Thank you. Music Thank you. Thank you. Thank you. Thank you. Join the ungovernables.
No filters, no apologies.
This season, we're cracking open Uniswap governance.
Welcome to a new episode of the Ungovernable podcast.
Howdy howdy. Welcome everyone to a new episode of the Ungovernable podcast.
Today we are thrilled to have Michael Lulon joining us, a pioneer of blockchain tech for over a decade.
Michael is the head of solutions engineering at Blockade, a leading Web3 security platform trusted by some giants, including Coinbase, MetaMask, and of course, Uniswap.
We are Joe and Austin from Alpha Growth, your premier DeFi operations and growth firm.
Michael, thanks for being here. What else should everybody know about you? Hey, good to be here. Thanks for having me.
I guess I always love to tell the story about crypto, but I started out in 2012,
mining Bitcoin on some school computers. And that's how I got invested. Suddenly I had to
Suddenly I had to figure out what the heck this crazy internet money was, and that took me down the rabbit DAOs, including Compound and Arbitrum,
figure out what the heck this crazy internet money was. And that took me down the rabbit hole
working closely with their team on a variety of challenges, even some governance attacks,
some security challenges specifically in passing proposals securely, lots of interesting things
like that. And then recently joined the Blockade team to really focus in on their product,
which is really trying to do all-round on-chain security protections integrated with wallets like MetaMask, working with Coinbase,
and even working with the Uniswap team on making sure that tokens are protected in their platform.
So I'd love to talk about that, but also anything else related to DAOs and governance
that I love to get my fingers into.
Definitely will be a lot of bases we can cover today.
But you brushed right over that story of mining Bitcoin
on school computers in 2012. You've got to double click into that a little bit at least,
because we've heard some pretty wild origin stories, but I think that one might take the
cake. What is the first time that you interacted with the chain or Bitcoin and you said, I have
It was really just one of those launch periods
where you're just, you know,
finding ways to kill time between classes.
And one of my friends at the time
was playing around with Litecoin, actually.
And it was like, hey, you know,
there's this thing I kept finding
I don't know where, but it was like,
hey, we could be uh making money
with this thing called light loin is a program that you can just run on your computer uh and it
prints out these tokens and they seem to be worth value and there's this like exchange called btce
which really takes you back uh we didn't know how shady it was at the time that's how early it was
everything seemed shady um and uh he was like you know you can make some good money on this i played
around with it but i actually found that the mining software was not that efficient.
Uh, and then I figured out you could actually install a Bitcoin mining software that would
run in the background and I could set it up in the startup folder of every computer that
was in, uh, the computer lab.
So I was able to get it running silently in the background.
I will have to preface, this is back when Bitcoin mining on a normal computer was still feasible. You could still make a decent amount of money on that. ASICs were just
coming online and starting to dominate the hash rate game. So there was a good year or so where I
was making a little bit of passive income from every computer that was running in that computer
lab. And then eventually they wiped the computers around the same time that ASIC mining
took off. And it didn't really make sense to do that any longer. But it got me hooked. It got me
to the point where I was looking at more about it. I was going to local meetups in Dallas, Texas,
where I grew up, talking about this sort of thing with a lot of other folks. And they were like,
hey, I want to set up a new miner. I want to set up a new wallet. How the heck do I do that?
kind of my tactical chops on crypto enough to help them out. So I started to become a general
purpose cryptocurrency consultant, for lack of a better term. Started a consulting agency just
called Cryptocurrency Consulting. There wasn't a lot of people doing that sort of work back then.
So especially whenever crypto went up, there's a lot of people knocking down my door, trying to figure out how to get involved and hopefully not get wrecked while they're doing so.
Had a lot of Coinbase support requests to people saying I haven't heard from Coinbase for a few weeks.
No one ever answers their support line. Can you help me out?
So there was also times where that became part of my job is just figuring out how to navigate Coinbase support.
out how to navigate. Coinbase support, really just every little challenge that people would
run into early on in crypto when there was very little support out there and most people were
just figuring out as they go. I ended up kind of just being the go-to guy. I even got on the local
news once explaining how crypto worked. It was a lot of fun. Oh, wow. I mean, it sounds like you're
a jack of all trades when it comes to crypto from mining to security to even get in the weeds for
support. I think one thing that I found super interesting is that you're also a lecturer
at UT Dallas. So what really inspired you there to be teaching students about this space?
So I started out at UT Dallas to get my computer science degree and graduated.
But when I was there, I did start a blockchain club.
So I was president of that for a couple of years. It was how I actually got to know a lot of people in the Dallas Ethereum community specifically, people like Hudson Jameson and other leaders
that, you know, it's a small, small world in Dallas, Texas for crypto and especially Ethereum.
But that was a great way to build those connections. But I also got to know some
professors. I did some research with them in the management school and specifically the financial technology program. So I ended up kind of TAing for a few of
those professors and kind of helped them prepare like notes and do, you know, education on blockchain,
you know, did a few workshops and other things that I ran for them. And then once I graduated,
they kind of said, hey, we want to actually do a full-blown blockchain course. We wanted us to be part of the financial technology program for graduate students
so that they can understand the technology, be able to actually build rudimentary contracts,
like ERC 2721. Fairly simple, but something that would give them an idea of what a financial firm
might step into if they hired these students later and then wanted to build out a digital asset or blockchain practice or build, you know, kind of innovate in that space.
So I ended up being brought in to essentially teach that course.
Originally, I was kind of unofficial.
Like I was just brought in to kind of be a guest lecturer,
but eventually they were able to make me official as a lecturer.
I'm normally supposed to have a PhD when I teach a graduate course,
but they were able to kind of make an exception there just because they're like, it's hard to find anyone that knows this.
Especially back when I started in like 2019.
But yeah, I still teach that course usually every second or third semester since it's part of a cohort.
And it's shifted a bit more to data analysis now.
It used to be, let's show students how to build smart contracts and kind of do basic programming around d5 and tokens there's still an element of that to the course
but now it's much more focused on data analysis because like realistically your average fintech
student probably isn't going to go out there and program smart contracts for like fidelity or
something else it's probably gonna they're probably gonna rely on an existing standard
like he opens up in contracts or uh or trust that to a different engineering team, but you can teach them how to do data analysis. Like how do I assess the risk of
opening a position on compound and ensure that I don't get liquidated? How do I kind of do an
analysis of how much volume is occurring on certain chains? Maybe assess what chains that
someone wants to launch a stablecoin on. So I ended up doing a lot of work with Python
and data analysis and a lot of the tools that they have there. So, but still teaching them the fundamentals, like why the heck does a blockchain work? What is
going on with private keys? Just other basic things that they could, you know, basically know
what they're talking about. Or I like to tell them the point of my course, it's not going to make you
a blockchain expert, but it will hopefully teach you how to smell blockchain BS. That's to say,
if someone comes in with a terrible use case or is just like,
I'm going to tokenize the Canadian oil supply or some crazy idea like that.
They kind of understand the limitations of technology to some extent to say
the problem you say you're going to solve a blockchain is not something
blockchain will actually solve.
that often happens a lot with,
kind of snake oil salesmen or people coming up with terrible startup ideas.
I was like, at least be able to think critically about this.
You might not be an expert, but you'll at least know enough to maybe at least get a sense of a bad idea when you hear one.
Yeah, and maybe tapping on that a little bit, too, is do you notice any fundamental misconceptions that students come into the course with?
That's a good question. Oh, go ahead. Sorry.
Yeah. I know that like recently, you know, there's been the meme coin cycles,
different narratives that I think, you know,
distract people and get their attention away from fundamental aspects about the
DeFi and blockchain space.
So I'm curious if you have any fundamental misconceptions there from students.
It changes, I think, every year that I teach it,
depending on what is trending.
I kind of missed the peak of the meme coin cycle.
As I last taught in fall, it was probably near the tail end,
but I have had students come in a lot, like not understanding why. I think the biggest one is
like not realizing just how decentralization works. They're always like, well, wait,
is Michael Saylor like running Bitcoin or isn't he like the guy or other years? I'll have the
same thing about Ethereum and Vitalik. I think the decentralization aspect is so hard for people to get on the outside.
They hear that and they're like, oh, something about it's decentralized,
something about it's like no one runs it.
But it's hard to tell, especially when there are crypto projects
that do have very prominent founders or things like Solana,
where there is a very active foundation and even projects like Ripple,
where it very clearly is uh just kind
of run by the company for better or for worse um i think that's the hardest aspect for students to
understand and a lot of the misconceptions they have coming in and i have to explain to them like
how and it's not even a binary thing like it's a kind of a spectrum of like bitcoin's like usually
on the very tail end of like very decentralized very established no one has any practical control over it ethereum
fairly similar maybe a little bit more influenced by the foundation and obviously a more active
development roadmap than solana and then like you know ripple would probably be on the other end of
like yeah there's a token supply but you know they could inflate at any time that the you know the
the company behind it controls most of their supply um again at the end of the day that's fine if if you're okay with trusting the ripple foundation but it's far cry from a more decentralized
protocol and like to say like that's why we can treat this as a different asset class it's not
just like someone's issuing stock that's like tokenized or another version of like a security
uh it's like you know genuinely a different class of assets that has to be treated differently and
such as our fintech students that's what's what I'm really trying to get them to understand
is it's closest to like a digital gold or a digital oil where the way that the system
works is that these things should be enthrined in the protocol and we should be able to treat
this as like an open system and anyone can interact with as opposed to just another software
platform or service that there's a company behind.
So what has been maybe an analog or a metaphor that you've been able to use that really resonates
with your students in terms of understanding the concept of decentralization, which is,
it's a natural concept, but I wouldn't say that it's a contemporary concept.
That's a very good question. I think the closest analog i've come to is probably talking
about like i might talk a little bit about linux if they're at least somewhat technically savvy and
familiar with that history of like hey there's this open tech standard that everyone can use but
no one controls there is development there is you know obviously people involved like
lanus torvalds that that steer it but ultimately anyone can fork it off, use it differently.
If you look at the history of Bitcoin and Ethereum, you can see a lot of forks, a lot of copies of that existing software and people trying new things.
But the difference here, of course, is the fact that there's a live network.
It's not just someone copying code and then running it and being responsible for running it.
In the case of blockchain, it takes that one step further of not just having an open code base but having an open network in which that code would actually be
running and people can interact with it so it's kind of like a a combination of like what the
open internet has kind of been conceptualized as even though there's you know a lot of centralized
actors behind the scenes like telecom providers um but you still have uh this open code base and
this open collaboration on how that code actually gets built over time.
And if people don't like it, they can always fork off or create their own version of what they want.
But it's a very difficult concept to convey because there really isn't a good existing comparison.
It is very novel and new.
So that's the closest I've been able to kind of get to conveying that with like existing examples most of the time it really the best way I can do it is just by going through the history
of like how did Bitcoin get created why did cypherpunks uh you know come to be a thing like
where they had this you know group of people that started a mailing list in the 80s or 90s that were
very concerned about you know uh corporations and governments creating technology that could
control people and like a, you know,
a supercharged version of 1984, and why they felt like we had to have technology that would
allow us to prevent that and create ways to have not just private communications, but also private
or, you know, privately controlled money, I should say. And that's, which is, you know,
kind of a still underlying ethos to this whole industry even
though we also have a lot of new players that are more interested in the use cases around building
financial applications or stocks or or other things so that's not the overriding ethos but
it's kind of the one that started it so when when students are like why are these Bitcoin guys so
upset and or obsessed about um decentralization and like token supply and who who gets to be a miner and who gets
to run a node i have to explain like there's this kind of like starting history of like being super
resilient to nation states and corporations and others and you know attempts to co-opt the network
they kind of have to understand to understand the discourse happening in this community which
um you know i'm sure you guys know it's a rabbit hole of going down that and figuring out who to work with and who not to upset, especially in DAO politics and
other things of, you know, what are we okay with having someone own and have some control over
for the sake of delivering on it? And what do we need to be very careful about when it comes to
implying control or making sure everyone feels heard and there's community consensus. It's a politically
charged atmosphere. And I'm kind of a partial at history. So I try to explain the history to
students to help them understand that. The decentralized centralized thing,
it's like you said, it's not binary. I somewhat see a future where you've got, I don't know if
it's Bitcoin or something else or a basket of all of these
different prevalent assets where every single country essentially creates a CDP that's backed
by these decentralized currencies. And each individual, of course, you can put your money
into USD CDP or Russian ruble CDP, and it's issued by a centralized party however it's backed by by
something that is that is not centralized i think there's a future where we at least see that
happening we might try that but then again when you hand away when you give away the
the centralized control it obviously the knobs and dials cannot be turned and you can't save economies if you can't control the currency um so all that to say you also mentioned use cases
and one thing that i've noticed by uh you know for my my time in this space i i try so hard to
not convince people that aren't in this space to be a part of the space but and i don't convince
them to try and go and buy any of this nonsense that we're working on. But instead I try to help them
understand why, why I'm here, you know, the Thanksgiving when I talk about crypto and they
say, oh, so you work at Bitcoin, so you work for Bitcoin. No, no, no, not even close. So I try to
make them understand, but sometimes every once in a while when someone is, is very, very curious
about what's going on, they'll ask really good questions. And because
they have such a nascent perspective and such an outsider's view looking in, sometimes we don't
see the angle that they're looking at it from. So I'm curious if any of your students have ever
brought use cases to your attention that you've never even thought of before that actually might
have some grounds, might hold water. Ooh, that's a very good question because I do have them do a project where they have to kind of come up with the, like their final project is
basically come up with a blockchain use case and define it and pitch it. And it is kind of tested
around just like thinking through, like, can you think of a feasible use case that isn't just like,
you know, kind of slapping a problem and thing, or blockchain will solve it kind of the same way
people say it about ai and
other things um and i've seen a few interesting ideas i think some of the ideas that come up a
lot are going to be like something that's very specifically focused on a financial problem of
trust or like very complicated markets you might never have even heard of like syndicated loans
or reinsurance or other things that are kind of very specific financial topics because
most of my students are financial uh students from like a bachelor's degree and then they're
like now learning how to code and do technology in their fintech program so you know they'll always
be thinking about like hey there's this like really obscure financial uh market or industry
that exists that most people might not have heard of. And there is a problem with trust or efficiency that occurs here where this potentially could solve it. I'm trying to think
there's anything that's like a real standout. I think the most interesting one has probably been
around syndicated loans and kind of like creating, like it doesn't have a very good marketplace right
now. It's hard to do discovery. It's usually very much like a kind of entities working directly with one another and putting together like these very
custom packages. I couldn't tell you the specifics right off the top of my head,
but I would say like it was probably the most interesting and compelling one just because I
didn't understand the industry well. And I was like, just based on what you're describing,
like, the whole problem is people don't understand it well.
Will you explain what a syndicated loan is yeah i let me actually uh look at my notes because
i remember this came up when i was talking to them it's basically a loan that's offered by a
group of lenders who work together provides funds for a single borrow so it's basically like imagine
um you know apple is like i want to you know take out a very large loan um and like a bc loan almost you get like a lot of
people in the round so to say yeah interesting so it's usually it could be a sovereign government
basically say okay i want to have you know a bank is like i don't want to just lend this much to one
borrower because what if that borrower doesn't pay me back like that's going to have a massive impact
so it's a way to kind of spread around risk and have a group of lenders that work together to provide funds for a single borrower.
Kind of what Maple Finance and Syrup actually acts as kind of a proxy for that because it's
these on-chain loans to institutions and the actual, the lenders themselves are multiple
people. It's crowdfunded loans essentially to
institutions i would say so that that's uh that is kind of what what maple's doing uh super
interesting okay the uh the security you're probably one of the most qualified people
literally on planet earth to talk about blockchain security um whether you like it or not it's a
pretty cool thing but and we're pleased to have you today. How would you say
that the need for security on chain has evolved over time? And where do you see it going?
So I think it started out, first of all, where we had very poor OPSEC, I think back to my time
in 2014, when we had Mt. Gox, the massive Bitcoin exchange that actually makes FTX look small by comparison,
not in terms of the amounts lost, but the impact it had on the market, because it was responsible
for, I think, 80% of the volume of the entire Bitcoin market when it went down. And it wasn't
due to any sort of necessarily fraudulent activity happening in the background like it was with FTX
entities. It was literally just terrible, terrible OPSEC. They had no concept of cold wallets.
Mt. Gox actually stands for Magic the Gathering Online Exchange, which tells you
how sophisticated they started out. They were basically doing trading cards and then they
pivoted into Bitcoin. Their security did not pivot with them. And the problem they had is
they were just like, people could just
hack into their server and they did so regularly, accessed keys that were holding funds for the
exchange and then stole it. And then over time, the exchange just bled money to the point where
they essentially lost so much that they had to suspend withdrawals and a lot of people lost their
funds. Exchanges have since become very sophisticated, but then we still see issues around private key
compromises. We can talk more about it later, but things like Bybit and Radiant and others show that
there are still operational security issues that can occur with exchanges or large financial
operators in the space when it comes to custodying funds securely. It's also a challenge on the user
side. The fact that users, when they self-custody,
they have their own keys and their own funds they control. They have to be responsible for that.
And right now, it is a, the space has become very sophisticated for separating users from their
funds using things like Drainer Wallets. And these are usually going, or Drainer Wallet websites,
I should say. And those are basically websites that are being built for wallets. And these are usually going, or drainer wallet websites, I should say.
And these are basically websites that are being built
And it's to trick users to come into the website,
think that they're interacting to either sign up
for an airdrop or maybe get a free token,
or they're interacting with a website that they think
is a website that they're used to,
like going to Compound or going to Uniswap or others.
But in reality, it's a impersonation.
attacker needs to do, all that operator of the website needs to do is get a user to sign a
transaction that they think is some sort of like, you know, sign up for an airdrop or something that
they would be used to doing. And it's actually a transaction that's going to steal their money.
And usually it's through doing an unlimited approval to some tokens or potentially to sign away a transfer that
they think is going to the smart contract when it's actually going to the attacker's wallet.
However it works, it's usually because the transaction details are not clear to the user.
There's no risks that are being raised. And that these attackers are incredibly sophisticated.
It's actually getting to the point where we're seeing
threat intel groups, especially here at Blockade. The research that they are doing shows that there
are drainers that basically are franchising their business. They're basically taking a software
package. So they're like, here's a package and a software kit that will let someone build a website
that will prompt a user with a transaction to steal their money. And then you can put whatever front end face you want over it. You know, you can try to pretend
like it's an airdrop or something else. You can try to hack into someone's Twitter account and
then use that to divert funds. We had this problem with Compound where someone also was able to get
access to the Compound domain and then redirect them to an impersonation website. And in whatever
case, a lot of times the people doing these attacks are not the original developers of the Drainer software, but they are essentially someone who got access to that software.
And then they have a fee sharing mechanism where whatever funds are stolen, a portion of those funds go back to the original creators of the Drainer kit.
And then the rest is kept by the attacker that actually had set up the website and managed to somehow get users to come into it and sign transactions. So that's why these businesses, in some cases,
are looking at making over hundreds of millions of dollars a year.
So these are incredibly sophisticated operators, incredibly profitable.
And this is one of the reasons I joined Blockade,
is that this is such a prevalent issue.
Even if your smart contract is secure, your exchange is secure,
all the software is secure, a user can still just, you know,
get wrecked through signing the wrong transactions
or being presented with something
they don't fully understand.
So I think that's the biggest issue.
And then still we have North Korean actors
that will go after big operators.
And occasionally, you know,
they will spend months trying to go after an attacker
And they'll basically say like, let's monitor them.
Let's figure out who works for this company, who's on this multi-sig, what their habits are, what different devices
they use, where they're physically located potentially, and figure out whatever they can
to be able to find a weak point and insert an opportunity to conduct a high-value attack.
And so that's what we saw with things like Bybit, where they were literally able to hack into the safe interface that would have affected all projects so in that sense we're
kind of lucky but they specifically said we're going to go after specifically bybit we're going
to make sure that there is a vulnerability in the website specifically so that bybit is presented
the wrong message uh when they're signing a transaction that they don't realize is actually
giving them control and then that's what got them access to then $1.5 billion. And then they're also very sophisticated when it comes to then
laundering that money or moving that money very quickly, moving it through bridges and swaps and
other things, and eventually trying to get it to a point where it can't be frozen or it's difficult
to trace down and they can figure out a different way to put it through operators that can't detect
if it might be stolen or not. So there's, and you
know, this is the theme of the day, probably going to fuel a good part of the North Korean nuclear
program. So these are nation state actors that have pretty good resources behind them, that
they've been doing this for years, they've gotten very good at it. And so like, when it comes to
security, it really comes down to like, one, on the user side, there's just very, there's, there's a lot of resources being put into scamming users that people need to be aware of.
Almost as much as is going into regular phishing emails or things like that, because it's just so profitable if you can get the money out of that user.
And then, you know, on the institutional side or the large exchange or operator side, you know, nation state actors might be coming after you just because you look like a juicy target.
you know, nation state actors might be coming after you just because you look like a juicy target.
And that could be a big payday to, you know, to pad out the national revenue.
It might be, you know, they might be collecting more in drainers or rather in hacks like Bybit than they would be in taxes.
Yeah. I mean, coming from traditional finance, for me, I was part of like the cybersecurity team, a few different banks.
And I remember seeing a pretty big visual of a map of all these different nation states basically trying to attack these banks.
And about every three seconds, there was a centralized entity where you're just shooting in the dark from that standpoint.
When it comes to security and blockchain for these scams and these different hacks, what do you think are some of the biggest innovations in the space to prevent this?
are some of the biggest innovations in the space to prevent this?
I think the first thing that's been a big help is just a kind of normalizing security,
both for exchanges and for like code, like smart contracts, where you're expect, you know,
coming out of the Mt. Gawk example, exchanges are now expected to do a high level of security,
like having worked with the Coinbase team, both at OpenZuplin and and now at blockade like they have a very sophisticated team where you know or multiple
teams really that are all focused on security in different areas of the business they take this
very seriously um you know they're they're they have a security team that's just as good as
probably the one that's at google or microsoft or facebook because of how much is at risk um
and i would say the same thing for any operator that's custodying funds
is there's a large expectation on them
to follow all security standards and then some,
like anything around SOC 2 or ISO 27001.
And then I would say for users,
this is one of the reasons I have joined Blockade
is providing more insight to kind of tell users and warn users when they're interacting with something potentially malicious.
So if there is a malicious domain or a malicious transaction that's presented to a user in a wallet that we support, and that includes MetaMask, Coinbase wallet, many others that we work with today,
we're able to actually detect if that domain or that token or that transaction is
malicious and then warn the user and not just warn the user but tell them why it's malicious hey
this is a known malicious actor uh this is trying to steal your funds in this way through an
unlimited approval um this is something that generally speaking we know for a fact you should
not interact with um because it has prior history or because we have seen this exact attack vector before and and present that to the user directly before they sign a transaction
before the money potentially gets lost um and in multiple stages if you connect to a malicious
app we tell you don't interact with adapt it's malicious if they proceed and try to continue to
interact with it and are presented malicious transaction we further say this is a malicious
transaction don't interact with it and here's why why. And so working with teams like MetaMask and Coinbase
and others, and Uniswap Wallet as well, I should say, we work with our wallet team too.
That has made a massive difference. We've actually seen
millions of dollars that have been attempted to be stolen from users, and we have been able to
block that and ensure that they don't proceed in cases where previously
we saw a very high rate of losses occurring with some of those customers.
So that's definitely innovation.
It's not just down to like detecting the security issues in that transaction, but simulating
the full result saying, if this transaction goes through, this is the amount of money
that will leave your wallet.
And there's a lot of cases where that might match up
to what a user's expectation was,
and they know not to proceed.
So I think like transaction simulation and validation
through what Blockade provides,
as well as detecting malicious domains and others
has been a big part of it.
There's other people doing this as well.
Security Alliance does a lot of great work
on providing their own threat intelligence,
working with a lot of different teams.
And I've been happy to work with them,
and other really good security researchers
have been a critical part of providing that
and working directly with teams rapidly.
having like this be provided as a general product
where you have a, you know,
24 seven threat intelligence team
that's constantly updating, tweaking
and staying ahead of threat actors.
We actually have some of our researchers that will pretend to be uh hackers uh and they will they will get into
some of these drainer groups and they will be able to see updates occurring um and see what's going
on so it's been um it's been a very uh challenging space though to be and you have to keep a very
close eye on what's going on uh you have to stay on top of anything that's occurring uh it's it's it's ultimately uh always something
you have to look out for like it's i think there's no static solution it's like you just have to
constantly evolve uh with what's going on in the industry it's no different than medicine right
antibiotics viruses bacteria you can't just there's never going to be one cure to cancer
there's never going to be one cure to cancer there's never
going to be one antibiotic that cures all diseases for the rest of time that's not how biology works
um okay so the one thing that i'm really this is more of like a maybe a philosophical ethical
conversation but the if defy is a public, I think you could also argue that security
inside of DeFi is a public good. So in your opinion, who's responsible for paying for it?
Oh, that's a good question. I think it needs to be spread out. There are multiple layers of security.
I think at the end of the day, if you are providing a platform through which someone
is going to be transacting with the blockchain, even if you don't control maybe the infrastructure around it, I think there is a responsibility around giving insight to the users about what they're doing.
a user has the ultimate responsibility to, you know, control their funds and know what they're
doing the same way that someone who's transacting on the internet or paying for something with cash
would. But it's really important they understand the risks the same way, like if I go on Amazon
and, you know, someone ends up scamming me, you know, I should be on, I should have understood
the risks by maybe reading the reviews and seeing that the product wasn't very good or something like that uh but if attackers allowed to like you know basically
if there's no you know feedback system or way to warn users like hey you know this person this
token or uh this sort of transaction has been known to cause losses uh that and there's a way
to detect that and a way to warn them then there actually should be a responsibility to then do it
if there's a tool available um it's the same way I would. So at the end of the day,
like, you know, especially this is very common for permissionless systems, like things where
you launch tokens, such as Uniswap, where, you know, anyone can launch a Uniswap pool
unless any token they want. And that's a core part of the protocol. There's no
controls at the smart contract level. And that's a really important part of how the system works.
at the smart contract level.
And that's a really important part of how the system works.
But if that's presented to a user in the interface
and that token that is in that pool
is known to be malicious or known to be a rug
or known to be something that's probably gonna harm a user,
then it is important to tell them that and say,
this is a token that exists on the decentralized protocol.
You can interact with it.
There's nothing we can do to necessarily stop that.
But we can warn you. We can tell you, hey, this is a token that is known to have malicious
history, and you should be aware of that before you proceed. So I think it really is around
presenting as much information to the user as possible, but also in a clear, like, objective
manner of like, hey, this is supposed to help you make a decision, but very clearly, this is
malicious. Now, beyond that,
if you get into a system where there is control, for example, if you're like an exchange or a
centralized provider, then yeah, I think there's a little bit more responsibility than to like,
just not list it at all if you know it's malicious. And we also work with centralized
exchanges to help detect potential, you know, malicious tokens or other assets that might not be,
you know, really like meet their
standards for what they want to expose their user base to. So I think the level of responsibility
is definitely going to be correlated with the level of control that you have. But in the
decentralized world, I think it just comes down to like providing as much information as possible
and warning users before they proceed with something that could cause losses. Because I
think that's, you know, if a user is just going purely off of like,
hey, I'm interacting with a smart contract
and I get this transaction, like, you know,
it's hard for a technical person to understand
what these transactions do sometimes.
For a non-technical user, it's very difficult.
And usually these scams occur when they're being directed
to, you know, take certain steps that someone
that has built up trust with
them and what we would call a pig butchering scam, which is you, you fatten someone up,
build up their trust, and then you get them to send you a lot of money. Um, you know, these,
most of these people haven't even interacted with crypto before. They don't understand how it works.
They've been convinced to set up a Coinbase account and move it into a wallet and then send
it to an address. Um, and if there aren't any protections in place to tell them exactly, hey, what you're about to do is very risky, or you're interacting with someone who's
known to be malicious, there's no real way for them to be protected. It's otherwise very difficult
to keep those things from continuing to happen because it's just so common and it's so profitable
for attackers. They'll reach out to, just like Nigerian scams,
they'll reach out to hundreds, if not millions of people. And if only just a few of those
reach outs actually succeed in getting money, those are still going to be potentially tens,
if not hundreds of thousands of dollars they might get out of the wrong person. I've worked
with people that have lost their entire life savings, like up to $700,000 through some of these scams.
And it's heartbreaking. And they're not dumb people. Like one of them was a retired accountant
or someone who is a doctor and other people that are very smart, but they just don't understand
this technology. And they were tricked by very sophisticated actors that put in a ton of time
to make them fall in and lose all their
funds. So, yeah. So, obviously, I'm very passionate about this. I'll wrap it up there.
But just to say, yeah, I think the responsibility comes down to just if you know there's information,
if you know there's tools you could be providing to users to give them more insight into what
they're about to do, I think there's absolutely responsibility for that. And then beyond that,
it's just a question of how much control you have to then block those most things on your own side. But on the most decentralized end of the spectrum,
if you're providing user interface to a user, you should provide some information about what
are potential risks around what they're doing. Yeah, I think it's important to have those
guardrails up for especially new users too, right? Like for the pig bookturing scams or romance
scams or whatever you're going to,
whatever scam is coming up next. So that way their first interaction with crypto
isn't going to be a bad one and completely leave a bad taste in their mouth.
But I want to touch a little bit more and take a deep dive on Blockade. Michael, for those who aren't familiar with Blockade, could you explain it in some high-level terms
Yep. Essentially, we are an end-to-end
on-chain security platform.
Our main objective is ultimately to solve
all the major security issues that we see in the industry
Coming from OpenZeppelin,
which is still a great company
for doing security audits and other things,
I think the biggest challenge we saw was like, okay, so we can try to solve security issues by doing more
audits, by being very active in DAOs like Compound and Arbitrum. But ultimately, we only have so
many people that can do that work. It doesn't scale beyond the really smart personnel that
OpenZeppelin had. And there was also work with Defender and other things that did provide some tooling.
But I think the big difference I found with Blockade
and the reason I've been really passionate
about the work we're doing here
is like it really is trying to go to where the users are.
It is trying to integrate into,
it's not just working with like a smart contract team,
but working with the consumer facing product.
So the bread and butter of Blockade
of servicing any transaction, a domain, a token, anything that's malicious or could harm a user
and working with some of the biggest companies in the space like Coinbase, OpenSea, Uniswap,
you know, and anyone else that we talk to that list grows every week. But then to also work
with those teams on, hey, now that we have all of this protection and
coverage provided to your user base, let's also work directly with your core team on what we can
monitor in your smart contracts. We can tell you and give you insights into like where users are
being scammed. We can tell you how that your change in a UI, maybe you made a big red button
a little bit bigger when you're warning a user based on the insights we give them, like we can show you how much that might have decreased scams or not. We can tell
you, you know, what's going on on the various different blockchains where you're listed.
And we can also help you protect core assets. You know, a lot of these teams will do their
own treasury management, or they have their own funds on chain through a multi-sig or an NPC
solution like Fireblocks or many others. And, you know, they're trying to make sure that what happens,
what happened to Bybit doesn't happen to them. So we have another solution that's come out called
Cosigner. And the whole point of Cosigner is to essentially do transaction screening on every
transaction that goes through a multisig and not only service those warnings and details to the
users of those multisigs, which could be, you know, managing millions of dollars, but also to then block that transaction or rather to refuse
to sign a transaction if warnings come up. And the reason that's important and the reason we've
kind of gone the extra step to be involved in the signing process is because of situations like
Bybit where if the user interface is compromised, there's no way to warn the user.
You know, the attacker, if they have control of the user interface
or they have control of the end user device, like they've hacked into your laptop,
you think you're interacting with, you know, the normal safe website,
but you're actually interacting with something that they've set up.
You know, if they have complete control of your end user device,
you have no way of knowing what's going on.
Maybe if you did some proper checks on a hardware device that you might be using to sign, you have no way of knowing what's going on. Maybe if you did some
proper checks on a hardware device that you might be using to sign, you could prevent that. But that
is a very challenging field that continues to need a lot of work to improve. We are working on trying
to improve that as well. But the biggest thing there is like, okay, well, if the person signing
doesn't know that they're signing something malicious, and there's no way to warn them
directly on their device, then the next best thing is to then be a part of that signing process
and independently be verifying the transaction. And then when we see that transaction as malicious
vectors or maybe other things that don't meet their policies, like, hey, this is sending more
money than our policy should allow in this multisig. There needs to be an extra override before this is
allowed to proceed. We can ensure that that's essentially enforced at the transaction level.
So basically, we would automatically sign any transaction
that goes through the safe if it passes all the checks.
So, you know, you queue up a transaction in safe,
and within probably 30 seconds,
we're going to have a signature on there if it's passed all of our checks.
We'll also send out alerts and say, hey.
Well, talk to our team about that. It depends. No, but what about just for the average person
who just wants to be smarter about on-chain management and wants to use a multi-sig
for their own transactions? Do you guys have a retail product in the pipeline?
It's a good question. We don't currently have a retail product. It might change in the future.
We don't currently have a retail product.
It might change in the future.
Right now we're very targeted towards institutional clients or large treasury wallets.
So teams that are trying to essentially manage a bunch of funds behind the scenes.
So it could be things like we're managing a large grant program with over $100,000 in
our wallet or something like that.
I think at some point, and I say this because we're very early in this product, it's something we've been offering only for a few months.
That could very well change
and we could start to offer it on a retail basis.
But right now we are focused primarily
on institutional customers
and ultimately building pricing
based off of their specific needs.
But I think I would love for this to be something
that's available to customers at some point in the future
where anyone could build a co a cosigner into their safe.
That would definitely be a great goal to see in the future.
For now, they do have the ability to use Blockade in their wallet or other things, so they still get warnings.
But I think at the end of the day that the attack vector that we're most concerned about that cosigner solves is not one I would expect to be deployed against a retail user.
not one I would expect to be deployed against a retail user. It's something that I would expect
like a normal actor to go to very sophisticated lengths to do that they would only and they would
only put in that much effort if they were going after a really fat target like a treasury wallet
or something operated by an exchange or a hedge fund or something like that. So that's why we're
focusing on that target segment. But as this product develops and matures, it could possibly
to retail just to continue to expand that coverage.
Okay, I look forward to that.
How, Michael, how does Blockade work with Uniswap?
So we've been working with the Uniswap team for, I think, at least a good six months,
if not more, at least since we've been in public with that announcement.
The primary way that we do so is in the user interface.
So whenever you go to the Uniswap app,
whether that's on mobile or on the website,
you'll go in and you'll maybe search for a token.
That's one of the first things you can do and say,
I would love to interact with this token.
You can put in the name, you can put in the address,
and it'll usually pop up. The thing that had become a problem is, like I was saying earlier, anyone can list a token on Uniswap.
And that could include rug pulls or malicious tokens or things that users should, you know, they would be potentially not wanting to interact with if they understood the full details and risks.
And so whenever you look up a token on Uniswap, if it is something that we see particular risks about, so for example, we're like, hey, this is like a known malicious token.
It is an impersonation token.
So like it might be an OK token on its own, but we know it's trying to impersonate like USDC or Link or something else.
Or it's got a honeypot warning like, hey, we see that this has been set up in such a way that you know it could be a honeypot they could be rucking you later on doesn't necessarily mean
it's malicious there's a lot of tokens that look like a honeypot but might just be kind of you know
a run-of-the-mill meme coin but generally just making sure that they're aware of those risks and
there's an entire documentation page uh that uniswap offers that kind of goes into detail
about these warnings um and it's something that you will see if you go into the uniswap offers that kind of goes into detail about these warnings.
And it's something that you will see if you go into the Uniswap interface, you look up any token that has one of these risks, it will pop up and specifically say, here's a warning backed up by
blockade. And this is why you should consider not proceeding or at least be aware of these risks
before you engage with that. And that's also something we have available in the Uniswap
wallet. I've definitely seen that before.
Thankfully, I haven't engaged with too many honeypots, I don't think.
So I haven't seen a ton of these warnings, but I have seen this token is not traded on leading U.S. exchanges.
I've definitely seen that warning before.
That's probably the most common warning because there's only so many tokens that are on the U.S. leading exchanges.
Only so many tokens that are on the US leading exchanges.
But to you, what is the most difficult aspect of balancing security with permissionless ethos of a protocol like Uniswap?
That's another good question.
I think it comes down to who's responsible.
I think the biggest challenge is figuring out who's responsible for security.
And luckily, I think teams like Uniswap do take a proactive
approach, but there are other teams we talk to where, you know, they don't take it as seriously,
or at least they don't take it as seriously until they see how big the problem becomes and how it
kind of affects their bottom line. Because, you know, at some point it's like, well, you know,
a user loses funds. Well, okay, that just happens. You know, it's decentralized, whatever. But then when you realize that this
actually can create churn, like if you, you have a user base that, you know, come in, came in,
it has money. And then suddenly, you know, a malicious rug pull takes all their money.
You know, it's very unlikely they'll want to interact with it again. You know, they,
they will either just not have any money left to trade on that platform, or they just decide that the remaining money should be better put elsewhere.
And so this actually can create a ton of churn on user bases.
I mean, you know, when users are constantly subjected to this, they don't want to engage anymore.
And so that's when some teams start to get more active.
After the problem has become bad and they recognize that it's having an impact on their usage, then they feel like there needs to be a response.
And sometimes that's already when they've taken some reputational damage.
But yeah, I think that's coming back to the decentralization part.
I think it's recognizing that, you know, we have to we're never going to fully remove malicious actors from the ecosystem if we want
it to be permissionless, but we can definitely help people recognize who's malicious and who's
not and make sure that we're very careful about how we flag it. So there's a reason that we have
so many different warnings. You know, we have some things that are red, some things that are
kind of yellow, because there are cases where, you know, a perfectly legitimate token gets a yellow warning or might get a warning, I should say.
And someone's like, hey, like, why am I being flagged? I, you know, I'm a perfectly OK token.
And it turns out like, yeah, there's kind of some weird stuff about the token.
It might have a unstable token price. It might have an unfair supply distribution, things that would trigger a potential warning.
But then it's important to kind of put that in context of like, okay, is this like a warning
that a user should just be aware of, but it's not necessarily a token that they should interact
with? It's just like, be aware this is kind of a riskier token than others versus like a token
where it's like, no, this is definitely malicious and there's probably no reason you should interact
with it. And then just making sure that we're accurate and fair with those ratings
that's something that uh we've done a very good job of doing compared to the rest of uh the
industry or anyone else that has tried to do similar work and it's honestly it's partly having
really good threat intel data uh having really well tailored heuristics and then just constantly
responding to uh what comes up and what gets flagged and making sure that we're constantly adjusting it. Like new token standards come out or new projects get launched and we have to make sure that we're keeping an eye, which is even worse. So it's a very fine line and our team's gotten very good at doing it. And we've gotten very good at working with the teams that build just have a different sort of expectation for their user base. And that's like probably the most crucial part of it. But yeah, at the end of
the day, I think it's mainly about communicating risk. Like there's a reason that, you know, even
though a lot of token projects are not considered securities or rather we're kind of in a better
regulatory environment to avoid that classification, you know, there's a reason the SEC, you know,
requires people to share risks about the investments that they make. And it's because, you know, people need to realize
that there's always a potential to lose money and why that might happen. And I think that's
something that, you know, I hope we don't have a lot of stringent regulation on that in this
industry, but I do think it's important for projects to be proactive about conveying those
risks, especially if it comes down to knowing
that there's a bad actor.
The stock exchange doesn't have a problem of meme coins or things like that.
It's very hard to get listed.
And the whole point of blockchain and crypto is to make it easy to get listed, make it
But of course, that lets in a lot of scammers and fraud.
And if we want the system to work in a decentralized manner, then we need to have other solutions that might necessarily gatekeep the ability to list tokens to provide enough information that the malicious actors that will take advantage of that are not going to be able to make as much money as they're making today.
information provided to users is so complete that very few of them actually step into interacting
with malicious token that most people have no business interacting with. There's no reason to
buy a token that is for sure going to get rugged if you knew that ahead of time. And that's the
thing we're trying to work on. We do provide today and continue to work on improving every day.
Yeah, it's like permissionless with information. I guess, and touching back on Uniswap, are there any unique insights that you got working with Uniswap that weren't really visible from the outside?
I don't think there's anything I can think of off the top of my head that would, that anyone wouldn't already maybe know.
I would say like the team is incredibly good at what they do.
I mean, I've had the privilege of working with them.
It opens up in prior as well.
I think they have a very good eye for user experience.
And that's part of the reason they've built out their wallet and app the way they have.
And I think the way that they've thought about
security has both been from a user protection perspective, but also from a user experience
perspective. And saying that, like, by surfacing these warnings and surfacing them in a very, like,
clearly built out way, they improve the user experience. Because sometimes we've had cases
where, you know, customers view security as impairing the user experience.
Oh, you're adding additional steps or additional checks that people need to look at.
But in reality, if you do it well, if you integrate something like Blockade into the user experience with real foresight into how you want the user to flow,
you're not just tacking it on, but you're making it a critical part of the flow and trying to make it look good and convey the information clearly, it's actually a net
benefit. Like I think we actually saw a study from one of our other customers, it might have
been MetaMask, that actually said that the user engagement went up after Blockade was integrated.
It didn't go down because they actually felt more comfortable interacting with it when they got
these additional warnings and insights
on how they were interacting with things.
Whereas before, they might have been hesitant to submit certain transactions
because they just weren't sure what was going on.
And so, yeah, that's a roundabout way to say
I think the Uniswap team takes these things very seriously,
and it's been a big part of why we've enjoyed working with them.
Yeah, and I guess maybe touch on one thing
like going on a variety of different chains
and having different versions
from a security architecture perspective,
how does this multi-chain approach,
multi-version approach affect like the attack service
surface and vulnerabilities within the protocol?
Ooh, that's a great question.
We do luckily exist in a world where most EVM chains follow a fairly simple,
like there's generally compatibility between them in terms of like,
you know, smart contracts should work generally the same on most.
There is a challenge with some things,
and there are also some rollups like the ZK
Sync and abstract rollups that have like some key differences that we have to be aware of
when we're integrating with them and providing support for them as Blockade does today.
So, but yeah, so the more different it is, I think for each chain, which, you know, for example,
Arbitrum is building stylists and other things that are kind of like supposed to be net improvements on the EVM as it exists, but it does introduce
new security challenges because there's new patterns and things that you have to recognize
and build new heuristics on, as opposed to just relying on what we've already developed
for EVM chains that remain largely the same.
And I think there's also definitely a challenge with the fact that attackers will sometimes
move into these new ecosystems, new chains that launch.
And if they don't have Blockade or others supported on launch, we work with some chains that have us on launch because they see it as a priority.
And some chains don't because they just feel like they should only bring us on once there's a problem.
But these are often chains that because they don't have these protections become a field day for scammers and attackers because they're like, great, this is a new
ecosystem. They haven't built up the same security safeguards that others have where we have less
success. I hear the same thing happen with MEV traders as well. So like a new chain launches,
if they don't have a lot of protections in place on the outset, it's definitely an area where
users will find themselves being negatively impacted. And it's much easier to rug or steal from those users than it is in other ecosystems.
And I think that's part of the challenge as well as the fact that, you know, moving between chains, having multi-chain architecture, maybe a transaction that's, you know, let's say, you know, bridging your funds over to a different chain, doing a swap, and then bridging
it back, that introduces new challenges on how you simulate that transaction accurately
Because usually cross-chain transactions are kind of like wrapped in a different transaction
And so trying to break that down and show it to a user, even if it's a simple thing,
like a transfer, could be very challenging.
It could be something that they're not able to clearly convey to the user in a wallet interface.
And we are working with some teams now
and talking through how could we solve this?
How could we make cross-chain transactions easier
and safer for users to interact with?
Because we have definitely seen attack vectors
where attackers will take advantage of that obfuscation
where it's like, hey, if we try to get them to send money directly to a malicious address on this chain like
blockade will flag it or other solutions will flag it but if we can try to make it as complex as
possible and have it to be oh they take some action to submit it to a bridge and then on another
chain it's sent to a malicious address if we can wrap it up enough maybe it won't be detected
we have our research teams already identified it.
We've already worked on heuristics that helped to detect it.
But we're also trying to see if we can go deeper and natively integrate with some of
these chains, some of the cross-chain standards that are being developed to make it easier
to actually display what happens to a user and then detect these security issues.
Yeah, they're always trying to poke holes in it from attacker's standpoint.
When it comes to the security risk, what do you think is the most overlooked risk in DeFi at the moment?
I think that it's still going to come.
I think it's going to probably be the dependencies that DeFi has on one another.
Like the fact that, you know, for example, we're all relying on tokens like USDC to be, you know, managed honestly.
And they have a blacklisting functionality.
And if they wanted to, you know, they could intentionally or maybe even unintentionally, they fat fingered it.
Not that I think they ever would.
I think they have a very good team.
But like, you know, they could feasibly blacklist a DeFi protocol
that DeFi protocol would be in a position
where it's like, crap, all the money,
most of the money that we have in our vault
and it breaks all of the ways
that our DeFi protocol would operate.
Now, this is a risk you can't eliminate,
but I do think that there is work
to be done on the mitigation front.
I think there are a lot of protocols
that just have to operate with the assumption
that certain things will just never be hacked. And if they do, well,
like game over. I think there's more we could do than that. I think we could definitely say,
hey, if that happens, then, you know, there is a game plan, there is a fallback mechanism,
even if it's just pausing the protocol and waiting for that situation to be resolved.
resolved. You know, we definitely went through war games like that with Compound and other protocols.
You know, we definitely went through war games like that with Compound and other protocols.
And yeah, so I think that risk of like some sort of core dependency and mapping out those
dependencies and kind of being aware of them in case like, hey, if there's a hack on some smart
contract, like a, you know, a swap router or something else that a lot of other protocols
have integrated with, make sure that they're ready. I mean, I know when Compound did have
some disruptions that occurred a couple of years ago, you know, one of the biggest,
the biggest thing that we had to do was work with protocols that were downstream of Compound,
that had integrated into Compound to make sure that we weren't adversely impacting them. Because
even though we were in a position where no funds had been lost, it was like a temporary disruption
that was going to be resolved. They were in a position where because of that
disruption, their system might be even in a more precarious state just because they didn't build
that protocol with any kind of scenario of compound kind of being a pause state for a period of time.
So like these are, those are the sorts of things that I think a lot of teams, you know, they are
thinking about it more, but I do think it's still an often overlooked risk.
If there was one security practice that you could snap your fingers and implement across DeFi, what would it be?
I would say threat modeling. I think everything comes from threat modeling.
And that's to say, like, before, ideally, you maybe have even coded the protocol.
Ideally, you maybe have even coded the protocol.
And definitely once you have, just list out all the threats that you expect the protocol to face and that you expect it to be resilient against.
So this is like an exercise that I think Compound did do well in their V3 implementation.
It's like, hey, we're going to write down all the things a protocol should be resilient to.
You know, it should be able to deal with things like, you know, liquidations.
It should be able to deal with, you know issues of certain assets uh being broken um and then write
rules and test against it right invariant rules write tests formally verify if you actually have
the ability to do that and then you can also use that threat model to drive what do you monitor for
in production what do you do war games around what do you do uh what do you build protections around and so and it's especially useful for auditors um because auditors can then take that
threat model and test against it in their audit um and they have a very clear idea of what is
expected as opposed to just kind of being told oh yeah make sure my protocol can't be hacked and
there's often a long list of assumptions that have to be drawn up to kind of narrow that scope
into something realistic because it's like well okay we're obviously going to have to assume that this operator key doesn't get hacked because if
that gets he you get that gets hacked then the whole game is over it's a question of like do you
expect to have some redundancy in that case or do you just build that in as a assumption that it just
won't be hacked and if so how are you protecting that key are you going to use a multi-sig are you
going to use something like block it cosigner maybe maybe that's a requirement that comes up at some point um but but that's yeah that's what
i think if every team was doing threat modeling they would be forced to think about everything
else they should be doing no that definitely gives uh gives me a lot of things to think about i hope
anybody else listening to this that's building something innovative should uh also be listening
to a lot of this wisdom michael where can people best follow your work?
They can follow me on Llewellyn Michael on Twitter, as well as Blockade or underscore
We do have a webinar coming up in a couple of weeks that we'll talk more about the Bybit
hack and how things like Cosider can help prevent them.
So that's definitely the best next thing to look at.
I'll also be in T token 2049 at Dubai.
If anyone wants to come and find me there,
I'll be walking around and talking to a lot of our customers
So we'll be happy to chat with anyone who's interested.
And generally speaking, I also try to stay active in forums
like Arbitrum and Compound and lurk around on their DAOs.
We didn't talk a lot about that, but yeah, I'm still kind
of involved in the DAO landscape, although not as much as I was previously. Beautiful. All right.
Well, that is a wrap of another episode of the Ungovernable Podcast. Michael, thank you again
for sharing all this expertise. It was a very interesting conversation. For our listeners,
do not forget to subscribe on Spotify and YouTube. We're going to be dropping new episodes every week. Follow us on X at Grow Uniswap. And yeah, please, everyone. Thank you.
Keep tuning in. This has been awesome. Michael, thank you. And we are Joe and Austin from Alpha
Growth. Thanks, everybody. Thanks for having me.
This was the Ungovernable Podcast by Alpha Growth.
Watch all our episodes on YouTube or Spotify or weekly live on X.