"Protecting Developers from Mercenary Spyware Abuse" by Joan Arus // Ethereum Cypherpunk Congress 2
Ethereum Cypherpunk Congress·Fri, Jan 9, 2026, 12:00 AM
Ethereum Cypherpunk Congress by Web3Privacy Now is the world's largest cypherpunk and human rights event. 4500 people gathering in Buenos Aires to celebrate privacy with internet freedom leaders like Richard Stallman, Vitalik Buterin, Roger Dingledine, and Eva Galperin. Join us in building a free internet for all. Website: https://web3privacy.info/ Congress site: https://congress.web3privacy.info/
Transcript
[applause] I want to start with a question. Who within this space is currently building privacycentric protocols or censorship resistant tools? Okay, I see some friends there. Okay, cool. Nice.
So I wanna I have a bad news for you. You for this activity could become a target of one of the most advanced surveillance technologies that currently exists. My name is Joan Arus and I am the co-founder of Sentinel Alliance. Previously I was CEO of Aragon project the DAO framework that helps secure over 40 billion in digital assets and before that I co-ounded uh Bdoni which is a universally verifiable anonymous boarding system. I have spent the last few years of my life in building decentralized governance protocols and for that activity me and my team we became a threat to national security.
I'm here today to explain what what was the playbook that was used against us, why should you care, and what we're doing about it. In 2019 and for two years me and my team were spied, hacked and infiltrated with Pegasus and Candidu. For those who don't know these words, these are what the IND industry calls mercenary spyware software. This is more than a piece of software. It is a capability.
It is. It has the capability to turn your phone into a spy in your in your pocket. It can access to your private and encrypted messages, your photos, your documents, your passwords. It can even activate the microphone and camera and turn that phone into a buck in the room. And you may be thinking what triggered all this like what could possibly trigger all these uh all these surveillance?
Well, it seems that for the Spanish intelligence agencies, what we were building was considered an national uh security, a threat to national security. We were not like ah and we were deemed a threat to national security because the potential use of the tools we were building. So not past actions, potential future use by third parties. And what's what's most striking is we were writing self-s sovereign identity protocols, not even mixets, voting protocols. These tools, the governments that use them, they argue that they use them to to fight crime and terrorism.
But we see how that is not the case. And why should you care? because this represents an escalation of the tornado cash playbook. In that case, authorities required to physically to have physical access to the device. They got the messages and they use that information to build up the case.
With mercenaries power, any government in the wall can remotely target your device and get those conversations without even needing you needing without even needing to to to arrest you. It also means that we go from a framework that prosecutes prosecutes um usage by third parties to a framework that makes developers liable for the potential misuse of those tools and the start reality is that open source developers are increasingly getting targeted. How many more developers do we need to see swatted, deported, prosecuted, or even jailed because of writing lines of code? Any of you who raise your hand, you could be next, if you have not been already a target. The theme of this Congress is without privacy there's no democracy.
I fully agree with that statement. I think we all but I with your permission I want to give it one spin more with unchecked mercenary spyware there is no privacy but there's neither democracy because mercenary spyware breaks the fundamental pillars in which democracy is sustained rule of law separation of powers protection of fundamental rights accountability of our institutions All of those go out the window if the government can deploy these technologies unaccountable without transparency without proper oversight [clears throat] and without proper oversight. So what is the technical threat? We are in a privacy conference right now. Mercenary spyware breaks completely the security model we've had for two or three decades now.
You see when when they can get root access to your device, it doesn't matter how good the encryption is for your payments or for your documents or your messages. They live between you and the encryption and they once they get in they can get everything you know key log they can kill your passwords they can get your credentials your token access to cloud infrastructure even see the private keys if you b if you see them on your phone they can see them too and what's worse is that I don't know how How many of you know about zitto click exploits? With this, they don't even require you to click on any link. They can get in your device. They just need your phone number or your iCloud account.
They get in, they get out, and you never notice. It's really, really hard because they this software doesn't leave a trace. In Android, it's very, very hard to detect. They can also leverage the vast information, the vast amount of information they got on you to send you hyperpersonalized messages and emails that make you click. And this is not restricted to phones.
They can also target Mac OS, Windows, Android devices. So it's not only your phone. What is the scale of this issue? Of course, governments love this technology. The lack of accountability combined with the extreme capabilities of this software makes this the the tool of choice for conducting surveillance operations.
It is a VC funded 12 billion industry. More than 74 governments around the world, including the vast majority of Latin American uh governments, deploy these technologies. And I'd like to stop here for a moment to remember two cases because this is more than a privacy issue. Cilio Pineda, Mexican journalist. He was gunned down in the street hours after he exposed alleged government corruption.
It turns out his phone had been infected with Pegasus a few days earlier. You see a photo of Jamal Kashogi entering the Saudi embassy in Turkey few years ago. He never made it out. He got out actually in pieces in plastic bags. I'm showing you these examples to show you what the stakes are.
When governments deploy these technologies unaccountable without oversight, the stakes are not abstract. They're real. They're final people end up getting killed and chopped up thanks to the intelligence they retrieve using these tools. So I spent the last few years of my life studying the playbook that they used against us and we've seen this is not just one rogue intelligence agency. It's a repressive ecosystem that weaponizes the pillars of democracy against you.
It all starts with the legislative which creates intentionally ambiguous laws aimed to give the coverage to the executive to engage in surveillance operations. This is probably the most important slide I wanted to you to see today. The redefinition of the terrorism offense in most European countries. Terrorism includes any action with the purpose to subvert the constitutional order or seriously destabilize the institutions or the economic social structures including those committed with informatic systems. Who here is building something that could challenge legacy social structures?
Who here is building network states, which is a word that amazes me a lot? See, building the capacity to opt out is a direct challenge to the monopolies that the nation states have had for the last 300 years. the executive. What's most striking is that these agencies engage in what I call a dual track operation. They've got some operations covered with warrants and there's another track that engages in illegal espionage.
Citizen lab uncovered uncovered three years ago 65 targets. The authorities acknowledged having spite with 18 of them but the rest as verified also by the Spanish police use the same technological infrastructure but no warrants for those. These are real examples of the messages that we received. I mean they even impersonated their own agencies with our own fiscal numbers. They used all the all the information they had on us to send all these personalized messages.
And in some of these cases, we did not even need to click on the link. It was a zero exploit. I hope you see how the resurface you know of developers is increasingly getting bigger and bigger. Then this intelligence is then laundered into reports that end up end up being used by the judiciary system to open new investigations and to prosecute you. In our case, we were investigated for alleged terrorism.
Terrorism. 12 years in prison for building digital boarding protocols. We were never able to access the cause. We never knew the details of the charges against us. And in the end, the judicial uh pro process was archived due to a procedural mistake committed [snorts] by the judge.
This went on for two years, [clears throat] which leads me to the press. We found all about this through the press. One week after the citizen lab report showed all these surveillance operations, one week after those reports, those intelligence reports leaked to the press. And all of a sudden, our faces, this is Jordi Vina in prime time on TV having to explain why he was not a terrorist. This went on for two years.
They um the press which should act as a system of balances and checks instead was acting as the attack dog of those three pillars. [snorts] You see the loop I I told you in the end you are the target and where does that leave the separation of powers the rule of law you know the right to have uh a fair trial privacy family life private family life all gone. This is why we created Sentinel Alliance. We had two options. Do nothing or act and try to change stuff.
We have three goals, three three main uh goals. First, actively defend victims. Second, raise global awareness across key stakeholders. And three, drive systemic change to prevent new abuses. We're trying to increase the costs, both economical, political, and reputational, of deploying mercenary power against civil society.
That's why we went on the offense. We believe the best defense for developers is actually going on the offense and that's we have filed the largest criminal complaint against two mercenary pyro companies and two state agencies. It is the largest in the world. We're going after them for uh I don't know the charges in revelation of secrets informatic secrets and access illegal access to computer systems with the aggravating factor of them being public officials. This has up to six years of uh jail time.
We seek to have an impact in three tiers. First of all, the victims obviously themselves. We want to clear the names and achieve the digital and financial restitution for the developers and the open source community. We want to build up jurist jury's prudence to break the doctrine that allow them to prosecute developers based on the potential use of the tools they use. And third for civil society without holding state agencies accountable there's no democracy.
But this is a hard path. We up against national intelligence agents. We have virtual infinite amount of funds. And on the other hand, the mercenary spyware industry which is well funded and al it's always shifting. That's why we're creating the developer legal defense fund.
We're seeking to see it with $1 million and this should allow us first of all to see the current prosecution through until the end which we expect it's going to take between five to seven years as our lawyers told tell us. Second, defend, detect and defend more developers, more victims, which we are sure exist out there. And three, increase awareness across key stakeholders because legal action without increased awareness on policy makers is not effective. If you are building privacy preserving technologies or censorship resistant tools, you are part of a tradition that seeks to expand human freedom. But that also means you are at the forefront of a battle between freedom and surveillance, between privacy and control.
The moment the tools you are building are used in a high stake use case, this playbook will be aimed at you. Remember the definition of terrorism as Fede, by the way, the Ethereum developer had the unfortunate luck to discover while traveling in Turkey a few weeks ago. We should not choose between our our work and our safety. That is why we are building these tools, these legal defense, because we want to build a future in which our children, our family, our fellow citizens are protected from state abuse. How can you help share this story across your communities?
This is this is highly unknown. Like everyone knows about the tornado cash case. It was highly highly public, but this is relatively unknown. Share this story across your communities. If you have the means or the organization you work for have the means, donate to the funds.
Every dollar donated is an investment in our collective security. And of course, if this message resonates with you, I think that's it. Yeah, you can always reach out to me via Signal or uh find me at Devcon. I'll be there all week. So, thank you very much.
[applause]
Automatic transcript — names and jargon may be misspelled.