[BidClub_]
Thread Guy · · 60 min

Inside the $300M Crypto Hack.. - Tom Kysar

Thread GuyTom Kysar

CryptoBlockchainFinanceTechnical
YouTube ↗
TL;DR
  • Tom Kysar’s core diagnosis is that the roughly $300 million–$350 million exploit was a failure of centralized cross-chain verification. A restaked-ETH wrapper relied on LayerZero’s default one-of-one validator configuration; LayerZero said compromised backup RPC infrastructure reported a fake bridge transaction, enabling unbacked tokens to be minted and exchanged for real assets through Aave within one transaction. “It works until it doesn’t.”

  • The damaging step was DeFi’s decision to accept a recursively wrapped asset as shared-pool collateral. Once the attacker could “hit infinite mint,” newly created tokens were deposited into lending markets, USDC and other real liquidity were borrowed out, and lenders were left holding bad collateral. Tom’s analogy is the familiar shitcoin rug—“the dev has infinite mint”—scaled into DeFi.

  • Defaults converted an ostensibly configurable security system into a single point of failure. LayerZero applications could appoint multiple decentralized verifier networks, but Tom says developers use defaults most of the time because many barely understand the configuration they deploy. LayerZero can therefore say the protocol behaved as designed, but Tom likens that defense to saying “the gun functioned as it should have” after someone shot themselves.

  • Somebody must absorb the bad debt, and Tom doubts existing reserves cover the entire loss. The unresolved question was whether holders on affected L2 deployments take the haircut or whether losses reach mainnet users; he read Aave’s statement as leaning toward L2 users bearing the loss. If the attacker is genuinely state-sponsored, he sees effectively no prospect of recovery or a white-hat bounty.

  • Hyperliquid carries a comparable category of bridge risk, but Tom ranks it far below the LayerZero configuration exposed here. HyperCore has a 12-validator network with staked validators, while its Arbitrum bridge—said by the host to hold about $4.7 billion as of April 26—uses a two-of-three multisig and holds USDC that Circle can freeze. It remains a centralized failure point, but the comparison makes it look relatively careful.

  • Tom expects a temporary liquidity retreat rather than a lasting break in DeFi demand. He cites a DeFiLlama post estimating roughly $15 billion exited DeFi in several days, yet predicts capital will return after several weeks as yields rise and users want leverage or dollars again. The specific one-of-one configuration may disappear, but “nothing really changes” because sophisticated losses remain socially distant from most market participants.

  • The episode’s longer-term conclusion is that repeated failures increase the premium on simple, durable assets—and redirect serious participants from trading toward building. Tom’s deliberately bleak maxim is “everything’s still kind of centralized,” whereas Bitcoin’s virtue is that it “does nothing” and has survived long enough that the U.S. government could not simply shut it down. His practical end state: hold assets unlikely to go to zero, build something with equity and genuine value, and stop expecting to trade your way to hundreds of millions.

Digest · the substance, structured for research

1. Gas.zip was built demand-first, with its trade-offs left visible

  • Tom introduces himself as the operator of gas.zip, a bridge optimized for small transactions, broad chain coverage, instant delivery, and low cost. Those priorities necessarily carry compromises.

  • His product philosophy came from “10 years building shit that nobody ever used.” This time, he wanted first to solve a problem for several thousand people and only afterward “back your way into” the technically sound solution, accepting some rounded corners around decentralization.

  • That background matters because Tom is not speaking as a reflexive LayerZero critic. Gas.zip has built on LayerZero, and he describes himself in broad terms as “a LayerZero guy” and even “a LayerZero shill”; his conclusion that the incident was “pretty bad” is therefore an insider’s break from alignment.

2. One default verifier allegedly became an infinite-mint authority

  • Tom’s reconstruction begins with a restaked-ETH wrapper whose name is uncertain in the discussion. LayerZero supplied the messaging layer that authorized burns on one chain and corresponding mints on another—functionally, Tom says, “the mint authority” or “the admin key.”

  • LayerZero applications can choose multiple decentralized verifier networks, or DVNs, to attest that a cross-chain action occurred. The exposed configuration used only LayerZero itself: “You can compromise one, you got it.” The theoretical multi-validator system had become a one-of-one trust assumption.

  • Why choose that setting? Tom’s answer is that developers often deploy repositories without understanding every embedded configuration. Defaults dominate behavior: “You put a default in—90% of the time people are going to use the default.” For roughly three years, that shortcut appeared fine.

  • Tom contrasts this with an Ethereum staker, who can be slashed for lying. Here, he sees no comparable economic penalty when the verifier is wrong—only “oopsies, like sorry, $350 million”—despite its authority over an asset backed by hundreds of millions.

3. Compromised fallback infrastructure turned fake collateral into real withdrawals

  • According to the account discussed, LayerZero’s primary RPC nodes were DDoS’d, causing verification to fall back to two backup nodes that LayerZero said had been compromised at the root level. Those nodes allegedly returned a fabricated block indicating that hundreds of millions had been bridged from a source chain when no such transfer occurred.

  • The frightening part for Tom is not merely a buggy contract but apparent access to “core internal infrastructure.” If an attacker could control private fallback nodes, he says, they could potentially do much more damage.

  • The false message greenlit an unbacked mint of the restaked-ETH wrapper. The attacker did not need $300 million to create it and theoretically could have printed far more; the protocol created units indistinguishable from the legitimately backed supply.

  • DeFi composability completed the exploit in the same transaction or block. The attacker deposited the fabricated wrapper into Aave, borrowed USDC or other real assets against it, and extracted the value before anyone realized what had happened. The lending pool retained the unbacked wrapper as collateral.

4. Aave’s shared collateral pool absorbed the wrapper’s failure

  • The host asks whether individual lenders affirmatively approved this obscure collateral. Tom distinguishes isolated markets, where lenders can refuse exposure to assets such as restaked ETH, from shared pools that permit multiple collateral types; he believes the affected Aave exposure largely sat in shared pools.

  • His analogy is counterfeit USDC: an unlimited minter could exchange bogus units throughout DeFi before detection, leaving every protocol that accepted them with a deficit. Here, the wrapper itself was not wholly fictitious; the exploit created additional units without adding the backing those units represented.

  • Aave therefore faces bad debt rather than a reversible bookkeeping error. Tom notes the existence of reserve or security funds but doubts they cover the entire amount, leaving a “massive loss” that users must absorb somewhere.

  • At recording time, loss allocation remained unsettled. Tom interpreted Aave’s statement as suggesting affected L2 users might take the haircut while mainnet users were protected, but he repeatedly hedges that the final treatment had not been decided.

5. LayerZero’s technical defense does not resolve responsibility

  • LayerZero’s response, as Tom characterizes it, is technically defensible: applications were warned not to rely solely on LayerZero, and the protocol processed a message signed by its configured verifier. Yet his gun analogy captures the missing accountability: saying the mechanism worked correctly does not answer why one compromised signer could authorize catastrophic issuance.

  • Banteg’s proposed path—get every involved party into one room—resonates because the public responses had become legalistic. The parties involved appeared to be preserving their defenses and pointing elsewhere rather than establishing who had accepted which risk.

  • Tom broadens the critique beyond one provider. LayerZero, Wormhole, Axelar, and comparable interoperability systems ultimately depend on small validator sets or multisigs attesting that an event happened elsewhere: “We don’t have decentralized cross-chain messaging. It just doesn’t exist yet.”

  • He says LayerZero OFTs have around $15 billion of value in them and thinks WBTC is an OFT. Wherever one authority can create cross-chain supply without corresponding value, the same basic drain remains possible.

6. Stolen money is easier to identify than to recover

  • Moving the proceeds from an L2 to Ethereum can involve a canonical withdrawal with a roughly seven-day delay. Once on mainnet, large hackers often seek Bitcoin’s larger liquidity through routes such as THORChain, then may attempt obfuscation through CoinJoin-like systems or offshore centralized exchanges.

  • Scale is the attacker’s problem: hundreds of millions are easy to identify, and it is difficult to move or off-ramp them. Tom’s hypothetical response if he had stolen the funds is telling—return them for 10% of the real money—because he does not know a clean way to realize the full value.

  • State sponsorship changes the recovery calculus. An opportunistic teenager using AI might panic at the prospect of jail and return a $3 million exploit for $50,000; if the actor is genuinely Lazarus or North Korea, the speakers see no realistic prospect of a white-hat return. The funds may instead sit untouched for years awaiting better privacy technology.

  • Thread Guy says major hacks now appear every two or three weeks, compared with every couple of months in the past. The attack spectrum includes both sophisticated groups spending months compromising infrastructure and inexperienced users pasting contracts into ChatGPT and asking it to “make the money come out.”

7. Hyperliquid’s bridge is centralized—but comparatively legible

  • HyperCore itself, Tom says, is maintained by 12 validators with stake that can be penalized for malicious behavior. The distinct vulnerability is the Arbitrum deposit bridge holding essentially the USDC represented inside Hyperliquid, secured by what he understands to be a two-of-three multisig.

  • The host cites approximately $4.7 billion of bridge TVL as of April 26. In principle, the multisig could move it arbitrarily; in practice, Tom credits communicated procedures, suspicious-activity pauses, and the fact that stolen USDC can be frozen by Circle.

  • Tom’s conclusion is deliberately relative: the bridge risk “absolutely” exists and is not ideal, but it ranks low among his current crypto security concerns.

  • Thread Guy calls Hyperliquid “one of the best bad implementations of security that we have today.” The pair use a car analogy: an ordinary Chrysler can look like a Rolls-Royce until the real comparison arrives. Hyperliquid has not achieved trustlessness, but juxtaposing implementations reveals which teams have treated their centralized choke points more seriously.

8. DeFi will forget the loss, but veterans will remember the lesson

  • Tom remains structurally bullish on DeFi because crypto may persist as an asset class and holders will still need basic financial infrastructure to borrow against digital wealth. The users hit here were generally sophisticated participants, not ordinary newcomers casually onboarded through an app.

  • He cites a DeFiLlama post estimating $15 billion had exited in several days, then predicts the familiar reversal: “Give it four weeks,” let yields rise, and capital seeking leverage or income will return. LayerZero may eliminate one-of-one signing, but replacing it with two-of-three mitigates rather than removes centralization.

  • Thread Guy says ETH appeared indifferent while AAVE and LayerZero sold off partly because directional traders saw bad news and “slug[ged] a short,” not because the broader community was hedging direct losses.

  • Neither speaker had seen anyone on their timeline admit losing money. Tom guesses perhaps 1,000 users. Thread Guy speculates that mid-sized liquid funds may have supplied the capital while chasing 6% ETH yields, and asks who supplies hundreds of millions to thin L2 pools with only hundreds of visible users. During DeFi summer, he says, that anonymous liquidity sometimes turned out to be Alameda, which ultimately was not as sophisticated as assumed.

  • Personal exposure determines collective memory. Thread Guy says he still remembers a DeFi-summer rug in which he lost roughly $10,000. Friends who lost money on FTX still rage about it; a loss borne by unfamiliar leveraged holders becomes another “war wound,” even though “money leaving the casino isn’t good.”

  • Repeated incidents nevertheless shape long-term allocation. Tom argues that Bitcoin’s simplicity—“Bitcoin doesn’t do anything, and that’s what I like about it”—limits its functionality but also its attack surface. Its resilience is established by surviving long enough that the U.S. government could not simply shut the network down.

  • His career advice follows the same risk reduction: hold durable assets, then create value in something you own. “You’re not going to trade your way” to immense wealth through intraday longs and shorts; the better path is to build a business or project whose equity might eventually be worth billions.

Verification Notes

The transcript is uncertain about the wrapper’s exact name (“rsETH or whatever,” later “rswETH”) and the source chain (“Duty Chain[?]”); the digest uses “restaked-ETH wrapper” and avoids naming that chain.

Full transcript
Thread Guy

Dude, I'm happy you came back on. I knew you came back on with no notice, too, which is awesome. You're one of my favorite—honestly, one of the sickest guests ever. You came on about 6 months ago. I consider you, honestly, a good friend at this point. Great comms on the crypto side. Do you want to give a quick intro on who you are, and then let's hit what the fuck just happened in DeFi? What is the future of DeFi? We'll get there.

Tom Kysar

Yeah, for sure. My name is Tom. I run a bridge called gas.zip, mainly geared toward smaller-value transactions, but with really high chain coverage. We're a bridge very similar to the Relays of the world today. We're focused on instant delivery and very cheap transactions, with a lot of tradeoffs. This is kind of what you get into with what happened with LayerZero today.

I spent a lot of time in my life building crypto stuff that literally nobody ever used. This is a lot of people's journey: I spent 10 years building shit that nobody ever used. This time around, it was very much like, "I want to build something that maybe some people will use," and afterward you can back your way into making that technically sound solution. I feel like that's how a lot of the apps people use today went with this generation's approach. Build something that first solves the problem of a couple thousand people. The corners are going to be rounded. Is it decentralized, like the Trump stuff?

I do bridging stuff. I did prediction markets for a long time. I mostly sit around and read Twitter all day, but bridging has been the main thing for the last couple of years. We've built stuff on LayerZero, right? Traditionally speaking, I'm a LayerZero guy. In a broad stroke, I'm a LayerZero shill.

That doesn't mean the stuff that happened today—or this week—was, for lack of better terms, pretty fucking bad. Plus, it's going to be fucking bad next week.

Thread Guy

Talk about it. I'll be honest: I was not online this weekend, and now I'm catching up. Some of it is all over the place. We had back-to-back incidents. We had Drift, which I know is kind of a fake DeFi label, but it got the label, and I think it was exploited for $300 million. Then we have everything that just happened over the weekend.

We can skip the Drift one. I think that's been debunked. That was just piss-poor management, some social engineering, and a little bit of everything. But there's this broader, secular terror—this terrifying fear around DeFi exploits and hacks. At the same time, we have what just happened with LayerZero.

Can you give us a breakdown of what just happened, how $300 million and some change was exploited—correct me if I'm wrong on that number—and then let's dive into the specifics of what DeFi looks like from here.

Tom Kysar

Yeah, so this was kind of the dark underbelly. This was the classic FUD that you would fearmonger about not only with LayerZero, but with a lot of DeFi protocols. It was one of those things where we all knew this wasn't ideal. It was kind of the worst fear that nobody really thought was going to happen, but we all knew could happen.

Thread Guy

Yes.

Tom Kysar

It pretty much all boils down to this: for lack of a better term, particularly in bridging, I have a saying that Roger Ver is like, "Everything's just kind of a scam, man," right? All this stuff kind of works until the scam doesn't work anymore.

What happened here was essentially that LayerZero is the messaging-verification provider for this wrapped Ether token. I don't even know what this wrapped Ether token is—rsETH or whatever.

Thread Guy

Yeah, yeah, one of these, like, rsETH. I don't even know what it is. I don't—I really don't understand it. Dude, I stopped once we got 2 or 3 loops down the restaked ETH.

Tom Kysar

Okay, okay, okay. But essentially, they act as the authority for minting and burning this token. LayerZero protocol will validate messages that say, "Burn some tokens over here, re-mint them over here." In shitcoin terms, they're the mint authority; they're the admin key.

LayerZero is designed in a way where validation of those messages should and can be done by many people. That's what the DVN is, right? Normally, when you say, "I have 1 ETH over here and I want it over here," there should be 3 or 4 validators in the middle that all agree on this process. However, the default in LayerZero is actually just LayerZero sitting in the middle.

Thread Guy

Just 1.

Tom Kysar

You can compromise 1. You got it.

Thread Guy

Yeah. That was the issue. LayerZero is designed in a way where the application gets to choose who those validators are. However, the default setting is just 1, and it's just them. This is why people aren't really super happy with LayerZero's answer, because LayerZero's answer is basically, "We told you not to just use us as the validator. You can go and put more validators in there."

Thread Guy

And is it cheaper, more efficient? Why do you just use LayerZero?

Tom Kysar

The real thing is, we built stuff. I think most people don't even fucking know how to configure the stuff they built. You don't even really know. It's just built into the config. You don't really dig into it and start understanding what's happening there. You start to comprehend all these different configurations that you can make. But even just building a simple application on top of these protocols, you probably don't even really fucking know what's happening there.

Thread Guy

Serious?

Tom Kysar

No, it's like you just deploy these repos. You might know what you're doing, but it's the default. It's the thing with everything, right? You put in a default, and 90% of the time people are going to use the default. They don't really know, and they don't really care. For the most part, it's been fine. In LayerZero's defense, the last 3 years have been fine.

This is how a lot of this stuff works in crypto. It's kind of centralized underneath it all, and we obfuscate it along the way. It works until it doesn't. At the end of the day, there was a wrapped asset backed by hundreds of millions of dollars that could be minted and burned arbitrarily by LayerZero—1 singular validator key running somewhere—with no security.

If you lie as an Ethereum staker, as a node participant in the network, you get slashed. You stake your ETH, and if you lie, there's a penalty. That doesn't exist here. This is just LayerZero lying. They didn't lie; they were wrong. There's no penalty for doing it. It's just, "Oopsies. Sorry—$350 million. That's it."

There was $350 million of backed liquidity that could be minted, or could back the minting, of this restaked token. Somebody somehow figured out how to compromise the singular LayerZero validator and say, "Mint 300 billion of ETH to this wallet." It got checked, greenlit, and went through.

Then those tokens don't even need to be backed by everything. They could have printed a billion of them. Once you get those tokens minted, they're used as collateral in Aave and all of these DeFi systems.

Thread Guy

God, you get these tokens—what do you do with them? You throw them into Aave and cash out USDC or something.

Tom Kysar

This is why Aave is now in a world where all the real money's gone, because they just printed a bunch of—

Thread Guy

Because if you're a lender on Aave, you're approving all this random shit. What even is it?

Tom Kysar

If you accept this weird wrapper token as collateral in all of DeFi, and I can just print this weird collateral token, I go and swap it out in all these DeFi systems for the real money. I give you this token that is backed somewhere, but that minting wasn't backed. I hit infinite mint on the token and swapped it out everywhere.

Thread Guy

Is it on you as a lender to approve this random restaked ETH token, or does that whole system just recognize this as Ether?

Tom Kysar

It depends on what pools you lend into.

So this is like—I think the ones that got hit in Aave were shared pools. If you go to a lending market, they'll have things called isolated lending pools. We've started moving toward some of these, where, when you're a lender, you essentially say, "Yeah, I don't want someone to be able to give me rswETH as collateral off my real dollars." I believe most of this was shared.

But this is how DeFi would work: if DeFi just blows up, imagine somebody could just mint USDC, right? The USDC would be worthless, but they could use that USDC to exchange USDC across the whole system.

Thread Guy

Exactly. And if at any point there's ever some exploit, before you could catch it, you could run to a DeFi platform—Aave—and borrow against it fast, get money out, and then they can't force you on-chain to return it.

Tom Kysar

And even—I mean, yes. The actual reality is that it happens in the same transaction, right? It's like—

Thread Guy

This happens in a single block. You didn't know what happened. It's like these guys mint these things. Okay, so somebody finds an exploit on LayerZero where they can basically mint—

Tom Kysar

What LayerZero said happened was that they compromised their RPC provider. The scary part here is that LayerZero runs nodes, and they connect to an RPC in your wallet. You have fallback systems: when a node isn't available, you fall back to another one, and another one.

They said essentially their good nodes were DDoS'd and turned off, so it fell back to 2 backup nodes that they run. The backup nodes were apparently compromised at the root level. This is the part I was kind of like—this is the scary part of the whole thing. LayerZero's core internal infrastructure was compromised somewhere here.

If this is true, their private internal nodes were running, and somebody was able to get in there and essentially put in a fake block. It said that this block happened on Duty Chain[?]. That's how they compromised the node to report that somebody bridged $35 million—or $350 million—from Duty Chain[?], and that didn't happen.

The terrifying part here is that the core infrastructure of this protocol was compromised at some root level. If you have root access to LayerZero's infrastructure, I would think you could really do some damage. There was a hole somewhere in LayerZero's infrastructure, and North Korea got in there, or whoever. How does this happen?

This is the first time we've really seen an attack like this, where they say, "I compromised your node provider." Even think of you—you just use your wallet, right? What happens if your RPC provider lies to you? It's terrifying. But that's what happened.

Thread Guy

Somebody said that you DDoS LayerZero's RPCs, and there are a couple of backup ones that you figure out how to get control of. There's root access, where you only need 1 validator from LayerZero, and you figure out if you can convince this validator, "I'm [__]." Generally, you convince this validator that you've greenlit the transaction, and you can mint $300 million and some change of this rswETH—double- or triple-restaked ETH—to your wallet.

In the same transaction, you send it to Aave, borrow against it, and pull out cash before anyone even realizes what happened. You have $300 million in cash. Bottom line being, you don't even know what happens, because it's like—

And whose money is this? Your money. The pool of capital—not on Aave, but the pool of capital to mint the $300 million in ETH—where does that stem from, or is that just—

Tom Kysar

It's like you're just creating a new asset. There's no money required. You just create $350 million worth and then borrow against it.

Thread Guy

How does that get created?

Tom Kysar

There was no—I mean, you know, there is backed restaked ETH of this that exists in the world.

Thread Guy

It isn't backed. This is just new added capital.

Tom Kysar

Yeah, this was just minting the shitcoin. This was just, "Mint the shitcoin," and—

Thread Guy

Got it. So basically, they minted a fake token that isn't worth $350 million, but they were able to borrow $350 million against it. The lenders are out $350 million in cash.

Tom Kysar

Oh, yeah.

Thread Guy

Aave gets destroyed because $350 million just went to something that was not real and bypassed their system, basically. They have rswETH in exchange for it now, which isn't worth anything because they just created it out of thin air. So what does Aave do? What's everyone looking at now?

Tom Kysar

Aave has what's called bad debt in the lending system, right?

Thread Guy

Yes.

Tom Kysar

And it's never good. They have reserve pools—an insurance reserve pool, like a security fund. I don't think it covers this. The broad story is that there's going to be a haircut. People are going to lose money.

Now they're debating where that haircut comes from. Does it come from people who had this wrapped ETH only on L2 chains? Does it come from people who had this ETH on mainnet? This hasn't been decided yet, I believe.

But Aave made a statement the other day that kind of leaned in the direction that the people on the L2s are probably going to be the ones to take the haircut, and that the mainnet users probably shouldn't be the ones who have to eat this loss. There's going to be a massive loss that has to be eaten somewhere, right?

Thread Guy

It's the users' money.

Tom Kysar

Yeah, that's the thing. This is what happens when you exchange real money for a token. It's not that the token was garbage. It's that you're trading coins, and the developer has infinite mint.

We have all this stuff in place to hopefully make it so the developer can't use infinite mint, or that the developer won't use infinite mint, or that it can't happen. But it still exists.

LayerZero—the DVN of all these OFT tokens, these wrappers and stuff—the interoperability network is the developer. We try to make it so 3 people need to agree before infinite mint can happen, but in a lot of these cases, it's just 1 of 1.

Thread Guy

Really?

Tom Kysar

There's no decentralized cross-chain bridging. All of this stuff—LayerZero, Wormhole, Axelar—it's all the same thing. It's a couple of validators, or 1 in this case. The terrifying thing is that we don't have decentralized cross-chain messaging. It just doesn't exist yet.

We all obfuscate it, and whoever obfuscates it the best has the best interoperability protocol today. But LayerZero is a multisig validating messages that happened over here and happened over here. You put all this stuff on top of it, and it becomes an interoperability network, but it's the same thing as you sitting there and saying, "Yep, a transaction happened over here. Yep, a transaction happened over here."

Thread Guy

Sorry. If it needed to talk natively, so—

Man, tell me this. I saw this post: how does the hacker get the money off-chain? CEXs won't take it. You can't lend it anymore. You're stuck. You can't off-ramp at all. What do you do?

Tom Kysar

It's hard. If you had hypothetically hacked $300 million, what would you do with it?

I would try to return it for 10% of the real money. I don't know how you get that money out. I really don't. But if you get it on L2, you can canonically bridge some of it out, which is the 7-day exit back to mainnet.

Thread Guy

Explain that.

Tom Kysar

You have money on Arbitrum and you want it back on Ethereum. This is the slow withdrawal, essentially. The money that the hacker has in ETH exists somewhere—in the Arbitrum bridge, or wherever it is.

The real issue is that once you steal such a large sum of money, it's hard to do anything with it. Even if you have it all in something like mainnet ETH, it's still really hard.

What you see today with large sums is that they try to get it to mainnet. Once you get it to mainnet, they try to get it to Bitcoin, because Bitcoin is the largest asset. Bitcoin still has tumbling pools, right? What do they have—CoinJoin, whatever.

Thread Guy

This is like, say something gets hacked and they shove it all into THORChain, right? And then—yeah, yeah, yeah. All right. Because the pool of BTC money to launder your money in is much larger than the pool of ETH to do that in in the world, right? But still, I don't know how—I mean, I would be led to believe there are still effective ways to do it, considering North Korea still does this.

I mean, Bithumb, you know, I think they laundered like a billion dollars with the Bithumb hack, right? And most of it has actually gone through THORChain. A lot of it is just these shitty centralized exchanges, because offshore CEXs, right? Shove it through KuCoin, shove it through whoever.

But then I don't know, because at some point, when you have such a large pool of stolen money, it's hard to hide it. You can't—it doesn't matter, right? You deposit it—

Tom Kysar

Take it, right? No one's going to take it. It's really easy to identify. You know, and this is—I don't know. Maybe North Korea has some nuclear bomb suppliers that just take their Arbitrum ETH directly. But in reality, I imagine they probably try to start laundering it, but a lot of the time you see the money just never move. They'll just sit there.

Thread Guy

Just sits there and you just [__] jerk off to it. Yeah. Show it at the club. When they used to arrest really early guys who'd steal a lot of Bitcoin on the dark net, blah blah blah, they would never move it. They'd arrest them 5 years later and talk to them, and they would be like, “Yeah, I didn't really do anything with it.”

And their bet was just to hold on to it. In 20 years—

Tom Kysar

Something would happen. There would be some new crazy Zcash or Monero, blah blah blah, and they would be—you know, they just sit on it forever, right?

Thread Guy

But I don't know if they've started trying to launder the money yet or move it around. Assuming this is actually what they think—a Lazarus, North Korea-esque, state-sponsored actor—I mean, there's no recovery there, right? There's no chance of this money ever coming back. There's no chance of a white-hat bounty. That just doesn't happen, right?

Sometimes you get lucky if it's some [__] kid who was just [__] around with AI and stole your protocol's $3 million. He's like, “Oh [__], I'm going to go to jail for that. All right?” And he's like, “Give me $50,000 and I'll give it back.”

But this is scary because we think there's some security around the wallets that hold our money, and that security just doesn't really exist. We don't really know, right? Even with EVM stuff, it should be the most secure. The contracts are verified, they're reused all the time, and everyone can read this stuff and figure out what was happening.

Then you go to all of this—this is my long-tail, bear Solana ecosystem case—where nobody knows what the [__] any of this stuff is doing, right? We don't even know what's happening on Ethereum, and Ethereum is open source, reused, audited, and everyone can read it. With Solana, nobody can even read most of this. Nobody knows what's happening, and that's probably playing in its favor right now because it makes it harder to attack.

But I can only imagine how many [__] exploits exist out here. Nobody can read this [__] yet. Nobody knows how to use it yet. If stuff like this is still happening with EVM contracts and systems that have been public and reused for many years, and we still find new problems every day, the more complicated you make something, the more it becomes security by obfuscation. That's not a good security method, right?

At some point, I don't know. I don't know how any of this Solana stuff works. I've no [__] idea. I don't think I've ever read a Solana contract. I don't know where I would read it if I wanted to. On Etherscan, I can go read contracts and kind of see what's happening. I have no idea with Solana, and that's good because it means there are a lot of people who can't easily go and attack it, right?

But at some point, I don't know. All this stuff is [__] terrifying, man. The fact that we put our money in this [__] is absolutely terrifying because a lot of it is safe, but do you have any idea?

I don't have any idea. You put your money in some DeFi thing, some app, possibly some perp exchange, right? Who the hell knows what's happening there? You don't read this stuff. I don't read this stuff, right? And the more complicated it gets, the more it's not a problem until it kind of is.

Nobody ever talked about the fact that LayerZero was secured by one validator. Nobody talked about this. It was there. A bunch of people knew it, and we all kind of knew it existed, but nobody ever talked about it.

Some guy made a good point: they onboarded this collateral on Aave and looked at the onboarding application. It was never even brought up that they were adding collateral that could be minted arbitrarily by one key that might be in LayerZero's basement server. It was never even brought up.

There's a lot of existential risk that exists in all of this. All things considered, we're probably pretty lucky to the extent that we've been. The hacks are bad, and we have all this stuff, but I think there are terrifying problems that exist out there that just aren't happening yet.

It takes well-resourced, dedicated, sophisticated attackers. That's kind of what you're seeing today with these North Korea-esque groups, right? That probably took these guys—I don't know how you even compromise LayerZero's core infrastructure—but this is the kind of thing that probably takes many months. It takes a lot of money, a lot of resources, and a lot of effort.

On the flip side, we've had a couple where kids just put a contract into ChatGPT and say, “Hey, can you make the money come out of this and give it to me?” Occasionally, it just happens.

Combine all of this together, and putting your money in contracts is honestly a terrifying proposition. All of crypto is kind of a terrifying proposition when you start to think about it, and we're giving everybody the tools to really poke at it today, right? This is why we see a hack every 2 or 3 weeks now. It used to be once every couple months that you would see a big hack.

Maybe? Big, big one every cycle.

Tom Kysar

And they're kind of the same thing. The Drift thing was functionally a centralization issue, right? It was somebody who had the authority to make these admin decisions.

Thread Guy

Social engineering type of thing. Yeah.

Tom Kysar

A [__], yeah. Whatever being compromised, it boils down to there being a single source, key, or person in the system that has the power to make these decisions. Their dev has an admin key, and you've been there: your coin is going up, and then the dev mints a bunch of it and rugs the pool. It's the exact same thing, but with DeFi protocols, right?

Granted, I think the TL;DR is that this one is not coming back, for sure. I think Wormhole was something kind of similar 2 or 3 years ago, if you remember, when Wormhole had a $5 million hack.

LayerZero's response is that the protocol acted and behaved as it should have, which isn't wrong. But it's also kind of like, “Hey, you shot yourself in the face, but the gun functioned properly. It functioned as it should have.”

Because it's true: LayerZero behaved as it should have. This validator validated a message. It's just that the message was fake.

Banteg had a good model a couple hours ago, and I think this is the way it's going to go. He said something along the lines of, “They should get everybody in the room together.” As of right now, everybody is not taking blame, talking in very legalistic terms, and lawyering up.

I think that's what's happening right now. Everyone is terrified of, “Was this my fault?” And nobody is sure who's under the gun for this.

Thread Guy

Is it like—no, is it whatever this Ether thing is? Who knows. But I think this is such a large amount that I don't think anyone's really going to take blame. It's not good either, because everybody's pointing their fingers at everybody else.

I have one question I have to ask you. I don't really want to ask it because I'm scared of what you're going to say. What happens to Hyperliquid here? This is the terrifying thing too, right?

Thread Guy

Take the Hyperliquid take. Just do it. Just do it. Just do it.

Tom Kysar

No, I mean, Hyperliquid is much better in the sense that HyperCore, the chain, does have this 12-validator network. There is a network of validators maintaining and running HyperCore, and these validators have a stake. If they behave maliciously, money will be taken from them. There's a cost.

The scary thing about Hyperliquid is the bridge. The Arbitrum bridge, when you deposit money into Hyperliquid, is still a multisig. I think it's a two-of-three multisig. How much money is in that bridge? This is the joke that Arbitrum became: the purpose of Arbitrum is just to be a bridge into Hyperliquid. There's a contract on Arbitrum that has billions and billions of dollars—essentially all the USDC that exists in Hyperliquid.

That is a multisig. Granted, from what we know about it, it's not anywhere near the same thing as what just happened with LayerZero. It's not like it got exploited because a single key existed on a server in someone's basement and North Korea got in, which is kind of what happened here.

The Hyperliquid multisig is, I think, two-of-three. They've communicated some of their procedures for how the multisig will interact. It can go into a paused mode if something looks suspicious. All things considered, it is a somewhat sounder deployment of this. At the same time, there is a multisig somewhere that can arbitrarily steal all of the money out of that bridge. That's its existential problem and concern. It's nowhere near the single-key scenario, but functionally, it's still a multisig.

Thread Guy

As of April 26, the Hyperliquid bridge holds approximately $4.7 billion in TVL.

Tom Kysar

If you steal it, you would get USDC. USDC is freezable by Circle, so it's a less desirable asset to steal because Circle can freeze those coins. But you would still steal it all and try to siphon it out for Ethereum as quickly as you can across all this stuff.

In a broad stroke, the Hyperliquid bridge being a two-of-three multisig is low on my list of modern crypto security concerns. Does the risk exist? Absolutely. Is it great? No. It's not something that—

Thread Guy

That's it if that happened, right?

Tom Kysar

It doesn't have to keep me awake at night. I think there are a lot of other things that are more relevant and higher on my list.

Thread Guy

What's relevant and high on your list? What's the biggest thing that's high?

Tom Kysar

Honestly, it was this kind of stuff for a while: interoperability and bridging, because a lot of tokens use these token standards today. LayerZero's is called an OFT. It's like an ERC-20, but it allows the token to burn and mint on all these different chains between each other.

Exactly what happened here is going to happen in many other cases, where you can mint a token when you shouldn't be able to. That token is now worth a lot of money in all these other systems, and you can clean all the real money out in exchange for it.

Pretty much every interoperability protocol has this risk. I think LayerZero's OFTs have around $15 billion of value in them. I think WBTC is an OFT today. Wrapped Bitcoin is one of these things, and they all have this same security model.

There is functionally some level of centralization in the world that is the authoritative validator of this supply being created and destroyed. If you can get it to create value without that value actually existing, this is what you get. Interoperability has been my biggest fear for a long time, and I think that's where a lot of the value resides.

The boiled-down version is that our biggest risk is centralization being exploited, much more so than a contract having a bug. Bugs happen. Our biggest risk is building systems where you or I have the authority to control the system more than the average person or regular participant, and then being compromised by a bad actor.

Underneath all this, we want to get to a point where everything is decentralized and trustless and build these good systems and services. Functionally speaking, it's still very early with a lot of this. That's the dark secret of the room that nobody likes to talk about: everything's still kind of centralized.

Thread Guy

That turns into a new problem, right? All right, it's two of the guys. It still exists, but you'll solve the root-level problem.

Okay, give me a take on this. One of the last things I want to ask you—by the way, thank you. Terrifying, but thank you. What happens to DeFi from here?

Tom Kysar

I don't think DeFi is going anywhere. I'm a big believer that DeFi wins in the long run. I don't think it wins to the extent that everyone expects, but I think DeFi wins in the sense that crypto will be a persistent asset class in the future.

There are people like me, probably like you, who are going to keep most of our life's value in some digital system, service, or asset. The ability for us to borrow against these assets and have some basic level of financial infrastructure that we can use—that's where I think DeFi wins.

I don't think DeFi ever dies. The average user didn't have his money staked in restaked Renzo ETH and then put into Aave in a loop. These are sophisticated people taking a loss here for the most part. They are average people and average DeFi participants, but this isn't some guy onboarded through an app and stacking DeFi easily.

My actual answer is that I don't think anything happens. This happens every couple of months, and we forget about it in 2 weeks. Everyone shrugs it off.

In the short term, DeFiLlama had a tweet saying that around $15 billion had exited DeFi in the last couple of days, proactively. So, in the short term, there will be a lot of capital that leaves. But give it 4 weeks. Yield starts going up a little bit, there are things people want to buy, and they want to start lending and getting some dollars back. It slowly makes its way back in.

You ever go on Rekt.news and look at the leaderboard of all the hacks of all time? I think this is another war wound that will go on that list. How many times has something changed? The last time you lost $500 million, nothing changed. Literally nothing. What will change in practice is that LayerZero is no longer signing one-of-one DVN messages, so this exact problem probably doesn't happen again in the future.

Even if it's now two-of-three, it's a new problem. All right, it's two of the guys. It still exists, but you'll solve the root-level problem. No, I don't think anything really changes.

In reality, everybody forgets about it because it's not their money. I'm going to forget about it, and you're going to forget about it, because it wasn't us. Did you lose money in FTX? I have friends who lost money in FTX who still wake up every morning, say a prayer, and hope Sam Bankman-Fried gets drone-striked that morning. They still hate him because they lost money.

The average person who lost money in FTX still feels it and remembers it. None of us really feel this. I would actually love to know how many unique people in this wrapped ETH lost money, but it wasn't me.

Thread Guy

It’s not you. It’s not a lot of these guys on our Twitter feeds, right? We all kind of shrug it off and forget about it because, well, it wasn’t me who lost the money, right? But when something happens and you lose money in it, you remember. I’m still thinking about the rugs I got scammed in during DeFi Summer, right? I still think about that. A guy scammed me for $10,000 or whatever.

For the most part, when it doesn’t affect the larger participant group of us, we tend to shrug it off and forget about it, right? That’s reality. It makes sense, right?

Tom Kysar

Even with the FTX thing, I didn’t lose money in FTX. There’s a very real scenario where I could have; I just didn’t use FTX. I have money in Coinbase. I know it’s not exactly the same thing, but I do have money on Coinbase—not all of it, but the majority of it. You know what I mean?

If $300 million were lost from Coinbase users tomorrow, this would be something like an FTX event that had long-lasting effects, because we would all be affected by it and it would suck, right? Rather than—I don’t know. I honestly think it was probably 1,000 people who lost money in this. I don’t know what the unique token-holder count is in that.

Thread Guy

Good take. I’m just here wondering, you know, trying to gauge the severity of the situation. The only thing you can really do is watch the market. ETH doesn’t really care. AAVE is down, as expected, but it trades like shit anyway. LayerZero is down, but it’s down because you and I see this stuff and we’re kind of like, “Oh, this can’t be good for AAVE. Maybe I’ll just go slug a short on it,” right? It’s not like we’re hedging our risk because we lost money in AAVE’s lending market or whatever. No, it’s mostly just directional shit traders who are like, “Oh, bad news—go short the asset,” right?

But it doesn’t really... Yeah. This is the bold take: there’s actually so much slosh of money in this system that we can lose $300 million and we’re kind of like, who does that actually affect? Who are these guys? I honestly don’t even know who a lot of them are. Who puts $300 million in this market?

Tom Kysar

Good question. Who are these guys? Who are you? Why are you doing this?

Thread Guy

Who are you? I agree. Sometimes I go on DEX Screener or pull up the Celo chain. It’s a chain—you know it exists, but you’ve never used it in your life and never seen it. Go look at the DEX pools. There are $200 million in these DEX pools. Who are you that you’ve put $75 million into some mid-tier L2 that has 300 users, and you just keep $100 million there? I don’t know who these people are, right? But it’s sure not me, it’s sure not you, it’s sure not any of us.

Who triple-restaked their ETH and then borrowed against it recursively in Aave? Some sophisticated friends I know made a lot of money. I’m not doing that shit. I’m not doing that shit. A lot of people do that, though.

It’s actually a good take, Tom. I’m not going to lie. This is actually optimistic. I don’t know if they’re institutional. The actual answer might just be these mid-sized funds. You see these mid-sized liquid funds and stuff, and they have $100 million. They’re like, “Oh, I want to get my 6% yield on ETH,” so they put it in here, borrow against it, and make some shitty angel investments or whatever.

All I know is this hack happened. I haven’t seen a single person on my timeline who’s like, “Fuck, I lost money.” I haven’t seen one. No, I haven’t seen one. I’ve seen people saying, “Fuck DeFi.” I haven’t seen one person say, “I lost money.”

Tom Kysar

Me either. Who lost the money? One of these people, right? And then we just kind of forget about it, and it’s like nothing really changes. I don’t know.

Thread Guy

This is kind of why things never really get better either, you know? There are some soldiers out there who constantly come back in and put hundreds of millions of dollars into these systems and take the blunt force of a lot of this.

DeFi Summer—this was Alameda. Alameda was debt-pooling with $300 million cash on-chain, right? You would go sell this yield-farm token and you’re like, “Who the fuck put $150 million in this shitcoin LP pool that launched yesterday?” You look, and it’s Alameda. You’re like, “Oh, they must be sophisticated and know what they’re doing.” Then you come to find out, no. It was Caroline and Sam Trabucco just like, “I don’t know. Put some money over here. We sell the shitcoin, and we don’t really hedge the stuff.” They didn’t know what they were doing either, right? Ultimately, they were the ones that would eat the loss.

And what was the end result of that? Alameda blowing up. These were the people capitalizing a lot of these very large on-chain pools of money, right?

Tom Kysar

[Snorts]

Thread Guy

But the number can be really big and really bad, which is kind of what happened here. In no light is this a good event. It’s not good for anything either, right? In a broad stroke, money leaving the casino isn’t good. Regardless of whether it’s your money or somebody else’s, money leaving is bad, right?

Tom Kysar

Of course, of course, of course.

Thread Guy

Money leaving is bad, right? But at the same time, it’s a lot worse when it’s all of us. It’s a lot worse when the group chat gets—when you go on Twitter, in your GC, and everyone’s just like, “Holy shit, I lost money.” That has much worse ramifications across everything: the vibe, the sentiment, everything.

We’re going to forget about it next week. That’s just the nature of the beast right now, right? Some things will change, some security will get better here or there, et cetera, right? But the optimistic take is that the active participants around here—I don’t think any of the ones who lost the money are going to affect the vibe a lot, right? I don’t think this kills the vibe. Is that good?

Tom Kysar

Yeah, it’s not going to cover FTX.

Thread Guy

Am I even going to cover it today? No one’s talking about it. It’s over. It’s kind of... I don’t know. This is the part that gets me: I don’t know if that’s a good or bad thing. I really don’t, right?

Tom Kysar

What does that mean, exactly?

Thread Guy

Part of losing $300 million is that it’s a really big thing. This is a world-changing, huge thing, right? And we’re just kind of like, does it really matter? Does it matter? I don’t know, because I know it matters when the 5,000 people who actively use all of these apps and products in crypto lose money. We all get pissed, our sentiment goes back, and we stop trading, making things, trying new things, and experimenting.

Here, it’s just a large loss, but is it going to change how you or I—or anyone reading this—is going to behave tomorrow? It’s not going to change how I behave tomorrow, really. It changes how I view things long-term; I want to build things in crypto, but tomorrow I’m not going to do anything different in crypto because this event occurred, right? I don’t think most people are either.

So you can just poof half a billion dollars out of the ecosystem, and it’s like: who did it affect? Who did it matter to? Is it going to change anything? In this case, I don’t really know if it does, right? It’s an interesting thing to cover. It’s a big event, but at the same time it kind of feels like shit to say, but it doesn’t matter. I don’t know. Does it matter? Are you going to not trade something tomorrow now?

Tom Kysar

No money’s leaving Hyperliquid. Yeah. The good in this is that it’s favorable for a Hyperliquid-type thing. Even though Hyperliquid has these decentralized multisigs, you look at that now, and even though it is a potential central point of failure, you look at that in comparison to the 1-of-1 DVN that LayerZero was running with all this value, and it makes Hyperliquid’s 2-of-3 multisig look really good, right?

It makes it look like all these guys know what they’re doing. Functionally, it’s still not great, but it really does. The shills will say it, right? They’re like, “The team is great, and they put care into the thing,” and you don’t really see that until you put it side by side with something that’s really shit.

Thread Guy

Yeah, yeah, yeah, fair, right? It’s like Hyperliquid is the least of my...

Tom Kysar

You say a Chrysler 300 looks like a Phantom until a Phantom pulls up?

Thread Guy

What? Sorry? Oh, yeah, yeah—Chrysler 300.

Tom Kysar

A Phantom pulls up, and you're kind of like, “Oh, actually, yeah.” Maybe you're looking at a used 2009 Rolls-Royce Ghost. Can I tell the difference between a 2009 Ghost and a brand-new one? Not really—until you sit inside, right?

Thread Guy

Right. Yeah, yeah. I like Hyperliquid. I think it's one of the best bad implementations of security that we have today, and that's a really good thing for—

Tom Kysar

Good. It's a good thing. My summary with all of it is, I used to literally have a sign on my wall in the yacht that said, “Everything is a scam.” Everything here is just a scam, and the best things put a bunch of extra stuff on top of it to confuse you and distract you from it just being a scam underneath it, right?

The only thing that's actually really decentralized is Bitcoin, functionally speaking. Everything else is kind of shit. You boil it all down, and there's security and centralization risk in everything, except for Bitcoin, give or take. Some show more than others, and anytime this stuff happens, I'm just kind of like, “Are you surprised?” Not really, right?

Everything is kind of a scam. Even with Ethereum, you can pull together all the validators today. Solana's validators are all in a goddamn Slack chat together. Even with Ethereum, if you said, “If we needed to get all the main validators together, we could probably do it in 20 minutes,” everything's kind of a scam.

I don't know. This is a long process, and it's only solved by crypto surviving forever. Bitcoin was a scam until we all woke up one day and realized, “Oh, the United States government couldn't shut down Bitcoin even if they wanted to.” They just couldn't. It's beyond their control. It's penetrated the world so deeply that you can't stop this thing, right?

That only happens by Bitcoin existing for 10 years and not dying. That's what will happen with Ethereum, Solana, and some of the other ones that persist and survive. You win by not dying over time, but you have to not die in that process, essentially.

In the meantime, it's all kind of a fucking scam still today, right? If somebody really fucking cares and has billions of dollars, they could crush almost any of these crypto products out of existence. Ethereum, Solana, whatever—any of these things.

Nothing is safe. This is the round loop, and I'm not there yet, but I still think about it occasionally. It comes up in my mind more every day: everything just leads back to you being a Bitcoin maximalist at the end of the day. At some point in all of our careers, I think we all just go back to being Bitcoin maximalists.

Because you still have this stuff where you're like, “What are we doing here, man? There's a fucking fee that controls 300—what is this fucking thing? Why did this exist? Why are we doing this?” You're like, “Oh, you know what? Actually, Bitcoin doesn't do anything, and that's what I like about it. It does fucking nothing, but that's what makes it good.”

North Korea can't come in and mint a bunch of fake Bitcoins. That makes Bitcoin kind of fucking useless. There's no Hyperliquid for Bitcoin. But at the same time, it's safe and secure, and it means something. All roads lead back to being Bitcoin maximalists at some point in our lives.

That's a terrifying thought because I really don't wish that upon myself, but at some point I think we'll make a new generation of Bitcoin maxis. It's going to take a while. It took those Bitcoin maximalists 10 years, right? But it's also terrifying because these Bitcoin maximalists are some of the little fucking assholes. They're the worst people I've ever seen.

Thread Guy

[Laughter.]

Tom Kysar

They're the worst. The vibe isn't there. It's just a fight with people, man. You want to be Jimmy Song on Twitter, like, “Oh my God.” These people are just—no. Luke Dashjr is a permanent underclass. Put me in a trailer, brother.

[Laughter.] He's Luke Dashjr, right? He's a Bitcoin Core developer. But if you were to ask, “You want to be Luke Dashjr?” you're like, “Yeah, no, never. Absolutely not.”

This is one of those times where, if you really sit and think about it for the next week or whatever, enough of these things build up. These are the events that help anyone who seriously works in crypto and considers it their career and profession mold and create their long-term thesis on the technology, for lack of a better term.

You'll see enough of these, and in the long run, this will shape your view of how you value decentralization and security, where you place your assets on-chain, and stuff like that. It shapes how you think about all of this in the long run.

It takes a lot of these kinds of things to get people to a good end conclusion. It's personal; it's where you feel comfortable. Does it affect you? No. In the long run, when you see 15 of these, at some point this is what gives you your opinion on security, decentralization, and the value of all of this.

Who knows? At some point, you might have $500 million in some lending protocol because you got super on-chain rich, and then the values of this stuff are different to you than they are to the Pump.fun shitcoin trader. You suddenly care about the security of the oracle and the lending markets.

Even if you care about it, it's a good learning experience, and it's good to understand what happened here. I think we're all good to understand what happened, but at the same time, forget about it. It's not really going to affect anything, and we're all going to forget about it next week.

Thread Guy

Honestly, Tom, that was the most beautiful closure of all time. I agree with you, by the way: all roads do lead to Bitcoin. I got to this at the end of 2025, and I was so sick of the game that I loved turning into a disaster with the memecoin stuff. I was like, “What am I doing? This is just the worst. I hate this.”

So you full-port into Bitcoin, pay some of it in taxes, keep what you can, buy more when you can, and fucking get on a podcast and call it a day, right? That's it.

Tom Kysar

This is like a second- or third-generation conclusion most people come to. You were like, “Actually, the best way for me to accomplish what I want to accomplish is to hold some assets that I believe essentially aren't going to go to fucking zero,” which is Bitcoin. You forgot about it, and now you have expertise in this field and vertical.

Instead of trading your way to a billion dollars—you have to make and build something, have a bunch of equity in it, and build that project or that thing. At some point, you're just like, “Yeah, I'm sick of getting rugged. I'm just going to hold Bitcoin and try to build something. Maybe someday I can sell this to somebody for billions of dollars.”

That's the road everyone eventually makes their way to. This is how the traditional world works, too, right? You're not going to trade your way to the big dollars.

Thread Guy

Not to be fair. No, you're really not. I don't think I've ever met anyone who just traded their way to even hundreds of millions. That's tough.

Tom Kysar

Yeah, tough—unless you were fucking buying $2,000 of Bitcoin at a couple hundred bucks.

Thread Guy

Yeah, if you bought and forgot, it happens, right? But have you ever met someone who's like, “I made $300 million trading on Hyperliquid this year?”

Tom Kysar

Long-short, intraday? No, no, no, no. Not really, no. I was like, don't do money. That's kind of the M.O.: go and do something where you're creating value in something that you own, right?

That's what this is for you. We have a startup. You have equity, right? That's the best use of your time. It's no longer Pump.fun trading 24/7.

Thread Guy

It’s you do your own business. Tom, where the fuck did GoPro go? You’re like our resident hack guy now. I guess you’re the resident hack guy moving forward.

Tom Kysar

I mean, sometimes I care, sometimes I don’t. This one was bridge-related, so I was like, “Okay, I’ve got to ruin it, you know?” Actually, what the fuck? I had such a good analogy. I saw a TikTok yesterday, and I had a really good analogy of how this came through. I was like, “Oh, there was a really good analogy of what happened here using some fucking video.” I can’t remember. I remember—

Thread Guy

You— it’s insane. Well, you said this last time. What’s my voice?

Tom Kysar

It’s nuts. The chat was all talking about your voice. Do you do speaking gigs or commentating or anything?

Tom Kysar

Nope. Nope. I have no— I’ve done nothing.

Thread Guy

It’s incredible.

Tom Kysar

No, I’ve literally done nothing. It’s weird, too, because you’re like the third or fourth person to say that—or people have said that in the last couple years. I don’t know. I mean, I’m like 30. Maybe I just hit puberty and my voice dropped finally.

Thread Guy

I fucking love your voice, Tom. I can listen to it all day, I’ll tell you what. Our resident hack debunker, Tom. This honestly, this is sick. Thank you for coming on. Thanks for your time. Thanks for staying for a while, dropping some fucking gems on us. We appreciate you, dude.

Tom Kysar

Of course. Thanks for having me. Let me know if I can ever fucking talk. But yeah, thanks, bro.

Thread Guy

We’ll do it again at some point. Hopefully not super soon in the case of the hack, but hopefully soon in the case of a W guest. You’re the man, dude. Later, bro.

Tom Kysar

All right, peace out, man. Peace.

Thread Guy

I fucking love that guy. Oh, wait, I want to find your TikTok. How good is he?