Transcript
this whole meme world thing. I'm really excited for everybody to see it, but they're also just
really good guys. So how do I really good time with them? And based in Korea as well, Korean team.
Korean team. Homegrown. Sick. Awesome. And you can slowly feel everyone start to get
doge-pilled. I mean, absolutely massive announcement. Yes, they were covered by all major news outlets
organically as well. So that was pretty cool to see Dogecoin in the headlines. We've got Kowshi
about integrating Dogecoin as well into their platform. They've got regulated products too.
Yeah, we're in the news. DogeOS is in the news. Our testnet is in the news. It's going, man.
The momentum's there. I can feel it. Yeah, it's going to get so many messages in the past.
I guess 24 hours now about it. Yeah, cheers for all the nice messages everyone.
It's been a wild ride up into this point, but the momentum is for sure snowballing.
You're building. So let's kick this thing off. We've got some great teams up here.
We have both Noah and Fio to my favorite teams on DogeOS. Fio being an audit team, but they have
this really awesome AI audit tool. If you guys want to introduce yourself, I'll let Noah start.
GMDM guys, how's it going? Thanks for having us.
Well, man. Thanks for being here.
Congrats on Doge being all over my timeline as well for the past 24 hours.
Cheers to you guys for being involved. I mean, we did give you a shout out in spaces yesterday.
We've had some lead up to this conversation, but tell everyone what's going on and why Doge.
Yep. Yep. Yep. Yep. Yep. Yep. Excited. Like Super Bullish on Doge altogether.
I remember speaking to Hof last year at Abu Dhabi as well, telling them all about the vision of Noah.
And I loved the whole idea behind DogeOS, the app layer, and it was like the perfect synergy for us
to be honest. So I'll just give you like a brief intro on what we're building at Noah. So Noah's
AI powered no code tool to build fully functional on chain applications. So you as a user can come on
board, type out your idea in plain English. And what Noah would do is build a beautiful front-end
website for you. Build the custom smart contracts for you as well. Run multiple test cases, edge cases,
pass all of them. Make sure does not have any bugs and then deploy it to DevNet and then attach it
to the front-end. So you as a user, you don't have any complexity as such. So you're waiting for, let's say,
10 to 15 minutes depending on how complex your idea is. And you'll get an almost production
ready depth with just a few prompts. So that's something that we've been building and we were chatting
with Hof last year about this. And I think it aligns pretty well with DogeOS, you know, narrative
altogether, like app layers and like Noah's here to build more applications and help out even
non-technical people build out their ideas specifically on Doge.
Yeah, man, glad to have you. I gave you guys a shout out yesterday in our big test and announcement
space, you know, trying to bring on really good tooling to help people build, especially Doge
community. And I think Noah's some of the best out there. Fio team, you guys want to introduce
yourselves? I'm Yara. I'm Tammy. I'm speaking under the Fio, the Fio little fishy banner. We used to
do a lot of anti-fishing stuff, but we we we kept our masks out anyway, because we liked him.
I'm Tammy. I am the one of the co-founders at Fio. I'm here with Thomas, who is also going to be
speaking today under the handle's shortened. Thomas is from Sweden. Fio stands for four-year-rise
only and we have been a security company pretty much since the dawn of Web 3. Like I'm not joking.
We've been doing this for a really long time. So long that Thomas still remembers doing a doing a
threat model with Anatoli when Solana was launching. So that's how long we've been doing this. And
we've been watching with great interest as vibe coding becomes so ubiquitous. And we've been trying
to answer it with our own our own AI to make sure that as we as everyone continues to build and
build more quickly, we can give people tools to build more securely. Nice.
And Fio is a team that I've worked with in the past multiple times on past projects. And so
strong endorsement for me. How did you doge pill them? What's the story behind that?
How does the story Fio? Yeah, yeah, let's see. This is pretty OG.
I had a relationship. So you know, I just I hit up my friend Tammy and I was like, you know, I'm
I'm a dojo s now. And we got to get audits going on dojo s. And then you know, they built this
incredible audit tool that I'm sure they'll talk about. And Tammy and team have been nice enough
to extend credits to all dojo s builders. So I'll let you get to that. But this was an easy one,
man. Established trust over a long period. And we're we're I mean, I we're working on on an audit
right now with you. So I mean, we're we're we're actively working working on audit. So
I actually based on that first second. We like to get in there. Yeah, we like to get in there
and audit, you know, at the at the top level. And then then we build out to all the projects that
are that are building on it. You want to give the community like a little bit of a background on
like how important and an audit is in today's landscape, especially in in DeFi protocols. But for a
you know, zero knowledge blockchain and what's like an outline of the process and yeah, I've
lot to hear it from just like a developer to or heavy tech minded person to just the community
to put it out there. That would be Thomas. Is he sure? Yeah, hi. Thanks for having me and great
congratulations on the test network. So looking forward to actually started testing some stuff.
So that's great that we're finally there. And yeah, I mean, I've been in this game for a very
long time. And as you will we a couple of years ago, I guess everyone saw the headlines that there
was a lot of lots of funds happening for various attacks. And the reason why and audit is important,
it's super important. Even more now, I guess, when everything is by coded that you actually find
and there is a paper. I'm not sure if time if you can share the link, which is quite funny,
which I'm starting to talk about with a lot of developers. It's a small paper that actually proves
that the number of abilities you can have in code is infinite because every time you add a line
with code to fix a problem, what that does is that that also interviews another potential hole
and the more potential holes you patch with more lines of code, the more potential holes you will get.
And we are now at the time and place in in in software development where AI actually finds more bugs
than humans. We are now even with our our small AI platform is actually finding more bugs per hour
for sure than we did a year ago and more bugs than any of our manual auditors found a year ago.
So this is now a point of if AI finds more bugs than humans and AI also writes the code,
unless you ask AI to find the bugs, you are going to go in with having more holes. And
since we know now know that the number of vulnerabilities in any platform is infinite. That's
a really hard thing to grasp because you can't have more bugs than lines of code really. But
given if AI keeps becoming more and more super intelligent, there is still every time an AI gets more
smart, there will be new shamed vulnerabilities that could happen. And that's why we've seen a lot of
I mean the loss of funds that we saw a couple of years ago were really easy. Second thing in all that
is important for is you have a lot of third party libraries, right? So regardless if you're a small
contract, you normally depend on a lot of third party libraries. And that's where we also seen a lot
than a lot of these loss of funds happening that you have a package that you pen on bug and hijacked
and they install something that changes the execution path of your contract or your front of
the application and basically train your funds. So I would say all the things has become more
important now. And AI models are good and they're becoming better. And basically our idea with this
is that on on big project, obviously, we still do manual code audits, but even our manual code audits
we're using more and more AI and to find the bugs quicker, if that makes sense.
So and the reason we still have to charge many many days, even with AI, is that an attacker,
we need to find all the bugs. We need to find all the potential holes in your contract.
And the attacker that drain user funds only have to find one. And if we have an attacker with
their super strong AI that only finds one, we are not going to be popular as all of this. So we have
to do a super thorough job on all this now, even with all the AI tools that we have. It's always a
red queen problem where the attacker always moves quicker because they only need to find one issue
and we need to find all of them. Does that make sense? That was a long, long winding explanation
what we're doing. But yeah, it makes a lot of sense. And I think especially for an ecosystem
that has a lot of protocols building on top, it makes sense to do some sort of like
have some sort of scalable products to be able for ecosystem users to be able to use and interact
with because we know audits are quite heavy and workload and quite expensive. So thank you guys
for being part of the ecosystem. I got a question for you, Thomas, like I should hear.
And I want to move over to no in a second because we've been talking about it a five-hour cut. I
always say a five-hour cut with you guys for a minute here. But what do you think about the
risk now of AI hacks and like it's which do you think is advancing more quickly, like the risk of AI
hacks or the benefit of AI security and sort of follow up question there is like do you think that
there's more of a need in the future for sort of like active risk-boddering protocols like a
hypernative or whatever sort of thing like that? Great questions. And I actually, I've been doing
a lot of research on especially the Chinese up-and-source models which we are facing our scanners on.
And I mean GLM5, three now and all the new models that were coming out are actually stronger. You
guys remember Mythos a year ago, like oh no it's so strong, we can't release it. We have to block it
between cyber. The problem is now, now the Chinese models do have all that capability without being
blocked behind some cyber gateway so people can't use it. So there is now a real quantifiable risk
of AI hacker attacks that is increasing. And the problem with the American closed source from
year models is that I have access to them because I work with security. So I'm trusted enough,
I've been speaking at big conferences. So I have the cyber security unlocked models from both
anthropic and open AI but normal people don't have that. So currently unfortunately, it's in the
attackers' favor because they have the new uncensored Chinese models which are actually better at
finding bugs than Mythos was when it was released. Do you think it's also better finding flaws though?
Yes to some extent. There's everything's a double edge sort here right?
Yeah and I mean, availability, yes to quantify that, availability is a flaw that can be used to gain
something. That's how I define availability. So it is better at finding these stuff and make them
exploitable. So I think there is some of my peers in this security we're actually talking about
them both in MacGethan where there are so many vulnerabilities that it's going to get hard to actually
patch them on time. So I think that's also super important with Web 3 and where we're going and
segue into NOAA as well because we're talking to NOAA actually to actually integrate with NOAA to
have our audit agents work together with their building agent at machine time. And I think
that's the future because if you develop fast and the attackers are finding ways to attack it fast,
you need to audit fast, you can't have an audit at the end of the project and say oh,
oh, availability. And then a new attack comes out the next day, the agents need to be super agile
that actually audits. So that's where we're actually talking to NOAA about integrating the platform so
that NOAA's platform for building the smart contracts and the whole Web 3 apps is actually
more or less real time audited with our agents. Yeah, that's like I made the connection
wanting you guys to do that. So yeah, who's behind the NOAA mic by the way?