DiscoverCypherTalk
CypherTalk
Claim Ownership

CypherTalk

Author: Oak Security

Subscribed: 0Played: 2
Share

Description

CypherTalk is a twice-monthly podcast on the realities of cybersecurity and privacy in a world that’s moving faster than our defenses.


Hosted by Jade Doherty (who translates technical security into plain English) alongside rotating security and privacy experts — including co-host Stefan Beyer, co-founder of Oak Security — the show explores how modern cybersecurity attacks actually happen: not just through bugs in code, but through people, processes, supply chains, and the tools we rely on every day.


The show also looks at the latest trends in privacy and its supporting technologies, such as cryptography and zero-knowledge proofs


Expect conversations that balance big-picture trends (AI-driven threats, privacy tech like zero-knowledge, shifting security standards) with practical takeaways you can apply immediately — whether you’re a developer, a founder, or simply someone who uses the internet.


Less hype. More clarity. Better security and privacy habits.


18 Episodes
Reverse
Jade Doherty and Stefan Beyer speak to Justus Hanna, co-founder and CEO of Grego AI, a bug bounty hunter turned founder building AI that finds vulnerabilities human auditors miss. Justus's path runs from hacking Novell networks as a kid, to Bitcoin in 2011, to picking up bug bounty hunting from scratch after a Wall Street layoff. The turning point came when his future co-founder showed him a system that found a high-severity bug in Lido's dual governance module, at a moment when every other AI bug hunter was producing pure slop. What sold him: the AI found bugs humans couldn't, faster and cheaper. He explains Deep Invariant Analysis as a proprietary harness orchestrating hundreds of specialised agents across many models, built to go five or six layers deep into complex systems and chain exploits a human would be very unlikely to reach. They tackle the big claims head-on: the $27.7M exploit prevented, the $250K bounty, why the protocol stayed unnamed, and the awkward truth that verifying an "AI-only" find still comes down to reputation. On the anxiety every auditor feels, Justus argues the harness is the moat, precisely because it's model-agnostic, and there's a candid detour on frontier-lab hype and safety theatre. The episode closes philosophically: his vision of an always-on "security operating system", and his advice to researchers, don't skip the manual apprenticeship. Learn the craft from first principles, then use AI as a superpower on top. Be Iron Man, not obsolete. Key Topics AI-assisted vulnerability discovery, Deep Invariant Analysis, and the harness-as-moat Verifying AI-found bugs, disclosure, and the incentive problem in bug bounties The future of the human auditor, and security as an always-on operating system Chapters 00:00 Introduction 00:24 From Novell Networks and Bitcoin to Bug Bounty Hunting 02:17 The Turning Point: Seeing Greg's System Find a Lido Bug 04:57 The Moment AI Beat the Human: Report Depth, PoCs, and Speed 06:29 What's Actually Different: Going Five or Six Layers Deep 10:58 Deep Invariant Analysis, the Harness, and Coordinating Agents 13:59 The 48-Hour Guarantee and the Human-in-the-Loop 15:43 The $27.7M Exploit, the $250K Bounty, and Verifying AI Findings 19:50 Bugs in Heavily-Audited Protocols: Is the Human Auditor Cooked? 24:39 Will the Models Eat the Harness? Why the Harness Is the Moat 27:26 Frontier Lab Hype, Safety Theatre, and IPO Incentives 28:24 The Vision: A Security Operating System Beyond Web3 31:52 The Attacker-Defender Asymmetry and Safeguards on Models 34:38 The Incentive Problem and Aligning White-Hat Rewards 37:09 False Positives, Slop, and Disclosure Bottlenecks 39:20 What a Major AI Lab Wanted to Know 41:02 The Role of Security Professionals in Two Years 45:22 The Apprenticeship Question: Learning the Craft Before the Tools 48:03 Training Juniors, CTFs, and Spotting AI-Generated Work 49:45 Where to Find Justus and Grego AI Resources and Links Justus on X: https://x.com/0xriptide Grego AI: https://grego.ai Oak Security's Research: https://research.oaksecurity.io/  
Jade Doherty and Stefan Beyer speak to Lorenzo Sicilia, Head of Technology at the Arbitrum Foundation, whose path into crypto runs through ConsenSys, Casval, and Outlier Ventures. They open with the distinction that shapes everything else: the Foundation is the steward and legal wrapper of the DAO, not the team behind the tech. Lorenzo unpacks how it ran the Arbitrum Audit Program on the DAO's behalf, vetting a shortlist of thirteen audit firms and funding early-stage teams, and gets into the hard parts with Stefan: the "rubber stamp" risk when a Foundation-blessed audit becomes a trust signal, the friction of re-auditing when each iteration costs $50K to $250K, and the brutal cost-per-line metric the program can now benchmark across firms. On security responsibility, Lorenzo is precise: the Foundation has none in the formal sense. Incidents fall to a 12-member Security Council, elected and rotated by the DAO. From there the conversation turns to what keeps him up at night, the L1-L2 trust boundary and the bridge, and why fraud proofs through BoLD have improved the picture, landing on his own preference for "code is law" while acknowledging where reality forces harder trade-offs. The technical heart is Stylus, Arbitrum's WASM environment for writing contracts in Rust alongside the EVM. Lorenzo is unromantic about it: a second runtime widens the attack surface, and while safe Rust has real advantages, no language removes the authorisation, economic, and oracle pitfalls that actually cause losses, treating any language as "safe" is a mental trap. The episode also covers the freshly-shipped ZK-on-BoLD upgrade, the road to real-time proving, and why AI currently hands the red team a big advantage over the blue team, though Lorenzo is optimistic defenders can turn the same tooling back on their own code. He closes with hard-won advice: authenticity and persistence over a polished demo, understand your oracles and dependencies, get key management right, and know when to switch from "fake it till you make it" to full paranoia, because in this industry, you don't get a discount. Key Topics The Arbitrum Audit Program, and the "rubber stamp" problem with Foundation-backed audits Decentralised security responsibility: the Security Council, the L1-L2 boundary, and BoLD Stylus and WASM security, ZK-on-BoLD, real-time proving, and AI's red-team advantage Chapters 00:00 Introduction 00:35 From ConsenSys and Outlier Ventures to the Arbitrum Foundation 04:11 What the Foundation Actually Does, and How It Differs from Offchain Labs 06:50 The Audit Program: How It Works and Who Funds It 10:18 The "Rubber Stamp" Problem and Vetting Audit Firms 13:18 Early-Stage vs Mature Teams: Who the Program Is For 14:54 What's Next: Additional Tools, AI, and the Limits of Scope 17:15 Lessons From the First Iteration, and Cost-Per-Line Benchmarking 21:11 The Foundation's Responsibility and the Security Council 24:49 What Keeps Him Up at Night: The L1-L2 Boundary and Bridges 29:16 Security Policy, Bug Bounties, and Disclosure Across the Ecosystem 30:48 Stylus: Does a WASM Runtime Widen the Attack Surface? 34:49 Safe Rust vs Solidity, Tooling Gaps, and the "Mental Trap" 39:13 Adding ZK to BoLD, and the Multi-Prover Approach 42:20 Real-Time Proving and Where Arbitrum Is Heading 45:20 ZK for Compression vs ZK for Privacy 46:24 AI in 2026: Red Team vs Blue Team, and AI Slop 50:31 Judging Teams: Authenticity, Resilience, and Real Problems 53:33 The Biggest Security Mistakes New Teams Make 55:25 The Foundation's Security Vision for the Next Few Years 57:52 One Piece of Advice: Dependencies, Keys, and Knowing When to Get Paranoid Resources and Links Lorenzo on X: https://x.com/aboutlo Arbitrum: https://arbitrum.io Oak Security's Research: https://research.oaksecurity.io/  
Jade and Stefan speak to Robert de Groot, a core contributor to Web3Privacy Now, the research collective and think tank behind the Cypherpunk Congress, and CFO at Gain. Robert starts from an unexpected place: privacy isn't really about hiding; it's about autonomy, the ability to choose what you reveal, to whom, when, and in what form. He connects it to something bigger than data leakage, the loss of the room to experiment and to fail, and the quiet self-censorship that creeps in when everything is recorded. From there the conversation opens onto the spectrum of privacy, from the journalist in a conflict zone who will work from a terminal if it keeps them alive, to the rest of us who just want a group chat that isn't intercepted and won't tolerate bad UX to get it. A big thread is the gap between personal privacy and business compliance, and why the two still don't align. Robert explains how Web3Privacy Now evaluates the 800-plus projects in its Explorer (the "hard variables," verifiable code over marketing claims), why "zero knowledge" and "private" have become marketing terms, and why privacy adoption lags even when the tooling is ready, the preventive-measure problem, the group effect, and cookie-banner fatigue. On the compliance side, he maps the middle ground: opt-in reporting, viewing keys, and selective disclosure (picking up the thread from our Jordi Baylina episode), including a one-time key you could hand your tax auditor and be notified when it's used.  He argues privacy will increasingly become a market-integrity feature, not just a civil-liberties one, shielding transaction amounts from competitors and MEV bots while keeping endpoints verifiable, and he closes on RWAs, why so many tokenisation projects quietly died on double-accounting overhead, and what "compliant by default" finally changes. Key Topics Privacy as autonomy, and the spectrum from uncompromisable to everyday The gap between personal privacy and business compliance, and the middle-ground tools that bridge it Privacy as a market-integrity feature for RWAs and institutional adoption Chapters 00:00 Introduction 01:06 Why He Started Worrying About Privacy: Autonomy and Self-Censorship 04:58 Surveillance, Society, and the Loss of Room to Fail 06:01 What the Ethereum Community Really Thinks About Privacy 08:36 The Gap Between Personal Privacy and Business Compliance 10:54 What Web3Privacy Now Actually Does 13:45 Evaluating Projects: Hard Variables and Verifiable Code 17:01 When "Zero Knowledge" and "Private" Are Just Marketing 19:39 The Cypherpunk Congress and Why Privacy Matters Now 24:00 Tooling Is Ready, So Why Does Adoption Lag? 28:49 Compartmentalization, Intent, and Privacy by Default 34:38 GDPR, Cookie Fatigue, and Whether Regulation Backfires 39:49 Privacy vs Compliance: Does Privacy Make Regulators Nervous? 42:14 The Middle Ground: Opt-In Reporting, Viewing Keys, Selective Disclosure 45:31 Selective Disclosure and the Jordi Baylina Thread 46:10 RWAs, Institutions, and Why Tokenisation Projects Kept Dying 53:03 Privacy as a Market-Integrity Feature: MEV, Front-Running, and Competition Law 55:43 The Most Useful Thing an Ordinary Person Can Do 58:30 Where to Find Robert Resources and Links Robert on X: https://x.com/robdotrego Web3Privacy Now: https://web3privacy.info Cypherpunk Congress: https://congress.web3privacy.info/ Event: https://luma.com/spsnos9t Oak Security's Research: https://research.oaksecurity.io/
After several episodes focused on security, this one turns to privacy, with Emanuele Francioni, co-founder and CEO of Dusk, a blockchain built for privacy and institutional use cases. Emanuele traces the through-line from a contrarian 2018 thesis to a live network to abstract financial instruments away from the intermediaries that leak both value and data. A core thread is the counterintuitive relationship between privacy and regulation. He disentangles anonymity from confidentiality, shows how privacy actually underpins rules like GDPR, DORA, and insider-trading law, and explains how Dusk encodes KYC, jurisdiction, and limits directly into the protocol. Then it gets harder: on a privacy chain, a vulnerability can be exploited in the dark. Emanuele uses the recent Zcash unbounded-mint bug to explain why Dusk's approach has to be proactive, why the team shipped three security upgrades this year (Aegis and Boreas among them), and why simplicity is the best safeguard. On the AI arms race he's candid, seeing Fable in action for three days genuinely scared him, but his conclusion is pointed: AI doesn't replace security expertise; it makes it more valuable. Key Topics Privacy vs confidentiality vs anonymity, and why privacy underpins regulation Encoding regulatory compliance directly into a protocol Securing a privacy-preserving chain, and the AI arms race in security Chapters 00:00 Introduction 01:05 Founding Dusk in 2018 and the Road to PLONK 07:14 How Privacy Fits the Regulatory Space 08:00 Anonymity vs Confidentiality: Disentangling "Privacy" 15:11 Selective Disclosure and Working With Regulators 21:30 Encoding KYC, Jurisdiction, and Limits Into the Protocol 24:25 How Privacy Changes the Approach to Security 27:12 The Zcash Unbounded-Mint Bug and Why Privacy Must Be Proactive 29:30 The Security Arms Race and Five Attack Attempts This Year 34:50 Why Simplicity Is the Best Safeguard 36:12 The Complexity Trade-Off: Custom VM, Sandboxing, Immutable Contracts 40:14 Shrinking the Layer One: Dusk EVM and a Privacy-Preserving L2 43:21 The AI Arms Race: Aegis, Boreas, and Restructuring Into "Pods" 50:22 Cross-Pollination: Pulling Ideas From Biology Into Software 55:10 Where AI Helps in Security, and Where Humans Still Matter 1:02:19 Oak's Research: Minor Human Intervention, Completely Different Output 1:04:27 Surprising Findings in Aegis: the BLS Truncation Bug 1:06:45 Boreas: a Live Incident and Real-Time Response 1:11:00 Operational Security, Supply Chain, and AI-Era Hiring 1:16:56 Wrap-Up Resources and Links Emanuele on X: https://x.com/autholykos Dusk: https://dusk.network Oak Security's Research: https://research.oaksecurity.io/  
Most of our guests come at security from the outside, as auditors and researchers. Antonio Viggiano sits on the other side of the table: he's a Senior Security Engineer at the Monad Foundation, working on protocol fuzzing for the chain's consensus and execution clients. Monad's architecture makes that a genuinely different problem. Unlike Ethereum, with its many interchangeable clients, Monad has a single pair: a C++ execution client and a Rust consensus client, both built by Category Labs. That tight coupling buys optimisations, but it also means a bug that looks real in one client is often quietly mitigated by the other. Test one in isolation and you drown in false positives. That's where Monad Bugfinder came from, and the origin story is the opposite of what most people assume. It didn't start as a bug finder at all. It started as a triager, because the team was being flooded with AI-generated reports: convincing write-ups, plausible proofs of concept, and hours of human time spent working out which ones were real. Bug hunters optimise for recall. When you're the one receiving the reports, you need precision. Antonio walks through the validation gates that made the difference, why AI has a higher false positive rate than humans, and why the best human reviewers still find twice as many bugs as the best AI systems. Key Topics AI-assisted vulnerability discovery and triage Invariant testing and protocol fuzzing In-house security teams at protocols Chapters 00:00 Introduction 00:38 From Solidity Developer to Security Engineer 03:10 Founding Recon and Cloud Fuzzing 04:39 What Is Invariant Testing? 06:38 Fuzzing Smart Contracts vs Blockchain Clients 08:41 Tooling Maturity and System Complexity 09:47 Extracting Invariants at the Protocol Level 11:11 Why Most DeFi Teams Don't Know Their Properties 13:29 Monad's Architecture: Two Clients, Tightly Coupled 16:29 Why Single-Client Bugs Create False Positives 17:21 Monad Bugfinder: Why It Started as a Triager 20:19 Precision vs Recall: Finding Bugs vs Receiving Reports 23:54 Inside the Triage Process 25:59 Reconstructing Proofs of Concept End-to-End 27:13 Should Smaller Teams Build Their Own? 30:06 Build vs Buy, and the Attackers Building It Too 32:27 Validation Gates: EIP Support and Differential Testing 35:49 Testing Against Geth and Nethermind 37:43 Local Clusters and Controllable Validators 42:00 Do AI Reports Have More False Positives? 44:37 The Economics: AI Tokens vs Audit Firms 47:47 Why Humans Still Find Twice as Many Bugs 48:14 When Your Scaffolding Goes Stale 51:52 Offense vs Defense and the Human Weak Link 54:27 The Roadmap: Making the System Generic 56:51 UltraFuzz: Agentic Fuzzing for Solidity 1:00:32 Specifications, Spec Drift, and AI-Written Code 1:04:08 Will AI Ever Write Bug-Free Code? 1:09:45 Where to Find Antonio Resources and Links Antonio's X: https://x.com/aviggiano Monad Bugfinder blog post: https://blog.monad.xyz/blog/monad-bugfinder UltraFuzz blog post: https://www.monad.xyz/blog/ultrafuzz  Monad: https://monad.xyz Oak Security's Research: https://research.oaksecurity.io/
loading
Comments