Leadership1 publisher2 min readPublished
AI lowers the skill floor for the 30-line attack that wrecked a 27-ton generator
Vox revisits the Idaho National Laboratory's Aurora Generator Test, where 30 lines of code destroyed a diesel generator, and argues that human-directed AI hacking of industrial equipment is the risk a board can actually inventory.
The Board Room · Leadership desk

What happened
- Researchers at the Idaho National Laboratory used 30 lines of code to corrupt a diesel generator's safeguards and flip switches that left it out of sync with the rest of the power grid.
- Electrical utility executives and energy department officials watched from a nearby room as the 27-ton generator jolted violently and sputtered dark smoke while its rubber innards tore themselves apart.
- Not long after the test, the federal government mandated that electrical utilities engage in basic cybersecurity hygiene.
- Vox reports that much of America's critical infrastructure, including gas pipelines, water desalination plants and cargo terminals, is still unprepared for even conventional cyber attacks.
- Attacks of this kind have stayed exceedingly rare in part because they are optimized for disruption instead of financial gain, which has made them unappealing to most criminal hackers.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- contradiction Vox also reports that China, Iran and Russia are already inside many US infrastructure systems and have not made much of a ruckus there, so capability has not been the binding constraint on physical attacks; motive has.
- exposure Vox's account puts a local reservoir or the power grid in theoretical reach of people who cannot write code. Small water and power operators without security staff sit inside that reachable set.
- decision The extinction talk from AI executives this week gives a board an unauditable AI risk line. An equipment inventory competes for the same paragraph in the register and the same hour of the same meeting.
Cheaper code enlarges the group that can attempt an Aurora-style attack without enlarging the group that wants a generator destroyed. The reason Vox gives for the rarity of these attacks, that they are optimized for disruption instead of financial gain and so hold little appeal for criminal hackers, is untouched by how cheap the code gets [8].
"Before, you needed to have highly skilled technical expertise," Alvaro Cardenas, a computer science professor at UC Santa Cruz, said about pulling off a real-life version of the Idaho test. "And now, you just have to have a general idea of what's possible" [9]. That is a claim about who can try, and Cardenas offers it as a researcher's judgement.
Andy Bochman, an infrastructure resilience expert at West Yost, made the volume point about AI agents: "they don't sleep; they don't get tired; and they don't get sick" [10]. Tireless probing bears mostly on the economics of reconnaissance.
The demonstration is nearly two decades old, and thirty lines of code were never expensive [1]. Cardenas's point is the expertise needed to aim them [9].
The board-deck version of AI risk is a paragraph on model safety plus a monitoring commitment. It is incomplete because nobody can check it against an asset. The checkable version names the machine, the controller whose safeguards can be corrupted until the machine runs out of sync with the system it feeds, and the routes by which someone outside reaches that controller [2]. This quarter, that work is an inventory. Whether motive spreads to match the cheaper capability is a question for the decade.
The man who ran the original test described the finding in physical terms. "The implication was that with just a few lines of code, you can create conditions that were physically going to be very damaging to the machines we rely on," lead researcher Michael Assante told the journalist Andy Greenberg for his book Sandworm [4]. "I had a very real pit in my stomach. It was like a glimpse of the future," Assante said [5].
What to watch
- Whether any federal requirement for basic cyber hygiene is extended beyond electrical utilities to pipelines, desalination plants or cargo terminals.
- A publicly attributed case of AI-assisted code causing physical damage to industrial equipment. Such a case would move this from expert judgement to incident data.
- Whether the state actors already inside US systems change from quiet presence to destructive action.