PODCAST · technology
Not Your Crypto Podcast
by NYCP
You might call this a Web3 security podcast, and you’d be right. The transparency and culture of the scene makes it a vibrant canvas to study, and we break down the biggest and most technically intriguing attacks in the space.But we think there’s more. When things break, they show you something deeper about how they work, and what they are. Like it or not the internet is different than it was. Join us as we take a critical eye to how it’s changing, by looking at how it fractures.Ideas welcome at notyourcryptopodcast at gmail.com
-
31
AI x Security Engineering
This one is a loosie, to explain we recorded an episode over a month and a half ago documenting our thoughts and opinion on AI's impact on security engineering but to due life getting in the way I wasn't able to edit and release it. However due to recent news about AI agents escaping sandboxes and hacking companies we still think the topic deserves thinking about and so we finally present it now for your consideration, we hope you enjoy it and gives you something to think about as well.
-
30
Lost in the (sea)weeds
Wow. This has been one of the biggest months ever for crypto hacks, so we’ve got a lot to work with.Let’s start here. On April 18th, a bridge used to transfer KelpDAOs liquidity token between chains got a message.The message said a user wanted to transfer tokens from unichain to ethereum, and that the tokens were already sent on the unichain side. So, the bridge did what it always does, and released tokens back to them on ethereum.The only problem was, the message wasn’t real.Bridges have often been the soft underbelly of crypto protocols. So how did it happen? We’ll dive into Kelp, the LayerZero protocol, and how attackers got onto two servers that turned out to be securing the whole thing.By the way, this episode starts with an explanation of KelpDAO, a “liquid restaking provider”. Don’t worry if you get lost in the seaweeds on that, we did as well. Just keep going. Now on to it.
-
29
You know nothing, John Snow
The jokes just write themselves with this one. In this episode, we bumble our way through an overview of Zero Knowledge Proofs, another entry in cryptography’s long line of mind benders.ZKPs come from one of the most consequential decades in history for nerds like us. Forget Classic Rock and the emergence of Hip Hop, the cryptographers were the ones really cooking from the mid 70s to the mid 80s, with incredible bangers like Public Key crypto, Diffie-Hellman key exchange, Cryptographic Hashing, and of course the beautiful Merkle Trees that gave us our blockchains.After that though, ZKPs were kinda shelved. But if there’s one thing crypto and Web3 have been good at, it’s inventing new abstract problems that need a nifty technical solution.So what are ZKPs, how do they work, and what do they unlock for the builders? We can’t promise you’ll come away from this episode knowing a lot, but hopefully it’s more than Zero. It’s worth a shot.
-
28
Balancing Act
Building on top of a gnarly bug in some dex math, an attacker constructs a flashswap strategy that leaves a crypto protocol’s liquidity pools drained of over a hundred million dollars. Wait wait wait, haven’t we seen this before? Don’t worry, this isn’t Cetus Part 4. Instead, we’re talking about the November 2025 hack of Balancer. You see, when Balancer was doing its math on your transaction, there was one small step that would always round a number down. A small thing maybe, but when you’re a galaxy brain hacker with all the tools of defi at your disposal, you’ll find a way to lever that up into millions of dollars. Let’s find out how.
-
27
It's getting chilly outside
We continue to be mostly uninterested in the ebbs and flows of the crypto market, but if we’re not yet in a winter, crypto has at least had a significant frost.That, combined with the looming end of year, inclines one to reflection.In this episode, we look back at the big product developments this cycle, and cast our exacting judgement - are we any closer to a decentralised internet? And does that still mean anything?Call us idealists, but that vision is one old acquaintance that shall not be forgot. For anyone who listened this year, thank you, and see you in 2026, when we’ll see if this winter of our discontent is made glorious summer. At the least, we’ve got some hacks queued up to yap about.
-
26
Governance Comes at you Fast
Our brains may have finally recovered from researching liquidity pool formulae for the Cetus episodes, so let’s pop another defi hack off the stack and see what we got.In April of 2022 (ancient history I know), an algorithmically backed stablecoin protocol called Beanstalk was drained to the tune of 181 million dollars. But that's not even close to the biggest number you’ll hear in this episode.What was the vulnerability? I’ll bet there was a juicy one in that smart contact. Well... not really? You see, the attacker flashloaned themselves 1 billion (!!!) dollars, then staked that in the beanstalk contract and minted a supermajority of the governance token supply.With that control they could immediately force through emergency proposals, including two of which they had prepped a day earlier to drain the funds.Bueller? Bueller?? Maybe dont take that day off, cause governance comes at you fast.Notes:Windwaker Speed Run: youtube.com/watch?v=FTry_ZJnUIg
-
25
Bringing Crypto to the Laundromat
When stuff gets hacked, there’s a lot of focus, rightfully, on the exploit. How did it happen? Which smart contract had a vulnerability? How’s it get fixed?The exploit, though, is just a small part of the story. By and large, attackers don’t want to degen with a massive bag of tokens. They want something more useful - no offense to the crypto heads.That means they need to cash out. But you can’t just roll up to a centralized exchange and click a few buttons. They’ll ask too many questions, and will freeze your funds before they give you the cash.So, what’s a hacker to do? In this episode, we return to the ByBit hack, still the largest on the books. The attacker wants to exchange and move their crypto in a way that’s difficult for observers to trace. That’s not a simple task on a public ledger. So what do they reach for?Let’s find out.
-
24
Are DAO's DOA?
Betteridge’s law aside, DAOs have been around for nearly as long as you could code on the blockchain (which, I guess, hasn’t been that long). In fact one just called “The DAO”, and its associated hack, was one of the defining events of early crypto.DAOs are decentralized organizations that you participate in by voting with a governance token that you own and stake.But, this is crypto, and everything is an asset. That includes not just your token, but also your vote. So, what if you sold it?In this episode, we explore the consequences of the vote delegation market, where voting power in DAO governance is bought and sold.Board positions. Community fund disbursements. Protocol updates. All for sale - but what’s the price?A wise man once said show me the incentive, and I'll show you the outcome. It’s not always quite that simple, but crypto sure gets close.
-
23
Selfish Mining: All You Need is a Bit of Luck
51% attacks have always been an animating theme in blockchain security. Since the integrity guarantees come from distribution, how do they break when one player gets the majority of the hashrate?Well, that was the question facing the Monero community in August after an actor entered the game, rained hashpower from the sky, and (very) publicly pulled off a six block reorg of the chain.But immediately after the announcement of a successful 51% attack hit the TL, another narrative emerged, claiming the numbers didn’t add up. No one saw the hashrate pass 50% of the network. And, you see, reorgs can happen at significantly less than 50%.In this episode, we cover selfish mining, the events around Monero in mid August, and the unique approach to Proof-of-Work that let it all come together.Sometimes, all you need is a bit of luck.
-
22
Cetus, Part III - I’ll take that crypto back, please
So, just over 200 million dollars is gone from Cetus’ liquidity pools. Damn. Time to call the insurance broker and make a claim. Just play it cool on the phone. Right?Wrong, of course. In crypto, the exploit is just the first shot fired. The ambush that takes you off guard. Keep your head up, and you’ll find that the attacker still has a long road ahead of them to navigate their massive bag through the ecosystem and cash out.And that ecosystem, well, it isn’t inclined to make things easy. When every validator, and every stake holder is against you, every second counts to get your bag out before you get frozen, or worse.This is the story of an ecosystem coordinating to recover the funds it lost. But how does that happen? And what does it mean when, acting together, it can seize tokens from an address?We’re glad to be back and philosophizing. Just don’t ask us how liquidity pools work again.
-
21
Cetus, Part II: Integer overflows triumphant return
If we can be sentimental for a second, some things in life remind you of simpler times. Maybe it’s a well loved book, or a familiar place. For us, nothing dials up the nostalgia like the return of a vintage vulnerability.In this episode, we continue our discussion of the Cetus hack. With the defi side covered in Part I, we now turn to the central mystery - how did the attacker manage to add a massive amount of liquidity with a single token?Well, there is one bug that will make a big number, small. And this one was perfectly placed to turn the key and unlock hundreds of millions of dollars.Integer overflows are back. And they’ve still got a few tricks to play
-
20
Cetus, Part I: Draining liquidity pools for fun and profit
Wow, it’s been a while, we hope you can find it in your heart to forgive us. Turns out, this episode took us a lot of research.So, what happened? At the end of May, Cetus, a dex on the Sui blockchain, faced a crisis. The liquidity pools that provide the exchange with capital were being drained of all their tokens, and fast. Cetus hit the pause button after 15 minutes, but already 200-some million dollars were gone.Looking at the record on the blockchain sets a mystery. A flash swap, a liquidity add, and withdrawals. For those (like us) not steeped in this world, this is standard defi operations. Don’t worry, we’ll explain. But at the end of the transaction, the liquidity is gone.So what broke? Follow along as we piece it together. Sometimes, when you give a little, you get a lot.
-
19
NYCP goes Cypherpunk
In January, Sony launched a blockchain. Their goal, according to them, was to “Realize the Open Internet that Transcends Boundaries."Well, that _was_ their goal, until the Open Internet actually showed up. And there was one boundary Sony didn’t want transcended. On launch day, memes started flying, including tokens named after Sony-owned IPs. As one would expect from a media giant, Sony took action. They started dropping transactions with IP infringing tokens from their nodes before they could get processed. Well, the Open Internet wouldn’t stand for that. Sonys chain, it turns out, is an L2 on top of ethereum. And ethereum is a censorship resistant network. But what’s that mean, and how does it work? Thankfully, there was now one of the most powerful forces on earth at the ready. Nerds with a point to prove. In this episode, we learn from them.
-
18
Crypto-Necromancy
A month ago, the Cronos blockchain voted to increase the supply of tokens in their ecosystem from 27B to 70B (!!!).This issuance was positioned as a reversal of the largest token burning program ever run in crypto, where 70% of the CRO token supply was burned in 2021. The tokens, Cronos Labs said, were needed to support issuing an ETF, and to support their crypto x AI roadmap. We reasonably have no word in English for something getting reverse-burnt, so call it an “unburning”.You’d be excused if you were a CRO tokenholder and a 2.5x increase in supply made you balk. Especially by resurrecting tokens from the dead.As voting went forward, this particular piece of crypto-necromancy risked not reaching quorum. That is, until the biggest player in the ecosystem stepped in in favour - Cronos Labs themselves.If one entity owns 50%+ of the token supply, is governance a facade? One token, one vote. But does it have to be that way?
-
17
Safe Cracking
Fortunately (for niche podcasters such as ourselves), more detail has been published about just how the ByBit hack happened.The story now turns to Safe{Wallet} - ByBit’s multisig wallet provider. After getting access to a developer’s laptop, Lazarus pivots through the cloud to put a transaction in front of ByBit. The cloud you say?!? AWS? S3? API tokens? Javascript?? We know these words! You’d be excused if you thought this was Web2 😏The upshot though - it turns out, what you see isn’t always what you get. Bonus - This episode kicks off with a discussion of a disputed market resolution on Kalshi, Polymarkets primary (non-crypto) competitor. Call your Grade 10 English teacher, because we’re about to Compare and Contrast. Is the grass greener? Maybe not, but don’t use that cliche in your essay.
-
16
ByBit Buys Back
1.4 million dollars worth of eth. Hm, what’s that? …no. That can’t be right. With a “B”?On February 21st, ByBit’s CEO clicked the most expensive click in history and authorized a transaction to send 1.4 billion worth of eth directly to North Korean hackers. But he (and the other multisig wallet holders) thought it was a routine transaction from their cold wallet to their warm wallet.How did it happen? You have a few options to learn about it. If you’d like a concise, polished explanation with visual aides - you can watch the videos linked below. If you’d rather listen to us, questionable choice, but we’re glad to have you. With an oopsie of this scale we’d better learn something. Hopefully there’s more to the answer than just “git gud” at crypto. Let’s see what we can find.Technical Sources: Largest crypto hack of all timeCheckpoint Research
-
15
The Odd Couple
On the blockchain, you are your keys… right? In this episode, the answer is - sort of. We take a look at zkLogin, a protocol that allows you to send transactions to a blockchain from an OAuth account. No, it’s not custodial. Its magic - or as near to it as cryptography gets (which is pretty near!). A mix of clever protocol design and arcane cryptography, right at the intersection of Web2 and Web3. This tech was made for us to yap about.
-
14
The 610 million dollar hash collision
So far we’ve covered events in 2024, 2023, and 2022. It’s time for 2021 to take the stand. In this episode we cover an attack on Poly Network, an open source and decentralized cross chain network that enabled communication between different blockchains. To make the network work (lol), you need a lot of liquidity in wallets on the chains you’re integrating. Well what if you could, just, you know, add yourself as the owner of those wallets? Of course it wasn’t that simple. But the great thing about security is that, it also kind of was? This is another one where you can crack out your CS textbook, because hash collisions are taking center stage. All it takes is one - and 610 million can be out the door. Show notes: https://research.kudelskisecurity.com/2021/08/12/the-poly-network-hack-explained/ https://slowmist.medium.com/the-analysis-and-q-a-of-poly-network-being-hacked-8112a35beb39 https://blog.merklescience.com/hacktrack/hack-track-an-analysis-of-poly-network-hack-and-latest-related-events https://blog.kraken.com/product/security/abusing-smart-contracts-to-steal-600-million-how-the-poly-network-hack-actually-happened
-
13
What are the odds?
We are not a current events podcast. We are not a current events podcast. We are not a…. but a current event did happen in November of 2024, and it turns out that Polymarket, a blockchain-based prediction market, got pretty big during it. “Pretty big”. Well, Polymarket attracted over 3 billion dollars betting on the outcome of the 2024 US presidential election. So, who won? Oh gosh oh gosh we’re not talking about the election. But “who won” is pretty important for settling those 3 billion dollars of bets. Join us as we dive into Polymarket, and UMA - the “decentralized truth machine” that resolves the outcome. Sometimes on the blockchain, “truth” is what the tokenholders say it is. And the market cap of UMA’s coin - well it’s certainly less than three billion. How much does the truth cost? Show notes: Polymarket Election Event
-
12
Come one, come all
There are many chains, so many L1’s, why are they here, wasn’t Ethereum supposed to be the one to rule them all? Obviously not, so in this episode we’re going to investigate the need for so many different chains. Building on the previous episode we identify where new blockchains have spun up to fill a specific need, meet a requirement or anticipate a future use case. Specifically, we will take an indepth look at those that are trying to meet regulatory requirements with the hope of becoming more attractive to established businesses. We will analyze technically how they have done so and what sets them apart from their peers while attempting to use the least amount of technical jargon possible. A listicle yes, but a useful one!
-
11
We don't need no regulation
Regulation is part of life, in any advanced economy if you are going to sell goods or services be they digital or physical regardless of the industrial sector the responsible entity will more than likely be subject to regulation of some sort. So this episode is about the other regulatory classes, like privacy, financial, compliance and even standards. We’re going to delve into the purpose they serve in web2 and ask whether it would need to change in order to accommodate web3 or vice versa. We’ll also lightly probe if there is any value in having any of these classes of regulation for web3 in the first instance.
-
10
A Bridge too Far
In October of 2022 an attacker made off with 600M (!!!) by finding a bug in a bridge contract connecting two of Binance’s blockchains. How did it happen? It’s time to blow the dust off your third year Data Structures textbook. Listen to us stumble our way through bridge contracts, relayers, Merkel trees, hashing, and cryptographic proofs. This is Web3, and it's fantastic. If any of our former professors are out there, you might want to skip this one. You taught us well but it's been a few years. Links: Immunefi’s Hack Analysis: Binance Bridge, October 2022 How Did the BNB Chain Exploiter Pass IAVL Proof Verification? — An In-depth Analysis by Beosin The PR fix Twitter analysis thread
-
9
Web3’s Security Bazaar
We’re used to security happening behind closed doors. But our inner nerd loves transparency - and heedless of Gandalf’s warning we want to study the arts of the enemy. When attacks happen in real time on a public ledger, and response is community driven in discord and on twitter, you get a decentralized security scene. Call it the bazaar to Web2’s cathedral. More eyes, more voices, more noise. Is that better? Whether you agree or not, it's certainly better pod material. And isn’t that what really counts?
-
8
Same, same but different...
MEV Boost, NFT fails etc, all these hacks were enabled by underlying technical vulnerabilities some of which can appear to the (un)trained eye very similar to classic vulnerabilities we see in web2. Are they or are we being flippant, only one way to find out. So this is the one where we really dig into the technical details of the most well known vulnerabilities in web2 and web3 and decide whether there are actually any similarities at all.
-
7
Web3 in suits
Several years after Web3 broke out, there’s a noticeable dearth of patagonia vests still hanging around the crypto scene. Where are the Web3 unicorns? Does blockchain have a space in the enterprise? Do consumers care? Underneath this question is a philosophical discussion on disintermediation, decentralization, and what it means for a technology to be successful on the internet.Start exercising those brain wrinkles with a different parallel - is open source a success? Building a commercial enterprise on providing open source software is famously hard. Despite that the internet runs on software that thousands of nerds maintain, for little or no commercial purpose. Maybe this whole time the internet was all about the love ❤️
-
6
When the apes hack back
Normally when data goes out the door, it's gone - you can’t put the cat back in the bag, the horse back in the stable, or any other animal-metaphor back in its proper place. But crypto isn’t normal. When an NFT goes out the door, what if you could hack it back? In late 2023, NFTTrader had a re-entrancy vulnerability that led to the loss of a lot of valuable assets. But that wasn’t the end of the story. Intrepid community members used the same re-entrancy to take their assets back. (Re)-enter the matrix with us to learn how. Show links: Overview tweet thread Summary of community response Re-entrancy primer
-
5
Twenty-five, sitting on twenty-five mil' part two
So was it a calculated crime of opportunity that was destined to happen or were they just cleverer than the front runners who are the real bad guys here...
-
4
Twenty-five, sitting on twenty-five mil' part one
25 million dollars gone in 12 seconds. That’s more DPS than even the most hardcore RPG fan could hope for. How is it possible to lose so much so quickly? Scratch the surface, and you’ll find a whole ecosystem built to maximize the value of blockspace by ordering transactions before they hit the chain. Everything’s for sale - welcome to the mempool, keep your head above the water.
-
3
Identity in blockchain
Who Am I? We can’t figure that out for you, but we can sound off about who you are on the web. Security is increasingly about identity, and blockchain brings that to its full realization. You are your keys. What else could you be?
-
2
Sky Mavis analysis
Wherein we briefly remember that we’re security people, and talk about one of the biggest heists of the Web3 age - Axie Infinity.
-
1
Why all the AI love and the blockchain hate
While we had our heads in the clouds, another hype cycle kicked up. It’s name is AI, and it threatens to change the internet faster than Web3. Why is that? Does it have to be that way? Find out if our predictions have aged like milk or wine.
-
0
Why are we here?
Web1, Web2, Web3. Why does it matter? In the digital age code is power, so whoever controls the runtime controls the world. The platform age is ending. Web3 isn’t a slow database, its an alternate runtime for the web. Join us on the precipice as we break down the history of the internet and the political economy of the web.
We're indexing this podcast's transcripts for the first time — this can take a minute or two. We'll show results as soon as they're ready.
No matches for "" in this podcast's transcripts.
No topics indexed yet for this podcast.
Loading reviews...
ABOUT THIS SHOW
You might call this a Web3 security podcast, and you’d be right. The transparency and culture of the scene makes it a vibrant canvas to study, and we break down the biggest and most technically intriguing attacks in the space.But we think there’s more. When things break, they show you something deeper about how they work, and what they are. Like it or not the internet is different than it was. Join us as we take a critical eye to how it’s changing, by looking at how it fractures.Ideas welcome at notyourcryptopodcast at gmail.com
HOSTED BY
NYCP
CATEGORIES
Loading similar podcasts...