Panel | Why can't we keep anyone safe? | ETHDam III - 2025
CryptoCanal·Tue, Oct 7, 2025, 12:00 AM
Welcome to the 3rd Edition of ETHDam, hosted May 9–11, 2025 in Amsterdam. This year, we brought together the brightest minds in privacy, security, and AI for a unique 48-hour hackathon + conference combo. 🌷 https://www.ethdam.com// 🌷 ------------------ Panel | Why can't we keep anyone safe? | ETHDam III - 2025 🎙 Panelists: Liz Steininger - Least Authority - CEO/Managing Director / https://x.com/liz315 https://leastauthority.com/ Christopher Von Hessert - Polygon - VP, Security / https://x.com/cvhessert https://polygon.technology/ Erik Arfvidson - Euler Labs - Head of Operational Security / https://x.com/code2042 https://app.euler.finance/ Eric Meng - Coinbase - Senior Blockchain Security Engineer / http://coinbase.com/ Moderated by: Jacob Czepluch - Phylax - Lead DevRel Engineer / https://x.com/_czepluch https://phylax.systems/ ------------------ About ETHDam & CryptoCanal ETHDam is powered by CryptoCanal, an education and events platform rooted in Amsterdam, expanding into Rotterdam and Zürich. Keep up with us to see updates on future events: https://www.cryptocanal.org/ Follow CryptoCanal on X: https://twitter.com/CryptoCanal Join CryptoCanal TG Community: https://t.me/CryptoCanalCommunity Join CryptoCanal Discord: https://discord.com/invite/XJVjpCqQBz CryptoCanal unites crypto enthusiasts committed to making a positive impact. Unapologetically political, we prioritize education, events, and services while championing cypherpunk values like privacy, sovereignty, and censorship resistance. ------------------ 🎥 Credits: Intro / outro by babyPRO - https://babypro.art/ ETHDam Photography by Paulus – https://concretestate.eu/ ------------------ Special thanks to our partners who made ETHDam possible: 🌹 Hackathon – Bouquet: Oasis Network https://oasisprotocol.org/ 🌷 Hackathon – Petal: Circles https://aboutcircles.com 💛 Conference – Gold: Zano https://zano.org/ Dash https://www.dash.org/ Bitvavo https://bitvavo.com/en 🩶 Conference – Silver: Igra Labs https://igralabs.com/hero 💛 Conference – Copper: Lido https://lido.fi/ DeTrip https://detrip.travel/ Cake Wallet https://cakewallet.com/ The Grid https://thegrid.id/ Calimero Network https://calimero.network/ 0xbow https://0xbow.io/ Mina https://minaprotocol.com/ JobStash https://jobstash.xyz/ Cyber Capital https://www.cyber.capital/ POAP https://poap.xyz/ Acronym Foundation (Supported our Top 10 Hackers) https://acronymfoundation.org/ 🌱 Sponsor: EF Ecosystem Support Program https://esp.ethereum.foundation ------------------ 0:00 Intro 1:19 Context: scale of losses in 2024 6:20 Lessons from Euler Labs' recovery and practices 9:32 Trade-offs of MDM and employee device privacy 13:36 Polygon’s culture of sharing real hack examples 14:44 Tips for individual OPSEC and device separation 16:51 Coinbase’s product-integrated security UX 17:57 Balancing education and internal awareness 21:02 Least Authority’s role and threat modeling 24:17 Coinbase on proactive smart contract security 26:26 Simulating phishing for training users 26:59 Question: recovering stolen funds from scams 27:45 Making crypto safer for regular users
Transcript
Welcome to East to Ethan. To Ethan, to Ethan, to East. This looks like a very uh competent uh panel we're going to have here. So, uh let's hope it will also uh not just be so on paper, but in but in real life. Um I'm Jacob.
I'm going to be moderating. I'm the lead devil at Filac Systems. I'll just give one light about what we are doing and then get on with the show. And we are building like we are building a new security primitive that allows protocols to define states that they never want their protocols to to reach. Um you can check my talk tomorrow for more detail, but uh I'd rather hear what you guys have to to say.
Um I'm joined today by Oh, now you're not in the order. I have the names. uh Liz um CEO and managing director of least authority, Christopher Van Hazard, VP uh head of security of Polygon, Eric uh the sorry Alvidson uh who is a head of operational security at Uler and Eric Mang, senior blockchain security engineer at Coinbase. So I think we have a pretty good uh panel lined up here. Um I'll just set the scene a little bit.
So since beginning of 2024, we have around 3.5 billion uh dollars lost to to hacks. Um that's not a small amount of money. Um smart contract vulnerabilities um don't even make up for the biggest part. Um usually like it's still a lot.
Um and usually there are fewer of these but much bigger uh amounts and impact. Uh but actually compromised keys uh and compromised devices etc. scams they make up for for the biggest part of uh of this amount. Um and that's even excluding the 1.5 billion from the safe uh front end that was compromised.
Um yeah. So basically today we'll talk a little bit about why we struggle still to keep everyone safe after 10 years of smart contracts tooling lessons learned. We still seem to struggle with this. Um, so yeah, I would like to start just with a quick round of introductions from each of you and maybe one sentence or two sentences about what you see as the biggest challenges we're currently facing in uh in this space. Hi everyone.
So I'm Christopher as you mentioned already. I lead security at Polygon Labs. Um so I I think one of one of the reasons of you know why we cannot keep everyone safe. Uh you got to look at it also from the other way. You know we are keeping a lot of people safe.
If you look at the total value lock that you have right now in crypto uh the easy how easy it is to actually be able to hack somebody nowadays with fishing. It's like it's incredibly easy to do it. So I would say you know we're trying to do our best. There's definitely a lot of holes to fix, but given how easy it is to hack somebody and how easy it is to access money, uh I think in general, you know, the job is is is doing quite well, but there's a lot for improvement. Thanks.
Uh yeah, I'm Liz uh from Least Authority and yeah, uh I I mean I think I agree with you on this that I mean, especially compared to like what we see going on in web two and everything, I mean it's not like it's exactly secure either. So I think some of the the fundamental design decisions that we've been making that are different from web 2 are pretty key to web 3's potential for being more secure in the future. And also um the other thing to keep in mind is the pace of innovation that we're seeing within the space too. So you can say yeah maybe smart contracts have been around for has it been 10 years already? Yeah.
I mean so so we should have some expectations for you know best practices in in some areas but in other areas we're still innovating so rapidly that it's difficult to establish best practices so quickly. Awesome. I'm Eric. I'm an engineer on our blockchain security team at Coinbase and uh yeah I mean I look at this stuff every day. there is just an inherent like learning curve that a lot of our users just have to overcome and it's getting more and more difficult especially as we expand into DeFi with the recent um memecoin era that we're entering as well and there are things that we're looking at there are a lot of things that we're doing however there are still things that our users also just need to overcome themselves and learn on their own but guarantee we are trying to keep everyone safe as as well as trying to make this space constantly safer for for anyone whether you're a builder or a user or a memecoin trader.
Uh, hi everyone. I'm Eric Arbitson, head of operational security at Oiler Labs. I think like the biggest challenges that we're facing and will continue to face are the social engineering attacks are probably the easiest path. Also supply chain attacks are extremely difficult to protect against and I think it's always a cat and mouse game. I think uh education is the primary defense that we have against this like educating people how to properly store their seed phrase and just like have a good hygiene on managing secrets and how you operate your accounts, what permissions you give and have like the least uh least uh what's it called?
um least uh privilege like meth meth methodology is always a good uh are good things that like people have to like implement in order to try to avoid getting um you know exploited or hacked. uh there's millions of ways that are happening and it's it's an ongoing battle of education and I guess like sharing with the community, sharing uh information and yeah, I'll give it back to you. Yeah, cool. I I think you already uh answered a couple of things I wanted to ask you next uh Eric actually. Um, so yeah, for for Uler, I think uh like you guys have been through a lot, but I think you're also an extremely good example of someone who's like recovered and like I just like to see it's it's awesome to see that that that a success story like you guys have been going through, I think.
Um, and as you just mentioned, yeah, smart contracts, they're not really the biggest uh problem. Not always. Like the thing is when you find a vulnerability in a in a smart contract, then you're probably uh really screwed, right? But it doesn't happen that often. But I I just like to know like at Uler, what are you guys doing like out of the extraordinary maybe to both keep your like protocol safe, but also um your users?
We had a small chat last week about this, but I would just like to know like what are you guys uh doing out of the extraordinary maybe uh that we other the rest of us could learn from potentially. One one thing that I I noticed that maybe not all the companies in crypto are doing is like setting up like MDM like uh managed device um management to like protect all of our employees devices. Also setting up EDR you know defenses for like when a computer gets compromised how to isolate like reverse engineer the attack see what information was leaked. Um most uh proper patch management on computer devices. Another thing we put a lot of emphasis is like uh protecting email and communication.
Those are like the biggest vectors that we're seeing right now like sending a malicious like email with a PDF uh and then you know exfiltrating information from that person compromising. Now you have this whole new uh type of attacks regarding like uh what is it called the you know people like going through the interview process sharing information. That's a big one. Uh we're also seeing um like uh people just lurking actually providing value and Discord and uh just waiting for somebody to ask a question like send them a DM. Hey, I can help you.
Impersonating people, impersonating uh our executives and our ater like there's always a battle. We use chain patrol to kind of like do DMCA takedowns on websites that are malicious. Um take down like on Telegram, LinkedIn, Twitter. there's like thousands of things that we can like uh we need to be always like wary because like impersonating I think is also a very key element like where it's very easy to create a new account right like anybody can create a new account and it's very easy to get like a thousand followers on your account like I've done it and it's like very is not a complicated thing to the other day I saw that there was a Visual Studio extension uh I I think I don't I don't remember the name exactly, but like it had even more uh likes than the actual official one. So there's it it was the official Solidity uh Visual Studio extension.
Yeah. Yeah, for sure. If anyone of you has uh anything to to add for um Eric's question, that would be great as well. But I think a follow-up might be uh you talk about these MBR stuff on people's laptops, stuff like that. And I think it's not necessarily security related, but I feel like that's also can be an uncomfortable thing maybe for employees.
At least I know someone who once worked at one of the companies represented here and he never used it his work laptop because he didn't like the fact that there was MBR on it and he used his private laptop. Um so because they don't like the surveillance kind of feeling, right? So there's two flavors. So there's the MDR like uh crowdstrike um sentinel one that is just monitoring like a behavioral of like what process are doing what uh data they're collecting and it's mostly just tracking if like you start like exporting data from like you can even put like canary files like let's say in your dot in your home user directory you can put like a like a file that like called secrets and if anybody reads it then that's a big flag that somebody's like scrolling through your computer. Um, but it's just like specifically for MDR, it's mostly just seeing what process are running and what uh like shell operations.
Then you have other ones that I think the ones that people get creeped out, they're like Net Scope. Netcope is a great tool, but it's also extremely painful for the security team operating because you basically get like full oversight on all the network connection. It's like a man-in-the-middle for a company. It does protect the users, but I I'm not like yeah, in terms of privacy, having that level of access of like, hey, you send this message or you send this document to somebody, please ask your IT team. Then you have like full visibility of everything.
Um, but it's just the level of things. I think MDR is a good approach and it's not like you actually have logs of who's accessing what information. So there's good traceability. It's not like I can go and just watch everything that my colleagues are doing. But yeah, I think there's different levels.
Net scope would be good for like a bank or like more sensitive operations where you need to monitor every single transaction. But I think just having like protection at the computer level and being able to determine, hey, somebody just installed a malicious or just just run JavaScript from like a library and they're starting to like do a C2 and like install a payload and then get privilege access on the computer. You should have visibility of that happening because that's transparent. I mean, it's not transparent. it's happening in the background and it's a very easy way to know that you know somebody's actually that is not intended has access to your computer.
I think playing a little devil's advocate what I hear a lot is it's also a little bit of u you know you're kind of installing a root certificate in your laptop that is allowed to do everything. So, you know, privacy, you know, we're here because of privacy. Privacy comes to a certain, you know, you're trusting that Crowd Strike or Falcon or even your own company will not do anything malicious or will not be looking at it. you know, um, you know, some of the concerns that I've seen, especially for public people, you know, people that are very publicly exposed, you know, they don't want to install these things because, you know, a government could subpoena, you know, somebody like Falcon or or stuff like that to actually have access to their laptop. Um, obviously there's no perfect solution.
Uh, and uh, obviously we are Polygon use very much MDRs and everything else. So completely advocate for for the idea of this. Uh the only thing I would say is um you know if you're really really concerned about these things first of all separate your life with your work life. You know most people that are concerned it's because they're using their work laptop in order to do you know personal stuff. And second of it if you're concerned that they could use your that machine as a man in the middle for to get access to your home network and everything else segregate the network.
just get another internet connection or completely if you're good at it and I guess you are if you're so concerned about it just segregate your network make sure that that laptop is only able to connect to a specific VLAN that has no access to everything else in um in in in your house no and obviously do the same with your kids and your wife and your dog because you know they can hack any of those things and your washing machine talking just I wanted to add to that like if you really want to go that like uh route I highly recommend and looking into CubeoS and like graphine and having like different profiles for different operations that you run. But um I I hope everybody uses them. They're great tools and I highly advocate that everybody starts using it. Yeah, for sure. Like good good advice.
And next question was actually going to you Christopher as well a little bit in the in the same direction. like Polygon has a very good track record I think of staying uh fairly uh like fairly on the good side of everything probably because you've been doing a lot of uh security related stuff very early on in the same way a little bit are you guys doing anything that wasn't just mentioned uh by Eric any any any other tips that you you've you have or that you tell your employees to to to follow I think like it was mentioned before and Eric mentioned again social engineering is the number one concern. It is incredibly easy to social engineer anybody in the company. So having layers as explained right now is very important. Um one of the things that we do at Polygon and uh I've done before in my past as well that that really resonates with users, people and everything else is learn by example.
You know, I assume everybody here is tired of having to click through the same security awareness training with, you know, Jane and do and, you know, Jane over talking about stuff and things like that. Like, I'm tired of doing it. Everybody just clicked through because it's boring and annoying, but it's a compliant thing that a lot of companies need to do. Another way of doing this that actually works is showing real hacks. Like when the bybit hack hack and the polygon, the first thing we did the day after it happened, we literally invited the whole company to a to a Google meet and we explained to the whole company how this hack happened, what we knew at least at this moment.
And then a week after when we got more information about it, we we jumped on that Google meet again with the whole company and we explained you know what what is the aftermath of everything else. And I was surprised of the amount of people that joined that Google meet like normally if security does a Google meet like who wants to join a talk about security guys like no nobody but we actually got a lot of attention. So we continue doing some of the things where we actually um you know just demonstrate how easy it is to hack and if it happens to one of you or one of your colleagues put them on the spot like invite them put them and like there there's nothing more real and translates better that somebody that that went through it and says like yeah this is what happened and the truth is like yeah I was dumb I didn't check I didn't verify I just clicked all through and you know this is what happened and I think this is the best way for people to learn and and educate themselves and and be vigilant. Now another very easy recommendation apart from the typical use wallets and stuff like that that I do right now is um have a separate operating system profile or a browser uh chrome profile only to do transactions like a lot of the fishing and the malware and everything else are coming through VS code well obviously VS code extensions or through uh Google Chrome extensions and stuff like that. So if you have just a separate prof profile in your computer or a separate profile in your browser that already will help a lot and it's not too you know it doesn't affect too much your user experience.
Having a separate laptop as well ideal especially if you're like in finance and you're signing transactions every day because that's your job. You should have a very tight you know computer only for transactions that is only used for that. Um, and and the same goes to them, you know, home uh uh, you know, hygiene. Like if you're using your laptop to, you know, watch porn and lend to your kids homework and everything else, you may not want to be doing crypto stuff as well in the same one, 100% to that. And the the idea of like even like airgapping, making sure that that laptop that you are using is just generally not online unless it's absolutely necessary.
Yeah. I mean I mean Christopher just touched on it all. I think there's the user education piece absolutely from what Eric said as well and the internal company education piece is huge. I mean yes we we hate clicking through all of the you know standard annual cyber awareness training. However, it is absolutely important that our company does know and our employees do know like how how the technical workings of of these vulnerabilities happen.
That way they're more prepared and and when they feel like the hairs on their neck tickling if they get an interview call from somebody that they might suspect is from North Korea or somewhere that isn't legitimate like they will be able to tell those see those signs a lot earlier and and flag to security as well. Like this it it really is I think the overall theme is just you you have to live with security as a mindset in your daily life. Like it doesn't just stop at work. It doesn't just stop at crypto. It is a daily thing that you have to embody.
Yeah. I just wanted to add to that like um one of the biggest pain points of like having to carry two computers is like I know at least up to MacBooks M2 there's now this new Linux operating system that you can install like uh as a multi boot. So you can always boot to like this different environment and you can have it completely just for like you know signing operations also using uh VMware or virtual box are great ways to segment like your risk um or where you do certain things like the more you like isolate compartmentalize like security things that are you're just going to do one thing the better it is cuz like you're not like mixing everything like having a developer environment and also using it for like doing critical security operations for signing. It's always a risk. So the more you segment and isolate uh your daily work or your personal life, the better.
It's better for you, better for privacy, better for everything. Yeah, for sure. And I think like that holds true also not just for working in a big company but also it's a very good tip for how you handle as a private person just who's into crypto like yeah separate uh your concerns have the standard hardware wallet yeah that's a good thing but like really uh maybe have two different laptops um as well same for wallets like you know probably this is very known in traditional finance like you have a small box and a and a big box I don't know in Spanish kakachica kaharande But uh you know where you have the big bucks are in one very safe compartment you know wallet hardware wallet multisig stuff like that but your daily transactions in crypto you do it from another you know smaller wallet and separate that. So if you are memecoin trading you probably are not going to memecoin trading with your bitcoin savings that you've been holding for ages. No true.
Yeah I actually have a I actually have a a laptop that hasn't been online for nine years that I sometimes use design transactions as well. Uh just as a Oh wow. It's a very I mean the the user experience is so bad that that's mainly why I don't use it for anything. You need security. It's a good way to just make sure you don't sell your crypto.
Just make it so difficult that uh it's almost impossible to to touch it. Um okay though I want to change the talk a little bit. So Liz, um you're working like you're the CEO of an auditing company, right? Or a security company. Um so I guess you are seeing both side of the sides of the battle.
So, I want to know a little bit about what are you guys like doing to try to stay ahead of the the bad guys kind of and what do you see the bad guys doing to try to get ahead of you? It is very much like this uh like uh cat and mouse game in in the auditing and the general uh security space. Yeah, I mean security kind of always is like that. And so um for every advancement and every innovation that we make, we also have to think about how could this be misused. Um, and so for for us it's really important to think like a hacker, think like to think about like if we were to break something, this is how we would do it.
If we were to try to do something that we're not supposed to do, this is how we would do it. Um, and so I mean that's the the simple the simple answer to that. Um, it it's very challenging though in the crypto space because um some well I mean we see a wide range. Some of it's more challenging, some of it's not so much because again, some of the things that are out there have been out there for a while and we know how to do it better like we all do. There's best practices around certain like uh management within wallets, uh key management and stuff.
And then uh smart contracts and things there's certain uh vulnerabilities that are you know we know we all know about and so uh that's where the education for people comes in to help to you know extend awareness and stuff and the best practices. Um but then on the other side there's uh innovation happening where you know people are doing new things to try to solve some new problems and that's where it's a much much more challenging uh and much more risky uh to find the security vulnerabilities. So yeah I I mean there's not really an easy answer to the cat-and- mouse game. It's just like we're all in it and we have to stay stay like aware and keep going. Yeah.
Yeah. I I was not really looking for an easy answer either. I just wanted to to hear like if there's like something that you guys are are actually doing in that regard. And I think what you just mentioned about like thinking like a hacker. It's it can be a very good exercise to do uh like on your own uh setup as well like sit down and think like if someone knew me or if someone would try to compromise me what are actually my weak points.
Uh I think that can be a good way of thinking like both in like physical like where you live like stuff like that but also in like your online presence. Um so I think that's definitely something people can try out and see if there's something they would Yeah. And we do have to work sometimes with uh especially clients to work on threat modeling like just basically this general practice of uh yeah what what are the threats against us like what do we need to worry about where's the incentive uh you know how are we going to slow people down in that and or stop them. Yeah, absolutely. Um, so I just do any of you have something to add to this?
I think maybe um Eric because you're also doing like smart contract security mostly, right? Um, so maybe if you could just like talk a little bit about the or extend on this because the question I wrote down for you is not that interesting compared to this topic. I think no, I mean I love technical questions and and as far as the smart contract pieces go, we we have a really rigorous CI/CD pipeline for anything that we build on chain. Um, not only do they go through intensive internal and external audits, we have formal verification. We have 100% code coverage.
We do fuzzing on all of them. So, we understand like what exact states and execution paths are even possible. We're we're even beginning to experiment a little bit with AI to see what's possible. Um, one thing that's also unique just because of the blockchain paradigm is, you know, you guys mentioned this game of cat and mouse. I almost like to think of it as a game of chess.
like there is a way that we can get ahead and stay ahead and counter attack even by by seeing the data on the chain by back testing against like the TTPs that we're seeing out there. Um it and and all this in combination with the expertise of our security teams allows us to to have an edge where we once didn't. You know, we're not just sitting there waiting for the next zero day to happen. we can actually prepare for it and and and doing those internal even even internal company exercises tabletop exercises those are very important in all of our flows as well. Yeah, totally.
And I think like what you just said in the end like these Yeah. both companies doing a lot of this like actual having a security uh division that like actually sends out training fishing mail stuff like that as well to just keep people like on their marks all the time. I think that's kind of stuff that also helps educate u people. Of course that is more internally in the companies and is not as easy to do uh for for private people. I don't know if you could uh do something where you can sign up for a service so you get a fishing email per per month that you should actually react to in some way because you should try to call it out.
I don't know if that's something to to do. Um do we have five minutes left? Um I don't know if any questions came in. Okay. Um you can hold you can keep it.
Okay. This was not really a question. just use fuss and donate to fuss. Uh send from graphine always. So that's that's good at least.
Um another 45 million plus was stolen from Coinbase users via social engineering scams in just the last week. Uh what can be done to freeze these funds or recover them? That's a question. Yeah, I mean unfortunately I'm an engineer, not a not one of the the heads of operations here. Um and and I can't speak to the specifics on that.
However, those those are again those are our main concerns right now are those targeted attacks. anything that can target a specific user. Anytime someone does a OSENT research ahead of time to any of our users, either even just getting their email address, that is something that we're looking at and something that we're tracking and and we're going to keep on developing internal policies as well as external policies to keep fighting those. Great. And this one is actually I think this is probably a very good question to to end this uh on because it's a little bit back to where we started.
So, um, all the suggestions we had so far, I think they're they're all very good, but as I hinted, they're maybe a little bit advanced for the regular user. Um, so what can be done to improve security for less sophisticated users out of the box? Um, any tips? Um, it I guess it just depends product to product. I think a good example for us at least um like for our Coinbase wallet for instance, we have Blockade integrated with the transaction simulations.
So before you even sign your transaction, you can see exactly what crypto is coming out of your wallet or what crypto is coming in. And then we also warn the user ahead of time if they're connecting to something malicious or a malicious website or a malicious DAP. So it there's a lot of lowhanging fruit that we can definitely capture ahead of time out the box and then also we're we're doing more research and and still investigating and researching on on the other security features that we can add in the future. Sure. But I think that's from like the product perspective what Yeah.
Let's just do a round for every one of you if you have like good a couple of good tips for like what you could do as a not super sophisticated user. Do you want to start? Yeah. Yeah. I mean from the from the product perspective for sure.
I mean we should be doing user research talking to people about like what default settings will help keep them more secure making that easier to understand and interfaces etc. like um is being worked on from the from the customer or the consumer angle the end user I mean for them it's a it's a difficult time right now because if you want to start experimenting and getting into these tools um you have to do some education. So I mean I'd recommend people to do some reading but also this idea of like sharing the the security failures like that users should be you know experimenting with lowrisk amounts to start and also being very open and sharing about like the security failures that they've had. So yeah I used the same laptop or yeah I said yes to something even though I kind of knew it was probably wrong and then I lost my money. And if people start experimenting with low-risk amounts and sharing their stories, then they can help educate each other in a really nice way and not really rely fully on the products.
Uh I have a couple of things I I would like to add. Uh I think two very easy things that everybody could do is uh check your email. I have been pawned. It's a great resource to see if your email or your not just your email being leaked, but you also what passwords have been leaked. That's like super easy.
I know most people tend to use the same password for everything. Use a password manager. And lastly, also pretty easy for everybody to do, although you're probably going to hate it, is wipe your computer at least once a year. Have external backup, you know, if you don't want to lose your files, but wiping your computer starting a fresh. You're collecting so much like programs that you install and you're clearly not updating them because you haven't run them in 6 months.
They're just there and there's other new attack vectors that attackers use. So, you know, wiping your computer is a healthy thing to do for sure. Christopher, I would say the last one, which is very simple. You know, everybody talks about trust, but verify like just read what you're doing. Like really just just read like I I make this mistake as well and I see everybody, you know, I see my wife at home, I see kids, I think every nobody wants to read what's happening.
like we've gone to a place where you know there there's a lot of information out there even MetaMask Rabby Phantom you know and Ledger they've they've implemented a lot of things it's not super intuitive but they implemented a lot of things to warn you about stuff so if you see uh you know the warning emoji just like read and and like read it all and then decide okay yeah yeah okay I'll I'll sign this I'll click on this because I can assure you that you know at least half of the mistakes happen because people just click through and don't read. And uh I know it's annoying. I don't read either, but you know, we should try to do it more. Yeah, for sure. And I think especially as Europeans, we've just been broken by these cookies.
Yeah. Yeah. Um okay. Thank you very much. This was amazing.
Uh give a big round of applause to the panelists. Thank you guys. [Applause] Amazing. Thank you so much. And Chris, nice to see you here again as well.
So easy for me. Perfect. Oh, I got my hands really full. Um, one fun fact because some people have been asking some questions. What the is this?
Um, there's actually a public key and a well there's a public address and a private key inside. And so this is from something called Capernacus. And the goal is to actually there's a bunch of NFTts and crypto that people have sent to this, but the only way to ever unlock it is to break it as a random fun fact. So he they're going to be knocking around I think over the next couple of days if you have questions about it, but that's what that is.
Automatic transcript — names and jargon may be misspelled.