Skip to content

Peiter "Mudge" Zatko: The Hacker Who Warned Washington

Abstract

In May 1998, seven young hackers from a Boston collective called L0pht sat down before a US Senate committee (using only their handles) and told the United States government that they could take down the internet in 30 minutes. The most articulate of them was Peiter Zatko, known as “Mudge.” That hearing is one of the founding moments of public cybersecurity policy. Over the next quarter-century Mudge traveled the full length of the field’s respectability spectrum: from underground hacker, to author of seminal buffer-overflow and password-cracking research, to a program manager at DARPA funding the next generation of security work, to executive roles at Google and Stripe, and finally to a whistleblower whose 2022 complaint about security failures at Twitter detonated in the middle of Elon Musk’s takeover battle. Mudge is the figure who carried the hacker’s adversarial mindset out of the underground and installed it, again and again, inside the institutions that most needed it.

L0pht Heavy Industries

In the early-to-mid 1990s, a loose group of Boston-area hackers turned a rented loft (the “L0pht,” with a zero) into one of the most influential hacker spaces in the world. L0pht Heavy Industries was a hybrid the era had no name for: part clubhouse, part research lab, part conscience of an industry that did not yet take security seriously. Its members (Mudge, Weld Pond, Brian Oblivion, Kingpin, Space Rogue, Stefan von Neumann, and John Tan) bought up surplus equipment, reverse-engineered commercial software, and published their findings publicly at a time when vendors preferred that vulnerabilities stay quiet.

Mudge’s individual contributions were foundational. His 1995 write-up “How to Write Buffer Overflows” was one of the early documents that turned a obscure memory bug into a widely understood and weaponizable class of vulnerability, the technique that underlay a generation of remote exploits (and the Morris Worm before it). He was the original author of L0phtCrack, the password-auditing tool that exposed how weakly Windows protected its password hashes and that became a standard utility for administrators and attackers alike. L0pht’s posture (find the flaws, prove they’re real, tell the public) was an early and influential argument for full disclosure in the long debate over how to handle vulnerabilities.

“We Could Take Down the Internet in 30 Minutes”

On May 19, 1998, all seven L0pht members testified before the Senate Committee on Governmental Affairs, chaired by Fred Thompson, on the security of federal computer systems. They appeared under their hacker handles, a deliberate, theatrical assertion that the underground deserved a seat at the table. Mudge delivered the line the hearing is remembered for: that the group could render the internet unusable nationwide in roughly half an hour by exploiting weaknesses in BGP, the routing protocol that holds the network together.

Why the 1998 Testimony Mattered

The hearing was the moment the US government heard, on the record and in plain language, that the infrastructure it increasingly depended on was fundamentally insecure, and heard it not from contractors with something to sell but from young hackers with nothing to gain by lying. The BGP claim was not bravado; the routing system genuinely lacked authentication, and route hijacks remain a live problem decades later. L0pht’s appearance helped legitimize the idea that adversarial outsiders were a necessary part of national security, and it prefigured the entire later apparatus of bug bounties, coordinated disclosure, and government red-teaming.

In 1999, L0pht merged into the security consultancy @stake, going commercial; Mudge became a vice president and chief scientist. The transition mirrored the broader professionalization of hacking in the late 1990s, the same migration from outlaw to consultant traced by figures like Kevin Mitnick and Kevin Poulsen.

Inside the Institutions

Mudge’s later career is a study in how completely the hacker mindset was absorbed by the establishment. After a stint at BBN Technologies, he joined DARPA around 2010 as a program manager. There he created Cyber Fast Track, a program that pushed small, fast grants to independent security researchers and hackerspaces, deliberately routing government money to exactly the kind of underground talent L0pht had represented, on timescales the normal contracting bureaucracy could never match. He then moved to Google’s Advanced Technology and Projects (ATAP) group and later to the payments company Stripe as head of security. Along the way he worked on initiatives to build an independent “underwriters’ lab” for software security, an attempt to give buyers objective measures of how secure a product actually was.

The Twitter Whistleblower

In November 2020, Twitter CEO Jack Dorsey hired Mudge as the company’s head of security, a high-profile attempt to put a respected adversary in charge of defending a platform with chronic security problems. The arrangement ended badly: Mudge was fired in January 2022. In August 2022 he filed an explosive whistleblower complaint with US regulators and Congress, alleging that Twitter had grave, unaddressed security deficiencies, too many employees with access to sensitive production systems, misrepresentations to regulators and its own board, and a lack of basic controls, and that executives had downplayed the prevalence of spam and bot accounts.

The timing was extraordinary. Mudge’s disclosures landed in the middle of Elon Musk’s contentious attempt to back out of his agreement to buy Twitter, a fight in which the number of bot accounts was the central legal issue. Mudge’s complaint instantly became ammunition, and he was subpoenaed to testify before the Senate Judiciary Committee on September 13, 2022 about the platform’s security failures. He had, once again, walked into a government hearing to tell the public that a critical piece of internet infrastructure was not as safe as its owners claimed, twenty-four years after the first time.

He later returned to government, rejoining DARPA in a senior role in 2024.

Legacy: The Adversary as Institution

Mudge belongs in this section not as a criminal (his record is essentially that of a white-hat throughout) but as a provocateur in the precise sense the encyclopedia uses: someone who changed the trajectory and public perception of computing by repeatedly confronting power with uncomfortable truths. His through-line is consistent across four decades: systems that people trust are usually less secure than claimed, and the people best positioned to prove it are the ones who think like attackers. He helped make that argument respectable, turning the hacker from a figure to be prosecuted into a figure to be consulted, funded, and, when necessary, believed when he blew the whistle.

His impact runs along the policy, security-culture, and technology axes: the 1998 testimony seeded public cybersecurity policy, L0phtCrack and his buffer-overflow work shaped the technical practice of the field, and Cyber Fast Track institutionalized the underground’s value to the state. Of all the people on this page, Mudge is the one who most fully demonstrates that the line between the outlaw and the establishment was never about skill, only about which side of the table you chose to sit on.


📚 Sources