[BidClub_]
Thread Guy · · 60 分钟

深入3亿美元加密货币黑客事件内幕……—Tom Kysar

Thread GuyTom Kysar

加密区块链金融技术
YouTube ↗
TL;DR
  • Tom Kysar 的核心判断是,这起约3亿—3.5亿美元的漏洞利用事件,本质上是中心化跨链验证失灵。 一个再质押ETH包装资产依赖 LayerZero 默认的单一验证者配置;LayerZero 称,被攻破的备用 RPC 基础设施报告了一笔虚假的桥接交易,攻击者因此铸造出没有资产支撑的代币,并在一笔交易内通过 Aave 将其兑换成真实资产。「一切正常,直到它不再正常。」

  • 真正造成破坏的环节,是 DeFi 决定接受一种递归包装资产作为共享资金池抵押品。 攻击者一旦能够“无限铸造”,就可以把新生成的代币存入借贷市场,借出 USDC 及其他真实流动性,留下手持坏抵押品的放贷方。Tom 将其类比为熟悉的垃圾币跑路——“开发者拥有无限铸造权”——只是规模被放大到了 DeFi。

  • 默认配置把一个表面上可配置的安全系统,变成了单点故障。 LayerZero 应用本可以指定多个去中心化验证网络,但 Tom 表示,开发者大多数时候使用默认配置,因为很多人几乎不了解自己部署的配置。LayerZero 因而可以说协议按设计运行,但 Tom 把这种辩护类比为有人开枪自伤后说“这把枪的功能运行正常”。

  • 总得有人吸收这笔坏账,而 Tom 怀疑现有储备不足以覆盖全部损失。 未决问题在于,受影响 L2 部署上的持有人是否承担折价,还是损失会波及主网用户;他认为 Aave 的声明倾向于由 L2 用户承担损失。如果攻击者确实受到国家支持,他认为追回资金或获得白帽赏金几乎没有可能。

  • Hyperliquid 承担着同类的桥接风险,但 Tom 认为它远不及此次暴露出来的 LayerZero 配置。 HyperCore 由一个拥有质押验证者的12人网络维护,而其 Arbitrum 桥——主持人称截至4月26日持有约47亿美元——采用三取二多签,并持有 Circle 可以冻结的 USDC。它仍然是一个中心化故障点,但相比之下显得相对谨慎。

  • Tom 预计流动性会暂时撤出,而不是 DeFi 需求永久崩塌。 他援引 DeFiLlama 的一篇帖子称,几天内约有150亿美元资金退出 DeFi,但预计几周后,随着收益率上升、用户重新需要杠杆或美元,资金会回流。具体的单一验证者配置可能消失,但“实际上什么都不会改变”,因为复杂的损失与大多数市场参与者之间仍然隔着社会距离。

  • 这一集更长期的结论是,反复出现的失败会提高市场对简单、耐久资产的溢价,并把严肃参与者从交易引向建设。 Tom 刻意悲观的总结是“一切其实仍然有点中心化”,而 Bitcoin 的优点在于它“什么都不做”,并且已经存活足够久,以至于美国政府不可能直接将其关停。他给出的实际路径是:持有不太可能归零的资产,打造拥有股权且具备真实价值的东西,不要再期待靠交易赚到数亿美元。

摘要 · 为研究而整理的核心内容

1. Gas.zip 以需求为先,代价则被明确保留下来

  • Tom 介绍自己是 gas.zip 的运营者。gas.zip 是一条针对小额交易优化的桥,目标包括覆盖更多链、即时到账和低成本。这些优先级必然伴随着取舍。

  • 他的产品理念来自“10年时间打造没人用的垃圾东西”。这一次,他希望先为几千人解决一个问题,再“倒推回去”寻找技术上严谨的解决方案,并接受去中心化方面存在一些不够圆润的地方。

  • 这一背景很重要,因为 Tom 并不是出于本能在批评 LayerZero。Gas.zip 本身就建立在 LayerZero 之上,他大体上把自己描述为“LayerZero 的人”,甚至是“LayerZero 的无脑支持者”;因此,他得出这起事件“相当糟糕”的结论,代表一个内部人士与原有立场的决裂。

2. 一个默认验证者据称变成了无限铸造权限

  • Tom 的复盘始于一种再质押ETH包装资产,讨论中没有确认其确切名称。LayerZero 提供消息传递层,授权一条链上的销毁,并在另一条链上铸造对应资产;Tom 说,从功能上看,这就是“铸造权限”,或者“管理员密钥”。

  • LayerZero 应用可以选择多个去中心化验证网络,即 DVN,来证明跨链操作确实发生。此次暴露出来的配置只使用了 LayerZero 自身:“你只要攻破一个,就够了。”理论上的多验证者系统,已经变成了单一信任假设。

  • 为什么会选择这种配置?Tom 的回答是,开发者经常在没有理解仓库中每一项内置配置的情况下直接部署。默认值决定了大多数行为:“你放一个默认配置进去,90%的情况下人们都会使用默认值。”大约3年来,这个捷径看起来一直没有出问题。

  • Tom 将其与 Ethereum 质押者进行对比:质押者撒谎可能被罚没。而在这里,验证者出错似乎没有可比的经济惩罚,只有“哎呀,对不起,3.5亿美元没了”,尽管它控制着一个由数亿美元资产支撑的资产的发行权限。

3. 受攻破的备用基础设施,把虚假抵押品变成了真实提款

  • 根据讨论中的说法,LayerZero 的主 RPC 节点遭到 DDoS 攻击,验证因此退回到两个备用节点;LayerZero 称,这两个节点在根级权限上已经被攻破。据称,这些节点返回了一份伪造区块,显示数亿美元已经从源链桥接过来,但实际上根本没有发生这笔转账。

  • Tom 真正感到恐惧的,不只是一个有漏洞的合约,而是攻击者似乎能够访问“核心内部基础设施”。他说,如果攻击者可以控制私有备用节点,理论上就可能造成更大范围的破坏。

  • 这条虚假消息放行了再质押ETH包装资产的无抵押铸造。攻击者并不需要先拥有3亿美元才能创造这些代币,理论上甚至可以印出更多;协议生成的代币与有真实抵押支撑的合法供应,在表现上没有区别。

  • DeFi 的可组合性在同一笔交易或同一区块内完成了整个攻击。攻击者把伪造的包装资产存入 Aave,以此借出 USDC 或其他真实资产,并在任何人意识到发生了什么之前抽走价值。借贷池最终留下的是没有资产支撑的包装资产抵押品。

4. Aave 的共享抵押池吸收了包装资产的失败

  • 主持人问道,单个放贷者是否曾明确批准过这种冷门抵押品。Tom 区分了隔离市场和共享资金池:在隔离市场中,放贷者可以拒绝接触再质押ETH等资产;而共享资金池允许多种抵押品并存。他认为,受影响的 Aave 敞口主要位于共享资金池。

  • 他的类比是伪造 USDC:如果有人拥有无限铸造权,就可以在被发现之前把虚假单位交换到整个 DeFi 体系中,最终让所有接受这些单位的协议都留下缺口。此次事件中,包装资产本身并非完全虚构;问题在于,攻击者创造了额外单位,却没有增加这些单位所代表的抵押资产。

  • 因此,Aave 面对的是坏账,而不是可以回滚的记账错误。Tom 提到系统存在储备金或安全基金,但怀疑它们不足以覆盖全部金额,最终会形成一笔“巨额损失”,由某处的用户承担。

  • 录制时,损失如何分配仍未确定。Tom 将 Aave 的声明理解为,受影响的 L2 用户可能承担折价,而主网用户受到保护;但他反复强调,最终处理方式尚未敲定。

5. LayerZero 的技术辩护无法解决责任归属

  • 按 Tom 的描述,LayerZero 的回应在技术上站得住脚:应用此前已被警告不要只依赖 LayerZero,而协议只是处理了一条由其配置的验证者签署的消息。但他的“枪”类比指出了责任问题:说机制正常运行,并不能解释为什么一个被攻破的签名者可以授权灾难性的资产发行。

  • Banteg 提议让所有相关方坐到同一个房间里,这一方案之所以引发共鸣,是因为公开回应已经变得法律化。各方似乎都在维护自己的辩护口径并将责任推向别处,而不是先确定究竟是谁接受了哪一种风险。

  • Tom 将批评扩大到单一服务商之外。LayerZero、Wormhole、Axelar及其他类似的互操作系统,最终都依赖小规模验证者集合或多签,来证明另一条链上的事件确实发生过:“我们没有去中心化的跨链消息传递,这种东西现在根本不存在。”

  • 他说,LayerZero OFT 中大约承载着150亿美元价值,并认为 WBTC 就是一种 OFT。只要某个权威可以在没有对应价值的情况下创造跨链供应,基本的资金抽干风险就仍然存在。

6. 被盗资金容易识别,追回却困难得多

  • 将资金从 L2 转移到 Ethereum,可能需要经过一笔有约7天延迟的规范提款。资金一旦进入主网,大型黑客往往会通过 THORChain 等路径寻找 Bitcoin 更大的流动性,随后可能尝试通过类似 CoinJoin 的系统或离岸中心化交易所进行混淆和套现。

  • 规模本身就是攻击者的问题:数亿美元很容易被识别,也很难移动或出金。Tom 假设自己偷走这笔钱后会选择用真实金额的10%换回全部资金,这一回答很能说明问题——因为他不知道有什么干净的方式可以实现全部价值。

  • 国家支持会改变追回资金的逻辑。一个使用 AI 的机会主义少年,可能会因为面临入狱而恐慌,用5万美元换回一笔300万美元的漏洞收益;但如果攻击者确实是 Lazarus 或朝鲜,几位嘉宾认为没有现实可能通过白帽方式追回资金。资金可能因此多年原封不动地躺在那里,等待更好的隐私技术出现。

  • Thread Guy 说,如今大型黑客事件似乎每2到3周就会出现一次,而过去大约每几个月才发生一次。攻击者光谱包括花数月时间攻破基础设施的高水平组织,也包括把合约粘贴进 ChatGPT、要求它“让钱出来”的新手。

7. Hyperliquid 的桥是中心化的,但相对更容易看懂

  • Tom 表示,HyperCore 本身由12名验证者维护,验证者拥有质押资金,恶意行为可能受到惩罚。真正不同的风险点是 Arbitrum 存款桥:它基本上持有 Hyperliquid 内部所代表的全部 USDC,安全机制据他了解是三取二多签。

  • 主持人称,截至4月26日,该桥 TVL 约为47亿美元。理论上,多签持有人可以任意转移这笔资金;但在实际操作中,Tom 认可其已沟通的流程、对可疑活动的暂停机制,以及被盗 USDC 可以被 Circle 冻结这一事实。

  • Tom 的结论有意保持相对性:桥接风险“绝对存在”,也并不理想,但在他当前对加密安全的担忧中排名靠后。

  • Thread Guy 称 Hyperliquid 是“如今我们拥有的安全性糟糕实现中,最好的一个”。两人用汽车作类比:一辆普通 Chrysler 在没有真正对比对象时,可以看起来像 Rolls-Royce。Hyperliquid 尚未实现无需信任,但把不同实现放在一起比较,可以看出哪些团队更认真地对待了自己的中心化瓶颈。

8. DeFi 会忘记这笔损失,但老兵会记住教训

  • Tom 对 DeFi 仍然保持结构性看多,因为加密资产可能会继续存在,而持有人仍然需要借贷等基础金融设施,以数字财富作为抵押。此次受影响的用户总体上是成熟参与者,而不是通过某个应用随意入场的普通新人。

  • 他援引 DeFiLlama 的一篇帖子称,几天内已经有150亿美元退出 DeFi,随后预测熟悉的反转会再次发生:“给它4周”,等收益率上升,寻求杠杆或收益的资金就会回归。LayerZero 可能会取消单一签名配置,但换成三取二只是缓解中心化,并不能消除中心化。

  • Thread Guy 说,ETH 看起来对此无动于衷,而 AAVE 和 LayerZero 下跌,部分原因是方向性交易者看到坏消息后“顺手做空”,而不是更广泛的社区在对冲直接损失。

  • 两位嘉宾都没有在自己的时间线中看到有人承认亏钱。Tom 猜测可能有约1,000名用户。Thread Guy 推测,资金可能来自追逐6% ETH收益率的中型流动性基金,并追问:只有几百名可见用户的薄流动性 L2 池,究竟是谁提供了数亿美元?他说,在 DeFi 夏季,这种匿名流动性有时最终会被发现来自 Alameda,而 Alameda 最终并没有想象中那么成熟。

  • 个人是否暴露在风险中,决定了集体记忆。Thread Guy 说,他至今仍记得 DeFi 夏季那次让自己损失约1万美元的跑路事件。那些在 FTX 上亏钱的朋友至今仍然愤怒;而由不熟悉的高杠杆持有人承担的损失,会变成又一道“战争伤疤”,尽管“钱离开赌场并不是好事”。

  • 但反复发生的事件仍会改变长期资产配置。Tom 认为,Bitcoin 的简单性——“Bitcoin 什么都不做,而这正是我喜欢它的地方”——限制了功能,但也限制了攻击面。它的韧性已经通过时间得到证明:网络存活得足够久,美国政府不可能直接将其关停。

  • 他的职业建议遵循同样的降风险逻辑:持有耐久资产,然后在自己拥有的东西上创造价值。“你不可能靠交易走到”巨额财富,靠日内做多和做空尤其如此;更好的路径,是建立一家企业或一个项目,让其中的股权最终有机会价值数十亿美元。

核验说明

讨论中并未确认包装资产的确切名称(“rsETH 还是别的什么”,之后又说成“rswETH”)以及源链名称(“Duty Chain[?]”);本摘要使用“再质押ETH包装资产”这一表述,并避免为该链命名。

完整逐字稿
Thread Guy

Dude, I'm happy you came back on. I knew you came back on with no notice, too, which is awesome. You're one of my favorite—honestly, one of the sickest guests ever. You came on about 6 months ago. I consider you, honestly, a good friend at this point. Great comms on the crypto side. Do you want to give a quick intro on who you are, and then let's hit what the fuck just happened in DeFi? What is the future of DeFi? We'll get there.

Tom Kysar

Yeah, for sure. My name is Tom. I run a bridge called gas.zip, mainly geared toward smaller-value transactions, but with really high chain coverage. We're a bridge very similar to the Relays of the world today. We're focused on instant delivery and very cheap transactions, with a lot of tradeoffs. This is kind of what you get into with what happened with LayerZero today.

I spent a lot of time in my life building crypto stuff that literally nobody ever used. This is a lot of people's journey: I spent 10 years building shit that nobody ever used. This time around, it was very much like, "I want to build something that maybe some people will use," and afterward you can back your way into making that technically sound solution. I feel like that's how a lot of the apps people use today went with this generation's approach. Build something that first solves the problem of a couple thousand people. The corners are going to be rounded. Is it decentralized, like the Trump stuff?

I do bridging stuff. I did prediction markets for a long time. I mostly sit around and read Twitter all day, but bridging has been the main thing for the last couple of years. We've built stuff on LayerZero, right? Traditionally speaking, I'm a LayerZero guy. In a broad stroke, I'm a LayerZero shill.

That doesn't mean the stuff that happened today—or this week—was, for lack of better terms, pretty fucking bad. Plus, it's going to be fucking bad next week.

Thread Guy

Talk about it. I'll be honest: I was not online this weekend, and now I'm catching up. Some of it is all over the place. We had back-to-back incidents. We had Drift, which I know is kind of a fake DeFi label, but it got the label, and I think it was exploited for $300 million. Then we have everything that just happened over the weekend.

We can skip the Drift one. I think that's been debunked. That was just piss-poor management, some social engineering, and a little bit of everything. But there's this broader, secular terror—this terrifying fear around DeFi exploits and hacks. At the same time, we have what just happened with LayerZero.

Can you give us a breakdown of what just happened, how $300 million and some change was exploited—correct me if I'm wrong on that number—and then let's dive into the specifics of what DeFi looks like from here.

Tom Kysar

Yeah, so this was kind of the dark underbelly. This was the classic FUD that you would fearmonger about not only with LayerZero, but with a lot of DeFi protocols. It was one of those things where we all knew this wasn't ideal. It was kind of the worst fear that nobody really thought was going to happen, but we all knew could happen.

Thread Guy

Yes.

Tom Kysar

It pretty much all boils down to this: for lack of a better term, particularly in bridging, I have a saying that Roger Ver is like, "Everything's just kind of a scam, man," right? All this stuff kind of works until the scam doesn't work anymore.

What happened here was essentially that LayerZero is the messaging-verification provider for this wrapped Ether token. I don't even know what this wrapped Ether token is—rsETH or whatever.

Thread Guy

Yeah, yeah, one of these, like, rsETH. I don't even know what it is. I don't—I really don't understand it. Dude, I stopped once we got 2 or 3 loops down the restaked ETH.

Tom Kysar

Okay, okay, okay. But essentially, they act as the authority for minting and burning this token. LayerZero protocol will validate messages that say, "Burn some tokens over here, re-mint them over here." In shitcoin terms, they're the mint authority; they're the admin key.

LayerZero is designed in a way where validation of those messages should and can be done by many people. That's what the DVN is, right? Normally, when you say, "I have 1 ETH over here and I want it over here," there should be 3 or 4 validators in the middle that all agree on this process. However, the default in LayerZero is actually just LayerZero sitting in the middle.

Thread Guy

Just 1.

Tom Kysar

You can compromise 1. You got it.

Thread Guy

Yeah. That was the issue. LayerZero is designed in a way where the application gets to choose who those validators are. However, the default setting is just 1, and it's just them. This is why people aren't really super happy with LayerZero's answer, because LayerZero's answer is basically, "We told you not to just use us as the validator. You can go and put more validators in there."

Thread Guy

And is it cheaper, more efficient? Why do you just use LayerZero?

Tom Kysar

The real thing is, we built stuff. I think most people don't even fucking know how to configure the stuff they built. You don't even really know. It's just built into the config. You don't really dig into it and start understanding what's happening there. You start to comprehend all these different configurations that you can make. But even just building a simple application on top of these protocols, you probably don't even really fucking know what's happening there.

Thread Guy

Serious?

Tom Kysar

No, it's like you just deploy these repos. You might know what you're doing, but it's the default. It's the thing with everything, right? You put in a default, and 90% of the time people are going to use the default. They don't really know, and they don't really care. For the most part, it's been fine. In LayerZero's defense, the last 3 years have been fine.

This is how a lot of this stuff works in crypto. It's kind of centralized underneath it all, and we obfuscate it along the way. It works until it doesn't. At the end of the day, there was a wrapped asset backed by hundreds of millions of dollars that could be minted and burned arbitrarily by LayerZero—1 singular validator key running somewhere—with no security.

If you lie as an Ethereum staker, as a node participant in the network, you get slashed. You stake your ETH, and if you lie, there's a penalty. That doesn't exist here. This is just LayerZero lying. They didn't lie; they were wrong. There's no penalty for doing it. It's just, "Oopsies. Sorry—$350 million. That's it."

There was $350 million of backed liquidity that could be minted, or could back the minting, of this restaked token. Somebody somehow figured out how to compromise the singular LayerZero validator and say, "Mint 300 billion of ETH to this wallet." It got checked, greenlit, and went through.

Then those tokens don't even need to be backed by everything. They could have printed a billion of them. Once you get those tokens minted, they're used as collateral in Aave and all of these DeFi systems.

Thread Guy

God, you get these tokens—what do you do with them? You throw them into Aave and cash out USDC or something.

Tom Kysar

This is why Aave is now in a world where all the real money's gone, because they just printed a bunch of—

Thread Guy

Because if you're a lender on Aave, you're approving all this random shit. What even is it?

Tom Kysar

If you accept this weird wrapper token as collateral in all of DeFi, and I can just print this weird collateral token, I go and swap it out in all these DeFi systems for the real money. I give you this token that is backed somewhere, but that minting wasn't backed. I hit infinite mint on the token and swapped it out everywhere.

Thread Guy

Is it on you as a lender to approve this random restaked ETH token, or does that whole system just recognize this as Ether?

Tom Kysar

It depends on what pools you lend into.

So this is like—I think the ones that got hit in Aave were shared pools. If you go to a lending market, they'll have things called isolated lending pools. We've started moving toward some of these, where, when you're a lender, you essentially say, "Yeah, I don't want someone to be able to give me rswETH as collateral off my real dollars." I believe most of this was shared.

But this is how DeFi would work: if DeFi just blows up, imagine somebody could just mint USDC, right? The USDC would be worthless, but they could use that USDC to exchange USDC across the whole system.

Thread Guy

Exactly. And if at any point there's ever some exploit, before you could catch it, you could run to a DeFi platform—Aave—and borrow against it fast, get money out, and then they can't force you on-chain to return it.

Tom Kysar

And even—I mean, yes. The actual reality is that it happens in the same transaction, right? It's like—

Thread Guy

This happens in a single block. You didn't know what happened. It's like these guys mint these things. Okay, so somebody finds an exploit on LayerZero where they can basically mint—

Tom Kysar

What LayerZero said happened was that they compromised their RPC provider. The scary part here is that LayerZero runs nodes, and they connect to an RPC in your wallet. You have fallback systems: when a node isn't available, you fall back to another one, and another one.

They said essentially their good nodes were DDoS'd and turned off, so it fell back to 2 backup nodes that they run. The backup nodes were apparently compromised at the root level. This is the part I was kind of like—this is the scary part of the whole thing. LayerZero's core internal infrastructure was compromised somewhere here.

If this is true, their private internal nodes were running, and somebody was able to get in there and essentially put in a fake block. It said that this block happened on Duty Chain[?]. That's how they compromised the node to report that somebody bridged $35 million—or $350 million—from Duty Chain[?], and that didn't happen.

The terrifying part here is that the core infrastructure of this protocol was compromised at some root level. If you have root access to LayerZero's infrastructure, I would think you could really do some damage. There was a hole somewhere in LayerZero's infrastructure, and North Korea got in there, or whoever. How does this happen?

This is the first time we've really seen an attack like this, where they say, "I compromised your node provider." Even think of you—you just use your wallet, right? What happens if your RPC provider lies to you? It's terrifying. But that's what happened.

Thread Guy

Somebody said that you DDoS LayerZero's RPCs, and there are a couple of backup ones that you figure out how to get control of. There's root access, where you only need 1 validator from LayerZero, and you figure out if you can convince this validator, "I'm [__]." Generally, you convince this validator that you've greenlit the transaction, and you can mint $300 million and some change of this rswETH—double- or triple-restaked ETH—to your wallet.

In the same transaction, you send it to Aave, borrow against it, and pull out cash before anyone even realizes what happened. You have $300 million in cash. Bottom line being, you don't even know what happens, because it's like—

And whose money is this? Your money. The pool of capital—not on Aave, but the pool of capital to mint the $300 million in ETH—where does that stem from, or is that just—

Tom Kysar

It's like you're just creating a new asset. There's no money required. You just create $350 million worth and then borrow against it.

Thread Guy

How does that get created?

Tom Kysar

There was no—I mean, you know, there is backed restaked ETH of this that exists in the world.

Thread Guy

It isn't backed. This is just new added capital.

Tom Kysar

Yeah, this was just minting the shitcoin. This was just, "Mint the shitcoin," and—

Thread Guy

Got it. So basically, they minted a fake token that isn't worth $350 million, but they were able to borrow $350 million against it. The lenders are out $350 million in cash.

Tom Kysar

Oh, yeah.

Thread Guy

Aave gets destroyed because $350 million just went to something that was not real and bypassed their system, basically. They have rswETH in exchange for it now, which isn't worth anything because they just created it out of thin air. So what does Aave do? What's everyone looking at now?

Tom Kysar

Aave has what's called bad debt in the lending system, right?

Thread Guy

Yes.

Tom Kysar

And it's never good. They have reserve pools—an insurance reserve pool, like a security fund. I don't think it covers this. The broad story is that there's going to be a haircut. People are going to lose money.

Now they're debating where that haircut comes from. Does it come from people who had this wrapped ETH only on L2 chains? Does it come from people who had this ETH on mainnet? This hasn't been decided yet, I believe.

But Aave made a statement the other day that kind of leaned in the direction that the people on the L2s are probably going to be the ones to take the haircut, and that the mainnet users probably shouldn't be the ones who have to eat this loss. There's going to be a massive loss that has to be eaten somewhere, right?

Thread Guy

It's the users' money.

Tom Kysar

Yeah, that's the thing. This is what happens when you exchange real money for a token. It's not that the token was garbage. It's that you're trading coins, and the developer has infinite mint.

We have all this stuff in place to hopefully make it so the developer can't use infinite mint, or that the developer won't use infinite mint, or that it can't happen. But it still exists.

LayerZero—the DVN of all these OFT tokens, these wrappers and stuff—the interoperability network is the developer. We try to make it so 3 people need to agree before infinite mint can happen, but in a lot of these cases, it's just 1 of 1.

Thread Guy

Really?

Tom Kysar

There's no decentralized cross-chain bridging. All of this stuff—LayerZero, Wormhole, Axelar—it's all the same thing. It's a couple of validators, or 1 in this case. The terrifying thing is that we don't have decentralized cross-chain messaging. It just doesn't exist yet.

We all obfuscate it, and whoever obfuscates it the best has the best interoperability protocol today. But LayerZero is a multisig validating messages that happened over here and happened over here. You put all this stuff on top of it, and it becomes an interoperability network, but it's the same thing as you sitting there and saying, "Yep, a transaction happened over here. Yep, a transaction happened over here."

Thread Guy

Sorry. If it needed to talk natively, so—

Man, tell me this. I saw this post: how does the hacker get the money off-chain? CEXs won't take it. You can't lend it anymore. You're stuck. You can't off-ramp at all. What do you do?

Tom Kysar

It's hard. If you had hypothetically hacked $300 million, what would you do with it?

I would try to return it for 10% of the real money. I don't know how you get that money out. I really don't. But if you get it on L2, you can canonically bridge some of it out, which is the 7-day exit back to mainnet.

Thread Guy

Explain that.

Tom Kysar

You have money on Arbitrum and you want it back on Ethereum. This is the slow withdrawal, essentially. The money that the hacker has in ETH exists somewhere—in the Arbitrum bridge, or wherever it is.

The real issue is that once you steal such a large sum of money, it's hard to do anything with it. Even if you have it all in something like mainnet ETH, it's still really hard.

What you see today with large sums is that they try to get it to mainnet. Once you get it to mainnet, they try to get it to Bitcoin, because Bitcoin is the largest asset. Bitcoin still has tumbling pools, right? What do they have—CoinJoin, whatever.

Thread Guy

This is like, say something gets hacked and they shove it all into THORChain, right? And then—yeah, yeah, yeah. All right. Because the pool of BTC money to launder your money in is much larger than the pool of ETH to do that in in the world, right? But still, I don't know how—I mean, I would be led to believe there are still effective ways to do it, considering North Korea still does this.

I mean, Bithumb, you know, I think they laundered like a billion dollars with the Bithumb hack, right? And most of it has actually gone through THORChain. A lot of it is just these shitty centralized exchanges, because offshore CEXs, right? Shove it through KuCoin, shove it through whoever.

But then I don't know, because at some point, when you have such a large pool of stolen money, it's hard to hide it. You can't—it doesn't matter, right? You deposit it—

Tom Kysar

Take it, right? No one's going to take it. It's really easy to identify. You know, and this is—I don't know. Maybe North Korea has some nuclear bomb suppliers that just take their Arbitrum ETH directly. But in reality, I imagine they probably try to start laundering it, but a lot of the time you see the money just never move. They'll just sit there.

Thread Guy

Just sits there and you just [__] jerk off to it. Yeah. Show it at the club. When they used to arrest really early guys who'd steal a lot of Bitcoin on the dark net, blah blah blah, they would never move it. They'd arrest them 5 years later and talk to them, and they would be like, “Yeah, I didn't really do anything with it.”

And their bet was just to hold on to it. In 20 years—

Tom Kysar

Something would happen. There would be some new crazy Zcash or Monero, blah blah blah, and they would be—you know, they just sit on it forever, right?

Thread Guy

But I don't know if they've started trying to launder the money yet or move it around. Assuming this is actually what they think—a Lazarus, North Korea-esque, state-sponsored actor—I mean, there's no recovery there, right? There's no chance of this money ever coming back. There's no chance of a white-hat bounty. That just doesn't happen, right?

Sometimes you get lucky if it's some [__] kid who was just [__] around with AI and stole your protocol's $3 million. He's like, “Oh [__], I'm going to go to jail for that. All right?” And he's like, “Give me $50,000 and I'll give it back.”

But this is scary because we think there's some security around the wallets that hold our money, and that security just doesn't really exist. We don't really know, right? Even with EVM stuff, it should be the most secure. The contracts are verified, they're reused all the time, and everyone can read this stuff and figure out what was happening.

Then you go to all of this—this is my long-tail, bear Solana ecosystem case—where nobody knows what the [__] any of this stuff is doing, right? We don't even know what's happening on Ethereum, and Ethereum is open source, reused, audited, and everyone can read it. With Solana, nobody can even read most of this. Nobody knows what's happening, and that's probably playing in its favor right now because it makes it harder to attack.

But I can only imagine how many [__] exploits exist out here. Nobody can read this [__] yet. Nobody knows how to use it yet. If stuff like this is still happening with EVM contracts and systems that have been public and reused for many years, and we still find new problems every day, the more complicated you make something, the more it becomes security by obfuscation. That's not a good security method, right?

At some point, I don't know. I don't know how any of this Solana stuff works. I've no [__] idea. I don't think I've ever read a Solana contract. I don't know where I would read it if I wanted to. On Etherscan, I can go read contracts and kind of see what's happening. I have no idea with Solana, and that's good because it means there are a lot of people who can't easily go and attack it, right?

But at some point, I don't know. All this stuff is [__] terrifying, man. The fact that we put our money in this [__] is absolutely terrifying because a lot of it is safe, but do you have any idea?

I don't have any idea. You put your money in some DeFi thing, some app, possibly some perp exchange, right? Who the hell knows what's happening there? You don't read this stuff. I don't read this stuff, right? And the more complicated it gets, the more it's not a problem until it kind of is.

Nobody ever talked about the fact that LayerZero was secured by one validator. Nobody talked about this. It was there. A bunch of people knew it, and we all kind of knew it existed, but nobody ever talked about it.

Some guy made a good point: they onboarded this collateral on Aave and looked at the onboarding application. It was never even brought up that they were adding collateral that could be minted arbitrarily by one key that might be in LayerZero's basement server. It was never even brought up.

There's a lot of existential risk that exists in all of this. All things considered, we're probably pretty lucky to the extent that we've been. The hacks are bad, and we have all this stuff, but I think there are terrifying problems that exist out there that just aren't happening yet.

It takes well-resourced, dedicated, sophisticated attackers. That's kind of what you're seeing today with these North Korea-esque groups, right? That probably took these guys—I don't know how you even compromise LayerZero's core infrastructure—but this is the kind of thing that probably takes many months. It takes a lot of money, a lot of resources, and a lot of effort.

On the flip side, we've had a couple where kids just put a contract into ChatGPT and say, “Hey, can you make the money come out of this and give it to me?” Occasionally, it just happens.

Combine all of this together, and putting your money in contracts is honestly a terrifying proposition. All of crypto is kind of a terrifying proposition when you start to think about it, and we're giving everybody the tools to really poke at it today, right? This is why we see a hack every 2 or 3 weeks now. It used to be once every couple months that you would see a big hack.

Maybe? Big, big one every cycle.

Tom Kysar

And they're kind of the same thing. The Drift thing was functionally a centralization issue, right? It was somebody who had the authority to make these admin decisions.

Thread Guy

Social engineering type of thing. Yeah.

Tom Kysar

A [__], yeah. Whatever being compromised, it boils down to there being a single source, key, or person in the system that has the power to make these decisions. Their dev has an admin key, and you've been there: your coin is going up, and then the dev mints a bunch of it and rugs the pool. It's the exact same thing, but with DeFi protocols, right?

Granted, I think the TL;DR is that this one is not coming back, for sure. I think Wormhole was something kind of similar 2 or 3 years ago, if you remember, when Wormhole had a $5 million hack.

LayerZero's response is that the protocol acted and behaved as it should have, which isn't wrong. But it's also kind of like, “Hey, you shot yourself in the face, but the gun functioned properly. It functioned as it should have.”

Because it's true: LayerZero behaved as it should have. This validator validated a message. It's just that the message was fake.

Banteg had a good model a couple hours ago, and I think this is the way it's going to go. He said something along the lines of, “They should get everybody in the room together.” As of right now, everybody is not taking blame, talking in very legalistic terms, and lawyering up.

I think that's what's happening right now. Everyone is terrified of, “Was this my fault?” And nobody is sure who's under the gun for this.

Thread Guy

Is it like—no, is it whatever this Ether thing is? Who knows. But I think this is such a large amount that I don't think anyone's really going to take blame. It's not good either, because everybody's pointing their fingers at everybody else.

I have one question I have to ask you. I don't really want to ask it because I'm scared of what you're going to say. What happens to Hyperliquid here? This is the terrifying thing too, right?

Thread Guy

Take the Hyperliquid take. Just do it. Just do it. Just do it.

Tom Kysar

No, I mean, Hyperliquid is much better in the sense that HyperCore, the chain, does have this 12-validator network. There is a network of validators maintaining and running HyperCore, and these validators have a stake. If they behave maliciously, money will be taken from them. There's a cost.

The scary thing about Hyperliquid is the bridge. The Arbitrum bridge, when you deposit money into Hyperliquid, is still a multisig. I think it's a two-of-three multisig. How much money is in that bridge? This is the joke that Arbitrum became: the purpose of Arbitrum is just to be a bridge into Hyperliquid. There's a contract on Arbitrum that has billions and billions of dollars—essentially all the USDC that exists in Hyperliquid.

That is a multisig. Granted, from what we know about it, it's not anywhere near the same thing as what just happened with LayerZero. It's not like it got exploited because a single key existed on a server in someone's basement and North Korea got in, which is kind of what happened here.

The Hyperliquid multisig is, I think, two-of-three. They've communicated some of their procedures for how the multisig will interact. It can go into a paused mode if something looks suspicious. All things considered, it is a somewhat sounder deployment of this. At the same time, there is a multisig somewhere that can arbitrarily steal all of the money out of that bridge. That's its existential problem and concern. It's nowhere near the single-key scenario, but functionally, it's still a multisig.

Thread Guy

As of April 26, the Hyperliquid bridge holds approximately $4.7 billion in TVL.

Tom Kysar

If you steal it, you would get USDC. USDC is freezable by Circle, so it's a less desirable asset to steal because Circle can freeze those coins. But you would still steal it all and try to siphon it out for Ethereum as quickly as you can across all this stuff.

In a broad stroke, the Hyperliquid bridge being a two-of-three multisig is low on my list of modern crypto security concerns. Does the risk exist? Absolutely. Is it great? No. It's not something that—

Thread Guy

That's it if that happened, right?

Tom Kysar

It doesn't have to keep me awake at night. I think there are a lot of other things that are more relevant and higher on my list.

Thread Guy

What's relevant and high on your list? What's the biggest thing that's high?

Tom Kysar

Honestly, it was this kind of stuff for a while: interoperability and bridging, because a lot of tokens use these token standards today. LayerZero's is called an OFT. It's like an ERC-20, but it allows the token to burn and mint on all these different chains between each other.

Exactly what happened here is going to happen in many other cases, where you can mint a token when you shouldn't be able to. That token is now worth a lot of money in all these other systems, and you can clean all the real money out in exchange for it.

Pretty much every interoperability protocol has this risk. I think LayerZero's OFTs have around $15 billion of value in them. I think WBTC is an OFT today. Wrapped Bitcoin is one of these things, and they all have this same security model.

There is functionally some level of centralization in the world that is the authoritative validator of this supply being created and destroyed. If you can get it to create value without that value actually existing, this is what you get. Interoperability has been my biggest fear for a long time, and I think that's where a lot of the value resides.

The boiled-down version is that our biggest risk is centralization being exploited, much more so than a contract having a bug. Bugs happen. Our biggest risk is building systems where you or I have the authority to control the system more than the average person or regular participant, and then being compromised by a bad actor.

Underneath all this, we want to get to a point where everything is decentralized and trustless and build these good systems and services. Functionally speaking, it's still very early with a lot of this. That's the dark secret of the room that nobody likes to talk about: everything's still kind of centralized.

Thread Guy

That turns into a new problem, right? All right, it's two of the guys. It still exists, but you'll solve the root-level problem.

Okay, give me a take on this. One of the last things I want to ask you—by the way, thank you. Terrifying, but thank you. What happens to DeFi from here?

Tom Kysar

I don't think DeFi is going anywhere. I'm a big believer that DeFi wins in the long run. I don't think it wins to the extent that everyone expects, but I think DeFi wins in the sense that crypto will be a persistent asset class in the future.

There are people like me, probably like you, who are going to keep most of our life's value in some digital system, service, or asset. The ability for us to borrow against these assets and have some basic level of financial infrastructure that we can use—that's where I think DeFi wins.

I don't think DeFi ever dies. The average user didn't have his money staked in restaked Renzo ETH and then put into Aave in a loop. These are sophisticated people taking a loss here for the most part. They are average people and average DeFi participants, but this isn't some guy onboarded through an app and stacking DeFi easily.

My actual answer is that I don't think anything happens. This happens every couple of months, and we forget about it in 2 weeks. Everyone shrugs it off.

In the short term, DeFiLlama had a tweet saying that around $15 billion had exited DeFi in the last couple of days, proactively. So, in the short term, there will be a lot of capital that leaves. But give it 4 weeks. Yield starts going up a little bit, there are things people want to buy, and they want to start lending and getting some dollars back. It slowly makes its way back in.

You ever go on Rekt.news and look at the leaderboard of all the hacks of all time? I think this is another war wound that will go on that list. How many times has something changed? The last time you lost $500 million, nothing changed. Literally nothing. What will change in practice is that LayerZero is no longer signing one-of-one DVN messages, so this exact problem probably doesn't happen again in the future.

Even if it's now two-of-three, it's a new problem. All right, it's two of the guys. It still exists, but you'll solve the root-level problem. No, I don't think anything really changes.

In reality, everybody forgets about it because it's not their money. I'm going to forget about it, and you're going to forget about it, because it wasn't us. Did you lose money in FTX? I have friends who lost money in FTX who still wake up every morning, say a prayer, and hope Sam Bankman-Fried gets drone-striked that morning. They still hate him because they lost money.

The average person who lost money in FTX still feels it and remembers it. None of us really feel this. I would actually love to know how many unique people in this wrapped ETH lost money, but it wasn't me.

Thread Guy

It’s not you. It’s not a lot of these guys on our Twitter feeds, right? We all kind of shrug it off and forget about it because, well, it wasn’t me who lost the money, right? But when something happens and you lose money in it, you remember. I’m still thinking about the rugs I got scammed in during DeFi Summer, right? I still think about that. A guy scammed me for $10,000 or whatever.

For the most part, when it doesn’t affect the larger participant group of us, we tend to shrug it off and forget about it, right? That’s reality. It makes sense, right?

Tom Kysar

Even with the FTX thing, I didn’t lose money in FTX. There’s a very real scenario where I could have; I just didn’t use FTX. I have money in Coinbase. I know it’s not exactly the same thing, but I do have money on Coinbase—not all of it, but the majority of it. You know what I mean?

If $300 million were lost from Coinbase users tomorrow, this would be something like an FTX event that had long-lasting effects, because we would all be affected by it and it would suck, right? Rather than—I don’t know. I honestly think it was probably 1,000 people who lost money in this. I don’t know what the unique token-holder count is in that.

Thread Guy

Good take. I’m just here wondering, you know, trying to gauge the severity of the situation. The only thing you can really do is watch the market. ETH doesn’t really care. AAVE is down, as expected, but it trades like shit anyway. LayerZero is down, but it’s down because you and I see this stuff and we’re kind of like, “Oh, this can’t be good for AAVE. Maybe I’ll just go slug a short on it,” right? It’s not like we’re hedging our risk because we lost money in AAVE’s lending market or whatever. No, it’s mostly just directional shit traders who are like, “Oh, bad news—go short the asset,” right?

But it doesn’t really... Yeah. This is the bold take: there’s actually so much slosh of money in this system that we can lose $300 million and we’re kind of like, who does that actually affect? Who are these guys? I honestly don’t even know who a lot of them are. Who puts $300 million in this market?

Tom Kysar

Good question. Who are these guys? Who are you? Why are you doing this?

Thread Guy

Who are you? I agree. Sometimes I go on DEX Screener or pull up the Celo chain. It’s a chain—you know it exists, but you’ve never used it in your life and never seen it. Go look at the DEX pools. There are $200 million in these DEX pools. Who are you that you’ve put $75 million into some mid-tier L2 that has 300 users, and you just keep $100 million there? I don’t know who these people are, right? But it’s sure not me, it’s sure not you, it’s sure not any of us.

Who triple-restaked their ETH and then borrowed against it recursively in Aave? Some sophisticated friends I know made a lot of money. I’m not doing that shit. I’m not doing that shit. A lot of people do that, though.

It’s actually a good take, Tom. I’m not going to lie. This is actually optimistic. I don’t know if they’re institutional. The actual answer might just be these mid-sized funds. You see these mid-sized liquid funds and stuff, and they have $100 million. They’re like, “Oh, I want to get my 6% yield on ETH,” so they put it in here, borrow against it, and make some shitty angel investments or whatever.

All I know is this hack happened. I haven’t seen a single person on my timeline who’s like, “Fuck, I lost money.” I haven’t seen one. No, I haven’t seen one. I’ve seen people saying, “Fuck DeFi.” I haven’t seen one person say, “I lost money.”

Tom Kysar

Me either. Who lost the money? One of these people, right? And then we just kind of forget about it, and it’s like nothing really changes. I don’t know.

Thread Guy

This is kind of why things never really get better either, you know? There are some soldiers out there who constantly come back in and put hundreds of millions of dollars into these systems and take the blunt force of a lot of this.

DeFi Summer—this was Alameda. Alameda was debt-pooling with $300 million cash on-chain, right? You would go sell this yield-farm token and you’re like, “Who the fuck put $150 million in this shitcoin LP pool that launched yesterday?” You look, and it’s Alameda. You’re like, “Oh, they must be sophisticated and know what they’re doing.” Then you come to find out, no. It was Caroline and Sam Trabucco just like, “I don’t know. Put some money over here. We sell the shitcoin, and we don’t really hedge the stuff.” They didn’t know what they were doing either, right? Ultimately, they were the ones that would eat the loss.

And what was the end result of that? Alameda blowing up. These were the people capitalizing a lot of these very large on-chain pools of money, right?

Tom Kysar

[Snorts]

Thread Guy

But the number can be really big and really bad, which is kind of what happened here. In no light is this a good event. It’s not good for anything either, right? In a broad stroke, money leaving the casino isn’t good. Regardless of whether it’s your money or somebody else’s, money leaving is bad, right?

Tom Kysar

Of course, of course, of course.

Thread Guy

Money leaving is bad, right? But at the same time, it’s a lot worse when it’s all of us. It’s a lot worse when the group chat gets—when you go on Twitter, in your GC, and everyone’s just like, “Holy shit, I lost money.” That has much worse ramifications across everything: the vibe, the sentiment, everything.

We’re going to forget about it next week. That’s just the nature of the beast right now, right? Some things will change, some security will get better here or there, et cetera, right? But the optimistic take is that the active participants around here—I don’t think any of the ones who lost the money are going to affect the vibe a lot, right? I don’t think this kills the vibe. Is that good?

Tom Kysar

Yeah, it’s not going to cover FTX.

Thread Guy

Am I even going to cover it today? No one’s talking about it. It’s over. It’s kind of... I don’t know. This is the part that gets me: I don’t know if that’s a good or bad thing. I really don’t, right?

Tom Kysar

What does that mean, exactly?

Thread Guy

Part of losing $300 million is that it’s a really big thing. This is a world-changing, huge thing, right? And we’re just kind of like, does it really matter? Does it matter? I don’t know, because I know it matters when the 5,000 people who actively use all of these apps and products in crypto lose money. We all get pissed, our sentiment goes back, and we stop trading, making things, trying new things, and experimenting.

Here, it’s just a large loss, but is it going to change how you or I—or anyone reading this—is going to behave tomorrow? It’s not going to change how I behave tomorrow, really. It changes how I view things long-term; I want to build things in crypto, but tomorrow I’m not going to do anything different in crypto because this event occurred, right? I don’t think most people are either.

So you can just poof half a billion dollars out of the ecosystem, and it’s like: who did it affect? Who did it matter to? Is it going to change anything? In this case, I don’t really know if it does, right? It’s an interesting thing to cover. It’s a big event, but at the same time it kind of feels like shit to say, but it doesn’t matter. I don’t know. Does it matter? Are you going to not trade something tomorrow now?

Tom Kysar

No money’s leaving Hyperliquid. Yeah. The good in this is that it’s favorable for a Hyperliquid-type thing. Even though Hyperliquid has these decentralized multisigs, you look at that now, and even though it is a potential central point of failure, you look at that in comparison to the 1-of-1 DVN that LayerZero was running with all this value, and it makes Hyperliquid’s 2-of-3 multisig look really good, right?

It makes it look like all these guys know what they’re doing. Functionally, it’s still not great, but it really does. The shills will say it, right? They’re like, “The team is great, and they put care into the thing,” and you don’t really see that until you put it side by side with something that’s really shit.

Thread Guy

Yeah, yeah, yeah, fair, right? It’s like Hyperliquid is the least of my...

Tom Kysar

You say a Chrysler 300 looks like a Phantom until a Phantom pulls up?

Thread Guy

What? Sorry? Oh, yeah, yeah—Chrysler 300.

Tom Kysar

A Phantom pulls up, and you're kind of like, “Oh, actually, yeah.” Maybe you're looking at a used 2009 Rolls-Royce Ghost. Can I tell the difference between a 2009 Ghost and a brand-new one? Not really—until you sit inside, right?

Thread Guy

Right. Yeah, yeah. I like Hyperliquid. I think it's one of the best bad implementations of security that we have today, and that's a really good thing for—

Tom Kysar

Good. It's a good thing. My summary with all of it is, I used to literally have a sign on my wall in the yacht that said, “Everything is a scam.” Everything here is just a scam, and the best things put a bunch of extra stuff on top of it to confuse you and distract you from it just being a scam underneath it, right?

The only thing that's actually really decentralized is Bitcoin, functionally speaking. Everything else is kind of shit. You boil it all down, and there's security and centralization risk in everything, except for Bitcoin, give or take. Some show more than others, and anytime this stuff happens, I'm just kind of like, “Are you surprised?” Not really, right?

Everything is kind of a scam. Even with Ethereum, you can pull together all the validators today. Solana's validators are all in a goddamn Slack chat together. Even with Ethereum, if you said, “If we needed to get all the main validators together, we could probably do it in 20 minutes,” everything's kind of a scam.

I don't know. This is a long process, and it's only solved by crypto surviving forever. Bitcoin was a scam until we all woke up one day and realized, “Oh, the United States government couldn't shut down Bitcoin even if they wanted to.” They just couldn't. It's beyond their control. It's penetrated the world so deeply that you can't stop this thing, right?

That only happens by Bitcoin existing for 10 years and not dying. That's what will happen with Ethereum, Solana, and some of the other ones that persist and survive. You win by not dying over time, but you have to not die in that process, essentially.

In the meantime, it's all kind of a fucking scam still today, right? If somebody really fucking cares and has billions of dollars, they could crush almost any of these crypto products out of existence. Ethereum, Solana, whatever—any of these things.

Nothing is safe. This is the round loop, and I'm not there yet, but I still think about it occasionally. It comes up in my mind more every day: everything just leads back to you being a Bitcoin maximalist at the end of the day. At some point in all of our careers, I think we all just go back to being Bitcoin maximalists.

Because you still have this stuff where you're like, “What are we doing here, man? There's a fucking fee that controls 300—what is this fucking thing? Why did this exist? Why are we doing this?” You're like, “Oh, you know what? Actually, Bitcoin doesn't do anything, and that's what I like about it. It does fucking nothing, but that's what makes it good.”

North Korea can't come in and mint a bunch of fake Bitcoins. That makes Bitcoin kind of fucking useless. There's no Hyperliquid for Bitcoin. But at the same time, it's safe and secure, and it means something. All roads lead back to being Bitcoin maximalists at some point in our lives.

That's a terrifying thought because I really don't wish that upon myself, but at some point I think we'll make a new generation of Bitcoin maxis. It's going to take a while. It took those Bitcoin maximalists 10 years, right? But it's also terrifying because these Bitcoin maximalists are some of the little fucking assholes. They're the worst people I've ever seen.

Thread Guy

[Laughter.]

Tom Kysar

They're the worst. The vibe isn't there. It's just a fight with people, man. You want to be Jimmy Song on Twitter, like, “Oh my God.” These people are just—no. Luke Dashjr is a permanent underclass. Put me in a trailer, brother.

[Laughter.] He's Luke Dashjr, right? He's a Bitcoin Core developer. But if you were to ask, “You want to be Luke Dashjr?” you're like, “Yeah, no, never. Absolutely not.”

This is one of those times where, if you really sit and think about it for the next week or whatever, enough of these things build up. These are the events that help anyone who seriously works in crypto and considers it their career and profession mold and create their long-term thesis on the technology, for lack of a better term.

You'll see enough of these, and in the long run, this will shape your view of how you value decentralization and security, where you place your assets on-chain, and stuff like that. It shapes how you think about all of this in the long run.

It takes a lot of these kinds of things to get people to a good end conclusion. It's personal; it's where you feel comfortable. Does it affect you? No. In the long run, when you see 15 of these, at some point this is what gives you your opinion on security, decentralization, and the value of all of this.

Who knows? At some point, you might have $500 million in some lending protocol because you got super on-chain rich, and then the values of this stuff are different to you than they are to the Pump.fun shitcoin trader. You suddenly care about the security of the oracle and the lending markets.

Even if you care about it, it's a good learning experience, and it's good to understand what happened here. I think we're all good to understand what happened, but at the same time, forget about it. It's not really going to affect anything, and we're all going to forget about it next week.

Thread Guy

Honestly, Tom, that was the most beautiful closure of all time. I agree with you, by the way: all roads do lead to Bitcoin. I got to this at the end of 2025, and I was so sick of the game that I loved turning into a disaster with the memecoin stuff. I was like, “What am I doing? This is just the worst. I hate this.”

So you full-port into Bitcoin, pay some of it in taxes, keep what you can, buy more when you can, and fucking get on a podcast and call it a day, right? That's it.

Tom Kysar

This is like a second- or third-generation conclusion most people come to. You were like, “Actually, the best way for me to accomplish what I want to accomplish is to hold some assets that I believe essentially aren't going to go to fucking zero,” which is Bitcoin. You forgot about it, and now you have expertise in this field and vertical.

Instead of trading your way to a billion dollars—you have to make and build something, have a bunch of equity in it, and build that project or that thing. At some point, you're just like, “Yeah, I'm sick of getting rugged. I'm just going to hold Bitcoin and try to build something. Maybe someday I can sell this to somebody for billions of dollars.”

That's the road everyone eventually makes their way to. This is how the traditional world works, too, right? You're not going to trade your way to the big dollars.

Thread Guy

Not to be fair. No, you're really not. I don't think I've ever met anyone who just traded their way to even hundreds of millions. That's tough.

Tom Kysar

Yeah, tough—unless you were fucking buying $2,000 of Bitcoin at a couple hundred bucks.

Thread Guy

Yeah, if you bought and forgot, it happens, right? But have you ever met someone who's like, “I made $300 million trading on Hyperliquid this year?”

Tom Kysar

Long-short, intraday? No, no, no, no. Not really, no. I was like, don't do money. That's kind of the M.O.: go and do something where you're creating value in something that you own, right?

That's what this is for you. We have a startup. You have equity, right? That's the best use of your time. It's no longer Pump.fun trading 24/7.

Thread Guy

It’s you do your own business. Tom, where the fuck did GoPro go? You’re like our resident hack guy now. I guess you’re the resident hack guy moving forward.

Tom Kysar

I mean, sometimes I care, sometimes I don’t. This one was bridge-related, so I was like, “Okay, I’ve got to ruin it, you know?” Actually, what the fuck? I had such a good analogy. I saw a TikTok yesterday, and I had a really good analogy of how this came through. I was like, “Oh, there was a really good analogy of what happened here using some fucking video.” I can’t remember. I remember—

Thread Guy

You— it’s insane. Well, you said this last time. What’s my voice?

Tom Kysar

It’s nuts. The chat was all talking about your voice. Do you do speaking gigs or commentating or anything?

Tom Kysar

Nope. Nope. I have no— I’ve done nothing.

Thread Guy

It’s incredible.

Tom Kysar

No, I’ve literally done nothing. It’s weird, too, because you’re like the third or fourth person to say that—or people have said that in the last couple years. I don’t know. I mean, I’m like 30. Maybe I just hit puberty and my voice dropped finally.

Thread Guy

I fucking love your voice, Tom. I can listen to it all day, I’ll tell you what. Our resident hack debunker, Tom. This honestly, this is sick. Thank you for coming on. Thanks for your time. Thanks for staying for a while, dropping some fucking gems on us. We appreciate you, dude.

Tom Kysar

Of course. Thanks for having me. Let me know if I can ever fucking talk. But yeah, thanks, bro.

Thread Guy

We’ll do it again at some point. Hopefully not super soon in the case of the hack, but hopefully soon in the case of a W guest. You’re the man, dude. Later, bro.

Tom Kysar

All right, peace out, man. Peace.

Thread Guy

I fucking love that guy. Oh, wait, I want to find your TikTok. How good is he?