Why I attack
Yesterday I was forwarded a bunch of messages that Prof. Ben Zhao (a computer science professor [a] at the University of Chicago) wrote about me on a public Discord server with 15,000 members, including this gem: Now I'll be the first to admit it: I study how to attack systems not because I'm driven by some fundamental desire to “do good”, but because it's what I enjoy and find interesting and exciting. Some people in the world are motivated by doing good; they become public defenders, or work at homeless shelters, or care for the elderly, and are better people than you or me. But I'm motivated by solving puzzles, and so that's what I do. So I thought that, in this post, I would explain why I write attack papers that expose security vulnerabilities. Because you can have fun writing attack papers and still also “give a shit about people”. Before I start responding to this message, I need to start with some background. All security vulnerabilities lie on a spectrum of how hard they are t
Why I attack Main Papers Talks Code Writing Writing Why I attack by Nicholas Carlini 2024-06-24 Yesterday I was forwarded a bunch of messages that Prof. Ben Zhao (a computer science professor [a] A full professor with tenure, so I feel entirely within my rights to call him out here. at the University of Chicago) wrote about me on a public Discord server with 15,000 members, including this gem: Now I'll be the first to admit it: I study how to attack systems not because I'm driven by some fundamental desire to "do good", but because it's what I enjoy and find interesting and exciting. Some peop
related reading
- Assessing Claude Mythos Preview’s cybersecurity capabilities \ Anthropicred.anthropic.com
- Security incident disclosure — July 2026huggingface.co
- Vulnerability Research Is Cooked - Quarrelsomesockpuppet.org
- Nicholas Carlininicholas.carlini.com
- Measuring LLMs' impact on N-day exploits \ Anthropicred.anthropic.com
- Project Glasswing: Securing critical software for the AI era \ Anthropicanthropic.com
- The End-State Fallacy: Where Is AI Security Headed?endstatefallacy.com
- Greg Brockman on Svbtleblog.gregbrockman.com
- Discovering cryptographic weaknesses with Claude \ Anthropicanthropic.com
- The Letter - Stop Hacklore!hacklore.org
- OpenAI – Hugging Face Incident Technical Reportcdn.openai.com
- FIRST Mid-Year Vulnerability Forecast Confirms Historic Surge, Projects ~66,000 CVEs in 2026first.org