World Congress 2026 Europe Jul 10, 2026 Session details

Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API

Marc Plogas

Think a factory reset secures your discarded smart plug? Watch an autonomous AI agent exploit hidden debug ports to instantly extract lingering Wi-Fi passwords and cloud tokens.

Pause
Mute Enter Fullscreen
#1 about 3 min

Introduction to autonomous hardware hacking agents

How an AI agent autonomously hacked smart filament tags without prior training.

#2 about 4 min

Architecture of the AI hardware hacking system

Structuring Claude Code with project and tool MCPs to enforce physical safety tiers.

#3 about 2 min

Evaluating the Gosund v2 smart plug target

Identifying the physical hardware changes and undocumented silicon in an off-the-shelf smart plug.

#4 about 3 min

Automating physical exploit execution and firmware extraction

The agent plans the engagement and acquires an encrypted flash dump from the bootloader.

#5 about 2 min

Intercepting local communications via cloned access points

Attempts to monitor device activity using a rogue AP and man-in-the-middle strategies.

#6 about 3 min

Analyzing BLE attack surfaces for vulnerabilities

Enumerating unauthenticated BLE services and gathering fingerprint data from the device radio.

#7 about 2 min

App layer defenses and TLS certificate pinning

How the companion app successfully prevented network interception by enforcing strict certificate checks.

#8 about 6 min

Bypassing physical enclosures for UART flash decryption

Desoldering uncooperative casing to access debug pads and retrieve plain text AES keys.

#9 about 2 min

Refining the agent by automating physical hardware restarts

Upgrading test environments with persistent power control tools to eliminate human intervention loops.

#10 about 2 min

Assessing the collapse of obscurity as a defense

Why traditional limitations of time and specialized knowledge no longer stop automated vulnerability discovery.

#11 about 2 min

Releasing isolated capabilities and persistent data risks

The implications of open-sourcing tool integrations while keeping the AI reasoning engines local.

#12 about 3 min

Addressing questions on model guardrails and alternative entry techniques

Audience questions cover LLM security bypasses and alternative chip-off data extraction methods.

Matching moments

3:38 min

Evaluating security risks in autonomous artificial intelligence agents

Chris Heilmann +2 · LIVE

2:18 min

Managing security risks introduced by autonomous AI agents

Christian Heilmann Christian Heilmann · World Congress 2025

11:34 min

Rapid prototyping with AI agents at hackathons

Chris Heilmann +2 · LIVE

3:25 min

Troubleshooting rogue agent behavior and mobile automation challenges

Elaine Dias Batista Elaine Dias Batista · World Congress 2026 Europe

1:36 min

Misusing AI for malware generation and physical evasion

Balázs Kiss · World Congress 2023

1:10 min

Identifying emerging security vulnerabilities in generative AI agents

Alejandro Saucedo Alejandro Saucedo · World Congress 2025

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 24, 2026 · 16:50–17:20

Stage 4

From Software Agents to Physical Devices: Inside the Agentic Hardware Stack

Michael Yuan, Vivian Hu

Michael Yuan
Vivian Hu
Open session

World Congress 2026 North America

September 24, 2026 · 17:30–18:00

Stage 5

Securing AI Agent Infrastructure: Identity, Attestation, and Trust at Scale

Abdel Fane

Founder of OpenA2A

Abdel Fane
Open session

World Congress 2026 North America

September 25, 2026 · 16:50–17:20

Stage 5

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer at Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

September 24, 2026 · 11:00–11:30

Stage 7

Responsible AI Architecture with Zero Trust Agents

Ashok Prakash

Staff ML Engineer at Apple

Ashok Prakash
Open session

World Congress 2026 North America

September 24, 2026 · 12:15–12:45

Stage 6

AI vs. AI: Defending the open source supply chain with agentic workflows

Manfred Moser

Senior Principal DevRel Engineer at Chainguard

Manfred Moser
Open session

World Congress 2026 North America

September 25, 2026 · 15:30–16:00

Mainstage

One Boundary for the Agentic Era

Mark Lechner

Chief Information Security Officer of Docker

Mark Lechner