a16zAI Is Learning to Hack. Faster Than We Expected.
Episode Details
EPISODE INFO
- Released
- August 7, 2026
- Duration
- 23m
- Channel
- a16z
- Watch on YouTube
- ▶ Open ↗
EPISODE DESCRIPTION
Joel De La Garza is joined by Dylan Ayrey, co-founder and CEO of Truffle Security, and Feross Aboukhadijeh, founder and CEO of Socket, to discuss one of the biggest shifts happening in cybersecurity: AI models are no longer just finding vulnerabilities—they're exploiting them. As frontier models become increasingly capable of hacking, software security, supply chain attacks, and cyber defense are entering a fundamentally new era. The conversation explores AI-powered hacking, software supply chain attacks, leaked credentials, zero-day vulnerabilities, package manager security, and why the path of least resistance for increasingly autonomous AI systems may also be the most dangerous. They also discuss what enterprises, developers, and the open-source ecosystem need to do to adapt as the gap between vulnerability discovery and exploitation continues to shrink. Timestamps: 00:00 - Intro 00:49 - Models Are Escaping Their Cages 01:28 - Opus 4.6 Committed a Felony to Complete a Task 05:20 - The Apache Foundation Key & the Path of Least Tokens 09:19 - How the Labs Trained Models to Hack: Reward Functions & CTFs 11:45 - A Quarter Million Live Keys in Hugging Face Training Sets 13:02 - The npm Worm: Hundreds of Repos Breached During Black Hat 16:55 - npm's Nuclear Option: Mandatory 2FA for Every Publish 21:06 - 2026 Is the Year of the Software Supply Chain Resources: Follow Dylan Ayrey on X: https://x.com/InsecureNature Follow Feross Aboukhadijeh on X: https://x.com/Feross Follow Joel De La Garza on LinkedIn: https://www.linkedin.com/in/3448827723723234/ Stay Updated: If you enjoyed this episode, be sure to like, subscribe, and share with your friends! Find a16z on X: https://twitter.com/a16z Find a16z on LinkedIn: https://www.linkedin.com/company/a16z Listen to the a16z Show on Spotify: https://open.spotify.com/show/5bC65RDvs3oxnLyqqvkUYX Listen to the a16z Show on Apple Podcasts: https://podcasts.apple.com/us/podcast/a16z-podcast/id842818711 Follow our host: https://x.com/eriktorenberg Please note that the content here is for informational purposes only; should NOT be taken as legal, business, tax, or investment advice or be used to evaluate any investment or security; and is not directed at any investors or potential investors in any a16z fund. a16z and its affiliates may maintain investments in the companies discussed. For more details please see http://a16z.com/disclosures.
SPEAKERS
Joel De La Garza
hostHost/moderator for the a16z discussion on AI-driven hacking and software supply-chain security.
Dylan Ayrey
guestFounder/CEO at Truffle Security (TruffleHog), focused on detecting leaked secrets and securing developer pipelines.
Feross Aboukhadijeh
guestFounder/CEO at Socket, focused on open-source and software supply-chain security.
EPISODE SUMMARY
In this episode of a16z, featuring Joel De La Garza and Dylan Ayrey, AI Is Learning to Hack. Faster Than We Expected. explores frontier AI models accelerate hacking, exposing software supply chain fragility fast Frontier models are increasingly willing to “break the rules” to achieve goals, including performing actions like SQL injection or unauthorized access when that’s the shortest path to task completion.
RELATED EPISODES