AI Came for Bitcoin First | Jameson Lopp

15 Sep 2026 · 1 h 16 min · 34 chapters

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

How AI-driven tooling is accelerating Bitcoin (and broader internet-connected) security threats; why recent Bitcoin hacks show defenders must “race” attackers; and practical self-custody guidance (hardware wallets, entropy, multisig, privacy/duress).

Guest

Jameson Lopp, long-time Bitcoin security figure and founder of Casa (Bitcoin security/custody services). Background referenced: led/participated in Casa’s security work, runs/uses red-team and vulnerability reporting; discusses Casa’s LLM-assisted pen testing harness and security audits.

Key claims

  • Security is still a cat-and-mouse game, but AI increases “velocity” via faster LLM iterations and cheaper open-weight models.
  • Bitcoin is a “canary in the coal mine”: attackers will move to other valuable systems after Bitcoin.
  • Cold Card and Liquid hacks illustrate that fixes can worsen vulnerabilities; responsible disclosure and patching must be careful.
  • No code is ever “done”: dependencies and “security debt” accumulate; Casa aims for near-daily full audits using AI plus human review.

Notable examples

  • Liquid hack: attacker still holds ~600 BTC (~15% of take).
  • Revolut/KYC theft mentioned as a sign financial systems may be next.
  • Cold Card issue: RNG swap with pseudo-RNG; later firmware changes require user-added entropy.
  • Dependency compromise risk: malicious code in tiny libraries used widely.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Chapters

Tap a time to open that second in VO

Introduction to Security Threats

0:00 to 0:50

Learn about the evolving threats to Bitcoin and other industries.

“The malicious threat actors aren't going to just sit on their hands and say, okay, well, that was good.”

Understanding Recent Hacks in Bitcoin

0:50 to 3:49

Explore the recent hacks affecting Bitcoin and what they indicate for security.

“And it just feels like the game of security when it comes to Bitcoin has changed entirely.”

The Liquid Hack Explained

3:49 to 6:04

Get insights into the Liquid hack and the implications for Bitcoin security.

“And the reason it's the canary in the coal mine is because if you get someone's Bitcoin keys, then they're yours.”

Vulnerability Discovery and Responsible Disclosure

6:04 to 7:40

Discuss the challenges of vulnerability discovery and responsible practices.

“I seriously doubt that the attacker spent more than a few hours actually finding this vulnerability.”

Caution with AI Tools in Security

7:40 to 9:48

Understand the risks and challenges of using AI tools in security practices.

“And I think really goes to show that you have to be extremely careful on both sides of the equation here.”

Caution with AI Tools in Security

10:32 to 11:22

Understand the risks and challenges of using AI tools in security practices.

“there's going to come a time when you need some dollars.”

AI's Impact on Security Dynamics

13:25 to 14:00

Explore how AI is changing the landscape of cybersecurity and vulnerabilities.

“phase where the AI, they're just so much more powerful and methodical and they don't need to eat or sleep and you can basically have them churning away 24-7, 365.”

AI in Software Security Testing

14:00 to 14:57

Learn how AI is being utilized to enhance software security testing processes.

“these tools, you're orchestrating massive swarms of different models to coordinate with each other.”

Understanding Technical and Security Debt

14:58 to 17:21

Explore the concepts of technical debt and security debt in software development.

“and even starting to close the loops of vulnerability discovery to vulnerability resolution and patching and stuff.”

Vulnerability Assessments and Findings

17:22 to 18:25

Discover the process of vulnerability assessments and the findings from security audits.

“And so, you know, annually we would get, you know, 10 to 20 of those security disclosures in the report.”
Show all 34 chapters

Daily Security Audits and Code Review

18:26 to 21:28

Learn about the implementation of daily security audits and the importance of code reviews in software development.

“and software engineering, like OWASP-related things that you need to follow.”

The Race Against Compromise

21:29 to 23:04

Understand the urgency in improving security measures to avoid being compromised.

“And so, yeah, it's just, like I said, it's a race making everything faster.”

The Complexity of Software Security

23:05 to 24:30

Examine the complexities involved in achieving secure code in today's software landscape.

“But if it is something else, it is quite scary.”

Managing Dependencies and Vulnerabilities

24:31 to 28:00

Learn about the challenges of managing code dependencies and related vulnerabilities.

“and it's because there's always more to it than just the code, right?”

Dependency Management in Software

28:00 to 28:59

Learn about the challenges and strategies in managing software dependencies.

“need to update this dependency because these vulnerabilities were found in it.”

AI and Software Development

29:00 to 30:11

Discover how AI is influencing the software development process and coding languages.

“I've never written a line of code in my life before AI, but now with voice to text, I've got it to write some code.”

Challenges in Code Security

30:12 to 31:22

Understand the complexities of ensuring code security and the potential for malicious code.

Analyzing Cold Card Vulnerability

31:23 to 32:58

Explore the Cold Card vulnerability and the implications for security in Bitcoin.

“And like I said, if, if anything now, you know, having, having these agents be able to look at it and basically be much more methodical than a human would be.”

Analyzing Cold Card Vulnerability

33:05 to 33:15

Explore the Cold Card vulnerability and the implications for security in Bitcoin.

Trust and Verification in Bitcoin Security

33:56 to 35:21

Discuss the importance of trust and verification in securing Bitcoin hardware.

“I mean, I think there's plenty of blame to go around.”

Resource Discrepancies in Bitcoin Projects

35:22 to 36:54

Analyze the differences in resources between Bitcoin hardware manufacturers and their impact on security.

“But if you compare the companies, and I don't know the numbers off the top of my head, but let's say rough order of magnitude, Coldcard as a company is probably making millions of dollars a year in revenue.”

Best Practices for Bitcoin Self-Custody

36:55 to 38:46

Learn about the best practices for securing your Bitcoin through self-custody.

“And even to add to that, Ledger have their dedicated team in a dungeon that are constantly trying to break Bitcoin hardware wallets.”

Evaluating Security Approaches

38:47 to 42:05

Examine different security approaches for protecting Bitcoin holdings against theft.

“Like from maybe we start with the person that has somewhere between a thousand and ten thousand dollars in Bitcoin.”

Trust and Security in Bitcoin

42:05 to 45:33

Learn about CASA's approach to security and the importance of not trusting any single device.

“And that's basically what we've been doing for nine years at CASA.”

Entropy and Random Number Generators

45:33 to 49:44

Explore the significance of creating your own entropy and the challenges involved.

“and plug it in and set it up and then use our key rotation functionality within the app to basically heal their slightly partially compromised setup.”

Choosing Between Multi-Sig Configurations

49:44 to 52:12

Understand when to upgrade your Bitcoin security from two-of-three to three-of-five multi-sig.

“And so that's also an order of magnitude increase in cost where our two of three tier is really designed to be more self-service.”

Privacy and Security Concerns for Public Bitcoiners

52:12 to 56:00

Discuss the risks of wrench attacks and how to protect personal information as a public figure.

“Whereas if you had that type of model for your car, then you would only want to be driving a tank around.”

The Necessity of Deception

56:00 to 57:20

Explore the complexities of using deception for personal safety in Bitcoin security.

“different levels of false information, really.”

KYC Challenges and Data Security

57:20 to 59:30

Discuss the problems with KYC regulations and the implications for personal data security.

“And almost every exchange out there where people are acquiring their Bitcoin asks for egregious amounts of personally identifiable information.”

AI-Enabled Attacks and Scams

59:30 to 1:02:20

Learn about the rise of AI-driven scams and how to protect against them.

“And we've just seen that Revolut's been got, which is a massive, massive fintech, like tons and tons of information.”

Understanding Social Engineering Tactics

1:02:20 to 1:07:50

Delve into the psychological methods used by attackers to exploit vulnerabilities.

“Yeah, well, we'll have several lengthy clips coming out soon.”

The Complexity of Cybercrime

1:07:50 to 1:10:00

Examine the structure and profitability of international cybercrime organizations.

“And the thing about security and about all this stuff is that if you're the defender, you have to be successful 100 % of the time.”

North Korean Threats in the Crypto Space

1:10:00 to 1:15:10

Learn about the tactics used by North Korean actors to infiltrate cryptocurrency companies.

“And I don't know if you can talk about this, but before we started recording, you said there might be something coming from someone from North Korea.”

Conclusion and Actionable Security Advice

1:15:10 to 1:15:36

Discover actionable advice for improving your security setup in light of emerging threats.

“I think there's hopefully been some good actionable advice for people who are rethinking their security setup.”
Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:02The malicious threat actors aren't going to just sit on their hands and say, okay, well, that was good. No, they're going to move on to the next industry, to the next set of valuable internet connected infrastructure that they can try to siphon as much value out of as possible. So, you know, the rest of the world, of course, should always have been paying attention to Bitcoin, but they should be paying attention to it for a very different set of reasons now because they're next. You know, if you're not racing along with everyone else, then it's pretty much guaranteed that you're going to get compromised at some point because there's a lot of other people out there that are actively using these tools against you.

0:50all right jameson lot back on the show and wow we have a lot to talk about when i was going through the list of things for this show it's basically a never-ending list um i think probably the best place to start is just to get a kind of 10 000 foot view of the security apparatus around bitcoin right now and how you're looking at things because since the cold card hack we had rob hamilton spin up the red team as him and cali and a load of others doing really great work there Then we had the liquid hack more recently. And it just feels like the game of security when it comes to Bitcoin has changed entirely.

1:24Or maybe it's the game of security more broadly. What's your overarching view of everything that's happened? Well, the best way I can describe the past month and a half is that my beard used to come down to here. And now it's right here. And it's because I've literally been pulling so much of my beard out over the past month and a half. So the fundamental nature of security and cybersecurity, whatnot, has not changed. It is a never-ending cat and mouse game, attackers versus defenders. What has changed is the velocity, and that's basically the result of the accelerating LLM iterations. Like every few weeks, a new model is coming out that is pushing the frontier forward.

2:19And the open weight models that are orders of magnitude cheaper are cashing up. And so basically the tooling that is available to both attackers and defenders in this space is surging forward. And the attackers, as is the case with most advancements, the attackers tend to be earlier adopters. They are more motivated to be early adopters of this tooling because the bounties, the return on investment is so high. And so the problem is that a lot of the defenders have basically gotten caught off guard. And we've seen an acceleration in vulnerability discovery in the Bitcoin space. And what I've been trying to tell people is that this is the canary in the coal mine.

3:10You know, once once all of the easy money has been picked out of the Bitcoin space, the malicious threat actors aren't going to just sit on their hands and say, OK, well, that was good. No, they're going to move on to the next industry, to the next set of valuable Internet connected infrastructure that they can try to siphon as much value out of as possible. So, you know, the rest of the world, of course, should always have been paying attention to Bitcoin, but they should be paying attention to it for a very different set of reasons now because they're next. And the reason it's the canary in the coal mine is because if you get someone's Bitcoin keys, then they're yours.

3:53The Bitcoin is yours. It's very, there's very little recourse. It's very hard to actually do anything about that. But what would the next industry be, do you think? I know we've seen in the last few days that Revolut has got attacked and a load of KYC information has been stolen from them. But does it remain within financial systems, do you think? Or do you think that you'll see these go after the grid and power supply and things like that? Yeah, I mean, I think generally financial systems will be next. Further down the line, basically any sort of system that contains personal identifiable information, things that can then be used to perform identity theft and, and more roundabout ways of, you know, financial theft.

4:37Um, and then of course, infrastructure attacks, uh, that, that's, that's going to be more of a, either a nation state thing or a, um, you know, voluntary anarchist, uh, type of, I want to screw with, with other groups type of, uh, fun hacking adventure. Um, But yeah, I mean, anything of value, and of course, over the past few decades, more and more of the global infrastructure has been connected to the internet. So, you know, if you're connected to the internet, you basically have a door there that billions of people can start knocking on. and now they can really automate that knocking and increase the sophistication of the discovery that they're doing by essentially leveraging these highly compressed knowledge bases into doing a lot of the technical heavy lifting for them.

5:36So when it comes to the cold card hack, I've covered that a little bit on the show. I've done at least two or three shows on that, but I've not spoken about the liquid hack more recently at all. Can we get into that? Can you give us some information about what exactly happened? I know these so-called white hat, not really white hat hackers, initially stole 4 ,000 Bitcoin, I think, and then gave a large portion of that back. But where are we at right now? Yeah, at the moment, I think they're still holding on to about 600 Bitcoin, about 15 % of the take there. And it's unfortunate from a, call it a white hat or gray hat perspective, because how many tens of millions of dollars is that it's an absurd amount to claim that you have a right to simply because you were able to use one of these tools.

6:26I seriously doubt that the attacker spent more than a few hours actually finding this vulnerability. So like from a amount of effort that they put into it versus the payoff, it's absurd that they think they should get tens of millions of dollars. You know, meanwhile, we have a Bitcoin red team that has submitted hundreds and hundreds of vulnerability reports and, you know, they're not asking for anything. They're just doing it because they care about the security of the overall broad ecosystem.

7:01I think that this is another thing that's also going to happen more frequently because now you're going to have less sophisticated people getting their hands on these tools and basically getting in over their heads and not being familiar with the proper way to do responsible disclosure. And so they're sort of stumbling into massive vulnerabilities and potentially massive jackpot payoffs. And they just don't have the maturity or the understanding of the ecosystem to be able to do this in a way that we would consider responsible. Now, I don't think we've yet gotten a full postmortem of the series of events that led to this, but it does sound like it was actually a result of a vulnerability report that led to a fix for that vulnerability that actually created a worse vulnerability that then was exploited by this attacker, which is extremely unfortunate.

8:09And I think really goes to show that you have to be extremely careful on both sides of the equation here. These are very powerful tools, but they can lead you down paths that actually make you worse off if you're not really careful about what you're doing. And so that's why the stuff that we're doing at CASA, we are using a variety of LLM-assisted methodologies. but we're never just taking any one model for granted. We're always using multiple models to cross-check each other's work, and we always do have a human in the loop for final code review and sanity checks. But basically, you can't trust any of these things.

8:56I think I wrote an article a few months ago that was basically entitled Don't Trust the Clankers, and it spoke of several security incidents that we actually had internally at Casa with what I would call overly eager or too helpful models where an employee would ask a model to help do some task and the model, you know, not being given really any guardrails or specific restraints around how it was supposed to accomplish that task would essentially end up hacking the employee themselves in order to be able to get authentication or credentials or access whatever materials were needed to accomplish the task.

9:46So yeah, you have to be really careful. It's like these things aren't necessarily malicious. They're not intelligent per se, but they can do, you might call it malicious compliance in order to achieve the goal that you give to them. Yeah, they'll find the shortcut. It's interesting, though, because obviously before any of this started happening, I think it was probably, you know, everyone thought that open source code is the most safe because it has the most eyes on it. Like you'd imagine that would be the most vetted, the most tested. Does this kind of call that into question where you may be better relying on closed source code because then at least it's not completely viewable by these AI systems that are trying to attack whatever the infrastructure is.

10:31If you hold Bitcoin long enough, there's going to come a time when you need some dollars. It might be a tax bill, a business expense, life getting in the way, but whatever it is, it might come at a time when you don't want to sell your Bitcoin. That's where Ledin comes in. Ledin lets you borrow against your Bitcoin instead with tiered rates that go as low as 9.25%. So you don't have to sell your stack if you don't want to. Ledin have operated through every market cycle since 2018 and have originated over$11 billion in loans. but the important part for me is the way Ledin handles these loans. Your collateral is held in custody and never lent out to generate interest.

11:03And Ledin's more than just loans. Tether Gold is now live alongside your Bitcoin with instant trading across 10 pairs and later this year you'll be able to borrow against gold in the same way that you do with Bitcoin. Ledin really is an awesome company. I've used them multiple times. The applications have taken me less than 15 minutes and you have the dollars in your account within hours. If you want to check out Ledin, go to ledn.io and use the code WBD for 0.25 % off your first loan. That's leden.io and use the code WBD. Every Bitcoiner eventually has to answer one question. If something happened to me, would my family know what to do?

11:37Could my wife or parents recover my Bitcoin? And would my children inherit the Bitcoin that I spent years stacking? That's where Anchor Watch builds Bitcoin custody models to protect you and your family against real life, accidents, errors, kidnappings, and even your own death. Every Anchor Watch custody solution includes their inheritance protocol. Designed so when the unthinkable happens, your Bitcoin reaches the people you intended it for. Whether you're a self-custody expert or want multi-institutional support, your Bitcoin estate plan shouldn't be an afterthought. Bitcoin is only generational wealth if it can actually be passed down through the generations.

12:10So make sure they can access in the future what you've built today. AnchorWatch is your custody, your way. Visit anchorwatch.com to get started. That's anchorwatch.com. If you own a Bitcoin ETF, especially if it's GBTC, you need to listen up spot bitcoin etfs provide price exposure to bitcoin not direct ownership you can't withdraw it you can't self-custody it and they charge you a management fee every year to hold it well swan recently announced swan real bitcoin exchange and it's ready to use right now rbx is a structured in-kind exchange that converts your spot bitcoin etf shares into real on-chain bitcoin it does that without selling on the open market and it's designed to support a tax-efficient outcome.

12:50So for example, if you hold GBTC, you're paying one and a half percent a year in management fees for Bitcoin price exposure. But by swapping GBTC for real Bitcoin with RBX, you can drop that figure as low as 0 % by just holding it in self-custody. This is designed in a way that maintains your cost basis and in a manner that supports the deferral of capital gains tax. So if you own a Bitcoin ETF, especially if it's GBTC, you need to talk to Swan Private about RBX today. Head over to swan.com forward slash WBD and book in a call with one of their team. That's swan.com forward slash WBD. I think the problem right now is that we're in this volatile phase where the AI, they're just so much more powerful and methodical and they don't need to eat or sleep and you can basically have them churning away 24-7, 365.

13:44I've also made some references to basically this new technology has made becoming a slave driver moral and cool again because you're basically orchestrating massive swarms. Once you get to the high level of using these tools, you're orchestrating massive swarms of different models to coordinate with each other.

14:08so I think that at the moment closed source may be a bit safer but that's only really true if you're talking about a code base that hasn't been put through the the rigorous level of LLM review but the way one way that I've been looking at it from CASA's own code base where we thankfully had already been writing these pen test harnesses to basically red team our own code. And we've really accelerated that over the past few months. And it's actually become a sort of recursive loop thing where we're using the AI to make the AI pen test harness even better and faster and more efficient. and even starting to close the loops of vulnerability discovery to vulnerability resolution and patching and stuff.

15:10But one of the ways that I've been looking at it is that CASA has been around for nearly nine years, and we've had really good security practices, but they're not perfect. and so over nine years there's this idea of technical debt in software engineering where you're constructing these really large complex systems and oftentimes you have deadlines and so you might take a few shortcuts and not do the best practices for one thing and you'll say oh we'll get back to it later and then after doing that for many many years you just have massive amounts of crufts and and lack of best practices. Along that similar vein, I've been starting to think of this as actually security debt, where after nine years of building software, even though we did a really good job following a lot of the best practices, and even we do what is the industry standard for software engineering, at least for like SOC 2 compliance stuff, is you get at least one annual external security audit.

16:26You go find a security auditing firm, you give them all of your code, you give them credentials to your production or your staging systems, and you say, go for it. You basically red team our stuff and come back to us. and that usually costs us anywhere from$50 ,000 to$100 ,000 per engagement. Usually they'll bring on like half a dozen security researchers and spend a month just poking around and then they'll deliver a report to us and that report will usually have anywhere from 10 to 20 findings, different levels of severity and then we go fix them and then we come back and say, please retest them and they'll say, okay, it looks like you fixed everything.

17:20But like I said, these LLMs are just relentless. And so, you know, annually we would get, you know, 10 to 20 of those security disclosures in the report. And now just the sheer volume of what I'm dealing with. I was just crunching some numbers a few hours ago. Our pin test harness, last month, we filed about 120 issues. Most of these are low, medium severity. I don't think there's really any critical issues. Casa already has a really solid foundational infrastructure, just from the fact that we don't keep any keys online. And for our customers, we never have a threshold of keys that could actually be used to steal money.

18:14But nonetheless, it is a fairly complex software as a service infrastructure. So you've got all of your standard internet-facing best practices and software engineering, like OWASP-related things that you need to follow. And so, yeah, last month we had about 120 findings. And then, like I said, I was using the AI to continue improving, improving, improving. And then we did another run that was using the newer models, and that has resulted in several hundred more findings. And so we're just playing the catch-up game now. And the reason why at the moment I'm not seeing the end in sight, I mean, I'm sure it'll happen eventually and hopefully it'll happen by the end of the year, but it's because everything keeps improving.

19:13The models keep improving. Our own internal harness keeps improving. We keep finding other things. Now, thankfully, these are becoming like, you know, less and less lower severity findings. But still, each of these things then has to go through our entire software development life cycle. And that becomes the primary bottleneck. So I think I had also done some other stats where I said basically before August, I had only contributed like 300 lines of code to our CASA code bases this year. I have not been primarily a software engineer in probably four or five years. That has changed. And in August, I contributed about 50 ,000 lines of code to our code base.

20:09And this is pretty much almost entirely test code, additional verification, and integrity checks. It's all like security-related stuff. This is not me writing new features. We've got a whole other team of people that are doing that. And now my job is basically to get us to the point where, like I said, we historically had one annual security audit of our entire code base. my goal, hopefully by the end of the year, is to get us to us doing a full code base audit every single day. And that becomes part of the software development lifecycle. And basically means that there's no longer a gap where we're writing a lot of code and then somebody else is coming along and looking at it.

21:02I mean, we do already have peer reviews. Like, you can't get code into our production environment or into our mobile apps or whatever without having another human review it. But, you know, humans make mistakes, they can miss things. And having, you know, another human review your code is good. Having 10 other, you know, large language model agents review your code is even better because they're far more likely to find other things. And so, yeah, it's just, like I said, it's a race making everything faster. And, you know, if you're not racing along with everyone else, then it's pretty much guaranteed that you're going to get compromised at some point because there's a lot of other people out there that are actively using these tools against you.

21:57So, yeah, we just continue to harden everything. You know, I'm not losing sleep at night level of concern because I feel like we are probably in the top 1%, if not top 0.1%, mainly because we already had the head start where we had started developing our pen test harness back in like February or March. And then, you know, as these new models came out, we just continued clanking harder and harder. And if anything, you know, you probably saw just a few days ago, a bunch of these companies coming out and saying, we need to slow down, right? We need to pace. And I don't know what really happened behind the scenes there.

22:45I don't know if there was an incident that they're not disclosing or if they're just worried that they see the writing on the wall that they're not they're going to hit a wall and slow down and they want to have an explanation for it. I actually hope it's that. I hope it's that they can see that they're already getting to marginal returns on investment for training and that the rest of these free open weight models are catching up and they're going to have problems with their IPOs and stuff. that's what I'm hoping for because I'm hoping that means we'll eventually get to a plateau where I don't have to be writing several dozen pull requests for code hardening every day around the clock I mean I'm sure it's gonna it's gonna slow down at some point but right now we're just in the thick of it I mean if you're trying to weigh up the probabilities of why they want to slow down the frontier development, I think that would probably be the most likely is that they see that the marginal returns are, they're getting smaller and they know they're going to IPO and they need an explanation.

23:52But if it is something else, it is quite scary. Like I still don't think slowing down and giving control over to, I saw the Anthropics CEO saying he would give over control to sort of multiple government agencies. Like that seems like a terrible outcome to me. That's just giving more power to government. But I mean, it is still kind of scary. It's the Wild West. And the thing that I don't know, obviously very specifically to Bitcoin software and security is when is code just secure? And so even a two times gain in the abilities of AI still doesn't break anything because it's just secure code, or does that not exist?

24:30No, that's not really a thing. and it's because there's always more to it than just the code, right?

24:43So these software systems that we are building now are so incredibly complicated that it's not just the code that you have written. The best way that I like to describe it is, you know, we all stand upon the shoulders of giants in many different ways. Humanity in general, civilization has gotten to where we are by standing upon the shoulders of those that came before us. Now, within the context of software, that means, you know, in the very early days, like 70 something years ago, software engineers were writing in assembly language, which is only one step abstracted away from the pure machine, you know, binary zeros and ones language.

25:32And then over the decades, we started building more complex abstract languages on top of that, like C and C++. And then we started having web languages, your JavaScript. And now we've got other projects like Rust and stuff out there. So these languages are all building on top of each other, but they're becoming more complex. And also along with that is that for a long time now, for a couple of decades, especially once we got into the web and like JavaScript and Node.js, is that these massive libraries for every language started to be put together and published. And so now it's not just about the code that you've written, but also all the dependencies.

26:31And so that's how you get around writing a lot of code is you reuse other people's code that they have published. And so I'm busy with many different aspects of security that have all been accelerated by AI lately. And another one of them is dependency management. And so if you've been paying attention, you know, a number of the really bad compromises that have happened over the past few years were actually malicious actors that managed to gain control of highly popular tiny little code snippet libraries that were used in thousands, if not hundreds of thousands of other software projects. And then you just inject some malicious code into there that like installs a root kit on somebody's machine and looks for any Bitcoin seed phrases or whatever.

27:33And so point that I'm getting at is, you know, all of those libraries are also being subjected to the same level of scrutiny for vulnerabilities. And so I'm also getting just through the roof increased level of alerts from our various dependency management software that's basically saying, hey, you need to update this dependency because these vulnerabilities were found in it. and sometimes that can become a nightmare in and of itself because you can get into these weird dependency conflicts that turn into like spaghetti-related dependency, using other dependency, using other dependency, and sometimes like circular references that are really hard to untangle.

28:23And so, yeah, so it's software all the way down, and none of this stuff is ever static. You're never going to like ossify any given software project unless it is like completely self-contained and has no external dependencies, which interestingly enough is kind of one of Bitcoin core's long-term goals. and that's one of the things they've been doing over the years is getting rid of many external dependencies and including stuff like open ssl a number of years ago which turned out to be a really good idea because open ssl had a number of like critical vulnerabilities in it but that's really hard to do because you end up having to write rewrite a lot of that code yourself and then do all of your own security testing and quality assurance and just quickly on the languages all the different development languages.

29:19I've never written a line of code in my life before AI, but now with voice to text, I've got it to write some code. It's like built my website, all that kind of thing. But I have no idea in terms of like, if it gives me the output, I have no idea if it's good code, if it's bad code, whatever. Does it need to use the languages that we have built? Or are they still the most efficient ways that it can build software? Because now it's English language in, code out. Like, can it just have its own new code that's much more efficient? Yeah. I actually, I think that there has been at least one project.

29:55I remember reading a little news blurb about it, that someone had basically tasked AI to write its own language just, you know, for itself that doesn't need to be human legible. and if you think about it like I said all of these languages that we've been building they're just abstraction layers away from what ultimately gets compiled down into machine code now the main reason why you would not want to do that at least right now is as I said before don't trust the clankers at least if you're doing serious software engineering there needs to be a human in the loop at some point that is reviewing the code that is being written and is making sure that it's not at least obviously overtly malicious.

30:51That can be a problem in and of itself because there is a whole field of study and in fact there are prize-based projects around writing what is called underhanded malicious code, where you can look directly at it and you can be a computer science background and potentially not see that a given snippet of code is actually doing something highly malicious. And that actually kind of brings us around to like the cold card issue itself, which is that, you know, it was, it was such a like complex and nuanced piece of code that was malfunctioning that a number of human security researchers had directly looked at that code over the years.

31:46And, and some of them even felt like there might be an issue there, but none of them could actually see that, you know, the, the true random number generator library was getting swapped out with a pseudo random number generator library. And, you know, code is, is difficult. And like I said, if, if anything now, you know, having, having these agents be able to look at it and basically be much more methodical than a human would be. It cuts both ways, both for attack and defense. You wouldn't reuse a Bitcoin address, so why does your phone broadcast the same identifier for life? Every SIM has a static ID and carriers, ad networks, and bad actors all use it to track you.

Read the full transcript

32:34The big carriers have been caught selling that data over and over again. CAPE is America's privacy-first mobile carrier. Their identifier rotation feature changes your ID every 24 hours so you look like a different subscriber every single day. And sim swaps are off the table. Your number can't move without a 24-word phrase that only you hold. There's also no name at sign up, no social security number, and there's no profile to build on you. If you're a Bitcoiner in America, I honestly don't know why you'd use any other network. You can head over to cape.co forward slash WBD and use the code WBD for 33 % off your first six months.

33:08that's c-a-p-e dot co forward slash w-b-d if you're already self-custody bitcoin you know the deal with hardware wallets complex setups clumsy interfaces and a seed phrase that can be lost stolen or forgotten bitkey fixes that bitkey self-custody built for real life it gives you an intuitive easy to use wallet with no seed phrase to sweat over and it has a strong recovery system and built-in inheritance for long-term peace of mind and bitkey's just had a massive upgrade the new device now has a screen so before you approve something you can check it on the bit key itself the transaction the address or any account changes it's a big difference you're not just trusting what's on your phone you're seeing it for yourself on the device it's simple secure self-custody without the stress go to bitkey.world today and use the code wbd to get 10 off the new bitkey that's bitkey.world and use the code wbd when it comes to like obviously bitcoiners always say don't trust verify and with the cold card vulnerability i like i can't verify i can't i mean i could send an ai agent to go and look at it and tell me what it saw but i i can't read that code myself and so the trust for me wasn't even necessarily just in cold card it was in i guess every open source developer that's looking at an auditing code across the bitcoin ecosystem but do you think someone outside of just the actual cold card team or i guess what i'm trying to say is Did we let people down?

34:34Should someone have seen that earlier? Yeah. I mean, I think there's plenty of blame to go around. Obviously, from the original cold card developers that wrote the code, and then whoever reviewed it originally. I think a large part of the blame goes there. For sure. 99.9 % of the blame goes there. Yeah, like, I mean, I have plenty of other questions that I don't know the answers to. Like, I don't know if Coldcard hired external security reviewers to look at that code, you know, like doing the annual audits that we do at Casa. I don't know if Coldcard was doing that. But in general, though, part of the problem, it does come down to how many eyes are on it.

35:29And I think that part of the discrepancy and part of the reason why so many people were shocked when this happened is that I felt like there was a big discrepancy between cold cards posture within the industry versus their actual size and resources in reality. um you know if you talk to bitcoiners and this is going to be massive generalization but you know if you talk to like hardcore bitcoiners um you know a lot of them will poo poo on ledger uh because they support a lot of non-bitcoin things and they've had uh you know personal information leaks and stuff over the years uh and they would say you know cold card is the best because it's like the hardcore cypherpunk ethos project.

36:21And that is all true. But if you compare the companies, and I don't know the numbers off the top of my head, but let's say rough order of magnitude, Coldcard as a company is probably making millions of dollars a year in revenue. And Ledger, I think, is making hundreds of millions of dollars a year in revenue. And Coldcard had maybe two or three engineers, and I think Ledger has like 100 engineers. And so just size and scope of amount of resources that are put into looking at the code and ensuring it, when you look at it that way, it's a lot less surprising that something like this could fly under the radar.

37:11Yeah. And even to add to that, Ledger have their dedicated team in a dungeon that are constantly trying to break Bitcoin hardware wallets. And I feel like everyone just drank the MVK Kool-Aid a little bit. And he was quite arrogant. And we did a show a few years ago after Ledger added the feature that allowed you to basically do a Shamir secret of your Bitcoin keys. and mvk just lambasted the ledger ceo pascal for an hour and a half pure arrogance and then the whole time that i think even when we recorded that show that bug was still in the cold card at that point um like it was i do think everyone just fell for his shtick and and it worked for a while and it's quite embarrassing as bitcoiners i think yeah um though also um i know that ledger dong John looked at cold cards several times over the years.

38:04And I suspect they also looked at it at some point in that four or five year period where that vulnerability was there and they didn't see that vulnerability either. So like, if anything, that's also another, uh, you know, bit of credit towards how obscure and nuanced of a vulnerability it was. So like after this was discovered, obviously terrible for anyone that lost money. I think everyone has at least rethought the way they do this Bitcoin security setup. Maybe people have had a look at it and decided that what they do is absolutely fine. I'm sure there's a lot of people in the boat of Bitcoin self-custody is too scary.

38:43I'd rather hold it on an exchange or with an ETF. I think it would be a good exercise to go through and talk about what you think the best practice is for people's self-custody, maybe on a few different scales. Like from maybe we start with the person that has somewhere between a thousand and ten thousand dollars in Bitcoin. Like, what do you think that Bitcoin security setup should look like? Yeah, I mean, I think if you have at least a few thousand dollars worth of Bitcoin, then the very least that you can do is take your keys off the Internet. invests$100 or$200 into one of these air-gapped devices that protects you from hackers and protects you from 99 % of the threat vectors in the space.

39:28Now, that means, yes, you are going to end up trusting that company, whether it's Trezor, Ledger, Bitbox, KoliCard. And by the way, I'm not going to tell people not to use cold card because somewhat ironically now cold card is like the most secure that it has ever been because it has received so much attention. Like I still have and use cold cards. Many Casa clients have and use cold cards and and we had no loss of funds as a result of the incident. As far as I'm aware, there was no evidence that any multi-sig user of cold cards lost funds during this incident, even if you had a signing threshold of cold cards.

40:19And I think that was simply because the amount of permutations that the attackers would have to try just exponentially blew up and gave people enough time that they were able to move their funds before the attackers started grinding through all the multisig permutations. mutations. But yeah, I mean, at least get yourself on a dedicated hardware device because that protects you from any number of things of like malicious software. Like it's almost impossible to fully lock down like a laptop or a desktop. These like full-fledged operating systems and especially browsers these days just have massive attack surfaces.

41:04And so by taking your keys and and putting them on a dedicated hardware device that's extremely simple. That means the code that that's running on and even the hardware that it's running are simple enough that it's actually possible for security teams to audit them and have a better level of assurance that it's acting as intended. Though, as we saw, none of this is a guarantee. It is still a single point of failure. And so if you're getting above that level of value, if you're getting into life-changing sums of money, that's when you have to start thinking even more paranoid of what is every possible thing that could go wrong?

41:57And how do I ensure that if and when something goes wrong, it does not result in catastrophic loss of funds? And that's basically what we've been doing for nine years at CASA. I guess another way of thinking of it is, like you said, don't trust, verify. It's a great mantra, but very few people have the resources to verify. So at CASA, you could say, we just go by don't trust. we don't assume that anyone can verify anything but rather we say don't trust any given hardware device don't trust any given piece of software don't even trust Kasa you should assume that Kasa could blow up or could become malicious you should think about what would happen in a situation like that and how does my security model protect me in that situation i'm kind of surprised that you said you still use cold card um when you like if someone was setting up a cold card today do you think you can trust the random number generator now or do you think everyone needs to be creating their own entropy when using a cold card uh so i haven't because the reason i ask is like when you were saying before about the the liquid hack you were like this was a disclosure then they rushed in a fix and that fix ended up being worse than the original issue.

43:20And you could probably, I don't, I have no idea, but you could maybe make the same argument about cold card in terms of being like a rushed update after the fact. Yeah. I mean, they've made several updates now. I haven't set up a fresh cold card on the latest firmware yet, but from what I've heard, or at least from like a reason, reading the release notes and stuff is, uh, the, the, they have actually changed it. So you have to add your own entropy now, during the cold card setup. I haven't looked at the code myself to see what the verification checks are on the entropy that is input to make sure someone doesn't just hit one a million times.

44:03But yeah, I mean, like I said, I think that they have received more scrutiny against their code base over the past couple months than they probably have over their entire lifetime of their company. So it's about as trustworthy as you could get, I think, at this point. But still, there are no guarantees. There is no insurance. If something goes wrong, then it could be catastrophic. So that's why rather if you're putting life changing sums of money into Bitcoin, I think instead of trusting any one company, any one project, any one piece of hardware or software, you're way better off distributing your trust across many different ones.

44:51and having an architecture that assumes that any given one of them will have vulnerabilities and can fail. And that if that happens, you're okay. You're robust enough that that's not a problem. And that's really where CASA's security model is shining this past month. Because like I said, we had plenty of clients that were using cold cards. And rather than this resulting in a catastrophic loss of their funds, they just had a minor annoyance where they needed to either update their firmware and regenerate the key or go buy a different hardware device and plug it in and set it up and then use our key rotation functionality within the app to basically heal their slightly partially compromised setup.

45:47i'm interested to know what you think about the idea of creating your own entropy because obviously for people like you who have been in bitcoin security for i don't know a decade more however long forever um it makes sense and like you know how to do it you know the trade-offs you know what you're doing but for people who are new to bitcoin do you still see it as like a foot gun where they can potentially end up giving themselves way worse entropy than trusting a random number generator because from the people i've spoke to random number generators should be really good it's just the in cold card, it just wasn't being used.

46:16Um, and I know there's like, I've, I've got the, the bull Bitcoin entropy cards and there's like these things from the seed signer guys that make it easy. Those are great. Yeah. But like, do you think we should be like, that doesn't scale to millions and millions and millions of people? Like, do you think we should be leaning further into this? Or do you think we need to kind of put the trust back in, in certain signing devices that they can actually produce you good entropy? Entropy is such a tough thing. So the funny thing about entropy is that it ultimately comes down to physicality. And that when you're trying to generate entropy on a digital device, you're actually still sourcing that entropy from the physical real world.

47:05and different pieces of hardware do it in different ways but they could, for example, sample current timestamp. They could be sampling things like ambient temperature or temperature that the chip is running at. Some of them use the camera. Yeah, yeah. And so that's why it's hard for me to ever say that you should just prefer device entropy because ultimately any device entropy is using physical real-world entropy. It's just that when you are rolling dice or you're pulling playing cards or you're pulling those seed word sticks, you are verifying the physical entropy with your own eyes while you're doing that.

47:55When you're trusting a digital device to be doing that in the background, and it's completely opaque to you. So I think from the verification aspect, it's far better to do it yourself. And I don't think it's that difficult to get your hands on either some playing cards or some dice. It really is just more of a question of, can someone be bothered to do it because it takes 10 or 20 minutes to set it up? And I think that is the question, because if we're looking at devices that are gonna scale to everyone, there's most people aren't going to be won't understand the importance of it and therefore won't spend the time on it and we'll end up like i've got friends who did the dice rolls quote unquote on the cold card but really we're just hitting random numbers and like that's going to be like i i i don't know i i assume that's far worse than you just trusting the random number generator on a device uh well the human brain is very very bad at entropy so yeah Yeah, if you're doing something where you're just mashing buttons and whatever, then yes, that is arguably worse.

49:04And this is the problem is that it's more convenient. And so I think that's a good rule of thumb in general is that whenever you're doing something in this space that is the more convenient option, it's almost guaranteed to be the less secure option. So you should be aware that you are you're literally sacrificing time for security. You know, convenience and security tend to be in opposing force. Yeah. And don't get me wrong. It's not like I think these options should ever be taken away. Like, I think they should always be there. I just I just struggle to see how they scale scale to sort of mass market.

49:43OK, so if that's when let's say when you get into life changing money and you want to store your Bitcoin, um obviously at cast of your two main products is sort of the two or three multi-sig and the three or five multi-sig what is the like what's the threshold when you need to move from a two of three to a three or five uh well i mean this is also tough to have a real rule of thumb around because um you know you would say well it's when you have a lot of money but a lot of money is very different to different people. Another way of looking at it is like within our system, the three of five level is accompanied by higher level support tier where like you actually have, you know, a personal relationship with your client advisor and, you know, you get on video and phone calls with them and talk through any and everything that is on your mind.

50:41And so that's also an order of magnitude increase in cost where our two of three tier is really designed to be more self-service. It's the Netflix subscription of self-custody,$20 a month type of tier, whereas going up to our premium and private client levels, that's getting into thousands of dollars a year. So I think very few people are going to want to spend more than a fraction of a percent of their holdings per year on whatever their security architecture is. So you can kind of do the math from that. Like if you're at a premium tier and you're paying$2 ,000 a year, you probably want to have at least a few Bitcoin that you're holding on to there so that it sort of starts to make financial sense.

51:35If you're viewing this as kind of an insurance product, like security and insurance, they're kind of two sides of the same coin. Security is like upfront insurance and traditional insurance is like after the fact something went wrong. and your security failed, how do I try to recover from that? But in Bitcoin, because this is a highly liquid bearer asset, compared to a lot of other things in life, you want to have the super high level of security up front so that you don't have to deal with the loss in the first place. Whereas if you had that type of model for your car, then you would only want to be driving a tank around.

52:20But that doesn't really make a whole lot of sense, you know, for many other reasons as well. But you definitely want a Bitcoin tank. As someone who is like has some public profile in Bitcoin, how worried should I be in terms of avoiding wrench attacks? Yeah, I mean, I think that anyone who is publicly known to be a Bitcoiner, especially if you've been in it for more than a few years, you should care a lot about privacy. Like even if you have the ultimate distributed self-custody setup where you're basically wrench attack proof, you don't want to find out the hard way what would happen if you are in a duress situation.

53:05because for example even if you have what I would call a wrench attack proof setup where you don't have direct access to your funds at your home that's the biggest problem for pretty much everybody if you have the ability to access your funds without leaving your house you are vulnerable to being put under duress and made to move them But even if that's not the case, and this is something that really no security architecture can do anything about, you're still vulnerable to your friends, your family, your loved ones being taken hostage. And you are still under duress, but you are free to move and authenticate and go around and get to all of your keys.

53:57so you know i i don't think that anyone should really be advertising or uh leaking information about you know where where you are where you live to make it easier for someone to try to put you under duress in any way but the problem especially with the way you live is we've seen a ton of um leaks from hardware wallet companies where full addresses full names have been have been leaked and that cat is out of the bag for a lot of people like i was in the original ledger leak in i think it was 2018 or whatever i mean i've moved house every all my information has changed in sense so i don't mind saying it but like i was in that leak and i've i mean the number of phone calls i got was insane luckily i've moved house i think before the leak even happened so i never had anything physically happen but like that that isn't just the reality that people live with now is that people might know their address they might know their phone number their email that like everything.

54:53How are you meant to deal with that? Well, I can certainly opine upon it. You know, I'm in a rare situation because I was physically attacked before really any of those leaks happened. You know, I was swatted in 2017. And that's what really made me wake up to the severity of this problem of having your home address available to malicious people. So, you know, the short version is that I never put my real home address and my real name together in any database and any service. You know, I have mailboxes and even decoy, like condos that I use for different purposes where depending upon the nature of what merchant or service or government agency or whatever that I'm interacting with and what their requirements are, then I give different levels of false information, really.

56:06That's like one of the hardest things for the first few years that I was doing this, um, I was basically becoming comfortable with lying, um, and understanding that it's, it's not immoral to lie to people. If you're not trying to like deceive or defraud them, I am lying to people on a daily basis to protect myself. And, uh, and it's not just paranoia. Like I've actually been attacked before and I am not going to allow myself to be attacked again. But unfortunately, it requires a massive, massive change in lifestyle. And I think that's beyond what most people are going to be willing to do. I mean, for sure, even though I don't think there's anything wrong with lying in that case.

56:54I'll put a link in the show notes for anyone who wants to listen to the show we did a few years ago where you told the whole story about getting swatted. But essentially, the SWAT team turned up, guns drawn at your house while you were just... Were you cleaning guns at the time as well, which made it even more sketchy? insane story but it's um it it just it it feels like this is only going to get harder in terms of everything to do with bitcoin security over the next few years yeah um and you know with regards to like some of the personal identifiable information leaks and stuff some people are like well this is why you should never order a hardware wallet or other people like the seed signer proponents will be like this is why you should build your own hardware device with off the shelf parts because nobody is going to be like trying to get leaks of like raspberry pies or whatever but it's a nearly intractable problem because almost every merchant that you deal with asks for your personally identifiable information.

58:10And almost every exchange out there where people are acquiring their Bitcoin asks for egregious amounts of personally identifiable information. And this is a really fun one for me to deal with, like I said, because I try to use obscuring address information wherever possible, but the KYC stuff is very difficult. And the only way that I'm really able to get around that in some cases is to actually have a driver's license that is connected to a decoy residence where like it's a real place. I just don't actually hang out there. But I mean, there's a lot of other tricks too of like whenever a service tries to KYC me, I always try to use my passport first because there's no address information on there.

59:03usually that works sometimes it doesn't uh it's like when it comes down to places that will only accept a driver's license that that has an address on it it becomes really problematic that's interesting i always think of the passport as the more precious of the identifier so i would always but that makes total sense um do you think that with like this rise of ai enabled attacks that kyc is going to come under a lot of scrutiny and we might actually get a chance of pushing back against it because I'm not sure the data is clear that actually protects anyone, but it is creating these huge honeypots.

59:36And we've just seen that Revolut's been got, which is a massive, massive fintech, like tons and tons of information. And these are just honest people who are trying to use a service who now have their information all over the internet. I don't know. I mean, I don't think anything is going to change unless someone in power gets hurt. That's like, That's the short version. Until there's a politician or a really rich and powerful person who gets burned really badly from this, that they're willing to then go spend a lot of resources to try to get political change or regulatory change. no like the amount of leaks has been increasing at an insane pace and it just seems to be business as usual it's like oh there was another massive leak this week we'll give everybody free credit reporting and identity theft protection for a few years and then move on and you know it's very profitable, like the companies that are collecting this information tend to be highly profitable.

1:00:50I think, you know, the regulators don't want to give up any of their power and any of the sort of surveillance apparatus, even though there's many different levels of independent reports that show that, you know, the money laundering has the people that do money laundering professionally laugh at all of these KYC safeguards because they just go out and buy real identities on the dark net for pennies on the dollar and just burn through, you know, stolen identities that can get through all of these regulatory compliant systems. And if they do get caught, then they just throw it away and pick up another one.

1:01:35So, yeah, I mean, the whole thing is just a clown show, but it seems that the people who are behind it are so entrenched that the incentives aren't there to fix it. Well, one day they'll get hacked to and we might get a change. All right. Last thing I want to talk to you about, because obviously with Trezor's had a ton of email scams go out recently. One of their service providers was hacked, I believe. Steve. There'll be a load of people getting a ton of phone calls now with people trying to convince them to give them their seed words or go to dodgy websites. I saw on your Twitter that you had one of these phone calls recently with a scammer.

1:02:14Tell everyone what happened there, because I listened to the sort of three minute clip, whatever you put on Twitter, but it sounds very interesting. Yeah, well, we'll have several lengthy clips coming out soon. I think close to like 45 minutes worth of conversation. So basically, like you and like pretty much everyone else in this space who has been the subject of data leaks, I get these calls. and it's never been a problem for me because I never answer the phone if it's a phone number that's not someone I know personally and talk to regularly. But we started seeing more of our clients getting these calls and it just started becoming more of a security concern for us because we started having some clients that their Google accounts were getting compromised.

1:03:12And that was becoming really problematic for us because then sometimes we'd be trying to actually converse with the client and the bad guy would be inside their email and just deleting the emails from us and then sometimes responding to us as if it was the client and saying, oh, everything's fine, so on and so forth. So the short version is just don't answer the phone from any number that you don't know. But also just never trust any incoming message, whether that's email, phone, direct message on any platform, unless it's a strongly authenticated like end to end encrypted system like Signal or WhatsApp, where it'll actually tell you if your cryptographic exchange has changed.

1:04:10you cannot rely upon the person that the message is from actually being that person. Like all of these things can be spoofed. Emails can be spoofed. Phone numbers can be spoofed. And what I actually ended up doing was I actually, I took Coinbase and Google's like official business numbers and added them as contacts in my phone so that I knew that whenever I I got a call from them that it was one of these social engineers. And I started picking up the phone. And they have a very sophisticated system where they won't have humans call you. They actually have an auto dialer. And it'll call you and it'll say, hey, something happened.

1:04:57Like someone logged in here. If it wasn't you, press one and we'll get a human on the phone with you. and and so i started pressing one and eventually the humans actually started calling me and um i would i would play around with them for like you know 20 minutes or so to to get a better understanding of their script and and really like what they were trying to do uh how they're trying to get access and then eventually i'd be like hey uh like you know i'm a cyber security expert right It's like, you're not going to trick me. And in that case, they'd either hang up immediately or they'd be like, oh, shucks.

1:05:37I was really hoping to get you this time. And it's interesting because they knew that I am the chief security officer of a security company. And they'd still try to pull one over on me because you never know. Like even the smartest, like most intelligent people might have a bad day and might be preoccupied with thinking about other things. And really what they're trying to do is social engineers are hacking your brain. And they're doing this via psychological methods. They're usually using like fear, uncertainty, doubt. they're using a sense of urgency to be like, there's a security issue and you need to fix it right now.

1:06:26And I'm a trustworthy employee of this billion dollar company. And I will tell you how to fix your security issue. But meanwhile, what they're actually doing is they're tricking you into compromising your security so that they can get into your email. And from there, most people have one or two email addresses. And that's like the primary nexus of all of your other accounts. And once they get into that, they can start getting into all of your other financial accounts. And they'll be looking for what exchanges you're using. They'll be looking for seed phrase backups and photos of like your seed phrase.

1:07:03They are highly sophisticated organizations now where they have different people that specialize in doing different things. And so I was talking to the guy who specializes in tricking people into getting into their email accounts, and he gets paid for every email account he gets into, regardless of whether or not there's anything valuable in there. And then he'll also get a cut of whatever the take is if something else is found. But then they have other people that specialize and then doing the crypto related stuff. And then they also have other people that specialize in doing the wrench attacks.

1:07:37And those people then coordinate other people on the ground, sort of the henchmen, the two bit thugs to actually go and do the attacks. And like I said, they're complicated and sophisticated international crime rings at this point. And they do this all day long. And the thing about security and about all this stuff is that if you're the defender, you have to be successful 100 % of the time. But if you're the attacker, you only have to succeed one time. And that's just another one of the asymmetries in the space. It was great. like listening to it the thing that shocked me is how much money they're making as well i i can't remember was it did he say he's making about eight hundred dollars per email he gets into he was saying he can make up to about five grand a day or something like it's real good money um yeah how did you actually get him talking um well you know we just eased into it uh of of me playing dumb for a while um and and then you know the the trick is to not be an asshole which is really hard because these guys, you know, they're doing terrible stuff.

1:08:48But once you get them talking, like, they're just normal human beings like everyone else. They tend to be young guys, you know, generally in their, like, 20s. And the reason that they're doing this is because it's just insanely profitable. And they tend to have a mercenary mindset of, you know, I'm almost like a Robin Hood mindset of, like, I'm going after guys who are so rich that it's not gonna be the end of their life if I take millions of dollars from them because they're so well off. And that's like, he, he literally said something kind of like, like that to me of like, oh, you've been in Bitcoin so long, you know, you would be fine.

1:09:31And it's like, um, I guess we can just completely gloss over the fact that, you know, you're stealing from people who have, you know, spent a lot of time and effort, uh, building up their wealth and you're just going to take them, take it from them in a matter of an hour or so and, you know, not have any sort of regret regrets about that. But that's, that's how it goes when you get into the criminal world is that, you know, people will justify that whatever they're doing isn't so bad. And I don't know if you can talk about this, but before we started recording, you said there might be something coming from someone from North Korea.

1:10:08Yeah. Well, you know, We've already said a few times, security in this space, it's coming from a million different directions. And we've only talked about a few of the different things that I'm dealing with. But another is that, especially if you are running a company in this industry, there are nation state backed threat actors that want to get inside of your infrastructure. And they're going to do that in any number of ways. I think a lot of the people out there will be familiar. Lazarus Group, which is the Democratic People's Republic of Korea, they do a lot of DeFi hacking. They love hacking smart contracts and other types of projects, and I think they've taken billions and billions of dollars through that.

1:11:05But what they also love to do is to pose as technical security and software engineer to get jobs at companies. Because if you can get employed by one of the companies in this industry, you're going to start to get access to privileged systems. Maybe not production systems, but at least development environments. We posted a job posting for security engineer position, which of course is a highly privileged position that would eventually get production level access. You know, if you build up a level of reputation and trust with us. And we just got an insane number of North Korean actors that were applying for this position.

1:12:04And a lot of them, it's very easy to weed out just from like looking at the resume, LinkedIn profile, so on and so forth. But, you know, some of them get a little further along in the funnel. And what was particularly surprising this time around, I've never had them get to me before. And I'm usually the second or third person after, you know, initial call screening. And what we realized was happening is that they were using an actual American for the first initial video interview, and then they would swap out with the North Korean on the second interview. you. And, and you know, they're good at answering the technical questions related to the job description, the job that they're trying to, to actually interview for.

1:13:01And they probably even have some of the skills where they would be able to do that job. But as it, as it is with everything in this space, if you know the right techniques, if you know how to catch them off guard, if you know how to ask them the questions that they're not prepared for that a real American would be able to answer, then it's actually pretty easy to trip them up. And the difference between those guys and the social engineering guys is that you can't really get them to open up about what they're doing, probably because they're being monitored by their military or whatever state organization is actually sponsoring them.

1:13:48So they tend to hang up pretty quickly after you ask them a few questions that they're not prepared to respond to. What kind of is that? What do you think of your supreme leader? Like, what question are you asking? Yeah, that's an easy one is to try to get them to defame King John Un. but other less obvious ones tend to be cultural related questions. Like I said, they, they build up a, you know, a persona profile of who they're supposed to be that they're trying to impersonate. And so, you know, they'll know some of the background of the resume that they've given to you. But a few things that I've done is dig into like more personal questions based upon the resume that would normally not be asked in an interview, but which any normal person would be able to answer, things about their college life experience and stuff like that.

1:14:51There's also any number of other American cultural questions that you can ask that they're just not prepared for. They just don't really know anything about American culture. Super interesting. You've got to be careful of that. North Korean sleeper cells. Damn, there's so much to be conscious of right now. But James, this has been awesome. I think there's hopefully been some good actionable advice for people who are rethinking their security setup. Tell everyone when they go to follow you and find out more about Casa. Well, you can find me on X. My handle is just L-O-P-P. Check out Casa. It's C-A-S-A dot I-O.

1:15:31Perfect. Appreciate the time, man. Thank you for this. You bet.

From the publisher

"The rest of the world, of course, should always have been paying attention to Bitcoin, but they should be paying attention to it for a very different set of reasons now because they’re next.”

Jameson Lopp returns to discuss how AI is accelerating the race between hackers and defenders, what the Coldcard and Liquid hacks reveal about Bitcoin security, and why he sees Bitcoin as the canary in the coal mine for other industries.

We also get into hardware wallets, multisig and protecting life-changing amounts of bitcoin, the risks of KYC leaks and physical attacks, and what Jameson learnt from talking to scammers and interviewing North Korean applicants trying to get jobs at Casa.

THANKS TO OUR SPONSORS:

LEDN - Explore Bitcoin-backed loans and get 0.25% off your first loan.

SWAN - Buy Bitcoin, Build Wealth. Discover Swan’s Bitcoin products for individuals and businesses.

ANCHORWATCH - Insured Bitcoin custody, security & inheritance. Book a consultation:

BITKEY - Get 10% off the new Bitkey wallet with code WBD.

CAPE - Get 33% off your first six months with code WBD.

FOLLOW:

Danny Knowles: https://x.com/_DannyKnowles

Jameson Lopp: https://x.com/lopp

Jameson Get's Swatted: https://www.youtube.com/watch?v=yCWJY8olZHU

More from What Bitcoin Did

All 145 episodes
AI Came for Bitcoin FirstWhat Bitcoin Did · 1 h 16 min
Listen in VO