New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Cyber, Fraud and the Future of Financial Resilience | EBC12

European Blockchain ConventionTue, Oct 6, 2026, 12:00 AM

Panel: Cyber, Fraud and the Future of Financial Resilience Speakers: - Otilia Pețu | NOA Group - Ilya Brovin | Sumsub - Harry Donnelly | Circuit - Mitchell Amador | Immunefi 🚀 Next stop: DAFNY – Digital Assets Forum New York - November 13th, 2026 https://eblockchainconvention.com/digital-assets-forum-new-york/ Connect with us: European Blockchain Convention - X (Twitter): https://x.com/EBlockchainCon - LinkedIn: https://www.linkedin.com/company/european-blockchain-convention - Telegram: https://t.me/EuropeanBlockchainConvention/1 Digital Assets Forum - X (Twitter): https://x.com/DAF_Global - LinkedIn: https://www.linkedin.com/company/digital-assets-forum/

Transcript

So, I have to admit that I am the only woman on this stage. So I warn you stage. So I warn you : expect me to ask questions that no one is thinking about or that you don't feel like answering. Um, good morning everyone. First of all, thank you for being with us.

My name is Otilia, and I will be the moderator of this panel. Um, let me start by saying that I'm not a cybersecurity expert. I am an advisor and strategic consultant. So we are lucky to have three specialists here. My role is to ask the questions that a CEO, board member, or investor would ask if they wanted to invest, understand the risks, and especially how much it costs.

So first of all, I would like each of you to introduce yourself for 1-2 minutes, telling us what you do and what your company does. Let's start, choose for yourself. Of course, I can start first. Hello, my name is Ilya. I am the Development Director at Sumsub.

At Sumsub, we focus primarily on compliance and fraud prevention. That is, KYC, KYB, transaction monitoring, fraud prevention, crypto, travel rule—this is actually a comprehensive platform comprehensive platform . We serve 4,000 clients worldwide, including nine of the 10 largest crypto exchanges. You know crypto exchanges. You know , wallets, fiat gateways, and all that stuff gateways, and all that stuff .

And it's probably worth noting that one of our biggest initiatives right now is to make identity reusable, composable, and programmable across the web. Hi, my name is Harry. I am the founder and CEO of Circuit. Circuit is in the business of disaster recovery and operational risk, so we focus on all causes of loss of funds due to operational risk, such as operational risk, such as hacker attacks, disasters, lost keys, and the like. We work with many different insurance companies.

Lloyd's of London has supported us, and we are trying to make this space much safer and prevent users from losing funds users from losing funds . Hi, I'm Mitchell Amador. I am the founder and CEO of Immunify. We are the largest crowdsourced security platform in the cryptosphere, and that means we have an army of hackers around the world responsible for your security from hostile hackers, North Koreans, and all sorts of attackers trying to rob you at any moment. The vast majority of on-chain finance partners with us in some form or another to protect their code, although it is never enough, as my colleagues can attest.

So, that's what we're doing, and so far so good. Thank you all. I'll start with Harry in the middle. So, Harry, Sergey mentioned an estimated $500 billion in permanent digital asset losses across the industry. My question to you is: in your opinion, how much of this could have actually been prevented in advance, and how much in advance, and how much could have only been tried to be reversed afterwards?

Yes. This $500 billion goes back to the very beginning and includes not only hacker attacks, but also funds lost due to people losing or forgetting their private keys . And this is huge money. People believe that approximately 1/5 of the total number of Bitcoins has completely disappeared and is inaccessible. Over time, we saw that when people understood where the biggest risk factor came from—if you lose your private key, you lose all your funds—they said, "Let's build better key management."

"Let's create custodial services custodial services ." And then, as other types of risks arose, other types of solutions emerged. So, we saw monitoring platforms, key recovery platforms, and automated response platforms. So we're developing better and better solutions to stop things like this, but a lot of things you only learn after the fact. We are currently seeing very interesting, somewhat crazy hacker attacks.

People come up to you at conferences, shake your hand, say hello, and then steal all your funds. Social engineering is becoming an increasingly important factor. We are seeing fewer hacks related to smart related to smart contracts, but more and more cases of people acting off-chain. The Buyback hack is a great example of how they hack a developer's computer and then use it to gain access to funds later. So we see that many problems are solved only retrospectively, but ideally after that it will be impossible to repeat them.

Thank you. I'll give the floor to Mitchell. You argued that paying hackers millions for finding vulnerabilities could prevent billions in losses. For a founder deciding where to direct a limited security budget, how do you view the split between bug bounty programs and traditional approaches like audits, in-house teams, and monitoring tools? Of course.

OK. For context: Immunify has paid out the largest bounties for detecting vulnerabilities on the internet, period. Of course? More than anything in Web 2, more than the entire traditional internet. And this, of course, applies not only to blockchain and smart contracts, but also to web vulnerabilities, which we also work with.

Why do we do this? Because the profile of attacks and risks we have in the cryptosphere is much more serious than more serious than anywhere else. As our colleagues just noted, there are so many ways to become a victim of robbery. It's, you know, an infinite number of ways that people can steal cryptocurrency steal cryptocurrency . These are excellent bearer assets; A single hack that can steal a dollar can just as easily steal a billion if you are unfortunately vulnerable vulnerable and those funds are stored in your vault.

So, that's the basis for this question. Now, regarding these tools, I think it's worth considering that we are currently in the era of a true " vulnerability apocalypse." Virtually every attacker in the world has access to advanced large language models that possess combined, albeit somewhat outdated, knowledge of various attack vectors: websites, servers, authentication systems, smart contracts— smart contracts— of course, everything. So there has never been a more challenging time to protect critical infrastructure. As developers of critical tools for your customers, you can no longer rely on thinking, “Oh, we can probably spend more than most attackers most attackers .

” This is not true. You know, some North Korean hacking group, and there are quite a few of them, as well as from many other countries, can afford to invest significant capital in trying to hack your system today. So, this is the reality So, this is the reality . Of all these methods, the one that I think has proven effective in the cryptosphere is crowdsourced security, specifically bug bounty programs. This works both before and after the project is deployed.

After deployment, After deployment, this is the traditional bug bounty model. Pre- deployment is about taking various crowdsourced security solutions and integrating them into your development processes. This could be an audit or a code audit competition. It could also look like the involvement of a group of hackers or automated systems. Increasingly, we are seeing the introduction of specialized LLM specialized LLM tools for finding vulnerabilities into the development pipeline, which your programmers use themselves before releasing the code.

And the return on investment in this is investment in this is phenomenal. It's better than anything else you could use. Let me set the context: In the past, the security benchmark or best practice was, "Let's spend more on defense than the enemy." Or "let's make the cost of hacking so high that they can't overcome the system," but now the bar has been raised to the point where you are required to find all vulnerabilities before you send the product to production. And crowdsourcing security solutions allow you to do just that.

So, when thinking about budget allocation, I would say: if you don't direct the bulk of the funds to such "white hat" solutions before and after the system is deployed. I'm not saying just pay out huge rewards at the end of the process. I also say invest upfront, before launching anything in your development pipeline, and do it at scale as much as possible. If you don't make these investments upfront, there's a high chance you'll be broke within the next few years, as we're seeing with large companies around the world right now. No pressure.

We discussed the budget and incentives. So I turn to Ilya on the human aspect, as Sumsub's own report on identity fraud showed how perfect synthetic identities have become at passing verification because they generally look real. So as a development person, when your product has to choose between faster approval from a legitimate customer or exposing one of these more convincing fakes, where do you personally think that line should be? Well, the first good thing is that we at Sumsub aren't the ones who actually make the decisions, right? Ultimately, our clients configure the system the way they want: either to be as secure as possible as secure as possible , but with lower conversion, or perhaps they want to optimize conversion and attract as many users as possible.

You know, our job is to our job is to give them the best tools to make that decision. But I think the broader issue, kind of the background to this question, is that technology really does provide a lot of advantages and a lot of tools for hackers in terms of security, as well as impersonation and identity fraud. And it will never provide 100% provide 100% protection, right? It is a constant struggle against these well- resourced and highly motivated individuals and groups. It's a constant tug of war war .

They try to implement some technology, you try to detect it and adapt as quickly as possible. So really you're just trying to be, you know, as good and as fast as possible, and that requires certain things. You need data, you need a flow of information. You need human verification and, of course, artificial intelligence models. So we do all of this.

But I think fundamentally we're seeing a shift from the kind of document-based identity verification that's been around on the internet for 10-12 years, to much more digital systems, to multiple-factor authentication, which is more secure. Most often, they are provided by trusted centralized parties, whether it be the government or some other recognized method. And I think that over time, the identification will shift in this direction. So that we don't have to rely on them anymore, you know. So let me check if I understood correctly.

You mentioned AI, and that was my second question. As AI makes identity fraud cheaper identity fraud cheaper , are we moving towards a situation where proving a person’s reality becomes more difficult and expensive than proving the legitimacy of a transaction? Well, it's not one or the other, right? Therefore, you must first allow someone into your system for transactions, and then also monitor those transactions. Actually, there is another point: one of our philosophies over the last 5 years in product creation product creation is end-to-end platform.

Because it 's not enough to just know at the initial stage who this person is, because you may think you because you may think you know, but maybe you don't. There is always a possibility, and only when they transact or act on your platform can you observe their behavior to determine if they are trying to do anything malicious after signing up. So that's true, but you're right. Yes, remote identification based on documents, I believe, is becoming more and more difficult over time. But the answer is obvious: you have no choice.

We all have to establish people's identities remotely, so either you have additional or perhaps better methods for doing this. Or not even “or”, but you apply multi-layered protection: pre- screening, fraud risk profiling, higher security methods, giving people multiple ways to identify themselves, and you just do everything you can. Let's say I'm satisfied. Well, listen, there is no universal solution. I know.

I know. You know, often when I talk to Web3 clients, they say, “Oh, this person has already been verified ( already been verified ( KYC) by someone. Let us skip KYC.” This is one end of the spectrum, right? At the other end of the spectrum are tier-one banks, which do so much work and create so many obstacles.

Whether that leads to better results, I'm not entirely sure, but that spectrum exists, you know. Thank you. Mitchell, what do you think about this in the context of our discussion, what would you say? How do you distinguish a researcher who reports a vulnerability from one who vulnerability from one who sells it to the highest bidder? How does the industry actually address this?

Wait, I didn't quite understand the question. Can you paraphrase? Um, how do you distinguish between a researcher reporting a vulnerability and someone selling the same vulnerability? Is anyone selling? Yes.

No, I still don't understand. I guess I'm asking if you can tell the difference between a "white" hacker and... Ah, I see. You know, regarding this issue of identity. Yes, yes, yes.

Got it. When you have to trust, because ultimately, on this panel we are talking about trusting a person who, even though he acts openly, still hacks systems. Of course. Well, I think our context is a little different. I mean, because of the nature of this relationship, we don't care.

And the reason we don't care whether someone offers a vulnerability offers a vulnerability that they could have gotten elsewhere, whether it's someone new, or whether they're a true "white hat" hacker, is because we don't have the luxury of choosing who to work with in those circumstances. For a small or insignificant vulnerability, yes, we can afford it. We can say, "Hey, you didn't pass KYC." Or: "Hey, you're from, you know, a suspicious country." And there are a lot of reasons why we might say, " we might say, " Hey, we don't want to deal with you."

But when it comes to serious things that can compromise all your systems, and this happens often... Can you give me one example? Of course. We constantly deal with such cases. This year we saw vulnerabilities in oracles that could compromise an entire set of price feeds, which would allow the entire market to be compromised, right?

We've seen cases of double-spending vulnerabilities, a whole bunch of vulnerabilities on blockchains that would allow for copying and issuing as many assets as desired, stealing them, and taking them off the network. We have seen cases where multiple copies of a certain type of NFT could be created, critical to protecting a very well-known internal system used by most crypto users and funds, which could cost them hundreds of millions of dollars. We've seen cases on exchanges and, say, in related blockchains that work with those exchanges, where you can manipulate the accounting between those two ledgers in a way that again allows for some kind of double-spending attack. And all of this, although it sounds abstract, can cost hundreds of millions or billions of dollars if implemented for properly " for properly " delicious" purposes, understand? So these are not some hypothetical things.

This is what happens every day in the world we deal with. This happens to the biggest companies in the world and the industry, and it's our job industry, and it's our job to protect against it to protect against it . Because of this, neither I nor my clients can be too concerned about, you know, the source of vulnerability, so to speak. Because at the end of the day, we have to prevent a billion- dollar breach. Our main concern is not the risk of non-compliance or fines from regulators.

We literally don't care. Not because the law is not important. These things are very important. Because if there is a billion-dollar breach, we will die tomorrow. Truth?

And our customers will hate us forever. You know, that's why I surveyed the whole team, right? We are a rapid response team. That's right. We are more like firefighters.

We don't have the luxury of worrying about whether we should cross this property to put out the fire. We must put out the fire, otherwise we will all die. Of course? Moving to a slightly different plane. Of course different plane.

Of course , we comply with all current and applicable laws. But when our clients have to choose between their own survival and the survival of their users, right? You must take these measures. Remember: the vast majority of projects that get hacked see their equity or token value (depending on the type of asset) drop by at least 50% or more. This decline will continue for years, and in most cases it will reach 90% or more or become fatal.

Of course? So it's not just a matter of preventing you all from getting robbed, we really want to ensure your safety and the safety of your money. This is very important. But also, if you are creating a project and this happens to you, most likely you are "dead", and all the capital you have worked on turns to zero after one of these critical events. Because of that, if a vulnerability comes to you, okay, if something really valuable comes, you don't say, "Hey, did you fill out KYC?

"Maybe I'll block your application." You say: " application." You say: " Thank you very much." I will find a way to pay you one way or another." That's what you say.

So the board of directors and CEOs are just thrilled with you. You are an you. You are an opportunity cost. Harry, in the context of this discussion, should we consider recovery as part of security itself, rather than what happens after it is breached? What do you think?

Er, sorry, recovery should be considered Should recovery be considered part of security itself, rather than something that happens after security has failed? How do you look at this? Yeah, I think, uh, like you said, you don't have the luxury of choosing whether you want something to be a part of it or not. Should this be any reason or method by which you lose or recover funds, you should make sure should make sure that this is provided for. And if we go back to the 500 billion figure that you mentioned, most of it is people who lose their keys or misplace them, and therefore lose access.

So recovery is incredibly important along with everything else you have. You don't have the luxury of thinking, " Should we do this or not?" Maybe we should back up the keys? Or maybe we should have a mechanism that allows us to recover if something goes wrong.” You must have it.

You can't just have one system, rely on it, hope it's okay, and then when it fails, say, "Oh, well, I guess we did everything we could." If you're really going to fulfill your fiduciary duty and make sure that not only your clients, but also, as you said, your team said, your team , your assets, and your company survive, you need to take this extremely seriously. You need to implement all possible protection measures. And if not, you will most likely be among those who will not survive, because this is a new world where any vulnerability you have will likely be discovered and exploited very, very quickly. And you won't be able to react in time because it's not only being sorted, evaluated, and seen at machine speed, it's also being exploited at machine speed.

And if you try to wait until people on your team have the time or the ability to do it, it just won't happen. So recovery, along with everything else, everything else, should definitely be a priority. And if not, it's unlikely you'll get your money back, and your company could go under. Yes. Just to highlight these dramatic changes that I think most of us are not aware of.

Most of us haven't had to live in this reality yet, but we are truly moving into a world that is very different for those of you who have a technical background or have worked in security for a long time, you have had to think about these issues. In the past, we didn't have to think about every vulnerability being exploited because it just didn't make sense. It was cost-inefficient, you know, security experts, hackers, and red teams— red teams— they're expensive. There weren't that many of them in the world. There are probably a million or two of them in total.

And most of them have jobs. This wasn't a problem, but now we live in a world where it's increasingly expected that if you have an attack vector in the work environment, it will be exploited. And these deadlines are being shortened deadlines are being shortened , you know, from months to weeks. It's already on its way to days, depending on where you look. At Immunify, the level of vulnerability incidents has increased by several hundred percent this year.

And the trend line is going up. So it looks like if this continues, next year I'll be dealing with 10, 15, or 20 times more vulnerabilities for my clients than last year. And we see this throughout the world of open source software. We see this in many critical codebases. We see this, for example, in Linux and other types of systems.

Everything that is there is found, is that clear? And if your risk management, your security posture, and your security investments don't match that, chances are you'll become part of that very unpleasant statistic where you become a victim and have to learn the hard way, because that's where things are going. And by the way, who are these people who are involved in hacking? Everyone. I have two questions for you, and please note that we have two minutes to finish, but please, if you can spare me about 30 seconds, I want to finish with that.

So, one question for all of you: In 5 years, what will be the biggest source of loss that we barely talk about today? 30 seconds for each of you. Well, if I were talking about 5 years from now, probably the main source of losses would be, you know losses would be, you know , government confiscations , government confiscations . The reason is that if we survive as an industry during this period, it will only be because we use new technologies to create unbreakable code. And 5 years is about the time we need to do this.

So, my prediction is: in 5 years I will do the job so well that I will no longer have a job, okay? But as a result, the main risk is that the governments that have driven our economy into the abyss will say, "Oh, we have all these old boomers who need more money in retirement. We need to take that away." And we're starting to see the early stages of this in things like wealth taxes and, and, like, what's that? Capital gains taxes, taxes on unrealized capital gains.

So capital gains. So , you know, within a few years, there will be a new risk profile. We can solve problems for you in problems for you in our own way, but other threats will arise. I like the idea that I did my job so well my job so well that I lost it. This is great.

Harry. Yes. Um, I think if you look back 5 years , even vulnerabilities that were built back then, like, for example, in Coldcard, 5 years ago this vulnerability was found. One would hope that within the next 5 years, every vulnerability that actually exists will be found using the methods we have now. So, there will only be new methods that we have n't yet discovered and haven't been able to fix or patch.

People are talking about quantum technology, I think. If you haven't upgraded your system to quantum by then, it will likely disappear. Hmm, I think so, I hope the I think so, I hope the job gets done. If we have formal verification, if people take this seriously, and if all the unnecessary are weeded out , only those who have taken steps to fix the old and prepare for the new will remain. Elijah?

I'm quite optimistic about the technological side, but quite pessimistic about the human factor, because in my opinion, the most recent serious problems have arisen where the weakest link is the human. We cannot fix a person with technology. I think that's going to be a problem, unfortunately, but hopefully we'll learn to be extremely vigilant extremely vigilant , but so you said " so you said " fix the person with technology technology ." Did I misunderstand something ? No, I don't think you can fix a person with technology, absolutely not.

So, we will remain the weakest link. And in an era of lack of trust, you know, I think that deep things, like, we know other people much less than we did, say, 20 or 100 years ago, right? I believe that the human factor will remain the biggest source of losses. I'll use this great point you made for the last question: Name one thing the Name one thing the industry should stop doing and one thing it should start doing—for each of you, since you said that people are still the worst vulnerability. I will start.

Okay, I will start. Okay, first, we need to stop being predominantly reactive in the security arena. Unfortunately, people don't learn, so it won't happen. But this is a losing battle. We need to stop doing this because the game has changed because the game has changed , and we will all be destroyed if we don't adapt to these circumstances very quickly.

The solution, of course, is to start proactively investing in security. We have the best security technology in the history of the Internet. Now is the best time to be a security buyer : you can get better protection at a lower price that covers most of your stack, but the problem is that most of us don't take advantage of it. We do n't even know. So, this is the central challenge.

If we can do this successfully, not only will you successfully, not only will you , you who are the vanguard, step forward and survive, but you will likely become one of the few survivors in the most profitable financial market in human history. You know, you'll avoid permanent underclass status and hopefully be rich forever. So it's not a bad deal So it's not a bad deal . You should do this . You should do this .

Alex, stop relying on people as your weakest link as your weakest link . Stop counting on people to respond to incidents in a timely manner . Stop counting on people to, you know, close the gaps that you know there will be. This is what we do at Circush. We allow you to automate incident response.

We allow you to automate the movement of funds to a safe place if something bad happens. And you really should come and talk to us about it. So start it. This is valuable to every industry on this earth. Stop flying in the clouds.

Thank you. Emilie. Okay, question. We look at it from different perspectives, do n't we? I mean, do we look at it a little bit from a compliance perspective?

I think there was a certain myth and hope that we could all live in a trustless society, relying only on systems. I always come back to the fact that essentially you need to know who you are putting your trust in during an interaction. If it's technology, the weakest link is the one on the other side of that technology. So I think we're probably going to have to get used to being a little less anonymous and a little more who we really are. And maybe that's even a good thing.

I have one question for you, Ilya, before I finish. This is just my personal curiosity, my assumptions. Do you think the era of anonymous internet is coming to an end? First of all, I'm not entirely sure that the anonymous internet ever really existed. For some of us, it For some of us, it existed.

Well, maybe so. But I think only for someone who has taken very, very many steps to become and remain anonymous, right? But in reality, I think we all have to accept the fact that we live in a world where that's not the case. And secondly, I think with the erosion of trust in general, right? You will actually appreciate the lack of anonymity more.

For example, knowing who you're really dealing with, or at least knowing why you can trust them you can trust them . Who, who said that this person is exactly who you take them to be? Is n't this a prelude to the end of privacy in society? Yes, but you know, there's privacy, there's security, there's enjoyment of life, right? There are many values ​​in this life .

There are all these discussions about Web 2 and Web 3, right? Do you value ease of use (UX) as opposed to self- storage and complete control, right complete control, right ? Life shows that too many people choose convenience and trust centralized institutions because they cannot rely on themselves to store their assets, so as not to lose keys and so on. So, I think it's a matter of debate. I would n't necessarily put privacy as the sole and most important, ultimate goal.

I always say: if you lose, if you invested money somewhere and lost your asset, who do you turn to who do you turn to ? You will go to the police ? You will go to the police . How can the police protect you if we live in a completely anonymous world where they don't know anything they don't know anything , right? So you end up turning to your police, to your government for help, right?

So there is a certain balance: you give up certain freedoms for certain things, and whether that balance is good, whether the system works—that is a whole other question, but fundamentally, Gentlemen, it is time for us to conclude. I hope you will continue this conversation over coffee. This is a philosophical discussion. Yes, and I think we discussed what could go wrong, but beyond feelings, this industry needs to build trust, and I thank you all for your honesty and open ideas. Let's thank them with applause.

Thank you. Thank you. Thank you all. See you later.

Automatic transcript — names and jargon may be misspelled.