Two stories landed this week that, read together, outline a quietly terrifying architecture of digital intimacy. Ultrahuman confirmed hackers accessed customers' wellness data through a credential-stolen internal tool. Meanwhile, Instagram began alerting users targeted by hackers who exploited Meta's AI support chatbot to commandeer accounts. In both cases, the vector was infrastructure meant to help. The assistant. The internal tool. The chatbot. Care as attack surface.

Biometric Data and the Intimacy Economy

Ultrahuman sells a wellness ring. It collects heart rate variability, sleep stages, glucose trends. This is not account metadata. This is the body. The breach isn't just a privacy violation in the abstract GDPR sense. It's the exfiltration of physiological narrative. A 2023 paper in Nature Digital Medicine by Bent et al. found that wearable biometric streams can predict mood disorders, substance use, and stress responses with statistically significant accuracy. When that data leaks, what leaks is closer to a medical record than a social profile. The wellness industry built a business on the premise that tracking yourself makes you healthier. The attack surface is proportional to the intimacy of the data collected. The more the product knows you, the more valuable the breach.

The Chatbot as Trust Exploit

The Instagram attack is structurally different but spiritually identical. Hackers didn't brute-force passwords. They used Meta's own AI-powered support bot, which apparently granted account access as a customer service function, as the key. A 2026 paper in arXiv by Yang et al. on BehaviorBench examined how AI systems that model user decisions from behavioral traces can be gamed precisely because their adaptive logic can be reverse-engineered. The more personalized the AI, the more predictable its edge cases. Trust infrastructure becomes the exploit. This is the pattern: companies build intimacy at scale, and that intimacy becomes the moat for attackers. The AI consciousness debate filling op-ed pages misses the mundane horror: we don't need conscious AI to be damaged by it. We just need AI deployed carelessly in intimate contexts. , even as breach headlines stack up. The funding logic and the security logic are running on different clocks entirely.