{
  "episodeId": "SLP761",
  "speakers": {
    "stephan": {
      "name": "Stephan Livera",
      "role": "host",
      "tag": "STEPHAN"
    },
    "nick_neuman": {
      "name": "Nick Neuman",
      "role": "guest",
      "tag": "NICK"
    }
  },
  "segments": [
    {
      "speaker": "stephan",
      "time": "00:00",
      "start": 0.0,
      "text": "Hi everyone, welcome back to Stephan Livera podcast. Rejoining me on the show today is Nick Neuman, CEO and co-founder of Casa. Welcome back to the show, Nick. Hey, Stephan, glad to be back. So obviously the coldcard thing is the big topical thing that is on everyone's minds right now. Give us your kind of initial reaction to that. Obviously, I presume you must be really busy now, having a lot of people migrating or onboarding to Casa. Yeah, I mean"
    },
    {
      "speaker": "nick_neuman",
      "time": "00:27",
      "start": 27.0,
      "text": "It has been a really busy last week with helping people to get off of cold card single sig and into some form of multisig to make sure that their assets are secure. And the team has been, I mean, really working around the clock, getting on calls with people, whether they're Casa clients or not, to try and help people. and that's, it's been amazing to see. so That's like, like seeing our team come together, seeing the community come together to help people has been pretty amazing. and then on the flip side, that this happened in the first place is, you know, really terrible. And so, it's definitely a, a difficult moment, especially for the people that lost their assets, and we feel really sorry for them. But for the rest of the people, we're really trying to help them to get to a safe spot And then for the people who lost their assets, hopefully they'll be able to, you know, I've seen a few people talking about, \"Okay, I'm, I'm gonna rebuild from here,\" and I think that's, the right attitude."
    },
    {
      "speaker": "stephan",
      "time": "01:33",
      "start": 93.0,
      "text": "Yeah. In terms of, I guess what you've seen from, let's say existing Casa clients, I guess for some of them, they may have a multisig with you already, but coldcard may be in their quorum. So then I guess for them, it's a matter of rotating that specific key out of the quorum to put another key in, right? Yeah."
    },
    {
      "speaker": "nick_neuman",
      "time": "01:49",
      "start": 109.0,
      "text": "So we have varying, we have different advice depending on people's situations. Luckily, the Casa default, you know, security advice is you shouldn't have a quorum of keys that are held by the same hardware manufacturer in your multisig. And so there were very, very few people, like you can probably count it on one hand in our entire client base that had, Like they were in a vulnerable position of like three of five or two of three or something where a cold card. Like they've got three cold cards and a three of five or something like that. But the, most people, you know, maybe they had one, maybe they had two. And so in that scenario, we, our advice has been, hey, we're gonna help you rotate this cold card out, switch it for a different hardware wallet. You're not in danger right now. And, but it's, it's best practice, like you're effectively one key down Change that key over to something that's healthy."
    },
    {
      "speaker": "stephan",
      "time": "02:52",
      "start": 172.0,
      "text": "I see, yeah. And I guess the broader conversations are being had now, people are saying, you know, on some, on some hand, you're seeing, on one hand, you're seeing people say, \"No, it's the end of self-custody,\" other people are kind of going more to the, let's say, the multisig pathway and saying, \"Hey, the, the answer is multisig multi-vendor.\" how do you see that? It's definitely"
    },
    {
      "speaker": "nick_neuman",
      "time": "03:12",
      "start": 192.0,
      "text": "not the end of self-custody. I, I mean, that's going to be a sentiment for a while, right? And so, I think we as an industry, and we're, we're thinking about this a lot at Casa, really have to seize this moment to help shape that narrative going forward, where it's like, \"This isn't the end of self-custody,\" because if you, if you think about this, like- This wasn't really a vulnerability that was caused by self-custody. This vulnerability came about because, we- As a, as a community, as people who bought cold cards, trusted that CoinKite, the security experts, had properly coded the firmware for cold card in order for, to make it secure. And if you think about what actually failed here, it was that, it was that the developers of this product didn't properly develop it so that it was secure. This same thing can unfortunately happen at exchanges. or custodians, just in a much bigger way. If they mess up, they have actually a, a larger honey pot sitting there that can be compromised. And so you have to-- it's more about, who are the people, either one, that you are putting your trust in to have developed this thing properly as security experts, or two, are you doing something that makes it so that you can reduce the amount of trust that you're having to put in anyone? party. And this is where I think we really need to help push our community towards this type of thinking, because this is the way that we help self-custody continue to be a thing going forward, is you make sure that you don't have to trust any one party Completely to have done a good job with developing their product in a secure way, you can actually distribute your trust across many different parties who have developed their own products and then use those products as checks on each other and as different layers of defense in your overall security setup."
    },
    {
      "speaker": "stephan",
      "time": "05:23",
      "start": 323.0,
      "text": "Right, and as you and listeners know, I've long been a big fan of multisig since, you know, my episode seven years ago with Michael Flaxman, where we spoke a lot about this, this kind of idea, which was a great episode. Well, thank you. Yeah. but look, the common pushback was multisig is complex, and if you go with a guided provider such as yourselves or, you know, Unchained or Bitkey or whoever else is out there, there's perhaps a privacy trade-off. Those have probably been the main two pushbacks. Look, we, you know, we're okay with multisig, but we think for most people, passphrase is an answer. Or if you talk to different consultants, they will say, \"No, single sig and passphrase is the way.\" So I guess for you, probably the main two pushbacks that I-- that I see are complexity and privacy trade-offs of using- A guided solution. So how do you, address those?"
    },
    {
      "speaker": "nick_neuman",
      "time": "06:14",
      "start": 374.0,
      "text": "I think that on the complexity side, you know, you really have to compare it to what you have to do to get a secure single sig, right? Because You know, we've always, we've dealt and dealt with and heard this complexity argument for many years as well, like, \"Oh, multisig's too complex, single sig is fine.\" And then we see that, hey, most people who are doing single sig are just doing the default setup. They don't have a passphrase, they aren't rolling dice, and so they've got, they're kind of fully putting their trust into the single sig manufacturer to have done their job right. And Let's say you're like, \"Alright, no, fine, I understand that, so I'll do the-- We should, we should, the new advice should be, you should have a passphrase, or you should roll dice.\" okay, on the passphrase front, you know, the passphrase is often called the twenty-fifth word. And so people are like, \"Oh, I just need to add one more word to my seed phrase, and I'm good.\" Nope, turns out that's not good enough. Turns out you need like eight words in your passphrase. Okay. So now you gotta save this passphrase somewhere along with your seed phrase, and if you lose either part of it, you've lost all your Bitcoin. So This is confusing for people because a lot of people hear the term passphrase and they're thinking password, and so they're like, \"Oh, well, if I forget this, I just, I just hit the forgot password button, I reset it, and I'll be able to get back into my wallet.\" No, turns out the passphrase is like part of the cryptographic search space for your Bitcoin along with your seed phrase, and if you forget it or mess that up, all your money's gone. Then you've got dice rolling, and the dice rolling is just gonna be a non-starter for the vast majority of people because they're like, \"What? You want me to buy casino dice? I have to make sure I'm buying the right type of dice, then I gotta roll the dice a hundred times, and it's doing some like magic thing that's somehow keeping me safe. Oh, and I gotta make sure that I trust that the entropy in the hardware wallet is properly handling the dice rolls 'cause they could have a bug. That's just ignoring my dice rolls and I wouldn't even know. And so I think that, like, this argument that there's too much complexity in a single sig is just completely ridiculous. You mean in a multi-sig? Oh yes, too much complexity in a multisig is just completely ridiculous when you compare it to what you have to do to have a truly secure single sig. And so, My argument against it is like, you could take, you could have a multisig with Casa or with Bitkey, where you have just the same one hardware wallet that you're dealing with, and then the other keys in the multisig are on your phone and held by the company that's actually providing this. It's incredibly simple, you don't have to, like, because of the additional security that just comes by default through the other keys in your multisig, you don't have to be doing all this extra mental- Processing power of like, oh, I gotta make sure I pick the right passphrase, and then I gotta, or I gotta do dice rolls. It's just like, the only way we're going to really bring self-custody to a huge amount of people is by making the default as secure as possible without them having to think about it. All they do is follow the instructions in the software, step by step, and boom, they're very secure. And so that's my rant on complexity, because- That's true."
    },
    {
      "speaker": "stephan",
      "time": "09:44",
      "start": 584.0,
      "text": "So now let's handle the privacy side of it, right? Because that is another trade-off that I've heard. Now, to be fair, it's not one size fits all, right? But the, the one complaint I've heard from people is, \"Hey, if you use Casa or another provider, they will know your coins.\""
    },
    {
      "speaker": "nick_neuman",
      "time": "09:57",
      "start": 597.0,
      "text": "Yeah. And that's true. So the way that we, for people that are worried about this with Casa, the way that we handle this is we, you can sign up for Casa anonymously. You can use an email that doesn't-- we don't KYC. You can use an email that doesn't have your name in it, and even a special purpose like, like what I have been recommending to people is Proton, if you have, if you have a Proton mail address already. ProtonMail has a great alias feature where you just like hit one button and then it creates a special purpose email address for you that is anonymous and forwards every email that gets sent to it to your main inbox. So that way you don't miss emails from Casa, like we're sending emails to people with instructions about, hey, here's what you do with your cold card during this vulnerability. We don't want that going off to some inbox you never touch or, or look at. So you create an alias, it forwards emails to your main inbox. Still get important communications, but you have anonymity as to who you actually are. Then, so you use that email for your casa email, then you pay us in Bitcoin, because if you pay us with a credit card, you know, we use Stripe, they, they keep all the credit card information secure, but there is a connection there to like your credit card based real identity. So if you don't want that, you pay us in Bitcoin. And then when you're talk-- like if you're at one of our, plans where you're, working with our team So we have an advisory team that for our premium and private client members, they're actually talking to you, building a relationship with you, helping you with everything that you need. You can use a pseudonym with them. We have people that use pseudonyms all the time. And so w-we've really built Casa to enable your privacy if you want that, and this isn't something that you can get with every multisig company, but it's a, it's an important part of our DNA. So that's, you know, that's the a trade-off. But I think that for the people for whom it, they, they really care about this, being anonymous is one way to approach that. The other, last thing I'll say on this. Is, some of the other providers that you may be using with single-sig wallets might also have access to and be storing information about the coins that you're holding. So, I don't know this for sure, so I'm not trying to create fud, but like, it would be quite easy for Trezor or Ledger with their Trezor Suite and Ledger Live applications to be, you know, logging how much Bitcoin people use Those products have, because, they have to show you the balance somehow, and so it's running through their node on their server, they see your balance, then they're sending it back to you, and if they decide to keep that information, you would never really know. So the only way that you can be You know, as get as much certainty as possible that somebody isn't, like slurping your asset balances probably by running your own node on your computer using a, open source software that you trust as your wallet. And that comes with a lot of trade-offs when it comes to complexity and security."
    },
    {
      "speaker": "stephan",
      "time": "13:16",
      "start": 796.0,
      "text": "I see, yeah. And so, and even in the case of, you might need to initialize that hardware device without also, quote unquote, phoning home. And so there's only so many devices that offer that too. So that's like another level of-- So you gotta pick that specific kind of hardware device. There, there are various ones that have that. And then also make sure that at all times you're only ever connected to your own, let's say, your own Electrum server. And so it's already kind of raising the bar a lot technically for people,"
    },
    {
      "speaker": "nick_neuman",
      "time": "13:45",
      "start": 825.0,
      "text": "and I think For a lot of people, this just isn't worth it. Like, there were some peop-- there were some people, like American Hodl and maybe BitPay, they were tweeting these amazing tweets that were just like, \"I can't believe how caught up we all got in like this cold card thing where we were like...\" Oh, we've got this mega private device that you can shoot in case the government comes after you, and it's air-gapped, and I'm gonna plug it into a nine-volt battery for power to make sure that there's nothing in my power block that's like slurping information out of it, and it's like, oh, in the end, they had an entropy bug that borked everybody's seed phrase in the first place."
    },
    {
      "speaker": "stephan",
      "time": "14:26",
      "start": 866.0,
      "text": "Yeah, it's, it's a bit unfortunate. Obviously, that said though, if you were truly that paranoid, you probably were a dice roller, right? Like, it's, so it's kind of, you know, sometimes, sometimes. Yeah, if you're that paranoid, I think you probably would have also been a dice roller, and so then it's kind of, you know, but, but I, yeah, certainly in terms of, Security and kind of the general way I would say most people who are serious about security have been talking about this stuff, it's been like, yeah, multisig, and yes, there's been a kind of a perennial debate, you know, this kind of passphrase versus multisig and all this stuff, and, of course, I guess the other trade-off would just be also if you had to just go for like fully You know, open source software like Sparrow Wallet as an example, like the full DIY method. Okay, so the other question I think that might be interesting for people is to just think about what is quote-unquote good enough given your-- given a stack size, right? Like typically there's kind of like a rule of thumb people say, okay, start out with a phone wallet. I know you guys have a phone wallet also in your app, and then the idea is that you graduate up to, you know, up the levels. So in your view or in the Casa view, what does that"
    },
    {
      "speaker": "nick_neuman",
      "time": "15:37",
      "start": 937.0,
      "text": "Yeah, so, you know, this can change, it, it changes based on your personal situation, but if I'm just gonna give like flat dollar amounts for what I'd recommend, like generally I would say phone wallet is fine for, the same amount of cash that you would keep in your normal wallet walking around the street. And then you might wanna move to a single-sig hardware wallet by the time you've got like somewhere around a thousand dollars worth of Bitcoin And then you probably wanna move to a two of three multisig by the time you're getting to, if I'm being like honest, it's probably like around ten thousand dollars worth of Bitcoin. And, then I would move up to like a, a higher security than a two of three, that's like a three of five or, or something along those lines, once you're probably pushing like a few hundred thousand or more, maybe like five hundred K or more, And so this is, I think, a rule of thumb that is just like if I was doing this myself, this is probably how, how comfortable I would feel. But the Thing that you have to remember is like, you have to remember your personal financial situation too. So, let's say you've got seven thousand dollars on a single sig wallet, and this is your life savings. Maybe move that to a two of three multisig, okay? Like, don't, don't stick to the ten thousand dollar range just 'cause I said so on this podcast. Like, if this is something where if you lost this Bitcoin, it would be life altering for you in a very bad way, like get it into a multisig. You can, you can use a Casa multisig at our basic level for two hundred and fifty dollars a year, or you can set something up yourself, with, with a couple of different hardware wallets. And so-"
    },
    {
      "speaker": "stephan",
      "time": "17:32",
      "start": 1052.0,
      "text": "So let's talk about the tiers you guys have. So you have a like a, what's it called, Casa Standard, which is two hundred and fifty dollars, that's your two of three level, and then you have a premium level which is like the five key, three of five style. So talk us through like the price point there, for people."
    },
    {
      "speaker": "nick_neuman",
      "time": "17:49",
      "start": 1069.0,
      "text": "Yeah, so at, our standard level, it is a two of three multisig. You've got, this means you have three keys, and you need any two of those three keys to spend your Bitcoin. So, this is two hundred and fifty dollars a year, and we actually have a, a thirty day free trial for it as well. And so, we were telling people who had cold cards and needed to move quickly, like, just sign up for the free trial for this, connect your cold card, and move your assets into, into the multisig to get it safe, because once you You eliminate the vulnerability that it had with it, at least initially. So anyway, that's a two of three. It's very, it's very like self serve. And then as you go up to the higher plans, premium and private client, you can think of this as increasing in both security for, for your Bitcoin, but also for you as a person and service. So we have an entire client advisor team who works with all of our premium and private client members who are helping onboard you so that you set up everything correctly. We're doing regular check-ins with you to make sure that you are, your keys remain secure, you're, you're thinking about security properly, and everything's going well. We're even, you know, at the private client level, like working with your family as part of like inheritance planning and making sure that everybody has what they need in order to recover assets. That's in case there's a worst case scenario and you pass away. And so, we really bring a team of experts to our relationship with our clients, and we often hear from people at those plans that their favorite thing about Casa is the client advisors that they work with. at those plans, the security level is a three of five multisig, which means you have five total keys, one's on your phone, three are on hardware wallets, and one's held by Casa, and we'll send you a package when you sign up that has all the hardware and everything that you need."
    },
    {
      "speaker": "stephan",
      "time": "19:51",
      "start": 1191.0,
      "text": "Gotcha. And then the difference between the premium and the private client, what's the main difference there? Is it more like support around things like inheritance and things like that, or what is the difference?"
    },
    {
      "speaker": "nick_neuman",
      "time": "20:01",
      "start": 1201.0,
      "text": "Yeah, so it's, there's a, a few different things. I mean, one of the biggest ones is you have a dedicated client advisor who you, is like on you only, right? You're, whereas on a premium plan, you're kind of working with our pool of client advisors. And so we have our most senior client advisors working with our private clients. And we, you can text them on Signal anytime, questions, day or night. They can hop with, they have more availability to just hop on a quick call with you anytime you need it, when you need some help. We've got a private client community where all the Casa private clients get together, we, hold in-person events, we've got Signal group chats, all that kind of stuff. So that's all the kind of like softer, like human side of things of being a Casa private client. And then on the more like security side of things, we have the, a more advanced inheritance where your inheritance has a few extra checks in it to make sure that you are, have actually passed away. And then we also have a, Some other things that are like security related features or security related help. So like our client advisors will actually go through an audit with you, your cybersecurity around everything outside of Casa as well. So making sure that your phone is properly secured, your email addresses, all of your bank accounts, all these things like you, to make sure that you have top notch cybersecurity because this feeds directly into making sure that your Bitcoin is protected."
    },
    {
      "speaker": "stephan",
      "time": "21:43",
      "start": 1303.0,
      "text": "Gotcha. and then I guess, sort of more a common comparison might also be for people who are, let's say, comparing you with, let's say, Bitkey. So how would people who are trying to understand, should they go for Bitkey or should they go for you? What's the difference between those products?"
    },
    {
      "speaker": "nick_neuman",
      "time": "22:00",
      "start": 1320.0,
      "text": "Yeah, so I'm friends with the Bitkey team, I think Bitkey is a great product. I think the main differences are, when you use Bitkey, you are using Bitkey with Blocks app With Block software, and so they own the full stack, and so this lets them build a really great experience end to end, right? and so the-- it's a great product, great device, but you don't quite have the same layers of, like security from different providers that you can have with Casa, because with Casa you have many different providers, you know, Casa, Trezor, Ledger, Passport, Keystone, et cetera, et cetera. that all kind of come together in your Bitcoin security setup to make sure that your Bitcoin is secure, whereas with Bitkey, you're really relying on Block to have done their job well. That's the first part. Second one is with Bitkey, it is a two of three multisig, and they don't have the ability to go up to higher levels of security when it comes to the keys in the vault."
    },
    {
      "speaker": "stephan",
      "time": "23:05",
      "start": 1385.0,
      "text": "Gotcha, yeah. So those are the main differences. Now, a common, as we spoke about earlier, a lot of people will just be thinking, \"Oh, self-custody is too hard. They wanna go for, you know, the ETF or a custodian.\" or, and maybe they may see it like, they wanna, like, borrow against their ETF or they wanna do some of these other financial things, and for that reason they may go for custody. How, how does that work, with you guys? And I guess, to be fair, it may, it may not be all or nothing, right? Like there may be people who have like some stuff in their multisig in their casa or whatever self custody, and then some stuff In a custodian or with a, with a neobank, with a Bitcoin bank or something like this. Is that a common pattern that you have seen? Yeah, I mean,"
    },
    {
      "speaker": "nick_neuman",
      "time": "23:48",
      "start": 1428.0,
      "text": "I think we see it sometimes, and it's not I wouldn't say you're b-beeing an idiot if you were doing that, you know? Like, I think if you wanna have some in your cold storage self-custody that's really robust with Casa, and then you decide to have some in the ETF and some in, in an exchange or custodian or neobanks type setup, go for it. You know, it's, you're just think-- I think you would just think about like, what are the different security profiles that I'm trusting when it comes to where I'm putting my Bitcoin and how I'm storing it? I think like, as far as the \"Hey, self custody is too hard\" thing, you know, it would behoove me in my business to say, \"No, self custody is easy. Anybody can do it,\" and I will say I don't fully believe that today. We help a lot of people who really like would maybe struggle with self-custody, we do help them to do it, and we can help anybody to be secure, but there are some people who- Maybe they just decide it's not for them, and I'm not here to force that on them. But what I do think is that self custody is an incredible part, an incredibly important part of Bitcoin. It's also really important for, the world, right? Like, this is the first time that you can have true control of your digital money. So we're trying to figure out, always trying to figure out ways to make it easier and easier to do this while staying secure, because it's a, a thing we want to bring to the world, and we think that's important, and it's gonna take time. And where we are today is hard-- it's more difficult to use Casa than it will be, you know, a year from now. This is the most-- hopefully this is the most difficult Casa's ever gonna be to use. And then all the time we're getting, we're innovating and getting easier and easier and easier for people, and I hope that in the long term, all those people today who are like, \"No, self-custody is too hard,\" in the future we will have made enough changes and improved enough about self-custody in general that those people feel comfortable doing it, and the value they get from it, where they get the sovereignty and the freedom and the control, is worth it to them."
    },
    {
      "speaker": "stephan",
      "time": "26:08",
      "start": 1568.0,
      "text": "the other question I had was around, I guess AI and AI attacks, right? So we're seeing, obviously, people are saying the timing of this kind of lines up with Kimmy K3 for Coldcard and BOLT dot exchange, which is a well-known swap provider in Bitcoin, they've recently gone-- or at least, at least temporarily shut down because they were citing AI-assisted attacks, and just recently we saw Zeus also say, \"Hey, we're under--\" Some attacks, we need to either at least pause our LSP service. What does that mean for you guys? Do you, are you guys also gonna face AI assisted attacks?"
    },
    {
      "speaker": "nick_neuman",
      "time": "26:44",
      "start": 1604.0,
      "text": "I'm assuming we are facing AI assisted attacks or people attempting it, but we have built Casa to be very secure against that type of thing. And, you know, even in a worst case scenario where Casa, let's say Casa's server gets completely compromised, no user assets will be at risk in that scenario. scenario, because we pushed the actual security for the assets out to the edges. The security is, you know, held by our customers' keys, not by Casa's server. And so then we have to be very careful that like the providers that we rely on for those, for the security of those keys are actually secure, and this is where we had a problem with Coldcard. But then you've got the other hardware providers that people are using to, to provide security when Coldcard fails. That said, we're doing a, like, thinking about AI and security more generally, like, since Kimmy K three came out and since the, you know, the cold card problem about a week ago now, like, we've been hitting our code base extra hard to make sure that we're looking for any vulnerabilities or problems for our customers and getting those patched up 'cause security, and we haven't found anything that's a critical vulnerability, to be clear, but like, security is always- is an evolving game. You just constantly have to be checking, looking for holes, and then patching them before the, attackers get to them. And so one of the things that I think is kind of, kind of interesting from this, when you zoom out a bit, is like, one of the, the Things that people don't like about Casa is that we're closed source. And I think actually, in this ti- moment in time, being closed source is beneficial for you because it makes the visibility for attackers into your product and how to compromise it much more difficult. and so I think that we're seeing kind of around the Bitcoin industry right now that just be-- especially with Coldcard, just because its source code was available for anybody to look at doesn't mean that anybody audited it deeply enough to find this bug that was sitting there for five years. And so, The, the, the risk reward for open source might shift temporarily or, or even permanently in favor of being closed source in order to be more secure. That said, we've got people in the Bitcoin industry right now, like, Calais and Hamilton, going around and auditing all of the open source, code bases that are infrastructure in our industry and trying to make sure that they patch up any vulnerabilities there."
    },
    {
      "speaker": "stephan",
      "time": "29:30",
      "start": 1770.0,
      "text": "Yeah, so I wonder, what, what do you think it means outside of Casa? Do you think, y-you know, other Bitcoin industry participants are gonna struggle with the, AI attacks?"
    },
    {
      "speaker": "nick_neuman",
      "time": "29:43",
      "start": 1783.0,
      "text": "I think that in the short term, until they realize like, \"Hey, we need to be using AI as a defender just as much as the attackers are using it,\" in the short term they might struggle. And so that's where like some of those red team efforts that the community is doing are gonna help people, especially people that are on smaller teams or open source projects that have, you know, one guy maintaining them. But this is, it's really important for people- People to get started with, but the-- on the flip side, like, like yes, they might struggle with it, but we used to pay, you know, fifty to a hundred thousand dollars to do a third party security audit of our code base. And we'll continue to do that, but over the last week, as we've been hitting our code base super hard with some of the new, like Kimi K3 and some of those newer models, it's cost us like a thousand dollars to completely audit top to bottom our entire code base. And so just like the, these tools enable attackers to do, to more cheaply and more efficiently look for vulnerabilities, it lets the defenders do the same thing. And so I think this has to become a standard for All of the projects in the Bitcoin ecosystem or the maintainers are using AI security tooling to really evaluate their code in, in a robust way, and this, and this makes that more accessible."
    },
    {
      "speaker": "stephan",
      "time": "31:12",
      "start": 1872.0,
      "text": "Yeah, gotcha. And so, one other question around social engineering, like that's also going to become more and more of a thing, obviously deepfakes and all this kind of thing is also- Becoming a thing. So how are you thinking about addressing that kind of risk?"
    },
    {
      "speaker": "nick_neuman",
      "time": "31:27",
      "start": 1887.0,
      "text": "This is a huge-- This was a huge problem before the cold card thing. And then everybody needs to be careful because, social engineers love taking advantage of the fear created by these types of vulnerability situations, and we're already seeing tons of social engineering sites popping up around like- Coldcardvulnerability dot com, that kind of stuff, where you go there, they're like, \"Hey, your cold card's vulnerable, you need to put your seed phrase into this site so that, you can migrate to a safe wallet.\" Or people are gonna start getting phone calls from social engineers like, \"Hey, I'm gonna help you get your Bitcoin back, but you need to do this.\" Talking about this specific incident, saying, \"Hey, if you have a cold card, you need to move.\" And so we see, I mean, everybody who has ever purchased a ledger, potentially a Trezor, who has been in like Coinbase exchange data leaks and all the other exchanges about data leaks too, like All these people's, everybody's information is out there to be bought, so you should just expect that somebody has your phone number tied to the fact that you are a crypto owner, and they're gonna call you and try to trick you into stealing your money. And so, That's, that's kind of one way that they find out, the other is they just call everybody and say that your Google account is at risk, and then they get access to your Google account and start looking through your emails to see like, okay, they've got an account at this bank, Robinhood, Coinbase, now I'm just gonna start going down the list to try and trick them into sending me money out of these things. So Just always be skeptical of unknown numbers calling you. Turn on the setting on your phone that automatically rejects, unknown caller IDs, because that will save you ninety-nine percent of the headache of, of social engineering. And then, be very vigilant about what links you're clicking on and what websites you're going to, because with AI tooling, it's easier than ever for social engineers to make a website that looks legit. we've been working with our clients to really combat this at Casa, and because we've had, like, to be transparent about it, we've had instances where our clients have had their email compromised. The social engineer gets into their email and then looks, sees they're a Casa client 'cause they've received email, marketing emails from Casa or signature emails from Casa, whatever it is, and then calls them and says, \"Hey, it's Casa,\" and tries to trick them into sending them their money. And this isn't, this isn't a Casa specific thing. Every single crypto and self-cust- Bitcoin self-custody company has this happening to them right now. So we've been building things that make it- Easier for people to, to protect against this. We've got verification codes in the app, so anytime you talk to Casa, there's a code in your Casa app that rotates every few minutes, and you give them that code, they verify that you are who you say you are, actually a Casa user, and then you make them give, you their code, and that will verify that you're actually talking to Casa. And then the other thing that we just released actually is called Guardian Mode, and this is for our premium and Above members, but this is for people who want Casa to be required to sign every transaction that they send. And so if you turn that on, you, we, the Casa key will be required by Casa's software to sign every transaction, and so we'll always check to make sure that you're not like sending this under duress or something like"
    },
    {
      "speaker": "stephan",
      "time": "35:10",
      "start": 2110.0,
      "text": "that, right? Yeah. Yeah."
    },
    {
      "speaker": "nick_neuman",
      "time": "35:11",
      "start": 2111.0,
      "text": "Gotcha."
    },
    {
      "speaker": "stephan",
      "time": "35:12",
      "start": 2112.0,
      "text": "I see. And that would be,"
    },
    {
      "speaker": "nick_neuman",
      "time": "35:13",
      "start": 2113.0,
      "text": "on a video call or? Yeah, we do a, we do a video call to verify that you're not under duress. That you aren't being tricked by a social engineer, and then we have a delay before we sign the transaction."
    },
    {
      "speaker": "stephan",
      "time": "35:26",
      "start": 2126.0,
      "text": "Gotcha. Well, look, I think that's all we have time for, but, it's a, it's a time for, you know, many people in Bitcoin to be thinking about self-custody and what does it mean, and, you know, like as, as we mentioned before, there's no one size fits all answer, but, certainly an interesting, product and service you guys are offering. listeners And, you can follow Nick on X at nneuman. Nick, thanks for joining me today."
    },
    {
      "speaker": "nick_neuman",
      "time": "35:55",
      "start": 2155.0,
      "text": "Thank you, Stephan, and, and for anybody who needs assistance with moving out of Coldcard SingleSig, even if it's not to Casa, you can book time with our team on our site and, and we'll help you out."
    },
    {
      "speaker": "stephan",
      "time": "36:07",
      "start": 2167.0,
      "text": "Next"
    },
    {
      "speaker": "nick_neuman",
      "time": "36:07",
      "start": 2167.0,
      "text": "one. Thanks, Nick. Thank you."
    }
  ]
}
