Securing Web3: Four Insights from MetaEra Summit
MetaEra Summit 2023, Singapore

Securing Web3: Four Insights from MetaEra Summit

With nearly $5B worth of exploits over the last 24 months, it is clear that security is one of the most existential problems the Web3 faces today.

Simply put, we cannot expect to onboard billions of users into crypto, unless we restore trust in the system.

Given the importance of security to the future of our space, I thought to share these takeaways from MetaEra Summit panel:?

  1. New Tech Stack, New Security Vulnerabilities

The main reason why cyber exploits permeate the security space is that Web3 is fundamentally creating a new tech stack - which will take years to battle-test. On the surface, it might seem like we are stating the obvious - after all, this is not unlike the internet in the early 2000s, when SSL/TLS, e-commerce, web hosting, ad-networks, and payment processing systems were built from scratch. What distinguishes Web3 systems is that not only are these systems new, but they are also permissionless.

  1. Human Error Is Still #1 Cause of Web3 Exploits?

According to the recent survey by Certik, people error accounts for 59% of all exploits in the Web3 security space in 2022! That is roughly 300 of 500 exploits in terms of actual count are to blame on human error.? Technology exploits and economics exploits represent 21% and 20% respectively. Simply put, despite its complexity and novelty, both technology and economic attacks represent less than half of all attacks in the Web3 space. This means training people and users the basics of Web3, and making the UX fool-proof should be a key priority for leaders in this space.?

  1. AI is a Double Edged Sword?

More than $95B has been invested in AI over the last 12 months - can it help make Web3 code more secure? On the one hand, combining AI with traditional program analysis, we can really detect customized logical bugs with 80% precision and and 10-20% false positive rate. For example, recently a critical bug - missed by two official audits - was uncovered by ChatGPT in the Banana Gun contract. AI also helps less experienced developers write code which is more secure, but ultimately experienced devs are still better at picking up bugs. Ultimately, AI tools are also becoming better at social engineering attacks (e.g. using AI for writing physicing emails), which brings us back to the human error factor described above.?

  1. We Need a Cross Industry Alliance

As an industry, we need to come together to build better standards for incident detection, prevention, and response. For example, Certik is collaborating with OKLink - a “regtech” product created by OKX - to implement post-incident fund locking practices, as well as Web3 taxonomy for data labeling. The former initiative instructs exchanges, like OKX, to lock the funds after the hacker wallet addresses have been identified as malicious. The latter addresses the inconsistencies that arise from data mis-labeling specifically around incident analysis and anti-money laundering.

TLDR: Better cross-industry standards could significantly reduce the hacks, thefts and reputation damage of the space.?

If you are building a security company in the Web3 space, I want to talk to you!?

***

Subscribe to my newsletter to have my takes on the most important Web3 events delivered directly to your inbox!?

Vlad Svitanko

??Founder of Cryptorsy Ventures: backing & scaling web3 projects. Public speaker, advisor, angel investor/VC.

1 年

Kate good stuff right here! Btw, what's your investment thesis? keeping an eye ??

回复

要查看或添加评论,请登录

Kate (Ksenia) Laurence的更多文章

  • Three Predictions for 2025

    Three Predictions for 2025

    #1: Stablecoin renaissance Prediction: More yield bearing stablecoins coming to market than ever before If there is one…

    5 条评论
  • BCVC Founder Summit 2024 Recap

    BCVC Founder Summit 2024 Recap

    What now is an annual tradition - we opened the summit with the results of the annual BCVC Founder/CEO Survey. Over the…

    3 条评论
  • Eigenlayer: The AWS of Web3

    Eigenlayer: The AWS of Web3

    In our most recent quarterly update, I introduced our LPs to what I think is going to be one of the most important…

    7 条评论
  • Ethereum's Broadband Moment

    Ethereum's Broadband Moment

    In 1998, Paul Krugman famously wrote that by 2005 the internet's impact on the economy will be no more significant than…

    7 条评论
  • The Golden Age of Crypto

    The Golden Age of Crypto

    During our inaugural BCVC Summit in 2022, the industry was in despair. FTX was crumbling quite literally as we spoke…

    12 条评论
  • 2nd Annual BCVC Summit 2023 Recap

    2nd Annual BCVC Summit 2023 Recap

    The second annual BCVC Web3 Founder Summit came to a close this past Friday, November 3rd. Ironically, our event took…

    13 条评论
  • The Future is Modular

    The Future is Modular

    This article was published on HackerNoon on August 10th, 2023 ? Until recently, blockchain infrastructure was mostly…

    8 条评论
  • More CeFi Crimes

    More CeFi Crimes

    Original version of this interview appeared on CNN Business on July 14th, 2023 Another day, another crypto entrepreneur…

    1 条评论
  • A Security Or Not A Security? That Is The Question.

    A Security Or Not A Security? That Is The Question.

    For me, that paradox of the US's approach to regulating crypto is kind of like trying to decide if a website is a phone…

    10 条评论
  • Give Me Regulation!

    Give Me Regulation!

    The reality is that over the last five years I have witnessed the failure of regulators to do their job in my industry,…

    3 条评论

社区洞察

其他会员也浏览了