# Dmytro Matviiv - How AI Killed the Crypto Security Industry — And What Rises from the Ashes

- Channel: [ETHCluj Meetup](https://streameth.org/ethcluj-meetup)
- Date: 2026-07-09
- Duration: 26:06
- Watch: https://streameth.org/watch/yt-VuMBgTS82FY
- YouTube: https://www.youtube.com/watch?v=VuMBgTS82FY

## Description

AI disrupted crypto security faster than anyone predicted — collapsing traditional audit demand, reshaping threat landscapes, and forcing the industry to reinvent itself. A candid insider view from the CEO of HackenProof.

## Transcript

Hey, thank you. Thank you. Actually, it was probably the best intro for my last 20 speeches for two years. Um, yeah, thanks everyone for coming. Yes, my background really is more than 14 years. It's not school and university it's real cases. So previously I have a background in uh building public infrastructure. So with cryptography itself postquantum grids I know about them even before it become a hype and actually yeah then we start doing hacken proof this August will be nine years of hack and proof and we actually have some something to share with you and I'm here to share because uh everything has changed so fast even yesterday if you go to security Twitter I would say like this yeah uh you can find like everyone is typing like oh one a good player or big player actually just disappear and announce that actually shut down. So even my presentation is already old. Yeah. So I made it really like one week ago but so many news. So okay I believe we can go. So first of all this is something that I see and what is happening with uh uh AI uh security and generally this security in a crypto because actually everyone is rely on the security and say oh my god AI is here who will protect us auditors and here Dimmitri saying yeah is killing crypto security so we also have problems let let us actually uh go uh is it correct to type it's not uh switching Okay, looks like working. So, whoa. Uh, just briefly, hacking improve actually trusted not only by web three players but web two. So, banks, institutional clients, uh, some um, airlines and etc., but actually good names that you know actually work with us currently, not in the past and etc. So, so we know actually what it is. uh also we work with bless exchanges we have already some numbers we top three in the world back bounty platform including web two we also actually have more than 70,000 researchers and we the biggest provider in the world for crypch exchanges so uh by this we solve everything I would say in security and u yeah so next uh I would like to to take a look what is changed for five years um in AI security. Yes. Um still okay. So what do you have from at the beginning? I remember in 2021 actually it was a stage where we tried to automate some stuff at the first time if you know Zappier yes I I like this actually project um it's not a financial advice but generally these guys actually did a cool stuff. So I was using Zapper to automate some stuff between application and it was like early adoption of what we currently use AI for. Then CH GPT moment but actually not everyone was using charge GP in 2022. Some of them started using in 2024. So it's like early stage when everyone was like oh my god something cool is coming. We will change this world for the better. AI will save the world and etc. And actually then we find AI inside of research. So previously when I was writing diploma yeah one day before I have to finish it I was actually in a books reading everything trying to find put some actually um reference nowadays those like people they can do everything just by second I don't know seconds minutes yeah you can actually do you know some you know actually yeah you can write a message and go for the coffee and actually what we have now we have a gentic systems. Now we're trying to understand like there is a human based AI, there is a gentic and we call another stuff of VI. So this actually making uh a next step. Let me just yeah to take a look at the vector of attacks. So generally in before 2025 yeah we know that someone accidentally was copy and paste code. Someone actually was drinking a beer and it fell down and data go somewhere. So it was like something accidentally might happen. Then hacker actually used code to plan attack. It was not easy as we know from entropic report but actually he actually attacked 17 companies. Then we have a Chinese state group where actually was exploited with cloud code. Yes. and targeted 30 plus entities. Then January 2026, solo hacker actually uh attack government and they actually steal more than 150 gigabyte of data and we don't know what will be next. So they right now take a look at this data but what will happen next? Um yesterday at panel discussion we actually heard from one of uh security expert that lately guy who actually was involved in drift attack. He was planning six months. Yes 6 months to make an an attack. So they actually invest some money into protocol. They actually become a trusted partner. They actually were like a friends and maybe planning some business together and then hope we have those attack. This is something that we still cannot understand what will happen after this stolen Mexican government data. Then we have lots of deep fake model. Everyone right now when we go to side event etc like do you know someone was trying to hack me by making a interview someone trying to uh pretend this is my friend for AI someone is helping. So fishing in deep stake is like very common popular and I believe everyone right now even don't calculate how many stuff we have for that and actually the biggest issue that when we currently take like decide to mention some hackers they can plan it the whole attack and beat into one hole. Yeah. while actually uh security defenders they try to protect everything. So uh let's go to next up. Okay, I would like to take a look at numbers. Uh just a moment. Yeah, here we are. So I mentioned here hacking report. Yes. uh they recently made the research for Q1 and I would like to mention that more than 30 accidents happened and the losses was 630 million yes and compared to Q12 it actually it's more than 200 percentage for for as a vector attack and you also can take a look that almost half is fishing and here you can think okay it's not only about smart contracts it's more about the operation and about efficient attack itself and of course two uh hacks as always or one attack can fully cover the whole damage. If you remember by bit yes everyone remember there was like winner of the year and unfortunately we have of course auditor protocols which is six of them from uh eight 18 audit audits and they also were exposed. So u this uh tell us that something is wrong and what is has to be changed with the AI and uh security. Yes. Uh moving forward. So I would specify here that first of all AI we have now three statements. So first of all, EI is uh right in vulnerability code at scale and we as crowdsource security uh provider we actually sometimes get requests for audits and we do those crowdsource security and then we get like 18 20 plus criticals only critical. So it might be around more than 200 vulnerabilities in one audit that actually can have around 3,000 lines of code. just image it's only 2,000 it's not like someone is coming say hey we have let's say the typical L1 might have around 40,000 lines of code yeah but this actually small code and everyone is trying to wipe code and etc write the smart contracts ask AI that it works and let's go uh shock number two actually EI is attacking because you also can see in the Twitter and et everyone like oh ask to earn $15 to me and he earned $15 to me. So currently this is the same human trying to predict vector of attack and then asking AI to to actually attack and um what we see uh in military. So I'm Ukrainian of course I very like interest in what is happening in military as well. So military try to actually also use EI a lot but also they considering to have restriction for AI. Yes. And uh so that is why some stuff that is part of military probably will stay private for many years and of course we know that and this is my topic I collapse traditional audience economics. So just to understand that around I would say 60 80 years um um tool uh is covering by u like as a yeah clients ask why actually we were paying 50k but now I can do for 500k um sorry $500 and actually uh all auditors like feeling the pressure of those EI for last two years. Uh also I would like to mention before I I will start doing saying about numbers and what is happening VCI um audits I would like to mention also two slides about bug bounties. So just to compare I I made also numbers for one of the biggest uh bug bounty providers in the world which is hacker one and they mention re recently that only for March they got three uh 30,000 um plus uh reports just imagine these numbers and also uh they also uh mentioned that compared to Q1 it was more than 800 percentage increase in um uh volume also for immunifi hacking proof. So we also known players on the market and we also can do statement that AI reports coming a lot. Uh, of course, um, here you can find, um, uh, Gregoro, um, this presentation was made a little bit early, but, uh, these numbers that you see 100,000 that he found critical and demonify. I would like to beat these numbers and specify that he got rewards from hacken proof for $250,000 for found EI actually uh, by by working with EI actually. Yeah, Gregory uh B in the protocol. So and around I guess this guy earned more than 1 million just a few months and also I would like to to specify some paradox that bounty platforms needs EI to generate EI and validate validate the reports. So just uh also from my oven example we have a community of hackers currently like in discord around 12,000 and they uh in discord they come and say hm you know the guy who was validating my report didn't reply me professionally to my report and I actually decided to check some replies and personal was like hello thanks for submitting reports I check it it's out of scope because of this line uh in the program and he like no it's not a professional reply then actually we took the same answer put into EI and ask it to reply a bigger stuff. He got like message I don't know like five six times bigger and he like I see now currently someone professionally reply me. So even hackers and people expects uh answer from AI more than from humans. Um also what I'd like to specify is about numbers in the hacken proof. uh key points that I mentioned about bug bounty that previously we had 2,000 reports per per year 7,000 per year and only for 2026 its number is just growing uh just go forward in May we already have more than these numbers just for last months and I would like to highlight this we try to prevent submitting reports EI and low base a lot uh if you take a look at players on the market they taking 20 u dollars they taking $200 just to let hacker to submit reports so paid submission right now not helping uh we also have reputation points if you actually didn't have any valid report before you might be not be able to submit to the company itself and still it's like growing a lot and um moving forward yeah my main question is about is are we going to replace auditors or not So about prediction market is growing. So you might feel that okay new projects not appear L2 is dying or something like this. Yeah. But to be honest we see that web 2 is moving to web three institutional clients are moving lots of stable coins. So market will grow. The the question is we during this period will be replaced. We we I mean like auditors. Yeah. uh are we going to be in another kind of positioning uh for the business or etc. And also what actually we see that uh uh nowadays matter for any big client is first of all architecture review formal verification security as operational discipline because even yesterday on the panel discussion we dis we were like thought that okay we have audits we have those we have those we have multistick well actually doesn't work so I would say yeah operationaliz this discipline is very uh important continuous monitoring and human expert judgments which is actually right now in bount we can move forward um so I would like to uh specify impact and risk so just to image that uh we have lot it's only for 2025 by the way we have EI auditors 50 plus on the market that I know personally and around 20 plus just uh listed it at hacken proof And uh AI makes a 20 times cheaper for sure vises in terms of numbers. Sometimes you can find even tools that saying hey if you have up to 200 lines of code or one 1,000 you can actually make it for free and then I also check some product even in web two you can come and they can generate you so um compatible final report and no human actually at all and then they come with this uh so two uh final report to some regulators and say okay now you can give me license cuz I s too uh compliant so no people there at all. I also would like to say that uh we have uh involvements of AI as you see a lot. Yeah. And actually at those time AI still cannot detect the whole patterns where code or infrastructure can be broken and also need there is a need for validation layer as a human or actually as a system. Okay, we can move forward on this and I would like to specify what we see and what we actually uh will see soon. So what happened in 2024 50 plus EI auditors dozens of company rise capital to build a new EI. Yes, we have a raise of UI at the moment. uh total venture investment in crypto security very was significant and business reality is actually most tools actually was moved to another uh sphere. Yeah. And also there was a battle vi tool. So previously if everyone is trying to earn money and selling EI and EI audits currently they're ready to give for free make a T post that some EI auditors is better than other AI auditors and then they cut employees who build these EI auditors because no money to support this EI auditor and also uh sometimes to support EI tool you need to pay more than for human in a in a company. uh and actually what we see what pattern we see so uh we trying to build EI tool actually one year ago to build EI tool was very expensive so just to compare it was around how a million to build EI tool that might cover mostly chains currently of course it's less and actually many um guys who built EI tool when it was ready they didn't know what to do that so they actually lost money by building EI tool Of course, if you're a CEO who was bug hunter, you actually um made a great uh product like Gregi, you can benefit from this tool for sure. And also I would like to say that many uh provider services they shut down. Just to just to uh give you a example, H finance uh Kodina uh they hold their businesses at all and they trying to involve companies by uh selling everything for free. Um it's their public statement. It's not my statement. And actually now we have a result of what we're doing. And still many providers give services for free to gain some names. But actually the reality they don't provide security uh for this company they try to involve companies actually to test their AI tool uh to actually to this business model we can move forward and um yes uh what we see uh my personal thoughts and actually of company we going to continue security coverage uh we going to see human and AI uh hybrid teams and we have this right now a lot uh book balance is still as one of uh continuous security layer. So if you take a look at any exchanges any product they do one final report and they actually don't uh uh do audit or smart contracts or pantasting etc. uh every time when they do changes. So that is why they just trying to cover one goal get compliant or get licensed from some regulators and operational security moving to code security a lot uh compliance the services we see right now uh also a lot Mica and other providers they will actually even be more specific on what they asking. So previously regulators could say you need vulnerability disclosure policy and that could be everything like just page on the website but currently they can specify you need a proof of reserve per two times per year okay let's move forward I have still some time I guess yes okay um also my favorite question who is winning right now so still white heads are winning this market to be honest um you can also take a look how We usually, you know what we say about losses? What we say? Oh, I lost my $10. Yeah, but actually maybe when I was losing $10, I prevent losing of 1K. And um uh give you an example. Let's say if you search in Google right now, unis swap, maybe the first link that you will see will be some ads promoted by some fishing website and if you connect your wallet, you will lose your money. Just an example. Yeah. And probably when you actually accidentally have a few wallets and when you connected to this website money was stolen only from one wallet you still have money on another wallet. So with white heads and the blackheads almost similar the same. So you actually had numbers of stolen and you have numbers of prevented uh attacks. Um generally this number is compared to two years and the white hats got 150 million rewards for preventing actually 10 billion um in numbers. Let's move forward and actually what we have as a perspective. Uh so we believe AI didn't kill crypto security generally but what we see uh that actually EI uh right now decreasing at least employees in security auditors and if you still see like good names or brands and say oh this good brand or like famous brand can do audits for me please check how many employees they have maybe it's only brand where only co is working and no more employees Because to cover security course right now is quite expensive and usually if a companies requested let's say for pentest uh for only web web for example $15,000 currently they can do it for5 $6,000 as it is how many minutes I have okay a lot great and actually yeah this is uh first thing another what I would like to specify about u uh stuff is that uh EI is killing process of uh uh like spec uh uh submitting reports. So about bug bounty for example what I see as a pattern and you can check link in Twitter many companies they move from hacker one from buck backout from eunify from hacken proof from many other players famous in the market because they say we don't want to deal with reports it's too much reports why we actually have to pay for reports I can buy cloud subscription for $200 and do the same but actually it's not the same uh first of all you will not run this cloud uh subscription or uh instance every day hackers actually do this every day and this I mean reports every day of course you don't like that you might get in 200 reports per day but still there are lots of tool like AI treasures and etc that can handle 100 reports per one hour this is something that for example hacken proof does and um uh also I would like to specify that Many companies who trying to find a good deal for AI uh um generated report to show to investors etc. They killing market itself because they did uh for $500 uh actually report they sent to investors then actually they got hacked because of other stuff they wasn't checked by EI just to understand EI cannot check everything can check what the owner of this tool connected to or how they actually u uh pro process the the vulnerability ility research uh and probably last slide from my side. So yeah just just see what is happening. So we actually right now cannot monet monetize EI tool. Uh so mostly AI tool currently is just brand recognition or vendors who have EI tool they try to get clients to their platforms or to their portfolio to search for issue by themsel by their AI tool and then if these players have a bug bounty trying to get these rewards from the clients. Second one, people who built EI tools including security auditors, they actually kill themselves in terms of business h because they spend a lot and now they rely on a next uh release of the clo or chart uh GPT and uh reality uh at actually we're not killing security or this as a market but we transform a lot and during this transformation we will see lots of hacks Because industry right now uh trying to get more and more AI stuff uh company is not ready. Uh employee who is working at company or were still working in company. They actually have lots of work because they need to deal with EI. They need to learn AI and they need to do automation and of course build something with EI. Um that's all. Thank you for your time and if you have any questions I would happy to reply. Um yeah have a good day.
