Cosmos Labs' 3 pivots in 6 months: Timeboxing experiments to find PMF | Barry Plunkett episode artwork

EPISODE · Oct 21, 2025 · 1H 14M

Cosmos Labs' 3 pivots in 6 months: Timeboxing experiments to find PMF | Barry Plunkett

from The Web3 Security Podcast · host TheWeb3SecurityPodcast

When the Interchain Foundation acquired Skip Protocol in 2024, Cosmos Labs inherited a 200-chain ecosystem with no commercial strategy and a massive security backlog. Barry Plunkett, co-CEO, explains how they systematically tested three strategic pivots in six months, killed two based on hard metrics, and found enterprise product-market fit by following "accidental traction" signals they'd initially ignored. First pivot: ZK-based IBC bridging to Ethereum paired with Skip Go's interop API. They timeboxed three months to the Babylon Bitcoin LST launch as a forcing function. Volume data post-launch killed the thesis—existing bridges were "pretty good" and marginal improvements don't create ecosystem momentum. Second pivot: position Cosmos Hub as a unified deployment platform for seamless multi-chain experiences. Direct enterprise outreach revealed Base and Solana's network effects created insurmountable BD cost disadvantages for a smaller ecosystem. The breakthrough: Fortune 500 companies and governments kept reaching out for help with Cosmos infrastructure pilots they'd started internally. That inbound signal became the strategy.   The security approach reflects the same first-principles methodology. Kevin, former head of security at Optimism who led Bedrock releases, implemented a policy: engineering managers receive HackerOne reports directly with no security intermediary layer. If you wrote the code and the bug was missed, you own the fix immediately—no backlog accumulation. For protocol-level changes, the team mandates line-by-line PR review sessions where code authors walk the full engineering team through every change. This catches critical vulnerabilities before external audits and prevents tribal knowledge from siloing. They coordinate patches monthly on the second Tuesday (Microsoft's schedule) after learning ad-hoc "patch when found" approaches burned out validator operators managing infrastructure across dozens of chains.   Topics discussed: Timeboxing strategic experiments to three months with quantitative kill criteria before resource commitment Following inbound enterprise signals over predetermined theses when accidental traction contradicts core assumptions Mandatory line-by-line PR walkthrough sessions with full engineering teams before protocol-level releases Monthly coordinated patch schedule (second Tuesday) preventing validator operator fatigue across multi-chain infrastructure Direct bug bounty report routing to code authors eliminating security intermediary layers and backlog accumulation Engineering manager accountability for immediate fix implementation rather than sprint planning security debt Graduating experimental modules through staged test environment deployments before long-term support commitment Analyzing why standalone IBC interoperability and Hub-native deployment strategies failed against established L1 network effects Standardized component interfaces (ABCI between Comet/SDK, IBC cross-chain) enabling parallel experimentation across 200-chain ecosystem Tokenization thesis: bringing cost of holding and moving money to zero creates financial services "Internet moment"

Episode metadata supplied by the publisher feed · Published Oct 21, 2025

Embed this episode

Ready to play

Cosmos Labs' 3 pivots in 6 months: Timeboxing experiments to find PMF | Barry Plunkett

0:00 1:14:15

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Web3 Security Podcast?

This episode is 1 hour and 14 minutes long.

When was this The Web3 Security Podcast episode published?

This episode was published on October 21, 2025.

Can I download this The Web3 Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!