# Your AI Agent Is the New Insider | Galin Dimitrov, Superteam Ireland | ETHSofia 2026

- Channel: [ETHSofia](https://streameth.org/ethsofia)
- Date: 2026-10-06
- Duration: 17:59
- Topics: AI agents, AI security, Blockchain Week Bulgaria, Claude Code, Drift Protocol, ETHSofia, ETHSofia 2026, Ethereum, Galin Dimitrov, OPSEC, Superteam Ireland, Web3 security, crypto hacks, npm, private keys, supply chain attack, Science & Technology
- Watch: https://streameth.org/watch/yt-aHjswRb_biA
- YouTube: https://www.youtube.com/watch?v=aHjswRb_biA

## Description

Galin Dimitrov, cybersecurity engineer and founding member of Superteam Ireland, traces four eras of crypto theft: scams such as OneCoin and BitConnect, smart contract exploits like The DAO and Wormhole, attacks on people as in Ronin and Bybit, and now AI coding agents. He walks through the Drift Protocol hack, which began with a fake trading firm approaching the team at a conference and ended six months later with $285 million drained in minutes. He then shows how malicious skills, poisoned npm packages and hijacked agent CLIs reach builders' keys, citing Anthropic's figure that users approve 93% of permission prompts, and closes with three rules: keep keys out of reach, treat every add-on as a stranger, and use a sandbox.

Keynote at ETHSofia 2026, 24 September 2026, Sofia Tech Park, Sofia. Part of Blockchain Week Bulgaria 2026.

Speaker

▸ Galin Dimitrov, Cybersecurity Engineer & Web3 Growth Lead, Founding Member, Superteam Ireland
Galin Dimitrov is a cybersecurity engineer with a BSc in Cyber Security and Digital Forensics from TU Dublin and six years at Fidelity Investments, where he secured and monitored 800+ production database servers and led Splunk-based incident response. He has also spent over a decade leading Web3 growth across agencies, Master Ventures and HYPE Partners, and is a founding member of Superteam Ireland. Today he builds AI and onchain products as a solo founder and has won several hackathons, including the Solana Privacy Hackathon.
LinkedIn: https://www.linkedin.com/in/galindimitrovvv

Chapters
00:00 The new insider, hidden in plain sight
01:30 Four eras of getting robbed in crypto
02:52 Era one: the scam is the product
04:20 Era two: attacking the code
05:32 Era three: targeting people (Ronin, Bybit)
06:43 Case study: the Drift Protocol hack
09:47 Era four: AI agents on your machine
11:23 Why 93% of prompts get approved
12:36 Three doors in: skills, npm and your agent CLI
14:14 Already happening: real losses
15:20 Three OPSEC rules for builders
17:10 Closing: read before you approve
17:44 Closing titles

Blockchain Week Bulgaria: https://www.blockchainweek.bg
ETHSofia: https://www.ethsofia.com
Future Finance Forum: https://www.blockchainweek.bg/f3

Follow Blockchain Week Bulgaria
X: https://x.com/BWBulgaria
LinkedIn: https://www.linkedin.com/company/blockchain-week-bulgaria

Follow ETHSofia
X: https://x.com/EthSofiaBG
LinkedIn: https://www.linkedin.com/company/ethsofia
Telegram: https://t.me/+b-33LJUpAB5iODNk

Nothing in this video is financial advice.

About the organiser
Blockchain Week Bulgaria, ETHSofia and the Future Finance Forum are organised by the Bithope Foundation, founded in 2014 by Vladislav Dramaliev. Inspired by Andreas Antonopoulos, it is Europe's first non-profit operating exclusively with bitcoin donations. Over more than ten years, it has supported 50+ charitable campaigns, and in January 2016 it co-founded the Sofia Crypto Meetup, now the region's longest-running monthly crypto event.
https://bithope.org

## Transcript

[music] &gt;&gt; Yes, so hello everyone. My name is Galin. And as they already introduced me, I am a cybersecurity engineer and I've also worked in a lot of the web three growth in the blockchain space. What I want to speak to you today is something that has caught my attention after participating and winning multiple hackathons. And this is something what is not that obvious. It's something that is hidden. We call it the new insider. And that new insider is hidden in plain sight. So, what I want to show you first is I want to quick raise of hands of people that have used uh OpenAI's Codex or Cloud Code. Just so I can see who is building. Very good. That's a lot of you. And when you're building, have you ever clicked approve without actually reading what you're approving? Okay, that's a good amount. And this is where the problem lies. Just because uh this insider it never gets tired, it never sleeps, and it actually has access to your entire machine, your entire computer. So, I want to introduce you first to how everything happened back in time in the web three space and how I've structured it into four eras of you getting robbed in the crypto space. So, the first era is the trust me, bro guys, which is we are all familiar with the for example, OneCoin, BitConnect. And this is where the attackers actually needed believers, somebody to believe in them instead of trusting a code for example, which brings me to the second era, trust the code. The attacker needed one book to gain access to your machine and then do whatever they wish to do after that. Trust the people. This is where you have a one insider, one leak, a person usually 99% of the hacks happen because of a person clicking when they're not supposed to click. And the new era where the AI agents are gaining access to your machine and downloading scripts, doing some malicious attempts. That is happening very quickly and it only requires one click from you, which you click to approve. So, I want to go deeper a little bit into each of these eras. The first era, as I mentioned, was where the scam was the product. So, you have a product, you don't even need a blockchain. In OneCoin's example, they managed to steal over $4 billion and and we actually managed to get to the top 10 in FBI's most wanted list. And there was no blockchain to verify it. So, it was just yeah, basically trust me and I'm going to make sure that you're going to earn more money than Bitcoin for example. That brings me to the second one, BitConnect. For those of you who haven't heard it, it was a type of a lending platform where people would deposit their money and they're going to earn a daily interest. And the daily interest was slightly crazy. It was between 1 to 3% a day. And this was the promise. The way that the attackers, the scammers made money was by paying the old investors with new investors and most of you know this as a Ponzi scheme or a pyramid scheme. That was 2016. That's more or less when I was first going much deeper into the crypto space. I was personally involved with it and it reached I think number four as the biggest currency in the world and even if it was number four that doesn't mean they're not going to scam you. The second era when they went after the code. So after they stopped trusting the bros they wanted to gain access to the code and that's what they did. A couple of examples I have here the Dow in 2016 where a reentrancy bug managed to split Ethereum to Ethereum and Ethereum Classic. And we have also Wormhole 2022 a signature verification flow as well managed to get access. So what the industry did for that is they wanted to protect against the code. So they started creating a lot of things to defend against that. So a lot of audits we have here a few companies that are already and keep on doing this because this is the easiest way to protect the code formal verifications, big bug bounties a lot of monitoring processes and procedures in order to avoid all of these issues that are happening. So the code got much harder to break. So what did the attackers do? They decided to change the target. So instead of targeting the code they started targeting the people. And how do they target them? They basically invite themselves into the platform. How does that happen? We have an example with Ronin. What happened with Ronin is in 2022, the attacker targeted an engineer. They targeted by inserting a malicious code into a PDF file, and that PDF file was disguised as a job offer. So, the engineer decided to just have a quick look, click on the PDF, and the code automatically fires on the back end. You don't even see anything, and just like this, your machine is already infected. Bybit, something similar where um developer's machine uh safe wallet was compromised. We have uh the signers approved the transactions that look like a routine transaction, but at same time, it had a hidden one inside of it. Just because they didn't look through every single transaction. They're just clicking approve and keep on going [snorts] with that. So, how one of these attacks happens, for example, uh one of the most recent ones is the Drift Protocol hack. Some of you has probably heard it, where I'm going to go through the stages of how exactly it happened, but initially it started with a basic DM. The attackers hired actors, and they sent these actors to uh crypto conference. These actors, pretending to be uh a quant trading firm, they said to the Drift Protocol, "Hey guys, we want to implement ourselves with you. And uh how can we do this? This is our uh repo. This is our vault. Can you please have a look at it? Let us know if everything is good." So, the engineer or whoever was responsible in there did that and that secretly hide a malicious code in the uh engineer's computer. But, that malicious code didn't execute straight away. It took about 6 months for the entire hack to happen. And what did they do? As I said, they approached Drift Protocol with a big conference similar to this one. They sent those actors. They introduced themselves. Everything was looking legit. Everything was looking perfect. And once they did that, they started gaining the trust of Drift Protocol. They started meeting them in different countries. They started going on a meetings and at the same time to gain even more their trust, they invested $1 million and deposited and deposited it into the Drift Protocol's vault. It's interesting because uh once they did that, they managed to get access to the tools and to the repos for Drift Protocol. They had that hidden script in the engineer's computer. And [snorts] once they had all of the information and all of the gathering of documents and everything that they needed, uh they decided to uh go ahead and run the attack. The attack happened on the 1st of April. Joking or not, that's when they announced um that the hack is currently happening. Uh this is not a joke. It's not an April's Fool joke and we've been hacked. A lot of companies that were building on top of uh Drift Protocol kind of had to close down. Some friends of mine as well that I know from different companies. And yeah, the whole idea is that it took them 6 months and on the end for only 12 minutes they managed managed to drain the protocol 285 million. So, as I said, it started with a basic handshake at a conference just like this one. So, we need to be always always careful. So, coming back to the new era. What is happening now with the agents? The agent does everything quite kick quickly on your laptop. You click on approve, the agent starts downloading some packages, it starts installing some stuff on your end, and this is where the hack happens. There was actually uh a very big hack recently that happened where uh normal general dependency that every single person installs automatically, that was already infected with a malicious code. And it's strange, it's weird, but apparently these things happen even today. So, you have a couple of options. You can spend 20 minutes to review the code, to review what is being requested to be approved. In these cases, the malicious code got in a couple of uh a couple of places. One of them is the skills.md. This is where when you train your AI agent, you train it to be very smart, to be able to do presentations, to be able to uh code on Rust, whatever that is. And in these skills, there is a possibility that there is a hidden code. And this is what happened with many skills, especially in the start. Or the second option is just click approve and go with it. So, guess what which one wins? Most of the people here and everywhere on the planet, they just click approve. 93% actually um the Anthropic engineering team said that the more approvals the AI agent uh is requesting you to do, the more you get frustrated and the more you just keep on clicking approve. And you get to a stage where you don't only quickly click click approve click approve, but you also just set up the option to auto approve everything. So, every single kill that comes, let's go with it. Every single hack, every single malicious code, every book, you just go ahead and install it on your laptop. So, it is something that everybody should be very aware of because everything that you have on your PC will potentially be hacked and exposed. If you have saved passwords, if you have credit card details, these are the basic things that very easily could be exploited. So, three doors in. I mentioned one of them is the skills document where uh you have a marketplace with different types of skills and attackers just create those skills and say this is the best skill, this is going to improve your agent so much, it's going to let your agent learn by himself, from himself, from other places, and the skill is amazing. But inside this skill, there is a simple code that just takes over everything. &gt;&gt; [snorts] &gt;&gt; The NPM package, NPM install, that's what everybody does, you have to do it. But at the same time, uh we had an example with uh master packages that were poisoned for 45 minutes. And everybody that did NPM install actually installed the malicious code on their laptop, physical machine. It could be in the cloud. It doesn't matter. You just go with it. And then the agent uh you you're on CLI. This is an example where uh the malware used your own actual AI agent, your own cloud code, or Gemini to hunt specific wallets and secrets that you have saved on your computer, on your local machine. If you have multiple projects on the machine, the script just runs in the back end, goes to your environment file, and downloads all the information. So, if you have multiple subscriptions for those environmental uh files that you need, that's all exposed. &gt;&gt; [snorts] &gt;&gt; So, this is not something that uh is going to happen in the future. This is something that's already happening and has happened. We have an actual engineer, blockchain developer, who lost half a million dollars by installing a very simple uh a very simple, sorry, extension. It was an extension, Solidity extension. He installed the extension, and inside of that extension there was a hack. Uh Prompt Mining, we have uh North Korea. North Korea has been I can probably move a little bit so you can see some of the things. North North Korea has managed to steal a lot of information, a lot of funds. They keep on doing it. And uh Prompt Mining was one of their inventions. So, where I'm getting now at the moment is you need to implement three rules for yourself to protect yourself against that. And these three rules, I've said here start on Monday, but you should start immediately. Don't wait for Monday. So, most important thing is keep your keys out of reach. What does that mean? Of course, if you if you have the possibility use a hardware wallet or just a separate signer. 2FAs. No private keys in the NV file. It's very important just because a lot of people want to do it the easy way, so they put all the keys everywhere. And yeah. Every add-on, treat every single add-on as a stranger. What does that mean? Don't just out to download uh everything that is available there. Make [snorts] sure that those keys and the scripts they you have you can read them first. It's very simple. It takes a little bit of time, but read the keys. Don't install them automatically and cancel your auto updates because a simple auto update can download a new script that has a malicious code as well. And use a sandbox, of course. Everybody who uses it on your own machine is potentially going to be uh hacked. So, these are the most important things that I can say. They're very easy to implement. They're very easy to follow. So, make sure you don't get hacked. As I said a little bit earlier, One Coin asks you to trust a company drifts attack ask for a handshake on a conference and your agent is only asking you one thing. Will you click approve without reading it? So, the most important thing is read it first because once it's on chain, there is no undo button. Thank you. &gt;&gt; [applause] [music]
