New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Coinbase | How Coinbase does Security - Eric Meng | ETHDam III - 2025

CryptoCanalTue, Oct 7, 2025, 12:00 AM

Welcome to the 3rd Edition of ETHDam, hosted May 9–11, 2025 in Amsterdam. This year, we brought together the brightest minds in privacy, security, and AI for a unique 48-hour hackathon + conference combo. 🌷 https://www.ethdam.com// 🌷 ------------------ Coinbase | How Coinbase does Security - Eric Meng | ETHDam III - 2025 𝕏 Follow: http://coinbase.com/ https://x.com/coinbase ------------------ About ETHDam & CryptoCanal ETHDam is powered by CryptoCanal, an education and events platform rooted in Amsterdam, expanding into Rotterdam and Zürich. Keep up with us to see updates on future events: https://www.cryptocanal.org/ Follow CryptoCanal on X: https://twitter.com/CryptoCanal Join CryptoCanal TG Community: https://t.me/CryptoCanalCommunity Join CryptoCanal Discord: https://discord.com/invite/XJVjpCqQBz CryptoCanal unites crypto enthusiasts committed to making a positive impact. Unapologetically political, we prioritize education, events, and services while championing cypherpunk values like privacy, sovereignty, and censorship resistance. ------------------ 🎥 Credits: Intro / outro by babyPRO - https://babypro.art/ ETHDam Photography by Paulus – https://concretestate.eu/ MC of ETHDam - James Campbell - he builds decentralized, end-to-end encrypted, privacy tools. Come and say hello on Farcaster https://farcaster.xyz/theref ------------------ Special thanks to our partners who made ETHDam possible: 🌹 Hackathon – Bouquet: Oasis Network https://oasisprotocol.org/ 🌷 Hackathon – Petal: Circles https://aboutcircles.com 💛 Conference – Gold: Zano https://zano.org/ Dash https://www.dash.org/ Bitvavo https://bitvavo.com/en 🩶 Conference – Silver: Igra Labs https://igralabs.com/hero 💛 Conference – Copper: Lido https://lido.fi/ DeTrip https://detrip.travel/ Cake Wallet https://cakewallet.com/ The Grid https://thegrid.id/ Calimero Network https://calimero.network/ 0xbow https://0xbow.io/ Mina https://minaprotocol.com/ JobStash https://jobstash.xyz/ Cyber Capital https://www.cyber.capital/ POAP https://poap.xyz/ Acronym Foundation (Supported our Top 10 Hackers) https://acronymfoundation.org/ 🌱 Sponsor: EF Ecosystem Support Program https://esp.ethereum.foundation ------------------ 00:00 Welcome 00:36 Coinbase Security Team Structure 01:53 Withdrawal Flow & Security Layers 03:25 Cold Storage & Key Management 05:26 Asset Listing & Custody Assurance 06:03 Base Protocol & Sequencer Decentralization 07:58 Smart Contract Auditing & CI/CD Pipeline 09:48 Key Management & Monitoring Practices 11:53 Ecosystem Risk Monitoring & Hexagate 13:28 Externalizing Security & Privacy Goals

Transcript

Welcome to East to E to E to E to E. Okay, next up we have Eric Mang with How Coinbase does security. Thank you very much. Awesome. Sweet.

Well, thank you guys for joining me this morning especially in beautiful Amsterdam. I'm always told it's raining here, but uh thankfully we have a beautiful week and uh thank you guys for your time and learning how we do web3 security at Coinbase. My name is Eric. I'm a blockchain security engineer on our security team and our main purpose is to secure the entire stack of where crypto lives at Coinbase. And outside of crypto, I still do crypto.

I I am a DID gen at heart. I love strategic card games, especially Magic the Gathering. Shout out to any commander players here and I love spending time with my wife and daughter. I think they will be here's an overview of the subjects that I'll be talking about today in the next 15 minutes. My hope hope and goal is that you guys get a really good understanding and behind the scenes look at how our security team works as well as the details of what we look at.

Here's a top down or uh overview of our entire security organization. I know there's a lot of names and teams here that do a lot of different things. Obviously don't have time for that today. And what I want to focus your attention on is that blue path right there, which covers down to those last two teams there, which is our decentralized financial and protocol security teams. These are their main two security teams that touch anything and review anything that is related to crypto and blockchain networks.

And obviously we are a cryptocurrency exchange, a developer platform, and a layer 2. And that means we're really good at three things at the digital bank level. That's receiving with uh sending and storing crypto. And I want to give you guys an overview of how that looks and where security fits in by walking through what a withdrawal flow looks like. So, say you have 50 USDC in your Coinbase account and you want to withdraw that to your web3 wallet on base so that you can do whatever you want on there, most likely trading meme coins.

And you hit that send now button. Well, what happens after that is now we place a lock on your account. Your account lives on this ledger layer. This ledger layer is internally in our systems as this database mapping of all the assets that you own to your account. From that ledger layer, we now move into the key management layer where we now prime our outbound hot wallets ready to send your funds.

And that keyword being the hot wallets, right? It's always connected online and you know is vulnerable to anything that may compromise those keys and send that money out. So that way because of that we only keep a limited amount of liquidity on there and if we need to replenish that liquidity we replenish those from our cold storage. What's really important to know about our cold storage is the fact that these are geographically distributed highly secure vaults. Any transactions that come out of here are have to go through many approval processes and we have transaction integrity and verify everything and every single transaction that that comes out of there.

From there we move on to the wallet interface layer. Now we call this the wallet interface layer because we cryptographically segregate the signing services themselves from the actual storage of the crypto as well. That way we have full control over exact the exact flows that happen within our systems. And from there we broadcast those instructions to our node and then your transaction will land onto the base network and then your account gets debited that 50 USDC. Now, every single jump here that you're seeing has multiple threats, multiple attack vectors, and obviously our teams have multiple processes in place to make sure that they're safe from those threats as well.

It's secure by design and we've been doing this for over a decade and you know this is this is what makes us really really strong as a digital bank. Now, the last thing I didn't cover was the asset addition piece. How do we know that USDC on base is secure for our customers to even trade in the first place? Well, all of our assets go through an incredibly rigorous listings process. This doesn't just involve security, but also involves compliance and legal reviews as well.

This makes sure that any single any single asset that lands on our exchange is safe for our customers to custody. And that is that key concept right there, custody. That's the ability to again send, withdraw, and store your crypto. We want to make sure that any customer that buys crypto on our exchange never has their custody violated. That means that you will always keep your crypto on our exchange.

And some examples of this may be burn or blacklisting features within smart contracts like USDC. And while there may be valid use cases for that, we still work with these asset issuers to make sure when they action these items as well as how they store their own private keys as well. Um, and we even actually ask for sock 2 audits, verified sock 2 audits from uh, reputable third parties. And then that last piece right there, we actually look at the underlying architecture as well. Let's say that it's a different L2 that the USDC is on, for example, arbitrum or optimism.

We actually look at that EVM execution layer to make sure that 1 plus 1 actually equals two at the EVM level. And then lastly, once all of that's validated, we help our crypto engineering team with that secure integration of those assets. And then finally, our customers can trade it on exchange. And now I want to get into the heart of our onchain operations with the base protocol. We operate one of the fastest and cheapest L2s in the entire ecosystem.

And what makes it particularly so powerful is the fact that security is baked in as a public good at the very start. And what better way to describe this than to go through the stages of decentralization. Some of you may have heard the morning panel about sequencers. Well, for those of you that haven't, the sequencer is the centralized node that controls all of BAS's execution. It controls which transactions land on chain as well as the ordering of those transactions.

A very powerful role. Obviously, Coinbase controls this. Our goal is to decentralize this over time. First is stage zero and these stages are defined by Vitalik's paper and by L2B more specifically using Vitalik's paper. And with stage zero, you have the introduction of a fault proof.

What is a fault? It's a very technical term for a sort of dispute game in which anyone is able to challenge the state of of the network of this of of the L2. Let's for example, if someone withdraws more from the bridge, then they actually post on the L1, someone can challenge that. And if you win that challenge, you get a reward. That creates a natural ecosystem of bounty hunters as well as people that are monitoring to make sure that the state of the chain is correct.

And then we move on to stage one. This is where we're currently at right now. We literally just released this last week. And in addition to fault proofs, we now have the added security council. And this is a distinct set of separate and unique stakeholders that control all of any smart contract upgrades on L2 and L1.

And then finally with stage two, we complete that decentralization cycle in which there's multiple fault proving mechanisms as well as having more stringent upgrading criteria. And then now going a layer deeper, you guys are probably wondering, well, how do we audit our smart contracts? Some of our onchain products you guys might be familiar with are CB ETH, CBTC as well as our smart wallet that was released last year. All of them go through an another incredibly rigorous CI/CD pipeline. within that pipeline is automated analysis at that um using Slither and at that at that smart contract level catching those lowhanging fruits and then we go into manual analysis using our internal auditing team.

Now that key piece being the manual analysis, right? Because still our researchers and auditors are stronger than any tools that are out there right now. We have 100% code coverage which means that we look at every single line of code and we also just recently started implementing formal verification as well as fuzzing and that means that we can actually validate all the execution paths and the state of the contract as well. After the internal auditing we'll begin the external audits. We pay top dollar for getting the best security researchers out there to also look at these contracts as well.

Sometimes they'll find additional critical highle bugs that we're glad that they caught. And we'll even sometimes also open it up to the public using code arena and other time box competitions where you guys could even compete and win additional rewards as well if you find any any bugs at all. It could be low, could be critical. It doesn't have to just be high and criticals. And then finally, we deploy that smart contract on chain.

And security doesn't stop right there. We still do a lot of key management as well as monitoring and that key management piece being really important here because in case there is something that goes wrong or there is a security event that happens on base we have specific rigorous processes in place that make sure that okay well let's say we need to pause a smart contract who's actuallying those keys who who gets to be in charge of that workflow what is the entire process from triaging to when we execute that transaction on chain we have strict runbooks in place to do so. And then finally touching on that monitoring piece, I it's hard to overstate how important monitoring is. And the main reason being we need to make sure that all the risks that we've identified and mitigated and built security solutions for stay at those safe levels. But you may be wondering, what do we monitor for?

Instead of creating another diagram going through all the different flows, this is really the best I could do to summarize everything. We we really do look at everything. We we have monitoring systems in place that look at everything that's onchain as well as offchain. However, if you were to twist my arm and I had to identify three things here, it would be these. The blockchain systems ecosystem as a whole and then obviously our smart contracts.

The goal of the blockchain systems is to make sure that any nodes, any network that we support on our exchange on our platforms get secure updates as well as following what is the real state of the chain and following that canonical state being a really key piece there because again we do deposits and withdrawals. What happens if there's a chain reorg? What happens if we get double spent? We need to know exactly where that money is at all times. And then with the ecosystem, we want to make sure we're staying ahead of all the tactics.

We want to make sure we know and understand what are the trending threats, how are customers getting fished, how are our customers being at risk when they connect their web3 wallet onto base, what is out there, what are the current campaigns going on. We look at that as well. And then finally at that smart contract level like I was saying in the previous slides we look at the execution as well as anytime a function that could be risky gets invoked specifically invariance that we call out from our threat models. Invariance being things that must remain true at all times. And it doesn't just have to be for our smart contracts that we deploy.

This also includes the ecosystem level smart contracts. For instance, the entry point smart contract that does all of the account abstraction on base. We're monitoring that. And then I just want to also plug in here that that we do have free monitoring for our builders with Hexagate. So if you do build on base, you do have that level of smart contract monitoring as well.

And then finally, security isn't just something that we do in house. This is something that we've been trying to externalize for years and trying to set the industry standards for what is safe. We do so through multiple avenues. First one being the fact that we publish a lot of blogs. Sometimes these blogs get really technical.

Other times, you know, they they they remain at the high levels, but we just published last week that we reach that stage when decentralization for Bass. So, if you guys want to read more about that, go to the base mirror.xyz. And then we often also publish our own audits as well. So, you'll find them in the GitHub or you'll find it in another blog.

And in these audits, we get fairly technical. We reproduce the proof of concepts that show the critical vulnerability that we caught as well as allowing our readers to build it themselves and recreate themselves and simulate it. We also operate one of the top bug bounty programs in Hacker 1 with over $2 million paid out to date. Thank you to our hackers for for keeping our ecosystem secure. And then finally, we're at a privacy conference.

Can't talk about what we're doing for privacy here. can't not talk about what we're doing for privacy. And recently we've just acquired the Ironfish team, not the blockchain, the team with the goal of making Bass a more privacy featured network as well. And that way anyone can use it freely with with guarantees with stronger privacy guarantees specifically. And with that, that wraps up the presentation here.

We are hiring. There are open roles. Please go to coinbase.com/careers to take a look. It doesn't just have to be security.

But if you are interested in joining our security team, please come talk to me afterwards or find me throughout the conference. I will be here uh throughout this the entire set of three days as well. Any questions? Yes. Why?

Hold on. So the sequencer uh will uh be um a liability. Um um why not become a based rollup so that you use Ethereum mainet as a sequencer. Right. I mean that's a great question.

Unfortunately I can't talk about what our base team is doing in that terms of direction. So I'm going to have to defer that one for later on. There there may be future announcements regarding that. Okay. Thanks.

in um thank you. In your previous slide, you mentioned that there were some privacy features coming to the to the rollup. Yes. Um can you maybe talk a little bit more about how those look or is it the same answer? It's the same answer.

Yeah. Unfortunately, I'm not part of that team that's deciding on what they're doing there, but that is a public announcement that that we did acquire the Ironfish team themselves. I don't know what specifically they're they're planning on building. However, I do know that the overall goal is to make Bass a more privacy featured network. I get it.

Thank you. Mhm. One last one. As far as you can tell, like what are you doing more thoroughly or differently than bybit? Then are you you specifically talking about the bybit hack?

Okay, sure. I mean I'm assuming that you are kind of strategies but you are doing something more like what would be your best guess that you are different I mean at least from a security perspective I can tell you that we don't have smart contract signers in any of our signing flow like we don't do any sort of like like for instance the bybit hack had the safe frontend compromise as well as they they use multi-IGs as well Um, we again going back to that that slide about our cold storage and stuff like that. We have very very tight procedures around how funds flow in and out of there. And it's different from what I understand from Bybit for sure because those signings services and all that stuff, they're secure from the start because of the way it's designed, not because of, you know, the way by does it, which is they have like all those different layers of of these third parties integrated in there. We're very very intense about what dependencies and third parties are are within our systems.

But is that safe at the core? No. No, it's not. It's different from safe. Yeah, it's different from safe.

Amazing. Thank you very much. Awesome. Thank you guys.

Automatic transcript — names and jargon may be misspelled.