CypherTalk

Oak Security

CypherTalk is a twice-monthly podcast on the realities of cybersecurity and privacy in a world that’s moving faster than our defenses. Hosted by Jade Doherty (who translates technical security into plain English) alongside rotating security and privacy experts — including co-host Stefan Beyer, co-founder of Oak Security — the show explores how modern cybersecurity attacks actually happen: not just through bugs in code, but through people, processes, supply chains, and the tools we rely on every day. The show also looks at the latest trends in privacy and its supporting technologies, such as cryptography and zero-knowledge proofs.  Expect conversations that balance big-picture trends (AI-driven threats, privacy tech like zero-knowledge, shifting security standards) with practical takeaways you can apply immediately — whether you’re a developer, a founder, or simply someone who uses the internet. Less hype. More clarity. Better security and privacy habits.

  1. 10 hr ago

    Privacy and Institutional Use Cases with Emanuele Francioni

    After several episodes focused on security, this one turns to privacy, with Emanuele Francioni, co-founder and CEO of Dusk, a blockchain built for privacy and institutional use cases. Emanuele traces the through-line from a contrarian 2018 thesis to a live network to abstract financial instruments away from the intermediaries that leak both value and data. A core thread is the counterintuitive relationship between privacy and regulation. He disentangles anonymity from confidentiality, shows how privacy actually underpins rules like GDPR, DORA, and insider-trading law, and explains how Dusk encodes KYC, jurisdiction, and limits directly into the protocol. Then it gets harder: on a privacy chain, a vulnerability can be exploited in the dark. Emanuele uses the recent Zcash unbounded-mint bug to explain why Dusk's approach has to be proactive, why the team shipped three security upgrades this year (Aegis and Boreas among them), and why simplicity is the best safeguard. On the AI arms race he's candid, seeing Fable in action for three days genuinely scared him, but his conclusion is pointed: AI doesn't replace security expertise; it makes it more valuable. Key Topics Privacy vs confidentiality vs anonymity, and why privacy underpins regulation Encoding regulatory compliance directly into a protocol Securing a privacy-preserving chain, and the AI arms race in security Chapters 00:00 Introduction 01:05 Founding Dusk in 2018 and the Road to PLONK 07:14 How Privacy Fits the Regulatory Space 08:00 Anonymity vs Confidentiality: Disentangling "Privacy" 15:11 Selective Disclosure and Working With Regulators 21:30 Encoding KYC, Jurisdiction, and Limits Into the Protocol 24:25 How Privacy Changes the Approach to Security 27:12 The Zcash Unbounded-Mint Bug and Why Privacy Must Be Proactive 29:30 The Security Arms Race and Five Attack Attempts This Year 34:50 Why Simplicity Is the Best Safeguard 36:12 The Complexity Trade-Off: Custom VM, Sandboxing, Immutable Contracts 40:14 Shrinking the Layer One: Dusk EVM and a Privacy-Preserving L2 43:21 The AI Arms Race: Aegis, Boreas, and Restructuring Into "Pods" 50:22 Cross-Pollination: Pulling Ideas From Biology Into Software 55:10 Where AI Helps in Security, and Where Humans Still Matter 1:02:19 Oak's Research: Minor Human Intervention, Completely Different Output 1:04:27 Surprising Findings in Aegis: the BLS Truncation Bug 1:06:45 Boreas: a Live Incident and Real-Time Response 1:11:00 Operational Security, Supply Chain, and AI-Era Hiring 1:16:56 Wrap-Up Resources and Links Emanuele on X: https://x.com/autholykos Dusk: https://dusk.network Oak Security's Research: https://research.oaksecurity.io/

  2. 16 Jul

    Antonio Viggiano on how Monad is Using AI for Security

    Most of our guests come at security from the outside, as auditors and researchers. Antonio Viggiano sits on the other side of the table: he's a Senior Security Engineer at the Monad Foundation, working on protocol fuzzing for the chain's consensus and execution clients. Monad's architecture makes that a genuinely different problem. Unlike Ethereum, with its many interchangeable clients, Monad has a single pair: a C++ execution client and a Rust consensus client, both built by Category Labs. That tight coupling buys optimisations, but it also means a bug that looks real in one client is often quietly mitigated by the other. Test one in isolation and you drown in false positives. That's where Monad Bugfinder came from, and the origin story is the opposite of what most people assume. It didn't start as a bug finder at all. It started as a triager, because the team was being flooded with AI-generated reports: convincing write-ups, plausible proofs of concept, and hours of human time spent working out which ones were real. Bug hunters optimise for recall. When you're the one receiving the reports, you need precision. Antonio walks through the validation gates that made the difference, why AI has a higher false positive rate than humans, and why the best human reviewers still find twice as many bugs as the best AI systems. Key Topics AI-assisted vulnerability discovery and triage Invariant testing and protocol fuzzing In-house security teams at protocols Chapters 00:00 Introduction 00:38 From Solidity Developer to Security Engineer 03:10 Founding Recon and Cloud Fuzzing 04:39 What Is Invariant Testing? 06:38 Fuzzing Smart Contracts vs Blockchain Clients 08:41 Tooling Maturity and System Complexity 09:47 Extracting Invariants at the Protocol Level 11:11 Why Most DeFi Teams Don't Know Their Properties 13:29 Monad's Architecture: Two Clients, Tightly Coupled 16:29 Why Single-Client Bugs Create False Positives 17:21 Monad Bugfinder: Why It Started as a Triager 20:19 Precision vs Recall: Finding Bugs vs Receiving Reports 23:54 Inside the Triage Process 25:59 Reconstructing Proofs of Concept End-to-End 27:13 Should Smaller Teams Build Their Own? 30:06 Build vs Buy, and the Attackers Building It Too 32:27 Validation Gates: EIP Support and Differential Testing 35:49 Testing Against Geth and Nethermind 37:43 Local Clusters and Controllable Validators 42:00 Do AI Reports Have More False Positives? 44:37 The Economics: AI Tokens vs Audit Firms 47:47 Why Humans Still Find Twice as Many Bugs 48:14 When Your Scaffolding Goes Stale 51:52 Offense vs Defense and the Human Weak Link 54:27 The Roadmap: Making the System Generic 56:51 UltraFuzz: Agentic Fuzzing for Solidity 1:00:32 Specifications, Spec Drift, and AI-Written Code 1:04:08 Will AI Ever Write Bug-Free Code? 1:09:45 Where to Find Antonio Resources and Links Antonio's X: https://x.com/aviggiano Monad Bugfinder blog post: https://blog.monad.xyz/blog/monad-bugfinder UltraFuzz blog post: https://www.monad.xyz/blog/ultrafuzz  Monad: https://monad.xyz Oak Security's Research: https://research.oaksecurity.io/

  3. 2 Jul

    AI Asssited Security with Prof. Arthur Gervais

    What does it actually mean to be "obsessed with AI for security"? In this episode of CypherTalk, Jade and co-host Stefan Beyer sit down with Prof. Arthur Gervais (UCL, affiliate faculty at UC Berkeley), known for foundational work on MEV, flash loan attacks, and AI-powered smart-contract security. Arthur's core conviction sets the tone: AI is not a zero-sum game. Strong researchers can now find vulnerabilities ten times faster, and the right response is to onboard everyone as fast as possible rather than lock the tools down. The conversation goes deep on A1, the agentic system his team built that turns any LLM into an end-to-end exploit generator with one unambiguous goal: generate a profit. The hard part, he stresses, isn't building it, it's target selection.   Key Topics AI for security enhancement AI-assisted vulnerability detection Real-time blockchain exploit detection   Chapters 00:00 Introduction to AI and Security 02:29 Arthur's Journey into Information Security 05:05 The Role of AI in Security 07:22 A1: The AI Agent for Exploit Generation 09:38 Autonomy and Ethics of AI Agents 11:53 Harnessing AI for Security Audits 14:15 The Evolution of LLMs and Their Impact 16:33 Dealing with False Positives in AI Security 19:06 The Academic Perspective on AI Research 21:42 Comparing LLMs for Security Tasks 24:05 Future Directions in AI and Security 25:26 The Power Dynamics in AI and Cybersecurity 29:04 Balancing Offensive and Defensive Strategies in AI 31:44 Real-Time Defense Mechanisms in Cybersecurity 34:20 The Role of Tooling in Smart Contract Security 39:04 Human Error vs. Automated Security Tools 41:24 AI's Impact on Social Engineering and Human Error 42:53 Emerging Threats from AI in Cybersecurity 44:17 Teaching Blockchain Security: Common Misconceptions 45:23 Future Directions in Blockchain Security Research   Resources and Links Arthur’s website: https://arthurgervais.com/ Arthur’s Google Scholar: https://scholar.google.ch/citations?hl=en&user=jLr_xi4AAAAJ&view_op=list_works&sortby=pubdate Arthur’s X: https://x.com/HatforceSec Oak Security’s Research: https://research.oaksecurity.io/

  4. 17 Jun

    Peter Kacherginsky's Quaterly Take on Web3 Security

    In this episode, Jade Doherty and Stefan Beyer interview Peter Kacherginsky, founder of BlockThreat, on his quarterly take on blockchain security and recent exploits. They discuss how to utilize threat intelligence, the shift from smart contracts to operational attacks, and the role of AI in cybersecurity. Topics The shift from smart contract exploits to operational and infrastructure attacks The impact of AI on cybersecurity and defense strategies The importance of architectural security and threat modeling The role of community funding and ethical research in security Predictions for upcoming security challenges in crypto   Chapters 00:00 Introduction to Block Threat and Peter Kachaginski 01:42 Utilizing Threat Intelligence Effectively 04:31 The Impact of Market Conditions on Security 07:43 Shifts in Attack Vectors: From Smart Contracts to Infrastructure 09:35 Analyzing Major Hacks: Drift and Kelp DAO 13:36 The Importance of Architectural Security 16:47 The Evolving Role of Ethical Security Researchers 20:58 The Future of Security in a Rapidly Changing Landscape 30:10 Navigating Ransomware and Legal Implications 34:41 AI's Role in DeFi Security 43:27 Community-Driven Security Initiatives 49:25 Building a Security Mindset in Teams 51:48 The Centralization Dilemma in Security   Resources Block Threat Newsletter - https://blockthreat.com  Oak Security’s report - https://research.oaksecurity.io/  Peter’s X - https://x.com/iphelix

  5. 2 Jun

    SEAL Certifications with Isaac Patka

    In this episode of CypherTalk, Isaac Patka, co-founder of Shield3 and certification lead at the Security Alliance (SEAL), joins Jade Doherty and Stefan Beyer to discuss the human, operational, and governance risks shaping Web3 security. From early smart contract bug hunting to incident response wargames, SEAL 911, Safe Harbor, and the launch of SEAL certifications, Isaac explains why security is no longer just about audits and code. The conversation explores how DeFi protocols can prepare for real incidents, why operational controls matter as much as smart contract reviews, and how AI is changing the threat landscape for both attackers and defenders. Isaac also shares practical insights on slowing down dangerous protocol actions, designing better incident response processes, and building a more mature security culture across crypto. Enjoyed the episode and want to get SEAL certified? Oak Security is a SEAL-approved provider, and can review and certify your protocol to make sure your operational security is as good as your smart contracts. Get in touch via https://oaksecurity.io/  Key topics Isaac’s path from electrical engineering and semiconductors to Web3 security How smart contract security has changed since the early Ethereum days The difference between audits, war games, threat modeling, and incident response How SEAL 911 helps coordinate emergency response across the crypto ecosystem SEAL certifications and why operational security needs its own standard Why SOC 2 and ISO do not fully capture Web3-specific risks Multisig operations, treasury controls, DNS security, DevOps, and identity management The rise of social engineering, insider threats, and operational attacks North Korea, Lazarus Group, and state-sponsored crypto threats How AI is expanding the attack surface for smaller protocols Why protocols should build in slowness, circuit breakers, and operational controls Sound Bites “An audit tries to prevent an incident and the war game tries to help you deal with an incident.” “Social engineering works for a reason. Humans are fallible.” “What is the slowest I can possibly make this and have it still be functional?” “People don’t think during the design process about where they should build slowness into the protocol.” “The core smart contracts have gotten a lot better, which has pushed the security risks to different parts.” “If more people would care from day one about operational controls or circuit breakers, that’s what I would want.” Resources Isaac Patka X https://x.com/isaacpatka Security Alliance / SEAL https://securityalliance.org/ SEAL Frameworks https://securityalliance.org/frameworks SEAL Incident Response Template https://frameworks.securityalliance.org/incident-management/incident-response-template/overview/ SEAL Certifications https://frameworks.securityalliance.org/certs/overview/ Shield3 https://www.shield3.com/ Oak Security’s State of Web3 Security Report https://research.oaksecurity.io/

    SEAL Certifications with Isaac Patka

About

CypherTalk is a twice-monthly podcast on the realities of cybersecurity and privacy in a world that’s moving faster than our defenses. Hosted by Jade Doherty (who translates technical security into plain English) alongside rotating security and privacy experts — including co-host Stefan Beyer, co-founder of Oak Security — the show explores how modern cybersecurity attacks actually happen: not just through bugs in code, but through people, processes, supply chains, and the tools we rely on every day. The show also looks at the latest trends in privacy and its supporting technologies, such as cryptography and zero-knowledge proofs.  Expect conversations that balance big-picture trends (AI-driven threats, privacy tech like zero-knowledge, shifting security standards) with practical takeaways you can apply immediately — whether you’re a developer, a founder, or simply someone who uses the internet. Less hype. More clarity. Better security and privacy habits.