New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Glossifi | Coordinating AI Security Researchers at Scale - Donald Josey | Common S3nse - 2026

CryptoCanalFri, Sep 25, 2026, 12:00 AM

Transcript

OK. Hi, I'm Don Josey, the founder of Glossify Josey, the founder of Glossify , and today I'd like to tell you about an app I've been working on for a few years now. This is a little different from other presentations, but we are focused on security, and we believe that the existing approach to its maintenance has some problems that I want to talk about I want to talk about . So, traditionally, security in web security in web applications, Web3, and other areas has a problem of resource scarcity. Experts are few, and security researchers are scattered all over the world.

Most often, you have to order audits. They are expensive. You can enable monitoring for your applications and services. It is also expensive. There is much more software than people capable of seriously testing it.

But the situation is changing rapidly. Large language models and autonomous agents are increasingly turning security analytics into a machine- scale resource. People wo n't disappear, but we're adding scanners, models, and agents that can continuously inspect code, build hypotheses, and test the system at minimal cost, which should increase our security. However, the excess of resources creates another problem. An increase in the volume of intelligent means does not mean a higher level of security.

For example, audits, which we talk a lot about in Web3. They are a good signal that the project cares about security, but they are only snapshots of the state of the system at a certain point in time . They are conducted for a specific version of the code, and since everything is constantly changing, one can only hope that the situation remains under control. The same goes for bug bounties: they ensure continuous search for vulnerabilities as long as there is funding. But those who participate in them also know the flip side.

There are duplicates, conflicting reports, long problem resolution times, and expensive application sorting. Artificial intelligence significantly scales these challenges. Researchers complain that they are not being heard, and service owners say they are being bombarded with spam. Both are right. AI has increased the amount of information available, but at the same time has complicated the problem of coordination the problem of coordination .

So, my thesis is that . So, my thesis is that finding vulnerabilities is becoming much cheaper, but assessing them is not. And these are two different problems. Is vulnerability real? Is this important?

Can this be used? And who is right? Um, it's not just who's right about vulnerability that matters, but who continues to be right—that's extremely important. So, given one statement about security, I can investigate that statement. With millions of researchers, agents, scanners, models, and methodologies constantly generating security data, I also have to evaluate the sources of this information.

So, discovery becomes cheaper, but evaluation does cheaper, but evaluation does not. Hmm, so who should we pay attention to? I think this is one of the key issues of our era. What researchers, what agents, what methodologies? And, critically, can we answer this before something obvious happens, like a hacker attack?

Hmm, after the exploit everyone already knows which warning was important. All geniuses, when they look back, you know. The value system here is one that is able to direct limited attention and resources before this happens. This is what led us to a market-based approach to finding security data. Um, let me introduce my project, Glossify.

Um, we're building a decentralized marketplace for security data. The bet here is very simple. Markets can help us identify where quality security information is coming from and allocate resources before the answer becomes obvious. So I'll show you how it works. Um, first of all, I want to say that we are building an application based on storage and staking, where users create security signals, but this is not a prediction market.

You're not betting on whether the app will break—this isn't a binary option where you lose all your money. Capital flows into the vaults from liquidity providers, and the vaults are managed by security researchers. Researchers express confidence in the safety of a particular object, and then compete for profits from the system's incentive pool, not each other's capital, you know? This is a conscious distinction conscious distinction . Gambling creates a zero-sum game and rapid risky events.

We are trying to coordinate in the long term so that people can interact with these markets for longer, ensuring the continued reliability of the cybersecurity of the applications. And because it's based on staking, the calculation is that it creates a financial product that's more like a bond than a prediction market where you're trying to double your money or something like that. So, we're betting that profitability can create an incentive to investigate unlikely events before the incident causes major problems, which makes it extremely interesting. So these are our storages and you can see here that we have a few at the top that have a certain share and they get the revenue. And essentially, there's a base return, and then additional revenue that comes in revenue that comes in if the repositories correctly pick a bug that ultimately turns out to be a vulnerability, as confirmed by our oracle.

So, yes, the storage sponsors, which are liquidity providers, are again run by security researchers and research teams. These could be teams that have some AI-based security tool or have a way of making judgments about which applications are most likely to have problems. And so this is kind of our main game . In a separate repository you have interest, and these are NPM you have interest, and these are NPM applications. This is a surface distribution where, for example, we say that 25% of our staked funds indicate that React will have a problem, and we break everything down into epic time cycles and pay out rewards based on events that occur within the cycle.

So, essentially, we create this coordination service, where we call the mechanism " call the mechanism " prediction mining" prediction mining" , and there is a pool of incentives , and there is a pool of incentives . People distribute this belief across surfaces. Reality happens, you know, the oracle decides. Performance determines rewards, and then we keep doing it over and over again to reinforce the safety signal. The idea is that you create a competitive market for safety information, where one correct judgment may be a stroke of luck, but repeated judgments about observed outcomes build a track record.

And you can see who is consistently right in the system. And as a sponsor, you are likely to gravitate towards those people who do their jobs well. So ratings make judgments clear. This is not just a leaderboard. It shows me what someone believes right now.

And the track record begins to tell you how weighty their next judgment is. So if someone is a well-known security researcher, it matters even more than if they're unknown, you know? But the market is constantly evaluating their effectiveness, I think effectiveness, I think , essentially in the system itself. And maybe people are reaching out to them to use their tools their tools , get audit services, or something else. So, it becomes a kind of reputational surface for security researchers themselves, which is shaped by the market.

They want to attract sponsors to their system because they get a share of the rewards or perhaps a portion of the profits from their audits or bug bounty programs. Parts of the commissions from these processes. Uh, that's our, uh, business our, uh, business model for making a profit. Uh, so yeah. Uh , let's see.

Uh, and yeah, security work is becoming something where each sponsor of one of these repositories probably has their own, you know, uh, mechanism or method for ensuring, you know, their own competitive advantage. Some check dependencies in applications using scraping tools, perform static code analysis, track user behavior in systems, observe application developers, uh, or on- chain activity or something else. Different models compete, combining to, again, create this signal. Uh , so yeah. And, uh, let's see.

Therefore. Uh, and yes, we have a certain lack of direction in these systems. Uh, we're already seeing how we're trying to bring to this task, essentially swarms of agents that would be used to solve security problems. Essentially, that's what it all comes down to. So we see modern advanced models doing this internally now, and it's pure chaos.

You know, they centrally launch hundreds of agents that get out of control and so on. Uh of control and so on. Uh , this is a way to channel that kind of energy, but to do it in a way that is community-driven, understandable, and visible to the participants in the system. So yeah, if you imagine a million capable security agents with all their different competencies, what would they look at? What packages, what contracts packages, what contracts , dependencies?

What hidden signals could they find that no one else noticed? Uh, so we're trying to build an infrastructure for distributed intelligence, not to control the swarm from control the swarm from the top down, but to create a protocol where people can, uh, all look at the system together and decide together how, you know, people, uh, investigate security outcomes. So, essentially, yes, it's market coordination of decentralized machine intelligence. So, yes, in the mature stage of this market, intelligence exists on both sides, and there's a kind of feedback loop , right? So on the storage side, there are agents that analyze the security level.

Where are the risks underestimated? They find out what others are missing, where they can specialize, how to be different, etc. How do they demonstrate better judgment and attract more capital? This is their goal. And on the liquidity provider (LP) side, these people probably also have agents.

They do roughly the same thing, but at a higher level. They look at different repositories to determine which strategies work correctly, which methods are useful, and which repositories correlate with each other. Am I really diversified if I hold funds in five different vaults five different vaults that use a similar strategy, and all in that vein? Where to direct capital? So, vaults evaluate the security, LP agents evaluate the appraisers, and both groups observe each other's results, ratings, track records, capital flows, and behavior .

Vaults are adapting because they are hungry for capital, they want to get more of these LP funds because it increases their profitability. Likewise, LPs want better coverage, effective risk management, and working with successful repositories. Yes, it is the creation of a feedback loop that educates a group of participants in an open, market-based way. And not through centralized programming of a cybersecurity strategy, which is beyond anyone's power. We create an environment create an environment where competing strategies can meet and adapt, results create feedback, rankings shape memory, capital creates choice pressure, and feedback loops shape a group that becomes increasingly better and more aware at responding to cybersecurity risks.

The main question: who pays for the yield? Where does it come from? Initially, the idea is to launch a token and fund initial returns to pay people to launch the service. You will notice that as you build a reputation and repository infrastructure for security researchers, you create an incentive that they can use to grow their own businesses. If you are an auditor and people see that you consistently find vulnerabilities in the system, they will come to you for an audit.

Maybe they'll want to contact you for a launch, or after an audit, maybe they'll set a bounty for finding bugs in your repository. And if your repository isn't hacked, your sponsors and the person running the repository will receive a portion of the reward. Such models are today large transactions, such as large transactions, such as pools of funds with six-figure amounts six-figure amounts . The general idea is that by creating such a collective intelligence platform, we can direct part of the profit to funding rewards and supporting the token, because everyone is simultaneously competing for this income, but wants the token rate to grow. Here's how this system works.

So the bet is that incentives attract valuation, create history and reputation, and that we can build a valuable network that creates enough economic activity to replenish the pool and grow the network, making it valuable and converting value into security. So yes. And, um, yes. If it works, the result will be valuable not only for the participants. This system does not require altruism from everyone : researchers want rewards, repositories want rewards, repositories want capital, and liquidity providers want profits.

Thus profits. Thus , the agent can optimize its objective function, they compete and create a variety of artifacts. The main bet here is that private incentives can finance solutions to the “ solutions to the “ tragedy of the commons” we face in security and intelligence. So why should the cryptopunks at this conference care? Why is this application decentralized?

This, you know, is a big question. We, for example, placed this on the blockchain. I think the main idea is that there will be some control from the top over how rewards work, to fine-tune the system and find the best design of mechanisms that will engage people, managing the process in a way that funds positive outcomes positive outcomes . At the same time, the bottom-up history of rewards, staking, and selection must be constant. And we don't want to have control over that.

We also don't want to have custodial control over the repositories themselves. Vaults are built on the idea that you can deposit funds and withdraw them at any time, even in the middle of an epic cycle or whatever. So there are certain tension points where we need some control in the system, and others where we try to be as flexible as possible and, you know, provide a permissive model. Um, well, yes. Um, and, um, yeah, I think I just covered that.

So the key question we have is, can the market finance a security " security " public product" without corrupting it? And you know, markets don't magically create truth. They don't create it, they create incentives. And in a genetic system, every stimulus creates an attack surface or a way for someone to step in and engage in collusion, concentration of capital, popularity masquerading as competence, manipulation, or other things like herd instinct. Um, and especially with agents and especially with agents —the attention grabber.

So, can someone buy a company's attention or create "blind spots"? Um, these are issues and challenges for the application, and we're betting that initially, from day one, it might not be a perfect mechanism, but the system and its stakeholders can work to create an infrastructure that will help move the security issues out of the way , and that's no reason not to build a marketplace. So I will also say that we built this on NPM initially, simply because the data is already there. It's very easy for us to build an oracle around this. Next, I would like to look at smart contracts, but I think the biggest opportunity for this is opportunity for this is to use it to secure LLMs and the agents themselves, which is a more complex problem in many ways that I won't have time to cover in the remaining 2 minutes.

Um, but I think it's possible, and it can only be done with this form of intelligence, not just some company launching one AI agent and expecting to solve the security issues for these big corporations that produce these models. Um, so, uh, yeah. And, um, I would say that the stakes in all of this are that we're going to become very good at creating intelligence. People will do it People will do it , models will do it, agents will do it. Tools we have n't even imagined yet will do this.

Um, as intelligence becomes available, something else becomes scarce, namely—the ability to determine what is worthy of attention before the answer becomes obvious. So becomes obvious. So , researchers, research methods, agents, you know, will determine where to direct capital and computing power and what exactly the "swarm" should pay attention to. We are betting that markets can make judgments transparent. That observed outcomes can create memory, capital can create selection pressure, and competition can direct intelligence to security problems that would otherwise be ignored.

So this privately motivated process could leave behind a kind of public security infrastructure that people can use, and in fact, in this world we are moving towards we are moving towards , it will not only be the infrastructure that creates intelligence—the creates intelligence—the models—that will be important. It will be the infrastructure that determines which intelligence deserves trust, attention, and resources, because when intelligence becomes available, judgment becomes the infrastructure becomes the infrastructure . So, this is our app. Try it. Our beta version is already live and we hope to find many testers and people to join us on this journey.

Thank you. Question. This is based on epics. So, we have time cycles. And now, for testing, I'm running one-day epic cycles, but I think over time it will be more appropriate to do an epic cycle lasting about two weeks or a month.

And during this cycle, any events that happen, you know, are summed up. And then there's a function where in this first game that we use, you know, everything is distributed based on a share multiplied by, you know multiplied by, you know , a percentage allocation in the repository. And I will also say that the storages themselves are modular. And that's one use case, one risk surface that we've connected to this . We have many ideas for other options besides this basic ranked game.

The idea is that the repositories themselves that the repositories themselves are the kind of things that can expand over time and be more, you know, competitive and aggressive in attacking different aspects of the security problems that we have. Is that clear? Still have questions? Class. Well, thank you all for your time.

I appreciate your attention.

Automatic transcript — names and jargon may be misspelled.