Cryptocurrency Opening Keynote

Michael Schloh MsvB, Chad Calease, Param D Pithadia

DEF CON 33 · Day 1 · Main Stage

Overview

The DEF CON Cryptocurrency Opening Keynote for 2024 provided a comprehensive overview of the current security landscape within the rapidly evolving cryptocurrency space. Moderated by Michael Schloh MsvB, this keynote featured insights from Chad Calease of the Kraken security team and Param D Pithadia, an electrical engineering student at Georgia Tech, offering diverse perspectives on both the theoretical and practical challenges facing digital asset security. The discussion delved into the profound impact of emerging technologies like Artificial Intelligence (AI) on both development and attack vectors, alongside critical considerations for self-custody and the evolving regulatory environment.

Watch on YouTube

Visual summary for Cryptocurrency Opening Keynote by Michael Schloh MsvB, Chad Calease, Param D Pithadia
Visual summary for Cryptocurrency Opening Keynote by Michael Schloh MsvB, Chad Calease, Param D Pithadia

Key moments

  1. 0:00 Introduction to Defcon Cryptocurrency Areas and Speakers
  2. 2:00 Speaker Introductions: Pam and Chad's Backgrounds
  3. 3:00 Defcon Crypto Area Highlights: Contests, Workshops, Vendors
  4. 4:00 AI's Impact on Crypto Security & Development Vulnerabilities
  5. 6:00 Evolving Cryptocurrency Regulatory Landscape and Clarity
  6. 6:50 Core Security Principle: Verify Before Trust in AI Era

Cryptocurrency Security in 2024: Addressing AI Threats, Self-Custody Challenges, and Regulatory Evolution

Speakers: Michael Schloh MsvB (Moderator, Defcon Cryptocurrency Areas), Chad Calease (Kraken Security Team), Param D Pithadia (Electrical Engineering Student, Georgia Tech)

Conference: DEF CON

YouTube: https://www.youtube.com/watch?v=6fPUzKlZDfA

Overview

The DEF CON Cryptocurrency Opening Keynote for 2024 provided a comprehensive overview of the current security landscape within the rapidly evolving cryptocurrency space. Moderated by Michael Schloh MsvB, this keynote featured insights from Chad Calease of the Kraken security team and Param D Pithadia, an electrical engineering student at Georgia Tech, offering diverse perspectives on both the theoretical and practical challenges facing digital asset security. The discussion delved into the profound impact of emerging technologies like Artificial Intelligence (AI) on both development and attack vectors, alongside critical considerations for self-custody and the evolving regulatory environment.

This talk is particularly significant because it addresses the growing tension between innovation, accessibility, and security in the crypto world. As the industry strives for broader adoption, it simultaneously grapples with increasingly sophisticated threats and a persistent gap in user education. The speakers highlighted how AI is lowering the barrier for attackers, making social engineering more potent, and underscoring the indispensable need for robust personal security practices and informed decision-making by users and developers alike.

The keynote served as a vital call to action for the DEF CON audience, emphasizing the "verify before you trust" mantra and promoting the adoption of advanced security measures. By dissecting real-world vulnerabilities and offering actionable defensive strategies, the speakers aimed to empower attendees to navigate the complex digital asset ecosystem more securely. The discussion also provided a glimpse into the cutting-edge research and hands-on workshops available at the DEF CON Cryptocurrency Areas, reinforcing the community's commitment to advancing security knowledge.

Background

▶ Watch: Introduction to Defcon Cryptocurrency Areas and Speakers (0:00)

The landscape of cryptocurrency security is in a perpetual state of flux, driven by rapid technological advancements, an expanding user base, and the continuous evolution of attack methodologies. The DEF CON Cryptocurrency Areas, encompassing villages, workshops, and contests, serve as a critical forum for addressing these challenges, fostering an environment of collaborative learning and practical application of security principles. This keynote was delivered against a backdrop of increasing mainstream adoption of cryptocurrencies, which, while beneficial for growth, also introduces a wider array of potential targets for malicious actors.

A central theme woven throughout the discussion was the impact of Artificial Intelligence. Param D Pithadia noted that the talk immediately preceding the keynote was also on AI, setting the stage for an exploration of how AI is not just a tool for innovation but also a powerful enabler for new forms of cybercrime. The problem of securing digital assets is exacerbated by the fact that the barrier to entry for criminals is significantly lower than ever before. As Chad Calease pointed out, it's increasingly "pay-to-play," meaning sophisticated attack tools and services are readily available, making it easier for individuals with limited technical fluency to perpetrate fraud and theft.

Historically, the cryptocurrency space has also contended with a lack of clear regulatory frameworks, which created uncertainty and potential vulnerabilities. The speakers acknowledged recent progress, particularly in the United States, and referenced the evolving MiCA (Markets in Crypto-Assets) regulation in the EU, which provides more definitive "guard rails." This regulatory clarity, while welcome, does not, however, diminish the individual's responsibility for robust personal security. The foundational principle of "not your keys, not your crypto" remains paramount, yet its practical implementation often presents significant user experience challenges, especially for new entrants to the space. The keynote therefore sought to bridge this gap by discussing both systemic issues and practical, user-centric security strategies.

Key Findings

▶ Watch: Defcon Crypto Area Highlights: Contests, Workshops, Vendors (3:00)

The keynote illuminated several critical findings regarding the current state of cryptocurrency security, emphasizing both emerging threats and enduring challenges.

Firstly, Artificial Intelligence (AI) was identified as a significant force reshaping the security landscape. Param D Pithadia detailed how AI-driven development tools, such as the agentic AI IDE Cursor, can inadvertently become vectors for sophisticated supply chain attacks. By manipulating package ranking systems, malicious actors were able to promote compromised Solidity packages, leading to the theft of funds and personal information from developers who implicitly trusted the AI's suggestions and auto-imports without sufficient verification. This highlights AI's dual nature: a tool for efficiency that simultaneously lowers the barrier for complex security exploits.

Secondly, the speakers underscored the pervasive threat of social engineering. Chad Calease stressed that the vast majority of successful "attacks" are not technical hacks but rather expertly crafted social engineering schemes designed to trick individuals into compromising their own security or that of their loved ones. The increasing sophistication of these attacks, often facilitated by AI tools for impersonation (e.g., deepfakes, voice cloning), necessitates an unwavering commitment to the "verify before you trust" principle. This involves cross-medium verification for communications and the establishment of shared code words with trusted contacts.

Thirdly, the discussion reinforced the critical importance of self-custody and robust key management. While centralized exchanges offer convenience, they introduce counterparty risk. The consensus among the speakers was that as users accumulate more significant assets, transitioning to hardware wallets (cold storage) and taking direct control of their private keys becomes imperative. However, this comes with its own set of responsibilities, including secure seed phrase generation (preferably offline with methods like dice for entropy) and resilient physical storage solutions (e.g., steel etching, geographically distributed backups) to protect against disaster scenarios like house fires. The concept of multisignature (multisig) wallets was highlighted as an advanced strategy for enhancing security by requiring multiple approvals for transactions, thereby significantly raising the cost for potential attackers.

Finally, the keynote addressed the persistent education gap for new users. As the crypto ecosystem expands, many new entrants lack the fundamental understanding of how blockchain and wallets truly function (e.g., that crypto isn't on the wallet, but the wallet holds the key). This lack of fluency, coupled with the tendency to "tap through" security prompts on decentralized applications (dApps) without reading contract details, makes them highly vulnerable. The speakers argued that both companies and the community bear the responsibility of educating users to strike a balance between enabling developers and ensuring new users remain secure. This ongoing challenge underscores the inherent trade-off between usability and security, where every concession for convenience potentially erodes resilience.

Technical Deep Dive

▶ Watch: AI's Impact on Crypto Security & Development Vulnerabilities (4:00)

The keynote provided several technical insights into both current vulnerabilities and advanced defensive strategies in the cryptocurrency domain. Param D Pithadia initiated a critical discussion on the implications of Artificial Intelligence (AI) within the software supply chain for smart contract development. He specifically cited Cursor, an agentic AI Integrated Development Environment (IDE), as an example of how developers are increasingly relying on AI for autofill and auto-import functionalities. A notable incident involved a group of hackers who exploited Cursor's package ranking system. By manipulating this system, they ensured that their malicious Solidity packages were suggested and imported by developers building exchanges or smart contracts. This sophisticated form of supply chain attack, facilitated by AI, led to the theft of significant funds and personal information from large companies whose developers, trusting the AI's suggestions, inadvertently integrated compromised code. This scenario underscores the need for rigorous code review and verification even when using AI-powered development tools.

Beyond software, the physical security of hardware was also touched upon, with Param mentioning his workshop on hardware security, specifically focusing on side-channel attacks and differential power analysis. These techniques involve analyzing the physical emissions (like power consumption or electromagnetic radiation) from a device to extract sensitive information, such as cryptographic keys, without directly interacting with the device's software. This highlights a deeper layer of security considerations beyond purely digital threats.

Chad Calease expanded on key management strategies, differentiating between various wallet types and their associated risks.

  • Hot Wallets: These include software wallets and funds held on centralized exchanges. While convenient for new users and small amounts, they carry higher risks due to their constant connection to the internet and reliance on third-party security.
  • Cold Wallets: Primarily hardware wallets, these offer superior security by keeping private keys offline. However, Chad emphasized that many new users misunderstand that the cryptocurrency itself is not stored on the wallet; rather, the wallet securely holds the private keys that control access to the assets on the blockchain.

For seed phrase management, the speakers advocated for extreme caution. Best practices include generating seed phrases offline, potentially using methods like dice rolls to ensure true randomness and prevent any digital footprint. For physical storage, solutions like etching seed phrases into steel plates were recommended over paper, to protect against environmental hazards such as fire or water damage. Chad even mentioned extreme examples of individuals burying cards on different continents, illustrating the lengths some go to for distributed, resilient storage.

A significant technical recommendation for securing substantial assets was the adoption of multisignature (multisig) wallets. While not elaborated upon in full detail during the keynote, Chad offered to discuss it further offline, indicating its complexity and importance. Multisig wallets require multiple private keys to authorize a transaction, meaning no single point of compromise can lead to asset loss. This significantly raises the security bar and the "cost for criminals," making it a powerful tool for individuals and organizations managing large crypto holdings.

The keynote also briefly referenced upcoming workshops that delve into specific attack vectors. Michael Schloh MsvB mentioned a workshop on drain attacks on ERC-20 tokens, indicating a focus on vulnerabilities specific to smart contracts governing fungible tokens on Ethereum-compatible blockchains. Another workshop, led by prominent researchers Elaine Shi and Alfonso from Carnegie Mellon, would explore oblivious access to secure blockchains, hinting at advanced cryptographic techniques for enhancing privacy and security in blockchain interactions, potentially involving zero-knowledge proofs or similar technologies. These technical topics underscore the continuous research and development efforts required to stay ahead of evolving threats in the cryptocurrency space.

Demo / Proof of Concept

▶ Watch: Evolving Cryptocurrency Regulatory Landscape and Clarity (6:00)

The Cryptocurrency Opening Keynote itself did not feature a live technical demonstration or proof of concept during the presentation. As an opening address, its primary purpose was to set the stage, highlight current trends, and introduce the various activities and learning opportunities available at the DEF CON Cryptocurrency Areas.

However, the speakers extensively referenced numerous hands-on opportunities throughout the conference that served as practical demonstrations and immersive learning experiences. These included:

  • Workshops: Param D Pithadia and Michael Schloh MsvB were scheduled to conduct a hardware workshop later that day, focusing on hardware security, side-channel attacks, and differential power analysis. This workshop would provide attendees with practical insights into physical attack vectors against cryptographic devices. Additionally, other workshops mentioned included one on drain attacks on ERC-20 tokens, led by Georgia Tech students, which would likely involve demonstrating vulnerabilities in smart contracts, and another by Elaine Shi and Alfonso from Carnegie Mellon on oblivious access to secure blockchains, which would explore advanced privacy-preserving techniques.
  • Contests and CTF: The DEF CON Cryptocurrency Areas hosted an elaborate contest with eight levels, designed for all skill levels. Specifically, the Kraken security team developed a "Level Eight CTF (Capture The Flag)" challenge. This CTF was described as an opportunity for attendees "to dig into the nuts and bolts, the hidden machinery of this," implying hands-on challenges that would simulate real-world security scenarios and require participants to apply technical knowledge to find vulnerabilities and secure systems. The significant prize pool for these challenges further incentivized practical engagement.

In essence, while the keynote itself was a high-level discussion, it served as an invitation to a rich ecosystem of practical, hands-on learning and demonstration activities available to attendees throughout the DEF CON Cryptocurrency Areas. These workshops and contests functioned as the practical "proofs of concept" for the theoretical and strategic discussions presented during the keynote.

Defensive Implications

▶ Watch: Core Security Principle: Verify Before Trust in AI Era (6:50)

The insights shared during the keynote carry profound defensive implications for individuals, developers, and the broader cryptocurrency ecosystem. Adopting these strategies is crucial for mitigating risks in an increasingly complex threat landscape.

  1. Strict Verification Protocols ("Verify Before You Trust"): This mantra is paramount. Individuals must implement rigorous verification for all communications, especially those involving sensitive information or urgent requests. Chad Calease's advice to cross-verify (e.g., texting a caller to confirm their identity) and establish shared code words or phrases with trusted contacts (friends, family, colleagues) is an essential first line of defense against sophisticated social engineering and AI-powered impersonation attacks.
  1. Enhanced AI Literacy and Code Auditing for Developers: For developers utilizing AI-powered IDEs like Cursor, critical scrutiny of AI-generated or suggested code is no longer optional. The incident with malicious Solidity packages highlights a new vector for supply chain attacks. Developers must rigorously review all imported packages, understand their dependencies, and implement comprehensive security audits, even for code snippets provided by AI. Companies should invest in training developers on secure AI integration practices and code verification.
  1. Prioritize Self-Custody and Robust Key Management: As asset holdings grow, users should transition from relying on centralized exchanges or hot software wallets to hardware wallets (cold storage). This shifts control directly to the user. Critical defensive measures for self-custody include:
  • Offline Seed Phrase Generation: Generating seed phrases in an air-gapped environment, potentially using physical dice for entropy, minimizes digital exposure.
  • Resilient Physical Storage: Storing seed phrases on durable materials like steel plates and distributing backups geographically protects against single points of failure like house fires or natural disasters.
  • Understanding Wallet Functionality: Educating oneself that the wallet holds the key to the crypto, not the crypto itself, is fundamental to secure practices.
  • Multisignature (Multisig) Implementation: For significant holdings, adopting multisig wallets significantly enhances security by requiring multiple independent approvals for transactions, making theft considerably harder.
  1. Adopt Strong Operational Security (OpSec): Chad Calease's advice, "Stealth is the new black," is a critical defensive posture. Publicly "flexing" or boasting about cryptocurrency holdings online attracts unwanted attention and increases the risk of physical attacks (colloquially termed "wrench attacks"). Maintaining discretion about wealth and crypto activities is vital to avoid becoming a targeted victim.
  1. Proactive User Education and Awareness: The industry and individual users must actively combat the security education gap. New users need to be taught to read and understand smart contracts before signing transactions on dApps, rather than blindly "tapping through." Educational efforts should clarify concepts like the true nature of hardware wallets and the risks associated with various types of crypto storage. Companies onboarding new users have a responsibility to balance ease of use with clear security warnings and educational prompts.
  1. Simulation and Incident Response Planning: Chad emphasized the importance of simulation – rehearsing worst-case scenarios, such as losing access to a wallet or facing a physical threat. Proactively thinking through potential incidents and planning responses can significantly improve resilience and peace of mind, ensuring that individuals are prepared before an actual event occurs.
  1. Recognize Usability-Security Trade-offs: Defenders must acknowledge that every concession made for convenience or usability often comes at the cost of security resilience. Intentional decisions about these trade-offs, understanding the associated risks, are crucial for building a robust defense strategy that aligns with an individual's risk tolerance and asset value.

By integrating these defensive strategies, individuals and organizations can significantly fortify their position against the evolving array of threats in the cryptocurrency landscape, moving towards a more secure and resilient ecosystem.

Key Takeaways

  • AI Introduces New Attack Vectors: Artificial Intelligence, while enabling development, also lowers the barrier for cybercriminals, facilitating sophisticated supply chain attacks through manipulated AI development tools (e.g., Cursor promoting malicious Solidity packages) and enhancing social engineering tactics.
  • "Verify Before You Trust" is Paramount: In an era of AI-powered impersonation, rigorous cross-medium verification for communications and establishing shared code words with trusted contacts are essential to combat social engineering and prevent fraud.
  • Self-Custody and Advanced Key Management are Critical: For significant assets, moving from exchange-based or hot wallets to hardware wallets is crucial. This requires robust key management, including offline seed phrase generation, resilient physical storage (e.g., steel backups), and considering multisignature (multisig) solutions.
  • Operational Security (OpSec) Prevents Physical Threats: Practicing discretion about cryptocurrency holdings ("stealth is the new black") and avoiding public displays of wealth is vital to deter physical attacks ("wrench attacks") targeting high-value individuals.
  • User Education is an Industry Imperative: Bridging the security knowledge gap for new crypto users is critical. This includes educating them on reading smart contracts, understanding transaction signing, and the fundamental mechanics of hardware wallets (i.e., that wallets hold keys, not crypto).
  • Balancing Usability and Security is an Ongoing Challenge: The industry continuously grapples with the trade-off between making crypto accessible and maintaining stringent security. Every convenience often comes with a potential erosion of resilience, demanding intentional security decisions.

About the Speaker(s)

Michael Schloh MsvB served as the moderator for the Cryptocurrency Opening Keynote. He is actively involved with the DEF CON Cryptocurrency Areas, which host a variety of interactive events including villages, workshops, and contests. Michael also co-led a hardware workshop during the conference, demonstrating his hands-on engagement with the technical aspects of cryptocurrency security.

Chad Calease is a member of the Kraken security team. His core philosophy revolves around being "productively paranoid" and fostering intentional habits for self-custody and security. Chad is a strong advocate for fundamental security practices such as 2FA (Two-Factor Authentication), the use of hardware security keys, and maintaining a low profile or "stealth" regarding cryptocurrency holdings to prevent physical attacks. He emphasized the importance of verifying communications and robust key management strategies.

Param D Pithadia (Pum) is an electrical engineering student at Georgia Tech. His academic and practical interests lie in hardware security, specifically in areas like side-channel attacks and differential power analysis. Param co-led a hardware workshop with Michael Schloh MsvB. During the keynote, he focused on the impact of AI on cryptocurrency security, particularly its implications for smart contract development and the lowering of the barrier for both developers and attackers.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

A DEF CON opening keynote that reads like a well-formatted blog post aimed at crypto newcomers — competent survey content, zero original research, and nothing an informed attendee couldn't have gotten from a CoinDesk think-piece. The 'technical deep dive' is a list of concepts with no actual depth, and the credentials on stage don't match the ambition of the slot.

Heather Calloway (CISO) — WEAK

This is a well-intentioned community keynote that covers real ground — AI-assisted supply chain attacks, self-custody, social engineering — but stays firmly at the awareness level throughout. The findings are credible, the audience is right, and the advice is sound, but there is no institutional analysis, no accountability structure, and no decision path that would be meaningful above the individual user.

→ Top-rated talks at DEF CON 33

All talks from DEF CON 33