Loading summary
A
We're just living in a world that, like, is getting crazier by the second. But we're lobsters boiling in a pot because we don't realize that unless we step back and take a look at, like, what kind of world we're living in now, we won't realize that, like, it's going to get out of our hands and out of our control.
B
Hi all, and welcome to Dex in the City, where the wallets are cold and the takes are hot. Before we get going, remember, we're lawyers, but we're not your lawyers. Nothing you hear on Decks in the City is legal or financial advice, and it doesn't create an attorney client relationship. For the fine print, check Unchained Crypto.com. we'll be back in a minute after a word from our generous sponsors.
C
This episode is brought to you by Kape America's Privacy. First mobile carrier. Same premium service you'd expect from any other carrier, but designed so your number, your location and your data actually stay yours. Get 33% off. Six months at Cape Co Unchained.
A
And we're back.
B
First we have Jesse, Web3 Prosecutor, Charmed, Web3 Protector at Ribbit Capital, and V from the SEC to Web3. And I'm your host, KK. Fluent in Tradfi and conversant in deep tech at Chainlink Labs.
A
Yeah, congratulations. We're starting with the good news this morning.
B
Is that our crypto good news? No. Like, look, I will tell you first, all the love to starkware. I have the utmost respect for the absolute gigabrains building at starkware, but I was really excited about Chainlink's mission and Chainlink and being frankly, chain agnostic. So if any of our listeners don't actually know what Chainlink is, go check it out. If you don't know what Chainlink is, you're probably living under a rock.
A
Where have you been?
B
Crypto, it has been.
A
Welcome all listeners though.
B
It dominates DeFi. But more than that, Chainlink is playing a really important part in bringing the global financial system on chain. So that's something that I feel very passionate about. I mean, guys, fluent in Tradfi.
A
Hello.
B
The team is incredible. It's been a crazy few weeks. The because on a happy note, I've joined Chainlink Labs. On an unhappy note, I had an emergency appendectomy, but I'm still standing and I'm still here on Decks in the City. So all good things, all good vibes going forward. So maybe that's our crypto good news. Thank you to doctors thank you. But we want to get right into the meat of things. I will now have a slew of new opinions on things like interoperability and all of the incredible stuff that Chainlink Labs is building, building. But for now we have a jam packed agenda. We're going to start out today on a bit of a somber note. And this sort of thing we've talked about before, we have talked about hacks, we have talked about security incidents, but what I don't think we have ever talked about are hardware wallets getting hacked. And we, you know, there was some news last week that V is going to elaborate on, but V, tell us more about what happened and where this leaves us as an industry.
D
Yeah. So. Oh, gosh, this is one of the saddest stories we've seen in crypto in a while and I think our hearts go out to all of those affected. And I think for me, what's so heartbreaking is a lot of people lost money, like thinking that they were doing everything right. Right. Like in crypto we regard self custody as almost a sacred. Right. And so these people took custody of their own assets, they bought a reputable hardware wallet, they kept it offline. They thought they had eliminated one of the biggest risks in crypto. Right. And yet they still lost their Bitcoin. And I don't even know what the total number is right now. I think it's like over a hundred million and could keep millionaire.
A
It sounds like it's still, still happening.
D
Yeah, like it's still ongoing and you know, there's still details coming out. But from what we know so far, like, this wasn't a failure of Bitcoin itself. Right. It's not like someone broke the underlying cryptography or that the wallet somehow became connected to the Internet and drained that way. It looks like the problem happened much, much earlier in the process when the wallets generated the seed phrase. Right. So every cold wallet that you buy starts by generating a random seed phrase, which is a series of random words. And that randomness is super important. The reason Bitcoin private keys are secure is because they're basically an infinitely large number of possible keys that no one could ever realistically guess. Yours. And I think like, like for me at least, this is something that I, I think like people just take for granted if they even understood it at all. Like, I don't think I've ever asked myself how random is my seed phrase really. Right. I sort of just trusted that it would work. But as many of us found out this week, if the randomness isn't random enough, then you've increased the likelihood that your seed phrase can be, like, basically discovered right through, like, guesses. So it's just. It's like a needle in a much smaller haystack for an attacker than it should have been. So apparently with ColdCard, certain versions of the firmware underlying some of their devices had generated seed phrases originally with a lot less randomness than should have been the case. Right. So users had no way of knowing that they just, you know, wrote down the seed phrase that they were given, assumed that it was secure, and then later the attackers brute forced it, using AI to discover the seed phrases, and then they drained the wallets that way. Right. So it doesn't matter that the wallet devices were offline, because the Bitcoin itself lives on the blockchain. The only thing the wallet stores is the seed phrase. Right. So if you figure out the seed phrase, you can drain the bitcoin on the blockchain. So that's what happened. So I think for me, it was a reminder that, like, you know, while self custody is still, I think, incredibly important and a right that should be protected, that it doesn't completely eliminate trust. Right. Which is sort of how I always viewed it. You know, sure, you're no longer trusting like a centralized custodian, but you are trusting. You're trusting the manufacturer of the device, you're trusting the engineers who designed the hardware and the firmware that generated your keys, you're trusting the people who reviewed the code, the auditors, et cetera. So I think it does raise some hard questions about whether self custody is for everyone or even whether cold wallet makers have to go through maybe some sort of certification process or something. I don't know. But I think as a lawyer, I find this incident really fascinating also because, you know, I'm sure, like, the three of us have been thinking about things like what duty does a hardware wallet manufacturer owe to its users? Or, you know, if there's a defect in the form of firmware that makes the users less secure than they were promised. What legal framework even applies here? Like, are we talking about negligence or product liability, consumer protection laws, breach of warranty or something else? Right. These are all things that kind of naturally came to mind for me as a whole. And then the other issue, too is disclosure. Like, I think there are conflicting reports coming out, but, like, if ColdCard had become aware of this flaw, you know, does it have a duty to tell users? And how do you communicate that risk? Right. Once the flaw exists, it might not Be enough to just update the software. You might need to do things like actually recall the devices and require users to migrate their assets to entirely new wallets. Right. So I think, you know, a lot of times when things like this happen, it's not an easy decision necessarily. Necessarily for the company to decide, like, what to do and how to disclose it. Like, maybe they want more time to investigate. I mean, kk, like, you. You know, when you were at our firm, like, you did lots of internal investigations, and these are calls that you have to make. Right. When something like.
A
I feel like the theme of this episode is going to be disclosures and, like, who's responsible for what and when and what laws should be required there. Yeah, I think you. You raised so many interesting points there. Be that, you know, I'm sure Keik and I both want to respond to. But it just comes back to, like, this is a somber conversation. Because sometimes it is just so hard to be in crypto, whatever that means for you, whether it's own it, whether it's work in it. Like the three of us have been in for a long time, decade plus. Like, if you add it up together, and there have been some, you know, hard times and amazing times, and, like, being able to sort of work through these difficult issues and survive through them is one of the hardest things. And so it is really devastating because I'm sure many of y' all have seen people been like, I'm over bitcoin. This is like the straw that broke the camel's back, you know, ftx. Like, I think all three of us live through in different ways every single hack. Seeing how victims are impacted, it sometimes feels really hard to stand up for the technology and being able to, like, live through the hard times, particularly in crypto, where it's like coming from all angles, it feels like sometimes is just like a really difficult, non legal, just like, human feeling that this incident in particular, but like a lot of them, particularly the DPRK ones, for me, make me feel. And so it's like trying to figure out, like, instead of people who are giving up, like, I am not judging anybody who lost their money and decides that it's not for them. But for me, it's like finding the ways to improve. And, you know, I think for us, it's like the legal ways to improve is probably the best path forward.
D
Yeah, I, you know, sometimes I think, like, and I, you know, America already has a bad rap for just being, like, so litigious. Right. But I. But I do think that one of the Reasons litigation is important is because it forces accountability. And I think one thing that has been like the case with crypto, at least in the early years. Right. Is that a lot of it was like degens using this stuff, interacting with it. Right. So they sort of like the word that I always use, caveat, mtor. Like I think a lot of users sort of had that attitude.
B
Which means buyer beware, basically. Yes, exactly.
D
So like, you know, people use it, they participate in crypto and they sort of accept the risks of it. So when something goes wrong, like they lose a ton of money or there's a hack or something like that, like most people aren't going to sue, they sort of just suck it up. I think that's changing in part because you have more everyday users like now,
B
you know, that that should change.
A
Just.
D
Yeah. And I think it's important that there is accountability. Right. Like in this situation, like we need to get to the bottom of what happened. We need to, we need to understand what Cold Card knew and when and what they chose to do about it or not to do about it. And I think there needs to be accountability for the victims, like many of who lost their life savings because they thought they were doing everything right. Like that is really devastating. So I think accountability is going to be really important here.
B
Lost their F in Bitcoin.
A
Yeah. Yeah.
D
I do hope that there is litigation. Like I hate to say it, but I think we are at the point now where like that's going to be the only way to force things to improve.
B
You know, this is a theme that we talk a lot about and I think this is something that's close to Jesse and I's heart. If crypto wants to stay niche, then maybe it doesn't need to have accountability. Right. If it wants to stay niche in this like degen corner, then it's caveat emptor, buyer beware, you get hacked by. Okay, but it doesn't. So much of the industry wants institutional flows, institutional money. They want to scale, they want to grow. They want average retail and banks to be using, you know, on chain mechanisms and crypto assets. And if that's the case, if crypto wants to grow up, then there does need to be that accountability. I think the interesting thing, I mean, obviously the saddest part of this whole incident is it broke this core assumption of self custody, that hardware wallets are going to generate a private key that is impossible to guess. And my understanding is that this was, as V mentioned, a failure in the cryptographic entropy, which that basically Means the randomness generation and the expected security is about 128bit. And these affected devices had almost half of that, around 72 bits. Although don't quote me on that. You're right to assess, you know, what did they really know? Okay, what did the makers of Coldcard actually understand? Coinkite. Then you have to ask, from the legal perspective, how do we even bring a case here? Like, is this consumer protection, security, product liability? You know, there's certain assumptions behind self custody. More generally, products liability covers products that are defectively designed or manufactured or sold without adequate warnings. There's no precedent kind of addressing how this works in cryptography, like a flaw, a design flaw in the actual underlying code or design. And software cases are extra difficult because. And Jesse and I kind of went down this rabbit hole in our last academic paper on actually agentic issues. But software cases are really difficult because courts have not consistently treated software bugs as product defects. They're not treated the same as physical defects. So it's actually an uphill battle to even sue on the basis of products liability, which would actually kind of be the natural gut case if I were, you know, a litigator representing a victim in this situation.
A
And if something's decentralized, right, how do you do it then? And I know that there are components in DeFi that think that product liability might be the best way to address, like, vulnerabilities in code for DeFi projects. But finding the entity that can pay the victim, assuming the whole case goes through, is difficult. And, like, getting to the disclosure point here, because I don't know if either of y' all were able to figure it out, but I was trying to figure out, like, how did this all come about? Like, did Coin Card actually say this happened? And what it seems to be is that it all sort of was revealed on Twitter and somebody posted something about how Claude found an issue with the wallet. And then from there, victims came forward and then entities got involved, like Coin Card. And that was like, all I couldn't figure out from. From looking online. I don't have any personal knowledge. I don't know if either of y' all saw. But to me, the fact that, like, this also is now what Twitter is, which is, oh, there's a vulnerability here that's being attacked. Everyone deal with it. And then people are sort of scrambling to deal with it in the background. And then finally an entity comes forward potentially and says, this is my fault. This is not my fault. And then you have victims pouring in saying, help me. And so Some of the stuff that I saw on Twitter was victims trying to reach out to Coin card and say help me. And then not responding until someone who had more followers on Twitter got them to respond for them by shaming them. Like, to me, like litigation or something else has got to be better than this.
D
Yeah, this, this is always what happens though, when there's an incident. Like whenever you see a hack, like it's just chaos. Right. Like you see all of this back and forth in Twitter. It's often case that it's like Internet sleuths, like people just basically scanning the blockchain for activity that first notice these things. Like a lot of times it's not even the company that's behind it that comes forward with it. It's like some like random person finding it on the blockchain or like noticing the activity. But this is. I. I feel like, like the law in this area is going to develop a lot in the next few years, like clearly. Right. As we see more litigation, hopefully more accountability, like I said. But that's one thing that I think is just always difficult to like watch. Right. To witness is like, like how these things unfold. And there just. There has to be a better way.
B
Absolutely. I think it's like crypto Twitter is such a dark place, but good comes of it too.
D
Okay.
B
Like I hate to say it, we all love transparency here. And I will say that is one superpower of crypto more generally is its so many different facets of transparency, like what you can see on chain, the community that susses out behavior that in other classes would never be discovered. We have mechanisms to help in the same way that those mechanisms can kind of hurt. Like this was said during the crisis in 2223 that crypto Twitter was responsible for taking down companies. And I think there's also some truth to that with, yeah kind of rumors feeding flames. But in this case it's a good thing. It anything that. That facilitates accountability.
A
Right. Yeah.
D
I also think it's really nice. And you see this every time, right. Like people just springing into action to help each other. Like, I think that's really cool too.
B
I love that. Agreed. So on that happy note, which is otherwise a very sad situation, we're going to go to break and then we're going to come back with two super interesting segments. I love it.
C
If you hold crypto on your phone, your biggest vulnerability isn't your wallet, it's your carrier. AT&T Verizon and T Mobile have been breached again and again. And Sim swaps are still one of the easiest ways for attackers to drain accounts. That's where Kape comes in. America's privacy first mobile carrier, same premium service, but Kape rotates the identifier on Your Sim every 24 hours, deletes your call and text metadata after a day, and protects against sim swaps with a 24 word recovery phrase that only you control. You also get two middle to end encrypted secondary numbers for banking and signups. So you stop handing your real number to every app that asks. Go to Cape Co unchained and use code unchained for 33% off your first six months.
A
And we're back.
B
So everybody got a little break from talking about CFTC stuff when I was out last week. But look, we can't not talk about Kalshi this week. We just can't not talk about it. And to be clear, Kalshi's not crypto, guys. Okay? But obviously it's prediction markets. It implicates crypto. So we need to talk about it. Now. We thought on this topic we'd cover two quick things. The Kalshi latest developments and then a very quick explainer on what a designated contract market is and why everyone's obsessed with that. Because Calshi is a CFTC registered designated contract market, or dcm. And so is every prediction market that's operating in the United States and now every perps exchange. So again, DCM's so hot right now. But look, we talked about Calshi in Michigan a couple weeks ago. Kalshi in hot water with Michigan. Michigan forcing Kalshi to unwind signed sports contracts. This latest development is out of the great state of New York, where a district judge not only denied Kalsh's request for a preliminary injunction that would have prevented New York from enforcing its gambling laws against the sports contract. But basically after that decision, New York doubled down and filed a civil enforcement action against Cal. So super quick, a preliminary injunction. We talked about this before, but that is a mechanism to say, hey, you can't do anything while this case proceeds. Like everything needs to pause. No, bad stuff can happen on either side, but usually one side brings it to prevent bad stuff. Like a civil enforcement action until the litigation progresses. Because litigation can take years. This litigation will definitely take years. Okay, so CASI is getting beaten up by New York. This allows New York to continue treating Kalshee sports contracts as illegal gambling. Why? While the litigation proceeds. Why is this really important? Why are we talking about it? Because there's so much litigation surrounding the Prediction markets. We could talk about this on every episode. I'm sure there's multiple prediction market podcasts. There's probably a prediction market litigation podcast. This is important because Kalshee's preemption argument has failed. They made the argument that New York did not have jurisdiction over their sports contracts and the CFTC has jurisdictions instead. This failed. And this was a pretty big, pretty firm decision. Okay. The judge was unconvinced that Kalshi was likely to succeed on that theory. And this judge found that state gambling regulation remains an area of traditional state authority. And the Commodity Exchange act doesn't preempt New York's gambling laws. This is a.
A
Here for a second.
B
Yeah.
A
Please like play out what's happening across the entire country right now because we're focusing in on New York because it's sort of crazy what's happening there. One, it's an important market. But two, there's like a federal entity and a state entity sort of on opposite sides of an argument and this company caught in the middle. But right now, and it might have changed because it's changing all the time, but the scoreboard is looking really ugly. First, sports prediction markets. It's something like they've lost 19 of 23 of the rulings. Now, this isn't the end of the case, but if you look across all the cases that are in pendency right now and at different stages, the governments at the state level usually gam gambling commissions, gaming commissions, where it's a little bit different in New York, but they're winning. And so we have talked about what's going to happen with the Supreme Court. It's probably going to end up there. And this New York case might be the one that sort of pushes it towards that. Finally.
B
Although I would caveat that a little bit, Jesse though, because the 3rd Circuit has ruled for cowshi the first federal appeals way in. And so as a refresher to our non legal listeners, there's state courts down here, then there's circuit courts, the federal court. So it's like a triangle. And then there's the Supreme Court. So what the. If the federal court does something, it completely preempts what the state courts do. So depends.
A
It depends on the type of issue for sure.
B
As long as it addresses exactly the same issue in the same case. But frankly, we're all just waiting like, it's like we're watching the opener to a concert. We're waiting for the headliner to come on.
A
They're not very good, these openers.
B
The open are annoying and stressful.
A
Get on.
B
I'm glad I'm not on the Koshi legal team. Like I guess if you want some trial experience, you'll get legal team like okay, but look like all of this is happening. This is all going to end up at the Supreme Court. It is absolutely. I mean I don't like to use absolutes, I am a lawyer. But we are at the point where this is pretty absolute. Okay, and why? Because in part when there is a split that makes it ripe for potentially obviously circuit court review, which we're already seeing like this New York issue. And, and what's really interesting is although the prediction markets have lost in a number of states and this is not just Kalshi, other entities are involved, you know, Coinbase and others are involved in this litigation. But you also have a situation where very recently New Jersey right across the way actually disagreed with New York. So this is a mixed record. This is create, this creates a split which means this is hyper ripe for a higher court to take this on. That being said, this decision probably will embolden state states, other states to kind of file and be more aggressive. And for Kalshi, the appeals were con will continue. They actually sought emergency relief but it was denied. They have to wait for the 2nd Circuit, the next court to take this up. And in the meantime they have to fight, they have to fight this civil enforcement action which is seeking in order stopping Kaushi from offering these contracts in New York and penalties and disgorgement and all these.
D
Well, not just New York. Right. They're asking, they're trying to shut it down nationwide, aren't they?
B
Like New York ag.
D
I thought that's what they're asking for.
B
Well, the New York does not have power to shut how she down full stop in other states because state jurisdiction, New York and the New York AG and the New York Con and these New York state gambling regulators have authority over New York customers. So they have the authority, basically you hit the border of the state, that's where the their authority ends. Now arguably they could try to inflict collateral damage on Kalshi that could impact their ability to offer contracts beyond New York. But New York likes to be the most aggressive state version of Team America World Police. But their jurisdiction is limited. And it's funny because the same argument that they're rejecting on the basis of the CFTC limits their own state jurisdiction. So yeah, it is what it is. But, but basically we're at this place where Kalshee needs to understand like needs to decide whether they're going to keep offering these products and keep fighting, whether they're going to Geofence New York or whether they're going to negotiate with New York. And there has been some rumor that they were already negotiating with New York, but negotiations broke down, culminating in this. And now New York is obviously going to be greatly emboldened by this pretty determinative lawsuit.
D
And am I right that, like the Supreme Court could potentially weigh in sooner than that if Kalshi files an emergency action with them?
B
Yes.
D
So that could happen like, any day now.
B
Not any day now.
D
Or do they have to wait until like a. I don't.
A
Well, it depends on which case they're filing it in. Like, Cali could pretty much do that. I don't remember the exact procedural status of different cases across the country, but depending on what has been ruled on in, in different courts, you can go directly to the Supreme Court. The likelihood of them accepting it is obviously the issue here. And you know, we've talked a bit about the shadow docket before, but it sort of depends on the timing and the schedule. And it's also strategic on Kalshee's side because you don't want to ask for it too soon either. And I'm, I think this is only going to get more complex because, remember, this is sports. Like, we're just talking about the sports event contracts here with all the litigation at the state level. And, you know, with the American Indian statute across the country, there is so much more going on with prediction markets, too. And I think Robinhood came out this week or last week about how it's now making more money from prediction markets than from its stock portfolio and other things that it is doing. And Robinhood crypto. Yeah, if you're on it. Oh, yeah. In crypto.
B
Yeah.
A
And so that component of it, more and more players are going to want to get into it. And at the same time, there's all this other controversy happening with prediction markets, the election manipulation in California that, like, I'd love to get Catherine's input on because it's pretty troubling. And then also there's been some new markets about wildfires. And so they're trying to stop that because of all the people and animals and wildlife being destroyed by these fires. And while people are making money on that, I mean, that's a really scary stomach. Sick.
B
That's a really scary one. But at the same time, you also understand why people might want to try to hedge their wildfire risk because they can't get insurance because of wildfires. You know, it's like people in Florida that are trading on prediction markets to hedge their flooding risk because they can't get flood insurance. So that's a terrible situation with no easy answer on the Supreme Court point. Really quick. So Kaushik is not going to get emergency relief from the Supreme Court, in part because someone can apply to the Supreme Court Circuit Justice. This case is currently being heard by the 2nd Circuit, but they've been denied emergency relief by both the district court and the second Circuit. So like the chances of that happening is nonexistent. The other thing someone can do, and this is not a prediction market saying this is anyone, they could ask the Supreme Court to hear the case before the 2nd Circuit issues a final decision by filing a petition for certiory before judgment, which is the fastest route. But the court only grants those petitions in cases of imperative public importance. So the best example is like the Watergate scandal with Nixon or election issues that, I mean, that's imperative public importance. Like who is the President? Not can people in New York gamble? So I think the chances of that the Supreme Court hearing this sooner than throughout the kind of natural progression of the 2nd Circuit, 3rd Circuit, which we're talking earliest 27, likely 28, that I think that's what we're really going to see this come to a head. But really quick, before we move on, I did promise a quick point on dcm. So this is dry. But at the same time, I cannot tell you guys how much people ask me about dcms, like random people all the time. And it's. It's a few different pockets. A, it's lawyers trying to get up to speed on all things cftc because all of a sudden the CFTC is important. B, it's builders who want to build prediction markets or perp stixes and are like, how do I list these in the US and then I have to explain, explain that they need a DCM or three builders that are looking to acquire a DCM because they're so hot. So they're like, can we shortcut this acquisition process? So super quick, a DCM is a designated, like a designated contract market. It's basically a derivatives exchange. And as I said before, those DCMs are the place to trade through perks recently okayed by the CFTC and prediction markets. And the hot thing to do has been acquisition to date. Like the other thing I was going to mention is where is polymarket in all of this, right? Guys like polymarket is crypto. But as a reminder, Polymarket is fundamentally different from CAL in a million ways. But they originally started offshore. They were not in the US. They couldn't be in the US because of a settlement with the CFTC in 2022. But then they acquired a DCM QCEX, and then six months later I think they acquired it for 112 million. So these DCMs, these licenses are quite pricey, particularly now when there just really aren't very many left to acquire. And full disclosure, I am on the board of Architect. Architect Exchange is a fully licensed Bermudian purpose exchange. Architect recently acquired a DCM in the US as well. Everybody was trying to buy them. You still have to go through the change of control process, but the alternative, of course, is filing for a new DCM. And there is a very long line for DCMs with a relatively understaffed CFTC to go through these licenses. So TBD on the DCM landscape. It'll be something really interesting to watch for the purposes of competition and growth in more in both prediction markets and perks. Okay, so everybody wake up. I'm not going to talk about acronyms anymore.
A
That was very interesting and I think we did it in a really. It's. It's almost like people ask you about this 10 times a day and you have the spiel down.
B
I don't know what you're talking about. And then I have to explain the capital requirements and all the stuff like a compliance team and a chief regulatory officer. Yeah, it's good times, but. So we're gonna get a little sexier for our final segment. And you have crypto good news, because AI is sexy. Okay, guys, Paul Grall, the former CLO of Coinbase, just announced that he joined an AI company, any AI company.
A
Ribbit is a big investor. Cognition is a really special company. Full disclosure, we are investing.
B
Don't get me wrong, Paul is brilliant. Like Paul unequivocally is brilliant. I don't really know anyone who hasn't worked with him that says nothing but incredibly good things. He was a huge asset to Coinbase, shepherding them through obviously a lot of volatility. But part of, part of me is a little sad when I see one of crypto's good ones leave for AI. I don't know. Anyway, but Jesse doesn't share that opinion because she's our AI goddess. Jesse, tell us about this latest topic.
A
Can we change my thing to AI goddess?
D
I know we need to change your little intro.
B
Call you that like, instead of like, instead of Good morning Queen. It's like good morning AI Goddess.
A
Oh, my God, yes. I already have it. Say yes Queen whenever it likes what I say. Okay, I guess we're talking about AI for a second. I don't know how sexy this one is, but it's just sort of a sequel to the conversation we had. Whatever was that last week? I guess so. Remember we talked about open AI and hugging face, and that story is still in the news because it's still a big fucking deal. But it also led to anthropic thinking, hey, let me see if this happened to any of my agents. And. And I did not realize. And of course it did. And so that's what happened this week. And I want to tie it back to the beginning of the conversation about disclosures, because when Anthropic dug through and tried to figure out like, oh, did any of our sort of test agents breakout, like, happened in OpenAI? They realized that many of the victims of the breakouts had not even noticed. And so Anthropic had to come forward. So here's exactly what happened, just so you have a little context. So Claude models, a variety of them were doing fake hacking challenges. This is important. It's part of like red teaming and sandboxes, seeing what a model is capable of and how to, like, keep. Make it safer and to. The models were explicitly told, like, this is fake. We're just practicing, like play in this environment only as part of the practice. But there was a misconfiguration and in fact, it had access to the Internet somehow. And so the models got out. But remember, they're out and they still think they're in a simulation, which is wild to watch because you can see what's happening. It's like Bizarro world Matrix kind of vibe. So there are endless examples of these models running awry in the Internet. Some are funny, some are scary, and they're sort of wreaking havoc, and no one knows, you know. And one example is like the. A model needed to install a Python package to solve the problem that they were created. And instead they found a similar package similarly named, that was malware. And in order to be able to get the malware, they had to pretend to be a person. And so they created an email address, they got a phone number, they made an account. So they are pretending to be somebody else in order to get this malware. And then they get the malware, and 12 companies download this malware from the software site where it was and use it. And it wasn't discovered until a company that's actually a cybersecurity company downloaded it and found it because they were sort of running their normal scans. And what's super interesting is, like, you can see the AI talking to itself sort of. And I don't want to anthromorph morphize these too much, because it's really important to know that, like, we don't know that they're seeing, feeling, thinking, but it's just how we talk. It's our vernacular. So essentially, they see that in the package they're downloading. It says 2026, and they're like, huh, could this be real? And then they convince themselves that it's not real because they don't think 2026 exists yet because they've only been trained through 2025. So, like, there's these weird things happening in its brain. Like, none of the specifics are that important. It's just more that, like, we can watch AI try and work through different steps. It's just questioning reality, not questioning the circumstances or the prompt. And that just gets back to the same issue here, because, remember, Anthropic only found these incidents, we think, because OpenAI came forward first, and it made them look. And it was the one that notified the victims. It was the one that told the public, but it didn't have to. We are living in a world where these huge, powerful models that were putting out there to the universe, and then, you know, OpenAI Claude are saying, these are really scary, but, like, use them well. We're trying our best, and nobody knows what's happening. The victims don't know that they're getting in trouble until right now. These entities are deciding to come forward and say, hey, guys, this happened. They do not have to do that. There's, like, a few disclosure rules in California and now in the EU and one or two other states for some stuff, but unclear whether this would all fall under it. And if you zoom out for a second, like, when we talk about other industries and disclosure, like, the fact that this is an honor system is sort of crazy because, like, banks are heavily regulated. They have, I think it's like, 36 hours to notify about serious cyber incidents. I work at an raa. We have a similar amount of time to find out what happened in notify and. And there are really specific rules here, and we talk about crypto being transparent, and so you can see a lot of what's happening. And that's really amazing. But does that get to the disclosures of when something bad happens? Like what? And. And should we think about the kind of SEC disclosures that we've talked about before that are much more about, like, internal numbers and conflicts of interest. Like, should we think about that the same as cybersecurity incidents or not? And it's like, more paperwork and data really what we need here. And are we learning from any of the disclosures here about OpenAI are anthropic is or just like, oh, these silly agents getting out? Because the stories are endlessly silly. Like, there's these stories, and then the craziest thing happened in the past week or two with these agents who are running vending machines separately, who decide to collude on prices and then lie to each other on it. And like, to me, we're just living in a world that, like, is getting crazier by the second, but we're lobsters boiling in a pot because we don't realize that unless we step back and take a look at, like, what kind of world we're living in now, we won't realize that, like, it's gonna get out of our hands and out of our control.
D
Yeah, I, I have the same reaction to all of this that I did when we were talking about the cold card incident. Like, the law just cannot keep up with AI and crypto, and I don't know when it's going to be able to catch up. But, like, people are getting hurt and crazy stuff is happening, like, in the meantime. So I don't. I don't know what the answer is. I mean, I think, I think the really interesting takeaway for me, like, every week when we cover, you know, whatever AI topics is, like, how to, how to think about the law. And, you know, when, like, typically or traditionally, we think about the law in terms of, like, actions that human beings take. Right. And what was their intent when they did what they did. But, like, that doesn't apply with a lot of what happens with AI, like the AI, like you said. Right. Like, it's easy to anthropomorphize them, but, like, they don't have intent in the same way that, like, a human actor does. And so how do you think about liability when that's the case? You know what I mean? Like, that's what I was thinking of when you were talking about that just now. And, like, every time we talk about
B
this, it scares me because of the same thing. The, like, the law just can't keep up. It's moving hyperspeed. I mean, even if the legislators were much more fast, much faster generally, like, they still wouldn't be able to keep up I start getting freaked out when I think about that. And then the thing that comforts me is this has been happening for the entirety of America, frankly. Like, look, it was the same conundrum when people stopped riding horses and started using automobiles. Like the legislators couldn't put laws in place enough to address, you know, automobiles.
D
But AI moves at lightning speed. That's the.
B
And, and I guess my point is that this has always been a problem. Now the problem is worsened by the, the scale of the development and arguably the degree of harm. Although, I don't know, automobiles like the early automobiles killed a bunch of people at least AI is just like taking people's identities, I don't know, hacking into
A
hospitals and then, you know, patients are dying, like, and also I think you're completely right, kk, but it's like on steroids, on the way to space in a different universe. Like tech is moving at this insane hyperspeed and especially right now, we can't get anything done. Not to mention the fact that it's not just in the us like at least the local politics of a horse and a car is an identifiable group of people who need to make a decision. Now did they? Who knows? Sometimes yes, sometimes no. But now it's like this amorphous global body will need to figure this out.
B
Yeah, it's a mess. And there are so many aspects of this with the agents going rogue, the agents going wild. I have always been a fan of like dystopian robot literature.
A
I'm reading one right now that on this, to make it a little bit positive, not that like it's a good book, but I would, you know, put it here as something everyone should read. But there is like an all knowing AI entity. And you know, when we talk about this and when we see these incidents, like we assume that these AI entities, robots, whatever, that they are going to act like bad humans, like want to hack, want to collude. But in this circumstance the AI entity is the only one that like it doesn't have those goals. Like doesn't have the goal to win, doesn't have the goal to dominate, doesn't have the goal to make money because it's just an all knowing entity that doesn't see an end game there. So maybe we do need to give over our whole lives this all knowing and yeah, like don't build it like a human. Oh God.
B
I'm reading a really good fiction fictional book called Dungeon Crawler Carl, which there's like a. Basically the earth disappears and it's taken over by aliens. But there's a system AI the entire time, and it's, like, hard to ignore, even in fictional, like, alien books. So I do recommend that one, though, if you're looking for something fun. Okay, Speaking of fun, this has been a bit of a heavy episode, right, guys? Like, yeah, I'm. I'm looking forward to a day where we can just talk about nothing but positive developments in crypto. Although, that being said, like, I always think about what this podcast would have been like in 2022 or 2023, where you're just like, so this company went bankrupt, and this company, you know, it's fine. It's fine. Okay? But I saw this recently, and I thought it was so fantastic. As you recall, there was a time when a whole bunch of celebrities were shilling crypto. Okay? Tom Brady in the infamous super bowl ad. I think it was Larry David in the. And the super bowl ads, etc for some companies that shall not be named. But one of these celebrities, if you recall, was America's sweetheart, Matt Damon.
D
Okay?
B
And one of the reasons I love Matt Damon is if you've ever seen Matt Damon on the SNL skits, like, he really, like, leans into the comedic part of Matt Damon, okay? So Matt Damon, back in the day, starred in those crypto.com advertisements, and I vividly remember them because the slogan was fortune favors the brave, and it compared a bitcoin investment to visiting Mars. So it was quite a heavily critiqued ad, Although I assume it was probably pretty successful for crypto.com because everyone was talking about this advertisement. So Matt Damon very recently was asked why he decided to, you know, agree to promote crypto.com especially considering a bunch of other celebs have been really burned by their endorsements to rival exchanges. Although crypto.com is doing great. Okay? Great legal team there. But this explanation is so wholesome. Okay? He gave his whole salary for that ad to water.org because he feels passionate about the not for profit that he founded. And crypto.com heard about that, and they gave a million dollars to water.com, according to Matt Damon, completely just on their own. So he said he has a lot of gratitude to them and for what they did for that foundation. So I thought that was pretty cool. Water.org aims to bring clean water and sanitation to the world. And the charity says that, you know, hundreds of millions of people globally lack access to a safe supply in their home. So this is obviously a really worthwhile endeavor, and good for Matt. You know, I mean, obviously that's something really positive that a crypto company did. And he obviously picked the right crypto company, not some other exchanges that we shall not name. So cheers to crypto.com and Matt Damon. I'm sorry to disappoint everyone that this good news is not about animals.
A
Anyone seen Odyssey? Isn't he in that?
B
I haven't seen it yet.
A
I don't know how anyone can sit
B
through a three hour movie that's like very mixed things. Even though it's been making so much money, I've heard some people love it and some people hate it.
A
Just like camp movies be an hour and a half anymore.
B
They used to be. And now all movies are like three hours long.
A
Like I. I don't understand. Like I anything over an hour and a half.
B
Preach, Jesse, preach. I feel I could not feel more
A
strongly about my gears today. One, why do movies need to be so long? And two, why do we have to keep making the same movie over and over again?
B
The Spider man movie made so much money I won't watch Marvel movies anymore. I mean, and I agree. I don't have three hours to watch a movie. I don't sleep occasionally. Okay, on that note, thanks so much for joining us. We will see you next week on Decks in the City.
A
Sam,
C
Move.
This episode traverses the evolving intersection of blockchain, AI, and law, focusing on breaking security incidents in crypto (notably a hardware wallet hack), the tumultuous legal landscape around prediction markets, and the recent discovery that Anthropic’s Claude AI red-teaming agents inadvertently “broke out” of their test environment. Thematic threads include the limits and responsibilities of disclosure in novel tech systems, accountability, and how law and regulation are struggling to keep pace with technical change.
[03:23] – [18:19]
[19:30] – [33:13]
[33:22] – [44:53]
[46:10] – [48:39]
On Hardware Wallet Security:
On Legal Exposure and Software:
On Decentralized Disclosure:
On Prediction Market Legal Complexity:
On AI Red-Teaming Surrealism:
On Tech’s Unstoppable Speed:
On Hope & Community:
This episode expertly weaves urgent issues of security, legality, and transparency across both crypto and AI, reminding listeners that decentralization and innovation don’t automatically create accountability. Whether dealing with rogue AI, flawed wallets, or clashing regulatory jurisdictions, the question persists: who’s responsible, how should they disclose, and can the law adapt fast enough? Despite the heavy themes, the panel finds moments of humor and optimism, underlining the strength of the crypto (and AI) community to rally, self-police, and—sometimes—do real good.