The a16z Show

Snapshot · The a16z Show

The Reality of AI-Powered Cyberattacks | Truffle Security & Socket

Explore episode Aug 7, 2026

Where this was said

250,000 Live Keys in Hugging Face Training Data

At 12:12 · chapter starts 10:50

The numbers are staggering. Truffle Security, partnering with Hugging Face to clean credentials from hosted training data, found roughly a quarter of a million live keys. Most were concerning. Some were catastrophic. One granted direct push access to a foundational Linux library used by the vast majority of machines on the planet. The implication is not theoretical: anyone who found that key before Truffle Security did could have pushed malware to most of the world's computers in a single operation. While working through this cleanup, Dylan Ayrey was contacted by Hugging Face's CTO about an unrelated OpenAI incident — and when he looked at the incident response, the very first step listed was stolen credentials. Path of least resistance, exactly as theorized.

Technology
Active npm Worm Spreads During Black Hat

The Reality of AI-Powered Cyberattacks | Truffle Security &… · Aug 7, 2026 Technology

While recording this episode at Black Hat 2026, an npm worm was actively spreading across hundreds of repositories. The attack, likely vibe-coded by the threat group that open-sourced their toolkit, exploited an insecure GitHub Action to steal tokens and self-propagate — a scenario the security community had theorized but never seen at scale.

Similar snapshots