The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Risk and Reason
Risk and Reason artwork

Dub's COO, Brett: Why “Move Fast” Breaks Fintechs

Risk and Reason · 2026-01-15 · 33 min

0:00--:--

Key moments - from our scoring

Substance score

66 / 100

Five dimensions, 20 points each

Insight Density14 / 20
Originality12 / 20
Guest Caliber16 / 20
Specificity & Evidence13 / 20
Conversational Craft11 / 20

Brett brings a military intelligence background to fintech operations, having served 12 years in the U.S. Army before joining a firm (working with Max Levchin) and now serving as COO at Dub, a rapidly scaling investment platform. His core argument challenges the "move fast and break things" ethos prevalent in Silicon Valley: financial crime isn't opportunistic or random - it's coordinated, methodical, and devastating when platforms lack operational maturity. He explains how fraudsters probe systems, find vulnerabilities, go quiet for months, then orchestrate mass attacks (10,000+ coordinated accounts hitting the same exploit simultaneously). At Dub, this means trading short-term growth levers - incentivized onboarding, loose KYC, higher deposit minimums, unvalidated ACH links - for sustainable compliance infrastructure. Brett advocates for "mission command" doctrine from military strategy: leaders set clear end-state objectives and acceptable risk parameters, then delegate execution to teams. The key insight is that operations aren't a constraint on growth; they're the foundation that enables scaling without catastrophic fraud exposure. Dub's 25-person team manages hundreds of thousands of brokerage accounts by maintaining this operational discipline from day one.

Key takeaways

  • →Fraud attacks on fintech platforms are coordinated, multi-month reconnaissance operations followed by synchronized mass exploitation, not random individual attempts - making late detection catastrophic.
  • →Incentivized onboarding (referral bonuses, signup rewards) immediately attracts fraudsters at scale; the cost of fraud exceeds the growth benefit within weeks.
  • →Operational rigor and risk calibration must be led at the executive level and integrated into product decisions, not siloed as compliance overhead.
  • →The optimal risk tolerance is determined by monitoring capacity: expand user acquisition only as fast as your manual + automated fraud detection systems can confidently cover the cohort.
  • →Mission command doctrine - setting clear end-state objectives while delegating tactical execution - enables small, lean teams to manage complexity and make decentralized decisions during chaotic growth phases.

In this episode

  1. 1Brett's Background: Military Intelligence to Fintech Operations
  2. 2The Atlantic Crossing: Flying a King Air in Extreme Conditions
  3. 3Appreciating Operations in Silicon Valley: Building from Zero to One
  4. 4Transitioning from Military to Max Levchin's Firm: Creating the Enterprise Deal Desk
  5. 5Mission Command Doctrine: Applying Military Leadership to Startups
  6. 6Calibrating Risk and Fraud Prevention at Dub
  7. 7Balancing Growth Against Compliance and Security Controls

Mentioned

DubAffirmMax LevchinStevenBrettAir CanadaUnitedFootprintChimeCash App

Guests

Brett (COO of Dub)

Topics in this episode

Dub (investment platform)Max Levchin / a firmFootprint (fraud monitoring tool)Mission command (Army doctrine)AML/KYC (anti-money laundering / know-your-customer)ACH fraudIncentivized onboardingSource of funds checksPrudent risk-takingCoordinated fraud attacks

Questions this episode answers

Why do fraudsters attack fintech platforms in coordinated waves instead of individually?

Fraudsters conduct multi-month penetration testing to identify vulnerabilities, then go silent once found. After months of quiet, they execute synchronized attacks with 10,000+ coordinated accounts exploiting the same weakness simultaneously, making detection and response too late to prevent massive losses.

What happens when a fintech platform offers incentivized onboarding like referral bonuses?

Fraudsters immediately recognize the profit opportunity and attack the platform en masse. They test the system, find exploits, then execute coordinated large-scale attacks that overwhelm the platform's fraud prevention before it can respond.

How should a fintech startup balance growth velocity against fraud risk?

Risk tolerance should be calibrated to your monitoring capacity - expand user acquisition only as fast as your manual and automated fraud detection can confidently cover. As detection systems improve, you can increase the risk lever; as you scale, you must maintain this balance continuously.

What is mission command and how does it apply to startup operations?

Mission command is Army doctrine for distributing vision: leaders clarify the end-state objective and acceptable risk parameters, then delegate tactical execution to the lowest level. This enables small teams to make fast decisions during chaos without constant top-down instruction, as long as everyone understands the mission.

Why did Dub prioritize operational infrastructure (like Footprint integration) over viral growth features?

Operational infrastructure reduces fraud risk by validating bank accounts, checking source of funds, and implementing ACH buffers - enabling Dub to scale user acquisition confidently. Skipping this for short-term growth creates hidden fraud liabilities that explode later in coordinated attacks.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

14 / 20

The episode delivers concrete operational insights around fraud detection, risk calibration, and startup scaling - particularly the specifics of ACH fraud prevention, incentivized onboarding attacks, and manual monitoring systems. However, significant portions are spent on aviation anecdotes and military service background that, while context-setting, dilute the operational density. The core insights (risk thresholds, mission command applied to ops, the discipline of being the process) are substantial but would have benefited from tighter focus.

Let's spend this next month and a half integrating footprint, for instance, versus building the next new feature that could drive viral growth. Even something along the line of, hey, do we want to use incentivized onboarding? The minute you start giving away even a dollar, fraudsters will come knocking.
for the first year and a half, me and our chief compliance officer, we answered every ticket and we approved every manual review personally. I'm talking, we didn't outsource to any contractor, we didn't hire anybody. I, if you came to dub between the dates of like when we launched to last October, I single-handedly took every like almost every KYC case, every case in general, like I was doing a thousand cases a week

Originality

12 / 20

Brett applies military doctrine (mission command, prudent risk, end-state management) to fintech ops, which is somewhat fresh for a podcast audience but not deeply original - military-to-startup translation is an established genre. The core argument that ops is undervalued in startups is sound but not contrarian. The specific fraud patterns and risk-calibration framework are competent but largely restate known best practices in compliance and startup scaling.

mission command is essentially the underlying mechanism for which military leaders distribute and organize the vision of what needs to get done
prudent risk. It is risk that is acceptable to the mission. Uh and you have, and as a commander, that one of the most important things is calibrating your prudent risk-taking capability.

Guest Caliber

16 / 20

Brett is a genuinely credible operator: COO of Dub (13th on App Store), prior BizOps and fraud ops experience at a major fintech, 12 years in military intelligence and special operations. He has shipped at scale and navigated real fraud attacks. The only caveat: he's still relatively early in his startup career (Dub is pre-Series A or early growth), so while credible, he's not a proven multi-exit operator or established scale veteran.

Most recently, you are the COO of Dub, which is the fastest growing investment platform. I think I recently saw 13th on the App Store.
I did work very closely with like the fraud ops team and the customer support team at a firm

Specificity & Evidence

13 / 20

Brett provides concrete examples (the $20 referral bonus attack, the 10,000 coordinated fraudsters, ACH fraud buffers, Footprint integration, 1,000 cases per week manually reviewed) and named organizations (a firm, Bumped, Robinhood, Chime, Cash App). However, he lacks hard metrics on outcomes: no dollar losses prevented, no fraud rate before/after, no specific onboarding volume numbers, and limited quantification of risk thresholds. The specificity is stronger on process than on results.

do we want to offer like $20, $20 brokerage dollars if somebody refers somebody or if somebody like signs up? And it's immediately like the minute you do that, you're gonna you're gonna pay the price. And then they're gonna start testing you, and then they're gonna attack you all at once.
10,000 people all came in, did the exact same thing, and now you're upside down and didn't have enough time to shut it off

Conversational Craft

11 / 20

The host asks reasonable questions but rarely probes deeply or challenges claims. Follow-ups are often surface-level or tangential (the aviation story, the rehearsal show reference). When substantive topics emerge (risk calibration, the fraud attack dynamics), the host doesn't push back, ask for specifics on metrics, or challenge assumptions. The conversation reads more as a friendly interview than a sharp interrogation of a COO's decision-making.

How do you think about what is the right level of risk that you take on?
what was an adjustment? We spoke a lot about here are lessons that you're able to learn from the military and bring to the private sector. And I have more questions that we'll see in time we're manning. I'm curious on the on the other side, what was it like going from a conceptually we know a target and we're going to try to attack that target to I'm now the target

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

risk20military15mission14sure13trying12firm10first10didn9army9operations9fraud8growth8compliance8build8startup8level8

Episode notes

In this episode of Risk and Reason, Eli Wachs sits down with Brett Chereskin, COO of Dub, to unpack how real fintechs think about risk, fraud, and operational discipline at scale. Drawing on his background in military intelligence and aviation, Brett shares why incentivized growth attracts fraud, how attackers probe systems before striking at scale, and why early stage companies must calibrate risk based on what they can actually monitor. The conversation explores mission driven leadership, prudent risk taking, and why operations is often the most underrated competitive advantage in fintech. Chapters (0:00) Incentives, Growth, And Fraud Tradeoffs (1:03) From Military Intelligence To Fintech Operations (4:28) Aviation Lessons On Risk, Buffers, And Failure (8:43) Why Operations Is A Startup Superpower (14:55) Mission Command And Prudent Risk (18:30) Scaling Fraud And Compliance The Right Way (29:35) Rapid Fire: Metrics, Discipline, And Dub’s Advantage Follow Brett Chereskin LinkedIn: X (Twitter): Follow Eli Wachs LinkedIn: Check out Footprint Footprint is an AI-native platform powering identity verification, fraud prevention, and AI fincrimes agents for banks and fintechs.

Full transcript

33 min

Transcribed and scored by The B2B Podcast Index.

Let 's make sure we put a buffer into the minimum account deposits to prevent ACH fraud. Let's spend this next month and a half integrating footprint, for instance, versus building the next new feature that can drive viral growth. Even something along the line of, hey, do we want to use incentivized onboarding? The minute you start giving away even a dollar, fraudsters will come knocking.

And they'll come knocking in mad. We actually had that conversation. Hey, do we want to offer like 20 brokerage dollars if somebody refers somebody or if somebody like signs up? And it's immediately, the minute you do that, you're going to pay the price.

And then they're going to start testing you, and then they're going to attack you all at once. I thought that affirms. Like attacks don't attack them once each easy. It might be some penetrating attack that they're trying to figure out, like vulnerabilities.

And then once they find it, they go quiet for like months. Boom. 10,000 people all came in to the exact same thing, and now you're upside down and didn't have enough time to show it off. Welcome back to the Risk and Reason podcast.

I'm thrilled to have Brett joining us today. We've known each other for, I'm going to generously say a couple of years by now. That may or may not be true. But it feels like that.

At least I've been annoying you on Slack for that long. Brett has a really cool background. You spent, I want to say 12 years in the U.S.

Army and have worked at some of the most iconic fintech companies that have scaled tremendously, such as a firm leading operations internally. Most recently, you are the COO of Dub, which is the fastest growing investment platform. I think I recently saw 13th on the App Store. If Steven's LinkedIn posts are to be believed.

So really a tremendous career, but I want to turn it over to you because I'm sure I missed a bunch of it. Tell us about how how did you get into the world of fintech and ops and everything in between? Yeah, I think thanks for the introduction. It's been quite some time.

We've been going back and forth and uh we're almost at the uh finish line there. Um but yeah, uh as you mentioned, the military. Uh so my my time in the military, I was military intelligence officer that was also an aviator, so I flew intelligence aircraft. Part of that was uh, you know, there's that you know, going two paths here.

One is operations, like military folks are typically operations first. Um as a commissioned officer, I led organizations. I was uh in special operations leading uh you know development of a drone uh unit and asset, uh, all the way to flying reconnaissance missions in Afghanistan. But that comes with the operational side, but also the security and uh kind of you know, how do we uh, you know, just the military intelligence side of things, keep a close eye on that stuff.

So as it relates to my movement into fintech, um, aviation also is a very regulated industry. It is very much about compliance for the sake of staying alive. Uh finance is much more compliance for keeping people's uh monetarily safe, right? And preventing crimes, uh monetary crimes.

So I think there's there's good overlap between those industries. Um, kind of a unique story. I was offered a fellowship at a firm for uh uh recently transitioning uh veterans that were trying to find civilian jobs and ended up uh having a unique opportunity to work directly directly with Max Levchin and some of the senior executives over there. That was an incredible like growth opportunity as my first job out of the army.

And then from there um honed my my skills and uh Steven, the CEO and founder of Dub, found me when I was getting ready to go on to my next thing, and uh and that's the story, and now I'm here. So uh yeah, kind of a ideological, logical step in the right direction towards this industry. We're we're gonna touch on all of this. Now you you told me a story when we got dinner recently uh about I may mess it up, but you were flying a very slow aircraft and the headwind was so strong.

Uh I I could be off, but I believe that you were trying to go across the pond and you had to kind of turn around, but your radio was jammed, so you you had to get some Air Canada plane to tell Nova Scotia that you're coming in. I I hope I'm directionally right here. Uh what was that like? Yeah, so uh the aircraft I flew, for those that know aviation, was like a variant on the King Air, which is a propped airplane that is not designed to fly across the Atlantic Ocean.

So I was stationed in Germany. We needed to bring it to New Jersey, and essentially we had to like pedal jump across the North Atlantic in the middle of the winter to get this thing reset. And we were flying between uh we ended up landing in Greenland, which is a unique place to hang out, uh, got fuel and was trying, we're trying to get to St. John, Canada, but we had this 110-knot headwind, and you know, when you get to that part of the the aviation world, you actually report on like the crossings of latitude and longitude.

So we're kind of trying to give the next crossing point that we're about to hit um to uh you know Maine is like it's like the uh the air traffic controller that's like in that region. And we couldn't get a hold of him, so we heard an Air Canada flight on VHF, and we're like, hey, can you just let you know the center know that we're we're about like eight hours out to our next reporting point? And the the pilot is like, How are you eight hours out from talking to me right now?

Like, how fast you're going? It's like uh ground speed of about a hundred miles per hour. He's like, What kind of aircraft are you? And we're like, Oh, we're a king air.

He's like, Why are you in the North Atlantic in a king air going that slow? And we're like, uh, we're the we're an army crew, and they're like, he was like, Oh, that explains it. And he passed it along with his satcom, but it was uh it was one of those funny moments where you know you're doing something a little bit crazy, but it reinforced the crazy when other airline pilots are just asking you what the hell you're doing up there. So uh it was a it was a good venture what are you doing in the cockpit of an eight-hour uh like 200-mile flight?

Calculating your fuel over and over and over again. So essentially, like if it got if it got too windy, if the headwind was too strong, you end up hitting like the point of no return, right? So we were constantly calculating manually and digitally over and over again. Are we going to cross that point of no return with high levels of confidence?

Like we we put in a buffer, but like you can never control the environment. So ultimately, there was and what's your altitude in this? We're I think we were flying at like 30, 34,000 feet. Um, so we're up there, pressurized aircraft.

We're we're playing up. And then we were actually also hunting for lower headwinds. So when you're up that high, you can actually maybe drop down. But here's the paradox: you come down further, you might lose the headwind, but your burn rate increases because engines are optimized at you know higher altitudes.

So boy, we're going way off topic. Well, I'm teaching you about the uh aeronautical uh principles. We're gonna we're gonna no fun intended land the plane. Uh my final detour here, have you have you seen the show The Rehearsal?

I have not. Okay, I'll I'll pitch you on this offline, but it's a show, a comedic show about uh the relationship of airline pilots, so I'm curious. Um but when when you we'll we'll we'll we'll we'll come in here. You you're doing you're doing spec you're doing spec ops.

Um you I I think that what I've taken away from having the the chance to speak with people like you, people like Kelly Deckerson, who who come from an army background, there's this appreciation for ops in a way of I've heard Kelly talk about, you know, he was on a battlefield in Iraq and the tanks were positioned in a way that saved people's lives just because of ops and the training. Uh I think ironically, when you go to Silicon Valley, ops are like the people who you have to bring in to to make sure you're staying on top of things.

Uh could you maybe talk about kind of the appreciation that you develop for ops? Because I've increasingly seen as we've grown, ops is actually what makes companies go up a lot more. I actually think that ops are the the areas that you didn't even realize that by building this function from zero to one, you will get so much alpha. But I think the I I I think it's this interesting thing where it it wasn't seen as sexy versus when you speak to people who are truly flying planes uh and launching drone programs in Kandahar, they'll actually tell you that that ops is the root of everything.

So uh how how do you kind of think about that? Yeah, I think you know, the biggest like so the the typical like thing that people say is like, hey, we're too lightweight, we're too lean to worry about operations right now. Let's let's build, let's find product market fit, especially early stage startups. They love to tout that they are flexible and they can pivot on a dime.

And the coming from the military, operations is the lifeblood of the organization because in a large organization, the you know, the military is huge and it's filled with people, and it's it's difficult to communicate. In the fog of war, it's difficult to communicate even tactically sometimes. So, like, what is the the what are the two things? There's actually three things that really tie it together.

When when all else goes and fails, it's your mission, your values, and the operational overlay, or the SOPs, or the common language spoke through action that ties an organization together and makes them succeed when stuff gets tough. And when I'm thinking about a startup, while it's not this giant organization, it is the fog of war. That's where I equate a startup to. You're in a fog of war.

You might not always be able to communicate with each other, you might lose slight context at the nooks and crannies of what's going on. Something stops happening, no one's covering it, and you don't know what's going on there. And that's where I think uniquely, like Stephen recognized as he was building dub, he's like, I want a strong operational culture. And like he indexed on that by hiring me early in the trajectory of the company.

And I think a lot, I'm not saying I'm personally responsible for any of this, but us all being dedicated to what the operational overlay does to the people, the clarity of mission and vision, and the ability to keep a few people doing a lot. Like we have hundreds of thousands of open brokerage accounts, we have hundreds of thousands of users, we have a million different things happening at any given moment. And without an operationally sound organization of, you know, we're currently only like 25, 26 people.

We couldn't do that, right? It just becomes quickly hazardous, and we've built a stable core. And I think another thing to call out here is like operations also is the foundation that you could build on. And I think being able to build on this foundation is what's giving uh dub the legs and the ability to kind of navigate market conditions, navigate private markets, navigate fundraising.

It's just there's a ton of inputs and just having that foundation to kind of pivot off of is really what's important here. Yeah, and I'm also trying to like not a number of complicated things too here. So that's always another topic that we should probably delve into. We we definitely will.

What was it like going from spinning up drones to uh working with Max Lovchkin uh at a firm? What was that transition like? What got you interested in that as well? Yeah, so I I eventually I started, I was like employee like I think under 200 at a firm.

It was early, it was 2017, and I knew nothing about tech. I knew nothing about startups. I was just like, how do I make as much money as I was making as a major in the army? And if that checked the block and I got to live somewhere cool like San Francisco, I went for it.

And I took a huge risk. I actually, during this fellowship, I had to like leave my wife in Florida to like help like close up the house and sell it and move it. But ultimately, um I realized I got in there, I was like, okay, none of these people are very operational. Um I think like, and it kind of gave me an identity crisis, to be honest.

I I was like this generalist. Like I love to I love to comment that people in the military, when you become a senior officer, you become a general. And like that term comes from the fact that you become the most senior generalist in the military, right? There's a reason behind that term.

And I think officers in the military in general are generalists, they're an inch deep and a mile wide. And I realized there's nobody like that, maybe other than the exec, some of the executives that were pretty like head on a swivel, very clearly understanding all the business inputs, the technology inputs, the customer inputs, and bringing it together. So when I looked at this at the microcosm, I was working on like new markets for enterprise. And I was like, wow, there's a lot of people that don't know what's going on.

And I made it my mission to make sure the right people had the right information at the right time. Like, that's operations 101, right? That's that's building a drone unit, that's deploying to combat. It's it's the the idea of building a team of people that have the same mission.

So when we got like, hey, we want to work with United, there's an RFP out here. I was like, okay, let me understand what everybody needs to know, when they need to know it, and why they need to know it, and let me get that done. And I and I remember I kicked off like this, like we called it like the enterprise deal desk. It started with a whole bunch of reluctant people being like another meeting.

And in three months, it became like the execs were in the room, and the they were actually like, hey, we need to kick some people out of here. Like, this is more of like a high-level like strategy discussion. Like, let's limit it to like one person per function. And like it be it, I didn't advertise it, I didn't ask people to come.

Uh, one lawyer hears that it's like they're getting the information they never got. Ops found out that from the support side, they were getting like an early read on the new clients coming through the pipeline, and it all synthesized into like this really meaningful function of like information delivery and collaboration. And people started getting ahead of the power curve, and we became better at expanding on new markets, right? And taking on enterprise clients for the first time.

So that was a transition. It literally went from I don't have an MBA, I didn't have any experience doing this. I had experience getting people the right information at the right time and having people work together, right? So direct correlation.

And I like this concept a lot in that I think we often say the constraint, why can't we just hire more engineers or more salespeople? It's information. It's we we it's only so scalable to train people in the things that they need to know. When you think about that transition, is there like a leadership lesson of this is how the army thought about distilling information that you're able to bring to the enterprise deal desk?

Yeah, I think one thing that I I love and I bug the hell out of people about this, especially leaders, is this idea of mission command. And this is army doctrine like 101. And mission command is essentially the underlying mechanism for which military leaders distribute and organize the vision of what needs to get done. And it essentially consists of a few things.

One is uh the mission that you have to really clarify the end state mission and goals. Um, it's a lot, I always say end state management is the key to execution because it stops you in your tracks from telling people how to do it, but it tells you you're telling them what you want to see done, and it lets them solve it at the most tactical, lowest level possible. So, like as a drone commander, is like we need to build, we like for me, it was like we need to provide this many hours of intelligence, surveillance, and reconnaissance over this geography by this date.

Like that was my commander's intent, right? How I did it, there's a million functions, and all the different individual functions will have a way of solving that. So, like, you need that to kind of, you know, your end state. So if you can clarify the your end state and your vision and then orchestrate that through a shared framework of values, um, that's what mission command is.

And like you also have to some things, like little buzzwords from the doctrine, it's like you have to be able to delegate uh to the lowest level possible. You have to be able to, you need to be willing to take prudent risk. And I always, and this is relevant to this, prudent risk. It is risk that is acceptable to the mission.

Uh and you have, and as a commander, that one of the most important things is calibrating your prudent risk-taking capability. So what it boils down to is judgment. Like you have to have good judgment, you have to have good values, and you have to have a clear vision. And if you can communicate those three things and then build in pretty systemic feedback cycles, you win.

And this is how your radio goes dead. Your soldiers know exactly what to do. Because they're not asking for what's next, they know exactly what the end state of the that mission is, including we call branches and sequels. What happens if we get to the end?

You do this. If we don't get to the end, we branch here, right? So these are like very hardcore doctrinal terms that I'm bringing up. I I like this concept of prudent risk.

Uh, you know, you probably see many different types of fraud uh not the attacks, like people who are trying to take advantage of your platform a different way. You know, we say if you want to get rid of all fraud, you can just let nobody on the platform. It's very easy. Um obviously there needs to be some type of toggle.

How do you think about what is the right level of risk that you take on? Obviously, at the end of the day, nothing's in a theoretical vacuum, and everybody's, whether they're aware of it or not, are taking on a form of risk, but how do you actually try to measure that and say this is actually a good risk for us to take? Yeah, this is actually one of the hardest. Um, this not only to like AML, KYC stuff, risk calibration and is like the heart of what an executive is designed to do.

Because there's no like hard and fast answer. It is completely a judgment call uh based off of experience and knowledge. And if you would uh you know, that's why execs wear a heavy burden because they they essentially have to sit there and it goes to business risk, it goes to you know spending on marketing, how much do we want to spend before we get clear like ROI? How much, like, how like we don't have attribution, how do we go?

So ultimately, like orchestrating risk, like first off, when it comes to like AML, KYC, onboarding, compliance, um, it's very important that you don't just look at it through a vet like a stovepipe. You're looking across the business. What how what is the stance of risk across your entire business? And where does this kind of financial crimes AML stack on running out of runway?

Or you know, we we're an investment platform. There's a million other aspects of risk that we have to deal with. We're also a registered investment advisor. There's we're managing risk across multi facets, but ultimately, when we first were kicking this thing off, um, we wanted To only take on as much risk as we would feel that we are capable of monitoring at any given time.

So, and I'll break this down more specifically. Like, if we were taking risk on who we were letting on the platform, we could only take on as many people as we could manually monitor every day, right? And so, as we built better monitoring systems, we could take on more people. And then we were like, okay, let's add redundant systems to our onboarding platform to give us an extra layer of confidence that who we're getting, there's a lower probability.

So, like everything was a mathematical equation of like the probability is going down as we scale up. And essentially that's like manual coverage to begin with, automated checking and redundancies, and then there's audits, and then it's essentially um live testing. Like now we're we're live for six months. How many failures have we had?

How many known failures, right? We have to assume there's unknown failures occurring, but then being able to like quantify the known failures against a known quantity of acceptable like pass-throughs is is where it really kind of honed itself. And it continues to this day. It's a toggle.

And by that, or like a I'm sorry, like a a lever. And by that I mean you know, some people can view it very much in a vacuum. I think this is a pretty fair way to say, you know, hey, like we can move this up or down, but are we a freemium product or are we a subscription? Uh or are we letting people deposit with a chime account or Cash App, or are we restricting this to a bank account we linked or something like a card we use with 3DS?

It also brings into focus this idea of you know risk in Teams from a KYC perspective, uh is a higher level, like can almost be thought of as a higher level conversation because it does directly impact product and the acting kind of product people are leading it. Um how crowd, I guess when you think about all those different levers that are in there, how do you how do you try to one approach uh like the way of thinking, like, do you the there's the I'm bad with analogies, but it's the the tail wagging the dog, right?

Like which one do you how how do you think about like which one should be dictating the other and like how that dance should play out? This is a this is a spicy topic, right? So we all know that as a startup growth is growth is king. It's the primary objective.

And when I go and say, well, we can't let you know, things like let's raise the minimum deposit, let's make sure that the bank account that they're linking is confirmed to the name on the account. Let's make sure, like there's you know, source of funds checks, let's make sure we put a buffer into the minimum account deposits to prevent ACH fraud. Let's let's do, you know, let's let's spend these next month and a half integrating footprint, for instance, versus building the next new feature that could drive viral growth.

Um yeah, right. Uh and just even something alongside the line of like, hey, do we want to use um incentivized onboarding? Well, the minute you incentivize anything, the minute you start giving away even a dollar, fraudsters will come knocking and they will come knocking in mass. So, like, we we actually had that conversation.

It's like, hey, do we want to offer like $20, $20 brokerage dollars if somebody refers somebody or if somebody like signs up? And it's immediately like the minute you do that, you're gonna you're gonna pay the price. And then they're gonna start testing you, and then they're gonna attack you all at once. And like I've still I saw this at a firm, like attacks don't just happen onesie twosies.

Like they might be some penetrating attacks that they're trying to figure out, like vulnerabilities, and then once they find it, they go quiet for like months, and then they just boom. 10,000 people all came in, did the exact same thing, and now you're upside down and didn't have enough time to shut it off. Like it's it's dangerous. So back to your question, tail wagging the dog.

I think this is I think it was unique where Steven, the CEO, was leaving leading growth and marketing. I was leading operations, and and with our compliance officer Justin, we're constantly kind of circling like what's the right levers to pull at what time. And and and then we had a CTO that came from Bumped, which is another broker dealer startup that learned a lot of the lessons on the fraud and compliance side. So he was dialed in.

And I think the four of us navigated a very tumultuous first year and a half of being live, but uh we did, in my opinion, damn good. Um, we we closed up all those gaps preemptively. We've built really robust systems ahead of when most companies probably would because we understood that if we didn't have that foundation of security and trust, we could blow it up no matter how fast we grew it, right? It it all makes a lot of sense.

Um I guess I'm curious, what was an adjustment? We spoke a lot about here are lessons that you're able to learn from the military and bring to the private sector. And I have more questions that we'll see in time we're manning. I'm curious on the on the other side, what was it like going from a conceptually we know a target and we're going to try to attack that target to I'm now the target and I need to try to build up the fences to prevent people from getting me?

Yeah, like luckily, my time at a firm, I uh I was in the BizOps space and and I was on the commercial side prior to that, but I did work very closely with like the fraud ops team and the customer support team. And um it be it became clear that like there's a lot of organized, very, very, very smart people um trying to exploit. And I think I that helped me. That me that was like my first big transition of like I'm the predator, but now I'm the prey from going from military to like a fintech.

And then um coming here, I I carried a lot of that, and like I did have a good, it was really a really healthy organization at a firm that really took it seriously. Like it was one of it was a heavy investment of the team, and they never joked around. And and I actually think it's harder at a firm than at dub because the job of a firm is to give away money, essentially. You're given loans, right?

So if there's a target, that is the prime target. One thing that's good about being a retail investing app is it's kind of hard to structure um attack that's gonna be like lucrative to these people. I think the biggest one that we were seeing attempts multiple times were essentially like um you they deposit with one bank and it's essentially money laundering. They're trying to like deposit with one bank and then withdraw to another.

And other than that, it was really hard like for them to walk away with cash. And then we built, there's already baked-in systems. So cognitively, I was I was primed for my firm time, and then coming here felt like I was going from like being like an absolute target to just a partial target, and a lot, but we all had good lessons learned. So we all committed to it.

Like we all said, hey, we want to make sure that we were the dual path in growth with security and and fraud protection. I guess we military is famous for being disciplined. How do you think about being disciplined like when you're scaling up a startup? One of the biggest things you'll hear in the valley is you have to be disciplined about how you hire, about what product you build.

You only have so many bets. How how do you think about that level of discipline? Because then it's also how do you say disciplined about your risk and compliance and making sure that that's actually scaling properly? Yeah, for okay, for the first year and a half, me and and our chief compliance officer, we answered every ticket and we approved every manual review personally.

I'm talking, we didn't outsource to any contractor, we didn't hire anybody. I, if you came to dub between the dates of like when we launched to last October, I single-handedly took every like almost every KYC case, every case in general, like I was doing a thousand cases a week, but like that's how you stay disciplined. You are the process. I I physically said I'm going to be the COO of this company and B the process.

And like it twofold. A, I saw the attacks happen firsthand, so I knew exactly what to look for and how to foil them and how to build for them. Two, I learned where people were heading friction with the app. So I was immediately feedback to the product because when you have the COO having to clean up a mess, that mess doesn't persist.

You know what I mean? Like, we'll fix that and fix it quickly and make sure users are in a good state. So I think, and and like this is something that like our board respected and our investors are like, wait, Brett and Justin are like on support? It's like, yeah, you sure are.

Because like there's no other way for me to train the next person, and you know, we're learning our hard lessons early, and that's when they're the most vulnerable, too. So even higher priority to take that action first. I have a couple of rapid fire questions for you at the end here. What's the metric that you're maybe most obsessed over?

Um, and this can be about operational efficiency, it can be startup metric. Uh what do you what do you obsess most about internally now? So our for us right now, what we care the most about is how much money our users are creating. Um making, right?

Like, are you like why exist, like, you know, and and we've been really, you know, the market's been up and to the right for many months, years now. Um, we're obsessing right now over like how do we ensure we continue the track record that we've provided for our users, and how do we make sure that everything we do is in their best interest? And like, this is how much over the SP 500 they've hit. This is, you know, all those investing metrics that we just we if we're not doing that, we don't deserve to be a company.

We shouldn't exist. Like, we're not making the world a better place. Because our whole premise is we're democratize democratizing access to retail investing strategies that typically aren't available to those that that don't have a ton of cash. So as long as we continue to make people make their lives better, that's what I'm obsessing over, quite honestly.

Tougher to manage a platoon or a uh or a team in a startup. Good question. Military folks, yeah, they're they're they're tough. It in a time of clear mission, like if we're going to combat, if we're doing something, like army's easy to manage because we all know exactly what to do.

But when you give them too much free time, it's very difficult. But I would say startups are much more difficult because you have a lot more constituents to make happy. Like in the army, it's one job, do the mission, do the mission right. Uh in this startup, especially as a COO, I'm like, do we how's spend?

Uh how's HR looking? How's growth? How's fraud? How's the market?

How's our you know, users' financial well-being? Like, there's there's a million things. Our product, is it working? Is it up?

God forbid it goes down for a second during a trading day. Like it's a different level of stress, yeah. And my final question: what do you think is dub's most unfair advantage? Or in other words, like what has you most excited about dub as we go into 2026?

I think we're we're we're the first to really tap into this idea of copy trading through the lens of a brokerage. Uh, we have a compliance moat, we have a head start, you know, Robinhood's trying to do it. EToro just said they want to get into the US and start doing it, but we have the users, we have the reputation, and we're building the brand, and the brand is becoming recognizable. And you know, let's go do this, is my attitude right now.

So we have nothing but opportunity. Uh we have white, white space ahead of us to grab and continue to grab, and I just want to take advantage of that. I love it. Thank you so much for joining.

This is awesome. Uh I'm gonna send you clips from the rehearsal, and I'm curious your thoughts. And uh I'm sure I'll see you soon. Awesome.

More from Risk and Reason

All episodes →
  • What Banks and Fintechs Get Wrong About Each Other w/ Ethan from FS Vector79 / 100
  • Why the Right Eviction Rate Isn't Zero w/ Brendan from Findigs92 / 100
  • From eBay Skunkworks to Agentic Payments w/ Shayanth from Highnote86 / 100
  • Zero Fraud Means Zero Revenue w/ Zach from Comun79 / 100
  • Hurricane Sandy Broke Banking w/ Phil from American Fintech Council75 / 100
All Risk and Reason episodes →