EPISODE · Apr 24, 2026 · 43 MIN
Hacking AI: Why Most AI Systems Are Insecure by Default
from Domesticating AI · host SoyPete Tech
Hosts: Miriah Peterson, Matt Sharp, Chris BrousseauRecorded: April 2026Status: ReleasedMost AI systems today are designed to be helpful — not secure.In this episode, we break down how AI systems actually get exploited in production:a real supply chain attack on a widely used AI dependencyprompt injection and why it still worksimage-based (multimodal) exploitstool and agent abuseIf you’re building AI — especially at a startup — you are the security team.A widely used AI dependency was compromised via a malicious .pth file:executes automatically when Python startsno import requiredtargets credentials, SSH keys, and environment variables👉 Just installing the package was enough.This highlights a critical reality:Your AI system is only as secure as your dependencies.Models cannot distinguish between instructions and dataExternal content can override system behaviorStill one of the most common AI vulnerabilities🔗 https://learnprompting.org/docs/prompt_hacking/injectionHidden instructions embedded in imagesAI interprets images differently than humansExpands the attack surface significantly🔗 https://arxiv.org/abs/2306.11698AI systems can take real-world actions via toolsPrompt injection → API calls, data leaks, unintended executionAgents amplify risk through autonomy and retriesIf you’re building AI systems today:separate instructions from datalimit tool permissionstreat outputs as untrustedvalidate everything before executionAI systems have an internet-sized attack surfaceSupply chain attacks bypass all AI safeguardsPrompt injection is a fundamental problemAI doesn’t fail safely — it fails wherever your system is weakestLiteLLM incident: https://github.com/BerriAI/litellm/issues/24512Attack breakdown: https://futuresearch.ai/blog/litellm-pypi-supply-chain-attack/LLM attack techniques: https://llm-attacks.org/OWASP LLM Top 10: https://owasp.org/www-project-top-10-for-large-language-model-applications/Gandalf challenge: https://gandalf.lakera.ai/We’ve launched a Patreon for Domesticating AI 🎉Get:early access to episodesbehind-the-scenes contentbloopers and uncut moments👉 https://patreon.com/DomesticatingAIPodcast🎥 YouTube: https://youtu.be/HTTxE7Y1skoWhat’s the weirdest way an AI system has broken for you?Keep your AI on a leash.
Embed this episode
Ready to play
Hacking AI: Why Most AI Systems Are Insecure by Default
No transcript for this episode yet
Similar Episodes
No similar episodes found.