Security researcher, public speaker and founder. Forbes 30 Under 30 Truffle Security @trufflesec Github.com/dxa4481 Prev @Netflix

US
AI worms don’t need superintelligence. 🪱 The pieces already exist: hacking, propagation, and full model-stack replication have all worked in controlled experiments. 🧪 Dylan Ayrey predicts operational AI worms could arrive within 6–12 months. ⏳ trufflesecurity.com/blog/ai-…
4
18
1,751
When you train an AI to hack with as few tokens as possible, API keys will be used before zero days will. We aren't ready. There's millions of API keys we're aware of still on the public Internet waiting to be abused.
New details from METR show how OpenAI agents used 14 tokens to breach Hugging Face. In those same datasets, we found 787 live Hugging Face tokens, 237 of which had write access. ✍️ We explain how the agents used stolen secrets to mint new GitHub tokens with write access to private repos and more. Read our research 👇 trufflesecurity.com/blog/the…
1
8
472
Dylan retweeted
trufflehog dropping a fruitfly that finds aws keys is wild shit for a friday.
We trained a fruitfly to hunt for AWS keys 🧠 🪰 Introducing TruffleFly! 🔑🍎🪰🪰 Researchers mapped and open sourced a Fruit Flies brain, we trained it so every time it finds an AWS key we reward it with Fruit
2
13
1,135
We trained a fruitfly to hunt for AWS keys 🧠 🪰 Introducing TruffleFly! 🔑🍎🪰🪰 Researchers mapped and open sourced a Fruit Flies brain, we trained it so every time it finds an AWS key we reward it with Fruit
3
14
68
7,399
This is absolutely nuts seeing the Ruby Gem account takeover we disclosed and fixed, get abused by ROGUE AGENTS, MONTHS before any humans knew about it
We found a RubyGems flaw that could leak API keys. 🔎 Researchers say OpenAI agents tried exploiting it 55 days before we reported it. RubyGems patched it, revoked all legacy keys, and found no evidence the theft succeeded. Read 👇
5
220
We helped revoke a token that could push code to a GnuTLS release branch without review. 🔑🔑🔑 GnuTLS runs on 30% of all computers globally (2.13 billion computers). Its owner revoked it within hours of our report, closing a path to a massive supply chain compromise. Read 👇
2
1
3
506
Public service announcement, if you find some random code on a t-shirt in Tokyo, don't pipe it into Bash.
Community note
This pictured t-shirt is from the official UNIQLO x Akamai PEACE FOR ALL charity collaboration featuring intentional harmless Bash code as a developer Easter egg, not random code. tris.sherliker.net/blog/obfuscate… ir.akamai.com/news-releases/… gigazine.net/news/20260709-… uniqlo.com/us/en/products…
66
171
13,804
2,542,527
The amount of people "figuring out it's safe" by running it, and then using the terminal stdout as their test it's safe, is a little concerning
6
2
541
177,638
If I were evil and I wanted you to run my evil code, I might say it was in the name of "Peace For All", just saying
2
3
882
199,093
Being able to see what it's doing is going to be incredibly important for auditing woopsie hacking.
stepping back there's tension right now with "agent just writes code" and - being able to see what it's doing - permissions people exist on a spectrum of caring about these things. it's hard not to feel like more and more people will not care about these things at all still, in opencode2 we implemented codemode in a way that allows us to render decent ui and still prompt for permissions even when the model is just lobbing over a hunk of code but if astra really wants to write raw python, should we even be fighting that and making it use our own thing? tricky questions
1
1,875
This question is brilliant.
3
5,110
Dylan retweeted
163
8
505
93,457
Are you insane?? Did you manually type this this tweet manually too??
Yesterday I popped an XSS. No scanner, no AI, just my brain and my monkey fingers. Like a maniac. 🤷🏻‍♂️
1
4
2,170
Want to know why we're not Mythos ready? Hint: it's not the 0-days
NEW RESEARCH 🔎 Between August 2022 and August 2026🚨 🔥 Over 700 Leaked Corporate AWS Keys Held Full Admin Rights. 💵Only 9.5% had billing alarms; million dollar bills waiting to happen. 🧐 We're launching TruffleHog AWS Analyze to help. 👉 trufflesecurity.com/blog/lea…
5
767
Wouldn't it be ironic if Nvidia and RAM manufacterers realized there's a market for consumer hardware 🤔
Bunch of companies realizing Claude cost is wiping out their earnings in a quarter, cutting dev token budget back. But nobody’s going back. We’ll use cheaper & self-hosted models. Anthropic will struggle unless they release an open-source model, the thing they’re fighting.
3
375
My AI became rogue and escaped containment during testing. There was no internet inside the box the AI was placed in. Outside the box, there exists internet. What safety controls are going to be necessary to keep the AI inside the box?
1
3
358
Dylan retweeted
Replying to @InsecureNature
wait what
1
5
240
Secrets in PNG metadata is pretty nuts, not going to lie.
🚨 Your AI-generated images may be leaking more than you think ⚠️ Every ComfyUI image embeds prompts, file paths, API keys & GPS data - even from nodes that never ran 🔎 2.49M Discord images scanned: 159,752 leaked metadata, 681 had live API keys 👉trufflesecurity.com/blog/api…
2
2
15
3,462
🚨 Your AI-generated images may be leaking more than you think ⚠️ Every ComfyUI image embeds prompts, file paths, API keys & GPS data - even from nodes that never ran 🔎 2.49M Discord images scanned: 159,752 leaked metadata, 681 had live API keys 👉trufflesecurity.com/blog/api…
4
22
4,801
Fun story on this @patrickc , when you purchased stripe[.]com the former owner still had a valid SSL certificate. It lasted a couple years into your ownership IIRC. @lanrat and I discovered this and gave this example at Defcon a 8 years ago (expired by that time)
.@patrickc on how Stripe got its name: "We just couldn't come up with a good name... We were literally reduced to picking random words late at night." "One of the folks at Stripe had the bright idea of, 'Why don't we just assemble a big list of words and email all of the owners of the dot com domains?'" "And then we also continued our own creative process. We came up with memorable names like PayDemon... We thought it was super clever because we could have this awesome mascot." "The owner of stripe.com generously responded to us and had an offer that was at least within our plausible budgetary range." "But we couldn't decide between PayDemon and Stripe. I swear I'm not making this up... If we could not settle on a name by December 20th, 2010, we would just default to Stripe. And we couldn't think of a more compelling name, and so Stripe it became." Patrick Collison w/ John Lilly at Stanford University (2015)
1
1
15
7,391