ATRIUMsearch → argument graph
AnecdoteVideo · 11:51 — 12:48

In partnering with Hugging Face to clean up training-set credentials, we found about a quarter million live keys — one gave direct push access to a foundational Linux library that could have pushed malware to most machines on the planet.

Dylan recounts how a credential-cleanup partnership with Hugging Face surfaced roughly a quarter-million live keys in training sets, including one with direct push access to a foundational Linux library that could have compromised most machines — reinforcing that stolen credentials, not zero-days, were the primary vector. ✦ AI generated

Dylan · a16z Podcast · 2026-08-07 · original ↗

starts at this moment · 11:51

Turned out there were about a quarter million live keys in their training sets, many of which had direct supply chain implications. There was a foundational Linux library that one of the keys had direct push access to. It could have pushed malware to most machines on the planet. And so, while we were in the middle of doing that, the CTO of HuggingFace shoots me a note and says... this open AI thing that just happened... And sure enough, the first thing listed out in the incident response, although it's true it did utilize zero days, but the first thing listed out was stolen credentials.

verbatim transcript · starts at 11:51

Transcript · around this moment

11:33test the models out and and show, okay, well, it got access to the data and it broke out of its harness. Um it's it's not like this is emergent behavior specifically. >> That's perfectly logical, right? Like the fastest way to get a gallon of milk is to steal it. >> That's exactly right. [laughter] So, so, um, I mean, what was interesting is we were in the middle of partnering with

11:51Hugging Face to clean up all of the credentials that had been exposed through all of their training sets. Not Hugging Faces training, but people who hosted training sets on HuggingFace. They used Truffle Hog for a wide range of reasons. Um, and HuggingFace has been a great partner in getting credentials cleaned up. We targeted their uh, training sets because we knew they had a lot of keys. Turned out there were about

12:11a quarter million live keys in their training sets, many of which had direct supply chain implications. There was a foundational Linux library that one of the keys had direct push access to. It could have pushed malware to most machines on the planet. And so, while we were in the middle of doing that, the CTO of HuggingFace shoots me a note and says, "Hey, this is crazy, but there's

12:30this open AI thing that just [laughter] happened, and I want you to take a look at And sure enough, the first thing listed out in the incident response, um, although it's true it did utilize zero days, um, but the first thing listed out was stolen credentials. >> Um, and that's that's how they were trained. The path of least resistance. >> Password is a password is always the

12:48first step, right? >> That's exactly right. >> And you've you've had your hair on fire, I think, pretty substantially for the last like 18 months. Um, I think right now as we're recording this, there's currently an ongoing active breach of of a big mpm repo. Isn't there something happening? It's more than just a repo. It's actually about you know few hundred repos. >> Oh wow. Okay. >> Yeah. So it's it's a worm. And this is

13:10one of the things that has been kind of an unfortunate innovation in the in the malware landscape uh on you know npm is that you know for a long time you know people had talked about this concept of an npm worm. You know this idea that you know if I could someone could backdoor a package. Yeah. um and then you know get developers to install that and then you

Around this claim