Episode Summary
Executive Summary: The episode follows security researcher Jags as he reverse-engineers Fast16, a mysterious NSA-listed malware line that ultimately appears to be a sophisticated cyber weapon built to sabotage Iranian nuclear calculations. With help from AI and colleague Vitali Kamluk, he uncovers malware designed to silently alter physics simulations, likely corrupting warhead-design math and destabilizing trust in computers themselves.
Main Topics: The hidden cyber war with Iran (Priority: 5/5): The episode frames U.S.-Iran conflict as having an almost invisible cyber-sabotage front, distinct from bombs and blockades, where malware is used to disrupt nuclear development. Jags as a cyber paleontologist (Priority: 4/5): Juan Andres Guerrero-Saade (Jags) is introduced as a researcher who digs through old malware artifacts to reconstruct attacks and understand how top hackers operated. The mystery of Fast16 (Priority: 5/5): Fast16 appears on an NSA malware list with the cryptic note 'nothing to see here, carry on,' prompting Jags to investigate what it was, who made it, and what it targeted. AI-assisted reverse engineering (Priority: 4/5): Jags and Vitali use AI tools to double-check reverse engineering work, which helps confirm that Fast16 was real, highly specialized, and difficult to analyze. Fast16's target: corrupting nuclear math (Priority: 5/5): The malware is shown to manipulate high-precision calculations in LS-Dyna, a physics modeling tool, likely to distort simulations relevant to nuclear weapon design. Epistemological warfare and human trust (Priority: 5/5): The episode argues that Fast16 was not just technical sabotage but an attack on certainty itself, making scientists doubt their instruments, results, and understanding of reality. Limits of attribution and historical certainty (Priority: 3/5): Even after the analysis, the exact authors and target remain partly unconfirmed, underscoring the secrecy and ambiguity of cyber operations years after they occur.
Key Arguments: Fast16 was not ordinary malware; it was a specialized cyber weapon designed to lie dormant until it detected specific scientific software and test conditions. The malware likely targeted LS-Dyna, a physics simulation tool used for high-stakes engineering and, in this context, nuclear warhead-related calculations. By altering only certain bytes and preserving the appearance of normal results, Fast16 could make scientists believe their work was flawed rather than suspect sabotage. The attack’s sophistication suggests deep knowledge of both malware engineering and nuclear physics, implying a highly capable state-backed operation. Cyber sabotage can alter decision-making and reality-testing, not just systems—creating doubt, delay, and confusion among expert users. The discovery matters because Stuxnet-like operations may have set a precedent for cyber weapons aimed at real-world infrastructure and scientific process. AI helped validate the reverse-engineering work by independently confirming patterns humans suspected, but it did not eliminate uncertainty or answer attribution questions.
Data Points: Ceasefire duration: 60 days - The intro references a proposed 60-day ceasefire agreement between the U.S. and Iran. Era of malware: mid-2000s - Stuxnet and Fast16 are placed in the same timeframe of cyber operations targeting Iran. Centrifuge damage: a fifth - Stuxnet is described as reportedly destroying about 20% of Iran’s centrifuges. Time difference: 12-hour - Jags and Vitali work across a 12-hour time difference while investigating Fast16. Software age: 21 years ago - Jags notes that the target software they needed was from more than two decades earlier. Research timeline: weeks, months - Jags describes spending many weeks and months trying to reverse engineer Fast16. AI validation depth: double and triple check - Vitali used AI models to verify his reverse engineering findings.
Pivotal Quotes: "Nothing to see here, carry on." — NSA malware list instruction: The cryptic description attached to Fast16 that made Jags obsess over the malware. "This is Stuxnet-like." — Vitali Kamluk: Vitali’s reaction after reverse engineering Fast16 and seeing its similarities to the Stuxnet era. "It was basically telling the computer two plus two equals five." — Jags: A plain-language description of Fast16’s core sabotage mechanism: corrupting numerical calculations while appearing normal.
Implications: The episode suggests cyber warfare has matured into a form of epistemic sabotage: not just breaking machines, but undermining trust in scientific results and reality itself. For security teams, it shows why old malware still matters, and how AI may help reveal hidden state-level operations.
About Planet Money
Wanna see a trick? Give us any topic and we can tie it back to the economy. At Planet Money, we explore the forces that shape our lives and bring you along for the ride. Don't just understand the economy – understand the world.Wanna go deeper? Subscribe to Planet Money+ and get sponsor-free episodes of Planet Money, The Indicator, and Planet Money Summer School. Plus access to bonus content. It's a new way to support the show you love. Learn more at plus.npr.org/planetmoney