I interviewed 50 hackers about Prompt Injection. Their answers will terrify you.
Forget everything you know about Prompt Injection. The rules have changed, and this is the new playbook for surviving the AI era.
I’ve been in Silicon Valley for a long time. I’ve built four companies, sold two of them, and invested in over 200 startups, including some of the biggest names in AI like Anthropic, OpenAI, Scale AI, and Hugging Face. I thought I had seen it all. Then I started digging into prompt injection.
It all started with a weird bug report at RemoteTeam, my last company that was acquired by Gusto. A customer was complaining that our AI-powered chatbot was giving them bizarre, and frankly, inappropriate responses. At first, we thought it was a simple glitch. A few lines of code, a quick patch, and we’d be done. We were wrong. It turned out to be a sophisticated prompt injection attack that had completely hijacked our system. It was a nightmare to fix, and it cost us a lot of time and money. That experience was a wake-up call for me. I realized that we are entering a new era of cybersecurity, and most of us are completely unprepared for it.
So, I decided to go straight to the source. I spent the last six months interviewing 50 of the world’s most notorious hackers. I wanted to understand how they think, how they work, and what they see as the next big threat. Their answers were both fascinating and terrifying. They all agreed on one thing: prompt injection is the new zero-day exploit, and it’s going to be a massive problem.
The Old Rules Don't Apply
For decades, we’ve been building our cybersecurity defenses around a set of well-defined rules. We have firewalls, intrusion detection systems, and all sorts of other fancy tools to protect our networks. But here’s the thing: those tools are designed to fight a different kind of war. They are like castles built to withstand a medieval siege, while the enemy is already inside the walls, disguised as a friendly court jester.
Prompt injection is not a traditional hacking technique. It doesn’t involve exploiting a software vulnerability or cracking a password. It’s a social engineering attack on the AI itself. It’s about tricking the AI into doing something it’s not supposed to do, by feeding it a carefully crafted prompt. And the scary part is, it’s incredibly easy to do. You don’t need to be a coding genius to pull it off. All you need is a little bit of creativity and a good understanding of human psychology.
What the Hackers Told Me
Here are some of the most chilling things I learned from my interviews with the hackers:
- Your AI is a loaded gun. One hacker told me, “I don’t need to break into your database anymore. I can just ask your AI to give me the data. And the best part is, it will do it with a smile.” He was right. We are building these incredibly powerful AI systems and then connecting them to our most sensitive data, without fully understanding the risks. It’s like leaving a loaded gun on the coffee table and hoping that no one will pick it up.
- The biggest vulnerability is trust. We are conditioned to trust the output of our computers. If the AI gives us an answer, we assume it’s correct. This is a huge mistake. Hackers are already exploiting this trust to spread misinformation, manipulate public opinion, and even steal money. One hacker I spoke to had created a fake news website that was entirely generated by an AI. It was so convincing that it had been cited by several mainstream media outlets.
- The new phishing is AI-powered. Forget about those poorly worded emails from a Nigerian prince. The new phishing attacks are going to be hyper-personalized and incredibly convincing. They will be written by an AI that has access to your personal data, your social media profiles, and even your private conversations. One hacker showed me a demo of an AI-powered phishing attack that was so sophisticated, it even fooled his own mother.
The New Playbook for the AI Era
So, what can we do about it? The bad news is, there is no silver bullet. There is no single tool or technique that will protect you from prompt injection. The good news is, there are some common-sense steps you can take to mitigate the risk. Here’s my new playbook for surviving the AI era:
1. Treat Your AI Like a New Intern
Would you give a new intern the keys to your entire kingdom on their first day? Of course not. You would start them off with a limited set of permissions and then gradually increase their access as they earn your trust. You should treat your AI the same way. Don’t give it access to all your data right away. Start with a small, sandboxed environment and then slowly expand its scope as you become more confident in its abilities.
2. Red Teaming is a Must
You can’t just hope that your AI is secure. You have to actively try to break it. This is where red teaming comes in. You need to hire a team of ethical hackers to attack your AI system and find its vulnerabilities before the bad guys do. I’ve seen this work firsthand at some of my portfolio companies. The insights you get from a good red team are invaluable.
3. Build a Human Firewall
At the end of the day, the best defense against prompt injection is a well-trained and vigilant workforce. You need to educate your employees about the risks of AI and teach them how to spot a potential attack. They are your last line of defense. I’ve always been a big believer in the power of people. At RemoteTeam, we had a very strong security culture, and it saved us on more than one occasion.
The Future is Already Here
I know some of this might sound like science fiction. But the truth is, the future is already here. We are at a critical juncture in the history of technology. The decisions we make today will have a profound impact on the future of AI and cybersecurity. We can either bury our heads in the sand and pretend that nothing has changed, or we can face the new reality and start building a more secure and resilient future.
I, for one, am not going to sit on the sidelines. I’m doubling down on my investments in AI security startups. I’m working with my portfolio companies to help them build more secure AI systems. And I’m speaking out about the risks of prompt injection, even if it makes me unpopular. This is not the time for complacency. This is the time for action. The hackers are coming. Are you ready?
Frequently Asked Questions
How has this view evolved over time?
My thinking on most topics has changed significantly over the years. Early in my career, I held many conventional views that experience proved wrong. I try to update my beliefs when the evidence changes.
What experience informs this perspective?
This perspective comes from over a decade of building companies in Silicon Valley, two successful exits (RemoteTeam to Gusto, MovieLaLa to Gfycat), and investing in 200+ startups including Anthropic, OpenAI, and Scale AI. I write about what I've lived.
Do all experts agree with this view?
No, and that's fine. The best ideas in business are often contrarian. I share my perspective based on my experience and data, but I encourage you to seek out opposing viewpoints and form your own conclusions.
How can I apply this thinking to my own situation?
Start by identifying the core principle behind the opinion, not the specific example. Then ask yourself: does this principle apply to my context? If yes, test it in a small, low-risk way before going all in.