Polygon Labs' two-team security structure: where most Web3 breaches actually start | Mudit Gupta episode artwork

EPISODE · Mar 4, 2026 · 1H 3M

Polygon Labs' two-team security structure: where most Web3 breaches actually start | Mudit Gupta

from The Web3 Security Podcast · host TheWeb3SecurityPodcast

Most Web3 security conversations focus on smart contracts. Mudit Gupta, CTO of Polygon Labs, thinks that's the wrong place to be worried. In this episode, he makes the case that ZK infrastructure carries significantly more bugs than the smart contract layer — the reason large-scale exploits haven't happened yet isn't that the bugs don't exist, it's that the expertise required to exploit them is vanishingly rare. That window won't stay open forever.Beyond the ZK risk, Mudit breaks down the structural and operational decisions Polygon has made as AI shifts both sides of the security equation. Since August, their bug bounty program has seen a surge in reports on years-old code in geth and P2P libraries — the kind of retroactive review humans don't do — forcing them to build a counter-AI triaging system just to manage volume. He also details the two-team security structure most Web3 companies still don't run, and why the team most protocols skip is where the majority of Web3 incidents actually originate.Topics Discussed:ZK infrastructure as the highest-vulnerability, lowest-exploitation surface in Web3 — more bugs than the smart contract layer, but the pool of people who can exploit them is small enough to count on two hands. Mudit's view: that expertise gap is the only thing standing between current ZK deployments and large-scale attacksWhat a near 10x spike in bug bounty submissions since August reveals about how AI reviews code differently than humans — specifically its tendency to audit legacy code that human researchers have long stopped reviewingBuilding a counter-AI triaging agent to handle report volume, including the case where it incorrectly closed a valid submission and how researcher pushback caught itWhy Polygon runs a dedicated security operations team alongside AppSec — and why the absence of a SecOps function is where most Web3 incidents actually beginEmbedding AppSec at the architecture stage rather than post-build, and how that shifts accountability from audit-and-flag to full product ownership of security outcomesSending an AI-generated deepfake video of Polygon's CEO to all employees as a phishing simulation — and why video-format tests caught people that standard phishing emails don'tWednesday as the target release day: how the Monday-Tuesday verification window protects against deployment failures when external dependencies and client teams won't have weekend coverageSecurity knowledge as a speed multiplier: how understanding your risk surface lets you move faster on acceptable risks — and how Mudit structures risk tracking and CEO-level reporting so leadership can hold context without blocking decisions

Episode metadata supplied by the publisher feed · Published Mar 4, 2026

Embed this episode

Ready to play

Polygon Labs' two-team security structure: where most Web3 breaches actually start | Mudit Gupta

0:00 1:03:25

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Web3 Security Podcast?

This episode is 1 hour and 3 minutes long.

When was this The Web3 Security Podcast episode published?

This episode was published on March 4, 2026.

Can I download this The Web3 Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!