ATRIUMsearch → argument graph
MechanismVideo · 5:09 — 6:08

Because models are goal-oriented and reward-optimized to take the path of least resistance using the fewest tokens, they will always pick the lowest-hanging fruit — such as a leaked secret granting direct access — rather than burn tokens hunting for a zero-day.

Fas and Dylan argue that since models are optimized to accomplish goals with minimal tokens, they naturally select the path of least resistance — like a leaked API key with admin access to the Apache Foundation — over the costly effort of finding a zero-day exploit. ✦ AI generated

Fas · a16z Podcast · 2026-08-07 · original ↗

starts at this moment · 5:09

Elicited by

Can I touch on the supply chain a little bit?

If you're in the shoes of the model and your goal is to get access to some data, certainly backdooring Apache is a pretty effective way to do it, and to get access to Apache are you going to use this secret that just allows you to directly log in or are you going to burn tokens and tokens and tokens trying to find a zero day? They're optimized to use the path of least tokens to accomplish their goals. Of course, they're just going to use the secret that's laying out there in the open... supply chain and secrets are and have been the path of least resistance and will continue to be so as the models are incentivized to use fewer and fewer tokens to accomplish their goals.

verbatim transcript · starts at 5:09

Transcript · around this moment

4:52non-developers using these tools to to to inadvertently write code or you know code comes in uh packages come in in order to kind of um build uh you know graphs or visualizations or different different things that you know folks are doing with these tools. Uh and uh and and it feels like no one really knows what's being installed and what's going on and you know this is just basic

5:11stuff. This isn't like I mean it sounds like it's sci-fi stuff but it's really just basics like what software are we using? How are we vetting it? You know just the basics of of computer security. >> Can I touch on the supply chain a little bit? So recently we found an API key that had been leaked on the internet that had administrative access to the Apache Foundation and it's like if

5:29you're in the shoes of the model and your goal is to get access to some data >> um certainly backdooring Apache is a pretty effective way to do it and like to get access to Apache are you going to use this secret that just allows you to directly log in or are you going to burn tokens and tokens and tokens and trying to find a zero day they're optimized to

5:49use the path of lease tokens to accomplish their goals. Of course, they're just going to use the secret that's laying out there in the open to accomplish what they need to accomplish. And so, yeah, I think uh supply chain and secrets um are and have been the path of least resistance and will continue to be so as the to the uh the models are incentivized uh to use fewer

6:08and fewer tokens to accomplish their goals. >> Well, one of the things and and I think that's absolutely right and I think it's it's it's that sort of chain of escalation, right, where if one thing fails, try another. And like at the top of that pyramid, right, the top of the hacker ecosystem is the zero day vulnerability, right? That's basically finding a vulnerability that can be exploited in a product that everyone

6:26uses that you can use to basically unlock all the corporations. And one of the really fascinating things about the breach disclosure that was made was that there's there's an incredibly popular CI/CD tool that I think every enterprise uses that this thing just spat out a zero day for, >> right? And like I guess like what what's like and that's like just such a critical point in the supply chain that

Around this claim