THE L0PHT

A handful of Boston hackers rented a loft, filled it with junked hardware, and spent the 1990s writing the advisories that embarrassed every software vendor in the country. Then, on May 19, 1998, all seven of them sat down in front of a U.S. Senate committee — under their handles — and told a room of senators they could make the internet unusable for the entire nation in about half an hour. It was the moment the underground walked into Washington in a suit. Two years later they walked back out with venture capital, folded into a consultancy called @stake, and became the exact thing a later generation of hackers would spit the word "sellout" at.

That's correct. Actually one of us, with just a few packets.

Peiter "Mudge" Zatko, answering Sen. Fred Thompson's question — "you think that within 30 minutes the seven of you could make the internet unusable for the entire nation, is that correct?" — before the Senate Committee on Governmental Affairs, May 19, 1998

WHO
The L0pht (L0pht Heavy Industries) — hacker collective and hackerspace, founded ~1992 in the Boston area FACT
THE CREW
Seven who testified: Mudge (Peiter Zatko, see the Mudge file), Weld Pond (Chris Wysopal), Kingpin (Joe Grand), Space Rogue (Cris Thomas), plus Brian Oblivion, John Tan, and Stefan von Neumann; Dildog (Christien Rioux) among the wider roster FACT
THE WORK
Vendor advisories, a "hacker think tank" reputation, and L0phtCrack — the landmark Windows NT password auditor/cracker they built and sold
THE DRAMA
The May 19, 1998 Senate testimony under their handles — "take down the internet in 30 minutes" — then the January 2000 merger into the consultancy @stake, branded by the antisec bloc as the original sellout
STATUS
WENT LEGIT — absorbed into @stake (2000), later swallowed by Symantec (2004); its alumni now run security firms, brief presidents, and testify to Congress for a living

This file is not an accusation; the L0pht broke no story it did not also try to fix, and the "sellout" charge against it is a verdict the underground handed down, not one the paperwork supports. The through-line is a single arc the whole scene would argue about for the next twenty years: seven hackers who did the responsible thing — warned the vendors, warned the Senate, took the paycheck — and got called traitors for it by the very movement they made possible. The drama is the gap between "professionalized" and "sold out," and both words describe the same January.

the drama timeline

ACT I — THE LOFT (1992–1997)

A rented Boston loft, a pile of salvaged hardware, and a crew that decided the fastest way to fix broken software was to humiliate the people who shipped it.

  1. ~1992

    A loft in Boston

    The L0pht forms as a shared workspace — one of the archetypal hackerspaces — in the Boston area, a place to store gear that wouldn't fit in members' apartments and to reverse-engineer whatever came through the door. It grows into a collective that styles itself, only half-ironically, as a "hacker think tank."

  2. 1997

    L0phtCrack ships

    The L0pht releases L0phtCrack, a tool that audits — and cracks — Windows NT password hashes. The command-line version circulates free; the polished GUI version sells commercially. It becomes the landmark password auditor of its era, proof that "hobby crew" and "shipping a real product" were not mutually exclusive.

  3. 1994–98

    The advisory machine

    The L0pht turns bug-hunting into a discipline: a steady stream of security advisories aimed at vendors who would rather not hear them, and a public argument that shipping broken software was the real crime — a stance that made the crew central to the era's disclosure wars.

ACT II — THE HILL (1998)

The scene's most famous field trip: seven hackers, seven handles, one Senate committee, and a sentence that has been quoted at every security conference since.

  1. MAY 19, 1998

    Seven handles testify

    All seven L0pht members — Mudge, Weld Pond, Kingpin, Space Rogue, Brian Oblivion, John Tan, and Stefan von Neumann — testify before the Senate Committee on Governmental Affairs on "Weak Computer Security in Government," seated behind nameplates bearing their handles. It is the first time hackers appear before a U.S. legislative body under their pseudonyms. Sen. Fred Thompson asks whether "within 30 minutes the seven of you could make the internet unusable for the entire nation." Mudge: "That's correct. Actually one of us, with just a few packets." The specific weakness, Space Rogue later explained, was a cascading flaw in BGP, the internet's routing protocol — and the L0pht said it had quietly warned the router makers first.

    The full C-SPAN feed of the May 19, 1998 hearing, uploaded by L0pht member Joe Grand ("Kingpin"). The moment the underground put on a jacket and testified — nameplates and all.
  2. 1998–99

    From menace to fixture

    The testimony makes the L0pht famous well beyond the scene — the crew that told the Senate the internet was held together with tape. Mudge in particular becomes the public face of a new idea: that hackers were the early-warning system nobody wanted to fund. The path from crew to contractor is now visibly open (see the scene timeline).

ACT III — THE @STAKE DEAL (1999–2000)

Venture money finds the loft. The think tank becomes a company. Depending on who's telling it, this is either the scene growing up or the scene cashing out.

  1. JAN 2000

    L0pht merges into @stake

    The L0pht merges into @stake, a newly funded Cambridge security consultancy, in a deal announced in January 2000. @stake arrives with roughly $10 million in venture capital and a promise that the L0pht can keep doing its research — now on a payroll. Mudge becomes VP of R&D and later chief scientist. The most famous underground crew in America is now a line item on a corporate org chart.

  2. 2000

    The FAQ nobody in the underground accepted

    Anticipating the backlash, the L0pht publishes a merger FAQ arguing the deal lets it do the same work with better resources and no more day jobs. To the professionalizing wing of security, this is the obvious, adult move. To the underground, a public-service crew taking VC money and a consultancy nameplate is the first crack in the wall.

ACT IV — THE ORIGINAL SIN (2001–)

A few years later a new movement gives the @stake deal a name, uses it as a template, and declares open season on everyone who followed it.

  1. 2001–05

    "Sellout" gets a poster child

    The antisecurity movement — the zines and crews behind "NO MERCY FOR WHITEHATS" — brands the exact move the L0pht made, underground talent taking corporate and federal paychecks, as the original sin of the scene. @stake and the L0pht become the standing example in a thesis that "going legit" is a betrayal. Figures associated with the bloc, among them Gweeds, push the "sellout = enabler" line hardest.

  2. 2004–

    Symantec, then everywhere

    @stake is acquired by Symantec in 2004, closing the loop from loft to multinational. But the L0pht's real legacy is its diaspora: Mudge to DARPA, Google, and Twitter; Wysopal to found Veracode; Grand to hardware hacking and TV; Thomas to a career of security strategy. The crew that testified in 1998 didn't disappear — it staffed the industry.

both sides, on the record

They sold out the underground: to the antisecurity bloc, the @stake merger was the moment the scene's most credible crew converted reputation earned on free advisories into venture equity and a consultancy nameplate. Once the L0pht made "hacker → corporate payroll" respectable, the pipeline from the underground to federal and corporate contracts became the industry's default — and, in their reading, its capture [6].

The theater outran the substance: critics note that "take down the internet in 30 minutes" was a headline-grade claim, and that trading on it to raise $10 million looked, from the outside, like exactly the kind of hype the L0pht spent the 1990s mocking in vendors.

They went legit — and that was the point: the L0pht's whole argument was that security work deserved to be a profession, not a hobby squeezed around day jobs. Taking funding to keep doing the same research, full-time, is the mature outcome of the case they'd been making to the Senate. Nothing in the record shows the work got worse [7].

The warning was real and responsible: the 1998 testimony was not a threat — the L0pht said it had warned the router vendors about the BGP flaw before it went public, and used the Senate stage to demand that anyone start listening. That is the textbook responsible-disclosure posture, performed at maximum volume [5].

"Sellout" is a verdict, not a fact: the charge belongs to a movement with its own politics, and it flattens a group whose alumni went on to build defensive tools, run corporate security, and testify again. Calling that betrayal says more about the accuser's purity test than about the L0pht [6].

YOU DECIDE

The facts are not in dispute: the L0pht built real tools, gave a genuinely alarming and genuinely responsible warning to the Senate, and then took venture money and became a company. Whether that last step is "professionalizing" or "selling out" is the whole argument — and it is an argument about values, not events. The antisec bloc made the L0pht the villain of a story about purity; the industry made it a founding legend of a story about growing up. Strip both myths away and you are left with seven people who were right about the internet, said so under oath, and then went to work fixing it for money.

The archive does not deify. The archive keeps the testimony — and the merger FAQ.

evidence locker

PRIMARY / REFERENCE

  1. Wikipedia — L0pht ATTRIBUTED — founding (~1992, Boston area), the hackerspace and "think tank" identity, the roster and handles, the May 19, 1998 Senate testimony, and the January 2000 @stake merger. en.wikipedia.org/wiki/L0pht 200
  2. Wikipedia — L0phtCrack ATTRIBUTED — the Windows NT password auditor/cracker, its free command-line and commercial GUI versions, and its later history. en.wikipedia.org/wiki/L0phtCrack 200
  3. Wikipedia — Peiter Zatko ATTRIBUTED — Mudge's identity, his role among the seven who testified in 1998, and his @stake / DARPA / Google / Twitter career. en.wikipedia.org/wiki/Peiter_Zatko 200
  4. National Security Archive — "When Hackers Went to the Hill: Revisiting the L0pht Hearings of 1998" PRIMARY — the hearing record and documents for the May 19, 1998 Senate Committee on Governmental Affairs testimony. nsarchive.gwu.edu/…/revisiting-l0pht-hearings-1998 200
  5. Daily Dot / Rep. Ted Lieu — "I spoke with a hacker who could have taken down the internet in 30 minutes" PRIMARY QUOTE — the verbatim Thompson/Mudge exchange ("just a few packets"), Space Rogue's BGP explanation and "probably less than 30 minutes," and that the L0pht warned the router vendors first. (Live but bot-blocked to automated fetchers — HTTP 403 to WebFetch, 200 to a browser user-agent.) lieu.house.gov/…/taken-down-internet-30-minutes 200 (UA) / 403 (bot)

THE @STAKE DEAL

  1. Computerworld — "Hacker think tank merges with security start-up" FACT — contemporaneous report of the January 2000 L0pht/@stake merger, the ~$10M in venture funding, and the promise the research would continue. computerworld.com/…/hacker-think-tank-merges-with-security-start-up.html 200
  2. attrition.org — "L0pht in Transition" PRIMARY — contemporaneous archive of the merger's reception, including the underground's own reaction to the @stake deal and the "going legit vs. selling out" argument. attrition.org/misc/ee/l0phtintransition.html 200

CONTEXT & CROSS-LINKS

  1. YouTube — L0pht Senate testimony, full C-SPAN feed (uploaded by Joe Grand / "Kingpin") PRIMARY — the complete May 19, 1998 hearing, posted by a member of the crew. oEmbed verified (HTTP 200). youtube.com/watch?v=VVJldn_MmMY oEmbed 200
  2. troll.fan — Peiter "Mudge" Zatko CROSS-LINK — the L0pht's most public alumnus, from the loft to DARPA and the Twitter whistleblower stand. troll.fan/dossiers/peter-zatko.html
  3. troll.fan — The Antisecurity Movement CROSS-LINK — the bloc that branded the @stake move the original sellout. troll.fan/dossiers/antisecurity-movement.html
  4. troll.fan — Disclosure Wars CROSS-LINK — the vendor-vs-hacker fight over how bugs should be told, where the L0pht's advisory machine lived. troll.fan/dossiers/disclosure-wars.html
The standard. The L0pht is a documented collective of public standing; its founding, its L0phtCrack tool, the May 19, 1998 Senate testimony, and the January 2000 @stake merger are matters of record, sourced above to reference works, contemporaneous press, and a primary hearing record. The "30 minutes" quote is given verbatim and attributed. Real names are used only for members who have publicly self-identified with their handles (Zatko, Wysopal, Grand, Thomas, Rioux); members who have not are kept handle-only, and no legal name is asserted for them. The "sellout" reading of the @stake deal is attributed to the antisecurity bloc and set against the "going legit" reading at full strength — it is not this site's verdict. If a line here couldn't survive scrutiny, it wouldn't be on the page.