New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Trust No Message: Scam Detection and Defense in the Age of AI | Alex Murashkin | ETHTaipei 2026

ETHTaipeiSat, Oct 3, 2026, 12:00 AM

Trust No Message: Scam Detection and Defense in the Age of AI | Alex Murashkin, Common Defense AI Security | ETHTaipei 2026

Transcript

Hello. Hello.

Oh, good morning.

Good morning. How's everyone today?

Good.

Good. Well, time to talk about AI, good and bad. So, yeah. All right. Well, uh I'm Alex, uh from uh common defense, uh cyber security arm of Quanam and uh today I'm going to convince you why you should trust no message and how to detect and defend against scams or social engineering attempts during the age of AI.

Hey, it's been a while. How many of you received a message like this over on Telegram out of the blue from somebody you barely spoke to potentially, right? So, uh yeah, it's um I see some uh people can relate to that. Yeah. And if you receive a message like this, uh well, you'll be surprised that uh you probably been surprised that there's a calendarly link right there.

So uh uh inviting you to actually join and and uh book a call and if you are naive you [snorts] would actually fall for that and you will book the the calendarly uh invite. it will land on your email and calendar and then you would maybe write something nice to that uh person trying to social engineer you saying oh yes great uh great great to hear from you yes talk soon and so on then you join the Zoom meeting and you see something odd right it could be either the video being u a little weird or the audio uh doesn't sound quite right. Why is that? Well, because this is a hacker. He's trying to get um get you to uh install something and you get a message like this on Telegram saying, "Hey, the Zoom quality is bad.

Let's switch to Microsoft Teams and there is a link there that says uh you know, you downloaded the Teams." You open the link and as you can see there's a fake link because teams is misspelled intentionally. Uh and you download that and you are hacked. That's that's what can happen and that's what happened many times uh in the past already. Well, why is that?

It's simply because web 3 security is no longer just about securing smart contracts, right? So as uh Vitalik was saying, there is a need for secure finance and yes, we have blockchains that are secure by design, but your laptop is not. So in 2025 alone there has been increase in uh hacks of your of crypto from personal uh laptops and then the number exceeded 158,000s and that's a huge number. Just imagine how many people lost their funds just because uh it was uh on someone's laptop or maybe just not properly secured. Impersonation scams increased 14 times in 2025 and more than$2 billion dollars were lost to due to operational security failures and that's a huge number because it's four times more than DeFi which is a different picture from 2021 when uh a lot of us were on stage and saying uh that uh uh you know this displaying the issues of defi hacks with uh of bridges and so on and nowadays in the last few years the situation is a little bit different and uh why is it so uh difficult uh to be here in this space at the moment?

Well, there has been a lot of uh new complexity uh due to AI. Just a few days ago, there has been a viral tweet uh by somebody uh who claims that uh he got a call from somebody pretending to be his wife and the the wife needed money for uh filling up the gas tank, but she drives a Tesla, so it was clearly not uh the real uh message. But nonetheless, uh the voice sounded exactly the same. And it's it's very very easy to fall for something like that if you are not uh alert enough. Fake personal IDs.

Maybe some older generations could be more comfortable when they speak to somebody and ask for the ID from that person and once they get an ID, they might be comfortable and saying, "Oh, okay. You seem like a real person." But not anymore, right? you can fake any ID very easily nowadays. you just have to use a uh the LLM that doesn't have that type of uh uh security feature and yeah so this doesn't help either now it's becoming a big uh issue and you can launch cheap attacks at scale right if previously someone would have to message everybody in this room you'll probably get banned after five or 10 messages right because all of them would look the same it will be from the same IP address and so on.

But nowadays, if we have let's say 200 people in this room, there will be 200 personalized messages that use everyone's background that is publicly available. And all of that can also be launched from different uh locations, right? And that's what enables uh AIdriven attacks at scale. And uh if uh some of you are from the early phases of the internet where the social engineering in early 20 early 2000s would look something like uh an email from uh someone pretending to be a Nigerian prince and you could probably you probably have enough time to respond to that, right? You just read an email and there is no urgency for you to respond to that, right?

But nowadays it's different. As you've seen in this attempt, uh hackers move you across different apps, right? It starts with Telegram. Then if you are hooked that the meeting invite arrives at your on your email, then you would uh it will be on your calendar as well. And then during the Zoom call, there will be back and forth switch between Telegram and and Zoom and maybe some other app.

And all of that just makes you uh lower your guards down, right? You just cannot keep up with this level of context switch. And there are just so many channels and applications nowadays. And another example of that is uh hackers uh if you bought something on marketplace and there is a delivery person uh asking for OTP for you to receive the delivery. But what can happen is that OTP is actually from your bank, right?

And that's how many people fall for that, right? You just you actually expect an OTP for your Amazon delivery and you do you do see some OTP somewhere on your phone and if you are not alert enough, you might also get um yeah say the the wrong OTP to the wrong person. And another complexity is that packs become organized. It's no longer somebody unemployed in the basement sitting trying to just uh fish for some uh random benefit, right? It's a it's an enterprise.

It's a business operation. So it needs to be seen as a big company where everyone has their own roles, right? It's uh there's a data broker somewhere who is uh uh looking for uh the public publicly exposed data about you. Then there will be someone who researches how to actually uh social engineer you. There will be someone who generates AI content to send it to you.

And there will be uh a caller with a flawless English talking to you so that you don't suspect anything. And that's uh eventually if they are successful they will extract some money from you. And uh an interesting article was suggested uh by my colleague uh it's about uh a sandbox experiment by any.run and which confirms the organized nature of some of these uh some of these hacks. I highly recommend reading this article.

It's it's very uh insightful. Uh what are the phases of social engineering? Well, maybe we can uh kind of split them up into three phases. Uh the first contact, that's when they reach out to you over Telegram, almost like a cold reach. And if you engage with that, that's when the next phase starts.

Uh and we can probably see a lot more interaction uh back and forth between you and the alleged hacker. And the execution phase is exactly when you actually get the malicious leak, right? That's that's when it uh the actual attack happens. But what can we do about that? At which stage can we actually prevent the damage in the first contact?

Yes, ideally if uh if somebody does not see the the first message in the first place, uh then there is just no interaction. So there is no potential for uh social engineering at all during the engagement phase. Yes, it's still possible to prevent the harm and the good thing about that is that there is a lot more context uh from the interaction because there will be at least a dozen messages from the uh hacker and you you have a lot more context and maybe you the hacker has a lot more footprint across different uh applications from your interaction. the execution phase that might be too late or is it? We'll find out in the next uh next uh slides.

So what what are the solutions? Well, the first one is it would be really nice if we manage to unify uh communication channels, right? there might be some uh some sort of um detection firewall which would sit between the protected user and all the possible communication channels right so it will be telegrams maybe even zoom and uh email and yeah so pretty much imagine having all your communication channels protected in this way and uh since we spoke a lot about privacy uh just uh earlier today uh it will be awesome nice if that solution would be hosted uh just uh self-hosted instead of trusting a third party with that. And how do we implement that? Well, the very naive approach is why don't we send every single message that I receive on my social media through a public LLM.

It will it's it has very good capability to analyze a message for uh scam, right? Or any any suspicion. Does it work? Well, it might work for small scale. Maybe it works for one person.

Maybe it works for a small group of people. But once you go to hundreds of users, that might not be sustainable, right? You will have to pay a lot of money for AI tokens in order to be able to do that. And even then, you might be throttled by AI if you by public if you do it this way. So, this approach doesn't work.

Maybe as proof of concept it does but uh longterm no. So what can we do about it? Well, we add some rules in the front. Uh some certain messages especially the cold reach messages can be detected just by specifying the pattern right. So for example, the the one I presented earlier, hey, it's been a while.

If that message was just stored somewhere as a hash and you can detect that as a pattern and potentially that's where you would make a decision even before the request goes to the public LLM and maybe any messages related to OTPs, they can be potentially flagged as uh something you need to be cautious about. Well, does it work? Does this approach work? It works a little bit better, but still it doesn't really scale that well. And then you would be really exhausted if you try to specify static rules and reax patterns for every single malicious message.

It just it's very hard to sustain that. So what uh was the solution? Well, you build a model. You build a customly uh trained AI model that handles all your B base case. And the AI model in this case doesn't have to be a a large language model.

So it can be machine learning model in traditional sense. Uh and that something can handle most of your most of the messages. Does it mean we still want public to be there? Well, as it turns out, yes, because there can be some cases where the AI model is not so sure about, right? And that's when the public LM can can help because it can uh throw a little bit more of the resources at it, a little bit more of the training data.

And not only that, public is also useful for augmenting or enhancing the verdict of the message, right? So imagine if it was just your own AI model, maybe it will be a binary classifier, right? that would just tell you, oh, this is a scam or this is not a scam or maybe it's a threepoint uh output where it's either scam uh benign or maybe something in between. But with uh AI you can just uh enhance that with uh a little bit like a deep dive type of approach where you would see that not only why this is a not only that this is a scam but also why and what kind of what kind of classification is that well and uh on yeah we took into account that concept we build it and it seems to be working And from the stats that uh we've seen from running a closed beta of this approach, uh there has been more than 2 million messages uh scanned in total, majority of those were from Telegram. And that's where 2.

7% of of the messages were flagged as uh malicious. And just to note, this is this these are messages not from the DM interactions. In case let's say you sign up for you join the big telegram group that's where all the scammers tend to to post different uh messages and that's that's where you receive the the most uh uh suspicious messages. Uh next goes email and then WhatsApp and then we also experimented with uh Slack but with corporate Slack and there was zero messages there obviously because it's a trusted setup so it's not as not as many uh you can have and you can see that at this scale at approximately 30,000 messages per day uh the approach that I described seems to be working pretty well and how about uh going back to the execution phase and is Is it really too late to react at this uh in this uh case? Well, it's not too late, but it will require a little bit more work from your side.

That brings us to the second solution, operational security hardening, essentially making your laptop more secure. So instead of seeing that when you follow the link maybe you will see that that you are not hacked that your system is not compromised and that everything is working perfectly. How to do that? Well actually before that we u there is another interesting uh stats that I can share. uh the the so web three losses are increasingly an obssec problem not just a code problem and a lot of exploits were happening due to access control issues and that's more than half right and just to compare smart contract vulnerabilities only accounted for 12.

8%. That's according to the 2025 data by uh hacken efficient scams we were in the second place 23.8% 8% and efficient scams is pretty much what I just covered in the uh in the slide so far. So what to do what to do about uh securing your uh setup? Well uh there are some basic checks that you can do.

A lot of them are common sense but nonetheless they need to be done. Uh the times when Mac OS was safe just by using Mac OS those times are long gone. you need to have an anti-malware installed on your laptop and uh at the same time some firewall and also you need to make sure that the storage is encrypted as well. uh and it's recommended to not use hot wallet at least not on the same laptop as you use for uh regular daily work right you can either use a a hardware wallet which uh I think there's still multiple opinions about how secure that is right depending on the provider that you use uh but uh what you can also do is just have a separate laptop that is not connected to the network uh at all and that is pretty much also a secure approach as long as you are also doing your part there and yeah so how do but how do we make it more uh systematic right what we've been doing uh at least uh yeah at quan stamp we came up with a list of 30 to 40 operational security checks and that list came up somewhere I don't know 2017 or 2018 and that's what we've been doing we we've been just basically checking everyone's uh in the company making sure that they have antivirus installed. uh basically firewall enabled and there is like there's 30 checks like that that includes your uh social media making sure that you have two factor authentication across the board everywhere and uh the good thing is that during the AI uh phase a lot of these checks can be uh automated so you don't have to actually do it manually but even then we've been using that uh internally and we realized that other cap companies other customers might be interested in the same thing.

So we just had uh occasional calls with some of the customers asking to just harden their setup just making their uh laptops more secure and we did that and at the same time there are standards uh some of those checks are generalized into standards. Uh one obvious standard that you know is so 2 even though it's not specific to web3. Uh but so 2 answers the question whether your organization is securely managed and that's something that a lot of startups are doing but in our experience a lot of web3 startups are not doing that because there is no explicit compliance requirement to do that. At the same time there is another standard called seal uh security alliance and that standard is a little bit more specific. It's it answers the question is the organization prepared for handling web three specific attacks right and those those are the two standards that are not really competing with one another but they are rather complimentary it will be ideal if your organization has uh works with uh web three uh it will be ideal if you uh follow both of them uh there are some differences right so for so two uh there is um the very mature attestation ecosystem right you you would be attested by a CPA organization and customer recognition is is very high so I think a lot of people know about sock 2 at the same time uh seal is uh somewhat new the ecosystem is still emerging but at the same time it's more focused on web three related threats right it can answer it can guide you how to uh use wallets securely, how to do uh multi signing securely and so on.

And uh yeah, and Quan Stamp is actually on track to be one of the seal uh certifiers. So I think that's something that a lot of companies have would uh would benefit from. Uh oh, I had a couple more interesting cases that uh we're also uh brought to me. So uh one other social engineering vector is uh making you use a vulnerable version of a legitimate application. Right?

So if in the first example I showed you that uh the hacker tried to get you to install a fake teams app. In this particular case, what happened was uh a hacker made somebody tried to make somebody to install a very specific vulnerable version of a note takingaking app, right? And that version would uh would allow an exploit and this exploit was uncovered after the person who was trying to get social engineered asked, "Oh, why do I need to install this specific version? Why don't why not the newest version?" And that's where it got it got suspicious right and uh yeah and this is just to highlight more that the updating to latest version is usually a good idea there are cases when it's also misused by hackers right so you hackers if they get a if they get hands on your npm uh credentials they can push malicious version of a package and there is a different prevention from that for that right but at the same time if you're using a very very old version of a library application or uh operating system uh you are more likely to to get to get hacked because the exploit will be available in the wild somewhere already.

Another interesting case is uh uh an exchange was impersonated and that's actually somebody uh that uh uh pretty much uh yeah I know personally. So what happened is uh yeah there was there was multiple there were multiple attempts to uh reach out to somebody who has an account at uh Gemini the exchange and it was extremely convincing with uh phone calls uh reaching out to the person directly and the person managed to record the phone calls and uh then my colleague sent that phone call to an LLM basically to the feature that is using LLM for analyzing voice and it was detected to be a 99% probability that this is a scam right and that's that was a very interesting application of uh uh this uh particular approach that you know LLM can help you detect malicious activity and uh not to mention that the email itself was flagged by common defense as well whenever it was received. Well, and uh finally, what to do when the hack actually happened, right? So, if all the layers of defense failed, what to do then? Well, that brings us to the third solution.

It's incident response. How to investigate and recover quicker from from this from the issue? And a lot of it might sound like common sense, but the first time you in this situation, you will be very lost. you don't know what to do, right? And uh having just a list of steps in front of you, a list of maybe eight or eight or 10 different steps or somebody who is familiar with those steps would go a long way.

So what what do you do? You first try to stop the bleeding, right? You disconnect the device. I think the important part will be disconnecting the device from the network because that's that's what would happen u more likely. You would need to preserve evidence.

You need to take screenshots and record timestamps and caches and so on. And the advice here is also to keep your laptop on disconnected from the network but keep it on so that if there is a malicious process there, it stays in the memory. You need to alert the right people. You need to alert your security team, leadership and maybe anyone you are in partners with to help you with that. And uh the hardest part will be to track and recover the funds if they are stolen.

That has a varying level of success, but in some cases it is very very possible if you do the right steps. Well, the takeaway is we have the big and ever growing social engineering problem in the space. AI makes it worse, but also AI can make it better. And the three solutions we go with is unified detection essentially the platform for uh checking the communications for malicious activity. You have obserening which is about securing your environment and incident response.

Thanks everyone. Uh it was a great uh pleasure talking uh speaking here and yeah go to common defense.ai check us out. Thank you so much. [applause]

[music]

Automatic transcript — names and jargon may be misspelled.