The Two Biggest Issues In Crypto Today | Weekly Roundup
Jason YanowitzSantiago Roel Santos
- Santiago Roel Santos de-risked to cash going into Q4 and is now redeploying — under 10% so far — into equities down 30-50%, explicitly not tokens. He holds Google ("it's a monopoly... I don't think they're going to be unseated"), Western Union, and ServiceNow, and tracks a "crypto-enabled businesses" watchlist of Klarna, Robinhood, and Figure. His accumulation logic: nobody catches the exact bottom (few bought Solana at $8 despite the call), so "you buy at 20 and then 15 and 12 and 8" because "we're a tweet away from the market ripping again."
- Rob's macro pushback: the market is still pricing some chance of a quick resolution. There is no direct US-Iran negotiation (messages via the Pakistanis), oil is near $120, there has been no equity capitulation yet, and a Hormuz supply shock would feed inflation and hurt rate-cut prospects — "if you're trading the short-term market right now, I don't think you can be in the market at all... you get paid four and a quarter to just sit on treasuries."
- The "crypto VC mass extinction" is consolidation: hit rates are collapsing toward traditional venture just as the easy token exit disappears. Santi's frame: "You could invest in anything at the early stages and the token would launch" — now a few funds raise huge and "everyone else is going to die." Santi sees 5-10 crypto companies a month offering to sell themselves, and estimates "80% of the crypto data companies have tried to sell in the last year or two."
- Venture's playbook has flipped from hunting the new thing to piling tens of millions into runaway winners like Rain and Polymarket. Moats form and break faster than ever, so once Ramp-vs-Brex-style separation appears, you concentrate; Carta data shows the median of the top 10% of seed deals at ~$120-125M valuation, up ~2.5x in a year, while sensible crypto seeds price at $20-25M — with hot-topic exceptions (pre-revenue stablecoin rounds at $50-100M+).
- Crypto token secondaries are generally in the 80-90% discount-to-spot range — and spot is already below the last round or even the Series A — the widest Santi has ever seen. At a 90% discount he flips: "I'm now a buyer at that level of certain projects... price is the single determinant of returns. Historically tokens just don't go to zero." Jason disputes 90% marks for many of the names he surveyed, while Santi says liquid names can still find buyers around 60% discounts; past the top ~30 tokens, however, "there's probably not a buyer for the vast majority. Today."
- The Drift hack — ~$280M drained in 12 minutes from a Solana perps DEX with ~$500M TVL — was primarily an operational-security failure. A worthless token (CVT) was wash-traded into oracle-accepted collateral, 30+ pre-signed durable-nonce transactions were staged, and a security-council multisig had been lowered to 2-of-5 with no time lock. It followed the Resolv Labs ($50M USR) and Stakehouse incidents; Jason's response: "I'm not keeping any money in DeFi right now."
- The real vulnerability is people: "The vast majority of hacks happening today are social engineering," and nobody audits team ops the way they audit code. Jason's quant tallies ~$1.1B in 2025 DeFi losses ex-Bybit and $350M this quarter alone, while Aave stablecoin yields sit below treasuries — "you should be paying 30% APY, not 10 or 8" for looped composability risk. Jason used Mike's tweet to frame the two biggest issues as transparency around security and tokens, which he said may be 12-18 months from being solved.
- Google's quantum paper cut the qubits needed to break wallet cryptography 20x (10M → 500,000), pulling the threat timeline toward maybe 2029 — and Jason predicts a contentious Bitcoin hard fork this year. There's no post-quantum Bitcoin address format yet (BIP 360 is only a proposal, and rushed code "might create a catastrophic vulnerability in the same move"), and coordinating a leaderless community evokes 2017's block wars. "Once again Nick Carter was right."
1. Santi rotated to cash in Q4 — now nibbling equities, not tokens
- His setup: he de-risked heavily going into Q4 — "I just don't think I'm getting paid enough to take this level of risk. Everything's all-time high" — without foreseeing the Iran war; now less than 10% of that cash is redeployed, "nibbling at names I like that are down 30 to 50%": Microsoft -24% YTD, Google -20%, Meta -17%. Equities only, no tokens, and "not jumping out of my seat" — he doesn't think they've bottomed.
- Actual positions: Google ("I feel really comfortable owning for multi-year periods cuz it's a monopoly"), Western Union, ServiceNow. His watchlist theme is crypto-enabled businesses — Klarna, Robinhood, Figure — to see how stablecoins and tokenization transform them, plus Better Homes for its facility with Sky.
- The accumulation logic, via Solana: Jason publicly called $8 "a generational bottom," but "how many people do you think actually bought at eight? You still would have done well if you bought at 20 and then 15 and 12 and 8" — because "we're a tweet away from the market ripping again."
2. Rob's macro pushback: no capitulation yet, treasuries pay you to wait
- Rob's caution: "I don't know if it's as easy as Santi is making it out to be." There's no direct US-Iran engagement — messages pass "through the Pakistanis" — oil is back near $120, and last night's press conference gave him "no confidence whatsoever" this ends soon. The market rushing back on any good news tells him people still expect quick resolution, which means capitulation hasn't happened.
- His chain: Hormuz supply shock → inflation working through → "bad things for potential rate cuts" → macro challenged the rest of the year. "If you're trading the short-term market right now, I don't think you can be in the market at all... you get paid four and a quarter, four and a half to just sit on treasuries." Long-horizon buying of secular-tailwind names is the one thing both agree you should be doing.
- For founders, the Lux memo (initially misattributed to Index) is the template: bake in far more conservatism — everything costs more, and capital markets "certainly aren't as open in crypto."
3. Venture's new game: spot the runaway winner and pile in
- Rob's lesson from a deliberately slow year (the fund took ~12 months to raise; ~14 months deploying): "It is easier than ever to be an entrepreneur... easier than ever to get disrupted really quickly. It's harder than ever to get a moat" — so when someone pulls away, they pull away faster. His examples: Ramp leaving Brex behind, Rain's month-on-month growth still accelerating at scale. Dragonfly has put tens of millions into a few proven names, Polymarket among them.
- The same dynamic runs through tradfi: one fund he spoke with went from $4B to $26B AUM in five years on a single early foundational-model position headed for a "trillion dollar plus IPO." Rob's twist — his job doesn't change: to beat Lightspeed and Ribbit in stablecoins and neobanks, he still has to live with seed companies to know early which will win.
- They use OpenAI as a sentiment check: Santi notes its $122B round, while Jason points out that the timeline had been saying Claude was pulling away and OpenAI was dead. Santi's conclusion is that "the timeline is more wrong than it's ever been... it's like a negative signal these days," partly because "everyone's a content creator" with Claude or ChatGPT whipping out posts.
4. The crypto VC mass extinction is consolidation, not collapse
- Santi's core frame: "Crypto was easy on a relative basis for venture for a long time. You could invest in anything at the early stages and the token would launch." Now failure rates are up, VC hit rates are falling toward traditional-venture norms, and with too much capital in a not-that-big industry, "it has to consolidate to the few that are [making money]... you're going to see a few funds raise a bunch of money... and everyone else is going to die" — the Andreessen-raising-$15-18B pattern, at crypto scale.
- Santi from the trenches: five to ten crypto venture-backed companies a month offer to sell themselves to Inversion ("What am I buying here?"); "80% of the crypto data companies have tried to sell in the last year or two"; two of his portfolio companies closed shop the day of recording; acquirers buy the equity and deprecate the token, as with Tensor.
- The active-management corollary: if you weren't in prediction markets, perps ("one perp really" — Hyperliquid) or stablecoins, "you should be looking at yourself." Santi's nuance: Lighter hasn't performed like Hyperliquid, but it's still worth $800M and plenty of investors are up a lot.
5. Seed is bifurcating: sensible pricing next to hot-topic froth
- Santi just did a seed at $20-25M that "would have been probably 40-50 a year or two ago" — sensible, if the team is smart. But Rob sees an AI-crypto crossover deal — "really kind of a seed, maybe they're calling it an A" — getting done in the hundreds of millions against fundamentals worth "50, 60 million bucks," plus pre-revenue stablecoin seeds at $50-100M and a pre-revenue second round above $100M happening right now.
- Carta data (all venture, AI-skewed, median not average): the median of the top 10% of seed deals is now ~$120-125M valuation, up roughly 2.5x in a year — "everyone's piling into the things they think are going to win and ignoring everything else." Rob himself just personally invested in a company's first round at $4B.
6. Token secondaries at 80-90% discounts — and Santi flips to buyer
- Santi's OTC survey of quality, venture-backed tokens (launched within a year, pre-first-unlock, teams and investors on one-year cliffs): discounts clustered in the 80-90% range to spot — and spot is already below the last round, sometimes below the Series A. "I have never seen that big of a discount" — historically 60% was where a buyer could hedge on perps and "almost categorically" not lose. Non-venture names have no bid at all. Crypto-equity secondaries are far tighter: a company raising at ~$4-4.5B trades secondaries around $2.5-2.7B, roughly 40% off.
- The flip, after a year of token bearishness: "At 90% discount I'll buy that thing. At that point price is the single determinant of returns... historically tokens just don't go to zero. I will flip — I'm now a buyer at that level of certain projects."
- Jason's dispute — he's an investor in four of the ten names Santi quoted: "I'm almost certain I can sell them for a lot less of a discount than 90%..."; Santi adds that liquid tokens with a positive outlook can find buyers at 60% discounts because they can be hedged on perps. His hierarchy: maybe 5-10 tokens people really like, another 10-20 they're constructive on at the right price, and "after you get past 30 tokens there's probably not a buyer for the vast majority. Today. There will be in a bull market."
- Jason's blunter read: "People have written off tokens as an investable asset class right now... except for maybe 10 of them." Santi's rebuttal from the tape: ex-Bitcoin ($1.3T of a $2.3T total circulating market cap) there's still more than $1T of liquid value and $107B in 24-hour volume — willing buyers exist.
7. The unresolved fight: is volume a proxy for what people actually want?
- Santi argues that most volume is market-maker and quantitative activity rather than a clean measure of what people like. Market makers participate where they expect soft flow, while other traders pursue volatility, basis, hedging, and cross-venue or cross-chain arbitrage. He notes that perp volume is down 60% since October.
- Jason pushes back on the funding-rate logic, raising base funding rates of roughly 10.95% and arguing that market makers can trade perps even without a directional view. Santi disagrees, and Jason moves on: "We're not going to get to the bottom of it. I'm moving us forward."
8. Anatomy of the Drift hack: ~$280M in 12 minutes
- The mechanics as Jason reconstructed them: the attacker created a worthless token (CVT), seeded a liquidity pool with a couple hundred dollars, and wash-traded it until price oracles treated it as real collateral. Then, using Solana's durable nonce feature — transactions that can be pre-signed and held indefinitely rather than expiring in minutes — they staged 30+ withdrawals and parameter changes in advance and fired them in sequence, draining ~$270-285M from a perps DEX holding roughly half a billion in TVL.
- The enabling failure: weeks earlier, Drift's security-council multisig had been lowered to 2-of-5 with no time lock. Santi's read on the compromise: one signer "got hacked, essentially," and somebody else blind-signed. The attacker then changed the admin key entirely and locked the team out — nothing could be frozen — after two audits had passed the protocol. Jason: "Why did you remove the time lock? It makes no sense."
- The pattern that alarms him: Resolv Labs was hacked ~a week or two earlier ($50M in USR via a compromised AWS environment), and Stakehouse's front end pointed to a wallet drainer two days prior. "I'm not keeping any money in DeFi right now. I'm just not. It's just not worth the risk."
9. The attack vector is people, not code — start auditing the ops
- Santi's thesis: "The vast majority of hacks happening today are social engineering" — Lazarus and North Korea's actual playbook is getting you to click the wrong email or spoofing a front end, not out-mathing your smart contract. Teams get "lulled into a sense of security" by convenience-driven shortcuts like fewer signers. AI cuts both ways: attack surface is "much higher than it's ever been," but security should use it too.
- Jason's proposal: audit firms audit code, but "nobody really audits the ops of teams" — MFA, password managers, what happens when someone sends you a picture of your kids. He cites Hasu's checklist: circuit breakers on deposits and withdrawals, time locks on any change, security councils that can shut things down instantly. At DAS, demand pulled Blockworks' token transparency framework toward rating RWA vaults' smart-contract risk — "we're not trying to compete with Moody's."
- Santi says he still keeps "a bunch of money in DeFi" and trusts particular teams with strong operational security, but he is selective about where that money goes. Rob says Dragonfly's current VC funds have never put LP capital into vaults; an earlier liquid-fund strategy was spun out years ago.
10. DeFi yields don't pay for hidden composability risk
- Jason's math: Aave stablecoin yields sit below treasuries; Morpho pays 5-9%. But composability means "you're only as secure as your weakest link" — he thinks Morpho had bad debt connected to the Resolv hack — so looped multi-protocol strategies "should be paying 30% APY, not 10 or 8." He is more worried about capital preservation and impairment than about incremental yield.
- Santi says his own math has also often shown that he is not paid enough to take that level of risk, even though he still has some money in DeFi and sometimes earns better rates. He says this view is more representative of institutional capital; Dragonfly's current VC funds have not pursued vault farming.
- Jason calls this a classic Taleb turkey. Rob's response is that it is situation- and context-specific: some products pay for risk, while lending stablecoins on Aave may not. "It feels like this whole pod has been the death of crypto... maybe that's a bottom signal."
- Jason closes the loop with Mike's tweet: the two biggest issues in crypto are transparency around security and transparency around tokens — "12 to 18 months away from solving both, but it's clear capital won't come back until we do. Investors won't risk their entire principal for 4% yields."
11. Quantum's timeline just jumped toward 2029 — and a hard fork fight looms
- Two papers dropped within hours. Google's quantum AI team cut the estimated resources to break the elliptic-curve signatures protecting Bitcoin and Ethereum wallets from ~10M physical qubits to 500,000 — a 20x reduction — with a key crackable in roughly 8-10 minutes on superconducting hardware, inside Bitcoin's ~10-minute confirmation window, meaning a transaction could theoretically be intercepted mid-flight. A newer, less-vetted Caltech paper from a startup whose name Jason rendered uncertainly as "Aura Oratom Oratomic" claims 26,000 qubits on neutral-atom architecture, at ~10 days per key.
- Jason says the US government had already targeted phasing out current cryptography by 2035, the NSA had suggested perhaps 2030 for especially exposed systems, and Google's estimate may bring the threat as early as 2029 — the acceleration is what has people scared.
- Rob explains why the upgrade cannot simply happen immediately: there is no switch to flip, Google itself would not be post-quantum until roughly 2029, a Bitcoin migration could take years, and self-custodied holders may not participate. Jason adds that there is no post-quantum Bitcoin address format yet — BIP 360 is a proposal, and rushing new code means "maybe you could fix the quantum problem, but you might create this catastrophic vulnerability in the same move." Then you still need a hard fork with no CEO to order it, in a community whose hardcore resists — "once again Nick Carter was right."
- Jason's prediction, revised: "A Bitcoin hard fork will become very contentious... I think it's this year" (he was off by a year), evoking 2017's big-blockers-vs-small-blockers — though exchange-held BTC may make coordination faster. Open questions on the table: dormant coins and addresses may be more exposed; CZ says all crypto has to do is upgrade to post-quantum algorithms, while Brian Armstrong says he's personally spending "a lot more time on this."
Full transcript
1. Content of The Week
Crypto was easy on a relative basis for venture for a long time. You could invest in anything at the early stages, and the token would launch or people would sell the token. This is why there was so much discontent on the timeline about, “Hey, we don’t have the opportunities that the venture capitalists do.” Now, when people are no longer making money, it has to consolidate to the few that are. You’re going to see a few funds raise a bunch of money, a bunch of other funds at that small, niche scale, and everyone else is going to die.
Nothing said on Empire is a recommendation to buy or sell any investments or products. This podcast is for informational purposes only and the views expressed by anyone on the show are solely their opinions, not financial advice or necessarily the views of Blockworks. Our hosts, guests, and the Blockworks team may hold positions in the companies, funds, or projects discussed.
All right, everyone. What's up? Good to be back. Welcome back.
is where April 2nd ratings go parabolic. Who do you got?
Tank the ship. He’s tanking it.
This is the pivot that we all need, coming at a time when the industry is low.
We really needed a moderator. Santi and I are ideas guys, okay? We’re not running ourselves in a straight line. We’re not making sure that we’re on schedule. We need Jason to keep us in check.
As long as you don’t compare me to Jason Calacanis, I’m happy to be your moderator. Just never make that comparison. I might have done that during the live pod that absolutely nobody listened to or attended.
I called Mike. I was like, “Dude, we’ve got to get these live podcasts.” By the way, thanks to everyone who attended that. It was great—3,000 of you. Thanks to the 12 of you who came to our Santi session. For those who weren’t there, which was 2,980 of you out of the 3,000, Santi forced all of his employees to come watch them and watch the whole thing. One hundred percent Inversion was 10% or 15% of the people in the audience, and people kept leaving during the chat. It was bad.
I called Mike and was like, “Dude, we can’t put these live podcasts at 4:30 p.m. on the last day of the conference.” We only had 12 people in the audience. He’s like, “I had zero for Balcurv.” He’s like, “We did a podcast for no people in the audience, but we sat on stage.” At least Empire is overtaking Balcurv.
Yanni, you remember in the early days we kept telling people—we’ve been through five years running, at least when I joined—that we were going to do this every week, bull or bear. We were going to keep doing this.
It’s honestly really rewarding just doing things. I have a lot of friends, founders, and investors who are like, “I want to get into the podcast game. What do I need to do?” I tell them, “You just need to show up every single week.” Even when your listenership falls off or you don’t have a guest episode, you just have to publish the episode. That’s the hardest part.
Do you think we’re getting better or worse? I’m in the numbers. Quality of the numbers. You guys skewed the numbers. The numbers tanked without me, obviously.
Actually, our engagement—you can track how many people listen to the end of an episode—has improved since Rob joined. More people listen to the end of an episode. There you go. They want to hear the content of the week. Yanni’s not sharing the actual data because it’s not that hard.
That’s not what I was going to say. I didn’t say that. I was going to say, clearly the pod did better after I joined until the market tanked. Now it’s just a market issue.
No, the real differentiator for Empire—you guys don’t realize I did the show by myself for a whole year. I wanted to build the How I Built This for crypto. I don’t know if you guys have ever listened to that podcast, but I was like, “These are great stories, like Brian Armstrong and Jeremy Allaire. I want to do the How I Built This.”
It turns out nobody cared. Also, it was really boring by myself. Incredibly boring by myself, actually.
Then Santi joined. We were debating at one point—I won’t share too many details—whether we should give this guy a little revenue share of the thing. Then Santi joined, and the show went—
Wait, there was revenue share on the table? Was I supposed to get revenue share?
At the time, there was, Rob. Back down. You’re still in the probationary period, so we have to get you on the—You’re not even on the cover, my guy. You’re still auditioning.
How am I still not on the cover? That’s not my fault.
You’re still in the probationary period, and we’re still gauging whether the quality of the conversations is there. You keep showing up every week, Rob, and the discourse needs to go up and up.
I’m like the SBF over here.
If you keep investing in Inversion, then we’ll be good.
2. Time To Buy The Dip?
All right, let’s get into the topics. We’ve got a lot to cover this week. We’ve got the Drift hack. In your announcement for the fundraise, Rob, you called it a crypto VC mass extinction. That was the first time I heard those terms, and I’ve seen a few other people tweeting about it. Dudes was tweeting about it. Santi, you’re talking about how token secondaries are down 90% to 95%, so I want to talk about that.
There’s this token-to-equity idea. We’ve got on-chain equities, but now Hart and a Cross was saying, “We’re going to flip our token back into equity.” There are a few other names I can maybe share that I think are considering doing that. There’s this whole Canton versus Solana debacle that was on Twitter, and then there’s obviously this Google quantum paper, which half the industry is brushing off and half thinks is the most important thing we have to address.
Maybe we can actually start with none of those, which is stocks—the good old stock market. Santi, you tweeted, “After de-risking heavily across the board since Q4, went to cash. I’m now nibbling at names I like that are down 30% to 50%. Not jumping out of my seat. Don’t think we’ve bottomed, but I’m not buying tokens, only equities.”
To give a little more context, Microsoft is down 24% year-to-date, Google is down 20%, and Meta is down 17%. Uber—you’ve got Bill Ackman saying it’s trading at this massive discount to intrinsic value. Brookfield is trading at a huge discount to net asset value. You’ve got these names that are down. How are you thinking about this?
I’m of the opinion that you’re never going to time markets. But if you have a reasonably long time horizon, you start seeing opportunities. It’s an incredible edge if you just want to hold stuff for greater than a year.
There are names on my shopping list that I track. You mentioned some that I like, such as Google and the entire software-as-a-service industry. Before being in crypto full-time, I was an analyst and an associate investing in enterprise software. I think there’s a disconnect between some of these names. ServiceNow and others are trading pretty far down, and, multiples-wise, I think they’re pretty compelling.
Obviously, I’m interested in stuff like Western Union, which I’ve been very vocal about. Going into Q4, I started writing more. I obviously went to cash. I was like, “Look, I just don’t think I’m getting paid enough to take this level of risk. Everything’s at an all-time high.” I didn’t have the foresight of the war in Iran and all that stuff. I just didn’t feel like I was getting paid enough.
To be totally honest, I’ve allocated less than 10% of my cash back into the market. I’m still not fully compelled, but I’m accumulating. There are names that I like, and as soon as they trade down, it’s really hard. I think you remember going back to when Solana was going down. You were public on the pod when it hit $8. You were like, “This is a generational bottom.” How many people do you think actually bought at $8?
I think you still would have done well if you bought at $20, then bought at $15, then bought at $12, and then bought at $8. You sort of accumulate because we’re one tweet away from the market ripping again, and the Strait of Hormuz is opening up.
And so I'm just of the opinion that if you're well-capitalized, I'm not jumping out of my seat yet, but I am willing to put some trades in and buy stuff that I just want to hold long-term. Like Google, I feel really comfortable owning it for multi-year periods because it's a monopoly. I don't think they're going to be unseated. What names do you like other than Google?
So, I do have a position in Google. I have a position in Western Union, obviously, and I have a position in ServiceNow. That's really it for specific names.
The other things that I'm tracking beyond the broader market, like the S&P, are in this short list of companies around a theme that I have: crypto-enabled businesses. In that bucket are Klarna, Robinhood, and Figure. I'm monitoring those because I want to understand how they can transform their businesses with stablecoins and tokenization.
Then there's Better Homes, for instance. I don't have a position, and I don't know much about it. It's just interesting that they have a facility with Sky, and the Framework guys invested in that. These are businesses that I'm tracking and that I like, but it takes time to do the work on these names.
I've spent so much time in the payments space that I'm willing to take a small position in Western Union. Figure is another company that we've done a lot of work on, so it bodes well with what I'm seeing. I don't have a position in Figure yet, but I'm monitoring it. Rob, what do you think?
3. Crypto’s VC Mass Extinction Event
I don't know if it's as easy as Santi is making it out to be. Santi and I talked about this, too, when you weren't here, Jason. Everything is just dancing for macro right now and has been all year, right?
There are obviously crypto-specific issues and crypto-specific concerns around the token specifically, whether there's value accrual, and all of the things that we're going to continue to talk about. But I don't think it's so simple right now as President Trump coming out and saying, “Hey, listen, the war is over.”
I think Iran has been very clear that they're happy to go the distance. There's a lot of conversation right now about negotiation, but there's actually no negotiation going on. We're passing messages back and forth through the Pakistanis, but there's literally no direct engagement whatsoever at the moment.
I don't know if you guys listened to the press conference last night, but I got no confidence whatsoever from that press conference that, first, this is likely to end anytime soon. He was very amorphous around the time frame. Second, you pretty much got nothing from it about how it would get resolved, what we would do if the Strait of Hormuz opened, or what that would mean for oil going forward.
I think oil is back up to almost $120. The futures are down, call it, a point and a half, maybe 2 points. I think you haven't quite seen capitulation yet from the equity market. There's some conversation in the news that maybe we've seen capitulation at the end of last week because we had a couple of really bad trading days.
Then we were up a point and a half yesterday, or maybe 2 points. We were up 2 points the day before, and the market very clearly wanted to rush back in on any sign of potentially good news. That means to me that people still expect there's some possibility that this ends quickly.
Even if it doesn't end quickly, we're at the point now where we're going to have a supply shock. We're going to continue to have inflation work its way through the market, and that's going to mean bad things for potential rate cuts. I think macro is going to continue to be challenged for the rest of the year, to be honest.
That means it's not as easy as, “Hey, listen, the war is over,” and everything rips for some extended period of time. I'm sure we'll get a relief rally, but what Santi is talking about—finding names that you want to hold for the next few years that have secular tailwinds—is absolutely what you should be doing right now.
But if you're trading the short-term market right now, I don't think you can be in the market at all. You get paid 4.25% or 4.5% just to sit in Treasuries. Every time there's a massive leg down, I think you're supposed to be buying the names that you like, just adding to the position—not buying 100% of your bet and rotating.
I totally agree with what you said. I just don't think it was Index Ventures that sent a memo to its portfolio companies a couple of months ago or so. It was, “Look, guys, if you're a startup, factor in the fact that it's going to cost you way more for everything that you're buying right now. Have enough runway.”
I think Index are really smart investors, too. They've done very well. We had Josh Wolfe on the podcast, talking about nuclear a year or so ago. Nuclear has done really well.
But he's not Index, is he?
He's Lux.
Lux, sorry. I think it was Lux. Maybe I'm confused, but anyway, it was one of those 2 guys that sent out the memo. It was pretty good. Oh, it was Lux. Lux sent it out. I think it was Lux, yeah.
Lux sent it out.
But anyway, I think if you're listening and you're a startup, you should probably bake a lot more conservatism into how you run your business because the capital markets aren't going to be as open. They certainly aren't as open in crypto.
Jason, you guys are one of the few that actually have capital out there to deploy.
But are you really excited to jump out of your seat and fund? I don't think the quality is there, and we've talked about this here. You're not jumping out of your seat to deploy.
Listen, we've been slow. I'll tell you.
Are you slow because you just got the capital—you just raised this fund—or have you had it for a while?
The way venture funding works is that you do a first close, and then you do some number of closes after that. Usually, it's anywhere from 2 to 4 total closes, and then you announce the fund at the end of the final close.
We've had capital, or been deploying out of this fund, for a little over a year—14 months. It took us about 12 months, start to finish, to raise the full fund, which is very typical. That's actually above the median in terms of how quickly venture funds raise.
We've deployed some of the fund, but last year we were not that slow. We didn't do as high a number of deals as we've done in the past in a year, but we put a lot of money to work because we leaned into the things that we knew were working.
That feels to me right now like the lesson: It's easier than ever to be an entrepreneur. It's easier than ever to vibe-code something. It's also easier than ever to get disrupted really quickly. It's harder than ever to get a moat in anything in software, and at the end of the day, crypto is mostly just software.
Finding things that you see running away with it and piling into those is where we've decided the opportunity lies right now. Because of the pace at which people can build and the pace at which they can build their moats, once you see someone pulling away, they pull away that much quicker, right?
That's the way Ramp has pulled away from the rest of the market and just left Brex behind. It's the way Rain is pulling away from everybody else doing the same thing. We were talking about this a little bit before the pod started, but their month-on-month growth continues to accelerate even at the size they're at now, which is a very, very big business.
What we've done is said, “Okay, let's identify those opportunities, wait and see where they are, and then really pile in.” We've done that. We've put tens of millions of dollars into a few different companies that we know are really working. We had talked about Polymarket a bunch.
That doesn't mean we're not continuing to look at all seed deals or that we're not going to continue to invest in seed, but I think seed has gotten harder than it's ever been in my time doing venture investing.
Yeah, I actually think, Rob, that's an extremely important point that signals a way bigger change in the industry that's happening right now. For 15 years, everyone has been excited about the new thing. Now—and I've said it way too many times on the podcast—last year was this line-in-the-sand moment.
I think we've moved into the phase where the big companies and the winners are going to win really big. I'm seeing that in the venture space right now. It's not just Dragonfly, right? Instead of betting on the new L1, the new L2, or the new DeFi app, people are saying, “Hey, I think we've actually got 3 to 5 winners in our portfolio. Let's just put $100 million into each of them, or $50 million, or $20 million.”
And you're seeing it behind the scenes, too. A lot of companies are talking about going public, and there's a lot of M&A. A lot of Series A, seed, and even some Series B companies are saying, “I think it's time to sell this thing. Let me exit this business,” because there's just no way forward.
Every month, I get at least 5 to 10 crypto venture-backed businesses that say, “Hey, do you guys want to buy us from Inversion?” I say, “What am I buying here?” If you built a business and you haven't gotten traction, I mean, I'm not kidding: I think 80% of crypto data companies have tried to sell in the last month, or in the last year or two.
Of course, we've seen a lot of businesses get acquired for the equity, and the token just gets deprecated, like Tensor and a few others. There's a whole cohort of companies that have raised over the last 4 years whose cash position is low, and they're shutting down or trying to find an exit. Even today, I just got word that 2 companies I invested in 4 or 5 years ago are closing shop. They just couldn't find product-market fit.
By the way, this is not specific to crypto. We're seeing it in the traditional market, too. Everybody—every single fund in the world—has exposure to a foundational model now, like 1 of the 3 or 4 big foundational models. They've had to pile into those, and they've piled a bunch of money in. That's everybody's AUM. That's what they've seen increasing.
I was talking to—we've been talking to some IR candidates—and 1 of the people we were talking to was at a fund that went from $4 billion to $26 billion over a 5-year span. You dig into why that is, and it's literally a single investment that they were in early. It's 1 of the big companies that's going to IPO this year and is going to do a trillion-dollar-plus IPO.
That's been the strategy: pile in, pile in, pile in. That's what we've done, and that's what we've seen work. Broadly, the biggest outcomes are getting bigger. The amount of competition at the earlier stage is getting tougher, and breaking out of that seed-Series A lull is harder than ever. But the ones who do are going to win big, and that's why I think you've seen a lot of people like us spend a little bit more time there.
The interesting thing for me—and I was having this discussion with somebody yesterday—is that it doesn't actually change my job that much. To be good and to win against Lightspeed, Ribbit, and all of these traditional funds that want to come into that space, especially in stablecoins, neobanks, tokenization, and so on, I still have to spend as much time as I was before with the seed companies. I need to know early which ones are actually going to win in the future and be able to stay on top of that early.
It's changed the way we write checks a little bit, but I don't know if it's changed the way we engage with founders at the moment.
I track, religiously, my hit rate, my failure rate, and my cohorts. It's as professional and systematized as it gets, of course, on the venture side. I want to put it in context: Is the failure rate higher than other cohorts? Are companies failing more?
Maybe it's a skill issue, but I do think that, while I agree outcomes are getting larger—you have SpaceX, which is going to IPO at a trillion-plus, right?
1/2 trillion probably. Yeah. OpenAI just raised the largest venture round in history. What is it—$110 billion, $120 billion?
$122 billion. $122 billion.
A $100 billion round. If you were on the timeline, you would have seen all the negativity: Claude is pulling away, OpenAI is dead, and it has a whole host of issues internally. Lo and behold, it just pulled off the greatest thing.
It's important to zoom out and say that what you hear on the timeline is very different from what's actually happening. So don't believe it.
The timeline is like a negative signal these days. It's like a negative signal.
4. Crypto's Token Reset
But that hasn't changed. Social media is always skewed negative, so I think it's important, if you want to be a good investor, to separate the noise, because there's a lot of noise.
I just mean, I think the timeline is more wrong than it's ever been—objectively wrong.
Because now everyone's a content creator. You can have Claude whip out, or ChatGPT whip out, a nice post. To round this out, I think active management is only going to get more valuable, because I don't buy this idea that most people are just putting their money in index funds and are passive. You should be paying that smart guy to do research for you, because I think that's valuable.
You're seeing it in crypto, too. If you're an investor in Hyperliquid or Bitcoin—or I guess I don't know what else you meaningfully outperformed—but there are a few funds that have really pulled away and are doing a really good job. If you're not in 3 or 4 names, like Rain or Polymarket, or if you were an investor in a prediction market or in Hyperliquid, you should be looking at yourself and questioning, “Am I really—”
I mean, it was either prediction markets, perps, or stablecoins.
Well, 1 perp. 1 perp, really. Yeah.
Because we're in Lighter, and it certainly hasn't underperformed as well as Hyperliquid yet. I think Lighter is great, and I think Lighter is going to do well and continue to do well. But it's still worth $800 million, so there are a lot of people who are in that investment who are up a lot on it.
Should we talk about secondaries? I think that's important.
But I want to make 1 last point on this specifically: I do think the failure rate in crypto is getting a lot higher. Companies are going bankrupt earlier, tokens aren't coming out of the gate particularly well, and then they're trading down very quickly. I think venture capitalists' hit rates are getting a lot lower as well, because crypto was easy on a relative basis for venture for a long time. You could invest in anything at the early stages, and the token would launch, or people would sell the token.
This is why there was so much discontent on the timeline about, “Hey, we don't have the opportunities that the venture capitalists do.” Now it's becoming much harder, but it's becoming much more like traditional venture, right? It's not getting harder than traditional venture; it's just a not-that-big industry, and it's getting much harder. That means only a few funds will survive.
This is why, in that article you talked about, Yano—and I think other people have said it—there's been some talk about which crypto investor and VC funds are going through a mass extinction event. I think that's true because there was too much capital for a space that's not that big. Now, when people are no longer making money, it has to consolidate to the few that are right.
That's what we're going to see, and it's going to look more like traditional venture. It's obviously going to be a different scale, but in the same way that Andreessen is raising $15–18 billion now, you're going to see a few funds raise a bunch of money. You're going to see a bunch of other funds at that small, niche scale, and then everyone else is going to die.
What I will say is that valuations at the seed stage are now sensible. I did 1 investment the other day, and it was at a $20–25 million valuation. That would have been probably $40–50 million a year or 2 ago. If you're a smart team, you're raising at that level.
But you mentioned that there's bifurcation among the team and the idea, right? There's an AI-crypto crossover deal getting done right now. It's really kind of a seed investment—maybe they're calling it a Series A, something like that—but it's getting done in the hundreds of millions because it's got this hot topic. There's no fundamental investment case that would say it was worth anything more than $50–60 million, but it's this hot topic, and people are doing it.
I see some of that on the stablecoin side as well. We've probably seen a few deals get done in the last few months where a pre-revenue seed or pre-seed is getting done at $50–100 million, and then the second round, still pre-revenue, is getting done at over $100 million. There's 1 happening right now that I know of that's doing that.
People see the things that are working, and they're trying to get some sort of exposure to them if they don't have it already. Stablecoins are 1 of them, and prediction markets are another. I think there's still this bifurcation.
There was actually Carta data, I believe, which said something like the top 10% of seed deals have a median valuation of $120 million. It was like a $125 million valuation. That's the median of the top 10%, which is up 2.5x in the last year. It's because of what I talked about earlier: everyone is piling into the things they think are going to win, and they're ignoring everything else.
Is that Carta data just crypto or across the entire market?
It’s everything, so it’s obviously skewed by big AI.
Is that the median or the average? There’s also—
It was the median. You have to look at the median. AI is pulling it because you have 1 or 2 companies raising at billion-dollar valuations because they came out of OpenAI or Claude.
Yeah. I just put money personally into something that raised at a $4 billion valuation for its first round. Let’s talk about secondaries, because Santi tweeted that the discount on the vast majority of crypto secondaries is an average of 90%. We’ve seen this before, right? Every bear market, there are usually 50%, 60%, or 70% drawdowns in secondaries. I’ve never really seen 90%, so I’d love to hear what you think.
Just so people understand, when I say 90%, these are tokens that have launched within the past year and haven’t had the first unlock for investors. Most of the time, the vesting schedule is such that the token launches, people get an airdrop, and the token is liquid, so you have some price discovery on 10% to 50%—maybe 20%—of the float. Then the team and investors are locked for a year, and you vest over a 3- to 4-year period.
When I’m saying a 90% discount, it’s a 90% discount on spot. Spot, by the way, is already down and below the last round, or even below the Series A round. Spot is pretty low already. When retail complains, “I actually don’t have access,” I’m like, well, you can go and buy stuff in the public market—a liquid token right now—that is below the last round, or maybe the Series A or seed round.
Of course, the obvious answer is that the last round was overvalued, which is true. The market clearly agrees with that, but I have never seen that big of a discount. A lot of times, when you’re looking to buy or sell OTC secondaries, people get more nuanced. They’ll buy the first-year strip, and then they won’t buy the full lot—the full position. Some teams don’t allow it, and some people do allow reassignment.
By and large, it was pretty much just to get a pulse of what that discount is, to understand sentiment in the market. As I said, I’ve never seen it across the board for quality names that Rob and I have invested in. Everything is basically bucketed in the 80% to 90% range. One is at an 80% or 82% discount, and the other one is at a 90% discount. Then there’s no bid for the non-venture-backed ones—just the absolute—
What about the secondaries on non-token companies?
Crypto?
Yeah, just a crypto equity business.
In this case, I didn’t ask for that. I can come back to you guys on the next podcast, but I was simply focusing on the tokens.
There’s no bid. People will quote you this crazy number, and then when you look at the volume, you have to ask: Have people actually transacted? I’m seeing less of a discount on the secondaries in equity businesses. I know someone who’s raising at around a $4 billion to $4.5 billion valuation, but their secondaries are now around $2.5 billion, $2.6 billion, or $2.7 billion. So what is that—a 40% discount, roughly?
So I think this is a story of crypto companies struggling, but also just pure hatred toward tokens.
I don’t think there’s hatred.
I think there’s hatred.
There is. I mean, I don’t have anything against a token. I just think most of them are very, very broken. I think people have written off tokens as an investable asset class right now. Except for maybe 10 of them, most people and most funds would say, “I do not invest in crypto tokens right now.”
Well, if that were true, the market wouldn’t be at a trillion dollars ex-Bitcoin.
Your total market cap is $2.3 trillion, and if you exclude Bitcoin, you still have Ethereum at $250 billion.
Take out Bitcoin. What’s the market cap sans Bitcoin?
No, no, no. That’s what I’m saying. Bitcoin is $1.3 trillion as we’re recording this. The total crypto market cap of liquid assets is $2.3 trillion. It’s not fully diluted; it’s just circulating. So you still have more than $1 trillion, and $100 billion gets traded every single day. The 24-hour volume is $107 billion. There are people out there who are willing buyers and sellers of these things.
I think there are 2 different things happening here. A lot of the crypto trading is quantitative in nature. There are tons of people—all of the big quantitative funds—that are trading a bunch of crypto right now. They’re trading short-term volatility or day trading. Maybe they’re trading basis in certain tokens like ETH.
I think what Yiannis is talking about is fundamental, long-oriented, buy-and-hold investors. And I absolutely believe right now—
Investors in crypto, man. Some people just kid themselves: “I’m holding for 3 months. I’m a long-term investor.” No, you’re not.
There definitely have been times—and there were times last year—
Everyone is hedging on the perps.
Well, what I’m saying is, if you look at it—no, we should get an OTC guy here, because the fixed guys or second line guys—the volume is way down. Perp volume is down 60% since October.
Clearly, we need the volume.
Even if people are hedging, they’re still long. For years they’ve been, and they still are.
I’m not—I’m not. Here’s why I don’t hate tokens. I’ve been critical of valuations and the structure of tokens versus equity. I’m just paying more attention to a business like Figure, where I can actually see real-time on-chain data that Wall Street doesn’t look at. On-chain data is an edge, right?
Nobody said you hate tokens, Jason.
I don’t, by the way. I don’t hate tokens in the sense that I think they’re overvalued. Structurally, they’re inferior to equity, but I can appreciate why certain people want to have a tokenized instrument. On Hyperliquid, you want to trade oil over the weekend. That is a valuable instrument.
It is alarming that there’s a 90% discount. Historically, a 60% discount for the whole lot meant you were selling to someone who was likely going to do something on the perps and hedge it. That person would almost categorically be very unlikely to lose money.
At 90%, I’m not trying to be picky here—there are still people who believe in it—but if you’re buying something at a 90% discount, you’re almost saying, “I don’t even want to buy this thing. I think it goes to zero.” Historically, tokens just don’t go to zero.
I’d actually take the other side. I would buy something at a 90% discount. At that point, price is the single determinant of returns.
So if we’re at the point—you’ve been saying for a year—
I will flip. That’s what I’m saying. I’m flipping. I’m now a buyer at that level for certain projects.
Of a token? I mean, I don’t spend that much time doing it. I just pulse people to understand.
I don’t think 90% is a number that’s actively happening in most of the names that Jason and I want to own.
No, no, no. You’re an investor in 4 out of the 10 that I got quotes from. I’m almost certain, depending on which names they are, that I can sell them for a lot less of a discount than 90%. I’m certain of that.
You mark your stuff however you want in your—
Regardless—my mark is not there.
We mark our book very aggressively. We discount locked tokens for lack of marketability, and we do a bunch of other things. We should get Omar—the, you know what I mean, to the world. If the bid goes at a 90% discount, we mark our book very aggressively.
I’m certain that for anyone you’re talking about—if the token is liquid and people actually have a positive outlook on it—there are buyers at 60% discounts for most of these things. If they’re liquid, people will just hedge them out on the perps. You see that all the time.
Regardless, I think the bigger point being made here—and in response to Yiannis' question around equity—is that there is definitely more of a bid today for the right names in equity than there is for most of the right names in tokens.
Other than maybe 2 or 3 tokens that people really, really like—or maybe 5 to 10 tokens that people really like—there’s another group of tokens that people are constructive on at the right price and at the right time. Maybe that’s another 10 to 20 tokens. After you get past 30 tokens, there’s probably not a buyer for the vast majority of them today. There will be in a bull market.
So when you say tokens that people like, I think you’re coming at it from the institutional perspective.
Historically, the marginal buyer in crypto is still a retail user.
Well, that’s what I’m saying. If we look at volume as a proxy for what people like—
Volume is not a good proxy for what people like, because most volume is market-maker and quantitative volume.
But okay, explain to me the rationale for a market maker.
It’s like a loop, right? A market maker is going to participate in markets that retail likes because there’s an inverse correlation with—
Soft flow.
That’s absolutely true. But you also have people who are going to participate in something they think might have soft flow in the future, even if it has sharp flow today at times. You see a lot of that happening on a lot of Hyperliquid markets, where there is definitely, at times, sharp flow depending on the market.
You also see a lot of people trading quantitatively. Whether they’re trading volatility, basis, hedging out, doing cross-chain arbitrage, or doing cross-venue arbitrage, that’s the vast majority of volume in crypto. That’s always been true. Crypto is the single best place to do delta-neutral strategies today, and it has been the single best place to do delta-neutral strategies for years.
That has always been the vast majority of the volume on these platforms. The marginal buyer who has made the price go up and is directional is retail, but volume isn’t necessarily a good proxy for that. Nothing’s going up right now.
But if you’re a market maker, people are trading and there are other strategies. Isn’t it true that if you’re a market maker, you’re going to play the perps, right? You’re looking at the funding rate, and retail really drives that. If you’re on a poker table, you always want to be short—
At a base funding rate.
Base funding rates are 10.95%, right? If the market is neither bullish nor bearish on a specific token, the base funding rate still exists.
We disagree.
I’m moving us forward. We’re not going to get to the bottom of it. There are a bunch of other topics. This is why you need a moderator.
Let me make one last point on this, though, which is that on the equity side, it’s the same thing that’s happening in traditional markets. There are a few names on the equity side that trade at premiums to the last-round valuation and that there’s basically insatiable demand for in the secondary markets. Then there are a bunch of names that people are kind of okay with, and nobody cares about anything else, even if it’s a good company. You’re seeing the same thing in traditional equity.
5. ZKsync Ad
ZK Sync is the bank stack of Ethereum. ZK Sync’s Provedium is the only Ethereum secured platform that is purpose-built for institutions that demand privacy, compliance, and full control of their data. ZK Sync enables financial institutions to thrive in the digital assets economy by launching and monetizing their own chains, tokenize real-world assets, build programmable markets, and settle cross-border in real time. Visit zksync.io to learn more about the bank stack of Ethereum and book a demo. As always, investments in blockchain technology involve risk. Terms and conditions apply.
6. Blockworks Investor Relations
Hey all, Blockworks co-founder Michael Ippolito here. Quick break to talk about something we’ve just launched, Blockworks investor relations. As the market shifts toward institutional capital, investors want more transparency, more standardization, and a higher level of professionalism. But, the traditional IR model is slow, manual, and not built for how crypto works. If you’re building on chain, your data’s already live, your business is already transparent. The challenge is turning that into a clear, credible story for investors. That’s exactly what we’re solving with Blockworks IR. It’s a single platform that brings together real-time analytics, branded investor portals, and hands-on advisory support, so you can communicate what matters. If you’re an on-chain business looking to level up your investor strategy, check out Blockworks investor relations at blockworks.com/investor-relations.
Let’s talk about the Drift hack. I’m guessing most people know Drift, but if you don’t, it’s a perpetuals DEX on Solana. It’s one of the biggest. They had about half a billion dollars of TVL going into the day.
We’re recording this on Thursday. The hack happened on Wednesday, April 1. I’m going to get most of this information right. This is how I understand it: $270 million, $280 million, $285 million was drained in about 12 minutes.
The attacker created a completely worthless token. I think it was called CVT. They seeded a liquidity pool with a couple hundred dollars and wash-traded it until the price oracles started treating it as actual collateral.
Solana has this feature called a durable nonce. Normally, a Solana transaction expires in a couple of minutes if you don’t submit it, but a durable-nonce transaction can be pre-signed and held indefinitely. What the attacker did was stage all these things in advance: every withdrawal, every parameter change. They pre-signed everything, ready to go at the click of a button.
When they pulled the trigger, these 30-plus transactions executed immediately in sequence, and $280 million was wiped out before anyone could really respond.
The problem here, as I understand it, is that a couple of weeks ago, Drift’s security council multisig had been changed from a higher threshold down to, I think, 2-of-5 signers, with no timelock.
Two of five, yeah. With no timelock.
That means any transaction can go through instantly with just 2 people signing off. So the attacker got 2 of the 5 keys. I don’t think we know how.
What most likely happened was that one person got hacked, essentially, and somebody else blind-signed. I like something this person did, and that’s fine. They probably compromised one of the keys and someone blind-signed. I think it’s similar to the Bybit playbook, where there was malicious code—
It’s a bit different because the Bybit playbook involved an actual hack at AWS. They were able to surface a fake UI through AWS.
Right.
To close the loop on this, Drift basically changed the admin key entirely once they had those 2 keys and locked the original team out. Drift couldn’t freeze anything or stop it. This protocol had passed 2 security audits, and nobody caught this. Nobody caught that a 2-of-5 multisig had been put in place.
I think the big question for me is that this is a huge deal. I know we have hacks all the time, but this is coming on the back of the Resolv Labs hack. I’m trying to remember how much the Resolv hack was for, but that happened a week or 2 ago, right? The hacker compromised the AWS environment, and they received 50 million USR stablecoins back in return.
You’ve got the Resolve Labs hack, and you’ve got Stakehouse. There was basically a phone-based social-engineering attack where their front end pointed to a wallet drainer. That was 2 days ago. Then yesterday was Drift.
This is bad. How do you use DeFi after something like this? I think the 3 of us are the people who would be power users of this stuff. I’m not keeping any money in DeFi right now. I’m just not. Why? It’s not worth the risk.
I still have a bunch of money in DeFi. I’ve still got a lot there.
Keep it there? Why? Why do you take that risk? The rates are lower in Aave than they are in T-bills.
I’m getting better rates in the DeFi I’m in than I would be getting elsewhere.
But you’re willing to take the risk if you were getting better rates?
Yeah. The math that I’ve done for a while is that I’m not paid enough to take that level of risk. The vast majority of hacks happening today are social engineering. That has been true for a lot of—
All right, they’re no longer smart-contract-related. There are oracle issues that have happened time and time again.
Yes, but there are oracle issues involving people causing liquidations or minting new tokens. At the end of the day, most of what has happened—and this is true of things happening outside of crypto as well—is that social engineering is actually the biggest issue right now.
That’s what Lazarus primarily does. That’s what most of the North Korean hackers do. There’s an issue right now where it’s that much harder to stop yourself from making a mistake and getting socially engineered. Your operational security needs to be at an all-time high.
There are people I trust who have significantly better operational security than others. There are DeFi founders I would absolutely trust to have as good operational security as people off-chain as well. There are places where I would keep my money. I’m very thoughtful about where that is, though.
That said, I think in this case and in others, there’s a sense of, “It’s kind of annoying to do these different things and have a bunch of signers.”
And maybe we have too many signers, so we can't respond to something as quickly. We move a little bit more slowly, and it causes people to get lulled into a sense of security. Then they get socially engineered and something like this happens, and it's terrible.
I think there's something to be said for needing to do more work on operational security. This was true of Bybit as well. The hack was actually at AWS and then through their Noesis front end, but there still weren't the right controls in place to check the pathways and where the actual smart contracts were sending the capital. There was an operational issue, and the biggest hacks have been that.
I have a general concern around security related to AI. We've seen these supply-chain hacks happen outside of crypto as well, and the attack vector and the surface area are much higher than they've ever been. It's much easier to find issues. At the same time, you need to be using AI for security, and that should theoretically make security more robust.
But we continue to have, in my mind, the biggest issue be social engineering. I was just looking at DeFi hacks, excluding Bybit—just DeFi protocols. My quant says that in 2025, you had roughly 1.1 billion in DeFi protocol losses. That excludes Bybit.
There were only 6 hacks that were 50 million-plus. One of them was Balancer, and then there were a few others. This quarter alone, including Drift, we've had 350 million in losses. It's not necessarily going up, but this idea of Lindy—there are more protocols, so the surface area, to your point, Rob, keeps expanding.
Do I feel marginally better putting my money in Aave than in a random protocol? Yes. But the rates in Aave—the protocols that have more Lindy, that you feel comfortable with and that are pretty battle-tested—are fairly low. If you want to go out on the risk spectrum and chase the higher yield, there's a lot of risk.
7. Drift Exploited For $280M
Yeah. My point, Yano, as we were recording DAS, is that the number is just alarming. Let me ask you a question: In your conversations with DAS participants, is this a topic that keeps coming up? Vaults were all the rage, right? Let's talk about vaults, but the value proposition of a vault—
Okay, so we've got this token transparency framework, and we rate these tokens. We're building this big disclosures framework for the industry. The thing that I didn't realize a lot of people wanted—and this came up at DAS and in our meetings with people—is that they want us to rate RWAs.
We don't need to rate RWAs. We're not trying to compete with Moody's. We're not going to rate bonds, and we're not going to rate the underlying equity here. But they want to know the smart-contract risk, or what vaults the RWAs are held in.
Hasu tweeted out that every DeFi protocol should have circuit breakers for deposits and withdrawals, time locks for any change, and security councils that can shut things down immediately. I don't think you actually need to impact the UI or UX for the front-end consumer. A lot of people were saying you have to change the UI or UX for the front-end consumer, but I don't think you need to do that. You do need to take better security precautions as a team.
You were saying a lot of these are social engineering. Drift had a time lock, and then they removed it. I'd love to know why that decision got made. Why did you move down to a 2-of-5 multisig? Why did you remove the time lock? I just don't get that decision. It makes no sense. If you're already securing that amount of money, why would you put your—
I also think you should audit your operational security, not just the code. I understand moving fast and making changes, but going down in size to reach a quorum? I don't know who recommended that. You wrote a security audit of yourself. Santi, I'm sure you've probably done this before.
They don't test the code of your bank account. What I realized is that we have all these audit firms that cover code and audit the code, but nobody really audits the operations of teams. It's like when you do a security audit: They're not auditing the code of your bank account. They're auditing whether, if somebody called or sent you a picture of your kids, you would give them your multifactor authentication. Do you have a password manager?
Right. I think we need to start auditing the operations of these teams. I'm curious what that would look like. There are firms that do very in-depth security work around social engineering and operational security, and people don't take it seriously enough.
That is the issue. Everyone knows about Lazarus and North Korea. They're like, "These guys are terrible. They're the largest hackers in the world and the most sophisticated." I don't think people realize that the vast majority of what they do is social engineering. They haven't necessarily found some flaw in your smart contract and proved that they're smarter than you. The vast majority of what they're doing is getting you to click on an email or a button that you shouldn't have, or spoofing a front end through some other service provider that then gives them access to your computer or your wallets.
That is the vast majority of what they're doing, and that is where things have gone the most wrong. There's no reason not to take this incredibly seriously.
The issue that you have, Rob, is that you trust some teams more than others. Say you trust Morpho, as an example, because you see Apollo getting involved and it has a track record. The issue, though, is that DeFi has high contagion risk. Composability is a beautiful thing, but you're only as secure as your weakest link.
If you're a vault manager interacting with a number of protocols, there's a lot of fragility in the system if one of those components or protocols goes down. You saw that, right? Morpho had bad debt, I think, with the Resolve hack last month, right?
You have Morpho Euler employed. You have a different thing, though. You're talking about bad debt because you took on some sort of risk in a structured product.
But that's what I'm saying. If you go on Aave, the yield on stablecoins is less than treasuries right now. There's no way we can agree that there's less risk there than going directly to buy from the government. There's no smart-contract—
If I go and buy a private-credit fund, you might be taking 10% losses right now on the private-credit fund. This is the same thing.
It's an unfair comparison. I don't disagree with you. I made the point at the RWA summit at ECC that the human risk is them gating you and not promising that it's a liquid instrument, then saying, "Oh, no, sorry, guys, it's not." It's like Terra. Same issue. There's an asset-liability mismatch; they just characterized it and gated it.
You still are, if you're underwriting a vault or underwriting Blackstone, underwriting the manager's ability to underwrite and make sure that credit is extended correctly. I think the quality of Blackstone, Apollo, and Six Trees is higher than your typical crypto vault manager.
Sure. I agree with that.
I don't think a lot of the private-credit stuff is dislocated right now because you have more redemptions than their ability to honor them, but I think the underlying quality is quite high.
Morpho, for instance, can pay 5% to 9%. That's definitely higher than treasuries. If you have your wealth in crypto and stablecoins, fine. A lot of this is that people don't have access to buying treasuries, their bank account doesn't pay them, or they just don't know. The convenience factor of moving your stablecoins quickly from farm to farm and/or vault is high, and I think there's a reason why there's a lot of volume on-chain.
But to me, it's a head-scratcher. I personally don't think these APYs reflect the amount of risk hidden in DeFi because of composability. If you're looping and interacting with many different protocols, I think you should be paying 30% APY, not 10% or 8%. That's where the calculus is just not compelling enough for me to come on-chain.
I'm more worried about capital preservation and impairment than maybe someone who just has less of a—
For me, I think my view is more representative of institutional capital. Rob, let me ask you a question. You personally might have stuff on DeFi. How much of Dragonfly's funds—I know you call it capital and whatever, and maybe you're recycling—are you guys putting into a vault?
We've never done that. That's not our fund, and that's not what our LPs allow. It hasn't mattered when DeFi farming was paying you 60% either. We used to have a strategy, right? We had a liquid fund of which that was part of what they would do, but we spun that out years ago. It's almost 4 years ago at this point because that just wasn't what we wanted to focus on. We wanted to focus on the core of the VC side.
Yeah, I think this is a classic Taleb turkey, though. I don't expect institutions to say, “Okay, maybe I'm clipping 400 or 500 bips more on a vault, but the risk of impairment is there, and it's greater than 5%, and the expected value at that point is negative versus going to private credit again.”
It is just very situation- and context-specific. I think there's absolutely risk involved with every financial product. In some cases, you're getting paid for risk, and in a lot of cases, to your point, if you're just lending stables on Aave, you're probably not. I think it's very situation-specific.
It feels a little bit like this whole pod has been you being like the death of crypto and Santi believing crypto is dead. I think that's a very—maybe that's a bottom signal—because it feels very myopic relative to the things that are happening.
No, I'm simply—I think—let me summarize this section.
I'm just being critical. I wouldn't be in this industry; I'd just be chilling and playing with AI. Let me use Mike's tweet to summarize this whole—maybe the last 50 minutes of this conversation. Then I do want to talk about the quantum thing because I'm curious to get your take. Maybe we can wrap on that.
Mike tweeted out yesterday, or this morning: “The 2 biggest issues in crypto today are transparency around security and transparency around tokens.” He said, “I still think we're 12 to 18 months away from solving both, but it's clear capital won't come back until we do. Investors won't risk their entire principal for 4% yields.” That's the second half of this conversation. “Or ape into an asset class that's down 80% over the last 5 years.” That's the first half of this conversation.
The good thing is these are very solvable problems, right? We can bring shareholder rights back to tokens. We can fix a lot of the security. Maybe it's a bottom signal, Santi, calling this stuff, but I do think it's important to call out what I think are the 2 biggest issues in the industry. Maybe that's the title of this episode: “The 2 biggest issues in crypto today.” I do think we can have other episodes where we highlight Polymarket and Rain for Rob. But I do think it's—
8. Bitcoin's Quantum Threat
That's every episode.
Let's talk quantum because I want to maybe wrap on that. I think we're running up on time, and it's important to get to that.
These 2 papers dropped this week within hours of each other, and they kind of moved the goalposts on quantum, I would say. I'm taking a lot of this from people on Twitter because I've spent a lot of hours watching videos and reading papers about quantum stuff, and I'm still trying to wrap my head around it. Take all this with a massive grain of salt. Maybe you 2 are much smarter than me here, but 1 was this Google paper and 1 was a Caltech paper.
The Google paper, as I understand it, is the 1 getting most of the attention. Google's Quantum AI team, which people think is 1 of the best in the world, showed that the implication of what they showed is that breaking Bitcoin and Ethereum's cryptography—specifically, the elliptic-curve signatures that protect basically every wallet—requires far fewer resources than anyone previously thought.
I think previous estimates said you'd need roughly 10 million physical qubits, and Google's number now puts it at 500,000, which is a 20x reduction. On a really fast superconducting quantum computer, they calculated that 1 of these keys could be cracked in 8 or 9 or 10 minutes. Bitcoin's block confirmation is about 10 minutes, meaning an attacker could theoretically intercept a transaction mid-flight, before the block gets finalized.
The Caltech paper is newer and less vetted, but I think it was potentially more alarming, or at least that's what people said. There's this startup called Aura Oratom Oratomic, I think it is. It's ex-Google researchers and Caltech faculty. They took these Google improvements and applied them to a different type of quantum computer: neutral-atom architecture. This was the first time I'd ever heard about it.
Their estimate is 26,000 physical qubits, which is obviously a much bigger reduction than Google's 500,000 physical qubits. The trade-off here is speed. Neutral-atom machines are much slower, so you're looking at 10 days to crack 1 key rather than 9 minutes. I don't fully understand that 1, but the implications seem big.
CZ came out and said he saw some people panicking about quantum computing's impact on crypto. At a high level, all crypto has to do is upgrade to a quantum-resistant, post-quantum algorithm, so there's no need to panic. But you also get Brian Armstrong coming out and saying, “I'm going to start spending a lot more time on this personally.” It seems like this is an issue that we all need to solve sooner rather than later.
Can I ask a question more than make a comment? I am not an expert by any stretch of the imagination. When someone says that we can upgrade to quantum resistance, do we have that today? If not, what stops you from doing it now? Is it because you just don't know what the attack is? Why wouldn't you upgrade now in advance of something that you feel is coming or is around the corner?
I'm definitely not an expert by any means, but you certainly can't just flip a switch and upgrade to quantum resistance today. Even Google says they won't be post-quantum until 2029 or so, and they're actively working on their systems for it.
The timeline to do an upgrade for Bitcoin is probably going to take a couple of years. Then there's the fact that all of these people who are self-custodying may not actually be part of any sort of upgrade. What happens to their tokens in the future?
I think the biggest concern has been how you get the Bitcoin community, which is not centrally operated in the same way other communities are, to upgrade Bitcoin as a whole to post-quantum over the next few years and move with an agreed-upon action and the necessary time frame if quantum is going to break current cryptography in the near term.
Technically, it's supposed to be easier—and it should be easier—to upgrade Bitcoin to be quantum-resistant than it would be for Solana or Ethereum, for a bunch of different reasons around how you would reverse-engineer a private key. But there's just a really tough conversation around how this very decentralized asset would align itself versus the centralized—
I would bucket it—I would answer that, Santi, in 2 ways. Rob, let me summarize Rob's thing.
There are 2 buckets, 2 reasons this is hard. One is that there’s no actual post-quantum Bitcoin address format you can switch to now. If people want to read about it, there’s a proposal: BIP-360.
I had dinner with one of the Bitcoin Core developers. This is 6-month-old information, but I’m guessing it still kind of stands true today: this is really new code. So if you do this stuff too soon, you actually weirdly introduce new bugs. You might fix the quantum problem, but you might create this catastrophic vulnerability in the same move.
So, yeah, we don’t actually have the post-quantum-resistant wallet formats yet. That’s the technical side. Then there’s the fact that you’ve got to hard fork Bitcoin, basically. As Rob said, there’s no CEO who can just do this.
I don’t know if you guys have been following Nick Carter’s tweets, but I’m going to go on the record and just say that I think, once again, Nick Carter was right, per usual. He’s usually 1 or 2 years ahead of a lot of this stuff, especially with regard to Bitcoin.
You can see how much pushback he’s gotten from the hardcore Bitcoiners who are like, “We’re not upgrading this thing.” And he’s like, “You idiots. We have to upgrade this.” I think he’s going to be right on this.
If you guys remember 2017, I think we are going to—my prediction last year was that a Bitcoin hard fork was going to become incredibly contentious. I think I was off by a year. I think it’s this year. A Bitcoin hard fork will become very contentious.
Santi, you remember 2017—the big blockers versus the small blockers. I’m not saying we get something of that scale here, but now a hard fork will probably actually get done. It will get done because so much of the Bitcoin is held by a lot of the exchanges. I think it’ll actually get done faster, but you’ve got a coordination problem on our hands again.
I do think one thing that’s worth pointing out here is that the main thing about this Google research paper is just the timeline, which has kind of accelerated. It brings forward the timeline that people are concerned about. The US government had already said, “Hey, listen, we have to phase out current types of cryptography by 2035 and be post-quantum by 2035.”
The NSA had kind of said, “Oh, well, maybe that’s as early as 2030 for certain types of systems that are very, very at risk.” Now Google is saying maybe as early as 2029.
I think the major thing that has people very concerned here is that most people—not all Bitcoiners, but most people—have understood that quantum is a risk at some point in the future. But I think everyone expected that we had a much longer time frame than 2029. That’s the thing that has people really scared now.
We should bring on someone like Jameson Lopp or Nick Carter, or a combination of them, or James Prestwich, who’s been more at the forefront of pushing stuff in Bitcoin. The security budget—James is a pretty big advocate of that, especially talking about Satoshi coins. All the addresses that have just sat dormant, I think, are more exposed.
We should have someone come in and talk about it, other than us prompting Claude and trying to figure out how to articulate this well on a pod.
I agree with Jason. Is the biggest risk you’re describing that the Bitcoin community is just so gridlocked and can’t reach consensus fast enough to adapt? Does that mean that other networks—the Zcashes of the world—are perhaps more likely to be ready to migrate and survive?
And then the third is: What happens if an attacker gets access to Satoshi’s 1 million Bitcoin? What do you do at that point? People see those coins move. Do you sell? Do you immediately dump? What do you do?
Yeah, I don’t know. Anyways, I think this is a big problem that people have to solve. I’ve got to jump to a meeting in a few. Let’s do content of the week.
Santiago, you’re first. You’ve been going first this whole pod.
I guess I want to start with Kochland.
Kochland?
Yeah. Turn around so we can hear you. This one? I just looked this up. Yeah, interesting. Kochland: The Secret History of Koch Industries and Corporate Power in America.
Koch Industries is one of the largest private companies in the US, I think in the world. They own—they’re just a diversified conglomerate. I want to read that. I haven’t read it, so it’s kind of a cop-out answer, but I’m excited to dig in.
All right. Listen, it’s the Final Four this week, okay? I’d be remiss if I didn’t talk about this UConn–Illinois game. We’ve got Lori, who you guys know. She’s won her pool at work 2 out of the last 3 years. If UConn wins again this year, she’ll have won 3 out of the last 4 years, which is probably the single best run in work-pool NCAA Tournament history. So I’m pulling for her.
Dude, she’s a legend. Maybe she should be raising a hedge fund for Polymarket. Yeah, let’s go.
She should be. I mean, she’s just running circles around the mid-market private equity.
So how did she do this, bro? What wizardry?
The wizardry has been that she is unabashedly, extraordinarily bullish on UConn every year. And UConn just keeps winning.
Wow, she got lucky there. She got lucky.
No, she didn’t get lucky. She picked a horse and ran with it. UConn is her Polymarket. Let’s go.
Love that.
I read my first fantasy or first fiction book in a long time. There’s this author I kept seeing. I asked so many people because I took a little time off and had time to read a fiction book, which was lovely. And everyone’s like, “You’ve got to read this guy, Patrick Rothfuss, The Kingkiller Chronicle.” It’s a trilogy. So, I read—
You’ve read it?
Yeah, I’ve read them. It would be years ago.
Yeah, yeah, I never knew about them. So, I read The Name of the Wind, which is the first one. It is incredible. And now I’m on the second one, The Wise Man’s Fear. If people are looking for a fiction book, it was the first fantasy book I’ve read since Harry Potter. You could categorize Harry Potter as a fantasy book. Santi, right up your alley. It’s a really, really good book, though.
Nice. Are we still waiting for the third one?
Still waiting for the third one. This is like a Game of Thrones situation where we’re 12, 15 years later and we still haven’t gotten it.
Exactly.
All right, folks, good to be back with you guys. Thanks for listening. We have a really good episode coming out on Monday with Chad Cascarilla, who’s the founder of Paxos. He’s been building Paxos since 2012. They’ve raised $540 million, and they got a lot right. They got some things wrong. He’s one of those people you can ask about pretty much anything in the world—health, food, meditation, markets, macro, or crypto—and he’ll have a really thoughtful answer. Hope you guys enjoy it.
That’s great. Yeah. Good to have you back. Thanks, folks.