# HackenProof | Preventing Billion-Dollar Hacks - Dmytro Matviiv | ETHDam III - 2025

- Channel: [CryptoCanal](https://streameth.org/cryptocanal)
- Date: 2025-10-07
- Duration: 15:26
- Watch: https://streameth.org/watch/yt-2ZiLfr0qEB0
- YouTube: https://www.youtube.com/watch?v=2ZiLfr0qEB0

## Description

Welcome to the 3rd Edition of ETHDam, hosted May 9–11, 2025 in Amsterdam. This year, we brought together the brightest minds in privacy, security, and AI for a unique 48-hour hackathon + conference combo.
🌷 https://www.ethdam.com// 🌷

------------------

HackenProof | Preventing Billion-Dollar Hacks: AI, Real-Time Monitoring, and Crowd-Powered Security - Dmytro Matviiv | ETHDam III - 2025     

🎤 About the Speaker: 
Dmytro Matviiv is the CEO of HackenProof, a Web3 bug bounty and crowdsourced security platform trusted by major projects such as the Ethereum Foundation, SUI, Aptos, Celestia, MetaMask, OKX, and SG Forge. With over 13 years of experience in cybersecurity, cryptography, and blockchain security, Dmytro is a recognized expert in building trust between ethical hackers and Web3 protocols. Under his leadership, HackenProof has become a key player in strengthening decentralized ecosystems against evolving threats. A Ukrainian national and proud father, Dmytro is also a seasoned public speaker, having presented at top industry events like Token2049 and Istanbul Blockchain Week. He is dedicated to raising security standards across the DeFi and Web3 landscape through innovation, collaboration, and transparency.

𝕏 Follow:
https://x.com/DmytroMatviiv https://hackenproof.com/ https://x.com/HackenProof 

------------------

About ETHDam & CryptoCanal
ETHDam is powered by CryptoCanal, an education and events platform rooted in Amsterdam, expanding into Rotterdam and Zürich.

Keep up with us to see updates on future events: https://www.cryptocanal.org/ 
Follow CryptoCanal on X: https://twitter.com/CryptoCanal
Join CryptoCanal TG Community: https://t.me/CryptoCanalCommunity 
Join CryptoCanal Discord: https://discord.com/invite/XJVjpCqQBz

CryptoCanal unites crypto enthusiasts committed to making a positive impact. Unapologetically political, we prioritize education, events, and services while championing cypherpunk values like privacy, sovereignty, and censorship resistance.

------------------

🎥 Credits:
Intro / outro by babyPRO -  https://babypro.art/
ETHDam Photography by Paulus – https://concretestate.eu/ 
MC of ETHDam -  Collins Ejiofor - developer working at the intersection of Web3 and AI. Check out his LinkedIn for more about his work and upcoming projects! https://www.linkedin.com/in/collins-ejiofor/ 

------------------

Special thanks to our partners who made ETHDam possible: 
🌹 Hackathon – Bouquet:
Oasis Network https://oasisprotocol.org/ 

🌷 Hackathon – Petal:
Circles https://aboutcircles.com 

💛 Conference – Gold:
Zano https://zano.org/ 
Dash https://www.dash.org/ 
Bitvavo https://bitvavo.com/en 

🩶 Conference – Silver:
Igra Labs https://igralabs.com/hero

💛 Conference – Copper:
Lido https://lido.fi/ 
DeTrip https://detrip.travel/
Cake Wallet https://cakewallet.com/ 
The Grid https://thegrid.id/ 
Calimero Network https://calimero.network/ 
0xbow https://0xbow.io/ 
Mina https://minaprotocol.com/
JobStash https://jobstash.xyz/ 
Cyber Capital https://www.cyber.capital/  
POAP https://poap.xyz/ 
Acronym Foundation (Supported our Top 10 Hackers) https://acronymfoundation.org/ 

🌱 Sponsor:
EF Ecosystem Support Program https://esp.ethereum.foundation

------------------

0:00 Intro 
0:30 2024 Hack Trends & Access Control  
1:30 Private Key Risks & Real-World Example  
3:00 Losses Without Recovery  
4:00 Smart Contract Exploits & Audit Gaps  
5:30 Operational Security Challenges  
6:30 Bug Bounties & Incentive Failures  
8:00 Monitoring Tools & AI-Driven Alerts  
10:30 Community-Powered Security Insurance  
13:30 Final Recommendations for Protocol Safety

## Transcript

Welcome to [Music] Eg. Welcome to the stage please Dimitro and yeah preventing billion dollar hacks. Yeah. Hello everyone. Um probably I should take Yes. One sec. You can let me check please. Yeah. Yes. Okay. Hello everyone. Actually I made like 17 slides so we'll try to speak uh quite uh fast but yeah so I'm of hacken proof and we actually as a company we work with big big names so all clients uh work with us for some stuff like security contest or bug bounty so we're working with many hackers on the market for eight years and we have quite big experience and I would like to share insights uh with you so um Actually a little bit data of course we need data and understanding. So uh about hacks in 2024 as you see the biggest one was access control. Yes we also have some fishing attacks smart contract exploit and etc. And u if you go to 2025 you will find out this uh for first quarter we already have by bit of course. Yes, we have FAMX. We have actually some other guys uh which is related to other kind of stuff not only access control. So if you take a look generally so at the moment still access control is the most biggest part of hacks and it's mostly goes to private keys. So you're losing those private keys somehow or compromise or you go to drink to the bar and someone help you to to lose your keys and etc. Uh but actually uh what you should understand that actually we monitor and we do uh research every quarter and we public it. So this data is grabbed by us. We actually understand that numbers of hacks goes down and down but hacks itself big and bigger and someone mentioned today about AI some mention about some bad hackers and etc. But actually what we should understand that this is well organized hacks and if you under those procedur to be hacked they will do everything. They will monitor your browser they will monitor your telegram groups. I have story from uh um like two months a two months ago one of our clients was calling and say hey you know we actually were chatting with my wife in different rooms and she expected to send money to my bank account because we were talking about this I keep uh had telegram pinned in chat ping in my telegram but actually someone was listening to us all the time and when was the right time to send money how million dollars he just wrote message like me to her and she just sent to those details. Then chat was deleted and they find out that SIM card that was uh actually sell uh sorry they was sold in uh Thailand was actually compromised and those guys were listening and just use this SIM card to to actually send details. So uh about losses as you see before we could actually recover some numbers and we could actually back some uh uh actually money but nowadays we have situation when lost is without recovery. Yes. And u uh if you take a look for example at BitMart, they lost 196 millions in 2021 and they launched uh almost two months ago program to recover at least some money and they are ready to pay uh 58 millions dollars to recover this money or at least get some information. So to summarize is actually related to smart contract exploits to access control and data breaches of course some fishing attacks flash loans attacks and etc. So as you see for example WER they actually were has um problem with access control and recommendation from other side of course doing like penetration testing uh up to date uh dependencies because we working on some projects we know about vulnerabilities and when hackers submit reports companies actually try to update as soon as possible and we work with researchers we know that for example we triaging every day and our triage team is working like 24 hours. So if critical happens all company try to uh to work fast on this. Of course the doence monitor and by the way today Pablo was mentioned about something uh um that AI will be teach they will have their oven model and this is something that we see for example for the doors. Last November we had um actually case for more than 200 millions the those requests to our platform to our website and that was a part of AI model. Um of course uh if you go to um the app exploit which is was 290 millions it was about insecure smart contracts and protocol there just quickly and briefly. So of course documentation you need to like to write everything because sometimes companies come to us and say hey we would like to do audits and we like okay it's like how million or etc but they like I don't use those code like they just you know like take some libraries they put together and they don't clean from different uh unnecessary code and of course that might be an issue as well for uh for for for those stuff. Um I did a mistake to be honest about the recommendation because just make a slice and those data from previous one but um I would like a little bit uh add here more details. So about by bit we working with by bit at this moment um we help them to do proof of reserve and etc and be compliance with ma um and we're working with many other exchanges. So at the moment we have 42 exchanges which is with the biggest provider security for them. And what I would like to to say here so by bit case is very difficult. Yes. Because first of all guys in North Korea even if you know that these guys hacked it's hard to get them first of all. Yes. Because this region is close for us. Second actually the story behind. So uh there might be of course recommendation like operational security. There might be recommendation monitoring and AI. I will go step by one um like each by each by each of course integrated custom smart contracts. Uh and one more stuff is around why listing white listing for wallets. Um and I will explain. So let's say um I know personally because it's other clients that one of uh exchanges uh they for example um know about ISA in their multisk for $253 millions but they don't want to pay researchers money because um researcher would like to negotiate and say like we would I would like to have at least bounty for 0.1 percentage uh for to actually submit and be fix it but actually company is not ready to pay and don't want to deal so this is one stuff is actually when company don't want to deal with security because they don't want to spend money for that and for them it's better to I don't know book some booth at conference spend for end users but not for security so even if you give recommendations it's more about choice of centralization of operation operation. So when I talk about operation security, you have to understand that first of all, it's how your team managing this. Sometimes security team doesn't want to even tell owners or co-founders that there is an issue and they try to I don't know like to fix or do something then you can see some messages messages in actually Twitter or link in hey those guys didn't pay me in proper word etc. So this is how you deal with operation security itself about monitoring. So let me just uh yeah I will I will go to monitor a little bit more. So monitoring and AI I will show in another slide. So let's go to bug bounty for example. So in this um in the April uh we emunify we two the biggest players in the market in terms of bounty. Uh, I mean paid out around 1 million uh and I guess 100 and we paid out 1,370 um uh in April for bounties for um for actually for for valid reports and uh as you see for example in terms of projects which is was hacked and bound it paid. So this actually how much they could save or how many times they can actually pay. So for one of um cases that we also have unfortunately for issues that was in sex for $53 million uh hackers got only $10,000 as a reward. So sometimes actually researchers doesn't want to submit records because it's not appropriate appropriate way to pay and of course for example near case. So they paid out almost two million uh dollars to researchers but they save a lot and they quite act active uh actually as a as a protocol with a security and but nowadays if you take a look at and we of course uh we handle lots of um reports so move and rust based projects they have the biggest amount of issue they quite like modern it's easy to work with them but the the biggest issue goes from these uh uh projects in terms of bugs. So uh about EI and monitoring tools. So there are lots of way how to actually you can stop uh for example some smart contracts or have you can for example notify about issue. So let's say we have tool which is called extractor but you can use another but the way how they actually work so you can actually u automate monitoring you can specify what is critical what is high what is medium issue and then uh you'll be notified in different channels how you would like to to know about this transaction. So for example with the case of buy bit of course if we could set up transaction with uh some custom smart contracts and specify okay this amount of money is going from this wallet of course there there will be notification or maybe if we are talking about white listing if you say that okay this wallet is not in white list so probably it won't be possible to at least send uh actually money. Yes. So first of all monitoring of course in the monitoring tools there are AIdriven alerts accidents you can block transaction you can actually add smart contracts and etc. So many stuff and uh I believe also lots of uh tools at the moment on the market and actually if you if you take a look at the uh Q3 in 2024 uh lots of uh hacks actually automated uh and could be prevented by just having those uh um response and uh of course uh some hacks have declined thanks to robust security practices. So the actually you can also take a look at some numbers uh for those uh last year we didn't um do research for these years uh fully. So we will definitely pause this as soon as we do. And uh one more stuff that I would like to mention also here is about uh uh heckot. Um nowadays we launch it's some kind of um uh insurance for security. So uh it it's actually appeared like four months ago. Um the the the actually the main things auditors or companies who do audits with other they can host for 30 days uh contest and security researchers can find issue in this research and community will pay instead of company or projects for this critical issue. We already launched 22 projects uh 22 finished one no uh so submitted 228 reports and we have unique critical reports after audits and all money was covered by community. So how it works? So for example let's say you have audits for 30k then auditor or you as a project so you can actually decide who will do that can allocate 10% of this which is 3k and we create some kind of staken pool for community for your token for token of your partners or etc that actually believe that your project is secure enough after these audits but they can earn a py from this three 3k so actually if for 30 days happening something with your I don't know critical if some critical found uh community actually pay tokens instead of you but they get APY if not they just get token back and actually that also uh get APY so if you're interesting in such case please welcome nowadays we have lots of requests for this so it's like insurance market yeah and uh as as last they would like to to say here uh so first of all uh about cases It's definitely not enough u tools, approaches, best practices and etc. So my advice just try to create a plan for everything. Like if you do contest or audits, try to combine them. If you actually do bug bounty, okay, try to think what else you miss. Maybe operation security. If you actually have wallets or multisk, how many people and what they operate? If you know that some wallets or some stuff will be sent uh to specific wallet, just try to wait less wallet. So just try to predict everything from your side as a as a as a yeah as a company. Thanks. Thank you very much.
