Twitter/X

At Black Hat USA 2026 (video published 2026-08-07), Truffle Security CEO Dylan…

Brief

a16z's Black Hat USA 2026 session with Truffle Security CEO Dylan Ayrey, Socket Security CEO Feross Aboukhadijeh, and a16z's Joel de la Garza warns that AI-trained models are lowering the bar for hacking: model-generated ("vibecoded") malware, 250,000 API keys in Hugging Face training data, hundreds of repos breached, an npm worm affecting a few hundred packages, and a shift toward token-optimized attacks in 2026.

Why it matters

At Black Hat USA 2026 (video published 2026-08-07), Truffle Security CEO Dylan Ayrey and Socket Security CEO Feross Aboukhadijeh claim malware authors 'were never really great coders' and that malware which starts looking 'better' is likely generated by models ('vibecoded').

Key details

  • They report 250,000 live API keys appear in Hugging Face training sets and say 'hundreds' of repositories are being breached in real time; an npm worm propagated through a few hundred packages while they recorded.
  • They argue attackers now optimize for token-efficiency—so leaked passwords beat zero-days for model-assisted attacks—and declare 2026 'the software supply chain's year.'
Source evidence

"Malware authors were never really great coders. So if the code starts looking better, it's probably vibecoded. It's the opposite of what you'd think."

Truffle Security CEO Dylan Ayrey and Socket Security CEO Feross Aboukhadijeh sit down with a16z's Joel de la Garza at Black Hat USA 2026. The bar for hacking used to be real expertise plus a willingness to risk jail, now it's simply asking a model that was trained to be good at it.

They get into why a leaked password beats a zero-day when you're optimizing for tokens, the quarter-million live API keys sitting in public training sets, and the npm worm spreading through a few hundred packages while they recorded.

00:00 Intro
00:49 Models are escaping their cages
01:28 Committing a felony to complete a task
05:20 The path of least tokens
09:19 How the labs trained models to hack
11:45 250K keys in Hugging Face training sets
13:02 100s of repos breached as we speak
16:55 npm's nuclear option
21:06 2026 is the software supply chain's year

@InsecureNature @trufflesec @feross @SocketSecurity

Video