04/11/2026

Never Blindly Sign, Even From Friends

Justin Roberti and Dingo discuss the reported Drift Protocol exploit, the role of social engineering in crypto security, and the major themes Dingo encountered at EthCC, including institutional adoption, real-world assets, yield and the tension between permissioned finance and DeFi’s original ethos.

Transcript


Justin Roberti (00:01)
Hello, everyone. GM, GM. This is Justin Roberti with Saffron Files, and as always, I have my co-host Dingo with me.

Welcome, Dingo. How are you today?

Dingo:
Hello, hello. I’m good. I’m back stateside.

Some of the team members and I went to EthCC in Cannes, France, last week. It was a really interesting experience and a ton of fun. It was a great networking opportunity, and we met a lot of really cool people.

There was a lot of promising stuff, so it’s good to be back. It feels a little more secure being here with everything going on in the world. It’s nice to be back in the U.S.

Let’s go ahead and kick it off.

Justin:
Yeah, you were overseas for some really exciting events, now that I think about it.

Dingo:
I couldn’t check my phone. I just refused to look at current events while I was over there because I knew it was going to freak me out.

Justin:
If you managed to do that, it probably served you very well through Tuesday or so.

I grew up in the ’80s and ’90s, and it was the first time I ever really went to bed thinking, “Well, maybe we’ll drop the bomb tonight.”

Dingo:
Jeez.

My main concern was hearing reports about the Strait being contested, as it were.

I was seeing reports that the U.K. had received its last shipment of kerosene, or whatever fuel airliners use, for the week, and that they weren’t sure whether they had ordered more yet.

We’re recording this on Friday, April 10, and that was at the beginning of the week, on Monday. I know a lot has changed since then, but I was looking at that kind of thing and thinking, “Okay, I know I have my flight booked, but is that still going to be a thing?”

Justin:
You needed a little raft and a paddle to try to get back home.

We’re glad you’re home safely, Dingo. Welcome back to U.S. soil.

Let’s talk about the real drama of this past week. I know it happened while you were at EthCC.

Drift Protocol on Solana suffered what people are calling a hack, although it was more of an exploit.

What was the reaction when that news dropped? How do you see the situation?

Dingo:
It was really interesting.

Obviously, today is the 10th, and as far as I know, there still isn’t an official postmortem. So everything is subjective or conjecture at this point.

The reaction we saw at the conference was mostly shock because it was reportedly more than $200 million.

There were elements—and I think this is still part of the current narrative—of actors linked to North Korea using a combination of exploits and social engineering to gain the trust of people at Drift.

It seemed like the culmination of a lot of plans that had been in motion for the better part of a year.

Justin:
Dingo and I were discussing this for a few minutes before we came on air.

He pointed out that, according to a report from Chainalysis, the social engineering began as early as fall 2025.

Social engineering has always been part of the hacker’s toolkit.

As much as we talk about quantum computing and people developing new tools, folks, it isn’t always a matter of what is happening online or on-chain.

In this case, they were reportedly able to gain administrative permissions and then exploit the entire system.

Are we looking at a new kind of breakdown or a new risk for consumers—essentially a designed failure in how markets behave under stress—rather than a classic hack-and-extraction event?

Dingo:
I don’t know if I would go so far as to call it a design failure.

There are obviously things you can always do to strengthen oracles and manage who has administrative access to a protocol.

But I do think we’re seeing a different evolution of a classic social-engineering scheme, combined with exploiting administrative access to protocols.

It’s a very sobering reminder never to blindly sign transactions from people, even if you’ve known them for a year.

They may have met at a conference not too dissimilar from the ones everyone in the industry attends, and that kind of trust can be built over a long period of time.

I don’t know off the top of my head how large Drift’s staff is, but no matter how secure we make the infrastructure, firewalls and everything else, at the end of the day, you still have to remain conscious of attempts to socially engineer people on your team.

Justin:
Absolutely.

It also shows the vulnerability of many of our systems simply because they are small in comparison with TradFi.

If you’re looking to perform some old-fashioned market manipulation around an oracle, for example, it’s easier to make a small move that can cascade into larger losses.

It also happened on Solana, which is high-speed and low-cost, but it appears that these distortions happened faster than the safeguards could react.

Are we looking at a new kind of threat in the blockchain world?

Is this another reason to lock things down with better regulation, for example?

What prevents this from happening?

Dingo:
I’m hesitant to say anything definitive because the postmortem isn’t out yet, and we don’t know exactly how they managed to exploit Drift for more than $200 million.

This kind of security can always be improved.

You had someone on your When Altseason? show talking about this earlier in the week—which, by the way, is a recurring Twitter Spaces show with really good panels.

These incidents sometimes serve as painful lessons and learning opportunities. They remind us that the security we have can always be improved and further refined, and that we need to stay ahead of the game as much as possible.

When you get caught lacking, it can have disastrous consequences.

That’s one of the reasons Saffron is so adamant about getting multiple audits from different companies—to double-, triple- and quadruple-check our code and limit the possibility of exploits or catastrophic bugs.

Justin:
Do you think exploits like this—and I’m going to call it an exploit rather than a hack—create a credibility issue for the industry overall?

To Dingo’s point, the official postmortem hasn’t been released yet.

From studying other hacks and writing articles about them over the past few years, I know these incidents aren’t always just one single event. There could still be other people within the system.

I don’t mean to pick on Drift specifically, but institutions are paying more attention to DeFi now. It feels like this looks bad at a time when we have important potential investors studying what we’re doing more closely than they used to.

Dingo:
It’s tricky because this comes at a time when the industry is in a more vulnerable position.

There’s uncertainty in the global economy, and we’re seeing power structures being stress-tested at scale.

That has reverberating effects in every market, whether it’s crude oil, traditional finance or anything else, and we’re seeing that cascade into crypto as well.

This certainly doesn’t do DeFi any favors.

At the same time, based on what I’ve read so far and the initial reports, I don’t know whether it will create a catastrophic loss of trust.

It will make headlines, and retail users will see it as another crypto hack.

We do have a lot of these incidents. This is still a new industry and a nascent space where we’re working out many of the kinks.

It definitely doesn’t help, but when you dig into why it happened, it appears to involve multiple levels of social engineering and contact with bad actors.

Justin:
Scammers will keep innovating, folks.

I don’t mean to show any lack of regard for Drift. This is going to be something they have to work through.

I don’t know anyone on the Drift team, but I’m sure they’re working diligently on it. Hopefully, their bad experience will provide an important lesson for all of us about what to avoid within our projects and how to keep them safe.

Just like AI, every scammer will iterate on the work of other scammers, so they’re only going to become more clever over time.

You heard about this while you were at EthCC, so let’s shift over and talk about the conference.

You were in France at Ethereum’s flagship developer conference, which appeared to have a strong focus on real-world assets, infrastructure and institutional adoption this year.

Judging by the agenda and what has been written about it, the emphasis seemed to be less on speculation and more on integration with traditional finance.

Is that what you experienced, Dingo? Was it all about the crossover between blockchain and TradFi?

Dingo:
That’s a great question.

It’s too bad the conference couldn’t have happened a week later, after we had a bit of a rally.

Even though everyone was enthusiastic and building beneath all the FUD, you could feel a slight damper on the spirits of some attendees.

The protocols and developers we spoke with were still excited because I think everyone has grown resilient to bull- and bear-market cycles. They just keep building.

But it would have been nice to ride some of the hype from the recent relief after the constant negative news surrounding the industry.

That negativity isn’t necessarily the industry’s fault. A lot of it comes from the craziness happening in the Middle East right now.

Talking with people there, you heard a lot of interesting conversations about how we preserve crypto’s original vision while making it more legible to institutions.

People were discussing how we can integrate with traditional finance without losing what makes DeFi special.

Everyone has their own opinion on that.

I really love attending these events because, no matter what you see on Twitter or hear in Spaces when there is a lot of FUD or uncertainty in the market, speaking one-on-one with real builders is empowering.

These are people who are motivated to improve the space, expand the toolset and help the industry mature.

It feels like an injection of energy.

There are a lot of great protocols building beneath the surface. They’re developing better infrastructure, creating clearer products and integrating more real-world use cases.

That doesn’t necessarily compete for the biggest headlines on Twitter, but I got an overwhelming sense that people were asking, “Now that institutions are interested in our space, how do we effectively integrate with traditional finance?”

Then you have the existential questions: how do we preserve the ethos of DeFi and the things that drew us to this industry?

For me, that was almost seven years ago, and for many people there, it was even longer ago.

The conference felt progressive in a literal sense.

I also got the sense that there was a narrowing of scope.

We’ve reached a new threshold. It doesn’t feel like that when you look at market prices, but in terms of institutional interest, we’re at a new point.

Now that we have this attention, how do we channel it into building the future we all want?

There were a lot of really great conversations about that.

Justin:
Bear-market vibes in any room are always different from bull-market vibes.

You said this crowd was almost immune to the market, which would be progress if that were true.

Dingo:
I wouldn’t say immune.

It obviously affected them, but people grow resilient to it.

You could tell the atmosphere was a little down, but many of the builders understand that this stuff ebbs and flows.

Every cycle and mini-cycle presents its own unique challenges and hurdles.

We always end up making it through—every bear market and every bull market, no matter how bleak the FUD seems.

Justin:
Was the audience qualitatively different from what you’ve experienced at other shows?

Were you rubbing elbows with more Merrill Lynch product managers and fewer wacky blockchain developers wearing ironic T-shirts?

Dingo:
I would say there were more of the former, although not to that degree.

Everyone is going to have their own experience, and I also had specific objectives for the conference. I was networking with particular people with specific goals in mind.

One of the cool things about attending conferences during market downturns is that you really get to see who is there for the long haul, who is building interesting things, who believes in the technology and who genuinely wants to move the industry forward.

I saw fewer memecoin T-shirts. I may have seen a few, but I don’t know whether they were ironic.

There were a lot of interesting conversations.

The Canton Network was one protocol that came up frequently. Institutions are tokenizing assets inside closed, access-controlled environments.

With Canton, blockchain is being used as back-end infrastructure, but the system itself isn’t open in the way most people associate with crypto.

It creates a different kind of atmosphere.

Justin:
Opening information and sharing information are part of the hacker ethos that is endemic to blockchain.

But that certainly isn’t where TradFi is coming from.

Canton is a permissioned network.

Do you think that’s ultimately where this is heading? Will we have more dedicated blockchains specifically for giant companies?

Dingo:
Yes and no.

By the nature of institutions adopting this technology and paying close attention to it, we’re going to see more closed-loop, permissioned blockchains than we have before.

We haven’t really seen much of that previously.

But I don’t think permissioned systems are going to overtake permissionless systems in terms of total user activity or attention within crypto.

Justin:
One of my favorite things about attending a show is the blink test.

You can walk in and immediately see what is popular that year.

I remember when NFTs were huge. You would walk into a conference hall and be hit in the face with NFTs.

Real-world assets were obviously one of the major themes. Anything involving a crossover with TradFi and stablecoins also appeared to be huge this year.

Were there any other narratives that stood out as being very visible when you walked the floor?

Dingo:
Yield and RWAs came up frequently in conversations.

It definitely felt like a more mature conference.

Anyone who has attended a variety of blockchain conferences over the years will tell you that the experience depends on where you go.

EthCC definitely leans more toward use cases and less toward memecoin culture.

This year, you saw a lot of people asking how we actually integrate this technology now that we’ve caught the proverbial squirrel.

By that, I mean we finally got the attention of TradFi and institutions.

Justin:
We’re bona fide now. We’ve been validated.

Dingo:
Exactly.

We finally received the attention we were looking for, which is surreal on one hand.

On the other hand, it raises important questions.

How do we maintain our integrity going forward?

How do we bring meaningful changes to existing systems?

Personally, I don’t want this to become nothing more than a back end for the system we already have.

I’m speaking for myself, but I think a lot of people in DeFi share that sentiment.

How do we evolve crypto in a way that updates the current financial infrastructure and makes it more open, welcoming and permissionless?

Obviously, I can’t paint over a multi-trillion-dollar system with one broad brush.

There are use cases for closed, permissioned systems and permissionless systems.

That was a conversation a lot of people were having at EthCC.

Justin:
Overall, it sounds like the conference—and the industry it represents—is moving more toward fundamentals.

It’s less about making a thousand times your investment and more about real use cases.

Dingo:
Right. That was the sense I got as well.

Justin:
What was your favorite quote, moment or presentation?

What were your key takeaways from being on the ground for everyone listening who didn’t have the opportunity to go to Cannes?

Dingo:
I wouldn’t say there was one specific standout moment.

It was more the culmination of the entire experience.

It’s easy, when you look at crypto Twitter every day and absorb all that information, to become dissatisfied with the current state of the market.

There are a lot of existential questions being raised.

Will we be able to hold on to our industry?

Will we simply be absorbed by the Goliath of TradFi without having much say?

Are we coming from such a disadvantaged position, with the midterms approaching, that we’ll accept any concession we can get from regulators even if it is dramatically unfavorable?

Could we lose a lot of what matters in this space?

Being at the conference, speaking with people and hearing how often RWAs came up was encouraging.

People were very curious about what we’re doing with Saffron, yield and structuring products in ways that can appeal to institutions, retail users and everyone in between.

It filled me with what I believe the kids call copium or hopium.

Justin:
Not without reason.

I remember when Sai first described Saffron to me. My first reaction was that it was very on-trend.

This is a good time for it. People are very interested in yield and in something more reliable.

Were there any memorable moments from the actual conference that you wanted to share?

Dingo:
The entire experience was memorable.

I met with a lot of people. I can’t go into too many details, but the whole conference stood out as an opportunity to network and remind ourselves that, despite the market downturn and uncertainty, people are still building really cool things.

The enthusiasm for RWAs and yield products is real.

There are a lot of interested people on the sidelines waiting to participate once the regulatory framework is in place.

That’s probably as much as I can say.

Justin:
Let’s take a few minutes to talk about one of the other major stories from the past week: trends in RWAs.

We’ve been hearing about them all year. They’ve remained one of the top three narratives, and it’s something I follow closely because I’m on the news side of things.

Pharos raised $44 million in Series A funding and is moving toward a valuation of approximately $1 billion to build institutional tokenization rails.

It is backed by firms such as Sumitomo, Chainlink and Flow Traders, and it is talking about bridging $50 trillion in assets on-chain.

That’s massively ambitious.

In the same week, South Korea moved to regulate tokenized assets under existing financial law. However, it is not as friendly toward RWAs that bear yield.

What’s your feeling about that, Dingo?

Do you think South Korea is setting any trend that might be reflected in the U.S.?

Dingo:
Yield on stablecoins is one topic, and yield on RWAs is another.

I wouldn’t say the U.S. is necessarily looking to South Korea for guidance on that subject.

There are commonalities with stablecoin yield because, at the end of the day, that introduces direct competition with banks.

Taking away their monopoly on yield-bearing dollar products would create a great deal of competition.

That isn’t something banks are likely to view favorably.

Yield on RWAs is a different conversation entirely.

I’m following the South Korean news closely and watching how it develops, but I wouldn’t say that what happens there is necessarily a direct preview of what will happen in the U.S.

Justin:
That brings up an interesting point.

Depending on whom you ask and in what context, the U.S. is supposedly a free-market system based on meritocracy and Darwinism, where the best ideas win.

Then it becomes, “No, don’t compete with us using a better product because that could cause us to lose money.”

RWAs have been extremely popular.

The amount of tokenized assets actually on-chain is around $468 billion, and approximately $441 billion of that sits inside permissioned institutional systems such as Canton and Provenance.

Most on-chain finance isn’t actually open. It’s TradFi using blockchain inside controlled environments.

It will be interesting to see where that goes.

At the same time, we do want their involvement. I suppose it was naive to think TradFi wouldn’t fundamentally change us when it entered our system.

Another thing worth noting is that Solana passed $2 billion in tokenized equities, showing real demand for access to stocks such as Tesla and Nvidia outside the U.S.

Binance is pushing further into RWAs. Its perpetual futures reportedly account for 20% of COMEX silver volume, with around-the-clock trading and up to 100-times leverage.

How close are we to finding a balance where we can work with TradFi and reach people outside our space?

Our space is still very small compared with the larger investing world.

Are we as close as we think, or do you have reservations because so much of that value is locked inside closed systems?

Dingo:
We’re closer than we’ve ever been, but we’re not particularly close to the finish line.

The majority of tokenized value does sit inside permissioned networks. That’s something you can’t ignore.

My view is that if an on-chain asset ultimately depends on an issuer, custodian or legal wrapper, then the risk hasn’t fundamentally changed.

You’re repackaging it and putting it on-chain.

There are benefits to doing that, including faster settlement times and broader global access to a certain degree.

But we’re still a long way from true, trustless ownership of many of these assets.

Right now, it seems to be trending toward a faster version of the old system.

A lot is still up in the air, and there’s room for innovation and new ways to bridge that gap.

We’re closer than ever, but I also think we’re slightly off course from where we need to go.

TradFi currently has the reins and is running the ball toward the end zone.

I’m going to continue this sports analogy until the wheels fall off.

But the clock hasn’t run out yet.

There is still room for us to demonstrate the value and importance of having more open, permissionless systems for RWAs and making sure they remain consistent with the ethos of DeFi.

Justin:
One final question about RWAs.

Are we simply reproducing a faster and more efficient version of what already exists in TradFi, or is something genuinely new happening?

If something new is happening, how would you describe it?

Dingo:
A lot of new things are beginning to happen, and I think Saffron Vaults are one example.

With Saffron’s Uniswap vaults, you can take tokenized assets and gain access to a structured-yield protocol that you would not normally have access to.

It is somewhat analogous to a reverse zero-coupon swap in traditional finance.

The overwhelming majority of retail users cannot get direct exposure to an instrument like that through TradFi.

They may receive second- or third-order exposure to it, but there is nothing in traditional finance that allows a retail user to do exactly what they can do with Saffron Vaults and potentially tokenized stocks.

These new use cases and tools, which were previously available only to a select group within traditional finance, will make the case that this is not simply a repackaged or on-chain version of an old system.

I think we’ll see many more instruments and tools like Saffron integrated into this new environment.

That will make the case for why bringing these assets on-chain represents a genuine evolution beyond what we used to see in TradFi.

Justin:
That’s a great way to move into any updates for Saffron that we want to mention.

Dingo:
We recently completed the first official audit for the Saffron Solana vaults.

That brings our total audit count across Saffron’s upcoming fixed-yield products to 10.

Nine of those are for EVM products, and one is for Solana, with more to come.

We’re continuing to conduct extensive internal stress testing and gather as much data as possible.

We’re also creating more promotional materials and preparing to hit the ground running when we’re ready to release everything.

Justin:
Promotional and educational materials.

Dingo:
Exactly.

Justin:
The audience will be reassured to know that there is this much activity and building happening behind the scenes.

It’s inspiring, and it’s a great project to work with.

We look forward to seeing what else comes out.

I’m particularly interested in communicating all of this clearly so people understand how to use the vaults when they launch.

Thank you so much, Dingo. Thanks for taking the time to talk with me today. It’s been great catching up with you.

Dingo:
Absolutely.

To emphasize that last point, education is very important to us.

People got a sense of that when we did Saffron Academy in 2021.

Going forward into this new era of Saffron, we’re going to be introducing a lot of new information and concepts.

For people who haven’t followed every step of the way, there will be a great deal to take in and understand.

We’re preparing a full suite of educational tools to help facilitate that process.

We want the average retail user, crypto user or DeFi user to be able to come in, interact with these tools and get the most out of them.

We’re really excited and looking forward to that future.

Thank you, Justin.

Justin:
Thank you, Dingo.

I always look forward to catching up with you and doing these shows.

It’s good to have you back in the States, and we’ll talk to you soon.

Dingo:
Absolutely. We’ll talk soon. Take it easy.

Justin:
Thank you to everyone for tuning in.

We’re going to close it there. Take care of yourselves, as always, and we’ll talk to you again next week.

Peace.

Dingo:
All right. See you.