episode.ascii — live render
● episode

Mission Critical

TL;DRCybersecurity engineer Shakeeb Ahmed allegedly exploited a smart contract bug in crypto exchange Crema Finance in 2022, stealing $9M via flash loans, then negotiated to return most of it before being charged by the DOJ.

Jordan interviews TechCrunch Senior Writer Lorenzo Franceschi-Bicchierai about a new chapter in crypto in the US; the first criminal charges for hacking a decentralized crypto exchange. Which is maybe the least interesting thing about the story these charges tell.

Transcript

Machine-generated transcript; may contain errors.

Speaker 1: Someone a couple of years ago compared the smart contract with the mission critical code. He was telling me that you could actually compare it to, like, the code that's used in an f 35 or to launch satellites in space. It's code that you really have to get right.

Speaker 2: I have read the charges against Shakeeb Ahmed a few times now, and I think I almost entirely understand it. Without getting too into the weeds, and there's a lot of weed the story is set exclusively in weeds. Here's the basics. According to the US Department of Justice, in July 2022, Shaqib hacks a decentralized cryptocurrency exchange. The 15 page sealed indictment unpacks how that the gist, and I'm gonna stop saying allegedly now because these are all allegations, is that he found a way to imitate the equivalent of an admin account that he then used to fraudulently manipulate the fees that a user got paid for lending the exchange money. He then borrowed a ton of crypto from somewhere else, briefly loans it to the exchange, gets paid out millions in these fraudulently inflated fees, before returning the loan and walking away with the money. He allegedly does this 21 times, extracting 9,000,000 US dollars in fraudulent fees from the exchange. In the days following the hack, the government then alleges Shaqib does two things. First, he Googles all of the stuff you would Google if you had just done a big cyber money crime heist. In a section of the sealed indictment named Ahmed's post attack Internet history, it outlines these searches. They include decentralized finance hack FBI, DeFi hack prosecution, evidence laundering, wire fraud, how to prove malicious intent, can I cross border with crypto, buying citizenship, how to stop federal government from seizing assets? It is by no means illegal to search any of these things, but I do get why, if you are trying to make the case that this person is guilty, you would include the fact he had googled them. Lastly, they allege that Shaqib sends an email. A very important email, an email that kind of changes what kind of crime this ultimately is. Because up until now, it's theft. But with this email to the exchange he had allegedly stolen from, it kinda becomes something else. A negotiation or a ransom might be extortion. I'm not totally sure, But we're gonna get to that. I called up friend of the show Lorenzo Franceschi Bicarai over at TechCrunch, who has been reporting at length on this story, to help me try and make sense of it. Scott's away this week, so this episode is my conversation with Lorenzo. The last thing you need to know for all of this to make sense has to do with smart contracts. These decentralized crypto exchanges, basically all of them, operate using something called smart contracts. Instead of the software that governs the exchange being stored on a server, it's stored on the blockchain. The very software that rules these exchanges is public and generally immutable, which sounds great until something goes wrong, like, say, a hacker finds a bug. And now you're trying to fix a thing inside of a thing that wasn't really built to be fixed.

Speaker 1: The safety of that money depends on code that is completely open source. It is public. And as you say, in many cases, it's immutable because the the developers don't even realize the risks.

Speaker 2: So here's my chat with Lorenzo about the charges against Shaquib Ahmed, what happens when someone finds a vulnerability in a system that is supposed to be beyond anyone's control, and whether giving back most of

Speaker 3: what you stole changes the fact that you did steal it, on this episode

Speaker 2: of Hacked. Thanks for sitting down with me, Lorenzo. It's good to have you back.

Speaker 1: Thanks for having me.

Speaker 2: So you've been covering the story since the US Department of Justice announced this arrest. And I wanna start with the person at the heart of all this. Who is Shaqib Ahmed? What do we need to know about him for this story to make sense?

Speaker 1: Yeah. So Shaqib Ahmed is, or was, we should probably say, someone who worked in cybersecurity. He worked at a couple of of, small companies, small cybersecurity companies, Optiv and Red Balloon. Red Balloon in particular is a startup here in New York. Then he worked for Amazon, I think Amazon AWS in particular as a security engineer. He had all the necessary skills to do a hack, to, you know, perform a cyber attack and, steal money, which is what he's accused of. And, you know, just to start, if I forget to say alleged, you know, we should assume that everything I say about Ahmed is, alleged based on what the feds are accusing him of. So so in short, he was a cyber cybersecurity engineer, and, he had, specific knowledge about how to exploit, systems, how to exploit smart contracts, and things like that. At least that's what the Fed say. To be honest, from his, LinkedIn, it's not clear that he specifically had knowledge about smart contracts and cryptocurrency, but a lot of the skills that you have as a cybersecurity researcher engineer, translate relatively well to smart contracts. At the end of the day, it's all code that, you find bugs in, that you find flaws in, and you figure out how to exploit those flaws.

Speaker 2: Mhmm. Yeah. I wanna talk a little bit more about, the difference between exploiting smart contracts and more traditional server side kind of software. But as you said, importantly, these are just charges. They haven't been proven in court. But broadly speaking, what is the Department of Justice alleging he did? 10,000 foot view.

Speaker 1: Yeah. So the DOJ is simply accusing Ahmed of stealing around $9,000,000 in crypto, from a cryptocurrency exchange, which the DOJ doesn't name. But because of the dates of the attack and the description of the exchange and the money stolen, it's clear that it was, crema. Mhmm. Some like an an, like a company from abroad that, operates a cryptocurrency exchange, which, you know, it's basically like what Coinbase or Gemini, Binance, all these companies provide. Essentially a platform to exchange money for crypto or some crypto or some other kind of crypto and things like that.

Speaker 3: Mhmm.

Speaker 1: And the the DOJ says that he exploited, this platform in July of, last year. And, he then proceeded to try to launder the money. He also was in touch with, the cryptocurrency exchange. There was a little negotiation going on, and, he agreed to return, almost all of the money. He kept, like, only 1,500,000 in crypto. He also agreed to tell them about the flaws that he allegedly exploited, in, you know, in an attempt to presumably in an attempt to be like, okay, I'm a good guy. I'm help I'm gonna help you fix these flaws, so nobody else, nobody else, exploits them.

Speaker 2: Yeah. I wanna talk a little bit about the the, the timeline of the negotiation that took place there because I think it's it's pretty important to whether this was a black hat, white hat, gray hat type thing. But before we get to that, I wanna dig a little bit more into how this hack worked. I read, I think it's a 15 page sealed indictment. The middle, like, third of it really digs into that hack. The rest of it's pretty readable. I think I read that middle section four or five times just trying to, like, grok how this hack actually worked. You've got fees for contributing to a liquidity pool. You've got these tick accounts. You've got flash loans. It's a lot. Can you help me make a little bit of sense of what are they accusing he actually did? How did this hack allegedly actually work?

Speaker 1: Yeah. So it's a little complicated. And to be honest, I am also not sure, about all the details and all those, like, sort of buzzwords that are common in crypto but are really not common outside of crypto. Yeah. But my understanding is that, essentially, Ahmed allegedly found, you know, flaws in the, exchanges smart contract, And he tricked the smart contract into believing that he was providing more liquidity, meaning more crypto to the to the liquidity pool. And, when people contribute crypto or liquidity to this pool, they get some fees. They get some sort of, like, reward for for contributing to the liquidity pool. So he essentially tricked the exchange, the smart contract, into believing, quote unquote, that he had provided more money, more crypto that he had, and so he cashed out on that. In terms of the flash loans, took out 21 flash loans. My understanding of the flash loan is that it's essentially, a loan in cryptocurrency that doesn't actually have collateral because it's done very quickly. And so he was able to do that without actually, giving any cryptocurrency, if that's that's my understanding. The indictment actually says so that that he performed at least 21 flash loans, and used them to generate falsely inflated fees from five separate liquidity pools. So I think it's a similar attack to the the first one that we we we described. It's essentially they he found a way to trick the the exchange into giving him more cryptocurrency that he was owed that he was actually supposed to get.

Speaker 2: Starting something new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's gonna work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch to brands just getting started, you can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button is used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shopify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, That's shopify.com/hacked.

Speaker 3: No one goes to Hank's for his spreadsheets. They go for a darn good pizza. Lately though, the shop's been quiet, so Hank decides to bring back the $1 slice. He asks Copilot in Microsoft Excel to look at his sales and costs and help him see if he can afford it. Copilot shows Hank where the money's going and which little extras make the dollar slice work. Now Hanks has a line out the door. Hank makes the pizza. Copilot handles the spreadsheets. Learn more at m365copilot.com/work.

Speaker 4: If you're alignment in charge of keeping the lights on, Grainger understands that you go to great lengths and sometimes heights to ensure the power is always flowing, which is why you can count on Grainger for professional grade products and next day delivery so you have everything you need to get the job done. Call 1800, click grainger.com, or just stop by. Granger, for the ones who get it done.

Speaker 5: You have one new message. Translating. Disney and Pixar's Hoppers is now available on Disney plus

Speaker 6: You could say that again.

Speaker 5: Critics are calling it Pixar's funniest movie ever and a wildly entertaining ride. Blizzard potato is certified fresh and verified hot.

Speaker 7: Now, we party.

Speaker 5: This is incredible. Wow.

Speaker 6: I am clearing the rest of the day.

Speaker 5: Disney and Pixar's hoppers. Now available on Disney plus rated PG.

Speaker 2: There's only one line in the whole document that really warrants a little bit of explanation that they don't really provide. And it it sounds like this smart contract has two different types of accounts, normal accounts, like, I think they call them position accounts, and then almost an admin style tick account. And with that tick account, he was able to fudge, I think, the rates that got paid out, like, the fees that got paid out for loaning the system money. What's unclear to me is how he was able to get a normal account to imitate that admin style account, what the vulnerability on the smart contract was that let him do that, I guess, kind of, yeah, that little subterfuge, that little imitation.

Speaker 1: Yeah. I mean, my intuition here is that the smart contract had some sort of bug that allowed him to pretend that he had an admin account Mhmm. And and and act as an admin whereas it was just a regular user.

Speaker 2: So he allegedly, figures out this vulnerability in the smart contract, uses this flash loan vulnerability to pump a bunch of money out, take out these inflated fees, return the loan, and walk away with with $9,000,000 in cryptocurrency. He then launders that.

Speaker 1: Yes. So the the feds alleged that Ahmed, then proceeded to launder the stolen crypto, which is, you know, pretty standard, technique, pretty standard thing to do after you steal crypto. You try to launder it and, essentially hide your tracks because, you know, as as, you know, all the listeners know, cryptocurrencies, are all based on blockchain technology, which the main feature of it is that all the transactions are recorded. They are recorded forever. They're immutable. So anything you do on the blockchain is recorded. Any movement of the crypto is right there. And so this makes it relatively easy for the feds to find or at least follow the money. You know, finding who did it is, is one thing because the blockchain is not, you know, the users are not necessarily identified there. You can see the flow of money, but you may not know who who did it, but you can see the flow of money. And that sometimes leads to a person because at the end of the day, you got some cryptocurrency. You may want to cash it out and not just keep it there. So what he did, or what he allegedly did was to do a series of transactions to launder it. He they were all pretty standard. He swapped some tokens from others, so some cryptocurrency from other kinds of cryptocurrency. He used bridges, which are, technology some sort of block blockchain technology that bridges from one blockchain to another. So you can go, for example, from the Bitcoin blockchain to the Ethereum blockchain and and exchange Bitcoin into Ethereum directly. He also transferred some of the crypto and or exchanged it, rather, into Monero, which is a relatively well known and pretty anonymous cryptocurrency. It's one of the few cryptocurrencies that are actually much harder to track. It's unclear actually if the law enforcement is able to track it at all, and it was specifically designed to be, very hard to track. So this was a smart move on his part. But, you know, the rest, I think, the well, the rest, clearly, the rest of the flow of the money was, the feds were able to follow and trace to him and trace to the hack.

Speaker 2: The next section of the indictment has a an interesting name. It's Ahmed's post attack Internet history, and it suggests that in the days following this, after the after the hack, after the laundering. He starts googling some relevant terms. I wonder if you could tell me a little bit about that.

Speaker 1: Yeah. So one thing that is interesting here actually is that I don't think it's clear from the indictment how they identified him.

Speaker 2: I was wondering that.

Speaker 1: And, I wonder if that's just because they didn't need to do that for the indictment and it will come up later in the case. That that would be my bet, because clearly, they're they were able to go from, you know, this anonymous person that stole the cryptocurrency and laundered it to actually identifying Mhmm. This person. And that's the first step, before they are able to look at his search history, because I imagine that once they identified him, however they were able to do that, then they just, you know, got a search warrant, went to Google, and asked Google what what Ahmed Googled, around those days. And they they struck gold because they found out that just a couple of days after the after the hack, he was googling stuff like DeFi hack, which stands for decentralized finance. He googled, stuff like why expensive crypto hacks are the cost of doing business. He also had searched, for embezzled. He searched for DeFi hacks FBI, DeFi hacks prosecution, and I'm quoting from the the indictment here. He Googled for wire fraud, which is, I guess, ironically, the, the crime that he was indicted for. He also allegedly searched for how to prove malicious intent, and then he also searched for, like, how to get, citizenship in other countries.

Speaker 2: Yeah.

Speaker 1: He even visited a website that, like a blog titled 16 countries where you your investments can buy your citizenship. So, you know, not only was searching for terms that are in there suggest that he was sort of, like, trying to figure out how much trouble he was in, but also then he moved on to, okay, what can I do about this? You know, he probably realized that he was in trouble. I mean, it's it's hard to believe that he did not know that what he was doing was a crime, but, you know, we'll see we'll see what him and, his lawyer, argue. I can imagine a universe, and this is me speculating, but I can imagine a universe in which he claims that he found those flaws, and maybe he was worried that they could be exploited, by somebody else. So he decided to exploit them and then get in contact with, with the target, which is something that actually has happened in, in the world of crypto and Web three. But, you know, in any of those cases, it's really hard for prosecutors especially to really believe that, these people actually were just sort of white hats, you know, looking for flaws and, trying to alert the targets, on how to fix these flaws. But it's a you know, we can get to it we can get into it a little bit later more if you want, but, yeah, this this does happen. It does happen. There's even, like, some companies that have, talked about it publicly about how they noticed there was a bug in a smart contract. And because smart contracts live on the blockchain as well, and so they're completely, basically, open source and anyone can read them, They were worried that somebody else could, steal the money, or in some cases, they even saw that someone started stealing the money, and so they stole it back or they stole it first, and then contacted the the target. So I think there's a universe in which Ahmed and his lawyer argued that that's what he did, but, even in, you know, even in that case, I don't think, the law doesn't care. I don't think the law cares about the intent of doing something like this. You know, at the end of the day, you're stealing money. You're hacking, smart contract and a company, and that's kind of all it matters in in a case like this.

Speaker 2: Yeah. Let's let's talk about that a little bit because, I was worried someone was going to steal this, so I stole it is a very interesting defense. And yet, it doesn't sound like this is the first time that argument has been made. We don't know that's what they're gonna argue, but it feels like it's going that way. So in the days after that this hack happens, Shaqib is googling the series of terms, and then the crypto exchange, Crema, makes a sends a message publicly on the blockchain to the hacker to which, allegedly, Shaqib responds, starting some kind of a a dialogue, almost a negotiation to give back some portion of this stolen $9,000,000. Take me through that and a little bit about why, a person in this situation might offer to do that.

Speaker 1: Yeah. So I think this is an important step because, you know, in in that universe that I was talking about before, I think one of the key things would be for him to have reached out to the cryptocurrency exchange proactively. Sure. I think it's gonna be much harder to argue that that was his intent because, you know, he didn't do it. So the the exchange did the first made the first step, took the first step. They posted on the blockchain, physically pleading for the hacker to return the money, which is super common. This has happened, you know, more times than I can count and more times than I can they have they have even, written about. But this has become a very common technique because a common strategy or rather because it's actually worked a few times. Perhaps the most, well known case of a of a hacker that returned all the the the stolen crypto was the Poly Network hack in also in 2021. In that case, the hacker or hackers stole $600,000,000 in crypto. With that was the valuation at the time. The Poly Network started a negotiation that was, in this case, all on the blockchain so everyone could follow it. And it was pretty bizarre. They called the hacker, like, dear hacker, dear white hat, please return the money. And, eventually, they did. The hackers returned all the money. Whereas in this case, going back to Ahmed and, Kramer, Kramer about posted the message on the blockchain, then Ahmed sent an encrypted email to the exchange. So we don't know exactly or rather the indictment doesn't show us the whole dialogue. But, basically, Ahmed is, allegedly emailed Crema and started a dialogue, and, he agreed to return most of the money, around $88,000,000. He kept something like $11,500,000. The exchange in their message reaching out told Ahmed, you know, if you return the money, we're not gonna press charges. You you might like well, you're gonna avoid prosecution, which it's definitely a promise that, you know, they cannot make because that's how the law works. But somehow, Ahmed, was convinced by this. He returned most of the money. He told them that he was gonna keep some, and in return, he was gonna tell them, the flaws. So the the indictment doesn't use these words, but this seems like, you know, they were Ahmed was sort of, like, trying to set this up as some sort of, like, bug bounty. You know, a more traditional, I found these flaws. Right. Give me a bug bounty, and, you know, and you can fix them.

Speaker 2: Mhmm.

Speaker 1: And, and the amount of money that he got is, is a lot, but the bug bounties for blockchain and Bitcoin and Web three crypto projects can be very high because, you know, the these mark on some some of these mark contracts contain, a lot of money, a lot of, liquidity, a lot of, crypto that's worth millions and millions, if not hundreds of millions of dollars. So a lot of these companies see, backbounds of, like, even $10,000,000 as something that is worth it because it, you know, it will save you from losing much, much more. And so long story short, Kremer and Ahmed negotiate, and eventually, yeah, Ahmed Ahmed returned some of the money. And that's, and that's kind of how, you know, that's how it ended, at least, between them, as far as we know.

Speaker 2: I mean, you used a really interesting word there, which is negotiation. Is in most cases, and I'm not I'm I know you can't speak to all bug bounties, but is it a negotiation? Because that seems relevant to me.

Speaker 1: Yeah. I

Speaker 2: think. You know, I found a vulnerability, and pay me some money for it is different than I found a vulnerability, and now we're gonna negotiate over whether it's worth 2 and a half million, 1,800,000, 1,500,000. That sounds a little bit more like a a hostage situation.

Speaker 1: Yeah. Exactly. I mean, obviously, the the listeners here know, but, like, a bug bounty usually just works like this. The company, whose software is, you know, we're talking about sets a set of, publishes a set of rules, a set of, like, you know, limits and boundaries, for what people can, look for for where people can look for bugs, and they establish a very clear list of, rewards for the type of bugs that people find. I think there may have been some cases where, you know, the impact of the bug was so high that the company decided to give the the person more money, but this is really it's not what happened here. It's completely different. Like, in this case, the the person, like, stole the money, so they exploited the bug. You know, usually, in bug bounties, you don't exploit the bug. At least, you know, maybe you do a proof of concept, but you don't, like, hack into the servers of Facebook, for example, to, like, show them that you found the bug. So, yeah, I think the hostage situation is a great way to look at it. I didn't think about it that way. But, yeah, it's essentially, you know, you can imagine, like, I don't know, someone stealing a car and saying, hey. I have your car. Just, you know, I found it. It was unlocked, and I ran away. But now it's been a couple of days. And how about I return it to you? You give me Sure. I don't know, $5,000, and, we, you know, we forget about all this. And, again, that's something that that would work either in the in the real world outside of the Internet. But, yeah, this is what happened here, and I don't think I don't I haven't checked this, but I don't think Cramer had a bug bounty, program. So, you know, this is really like, I don't think anyone can call this a bug bounty, you know, in in good faith. It's clearly you know, this was a cyberattack. This is a a theft, and, then the hacker somehow hoped that by returning some of the money, they could get away with it, which he didn't or they didn't.

Speaker 2: It does raise the question of whether or not how do I put this? Whether or not crema honored the arrangement. And, again, it's an agreement made kind of at gunpoint a little bit, so you couldn't really blame them for making the deal and then immediately turning around and turning him in. But you do wonder how the feds got on to the case and whether or not, Crema was involved in that.

Speaker 1: Yeah. I'm not a I'm not a legal expert, but I think that it doesn't matter. In a case like this, it doesn't matter if Crema Sure. Presses charges because presumably some of the users on the exchange are Americans, and so those are actually, you know, those are victims as well. So even if Crema doesn't press charges, the DOJ investigates because there's a bunch of Americans who have lost quite a lot of money potentially. You know, we don't know we don't know how much, you know, we don't know how many users, were affected or if it was just, like, money that Crema owned. But, you know, essentially, if there's a theft and the DOJ can get involved even though, you know, even if Crema doesn't press charges or or decides not to press charges. That's my understanding at least. Like, I basically, what I'm saying is that when Crema promised this, they weren't, you know, either lying or they didn't know how these things work.

Speaker 2: That makes sense.

Speaker 1: Even if they were honest, I don't think they realized that that's not how it works.

Speaker 2: Well, it's it's an easy promise to be able to make. It's like, sure. Whether or not we make these whether or not we refer this on the law enforcement is relevant to, but ultimately distinct from whether or not law enforcement decides to pursue it.

Speaker 1: I think that you sort of you suggested this. You know, they were they were trying everything they could to get the money back because as we were discussing, you know, the blockchain doesn't doesn't forget. And, also, cryptocurrency cryptocurrency transactions are usually irreversible. And so once the crypto is gone, you really need to get it back. You know, it's not like a bank that has some sort of insurance. So, you know, pleading with the hackers to get the crypto back is the easiest way to solve the problem and, get the money back for your user or customers.

Speaker 2: This story partially caught my attention because the government referred to it as a first of its kind. And I think what they mean when they say that is that it is the first charges laid concerning the hack of a specifically decentralized crypto exchange. I think that's what they mean when they say it's a first. Is that your sense of it? How was it a first? And as a journalist who has covered these kinds of stories, how is it also maybe familiar?

Speaker 1: That's interesting. I I forgot that they claimed that it was a first case. I mean, I don't really understand why they call it the first case because Yeah. A lot of smart contracts have been exploring in the past. Maybe nobody has gotten caught, yet. But I don't see how this is different from, you know, exploiting the Poly Network or Ronin, which was like that sort of video game, where the North Koreans stole a lot of crypto. So, yeah, it's strange. I I don't know exactly why they called it the first. It's also, like, only in the title of the press release, and it hasn't it hasn't really been explained. So, yeah, honestly, I don't know exactly what the DOJ meant here.

Speaker 2: It's a little unclear. I wonder if it has to do with charges being laid against an American, but it does seem like a pretty in the weeds distinction.

Speaker 1: Yeah. I mean, maybe you're right that it's because it's a decentralized exchange rather than a coin based sort of exchange. Mhmm. I don't see how that distinction is very, very relevant to most of the public, to be honest.

Speaker 2: It it brings up an interesting question. So decentralized exchanges, especially ones using, like, big liquidity pools governed by smart contracts versus the older order book style. This this whole tech really lives and dies by the quality of the smart contract. And some smart contracts are upgradable, but my understanding is once they're deployed, once they're out in the world and people are using them, they're either immutable or much harder to change than server side software. Does this style of decentralization make fixing vulnerabilities in a design just a lot harder when it comes to things that deal with money?

Speaker 1: Yeah. Absolutely. I mean, I don't know. Maybe this shows my bias on, you know, my opinion on cryptocurrencies and Web three and all this stuff. But to me, it's it's ridiculous that, you're essentially resting the the future of a lot of money that comes from, you know, people who at the end of the day are investors. You know, not all of them are millionaires or billionaires. A lot of them are sure small investors who have read about crypto on some, some magazine, some newspaper, and they've seen the returns that some, some people have made and they decide to put maybe all their, all their savings in it. And all that money is, you know, that's the safety of that money depends on code that is completely open source. It is public. And as you say, in many cases, it's immutable because the the developers don't even realize the risks, especially a couple of years ago or even last year when when crypto was still, really when most, you know, when most cryptocurrencies were incredibly valuable and were growing in value constantly, there was a lot of interest, not only from investors, but from developers to create new new financial products, basically, new crypto projects, new anything, you know, Web three games, anything that you can think of. And so there was sort of a rush. There was a gold rush to cash in. And so a lot of people that had, even limited, to be honest, even limited the software development knowledge, launched projects, put these smart smart contracts online, didn't even get an audit or and just hoped or didn't even realize that this is how it works. You know, code is out there. If someone finds a flaw, then there is nothing you can do to stop it. And, because, cryptocurrency transactions are almost, immediate. I I mean, Bitcoin is a little slower and, you know, they're not, like, technically immediate, but they're pretty quick. And so if you're not monitoring what happens on your network, you're not gonna find out. There there are security companies now that offer threat intelligence and monitoring of, of this kind of attacks. But at the end of the day, these are just, or some of these are just, you know, regular transactions. And, it's really hard to tell whether someone is moving $9,000,000 in crypto because they're just moving them, or it's because they're stealing them. So so, yeah, someone a couple of years ago, compared the smart contract with the mission critical code. He was telling me that you could actually compare it to, like, the code that's used in an f 35 or to launch satellites in space. It's code that you really have to get right. You know, one thing is to launch, like, I don't know, threads, for example, Facebook launch threads. There are some bugs in it. Sure. You know? Maybe, you know, maybe some of them are embarrassing or, you know, can have a different kinds of impacts. At the end of the day, it's a social media network. You find the bugs, you fix them, and life goes on. Here, if there are bugs, if you get unlucky, if the bad people find those bugs, then all of a sudden you're out of $9,000,000 or $600,000,000 or who knows how many million dollars. So, you know, to me, it's still to me, it's still crazy that we're, rest in the faith of all this money on, code that it's, not only public, but a lot of times, unfortunately, developed by people that don't really understand security and don't understand the risks involved.

Speaker 2: Appreciate you, taking the time to chat with me about this, Lorenzo. It's a it's a very interesting one, and I think we'll be following

Speaker 1: it. My pleasure.

Speaker 7: Starting a business can seem like a daunting task unless you have a partner like Shopify. They have the tools you need to start and grow your business. From designing a website to marketing to selling and beyond, Shopify can help with everything you need. There's a reason millions of companies like Mattel, Heinz, and Allbirds continue to trust and use them. With Shopify on your side, turn your big business idea into sign up for your $1 per month trial at shopify.com/ special offer.

Speaker 6: Athletic Brewing Company crafts award winning non alcoholic beers for those who wanna be part of every round. With over 185 flavor awards, they're exceptional NA beers that fit your lifestyle and any social occasion. Summer's full of good times and athletic fits right in. Go to athleticbrewing.com to have brews delivered to your door or find them at a bar, restaurant, or store near you. Near beer, athletic brewing company fit for all times.