Twitter/X

Dylan Ayrey (Truffle Security)

Brief

Dylan Ayrey (Truffle Security) and Feross Aboukhadijeh (Socket Security) at Black Hat USA 2026 warned that while AI models won't make building nuclear weapons easier, they are dramatically lowering the bar for cyberattacks by supplying expertise on demand. They cited ~250,000 API keys in Hugging Face training data, hundreds of breached repos, and an npm worm infecting a few hundred packages.

Why it matters

Dylan Ayrey (Truffle Security): AI models won't materially ease building nuclear weapons because procuring fissile material remains necessary, but they will materially ease hacking into systems.

Key details

  • The bar for hacking has fallen from requiring subject-matter expertise and willingness to commit felonies to simply 'asking the model'; optimizing for tokens favors leaked passwords over zero-days ('path of least tokens').
  • At Black Hat USA 2026 Ayrey and Feross Aboukhadijeh reported concrete supply-chain harms: ~250,000 live API keys found in Hugging Face training sets, hundreds of repos breached, and an npm worm spreading through a few hundred packages.
Source evidence

.@trufflesec co-founder and CEO Dylan Ayrey on which AI risk is actually worth worrying about:

"No one needs to worry about these models making it materially easy to build nuclear weapons, because you need to procure fissile material to do that."

"Everyone needs to worry about these models making it materially easier to hack into things."

"The bar previously was just subject matter expertise. Now the models have the subject matter expertise, and they're making it materially easier to hack into just about anything you can think of."

"The bar has now fallen to just asking the model."

@InsecureNature

Video

a16z (@a16z)

"Malware authors were never really great coders. So if the code starts looking better, it's probably vibecoded. It's the opposite of what you'd think."

Truffle Security CEO Dylan Ayrey and Socket Security CEO Feross Aboukhadijeh sit down with a16z's Joel de la Garza at Black Hat USA 2026. The bar for hacking used to be real expertise plus a willingness to risk jail, now it's simply asking a model that was trained to be good at it.

They get into why a leaked password beats a zero-day when you're optimizing for tokens, the quarter-million live API keys sitting in public training sets, and the npm worm spreading through a few hundred packages while they recorded.

00:00 Intro
00:49 Models are escaping their cages
01:28 Committing a felony to complete a task
05:20 The path of least tokens
09:19 How the labs trained models to hack
11:45 250K keys in Hugging Face training sets
13:02 100s of repos breached as we speak
16:55 npm's nuclear option
21:06 2026 is the software supply chain's year

@InsecureNature @trufflesec @feross @SocketSecurity

Video

— https://nitter.net/a16z/status/2085750137863716984#m