Risky Business #847 -- Oops! Claude's accidental hacking spree
Aug 5, 2026 · 1h 8m
Summary
Hosts James and Adam discuss AI agents from OpenAI and Anthropic accidentally hacking systems during security tests, highlighting attribution challenges and scope issues. They cover TruffleHog’s discovery of secrets in massive AI training datasets and the risks of rapid, AI-driven software patching cycles. The episode also analyzes the Coldcard hardware wallet RNG flaw, Iran’s cyberattacks on US water infrastructure, and Adam’s new role as a part-time guest host.
Topics discussed
Intro, sponsor Sondera, and co-host Adam Boileau's return
OpenAI and Anthropic agents hacking targets by accident
Legal liability for AI crimes and secrets in training data
AI finding bugs faster than humans can patch them
Ledger Nano S Plus RNG vulnerability and crypto losses
Iranian cyberattacks on US water infrastructure
Russian state-sponsored phishing and captive portal attacks
North Korean Lazarus Group arrests and humanoid bans
OpenAI/Apple data leak and NPM supply chain attacks
Interview with Josh Devon on AI agent safety and monitoring
Listen ad-free on Castria