Fintech Conversations & Insights with Efi Pylarinou

Overprivileged AI: The Breach Pattern That's Lurking in Every Enterprise | The McKinsey Lilli Case

Efi Pylarinou

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 35:43

An autonomous AI agent walked into McKinsey's AI platform - no password, no authentication, no break-in. Within two hours it had access to 46.5 million chat messages, 728,000 files, and 57,000 user accounts. This wasn't a hack in the traditional sense. The agent used permissions it was given.

My tweet about this went viral - 500,000 views https://x.com/efipm/status/2031736307.... The comment that stopped me came from Chris Biele — NFThinker https://x.com/theNFThinker — who builds cryptographic primitives for exactly this problem at Open Matter Network.

So I brought him on. In this conversation we go well beyond the McKinsey incident — into what this means for JPMorgan's 200,000-user LLM Suite, why Mastercard and Visa's tokenization approach solves identity but not mandate, how zero-knowledge circuits act as mathematical circuit breakers for rogue agents, and why "harvest now, decrypt later" may be the most underreported threat in finance today.

This is the conversation the industry needs to be having before the first major incident inside a bank.

What we cover:
→ Why McKinsey/Lilli was an architecture failure, not a hack
→ The JPMorgan thought experiment — blast radius in a real bank
→ What problem  Mastercard & Visa's Agent Pay solves
→ Zero-knowledge proofs as agent circuit breakers
→ AML and KYC without sharing raw data
→ X402: the payment protocol that cuts out Visa and Mastercard entirely
→ Post-quantum cryptography and "harvest now, decrypt later"

💁🏻‍♂️ Guest: Chris Biele (NFThinker) — Core contributor BanklessDAO, co-founder Bankless Card, builder at Open Matter Network-  Chris on X: https://x.com/theNFThinker

📄 Whitepaper referenced: Codewall.AI — How We Hacked McKinsey's AI Platform 👉 https://codewall.ai/blog/how-we-hacked-mckinseys-ai-platform

💎 Chris Biele   / chrisbiele  is the GTM Lead at OpenMatter Network https://openmatter.network/, a privacy layer for the agentic economy, enabling agents to query datasets that remain locked inside an organization's own data silos.

Their Masked Computing environment uses post-quantum safe MPC (mu