
bountyhunt3rz: life on the blockchain · 2026-04-07 · 53 min
Key moments - from our scoring
Substance score
41 / 100
Five dimensions, 20 points each
n4nika, a proud member of the Austrian Mafia security group, shares his two-year trajectory in blockchain bug bounties and private security work. Starting with a niche-first strategy - deliberately choosing underexplored languages and chains rather than competing in saturated Solidity contests - he's built expertise across Sway (Fuel's custom language), Ton (Telegram's blockchain with its own FanC language), and increasingly Bitcoin-adjacent infrastructure like Babylon, Citria, and Clementine bridges. He discusses the harsh realities of bounty hunting: lengthy local network setups often exceed exploit development time, and teams frequently demand full end-to-end proofs of concept despite valid bug discovery. The conversation pivots to AI's transformative role in security. Both speakers agree human auditors alone can't cover massive codebases like Geth or blockchain clients, and while AI isn't yet mature enough to replace manual research entirely, it excels at scanning enormous projects and reducing researcher bottlenecks. They explore the alignment problem: paying bug bounties competitively enough to match black hat incentives remains nearly impossible, making continuous AI-assisted security monitoring essential for ecosystem protection.
He deliberately pursued niche languages and blockchains with low competition two years ago when Solidity dominated contests. Starting with Babylon's custom Go implementation, he adopted a strategy of focusing on abstract, lesser-used languages across contests to build a unique skill stack.
FanC has completely different primitives and interaction models - there's no atomic transaction model like Solidity, and contract communication uses asynchronous message passing instead of immediate CPIs, creating novel bug classes that require a different mental model.
Babylon controls approximately 52,000 BTC staked (around $4 billion TVL) as the first protocol enabling native Bitcoin staking directly on-chain without leaving Bitcoin, allowing holders to use staked Bitcoin as collateral on connected chains.
Modern blockchain projects are too large for human researchers to fully cover - similar to Geth or Linux kernel complexity - so AI can scan massive codebases efficiently and reduce researcher bottlenecks, though it still requires human validation for novel attack vectors.
The opportunity cost for experienced researchers to hunt bugs full-time for bounties is extremely high compared to black hat opportunities, and even protocols allocating significant bounty pools can't compete with coordinated attack incentives or trading advantages.
Our reviewer’s read on each dimension, with quotes from the episode.
There are a handful of genuine operational insights (niche-language strategy to reduce competition, AI being actively used by black hats to farm contracts, parallel manual+AI review workflow, audit-prompt MD files as a red flag) but they are heavily diluted by extended filler: Windows nostalgia, diet commentary, drug advocacy, and sponsor self-promotion. Insight-per-minute is low for a 53-minute episode.
if you're starting now, you just gotta go for some niche and just double down on some niche things that no one else is doing
I'm so confident that this is, has already happened. I mean if you look at this year's exploits, there's been so many small to medium size...there has to be someone out there just farming all the the contracts with AI
The niche-language arbitrage strategy and the observation that this year's exploit profile has shifted toward smart contract bugs (versus prior-year private key leaks) attributable to AI-enabled black hats are mildly contrarian. Most of the episode recycles well-worn takes: AI is changing everything, code is law, DeFi risk is underpriced, bear markets kill incentives.
If you compare to last year, where most of the exploits were like, private key leaks and other compromises, there's not been that many smart contract exploits. And this year has just been exploding in, in regards to numbers
you'll see certain ones where it's like their audit prompts that they've given to Claude...is this a new red flag for bounty hunters
n4nika is a genuine two-year practitioner with documented findings across Scroll, Citrea (Bitcoin L2 bridge, ~$50K payout), Babylon, and niche-language contests; not a thought-leader but a real operator who has done the work. That said, they are relatively early-career and the conversation does not extract the depth of expertise that a more skilled host would surface.
my first big contest was Babylon...their whole premise is that you can do native staking. So you stake your bitcoin on bitcoin. They never leave the chain
I came from, I was studying it. So I was doing software development, a little bit of electrical engineering and we mostly did C. C assembly
A modest number of real data points appear: Babylon at 52,000 BTC / ~$4B TVL, bug bounty reduced from $2M to $500K, ~$50K Citrea finding, Stone Fi at ~$20M market cap, Nexus Mutual claiming 6B protected. However, many claims are delivered without evidence and the bulk of the conversation is opinion and anecdote.
52,000 BTC staked right now...It's like 4 billion or something
they bought it 2 mil, but they reduced it to half a mil
The host repeatedly derails into personal tangents (Mario's diet, Windows 2000, drug recommendations, Tenderly alert story) and self-promotes his own AI tool multiple times; genuine follow-up questions do appear occasionally but are not sustained, and no claims go meaningfully challenged. The best technical exchange - on what AI catches versus humans - is cut short before any real depth is reached.
take a little magic mushroom and go deep into the forest, into the Austrian forest and just think about it
He's an Austrian beast. Loves it
Computed from the transcript - who did the talking, and the words that came up most.
riptide & n4nika discuss his fluency with almost every programming language on the blockchain, building your skillz via ASM and C, AI on blockchains, offloading investor risk with insurance, hack volume YoY, effectively using AI + manual review, how and why to touch grass, and much, much more ...
Transcribed and scored by The B2B Podcast Index.
Speaker A: Bounty Hunters Life on the blockchain. Welcome back to Bounty Hunters Life on the Blockchain. This episode is sponsored by my company, uh, Grego AI, the number one AI security tool in Web three. And I will flex that all on everyone, uh, if we drop this episode this week. Humble, Humble flex, of course. Uh, with multiple high and critical bugs found in Lido chainlink ENS and redacted. Grego AI to secure your protocol or your entire ecosystem. Reach out or reach out to me. Uh, our guest today is. I don't even know how I say your name. Is it N. Fornica?
Speaker B: It's Nanika. Hey, man, pleasure being here. Thanks for having me.
Speaker A: Hey, thanks for joining, man. Uh, very, very nice to finally have you on and very nice to finally get back on the podcast. It's been a big gap between the last. It's just like, um, you know, I'm not doing human bug hunting, man. I'm doing the AI hunting. And, uh, I'm running this business now. And it just takes so much of my time and I feel, you know, disconnected sometimes from, like, manually looking at contracts. And I gotta say, I really miss it.
Speaker B: Understandable, man. And I see you're. You're killing it, huh? Like some crits highs.
Speaker A: Oh, yeah, yeah, we're gonna drop one this week. We can't give any details. Well, you'll just see the payout amount, uh, which is really, really big. Yeah, that should be good stuff. But, uh, were you in France for the event?
Speaker B: Unfortunately not, no. Couldn't make it this year.
Speaker A: But I see you did the last one, right?
Speaker B: Next one. Yeah, I was at the last con. It was, um. Yeah, last year's ECC was pretty good, dude.
Speaker A: That was. This is my first time to con, and I tell you, man, everything was awesome, man. We, uh, we were able to sponsor the Wonderland ctf. I was able to compete in it with. With Austrian Mafia, with Jack Mario. We. We had, uh, we had the Frenchman there. We had Zigzag. Uh, that was great, man. What. What a great time. And shout out to the Wonderland guys. Great crew. And, uh, just the event was. Was kick ass. A lot of good meetings and yeah,
Speaker B: I'm telling you, highly recommend. I missed it. Yeah. Yeah.
Speaker A: Well, you know, hopefully next time it's in summer because, uh. Kick ass. Yeah. So are you part of the Austrian Mafia as well?
Speaker B: I am, I am, yeah. Proud member. Proud member.
Speaker A: I love it, man. These guys are just. I've never seen anyone, uh, with. With the craziest diet like Mario. So we're at the Table. And this guy's eating. He's just eating and eating, and he's just jacked. He just eats constantly. He has octopus for breakfast, steaks for dinner. I mean, this guy's, uh, he's an Austrian beast. Loves it.
Speaker B: The man can eat the table.
Speaker A: He's an animal. So, uh, what about you, man? What have you been up to? Last thing I think I saw from you, you found a bug. I think it was on scroll. Was that your last one?
Speaker B: It was scroll, yeah. Yeah. I've been, I'm telling you, I've been all over the place doing some bounties, doing private work, working on some internal tooling. So whatever comes up, I'm doing it for chill.
Speaker A: Uh, you've been doing this, what, a couple years?
Speaker B: Yeah, it's been almost two years now. Honestly, probably a little more than two years since I started, but a little less than two since I did it full time. So I've been in the space for quite a bit now. But I mean, it passed so fast. Like, I can't even tell you how fast the past two years were going. It's, uh, crazy.
Speaker A: Yeah, I, I, I tweeted this out today, but I got, I have, like. Do you use tenderly at all?
Speaker B: I don't know.
Speaker A: All right. It's just like, you could trace through transactions, set alerts, and I've been using it. You don't realize how the time passes. But I set an alert three years ago for this deployer address for God knows what I was looking at. And it just triggered. It sent a message to my telegram today. And I'm thinking, I'm like, holy shit. Oh, shit. An alert triggered. And then I look at the transaction and it's like the deployer sending eth to another address, and it hadn't done anything in three years. And I'm like, okay, what the was I looking at here? Like, I have no clue what this bug or situation. So it's just like, always label your alerts, okay? Especially if you have the three years old.
Speaker B: That's alpha right there, man.
Speaker A: Alpha, Alpha drop.
Speaker B: Label your already, man.
Speaker A: But, you know, yeah, time flies, man. You look back, you're like, what the fuck, man? It's just hopefully, um, you touch grass at some point.
Speaker B: I try to. I try to.
Speaker A: Oh, man. So I want to ask you something. So you had, um. I saw this scroll bug. I don't think you did a write up on it. And the reason I'm asking is because we've been like, we have a team of SRs that we try to, that we work with. And a lot of these issues with like the DLT bugs, uh, I mean, sometimes half the battle is setting up the local net to do the sims. And I saw you had the same problems and I'm like, dude, this is the case for everybody. And I think there's a hall of fame, just piece of shit projects up there that may have great tech, but the docs on setting up LocalNet and just the intricacies of doing so, where they'll take that result as like, hey, a valid, uh, bug bounty submission. There's, There's a top few that just are the worst ones to be able to set up. And if you set them up properly, it's like legendary status.
Speaker B: I'm telling you, it's, it's terrible. Like for every single bug, I usually like when it's in blockchain dlt, every single time, the setup and getting everything to work takes longer than actually finding the bug.
Speaker A: Yeah,
Speaker B: it's such a pain. Like usually you have some setup script, like it should work out of the box, but for some reason it doesn't. So you just have to debug forever to somehow get a working local net and then hopefully confirm your exploit. And it's, uh, driving me nuts sometimes.
Speaker A: And usually they don't take the bug, even if it's a simple bug and you could just say no. Look like literally it's right here and it depends on the team. But I've had times where they're like, no, build a full end to end. And you're like, oh, fuck. But then I've also had the time where I built the end to end and then the bug wasn't valid. So I see the point.
Speaker B: I mean, so often there's just one tiny thing you miss and that's one of the reasons you actually have to write the poc. I mean, it's good you have to because it just shows you, hey, there might be some tiny detail missing that you didn't see in like a huge call stack of stuff you're going through and then you just have to throw it out. But I mean, that's part of the game.
Speaker A: Yeah, yeah. I mean, I mean they're not paying you a bunch of money for nothing, so.
Speaker B: Exactly.
Speaker A: You got to.
Speaker B: If they pay you at all.
Speaker A: Right. I know, 0 or 1. Right. I feel like sometimes we get, we get like this, um, maybe entitled feeling where we say, hey, look like I'm hunting for free. I found the bug. Why should I have to build the full E to E Look, I found the bug and you convince yourself that whatever. But it's like, dude, it's part of the job, man. You just need to suck it up and.
Speaker B: Yeah.
Speaker A: And just do the work.
Speaker B: It's the one part that I gotta say really suck. I mean it kind of sucks the, the process of building it up, but then actually getting a, uh, full exploit to work. The feeling is amazing.
Speaker A: Yeah, yeah, it is, it is. I mean, that is the best, man. Um, I wanted to ask you about like I was looking at your cantina profile and you have. And I don't know if you're using like LLMs to understand some of these. Are you just like a polymath with these languages? But you have I think every language in your bio here, like Sway. No one uses Sway. Okay, I know, uh, you got the ton. The ton.
Speaker B: Yeah.
Speaker A: What's going on here? And then you got, you got all the other go. Right. Like everything else. So what's, what's happening here?
Speaker B: I'm telling you, that's, that's really coming from how I just approach my whole being in this space. It's just. I started out two years ago and back then everyone was doing solidity. Right. Like everyone was doing solidity audits. There were more and more auditors coming in. All the contests were solidity and there was like one or two rust contests. And I was like, if you're starting now, you just gotta go for some niche and just double down on some niche things that no one else is doing. And I started doing that and then I. It turned out pretty well. Like in my first big contest was Babylon, which I won't. So it was like some custom M Go implementation. So uh, from there and I just stick with it and try to do the most niche thing everywhere I could do. And that's just how I got into taking whatever language like for this is mostly contests. Whichever contest has the most abstract language and the thing that the least people do, I just went into it. So I stacked up, uh, quite a few different things there.
Speaker A: But you were, you were just coming from like, what was your background before this?
Speaker B: So I came from, I was studying it. So I was doing software development, a little bit of electrical engineering and we mostly did C. C assembly. So rather low level stuff.
Speaker A: Mhm.
Speaker B: And yeah, that was basically, I mean C is basically the uh, foundation for everything. So as long as you know C and you know C well and you know the concepts on the lower level, you can apply to basically any language.
Speaker A: I've heard that same thing that it's a great base to, to build off of. Not many do it nowadays, I would say. I don't. I, I've never learned assembly, I've never learned C past like, you know, very basic kind of. I understand the structure and everything, but hadn't wrote anything uh, substantial at all. Yeah, that's. To have the assembly understanding is um, if, like, if you look back with historical programming, I mean that was like if you were fluent in assembly and, and then obviously see on top of that you could build anything you want.
Speaker B: Absolutely. I mean just looking back at all those engineers that built the things up from scratch in assembly and stuff, it's, it's crazy work. Like I couldn't even imagine building the things that were built by some of the engineers there. It's uh, quite crazy. I mean myself as a geek myself, I, I really enjoy doing the lower level stuff, C and then down to assembly because it's just, it's super cool to do the really technical stuff stuff but like building big things, big projects in that this must be so much work.
Speaker A: Oh, I can imagine. I've been seeing the discourse over the past few months on X about people obviously younger than me who realized like they looked at Windows 2000 in 98 and stuff and they were loading up Office and it loaded immediately and how snappy that OS was. And I remember it, I think that was peak Windows. Windows 2000 business is what I used to roll with. But I was like, yeah, I uh, remember it was fast as fuck. And this new Windows, like my son uses it and it's a joke. Like everything's a joke. Yeah. And it's, it's the whole thing. And, and this is what programming has become is in these big corporations is just, it's complete bloatware. Everything you put on is bloatware. Download an Xbox game, it's like 50 gigs. Every program is minimum a gig for just like. It's like the whole thing was vibe coded before vibe coding came out.
Speaker B: Absolutely. It's. Yeah. Ah. I mean back then things were optimized. It had to run the hardware so uh, it had to fit. Like it had to run on the little things you had. And now it's just. Can throw anything in there you want to.
Speaker A: And we need a reversal though because imagine what we do with this hardware now if everything's optimized.
Speaker B: Yeah.
Speaker A: I mean it makes a geek salivate. Imagine the optimization on this. Uh, dude. So, all right, so you had, Let me ask you this. So when you looked at, let's see you had two projects here, Chorus One and Mighty Bear, which were on the ton blockchain, right?
Speaker B: Oh yeah.
Speaker A: All right. Because we always hear these things like, oh, this is more secure. We need this language for this. Like what was your, if you recall, like what was your thoughts on this? Is this, is this the new language taking over everything? Is this more secure? Is this like any feedback on those?
Speaker B: I still remember. So I think it was about a year ago when I did the first uh, Ton Fan C audit. And I was just going into it because I thought it was low competition. No one did it. And I was right at that and I did the audit and after that I was like, man, I never want to see that language again.
Speaker A: Why?
Speaker B: It's. It's just so you can understand. For fancy, it's custom built for the ton blockchain, right?
Speaker A: Mhm.
Speaker B: And on the blockchain you just have completely different primitives and things are just handled completely different. Like you don't have the atomic transaction model. It's basically if you wanted to cpi, you send a message from your contract which gets sent, I think as far as I know, asynchronously to the um, destination cont. Um contract and you don't get uh, an immediate atomic response. So you have like a complete different model of how you interact with contracts. And there's so many caveats there and so many things you could up. It's. I never really got to like it.
Speaker A: Are there any bug class carryovers? Like is there re entrancy or overflows?
Speaker B: I think your mic just died. Riptide.
Speaker A: Uh, hello? You still there? Oh shit. We do not have our guest. He has disappeared. He's disappeared into the ton blockchain and now I'm sitting here talking to myself. Hello? You there?
Speaker B: Hey man.
Speaker A: Yeah, okay, dude, Rural. Rural living with Starlink is usually good. However, I don't know what just happened there.
Speaker B: Okay, now. Yeah, yeah, back, get back.
Speaker A: Okay. Oh, uh, shit man. Okay, hopefully we're good. It says green on my end, so. Yeah, Elon turned it back on for me.
Speaker B: Thank you.
Speaker A: Uh, I think the last, the last I heard from you we were talking about, I was asking about like any other bug classes. Do they apply to ton? Like reentrancy overflows. And then you went, you went dark.
Speaker B: I mean, uh, yeah, to a certain extent of course you have your like, your type issue. You have under overflows depending on how you configure it. But um, there's just a few different things that you got to consider because you have A completely different cpi, um, system. And honestly I'm not that deep into the language. At some point I really did not want to have any more to do with it, so I kind of stopped doing audits for that language. But it's just the big thing is that there's new bug classes which you have to look for. And it's just a mental model on that is just. I don't really like it.
Speaker A: I'm m just wondering is, are there a lot of funds being secured on that blockchain?
Speaker B: I mean, there's definitely some. I think there's a few quite big, uh, protocols like Stone Phi. I don't know how big they are really, but yeah, that's definitely okay. They got like 20 mil market cap. There's definitely quite some on there. I mean, it's the native, uh, chain for Telegram. So as far as I'm concerned, as far as I know they handle some payments through that, but I never really looked that deep.
Speaker A: Here we go. Ton stakers. Ton. I've never even heard of these things. Uh, the world is so big, you just don't know, like, people that are using this. This is awesome. Yeah, a ton. And what about. All right, what's this other one? Sway. And this was with Redstone.
Speaker B: Who else was interesting?
Speaker A: What, what is that like?
Speaker B: I don't know if you remember, but there was a big attackathon last year on. Or no, actually two years ago, I think on Unify, which was Fuel.
Speaker A: I remember that was that Sway.
Speaker B: That's the big new L1 or uh, I think it was L1 or L2. And their native language was Sway. So they built the Sway language to be used on their blockchain. And it's basically a. It's similar to rust. It's rust based and you have some new additional primitives. But I did that one audit, that one competition and then never anything for that again.
Speaker A: Well, this was the future Fuel. So let's see where we at now. Yeah.
Speaker B: Because I didn't hear anything of them.
Speaker A: 12 million. Let's see. Fuel ignition. 4 million. Oh, yeah. I'm. I'm so shocked that this didn't take all the market share away from everyone.
Speaker B: I mean, they bought a 300 million TVL at some point.
Speaker A: Oh my God. Yeah. Probably incentives farming. Yeah. Usual.
Speaker B: Yeah.
Speaker A: I'm shocked. Absolutely shocked. What about these other ones? The other ones that I do see have staying power that you've done are some of the bitcoin ones. Like you did this one where you, you got. I mean you earned like 50 grand off this Citra, uh, bitcoin application.
Speaker B: Yeah. Recent. Yeah. That's like the one thing I really focus on right now is just anything bitcoin adjacent, crosschain and especially infrastructure for bitcoin. So that for example was, that was last year they built a new Bitcoin L2 and Citria was their bridge for that.
Speaker A: Uh, okay.
Speaker B: Quite interesting. Pretty good contest.
Speaker A: First, uh, ZK roll up on bitcoin. Clementine bridge.
Speaker B: Yeah, Clementine is a bridge for them. Exactly.
Speaker A: Okay. Yeah, I think that's a, uh, these ones will be around like it's actually if you're going to do defi. Do it where no one's doing it. I think there's only a few. There's probably more than I think now like the bitcoin projects because you have all these. Yeah, you have people owning all this bitcoin and they obviously want yield and I mean I think there's plenty of demand for it.
Speaker B: Absolutely. Especially if you look at the Babylon 1. So Babylon's this really big player in the bitcoin field. That was actually the first audit that ever did, was the contest for Babylon, the first big one I did. And their whole premise is that you can do native staking. So you stake your bitcoin on bitcoin. They never leave the chain and you can use them as collateral or as staking power on connected, uh, chains, which is quite interesting. It's pretty cool. And I mean they got, as far as I know, they got like 5 billion in uh, TVL pretty quickly. Just uh, everyone was going to them because first they were the first to do it. And it's a great, great thing to do actually, if you can just use your native bitcoin and uh, get some value from them.
Speaker A: Yeah. So there's some big players, 52,000 BTC staked right now. Yeah. Wow.
Speaker B: It's like 4 billion or something.
Speaker A: And so they just stay on. So you must sign something on. I don't even know how this works.
Speaker B: Yeah, it's a completely different system like bitcoin. That's actually very interesting. Bitcoin, how it works is quite nice. The layer on top.
Speaker A: Let's see. So they're securing over 3 billion active bug bounty. A half a million. Oh yeah. Definitely aligning the incentives there. Uh, guys.
Speaker B: Yeah, they bought it 2 mil, but they reduced it to half a mil.
Speaker A: Bear market. Yeah.
Speaker B: Yep.
Speaker A: It's, it's well, you know, black cats, they don't work in the bare markets anyway. They get a little notice luckily. Yeah, we'll we'll never align incentives, uh, I swear to God.
Speaker B: It's just, it's impossible.
Speaker A: It's impossible.
Speaker B: It's, it's definitely possible to make it better, but getting to a point where you can get guaranteed to pay your whiteheads and incentivize them enough to actually hunt on a level that blackheads do is so hard. And we're nowhere near that at this point.
Speaker A: Yeah, yeah, I think we could solve that using um, AI because it's just such a time suck. It's such a huge opportunity cost for them to have a human go ahead and hunt through all their contracts for however long it takes versus if you have a high level AI able to match that SR and can review that in a matter of hours and you're paying the cost of compute, uh, honestly I think that's what we need to help secure this ecosystem. I think this model that we have now is kind of done the one off audits because black cats have access to all this advanced AI and something will just be uncovered. So it's like you need like a constant security posture.
Speaker B: I think at this point you definitely need AI, like you can't go without it. But at the same point, at the same time, I think even though AI is getting better and better, you still need some level of human research as well because you, at least from my point of view, it's not exactly there yet. And uh, what I think is the big thing where it's really amazing at is really big code bases like for example blockchain targets. Just because the real, real bottleneck here for researchers is, as far at least from my experience, is that those projects are so huge that it's almost impossible to cover all of it. And you have an AI that can actually cover it and reason on it in a reasonable way, in a productive way, then uh, there's a huge time uh, save there and you can definitely improve your output by quite a bit.
Speaker A: I absolutely agree with you. There's so many vectors when you think about it. If you run a big blockchain and maybe you have 10, let's just say 10 devs that you have and maybe you have uh, two of the original team. And so these guys know the most of the code base and they're the senior guys. Then you have another team of 10 and you're working on. This is your, is your approval pipeline correct? In GitHub, you know who's making changes, who's actually reviewing. Can they review everything? And it's there, like you said, there's so Many moving parts to these big projects that it's, it becomes unmanageable. It, it does. When you look at it, it's like, like look at, look at geth. Right? Look at, look at it. It's such a big project and you just look, you're like, oh, I wonder if there's any bugs here. Just go to the issues tab. Like there's so many fucking problems and that's any big project. And it's, it's almost like you can't not have that. Every possible look at the Linux kernel, look at everything. Everything is being touched by a lot of people. They're looking at it and there's always some issue. And so how do we, you know, how do we move forward and secure all of this with AI to change from decades and decades of precedent where this is just always just how we do business?
Speaker B: Yeah, absolutely. I mean as you said it like at some point it just gets unmanageable. And I really love that AI is being harnessed and improved so much in this uh, space that you can get more and more coverage. Of course it's always hard to say how much really like how much is still hidden, how much is there still to find. But it definitely like, especially as we saw, um, with all the AI bounties and so on, it's getting definitely better.
Speaker A: Mhm.
Speaker B: And it's definitely saved a bunch of money already.
Speaker A: As long as we can incentivize the white hats whether I don't care what tools you use, human AI, whatever, as long as those parties have enough power and incentive to do what they do, that we outweigh the black cats and beat them as far as front running the transactions, whatever it is, we're in a better position. It's just, I don't want to see that power balance shift, um, toward, you know, how many. I wonder if there's any kind of hypothetical percentages, like what, what percentage of hackers out there are opportunistic gray or black hats? And now with AI, you've, it's like the script kiddies, right from back in the day. Now they've been able to amp up their skills with AI and become maybe master criminals.
Speaker B: Whereas I'm telling you, I, I'm so confident that this is, has already happened. I mean if you look at this year's exploits, there's been so many small to medium size, I mean, what small to medium size, Hundreds of thousands, millions of dollars. But there's been so many that there has to be someone out there just farming all the the contracts with AI.
Speaker A: Yeah.
Speaker B: If you compare to last year, where most of the exploits were like, private key leaks and other compromises, there's not been that many smart contract exploits. And this year has just been exploding in, in regards to numbers.
Speaker A: Yeah, that's a good point because you were seeing like, white hat mage, like some of these guys hitting some crazy bounties, but they have some, Some detection capabilities. Like, I always view it as. There's. There's auditors and bounty hunters, right? And. And they may have the same technical skill set, but one is just really good at finding bugs and the other isn't. And they might, they might be able to be great if you put them on the same contract, maybe they see the same bugs. But finding that contract is like the bounty hunter just knows he's got a system set up. And it's hard to explain it because everyone does it differently, but, uh, that's the truth about it. So now these black hats, you're right, man, because you see like, I see exploits all the time now. And I'm like, yeah, there's. There's somebody out there with his AI, with his. He's got his passion skills set up, he's got going and he's finding shit. And he's like, well, hey, Clyde, tell me how to exploit this, this live. Um, how do I, how do I, how do I vpn, how do I use private meme pool and make no mistakes? Yeah, exactly, man. What a crazy time. Crazy dude it is.
Speaker B: That's. I'm really curious how this goes. And on the other hand, then you have exploits where you can't really do anything with tooling. I mean, you can do this to a certain degree, but mostly you can't do anything with tooling or improving your contracts. For example, the drift tech now is just. How would a white hat help you there? So you will always have this disparity of exploits that can be prevented and others that still can be prevented, but just. There needs to be a different approach on how to prevent them.
Speaker A: Yeah, I mean, how do you avoid the drift thing? You could, you can come up with a lot of, A lot of things, oh, they shouldn't have done this. The, The. The Durable nonces, they called it. And in the end, right, if you have like an owner, like anyone that has admin privileges, you're at risk. What more can you say about it? Like, you're accepting that risk. I don't care what you're saying about your, uh, opsec. And, you know, you could do everything you're still relying on some human to not make a mistake, which is very risky when you think about 200 million at risk.
Speaker B: Yeah. Then you have uh, your counterparty which has basically unlimited resources and you somehow have to defend against it.
Speaker A: Yeah. I think you should have what the blockchain was kind of built for. Right. Do the immutability, have it permissionless, but don't have it centralized with some owner, with some multisig like design it the right way where you don't have to do that. Uh, and if you've designed these systems and I haven't, but I've admired the people that have like Michael at Curve, the Uniswap team there. Those, those contracts are not bug free and there are bugs that you're willing to accept by deploying, uh, immutably. But it's like, okay, are those protocol destroying bugs? No. Are those going to take funds from users? No. And I think the trade off is worth it.
Speaker B: Absolutely. Yeah. I mean you're just eliminating a whole aspect of risk there. You don't have to rely on anyone. It's just build secure code. And yeah, code is law at the end of the day.
Speaker A: And this is coming up a lot where people are saying the um, interest rate, the rate you're getting doesn't reflect the risk that you're taking in defi lately. And it only reflects the rate when you get DeFi Summer 3000% APR. To be honest, I swear to God man, I don't know. People put money in these fucking protocols and it just blows my mind. And, and they don't do their due diligence. And um, even if they do like, even I speak with investors and LPs and stuff like that that are putting funds in a new protocol and they're like, they come to us, we do a, an audit of it and they're trying to reduce their risk. Right. You're trying to know everything you can like any investor would do. And um, the fact is we can't guarantee that it's 100% uh, bug free. Nobody can do that. And the risk, it just doesn't reflect it, man. And then, and then add in the, the admin risk too. You're, you got a 25 year old dev. Nothing against 25 year olds. But uh, growing up in a non opsec cloud focused world where he's got 26 browser extensions and then he, you know, does some nefarious stuff on his laptop that he shouldn't be doing and it's the same work laptop and he might have a hot Wallet. And then the multisig gets together for beers, uh, on the weekend. It's just. How do you quantify those risks as an investor?
Speaker B: I can't even imagine how to do it. I mean, it must suck. Uh, at, uh, some point, you just have to accept it, I guess.
Speaker A: But, uh, that's not a good answer.
Speaker B: No, it is not.
Speaker A: No. All right. I met this dude. I met this dude at. And he was from a project that he was starting called Core 3. I think it was Core 3. And he was showing me his. It was a risk dashboard that he was trying to take Tradfi financial ratings and metrics to Defi, which is really cool. So, you know, if, if you have. And you know, there's always some, some sneaky going on to Tradfi as well. But if you say, okay, this company's rated A minus, and here's the rationale, the criteria, uh, for that, okay, one can have a reasonable assumption on, um, the riskiness of this debt. And uh, so he's building this for Defi, and he has, like, protocols, rated chains and stuff. And I was, okay, it's cool. And I looked through the criteria and obviously I look at security. I say, what's your security criteria? And it was like, has it been audited? Okay, yes. More than one firm? It gets more weighting. Uh, does it have a bounty? Yeah, okay, that gets more weighting. Um, but. And then I think there's one other metric. And it was like, well, that was it. I was like, well, you know, it should be. You could probably improve this. It's like, oh, it's a draft, but it's something, I guess. But you could add in stuff like what L2Bead has with the L2s. Like, okay, are there. Is the multi sig, like, how many guys in the multi sig Is this immutable? Like, so many different things you could tack on in there to help quantify this to, uh, potential investors.
Speaker B: But as you said, like, once you start investigating on who holds the multi sick and how much can you trust the people holding the multisig? It just, it gets so complicated. It's, uh. I doubt that any VC really does that deep of a research on, on like the multi sig owners. The exact, um, uh, the exact layoff layout of the contracts, like the roles and stuff. It's. It's just so hard to manage, especially if you're not a very technical person.
Speaker A: Yeah. How do we fix that?
Speaker B: That's a great question, man.
Speaker A: I don't know. I don't know. Ah, because you think in mass adoption, how do you get people to do it? And the thing that I would like to see is for them not to worry about it, just like you don't worry about, um, I mean, we need to factor insurance in here too, right? Because how do you not, at least in the U.S. right, you deposit money into a bank and then, um, like back in the days, you would have to choose your bank and you would have to assess the risk of the bank. And once they introduce this, uh, FDIC insurance, which is basically the government backstop for your deposits at the bank, well, no one cared. Every bank was treated the same as long as it had a charter and it had this insurance. So that risk was offloaded to the government because of the amount of money at stake. Right. So on the blockchain, where you're looking at a worldwide environment, where do you offload that risk to is that. I mean, we had. Nexus Mutual was the only insurance protocol I remember, and I saw them at the conference. I guess they're still around, but there's not like a government backstop for this thing. So it's going to have to be from the private sector and maybe that's from an insurance product.
Speaker B: I think in that case, uh, decentralization is actually holding us back a bit because the blockchain is just the wild west. There's no central entity which you can blame. There's no, no real company which you can prosecute, whatever. So you don't really have that on the blockchain. And you can't have one entity which takes all the risk and then takes, um, responsibility for it. So there's just a gap between how you can do it in transfer and how you can do it, uh, on the blockchain. Because it's just everyone on their own and there's just not as many regulations. And that doesn't mean we would need more regulations. I mean, maybe we do. But that then again goes somewhat against, uh, the principles of decentralization. So there's always this gap between what you can actually do and how much you have to compromise on the other side.
Speaker A: Then, yeah, I think the private market will figure this out, uh, absolutely, at some point. So, I mean, I think when Nexus Mutual came out, I remember that being like. I think their idea was like, hey, the protocol wants to attract tvl. They're going to have this insurance for a hack. I don't. Maybe the economics didn't work out where the insurance was too expensive. Maybe it, I think it launched during defi summer. Something like that. So people didn't give a fuck. They didn't care at all. It's like, it's sure not. Who cares? 3000 APR. I don't care. Maybe that's it.
Speaker B: I mean, if you tell a random guy who doesn't know crypto he's getting 3000% apr, I'm m pretty sure he'd take it.
Speaker A: I know, right? Like I go to their website and they're like, all right, 6 billion in crypto protected, 10,000 covers provided. Number one in claims. I have no idea. But um, that's what we need, man. We need something here.
Speaker B: Absolutely, yeah.
Speaker A: Like the last ones I see here are from back in the day. Right. Rari Capital, ftx, Euler Yearn, Holden Cream. These are all old, old ones, man. I think. Damn. I like this idea though. This is another great product. People should build something like this. So how do we ensure the. Especially during bear market. This is just widely in everyone's face, like, hey, this yield sucks. And the risk is uh, unknown. And that's a terrible, terrible place to be. I think we're only attracting capital because people believe in like a four year cycle. And you know, there's a lot of benefits to crypto and I think the investment outlook is positive over the long term, of course. But uh, this needs to be fixed. Yeah, definitely, definitely. Um, m. So let's see otherwise, what, what else going on over there? What else would you like to talk about, sir? Any, uh, what are you doing now? Audits, contests, bounties.
Speaker B: Um, building, building, some stuff. Doing, uh, private audits. So got some private audits going on, some new ones coming in. Building some tooling.
Speaker A: What are you building? What kind of tooling?
Speaker B: Of course, a build of building around. With AI, it's basically everyone these days.
Speaker A: But what is it? Can you give us a high level?
Speaker B: Basically also, uh, AI auditor specialized on blockchain dlt.
Speaker A: Yeah, good idea, good idea.
Speaker B: But I feel like everyone's doing that nowadays.
Speaker A: Yeah, but hey, look, I'm knee deep in this. Not everyone's doing the same thing. Just build yours differently. Like think about it and come up with a unique architecture.
Speaker B: Exactly. And you can create some unique selling points. You have to be better than someone or have something that other, uh, can do.
Speaker A: Yeah. You can't just put some skills in there, some prompts and expect to like. Because what's the goal? Like, why do anything you want to be able to 10 100x the competition? So you need some groundbreaking shit.
Speaker B: Exactly, yeah.
Speaker A: So if you could build that, I mean I advise take a little magic mushroom and go deep into the forest, into the Austrian forest and just think about it, think about it deeply. Maybe you come up with some, some cracked ideas.
Speaker B: There's, there's going to come very, some very good ideas there.
Speaker A: Dude, I tell you man, the crazy stuff comes on my feed were these back in the day 60s, these scientists were given LSD and they came back with some crazy new new theorems and hey man, whatever it takes. Like if you're on that day to day, here's another alpha, alpha drop. If you're on the day to day, like you wake up and you say I'm gonna crank some bugs. You wake up now, you maybe do some push ups and then you hit your coffee and then you get on your screens. Well, you're gonna be on that same, same path every single day. Locked in. Caffeine does that to your brain, locks you in. And you're kind of, you kind of have boundaries with your thinking in my experience. And so how do you open up those boundaries? Well, you need to deviate. It's not like you come to the screen drunk. I think alcohol is one, one area where this, it does not help at all. Right. But different things help. Like if you go, go for some hill sprints and then you come back and that, that can kind of open up new pathways. If you could do um, you know, some, for some people, like different drugs may just have better effects than others. But if you just take something to expand your mind as you know, with marijuana or um, mushrooms or maybe um, lsd, I don't know, but like something that allows you to think differently than how you normally think and think differently than the competition and it could open up. Um, yeah, and this is me completely advocating for you don't do drugs if you're already mentally. But you know, it could, it could help.
Speaker B: Well I gotta say, especially in our space where most of the people are rather technical and kind of nerdy and really get obsessed with the technicalities of stuff and just be on the stuff for 12 hours a day straight, taking a step back, getting a good workout in is such a mind changer.
Speaker A: Mhm.
Speaker B: Such a game changer. It's crazy. Like if you actually take care of yourself and you actually improve outside of, of being a geek, it's uh, it's
Speaker A: true, it's good man. That, and when you really love doing something, you have a passion for something. And especially when you're young, you just, you have no problem sitting in front of that computer for 10, 12 hours I remember, man, I remember doing that. Just, I wouldn't feel anything. You could just sit in the chair and like 12 hours go by. Hey, I'm a little, I'm a little tired of staring at the screen. But I could do it day after day after day. And uh, when you get older, I mean you're like fuck man, you need some more balance. But it actually is like your body and your mind telling you hey look, you'll find more bugs this way. Just get the out of the house for a bit.
Speaker B: The amount of times I just went into a protocol like got it, uh, like thought about it, got to know it quite well and then just took a step back, I don't know, went to sleep or went to the gym or whatever and then just thinking about it and then getting some idea. The amount of times it has happened to get a great idea and a great exploit path just by thinking about it while not staring at the code is there's been many.
Speaker A: And how do you deal with like the new problem with getting lazy with AI? Like how do you deal with like oh, AI, I'll just look at this. Instead of using your brain, do you ever have that?
Speaker B: Of course.
Speaker A: How do you find it?
Speaker B: I think everyone deals with that. Uh, it's just so prevalent, AI is so prevalent that at some point just you have to thought like what if AI can do all of this. But I gotta say for most of the things you just gotta uh, take a uh, step back. I usually separate it. Like when I do a review or something I, on the one side I launch my tool edit, I generate all its output and on the other side I do the manual review. Review. So I do the manual review. I like help take AI to help me with understanding of the code base, like what leads to what, uh, what areas um, in the code base are responsible for which functionality and so on. And once I got a good understanding and once I have produced some findings and once I know what's going on, I take a look at the AI findings and then cross reference those against the code base. And I think if you explicitly do the audit yourself while also relying on AI in parallel, you still got some, uh, you got the benefits of both, like you don't get lazy and you actually continue providing value with your knowledge and with your experience. But on the other side you also um, find all the low hanging fruits and everything that you might miss just because you already seen that stuff so many times by running AI in parallel. And I think that helps quite a lot to just take Both and try to not get complacent by only relying on AI.
Speaker A: That's a good strategy. Are there any things that you've noticed that AI finds consistently that humans miss or that you've missed? I think it's like certain combinations of bugs because it'll find some weird edge case stuff or like you say, cleaning up a lot of things.
Speaker B: I think often I had some things where for example in Go and Rust, uh, especially Go, some typecasts or like some things that were very specific to the language that you would just read over and think it's correct because it looks correct, but then you have a small assumption like some slightly wrong syntax. And those things it catches very well. I would say, like had some bugs where I uh, found them this way just because the syntax looks correct, it seems correct. And uh, if you don't dig into every single um, M deeper into the Go feature itself, you don't find it, but AI finds them quite easily.
Speaker A: Do you think the teams are like. When you're looking at these audits, do you think teams are dropping the ball with security? Like are you seeing more prompts in the code base? And, and just maybe you could see that the code is maybe not as tight as the uh, code you used to review?
Speaker B: Not really. I mean I'm, I'm right now mostly working with some bigger clients which I've had over for some time. So I'm reviewing code of teams that already have produce a lot of code, not some new project. And I feel like they maintain their quality mostly. So it's been looking not too bad. I mean I've heard of some projects, ah, like not some projects but from some people, uh, that they had completely vibe coded contracts and like everything was broken. But I've not had that much of an experience with that. So I gotta say it's actually not that bad. And I feel like especially in the blockchain space and blockchain DLT space, you can't really get away with it.
Speaker A: Why do you think that is?
Speaker B: Because especially if you build something from the ground up, those systems uh, are just really, really complex and have so many moving parts that it's gonna up something.
Speaker A: M. Do you. Are you seeing those prompts, the MD files in the repos?
Speaker B: Um, no, not really.
Speaker A: You haven't seen that? Okay. I've been looking at some repos lately and you'll see like uh, function of the contracts, MD or whatever. And it's like, okay, that's an explainer generated by an LLM. That's cool. But then you'll see certain ones where it's like their audit prompts that they've given to Claude. Okay. Ensure that there's no reentrance. It's just all these different things and you're like, is this a new red flag for bounty hunters to say, huh, did a human look at this or
Speaker B: did they just trust you got to step back, trust the prompt and say there's no bug in here because they ran this prompt on this.
Speaker A: Yeah, yeah, trust the prompt.
Speaker B: Exactly. Yeah. Oh, uh, but we definitely gonna see more of that. It just, it just reduces the barrier of entry for even non technical people to build stuff which on the one side is good, but on the other side for security it's terrible.
Speaker A: Mhm. Yeah. This is a double edged sword that we've been talking about a lot. We love, I love the fact that anyone with an idea can deploy and the barrier before was you had to know how to code and now you don't have to know how to code. And that opens it up even more and there's your, your biggest sell on like wow, this market's going to explode. But the security issue is yet to be addressed and that like uh, yeah, this only gets addressed with AI I think because just too much stuff will be coming on the chain and you're
Speaker B: going to have to have these especially we now that we see the contest m markets going pretty much to zero. I mean there's one of uh, one or two contests sometime. It's, I don't really know how we're going to attract new talent and new people getting into the space because there's quite a few people that got into it a few years back and back then you could prove yourself, you could prove that you can win contests that you know what you're doing. But how is anyone going to do this now that there is no real opportunity to prove yourself? So I think that's a really important thing to address for us because we need new people in the space at some point.
Speaker A: Maybe the bar has just been raised where you have to show yourself. Finding bugs live as bug bounties like hey look, this is what I bring to the table. And um, I'm more skilled than the next guy. But you can't have the same guys, uh, finding these tiny bugs. Those don't have value anymore, the old bugs. And the bar has just been raised and difficulties increase.
Speaker B: Absolutely. Yeah.
Speaker A: That's probably where we end up, which is probably a good thing. It's unfortunate but I think the good guys will rise to the top. And if there's new bug hunters out there and new really good srs, you'll see them. And they'll probably be a hybrid of human AI, um, masters out there.
Speaker B: At this point, you have to use AI otherwise you're falling back.
Speaker A: Yeah.
Speaker B: At least to some degree.
Speaker A: Yeah, yeah. I mean, still, man, double sided coin there. Because I know guys that don't use it at all. And they're bounty hunting and they're finding.
Speaker B: Yeah, okay. Yeah, yeah, yeah.
Speaker A: I mean, it all depends. Like, if I was doing a normal audit as, uh, as a protocol, I at this point, I would. And this, I called this last year, I was like, you're going to get to the point where you're, you're not having AI eyes on your protocol for an audit and you're going to ask for it. And I think we're at that moment now where people are like, whoa, all right, humans looked at it, but AI found some cool shit last time. Let's have it look through it again.
Speaker B: Yeah, I mean, it doesn't really hurt.
Speaker A: No, no, it doesn't hurt. Not at all. Why not do it? Yeah. Cool, man. Anything else on your end? We are creeping, uh, up on the hour. Mark. Any burning questions?
Speaker B: No. No?
Speaker A: Okay. Well, that's it. Well, sir, thank you for coming on. A real pleasure to finally get you on the podcast.
Speaker B: Thank you so much. It has been a pleasure.
Speaker A: I'm gonna have to get every member of the Austrian mafia on here now, now that I met them in person. Please do. All right, man.
Speaker B: You're not gonna be disappointed.
Speaker A: We will see you all next time on the blockchain.