episode.ascii — live render
● episode

The $1.5 Billion Crypto Heist & Vibe Coding Beats Big Tech Interviews

TL;DRNorth Korea's Lazarus Group hacked crypto exchange Bybit in February 2025, stealing ~$1.5B in Ethereum by compromising a Safe Wallet developer via a fake job offer, then injecting malicious code to hijack a routine cold wallet transfer.

Transcript

Machine-generated transcript; may contain errors.

Speaker 1: As all of you are aware, well, about two hours ago, Bybit experienced a hack on our Ethereum cold wallet.

Speaker 2: So this particular record gets broken pretty often. But as it stands right now, this is the story of the biggest crypto heist of all time.

Speaker 1: The hacker, have managed to hack the UI of all of the signers computer so that although we saw it was the correct URL of the safe wallet, but maybe it was not. Or it could be I'm just I'm just saying all the possibilities. I'm not accusing anything. It it could be that a safe, server was hacked, so it was sending this, but we don't know.

Speaker 2: That was the voice of Ben Zhao, CEO of Bybit, almost immediately, I think, like, a couple of hours after discovering that his company had become the victim of this record setting hack. In February 2025, Bybit, a major cryptocurrency exchange, suffered a devastating breach losing nearly 1,500,000,000 US dollars in Ethereum.

Speaker 3: Dun dun dun.

Speaker 2: Dun dun dun.

Speaker 1: After signing thirty minutes later, then we got the emergency call, that, our cold Ethereum wallet is drained.

Speaker 2: To execute a heist of this scale, the attackers exploited both software and people using something called a Trojan transaction. And in all of the confusion that followed, analysts quickly traced stolen crypto across multiple blockchain networks with early signs pointing to a very well known group with a history of state sponsored cybercrime, North Korea's Lazarus Group, and their ongoing Trader Traitor program. The impact rippled across crypto markets. Markets were already rippling for a bunch of other reasons. And the hack raises questions, not just for Bybit. Like, how did the attackers infiltrate a security layer, this cold wallet system that's supposedly pretty trusted? Could this happen again? And will more nation state hackers increasingly turn to cryptocurrency theft as, like, a geopolitical weapon?

Speaker 1: So the maximum damage damage that we have witnessed currently so far is the total amount of around 401, thousand Ethereum, that's been hacked. This is the affected amount.

Speaker 2: We've got a lot of stories to get to. Vibe coding has entered the lexicon since our last episode.

Speaker 3: Big vibe coder. Huge vibe coder.

Speaker 2: Big vibe coder over here. But first, I think we unpack what seems to have happened here in the buyback hack. What might be the largest crypto heist of all time and another escalation in state sponsored cyber heists here

Speaker 3: on hacked. Hey, Jordan. How you doing?

Speaker 2: I'm doing good, Scott. How you doing?

Speaker 3: Pretty good. Pretty good. Just vibing out.

Speaker 2: You're vibing out. You're vibe coding. Famously, you're vibe coding a lot.

Speaker 3: I have fallen in love with vibe coding.

Speaker 2: You you actually have. Yeah.

Speaker 4: This is this is not

Speaker 2: a bit.

Speaker 3: Entrenched in it.

Speaker 2: You're really new.

Speaker 3: We can talk about that in a bit. But I think right now we should talk about the show's presenting sponsor, Push Security.

Speaker 2: Push Security. They're hacked is brought to you by Push Security. They keep you safe in the browser. They keep your identities locked down. We're gonna talk about them a little later in the show, but hacked is brought to you by Push Security.

Speaker 3: Vibe coding.

Speaker 5: Vibe coding. We need to talk about it on

Speaker 2: We have we have a good story about vibe coding. We're not just talking about that concept. And we're gonna save saying that word one more time for that section of the show because right now, we have a crypto heist to talk about. This one was fascinating. Like, there's a lot of these, and there's a lot of state sponsored cybercrime. And then every so often, one comes along with just one heck of a fire show. It's big. It's technically really complicated. It's quite murky what's happened. But the CEO came out and spoke publicly, and there's been a bunch of blockchain forensics that's already taken place. So in a pretty rapid, like, a pretty compressed period of time, we got a really good sense of what had happened in this heist. And it's just it's colossal. $1,500,000,000. I've been employing a, heist scale for a few years, the Ocean's Eleven system, 2,001 Ocean's Eleven store in George Clooney. They stole a 160,000,000 US dollars. So this is the better part of ten ocean's elevens.

Speaker 3: K. Well, here here's where I go with it.

Speaker 2: Okay.

Speaker 3: North Korea has an annual GDP of about $23,000,000,000.

Speaker 2: Oh, that's pretty good.

Speaker 3: That's a good one. When a state sponsored hack happens and they steal 1,500,000,000

Speaker 2: That's big.

Speaker 3: That's about 6% of their national GDP, which is huge.

Speaker 2: Yeah.

Speaker 3: Just to put that into context, if you were to see the 6% of America's, The United States Of America's GDP, which is 27,800,000,000,000.

Speaker 2: Okay.

Speaker 3: That would be $1,600,000,000,000.

Speaker 5: Yeah.

Speaker 3: Sure. Gonna like, that that's a huge chunk of the, like well, currently, the the national deficit for The United States.

Speaker 2: Yeah. Sure. And there's it's quite it's like it's very technically sophisticated what they've done here. There's social engineering. There's technical stuff going on. But you made a a a billion and a half dollars doing it. Like, anything is efficient if it makes you a billion and a half dollars. That's what makes this a fascinating story.

Speaker 3: Learning lots about your your inner morals.

Speaker 2: I didn't say good. I said efficient. Unless you start with $1,700,000,000, anything that gets you up to 1.6 was certainly efficient, especially when it was probably a bunch of people in a room. Okay. So let's start. I'm gonna start really high level because it took me a while to wrap my brain around what I'm my understanding of what occurred here. The the big story compressed down, their goal was to get a piece of malware called plot twist onto the system of someone at the cold wallet company that Bybit used. This was a supply chain attack

Speaker 3: Mhmm.

Speaker 2: With many, many other steps, but it was fundamentally a supply chain attack. So, hoo, boy. Bybit's Ethereum cold wallet was considered secure due to being offline and protected by this multi signature authorization system. Multiple different parties had to approve transactions. It's not connected to the Internet most of the time.

Speaker 3: This is safe, right? It's called safe.

Speaker 2: Exactly. We're gonna get to yeah. Safe Wallet. The company is safe, and then in brackets, wallet. So you can hear us say safe wallet. It's kinda confusing because are we talking about cold wallet? Yes. We are. But the specific brand of cold wallet is safe wallet. On 02/21/2025, during a routine transfer from Bybit's cold wallet to its operational hot wallet, which is connected to the Internet, hackers activated malicious code injected into Safe Wallet's interface. They performed this thing called a Trojan transaction, which manipulates the transaction data displayed by Bybit's signers, showing this is a real legitimate transfer. Everything's all good, while secretly executing this hidden malicious, like, set of instructions to transfer it elsewhere to the the thieves, essentially. As we heard a little bit in the intro, the CEO, Ben Zhao, confirmed he was the last person to sign using a Ledger hardware wallet. He noted that there were some limitations on this. There's a lot of code that gets turned up. It's the sort of big flurry of a moment, and there weren't really clear transaction details. They executed this hidden contract upgrade. They swapped the two wallets, and approximately 401,000 Ethereum, $1,460,000,000 was transferred from Bybit's wallet to the hacker controlled addresses within, like, moments. There were no cryptographic weaknesses here. The vulnerability was through manipulated user interfaces on people's screens and a compromise, like, human trust, social engineering moment. So we dig into the tech side of it now a little bit here. You want me to, or are

Speaker 3: you gonna dig into it?

Speaker 2: I I I've got I wanna lob my understanding of it at you and see if it if it it checks out with what you're understanding. So the attackers targeted a software developer working for Safe Wallet, the company. The multisignature wallet platform used by Bybit for cold storage. They described themselves as in their on their website. I checked. This is still up. The most trusted decentralized custody protocol and collective asset management platform. Cold wallet for anyone that doesn't know is an offline storage solution for cryptocurrency. It's disconnected from the Internet. And what happened is the safe wallet developer downloaded a fake version of an application called Docker. A Docker is a piece of software that lets you, like, package software stuff up.

Speaker 3: It's a virtualization thing. We Virtually. It's not. Yeah.

Speaker 2: Yeah. Not interesting to this. They downloaded a fake version of it, and that fake version contained a piece of malware called Plot Twist. The whole goal of this was to get plot twist into the safe wallet system, and it granted the attackers this persistent remote access to the developer's computer. They were running a Mac, and now the hacker had access into the system. The way they did this, the way they got this dev to click on this funky link was a social engineering tactic. We've talked about it before. Apparently, it's been formalized in North Korea's, like, Lazarus Group ecosystem. It's called their traitor traitor program. It's dubbed that by the law enforcement in the West. And it's basically I know right.

Speaker 3: Enforcement deserves a commendation with that.

Speaker 2: They are they are quite good at naming things. We've talked about this before, but it's always like blazing stallion eagle front force. All trader trader basically is is you pose as a tech recruiter, like a blockchain project coordinate. You pose as someone with a big implied bucket of cash behind you, and you just start a conversation with someone. You get them invested in the whole situation, and then you send the thing over. They use that to steal AWS tokens and credentials enabling to access the safe wallet back end and get these malicious plot twist scripts running on the system. So the way we figured this all out so quickly, and I find this fascinating, I was trying to get him on the show for this episode and couldn't make it happen in time. Starts with a a character named Zach x b t. He's this renowned crypto investigator. He described himself as a former rug pull victim turned forensics kind of anonymous person on the Internet who digs into these things and in the day He's

Speaker 3: got a chip on his shoulder and he's going after it.

Speaker 2: A 100%. That's totally it. Really cool character. Really wanna talk to him for the show. Meticulously traces the stolen Ethereum across wallets and blockchain networks, and figured out based on some preliminary test transactions that this was all linked to some wallets that had previously been used in Lazarus Group operations. That was confirmed by Arkham Intelligence, which is like a blockchain analytics firm that was then confirmed publicly by the FBI, who stated publicly in an announcement, this is part of that traitor trader operation. Be aware that this is happening. A lot of job offers aren't real. They're apparently state sponsored hackers, and that's what occurred here. Bringing us to Lazarus Group, also known speaking of names as Guardians of Peace or Hidden Cobra.

Speaker 3: Hidden Cobra. Hidden. The piece hidden Cobra seem to be. Yeah. To position.

Speaker 2: There's there's layers to this thing.

Speaker 3: They

Speaker 2: are widely widely thought to be operated by the North Korean government. They've been active since 2009. They've been implicated in a bunch of hacks we've talked about in the show. 2014 Sony hack, the swift banking attacks, countless cryptocurrency heists. We talked about the Ronin network hack in 2022. They've been around, for for a long long time. All evidence would point to them. There's a bunch of stuff about how they laundered the funds, something called peel chaining, which involves essentially just like imagine a firework going off where it's suddenly just like an initial lump sum is just divided into thousands of intermediary wallets, and it immediately becomes you're trying to track the analytics across these, which makes what Zach was able to do pretty remarkable. But, the next major thing in the hours immediately following, as we discussed in the intro, Bybit CEO, Ben Zhao, immediately acknowledges the bridge publicly, says that they have enough kind of capital to be able to honor everyone's investments in the platform. They hadn't locked down some kind of withdrawals. It's sort of been locked down, but generally speaking, people could get their money out. So this wasn't a a real run on the bank situation as a time of recording. It seems like everyone's stuff is okay. They immediately secured a bridge loan of 80% of lost Ethereum to stabilize the reserves and get everything to be okay. It's quite the loan.

Speaker 3: Dude, but here's the question. Do they get a bridge loan in real money, or do they get a bridge loan in Ethereum?

Speaker 2: That's actually a really, really good question. Yeah. I don't know.

Speaker 3: Like, do they go to a real bank, borrow some real money, money, and go on the Internet and buy Ethereum with it to be like, and we filled the filled the tank back up.

Speaker 2: Yeah. Sure. And it by that point had Lazarus Group turned the Ethereum into fiat capital from some of, like Yeah.

Speaker 3: Were they buying their own stolen Exactly.

Speaker 2: Yeah. It wasn't a weird way. Was there some Swiss bank somewhere acting as the head eating tail of the aurora bore us? That is this financial crime. It's a cool question. I don't think we know the answer to it yet. They offered a 10% bounty of a 140,000,000 US dollars for recovery information. I sure hope Zach xbt got that bag. And the reason they are not replying to emails right now is

Speaker 3: they're spending it.

Speaker 2: Yeah. Good for them. You know, what an arc from rug pull victim

Speaker 3: to wealthy investigator. Exactly. Online personality and investigative

Speaker 2: and now retiree. That's kind of the Bybit story. As of right now, we've got the better part of $1,500,000,000 vanished into the nebulous underworld that is cryptocurrency laundering with seemingly a state sponsored group behind it. Is my understanding of what occurred, copacetic with yours, Scott?

Speaker 3: Yeah. Yeah. The the thing for me is like the the the beauty of the hack, for lack of better words is the is the fact that they had access. They probably saw the back end of the system, then they got to to work creating the Trojan Yeah. Waiting for the one day. They probably even identified the victim that they wanted, so it would have had to have been very specific, like trigger points, like,

Speaker 2: it needs

Speaker 3: to be from these wallets because they have the balance that we're going after. Like, this is the Moby Dick.

Speaker 2: Yeah.

Speaker 3: And it's like they waited for it. And, yeah, just a few little JavaScript injections. Everybody hits the go button to do something that's like a standard part of their their business operations and all of the trust check marks in the back end that need to be met for the transaction to occur occur, and then they just hijack that transaction and turn it into their own. It's kind of beautiful, but also devastating. And and the thing Catch a strong The people that I feel the worst for in this story is the developers at SAFE because it's like, I feel like they this could be crippling to their business. And it sounds like they make a very well thought out tool to do what they're trying to do, and they've spent a lot of time considering things. And then for something like this to happen Completely. Was brutal for them. Like, they're the people that I feel worst for in this entire operation.

Speaker 2: Yeah. It there have been a few stories like this. Supply chain attacks always reveal weak links.

Speaker 3: Mhmm.

Speaker 2: And increasingly, with these very elaborate cold wallet, hot wallet, multisignatory systems that should be really, really complicated because they're a very thin wall between people in the billions of dollars, which is pretty big carrot. There is it's some somewhere in that system, there's just a person sitting at a computer. And if you can get access to their computer, you essentially have imbued yourself with all of the authority that they have over that wildly important set of transactions. Yeah. This wasn't it's like it wasn't someone at Bybit. It wasn't someone with the bit the billions of dollars of cryptocurrency. It was just a person that had the right, like, dev access into this system because they they were just doing their job who just the right like, the right bit of social engineering on the wrong day that you click on that one file and suddenly this giant thing has been set in motion. It's kind of humbling in a weird way. Like Yeah. Fascinating.

Speaker 3: There there's, like, a interesting text side of this because, like, all of the new development tools, like, almost everything is written in open source Mhmm. Using Docker. Like so Docker is a virtualization container. So you can set up, like, essentially a virtual computer that's running a specific part of your application. And then often those containers, you're cloning them off of, like, Docker Hubs. So there's like a there's like a like, a search engine full of prebuilt versions of these things. So, like, oh, you need a Postgres, like, SQL server? Download the one from your Docker. Yeah. It's just like their templates, and you can just go and grab them, and they're, like, preset up and preconfigured. You don't have to, like, do anything. The real question becomes how many of those templates have state level malware injected in them? Because that's where my mind goes. Because I know that they have this issue too with, like, like, Visual Studio Code has, like, probably become in the in the history of, like, small IDs for lightweight coding, like, stuff that Yep. Like, you know, vibe coders, like, Sure. We'll get

Speaker 2: to it.

Speaker 3: Yeah. Visual Studio Code is, like, the more the biggest, like, I'd say, small scale IDE these days. And, like, if you're not using full Visual Studio, like, if you're not building massive, big native applications, you're typically in like, most people are writing code in Visual Studio Code. Okay. It's extendable. So there's a plug in interface, and you can download all these extensions, and it's a public plug in market. Oh, for sure. How many of those plug ins have malware injected in them that are giving people access to code bases and copying API keys and auth credentials. And, you know, this kinda kinda links back to the identity attack conversations with Adam from a few weeks ago about, like I don't know. The more access that like, the more we're letting people kind of, like, I see how corporations get to the point where they're like, you can't install anything on your computer. You can't run anything on your computer unless it's in an authorized list because it's like especially for developers who, like, move, like, there's an expectation that you're gonna move quickly, solve problems, you know, utilize tools that make you more efficient like AIs or Docker, like, templates or plug ins and extensions and Versus code. And it's like, how many of those have potential security risks in them? And the answer is they or could have potential security risks in them. And the answer is, like, all of them could have potential security risks in them.

Speaker 2: It's funny to think about how do I put this? I know folks who have jobs where the most catastrophic thing that could happen is not that catastrophic if someone got into their system. The worst thing that could happen is like a ransomware attack of a small teeny tiny little organization, and their computers are like military grade lockdown. My IT person there who is like just, you know, thumbtacks on corkboard conspiratorial, like, I swear to God nothing's getting in, that this could happen to a developer, like, a human error, but, like, that this could happen to a developer whose system was we learned standing between a state sponsored cybercrime group and a billion and a half dollars is, like, that's just fascinating. That's just an interesting that's an interesting tension when I think about, like, the elementary school teacher whose computer is, like, like, nuclear is, like, siloed, requires two keys turned at the same time to turn it on kind of thing.

Speaker 3: The the human error is like It's

Speaker 2: the whole thing.

Speaker 3: I know, but it but it's I don't even like, what is the human error in this case?

Speaker 2: You clicked on a funny link. You clicked on a funky link that someone sent him.

Speaker 3: Oh, did he? Is it do he actually click on a link?

Speaker 2: That's my understanding of it was that he was sent a link. So the Trader Trader program, I don't know what the narrative, like, conceit was, whether this was a a recruitment or a blockchain. Sure. Sure. Sure. Sure. Sure. Sure. Sure. Was. But And they were

Speaker 3: like, hey. Do a coding exercise in this Docker and then send it back to us and through the execution of it, it installed the malware?

Speaker 2: Okay. He was sent something and ran. That's my understanding at this stage. And, again, this is like we're like two weeks out, so this is all pretty murky. But my understanding was that they downloaded a fake doc Docker application and and ran it, and that's what happened. So it was it was a just a human it was social engineering. It was those people we saw at Defcon in the booth making the call. Just a really well spun lie. Hey.

Speaker 3: We got a job at Anthropic coming up for 750,000 a year. Are you interested? I am. Download this docker and complete the three exercises in it and send it back to us.

Speaker 2: Leet code style interview test, like, get in here. Like Yeah. Yeah. Yep. You you dangle a carrot in front of someone's face. Mhmm. They go for it. It's it's it's human. It's really natural.

Speaker 3: I I think I'm gonna take a little bit of a distraction as I do. I will take a small indication here

Speaker 2: to chase the thought that

Speaker 3: I'm familiar, Matt. To to chase the thought that just jumped into my mind, and when we look at this is gonna be a commendation for the traditional financial sector is what I'm about to say. Because if we look at this ultra techie, young, you know, like, most people that are into crypto are, like, younger. Like, there there's the crypto, like, bandwagoners, but the people that are, like, crypto people, They're often, like, tech rooted, you know, very cyber smart, and they've somehow created an industry that is so rife with bank heists and and theft. But on the other side of that coin, the fiat currency world, a world that I would look to as like a dinosaur and, like, you know, like like crypto exists because the fiat world and the traditional banking sectors aren't the greatest solution. It's like VHS rental in a Netflix world.

Speaker 2: Totally. It's slow. It's costly. It's Yeah.

Speaker 1: There's a burst

Speaker 3: of loss.

Speaker 2: I get it. Yeah. I get the desire to look for an alternative.

Speaker 3: So maybe they just don't ever get reported, but, like, how many times can you think of in your last twenty years of your life that you've heard of a digital heist? Because money is numbers in a database table in the financial system just as much as it is in the crypto system. Yeah. So it's like, could the crypto system like, the like, this this theft by the Lazarus Group for $1,500,000,000 is the single largest heist that they've apparently ever had, but they're I saw just had the stat up. Yeah. Last year alone, they only got 1,340,000,000 out of 47 other attacks. So, like, when you look at it, like, the they did forty forty seven of these things last year. Like, I can't think of a single digital hijacking and digital heist from a traditional bank.

Speaker 2: Anywhere in that sphere. There's so much friction in those systems and so many redundancies. And, like, the thing that crypto does good is it bypasses a lot of really cumbersome expensive, like, transfer protocols, basically. It's just like sending money sucks internationally, and there's a lot of there's just more efficient ways of being able to do it. But that friction is also a redundancy. It's like, if you if you were to manage to move the the the numbers in the computer around, there's just a lot more of a safety net for catching it before it gets anywhere. Yeah. Anyone who's ever had a credit card stolen knows this to be somewhat at least true. There's redundancies. There's backstops. And those don't get lesser the higher up you go. The larger the sums of money, the stronger the redundancies are because they don't wanna piss off their big customers. They'll, in some cases, swallow the cost, which is kind of what we're starting to see with things like Bybit. They're reaching that level of institutional, like, capital that they can kind of, like,

Speaker 3: eat it,

Speaker 2: create redundancies and safety nets that most people couldn't. In this case, an unfathomably large loan and a one point, a $140,000,000 bounty to find the sons of bitches responsible. Like, it's it's just different, when you get to that scale.

Speaker 3: Yeah. Anyway, that just jumped into my mind.

Speaker 2: Oh, it's fascinating.

Speaker 3: We hear about the like, we've talked about this for, like, five years straight now. We talk about crypto heist because they're so common. This one's amazing because it's so big.

Speaker 2: Big.

Speaker 3: And essentially, like Yeah. It's like if we if we tried to make a single episode covering all of the digital bank heist in the traditional financial sector, I think we'd be like, I haven't done any research in this. This is all just

Speaker 2: I I know what you're saying. Yeah.

Speaker 3: But, like, I they never make the news. We never see them trending and headlining where it's like, it seems like every day there's another one about a crypto heist.

Speaker 2: Yeah. It's if we were to try and cover every crypto heist, we would have to go to a daily news show. We would have to become, like, the daily for cybercrime, and it would just be a churn. And the story would always be the same. And if we were to do one for every major traditional financial there's an interesting argue argument to be made that that sector like, the traditional finance sector has matured to a point where the heist is now sort of just rent seeking and, like, it's just it's like it's baked into it. It's like, no. The theft is taking place. It just doesn't you just don't have to put on a bandit's mask anymore. You can just you can just make your cash in different ways. But in any case.

Speaker 3: You I'm gonna take one more digression

Speaker 2: just to let

Speaker 3: you know the protocol. So that you mentioned money transferring, which immediately triggered in my head an article that I read. I think it was even this morning lying in bed, and it was about, remitly. Remitly. Remitly. You must have seen the TV ads for Remitly or on, like, sports feeds. Yeah. They're like a they're like a last time I was surfing in Nicaragua, we ran into the Remitly promotional team, like, eating lunch at the restaurant we were in. Like, they're, like, kind of a yeah. They're, like, they're, like, one of those apps.

Speaker 2: Some waves. And the guy asked me if I wanted to send money online conveniently across a 100 different currencies.

Speaker 3: Yes. Exactly. So this is not an ad for Ramily. This is any spot. But but but the,

Speaker 2: That's funny.

Speaker 3: But, essentially, they're one of those apps set up for, like, oh, you're a, you know, immigrant to North America. You have you make

Speaker 2: Oh, to send money sure.

Speaker 3: You send money home. Like, they're set up to do that. They charge, like, outrageous fees. Like, it's something like 12% processing fees or something. But anyway, so they're public, remitly. They're, like, the biggest. And, I read an article in investor news the other day. I can't remember who it was. Maybe it was Fortune Mag, that a hedge fund has now taken out a $4,000,000,000 short position in them because and this is the best part. They did a reverse image search on all of their reviews for their app, and it turns out that a majority of them are stock photos.

Speaker 2: Oh, no.

Speaker 3: So so so they're like, oh, these people are manufacturing positive sentiment in their reviews, which I'm sure happens in a number of companies. And all of the other people that have real photos hate them and are complaining about it. Like, we're gonna take so they took a $4,000,000,000 short position against them. Another random deviation, but I thought it was the way the way that they detected that maybe they should take the short position by, like, doing like, writing a piece of code to go through and iterate and then do a reverse search against stock libraries

Speaker 2: Yeah.

Speaker 3: To see how much of their reviews are faked, I thought was brilliant for, like, a

Speaker 2: Validating that fun. That suspicion of being like, I'm pretty sure this product it's like I've looked at this product. It seems really bad. I think it's really bad. All these reviews seem to think it's positive. I've developed a theory. Even still, the risk tolerance of being, like, a four Billy. I'm gonna I'm gonna put four bills on the line.

Speaker 3: We're pretty sure about this one, guys. 4,000,000.

Speaker 2: You you gotta go on a real publicity terror telling people that that product sucks because you people could go a real long time without noticing that. That's fascinating.

Speaker 3: Well, the then the beauty is too is, like, just the fact that it is such an interesting way to figure out that it maybe is not a great company. Like, I know they I think they had some major leaderships leave too, which is also triggering it. But I imagine this is getting a lot of press because it's an interesting way to be like, you know, we're shorting this company because they're lying to you.

Speaker 2: I just wanna very briefly loop back to we were talking about fiat heists versus crypto heists. It's 1,500,000,000. You you got the Razzlekhan and Dutch one in the billions. We got all these billion multibillion dollar crypto heist. I looked up the largest fiat heist of 2024, the Easter Sunday heist, which occurred in the early morning hours of 03/31/2024, just about a year ago today. They broke into a Garda World facility, which is like a private security firm.

Speaker 3: Stole ATM transfers or something.

Speaker 2: It's like $20,000,000.

Speaker 3: Yeah. Well, but but

Speaker 5: but here's the thing is

Speaker 3: that's still that's not even a digital heist. Like, the way that what I was talking about is like Right. There's been so many crypto digital heists occur. How many fiat digital heists? Like, I know that I can, like, people can take a gun and go demand money. Like, that happens. And that has happened for ever.

Speaker 2: For eons. Well, always has, always will. But I take your point. Moving the decimal in the computer, the the social engineering hack, but for for dollars and cents. Like,

Speaker 3: when is like, like, if we consider, like, all of the major crypto exchanges and companies that have fallen, like, show me the equivalent in Wells Fargo. Show me the equivalent in, you know, Hong Kong Bank. Like, show me, like, all of the massive banking institutions. You just don't see them. No. So it's like an interesting anyway, we can go to the ad oasis. But I just found it if people were spending so much time stealing crypto, like, what if they spend all that time stealing digital currency or, like, digital fiat?

Speaker 2: Seems a lot harder.

Speaker 3: Seems seems.

Speaker 2: We should probably tell folks about who the show is brought to them by.

Speaker 3: We should.

Speaker 2: I think it's brought to them by Push Security.

Speaker 3: Yeah. Push. The the guys at Push are great.

Speaker 2: They're fantastic. Great product. We like working them working with them, and we like telling folks about them.

Speaker 3: It's not every day that something comes along where I'm like, damn. I should have thought of that. How did I not think of that? And this is one of those products.

Speaker 2: Push Security is a hundred percent one of those products.

Speaker 3: The problem they're tackling is identity attacks. You know, we talked about it a little bit earlier in the episode. Phishing, credential stuffing, session hijacking, account takeover. Basically, the number one cause of breaches right now. And their approach? Well, it's pretty interesting.

Speaker 2: Instead of trying to lock down everything at the infrastructure level, they start where people actually work, which is inside of the browser. They built a browser extension that observes employees, creates corporate identities, and logs into their work apps, which when you think about it, makes a heap of sense.

Speaker 3: And because they've got that visibility, they can see exactly how the identities are being used. You know, are people using stolen credentials? Are they reusing passwords across them? Have they figured out ways to bypass and skip multi factor authentication? Are they using a local account so they should be using the single sign on authority?

Speaker 2: And the kicker is when they do find all those vulnerabilities, they can automatically enforce controls all right there, right in the browser.

Speaker 3: But it's not all just about protecting identities. Push or monitoring them too. In real time for attacks using adversary in the middle tool kits, clone login pages, which are becoming a big deal with AI because you can clone them very easily, stolen credentials, and stolen sessions tokens.

Speaker 2: It's endpoint detection response except all inside the browser.

Speaker 3: And the team, you know, obviously, we had Adam on, super sharp, killer research, red team backgrounds. They put out great research. They're just smart, great people. We respect them. We respect their product, and that's why they're our sponsor.

Speaker 2: Push Security. It's a super smart approach. It's a really solid team. It's interesting research.

Speaker 3: You should

Speaker 2: check them out. Go to pushsecurity.com to learn more. Starting something new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's gonna work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch, to brands just getting started, you can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button is used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shopify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot, and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, that's shopify.com/hacked.

Speaker 6: When you need to build up your team to handle the growing chaos at work, use Indeed sponsor jobs. It gives your job post the boost it needs to be seen and helps reach people with the right skills, certifications, and more. Spend less time searching and more time actually interviewing candidates who check all your boxes. Listeners of this show will get a $75 sponsored job credit at indeed.com/podcast. Podcast. That's indeed.com/podcast. Terms and conditions apply. Need a hiring hero? This is a job for Indeed sponsored jobs.

Speaker 4: This Father's Day, do more with dad and spend less with low prices guaranteed at the Home Depot. Get him fired up with a new grill and accessories, like the Next Grill five burner for just $299 so you can spend more time together while he becomes the grill master he was always meant to be. Or build memories with savings on top brand power tools so you can tackle projects side by side. Gift more and do more together this Father's Day with help from The Home Depot. Exclusions apply to homedepot.com/pricematch for details.

Speaker 7: Send help is now streaming on Hulu and Hulu on Disney plus.

Speaker 8: We're somewhere in the Gulf Of

Speaker 9: Thailand. Getting us out of here should be your focus. I'm your boss. You work for me.

Speaker 8: I'm not in the office anymore.

Speaker 7: It's bold, relentless, and endlessly rewatchable. Discover why critics give it 93% on Rotten Tomatoes. You're so fired.

Speaker 6: Oh, am I?

Speaker 8: No help is coming.

Speaker 7: Send help. Rated r. Now streaming on Hulu and Hulu on Disney plus.

Speaker 3: Are we vibing out yet?

Speaker 2: I think we're vibing. I think we're getting to vibe coding.

Speaker 3: Let's get to vibe coding.

Speaker 2: So there's this clip where if everything is as it appears of a Columbia University representative trying to decide whether a student built a piece of software to cheat on coursework or just to cheat on job applications.

Speaker 5: So when when you mentioned that there are some classes at Columbia that do teach some foundational lead code, either courses or topics. Could this software be used for those classes?

Speaker 10: You're never gonna be in a class where your data structure professor is on a one on one Zoom with you, asks you to share your screen, and then watches you, like, code up leak code. Like, that that's not a thing that at Columbia. So, yeah, like, I guess it could it could work, I guess. But, I mean, the the same way that if I made a new browser, then the new browser could be used to Google up questions. Like like, it would be just be such a roundabout useless way of using the product.

Speaker 5: But it could happen if a teacher did, like, choose to to do that with a student or or multiple students in the class?

Speaker 10: In the case where you are in a one on one Zoom with your professor and they ask you to share your screen to make sure that you're not looking at any solutions online, then, theoretically, yes, you could use a tool. But, like, to be frankly, it's it's my first time thinking about it being used like that.

Speaker 2: My backup. So there's this piece of software called LeetCode. EliteCode is an online coding platform primarily used for preparing for, like, software engineering job interviews. I have never had to use this piece of software, but I'm betting that both you and I, Scott, know people who have.

Speaker 3: Oh, definitely. I know a good friend of mine from Vancouver used it recently to prepare for job interviews.

Speaker 2: There you go. Big tech companies use leet code style problems in their hiring processes. It's like a standardized way to test coding skills. And because of that, a lot of candidates find themselves, like, grinding through LeetCode prep as they go into these job applications. It can be job prep. It can be training. But LeetCode's a big thing in that ecosystem.

Speaker 3: I find it to be, like, a self fulfilling prophecy. Like, when Google started doing this stuff, it was to see how you thought. Like, they would bring people in and give them abstract problems and be, like, solve this. And then they would literally watch you solve it. And they would see how you, like, broke down the problem, looked at the potential solutions. Like, even if you didn't get it right, they got a good understanding of, like, how you would tackle a problem in the real world. And now it's just turned into this ridiculous, like, LSAT cram session for software engineers where they just, like, have to be ready to answer all of these problems. Like, write me the pseudo code for Towers Of Hawaii. Like, okay. Here it is. Like, they know how to do it, like, off the back of their hand. Like

Speaker 2: Yeah. It felt like as I was reading and learning about it, it felt like sort of the, like, historical realization of this thing that started in the nineties. Like, Microsoft had those famous brain teaser interview questions.

Speaker 3: Totally. Yeah.

Speaker 2: And then you got Google in the February with, like, algorithm, like, whiteboarding questions, like, essentially math in front of us right now. And it's just kinda kept evolving and becoming more automated and more standardized. And LeetCode is kind of the, like, ultimate expression of that.

Speaker 3: The other thing I'm I will say is, like so a friend of mine that used this recently, he would talk to me between his interviews, and I helped him do a little prep and stuff. And it was like, the interviews now are nuts. Like, he had full day interviews where he had to go in and write code in front of the, like, lead software engineers, like, on a like, put him up on the screen and, like, watch him write code and use the IDE and stuff. And it's just like like I don't know when, like, twenty four hours worth of interview time became a thing, but, like

Speaker 2: Unpaid interviews that are in the. Yeah.

Speaker 3: Sure. So

Speaker 2: Yeah. So LeetCode, as I understand it, if you were looking for certain jobs in in big, big tech, that's typically what's standing between you and the offer in terms of both training and testing. And Roy Lee, the student in that first clip that we heard, does not like LeetCode. Quote, it made me hate programming. And he wasn't alone. This this comments are always anecdotal, but I sure found a lot of them that echoed that general sentiment of just sort of exhaustion with this system. Quote, lead code is literally tech companies telling you to spend months on something to make their interview process cheaper. Quote, lead code is the most useless way to test a dev. 99% of us will never use any of these algos in real life. And the last one I'll say here, oh, man. They're mad that we're using their method of wasting our time right back at them. That last one is foreshadowing. The shade here on leak code does need to be taken with a grain of salt as we will see some of this. There's a marketing component to this, but it's still a really fascinating story. So Roy is a software at Columbia. He's been grinding on LETCode prepping for these, like, FAANG interviews. He's doing exactly what we're supposed to do. He says he's putting, like, six hundred hours into this process, and he's just he's miserable going through this. LeetCode has anti cheat functionality in it, basically saying, like, you just you can't ask chat jippity to go do this for you. Roy hits a wall, and I'm speculating here, but I think given what he said about this story, I think this has some validity. I can imagine there's something profoundly demoralizing about grinding for hundreds of hours on these technical prep tests, when all you read about is about how AI is gonna destroy these jobs that you were currently applying for and have just trained for for the last four years of your life. Speak nothing of the fact that you know intellectually the software can solve the thing that it is asking you to do. Is that good? Is that bad? I don't know. I understand the idea that these companies want people who actually understand what is occurring under the hood of this code. You do not want a Vibe coder in a $500,000 a year software engineer position.

Speaker 3: They're all gonna be vibe coders soon.

Speaker 2: I know. It's complicated. It's weird.

Speaker 3: So so he so here here's the thing for me is that it's Yeah. Yeah. Yeah. It's like the origin of this was great. You know? When Microsoft was doing it, when Google was doing it, they were doing it to, like, filter out people. They wanted the smartest, the best, and the brightest, and they were willing to pay for it. They just wanted they just needed to figure out a way to find those people. And it's like, they don't want people that studied this and can recall it from memory. They want people that can understand it and figure it out. So all this has done is like, I kind of agree with this guy. This is like the entire sentiment of where this began is ruined. You've just turned this into a history exam. It has nothing to do with, like, how you think anymore, which is what the point of it was. Yeah. Was, like, we need people that can, like yeah.

Speaker 2: I'll talk to you.

Speaker 3: Take a big, big problem, break it down into compartmentalized pieces, solve those pieces, and solve the overall issue. And it's like, that's gone. And now it's like, these have structures. Like, there's training systems that will walk you through 247 of these puzzles explaining to you exactly how to solve them in the optimal way. And it's like, that's great training because you'll passively learn from that. But at the same time, it's like I don't know. The entire interview process to me is just kind of not as good as it used to be.

Speaker 2: It it that one comment I read, and again, it's a YouTube comment. It's it doesn't mean anything, but it seems apt. Leetcode is literally tech companies telling you to spend months on something to make their interview process cheaper.

Speaker 3: Mhmm.

Speaker 2: The efficiency of being like, well, if you just want us to know that you're kind of legit enough that we should look at you, spend hundreds of hours on this thing. K. Bye. It's like, oh, that you can see why that's a bummer and why some people might butt their heads up against it and maybe why Roy made the call that he's about to make.

Speaker 3: To to me, I I don't like, to me, we're already asking that. It's like, did you go to Stanford? Did you go to CompSci? It's like yeah. But but it's like you already spent thousands of hours on that training regimen. Like, what's another five hundred hours into something else? It's like it's just it's just it's essentially a certification. Like, they may as well turn it into a certification process, like a little post grad professional program. And when you graduate with your bachelor's in computing science, you go into this, you spend another five hundred hours, you get a certificate in, like, computer algorithmics. And it's like, here you go. You've passed. And now now you don't even need to do any coding exams at these places. They know you know how to do them. And it's like, they may as well just do that with it. It. Like they may as well just put it online.

Speaker 2: I'm I'm I'm not sure that they're gonna be able to given what is about to occur because it seems as though the gamification of that certification has been itself gamified. Royally decides to cook up a workaround And instead of continuing, like, the endless prep cycle, he builds a piece of software he called Interview Coder. This is what I was talking about earlier of the grain of salt that there is a little bit of, like, this is a marketing story for a piece of software, but I think it's pretty interesting. It takes a photo of what is occurring on the screen during the interview, runs that through a large language model that analyzes it, produces the correct result, and then feeds it to you outside of whatever computer that you're doing it on that has the anti cheat stuff on it and allows you to just sort of see the correct answer on the very edge of your peripheral vision and answer it and copy it. You can instantly process coding problems. You can figure out, like, the optimal solution to this question they've put in front of you. And because it's sort of because of that way that it works, it's operating undetected by this anti cheat software that LeetCode uses. He uses it, allegedly, on interviews with Amazon, Meta, TikTok, passes every single interview. This audio I'm about to play is from him, it seems, completing a Amazon job job interview and, getting a job offer from Amazon.

Speaker 9: So, what I would like you to do is to, write me, a data structure. So it will be like a class. So, which inside will do something with the data. And the idea of this class is that it will literally, find media. So there are two operations, add and get. And get He

Speaker 2: uploaded that to YouTube. I actually had to do a pretty a little bit of a circuit to get that audio because Amazon copyright striked it, which is what makes me think it's real. That is ripped from another upload under the name, handsome young Korean male hacks Amazon's interview process with AI reuploaded. And I enjoy I enjoy the I enjoy that.

Speaker 3: You know you know what the best thing is? It's like, this is I assume it's like, the interview process will change and adapt, and this will be this will be a flash in the pan. But, like, Roy's gonna get a real job offer out of this. Roy might have

Speaker 2: a business out of this. He's turning $60 a month for this.

Speaker 3: Yeah. Yeah. But that that's gonna go away. Like, I would assume. Of course. Of course. The the interview process will adapt unless he wants to stay like, this is, like, game cheating, but for interviews, if you consider interviews a game. But, like, he saw a big problem, compartmentalized it, figured out a solution, solved it Yeah. And was like, he's he he This

Speaker 2: is the whiteboard test.

Speaker 3: This is, like, hiring the whiteboard test. Yeah. Exactly. Like, Microsoft and like, you should hire this person. Like The,

Speaker 2: the aftermath of this was, like, didn't have that quality to it. It wasn't like a round of applause, flowers for the young man. Yeah.

Speaker 3: Sure not.

Speaker 2: It's like, no. They after it was crushing. Amazon rescinds the offer. Columbia got a formal complaint from Amazon and had that disciplinary hearing. Yeah. Roy dips. He just he leaves Columbia

Speaker 3: Handsome young Korean dips.

Speaker 2: Handsome young Korean male hacks and dips. He was scheduled for disciplinary hearing on March 11. I don't think he stuck around. I won't be a quote. I won't be on campus when Columbia wants to talk to me. And at the heart of this is this kind of question of, like, is the game that he was is the system he was trying to game already obsolete by the time he tried to game it? You kind of alluded to this earlier. It was, quote, LMS will make most human intelligence work obsolete in two years. Why should I care? I don't have time to work two years in a big tech job, or do I want to anymore? Is that are those timelines accurate? I don't know. But I get the sense it's almost like a doomerism feeling of, like, Yeah.

Speaker 3: Yeah.

Speaker 2: All anyone is telling me none of these jobs will exist anymore. The CEOs of these companies are telling us a lot of these jobs won't exist anymore. What what are we doing here?

Speaker 3: The the thing for me is like Yeah. Right now Yeah. Senior software engineers, people that can pass the whiteboard test off of just instinct, are more valuable than anything Because it's all of the all of the work that those people hate, the boring fill in the blanks code, these tools crush that. But it's like the here's a problem. Let's make a solution. And it's like the architecture, the problem solving, the okay. This there's nothing out there that does this. We need to create a library that does that. Like, all of the senior stuff still exists. The the the juniors like, my biggest fear is, like, we're gonna age out. Like, the senior devs, like me, and, like, you know, people that are in our generation are gonna age out because, like, even if you're a 27 year old grad few years out and you've been using AI for the last three years to optimize your development, like, the point's gonna come when, like, you're gonna be the senior.

Speaker 2: Right. And you don't understand what's going on under the hood quite as well as you maybe need to.

Speaker 3: The the thing the thing is, though, is that, like, I will say, like, as somebody who's been vibe coding as of recently, it isn't just letting the AI do stuff. Like, you still I don't know. That sounds so good. Getting you're transitively learning so much. Like, so I like, Jordan knows this and but the listeners don't, but I've been building, like, an open source app privately, and I'm gonna launch it whenever it's done. The, wanted to build something multi platform, OSX, Linux, Windows. So I started using Electron. You know, I talked about it with Atom. It's, like, kind of the the heart and soul of so many of these new Chromium, you know, kerneled apps. And, yeah, I'd never built anything in it. And I started doing some, like, build up research, but the research is so much more efficient when it's backed by AI. So instead of just googling and reading API docs, I just have a conversation with an AI. Eventually, you're like, hey. Generate me some code. You realize that there's problems in it. Right away, you learn more about the the interface, the stack, the every part about it. And it's like, so I'm actually on v five of this this product that I'm building because over the first four iterations, I was just learning. And it's like, even though I was utilizing AI to do it, like, for lots of things, research, bullshit code, things like that, but it's like you just passively learn. So it's like I still think people are gonna be Mhmm. Like, it's vibe coding is not just about, like, going to the beach and doing nothing and having it write everything for you. I think you actually do end up like, as somebody that is a senior developer, it's really great for me. If I was a junior developer, I don't know if I'd be learning as quick, picking up the intricacies and the the tiny details, the efficacies inside of the nuances. So so that that's I don't know. I guess time will tell, but man oh man is AI getting good at coding.

Speaker 2: It's for me, it's like a I'm I wouldn't go as far as say I'm agnostic on the tech, but the thing that concerns me is the, like, dependency concept. It's that when something pops off, it's great that you were learning while you're doing this. And I believe it. It's not just type in a prompt and get a piece of software back out. You're still developing software. But it's when shit pops off and something doesn't quite work and it can't solve it. Where is the actor in this situation that knows how to go in and solve things? You're you're you are increasingly reliant. And I don't think that's in a lot of cases, like, we rely on tools and technology all the time. I'm not gonna get into a big panic about that. A lot of engineers use calculators. That's fine. But I understand how it makes this trans transitory period of, like so so what is it I'm applying for? What is the job here? What is my career ladder look like when this technology is changing so rapidly and all of these threats are kind of in the ecosystem? It's it's a it's an odd moment, and it all kind of gets expressed right here in this little story.

Speaker 3: Well, the the shot I'd throw back is, like, that that that scenario where, like, AI can't figure it out. Yeah. I would actually contest that a bit because, like, when something goes wrong in code, it's either a logical like, the logic has failed somewhere, and there's nothing more logical than the AI compared to a human. Like, the AI wins that one. Check mark. It's often what it is is, like, some protocol changes or some API changes, and they just haven't they publish a new, you know, API, and it's like the old calls don't work anymore. That's often what's breaking things. But, like, but the nowadays, instead of me going to the API source and reading through their documentation, I can just ask an AI and it summarizes it instantly for me. It's like, oh, the version 1.4 changes, all the changes made to this, you know, CRUD operation for this and boom boom. Here's how the new context needs to look for the call. Would you like me to update it? Yes. Done. So it's like, I just just don't know.

Speaker 2: Like You don't you don't foresee situations where the concept of overrule and maybe that's it. The concept of overreliance on this doesn't really concern you.

Speaker 3: No. The concept of overreliance is gonna be what kills the industry. Okay.

Speaker 2: Yeah. I think I think we're saying the same thing here.

Speaker 5: Yeah.

Speaker 2: Yeah. Yeah. That's that's the the sort of not threats, but that's the thing I'm alluding to.

Speaker 3: The thing that I'm referencing when I talk about it now is, like, the AI is good at, here's the problem. Yep. Big and wide. I'm I'm doing this in video to Jordan and, like, compartmentalizing a small a big problem into a bunch of small things.

Speaker 2: Discreet steps.

Speaker 3: It's really bad at that. It can't go It's no. See, it can. But, like, if you can't just go to a thing and be like, make me this, and then it, like, loses the context of it sometimes. Some of the new AI's are much better with context. But, like, it it has a hard time solving a massive problem well. It it's really good if you give it the small boxes and you're like, hey. Figure out, like like, do this small thing. Write me the function that does this. Make sure that it's type checking, it's error checking, error handling. It's doing all of these things. It's great at that. But if you go to it and just type into, like, Clio or, not Clio. Clio said law software.

Speaker 2: Cloud.

Speaker 3: Cloud.

Speaker 2: So you have to

Speaker 3: say it. If you if you just go to cloud opus and be like, yo, make me this app. It'll cough you out a bunch of stuff. It starts to get confused halfway through. Like, it's not great. Like, I've had it be like, this is the directory structure that you want your app to have, and here are the files that we're gonna build. And then it will give me half of those files because it just forgets about it halfway through. Like, they're just it's just not great.

Speaker 9: So

Speaker 3: you still need somebody there to, like, put the pieces together.

Speaker 9: And

Speaker 3: the other thing I'll say is, like, if you ask it to do something, it often takes the cheapest route. That's the thing that I've been finding with it is, like like, make me, like, do this, refactor this to be more like this. It'll do it, but it'll leave off type checking, air handling. So you have to go back through and be like, hey. You know, this looks like it's gonna be, security risk and allow for SQL injection. It's like, oh, yeah. You're right. And then it, like, is like, here's how we can fix that. I'm like, well, great.

Speaker 2: I wish you had done it the but that to me feels like a feature, not a tool thing where it's like it's just like we this we have acknowledged that seven out of 10 times a developer will ask some question about security redundancy. So why don't we just bake that into the prompts? Like, bake that into the back end of how this thing works. And just over time, it's just gonna solve those those things.

Speaker 3: When I started this just this chat, I said, right now. And I'm like, there you go. Because it's gonna change.

Speaker 2: Yeah.

Speaker 3: It's gonna be better. Like, I know there was another article that I stumbled on. I think it was also in Fortune, about how, like, the Anthropic CEO, the IBM CEO, Metas, they're all talking about how AI is a, supercharging their development teams because it's, and I'll talk about that in a second because that's crazy. The state of of AI IDEs, wild. But, yeah, it's just it's supercharging their teams, and at the same time, it's gonna be replacing, like, junior devs. Like, they're just not gonna need as many because when you can get a senior developer who's got a four x output to what it's expected, like, because he's been or they've been, supported by AI tools. It's crazy. Like, the industry is in for a a rude, rude shock.

Speaker 2: There's like this this con hard, hard, hard tangent. It was like a it's a guy named Victor Turner who had this concept in sociology or anthropology or something that liminalities are the roots of, like, human discomfort. When we find ourselves strung between two different well understood states, that's when we're uncomfortable. It's the group of people that doesn't. You don't banish the person, and you don't put them in a cage. You make them live on the edge of the society. You just kinda put them over there, and that's what we don't like. And it feels like we're living in this liminal moment where, like, we're not we're not quite there yet. We haven't quite gotten to whatever this is gonna turn into, but we're no longer in the world we just came from. We're suspended in this point in the middle, and it is it's discomforting. It's a it's it's not a good feeling for a lot of people.

Speaker 3: But we're just in we're just in a new technical revolution, like like technological revolution. Yeah. Right in the middle

Speaker 9: of it.

Speaker 3: Right in the middle of it. Where it's like we we had this with computers. We had this with cell phones.

Speaker 2: Totally.

Speaker 3: You know, the mobilization of the workforce, the mobilization of communication. Like, do you remember, like, in your lifetime, you would have had, like, a house phone? And, like, when you went outside the house, you wouldn't have got a phone call. Yeah. Like, you would have had

Speaker 2: yeah. 100%.

Speaker 3: Yeah. No.

Speaker 2: But things that I didn't do when I moved out. And that was like it was like, okay. A transition had occurred. It had occurred in my mind before it had occurred in the minds of my parents type thing. But I'm not going to get cable. I'm not going to get a landline. I'm not gonna do

Speaker 3: all

Speaker 2: these things.

Speaker 3: You're a millennial wire cutter.

Speaker 2: Exactly. The transition had happened when I had the brain plasticity of a 16 year old and it was fine. But now I'm not and I don't and it isn't. Like, it's it's just different.

Speaker 3: Yeah. So so so this is just another one of those things. Like, we like, I think we talked about it before, but, like, the economic impact of, like, the mobilization of communication and instantaneous communication. So, like, email, replacing letter mail and fax machines. Even fax machines, technological revolution. You know, all of a sudden, we can send a letter across the world in four and a half minutes instead of four weeks. Like, that was like and this is the same thing. We're just further down the whole of the technological revolution. It's like, now we're at the point where it's like one of our premier, you know, wizardry jobs, the software engineers is is oddly gonna be the first thing killed by by their own creation. Sure. So it's like,

Speaker 2: yeah. What a time to be alive, Scott.

Speaker 3: What a time to be what a time to be alive. But as somebody who likes to build things Yeah. And doesn't like bolster The minutiae. It is amazing. The last couple of weeks, like, I've been using Versus Code or Visual Studio Code. Yeah. So I've been using some of their, like, extensions inside of Versus Code. And last night, I tried Cursor, which is like the which is like a a branch of Visual Studio code that's been, like, injected with AI malware. Like, it it is entirely well, no. No. I'm just, like, saying, like, it's inside the heart of the system. Like, you're it's not just Visual Studio Code with, like, a channel.

Speaker 2: Talking and pasting. Yeah. Right. It's like it's like, no. We've woven these things together on a foundational level.

Speaker 3: Yeah. Yeah. Yeah. AI lives inside of the your project. Yeah. So it's like and I have to say, and this like, this is not a paid ad for cursor, but it should be. Holy fucking shit.

Speaker 2: It's that big of a difference,

Speaker 3: It's like it's reading your mind. Like, you'll import a library into a file, and you'll, like, go to define the con like like, to import, like, a value and you go to use it, and it'll be like, is this what you wanna do? And it'll just show you the code of what you're about to write, and you just hit tab, and it's in your file, and you're like, holy fucking shit. Like, that's all I was, like, thinking.

Speaker 2: Cool.

Speaker 3: So immediately, I set us up a corporate account. So any of our devs are all have cursor licenses now. It's not cheap, but it's not expensive. And for, like, the kind of optimization that that could do, like, I couldn't even imagine.

Speaker 2: Strange.

Speaker 3: Yeah.

Speaker 2: Roy Lee. Saw it coming.

Speaker 3: Roy Lee will be just fine. He will end in some massive tech company or start his own. Maybe.

Speaker 2: Okay. I think I think that's another I think that's another one in the bucket. What do you think?

Speaker 3: I think that's another great episode of hacked podcast brought to you by Push Security.

Speaker 2: Push Security. They keep your identity safe in the browser where it lives, where we do all of our work. You should check them out. Pushsecurity.com. I like this one. We got a big old a big old crypto heist and a and a crazy job application hack. I found those fun. Appreciate you you listening. Excited to catch you in the next one.

Speaker 11: Lots of places can expose you to identity theft. Oh, no. That's why LifeLock monitors hundreds of millions of data points a second for threats to your identity, which is way more than anyone can do on their own. If we find anything suspicious, like new loans or changes to your financial accounts, we alert you right away, all through text, phone, email, or the LifeLock app. Get the alerts that could make all the difference. Save up to 30% your first year at lifelock.com/podcast. Terms apply.

Speaker 2: When I found out I was gonna be a

Speaker 10: parent, I immediately felt a lot of anxiety and worry. So I went on to BetterHelp to try to look for a therapist

Speaker 5: to help me with that.

Speaker 6: My relationship with my family and with my boyfriend and with myself were suffering. I really needed help.

Speaker 8: I was ruminating a lot. Really getting those thoughts out to a therapist and getting feedback was just life changing.

Speaker 2: Discover what BetterHelp online therapy can do for you. Visit betterhelp.com today.