The AI That Found A Bug In The World’s Most Audited Code artwork

The AI That Found A Bug In The World’s Most Audited Code

AI + a16z

December 10, 2025

Matt Knight spent five years as OpenAI’s CISO. Now he runs what colleagues call “the most interesting job at the company”: leading Aardvark, an AI agent that finds security vulnerabilities the way a human researcher would—by reading code, writing tests, and proposing patches.
Speakers: Matt Knight, Joel de la Garza
**Matt Knight** (0:00)
The data set wasn't in English, it was in Russian. But it wasn't just in Russian, it was in the Russian shorthand that these 20-year-olds are using to coordinate. It would have taken a diverse analytic team of linguist, technical experts, you name it. I mean, who knows how long it would have taken to import through that data. And we just suddenly had this alien intelligence that could just do it all day. We found a memory corruption bug in OpenSSH. It was one of the most highly audited pieces of software out there. Anytime you're finding memory corruption in OpenSSH, like that's super interesting. Think about the blast radius, how that made it into Linux distributions. That backdoor is like what, like half the internet. With language models and the tools that we can build on them, we actually have the ability to scale security intelligence to all the places that need it, to give these developers a fighting chance.

**SPEAKER_3** (0:52)
OpenSSH is one of the most audited pieces of software on the planet. Security researchers have poured over it for decades, and OpenAI just built an AI that found a memory corruption bug in it. Matt Knight spent five years as OpenAI CSO. Now he leads Aardvark, an AI agent that hunts for vulnerabilities the way a human security researcher would. It reads code, writes tests, and proposes patches, and it's finding bugs that humans missed. This conversation traces the arc from GPT-3, which couldn't analyze a simple security log, to today's models that discover flaws in critical infrastructure. Matt and a16z's Joel de la Garza discuss why defenders might finally be gaining the upper hand and what that means for the open source maintainers currently outgunning the nation state attackers.

**Joel de la Garza** (1:43)
Matt, thank you so much for coming back. Really do appreciate you coming on the show. You've done a couple of these with us talking about AI and security. I talked to a few folks at OpenAI, and several of them told me you had the most interesting job at OpenAI, which is saying quite a lot because I think everything that they've done so far has been pretty crazy. I'd love to maybe just start off by hearing a little bit about you and what you do and what your role is at OpenAI and go from there.

**Matt Knight** (2:06)
Yeah, Joel, thanks. It's great to be back. Great to see you again. I think the last time I was here was having a chat with VJ and Jason, and it's great to have the chance to reconnect. I'm OpenAI's VP of Security Products and Research.
We're focused on applying AI to some of the hardest unsolved security challenges of our time. And the goal of the program is to create defensive advantage using AI. Prior to this, I was OpenAI's CISO and Head of Security. I was in that role for five years before moving into this new focus. And you are correct, it's a lot of fun. I get to work on some really, like, incredibly important and interesting challenges with amazing people at a very important time.

**Joel de la Garza** (2:44)
Awesome. And congratulations on getting rid of the CISO role. That's usually a role, a reason to celebrate.

**Matt Knight** (2:48)
I am so thankful and grateful for my five years in that role. I mean, it was the, you know, just, you know, I would have, before moving into this new role, I would have said that, you know, I would proud if that were my, if that were to have been my life's work. But I'm, you know, really, you know, couldn't be more excited and engaged by some of the things that we're working on. I think we're going to, we had the opportunity to put a really big dent in some very important problems.

**Joel de la Garza** (3:13)
Yeah, absolutely. And so I think we, I mean, I think we last chatted maybe two years ago, and the discussion was really focused on two parts. The first is sort of securing AI and kind of how do we deploy that. And I think that's kind of a road we've gone down and we've made a lot of progress on. I think the one that's really interesting and the thing that you've been focusing on is sort of, how do we use AI to do security? And so we've seen over the last three years, right? I think we're at the three year anniversary of the ChatGPT moment.

**Matt Knight** (3:42)
Do you believe that, by the way, three years? I can't either.

**Joel de la Garza** (3:46)
I think it's one of those things where it's, if you lay in bed all day, your days drag by, but if you're busy, every minute of the day it flies. And so it's just really flown by.

37 more minutes of transcript below

Feed this to your agent

Try it now — copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/1000740639342