David Schwed / Halborn

How Halborn is building Web3 security practices

InterviewDecember 5, 202222:18

In this episode

Ashton Addison speaks with David Schwed, COO of Halborn on security measures in the blockchain space, their recent $90M fundraising, how we can build dApps and DeFi in a way that institutional investors feel safe, and what security will be needed for continued Web3 adoption.

Key takeaways
  • Smart contract audits require human expertise to identify business logic vulnerabilities that automated tools cannot detect, particularly when developers lack financial services experience.
  • Halborn's security approach covers risk management across entire Web3 projects and ecosystems, not just smart contract auditing or penetration testing.
  • Red flags like absence of board oversight and unaudited financials can indicate potential risks in centralized exchanges, though security firms may not publicly warn against specific platforms.
  • Institutional capital adoption in Web3 depends on establishing trust through comprehensive security measures and addressing criminal activities that damage ecosystem credibility.
  • Self-custody requires equivalent security infrastructure to traditional banking; without proper safeguards, self-custody presents greater risks than regulated custodial providers for most users.

Transcript

Read the full transcript 4,558 words, auto-generated and lightly edited

I'm Ashton Addison from blockwest capital for investment pitch media and today on the Crypto Coin Show we have David schwed the Chief Operating Officer of halborn David welcome to the show and thank you for taking the time thanks for having me you're very welcome I feel like this is a perfect time to have this discussion around cyber security security risks and proper

measures need to be taken in blockchain whether it's to do with defy or centralized exchanges or your personal security of your funds becoming ever more important with things happening in the industry that are everything seems fine until it isn't you know and we saw with the FTX crash this contagion of all these different companies that are interlocked and your

funds may not be safe with those companies so I'm excited to dive into your insights into the industry being a sort of an expert in this space I would love to start up our conversation by just hearing a little bit more on your background and how that led you to getting involved with halborn security and then we'll dive into all the details sure absolutely so you know at a you

know 20 000 foot level the early part of my career I spent in Trad fi in various roles such as you know infrastructure information security risk management in 2008 I co-founded the Telecommunications Company which I ran for about 10 years before we were acquired while I was at my company I was enamored by digital Ledger technology unfortunately not from a you know

evaluation perspective you know so I you know bought and traded some Bitcoin back in 2012 or 2011 into 2011. But again it was really more about you know as a as a yeah I was not necessarily A Cypher Punk per se but you know just a general interest in this you know concept of this distributed Ledger technology and you know the different potential use cases for it and when I

had sold my company a friend of mine was over working for Mike novogratz Galaxy digital and there was an opening for Chief Information Security Officer so timing was right was enamored by the technology so I went over to Galaxy to help stand up their information security you know I guess program if you will I spent about a year there left went into

Academia where I was the director of a cyber security master's program for University of New York and then I went over to BMI melon where I was their Global head of digital assets technology so for them it was building out the custodial platform as well as exploring you know looking at you know other types of you know use cases for it for digital assets whether it's tokenization

or execution Services as well and while I was at BMI melon you know there was a need for you know engaging with different firms to come in and you know do some third-party assessments so hellborn was one of the firms that I was particularly interested in really from a reputation standpoint you know for me you know I'm big on let me tap into

my community of csos and ask them you know who do they trust and you know about four or five of them all gave me the name halborn so I reached out I had conversation you know developed a relationship with hellborn and you know now I'm over at Albert now incredible background and leading up to that point now so what is your main focus with halborn and what are all

of the different arms that they're reaching into in terms of security sure you know so my role at halborn is really to help the company grow right so it's either you know building helping build new products and services operationalizing our back office you know doing more with less if you will you know it's challenging today for anybody in the web 3 security because

there's this you know how do you scale type of a problem and some firms are taking the answer of let me build technology and you know to use people less and to use technology more I am personally of the mindset and hellborne is as well that you know we're not at the stage at this point where security you know smart contract audits or program audits can be automated you still

need eyes on glass you know you can leverage technology to perhaps Identify some low-hanging fruits but this is still it's you know at the end of the day this is a bear asset whoever holds it owns it so you know we can't necessarily rely on you know static and dynamic code analysis there needs to be actual you know red team pen test Engineers that are actually looking

through the code and identifying not only vulnerabilities in the code but more importantly vulnerabilities and business logic you know you have a bunch of developers today that are writing Financial Services applications that aren't necessarily people that have been in the financial services industry for the last 30 years so they're making some fundamental mistakes from a business

logic perspective that you're not going to get picked up from automated tools or even for automated testing it's going to have to be someone who has that mindset that goes through and says how can I exploit this for malicious gains and that's where you know people come into play definitely and does halborn you know you focus on the security of decentralized

applications and defy but also on you know blockchain transactions and into monitoring illicit funds and if there's centralized exchanges involved correct you know there are multiple different types of people within crypto or organizations other than crypto you know there is the you know True Believers the Libertarians that you know this is the people's money and

we're not going to trust you know a government you know from a from a you know currency perspective listen there's definitely a use case for d for digital Ledger technology for that type of you know audience however you know the audience that the other side of the house is really like the financial services and it's really like the institution the

Enterprise and for them in order for an onslaught of capital to be not that there isn't already but even more to be injected into the ecosystem there needs to be trust and when you have all of these hacks and you have all of these you know again criminal activities alleged criminal activities from certain organizations it sets the ecosystem back so

hellborn's mission is to really secure all web 3 projects the ecosystems from a totality so we're not necessarily focusing on just smart contract auditing we're not necessarily focusing on pen testing we are focusing from a risk management perspective of what do I need to secure for this particular web 3 project in order to instill trust within the within the

community and that's our mission our mission is really to secure web 3 projects and ecosystems okay and take for example the recent FTX insolvency and debacle obviously there's a lot of trust that people give giving their funds into FTX and sometimes those funds are moving around on the blockchain but also in the exchange there's just your balance which

is you know sort of their internal controls and that's not always been able to be tracked by Third parties and cyber security firms you know do you see if any security firms had you know like a yellow flags going up you know since the spring crash of Celsius and Luna that people are watching the blockchain and looking for other issues and trust issues and it seemed like

this sort of came out of left field and no nobody including the security firms like saw what was coming well I think if you if you take a step back and you look at like what is security security is really just a subset of risk management and if you look at the end of the day and if you look at just pure risk management practices there are look you know

they're definitely red flags right I'm not sitting here and saying that I was shouting from the rooftops don't use FTX you know I really honestly didn't have an opinion on them one way or the other you know personally I'm not I don't use exchanges you know I sell custody however I'm qualified to self-custody and I'll touch on that in a second you know but again looking back red

flags you know no board of directors no audited financials you know it you know that to me screams that there's something potentially going on under the hood and you know when you look at risk management as a whole you know you we always say you know not your keys not your crypto which is true but again I'm not advocating that everybody even novice users start pulling their money

off of exchanges and self-custing because that's like saying I don't trust the banks you know Vault I'm going to take cash and put it under my mattress now if you don't have the same type of security or physical security for your house putting it under your mattress isn't a better solution than leaving in a bank so for many people leaving it on in exchange leaving it with custodial

provider is the way to go but you know from in an Institutional perspective IO would always Advocate how much money are you leaving on in exchange versus how much money are you self-custing versus how much is it cold it really comes down to again risk management do I actually need access for liquidity purposes for certain types of my assets if I do potentially leave it on an exchange or

at the end of the day you know hold it off the exchange at night you know again there's going to be some fees for on-chain transactions but if you don't need ready access for liquidity I would say you know self-custody that's a great point and I think an important part of risk management is also diversifying your assets you know not just inside and outside of crypto but the location

that your crypto is in Don't Leave It All in One account correct 100 and you mentioned they're you know being qualified to do self-custody but you also want to have the a certain level of security you know if you have 100 bucks on your mattress it's not as bad as having 100 million right or billions which you know recently there was a story that you know one of the

Silk Road hackers they found like a few hundred million like just in his bathroom on us on a USB stick not hidden very well with the institutions that are coming in to digital assets you know obviously if they have hundreds of millions they're going to want to secure it and custodial Services seem to be the best option for that I'm guessing that those

custodial services are also working with cyber security firms to ensure that they have the proper security to secure customers funds yeah absolutely and you bring up like a great point from when you're doing due diligence you know when you're looking at firms you know from a custodial standpoint it's it's asking those you know perfect questions right like there's a key

differentiator between a qualified custodian and the space and a technology you know custodial provider you know for example it's really at the end of the day who's holding my keys so if you're going with a qualified custodian they're holding the keys on your behalf and if you're using a technology custodial provider there's additional level of Safeguard in the

sense that you either and if you're using MPC technology or an HSM you either hold the keys in order to effectuate a transaction or if it's MPC you hold a piece of that key share so in that case it really truly is your crypto because the challenges just like Banks you deposit money they lend your money out in order for the banks to earn money and that's what pays your interest

there's no difference in crypto we're depositing crypto they're lending the money out the problem is it's not Trad five you know 30 years worth of experience with you know Enterprise level risk management tools it's unfortunately people that are first figuring out you know what do we want to do here and the other issue is we are leveraging we're not leveraging we're offering

such high yield that you know as a as a consumer I would take a step back and ask well where is this yield coming from you have to be either making risky you know lentil you know lending practices or you're not spending the proper money in order to secure that ecosystem like you can't just print money out of thin air it's coming from some place so

in this case it turns out that they were either completely fabricating and making things up and or making some very very risky loans and that's where you get those high yields but the consumers aren't participating or agreeing to those risky loans it's the institutions that are doing it on behalf of their crypto so I think from a due diligence perspective some of these practices

could be very easily uncovered just by asking certain questions yeah that's a great Point David and you know for example when Luna's UST stablecoin was offering 20 yield in stable versus you know 10 which is still still fairly High to the other coins it just seemed like too good to be true and it turns out that it was too good to be true yeah and you know I didn't

touch that one because I just thought that it just seems weird like you know why why are they offering double for my money for the same thing and you know in defy there's even though a lot of these C5 lending platforms have all sort of collapsed for the most part and they were offering higher yields you know D5 still seems to have a lot

better yields than in the bank and using these smart contracts so do you see the institutions looking at D5 platforms and like hey we should move our funds into these D5 platforms and Trust the security firms that are looking at the Smart contracts and ensure that you know our money is safe with those and sort of have you know

the centralized custodian ship but also like into the smart contracts and D5 for the yields I think when you get into like large large financial institutions like you know gcip and gcipes you know globally systemic important Banks and financial institutions I think personally I don't think we're going to see a shift into D5 for at least a few years for a variety

of reasons you know one is obviously the security concerns you know the problem that I'm seeing is there's kind of twofold is you have decently well-capitalized projects entering into the market so the D5 protocols or all of these startups are getting you know Nice Seed checks whether it's you know 10 15 20 million dollars however it's not enough money to

stand up an enterprise-ready cyber security program or practice in order for banks to feel comfortable to use them from an asset perspective so I think until the ecosystem gets to a point where Banks from a due diligence perspective feel that their security posture and environment is up to the level that you know that a bank would work you know would want I don't think

we're going to see Banks entering into that into that market at least that's my opinion yeah it you need a lot more than that you know for the banks at least to trust to trust you and in terms of you know having that level of security that's necessary obviously that takes takes a lot of money what are some of the steps that defy Protocols are going to need to

step up their security to eventually make their way to being trusted by the Banks yeah I mean there's a couple of things they can do right so the first piece is well number one you know kyc and kyt and sanctions I mean that has to be addressed in defy you know Banks regardless are not going to be able to even participate if they're potentially the counterparty that they're dealing

with hasn't been kyc'd or kyt so let's kind of move that obstacle off to the side that needs to be solved in order for D5 to you know to enter into the market but outside of that it's it's really you know if I'm if I'm a D5 project or just any you know web3 project that wants to play in the in the institutional world you have to you have to hire csos right you have to hire

actual csos and not directors of security that you're now giving a nice fancy title to there's a big difference between a CSO and a director of security and you know what I'm seeing in a lot of these you know web3 startups is you know the CSO that I'm talking to is really a director of security and it's not to knock that individual's technical jobs they're phenomenal security people

they're just not at the level of the C levels you know security officer where they're really understanding strategically how to stand up a program to address you know Banks so I think that's the first up and the other piece is really for these new you know csos individuals to really stand up an environment that would pass A bank's audit you know again without you know

telling you where I was or the companies I was talking to you know but you know I have talked to some web three startup companies where if you look under the hood you know they're you know in effect yoloing their infrastructure in a sense you know where there's no backup there's no resiliency there's no segregation of Duties they're not adequately testing things before

they go for production you know I've worked with organizations where we'll request a feature and they'll tell us oh you can have it by next Friday thinking that we'd be happy with it but you know coming from a large financial institution like how can you roll out a new feature and adequately test it get a third-party attestation fix all the bugs that they you know no

you know probably found and roll it out in a week if you're telling us that you can roll something out to production in a week you're obviously not doing the type of testing that we're looking for so I think they need to borrow you know a Playbook from from large financial institutions yeah it's it's so interesting with D5 platforms because you know when when D5 summer first

happened and people are getting excited about yields the thing is that if he didn't get on in the first day you know before you even had time to check the audits or you know what the smart contract says that's when the yield is the highest and then it sort of goes down and people are just so hungry for high returns that they don't even read you know any of the security

information they just like throw their money into contracts that you know we're still seeing over 100 yield on something that's like seems very ponzi-like yeah I mean you're right right I don't think necessarily these projects are starting out to be a Ponzi scheme but in order to pay out the yield they have to have new people coming in and injecting

fresh Capital that's going to dry up at a certain point so whether people stop having Capital to you know put into these liquidity pools you know and or you know there's bad news and everybody starts doing a run and starts liquidating their positions you know that's when you start creating you know this Panic that's happening right now and I recently saw in the news

that halborn just closed they got huge fundraising round of like 90 million dollars first of all congratulations to your team that's that's incredible I'm curious on you know with that Capital you know obviously you said it takes a lot of capital to work with these big Banks and work with big players you know what is that Capital gonna be mainly used for and how is your

team going to continue to expand out from here sure you know so the capital is really for us to grow right so you know we're we're Professional Services organization at the moment and we have launched two products and we do have a you know a product roadmap for 2023. so for us you know we are uniquely positioned to understand what's lacking in

the market from a security perspective and that's and that's what we're trying to build so between what we see from doing our daily you know Audits and engagements to also working with some of our larger clients and asking them frankly like what tools are missing for you that's what we're building and that's what the money you know primarily would

be used for great and if I'm looking at you know a default product or custodial service what I see like you know security by halborn or do you guys sort of have a public-facing check mark Or you advertise who you work with how does that work from like an end user perspective sure so it really depends on the client some clients want publicly you

know exposed reports and some of them want to keep them private and only you know provide to their clients so the ones that permit us to have public reports it's on our GitHub repo so if you go to the you know on our website at the bottom there's a link for our GitHub repo and you can see our public reports now the public reports don't necessarily go into the full details of you know

some of the vulnerabilities that have been found it's more of a high level with you know whether or not that particular vulnerability has been remediated and we also validate the remediation too so we don't just issue the report we'll issue the report work with the client to remediate retest and then issue the final report to say you know this particular vulnerability has

been remediated but you can find all of that in our repo great to know David and moving forward with D5 projects you know I don't think people are going to stop creating new ways to generate yield do you think there will be some standard of security or like standard implementation that the D5 Community can come to a consensus that you know these need to be

the things that you know at least at some point like the Audits and insurance and other things for I guess you know eventually people get tired of investing in things that don't have all of these standards yeah so I do I think we will get to that point where there is a framework or there is and again framework and regulation to me are kind of like not

the gold standard they're the bare minimum where you need to be I don't think we haven't seen that yet in crypto you know there's been some organizations that have tried to come out with certain ones the one that I'm you know personally most bullish on is the non-profical crypto Consortium so they release something called the ccss standards which again is focused more

on Key Management C Generation and they have different standards right they have a level one level two level three you know escalating level of security so I think we need more either organizations like crypto Consortium coming up with different Frameworks or crypto Consortium you know tackling other areas as well but I do think that it's something that is needed

and I do think that you know there are organizations working on it we are participating in a few to kind of offer our feedback as well but I do think that is something that will you know effectively help right like once their Community can can get consensus on you know this is where we think that bare minimum on security is and then as long as I'm organization can hire a firm

like hellborn or one of our competitors to come in and audit them to those particular standards but again the height is risking these are bearer assets you know so what worked in Trad fi as far as let me get a stock two sock 370 you know from you know the older in the olden days or ISO standards you know those are all point in time relying on an auditing firm to come in which is

absolutely necessary but I don't think that you know customers should absolutely or client should absolutely rely on that per se I think they need to also start doing their own due diligence as well you know and again they can hire a firm like halborn and one of our competitors to kind of come in and help them you know do due diligence of you know whatever

custodian or the provider that they're working with great information thank you so much David for all your insights into you know security of web3 of the ultimate importance if the industry is going to grow and improve and bring in more big money to take it to the next level from mainstream adoption I really appreciate you coming on to talk about

halborn and I will leave the links to halborn Securities the docs and the platform in the description box below as well I appreciate you taking the time and let's follow up in the near future great thanks for having me

More interviews

Browse all 1,084 interviews

Get new interviews firstCCS Insider, the free newsletter from Ashton Addison. Twice a week.

Subscribe free