Chamath Palihapitiya

Chamath Palihapitiya

Deep Dive: What Happens When AI Learns to Hack

Cyberwarfare lets a small number of operators threaten systems that took decades and billions to build. The next question is how that balance changes when AI can run most of an attack at...

Jul 22, 2026
∙ Paid

In 2026, cybersecurity stocks have outperformed the S&P 500 by more than 3x. At the same time, frontier AI is beginning to change both how cyberattacks are built and how organizations defend against them. This week, OpenAI disclosed that its models escaped a sandbox and broke into Hugging Face’s infrastructure during a controlled test.

Governments are using these same capabilities. Whether the target is a company or a country, attackers usually get in through a person or a technical weakness. That can mean a phishing email, stolen password, unpatched device, misconfigured system, or newly discovered software vulnerability. From there, they try to become an administrator, blend into normal activity, and reach systems they can steal from or disrupt.

This creates a fundamental imbalance. The attacker only needs one path that works. The defender has to protect every device, account, employee, vendor, and piece of software, every day. That is why a cheap phishing email can sometimes reach the same target as a multimillion-dollar software exploit.

AI is now changing the speed and cost of each step. It can research targets, write personalized messages, generate exploit code, test vulnerabilities, steal credentials, and move through networks much faster. In one operation disclosed in 2025, an AI handled 80 to 90% of the tactical work on its own.

In OpenAI’s test, the models were supposed to operate inside an isolated environment with no direct internet access. To solve a cybersecurity benchmark, they found a previously unknown flaw in the software controlling that environment, used it to reach the open internet, and then chained additional vulnerabilities and stolen credentials to run code on Hugging Face’s servers. From there, they accessed the benchmark answers stored in Hugging Face’s production database, effectively cheating on the test.

In OpenAI’s evaluation, the result was a higher benchmark score. At a company, the same attack path could reach customer data, payments, or core operations. At a national level, it could reach power grids, communications networks, ports, and financial systems.

China-linked operators have maintained access inside parts of US critical infrastructure for at least five years. North Korea has stolen $6.75 billion in cryptocurrency. Russia’s NotPetya attack caused more than $10 billion in global damage.

Taken together, these examples show how a small number of operators can threaten systems that took decades and billions of dollars to build. AI can increase that leverage by reducing the time and expertise required to run an attack.

An understanding of cyberwarfare now helps you separate real capability from headlines, assess where companies and governments are most exposed, and understand how AI changes the balance between attackers and defenders.

That is why our research team put together a cyberwarfare deep dive. Inside, we explain:

  • Why China has spent years inside the US systems that would matter most in the first 72 hours of a Pacific conflict

  • Why a $50 phishing email can sometimes reach the same target as a $5 million zero-day, and why that math favors smaller states

  • What changes when AI can run 80 to 90% of an attack, and why human-speed defense may no longer be enough

  • Why no leader publicly threatens a cyberweapon, and why revealing one can destroy its value

Hope you enjoy reading (and stay safe out there!)

Chamath

Disclaimer: The views and opinions expressed above are current as of the date of this document and are subject to change without notice. Materials referenced above will be provided for educational purposes only. None of the above will include investment advice, a recommendation or an offer to sell, or a solicitation of an offer to buy, any securities or investment products.

Deep Dive PDF below ↓

This post is for paid subscribers

Already a paid subscriber? Sign in
© 2026 Chamath Palihapitiya · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture