Hardwired by AlphaWire

Beyond the Audit - Fidesium

Elysian IT Services Season 1 Episode 1

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 45:16

In this episode of HardWired, Harry sits down with Bock from Fidesium to explore his background, the story behind the company, and why smart contract auditing has become such a critical part of crypto security.

We discuss recent hacks, the realities of manual audits, and why operational security matters not just for teams building in Web3, but for anyone responsible for protecting capital, infrastructure, and trust.

We also look at how cyber security is evolving in crypto, what auditors are actually looking for, and why the gap between “looks secure” and “is secure” is often where the biggest risks live.

Some ideas explored:

  • Bock’s background and what led him into crypto security
  • The role Fidesium plays in smart contract auditing
  • Why manual audits still matter in an AI-driven world
  • What recent hacks reveal about common weaknesses in crypto
  • The importance of op sec for founders and teams
  • Where projects often underestimate security risk
  • How to think about security as a long-term discipline, not a one-off task
  • Why trust in crypto has to be earned, not assumed

A conversation about security, vigilance, and what it really takes to build safely in crypto.

You can find out more about Fidesium here:

https://www.fidesium.xyz/

This episode was brought together by AlphaWire: https://alphawire.xyz/

SPEAKER_01

Very good. Well, hello Bok. Welcome to the first episode of Hardwired by AlphaWire. Thank you for coming on. Thank you, Eric. So, a bit of structure for today is we're going to talk a little bit about your story, how you got into building the company that you're building. But where I like to start whenever I interview anybody is sort of who are you, where are you from, how have you come to be doing what you're doing? So if you want to tell us a bit about that.

SPEAKER_00

Oh yeah, brilliant. Um, yeah, so my name's uh Greg Bach. Um been in startup land for several decades now. Uh I'm originally from Detroit. Uh my last startup was called Booking Bug, later renamed Journey. Uh through a weird set of coincidences. My co-founder happened to be British uh over the course of several years in growing that company, moved to the UK, kinda started a life here. Uh and yeah, it was uh interesting. The everybody over here constantly wants to move to uh San Francisco to uh start their startups, but uh the incentives and the environment, especially for what we were building, which was a booking and reservation system, were actually quite uh it was quite a bit better and easier in the uh London ecosystem at the time. And there was a much there was a much closer knit group of people going through the founder journey, which made for a just better sense of community. You know, there was a lot of pub drink-ups, the local London VCs were very involved, and there was this like really nice like meetup culture of show up and you were kind of accepted, and met a lot of great people back there. And honestly, that was where I began my kind of journey in crypto. I had a very good friend, Charlie Cox, who was an original miner for Ethereum. Uh I would love to say I was smart enough to listen to him when he uh when he first told me to get on this, and uh I was just busy with my startup, and uh to much much to my bank account's uh dismay, I did not listen. I could have had I listened to Charlie, I could have been mining Ethereum for eight cents. I think a little bit less when I met him.

SPEAKER_01

I I I looked at buying GPUs many, many, many times. I think I even bought a custom built uh motherboard just for mining and just didn't buy any of the other stuff and never got into it. And this was like early days, like 17, 18, I was looking at doing this and never got it off the ground. But you still ended up in crypto, which is the good part.

SPEAKER_00

Yeah, I eventually listened to Charlie and then bought some what would eventually turn into uh blue chips, and did uh quite alright out of that, and then ended up selling uh my last business to a private equity firm out of the United States, took a little break, and during that break, uh kind of went uh full DGen mode and was uh slinging uh shit coins and uh doing DGen things. And over the course of that journey, when I really got into it, um, as I'm sure everybody has kind of fallen to, so many rugs, so many hacks. Uh, you know, as there when Mount Mount Gox went down, um, you know, the early big security incidents all around crypto. And so during this break, uh I ended up running into my co-founder, uh, when Mr. Abraham Polishuk.

SPEAKER_01

So so when when was this? What sort of time frame are we looking at?

SPEAKER_00

Uh this would have been end of 2022, beginning of 2023.

SPEAKER_01

So just after the crazy times then, when it was all everything was good in the world and everybody everything could only go up. You thought it was gonna go on forever.

SPEAKER_00

Oh no, no, no. We uh we had a we had a good opinion of it. We like we looked at it, we're like, alright, well, we can catch a little bit of the end of the hype, and then we can build during the bear. So the original plan was to raise on the idea, get a pile of money, and then we could build through the bear market, and then come out the other side victorious. So we were at least slightly more realistic. Yeah.

SPEAKER_01

Better than most, sorry. Well, it never does. Best led plans in crypto startups never never really ends up where you want it to end up. But so you're at the end of 22, you you met your co-founder. How did you meet him?

SPEAKER_00

Uh, so Abe had joined uh the Antler Accelerator because he was like chomping at the bit to start a company. I happen to know um my buddy Jed Rose, who works at Antler, uh, one of the partners, and this they were moving on, uh, me and Abe joined in Cohort 8. So it was their version of a kind of lead accelerator. And honestly, I was just joining to like see what was out there, and really kind of wasn't planning on starting a company. And then I met Abe. We were the only two people in the room full of like finance and other bros who uh were into crypto, so we kind of naturally gravitated towards each other, and yeah, we just you know started looking uh for problems. What is the biggest problem in crypto through the entirety of crypto's lifecycle? Security, and thus Fidesium was born. And Fidesium started as transactional security. So we started off as a plug-in that uh took apart your transaction hash, if anything tried to hit your hot wallet, and we just were scanning for nefarious bad things, right? A very light version of an automated scan that simply looked at is this going to rip you off in the next five seconds? And people liked it, and it did pretty well, and no one wanted to pay for it. So then we grew the product again, interviewed some more people, and we came up with uh Fidesium V2, which was kind of like a research DEX. So we increased the amount of scans we were doing, figured out more about the contract, the team, the wallets interacting with the uh contract address, and then we released this dashboard that uh produced uh a report, which we call the risk audit. Once again, people kind of liked it. They said it was interesting, got some decent usage, no one wanted to pay for it. And about the time we went to ask people what would they want in a risk audit to pay for it, uh the general feedback was kind of the weird one was no one had a problem with what we were providing, but they're like, you cannot use the word audit. Audit in web 3 has exactly one meeting, and it means someone reviews your code and does this, this, and this, this. And we're like, oh, okay, that's interesting, and so we went back, we're brainstorming for a couple days, and in the middle of a brainstorming session, uh we're like, oh, actually, okay, we can either try to find a different name or figure out a different use case for this information we're gathering, or we can go do a deep dive and figure how far away we are from an audit. And so we started diffing our report against a bunch of open source stuff and reports by other audit firms, and we were like, honestly, the build is not that far out. So we started building, uh, then version three of Fidesium was the automated audit tool, and so we kind of did more interviews and we found kind of the gap we thought we'd want to play in, which was a very easy to use piece of uh developer tooling that automatically scans your code every time you change the code, and that would just continue to grow basically forever, right? Security is at arms race, it's never done, you just keep on building and building and building. And so we created a tool using uh AST analytics, advanced static analysis, a little bit of formal verification, and it scans every time there is code, uh, change the code. So whether that's a pull request, whether that's uh commit by a junior dev, and then that tool, finally, someone started to pay us. And so we thought we were on the uh right track. And then since then, we've just been still developing the tool, it gets better by the month, and we've also expanded into other security services just because you help someone with one thing in security, it's then just makes sense to help them kind of with all of it. Once you understand their project, their business, and the team, it just makes it easy to deal with them.

SPEAKER_01

And how have you found how have you found that sort of journey from cover uncovering a problem, sort of going out into the market and trying to find those customers, especially in Web3, which is already a niche and crypto projects are niche in themselves, but then security services are a sort of a niche within a niche. Has it been tough to kind of understand what the kind of customer need actually is out there and then pivot your offering to that? Has it been a bit of a journey of self-discovery or a trial by fire, I suppose?

SPEAKER_00

Oh man, there have been uh several amazing uh discovery points. Um so to your first point, yeah, Web3 a web 3 startup is a niche among niches, and it operates. I mean, startups are all the same. You want a product that finds customers that provides some service or gives them something they're looking for. In Web3, it's just a different zeitgeist. Like, people in Web 3 behave differently. They don't use email, everything's on Telegram. Um, there's you know, there's not a suit in the room, even at major conventions. In fact, like wearing a button-up shirt is gonna get you some side-eye. So it's a very, very different world to play in. And then the niche of the niche of the niche um with security, it's starting to mature. I think we're still, weirdly, for all the security incidents for all the hacks, we're still almost a bit early. And I think that's for two reasons. Uh A, we are still early. Like blockchain, web3 startups are still relatively a young technology. They don't have a ton of institutional uh money backing them. In fact, you know, kinda one of the points of blockchain is being anti-institutional, inventing new payment rails, trying to replace the banks. So that changes the math quite a bit on go-to-market and how you approach your customers. And then the last one is uh, you know, crypto people are D-Gens, you know, they they don't call it the yellow casino for nothing. And it attracts just a very similar type of non-risk adverse uh people to it. And so getting them to understand the need for security, uh I mean they understand it, but getting them to prioritize it uh sometimes feels like a very, very uphill battle.

SPEAKER_01

I think it's changing a little bit though. Uh I think from my point of view, it was always going to be a kind of a moving goalpost in terms of security and compliance, especially because a hell of a lot of it hadn't been codified, there wasn't a rule book to follow, there wasn't a best practices to follow. It was very much you do what you think is right for your company at the time and and then kind of steam on forwards. Now that has been to the detriment of to quite a lot of those companies and to the industry, in that a hell of a lot of money has been extracted, whether that's in stablecoins or in Bitcoin or in any other coin, the the amount of monetary value that's been removed just by hacks is astounding. And I suppose at the end of the day, that's what lots of Fidesium is there to combat to some extent. And we obviously had a conversation before this uh this recording, and I know you guys have have branched out to do some other services. Do you think auditing firms are going to start offering that full gamut? Do you want to tell me a little bit about what you guys are doing nowadays and and how it's changed in your view?

SPEAKER_00

Yeah, yeah. I mean, uh some of the bigger audio firms have always uh offered a few more services, but they've they really have been around the more traditional code end. So, you know, penetration test, code reviews, um, some have branched so far is into hardware um security testing. Uh what I think you're gonna see a lot now, especially after April. Um April was a very crazy month for hacks, as I think we all know, if anybody pays attention, to uh the Web3 hack world. Uh there was a huge shift in April. Um it turned almost entirely to OPSEC attacks. So infiltration of companies, um bad links, stealing keys, uh attacking dependent contracts and dependent services in order to attack the protocol in question. And so uh part of my background, my last startup, I dealt large uh with uh banks, high street retail, and so the kind of process-driven compliance level security was uh something I have a lot of experience with. So we were we started thinking about this a bit early before April came down, and uh sadly we were a bit too late with the offering. Um slightly behind the curve, certainly behind the curve of the the hackers, but Fidesium is now moving into uh SOC2 compliance and ISO because this is where it's it's a brand new world. I mean, as we just said, Web3 is growing up um slowly but surely on the security end. Uh there is there are a lot more tools for securing your code base. There are a ton more platforms, really great platforms for hosting bug bounties. You know, there's a stronger-than-ever community of uh white hats out there fighting the good fight, finding bugs, disclosing uh responsibly. But now we're moving on to the next stage. The hackers, you know, the enemy is the only one uh who can tell you where you're weak, to quote uh Urs Scott Card. And that's exactly what happened. And I think we're even gonna see, my prediction is coming into June, what we're gonna see is even a further kind of shift. You know, the the OPSEC failures of April are almost somewhat easy to correct for as long as they're front of mind. Even if you don't have good processes, you can just be scared enough about what happened that you will just treat everybody suspiciously, and that will probably solve a lot of the like easy-to-fix problems in OPSEC, right? Companies should still go through and have an eye to what they're doing, how they're doing it, and who's responsible, but a healthy dose of fear goes a long way to a new attack vector. The next one is not so easy to fix, and I think it's we're gonna see it really ramp up, and that is gonna be um small vulnerabilities into once overlooked parts of your supply and dev chain. When in May we already saw some of this, and I think it's gonna continue to grow, where hackers are going to infiltrate via trusted partners. So, you know, the Web3 protocols may get more paranoid, they may lock down some of their procedures, but I really see uh attacks in their secondary, tertiary um support partners um getting hacked and then the attackers gaining entrance to that. So still an OPSEC failure, but a very, very particular kind of one.

SPEAKER_01

Yeah. I think I think what we're seeing in the market is just the the absolute proliferation of of people trying to expose vulnerabilities in these platforms and just get in whatever way they can. Obviously, there was a little bit of a wising up to code issues. That was something that plagued like 27 to like 22, I'd say. Then a lot of groups, as they always do, when one kind of door closes, another opens, or they look for another opening, they stopped focusing so much on the code exploits and and really started to dive into operational security issues. And it's something I wanted to bring up today is do you think OPSEC has become more of an attack vector, especially with the amount of um repositories and kind of code knowledge around very smart contract language that's uh weren't probably there in the beginning, the the the best practices have got better. Do you think OpSec's kind of overridden the code vulnerabilities now as an attack vector, or do you still think it's the same?

SPEAKER_00

Oh, uh certainly by the frequency of current exploits, you know, in the past couple months, uh OPSEC I think accounts for like something like 70% of what was stolen recently. So in the short term, yeah, OPSEC is just absolutely well, it's a new fertile hunting gown, right? And I mean the other problem with it is uh you know, Lazarus has claimed responsibility for a decent amount of these uh attacks. I mean, you know, the I believe it was Drift was like a six-month you know operation. And I mean, these are state-backed phony companies, you know, posing as trusted partners with, you know, enough credentials to get them through the door, gaining trust, building relationships before the execution of the drain. And it's yeah, I mean, it's really frightening stuff the amount of money that went into the back end before this. I think code exploits, code exploits, look, are never going away. Um, there will always be, you know, new vulnerabilities discovered. Uh Enterprising hackers will always find, you know, interesting things to do with code and ways to exploit. I mean, good god, Microsoft uh is currently got someone booted off GitHub because there were uh the the hacker uh disclosed six zero day vulnerabilities to the Microsoft kernel.

SPEAKER_01

Wow.

SPEAKER_00

So yeah, I mean codhacks are never going away. We always have to keep the security up on that. I think the tooling's getting better, but the tools to attack it are getting better.

SPEAKER_01

Yeah, I was gonna say it's an arms race, and it's one one person kind of streams ahead. Or one side streams ahead and then the other one catches up.

SPEAKER_00

Yeah, and AI is just speeding that cycle like nobody's business. Um, and it's also helping. I mean, where the AI's really gotten good is uh this is kind of obsex, but uh just the confidence scams. You know, faked sites, uh bad links, spoofed uh telegram accounts, things that look like they come from trusted sources, trying to get any package on your machine to steal your uh private keys. You know. And it's just the the current level of AI makes it so easy to send a now believable message from a hacked account. Uh it makes it unbelievable easy, you know, lovable to spoof an entire site and you know use a Cyrillic character in it. Um I've seen some really interesting uh link spoofing uh lately where uh through Telegram the URL printed in the message is and the correct URL, but the link attached to the text is a slightly spoofed version. And it's just yeah, getting wild. Um the DeepSake software, I'm trying to remember who was at like six months ago. Uh they impersonated the CTO. It was something, uh, one of the Binance subsidiaries.

SPEAKER_01

Yeah, I I remember that one as well. They they'd like they'd fully mapped his whole face onto his face and the voice changer and everything. It was craziness.

SPEAKER_00

Yeah, and he jumped into a call and improved a transaction and away it went. Yeah, yeah. So I mean, just serious text, serious planning going into these things. So, yeah, I mean, really buttoning down Um your operational security. And I mean, even if you don't go for any of the certifications or you know, you don't want the little badge on your website, that's all fine. But taking a good, serious, long look of where like your risk lies in your company, like where you are porous, you know, how big the attack surface is, is just gonna be table stakes moving forward. Like in your head, doing things securely or correctly is no longer gonna be enough. You're just you're not thinking adversarial enough. Um, it's it's definitely worth having someone come in, give it a kick, you know, like spend some honest time of how they would attack your protocol from like every kind of angle and start showing up those weak points.

SPEAKER_01

Yeah, I think I think it's only gonna get worse. And I think I think there's a big blind spot that people will just think about one area and not really think about how it interplays with the others. Like some people people are starting to understand that they need a good order, they need to understand where the vulnerabilities in their smart contract might be, or the vulnerabilities in their platform might be if it's if it's not based on fully on the blockchain. But all of that intermixed with how are you managing who has access to what, who has the private keys and the and the multisig, to where stuff goes, how it moves, have you got procedures in place to control who's allowed to do these things? Is there a time lock? Like there was an interesting one, maybe you can fill me in on some of the details about I think it was drift, maybe. They have no time lock on their multisig, it needed like two out of six to approve or something. Excuse my misremembering of the facts, but oh no, no, you're pretty close.

SPEAKER_00

Yeah, it was only yeah, it was it was only three or five. They and then they approved some durable nonsense. There were no time locks, there was no fall down for anomalous transactions, there was no circuit break anywhere in the system. When the money started flowing out, uh, like there was no one watching the bridge as it drained away. It just, yeah, it was security failure after security failure. Um, you know, we we've seen this a couple times with uh some lesser-known um uh perps dexes and other DEXs where uh they're reliant, you know, another part of security, uh they are grabbing information from a single point of truth. So a single Oracle provider says what the price of something is. And I think it was it was uh this one wasn't drift, this was the other one. Uh sorry, I'm blanking on the name right now, but uh the attack uh centered around poisoning a bunch of the uh poisoning a couple of the oracles and then doing a denial of service attack on the others so that the protocol had to go to the poisoned oracles, and then they manipulated the price and then they stole all the liquidity.

SPEAKER_01

Yeah. I think I I don't think people realize how much it goes on where it doesn't actually come off, like how many things are actually in the works that you obviously only hear about when something gets hacked. I don't think people realize how much activity there is on people trying to hack things and maybe not getting all the way, or they get found out, or they get blocked at one area, but it is so so right. I didn't have obviously persistent, yeah.

SPEAKER_00

And what I think what I think people miss is they hear of a hack and they think of that particular attack vector, but what they miss is yeah, it's not one thing once in a while. It is literally everything all the time, right? So there's something out there constantly sniffing your contracts to see if they can find a vulnerability in it. There's someone obviously sending, you know, bogus links to all your employees all the time to see if they can get someone to click on them. Fake job interviews, uh, fake meeting requests to bad sites. Um and then you have the all the supply chain attacks. Um, you know, something that was trusted yesterday gets poisoned, and you install a new package into your just your dev environment, and then that secretly deploys a package. Uh, you know, uh fake employees getting jobs that are, you know, plants by Lazarus, or you know, and I mean like this is not like you know, this isn't a couple like nerdy kids like trying to get at you. These are like these are state-sponsored events, you know. Their budget is bigger than yours, and you've somehow gotta find a way to fight back.

SPEAKER_01

Yeah. So how do you fight back? That's very nice. Thank you for doing my segue for me. You very much led me on to my next question. But so obviously we we've we've talked a little bit about manual audits. Give us like a quick rundown of like what is a manual audit, what goes into it, how does it protect somebody, and then we can go into the ones that are kind of in the news and a bit more esoteric.

SPEAKER_00

Yeah, so uh manual audit, um it's not also not a single thing. There are obviously many, many, many layers. And it's at its at its simplest, it is a very talented d developer that can think adversarial, a hacker, white hatch generally, who will read your code, look for attack services, attack those attack surfaces, and see if they can get in. And then it goes all the way up to building fuzzing rigs to check bounds on functions, uh using all the AI tools, architecting uh your entire protocol to see if uh anything your protocol deals with, like what happens if basically it is a huge game of questioning your assumptions, right? Everything is written, assuming the price is this, the price is that. Oh, I can't oh, this is gonna bug me. I can't think of who it was. But one protocol got hacked, I believe, because the traded amount uh that broke the function uh was like someone managed to pass in negative 100 million, and the negative plus the large number overflowed and broke the function and allowed them to process a bunch of requests, then the request didn't fail property properly, so like even though they didn't get any money out, the request passed, then they captured that, changed the amount, and then put it back through. So it was very weird, it was a very clever hack, but so yeah, so what you really have to do is your code attack it as hard and as much as you possibly can. Use every tool at your disposal to attack it. Then the next thing is monitor for suspicious activity once you're live on uh mainnet. Um hopefully your audit is good enough that it will let you know kind of what you need to be monitoring. You know, where are the attacks likely to come from, suspicious activity, oh KYC, M L AML, and the like to see if any suspicious bullets are coming at you that way. And then there is the entire land of obsect, which is more process-driven, where it's you know, think adversarial early saves you a lot. You know, processes can become very onerous if you're build if you're if your company grows up doing things in an insecure and loose way, trying to put these controls in uh top down once the system is already built is very, very difficult. Design them from the beginning to be secure, like at least keep an eye on this from when you're a very small company, and it's much easier to stay secure long term, right? Setting up processes around you know, sandbox environments, if anything's gonna get um any packages are gonna be added to the dev environment, right? Uh they first get tested on a you know air gapped machine that just has nothing on it, you know, no none of your core devs ever try something new. Like ever. Um better vetting processes for employees. Um yeah, partnerships need uh a more rigorous looking at just uh yeah, like three of five multi-sig is like bare minimum, you know? I mean, no single keys. Oh my god, never post your keys anywhere, never share your keys. I mean, all this should be just known stuff, but there was a hack last month where the hacker got in and they found the keys in an old Slack message. They got access to the Slack chat history.

SPEAKER_01

It's it's silly things, and it's things that you wouldn't do in your right mind if you were considering it. But when you're a bit fly by night, you're running fast, you're trying to get products out the door, you're trying to get customers onboarded, these things become secondary, but it can it can ruin a company. Like I was looking at um Radiant uh Dow or Radiant, they literally put out an announcement yesterday, I think they got hacked in 24 or an X4 or exploited. I can't just remember the details, but they're showing down, they haven't been able to recover from it, and they were quite a big lending and borrowing market, they'd done a good a good token launch. I even used the platform back in the day, and it's it just shows you that you might have built a really, really good company, you might have got a load of TVL on board, a load of customers on boarded, but if you haven't considered this properly, it it can it can ruin the company, ruin the project, ruin the protocol.

SPEAKER_00

Oh yeah, and I mean listen, it is hard, and that's why you need processes. Because yeah, I mean, like some of these things, it's like one tired person makes one mistake. Hackers only need one lucky break. You need to stay vil vigilant 24-7 all the time. It it there is an there is a huge asymmetry to the risk reward of both sides of these things, right? And it's like that is what you're really fighting. You're fighting the asymmetry. Attackers can Oh, they can attack you whenever they feel like it. They don't need to be they do not need to be attacking 24-7. They just need to get lucky for one one tiny instance if you don't have the correct processes uh in place. And so, you know, what all this thinking is, what adversarial thinking does for you at the heart is okay, let's say a mistake is made. Well, with good processes, the mitigation of loss from that mistake is a lot less. Right? If you have certain circuit breakers when something goes weird with the liquidity and the protocol, if you know what to monitor. Um if you're uh as you say, uh oh god, uh uh the limits on approvals, you know, having things um time out. There there are steps and steps and steps and defense you can take in depth to mitigate a lot of the risk. And that's what people have to be thinking of from the very start.

SPEAKER_01

Yeah, I have a lot of conversations with startups, and and I say, so what is your your operational security plan? How are you approaching security on the whole? Have you got a partner? Have you got a game plan? Have you audited where your problems might be? And nine times out of ten, the answer is we did a little bit of it, we we've sort of had a look.

SPEAKER_00

Almost everyone I talk to, uh like way more than nine of ten. Like, they either haven't done it, hadn't thought about it, or yeah, you get a sheepish, we've kind of looked at it, which means we ain't looked at fucking anything seriously.

SPEAKER_01

Yeah. So what's what's next then? What's the ideal world? So we kind of we've talked a lot about the state of play, how things have changed, where it's going, we've done a bit of fear-mongering about all the hacks that have gone on, which you can't not do with a security audit conversation. But if if you were to kind of give a sort of five or ten point list of how you would approach it going forward, obviously budget comes into it. Some people have less than others, some people are bootstrapped, but but how would you sort of approach it going forward really for a startup? What would you do?

SPEAKER_00

Oh, yeah. I mean, there's a lot of resources out there. So point number one is just being aware. Like, you know, and this costs startups nothing, but just be aware. Follow all the security profess professionals on uh X. There's a ton of them. They drop amazing amounts of knowledge for free. And you know, pay attention to what the hackers are doing. Like stay abreast of the information. That alone will just get you in the right mindset. Then yeah. Get an audit, get the best audit you can afford. You know, don't I know it's hard, but you know, this is not something you want to skimp on. Uh the next would uh point three would be have a good look at your operational security early. Um contract, uh contact a firm, even if it's just a consultation, you know, figure out where the edges of your risk lie. Like what does the attack surface look like? Great snap. Number four, you gotta do the work. It's it's hard work, it's hard craft, and there's no way around it. You have to be vigilant, you have to do this stuff. And if you get in the habit of doing it early, it gets easier. So, yeah, I would say those would be the the four things.

SPEAKER_01

No, I I can't say I disagree with any of that, to be honest. I think I think people need to wisen up, especially people that are going for projects that are going for kind of 500 million, a billion in TV L and up. It seems like a very, very silly thing to not consider sort of from the outset and and and ongoing, and we've seen some of the biggest players in the space that will have had the budget as well. Like look at Drift. Like Drift had what, half a billion in TV L or something at one point. They were making they must have been making some enough fees to pay for some audits, they'll have done it once. I'm only speculating, so not me uh telling stories about about what's going on, but they'll have my best guess is they'll have done some audits, they'll have done it once, maybe twice, but they won't have stayed up to date on where they've ended up and how things have changed. And I think that's probably one of the bigger risks is that when you first build out your systems and first build out your product, and you get your audit done, and and you kind of get signed off, or you're all fine at this stage. But then you add in an earned product in the case of drift as a made-up example, or you add in another lending and borrowing pool, and you don't consider how that's affected the vulnerabilities that were looked at when you did the first audit, and it's that ongoing security partner, I think, is a really important part to think about.

SPEAKER_00

Oh yeah. I mean the other one is um oh God, I'm trying to uh hold on, let me just wanna look at one thing. Um Yeah, it was either I can't remember if it was either uh Drift or Kelp. Like what led to uh the hack was a known problem that they said it was brought up uh in several audits and they just ignored it. They said, no, we don't think this is eventually gonna be a comeback problem. It was uh they just let uh single point of failure live.

SPEAKER_01

I vaguely remember that as well. I can't remember which it is either.

SPEAKER_00

Oh yeah, kelp yeah, kelp used a uh one of one uh DVN single verify for the layer zero bridge. That's what it was. That's a very good point. It was a known problem. It's just insane.

SPEAKER_01

That's a very good point that that it brings up as well. It's not just your own security and how your protocol or platform works. When you start to onboard other partners and and sort of link into other protocols and have connections to bridges and other things, you then become exposed to how they've set up their operational security and their code security and how it all fits together. If you haven't considered that, that can be the attack vector that gets exploited.

SPEAKER_00

Exactly. Yeah, which was very much what happened to Kelp though. Um yeah, single pony value on that DVN, and then that was I misspoke earlier saying it was drift, it was kelp uh that uh had the compromised RPC nodes, and then once the RPC nodes were compromised because of the failure of the DVN, uh they were able to change the price and uh pull out all the liquid liquidity.

SPEAKER_01

It's a scary, scary world. So yes, it is. We shall be wrapping up this interview in a moment. Thank you very, very much for joining us. It's been great chatting to you. Before we go, I was sort of gonna make a habit of asking people that have startups to say, where can they find you? How's best to get in contact? What who do you help? What what's if somebody wants to reach out, what do they do?

SPEAKER_00

Oh, um, yeah, you can find us at our website, uh fidesium.xyz, uh probably the easiest place. Uh contact forms all over it. Uh we help all early mostly or currently mostly early stage, slightly younger um Web3 projects. Uh we have a great team of security researchers. We build all our tooling in-house. Uh, it allows us to deliver an outsized uh value for cost. We can give a deeper, more robust audit for uh a comparable price that you would find uh somewhere else. And then we also offer a bunch of other very important security services. Like we will review your architecture, we can uh help you discover your attack services from an opse point of view, we can help you get your SOC2 compliance in line, as well as pen testing and a bunch of other services. We're just we've all been in the security game long enough that uh we have experience across like kind of the landscape. And then the nice thing about dealing with Fidesium is we're a small firm, everybody's super dedicated, you don't get pawned off on some unknown, you get the core team and only the core team.

SPEAKER_01

Very, very good. Thank you very much for joining us, Boc, and this has been Hardwired.

SPEAKER_00

Thank you very much, Harry.

SPEAKER_01

Cheers. Bye-bye.

SPEAKER_00

Cheers.