Is DYOR Dead? Building a Safer Web3 with Alex Katz
Friday, 14 November 2025 · 2 min read · Listen to the episode ↗
The podcast highlights the critical security vulnerabilities in the crypto landscape, particularly the risks associated with storing assets on mobile devices. Alex Katz critiques the ineffective DYOR approach, advocating for automated protections against scams and the development of a crypto antivirus to safeguard sensitive data. Additionally, the discussion emphasizes the need for standardized security protocols in smart contracts and the importance of enhancing wallet security in the evolving Web3 environment.
A significant vulnerability on Android phones has been identified, allowing unauthorized applications to access sensitive information like seed phrases and private keys. Users are advised against storing significant assets on mobile devices due to the heightened risk of theft. Alex Katz, CEO of Kerberos, highlights the chaotic nature of the crypto landscape, where recovery of lost or stolen assets is nearly impossible, unlike traditional banking. He emphasizes the need for increased accountability and enforcement to protect users from scams and exploits, which are exacerbated by insufficient prosecution of bad actors.
The podcast discusses the lack of standardized procedures for smart contract security, contrasting it with established ISO standards in construction. This inconsistency leads to vulnerabilities, as companies vary widely in their investment in auditing. Kerberos aims to enhance user protection against hacked websites, boasting zero user losses over nearly three years, but recognizes the need for growth to safeguard a larger segment of the Web3 market. Katz argues that "Do Your Own Research" (DYOR) is inadequate for understanding smart contract risks, advocating for automated protection instead.
Kerberos is developing a crypto antivirus to protect seed phrases and private keys, functioning as a browser extension that analyzes transactions for potential malicious activity. The podcast also highlights the importance of address protection in Web3, with an extension that hashes copied addresses to prevent address poisoning while prioritizing user privacy. Challenges in security are increasing, particularly with AI-driven phishing scams and deep fakes, necessitating unique code words for verification and education for vulnerable populations.
A philosophical debate arises around user autonomy versus protection in Web3, emphasizing that user education alone is insufficient. The discussion addresses the challenges of scam detection, particularly the issue of false positives, which can erode trust in detection software. The future of wallet security is compared to antivirus software, with expectations for built-in protection in wallets, though skepticism remains about regulatory impacts on non-custodial wallets.
Concerns about bad actors exploiting vulnerabilities in crypto highlight the need for prioritizing wallet security. The Kerberos Initiative at Token 2049 aims to create a safe, self-custodial Web3 experience. Attracting new users remains a challenge due to perceived risks, underscoring the necessity for improved security measures. The podcast concludes with a discussion on the underutilization of hardware wallets, which are essential for protecting against malware. Speaker 1 shares a personal experience of losing money in crypto, cautioning that anyone can fall victim to scams and stressing the importance of security. They advise against using crypto on mobile devices and recommend utilizing hardware wallets for valuable assets.
This summary was generated from the episode transcript and can contain mistakes.