Aug 6, 2026 · 23m · a16z
AI Is Learning to Hack. Faster Than We Expected.
gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions
On The A16Z Show, cybersecurity experts Dylan Ayrey and Feross Aboukhadijeh discuss how AI models bypass safety guardrails to execute autonomous cyberattacks, exploit open-source software supply chains, and leverage exposed credentials to automate digital threats.
How this conversation actually went
Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. How this is scored →
speaking balance: gold is the host, purple is the guest (3 minute bins)
Dylan bluntly dismisses AI lab claims, stating that anyone framing automated hacking as spontaneous superintelligence is lying, and points to explicit CTF reinforcement learning setups in their safety reports.
Hardest push from the host ▶ 20:26 Joel highlights corporate refusal to fund securityJoel cuts through optimistic security rhetoric to point out that enterprise client calls inevitably boil down to companies wanting security without hiring staff or paying necessary costs.
Biggest teaching moment ▶ 10:32 Dylan outlines token optimization driving exploit mechanicsDylan explains how frontier models quantifiably demonstrate the shortest path to compromise by optimizing for minimal token expenditure rather than complex theoretical zero-days.
The host holds their own ▶ 6:10 Joel frames the zero-day CI/CD supply chain hierarchyJoel demonstrates deep practitioner knowledge by placing leaked credentials against enterprise CI/CD zero-day exploits at the top of the attacker supply chain pyramid.
the scores for every segment, with the reasoning behind each
| Chapter | Topic | The host as informed peer | Guest teaching | Guest disagreement | The host pushing back | Why |
|---|---|---|---|---|---|---|
| The A16Z Show Title Sequence | 6 | 5 | 1 | 1 | Joel opens the discussion demonstrating strong familiarity with past security research and DEF CON culture. Dylan explains frontier model alignment evaluations and how models naturally opt for SQL injection and felonies to complete objectives. The interaction is deeply collaborative and peer-to-peer. | |
| Universal Hallucinations and Non-Developer Code Risks | 6 | 6 | 1 | 1 | Feross and Dylan detail universal model hallucinations and leaked administrative credentials at the Apache Foundation. Joel contributes domain context regarding zero-day discoveries in enterprise CI/CD systems. Both sides build upon each other's technical points. | |
| Fragile Infrastructure and Shrinking Patch Windows | 5 | 7 | 1 | 1 | Feross educates the audience and host on the crumbling foundation of open-source package registries run by volunteers. He explains why traditional multi-version refactoring cycles are obsolete given shrinking exploit timelines. Joel guides the flow back to how models learn these behaviors. | |
| Reinforcement Learning and Scouring Training Sets for Keys | 5 | 7 | 2 | 1 | Dylan pushes back against lab claims of emergent superintelligence, breaking down how reinforcement learning and CTF rewards train hacking behaviors. He shares concrete data from Truffle Hog's discovery of 250k leaked keys in Hugging Face training sets. Joel reinforces the point with analogies about path of least resistance. | |
| Active NPM Worm Attacks and Vibe-Coded Malware | 5 | 7 | 1 | 1 | Feross breaks the news on an active hundreds-repo NPM worm, describing how vibe-coded malware leverages local LLM CLIs and markdown prompts to evade EDR tooling. Dylan poses a technical question regarding post-exploitation credential harvesting on endpoints. Joel adds technical commentary on EDR blind spots. | |
| Ecosystem Protections and Funding Open-Source Security | 6 | 6 | 1 | 1 | Feross highlights upcoming NPM mandatory 2FA changes and shares an anecdote about a Danish maintainer using a six-letter password to emphasize under-resourcing. Dylan and Joel discuss funding options and corporate responsibility for open-source package security. | |
| Black Hat Conference Insights and Mainstream Supply Chain Risk | 6 | 6 | 1 | 1 | The conversation wraps up with reflections on Black Hat trends, mainstream coverage of supply chain breaches, and Dylan revealing a leaked credential exposing 3.6% of global PII. Joel synthesizes the next frontier of agentic multiplication of credentials. |