
Loading summary
A
Are all batteries the same? That's like asking if all soccer players are the same. Take Messi, the most decorated player ever. Is there any other player who has achieved that? No, just him. Now take Duracell. Is there any other battery with powerboost ingredients inside? No, just Duracell. Remember, goats only trust goats because they're built different. And Messi only trusts Duracell.
B
This episode is brought to you by Google Chrome. You think you know a browser, but Gemini and Chrome? That's new. It can help you with practically anything on the web, like restoring a vintage motorcycle from a 50 page restoration block. Or finally break down that long article you've had open for weeks. Gemini and Chrome is here for it, ready to make anything online make sense. There's no place like Chrome. Check responses set up required compatibility and availability. Veras 18. Welcome to Coruscant Technologies, home of the Digital Executive Podcast. Do you work in emerging tech? Working on something innovative? Maybe an entrepreneur? Apply to be a guest at www.corazon.com brand welcome to the Digital Executive. Today's guest is Mitchell Amador. Mitchell Amador is the founder and CEO of Immunify, the leading bug bounty and security devices platform of the on chain economy. Working at the front lines of Web3 Security, he has directly helped prevent over 38.5 billion in hacks and thefts across the ecosystem. Through Immunify's growth, he has helped protect many of the ecosystem's most critical protocols including MakerDAO, Optimism, Filecoin, Layer 0, Chainlink, Arbitrum, Lido and Polygon. Mitchell has led and participated in dozens of live on chain incident response war rooms, stopping exploits in real time and negotiating the return of millions in stolen funds from international black cat actors. Well, good afternoon Mitchell. Welcome to the show.
A
Thank you. It's great to be here.
B
Absolutely, my friend. I appreciate you doing this. You're in Portugal, I'm in Kansas City, the United States and and several time zones and calendars to get here and I just immensely appreciate you for making the time. And Mitchell, if you don't mind, I'm going to jump right into your first question here. You founded Immunify in December of 2020 and helped scale bug bounties from an experimental practice into a core security standard for all web3 building what's now the largest blockchain security community with with over 45,000 researchers and more than 25 billion in user funds protected, what did you see early on that convinced you? Incentive aligned crowdsource security could work where traditional cybersecurity models had failed.
A
Sure. Well, I, I think it was being native to the industry and understanding how rapidly things spread in crypto was key to that insight. And specifically I came to two conclusions. Number one, the proliferation, the success of defi, which happened very quickly all of a sudden, as things do in crypto, meant that we had sudden gaping security holes that scammers and attackers and a whole host of negative actors would coalesce around very, very rapidly. A key and essential quality of crypto is how quickly things diffuse, how quickly information travels throughout the whole network in this process of viral diffusion. This applies to good things like realizing all of a sudden that things like defi and on chain finance are really, really useful and have unique value propositions you just can't find anywhere else. But it also applies negatively in the sense that when people realize that there is an opportunity to steal money, it quickly diffuses through the criminal side of that same network. And that's what we saw. And so in seeing that, knowing that having, having had a front row seat to the consequences of that in 2017, during that initial market run, that really led to some great things, but also to a lot of damage to a lot of people, I realized that the only way we could possibly keep up to that was if we corralled the global security community in the same way, knowing that the security community will outnumber the criminals and the attackers many times to one. So it was less of a total certainty that this would work. It was more of a absolute conviction that this is the only thing that can work right now. We simply do not have time before the realization that hackers and thieves can earn life changing money here by attacking the systems before that. That uses through the on chain society. We need to bring the security to bear and protect as much as we can. There was this necessity that Jeffrey's insight, that's awesome.
B
And absolutely you saw first off, you had experience in the DEFI space here, but that security gap was definitely a necessity and we saw that. I've been in this space as well for quite a number of years. Love this space, this, this space here. Blockchain Web3 and crypto did scale quickly. We saw a lot of things come and go and, and part of it was with this scaling of these different platforms and currencies. We saw a lot of fraud that went on and security is obviously paramount now. And I appreciate what you're doing to secure this market. Mitchell, you've argued that security has to move from static to continuous real time threat monitoring and tooling that keeps pace with evolving risk and that the industry needs to treat security as infrastructure, not insurance. What's the practical difference between those two mindsets and what changes inside an organization when it makes that shift? Sure.
A
Okay, there's a few things here. Number one, we've gotten to the point where these systems have so much money and are so mature, there are many multibillion dollar protocols at this point that you need to understand. There are attackers who are perusing your infrastructure 247 trying to find ways to rob. Now, the North Koreans with Lazarus Group are of course the most famous of these attackers, but there's a great many others. Criminality is an inclusive and open society. So there's lots of people who are snooping at your cell at this stage now to deal with that. The only way you can do that is you just shift from a, oh, hey, we have a anti crime problem, an anti petty theft problem to hold on. We're in a never ending war against some of the most well funded hacker groups in history of the world, typically backed by nation states. And the consequence of that, the essential consequence is you need to be thinking on the frontier, on the frontier of competitive advantage and protection all the time if you want to stay safe enough. Okay, you are now so many, like so many other countries in the world that need to be investing in R and D and staying on the cutting edge of whatever you can do to stay safe. Now, given that that's where real time protection comes in and it's less of a, hey, let's go and use these products, let's go and use these tools. It's more of a mindset. How do we constantly stay on the edge of security given that we're in the most adversarial and hostile and dangerous environment in the entire Internet. And out of that comes, hey, maybe we should be investing real time, truly, hey, maybe we should be investing more in bug bounties and similar types of crowdsourced tools, which are the most effective way to access the latest and the greatest in security knowledge. You know, how, hey, maybe we should be trying out new technologies and new techniques like firewalling. Otherwise, like, it doesn't really matter what the specific tool is. What matters is are you on the frontier? Because your attackers, they certainly are. And if they get the equivalent of a nuclear cybersecurity weapon before you do, you're dead. So this is the first part of that question. Now, the second part of that was on the distinction between is security infrastructure or is security insurance? And the reality is these, these two things are going to converge in crypto over time, but that convergence is going to take at least another five to 10 years. And the reason is because insurance provides a financial backstop or protecting against risk in the most general possible way by saying, hey, we can just afford to bear the cross or whatever it is. But it can only do that when it has effectively price risk. And that means knowing really, really well the nature of the type of risk you face and the kind of damages that could be inflicted. And we are not there. We are not there. We are a long way from it. We've been tracking every kind of hack and every kind of critical disclosure event that happens in the industry. Over 93% of all critical disclosures in crypto in the last six years or so have gone through immunify. For context, we have a really comprehensive data set on this. And while we can tell you what the average hack is likely to be and what the median hack is likely to be, and what's the probability impact in any given year, there is a huge variance, there's a really long tail. And that creates a power law effect in terms of impact that makes the risk quite difficult to price at this stage. Okay. And in consequence, we cannot think of security as insurance. It cannot be so predictive and it cannot be so wide ranging in coverage. What we can do is think of it as security, as infrastructure. We can think of it as the walls right around your town. We can think of it as the moat around your castle that while not foolproof, right, while, while possible to defeat, and you know that perfectly well, provides an extremely advantageous form of protection that will cover the vast majority of threats that you could possibly and can be done at relatively low cost as well. All things considered, the cost of these security measures is almost nothing compared to the amount of bands they provide. And so this is the attitude that we need to be taking. Number one, we need to have this attitude of like, hey, it's cyber defense, not cyber security. We're at war. We're fighting against nation state actors, not petty criminals for the most part. And number two, we need to be thinking of this as a constant piece of infrastructure that our societies and our economies require to sustain themselves. It's not going to be foolproof. It can't cover all the risks, it can't cover all the costs. But it is impossible to live without it. And the moment we do that, we become a defenseless nation and a in a very, very hostile force.
B
Thank you. Really appreciate that. And there's so much to protect here. You talked about this being a multibillion dollar industry, of course, but there's a never ending war engaging with these professional hacker groups, state sponsored hackers, but we have to shift to a mindset, to an ever vigilant, continuous monitoring security. And you did kind of talk about the infrastructure versus insurance. What is that really? And we know those will converge in the future, but right now, again, there's a whole lot of things that need to fall into place before we can move in that direction. So I appreciate the insights. Mitchell, you've warned that generative AI, including the latest Frontier models, has become the main driver behind the increased frequency and sophistication of DEFI exploits with hackers using AI to rapidly scan code bases and craft exploit payloads. You've called the next three to four years at critical test, with the asymmetry favoring attackers until defenders deploy the same AI for defense. How is Immunify arming defenders for that fight? And who's winning right now?
A
Sure. Well, right now I would say that the attackers are winning, okay? And you can see that in the increase in the frequency of hacks that happen in crypto. You can also see that in the mass proliferation, new vulnerabilities, hacking and cyber attacks that are happening in the broader economy. So that's the reality. Attackers are moving fast. They're leveraging this latest and greatest tool from the Frontier and they're using integrated. Now we recognize that it is extremely difficult for defenders to keep up with attackers in this way. The reason being every change to their security posture and their tooling requires a complicated and risk sensitive decision making process and governance process, for lack of a better term. All these tools cost money. All these changes require people. All these things change your internal corporate or governmental policies. There's no easy way to do these things, Brian. They need to be done step by step with proper security control so that you don't make a misconfiguration or you don't step over your own foot in such a way that makes the attempt to implement the cure to this problem even worse than the disease by introducing new vulnerabilities. And because of that, the attackers always have the edge, they're always moving faster. But there is a flip side that we can take to this whole situation. We can flip the coin and say, hey, well, why don't we just leverage the same fundamental advantages that attackers have for defenders instead? And we have the perfect tool to do this in the form of the bug bounty program. And so what we're doing at Immunify, we already have Thousands and thousands of security researchers around the world, almost all of these guys are running their own AI stacks, they're effectively their own independent red teams. Now we can no longer get just like, hey, a hundred eyes on code. It's like we can get a thousand eyes on every piece of newly deployed code that comes to immunify more defense in depth than we've ever seen before. And what we're doing is making it as effortless as we can possibly do to give them the latest and greatest in frontier models and in vulnerability finding technology. Because this way we're going to turn our army of white hat hackers who are been defending society for years, into a force that can move even faster and leverage the existing security tooling that most major companies and protocols have to keep them safe even better. And moreover, we accelerate that because we're getting them access, we're getting our white hat to access the customer code faster and earlier than attackers get it so that every single cut piece of code that hits the Internet in crypto has had effectively the review of a thousand different eyeballs from 100 different AI systems, from hundreds of security researchers around the world before an attacker even has the opportunity to see it. And we believe if we can do that, if we can do that well then we could prevent something in the realm of 95, I would say, yeah, probably 95% of all of these attacks that are presently plaguing the Internet as a whole.
B
Thank you. Appreciate that. As you mentioned, currently the attackers are winning in these attacks and exploits and especially if they're using AI just again makes that whole entry point for the bad guys to enter with AI. Of course, we talk about that here a lot. Defending is constant, proactive work. It can be daunting, as you talked about, but your premise is to provide safety, insecurity and security in a fast and simpler way. Your goal is to find vulnerabilities before the hackers do. And I just like that mindset that you have is to make people feel safe knowing that they've got a good partner like you and immunify to help them thwart these attacks. So I appreciate that. And Mitchell, the last question of the day I have for you. You've cautioned that the next systematic failures will come from a shared assumptions failing everywhere at once. Shared code, shared signers, shared infrastructure, shared ops, oracles, the invisible dependencies that break next as crypto scales into mainstream finance. What does on chain security need to look like five years from now to be genuinely fit as critical market infrastructure? And what has to happen for the industry to get there before those shared dependencies fail.
A
Sure. Okay, this is a multifaceted question. Number one, these shared dependencies that are such a risk, the reality is crypto and the Internet as a whole has tons of shared dependencies. And for a lot of cases, nobody's particularly responsible for these shared dependencies. There's no grand organization with infinite budget and a big security team that is maintaining a lot of these open source repositories or tools. It's just something that everybody uses and that creates problems because you can have players who have multiple. Basically this dependency lives in their security perimeter, but they feel like, hey, well it's not mine. Do I really need to be the one to maintain this? And when everybody thinks that way, those systems get compromised. So there are a number of cases, for example, compromising wallets, where they would depend on an open source cryptography library and an attacker being clever would not go after the wallet itself, but would instead go after the cryptography library compromise that because it was being maintained by some unloved volunteer, take it over, and then introduce very subtle vulnerabilities that they could compromise downstream in order to affect the wallets as upstream or downstream users rather. So there are lots of cases like that that have happened. Bridge hacks are a great example of this. And there have been some cases recently, such as the calpdao hack, that suggest that even further. And we need to solve this as a whole. We've figured out so many of the problems in on chain security, but what we need is to now solve the last set of ecosystem wide problems, the same problems that countries and international unions have solved for safeguarding their local economies by creating the conditions right and maintaining the conditions, the public good, so to speak, that all commerce and all economic growth depend on. And we need to do the same thing with crypto. That means taking care of these dependencies, among many other things. So that's number one, I would say, on the list. And what was the second part of that question? Just refresh me, Brian.
B
Yeah. What has to happen for the industry to get there before these shared dependencies fail?
A
Great question. Two things. Number one, we as ecosystem managers, we need to have this attitude of stewards. We need to do this either at the level of layer one blockchains, either at the level of bridges and cross chain communities and products, or we need to do this at the level of financial players and the stakes that govern. And you see various forms of that going on today. You have players like Ethereum who try to manage Their own ecosystem, their own kind of thriving and open garden. You have financial players like USDC and COINBASE that are pushing your point of view. And then you finally have national players like the United States government which is trying to push, put its point of view in the form of US stablecoins around the world or Europe with its MICA propositions. So you have various attempts to, to safeguard that situation like so. Now all of this has to happen before, I would say two things before we have many, many more trillions of dollars and I think we should be going expecting a world where we're going to have 10 or 20 trillion dollars on chain over the next year, four or five years. We need to solve these kind of ecosystem wide coordination problems by then and then. Now we have another threat that's kind of gone in parallel which is the rise of frontier models and their application to cyber security and specifically finding vulnerabilities. And we need to build defensive tooling in conjunction with this kind of social technology, so to speak. We need defensive tooling that is advanced enough and well distributed enough across the ecosystem such that even if frontier models continue to advance the crazy pace they are, we believe we can create ultra secure code which eventually becomes truly an objectively secure code with no effective vulnerability. That's the second factor. Both of these things are not done today. There are many different players who are making both of these moves today. I believe with, with conviction that we will solve both of these problems within two to three years, quite frankly. But it is unclear which design philosophy, which kind of opinionated worldview for each of these categories is going to be the one to do it. But if any of them succeed anywhere, then it's game over. And now crypto is clear to scale to countless tens of trillions in wealth on chain for society demand.
B
Thank you. Appreciate that. Obviously in this crypto defi space there's a lot of shared dependencies you talked about, which most folks that are in this space, they think it's not their responsibility. And you talked about an example, bridge hacks. We need to change that mindset as you mentioned, creating conditions for prosperity and security like we do in the tradfi space in local economies. We all need to have that attitude of being good financial stewards. No matter if you're running at layer one blockchain or bridge etc. I really do appreciate that at the end of the day mindset has to be community wide and you're leading the charge there. So I appreciate that. Mitchell, it was such a pleasure having you on today and I look forward to speaking with you real soon.
A
Awesome. Thank you very much, Brian. It was a pleasure to be here.
B
Bye for now.
Guest: Mitchell Amador, Founder & CEO of Immunify
Host: Coruzant Technologies
Date: July 9, 2026
Duration: ~20 minutes
This episode dives into the urgent and evolving landscape of Web3 security with Mitchell Amador, founder and CEO of Immunify. Amador shares his frontline insights combating hacks and exploits in decentralized finance (DeFi), the rise of AI-driven cyber threats, and the critical need for the crypto industry to shift from static defenses to real-time, infrastructure-level security. The conversation highlights lessons from past attacks, the challenges ahead as crypto scales, and calls for a new mindset: treating security as a continuous, community-wide responsibility essential for mainstream adoption.
(02:10 – 04:58)
"A key and essential quality of crypto is how quickly things diffuse, how quickly information travels... when people realize that there is an opportunity to steal money, it quickly diffuses through the criminal side of that same network." — Mitchell Amador [03:35]
(05:54 – 10:45)
"We're in a never-ending war against some of the most well-funded hacker groups in history... typically backed by nation states." — Mitchell Amador [06:23]
"We need to have this attitude of... cyber defense, not cyber security. We're at war." — Mitchell Amador [09:30]
(11:51 – 15:04)
"Every single piece of code that hits the Internet in crypto has had effectively the review of a thousand different eyeballs from 100 different AI systems... before an attacker even has the opportunity to see it." — Mitchell Amador [14:23]
(16:23 – 20:58)
"For a lot of cases, nobody's particularly responsible for these shared dependencies. There's no grand organization... maintaining a lot of these open source repositories." — Mitchell Amador [16:40]
"We need to solve these kind of ecosystem-wide coordination problems by then." — Mitchell Amador [19:00]
Mitchell Amador shares an urgent, battle-hardened take on the evolving threats to Web3 and the DeFi ecosystem, outlining why traditional cybersecurity models fell short and how Immunify’s crowdsourced, AI-enabled approach aims to tip the balance back to defenders. He advocates for a mindset shift—treating security as essential, ever-evolving infrastructure and "warfare"—and calls for industry-wide, proactive stewardship of shared dependencies. Amador ends with optimism, believing that with continued innovation and ecosystem coordination, the next few years could usher in a truly secure on-chain economy, ready to scale into mainstream, critical financial infrastructure.