On The Brink with Castle Island - Adam Healy (Station 70) on Digital Asset Cybersecurity (EP.539)
Episode Date: June 26, 2024Adam Healy, the co-founder and CEO of Station 70 joins the show. In this episode we discuss: Adam's career and path that led him to enter the digital assets industry as a CSO and eventually co-founde...r of Station 70. The evolution of digital asset custody from a technology perspective. The evolution of MPC as an infrastructure technology. The threat vectors that CSOs must confront in managing a custodial business. Cybersecurity best practices. The inception of Station 70 and the state of private key backups in the digital asset industry. How market structure is likely to evolve with more banks and broker-dealers getting active in the space. To learn more about Station 70 visit their website.
Transcript
Discussion (0)
Today on the podcast, I sat down with Adam Healy, the co-founder and CEO of Station 70,
a cybersecurity company that's focused on disaster recovery and the backup for private keys.
In this conversation, we discussed the evolution of the digital asset custody space,
the most common attack vectors that companies in this industry are confronting,
and the products and services that the Station 70 team are bringing to market to make the industry more secure.
I think you'll enjoy this one.
So without further ado, here is my conversation with Adam Healy.
Matt Walsh and Nick Carter, our partner,
at Castle Island Ventures.
All of these expressed by them or the guests on this podcast are solely their opinions
and do not reflect the opinions of Castle Island Ventures.
Guest and hosts may maintain positions in the assets discussed in this podcast.
You should not treat any opinion expressed by anyone on this podcast as a specific
inducement to make a particular investment or follow a particular strategy, but only
is an expression of their personal opinion.
This podcast is for informational purposes only.
Brought down by bad mortgage investments, Lehman, which has 25,000 employees, will be
liquidated.
The federal government loans American International Group, AIG, $85 billion.
a different kind of market and the Fed is asleep. The federal government is stepping it to stabilize
Fannie Mae and Freddie Mac, the two mortgage giants that have been threatened by the housing crisis.
The Bank of England has pumped 75 billion pounds more to Britain's ailing economy with a new round
of quantitative easing. You print a couple trillion dollars and all of a sudden people start to worry.
So out of this worry, we have something called the Bitcoin. Bitcoin.
All right, Adam, thanks so much for doing the podcast today. Excite to have you on.
Happy to be here and glad we put this together. So you have seen this industry develop
quite a bit over the years.
We'd love to just start with your background professionally and then the path that led you
into the digital asset ecosystem.
Sure.
I often joke when I talk to folks that before I got into this land of fake internet
money, I worked at a bunch of other places.
So it was really just odd how it played out how I ended up in crypto.
It started my career in the government space spent probably about 11 years in government between
military contracting and then as a civil servant, primarily working in the intelligence community.
So it was a weird time, weird era peak of a couple different wars, traveled around the world,
and got to do some pretty interesting things.
And then kind of moved into the private sector and randomly, some folks that we know,
some mutual friends of ours, I had no real prior relationship with reached out to me and said,
hey, we're looking for a CISO to help build a custodian.
And I was looking for a reason to move back to New York and jumped on that and got into crypto full-time.
This was like 2017, 2018.
It's been a roller coaster ever since, and that small custodian ultimately got acquired by ICE,
which is one of the couple of acquisitions that became backed, and it's haven't really looked back since then.
It's been a wild ride.
When I think back to 2017, when we first met, I think the way that custody was even contemplated
by some of these institutions looks totally different.
So maybe you could just talk a little bit about that initial role, how keys were managed
by institutions and how that's evolved.
Yeah, custody, 2017, 2018, 2019.
looks a lot different than it does today.
What everyone is doing today is much more sophisticated.
I think there is a point where a lot of firms still were just thinking,
hey, we'll put some things in a laptop and put it in a safety deposit box
and kind of hope for the best.
And we could get a regulator to sign off on that, maybe buy some insurance.
And outside of some of the big players, right, Coinbase, BitGo, and a couple others,
that was what a lot of people were thinking.
And that was what in many ways was kind of the industry standpoint.
There wasn't a lot of sophistication to it.
The concept of pot versus cold.
I remember the very first insurance questionnaire was basically just so basic.
It reminded me of cyber insurance questionnaires from like 2010.
Do you have a firewall?
Yes or no.
And like that was like the level of sophistication around getting insurance for custody.
So things have matured quite rapidly from that.
And now I think there's been a lot of regulatory clarity, some in the U.S.,
but certainly overseas that we've seen that has helped state the,
the custodial landscape and then also the non-custodial landscape.
But that is, I think, caused everyone to be a lot more mature about it.
That plus the saying in the military is always your enemy gets a vote, right, with the fights over.
And I think the threat actors, from a security perspective, also get a vote of kind of how
custody is designed today.
And as the custody solutions are really become more sophisticated, the threat actor population
has also gotten incredibly sophisticated.
And we've seen some very, very interesting issues, kind of circuit.
and security incidents,
both on the technical security front,
the cybersecurity front,
but also on the physical security front.
There certainly have been some very high-risk situations
for individuals that have unfolded
that are kind of known crypto holders
over the last handful of years.
So all in all,
the level of sophistication,
a level of technology,
the level of regulation, insurance,
is all just annexed since, let's say, 2017-2018.
One of the more interesting things to me,
just having been in the industry,
is just the evolution of actually using cryptography and using some of the software that we're all
excited about to safeguard the actual keys, like the bearer assets. So kind of start in a world
where multi-sig wasn't a thing and it becomes a thing. And then you start to see companies harness
multi-sig and build businesses on top of that technology. More recently, MPC custody becoming a thing.
And maybe talk a little bit about just the evolution of MPC, how you initially thought about it
and what role that technology plays in this industry today.
Yeah, absolutely. It powers a lot of the industry. You know, the first time I heard about it,
I don't know if Michael will like me tell him the story, but I'll tell it anyway. I think he can text me later
is the first real discussion I had with MPC was what was Michael Shaloo and I rework on like
55th in Midtown, New York. And he basically was explaining to me what Fireblocks was going to do.
And I think Fireblocks had like 10 customers at the time or something. It was very early. And I was like,
this kind of makes sense. Like I have to really digest this and wrap my mind around it.
I ended up reading, there's a really good white paper for anyone that wants to read it.
It's called Pragmatic MPC.
It's available out there for PDF.
And I started to wrap my mind around this.
And what I realized, and you mentioned multi-sig, on-chain multi-sig, that's what most people
mean, right, when they say multi-sig, on-chain multi-sig baked into the protocol itself.
In most cases, it's very good.
There are certainly some limitations, especially if you start from my perspective, thinking
about, well, if we're going to use a smart contract to enforce custody in some construct,
I may be a little too paranoid for that.
I think there's a time and a place.
I have this philosophy of software as written by humans
and humans are inherently flawed,
and all a smart contract is a software.
So do you really want that to be the kind of single point of failure
for custody operations?
And then there are other flavors of multi-say,
great pay discreet hash and things for Bitcoin and others.
But the thing when it comes to running a custodian at scale
and are running any operation at scale
is how repeatable, how generalizable is.
that technology. So if you have 50 assets and maybe 15 of those assets all have very unique
versions of multi-sig implementations, now you have to have your custody operations support 15 versions
of how to do signatures. That becomes operationally complex. It becomes a security challenge.
And it also becomes a security challenge because it's operationally complex, right? The more
moving parts, the more things that you have to instrument and control and metric and alert on,
it becomes more complex. And this is not necessarily a problem.
saying a lot of people, and we know some of them, are on-chain multi-sync fanatics, and that is
their religion. That's totally fine, like everyone can have their opinion. But now, where MPC, I think,
makes that a bit easier is you can wrap the on-chain keys with an MPC protocol and really just
kind of have one implementation that manages the security wrapper around the on-chain keys.
And if you're doing things like trade execution or your exchange, you're doing different things,
then you obviously have to have integrations with the various protocols.
calls to use those on-chain keys, but from a pure custodian perspective, aka my job is to take
private keys, securely hold them, and have them available when a customer who ultimately
were holding those on behalf of needs them. MPC has a lot of advantages. And it's come a long
way in a very short amount of time. And now you're starting to see what I largely consider is
the MPC market becoming very saturated. And that's across both custodial offerings, but then
also what we would call self-custodial offerings. And I'm sure anyone listening to this podcast understands
the two, but for those that may be stumbling into crypto for the first time, the 32nd primer on that
is custodial offering would be something like, say, Coinbase custody, where the custodian,
through some regulatory structure you may or may not make them qualified, has sole control
of the underlying non-shame private keys. As compared to self-custody, where you're using
using, let's say, a fireblocks, and that is a wallet service that is using something like
MPC or other protocols in the case of fireblocks.
They use MPC to basically provide you tools to self-custody those assets using their software.
The Web 2 analog to that, I think, is Uber, right?
Uber has the software, but they don't own cars.
And basically, they're providing you software to interact with the drivers in the cars,
much like a fireblocks is providing you software to interact with the blockchain.
So ultimately you as a VC fund or a hedge fund or whomever are in control of those bearer
instruments, those on-chain private keys, be that are wrapped in MPC from a security perspective.
So hopefully I kind of explain that and set the table for those that maybe are new to this.
But MPC has come a long way.
But we're perform it, which is not really because MPC has gotten not much better,
but because the hardware that we all run around with, we all now have secure enclave.
and trusted execution environments effectively in our pockets.
So that has really facilitated the adoption of the software in a very, very mainstream web.
And we're starting to see that.
I don't even know how many MPC wallets are in the industry today.
I probably tracked the top 10.
And five years ago, there weren't 10 that could be the top 10 or maybe three.
So it's definitely come a long way.
We've seen actually legacy firms, like think of PayPal, for example,
buying into the NPC space to, say, their acquisition of,
curve. So we've seen this now where it's now become so mainstream and security it offers is so
good that PayPal, for example, has acquired a firm, you know, Coinbase acquired Unbound also,
obviously not Web 2, Web 3 Native, but we're starting to see that technology being very,
very sought after because it is so good at this point. We live in this industry where people are
generally pretty paranoid about security. I think if you're a good operator, you certainly are.
And I remember in the early days of MPC custody, you would hear critiques from people that were
maybe in the multi-sig camp, on-chain multi-sig camp, just saying, look, there are not that many
people on planet Earth that really understand this MPC stuff at a really granular level.
And it's pretty new.
So we're going to either go slow or in some cases, I guess, take aggressive stances against MPC.
You mentioned the number of companies that have popped up, the fortifies, DFNSs of the world.
It seems to me like that dynamic of their not being.
that many people in the world that actually truly understand this, that seems to be changing quite a bit.
Sure. You look at, like, Yooda Lindell, you look at Jonathan Katz, you look at some of these
professors that have come out of academia. It's interesting that you mentioned DFNS, I think,
and I'm pretty sure, that one of their cryptographers actually studied under Jonathan Katz at UMD.
So there's that technology, like any technology, has started to expand because it is new and
interesting, because it has a lot of promise. But yeah, there's still a finite group of people
and understand it. And I think that's probably true with Bitcoin or blockchain or anything, right?
There's really not many people. And I say we, I mean, a lot of folks within the security space
in the crypto industry that I circulate with, we say all the time that the number of people
that can actually securely designed cold storage custody is probably 100. There's not that many
of them in the world. And that's because it is complex. That being said, the number of people that
can audit it is also pretty small, but they're there. And I think that's where you can
kind of belts and suspenders, right? It's, yes, you're going to build something that is an
NPC protocol to do custody or provide a non-custodial wallet, etc. But now you have some
firms that are very good in auditing. There's probably three firms that I would trust to do,
actually do an audit of the underlying cryptography. And that's it, right? There's hundreds and
hundreds of security consultant firms, but there's probably three that you would really want to
get their stamp of approval of when it comes to your MPC product.
I'm going to sound like a broken record because I've said this on a number of podcasts.
But what I'm probably the most excited about in this MPC category is the potential to have
collaborative custody schemes where you don't actually trust a single custodian.
So what I would like for institutional custody would be for fidelity to play a role in it,
but also maybe another financial institution or maybe have a law firm play a role.
Do you think that we're on the path towards having sounder custody practices just by institutional
diversification on the back of this MPC technology?
I think the answer is twofold.
On one end of the spectrum, you have a group of firms that must have,
the term I used earlier, which we can unpack a little now,
is they must have a qualified custodian.
So they must have a custodian that has sole control of the on-chain keys
that allow you to affect the blockchain transaction,
and that custodian is regulated by someone like DFS or whoever.
DFS being the most popular, right?
the vast majority of your tier one custodians, as I would define them, are regulated by New York
States' DFS as part of the trust arrangement. However, the firms that don't necessarily require
qualified custody, distributing keys amongst some number of third parties, legal firms used
a case of fidelity or others, I think that certainly facilitates that because the beauty of it
is it allows you to affect the on-chain transactions in a very, very high assurance.
secure way. Of course, pending the architecture that's in place, I'm just kind of using kind of my
top ten wallets as my proxy for this. It allows you to affect that on-chain signature in a very
secure way, which is different than things like Shamir, which had been used kind of previously for
off-chain multi-sig, if you want to call it that, or even some of the on-chain multi-sig protocols.
So I think it facilitates that. I've yet to really see a number of, we'll say, the wallet providers,
implement a strategy like that.
There are certainly some that are out there,
but they are as always doubles in the details
because the other problem that you have when you do that.
And now I'm putting my old CSO,
my recovering CSO hat on, as I like to say,
is the case around third-party risk is very real.
At the end of the day, right,
let's say we're using an MPC protocol,
it's extracted through some software,
maybe there's a mobile app,
maybe there's a web app involved.
We're still reliant,
even with all that fancy math and pornography and security
on effectively web 2 authentication into that service.
And I've seen a lot of data breaches in my day, and I've helped investigate a number of them.
And law firms aren't the best at security.
Even banks aren't the best at security.
There was a data breach just recently with Truist, which is a not maybe a Tier 1 bank,
but a material regional bank in the U.S.
And they're just not very good at security.
So now you've taken this general concern of third-party risk at your organization.
is Dropbox going to get breached in some of our documents leaked?
And now you're applying this third-party risk model to a bearer instrument,
so, you know, money effectively.
If I put my C-SO head on, there's some concerns there.
It would have to be a well-architected operational process
on top of very sound MPC technology.
Yeah, I mean, you almost wonder if at some point this becomes a regulatory or legislative
action where the definition of qualified custody gets to change.
and maybe a cybersecurity firm would be the better one to have one of three signing keys or something
like that where maybe at some point after we're done battling market structure, stable coins,
and whether or not the banks can even custody this, the next frontier of things that the industry
should push for is just sounder custody practices.
I would love to see it.
I won't hold my breath for any legislative agenda that supports that.
I feel like they have the Congress has their own challenges to work out on a number of other
pressing matters, in my humble opinion.
but it would be something that I think that the industry should lead, right?
There should be more focus on that.
I think of it almost as custody is a foundational aspect to the industry,
custody and self-custody services,
and there's very few standards that can be applied
to actually instrument what is safe and what is not,
and there's not a lot of consensus across organizations,
and rightfully so because a lot of these organizations are competitive with each other
around what is right and what is not, what is good design,
with bad design.
It's an interesting space to be in.
The first thing I would like to see from the industry is coming together on some
standards, CCSS being probably the most recognized, but at the end of the day, it's not
all encompassing.
And you can make the argument that maybe it shouldn't be, but you have firms that say,
hey, we've got a pen test, we've got a sock two, we're secure.
And I think those are important, having done diligence, you know, as formerly the CISO
at BlockFi and backed, I've had the opportunity to diligence.
pretty much every custodian, pretty much every wallet provider, every large trading counterparty,
every large trading venue or exchanging, I've gotten to see behind the scene that pretty much
all of the major players in the industry over the last handful of years. And the way that we approach
security is very fragmented. And there is no real standard. Right. So you have, like I said,
you have these firms today. We have a penthouse. We have a sock two. We're secure. And my anecdote
always is, well, so did Home Depot in 2015. And they also had a PCI audit and an ISO audit and an
audit, but that didn't mean that they didn't have the world's largest credit card breach happen.
And 80 million credit card numbers got stolen. So audits are important. I would love to see
the industry standardized on a custody audit structure. I would love to see like EY or KPMG
or Deloitte kind of quarterback that. Do I think it's going to happen? Maybe over some time horizon.
But I think that would be a good first step. It's not going to be the silver bullet. It's not going to
all of the data breaches we see, but it's certainly going to help mature the industry.
So you mentioned being the CSO at some of these large-scale players in the industry.
Maybe take us into the mind of a CSO on a day-to-day basis.
I mean, what type of risks are you thinking about?
What are you losing sleep on as a CSO at a big custodian?
I forget where I got this, but I always joke that people asked me when I was CSO at Blockby,
and we were in like a rapid growth mode, millions of retail customers, hundreds and hundreds
of institutions. I sleep like a baby every night. I wake up every couple hours crying. Not
necessarily true, but pretty close. Some of the things that I would worry about, they range.
And every day was a different challenge, right? Some days there were legal and regulatory challenges.
Other days, there were security challenges internally that we were having to deal with.
Third party security breaches became a big issue, right? We were customers at Block 5, HubSpot and
ACTA, and both HubSpot and ACTA, each individually, independently had data breaches within
a week of each other. So third-party risk is a very, and this gets back to the point around
a decentralized signing apparatus, let's say a law firm or an accounting firm, like third-party risk
is very real. So it could be a third-party risk that we were worried about. Diligence of counterparties,
custodians, third-party trading partners, etc. That was always top of mind. And then all the internal
IT hygiene, security hygiene of how we run the business.
And probably one of the things that kept me up a lot.
And I worried about a lot was physical security.
So BlockFi had kind of a unique role where I spanned a lot of different responsibilities,
but physical security around the office, around key executives, like Zach and Florey,
those were concerns.
But then also some of our customers, like I won't go too much into detail with it,
but I don't actually know where the case stands right now.
But we had a customer at one point that was being held, we will say,
in a foreign country and their crypto accounts, BlockFi and some other crypto firms, were being
actively emptied by this individual's captors. So that was another big issue. And that resulted in
the FBI getting involved, the State Department getting involved because it was a U.S. citizen
traveling overseas. It was a very big issue. But those types of things that certainly worry me,
probably first are the physical security forms. Yeah, those are scary incidents there.
How do you think about just the evolution of nation state attacks? I mean, there's been
a lot of chatter in the industry around just the role of North Korea and other adversarial
nations and how they are potentially looking at some of these centralized institutions to attack
them. Yeah, I think if you look at it through the lens of an attacker, so you put your red team
hat on, and it's a target-rich environment. There is a crypto continues to grow every year,
regardless of what the headlines pontificate of Bitcoin being dead, hasn't happened yet. And every
year, crypto seems to grow. We certainly have had some down years, but we're up, I think, or at least
most of us are. So I think at the target-rich environment, there are a lot of firms that don't
understand security and don't invest in it up front. Like I think about what we're doing at
Station 70, and what took us two and a half years to build at Block 5, because when I got there,
the firm was established and there were a lot of moving pieces and infrastructure already built.
At Station 70, we're already beyond that from a security health perspective.
or less than a year old.
So I think there are a lot of firms, especially smaller ones, that don't invest even
moderately into security and they end up paying that tax later when something bad happens.
Nation states are a big concern.
Within crypto, though, we have the threat actors range from opportunistic, moderately skilled
threat actor to nation states.
And when we say North Korea, right, what we really have to ask ourselves, sure,
it's effectively an open secret at this time that North Korea is using stolen crypto.
to finance their nuclear program.
That is the general consensus of everyone.
But is it just North Korea or is it actually North Korea and Russia timely that there were
some visits from Putin into North Korea this week?
Or is it North Korea in China?
Does North Korea have an aggressive cyber threat program that they are actively targeting?
Absolutely.
Does it need to be super sophisticated to target some of these crypto firms?
Definitely not.
Some of the more sophisticated work, though, you would have to assume,
that it is being backed by Russia or China to facilitate some of those more complex attacks.
But the nation states are a big concern.
So that is one of those things, though, that you'll never outspend what the nation state can spend.
You'll never going to, if you're a 50-person shop in crypto, doesn't matter what you're doing,
you've got some capital, you've got some revenue.
You're not going to be able to outspend what a very sophisticated threat actor is going to spend.
So you essentially have to leverage your knowledge to build defenses.
your knowledge of your own product to build the defenses that make it very difficult for an outsider
to penetrate. This, without turning this whole discussion into, you know, defense in depth and security
and identity, how do we layer these things and what order do we layer these things? It's something
that you really have to think about as a first order problem if you were in crypto today.
I tell firms that I have spent an hour or two with helpless small crypto firms over the last
a handful of years, just providing them some basic advice on what they should be doing.
And I would tell my advice to any firm that's in crypto, too, there is a lot of people in security
across the industry, and you likely have a one or two degree of separation from one of them.
You should use your network to get folks involved in your project or your token or your
protocol or whatever you're working on early to kind of provide you some guidance,
if nothing else because it will pay off for you later.
Maybe without going into all the gory details of the recommendations there,
maybe talk a little bit about some of the low-hanging fruit
that you would advise anyone operating in this space to look into.
Depends how technical we want to get down the path.
But I would say the low-hanging fruit would be hardened identities, right?
So first and foremost, get on a solid SSO provider.
I've stopped recommending ACTA, although I think they do a lot of really great things.
I was very unimpressed with how they handled their last couple data breaches.
And as a former enterprise customer that paid for very premium support of ACTA,
I couldn't get answers that I needed in a timing manner.
A lot of people use ACTA, a lot of people use Azure AD,
a lot of people use Google as their kind of identity provider in addition to their email service.
So pick a good SSO provider and kind of go all in on that,
but only support hardware token for two-factor authentic.
Right. Ubekees is what I recommend. A joke that I heard a Fortune 500 CISO make in 2020 was if John Podesto would have used
ubiquies, Hillary Clinton would have probably been president. And it's true, right? Politics aside,
it's a funny anecdote because it's probably true that that email wouldn't have gotten compromised.
So it's a UBekis. You know, they're $60, $80 per person and they are well worth their investment.
The other piece is around devices.
More and more we're seeing fishing and less around.
We still obviously see malware being deployed,
but we're mostly seeing credential harvesting type fishing attacks.
So make sure your teams are really paranoid around fishing.
Make sure your devices have something like Crowdstrike or Sentinel 1 deployed
and make sure that you are doing things that ensure the integrity of that device.
That has a pro and con around engineers want to be able to install certain.
things and there's a balance there as with anything security usability and security is always the
balance the other two probably more technical things or maybe i would say invasive things
is everyone is using a cloud gcp azure a w s whatever your cloud environment should be default
deny on egress every outbound connection your systems are making could be explicitly allowed
I should not be able to log into one of your EC2 instance in AWS and access Google.
Like that should not happen.
A lot of people, and I've done a lot of audits on firms, either as a helping hand or in some
cases as an investor trying to make sure that they were on a good foot in, you can't tell
me that you have a high integrity assurance of your cloud environment if you don't know
what's leaving your environment.
And kind of that leaving the environment could be source code.
It could be private keys for crypto.
So it could be other intellectual property.
It could be any number of things.
You start to talk about source code and things around intellectual properties after now.
You reinsert the nation's.
Specifically kind of as a prime example of that.
So that's very important.
And then the other piece, super low lift is get something deployed that handles email
encryption and data encryption for sensitive things.
And maybe that's something that's turnkey like Virtue email encryption.
Maybe that's something like a little bit more rigorous like PG.
that becomes a little bit hard to manage. But if you do those four things, you are going to be
far head of a lot of firms that are out there. And in my opinion, those four things are pretty
low left. I think there are a lot of people taking notes during that answer. So super helpful.
We'd love to talk a little bit about Station 70. Obviously, we're super excited to be an investor in
what you're building here. But talk a little bit about the origin story of the idea and a little bit
what you're focused on here. Sure. So the way Station 70 came to be is almost counterintuitive, right?
we talked about kind of my previous roles as a C-Syso,
I have purposely tried not to build this product for like seven years,
purposely, because I, at Back as a C-So and at BlockFi as a C-So there for, what,
three and a half years, we used different wallet services,
different technologies to support our internal operations.
And it always came to be an issue of, well, where do we put the backup keys, right?
Like, you're using Fireblocks as kind of the bigger example in the institutional space.
Well, when you onboard with Fireblock, they actually happen to have it right here.
They email you this like 37 page document that says, hey, you have now go back up these keys, right?
Because we Fireblocks is just a MPC wallet provider, you using Fireblocks or your own custodian.
So at Blockby, we were big Fireblocks users, and we were users of a lot of different wallets and a lot of different self-custody solution, MetaMask, and we had a lot of different things in motion.
So I looked around the industry numerous times.
I said, hey, like, somebody has clearly solved this problem.
Like 100% somebody must have solved this problem.
And come to find out, no one really was at least not in a way that I thought was
institutional grade security that took into account various failure modes around operations
and how we would actually get the backup circuit back to us in a secure way in a time manner.
So what we ended up doing at BlockFi was we built something that,
was very complex. And it took into account our very unique operating model, institutions,
and retail. And it was really, I wouldn't say over-engineered, but it was very thoroughly
engineered and it was very specific to BlockFi and wasn't something that could really be sold
or along those lines to a third party. So we won't get too much into the BlockFi FTX saga.
We both lived that in the front row more or less is when I was starting to think about,
well, you know, I really care about this industry. What are some of the gaps that I've
where I could bring some skills to the table and help make trust and safety better at institutions.
So I reached out to Dr. Adam Everspa. He's got his own very impressive background of PhD in applied
cryptography. I believe he was the first PhD cryptographer that Coinbase hired. That's not right.
Somebody will fact-check me, but I believe he was. And he ended up leaving Coinbase after the IPO,
joined BlockFi. And I reached out to him and said, hey, what we should do is we should build a brand-new service,
that is SaaS-based, that is a Web3 solution for a Web3 problem,
and build a disaster recovery suite of products that allow institutions
and retail next year.
We don't want to spoil that, but there will be a lot of needs on that next year.
But institutions, regardless of which wallet provider they use,
if they're doing self-custody in any way, shape, or form,
whether it's a ledger device or fireblocks or MPC or 24 words or 12 words, it doesn't matter.
Why don't we build a product that allows them to have an easy button for disaster recovery?
And then an easy button in the event that their wallet service is down or their wallet service as a data breach of how to get back to operations, how to either move those keys elsewhere or do something, whatever it is based on their business continuity policy, to get back to operations.
So we spent the last probably nine months getting to where we are today.
As you and I are having this conversation, we're about two weeks out from a GA launch.
We've been running a beta for about 90 days now.
We've got about 20 customers in the beta, some top-tier firms, got some great feedback.
And we're really excited for launch here in a few weeks with Fireblocks as our go-to-market partner.
We will really be a native Web3 solution to solve this with security being the first-order problem that we're solving as part of this disaster recovery,
broader problem. And what we wanted to avoid was, like using military analogies of
the carthal, is we wanted to avoid what we would call fighting the last war. So we talked about
2017 technology and safety deposit boxes and all of the stuff. Like that was not at all what we wanted
to do. There's so many issues with that. There's so many problems with that approach. We said,
hey, we're going to build something that's cloud native that looks more like an MPC wallet
than it does a safety deposit box circuit 2017. And we're going to be using things like
the execution environments and HSMs and modern cryptography that's well-honored, well-engineered.
So that's what we've been building, and we're really excited about getting us launched and then
starting to expand to kind of what I would consider the top 10 institutional wallets and being
their disaster recovery partner as we kind of mature at the company.
It's been really shocking to me to look at the MPC user base in this industry and understand
who's actually even backing up keys.
I think that would be like one thing that's maybe just an own goal for the industry is that
despite this great technology, some people aren't even using the safety deposit box option,
right? Like there is just a lot of unsafe behavior that is happening in the industry,
despite the tools that are there.
Well, a lot of it is due to because the tools aren't there. If we want to see this industry
grow, we have to create better tools. And obviously, I'm biased. So my bias is we have to
build better trust and safety tools. Disaster Republic is a core function. If you've ever done
to or you've ever done, really any audit at all, disaster recovery is something that you have
to address. Why it is not better addressed in the context of self-custody or MPC wallets is likely
this gets back to the standard because the auditors don't fully understand how that type of
works. But I do, or to a reasonable degree at list, and I can tell you now that I won't give
specific stats because some of them are pretty confidential. But if you look across the universe of the
top 10 MPC walls that are out there, a very small percentage of them are actually backed up
in a secure way. And a subset of them are backed up in an insecure way. I'll give you an anecdote
about that in a second. And then a vast majority of them, we'll just say over 50% are probably
not backed up at all. But, you know, I was talking to somebody that actually, we both know,
CEO of a prominent crypto firm recently. And he said, well, we have our own internal process
to back up keys. Why should we use you? I said, well, cool. Well, what's that?
process kind of look like, don't give me specifics, but just give me an overview. And he goes,
oh, like, I don't know, our CEO has a USB drive and some stuff happens. I was like, well,
you're the CEO, right? And he's like, yes. And I was like, so what you just said actually should
worry you more than it worries me, right? Like, we can talk about insider threat. We can talk about
illusion. We can talk about key man risk. We can talk about general good practices around disaster
recovery for any system, whether it's crypto or not. And nothing you just said about your
CTO having a USB drive meets any of those bars. So that's pretty much why you can use us. And he's like,
okay, let's have some more conversation. So it is really kind of that mindset where I think until someone
actually points out why that's bad, there's an education part to it. And most people, I think,
just don't put those dots together. It's such an interesting time to be building what you're doing
because the market structure here is just on the cusp of changing a lot. So you have these bills that are
making their way through Congress, which would give clarity to the banks and the broker dealers
on how to enter this industry. And then you also have just the explosion of stablecoins. So you have
just these net new participants in the industry that are coming in, not buying Bitcoin or Ethereum,
but just accessing U.S. dollars on blockchain rails. So I think the cast of characters who will be
in the custody arena is likely to change. How do you see that evolving as more of these
maybe tradfai institutions or fintech start to provide some of these services?
Yeah, I think it's telling that, like we mentioned earlier, PayPal bought Curb three or four years ago, whatever that was.
I think there's a lot of institutions, right, a big discussion of recent years in the crypto space with B&Y, and that obviously fidelity and ice and back.
There's a lot of players that are more in the trad by sense that I think has looked at it where I think a lot of them have been unable to mobilize is due to some of the regulatory uncertainty that you mentioned.
And my hope is some of that gets solved.
And it's funny, the very first panel in, like, 2017 I was ever on in crypto.
Was that some crypto conference in New York?
It was me, Mike Belchie, and someone from DTCC.
And I like all those guys.
Like, I like Mike.
I like all these guys.
And I remember, as we were wrapping up that panel, which is 2017, somebody said,
well, what do each of you folks get figured out in the industry over the next year?
And I was like, regular clarity.
Like, that's what we made.
Well, it's 2024 and we're still hoping for better regular clarity.
But to your point around stable coins, I think where we're getting better regulatory clarity is outside the U.S.
And that ties directly into something that I've heard you say before around the leveraging of stable coins for U.S. dollars outside the U.S.
and how that actually not only helps the U.S. economy and the dollar become stronger, but from my view, also provides a very interesting way for the U.S. to flex soft power globally.
And I hope that Congress notices this and see the kind of upside of both of these arguments
and mobilizes more smartly on getting through this legislation passed.
Yeah, in a lot of ways, the stablecoin story is it's impossible to ignore.
I mean, you can try to ignore Bitcoin, I think.
You try to ignore Ethereum, I guess at your own peril.
But as a category, stablecoins would be the 16th largest holder of U.S. treasuries.
So it's actually in the U.S. geopolitical defense perspective, this makes all the sense in the world
that you'd want to lean into this technology.
And I think unlocking a stablecoin bill, to me, that would just bring a lot more net
new participants into this industry.
So my hunch is that you'll have a lot of these institutions that are confronting their
first custody challenge, not necessarily on BTC or ETH, but how do we secure dollars on chain?
Yeah.
And it's over a time horizon.
We will get there.
A lot of these questions around custody will become even more important because you'll have
new entrants that maybe don't understand.
some of the nuance of some of this technology
and they're going to need better tooling,
better trust and safety, bigger easy buttons
effectively. And
I actually was just talking to somebody about this
recently and I had a vendor recently
offered to get, they said, hey, we can get paid in Fiat
or crypto. Five years
ago, that wasn't a conversation that
most, like you didn't hear mainstream
non-crypto-native vendors offering you
a 2% discount to pay in stable
client. So a lot has happened
in a few years and I think over a time
horizon, two, three, four, five years,
as some of these things get sorted out, it's going to be a very different landscape to your point.
It'll be interesting, too, just to see the things that crypto has created that can be ported back into the quote-unquote real world, right?
I think about stable coins as something that is crypto originated, but we'll end up being very ubiquitous in the traditional world.
Think about the within the defy context, the AMM is something that's being experimented with in TradFi, the perpetual swap.
As an industry, we're actually building some really interesting technology that you think would be extensible.
into other categories, even if it's not for bearer assets?
Yeah, I mean, you know that I've got some strong opinions on that.
And I think that a lot of the security tech that we've built in, not at Just Station 70,
but even more broadly, a lot of that hasn't found its way back into mainstream,
what we would call non-digital asset enterprise security settings.
Some of the cryptography super novel, there's some tooling that's really interesting.
So I'm actually really excited about that.
Again, I'm biased because I think about security.
and things like disaster recovery every day.
And I'm really excited about seeing what some of these products look like
as they make their way back into more traditional cybersecurity programs,
more traditional fraud programs,
because we deal with this every day.
If you're a crypto firm, it doesn't matter if you're five people or 100 people
or 1,000 people, you are under constant threat.
You are constantly getting bartering with attacks,
and there's been a lot of really good tools and a lot of really good technology built.
So I'm personally excited about seeing some of that make its way back.
Who knows? Maybe in a year from now we'll have another discussion on this podcast, and Station
70 will be shipping something into that space. We'll see what happened.
Love it. All right. Well, Adam, this has been great. Where can we send people to learn more about
station 70? And I think by the time this comes out, you'll be ready to onboard some customers.
So where can we send folks?
Yeah. So station70.com, all one word, station70.com. We can also email us at info at
station 70. Feel free to connect us on the socials, all station 70, or also,
me personally. I'm on LinkedIn. I'm pretty active. If you want to know, what are the top five
questions I would ask a vendor? We talk about third-party risk and security. I just wrote something
on LinkedIn about that. So yeah, across any of those avenues, you can find us, you can find me,
and we like engaging with folks, so feel free to reach out. And if you are an institution,
you have any concerns around your disaster recovery, your MPC wallet provider, we have a lot of
conversations that we have in good faith because we think that's the right thing to do for the
industry. We hope that that will come full circle and a lot of that will turn into.
to customers, but we're also happy to just spend some time talking through kind of our view
in that landscape. Awesome. Well, really appreciate it coming on today, Adam. Really exciting stuff.
Likewise. Thanks, Matt. Have a good weekend. Thanks for listening to another episode of On the Brink with
Castle Island. To find out more about Castle Island, visit castle island.Vicc. Visit castle
www.V. To listen to all of our podcast episodes, please go to On the Brink dashpodcast.com
or just click on the tab in our website. Thanks for listening.
