New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Crypto Security Risks, Reality, and Road Ahead | Alexis Johnson - Light Node Ventures

Ethereum DenverMon, Mar 9, 2026, 12:00 AM

🚀 Get Ready for ETHDenver 2026! 🚀 We're already hard at work preparing for next year's biggest Web3 event! Keep your eyes peeled for more info on ETHDenver 2026—it’s going to be epic! 🌟

Transcript

Awesome. Super excited to be here today at East Denver talking about the future of crypto security. Uh before we dump before we uh jump in, would love to do a quick round of introductions. I'll start. Alexis Johnson, co-founder and CEO of Lightnote Ventures, been around in the industry for the past seven years based out of New York.

We help companies grow and scale and ultimately commercialize their technology.

I am Franchesco, uh, founder and CEO of Almanax. We've been around since 2024. We built a product that does AI security audits. Uh, we continuously scan code pushed by companies for security vulnerabilities to find issues before bad actors do. Um, do a lot of work with Salana, Appto, Stellar, and Privy.

I'm Ido, one of the co-founders and CEO at Blockade. Uh, Blockade works with some of the biggest companies in crypto to protect them, their users, uh, their infrastructure from fraud, fishing, different kind of hacks. Uh, we have a whole bunch of different solutions focused on preventing kind of these different exploits or malicious activity kind of in real time. Excited to be here today with uh, these esteemed panelists.

Yeah. Uh, Rob Beny, executive chairman and co-founder over at Halbourne. Halbourne today is the uh leader in all things enterprise web3 cyber security. Um so we help advise the world's largest financial institutions, banks um you know folks like city UBS, JP Morgan and others uh on everything that they're doing in digital assets. Uh we provide advisory assurance.

We also have a um an AI security stack that we've been working on as well that's going to be launching soon and really excited to uh continue to grow and build.

Awesome. So, let's start with where things stand today. What are some of the most underestimated security threats in crypto right now and why are builders, user users, and investors still getting them wrong? We want to go to our own. You want to start that way this time?

Uh, sure. Uh, I mean that's a big one. So tail as old as time that's existed way before the world of web 3. Um, people people will always be the biggest security vector that um, and that'll be continue to be underestimated. Um, I think that, you know, we're here at Eat Denver full of a room full of web 3 builders.

Um, in the world of web 2 and and like the traditional world of software development, you want to move fast and break things. You know, we're all aware of that. Uh, in web 3, if you move fast, you lose all of your investor money. Um, so moving slow should actually continue to have to be a fundamental feature um that I think more folks need to be focused in on. um if it can go wrong, it usually does.

And so um there's there's there's a lot to think through there. Um so I'm always going to say humans because, you know, whether it's fishing, spear fishing, just convincing people to do something uh by greasing some palms, it's tends to be a lot easier than people anticipate. So I'll start there.

I was gonna say humans. Uh but so I 100% agree. I think if I can't say humans then I have to say something else. I think it's you know ultimately like complexity complexity breeds like security challenges right and so at the end of the day I think like the the more complex these systems become uh the the broader the gaps become and I think ultimately you know uh um one of the beautiful pieces of kind of building infrastructure across smart contracts or all sorts of these different things is you have this kind of interoperability you have this this kind of programmat this programmability that you can just go in and kind of configure things in in kind of a really free and permissionless Um, and I think that introduces this embedded layer of complexity that people don't necessarily see beyond the surface, right? We were just talking before about how uh, you know, obviously crypto assets, you know, spike up and spike hard and you don't really know why.

And there's a bunch of embedded leverage across the system. And similarly to how there's embedded leverage across the system, uh, across these, you know, smart contract infrastructure, there's a bunch of embedded dependencies. There's a bunch of embedded complexity. There's offchain oracles, there's human signing things, there's all sorts of these these different kinds of things. And so I think that introduces a bunch of risk that you just don't necessarily know.

You're just deploying funds into this thing and behind the scenes there's like this big, you know, uh, iceberg, uh, that you don't even see. Uh, so I think that's like the second thing that people don't understand.

Yeah, I agree with agree with you guys. Uh, to add another perspective, we're entering a world where most of our code will be produced by AI. I think like Stripe released yesterday like a stat where in the past few months like most of their pull requests are that are open are actually 100% written by AI. And so that trend Coinbase I think a few months ago was at 40%. And so that trend is only going up from now.

So we'll we'll write way less code manually at least. Uh, and I think we'll end up like reviewing a lot less code because like when you like speed out thousands of pull requests in the span of a week, we don't have enough human capacity to look at all that. And so how do we ensure and put guard rails in place to make sure that especially in crypto when like you have some like smart contracts with immutability and so if you're actually pushing something that is vulnerable uh and an attacker finds it like you can't oh you can't say we'll fix it in the next sprint uh you need to put a lot of like that security focus up front before you go and deploy. And so one of the big challenges that we're facing is like how do we ensure that we have the right guard guard rails in this world of AI producing so much code and and making sure that we do all of these up front because in crypto obviously uh there's no fix in the next sprint.

Got it. And now that we've grounded ourselves in today's security threat landscape, let's take a step back. How have crypto attacks evolved over the past three to five years? And what does that shift tell us about where security is headed? Never heard that ei have crypto attacks evolved over the past three to five years.

Yeah.

And what does that shift tell us about where security is headed?

Yeah, we at my previous company, we used to do a lot of like um investigation work on how hacks uh happened and where the money was going. Obviously uh as Rob was saying earlier like humans are always like the weakest link in in the chain and so a lot of like social engineering that isn't new you know that happen in web two as well it's still happening in web two um and obviously in web 3 uh we're seeing some of like I think was last year that uh like a maintainer of a popular like library like in the XRP ledger sort of like ecosystem uh his account was like compromised and an attacker was able to uh inject malware in like this widely used dependency. Uh that you know might sound like hey there's um you know like vulnerabilities in code but like that that is social engineering. I think that hasn't really changed. Uh I think we're what we're going to see now and we've seen it with open claw.

If you guys have been following the the open open claw saga, uh a lot of the skills uh that people were like using and installing uh had malware in it, right? So that that's that supply chain risk has moved from like just like libraries um to actual like skills and tools and MCP servers that like people are using when like producing so much code. So I think we're going to see like North Korea and state sponsor hacker focusing a lot more on like these hidden things that are still part of like supply chain race but are like slightly differently nuanced compared to just like injecting malware and like kind of dependency. I think um again you asked between over the the past kind of three to five years. I think in the past we've seen that the overwhelming majority of kind of exploits or hacks across the space have ultimately been a result of private key compromise.

I think like if you go way back like you know 5 years or so like that's that's where the overwhelming majority of risks kind of existed. And I think um as as we've kind of you know trended into present day we've seen that shift in I'll say like private key compromise has also been like a result of um of of course you know broader supply chain attacks um you know broader cyber operations uh what we would consider also to be key misuse uh where you know someone is convincing you to sign something that you probably shouldn't um and I think that's like trended in the direction of that continues to happen and continues to be incredibly popular like the largest hack that happened last year like by bit is like a result of you know key misuse essentially right through like a broader cyber operation. Um but I think that uh what we're also seeing just in terms of like um the not necessarily the denomination of value that is stolen but um the quantity of hacks is of course like bleeding into smart contract vulnerabilities um is of course bleeding into um and continuing kind of uh increase across kind of key misuse um and I think less so around kind of actual uh key compromise right like I don't think we're seeing as many uh you know uh um private keys get uh get stolen beyond kind of these these cyber our operations wallets have become really really great I think. Um so that's kind of the evolution I've seen over the past couple years. In a lot of ways things have never changed.

In a lot of ways things are changing. So, you know, I mean, with uh with with what Almax is working on, you know, it's like AI will continue to gobble up all of the development and, you know, it's it's a constant cat-and- mouse game, uh, the world of security. So, it, you know, as technology evolves, people are using technology for good and people are using technology for bad. Um, of course there's plenty of onchain attack vectors that continue to evolve. I mean, IDO just did a great job of going over specifically which ones.

I think that uh when you look at all of technology that's being built and especially all of finance, so onchain and off-chain finance, you know, banks don't mess around. They have massive risk departments. They have massive security departments. they work slowly because it is money. Um, in web 3 when code is money, uh, security is the single most important thing in the world, right?

So things will always continue to evolve. Um, but at the end of the day, if you are building in this space, um, I think you're doing yourself and your customers a great disservice by not focusing on security first and foremost and kind of leaning into that. So that's kind of how I would think about it.

Got it. So if the nature of attacks you know have changed significantly over time it raises a bigger question today. What matters more preventing attacks before deployment or detecting and stopping them in real time? And where is the industry still the weakest?

Yeah. Uh in our industry which I'll define as the crypto industry for now um these are bare instruments. So when you lose it, it's gone. Uh that's that's very different. That's very very different.

That's digital asset teams at, you know, at gibbs, you know, are still trying to wrap their heads around that and and still trying to figure out um the right way of approaching all of this. Um so yeah, I mean that's that's just one one thought I'll pass off to you for now.

Do you mind repeating the question uh what uh we might have heard?

Yes. Yes. today. What matters more preventing attacks before deployment or stopping them in real time?

Got it.

So, I think, you know, it's hard to it's hard to say what is more, right? Um I I do agree with Rob, right? Like the the this dynamic that exists across the industry is is very very different than traditional cyber security. In traditional cyber security, if you can, you know, detect a hack that is taking place uh even a week after it's happened, maybe data's not gone. Like maybe uh um uh maybe the breach has not, you know, reached its full potential, right?

The person is just the the threat actor has just like, you know, uh breached the network. They're now pivoting. They're moving laterally, they're doing all sorts of these different things. Um but you actually haven't experienced like the sheer loss or harm that could affect users, right? Um and even after that happens um you know the loss of data is not necessarily financial harm to the broader organization or you know uh um the users themselves.

Obviously there's fines and things like that um in in these regulated indust industries but but high level I think that there's like a fundamental difference where um as like just the liquidity of these incidents is like so vastly different when it comes to you know stealing data versus versus stealing crypto which is which is virtually stealing money right and so um and so I think like you know Rob said this in the beginning right where it forces developers of specifically smart contracts to almost be developers of like hardware right where it's like you have really really make sure that nothing is going to go wrong. Um and so I think that's critical, right? Um and and then I think the second piece to that is you know you deploy something there is so much complexity across these networks there are things that change post deployment and so having kind of detection in real time is is obviously critical. Um but it's not just a matter of detection. you have to have these like layers of of kind of incident response and kind of real-time um responses to actually go and kind of stop and contain these things as they happen.

Um and I think that fundamentally is very different than any other industry. And so it almost like makes securing things in crypto like require this level of attention that other kind of security practitioners just don't really understand yet today which I think is like is fundamentally different. Yeah.

Yeah. Um we focus mostly on prevention at Almanx because obviously in crypto as you guys mentioned um once the money is gone it's gone. It's not a loss of data. It's a must a loss of like money and it's not revertible that transaction. Uh we and there's a reason why a lot of like most companies like do several audits and they do like several security reviews before you go and deploy because because of all what all we just said.

uh but what Eido works on uh on the like continuous monitoring and real-time detection is like super important right and I remember some of the hacks that we were investigating like 2020 2021 there weren't a lot of like tools for real-time detection at the time

and uh you know in a traditional cyber security space uh you have you know these like acronyms MTD MTR uh meantime to detect meanantime to respond

uh that generally large companies and enterprises have an SLA of like very short amount of times, right? For you to like detect that something is happening and for you to detect like to actually recover operations. And so I remember some of the biggest hacks that we were investigating like companies were realizing that they got hacked you know days after.

Yep. And that that no institution is going to do anything in this space if you know there's no solution for you to detect in real time because obviously if you're detecting it days after you know the attackers has like days to actually extract as much value as they can and then like the mean time to recover I think it's like one of the largest hacks we investigated was like 30 days it was like ridiculous. So uh both are very important obviously uh we focus on prevention uh but you know no institution is going to do anything if there's no great monitoring tool and thanks to it there are now

yeah I was going to say I think there's some really good diversity on this stage too because you know you got monitoring the audit advisory side you have the preventative side of I you know early SDLC pipeline kind of uh scanning assessment and you know the this isn't a horn thing this isn't you know it's like it's a it's a problem with the entire industry that continues to look to be solved which is that you kind of need all of it and that's not always cost-effective like it's good to have a halorn audit but it's also good to have five other audits and it's also good to have a bounty program and it's also good to have monitoring and it's also good to have SDLC pipeline sort of AI security reviews for every PR review and by the way even when you do all that you're still not totally secure there is no such thing as a 100% guarantee of security in this industry and in fact I take that back like the all the the entire world like there's it's just a um you know and again this isn't a Halburn thing it's the reality of like in a lot of cases some firms I see are kind of like selling the illusion of security um and I think that the more realistic that you can be with you know you know in in this room we're full of a bunch of builders and web 3 it's like you know you want to be really clear with your investors that you take this stuff seriously and you're doing the best that you can but there is absolutely never a guarantee Um and then like you know and then you go and work with an incident response team. God forbid something happens. But you know these are um so the reality is that you need prevention, you also need response. Um and that that'll just I think that'll kind of always exist.

And to to piggyback on what Franchesco mentioned about Ido's company, right? for Ido. Blockade focuses on proactive transaction simulation and real-time protection. What are the risks of over reliance on automated protection?

It's a good question. Uh I I think so what what's what's funny is you know and Frances mentioned this too is you know days to respond days to detect like doing all these different things and kind of the meantime detection meantime to response. Um, I think that again what's interesting about about this is it's not that you like it's not that reducing the time from days to minutes even matters. you have to reduce it from days to like zero. Um because you know like Rob said, the money's gone, right?

And so if you don't have prevention that is real time um and automated, you actually don't you don't you don't have anything at all, right? Um and so and so it fundamentally again changes these things like right in traditional organizations you have, you know, these these uh security operations centers and they're online and on call in real time and and and and real time for them means you have a person that'll review an alert and respond accordingly. And in crypto, if we have a person that reviews an alert and responds accordingly, it's probably great, but it's but it's but it's probably too late. And so uh um and so I think automation is not an option. It's like a requirement.

You have to have these ability the capabilities to go in and kind of deploy these things and kind of remediate in real time. Um what is but your to your question like more directly is like you know what is the problem of having like reliance on these things is um is that you have false positives and that uh security you know security obviously across all industries adds adds friction right and so if me as a user I have an EDR in my system and it has a false positive then I can't run some piece of software but in this case right then I could potentially be stopping freezing doing all sorts of things that could cause financial damage to to users and people and and you know and we have seen like competit competitive solutions and things like that like have these like false positives across the space and uh uh and ultimately like occur downtime or things like that for their users. We thankfully have not had something like that happen but it could uh you know like Rob says like uh uh you know nothing is 100% perfect. Um I think the trade-off then becomes is like would you prefer having a little bit of downtime for a lot more security? Uh and then I think the question then becomes right which providers offer what guarantees across that downtime and across these different things or I'll correct myself not guarantees but statistics across like you know their resiliency to some of these different things.

So I think it's like a trade-off that every team has to have with themselves honestly.

Got it. And even with smarter tooling and real-time protection we're still seeing major incidents which brings us to audits. And for Rob, Halbourne has audited some of the biggest crypto projects in the industry, yet they're still high-profile exploits. What are teams misunderstanding about what an audit actually guarantees?

Yeah, I mean, um, you're always going to need more sets of eyes and ears on a codebase. Um so I think that um one of the fundamental features as well as one of the fundamental bugs of providing human beings to manually code you know comb through code bases um is that it's a point in time and teams move fast. So you know we're always going to be here to be your point in time you know advisor and assurance partner. Um, but you're, you know, development teams used to work in sprints. With the age of AI, no one's, no one's doing sprints anymore.

You know, you're just like, "Okay, is this is this ready? Has been checked? Great. Push it out." You know, like my development team's pushing three updates to our codebase, you know, a week now.

So, this is this is the speed of which everything's moving, right? Um, so this is why you need to just continue to build up that stack, um, and continue to work with people in the space that really know you. I think that, um, one of the things that you can do is, you know, if you work with any, um, I don't consider this necessarily an audit firm, but if you work with a quote audit firm, you know, is to always interview the actual engineers that are doing your project and and and doing the work. Um, make sure that you're asking the right questions. Uh basically you need to be able to interview.

Now granted in this space I'm not going to say we is known for the best hiring practices but you got to go back you got to go back to the to to basics here right like um when you interview people to work at your company you should be doing the same thing with your security providers. Um and you want to work with the people who are worked with trusted people as well. Um so you know I think that there will always be a need even in the age of AI. So like you know the reality is that the whole world is changing. Um our entire industry is changing as well.

Um but as there's this continuation of AI everything automate everything um I'm still convinced that you're always going to need the human in the middle to comb through and do the manual code reviews along the way. They can do it a little faster now. Even a lot faster now. Um, but you're always going to need that sort of extra pair of eyes and ears. Um, and hopefully you can get dozens of those extra eyes with all the major updates is what I would say.

So,

awesome. And that's a great way segue to the next topic. With rising complexity and scale, many teams are turning to AI as a part of the defensive layer. And for Francesco, where is AI actually delivering real time protection today in crypto? And where is it still mostly hype?

Yeah, it it's not I mean we're getting to the superhuman capabilities, right, in a lot of fields with AI and security has made tremendous progress in the past year. When we work with teams, we always recommend that after the users they go talk to people like Rob um and Alburn um because having a human in the loop, it's still required. Um I don't know if you guys if you guys saw a few days ago actually there was one of the first cases of a vibe coded smart contract that ended up like getting hacked and so it you know these tools accelerate like development like tremendously and we can use them to accelerate like security reviews also tremendously uh but I agree with Rob like

you know a fun fact about that exploit because it's very widely known on on X.

Yeah.

Not audited.

Not audited. Not audited.

Yeah. No,

there he is. You know, we've seen and to your earlier question, right? A lot of teams have considered audits as like stamp of approvals like before deploying historically.

Uh and and that's that's not what they are, right? It's just like a point in time snapshot of okay, we've reviewed these things and it seems like it's secure. there might be stuff but um what what we focus on I think that most teams will and and this is like traditional practice in web 2 and we're seeing it like more and more widely adopted in web 3 as well is having a lot of like these security reviews like done as you're pushing code and not at the end of the process right um like a lot of like audits I've seen a lot of teams in the past like going to like audit firms uh with absolutely no like static analysis tools uh run in their CI/CD pipelines to find issues up front and they show to they show up to an auditor and the auditor ends up like finding

like tens and tens of vulnerabilities and high high vulnerabilities and so if you get to that stage and your auditor is finding a ton of vulnerabilities like there's probably going to be way more um

Yeah. So our our best practice at the company right now is um if you find three criticals in a codebase tell tell the customer to start over.

Yeah. Exactly.

Like just just stop.

Exactly. And so what what we're seeing is now uh we integrated in the pull request review for a lot of teams and we're seeing around like 40% of the vulnerability of the alerts that we speed out uh getting actually patched in the same PR review. And so there's a lot that can be done as you're developing right before you go approach someone like Rob.

Awesome. And last quick question, right, as we zoom out and look ahead over the next 5 years, what is the most important security breakthrough that you expect in crypto? And what risk uh what risk worries you the most?

I mean, I'm biased. I'm going to say AI, obviously. Um, we just placed 10th in the uh Monet audit competition against like 1,600 security researchers. um they're superhuman tools and like companies should use it but but bad actors will. No,

I think actually you know the the the biggest innovation probably will not be a security tool but rather uh asurances right so like Rob mentioned um that like if if if security holistically becomes so good why can't it promise sec like if security reviews or or or solutions become so good why can't they promise assert uh asurances and so I actually think the biggest breakthrough probably will be insurance um uh and So, I don't know if that's exactly a security product, but uh a security offering that'll kind of overlay that with high confidence, I think we'll do really really well.

Uh I think that where we sit today 5 years from now is going to look really funky. Um and and I in the best way possible. Um a couple of us are going to have robots in our house doing our chores. Um, people are going to find funny, silly ways to use those robots to like get private access to uh to your key someway. So, these are these are the fun little quirky things that we're going to see.

Obviously, AI is progressing at a rapid pace. You know, I think we had the chat GPT moment in 22. I think right now we're sitting through the open claw and the clawed opus 4.6 moment. You know, it'll be 4.

7 next month. will be, you know, five soon. So, these are all just massive changes. I don't think anybody's really truly uh uh wrapped their head around how these things are going to happen because there's going to be a lot of unknowns that are going to slip in and a lot of surprises. I think that overall, you know, security is going to be of absolute fundamental importance if you build anything that has a smart contract or anything that has um financial value associated with it.

And so, in a lot of ways, things will not change. You're going to want to make sure that you're hiring good people. You're going to want to make sure that you're actually drilling your people on ethics. Um, hey, if you get approached by someone for a hundred bucks, are you going to say yes to this? You know, these are like actual questions that you want to be asking people, you know, like even like your lowest level security, customer service security.

Um, and if you just look at all of the sort of traditional cyber security risk assessment frameworks that are out there, you can still apply those to everything that you look at 5 years from now. They're just going to look a lot different. like the way that you approach web 3 security is very different than traditional security. Um, which is why in the age of robotics, in the age of AI, there's going to need to be a continuation of building out frameworks, building out best practices. Um, one of the crazy statistics that usually isn't talked about is that in the world there's over 5 million unfilled cyber security jobs.

Um, in the United States it's close to about 600,000 unfilled cyber security jobs. So, the reality is there's not enough practitioners in the space. Um, you know, we all need to get along. We all need to just keep working together because it's still not going to be enough. Um, but you know, I think that it's still um something that we'll just continue to work on and look through.

So,

amazing. And with that, we are out of time, but I'd like to thank our panelists here for uh contributing and the audience for listening in. Thank you. Thanks, guys.

Automatic transcript — names and jargon may be misspelled.