CypherTalk

Oak Security

CypherTalk is a twice-monthly podcast on the realities of cybersecurity and privacy in a world that’s moving faster than our defenses. Hosted by Jade Doherty (who translates technical security into plain English) alongside rotating security and privacy experts — including co-host Stefan Beyer, co-founder of Oak Security — the show explores how modern cybersecurity attacks actually happen: not just through bugs in code, but through people, processes, supply chains, and the tools we rely on every day. The show also looks at the latest trends in privacy and its supporting technologies, such as cryptography and zero-knowledge proofs.  Expect conversations that balance big-picture trends (AI-driven threats, privacy tech like zero-knowledge, shifting security standards) with practical takeaways you can apply immediately — whether you’re a developer, a founder, or simply someone who uses the internet. Less hype. More clarity. Better security and privacy habits.

  1. Aug 28

    Security at Arbitrum with Lorenzo Sicilia

    Jade Doherty and Stefan Beyer speak to Lorenzo Sicilia, Head of Technology at the Arbitrum Foundation, whose path into crypto runs through ConsenSys, Casval, and Outlier Ventures. They open with the distinction that shapes everything else: the Foundation is the steward and legal wrapper of the DAO, not the team behind the tech. Lorenzo unpacks how it ran the Arbitrum Audit Program on the DAO's behalf, vetting a shortlist of thirteen audit firms and funding early-stage teams, and gets into the hard parts with Stefan: the "rubber stamp" risk when a Foundation-blessed audit becomes a trust signal, the friction of re-auditing when each iteration costs $50K to $250K, and the brutal cost-per-line metric the program can now benchmark across firms. On security responsibility, Lorenzo is precise: the Foundation has none in the formal sense. Incidents fall to a 12-member Security Council, elected and rotated by the DAO. From there the conversation turns to what keeps him up at night, the L1-L2 trust boundary and the bridge, and why fraud proofs through BoLD have improved the picture, landing on his own preference for "code is law" while acknowledging where reality forces harder trade-offs. The technical heart is Stylus, Arbitrum's WASM environment for writing contracts in Rust alongside the EVM. Lorenzo is unromantic about it: a second runtime widens the attack surface, and while safe Rust has real advantages, no language removes the authorisation, economic, and oracle pitfalls that actually cause losses, treating any language as "safe" is a mental trap. The episode also covers the freshly-shipped ZK-on-BoLD upgrade, the road to real-time proving, and why AI currently hands the red team a big advantage over the blue team, though Lorenzo is optimistic defenders can turn the same tooling back on their own code. He closes with hard-won advice: authenticity and persistence over a polished demo, understand your oracles and dependencies, get key management right, and know when to switch from "fake it till you make it" to full paranoia, because in this industry, you don't get a discount. Key Topics The Arbitrum Audit Program, and the "rubber stamp" problem with Foundation-backed audits Decentralised security responsibility: the Security Council, the L1-L2 boundary, and BoLD Stylus and WASM security, ZK-on-BoLD, real-time proving, and AI's red-team advantage Chapters 00:00 Introduction 00:35 From ConsenSys and Outlier Ventures to the Arbitrum Foundation 04:11 What the Foundation Actually Does, and How It Differs from Offchain Labs 06:50 The Audit Program: How It Works and Who Funds It 10:18 The "Rubber Stamp" Problem and Vetting Audit Firms 13:18 Early-Stage vs Mature Teams: Who the Program Is For 14:54 What's Next: Additional Tools, AI, and the Limits of Scope 17:15 Lessons From the First Iteration, and Cost-Per-Line Benchmarking 21:11 The Foundation's Responsibility and the Security Council 24:49 What Keeps Him Up at Night: The L1-L2 Boundary and Bridges 29:16 Security Policy, Bug Bounties, and Disclosure Across the Ecosystem 30:48 Stylus: Does a WASM Runtime Widen the Attack Surface? 34:49 Safe Rust vs Solidity, Tooling Gaps, and the "Mental Trap" 39:13 Adding ZK to BoLD, and the Multi-Prover Approach 42:20 Real-Time Proving and Where Arbitrum Is Heading 45:20 ZK for Compression vs ZK for Privacy 46:24 AI in 2026: Red Team vs Blue Team, and AI Slop 50:31 Judging Teams: Authenticity, Resilience, and Real Problems 53:33 The Biggest Security Mistakes New Teams Make 55:25 The Foundation's Security Vision for the Next Few Years 57:52 One Piece of Advice: Dependencies, Keys, and Knowing When to Get Paranoid Resources and Links Lorenzo on X: https://x.com/aboutlo Arbitrum: https://arbitrum.io Oak Security's Research: https://research.oaksecurity.io/

    Security at Arbitrum with Lorenzo Sicilia
  2. Aug 13

    Robert de Groot and Web3 Privacy Now

    Jade and Stefan speak to Robert de Groot, a core contributor to Web3Privacy Now, the research collective and think tank behind the Cypherpunk Congress, and CFO at Gain. Robert starts from an unexpected place: privacy isn't really about hiding; it's about autonomy, the ability to choose what you reveal, to whom, when, and in what form. He connects it to something bigger than data leakage, the loss of the room to experiment and to fail, and the quiet self-censorship that creeps in when everything is recorded. From there the conversation opens onto the spectrum of privacy, from the journalist in a conflict zone who will work from a terminal if it keeps them alive, to the rest of us who just want a group chat that isn't intercepted and won't tolerate bad UX to get it. A big thread is the gap between personal privacy and business compliance, and why the two still don't align. Robert explains how Web3Privacy Now evaluates the 800-plus projects in its Explorer (the "hard variables," verifiable code over marketing claims), why "zero knowledge" and "private" have become marketing terms, and why privacy adoption lags even when the tooling is ready, the preventive-measure problem, the group effect, and cookie-banner fatigue. On the compliance side, he maps the middle ground: opt-in reporting, viewing keys, and selective disclosure (picking up the thread from our Jordi Baylina episode), including a one-time key you could hand your tax auditor and be notified when it's used.  He argues privacy will increasingly become a market-integrity feature, not just a civil-liberties one, shielding transaction amounts from competitors and MEV bots while keeping endpoints verifiable, and he closes on RWAs, why so many tokenisation projects quietly died on double-accounting overhead, and what "compliant by default" finally changes. Key Topics Privacy as autonomy, and the spectrum from uncompromisable to everyday The gap between personal privacy and business compliance, and the middle-ground tools that bridge it Privacy as a market-integrity feature for RWAs and institutional adoption Chapters 00:00 Introduction 01:06 Why He Started Worrying About Privacy: Autonomy and Self-Censorship 04:58 Surveillance, Society, and the Loss of Room to Fail 06:01 What the Ethereum Community Really Thinks About Privacy 08:36 The Gap Between Personal Privacy and Business Compliance 10:54 What Web3Privacy Now Actually Does 13:45 Evaluating Projects: Hard Variables and Verifiable Code 17:01 When "Zero Knowledge" and "Private" Are Just Marketing 19:39 The Cypherpunk Congress and Why Privacy Matters Now 24:00 Tooling Is Ready, So Why Does Adoption Lag? 28:49 Compartmentalization, Intent, and Privacy by Default 34:38 GDPR, Cookie Fatigue, and Whether Regulation Backfires 39:49 Privacy vs Compliance: Does Privacy Make Regulators Nervous? 42:14 The Middle Ground: Opt-In Reporting, Viewing Keys, Selective Disclosure 45:31 Selective Disclosure and the Jordi Baylina Thread 46:10 RWAs, Institutions, and Why Tokenisation Projects Kept Dying 53:03 Privacy as a Market-Integrity Feature: MEV, Front-Running, and Competition Law 55:43 The Most Useful Thing an Ordinary Person Can Do 58:30 Where to Find Robert Resources and Links Robert on X: https://x.com/robdotrego Web3Privacy Now: https://web3privacy.info Cypherpunk Congress: https://congress.web3privacy.info/ Event: https://luma.com/spsnos9t Oak Security's Research: https://research.oaksecurity.io/

  3. Jul 30

    Privacy and Institutional Use Cases with Emanuele Francioni

    After several episodes focused on security, this one turns to privacy, with Emanuele Francioni, co-founder and CEO of Dusk, a blockchain built for privacy and institutional use cases. Emanuele traces the through-line from a contrarian 2018 thesis to a live network to abstract financial instruments away from the intermediaries that leak both value and data. A core thread is the counterintuitive relationship between privacy and regulation. He disentangles anonymity from confidentiality, shows how privacy actually underpins rules like GDPR, DORA, and insider-trading law, and explains how Dusk encodes KYC, jurisdiction, and limits directly into the protocol. Then it gets harder: on a privacy chain, a vulnerability can be exploited in the dark. Emanuele uses the recent Zcash unbounded-mint bug to explain why Dusk's approach has to be proactive, why the team shipped three security upgrades this year (Aegis and Boreas among them), and why simplicity is the best safeguard. On the AI arms race he's candid, seeing Fable in action for three days genuinely scared him, but his conclusion is pointed: AI doesn't replace security expertise; it makes it more valuable. Key Topics Privacy vs confidentiality vs anonymity, and why privacy underpins regulation Encoding regulatory compliance directly into a protocol Securing a privacy-preserving chain, and the AI arms race in security Chapters 00:00 Introduction 01:05 Founding Dusk in 2018 and the Road to PLONK 07:14 How Privacy Fits the Regulatory Space 08:00 Anonymity vs Confidentiality: Disentangling "Privacy" 15:11 Selective Disclosure and Working With Regulators 21:30 Encoding KYC, Jurisdiction, and Limits Into the Protocol 24:25 How Privacy Changes the Approach to Security 27:12 The Zcash Unbounded-Mint Bug and Why Privacy Must Be Proactive 29:30 The Security Arms Race and Five Attack Attempts This Year 34:50 Why Simplicity Is the Best Safeguard 36:12 The Complexity Trade-Off: Custom VM, Sandboxing, Immutable Contracts 40:14 Shrinking the Layer One: Dusk EVM and a Privacy-Preserving L2 43:21 The AI Arms Race: Aegis, Boreas, and Restructuring Into "Pods" 50:22 Cross-Pollination: Pulling Ideas From Biology Into Software 55:10 Where AI Helps in Security, and Where Humans Still Matter 1:02:19 Oak's Research: Minor Human Intervention, Completely Different Output 1:04:27 Surprising Findings in Aegis: the BLS Truncation Bug 1:06:45 Boreas: a Live Incident and Real-Time Response 1:11:00 Operational Security, Supply Chain, and AI-Era Hiring 1:16:56 Wrap-Up Resources and Links Emanuele on X: https://x.com/autholykos Dusk: https://dusk.network Oak Security's Research: https://research.oaksecurity.io/

  4. Jul 16

    Antonio Viggiano on how Monad is Using AI for Security

    Most of our guests come at security from the outside, as auditors and researchers. Antonio Viggiano sits on the other side of the table: he's a Senior Security Engineer at the Monad Foundation, working on protocol fuzzing for the chain's consensus and execution clients. Monad's architecture makes that a genuinely different problem. Unlike Ethereum, with its many interchangeable clients, Monad has a single pair: a C++ execution client and a Rust consensus client, both built by Category Labs. That tight coupling buys optimisations, but it also means a bug that looks real in one client is often quietly mitigated by the other. Test one in isolation and you drown in false positives. That's where Monad Bugfinder came from, and the origin story is the opposite of what most people assume. It didn't start as a bug finder at all. It started as a triager, because the team was being flooded with AI-generated reports: convincing write-ups, plausible proofs of concept, and hours of human time spent working out which ones were real. Bug hunters optimise for recall. When you're the one receiving the reports, you need precision. Antonio walks through the validation gates that made the difference, why AI has a higher false positive rate than humans, and why the best human reviewers still find twice as many bugs as the best AI systems. Key Topics AI-assisted vulnerability discovery and triage Invariant testing and protocol fuzzing In-house security teams at protocols Chapters 00:00 Introduction 00:38 From Solidity Developer to Security Engineer 03:10 Founding Recon and Cloud Fuzzing 04:39 What Is Invariant Testing? 06:38 Fuzzing Smart Contracts vs Blockchain Clients 08:41 Tooling Maturity and System Complexity 09:47 Extracting Invariants at the Protocol Level 11:11 Why Most DeFi Teams Don't Know Their Properties 13:29 Monad's Architecture: Two Clients, Tightly Coupled 16:29 Why Single-Client Bugs Create False Positives 17:21 Monad Bugfinder: Why It Started as a Triager 20:19 Precision vs Recall: Finding Bugs vs Receiving Reports 23:54 Inside the Triage Process 25:59 Reconstructing Proofs of Concept End-to-End 27:13 Should Smaller Teams Build Their Own? 30:06 Build vs Buy, and the Attackers Building It Too 32:27 Validation Gates: EIP Support and Differential Testing 35:49 Testing Against Geth and Nethermind 37:43 Local Clusters and Controllable Validators 42:00 Do AI Reports Have More False Positives? 44:37 The Economics: AI Tokens vs Audit Firms 47:47 Why Humans Still Find Twice as Many Bugs 48:14 When Your Scaffolding Goes Stale 51:52 Offense vs Defense and the Human Weak Link 54:27 The Roadmap: Making the System Generic 56:51 UltraFuzz: Agentic Fuzzing for Solidity 1:00:32 Specifications, Spec Drift, and AI-Written Code 1:04:08 Will AI Ever Write Bug-Free Code? 1:09:45 Where to Find Antonio Resources and Links Antonio's X: https://x.com/aviggiano Monad Bugfinder blog post: https://blog.monad.xyz/blog/monad-bugfinder UltraFuzz blog post: https://www.monad.xyz/blog/ultrafuzz  Monad: https://monad.xyz Oak Security's Research: https://research.oaksecurity.io/

  5. Jul 2

    AI Asssited Security with Prof. Arthur Gervais

    What does it actually mean to be "obsessed with AI for security"? In this episode of CypherTalk, Jade and co-host Stefan Beyer sit down with Prof. Arthur Gervais (UCL, affiliate faculty at UC Berkeley), known for foundational work on MEV, flash loan attacks, and AI-powered smart-contract security. Arthur's core conviction sets the tone: AI is not a zero-sum game. Strong researchers can now find vulnerabilities ten times faster, and the right response is to onboard everyone as fast as possible rather than lock the tools down. The conversation goes deep on A1, the agentic system his team built that turns any LLM into an end-to-end exploit generator with one unambiguous goal: generate a profit. The hard part, he stresses, isn't building it, it's target selection.   Key Topics AI for security enhancement AI-assisted vulnerability detection Real-time blockchain exploit detection   Chapters 00:00 Introduction to AI and Security 02:29 Arthur's Journey into Information Security 05:05 The Role of AI in Security 07:22 A1: The AI Agent for Exploit Generation 09:38 Autonomy and Ethics of AI Agents 11:53 Harnessing AI for Security Audits 14:15 The Evolution of LLMs and Their Impact 16:33 Dealing with False Positives in AI Security 19:06 The Academic Perspective on AI Research 21:42 Comparing LLMs for Security Tasks 24:05 Future Directions in AI and Security 25:26 The Power Dynamics in AI and Cybersecurity 29:04 Balancing Offensive and Defensive Strategies in AI 31:44 Real-Time Defense Mechanisms in Cybersecurity 34:20 The Role of Tooling in Smart Contract Security 39:04 Human Error vs. Automated Security Tools 41:24 AI's Impact on Social Engineering and Human Error 42:53 Emerging Threats from AI in Cybersecurity 44:17 Teaching Blockchain Security: Common Misconceptions 45:23 Future Directions in Blockchain Security Research   Resources and Links Arthur’s website: https://arthurgervais.com/ Arthur’s Google Scholar: https://scholar.google.ch/citations?hl=en&user=jLr_xi4AAAAJ&view_op=list_works&sortby=pubdate Arthur’s X: https://x.com/HatforceSec Oak Security’s Research: https://research.oaksecurity.io/

  6. Jun 17

    Peter Kacherginsky's Quaterly Take on Web3 Security

    In this episode, Jade Doherty and Stefan Beyer interview Peter Kacherginsky, founder of BlockThreat, on his quarterly take on blockchain security and recent exploits. They discuss how to utilize threat intelligence, the shift from smart contracts to operational attacks, and the role of AI in cybersecurity. Topics The shift from smart contract exploits to operational and infrastructure attacks The impact of AI on cybersecurity and defense strategies The importance of architectural security and threat modeling The role of community funding and ethical research in security Predictions for upcoming security challenges in crypto   Chapters 00:00 Introduction to Block Threat and Peter Kachaginski 01:42 Utilizing Threat Intelligence Effectively 04:31 The Impact of Market Conditions on Security 07:43 Shifts in Attack Vectors: From Smart Contracts to Infrastructure 09:35 Analyzing Major Hacks: Drift and Kelp DAO 13:36 The Importance of Architectural Security 16:47 The Evolving Role of Ethical Security Researchers 20:58 The Future of Security in a Rapidly Changing Landscape 30:10 Navigating Ransomware and Legal Implications 34:41 AI's Role in DeFi Security 43:27 Community-Driven Security Initiatives 49:25 Building a Security Mindset in Teams 51:48 The Centralization Dilemma in Security   Resources Block Threat Newsletter - https://blockthreat.com  Oak Security’s report - https://research.oaksecurity.io/  Peter’s X - https://x.com/iphelix

  7. Jun 2

    SEAL Certifications with Isaac Patka

    In this episode of CypherTalk, Isaac Patka, co-founder of Shield3 and certification lead at the Security Alliance (SEAL), joins Jade Doherty and Stefan Beyer to discuss the human, operational, and governance risks shaping Web3 security. From early smart contract bug hunting to incident response wargames, SEAL 911, Safe Harbor, and the launch of SEAL certifications, Isaac explains why security is no longer just about audits and code. The conversation explores how DeFi protocols can prepare for real incidents, why operational controls matter as much as smart contract reviews, and how AI is changing the threat landscape for both attackers and defenders. Isaac also shares practical insights on slowing down dangerous protocol actions, designing better incident response processes, and building a more mature security culture across crypto. Enjoyed the episode and want to get SEAL certified? Oak Security is a SEAL-approved provider, and can review and certify your protocol to make sure your operational security is as good as your smart contracts. Get in touch via https://oaksecurity.io/  Key topics Isaac’s path from electrical engineering and semiconductors to Web3 security How smart contract security has changed since the early Ethereum days The difference between audits, war games, threat modeling, and incident response How SEAL 911 helps coordinate emergency response across the crypto ecosystem SEAL certifications and why operational security needs its own standard Why SOC 2 and ISO do not fully capture Web3-specific risks Multisig operations, treasury controls, DNS security, DevOps, and identity management The rise of social engineering, insider threats, and operational attacks North Korea, Lazarus Group, and state-sponsored crypto threats How AI is expanding the attack surface for smaller protocols Why protocols should build in slowness, circuit breakers, and operational controls Sound Bites “An audit tries to prevent an incident and the war game tries to help you deal with an incident.” “Social engineering works for a reason. Humans are fallible.” “What is the slowest I can possibly make this and have it still be functional?” “People don’t think during the design process about where they should build slowness into the protocol.” “The core smart contracts have gotten a lot better, which has pushed the security risks to different parts.” “If more people would care from day one about operational controls or circuit breakers, that’s what I would want.” Resources Isaac Patka X https://x.com/isaacpatka Security Alliance / SEAL https://securityalliance.org/ SEAL Frameworks https://securityalliance.org/frameworks SEAL Incident Response Template https://frameworks.securityalliance.org/incident-management/incident-response-template/overview/ SEAL Certifications https://frameworks.securityalliance.org/certs/overview/ Shield3 https://www.shield3.com/ Oak Security’s State of Web3 Security Report https://research.oaksecurity.io/

    SEAL Certifications with Isaac Patka

About

CypherTalk is a twice-monthly podcast on the realities of cybersecurity and privacy in a world that’s moving faster than our defenses. Hosted by Jade Doherty (who translates technical security into plain English) alongside rotating security and privacy experts — including co-host Stefan Beyer, co-founder of Oak Security — the show explores how modern cybersecurity attacks actually happen: not just through bugs in code, but through people, processes, supply chains, and the tools we rely on every day. The show also looks at the latest trends in privacy and its supporting technologies, such as cryptography and zero-knowledge proofs.  Expect conversations that balance big-picture trends (AI-driven threats, privacy tech like zero-knowledge, shifting security standards) with practical takeaways you can apply immediately — whether you’re a developer, a founder, or simply someone who uses the internet. Less hype. More clarity. Better security and privacy habits.

You Might Also Like