# Good Things take Time: The Human Layer of Security by Toby (Consensys Diligence) // ECC2

- Channel: [Ethereum Cypherpunk Congress](https://streameth.org/ethereum-cypherpunk-congress)
- Date: 2026-01-09
- Duration: 15:23
- Topics: web3, privacy, now, crypto, cryptography, blockchain, data, security, human right, rights, tech, technology, internet, open source, free, freedom, ethereum, hackers, ethics, cypherpunk, dev, developer, dapp, decentralization, bitcoin, computer, surveillance, cyber, peer2peer, p2p, love, solidity, zk, zero knowledge, education, academy, w3pn, congress, ethereum cypherpunk, buenos aires, argentina, vitalik buterin, privacidad
- Watch: https://streameth.org/watch/yt-pBpkqaR4d_A
- YouTube: https://www.youtube.com/watch?v=pBpkqaR4d_A

## Description

Ethereum Cypherpunk Congress by Web3Privacy Now is the world's largest cypherpunk and human rights gathering. +4500 people united in Buenos Aires to celebrate privacy with internet freedom leaders like Richard Stallman, Vitalik Buterin, Roger Dingledine, and Eva Galperin. 

Consensys Diligence website: https://diligence.security/

Join us in building a free internet for all:
Website: https://web3privacy.info/
Congress site: https://congress.web3privacy.info/

## Transcript

[applause] &gt;&gt; My name is Toby. Good to meet you guys. Um I'm I'm the team lead of Consensus Diligence. We are a group of security researchers. We are around since 2017. Uh few familiar faces here as well. Thanks for coming by. Um yeah, and I want to talk a bit about uh how good things take time and what the role of the human layer in security is. Um Yeah, so there are a few things that we see over time. Um obviously, as you guys notice as well, things are getting more complex. Um Protocols are getting crazier crazier. Moonmath uh CK is introduced everywhere. Um Things are getting more secure. Building blocks are getting more secure, getting combined. Everything gets just bigger. At the same time, funny enough, roadmaps and timelines kind of either stay the same or getting shorter, which is understandable. Everybody wants to deploy and that's okay. Um and another thing that we see is essentially AI everything. So, um in all of that, you would say it's it's it's getting kind of like a in a gold rush mood, it feels like. Um but obviously hacks are still happening and that's like a pretty pretty sizable hacks are still happening. Um And what we see over time is like a pattern that that hasn't changed since the beginning is that uh critical hacks are starting in the dev's logic essentially. So, that means we have um So, we have more and more advanced tools and technology that find like lighter lighter attack vectors, but the really juicy stuff is still in how the systems uh how the business logic of the system works and how we can manipulate that. So, for this we still kind of need a need a human and it takes time to find those. So, it's it's not done in crazy short timelines. So, time is quality in security. And that's Sorry, can you skip the next uh yeah, you got it. Um so, that's true for a good meat, right? That's true for uh good code as well. You can't wipe code everything. Next. And it's also true in security. Um especially when projects with uh next. Especially when projects with these very complex uh code bases come to us and essentially say, "Hey, let's have an audit, but just so you know, we launch in 3 weeks. Um by that time it has to be safe." Um yeah, so good things take time. Um And I want to touch a bit on the human layer in all of this because obviously at the moment we're we're quite central in this. Uh and why essentially speed won't replace the understanding necessarily and how tools can enhance us obviously, how they can help us, uh but still why humans are very much in the center of this. So, let's take an example, very simple. Um this is a recent project that we uh that we audited. And just for the for the example's sake, let's say uh there is a smart contract which takes some collateral in and mints some new stuff. Uh in this process, the rewards are generated uh and the system takes the rewards and treats it as excess collateral and puts it in a separate place under quarantine and puts a time lock on it. Once the time lock is expired, uh the the funds are cleared, um accounted for in different system, uh just leave the system essentially, so the whole thing can start again. Um Our auditors found a few odd things here. Uh first is uh the quarantine and the time lock can be bypassed under certain circumstances. So, uh it was in it of itself not an issue, but was a very odd thing odd thing. The second is that upon bypassing the the quarantine and the time lock, the funds are not cleared automatically as they are intended to do. So, they stay there for you to use. And the third thing is that the smart contract was under certain circumstances could be manipulated, so it accepts different um funds than the than the actual collateral. So, I think you can combine it already that um if you want to if you are a malicious actor and you want to hack the whole system, you essentially uh bypass the You can go one further. You bypass the time lock. You use the funds that should be cleared, but are still there. So, these kind of ghost funds essentially. And you trick the smart contract in accepting these as collateral to mint new stuff. So, that is literal money from nothing. That is that is uh a proper hack where you And And this is the interesting part where you need to combine sif- different complex components. It's like a more than a 10-step sequence with a timing aspect and um yeah, different very complex context. So, that means as of now it's super hard to identify and find for for AI. So, as of now you need crazy creativity and like this this context uh reasoning that makes it possible for human and you need time obviously. [snorts] This is not found like in a day or something. Um Yeah, so uh can go next. We All we need as opposed to, you know, machines is just like a little hug after days and weeks of like staring at code. Uh some snacks, some caffeine and a salary. And I think this is still a very fair deal. Um so, let's go on another example I want to I want to show is where or why humans are still a very central aspect of security is that um that uh we put humans in the de facto standards that we define for the industry. One example I I uh put down here, which is the E Trust Security Specification of the Enterprise Ethereum Alliance. So, what this is is essentially an attempt to create and describe a standard for security. So, they formulate three security levels and basically define what it takes to achieve these security levels. And under these security levels you have different attack vectors defined and then then explain what it needs to cover these. Um so, it's an attempt essentially to inform hopefully regulators about how to build regulations, how to define audits and how later on define certificates. And the very first level, this level like S, M, and Q are the levels. Very first level S, this is the low-level contextual stuff that can be found by tools. So, in this case they defined even by static analysis. So, they would basically say it's it's fine this this category of attacks can be found by by tools. The second level already um covers attack vectors that need to be that need to be checked and and verified by humans already. So, in the standard it says, "Please hire a human to do this heavy logic stuff." And in the third level, it basically says um the entire logic has to be verified and obviously at the moment that requires a human to do. So, big shout out also to Charles Neville. He's also in Buenos Aires. You can if you find him, big guy with a cowboy hat, can't miss him. Uh he's spearheading the whole um endeavor. We supported a bunch of other audit shops um also supported here in in creating this uh standard and we hope it one day will make an impact on regulation. Let's see. So, um what we what we see um Uh sorry, can you go to the next as well? So, we we see definitely the human is in the center, but we also understand there is a temptation in in speed. We want to automate as much as possible and as security researchers we also want to do that, right? We also want to build tools to like do the do the lifting or at least part of the lifting for us. Um But it's it's still at the moment the fact that tools are only take like caring for the things that we tell them to care for. They don't yet understand why it matters. So, um yeah, it's it's not there yet. Um but there are a few things going on. Um and I want to show you some of them. For example, Bernhard Müller's work, uh he's ex-diligence, now works with uh Sherlock. And apparently month or one and a half ago um their agent found a critical bug which could have led to a 2.4 million uh dollar hack. The details are not revealed, so it would be very interesting to see like how much human intervention was there and how much uh AI was was there. Um Another one is Tintin Webs uh Superchunkie. Tintin is um a member of the diligence team as well, creating a different approach, basically saying the agent shouldn't shouldn't do or is not good yet at finding crits, but is very good at helping me um you know, exploring the code base, understanding the code base, um guiding my focus. Uh so, that is what Superchunkie does. Um you can check check him out on on Twitter as well. Uh and Valentin, who's our head researcher for fuzzing. So, different approach, not AI um at the moment fuzzing driven. And together with the University of Technology in Vienna, the they are focusing at the moment on ZK fuzzing. So, for CK pipelines and um at the moment focusing on ZK VMs and EVMs. So, in the in the primitives trying to find critical bugs. Um very successful at the moment. He's speaking also um on the Dean DSS on Thursday and at the ETH Proofs Day panel on Saturday. So, you can catch him there. It's it's crazy what's going on there. And if you want to check out sources later on, good stuff. Um Yeah, so we we understand and then we we are doing it. We're we're working on tools. We're working on AI. We want to advance the whole thing. And it it seems like it's funny. It seems like every generation tries to replace the human labor in some way because you know, it costs too much and costs have to go down. Only to end up kind of reintroducing the humans to the loop because in the end that's kind of what we're doing it for, right? So, it it's like this irony that we're doing it again and again and software is doing it. Military is doing it. Every industry you can think of. Like I believe in the in the '80s there was this craze in the in the finance world of like trading bots. Then it got out of hand at some point. We come up with regulations and now we have people checking what the bots do. Um because it's necessary at the moment, right? We need someone who needs to understand why these systems were built in the first place. We need to understand is the is the direction of the system actually aligned with our goals? Like our moral values, our set of beliefs. Is it Essentially, is the system serving humanity? And this this is the central part is it's from humans for humans and we shouldn't shouldn't forget like all the all the ecstasy about about technology. Um can go one further. So, yeah. Every every system trying to replace its human layer eventually kind of brings it back. Um yeah. You can go ahead. And what what we think in the whole in the whole replacement debate is that it probably won't replace top researchers looking for zero days. It will will kind of feel like this. You know, it will be a very enhanced level of of working where machine is doing machines are doing the the easy things, guide our focus so that we have more time for the human to do what they are actually good at. And and this is this is where where we think we're going to land and I think also where we should land. Um yeah. Go one ahead. Um what I want to add here as well is that So, it's also important to understand that o- over the time also we we understood that the teams are that that are working with us are very appreciative of the human input here as well. Cuz you need to also understand that we we definitely want to Um so, good auditors want your project to be secure. So, we have a passion also that we that we bring in there because it's not a it's not a it's not a product, it's a service, right? Can go one further. So, we see it we see it really as a craft. Um And a craft means it's like the the rare moment of like undivided attention where you uh where you have someone of the like some of the most talented hackers on the planet look at your code, read it line by line and you know, take the time to find these juicy bugs essentially. So, it's one of those moments that should be appreciated and should given the time it it needs essentially. So, it's it's a service at its purest form and when I say service I mean it's essentially two people working together in a relationship and they don't want to disappoint each other. And this is what what, you know, I see with with our auditors. It's like they have the passion that bring in. Um they want your project project to be secure. They want to have a genuine understanding where you're coming from and what what you intend to do with your project. No rubber stamping. Um no sugarcoating sometimes. That's also necessary. But in the end I think that's what human auditors and I diligence we try to contribute to the Ethereum ecosystem is like the genuine wish for it to be secure. Yeah. Um and there's a reference that comes to mind in in this craft aspect also is that um Yeah, it's from it's from Daniel Kahneman's book Thinking Fast and Slow where it says um fast thinking is sufficient, slow thinking prevents catastrophe and that's exactly what auditing is. It's professional slow thinking essentially. So, that that's what we need. Um yeah, and it also in all of this human interaction brings a load load of fun, you know? Um it's always like in in our collaborations there's loads of golden retriever energy where it's you know, where we are excited when we find something that I described earlier while well, yeah, breaking your code. Very sorry about this, but it's it's it's good fun as well, you know? And I think that's that's a lovely thing in in human interaction that I don't want to miss at least. Right. So, yeah. Um Good things take time. And I think if we're all serious about shipping reliable, trustworthy, and privacy respecting technology, then we should definitely protect the human layer. And we should definitely give it the time it needs. So, yeah. Thank you very much for your time. Thank you very much for coming by. And um yeah. You can catch us later also. Half of our team is is here as well. Thank you guys. Cheers. &gt;&gt; [applause]
