Chainguard co-founder and CTO Matt Moore built a fix to the broken open source trust model
In this episode
In 2020, the SolarWinds attack exposed the vulnerability of supply chains worldwide, a problem this episode’s guest, Matt Moore, had already been working to solve for years. In 2021, he co-founded Chainguard to protect supply chains from future breaches. His conversation with 1Password CTO Nancy Wang and Google Gemini’s Dev Tagare covers why ending long-lived credentials is “one of [his] hills to die on” and how AI agents have complicated supply chain security, with a live demo on how standard tools overlook many vulnerabilities.
“If you look at what a lot of folks are doing as part of this malware, it's stealing credentials. Why? Because credentials let you launch the next wave of these things. [...] It feels borderline negligent that so many long-lived credential leaks are leading to the kinds of issues that we have.” - Matt Moore
Old defenses don’t work against new threats
AI is shrinking the window for patching, as AI-powered attacks accelerate and demand for pre‑alpha code grows
Hacks usually target the delivery pipeline rather than the source code
Net-new, AI agent-written code creates more burden for teams to maintain and secure
Most breaches exploit long‑lived credentials
Audited least privilege flips the security model from restricting identities to guarding sensitive resources
Also available in audio format on the following platforms: Apple Podcasts, Spotify
Matt Moore
Matt Moore is co-founder and Chief Technology Officer of Chainguard, where he drives the company’s technical vision and application of AI to secure the software supply chain. Before Chainguard, Matt started and maintained a number of popular open source projects and led the development of several Google Cloud products, including gcr.io, Container Analysis, and Cloud Run. Prior to Google, Matt worked on compiler optimization at Microsoft. He holds a Bachelor of Science in Computer Science from Carnegie Mellon University.
Matt is active in the developer community and can be found on LinkedIn and X.


Get the episode transcript
More episodes

OpenAI Agent Security Lead Fotis Chantzis discusses one of the biggest unsolved problems in AI

Vercel Chief Product Officer Tom Occhino reflects on React and how AI transforms software creation

Cursor Head of Security Travis McPeak considers how to secure agents without slowing work

Braintrust founder and CEO Ankur Goyal examines why AI learning happens after launch

Mercor co-founder and co-CEO Adarsh Hiremath addresses the AI onboarding problem

Temporal co-founder and CTO Maxim Fateev uncovers the distributed systems hiding behind AI agents

Cognition President of New Enterprise Jeff Wang envisions a future where AI agents prove their own work
