← Field Notes

Patch Tuesday, Exploit Wednesday: How AI Just Closed the Gap Between a Hack and a Fix

Sigma Prime co-founder Mehdi Zerouali tells Caribbean builders the real risk of vibe-coded software is not bad code — it is what nobody thought to ask an AI to protect.

Patch Tuesday, Exploit Wednesday: How AI Just Closed the Gap Between a Hack and a Fix

A blockchain security specialist tells a Caribbean builder community that the real risk of vibe-coded software is not bad code. It is what nobody thought to ask an AI to protect.

A hacker named Chompy stood on a stage in Sydney last weekend and explained how she had automated something that used to take a team of elite researchers weeks to do by hand.

Every second Tuesday, Microsoft releases security patches for Windows and its other software. For years, the pattern that followed was predictable enough to have its own name: patch Tuesday, exploit Wednesday. A patch would drop, and a small number of specialists, maybe a thousand people worldwide with the skill to do it, would spend days or weeks reverse engineering the fix to figure out exactly what vulnerability it closed, and how to exploit it before everyone updated.

Chompy did it in hours. Using publicly available AI models. No privileged access to Anthropic or OpenAI required.

That story, told by Mehdi Zerouali, co-founder of the blockchain security firm Sigma Prime, was the moment a routine Q&A about vibe coding turned into something more unsettling. It also became the clearest answer yet to a question that Caribbean founders building with AI tools rarely stop to ask: what happens when the barrier to attacking something drops as fast as the barrier to building it?

Building got cheap. So did breaking things.

Zerouali was speaking to a community of builders in a call hosted by Lily Dash and Melissa, the kind of session that mixes people who have coded professionally for twenty years with people who have never written a line of code and are shipping products anyway, guided entirely by AI agents. That split audience shaped the conversation. Zerouali, who has spent fifteen years breaking into systems for a living, first as a penetration tester in Paris, now running Sigma Prime out of Sydney while it helps secure much of the infrastructure around Ethereum, kept circling back to the same idea from different angles.

The open weight AI models that anyone can download, he said, are catching up to the frontier labs fast enough that the American AI giants' security edge over the open models "will basically be inexistent in a few years." Combine that with models that have no built in guardrails, and the economics of hacking change completely.

"Now all of a sudden you have basically any man and his dog with the ability to build cyber weapons," he said. Organisations that still take weeks to apply a security patch, which describes most large institutions, banks especially, are left exposed during a window that used to be safe by default and no longer is.

Zerouali said he is watching critical infrastructure most closely: power plants, water treatment systems, the things a region cannot function without.

The small shop is now a target.

For years, the calculation protecting small businesses from serious cyberattacks was simple: the effort was not worth the payout. A neighbourhood hacker was not going to spend hours breaking into a dry cleaner's point of sale system for a few hundred dollars. The economics said go after bigger fish.

Zerouali said that calculation no longer holds. AI has pushed the cost of an attack toward zero, which means it now makes sense to go after the businesses least prepared to defend themselves.

"The target space is now including small family businesses that are historically the least prepared to deal with this sort of disruptions," he said.

It is a shift with a direct line to the Caribbean, where small and micro businesses make up a large share of the private sector and few have anything resembling a dedicated security function. The businesses least able to absorb a breach, financially or reputationally, are the ones for whom an attack just became affordable to launch.

Treat customer data like nuclear waste.

If there was one idea Zerouali wanted the room to leave with, it was this: personally identifiable information is not an asset. It is a liability that happens to have business value attached.

"Treat PII almost as nuclear waste," he said. "Nothing can go wrong from a privacy standpoint for your customers if you don't hold their data."

He was not speaking abstractly. He pointed to a wave of physical attacks against crypto founders in France, where leaked home addresses led to break ins, kidnappings, and in one case involving a Ledger co-founder, a finger cut off. The information a company decides to store, he said, becomes something a criminal can act on, whether that company gets hacked or the data simply leaks through a careless third party.

For early-stage builders collecting phone numbers, emails and addresses because a product needs them, Zerouali's advice was blunt: encrypt the database, tighten authentication, and make sure one customer can never see another customer's data, something he called a common and costly failure. Backups need the same protection as production systems, because attackers increasingly go after the unguarded backup rather than the hardened production environment.

The harder question, and the one he pushed the room to actually sit with, is whether a business needs to keep the data at all. Can it be anonymised. Can it be deleted after a few days instead of stored indefinitely. "A lot of organisations and startups think of these things later," he said. "That's why I was trying to convey shifting security to the left." Left, in security terms, means the start of the build, not a compliance checkbox bolted on before launch.

What a two to five person startup can actually do

Asked directly what a small team without a security hire should prioritise before their first paying customer, Zerouali gave a short, practical list rather than a lecture:

Scan the codebase for exposed secrets, meaning API keys or access tokens accidentally committed to a public repository, a mistake he said he sees constantly among non-developers using AI coding tools. Tools like GitHub's Dependabot can flag outdated dependencies automatically, closing off a class of vulnerability that has nothing to do with the code a founder actually wrote. And access control has to be explicit: a customer account should never be able to reach an administrator's functions, a flaw he said is common in AI-generated applications unless a founder writes the rule directly into their instructions to the model.

"By adding to your Claude.md instructions to your LLM, saying, hey, whatever we build, make sure that access control is tight," he said, "it goes a long way."

On the newer question of AI agents handling money directly, holding wallet keys and executing transactions on a founder's behalf, Zerouali was less alarmed than the framing might suggest. The industry, he said, is moving past a reflexive no toward a more useful question: what controls surround the agent. Spending limits. Transaction caps. A manual approval step for anything above a threshold. The agent can hold responsibility. It should not hold it unsupervised.

Fragmentation is a cost. It might also be the opening.

The conversation's sharpest regional turn came when Melissa raised something specific to the audience in the room: the Caribbean's defining structural fact is not that it lacks ideas, but that those ideas have to survive contact with more than a dozen separate jurisdictions to reach regional scale.

Zerouali's answer connected that fragmentation directly to his own upbringing. He was born and raised in Morocco, where a strict annual cap on how much money residents can convert into euros or dollars, around two to three thousand dollars a year, has pushed people toward stablecoins as a way around currency controls they have no say over. His brother, a video game developer, pays contractors in Argentina in stablecoins because the money arrives instantly rather than sitting in a slow, expensive banking corridor.

"When trust is a scarce resource, when fragmentation is a plague, blockchain systems have really their use," he said, adding that he is not in the business of pushing blockchain as the answer to everything. But for a region where a transaction, a supply agreement or a payment has to hold up across jurisdictions that do not share regulatory infrastructure, he described the technology's core appeal in plain terms: a smart contract lets two parties who do not know each other agree on conditions in code, publicly, immutably, without either one needing to trust the other's word.

What builders actually control

Zerouali was careful throughout not to let the conversation drift into fear for its own sake. Certification, he said, is not a substitute for security. He has watched ISO 27001 certified companies get hacked, because certification measures a narrow, defined scope, not the whole business, and it is often chased to satisfy an investor rather than to close an actual gap.

What he kept returning to instead was cheaper and available to anyone: talk to the people building alongside you. Try to break your own product before someone else does. Ask a friend in the community to find the ways your system could be misused, because builders are structurally bad at spotting the flaws in things they built themselves.

"Just being aware of these potential failures is very valuable," he said.

It is not a technical fix. It costs nothing but attention. In a region where the tools to build have never been more accessible, and now, by Zerouali's account, neither have the tools to attack, that kind of attention may be the cheapest security a small team can afford.

#dispatch#builders
ShareX / TwitterLinkedIn
Keep reading