
The Breakdown How Crypto Is Fighting Back Against North Korea | The Breakdown
4 snips
Apr 28, 2026 Nick Bax, a blockchain investigator and SEAL 911 incident responder, explains how DeFi is under attack from sophisticated actors. He outlines the shift from SIM swaps to remote access and social engineering. He covers multisig failures, AI’s role in speeding attacks, North Korean operatives using rented identities, and what it takes to become an on-chain investigator.
AI Snips
Chapters
Transcript
Episode notes
Old Vulnerabilities Fade But New Ones Replace Them
- Older attack classes like SIM swap faded after industry fixes and reduced SMS 2FA use, but new vectors replaced them.
- Nick notes attackers now aim for remote access to developer machines to compromise multisig signers.
Harden Multisig Signers With Endpoint Protection
- Harden signers' endpoints with proper EDR and follow evolving multisig best-practices to reduce remote compromise odds.
- SEAL publishes frameworks and updates them after each incident to include practical mitigations attackers bypassed.
AI Speeds Both Attackers And Responders
- AI accelerates both attacks and defenses, currently giving attackers speed advantages but promising longer-term defensive benefits.
- Nick says AI automates tasks like payload creation and analysis, making incident response more time-pressured now.

