AI Supply Chain Attacks on Smart Contract Tooling
Param described how a group of hackers created a malicious Solidity package and gamed Cursor IDE’s package ranking so it appeared first in autocomplete suggestions. Developers writing smart contracts pressed tab and auto-imported the malware without realizing it. Several large companies lost funds and had personal information stolen. AI-assisted development lowers the barrier for this kind of attack in both directions: it helps defenders audit code, but it also lets attackers craft supply chain traps with less skill than before.
Verify Before Trust: OPSEC Against Social Engineering
Chad said most cryptocurrency theft in the wild is not technical hacking. It’s social engineering. Deepfake voice calls and impersonation messages are now pay-to-play tools accessible to low-skill attackers. His defense: if someone calls you, text them on a separate channel before acting. Keep a code phrase between yourself and close contacts for out-of-the-ordinary requests. Publicizing crypto holdings invites physical attacks. France has seen a pattern of targeted wrench attacks against people who broadcast their wealth online.
Self-Custody: Exchanges, Hot Wallets, and Seed Phrase Storage
Chad framed wallet storage as a risk matrix. Exchanges work for beginners using small amounts (“cheaper than bowling”) but not for growing holdings. Software hot wallets carry meaningful risk. Hardware wallets are the preferred step up, but they require key management discipline. The phrase “not your keys, not your crypto” holds, with a UX learning curve attached. Seed phrases on paper can burn in a house fire. Steel-etched phrases stored offline survive. Multisig raises the cost for attackers further and is worth the complexity once savings become significant.
Adoption vs Security: The Long Arc to Usable Crypto
Param noted Coinbase announced partnerships with Chase and other banks to smooth on-ramps to non-custodial wallets. Chad compared crypto UX to early automobile safety: cars grew more powerful before airbags existed, and insurance took decades to become standard. The convergence is slow. Shopify now accepts USDC. Coinbase’s L2 Base has active builders from nearly every country, including pre-teens in rural areas developing on-chain applications. Financial freedom is a strong enough pull to drive global adoption ahead of infrastructure maturity.
Q&A
What are the risks of keeping crypto in a hardware wallet versus an exchange? Chad outlined a risk matrix: exchanges work for learning with small amounts but hardware wallets are preferred as holdings grow, with seed phrases stored in steel offline rather than paper. ▶ 12:48
How will crypto adoption and security converge over time? Param cited Coinbase’s new Chase partnerships for smoother fiat on-ramps; Chad used the car airbag analogy, expecting decades before the UX becomes seamless but confident the trajectory is clear. ▶ 18:16
Notable Quotes
it’s easy to be a criminal these days. Chad Calease · ▶ 8:21
It doesn’t require a lot of fluency. Chad Calease · ▶ 8:23
I encourage everybody to have a code word Chad Calease · ▶ 8:28
and and and simulate simulate simulate Chad Calease · ▶ 17:10
Key Takeaways
- Cursor IDE’s package ranking was gamed to auto-import a malicious Solidity package, draining funds from smart contract developers.
- Most crypto theft is social engineering; verify contacts through a second channel and avoid publicizing holdings online.
- Move from exchange custody to a hardware wallet as holdings grow; steel-etched seed phrases survive house fires, paper does not.
About the Speaker(s)
Michael “MSvB” Schloh von Bennewitz is a computer scientist specializing in cryptosecure electronics and embedded development. He founded Monero Devices and maintains open source software repositories in the space. A prolific speaker in four languages, he presents at technical meetings every year.
Chad Calease works on the Kraken security team, focused on resilience engineering and human behavior in crypto systems. He approaches security through what Kraken calls “Productively Paranoid” thinking, a design principle that treats failure as inevitable and builds around that assumption.
Param D Pithadia is an Electrical Engineering student at Georgia Tech who got into cryptography and hardware security through coursework covering side channel attacks and differential power analysis. He also works at a software company on crypto adoption and ease of use.