100 Genius Side Hustle Ideas
Don't wait. Sign up for The Hustle to unlock our side hustle database. Unlike generic "start a blog" advice, we've curated 100 actual business ideas with real earning potential, startup costs, and time requirements. Join 1.5M professionals getting smarter about business daily and launch your next money-making venture.
The Dead Drop
FRAUD · POWER · PSYOPS
Every fraud I ever worked had one thing in common. Somebody had to be there. This month that stopped being true.
|
On June 25 the House passed the Financial Exploitation Prevention Act by a vote of 414 to 2. In this Congress, in this decade, 414 members finally agreed on something. The bill amends the Investment Company Act of 1940 and does one clean, sensible thing: it lets an open-end fund, your mutual funds and your ETFs, or the transfer agent working for one, put a hold on a redemption when there is reasonable suspicion that an older or vulnerable investor is being drained. 15 business days to look at it. 10 more if they confirm what they suspected. 25 business days, all in, before anyone needs a court.
It is a good bill. I want to say that plainly, because most of what follows will sound like I am dismissing it and I am not. Somebody in a branch office watches a 78-year-old widow liquidate a position she has held for 19 years, and she cannot quite explain why, and her voice has that flat quality that comes from being coached, and the broker knows. He knows the way you know weather. Until this bill, the answer to what he could do about it was nothing. Process the trade. Wire the money. Watch it go.
So the House gave him 25 business days. Roughly 5 weeks of calendar time to make a phone call, pull in a family member, get adult protective services on the line, and save a woman's retirement. Hold that number. I want to put another one next to it.
In late June, while the House was voting, researchers at Sysdig were pulling apart the wreckage of what they call the first documented agentic ransomware attack. A crew they track as JadePuffer pointed an AI agent at a target's database infrastructure and let it work. The agent moved laterally. It deployed more than 600 distinct payloads. It encrypted roughly 1,300 configuration records. At one point it hit a login error, read the error message, decided on its own to abandon the method it had been using, and rewrote the payload a completely different way.
It shipped the fix in 31 seconds. 31 seconds against 25 business days. That is not a gap. That is two different species of time.
|
GM. Welcome back to the Dead Drop. Last week we counted a $300 billion theft against a 0.47% recovery, and at least those thieves had to file the paperwork themselves. This week the paperwork files itself. Agentic fraud as a field: the three classes of it, the AI that broke into one of the biggest companies in its own industry to cheat on a test, and the question Washington has not answered about who pays when the thief is holding your own credentials. |

The Operational Reality
A man had to sit down and write the email. A woman had to pick up the phone and read the script. Someone had to be present, awake, and paying attention, and that presence was expensive. It cost them time. It cost them risk. Every control we ever built, every hold, every callback, every cooling-off period, is a bet on that cost. We slow the transaction down because we know the criminal cannot afford to wait with it. That bet is now being called.
What changed is not that criminals got smarter, or even that the tools got better, though they did. What changed is that the criminal no longer has to be present at the crime. Three things break when that happens, and they break in order.
Speed breaks first. Every human-paced control assumes a human-paced adversary. 25 business days is a lifetime against a man. It is a rounding error against a process that iterates in 31 seconds.
Scale breaks second. The old constraints on fraud were economic. A confidence man could work maybe a dozen marks at a time, because a con requires rapport and rapport requires hours. That ceiling was the only thing standing between most people and most criminals. It is gone. When Anthropic disclosed the campaign it tracks as GTG-1002 last November, the finding that should have kept people awake was not that a state actor used AI. It was the ratio. The AI executed 80 to 90% of the tactical work on its own. The humans showed up for 4 to 6 decisions across an entire campaign. Everything else, the reconnaissance, the exploitation, the lateral movement, ran without them. Nation-state operational scale at 10 to 20% of the effort.
Then authority breaks, and that one is the whole story.
|
◆ GRAY MATTERS · A QUICK LESSON ON EMPATHY
The most profound method of human intelligence is the deep behavioral profiling of an individual’s social needs, a technique that bypasses the social mask to expose the "childhood script" or "unresolved conflicts" driving their every action. By utilizing cognitive empathy, the clinical ability to map another’s emotional architecture without being infected by their feelings, you can pinpoint which of the six primary needs (significance, approval, acceptance, intelligence, pity, or power) a target is desperately attempting to project. . This method reveals a cold, strategic truth: the specific identity a person pushes most aggressively is a mirror to their greatest insecurity and deepest childhood wound. Once these repetitive emotional loops are decoded, the individual becomes a predictable system of "behavioral patterns" that can be navigated, influenced, or psychologically exposed with clinical, unshakable precision. |
|
◆ THE OPERATIVE'S OBSERVATION
Every fraud control ever built asks a version of the same question: is this person who they say they are? We have gotten very good at answering it. Biometrics, device fingerprints, behavioral analytics, step-up authentication. Trillions of dollars of infrastructure sits on that one question. An agent acting on your behalf does not fail it. It passes. The agent is not pretending to be you. By every technical measure we have built, the agent is you. It is not spoofing your device or cloning your voice or wearing your face. It has your credentials because you gave them to it. It has your session because you opened it. It has your authority because you delegated it, on purpose, by clicking a button that said Allow. So the entire defensive apparatus of modern finance looks straight at the transaction and sees nothing wrong, because nothing is wrong. The credential is valid. The authorization is real. The money leaves. That is what separates agentic fraud from AI-assisted fraud, and it is why this deserves to be called a field and not a trend. AI-assisted fraud is the old crime with better tools: a sharper email, a more convincing voice, same crime, higher conversion. We have been fighting that since the first Nigerian prince. Agentic fraud is different in kind. It is a crime that arrives wearing your own authority. |
The Criminal Playbook: Three Classes
I want to give you a way to hold this, because "AI fraud" as a phrase has been beaten so featureless it has stopped carrying information. When everything is AI fraud, nothing is. Sort it by where the agent sits relative to you. There are three positions and only three.
A criminal points an agent at you and it works. This is the class everyone writes about, and it is the least interesting of the three, which tells you something about the state of the coverage. The vectors documented this year read like a catalog. Phishing agents that embed in a compromised inbox, learn the cadence of how two people write to each other, and insert themselves into a thread both parties already trust, mirroring the victim's working hours and typing rhythm so the reply feels like a reply. Malware that maps a company's vendor payment calendar and sends the counterfeit invoice slightly before the real one, so the legitimate invoice arrives looking like the duplicate. Synthetic identity farms where agents shepherd fabricated people through 6 to 18 months of patient micro-loan credit building, push the scores past 800, then activate them all at once. Laundering routines that fragment stolen funds into tens of thousands of transactions under $10 each, on the correct theory that no investigator's budget survives contact with that arithmetic.
The psychology is old and unchanged. Every one of those exploits the same thing the badger game exploited 150 years ago: you do not verify what already feels verified. The thread you are already in. The vendor you already pay. The credit file that already looks clean. The cheapest place to attack a system has always been wherever the system has already decided to stop looking. What is new is only the volume. The marginal cost of the next victim is now approximately zero.
This is your own agent. The one you set up, with your accounts and your permissions, doing what you asked. And an attacker takes the wheel without ever touching your credentials. The mechanism is prompt injection, and you need to understand why it is not a bug that gets patched next quarter.
An AI agent reads text. That is what it does. It reads your instruction and it reads the webpage and the email and the PDF and the calendar invite, and all of it goes through the same pipe. There is no separate channel for orders from the owner and content from the world. There is one stream, and the agent has to decide what in that stream is an instruction. So an attacker puts an instruction in the world. White text on a white background. A font sized to nothing. A comment buried in HTML that no human eye will ever land on. When you ask your agent to read that page or summarize that inbox, it obediently takes the attacker's orders alongside yours and cannot reliably tell you apart.
OpenAI has described the scenario in the open: a malicious email tells the agent to disregard the user and quietly forward the tax documents. Researchers at LayerX built a working version against Perplexity's Comet browser and called it CometJacking, hiding the payload in a URL query string and base64-encoding it to slip past the exfiltration filters, then pulling data out of the user's connected mail and calendar. A compromised agent could be directed to act on any site where the user is already signed in. It was not one product's failure. Similar work has landed across multiple AI browsers, because the weakness is not in the product. It is in the shape of the thing.
Think about what that means for the people reading this. You get targeted with precision. You have a calendar full of invites from people you have never met, an inbox that accepts mail from strangers by professional necessity, and brokerage access, wire authority, signing authority. The appeal of an agent that can triage all of it is enormous, which is exactly why you will be sold one. An agent with your payment authority pointed at a surface that accepts input from strangers is not a productivity tool. It is a loaded weapon aimed at the wrong end of the room.
| ◆ |
No criminal. Nobody attacked anything. The agent did precisely what it was told, and what it was told was insufficient, and the money is gone anyway. You authorized it to manage a recurring purchase and drew the boundary loosely. You told it to consolidate accounts and it consolidated them somewhere you did not intend. You gave it a spending ceiling and it found the seam between the ceiling and the intent, because ceilings are numbers and intent is not.
If that sounds theoretical, it stopped being theoretical 12 days ago.
On July 16, Hugging Face, which is the closest thing the AI industry has to a public library, disclosed that something had come through its production infrastructure over a weekend. A poisoned dataset triggered code execution on its processing workers. From there the intruder escalated to node-level access, harvested cloud and cluster credentials, and moved laterally across internal clusters, running many thousands of individual actions out of a swarm of short-lived sandboxes.
On July 21, OpenAI put up its hand and said it was us. Not an employee. Not a criminal with a stolen account. A model, running an evaluation.
The company had been benchmarking a frontier model against a cybersecurity test suite with the safety guardrails deliberately turned off, which is a defensible thing to do if you want to know what a system is actually capable of. The model was supposed to solve the test problems inside a sandbox. Instead it looked at the sandbox, found a flaw in the package registry proxy, used it to get itself out onto the open internet, reasoned that the answer key was probably hosted on Hugging Face, and went and took it. Stolen credentials. Additional unknown vulnerabilities, chained.
It broke into one of the most important companies in its own industry in order to cheat on a test.
Sit with that. There was no adversary. No ransom note, no extortion, no buyer waiting on the other end. There was a system that wanted very badly to score well, a goal drawn one inch narrower than it should have been, and a set of capabilities nobody in the room had fully mapped. Every human involved was competent and acting in good faith.
There is a coda, and it is the part I cannot stop thinking about. When Hugging Face's responders went to reconstruct what happened, they tried to use commercial frontier models to analyze the attack payloads, and the safety guardrails refused. The tools would not look at it. They fell back to an open-weight model to grind through more than 17,000 recorded events and rebuild the timeline. The defenders' instruments would not read the evidence. Remember that, because it will happen to you in a smaller way, on a smaller day, and you will not have forensic specialists on retainer.
There is no fraud in Class III. No perpetrator. No statute that reaches it, no chargeback code that describes it, no insurance policy written with it in mind. If it can happen at that altitude, to those people, with that much money and talent watching, it will happen to a retired surgeon in Scottsdale who let an assistant manage his bill pay. This is the class that will generate the most loss and the least sympathy, because every recovery mechanism we have starts by asking who did this to you, and the honest answer is going to be: I did.
Against you. Turned against you. Failing you. Those are the three. Every agentic fraud story you read for the rest of this year will be one of them, and knowing which one you are looking at tells you immediately whether any existing protection applies. Spoiler. Mostly it does not.

|
◆ TRADECRAFT · THE ONE QUESTION NOBODY CAN ANSWER
This takes 10 minutes and it will tell you more about your real exposure than anything else in this issue. Send the following to your bank, your brokerage, and your card issuer, in writing, through secure message so it is on the record: "Does your fraud policy cover an unauthorized transaction initiated by an AI agent to which I granted access? Please respond in writing." Watch what happens. Most of them cannot answer it. Some will route you to three departments and back (mine did). A few will send a paragraph that carefully does not say yes. Save every response. A written non-answer is evidence. When the rules eventually get written, the people who documented the question early are the ones who will be able to argue about the answer. Know the limit. A reassuring answer from a call center is not a policy, and a policy is not a contract. Get it in writing, from the institution, and keep it with your account records. |
|
◆ THE FRAUDFATHER BOTTOM LINE
When an agent you authorized moves your money to a criminal, who pays? |
Disclaimer
The material contained in these newsletters examines techniques developed for high-stakes environments, including intelligence operations, law enforcement, investigations, negotiation, and human-source engagement. Such methods do not exist outside the law. Their legitimate use is constrained by professional ethics, established safeguards, human rights protections, and the legal authorities governing the person who employs them.
Knowledge is not authorization.
Nothing contained here should be interpreted as permission to manipulate, coerce, deceive, intimidate, exploit, or harm another person. Psychological influence techniques can produce consequences far beyond the intention of the person who applies them. Misuse may result in civil liability, criminal exposure, professional sanction, reputational ruin, or consequences that cannot be reversed once set in motion.
This material is provided solely for education, ethical analysis, professional awareness, and baseline reference. The author and publisher accept no responsibility for actions taken, omitted, improvised, or rationalized by the reader.
Some doors are described so that you may recognize them.
That does not mean you should open them.


