AI could make devices too secure for government hacking. That might backfire on all of us

Cryptography professor Matthew Green floated a genuinely unsettling idea last month, and the cybersecurity community hasn’t stopped arguing about it since. His thesis, posted on X and expanded in a blog post that spread fast through security circles: AI is getting so good at finding software vulnerabilities that it could eventually help companies make their software nearly bug-free. And that, according to TechCrunch, is where things get complicated for everyone’s privacy.

The uneasy truce that’s been keeping things balanced

For the past decade, a quiet arrangement has held. Governments stopped pushing for encryption backdoors, and in exchange, they spent heavily on commercial spyware and zero-day exploits to hack into suspects’ devices when they needed access. Apps like Signal, WhatsApp, and iMessage rolled out end-to-end encryption to billions of users starting around 2014. Apple encrypted iPhones by default. The FBI warned about “going dark.” And yet law enforcement kept catching criminals, largely because software stayed buggy enough to exploit.

Green calls this “an uneasy kind of truce.” But he thinks AI is about to break it. If large language models can find security flaws faster and at scale, companies will patch them faster too. Fewer bugs means fewer entry points. And when governments can no longer buy their way into devices through the exploit market, Green warns, they’ll start demanding backdoors again. That’s the nightmare scenario for privacy. Backdoors don’t stay exclusive to the good guys.

Not everyone buys the argument

TechCrunch spoke to a range of offensive security researchers, privacy advocates, and zero-day market insiders. The picture that emerges is messy. Luna Tong, a researcher with experience at major exploit-development firms, agrees with Green. She describes the current moment as a “gold rush of bugs” but says it’s temporary. Another veteran offensive security researcher, speaking anonymously, said he worries AI will make human bug hunters obsolete and that defenders will eventually outpace attackers.

But others push back. Hamid Kashfi, founder of DarkCell and also active at AI cybersecurity startup Xbow, makes a pointed counterargument: for every AI-discovered bug that gets reported to a vendor, roughly 20 go unreported. Researchers who sell to governments rather than disclose publicly have little incentive to stop. So the exploit market doesn’t necessarily dry up just because AI finds more bugs.

  • Easy, surface-level bugs will become harder to monetize as AI finds them quickly
  • Complex, high-value vulnerabilities are likely to persist longer and stay attractive to government buyers
  • AI can also assist the researchers selling zero-days, not just the defenders patching them
  • New device security protections are already making exploitation harder, independent of AI

The backdoor threat is real, but maybe not imminent

Eva Galperin, cybersecurity director at the Electronic Frontier Foundation, adds a layer of realism. Finding bugs faster doesn’t mean they get patched faster. Patching is slow, complicated, and often deprioritized. She also points out that AI-assisted “vibe coding” is introducing new vulnerabilities as fast as others are being fixed. Still, she’s clear that authoritarian governments will always push for exceptional access. That pressure never really goes away.

Katie Moussouris, founder of Luta Security and someone who has spent decades managing vulnerability disclosure for major companies, puts a rough timeline on it. “We have at least until after the next presidential election before the intelligence community is materially hampered enough to push for backdoors in a serious way,” she said. So not tomorrow. But the direction of travel is what matters here. If Green is even partially right, the privacy protections most people take for granted today are built on a foundation that AI might quietly erode.