New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Security on Ethereum - Panel Talk

ETHCluj MeetupTue, Jun 9, 2026, 12:00 AM

Sebastian Banescu, Dmytro Matviiv, Riptide, Krzysztof Urbansky, and Steffen Kux discuss how Ethereum security is evolving across smart contracts, infrastructure, and user behavior in an increasingly complex ecosystem.

Transcript

Thank you very much. My name is Sebastian. I run Adavar Labs. We're a boutique security audit firm. Uh we do formal verification, fuzzing, continuous security, and all the good stuff.

Yeah, my name is Jeff Cooks. I'm co CEO from Corpus Core. We are right now building technology core technology I presented in the morning to verify and to make our transactions secure. Yeah, I started early in 2017 right after the DAO. So at Sloet which is known for the DAO.

So I'm very yeah not connected to a lot of security things. Hey, my name is Chris and I'm from L2B. And if you don't know it, L2B is a community water that is uh overseeing Ethereum uh layer 2 uh infrastructure and all the technologies involved. So, Interrop, ZK, DA um yeah, and we assess the security guarantees of those technologies to see if they actually do inherit Ethereum's um security. So like to dumb it down like if ever you saw like stage one stage two roll up it's us who define it and it's us who decide who get the batch.

Uh hello everyone I'm Dimmitri I'm co hacker proof nine years on the market already and we actually first of all bounty platform one of the biggest in the world and um so hackers submit reports and get rewards and also we are building parallel crowdsource um audit marketplace that means that everyone uh including audits firms as researchers developers they can actually participate gain some points uh leaderboard board and actually then participate by providing services for you. So you can actually um have reports for penetration testing for audits and etc. And also for example you can find CISO CTO we don't charge for that through our marketplace or get proposals from different providers let's say for so um ISO etc and we also don't charge for that. So we our goal is to build crowsource security marketplace and of course VC focus uh from web two is coming as well and yeah just just working for for the community.

Hi I'm Riptide or justice Hannah CEO and co-founder of Greg Aai. We do AI audits. Uh we do AI security services to protect uh the blockchain from black hats. I'm also a top top ranked bounty hunter. I've been doing this quite a long time.

So, uh, great to be here today. Thanks.

Um, one of the first questions that I want to start this panel with is, um, regarding what happened just, um, last month. So, April 2026 was recorded as the worst month in cryptoc history based on like, um, what Google says at least with over 24 breaches and over $600 million lost. What do you think is the systemic failure you think the industry still refuses to acknowledge nowadays?

Anyone can start.

I'll start. I think the biggest thing is something we've been talking about in the industry for a long time which is trust assumptions. Uh it's not like these these um let's just we could talk specifically about Kelpell and layer zero but um these are assumptions that as security researchers we saw and these were flagged in the community and these are written off by the protocol teams and um there's nothing much you could do from uh a third party perspective other than recommend um make your recommendations known and then we could just hope that these are adopted uh bounties won't pay out for these kind of things. We report these and these are closed as out of scope. Um same with centralized ownerships uh or proxy upgradable contracts.

And the whole issue is like we have the tools. We've had the tools for years, for five, six years, seven years now. And it's it's about teams wanting to adopt these tools and actually putting the cryptography in place that's designed. The safeguards are there. just we need humans to honestly stop being lazy and just just use the protections that have been designed by some of the greatest minds in this industry and that's it just that's all we ask for I I can power this as a in the web 3 world we actually often act a little bit childish only if there's pain we solve something and when we see at this hex in 2026 in 2025 we see a lot of things which as said could have been prevented because we have the technology.

So I think what really is needed now is that we see what are the ethos, what are the uh characteristics of web 3 and that we then start using this not being lazy or being comfortable using what we have done always because it worked it should work in future as well. Now we must stop to have trust assumptions. We must stop to build on hope. We really need to see what can we verify where do we need to add additional tools to make it secure.

Yeah, I also want to add here that uh we as a bounty platform we work with many guys like near foundation and is totally right some bugs actually are closed like out of scope. Yeah. And not included. But also you have to understand that many projects and it's not only about protocols it's exchanges for example they have I would say a list of services they have to gain in order to get a rating score somewhere but they don't care much uh about scope that is included or they try to include only hollow scope and not like worrying about everything so people actually might be a little bit like lazy to do some stuff until someone is pushing them. Yes.

So for example um if regulators is asking for having one I don't know proof reserve or penetration testing uh report per year they will do only one and not more. So if actually and what is this report they will just do this report uh prepar for report and everything that is go after this report like any changes they not worrying about these changes they not review and etc. So as guys already mentioned it um we have solutions on the industry. Yes AI like hearts us but actually first of all currently we have results on not using some solutions that exist. That's all.

Yeah. back. So I can only agree with what the uh my colleagues said before but I would like to also say that uh in order to improve things we need to do better and not like we as builders we as users like you guys need to do better. We need to stop accepting Really, for so many years, I've been told like literally a year ago, I was sitting on a very similar panel about security in the interrupt. And I was being told that the only things that users care about is speed and cost.

And if the only thing that you actually do care about is speed and cost, then you got layer zero exploits. Because it's not that we didn't know about vulnerabilities in layer zero. Like I literally like I wrote an article three years ago about lack of security in the layer zero framework. Not the like the layer zero itself does not guarantee any security guarantees at all. You have to design them yourself and actually if you don't then then your infrastructure is in a really bad shape and what happened basically they zero pushed back on us which is understandable like I don't blame zero I actually respect the team but they are running their own business.

So if you guys accept the fact that they are, you know, selling you and you don't call them out on that, then it's your fault. So in order to improve, we need to stop accepting this We need to stop accepting accepting the fact that it's okay for us to be using simply just some EOA to transfer funds. We like we do have better technology, but you know what? It's expensive to build better technology. It's expensive to run better technology.

So if we are not willing to pay for better security, we will be sold over and over again on the technology which will cause us pain in the future because like if we accept the you know multi-IGD driven um infrastructure from top to bottom then we will wake up in the world that the most common bridge being used will be Western Union because like how do they differ from those stupid protocols that are just EOS? pushing money funds from one side to to another. We need to do better. We need to accept less shitty stuff. That's my call to action.

Yeah, I agree with u everything you guys said. I'm going to not pound on layer zero anymore. Uh I want to talk about a different hack that happened last month which was due to operational security. Uh I don't know if uh people here know this protocol on Solana called Drift and it was responsible for onethird of of the amount lost last month. So around 200 million.

Um it was a very sophisticated hack and I guess to answer your direct question what's what are the systemic risks in web 3? It's uh you know the Lazarus group. I think like if they target one particular protocol because they have a lot of TVL or a lot of volume that protocol is in trouble. Um so you know we all have to work together to to make things secure. be the hack that was executed on um Drift.

If people here don't know it, it was a more than six month operation where the actual attackers met their victims at token 2049 in Singapore last year. They shook hands. They said, "We're integrators. We want to integrate with your protocol." They deployed $1 million worth of assets into Drift as a customer.

They had a relationship for over six months and at some point one of those guys who they trusted at this point sent them a repo and the only problem was that the laptop which was open which was used to open that repo was the same laptop that that person was using to sign a multisig that was able to transfer all the funds from the drift treasury and the drift smart contracts. So I I guess I put it in a nutshell, but but that was that's the level of of sophistication that the Lazarus group has and um I think you know the operational security risk is nothing to sneeze at and I'll be I'll be talking more about that in my talk tomorrow.

Can I follow up with one more thing there

please? just thinking about so you have great points on the opsseack and like I just think about like how do we prevent this if the protocol teams don't do it then how does the user base do it because in traditional finance if you go deposit to JP Morgan I mean you have insurance and everything but you don't really care about their their security you just like okay my stuff's insured but in the blockchain we may not you know the guy who deposits into drift doesn't have the technical knowhow Some do, but most probably don't to assess that kind of risk. And even with layer zero, like who's got the time as a capital allocator to dive into to like all the tech details to to determine if it is indeed safe, like what are the trust assumptions? I think you do great work at L2B with this, but it's still like highly technical and how do we get the layman and should we have them accept, you know, be able to accept some sort of risk uh knowingly versus, you know, the traditional finance model which you have an insurance product that backs it. So, I don't know the answer to that, but something we need to think about.

Um, why do you think then we keep putting money into the same thing if we we all have to do better? And at every single talk, we all say we have to do better. Actually actually yeah we I don't say that we put money there. Yeah. So usually how it works um and we Yeah.

So in industry we have some grants especially when new protocol appears they give a grants and you guys trying to build a new things. This is quite often that is happening. Uh and for example quantum network they also have a new language which is d and they're looking for specialist and etc. they try to build there will be might be okay not it's not a statement but might be issue because of new technologies and everything around uh etc and these young guys people without expertise building something they release and only that they care about first hack about having some audits and it's not about even operational security they can do for example audit for smart contract but they don't care about other part how they operate where they store what else they need is it just one smart contract or they have more stuff. What what is coverage?

Yeah, as actually Kristoff mentioned in one his talk, what is coverage of this? So I would say we like business put money in order to develop their own business and probably they have to have more restriction how to get some grants or how to use these grants. I would say some kind of checklist but if if it's possible to control each company who built on top of your technology I'm not sure are you ready to control I know 10 projects and each person in the product also not sure so I do believe that if you owner only business and you have risk you have to understand how to control this risk and build your own checklist I don't know security assessments and etc and of course Users need transparency. So if you know way how to check the coverage of projects or the I would say uh procedural how they proceed with that. So it would be great to to find his way.

Um may I add something? I think like um everyone uh each one of my co-panelists mentioned a slight thing which I wanted to double click on and that is um something that has to do with regulation. So you know to basically answer your question about why do people keep on putting money into something like DeFi which is risky. I think that's not the problem. the maybe one of the core problem or one of the big helpers would be regulators because now you know we have Mika which focuses a lot on tokens.

I think we need to have something that focuses on security of onchain contracts. So not not regulating the financial aspect but the security part of it and basically asking protocols to be you know forcing protocols to be more mature and have a sock 2 or ISO 27,0001 to make sure they have good operational procedures in house to make sure they have a legitimate audit and didn't just you know get some someone to sign off of it and give give them a rubber stamp. So all that stuff could be enforced by regulators all over the world. Of course, you know, since we have so many jurisdictions, it's hard for all those regulators to coordinate on a common legislation. But I think if regulators would come in and they would have solid legislation, say, "Hey, you're going to go to jail if you just deploy a DeFi protocol that is not properly secure and doesn't have all the bells and whistles, then we would see less of these issues or maybe maybe a few less issues like like we've seen last month."

That's my impression.

Yeah. when when we compare the banking systems and our newer DeFi systems, we uh can see if you want to build a banking product, it's very very complicated. Now, if you one day work with a bank and you wanted to integrate a new library, this takes weeks, months until you can do it. So it's good that we in uh we are free doing things very quick and testing things but as soon as we start to build products and protocols which have a lot of money locked in it we cannot go on this easy way to okay it worked so we just try it then we need to be more adult we we have to stop testing things and then start really yeah building on security tech. This is but this is not an easy change because a lot of the things we accomplished in web 3 where because we did things quickly and we we failed at some points.

But now is the time that we are that we have to grow up and really think okay what is really needed to make the security working so that we can compete with security uh applications like banks and so on. So answering your question, why are we putting money there uh all over again the answer is easy. We are greedy and uh and you know and that's in our nature. So we we won't stop doing this. The only thing that we can do to counter it.

We can at least expose the risks that we take. They are usually out there. Uh you know projects like ours but not only us but like project like ours exposes those risks. So like if you want to help like we just recently published the information about Gnosis chain and the risk assumptions behind Gnosis chain and and and how it operates in the interop like if you want to help go to Twitter go to L2B account subscribe for news from this account and hit smash quad tweet on our recent post. This would help a lot because like just spreading a word to to make people aware of what are the risk assumptions and and and security guarantees is already at least you know one step forward because I I'm sure we'll never get rid of being greedy but at least we should make informed decisions and also we should we should also call out all those honeypotss out there that they should do better like for example I love Hyperlit but you know Hyperlid is a honeypot.

Like from my perspective, it's a honeypot. Like it's asking to be to be hacked literally. Like there there is so much money in there that I'm sure that all those sophisticated actors that are becoming much more and more sophisticated, they will try to find a way to you know make use of it because why not? Especially that, you know, in crypto they can easily then run away with their money. So yeah, like we need to we need to just just talk more about it, speak more about it and be be less afraid of calling out obvious risk vectors.

And before I pass it on, like we've got a question from the audience.

Thank you. So I I do think that we definitely need to call out bad projects, but there's been way too much complacency uh among the technical people where we're just will unwilling to be negative. This is a this is a massive massive cultural issue now, especially in web 3, where we're just absolutely unwilling to be negative um as a culture. And I call out other projects that do not implement the cryptography they claim to implement. And I get lots of hate.

I get death threats as a result. And I'm okay with that because nobody else is willing to stand up and call out that they're not even using the cryptography that they claim to. And that's that's our fault collectively that that the people in this room you know we have done this wrong. We have to you know actually say this is bad not just here but professionally. Do you guys think that we can change this as a community?

I cannot agree more. And you you know one thing that I would like to add that like we like the the way I approach it is I I try not to say that those projects are bad or evil because like I also have some entity to them but we need to be simply we need to be honest about what it is and if it is a multis on the multisc let's call it like that you know not like I accept the fact that not the whole world is decentralized but let's be honest with how decent rates it is and what risk vectors are there and what security guarantees are actually in place. Being honest is enough. We don't have to be negative, but we need to be loud about it. You know, great point.

And when you do bring it up, they smash you. They got the Kohl's. You got the investors for the product. You have everyone will that will come all on you for reporting it honestly and saying the truth. So, I appreciate you doing that.

That's you're you're a rare person in the community and like that is what we need. We need more transparency and I think uh you know there's different ways to look at it as well. Like if you're an investor in Tradfi, you look and you want to buy bonds, you have a rating agency. And for for all of its flaws, you at least have some sort of transparency on the investment and the risks. In DeFi, we have L2B.

We have some startups like Core 3. They're trying to bring those Trafy metrics to the usual investor. But I'm not talking about like the investor that wants to put a couple thousand in. Like these institutional investors that are putting in millions, that's a lapse on your own security if you don't have an internal audit uh or or a security partner to evaluate these investments for you. And if they're giving you the the straight facts and saying, "Hey, look, this is centralized.

These guys can pack up their their three of six multisig and and bail with all your funds." If they're willing to accept that risk, fine. But as long as they're aware of it, but we're we're normally talking about institutional investors like the drift hack I bet was comprised of the majority of what maybe 200 300 investors the the bulk of the funds and these guys made that that decision to put the capital there probably knowing the risks I would imagine and if you didn't well you're irresponsibly playing with your client's money.

Can I tell just not funny but real story? If you check token 2049, I was sitting with CEO of drift alsite chat and discussing security issue and um so when you talk about something or promising I don't know your wife or families and it's about your future health just try to do this. So same same here uh if you feel that something is missed in security of project that you use or maybe in your smartphone or you cannot trust your smartphone just do it as soon as possible change the application just change smartphone approach and etc. Don't wait one week more. If you didn't set up two factor certification in Telegram, just do it.

If you don't trust Telegram, use signal. So first of all, try to do best as soon as possible. So same with the projects. Yeah. If you get money or you feel that okay I don't care that I will be for example hacked but I hacked I I I believe that the biggest problem uh that I will be hacked when I have some money from community etc.

Yeah. So big big risky is money how I actually protect this money by my operational security personally or etc. Uh I also give one more story. We have a client who actually had exposure one of wallet. Yes.

And founder of this company just wrote me say hey Demetro it's not your problem it's my fault and just it was my key key leakage and me like how it's possible I mean like really how it's possible. So uh that is why uh probably have some rules for yourself if you cannot I don't know follow some checklist and etc. If you open GitHub repository maybe open on another laptop to to not have sensitive data and uh uh re everyone maybe you you have calls with those different guys VC interviews uh any searcher. So as I mentioned we posted a jobs on our marketplace and one of company like say hey I see you helped to find CTO and CISO for Spain based company could you help also to find us CTO and I I mentioned of course let's go for the call we had a call he was uh talking about actually uh what they do uh and etc and then he asked me to go to his GitHub and actually uh yeah you can actually try some stuff at your computer and say man I will not do this and then actually it's real story. So in linkadin the guy actually pretended as another guy he was going to interview about CTO someone in trying to scam and offer a job and trying to check immediately how this guy is a good CTO for example and yeah so lots of scammers lots um just wanted to also come back to your question um I think like the the community is not bad mouthing projects because it gets into this toxic he said she said or he said he said um discussion, right?

So if you say a project is bad and call them out, there's going to be a thousandx more people coming and saying no, he's lying. He doesn't know what he's talking about. Right? So it's it's just sort of like a useless fight on social media. I think again, sorry for sounding like a broken record.

We need someone who's like a recognized authority in a particular state that can come and actually verify the claims that you make that someone's not using proper cryptography. So, you shouldn't be necessarily uh forced to go to social media and bmouth a project. you can report them to someone like an authority that can then do their check and see if that project is not using that particular crypto primitive like they're supposed to.

Who's who's this authority? Like there should all be public sourc like like the example with banking we just heard with banking is regulated in every state the same way DeFi should be at least from a security perspective. I'm not saying we should centralize DeFi or anything. There should be some kind of cyber authority or financial authority that can actually regulate the way in which these companies do security. Right?

If it's fintech, right, DeFi is fintech. There is an authority that regulates fintech. Now, I I I guess there's no qualified personnel that can currently check the state of DeFi projects, but maybe they should have a department that can do that. maybe with the help of auditors, right? They they would employ independent auditors to check those things, but I guess getting into a fight on social media will not actually result in the the solution.

Maybe in some cases, but if you have someone who can enforce this and really like, you know, keep those founders that are irresponsible accountable, then then you could have more secure projects because right now there's no accountability for those founders except for VCs not giving them money when they start their next project. Right.

Yeah. All right. So, you have VCs that could hold them accountable and ultimately you vote with your dollar. So, people should not invest in these protocols there. This is DeFi.

There should be no authorities, no centralized authority. This is the market. We have open source. You want to decide, you decide to put your capital there. But all I'm saying is you need to educate people on the risks.

If your obsc sucks, just the more transparency we have, the better. But the last thing I and I have to have a counterpoint on this is I cannot I cannot agree at all to have the government involved of which country? like I don't want any of these bureaucrats involved in regulating what what we built as a group just because we have some problems with it. Like we can we can fix this rather than bring in that complete mess. I absolutely agree.

So I'm not a friend of too much regulation. It's not because I think all regulators are bad but when we uh look so I'm from Germany. I know what bureaucracy means. So, so I I have a colleague, he's now building a token completely mika compliant. It's insane.

Now you you work for months and months to fill papers and papers and whatever information they want. If this makes it more secure, I don't know. So if I look at some of the regulations in the European Union, the AI act and whatever that I see a lot of things which are maybe not bad from the idea but the execution is not really good. So I think what we really need we have decentralized protocols. So we need such transparency things like L2 beat or wallet beat.

things where we really benchmark our solutions so that we can see what technologies are used, what are only claimed to be used or not even tested so that we see what protocols or what applications are using the technologies which are available. So that we then can do a kind of rating so that we see okay this is the current state-of-the-art in the technology and who is really using it and who not. I also want to say that many things we underestimate. So let's say just imagine for a second that your telegram can be hacked. Yes.

What do you think like oh my god my telegram will be hacked. they will need to create the new telegram probably to save my family to send my friends and etc. But come on uh so many examples on a market where Telegram was hacked of CTO co-founders of security firms. Yes. And what happening?

They actually were on the market for eight seven years. They have so many contacts. They get so many messages. They people trust them a lot. And it's not only about brand damage.

It's actually potentially you can be under risk with everyone. So even if you see message from the one guy who was writing you 3 months ago, you should be scary if he's just writing you, hey let's go on a call and etc. So if you have any project, if you have any business, you don't need to like underestimate anything. Yeah. I'm like so that is why about telegram smartphone links social media everything should be like yeah caring as I don't know as much as possible it takes time for sure but then if sometimes even if you don't know how to estimate or understand believe me just call to this guy from security firms everyone will go for the call will not charge for that give some advice and etc that's true so uh probably as you mentioned should be too lazy.

Yeah.

Yes.

Let me just add one quick thing like I kind of sympathize with you saying that we need more regulation. However, the issue with that approach is that like I work with regulators and if we ask them to regulate DeFi, it would be very similar if they ask the bunch of us to you know adjust corporate law. We have no idea about it. Like we would just do random stuff and that's exactly what they are doing when they are trying to regulate DeFi. So we need to you know we need to fill in uh with with our expertise until they catch up.

Uh so let's use you know sorry for bragging about our project but like let's use what we have you know we are about to beat which is like we don't foresee ourselves as regulators we foresee ourselves as watchdog but when Vitalik said I think it was two years ago that that he won't be talking about any project that is not stage one roll up at least it incentivized several projects to actually do better I strongly believe that some projects improved on their security guarantees strictly because of him saying that. So if every one of you would go out there and say that hey the only the the minimum requirement that we have for the chain that we will be using a stage one roll up that would help actually push the our industry to to you know to do better at least a bit.

I can see the the conversation got pretty heated here. Uh but as we are on a panel about security on Ethereum I do have a question regarding that. Um, and we have I I want to kind of wrap up the conversation with questions. So, I'm going to um we're going to have to go a bit quicker, let's say. Um, one of the questions that I have for you is regarding AI.

Um, and then we know that right now it's being um used both to find vulnerabilities, but also to exploit them. Um, are these kind of people that are both defenders and attackers kind of winning the race against or on against or on Ethereum?

I can actually start. So uh we have a bug bounty platform and we receiving a lot of reports a lot like so just to compare for last few months we got more reports than for some years together so it's like a lot uh we have lots of mechanism like paid submissions reputation points and etc. uh they're ready to pay. We even uh um like getting money from paid submissions. It's strange but more than some projects pay as a monthly subscription.

So it doesn't work uh by by replying your question. So currently what we have and um that actually hackers uh a good hackers yeah white hats they actually use AI to create a understandable readable reports. Of course they they would like to submit as possible everywhere and they actually do this. But what actually companies uh do uh even at based project they got these reports and they also work with AI they work with uh automation and etc. and they need to spend more time to actually validate each report and what happening next in a few months you will see a new post on Twitter in linking that someone is leaving but bounty platform doesn't matter which one they like it's enough for us we leaving no more reports they don't want and then they will start receiving reports probably from Google through Google form or a mail they will skip all reports or maybe scanned by some uh tool and and that's all so they will even ignore some important reports.

Yeah. So I do believe because of this EI noise um many companies will start ignoring reports because too much for them this reports and opposite bad hackers they have so many open data right now and they can build a gentic EI and actually be concentrated on an attack and they can plan this attack for months. So currently I believe white hats losing uh and industry losing against blackheads that's all because we like everyone is tired too many stuff around EI is doing new development someone is develop another one is already developed uh how many EI auditors even appear for for last year everyone is AI auditors EI tool and etc what's about the expertise behind and etc uh Ethereum just put like uh or like the DA fund right now has $175 million to to spend the security on Ethereum, right?

I run an AI auditing company.

All right. My point of view is this. I I think you're right. I think we are losing uh on the white hat side because uh number one, I mean bug bounty programs, it's like a bare market for bug bounties as well. And you report something and there's just like try to get paid from that.

It's very very hard. you get white the hats and go gray hats. Uh you have a lot of SRS with a lot of talent. Not saying everyone does this, but there are people that do it and you know you can run off with the money. That's a problem.

Uh when you have the skill go to the wrong side. But from like the white hat side, we have AI like we built this AI auditing platform that we still say is not 100% guaranteed to find all bugs. It's that's BS. But we say no one can guarantee security. So you still do this layered approach.

We we advocate a hybrid audit approach. Uh but we also have seen our AI catch bugs that humans just aren't catching. And so using it responsibly uh we could fight back. Uh but there's so many different levels like a protocol will take AI, they put a claw prompt in the repo and then they say, "Oh, well we we did an AI audit. We had a skill set up and this is what it found.

It's so it's fine." So you can misuse it just as much as you could use it properly. It's about educating people uh that it's not all AI slop that some tools are built different, some methods are different. Um but that's how we kind of fight back against this AI onslaught from black hats.

Um I wanted to give an analogy which many people probably already know. Um security is like a football game. So you have the black hats which are strikers and they need to basically just give one goal that reaches the the post and they won, right? They basically win the game. And the defenders, they need to fend against the white hats.

They need to fend against all shots. And now imagine with AI what happened is that the sizes of the teams are distorted because now you suddenly have thousands of attackers on the field and pretty much the same number of defenders, right? So it's a pretty tough job for defenders. So yeah, I would I would totally agree that attackers are pretty much winning because they have an an advantage right now with AI. So we you know, we're we're trying to catch up on the on the white hat side and um yeah, But from my perspective, I'm a bit more optimistic about it probably uh because it's true that you know AI changed the rules of the game.

Uh especially in my opinion, what happened is that suddenly the long tail that in the past was not profitable enough for the you know black hats to to to go and and spend their time exploring. Now they can simply automate it. So they are looking into those longtails. That's why we are seeing all those weird small libraries that are being used all over the place suddenly getting exploited because previously nobody was looking into that and now they can simply they can afford to look at everything at once. However, you know, in my opinion, what we will see is probably like the next 6 months is not the best time to build stuff.

like Patrick Collins from Cipher today tweeted after reporting on another um supply chain attack that that he would probably give up building anything for the next six months to just wait until the dust settles and everything is actually exploited and and secured because the the good thing about like all those you know all those blackheads attacking everywhere at the same time is that once it gets exploited and fixed it's not like that the bugs are shown popping moving up inside this code. Again, I've read this very good article about the Methos um experiment on on Carol and while while initially it was reported that hey methos found five critical vulnerabilities in in this you know so widely used tool curl apparently it wasn't five it was one and it wasn't that much critical it's just like low key so it will get fixed in the next release so it's such not a critical issue that simply it's not even patched immediately but it's simply going out with a new release. So, and it's not like that there will suddenly, you know, that better AI will find finally find new exploits in code because maybe there simply aren't anymore. And I believe that what we are seeing right now is simply covering the field that was not covered before. But after the the dust settles, maybe in 6 months, maybe in a year from now, we will wake up in a much safer and much more secure digital world.

I just want to add two things about EI um and Ethereum. Yes. So first of all one of um actually clients also who has bound is they like why actually we have to uh waste so many time on a white heads if actually I can run some test by uh AI tool and yeah that's doing my stuff and he was like uh made a point that look this EI finds the issues that no one from white hats posted in my program and I said to him this that's normal that some AI found something better than someone submitted before yes what if someone could actually exploit this before so that is why it's not something that you can be angry on someone that someone didn't submit but you has to be happy that you found this earlier than actually blackheads and also you mentioned about um funds and etc that disc currently what really I like at this moment There is um G given if round. Yes. Where lots of EI opensource tools currently participate in um uh in this security rounds it will be finished in two days.

So if you did participate in V for some projects you can do it. Yes. So LTB is there as well other projects there is also seal and many nice cool projects. So this is something when uh they I don't know when u they already verified and approved by market you can actually use for your needs but at the same time doesn't matter how many or how much Athereum will give as a security um yeah rounds it's still on the user side and business side to make a final decision what to do with it. So, we have two more minutes.

Very quickly, uh, if this panel comes back together in two years, what's one of the issues that you think we're still going to be talking about? And what's one thing that you think we're going to be we're going to have solved?

Unfortunately, we we all know the answer because the same bugs in 2026 are they were in 2018 and they're still here and they've reintroduced things with uh AI vibe coding and humans getting lazy is the problem. How do we solve that? like we're going to see that reappear in two years. Um, no doubt. I hope that AI on the white hat side helps secure and I think you have some good points like it cleans up a lot of bugs that are outstanding.

I think uh two years is a long time in crypto and plus AI I mean I'll be I think 60 by the time two years hits. Uh I think we'll have made some progress honestly. I think the AI rush and the push people start integrating it more. Ultimately, I'm an optimist. I think we will have a more secure ecosystem.

However, this is very much human dependent. So, we'll see how that goes. One thing that I afraid probably probably on like the reason of this EI such I believe we might see even more centralized projects and access systems and decentralized to be very honest. So I hope it won't happen and aside mentioned same stuff issue same problems as many years ago nothing changed that's all so I'm absolutely sure that two years from now I will still be saying that please stop saying that the only thing that users care about is speed and cost like this this will not change but I I hope that what will get fixed in two years is that we will fight back because for for too many years we're just like sitting idly watching our protocols getting hacked and accepting the fact that it's okay for the bad guys to go to to to get away with their the the funds. I think that this year we started fighting back and actually going against those bad guys and trying to hit back at them and I do hope that we'll get better at this so that they will they will not be able to just you know wander around our space uh without getting noticed and we will fight back against them.

So what I hope what we really accomplish in the next two years is that we on protocol level do the really basic things like verifying everything having privacy as needed and having all the things which are now available in place. I hope this we don't have to talk in two years. There will be a lot of other topics we might have to talk but I hope that these fundamental things we have solved them. Uh so yeah, I just want to echo what uh my co-pilot panelists also mentioned. Um one thing I think will be more uh hot maybe in two years from now is going to be the quantum risk.

So it seems like some uh I see Yan is uh very much agreeing um yeah it seems like there's certain advances in that field and not sufficient people are talking about that risk. So, um my bet is that's going to be a hot topic in two years. Yeah.

Well, I do believe this was one of the best uh panels that I've moderated, but I think like some of the panels that I like the panels that I'm moderating generally, I think they're some of the best. So, I want you to give like a big round of applause to like our speakers today and I hope you enjoy the conversation. I think it was amazing. I want to thank you guys for being with us today. Um, and that's it.

I would kindly ask you to leave the stage.

Automatic transcript — names and jargon may be misspelled.