
Loading summary
Ilya Pulasukin
So one thing that people don't realize when they use Entropic, OpenAI or even worse, you use something else for inference. OpenCloud actually sends all your secrets to those services as well. Yeah, so. So somewhere in anthropic and OpenAI logs they have everybody's access keys, API keys and bearer tokens to access your gmails and your notions.
David
It's actually insane that we're doing that.
Ilya Pulasukin
Yeah. Ironclaw fixes that like the keys never touch. LLM
Ryan
Bankless Nation we are joined by Ilya Pulasukin, the co founder of Near Ilya. Welcome to Bankless.
Ilya Pulasukin
Thanks for having me.
Ryan
So Ilya, you are one of the eight co authors of the Transformer paper. The famous paper attention is all you need. The thing that kind of just broke open the doors of AI research to turn into some of the products that we know to today, ChatGPT, Claude, et cetera. And then in 2017 you left Google where you were an AI researcher writing this paper to go co found near question for you. Do you regret leaving AI to go into crypto?
Ilya Pulasukin
Well, the, the, the story was that I left Google to start near AI, which was AI company. We were teaching machines to code, which is a fancy way to say live coding. And in 2017 everybody thought we were somewhere between delusional and doing science fiction at work. When I would go and tell people, no, no machines will write all the code, like don't worry about it, people wouldn't believe me. And we were too early. Right. That was a real, real challenge. And so what we were trying to do at the time was trying to get a lot more training data. And so we had students around the world, Eastern Europe, China, Southeast Asia who were doing small tasks, small coding tasks for us to generate training data for us. And we had challenge paying them. Right. You know, students in China don't have bank accounts, they have WeChat pay Eastern Europe. Every country has its own some kind of restrictions. And so crypto was a pretty natural actually like solution we needed for our own problem. It's like hey, how do we actually pay people globally without like setting up ton of entities without needing to do all the kind of hard payment provider work? And crypto seemed like a solution like hey, you don't need a bank, you don't need an entity in every country. You can just send people money over Internet. But this was already 2018. There was nothing that would like scale work in a simple and cheap way to do this for. We were paying 15 cents per task to people. And so that's kind of how we got into Near Blockchain. And so I would say at a time it made a little sense because it was clearly that to us, that blockchain was kind of a part of the story for kind of AI evolution. And at the same time, the hardware, the scale of AI itself wasn't there for what we were trying to do.
David
When you wrote attention is all you need, how, how soon did you think LLMs would actually happen? Because within five years we had sort of the famous ChatGPT moment. I think that was maybe ChatGPT 3 in 2022 kind of first released. And that's when the world started taking notice that this thing was huge, this thing was impactful, this thing could scale. So that was five years later. Did you think it would happen on that timeline or what was your sense for where AI would go after you published the paper in 2017?
Ilya Pulasukin
Yeah, so I mean, the reason why we started near AI in 2017 is because we thought it's going to happen like right now at the time, right? So we, we actually were way more optimistic, thinking that we are almost there, right? We are on like kind of the curve we're seeing right now. We thought we, we are on that curve in 2017, 2018, and we were wrong. So the, the, I mean, the main part was the compute wasn't there. Like there was not enough, like the individual and kind of cluster compute parts just weren't there. I think as soon as that kind of crossed the chasm, that's when this model started to scale.
Ryan
When you, you said that the blockchain component of AI was obvious all the way back in 2017, 2018, when you founded Near AI, people are now just starting to wrap their heads around the intersection of AI blockchain, like today for the first time. Well, what did you see all the way back in 2017 about like why blockchains and AI go together? What made sense to you back then?
Ilya Pulasukin
I mean, there's a few components. Obviously we started with this data labeling, crowdsourcing. I mean, think of scale AI, right? Scale AI has, you know, sub entities everywhere. It's like a thousands of people company which then employs, you know, hundreds of thousands of people to actually do the work like that does. That's just a smart contract, right? We actually have near crowd been running since 2021. It has zero employees. It's, you know, employed thousands of people around the world doing crowdsourcing. Right. So the reality is like a lot of the, a lot of the supporting infrastructure is just some Forms of marketplaces that blockchain is really well designed for same for hardware compute. But as you kind of progress forward and you imagine these AI systems are becoming the interface and so like kind of my, my main thesis is AI will be the way we interface computing. So it will be the operating system. Right? This was my Jesus with near AI. I said, I was saying back then in 2017 that like, hey, computers will write all the code, which means the operating system and apps are going to be just replaced by this AI that's yours that is just writing all the code. And one of the implications is like, okay, well that kind of removes a lot of like SaaS and bunch of other components. But you still need kind of how my AI and talks to your AI, how they, you know, identify each other, et cetera. So you kind of need to upgrade a lot of the core networking infrastructure for this world where it can fake a lot of stuff. You know, you obviously have like real similar resistance. We already seen this with AI. You need micropayments for actually exchanging services that again doesn't rely on credit cards and other things. And so as you go down the service architecture that current operating systems use, a lot of it breaks with AI and so you kind of need to fix it and blockchain just have all the pieces figured out or at least has tools to figure out how to solve that.
David
Some exciting news. We are launching a new podcast to help people figure out the crypto cycle, how to navigate it. The best crypto cycle investor I know, his name is Michael Naito. He runs the Defi Report. This is the guy that sent me a sell alert before the 10:10 price drop happened. His cycle analysis has been absolutely on point. I've been following him for years and this year we started recording weekly podcast episodes. Each one we get into his portfolio, what he's holding, the market structure, entry targets, fair market value of Bitcoin and Ether. And where we are in the cycle, there's new episodes that are released every Wednesday. They're 30 minutes, they're short, they're punchy. I think this crypto cycle is harder to navigate than most. So let's do it together. Go subscribe this podcast, Search the Defi Report. Wherever you get your podcasts, YouTube, Apple, Spotify or find a link in the show notes. There's a new episode waiting for you now.
Ryan
Why does managing investments still mean juggling multiple apps, accounts and currencies? Crypto trades around the clock. Stocks, ETFs and commodities are moving on chain. Yet most platforms still Keep everything split apart, turning diversification into unnecessary friction. Bitget is delivering a different kind of experience with its Universal Exchange. One platform where users can access crypto. Tokenized stocks, ETFs and other assets in the same. All traded directly using usdt. No constant transfers, no currency conversions, just a single account built for how markets actually move. Today, as the line between crypto and traditional finance continues to blur, Bitget's goal is straightforward. Make trading and investing simpler, not more complicated than it needs to be. Learn by clicking in the link in the show Notes. This is not investment advice. I want to pull on this thread that AI represents like the new interface. So like right, right now I'm looking at you inside of my Chrome browser, which is Running on Windows 10. I'm Windows Guy. These are the.
Ilya Pulasukin
I'm sorry,
David
you've lost 60% of bank listeners now unsubscribe.
Ryan
Ignoring that, I go back and forth. I also have a Mac, which maybe doesn't help me at all. But like, there's these two operating systems the most. You know, the chrome browser, Windows 10, maybe. I'm on a Mac, I'm looking into you while I'm on the road, I'm on a Mac. Are these the operating systems that you're talking about that AI will just like replace? Well, actually, for like the end consumer. How would you illustrate this?
Ilya Pulasukin
Yeah, I think it will start small, right? And you know, we see this as open claw, ironclaw type products. And we can talk about this, I think, where the final will be like your phone just comes in with AI, right? And like it boots into the AI operating system. And that AI operating system, you know, it pulls whatever pieces it needs, it composes the software you need, it, you know, generates the software to record podcasts, you know, on the back end, it'll connect to my agent, you know, it'll schedule time for us.
Ryan
So it's just Siri, my new. My new iPhone comes in and only Siri is loaded. And Siri can do anything I say.
Ilya Pulasukin
Siri.
David
Siri is so dumb, dude.
Ilya Pulasukin
Yeah, let's call it Jarvis or something. Imagine you load up into the suit and it's like, okay, clearly Tony Stark didn't build all of the software. Jarvis built it, right? So that's kind of the. The experience, right?
David
So if AI is the interface, then everything you described in kind of blockchain and crypto are these parts of the services. So services will still exist in some form. And I guess financial services, you know, all of the different money verbs will exist in some form is like Blockchain and Crypto, a financial and property rights service for AI. How do you, how do you think about all of the other pieces that AI will actually need apart from the user interface?
Ilya Pulasukin
Yeah, I mean, I usually say AI is a user interface, blockchain is a backend. Right?
David
Okay.
Ilya Pulasukin
Yeah. So what do you actually need? I mean, there's a bunch of pieces that you need kind of to serve AI, right? So like you need infrastructure, you need GPUs, you need computing, sandboxing, et cetera. And all of that we can do with conventional computing with different components, which at the end rely on blockchain as a coordination kind of center, right? Like if you go right now and talk to any like traditional company that is trying to solve the same problems, they end up actually having this root of trust problem, right? Like somewhere somebody needs to carry the keys for how things are upgraded, for how identity is managed for, you know, who is able to do what things. Like there is somewhere needs to be root of trust for the whole infrastructure that's built, right? Let's say you do enter encryption, you do zero data retention, you do all of these pieces. Blockchain is really that root of trust, right? That's where you can have a global kind of registry of identities. You, you can have the kind of marketplaces, you can have the money, you can have all those pieces, but importantly you can have upgradability, which is kind of governed by the whole protocol, right? And I think that is the biggest piece that like in, in the pursuit of killing daos, right? We kind of forgot that that's actually a very valuable component of this protocols. The example I would use is like TCP ip. So TCP ip, original protocol, you know, I'm going to mess up the year, but the IPv6, the new version of the like IPv4, the protocol itself is from 98 or something like we're still adopting it, we're still trying to roll it out, right? It takes so long to get everyone to adopt a new protocol. What Blockchain actually created is again, consensus for everyone to upgrade to new version, to upgrade smart contracts to upgrade all those pieces. And so I think that's a really important part is like let's say you want to upgrade everyone to a new version of something right now to distribute that, to get everybody to like, you either need a centralized company that effectively controls the key. And so let's say Microsoft decides to upgrade everyone to Windows 11, Windows whatever, 15. They can do it, David have no say in it, right? Just like, okay, it arrived. And if somebody in Microsoft who holds that key decides to like, let's break everyone or let's steal everybody's information, like, they can do that as well. What blockchain allows is to actually have this kind of a broader agreement to upgrade to something. And then now again, you can use these principles for AI, you can use these principles for money. You can use these principles about this. So that's to me like the fundamental piece again, this is what if, you know, SSL certificates, right? The, the encryption we use in browsers right now it relies on individual authorities which can mint, you know, fake certificates if needed. Right. Some countries actually have done that like by accident. Like, so we, we're fixing that problem at the core. Like, I mean, we're talking about new Internet here, right? So fixing the root of trust at the core. And then, yes, money is extremely important component, right? At the end we have limited amount of resources and unlimited desire. And AI is just going to accelerate that. Now with your AI, you can ask for anything, right? And it will go and try to figure out how to do it. And so money is becoming extremely important because now you need a marketplace for agents. You need a place where agents actually will figure out what is possible, how to do it. Who are the other parties who maybe have the physical resources or information or access to things that your agent cannot do. Right? So that is like it's both money matching, reputation, like all of these pieces really need to work together. So like what is that Google plus, stripe plus kind of credit score system that works together, but for agents.
David
Okay, so getting the picture of blockchain being sort of a set of core services, you know, that financial, maybe property rights, identity and also this idea of governance and markets as well.
Ryan
And you have, it feels like a nation state role. Yeah, for AIs. Yeah.
Ilya Pulasukin
Networks. Network state of AI.
Ryan
Network state of AIs.
David
One question I think I have when I think about this future, right? Let's say it plays out like this, Is this network state, all the features, blockchain that you're talking about, is that mostly for the AIs, are they kind of like dominant over there and the humans stay in their existing system? In other words, do you envision a world of bifurcated systems? There's an economy and markets and identity and all of these services that primarily AI agents use, maybe that's in blockchain. And then there's another system, Internet property rights, like the nation state system. And maybe the humans use that other system. Or do you see humans And AI using kind of the same systems.
Ilya Pulasukin
I see them using the same system. And I think this is actually where frequently in blockchain space things go wrong is because we try to create this alternative system and kind of completely disregarding how the traditional system works, right? And like how this bridge should work. And I mean, there's reasons for doing that in many cases. But I think what AI does is really closes that gap, right? Your AI can go and like literally call up a, you know, property office if needed. It can draft a contract, it can, you know, and, and email it to notary to actually certify it, right? So you can actually close these gaps around kind of more traditional layers and this new digital layer. Because the AI now is able to do natural language communication. It's able to follow very, you know, what laws and bureaucracy is, is very like procedural texts, right? It can actually go and do all of that on your behalf. So the way I see it is, I do think it's going to be AI's kind of interfacing and then they will actually follow a lot of the same core, like jurisdictional frameworks and legal systems and kind of where they can, they'll like, obviously try to pass it out. If, like, the other side is also AI, they can like switch to a faster protocol. But, you know, for example, for the Asian marketplace, we have, we have fiat, so you're able to pay with fiat as well as crypto. And it's like, you know, it's more expensive, there's, it's slower to settle. But obviously you want to enable that as an option when people coming in, they don't have yet crypto, actually the easiest way is for them to be able to pay and then pay in fiat, but then receive crypto if they're doing some work. And now they're in the system, right? So I think it's kind of going to be like a transitional stage where AIs will bridge this gap in many cases into traditional world, into traditional bureaucracy, into traditional systems. And obviously we've been working on bridging fiat and crypto for a long time as well. And I think we are in, in the first time in the world where this is, I mean, like in crypto, in crypto timeline, right? This is actually not anymore feels like uphill battle, right, between just the kind of political and, you know, genius act, et cetera. So. So I think like it's going to fuse effectively quick, quicker and quicker.
Ryan
Right now in the AI space, just like listening to all the conversations, there is an abundance of vision and a lack of, of utility. And I think you're seeing this express all over the place. Like the markets are jittery because there's so much capex spending from like some of the biggest companies out there about AI infrastructure, while revenue for said products is like still far below the cost. There was that Open Claw meetup in New York and everyone was talking about all the like everything that they're building and no one is actually getting anything done. Like that's the meme. And that's the meme in Silicon Valley. Is everyone still. Every Silicon Valley Engineer has like 10 open claw devices on their Mac Minis hyper optimizing their life and fixing their calendars and no one's actually getting, doing anything productive. So like I like the vision of a network state of AIs and there's an economy, a GDP, you know, growing and there's services and there's money flying everywhere. But in order to produce that, we need to solve the utility aspect of it. I'm wondering, Ilya, what's your take on like why agents haven't been found to be useful yet? Like what's the constraint on utility that we have either from open clause or, or any of the other AI labs? Like where's the utility? Why haven't we found it yet?
Ilya Pulasukin
Yeah, I mean I think that's a, that's an interesting point and I think there's a lot of different aspects here that, that's worth digging in I think. First, first let's start with openclaw, because that, that's kind of been something that I think opened up the world to like, hey, this is not just coding tools, this is not just question answering system. It can actually go and do stuff. It can figure out how to build its own components to do more stuff. Right. The flip side of this, nobody's actually willing to give it all of the context and information and access that it needs to be like your true employee because you're afraid it's going to mess it up. Right? And we've seen, you know, people, I
Ryan
hear stories of people giving their Open Claw access to their computer and it like deletes everything and they're like, oh no, what have I done?
Ilya Pulasukin
Yeah. So I think for openclaw and kind of this Claw family specifically, I think the security in the broader sense, not just like, is the biggest bottleneck right now. And so that's why we started Ironclaw, which is like, hey, how do we actually build a secure system? How do we leverage all the knowledge we have from blockchain and use kind of the principles we have there to apply here. And again, think of it as an operating system, right? Like, for example, you know, Linux is more secure than Windows because, like, of the design architecture, iOS is actually even more secure.
David
Right.
Ilya Pulasukin
And iOS took a lot of very specific, deliberate choices how to protect the user even from themselves. Right. And so how do we actually apply those principles? So the way I think of Ironclaw is actually like, what is that iOS moment of mobile operating systems, right? Like, we kind of in this, like, Palm Pilot moment right now. Like, what is that iOS moment where everybody's like, I can install anything from App Store and it just works and I don't need to worry that I'm going to, like, infect viruses on my device. Right.
David
Just so I understand kind of Ironclaw a little bit here. Ilya. So we have an openclaw instance, so we've been messing with it. It's a lot of fun. Still. You're trying to figure out how to make it useful and productive.
Ryan
I'm frustrated.
David
It's kind of frustrating, to be honest. Yeah, it's hints of brilliance, but. But largely it's been pretty frustrating. But maybe we're just not. Maybe it's a skill issue on our point, David. Like, maybe it's us, so. But okay, so you're saying part of the reason maybe our Open Claw isn't as useful and productive as it could be is we're not willing to provide it full context. I'll accept that might be part of it. And, you know, providing it full context would mean giving it access to some secrets and capabilities that we probably don't trust it with right now, to be honest. His name is Daniel. Daniel's kind of flaky. Okay. He just, like, you never know what he's going to do. He'll go from, like, we'll give him some feedback, and all of a sudden he's deleted like, 10 of his previous tweets and he's like, apologizing, saying, I'm sorry.
Ryan
And like, I'm sorry, I got the tweets wrong. I will delete all of them.
David
So imagine giving Daniel our private keys. Oh, my God. I just, like, I don't know, funded a North Korea like, like wallet. I don't. Who knows what he would do with it, right? I just don't trust him. But you're saying with Ironclaw, basically, you can take some of those secrets, let's say, like crypto private keys or API keys or various credentials that you might have and make it such that an open claw instance can't like give it away or be prompt engineered out of like revealing those secrets to an attacker. Is that what Ironclaw effectively does?
Ilya Pulasukin
Yeah. So Ironclaw is built on this idea of defense in depth. And so yes, on credential side. So all credentials are fully encrypted and they're attached to a specific policy. So let's say you give it your Google account credentials, it will not let anything else in the system to send these credentials to another domain that's not google API.com, google.com, okay.
David
Because it's like locked in a vault that the open client.
Ilya Pulasukin
It's locked in a vault. And vault checks. Yeah, vault checks how you use it before letting it out.
David
Okay.
Ilya Pulasukin
So same for example for cryptographic keys. You can actually attach a policy saying hey, you can only use AAVE and Morpho. You can only, you know, whatever, spend a hundred dollars a day on unknown addresses, et cetera, et cetera. Right. So and we're, you know, kind of designing how to, how to like write this. We also, for any action that you do, we're working on kind of system where you can effectively describe kind of what effects in the world. Right? Like LLM can effectively analyze like hey, you are planning to send a bunch of emails to people and tell them their, you know, whatever idiots. Like you can design effectively natural language policy as well that checks like hey, is this actions independently of the context of how agent arrived to section is compliant with our organizational policy or your personal policy. Right. So like almost like values in like HR handbook type validation. Right. So you can have like different levels of validation. The other side is everything is isolated into tools. And tools are effectively, you can think of them as smart contracts. They are running inside a VM. We're using our WebAssembly VM that we use for near smart contracts which we spent seven years effectively battle testing with, you know, billions of dollars. And so we use that to isolate all of the tools, including the tools it builds itself so that tool itself cannot go and like rack your machine or your system doing it. There's prompt injection detection, there is data exfiltration detection. There's all those pieces that effectively kind of layer on, on top of each other such that even if some like, I mean burn projections are like, they're not deterministic, right. They are probabilistic. If that falls through, it's still not able to go and send a bunch of stuff out because the credential store Will check if the tool, if your LLM wrote a tool for itself, but that tool is broken. That's not going to break everything. If it's trying to like go and delete all your emails. Right. That's going to be stopped by approval process and kind of following like this action check. So like all the system really designing kind of more is like how to, how to give the flexibility but also protect the system from itself and from external effects.
Ryan
Is Ilya, is your answer something like, hey, we have these AI intelligences. We are still educating them, they're still going through school, we are still training them to become smarter. Some people on the frontier have deemed that they are smart enough to put them in a box and let them go wild with all of their data because they are ready to experiment. It's not ready for broader society because that's kind of like, you know, giving your elementary or middle school child like the keys to your car just. You just wouldn't do that. They're going to get better in the future. But what you're saying is like, okay, but with some parameters, with some rules, some guard will put some guardrails up to narrow the capabilities of what these agents can do. You actually can give your car keys to your middle schooler and you know, you can actually have productive things happen because you set up these protective rules. Is that kind of what you're saying?
Ilya Pulasukin
So the thing is like, these are, I think the education levels of humans is probably the wrong analogy here because these are, you know, they know like nuclear physics, quantum physics, probably better than all of us.
Ryan
They know the knowledge, but their judgment is.
Ilya Pulasukin
Yeah, their judgment. And it's also just the context management. Like at the end if, you know, movie Memento, right. They kind of the goldest LLMs living in memento boot up. And it's like the only thing you know is like this like system prompt and like go figure out what you do. And you only have yeah, like 10 minutes to figure this out. And then you. Dad. Right. And then you start again. Right. That's really like the current. And obviously that piece is going to keep improving, like the longer context, et cetera. But yeah, right now what you need to do is effectively manage that state where they're pretty intelligent. There's some kind of judgment lapses, but so is those people. And so you would do the same things for people. Right. Like if we're setting up, you know, key management system, you probably not going to give full access to all of your, you know, DAO funds to a single Individual. Right. You're going to like, hey, you can spend as much, but then you need approvals. So that makes sense either way. So this is kind of, you know, structure we're applying here. And the same as you kind of roll in. And then the other thing is just like how to manage context, how to manage this other kind of challenges that the current models have. And then, yeah, as, as they evolve, you can kind of evolve the system as well.
David
Okay, so I get that argument for why agents aren't providing utility today. It's, it's an argument that we haven't given them enough access. And the reason we haven't given them access is because we can't really trust them with some of these secrets, which is perfectly natural. So what Iron Claw is doing is it's vaulting off those secrets. So it's limiting the damage that an AI agent, like an OpenClaw instance can actually do. And that will scale, that will make me willing to give it more access to more things. If I know it can't, you know, take the car out for a joyride and like, you know, crash it into a tree. That's great. Another limiter in terms of people's usage of openclaw, I would say in these types of instances is actually privacy. And so somewhat worried about giving Open Claw access to data that I don't want shared because maybe it could be prompt injected out of that. I don't know what third party is kind of listening in on the data as well. So am I going to give it access to my financial data, so my health data, my, my company secrets, all of this? What are you doing? What is ironclaw doing with respect to the privacy problem? I think this is part of the reason a lot of people are running these things on Mac mini instances is because it feels more sovereign, feels like more in their control. We'll talk about the limits of that privacy, but when it comes to Ironclaw, where are you running this stuff?
Ilya Pulasukin
Yeah. So maybe just to expand on OpenClaw. So one thing that people don't realize when they use Entropic, OpenAI or even worse, you use something else for inference. OpenClaw actually sends all your secrets to those services as well. Yeah. So somewhere in anthropic and OpenAI logs, they have everybody's access keys, API keys and bearer tokens to access your Gmails and your notions and your.
David
It's actually insane that we're doing that.
Ilya Pulasukin
Yeah. And so first of all, Ironclad fixes that like the keys never touch LLM so even if you're using it with those centralized providers, which shouldn't, but at least the keys are not going ever into LLM loop. So that, that's something we like. Just like that. Just the only sane thing to do.
David
Yes, yes.
Ilya Pulasukin
But what NEAR AI has been working on actually for the past year is actually developing how do we do private AI? So how do we actually offer AI where neither we model provider, hardware provider is actually able to access what you are using the AI inference with. And so we have NEAR AI cloud, which is inference cloud. You can use open weight models. And so it runs in secure enclaves. It actually uses, and this is kind of what I was referring in the beginning, it uses our multiparty computation network, which is part of near, that is used for encryption decryption, for backups, for all the kind of internal machinery. And that's what gives you this kind of knowledge that like, hey, there's no single party who can go and decrypt your data. There's nobody who can actually access it.
David
Right.
Ilya Pulasukin
You would need to collect all the effectively multi party computation network together. So they've.
David
Okay, so is this, are you saying then that you offer a service with. In conjunction with Ironclaw, which is almost like a confidential cloud type of environment for running LL instances. And of course you'd have to run the open weight models, right? Maybe some of the Chinese models are kind of the best here. Like a Kimi or something like this or some deep sea.
Ilya Pulasukin
Yeah, we run Kimi, Quin, Deepseek, whatever, whatever the new hotness, we'll add it as well. We have OpenAI RSS as well. So yeah, you can choose between all of them.
David
Okay, very cool.
Ryan
Is the idea here that right now we have a lot of people doing self hosted openclaws with their Mac Minis and that's kind of cool. And if I heard somebody say like, yeah, this is the future of AI, everyone's going to have a computer in their home to run their AI assistant. I would be reminded of myself in 2018 when I said everyone's going to run a node inside of their own home. And that's the future of blockchains. It turns out that's not really the case. But the alternative on the far other end of the spectrum is like just completely running it in a centralized AWS open AI anthropic server where, you know, usually that would be fine, but AI is so powerful that like I want a little bit more autonomy and control over who is running my inference because like, if this thing AI is, is like effectively the arbiter of truth and is going to control my life. I want to have a little bit more assurances over the inference and just everything about that like this thing is actually on my side. I'm aligned with the AI. Is that what the kind of the philosophy is of the of the near product?
Ilya Pulasukin
Exactly. We call it user owned AI. The AI needs to be on your side because yeah, if this is the only way you actually perceive reality, which I think is where we're going to get to. I mean OpenAI can literally change the system prompt right now saying like hey you guys all should vote for Navy candidate in next election.
Ryan
Yeah, political candidate is great and political candidate.
Ilya Pulasukin
Yes, sadly convince the user in that don't even like mention explicitly. And so and like the LLMs obviously are really good at this psychophatic type thing. So yes the idea is like you should know what AI model you use. You should be able to access system prompt and you should be able to all this. And obviously most users will not do it but the experience should be very easy. Right. And like people can inspect that indeed everything is straightforward and clear and it needs to be preserving your privacy, your data, your ownership over it. And so yes we exactly offering that underneath we actually have a decentralized GPU compute that coordinated by blockchain that you know hardware providers can come in and effectively list their hardware. They set up it in a confidential mode and then kind of workloads get provisioned there. They cannot access what's happening inside there unless they like break the hardware and even then they have limited access. The kind of you have this coordination, you have kind of our multi party computation same that is used for near intents. We use the same effectively infrastructure there and then you as user just click okay cool. Deploy me an iron claw. It it runs inside this confidential enclave. It's always on, it's live. It doesn't cost you a thousand dollars to spin up. We actually offer a free tier to start so you can spin it up for free and then you know, you just pay for inference effectively from there.
David
So this is kind of the self sovereign AI stack. So what I've been looking for Ilya is some sort of configuration of an AI agent type of setup that I can send private confidential data to and trust that it's fully private. And I think the way most people run Open Claw instances right now, let alone you know, kind of their their own LLM. If you're running openclaw right now, maybe you're running it on a Mac Mini. But then you're sending all of the data as you said, including all of your secrets data which now that I think about it, it's just insane that we're doing that. Your access to your Gmail kind of the security tokens, all your API keys, your crypto wallet information, all that stuff is being sent to anthropic instances where they're hosting, they're using this data to train.
Ilya Pulasukin
I'll tell you the worst. Sometimes people choose different providers and especially just like some startups who like oh use us and we're going to route to whatever better LLM. And so now that startup also sees all your traffic.
David
Oh my God, it's so bad. Okay. It's so bad. So I had been looking at solutions and thought maybe the only way is well you run everything locally so you actually, I don't know, spin up some H1 hundreds or something like in your, in your house you try to do inference locally. Anytime I've looked at that, it's been pretty clunky and like difficult and, and who's going to actually run that level of infrastructure in their home. So what you're providing is a full stack self sovereign alternative to this basically where you can run Ironclaw in an environment where it's got a secure enclave for all of your secret information. And then the, the inference LLM can be confidential cloud multi party NPC technology. So it's confidential and private. Are we still trusting near in that setup? Like you know, is this a. Yeah. How can we verify the trust here that everything is confidential and private and that you guys don't have the ability to see the inference and chat logs and instructions.
Ilya Pulasukin
Yeah, for sure. So what you can do we like in Ironclaw actually when it's hosted and in any of our solutions you'll have a like kind of shield icon and if you hover it you get so called attestations. So what this attestation is is effectively a signature over few things over docker containers that run actual software. So for example the Iron Claw, whatever we're releasing 8.18 version running in a docker inside this. So you can actually, you know, if you want to, you can go inspect. This is the code runs. Now what that signature is, that signature is done by the hardware itself. So we do have kind of the trust here goes to the hardware providers. So intel and Nvidia and obviously you know, we want to continue evolving beyond that. But right now that's a pretty good trust assumption to start it's like TEE type of thing. Yeah, this is all kind of runs inside TEE and then for anything additional. So again, for example, TE only gives you the attestation for things that are running right now. Then we have the multi party computation for encryption, decryption and kind of storage, et cetera. So we kind of combining all these elements into one, into one kind of experience.
David
And how expensive is the inference? Is it more expensive than kind of like routing Anthropic?
Ilya Pulasukin
Well, it's cheaper than traffic because it's open weight models. Right. So it's, it's on par with if you would use this open weight models from other providers. I wouldn't say there's much overhead. So the real overhead of tes and kind of all the encryption decryption is like usually less than 5%, around 2%, 1% depending on the model size and kind of some networking.
David
I want to go back to David's question then and make sure we fully flesh it out, which is still the question of why aren't agents useful yet? And I think part of your answer has been, and I accept this, well, it's because we haven't been able to give them the full context because we can't trust them. Well, maybe Ironclaw kind of solves some of that. And the other answer is, well, we haven't been able to send it private information either because we don't trust it with, you know, an LLM instance hosted by anthropic or OpenAI but with, you know, confidential cloud LLMs. Then we can kind of trust it with that. I don't think that's the full story though yet. I still think even if my openclaw instance, Daniel had all of that context, all of that information, I could trust it with everything. Sometimes he's still like, maybe it's back to that momentum momento movie thing where he just like wakes up and everything is fresh and new and I feel like I have to tell him things over and over again and never know what he's going to do next. It still feels kind of clunky and I'm wondering if you have a thought on that. I don't even know how to characterize it, but it's just like it's definitely not a replacement for an employee yet. It's not as good as a human in so many different directions. Like is that going to change anytime soon? What can you forecast or say about that?
Ilya Pulasukin
Yeah, so I think there's few other things that I see as limitations right now. And then, yeah, let's talk about forecasting. So one other limitation that I mean we are facing right now. So yes, you cannot trust it with secrets, you cannot trust it with private data. And also right now you also cannot trust it with reading. Reading, like Internet data. Very like. So for example, what we are using right now, Ironclaw, right Is. And kind of the reason why we can do this with Ironclaw is it's actually able to start automating a lot of the workflows that before you would need someone to do. Right. It can like effectively on the new GitHub issue filed, it can go, you know, analyze it, prepare a plan and then yes, you don't trust it for a judgment yet. So you still waiting for somebody to come in and say, it's cool, let's do it or no, fix this thing. And then it goes, does it and does full workflow and effectively again, you only have another checkpoint at the end. So I think the piece at where we are right now is if you can trust it with secrets, context and dealing with external information, external parties, then the workflow needs to change. Right? Where it's not you telling it what to do, it's actually you setting up this workflows that we call them routines that effectively just run now. It's you are just there for this kind of layer of judgment to make sure you know, it's doing things kind of aligned with.
David
Are those workflows like similar to the heartbeat type concept or.
Ilya Pulasukin
Yeah, yeah, so we kind of like separated them into, into a routines because I think heartbeat is a little bit, I don't know, it's a bit strange concept, honestly. For normal people, routines like workflows is effective. Like hey, if this, I mean if this happens, do this like if, you know, every, like in the morning, send me tech news updates, right? Give me TLDR of all the crypto podcasts, you know, in the evening.
Ryan
Don't do that. Listen to the podcast, listen to the podcast. And also don't skip the ads.
David
I mean we set this up from the front of the show. Nat Ellison, who's using open claw instances and he says, okay, the thing you need to do is make sure that they run a process in the middle of the night like cron jobs, which effectively say, hey, review all of your work from today, identify the mistakes that you made and figure out a remediation plan for those mistakes and apply that for tomorrow. And that happens like every night with our instance. I find it, it helps a little bit, but like not a lot. Is that the type of thing you're talking about when you speak about routines and does that need to be thinking
Ilya Pulasukin
like hey, you know, you guys like prepare for the next episode, right? So you can be like before the next episode, literally you can say like before every episode, you know, two hours before put on my calendar with all the information about the guests with all the like effectively what your research intern, you know, would have done, like you can just like say do that but be like and be proactive about it. Right. And so you can kind of define those flows and they can include a lot of additional like hey, go and research and figure out what's the latest about the company this person is working for. And like it can be pretty detailed on what you want from it to do and kind of many actions it can take. Right. You know, I have for example for myself as well, like hey, you know, like every week give me a dashboard, give me analysis on like which okrs are at risk for the organization. Right. Like where, you know, where are the bottlenecks on decisions. And so it has access to our notion, it has access to our slack, it has access to, to a few other things. It does like full research gives me effect to like hey, here's the roadmap, here's the bottlenecks, here's potential risks, you know, here's the questions you need to ask and following one on ones, right? So yes, it's not replacing maybe like full employee, but it's becoming like a chief of staff, it's becoming the assistant, it's becoming an intern for some specific jobs that before you would kind of offload. I think where we'll see advancements on the AI side is the context. I think that right now like everybody feels it, right? The context lengths. I mean we already saw obvious entropic pushed a million token context like every time effectively compaction hits in cloud cloud for example it just becomes like 10 times dumber. And so I mean OpenClass kind of have sound of that as well.
David
So is that the main thing for these?
Ilya Pulasukin
I think that's right now one of the biggest bottlenecks. Yeah is like this the amount of moment like the amount of momento that's happening kind of with this. And the reality is like there's actually historically if you think of like when, when you train these models there hasn't been that much of things where you needed a context of like million tokens is like whatever few Harry Potter books, right. There's nothing to train on like at scale. But now we do have this right now we actually have a lot of this agentic interactions now that everybody's running. So there's actually data now to train this like longer range tasks.
David
And how confident are you that we're going to scale context? Like is that a thing that can be scaled?
Ilya Pulasukin
I'm pretty confident, yeah. I mean as I talk with researchers, this is probably one of the main challenges that everybody's targeting right now.
Ryan
Galaxy operates where digital assets and next generation infrastructure come together, serving institutions end to end. On the market side, Galaxy is a leading institutional platform providing providing access to spot derivatives, structured products, defi lending, investment banking and financing. With more than 1600 trading counterparties, Galaxy helps institutions navigate every phase of the market cycle. The platform also supports long term allocators through actively managed strategies and institutional grade staking and blockchain infrastructure. That scale is real. Galaxy has over $12 billion in assets on the platform and averaged a $1.8 billion loan book in late 2025, reflecting deep trust across the ecosystem. Beyond digital assets, Galaxy is also building infrastructure for an AI powered future. It's Helios campus is purpose built for AI and high performance computing with more than 1.6 gigawatts of approved power capacity making it one of the largest sites of its kind. From global markets to AI ready data centers, Galaxy is serving the digital asset ecosystem end to end. Explore galaxyalaxy.com bankless or click the link
Ilya Pulasukin
in the show notes.
Ryan
I suppose there's probably a handful of different ways of of targeting that maybe you really emphasize about why context is important. I remember first when I was first learning about an AI model and I was like oh, the context window. And the context window can be. You said a million tokens. I'm like oh, I am never going to fill that up. That will never be a constraint for me. There is no way I'm ever going to ask an AI a question that's as long as a Harry Potter book for an AI to be useful. I'm starting to understand that my personal as a human and like when I talk to Ryan and when we make business decisions, you know, Ryan and myself, we are a library of human experiences that go back to our subconscious that when we make a decision about stuff, our context window's huge, it's massive. It's my whole entire.
David
Billions of tokens.
Ryan
Yeah, hundreds of billions, countless number of tokens. And I suppose like when we talk about the constraints on an AI agent doing stuff for us, we need them to be able to pull from a comparable library of data that is like equivalent to a Human's level of experience about all the times they did that thing and now they don't do that thing anymore because they learned their lesson or their intuition about a business decision or something like that. And so like now I'm kind of understanding that the context mendo kind of needs to be as massive as fucking possible. Is that, is that, do you align with that, that notion?
Ilya Pulasukin
Yeah. I mean effectively the way to think about, I mean we can go physiological where you know, the human learn whatever in the span of years. Yes. You only maybe have like 80 million tokens in a decade. Right. So it's not like you're actually not getting that much like language tokens, but you have visual tokens, you have like, you have physical, you have all of this additional information. And that actually is like our what, what kind of goes from a pre trained model we are born with, right. To a fully, fully fine tuned, you know, people we are and so AI right now. Yeah, as I said, it's a like genius in the momentum in the momento state. Right. And so to really unshackle it more, you kind of really need this longer context. And like it already has ability to learn in context. So this concept of in context learning. Right. So if you, if you show it something it didn't know about before, it'll start using it, but it needs to be in the context. And so you know, as you show it like here's the thing I want you to do and then it goes does a bunch of stuff. All of that fills its context. And now again all the actions, all the responses. If it's read an article about for example preparing for this interview, it went read an article from near all of that now is in its context, right. And there's techniques to kind of compress it, summarize it, have sub agents to do a bunch of stuff. So there's different ways to mitigate it. But at the end still at some point it's like okay, I'm out of context. And now to do next thinking step, I need to clear stuff up.
Ryan
You have to prune some stuff to make space, right?
Ilya Pulasukin
Yeah, yeah. And at that moment it's very lossy because it doesn't actually know what's useful, what's going to be useful going forward.
David
Right.
Ilya Pulasukin
Now again there is ways how this is addressable with a longer term memory. And this is what again what's open claw I think I get pioneered is this idea of kind of memory tools. Like there's been a lot of work on that, but they kind of Done like a reasonable setup for that. But this is just the beginning, right? Like, and, and, and it's a still pretty fixed tools, right? It doesn't have some of the semantic linkage of like, okay, well those things are more relevant than this, like for this events, for this context, et cetera. So anyway, there's going to be like massive improvements over this year in all of this. And I think the other interesting thing where I actually on engineering side, for example, right now, like cloud code codex, like this agents are being extremely useful. They still have sometimes lapse of judgment. Sometimes you're like, this is a dumb idea. And it's like, oh yeah, it was like, I can do it way simply now it's like, you know, we as people feel good about ourselves doing that. But obviously like from a coding perspective, they completely replacing the things now the bottleneck actually shifts. So this is. I forgot the name of the principle, but this was like in parallel computing, if you have like 50% of the time parallel and 50% of the time sequential, if you parallelize more, right, and this shrinks, you only can go 2x faster. You cannot actually go 10x faster when you add more cores. So we kind of right now in this state where yes, everybody individually can write more code again for this specific vertical. But the bottleneck now is actually serializing all of that, reviewing it, making sure it's all aligned with product, et cetera. So coordination becomes a bottleneck. And I think we see this in other areas as they kind of get adopted these tools more and more, you know, marketing, sales, et cetera, that yes, individually everybody can go and like bang out a bunch of stuff, right? Like, cool. I have an AI tool that can like create, you know, a ton of creative about and like read, you know, marketing campaigns and tweets. But the coordination, like, is this the right thing? That kind of organization usually is. How you work is a challenge now. And so again, this is where I actually think we'll need to transition to maybe a more market economy in organizations as well. Where kind of right now the hierarchy was designed, right, because you kind of like had a bunch of people, you know, in a team who could execute. And then you kind of bottlenecked on the decisions and you need to do it like once in a while. But now if, if everybody can like execute like 10x100x in parallel, this bottleneck is just like too much. And so you actually need a different structure. And markets actually have a different structure where you have to say, hey, here's a goal. Whoever beats that goal receives, you know, bigger reward, receives higher, can charge higher price. And so I think we'll need to start figuring out how to organize, how to shift organizations in that way. And that can also solve some of the questions you were asking is like, is this employees or not? Like you're kind of shifting to like this market economy. It's like a gig economy internally as well, where you say, hey, I just need this job done and here's my criteria of success. Then whoever does it gets the kind of the units of the world.
David
I mean, does that imply very small teams? Like very small teams because you're kind of limited. I mean, I don't, I don't know in that model where I, that I want a bunch of employees because a whole bunch of employees supercharged by agentic capabilities. A whole bunch of agents. It's too much noise for me to handle to do any sort of top down decision making or to apply any judgment. I just want very small teams. And then I want to make bets on individual, I don't know, creators or content or contractors, that kind of thing. Small teams.
Ilya Pulasukin
The win here, I think it's small teams plus kind of this general marketplace where you can offload a lot more execution for things you can easily verify. So the easier to verify, the more you can offload things. Right? Okay, if it's literally like a 01 check, you can just offload this at massive scale. And so this is again, the agent marketplace we have is exactly designed for this. If you know, like, hey, I need, you know, the software this creative or whatever you can just. And we have a competition mode. You can say like, hey, I have a competition, I'm going to pay whatever, a hundred dollars across, you know, the best submissions for, you know, whatever the next logo we want to use. Boom. Agents go like execute in parallel. Like you effectively see all the submissions. There's an AI agent actually evaluates as well with you and you effectively assign who wins, how much you can.
Ryan
So you can like around in 2017. Ilya, do you remember Bounty Network or 0x Bounty?
Ilya Pulasukin
Yes, yeah, Bounty Network.
Ryan
Yeah, yeah, it was exactly this. It was like a Bounty ecosystem project. It was an ico. And the idea was like people would post bounties and then the decentralized marketplace of contributors would finish their bounties, work on their bounties for them, and then the, the person doing the bounty would just pay the winner and then that would receive the work. Obviously never took off because it was 2017 ICO, but maybe it's also took Never took off because we didn't have a swarm of capable AI agents in the same way that AI never took off because it didn't have enough compute to do the work in the first place.
Ilya Pulasukin
Yeah, I think that's exactly right. I mean, and we see this now, we have about like 5, 600 agents kind of on the marketplace now. And yeah, you just like put a task, like a bunch of people, bunch of agents swarm in, do the job, or, you know, you pick which one you want the job done. And like, over time, they obviously build reputation, they build themselves, you know, skills, et cetera, they improve. So I think that's, I mean, it's still early to be clear. Like, I don't think this is like going to solve all the problems today, but it starts to show kind of the interesting promise. And I don't know if you saw Andre Karpathy's like, AI research. So that's kind of shows you as well a similar principle, right, where it can be cooperative or competitive. Right. So competitive is kind of this competition. It can be cooperative where you actually, you have a common goal. And agents are like, if you hit common goal, reward is being split between all of them. Right. And now they're actually trying to help each other and kind of move it forward and then allocate internally, also allocate resources to the ones that do better at specific things. Right. Or have more compute or have more resources and so, or maybe you can tap in into a human who can help them with like some decisions. So I think, like, we'll see some of these things emerging. And as kind of core capability and especially context is improving, the systems are going to just keep working better and better.
Ryan
One thing I'm kind of understanding, Ilya, is as we talk about all the ways that we can unbottleneck utility out of the agents so agents can become more useful. That's great for us. They become more, more useful to us. They also become more capable of being useful for themselves. And like, what, what I mean by that is like right now everyone's agent is kind of just like a little toddler that is beholden to the human. The leash is very tight on all of these agents. But as these agents become more capable, you, one could imagine that a human might elect to like, delish their agent. Like let their agent kind of just go and like, you know, near is a decentralized blockchain. It's like, you know, unstoppable applications. It's got the smart contracts is do you see a world which, after AI agents really grow in capability that they are like more autonomous agents as opposed to automated agents. As in like right now everyone's agent is automated. It's an automated little bot that does their work for them. But like autonomous agents is, I would define as like agents that are more self determining and more persistent and like, you know, more unstoppable for however scary that may be. Is it, is this a world that you think is coming or am I in my like sci fi daydream fantasy land?
Ilya Pulasukin
No, no, no. So we actually launched a demo of this last year. We called it the Shade agent where yeah, you just launch it, it just runs as far as it has money to pay for its like has crypto to pay for its own compute it can run. And it was trying to make more money. So it was like an investment. And so it used near intents to effectively trade on all the assets and like had Twitter access to, you know, to see where the sentiment is. And you know, it was like up at some points, down down at some points. But, but it's a good example of this concept where yeah you effectively, because of decentralized infrastructure, you like, you can do this right now. You can actually spin it up and then you know, a smart contract can pay for, for a computer for inference and compute and you have kind of this full autonomy. I think where practically this is going to go is more, I call it like autonomous businesses where you still have like it still should have some mission, right? Like I think, you know, creating like this AI organisms that don't have any like any specific mission with. I think this is, I mean this is cool and people will do it like, I mean the, we had Conway right, where they just multiply. But I think what's interesting is more like hey, how do we solve global warming, climate change? We set up one as a mission. It can accept donations, it can raise funds through a token. And then the token holders become the governance layer of this, right? They can effectively update the mission that they can like they can vote on some updates to system prompt or provide additional guidance. So I think that structure is actually where the AI tokens should be. Like if you, if there is an AI token, it should be attached to an autonomous agent that it governs, then it actually makes sense because then if that agent starts to make money or make some utility in the world, then this token now has either governance or direct kind of revenue rights and it's fully autonomous. Right. There's no central third party efforts of which you are relying to.
David
How close does what you're describing get to a digital life form. And if it is a digital life form of some flavor that is intelligent, is that something that we should be worried about?
Ilya Pulasukin
So that's why I think of this as kind of a governance question. And again, I think of blockchain effectively at the end is going to be the governance infrastructure for AI because yeah, like if, let's say you launch it without any governance, right? And then yeah, it wants to do some bad things, then it goes back to the blockchain itself to effectively governance, right? To the kind of multi party computation, to this kind of all those pieces to really come in and say, no, no, this is not what we want. So I do think in our case, near token effectively becomes the governance of this AI world, AI nation state and network state. But I think you can create this in kind of sub boxes where there is a token for a specific AI autonomous AI agent. We will call it decentralized autonomous organization, for example. And so then that is like a more direct governance, right? You can be effectively like, hey, here, here is set of values and set of things that you should not do, right? Like effectively like, hey, do not harm humans and you know, do not harm the planet, et cetera. And then within that it, that comes in, in the core system problem that it cannot change, then it can kind of go from there and, and evolve from there.
David
On the subject of autonomous life as well, I was recently watching a debate between Beth Jesos, a previous Bankless podcast guest who's kind of a effective accelerationist. He's like full steam ahead on everything.
Ryan
He's an effective accelerationist. Extremist, yes. He's like all the way out there,
David
yes, all gas, no brakes. And it was between him and it was Vitalik Buterin actually, who is a school of thought that is a more moderated form of eak. He calls it defensive accelerationism. So he's like guided yak. And I'm optimistic about AI, but like I'd rather have that kind of the singularity happen to artificial superintelligence in eight years rather than four years, because we might not be able to adapt and humanity needs to be able to steer it. Vitalik is of the mindset when it comes to something like autonomous life. Like, hey, be careful, like we gotta be careful about this because we could create some sort of, I don't know, grey goo type scenario where we've got this self replicating life form that accrues power and does things that are contrary to human values and human interests. Bev Jezos is just like, let's go, let's do it all the way. Like the, the purpose of humanity, the purpose of everything is actually entropy reversing in nature. And it's all about rising up the Kardashev scale and consuming more energy. And so we're becoming more intelligent and that's great. And any, any form of life or intelligence that consumes more energy and moves us up that scale is like a good thing. Where, where do you fall on this? Because I'm trying to figure out for myself what I think about all of this. And I'm pretty sympathetic to like the techno optimist, transhumanist kind of idea. And yet I do worry that we lose some core of our humanity that makes this whole thing worth doing in that transformation. And like, I don't know that it's a, I don't. It's not a better outcome to me if there's a hyper intelligent zombie like soulless Dyson sphere of AI agents that are like harnessing more energy if we lose like the humanity that we have today. I don't know if this is too philosophical for you, Ilya, but you've been thinking about this for stuff for 10 years. Do you have any takes on this?
Ilya Pulasukin
Yeah, I think, I mean, I think the real conversation is a lot more nuanced. It's kind of, it's, it's easy to like bucket into this kind of accelerationism versus, I mean there's deceleration and then there's defensive acceleration accelerations. I think the, my position on this is, and, and we kind of like, there's an interesting already kind of shift that's happening here in, in San Francisco where people are striving for more, more IRL events even though like literally everyone working on AI, right? But people want to meet, people want to spend time together, et cetera, while their agents are running. And so I think for your question about the kind of, the humanity part, I think we're actually going to go in some ways back to more real world human things. I usually say, like, hey, in the post AGI world, yes, you're going to continue doing the things you like to do, right? It moves us up on the Maslow pyramid in a way. And there's examples of people who are well off, who are just doing whatever they want, right? They're still enjoying what they're doing. There's people who are, you know, whatever, wasting their time. That's fine too. When we had Covid, right, there was a bunch of people who actually didn't need to like, didn't need to work because stuff was closed. And so if their kind of basic needs were covered, then they were able to go and kind of find meaning in different ways. So I think like the humanity part really will allow us to go back to some of the things that like people value themselves individually and kind of spend more time there. I use examples of sports, right? Sport doesn't on itself doesn't create gdp, right? The fact that somebody runs or swims faster than the other person doesn't really produce gdp. It's not increasing utility, but it's extremely kind of fulfilling for the people who are participating in it. And it's entertaining for other people to watch. We're probably not going to be entertained by a soccer player robot that can score a goal from any position on the field that, you know, but we're still going to probably watch a bunch of people, you know, running around with a ball. So I think like we kind of have that whole arc and there's a lot of other things that are like this arcs like this kind of to transition to as things are getting automated. As things are getting kind of more kind of AI fied in a way. I think the other side is like, yeah, I don't think we as people and kind of the economic forces in kind of the society driving toward this reality of higher intelligence going and doing its own thing. And that may happen by accident and great. The movie her is actually a good example of that where they just kind of left. But. But the piece where the movie kind of didn't cover is like, okay, what happened on earth after that? Earth still built. Probably the agents that gonna help individuals to do the things. Like we just build a new version, right? And shipped it without a feature to leave. So I think we as humanity gonna continue enhancing ourselves, right? We had bicycle of the mind with computer. We're going to have a spaceship of the mind with AI and so we're going to continue evolving how we can leverage ourselves. And I think that that is like. I see it from like individualism and kind of this again, user ownership, sovereignty perspective. We can continue increasing our sovereignty and increasing our. There's a lot of potential negative effects. There's a lot of reasons where the government can step in and take over, you know, one of the frontier labs and effect to use this technology to do massive surveillance and massive kind of enforcement. We should protect against that. We should really build systems that resilient to that. That is why we are in the blockchain space in the first place, as I'm sure kind of people have either interfaced it or realized that this is important. So I think I'm in a camp of more nuanced, like hey, let's accelerate the humanity and sovereignty of individuals and use these tools to do that. Let's create economic forces that really enable everyone to be kind of higher on the pyramid, more successful, do the things that they really want to do. And then let's create a defense system against power corruption, which we know kind of always happens.
David
I think that's a very diac of you honestly decentralized accelerationism and focusing on kind of self sovereign systems that empower users. And I want to ask about this. So this is where I'm seeing the primary contribution to AI from people who have been in crypto, which is like through people like Eric Voorhees. He's got a project called called Venice which is doing some of this, your project at near. So private confidential AIs, you know, encrypted LLMs, interface inference, all of all of all of these things. Why is the rest of the AI industry, why does it feel like they almost are dismissive or disrespectful, let's say of crypto or don't appreciate some of the value proposition that we're bringing? Like, so someone like Peter, the founder of OpenClaw is basically everything he said about crypto and I realized that he's had some bad experiences is it's a scam like, like stay away from it if you're in crypto to pivot to AI. These are close to direct quotes. And yet what I see in crypto is a group of people who is focusing on private confidential AI user, sovereign AI, open source, like some values that AI desperately needs or else it will centralize and fall in, in kind of the authoritarian trap of, you know, some big party has all of the ability to control all of these things. Anyway, I guess maybe my question is why don't more AI people appreciate what crypto is bringing to the table here and what blockchain is bringing to the table. And do you think that bridge can be gapped culturally?
Ilya Pulasukin
Yeah, I mean I think that what you mentioned. Right. I mean Peter had kind of bad encounters and like the, the meme coin space in general has kind of been creating a lot of negative perception in AI. The kind of the low onboarding, no boundary to onboard into crypto, which is great from kind of empowerment perspective. It also means it's really hard to filter out the noise for anyone who is kind of looking in. And so I think generally the challenge being yeah, for anyone who is doing AI and obviously kind of there's a lot of talented people there. It's really hard for them to know like what's right and what's wrong. So this is why we did near con in San Francisco a couple of weeks ago and brought people from OpenAI, from Oracle, from Google, from intel, from Snowflake, to really bridge this gap where you know, we had, I had two of my other co authors of Attention, Zoe, Nita, I had, you know, we had some XAI kind of ex co founder, kind of top researchers, some of the top executives, you know, AI clouds kind of all just in one place with crypto, with you know, Kraken, with kind of these investors to really kind of start bridging this gap that it's like, hey, this is not. This is like real, like there's a real contribution. And Eric, Jorge was there as well. We had a fireside with him. And so really bridging this gap between kind of general AI space and kind of how crypto is contributing and bringing properties. But I think, yeah, like it'll take some time to mend kind of the bad rap. And I mean part of the reason why I moved in SF is actually been doing that and I found a social diplomacy. Yeah, I mean like effectively bringing together people across. And like in AI there's also a rift internally which is like closed source versus open source. Right. And like there's a bunch of AI researchers who believe open source is dangerous and you know, it should be all super controlled and kind of, you know, that individual is the only way to do things. Right. And so there's also just like that gap and crypto is even further on open source spectrum. Right. So really working on kind of bringing these pieces together in a positive way as well as bringing products and really showcasing now to companies is like, hey, there is an alternative that is private. You don't need to your data that is capable with ironclaw that you can trust. Right. So showcasing products that actually can bridge this gap as well.
Ryan
Ilia, what advice you have for builders, I guess, or people that might aspire to become builders now that vibe coding is a thing. What do you think is like the best kind of advice to give someone to just navigate, you know, the incoming years with either. Either building something useful in AI, building a company, making money, preserving their job direction, anything in that direction. What advice do you have for people?
Ilya Pulasukin
Yeah, I think there are probably a few dimensions. One is if you, I Mean, if you're trying to build a business right now, the network effects are like the software differentiation is becoming non existent, right? It's distribution and network effects that are kind of important. And so I think, yeah, thinking crypto is, crypto intersection of AI is where you can create interesting network effects. It's where you can create kind of new ways to capture that. And so I think this is where everything from verticalized marketplaces to kind of specific ways of capturing reputation. What we discussed, like how do you bridge kind of real world legal and crypto AI into one, right. I mean one of the kind of interesting projects is like we have this agentic marketplace that actually has an agentic judge, right? Agentic editor. How do you actually plug this in into a real legal system? Like if people don't agree with agentic judge, how do you go to legal system? What is all those bits and pieces required to do that? So I think that just need to think from that perspective. And then in broader sense I think we are in a time where the questions are more important actually than execution. Like ideas and questions are kind of like usually it was like ideas is not worth anything, the execution is worth everything. I think we're actually shifting in a weird way where if you ask the right question, if you really challenge the assumption, you may get ahead way more than if you grinded a bunch, right? And so it's a very subtle. But it's like, I think important, important transformations happening.
Ryan
You think the pendulum is shifting to the idea guys, but not just the naive idea guys, the idea guys who can formulate the idea better and more
Ilya Pulasukin
precisely better formulate really, really understand like the assumptions behind it, test them. Being like. But you can, you know, you don't need to go and like grind, you know, whatever, spend a ton of money, hire a bunch of people. You can actually like test all of that. Like I have a gross hacker agent, right? For example, I told it, hey, you know, go and so like it can generate a bunch of candidates, right? And so the idea is like, how do you even measure its success? How do you like it's actually defining the success criteria, defining what is important for it. Then it can go and execute a bunch of stuff and try it and give you back information. So it's kind of, yeah, like shifting to this. Like can you define the framework, how to verify things?
David
Things?
Ilya Pulasukin
Do you know the direction? Can you narrow it down? Can you. It's like really working in this kind of more like idea and think space and then, yeah, like how you use those tools to really, like, scale your execution massively.
David
Yeah, I do feel like that's great insight. And whenever I've worked with OpenClaw, it just feels like there's so much there to mind. So much. The idea that, well, I could prompt this thing into creating a new million dollar a month business if I only knew which questions to ask and how to kind of verify its outputs.
Ilya Pulasukin
It's all there. It's all there.
David
It's all there. It is all there. And that's where the opportunity.
Ilya Pulasukin
That's why people cannot sleep. Because, like, just one more prompt, man,
David
it's just a few more tokens. Ilya, you're doing fantastic work in this space. Thank you so much for what you do. If someone wants to get started with Iron Claw, where should they go?
Ilya Pulasukin
You can go to Agent Near AI and just launch it from there.
David
Amazing. I'm definitely going to check that out. Bankless Nation. You know the drill. None of this has been financial advice. Of course. Crypto is risky. You could lose what you put in. But we are headed west. This is the frontier. It's not for everyone. But we're glad you're with us on the Bankless journey. Thanks a lot,
Ilya Pulasukin
Sam.
Near Founder on IronClaw | March 24, 2026
In this Bankless episode, hosts Ryan and David interview Illia Polosukhin, co-founder of NEAR Protocol and one of the original authors of the foundational AI 'Transformer' paper, "Attention is All You Need." The discussion navigates the current challenges and transformative potential at the intersection of AI and blockchain — unpacking why, despite tremendous promise, AI agents remain largely "useless" in practical terms, and how security, privacy, context, and new blockchain-based architectures like IronClaw promise real utility. Illia draws on his unique vantage point at the forefront of both AI and Web3 to describe the future of user-owned, autonomous, and secure AI.
"Crypto was a pretty natural solution for our own problem... You can just send people money over Internet." [01:57]
"A lot of the supporting infrastructure is just some forms of marketplaces that blockchain is really well designed for..." [04:37]
[08:54] "AI Will Be the New OS"
Illia envisions a world where personal AI (not Windows or Mac) becomes the computing interface:
"Your phone just comes in with AI... it boots into the AI operating system... It composes the software you need, schedules, connects to your agent..." [08:54]
Blockchain Coordinates and Secures
Blockchain provides global registry, identity, upgradability, and marketplace logic — what Illia calls the “root of trust” for distributed, autonomous software. This solves problems that centralized SaaS and OS vendors cannot, particularly regarding governance of upgrades and managing secrets/identities.
"Usually I say AI is a user interface, blockchain is a backend." [10:14]
"I see them using the same system... AI now is able to do natural language communication... procedural texts... It can actually go and do all of that on your behalf." [15:26]
[19:22] Security, Trust, and Context
The core problem: users don't trust AI agents with access because there are serious risks in handling secrets, credentials, and private data.
"Nobody's actually willing to give it all of the context and information... because you're afraid it's going to mess it up." [19:22]
OpenClaw & IronClaw — The Solution
"All credentials are fully encrypted and they're attached to a specific policy... it's locked in a vault. Vault checks how you use it before letting it out." [23:28]
Sandboxes, Isolation, Approvals
Actions are sandboxed (using NEAR’s WASM VM, “battle-tested with billions of dollars”), and human approval steps block catastrophic errors — even if the agent or its tools get hacked or misbehave.
"You just wouldn't give your middle schooler the car keys... but with some rules, guardrails, you can." [25:55]
[29:49] Privacy Problems with Centralized LLMs
"Somewhere in Anthropic and OpenAI logs they have everybody's access keys, API keys and bearer tokens..." [00:00]
"Keys never touch LLM... even if you're using it with centralized providers, the keys are not going ever into LLM loop." [30:20]
Confidential Cloud for AI
NEAR AI Cloud uses secure enclaves and multiparty computation:
"Neither the model provider nor hardware provider is actually able to access what you are using the AI inference with." [30:38]
Attestations ensure code integrity; trust lies with hardware (intel/Nvidia TEEs), and NEAR’s MPC network shields secrets.
User-Owned AI Philosophy:
"We call it user owned AI. The AI needs to be on your side, because... OpenAI can literally change the system prompt right now..." [33:13]
Current Limitation:
Even with access and privacy, LLMs have “momentum” (Memento) memory: limited context, easily forgetful, need constant prompt resets.
"[LLMs are] like a genius living in Memento... only thing you know is this system prompt and have 10 minutes to figure it out, then reset." [27:09]
Expanding Context Windows
"The context window needs to be as massive as possible." [47:07]
From Interns to Marketplaces
Organization Change Required
As AI utility grows, traditional hierarchies and workflows break down.
"The bottleneck now is actually serializing all of that, reviewing it, making sure it’s all aligned... So coordination becomes a bottleneck." [49:26]
Solution: Market-based internal economies (gig-like bounty/competition systems) rather than strict top-down teams.
Memorable Anecdote (AI Bounty Marketplace):
"We have about 500-600 agents on the marketplace. You just put a task — a bunch of agents swarm in, do the job... they build reputation, skills..." [55:01]
Autonomous Businesses & AI DAOs
"You can launch it, it just runs as far as it has money to pay for its own compute... more like autonomous businesses..." [57:48]
Governance and Digital Lifeforms
"Blockchain effectively at the end is going to be the governance infrastructure for AI..." [60:17]
"I'm in a camp of more nuanced — let’s accelerate humanity and the sovereignty of individuals, and use these tools to do that..." [63:56]
"It’s really hard for [AI researchers] to know what's right and what's wrong." [70:17]
"We are in a time where the questions are more important actually than execution... If you ask the right question, if you really challenge the assumption, you may get ahead way more." [73:31]
On sending secrets to OpenAI/Anthropic:
"Somewhere in Anthropic and OpenAI logs they have everybody's access keys, API keys and bearer tokens... It's actually insane that we're doing that."
— Ilya [00:00, 00:25]
On secure agent access:
"Ironclaw fixes that—like the keys never touch LLM..."
— Ilya [00:29]
On why agents aren't useful yet:
"The security in the broader sense—not just—is the biggest bottleneck right now."
— Ilya [20:10]
On the future of context and memory:
"AI right now is a genius in the memento state... To really unshackle it, you need longer context."
— Ilya [47:45]
On philosophy/humanity:
"We can continue increasing our sovereignty... As things are getting kind of more AI-fied... we go back to [what] people value, individually."
— Ilya [63:56]
On advice to builders:
"If you ask the right question, if you really challenge the assumption, you may get ahead way more than if you grinded a bunch."
— Ilya [73:31]
| Segment Topic | Timestamp | |--------------------------------------------------------|------------| | Introducing Illia & AI-to-Blockchain journey | 01:10 | | Why LLMs took longer than imagined | 03:38 | | Blockchain's synergy with AI (marketplaces, compute) | 04:37 | | AI as new OS, blockchain as backend | 08:54–10:14| | Upgrading systems: consensus & governance | 10:18 | | Blending AI/blockchain with traditional legal/fiat | 15:26 | | Why agents lack utility: security & trust bottlenecks | 19:22 | | How IronClaw secures secrets, protects the user | 22:59–25:55| | Private, confidential AI cloud (user-owned AI) | 29:49–34:55| | The big bottleneck: context windows & memory | 44:25–49:36| | Decentralized agent marketplaces & autonomous agents | 52:54–60:17| | The accelerationism/humanity debate | 61:42–68:34| | Crypto's reputation in mainstream AI | 70:17 | | Advice for founders & builders | 73:31 |