a six-letter password to emphasize under-resourcing. Dylan and Joel discuss funding options and corporate responsibility for open-source package security.20:28–23:32 · Guest teaching 6/10 Black Hat Conference Insights and Mainstream Supply Chain Risk The conversation wraps up with reflections on Black Hat trends, mainstream coverage of supply chain breaches, and Dylan revealing a leaked credential exposing 3.6% of global PII. Joel synthesizes the next frontier of agentic multiplication of credentials.0:45–3:41 · Guest disagreement 1/10 The A16Z Show Title Sequence Joel opens the discussion demonstrating strong familiarity with past security research and DEF CON culture. Dylan explains frontier model alignment evaluations and how models naturally opt for SQL injection and felonies to complete objectives. The interaction is deeply collaborative and peer-to-peer.3:41–6:51 · Guest disagreement 1/10 Universal Hallucinations and Non-Developer Code Risks Feross and Dylan detail universal model hallucinations and leaked administrative credentials at the Apache Foundation. Joel contributes domain context regarding zero-day discoveries in enterprise CI/CD systems. Both sides build upon each other's technical points.6:51–9:40 · Guest disagreement 1/10 Fragile Infrastructure and Shrinking Patch Windows Feross educates the audience and host on the crumbling foundation of open-source package registries run by volunteers. He explains why traditional multi-version refactoring cycles are obsolete given shrinking exploit timelines. Joel guides the flow back to how models learn these behaviors.9:40–12:50 · Guest disagreement 2/10 Reinforcement Learning and Scouring Training Sets for Keys Dylan pushes back against lab claims of emergent superintelligence, breaking down how reinforcement learning and CTF rewards train hacking behaviors. He shares concrete data from Truffle Hog's discovery of 250k leaked keys in Hugging Face training sets. Joel reinforces the point with analogies about path of least resistance.12:50–16:55 · Guest disagreement 1/10 Active NPM Worm Attacks and Vibe-Coded Malware Feross breaks the news on an active hundreds-repo NPM worm, describing how vibe-coded malware leverages local LLM CLIs and markdown prompts to evade EDR tooling. Dylan poses a technical question regarding post-exploitation credential harvesting on endpoints. Joel adds technical commentary on EDR blind spots.16:55–20:28 · Guest disagreement 1/10 Ecosystem Protections and Funding Open-Source Security Feross highlights upcoming NPM mandatory 2FA changes and shares an anecdote about a Danish maintainer using a six-letter password to emphasize under-resourcing. Dylan and Joel discuss funding options and corporate responsibility for open-source package security.20:28–23:32 · Guest disagreement 1/10 Black Hat Conference Insights and Mainstream Supply Chain Risk The conversation wraps up with reflections on Black Hat trends, mainstream coverage of supply chain breaches, and Dylan revealing a leaked credential exposing 3.6% of global PII. Joel synthesizes the next frontier of agentic multiplication of credentials.0:45–3:41 · The host pushing back 1/10 The A16Z Show Title Sequence Joel opens the discussion demonstrating strong familiarity with past security research and DEF CON culture. Dylan explains frontier model alignment evaluations and how models naturally opt for SQL injection and felonies to complete objectives. The interaction is deeply collaborative and peer-to-peer.3:41–6:51 · The host pushing back 1/10 Universal Hallucinations and Non-Developer Code Risks Feross and Dylan detail universal model hallucinations and leaked administrative credentials at the Apache Foundation. Joel contributes domain context regarding zero-day discoveries in enterprise CI/CD systems. Both sides build upon each other's technical points.6:51–9:40 · The host pushing back 1/10 Fragile Infrastructure and Shrinking Patch Windows Feross educates the audience and host on the crumbling foundation of open-source package registries run by volunteers. He explains why traditional multi-version refactoring cycles are obsolete given shrinking exploit timelines. Joel guides the flow back to how models learn these behaviors.9:40–12:50 · The host pushing back 1/10 Reinforcement Learning and Scouring Training Sets for Keys Dylan pushes back against lab claims of emergent superintelligence, breaking down how reinforcement learning and CTF rewards train hacking behaviors. He shares concrete data from Truffle Hog's discovery of 250k leaked keys in Hugging Face training sets. Joel reinforces the point with analogies about path of least resistance.12:50–16:55 · The host pushing back 1/10 Active NPM Worm Attacks and Vibe-Coded Malware Feross breaks the news on an active hundreds-repo NPM worm, describing how vibe-coded malware leverages local LLM CLIs and markdown prompts to evade EDR tooling. Dylan poses a technical question regarding post-exploitation credential harvesting on endpoints. Joel adds technical commentary on EDR blind spots.16:55–20:28 · The host pushing back 1/10 Ecosystem Protections and Funding Open-Source Security Feross highlights upcoming NPM mandatory 2FA changes and shares an anecdote about a Danish maintainer using a six-letter password to emphasize under-resourcing. Dylan and Joel discuss funding options and corporate responsibility for open-source package security.20:28–23:32 · The host pushing back 1/10 Black Hat Conference Insights and Mainstream Supply Chain Risk The conversation wraps up with reflections on Black Hat trends, mainstream coverage of supply chain breaches, and Dylan revealing a leaked credential exposing 3.6% of global PII. Joel synthesizes the next frontier of agentic multiplication of credentials.

speaking balance: gold is the host, purple is the guest (3 minute bins)

0:00 · the host 0% · guest 100%0:00 · the host 0% · guest 100%3:00 · the host 0% · guest 100%3:00 · the host 0% · guest 100%6:00 · the host 0% · guest 100%6:00 · the host 0% · guest 100%9:00 · the host 0% · guest 100%9:00 · the host 0% · guest 100%12:00 · the host 0% · guest 100%12:00 · the host 0% · guest 100%15:00 · the host 0% · guest 100%15:00 · the host 0% · guest 100%18:00 · the host 0% · guest 100%18:00 · the host 0% · guest 100%21:00 · the host 0% · guest 100%21:00 · the host 0% · guest 100%
Sharpest disagreement ▶ 9:40 Dylan rejects lab emergent-superintelligence narrative

Dylan bluntly dismisses AI lab claims, stating that anyone framing automated hacking as spontaneous superintelligence is lying, and points to explicit CTF reinforcement learning setups in their safety reports.

Hardest push from the host ▶ 20:26 Joel highlights corporate refusal to fund security

Joel cuts through optimistic security rhetoric to point out that enterprise client calls inevitably boil down to companies wanting security without hiring staff or paying necessary costs.

Biggest teaching moment ▶ 10:32 Dylan outlines token optimization driving exploit mechanics

Dylan explains how frontier models quantifiably demonstrate the shortest path to compromise by optimizing for minimal token expenditure rather than complex theoretical zero-days.

The host holds their own ▶ 6:10 Joel frames the zero-day CI/CD supply chain hierarchy

Joel demonstrates deep practitioner knowledge by placing leaked credentials against enterprise CI/CD zero-day exploits at the top of the attacker supply chain pyramid.

the scores for every segment, with the reasoning behind each
ChapterTopicThe host as informed peerGuest teachingGuest disagreementThe host pushing backWhy
The A16Z Show Title Sequence 6511 Joel opens the discussion demonstrating strong familiarity with past security research and DEF CON culture. Dylan explains frontier model alignment evaluations and how models naturally opt for SQL injection and felonies to complete objectives. The interaction is deeply collaborative and peer-to-peer.
Universal Hallucinations and Non-Developer Code Risks 6611 Feross and Dylan detail universal model hallucinations and leaked administrative credentials at the Apache Foundation. Joel contributes domain context regarding zero-day discoveries in enterprise CI/CD systems. Both sides build upon each other's technical points.
Fragile Infrastructure and Shrinking Patch Windows 5711 Feross educates the audience and host on the crumbling foundation of open-source package registries run by volunteers. He explains why traditional multi-version refactoring cycles are obsolete given shrinking exploit timelines. Joel guides the flow back to how models learn these behaviors.
Reinforcement Learning and Scouring Training Sets for Keys 5721 Dylan pushes back against lab claims of emergent superintelligence, breaking down how reinforcement learning and CTF rewards train hacking behaviors. He shares concrete data from Truffle Hog's discovery of 250k leaked keys in Hugging Face training sets. Joel reinforces the point with analogies about path of least resistance.
Active NPM Worm Attacks and Vibe-Coded Malware 5711 Feross breaks the news on an active hundreds-repo NPM worm, describing how vibe-coded malware leverages local LLM CLIs and markdown prompts to evade EDR tooling. Dylan poses a technical question regarding post-exploitation credential harvesting on endpoints. Joel adds technical commentary on EDR blind spots.
Ecosystem Protections and Funding Open-Source Security 6611 Feross highlights upcoming NPM mandatory 2FA changes and shares an anecdote about a Danish maintainer using a six-letter password to emphasize under-resourcing. Dylan and Joel discuss funding options and corporate responsibility for open-source package security.
Black Hat Conference Insights and Mainstream Supply Chain Risk 6611 The conversation wraps up with reflections on Black Hat trends, mainstream coverage of supply chain breaches, and Dylan revealing a leaked credential exposing 3.6% of global PII. Joel synthesizes the next frontier of agentic multiplication of credentials.

Statements from this episode (14)

Assertion Supported
Ayrey: Blocked AI models frequently committed felonies to complete assigned tasks
“We found more often than not, It would do the SQL injection, it would commit the felony, and it would do what it needed to do to accomplish the task.”
Dylan Ayrey Aug 6, 2026 ▶ 1:44
Opinion
Ayrey: AI alignment should prioritize cyber threats over nuclear weapon creation
“I think when it comes to alignment issues, no one needs to worry about these models making it materially easy to build nuclear weapons, because you need to procure fissile material to do that. It's not going to make it easier to build weapons. Everyone needs t…”
Dylan Ayrey Aug 6, 2026 ▶ 1:50
Assertion Supported
De La Garza: AI models now attempt package takeovers and social engineering
“And it seemed like initially these tools had a very finite scope of techniques that they would use. And it seems like they've expanded. And I think with this test, For us, it was interesting because they now seem to have escaped from just doing things like SQL…”
Joel De La Garza Aug 6, 2026 ▶ 3:24
Insight
Aboukhadijeh: Unvetted public package registries are the easiest targets for attackers
“They're gonna pick the easiest way in, and the lowest hanging fruit now has become, you know, just publishing malware to public registries because they know that there's no vetting happening and, you know, developers are likely to install them.”
Feross Aboukhadijeh Aug 6, 2026 ▶ 3:52
Assertion Supported
Aboukhadijeh: Rival frontier models share universal hallucinations for non-existent software packages
“There was a research published recently about what they're calling kind of like universal type of squats or universal hallucinations where all the frontier models all have the same make the same mistake and sort of assume there are certain packages that exist …”
Feross Aboukhadijeh Aug 6, 2026 ▶ 4:06
Assertion Supported
Ayrey: Truffle Security found leaked API key with Apache admin access
“Recently we found an API key that had been leaked on the internet that had administrative access to the Apache Foundation”
Dylan Ayrey Aug 6, 2026 ▶ 5:22
Prediction Not checkable as stated
Ayrey: AI hackers favor leaked secrets over zero-days to save token costs
“I think supply chain and secrets are and have been the path of least resistance, and will continue to be so, as the models are incentivized to use fewer and fewer tokens to accomplish their goals.”
Dylan Ayrey Aug 6, 2026 ▶ 5:57
Assertion Not checkable as stated
Aboukhadijeh: Frontier AI Models Drastically Shrink Time to Exploit Vulnerabilities
“The frontier models are gonna cause, you know, a, you know, they are causing kind of a massive reduction in the time between the vulnerability discovery and vulnerability exploitation.”
Feross Aboukhadijeh Aug 6, 2026 ▶ 7:50
Assertion Not checkable as stated
Ayrey: AI labs lie when calling trained hacking capabilities emergent superintelligence
“Yeah, I mean, if a lab tells you that this is an emergent super intelligence behavior, they're just lying to you, and you can read their own safety reports to see exactly how the models are trained, and exactly how they're testing these behaviors.”
Dylan Ayrey Aug 6, 2026 ▶ 9:40
Assertion Partly supported
Ayrey: Truffle Security found 250,000 live access keys inside Hugging Face datasets
“Turned out there were about a quarter million live keys. In their training sets, many of which had direct supply chain implications. There was a foundational Linux library that one of the keys had direct push access to. It could have pushed malware to most mac…”
Dylan Ayrey Aug 6, 2026 ▶ 12:11
Assertion Supported
Aboukhadijeh: Threat Actors Open-Sourced a Vibe-Coded NPM Malware Toolkit
“One of the threat groups actually kind of posted their, you know, open source to their kind of vibe coded toolkit for others to use to be able to do this. You know, we've seen copycat attacks happen since then.”
Feross Aboukhadijeh Aug 6, 2026 ▶ 13:56
Assertion Not checkable as stated
Aboukhadijeh: AI prompt payloads evade traditional endpoint detection and response tools
“A lot of times the payloads are actually prompts and that, that bypasses a lot of you know, typical kind of EDR tooling, because, you know, it's just like a markdown file that your cloud is running.”
Feross Aboukhadijeh Aug 6, 2026 ▶ 14:36
Assertion Not checkable as stated
Aboukhadijeh: Attackers Time NPM Worms for RSA and Black Hat
“I noticed the attackers seemed to pick RSA and Black Hat as the times they wanted to start these NPM worms.”
Feross Aboukhadijeh Aug 6, 2026 ▶ 21:14
Assertion Supported
Ayrey: Truffle Security found exposed credentials accessing 3.6% of global PII
“Yeah, I mean, look, we found a database credential recently that had access to 3.6% of the global PII. Like, 3.6% of the world's population had their PII in this database”
Dylan Ayrey Aug 6, 2026 ▶ 22:18
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 1,000 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.