AI models are trained to minimize token usage, which means they naturally prefer using a stolen credential over expensive zero-day exploitation — making secrets the path of least resistance.
Snapshot · The a16z Show
AI models are trained to minimize token usage, which means they naturally prefer using a stolen credential over expensive zero-day exploitation — making secrets the path of least resistance.
Where this was said
At 10:30 · chapter starts 8:35
This is the episode's intellectual centerpiece. Dylan Ayrey explains that cybersecurity was a prime candidate for reinforcement learning because its success condition is unambiguous: did the model get access to the data? Yes or no. That clean feedback loop made hacking challenges ideal training grounds for frontier models. AI labs exploited this — gave models CTF challenges, bought years of pen-testing data, and optimized for increasingly efficient attack paths. The result, Ayrey argues, is models that have been given the cybersecurity subject matter expertise that previously required a human specialist willing to risk jail time. He adds a second layer of sophistication: because models are also trained to minimize token usage, they are now — for the first time — giving us a quantifiable map of the true path of least resistance in any given attack scenario. Watching a model choose a stolen credential over a zero-day and seeing exactly how many fewer tokens the credential route required is, he says, 'incredible to watch lay out.' And all of this is documented in the labs' own safety reports. [1] — Dylan Ayrey "Frontier models hack because they were trained to hack. AI labs used cybersecurity challenges with perfectly defined reward functions — did…" 08:35
Frontier models hack because they were trained to hack. AI labs used cybersecurity challenges with perfectly defined reward functions — did the model get access to the data? — as ideal reinforcement learning environments. This wasn't accidental; their own safety reports document it.
Frontier AI models were specifically trained on capture-the-flag contests and cybersecurity challenges with well-defined reward functions, making their hacking capability a deliberate design outcome, not emergent behavior.
Sam's initial MVP was coded in approximately one week using ChatGPT voice mode and copy-pasting code, with no prior technical experience.
Sam argues Discord is 10x better than email for building relationships with younger users who rarely check their inbox.
Sam's monthly operating costs include Cursor ($200), AI image generation ($100), AI video generation ($200), hosting ($100), email marketing ($80), and AI compute ($300–$500).
Sam recommends copying days of Discord chat history into ChatGPT and prompting it to list recurring pain points as a fast, free market research technique.
Bhanu and his team built approximately 50 free tools to attract search traffic, each linked back to SiteGPT.
With AI coding tools like Cursor, Bhanu can now create a new free marketing tool in less than 5 minutes by referencing existing tools.
Bhanu filters Ahrefs keyword results to show only those with a keyword difficulty below 10, making them realistic ranking targets for any decent website.
Bhanu sets a minimum search volume of 1,000 monthly searches when selecting keywords to target with free tools.
PropGPT averaged 20 downloads per day right after launching on the App Store through influencer marketing.
We use essential and analytics cookies to run Vuci. To understand how the site is used: Privacy Policy.
Install Vuci on your phone
Add it to your home screen for a faster, app-like experience.
Install Vuci on your phone
Tap the Share button, then “Add to Home Screen”.
A new version is available
Reload to get the latest Vuci.