1
00:00:12,440 --> 00:00:14,920
Hi, everyone. 
This is Lindsay O'Donnell Welch 

2
00:00:14,920 --> 00:00:17,840
with Decipher. 
And I'm here today with Arie Red

3
00:00:17,840 --> 00:00:21,880
Board, the Global Head of Policy
at TRM Labs. 

4
00:00:22,040 --> 00:00:24,480
Arie, how are you doing today? 
I am great, Lindsay. 

5
00:00:24,480 --> 00:00:26,720
Thank you so much for having me 
and really looking forward to 

6
00:00:26,720 --> 00:00:29,840
the conversation today. 
Yeah, Thank you so much for 

7
00:00:29,840 --> 00:00:31,880
coming on. 
And you know, we're going to 

8
00:00:31,880 --> 00:00:36,240
talk today about something that 
honestly, I don't know too much 

9
00:00:36,240 --> 00:00:39,480
about, which is the overlap 
between cybercrime and 

10
00:00:39,480 --> 00:00:41,840
cryptocurrency. 
And it's, it's a really, really 

11
00:00:41,840 --> 00:00:45,640
fascinating subject. 
But I was looking at TRM Labs 

12
00:00:45,640 --> 00:00:49,040
website last night and there 
were just a lot of terms that 

13
00:00:49,040 --> 00:00:53,640
kind of lost me like wallet 
screening or like in the 2026 

14
00:00:53,640 --> 00:00:56,400
crypto crime report you guys 
released earlier this year, like

15
00:00:56,960 --> 00:01:02,040
a 7A5 tokens, things like that. 
So I really want to, you know, 

16
00:01:02,040 --> 00:01:05,680
hear from you on all these 
different terms and like get 

17
00:01:05,680 --> 00:01:08,720
into this. 
But first, can you tell me a 

18
00:01:08,720 --> 00:01:12,800
little bit about how you 
specifically got into this space

19
00:01:12,800 --> 00:01:15,760
and specifically with crypto? 
Absolutely. 

20
00:01:16,320 --> 00:01:17,400
Yeah. 
Well, I'm glad that you're 

21
00:01:17,400 --> 00:01:20,080
struggling with that stuff 
because that is 1 area where I 

22
00:01:20,080 --> 00:01:22,200
could be helpful. 
My wife I think gives me a hard 

23
00:01:22,200 --> 00:01:23,160
time. 
She says that I don't know 

24
00:01:23,160 --> 00:01:25,840
anything other than about 
anything other than that stuff 

25
00:01:25,840 --> 00:01:28,840
anymore. 
You know, sports, politics, it's

26
00:01:28,840 --> 00:01:31,360
just like all crypto crime all 
the time. 

27
00:01:32,400 --> 00:01:35,560
But by way of really quick 
background, Harry Redboard on 

28
00:01:35,560 --> 00:01:40,160
the global head of policy at TRM
Labs, Prior to joining TRMI, 

29
00:01:40,160 --> 00:01:42,720
spent about 11 years as a 
federal prosecutor at the US 

30
00:01:42,720 --> 00:01:45,240
Department of Justice. 
And I really spent most of that 

31
00:01:45,240 --> 00:01:48,160
time at the intersection of 
money laundering and national 

32
00:01:48,160 --> 00:01:51,400
security, what I call threat 
finance, essentially stopping 

33
00:01:51,400 --> 00:01:54,000
bad actors from getting the 
money they need to do bad 

34
00:01:54,000 --> 00:01:56,720
things. 
So think sanctions of Asian 

35
00:01:56,720 --> 00:02:00,720
criminal prosecutions. 
Think export control, terrorist 

36
00:02:00,720 --> 00:02:03,640
financing. 
I then spent about two years at 

37
00:02:03,640 --> 00:02:06,320
the US Treasury Department 
working in the office and 

38
00:02:06,320 --> 00:02:08,560
overseas, the national security 
apparatus there. 

39
00:02:08,560 --> 00:02:12,320
So OFAC, the Office of Foreign 
Asset Control, is our sanctions 

40
00:02:12,320 --> 00:02:16,040
regulator, FinCEN, which is the 
US Financial Intelligence unit, 

41
00:02:16,400 --> 00:02:20,720
a policy component called TFFC. 
Really sort of all the ways that

42
00:02:20,720 --> 00:02:26,120
the US Treasury has built 
national national security, a 

43
00:02:26,120 --> 00:02:29,200
national security component to 
stop bad actors from engaging 

44
00:02:29,200 --> 00:02:33,160
with the financial system. 
I left Treasury about six years 

45
00:02:33,160 --> 00:02:38,040
ago and joined what was a seven 
person startup at the time at 

46
00:02:38,040 --> 00:02:44,480
TRM were over 400 people today 
with a really global team and we

47
00:02:44,480 --> 00:02:47,440
work with law enforcement 
agencies, regulators and 

48
00:02:47,440 --> 00:02:51,720
compliance teams globally to 
stop illicit actors from using 

49
00:02:51,720 --> 00:02:55,640
cryptocurrency. 
Yeah, that's, it's really 

50
00:02:55,640 --> 00:02:58,520
interesting. 
I'd imagine there is a huge 

51
00:02:58,520 --> 00:03:02,240
interest from law enforcement, 
especially in in what you guys 

52
00:03:02,240 --> 00:03:04,760
do and what you see in the 
threat intelligence that you've 

53
00:03:04,760 --> 00:03:08,920
collected in these areas. 
And you know, from from my 

54
00:03:08,920 --> 00:03:12,160
perspective, you know, I think 
there's almost like a 

55
00:03:12,480 --> 00:03:15,960
misconception that like 
cryptocurrency is fully 

56
00:03:15,960 --> 00:03:18,920
anonymous and that's certainly 
not the case, right? 

57
00:03:18,920 --> 00:03:23,040
I mean, transactions are still 
being recorded and can be traced

58
00:03:23,040 --> 00:03:25,080
at some level. 
That's what's really 

59
00:03:25,080 --> 00:03:26,960
extraordinary about the 
technology and that's very much 

60
00:03:26,960 --> 00:03:30,000
we what we do, we provide for 
law enforcement. 

61
00:03:30,000 --> 00:03:31,960
It's really tracing and tracking
software. 

62
00:03:31,960 --> 00:03:35,360
It allows them to track and 
trace every transaction on 

63
00:03:35,360 --> 00:03:38,640
public blockchains, which are 
immutable public ledgers, which 

64
00:03:38,640 --> 00:03:41,720
means every transaction is 
logged and forever. 

65
00:03:41,960 --> 00:03:44,880
So it allows law enforcement to 
track and trace the flow of 

66
00:03:44,880 --> 00:03:47,600
illicit proceeds. 
So if you have a ransomware 

67
00:03:47,600 --> 00:03:52,160
attack or you have a hack law 
enforcement, think FBI or IRS, 

68
00:03:52,160 --> 00:03:56,840
criminal investigation, DEA, 
Secret Service, they use TRM to 

69
00:03:56,840 --> 00:04:00,400
track and trace those flows, 
ultimately with the goal of 

70
00:04:00,400 --> 00:04:03,600
building an investigation, 
prosecution, A seizure, 

71
00:04:04,000 --> 00:04:07,600
forfeiture action and getting 
those funds back from those bad 

72
00:04:07,600 --> 00:04:09,080
actors. 
So that's really the 

73
00:04:09,080 --> 00:04:10,680
extraordinary thing about this 
technology. 

74
00:04:10,680 --> 00:04:15,280
You know, I spent my career as 
an AUSA investigating cases 

75
00:04:15,280 --> 00:04:19,240
involving bulk cash smuggling 
and networks of hawalas and 

76
00:04:19,240 --> 00:04:22,560
shell companies and high value 
art and real estate, right? 

77
00:04:22,800 --> 00:04:26,160
There was no TRM to track and 
trace those things on open 

78
00:04:26,160 --> 00:04:28,880
ledgers. 
And it's really extraordinary. 

79
00:04:29,160 --> 00:04:31,960
It's a really extraordinary 
capability today when it comes 

80
00:04:31,960 --> 00:04:33,560
to investigations and 
compliance. 

81
00:04:34,680 --> 00:04:37,720
Yeah, that's really interesting.
I'm sure that you have some 

82
00:04:37,720 --> 00:04:41,680
fascinating stories, just like 
being able to trace these types 

83
00:04:41,680 --> 00:04:44,720
of things over the years even 
outside of cybercrime. 

84
00:04:44,720 --> 00:04:49,000
Like do you have any like 
specific incidents that maybe 

85
00:04:49,000 --> 00:04:51,200
you track that is? 
There, there, there are really 

86
00:04:51,200 --> 00:04:52,720
so many. 
I mean, I would encourage your, 

87
00:04:52,720 --> 00:04:57,040
your listeners. 
We put at least one blog post 

88
00:04:57,040 --> 00:04:59,760
every week about law enforcement
sort of really using our 

89
00:04:59,760 --> 00:05:03,000
technology to track and trace, 
you know, illicit proceeds. 

90
00:05:04,160 --> 00:05:07,840
And, and there's so many 
examples years ago, I feel like,

91
00:05:08,080 --> 00:05:10,000
and maybe for your audience, 
particularly interesting. 

92
00:05:10,000 --> 00:05:13,320
You know, you had the Colonial 
Pipeline attack, which to me was

93
00:05:13,320 --> 00:05:17,360
like this just extraordinary 
watershed moment when cybercrime

94
00:05:17,360 --> 00:05:20,600
went from being, you know, I 
think something that wasn't a 

95
00:05:20,600 --> 00:05:23,840
law enforcement focus and, and 
maybe an annoyance to something 

96
00:05:23,840 --> 00:05:27,360
that really became a global 
security issue. 

97
00:05:27,960 --> 00:05:32,320
You know, you're shutting down 
the gas supply to the the East 

98
00:05:32,320 --> 00:05:34,400
Coast of the United States. 
I remember, you know, waiting in

99
00:05:34,400 --> 00:05:36,480
line in, in, in Washington to 
get gas. 

100
00:05:37,520 --> 00:05:42,920
FBI used our tool to track and 
trace that ransom payment and 

101
00:05:42,920 --> 00:05:45,480
was ultimately able to use their
tools to seize back. 

102
00:05:45,480 --> 00:05:48,560
And really, I mean, over the 
last five years since then, as I

103
00:05:48,560 --> 00:05:51,440
said, there's just myriad 
examples of law enforcement 

104
00:05:51,440 --> 00:05:55,400
using these types of tools 
really more and more at scale. 

105
00:05:55,880 --> 00:05:59,280
And we see, we've seen recent 
investigations involving Iran, 

106
00:05:59,360 --> 00:06:04,080
North Korea, you know, 
ransomware groups, Russian 

107
00:06:04,560 --> 00:06:07,280
sanctions evasion. 
What what what's happening 

108
00:06:07,280 --> 00:06:12,720
really is that as we move fully 
into a digital space, bad actors

109
00:06:12,720 --> 00:06:15,560
are also moving funds on block 
chains, right, in ways that they

110
00:06:15,560 --> 00:06:18,800
never did before. 
And the ecosystem is growing and

111
00:06:18,800 --> 00:06:22,400
so is sort of illicit activity. 
You mentioned a report that we 

112
00:06:22,400 --> 00:06:25,200
put out a few months ago, sort 
of our crypto crime report. 

113
00:06:25,840 --> 00:06:29,720
We said that there was about 
$158 billion in crypto related 

114
00:06:29,720 --> 00:06:34,040
crime in 2025. 
That is a record setting year. 

115
00:06:34,600 --> 00:06:38,520
It's still made-up only about 
1.3% of all activity within the 

116
00:06:38,520 --> 00:06:40,600
crypto ecosystem. 
So we're talking about a 

117
00:06:40,600 --> 00:06:44,680
relatively small percentage of 
overall activity, but it's 

118
00:06:44,680 --> 00:06:47,520
still, you know, 1.3%. 
That keeps me up at night 

119
00:06:47,520 --> 00:06:50,440
because it involves North Korea 
hacks, it involves ransomware 

120
00:06:50,440 --> 00:06:53,200
and terror financing, But the 
bottom line is more and more 

121
00:06:53,200 --> 00:06:57,720
activity is happening in crypto,
both lawful activity and and 

122
00:06:57,720 --> 00:07:00,520
illicit activity. 
Yeah, absolutely. 

123
00:07:00,520 --> 00:07:03,640
And you know, you mentioned the 
Colonial Pipeline ransomware 

124
00:07:03,640 --> 00:07:07,320
attack. 
I still remember when the DOJ 

125
00:07:07,320 --> 00:07:11,200
came out and said, hey, we were 
able to get all this, you know, 

126
00:07:11,360 --> 00:07:13,480
essentially recover these funds 
from that. 

127
00:07:13,720 --> 00:07:17,680
That was a really interesting 
point because, you know, at that

128
00:07:17,680 --> 00:07:21,080
point, I think the government 
was also saying, look, if you 

129
00:07:21,080 --> 00:07:24,360
work with us and collaborate 
with us, then here's like what 

130
00:07:24,360 --> 00:07:27,320
we have the capabilities to do 
and we can, you know, kind of 

131
00:07:27,320 --> 00:07:29,640
recover this. 
So, you know, I think there's a 

132
00:07:29,640 --> 00:07:34,920
really interesting, you know, I 
guess angle there in terms of 

133
00:07:34,920 --> 00:07:39,360
how that these attacks or 
incidents play out after they 

134
00:07:39,360 --> 00:07:43,200
happen with capturing that, 
being able to capture that money

135
00:07:43,200 --> 00:07:46,360
back. 
Yeah, absolutely. 

136
00:07:46,360 --> 00:07:50,280
And you know, look, we are an 
investigative tool and law 

137
00:07:50,280 --> 00:07:52,880
enforcement is sort of using us 
to track and trace these funds. 

138
00:07:52,880 --> 00:07:55,240
And, you know, we we've seen 
that also recently right now, 

139
00:07:55,480 --> 00:07:59,640
there's been this proliferation 
of scams really driven by 

140
00:07:59,640 --> 00:08:05,200
transnational cybercrime groups.
There was a recent takedown of a

141
00:08:05,200 --> 00:08:08,040
group called the Prince Group in
Cambodia, for example, where the

142
00:08:08,120 --> 00:08:13,040
US was able to actually seize 
and begin a forfeiture action 

143
00:08:13,040 --> 00:08:17,240
for $15 billion, the largest 
ever forfeiture in U.S. history.

144
00:08:17,640 --> 00:08:21,160
I think the largest forfeiture 
of anything anywhere in history.

145
00:08:21,440 --> 00:08:23,960
And it's really an only in 
crypto story because bad actors 

146
00:08:23,960 --> 00:08:27,560
are now able to move larger 
amounts of funds faster 

147
00:08:27,640 --> 00:08:30,920
cross-border than ever before. 
But the paradox is we can now 

148
00:08:30,920 --> 00:08:34,159
track and trace them and 
potentially seize them back, 

149
00:08:34,720 --> 00:08:36,880
back for the victims, back for 
law enforcement. 

150
00:08:37,200 --> 00:08:38,919
And I think that's really what 
we're seeing now. 

151
00:08:38,919 --> 00:08:40,799
So we're going to see more and 
more, right? 

152
00:08:40,799 --> 00:08:44,039
I mean, I can go through any 
number of different types of 

153
00:08:44,039 --> 00:08:47,440
cases, but the reality is crypto
is becoming used more and more 

154
00:08:47,440 --> 00:08:52,200
by both good and bad actors. 
Yeah, it's funny, I do like to 

155
00:08:52,280 --> 00:08:56,800
look through DOJ indictments and
like, because it's always 

156
00:08:56,800 --> 00:08:59,200
interesting. 
You can really figure out how 

157
00:08:59,600 --> 00:09:03,200
FBI agents are able to kind of 
draw evidence and identify 

158
00:09:03,200 --> 00:09:05,080
people that they're charging in 
attacks. 

159
00:09:05,080 --> 00:09:09,040
And a lot of the times the the 
crypto wallets are kind of what 

160
00:09:09,040 --> 00:09:13,760
they're using as their primary 
piece of evidence there. 

161
00:09:13,760 --> 00:09:17,280
And I think there was like a 
really interesting case with 

162
00:09:17,280 --> 00:09:20,080
like one of the Scattered Spider
hackers. 

163
00:09:20,720 --> 00:09:23,720
I think it was like a few months
ago where they basically they 

164
00:09:23,720 --> 00:09:26,240
said they analyzed the 
blockchain and then found a 

165
00:09:26,240 --> 00:09:29,000
wallet on a server that 
contained portions of the ransom

166
00:09:29,000 --> 00:09:33,680
payment by victims and attacks. 
And then they also found that 

167
00:09:33,680 --> 00:09:36,280
that wallet had been used to buy
gift cards. 

168
00:09:36,280 --> 00:09:39,360
And those gift cards were used 
for the food delivery service. 

169
00:09:39,360 --> 00:09:42,560
So like, you know, being able to
connect all these pieces. 

170
00:09:43,640 --> 00:09:47,480
Do you think that bread actors 
or ransomware actors are 

171
00:09:47,480 --> 00:09:52,440
becoming more aware that these 
bread crumbs are being left 

172
00:09:52,440 --> 00:09:56,080
behind and like how to kind of 
pivot away from that? 

173
00:09:56,080 --> 00:10:00,520
Or is this still very much like 
a, you know, something that's 

174
00:10:00,520 --> 00:10:02,920
there and like, useful? 
Yeah, I know. 

175
00:10:03,160 --> 00:10:05,120
Look, these are very 
sophisticated actors. 

176
00:10:05,520 --> 00:10:07,720
There's no question, certainly 
from a cyber perspective. 

177
00:10:08,040 --> 00:10:10,840
And of course, they know and 
they've known for a long time 

178
00:10:10,840 --> 00:10:13,480
that law enforcement is using 
blockchain intelligence tools 

179
00:10:13,480 --> 00:10:16,320
like TRM to track and trace 
these payments and ultimately 

180
00:10:16,320 --> 00:10:18,480
sees them back. 
You know, it's interesting. 

181
00:10:19,120 --> 00:10:23,040
A lot of bad actors globally 
have gone to stable coins. 

182
00:10:24,040 --> 00:10:26,720
They're moving to stable coins 
for a whole host of reasons why 

183
00:10:26,720 --> 00:10:29,360
most why why like lawful actors 
are using them too. 

184
00:10:29,840 --> 00:10:33,720
It's a way to move funds fast in
a stable way tied to the US 

185
00:10:33,720 --> 00:10:36,360
dollar. 
Ransomware groups are actually 

186
00:10:36,360 --> 00:10:37,840
an exception. 
And someone asked me about this 

187
00:10:37,840 --> 00:10:40,800
recently and I explained that 
like stablecoin issuers like 

188
00:10:40,800 --> 00:10:45,320
Tether, like Circle, have really
unique capabilities to burn and 

189
00:10:45,320 --> 00:10:47,640
reissue their native token, 
which means they can actually 

190
00:10:47,640 --> 00:10:51,160
remove it from your crypto 
wallet and put it in a place 

191
00:10:51,160 --> 00:10:53,280
where you cannot access access 
it. 

192
00:10:53,560 --> 00:10:55,600
It's extraordinary. 
It's been a conversation that's 

193
00:10:55,600 --> 00:10:59,480
been going on for a number of 
different reasons recently, post

194
00:10:59,480 --> 00:11:02,000
drift hack. 
What are the obligations of a 

195
00:11:02,000 --> 00:11:04,240
stablecoin issue? 
What should they be doing here? 

196
00:11:04,560 --> 00:11:06,840
But the reality is they have 
this capability and Tether has 

197
00:11:06,840 --> 00:11:08,400
shown that they can do it at 
scale. 

198
00:11:08,800 --> 00:11:14,480
They just did a 300, almost $350
million seizure, I'm sorry, 

199
00:11:14,920 --> 00:11:19,960
freeze last week involving Iran.
So ransomware actors are still 

200
00:11:19,960 --> 00:11:24,520
looking for Bitcoin, which is 
unstable, but it is truly 

201
00:11:24,520 --> 00:11:27,960
decentralized in a way that you 
cannot, you know, rollback 

202
00:11:27,960 --> 00:11:30,120
transactions, you cannot freeze 
funds. 

203
00:11:30,560 --> 00:11:33,080
And that's up to the exchanges 
sort of not to move them. 

204
00:11:33,080 --> 00:11:36,560
So ransomware actors are very 
sophisticated, but so is law 

205
00:11:36,560 --> 00:11:39,680
enforcement. 
And it's this cat and mouse game

206
00:11:39,680 --> 00:11:42,640
that has gone on forever between
the good guys and the bad guys 

207
00:11:42,640 --> 00:11:47,440
where, you know, bad actors are 
early adopters of of new 

208
00:11:47,440 --> 00:11:52,080
technology historically and law 
enforcement is is playing catch 

209
00:11:52,080 --> 00:11:53,760
up. 
But I think that we see law 

210
00:11:53,760 --> 00:11:56,920
enforcement more and more 
leaning into technology. 

211
00:11:57,080 --> 00:11:59,400
I mean, 11 sort of important 
point I think to put on your 

212
00:11:59,400 --> 00:12:02,880
question is AI has really 
supercharged this type of 

213
00:12:02,880 --> 00:12:07,480
activity, the scam activity, 
certainly the ransomware 

214
00:12:07,480 --> 00:12:10,120
activity. 
You know, we, we have always 

215
00:12:10,120 --> 00:12:12,440
lived in a world where 
ransomware groups were looking 

216
00:12:12,440 --> 00:12:14,120
for affiliates, right? 
They were looking for a 

217
00:12:14,120 --> 00:12:17,240
franchisees, essentially someone
who sits to sell and deploy 

218
00:12:17,240 --> 00:12:19,800
their malware. 
Well, you know, in the age of 

219
00:12:19,800 --> 00:12:22,960
AI, you don't need that, right? 
You can establish agents that 

220
00:12:22,960 --> 00:12:25,400
could go out and at scale deploy
your malware. 

221
00:12:26,200 --> 00:12:29,480
You don't have to have a revenue
sharing model with anybody else.

222
00:12:30,000 --> 00:12:33,560
And I think it can allow, it 
will ultimately allow ransomware

223
00:12:33,560 --> 00:12:38,480
actors to move much faster to 
continue to attack global health

224
00:12:38,480 --> 00:12:42,160
systems and, and manufacturing 
and, and critical 

225
00:12:42,160 --> 00:12:45,120
infrastructure, but really do it
at a scale that we've never seen

226
00:12:45,120 --> 00:12:48,400
before. 
And that to me is not a national

227
00:12:48,400 --> 00:12:51,120
security threat. 
That is a civilization level 

228
00:12:51,120 --> 00:12:55,080
threat. 
And that's why I I evangelize 

229
00:12:55,080 --> 00:12:59,800
all the time that we need to be 
countering this activity by 

230
00:12:59,800 --> 00:13:04,200
using technology for good. 
Yeah, that's, that's really 

231
00:13:04,200 --> 00:13:07,000
fascinating. 
That's a great point about the 

232
00:13:07,000 --> 00:13:10,880
use of AI as opposed to, you 
know, continuing to lean on the 

233
00:13:11,200 --> 00:13:15,800
affiliate operational model. 
Have you seen that in I know you

234
00:13:16,000 --> 00:13:18,680
at the back end, you're able to 
collect all this data and kind 

235
00:13:18,680 --> 00:13:22,320
of intelligence at the back like
in terms of ransomware attacks, 

236
00:13:22,320 --> 00:13:25,040
like have you seen any kind of 
evidence of that yet or is this?

237
00:13:25,040 --> 00:13:27,080
Something we definitely, we 
definitely have. 

238
00:13:28,280 --> 00:13:31,680
We, we have not necessarily seen
it at scale the way we've seen 

239
00:13:32,440 --> 00:13:35,920
scam these scam transnational 
criminal groups from a scam 

240
00:13:35,920 --> 00:13:39,320
perspective, really using it 
from the scam perspective. 

241
00:13:39,320 --> 00:13:44,480
I we see it in every case, the 
use of defect technology really 

242
00:13:44,480 --> 00:13:49,360
targeted phishing emails. 
You know, they're, we're gone to

243
00:13:49,360 --> 00:13:52,120
the days of the Nigerian Prince 
and the broken English right. 

244
00:13:52,440 --> 00:13:55,320
It's perfectly tailored phishing
attacks on people. 

245
00:13:55,600 --> 00:13:57,320
Slightly different on the 
ransomware front, but we're 

246
00:13:57,320 --> 00:14:00,360
definitely starting to see it. 
And to me, it's a huge, huge, 

247
00:14:00,360 --> 00:14:02,800
huge threat. 
Yeah, definitely. 

248
00:14:04,160 --> 00:14:06,920
Well, I wanted to talk to you 
mentioned the Drift protocol 

249
00:14:06,920 --> 00:14:10,920
heist and that, you know, I 
definitely wanted to talk about 

250
00:14:10,920 --> 00:14:15,240
that. 
It seems like, I mean that these

251
00:14:15,240 --> 00:14:20,040
crypto heists are absolutely 
fascinating to me just because 

252
00:14:20,040 --> 00:14:23,400
of the sheer amount of money 
that criminals are able to kind 

253
00:14:23,400 --> 00:14:27,800
of, you know, drain from them. 
And I know you know in the past 

254
00:14:27,800 --> 00:14:34,240
we've had the like I think it 
was by bit was $1.5 billion and 

255
00:14:34,240 --> 00:14:38,840
then Ronan network breach in 
20/22 was 625,000,000. 

256
00:14:39,800 --> 00:14:45,160
So I and I think that it was 
285,000,000 that was drift which

257
00:14:45,160 --> 00:14:48,960
was a couple weeks ago now. 
So wanted to hear your 

258
00:14:48,960 --> 00:14:53,240
perspective on kind of what you 
know, your takeaways were from 

259
00:14:53,240 --> 00:14:55,280
that specific one. 
Yeah. 

260
00:14:55,320 --> 00:14:59,040
You know, as I mentioned, we put
out a report today that 

261
00:14:59,920 --> 00:15:03,640
basically ties together 2 
attacks in the first four months

262
00:15:03,800 --> 00:15:08,000
of 2026. 
North Korea has stolen about 577

263
00:15:08,000 --> 00:15:11,000
million already this year. 
Last year it was close to 2 

264
00:15:11,000 --> 00:15:16,560
billion. 
That that is 76% of all stolen 

265
00:15:16,600 --> 00:15:20,600
crypto this year has been 
attributed to North Korea, which

266
00:15:20,600 --> 00:15:23,800
is just a stunning number. 
And they've gotten much better. 

267
00:15:24,520 --> 00:15:26,840
North Korea's been very, very 
good at this for a long time. 

268
00:15:26,840 --> 00:15:29,200
I think it's important, I think,
for your audience to know who 

269
00:15:29,760 --> 00:15:31,800
he's really following this. 
I mean, North Korea has 

270
00:15:31,800 --> 00:15:35,440
professionalized hacking and 
particularly crypto theft in a 

271
00:15:35,440 --> 00:15:38,000
way that we've never seen from 
any other regime. 

272
00:15:38,000 --> 00:15:42,520
And it's not even close. 
North Korea, you know, from a 

273
00:15:42,520 --> 00:15:47,440
young age, they'll take kids who
are showing aptitude for STEM 

274
00:15:48,160 --> 00:15:51,200
and essentially train them to be
cyber warriors. 

275
00:15:52,120 --> 00:15:55,440
And people often talk about 
state sponsored activity in 

276
00:15:55,440 --> 00:15:57,320
North Korea. 
It is not state sponsored 

277
00:15:57,320 --> 00:15:59,520
activity. 
It is the state itself. 

278
00:16:00,440 --> 00:16:04,080
North Korea is a criminal state 
that has decided that without 

279
00:16:04,080 --> 00:16:07,680
any meaningful economy, they can
steal billions of dollars of 

280
00:16:07,680 --> 00:16:11,240
cryptocurrency to fund weapons 
proliferation and other types of

281
00:16:11,240 --> 00:16:15,840
destabilizing activity. 
I think what's gotten so really 

282
00:16:15,840 --> 00:16:19,160
like troubling about the 
situation is they've moved from 

283
00:16:19,160 --> 00:16:23,560
sort of tech using technology to
really using, you know, social 

284
00:16:23,560 --> 00:16:26,360
engineering and scale. 
And you know, you mentioned the 

285
00:16:26,360 --> 00:16:29,640
Drift protocol and you mentioned
that your, your, your audience 

286
00:16:29,640 --> 00:16:33,160
might not be, you know, super 
crypto native, but Drift is a 

287
00:16:33,160 --> 00:16:35,840
trading platform built on the 
Solana blockchain, which is a 

288
00:16:35,840 --> 00:16:40,240
major crypto blockchain. 
Think of, think of Drift is like

289
00:16:40,240 --> 00:16:43,840
a decentralized exchange where 
people can trade crypto assets. 

290
00:16:44,480 --> 00:16:46,240
And it is a governing body, 
right? 

291
00:16:46,240 --> 00:16:50,160
You have to have some type of 
mechanism for, for allowing 

292
00:16:50,160 --> 00:16:53,200
transactions to go through 
essentially a Security Council 

293
00:16:53,600 --> 00:16:57,040
that's made-up of multiple 
signers who have to jointly 

294
00:16:57,040 --> 00:17:01,560
approve major changes. 
And essentially, North Korea 

295
00:17:01,800 --> 00:17:05,760
spent months, I mean, we're not 
talking about, you know, a few 

296
00:17:05,760 --> 00:17:07,920
days here trying to breach the 
controls. 

297
00:17:07,920 --> 00:17:11,680
This was months getting close to
Drift's employees, meeting them 

298
00:17:11,680 --> 00:17:15,440
in person meetings, at 
cryptocurrency conferences. 

299
00:17:16,640 --> 00:17:20,800
It's really just unprecedented. 
And that allowed them to 

300
00:17:20,800 --> 00:17:28,560
ultimately get to to ultimately 
get control of these mechanisms 

301
00:17:28,560 --> 00:17:30,200
that allow transactions to go 
through. 

302
00:17:30,840 --> 00:17:34,720
And we're able to essentially 
unlock that exchange and steal 

303
00:17:34,720 --> 00:17:40,520
$285 million. 
The planning was just 

304
00:17:40,520 --> 00:17:42,680
extraordinary. 
And I think what it also says to

305
00:17:42,680 --> 00:17:45,040
me is that like, they didn't 
just pick drift, right? 

306
00:17:45,320 --> 00:17:48,120
They likely picked many of 
these. 

307
00:17:48,800 --> 00:17:50,720
And I think what I'm so 
concerned about is that we're 

308
00:17:50,720 --> 00:17:54,840
going to start to see a litany 
of these types of attacks based 

309
00:17:54,840 --> 00:17:57,400
on essentially months or even 
maybe years of planning. 

310
00:17:59,280 --> 00:18:03,040
So I, I, I, I look it, North 
Korea is, is, is a country and, 

311
00:18:03,080 --> 00:18:08,600
and you know, a, a threat actor 
that we followed for a really 

312
00:18:08,600 --> 00:18:11,200
long time. 
We have a guy at TRM named Nick 

313
00:18:11,200 --> 00:18:13,040
Carlson. 
I think Nick is, Nick is a 

314
00:18:13,040 --> 00:18:16,120
former FBI analyst who I used to
work really closely with when I 

315
00:18:16,120 --> 00:18:18,760
was a prosecutor. 
And we essentially went to TRM 

316
00:18:18,760 --> 00:18:21,400
together. 
And he, he's one of the foremost

317
00:18:21,400 --> 00:18:24,080
experts in the world, But I 
think his, his view tends to be,

318
00:18:25,160 --> 00:18:27,640
Hey, crypto is just the next 
thing, right? 

319
00:18:27,720 --> 00:18:31,080
First it was, you know, 
counterfeit $100 bills and, and 

320
00:18:31,280 --> 00:18:33,560
counterfeit cigarettes and 
narcotics. 

321
00:18:35,600 --> 00:18:38,720
And now, now they've moved to 
crypto because you can actually 

322
00:18:38,720 --> 00:18:40,200
steal funds at the speed of the 
Internet. 

323
00:18:41,840 --> 00:18:47,520
Yeah, I think the The Drift 
Protocol hacked definitely, as 

324
00:18:47,520 --> 00:18:52,840
you said, it shows kind of just 
how good, you know, these North 

325
00:18:52,840 --> 00:18:55,040
Korean actors have gotten that 
social engineering. 

326
00:18:55,040 --> 00:18:57,720
I mean it, it's played out 
really almost like a spy novel, 

327
00:18:58,040 --> 00:19:00,440
like the way that. 
It's, it's absolutely 

328
00:19:00,440 --> 00:19:03,000
extraordinary and it, and it's 
been that way for a long time. 

329
00:19:04,520 --> 00:19:07,360
If, if, if listeners want to go 
really deep on this, The Lazarus

330
00:19:07,360 --> 00:19:13,240
Heist podcast is excellent on 
the BBC with, with, with Jean 

331
00:19:13,240 --> 00:19:18,640
Lee, who was AAP Bureau 
correspondent in North Korea. 

332
00:19:19,600 --> 00:19:22,840
It's really, it's really 
extraordinary and goes back in 

333
00:19:22,840 --> 00:19:25,080
time and talks about all the way
sort of North Korea has 

334
00:19:25,080 --> 00:19:28,440
professionalized this. 
But it's, it's something that's 

335
00:19:28,440 --> 00:19:30,080
been going on for years and 
years. 

336
00:19:30,080 --> 00:19:32,040
And, and I think they've just 
gotten to the point now where 

337
00:19:32,040 --> 00:19:36,280
they it's crazy that when the US
thinks about adversaries, we 

338
00:19:36,280 --> 00:19:40,440
think about Iran and China and 
Russia and North Korea is even 

339
00:19:40,440 --> 00:19:43,280
in the same breath. 
But it's because they've 

340
00:19:43,280 --> 00:19:48,280
professionalized this capability
to steal funds at the speed of 

341
00:19:48,280 --> 00:19:50,360
the Internet and use it for 
weapons proliferation. 

342
00:19:51,240 --> 00:19:54,120
They're they're in the 
conversation and we need to 

343
00:19:54,120 --> 00:19:58,520
fight back. 
When you look at North Korean 

344
00:19:58,520 --> 00:20:03,840
actors and how they utilize, or 
should I say, I guess like. 

345
00:20:05,480 --> 00:20:10,680
Cryptocurrency, how is that 
different from what you see with

346
00:20:10,760 --> 00:20:14,640
ransomware actors or not 
necessarily North Korean actors,

347
00:20:14,640 --> 00:20:16,480
just other types of cyber 
criminals? 

348
00:20:16,720 --> 00:20:20,760
Yeah, no, absolutely. 
For North Korea, it's different,

349
00:20:20,760 --> 00:20:26,520
right? 
Cyber criminals tend to be bad 

350
00:20:26,520 --> 00:20:29,840
actors who are motivated by 
greed, who are trying to steal 

351
00:20:29,840 --> 00:20:33,440
funds that may that that are 
that may be state sponsored, but

352
00:20:33,440 --> 00:20:36,120
may just be sort of a rogue 
criminal element. 

353
00:20:36,120 --> 00:20:38,360
Think of a gang. 
North Korea is different, right?

354
00:20:38,360 --> 00:20:46,440
This is a government that has no
other means of, of, of their 

355
00:20:46,440 --> 00:20:48,040
economy. 
So they're stealing 

356
00:20:48,040 --> 00:20:51,440
cryptocurrency and using it to 
fund their own, their, their 

357
00:20:51,440 --> 00:20:53,480
regime essentially. 
I think that's, that's 

358
00:20:53,480 --> 00:20:55,800
significant. 
So they launder very differently

359
00:20:55,800 --> 00:20:58,960
too. 
They launder in a way where it 

360
00:20:58,960 --> 00:21:01,440
doesn't, you know, no one, they 
don't care about being caught 

361
00:21:01,920 --> 00:21:04,360
because no one is ever going to 
be caught or extradited anywhere

362
00:21:04,360 --> 00:21:06,800
arrested from North Korea. 
What they care about is that 

363
00:21:06,800 --> 00:21:09,960
they can off ramp as much of the
funds as they possibly can as 

364
00:21:09,960 --> 00:21:13,160
fast as they can. 
So they're using, you know, 

365
00:21:13,160 --> 00:21:15,520
various different services. 
They're trying to move the funds

366
00:21:15,520 --> 00:21:19,640
as quickly as possible. 
They are using Chinese money 

367
00:21:19,640 --> 00:21:23,800
laundering networks to actually 
launder the proceeds of a lot of

368
00:21:23,800 --> 00:21:29,520
these Chinese gangs that have 
been doing this for years and 

369
00:21:30,080 --> 00:21:32,840
and really acting sort of as a 
nation state actor as opposed to

370
00:21:32,840 --> 00:21:34,920
what sort of a rogue criminal 
group would do. 

371
00:21:36,280 --> 00:21:37,520
Well, yeah, that's interesting 
too. 

372
00:21:37,520 --> 00:21:42,680
I mean, in the in the Drift 
Protocol hack or heist, I guess,

373
00:21:43,200 --> 00:21:46,800
you know, they were mentioning 
that the initial people who were

374
00:21:46,800 --> 00:21:49,000
carrying out the social 
engineering weren't necessarily 

375
00:21:49,000 --> 00:21:53,040
North Korean nationals. 
So that was almost like, you 

376
00:21:53,040 --> 00:21:56,360
know, there's multiple different
entities being involved there. 

377
00:21:57,040 --> 00:21:59,120
Yeah, that fact really took my 
breath away in terms of like, 

378
00:21:59,120 --> 00:22:02,240
you know, I mean, North Korea, 
it's not easy for North Korea to

379
00:22:02,240 --> 00:22:04,000
necessarily find people to do 
their bidding. 

380
00:22:04,000 --> 00:22:06,680
And the fact that there were, 
you know, non North Korean 

381
00:22:07,120 --> 00:22:09,400
people who were the ones at the 
conferences having this 

382
00:22:09,400 --> 00:22:11,080
engagement. 
And I think it's a really 

383
00:22:11,080 --> 00:22:13,680
interesting question that's 
going to lead to much more 

384
00:22:13,960 --> 00:22:16,320
investigation from FBI and 
others. 

385
00:22:16,760 --> 00:22:20,280
Yeah, certainly. 
You know, when you look at like 

386
00:22:20,800 --> 00:22:25,400
it's just over the years, like 
over the past what like decade 

387
00:22:25,400 --> 00:22:29,480
and a half, two decades, like 
these types of attacks have 

388
00:22:29,480 --> 00:22:31,520
really evolved. 
But like even looking back at 

389
00:22:31,520 --> 00:22:35,400
like going way back, like the 
Mount G Ox, you know, attack and

390
00:22:35,400 --> 00:22:38,880
things like that, Like how have 
you seen these types of crypto 

391
00:22:38,880 --> 00:22:42,240
heists or hacks like evolve over
the years? 

392
00:22:42,920 --> 00:22:46,760
They've gotten much bigger for 
sure, and I think the laundering

393
00:22:46,760 --> 00:22:48,200
has become much more 
sophisticated. 

394
00:22:48,200 --> 00:22:51,360
We now have all kinds of privacy
techniques and mixers and 

395
00:22:51,360 --> 00:22:54,560
privacy coins and other types of
cross chain swaps, right? 

396
00:22:54,680 --> 00:22:58,160
Moving funds across block chains
as fast as, you know, at rapid 

397
00:22:58,160 --> 00:23:00,400
speed in order to obfuscate the 
flow of funds. 

398
00:23:00,840 --> 00:23:03,600
Mixers for your audience or 
essentially exchanges on block 

399
00:23:03,600 --> 00:23:07,080
chains where you put in funds, 
it mixes them up with other 

400
00:23:07,080 --> 00:23:11,960
users and sends them out clean. 
The other side, we trade at TRM.

401
00:23:11,960 --> 00:23:14,560
We trace, you know, funds 
through many mixers with a high,

402
00:23:14,640 --> 00:23:16,000
pretty high degree of 
confidence. 

403
00:23:16,240 --> 00:23:19,000
But there's no question that 
these laundering typologies has 

404
00:23:19,000 --> 00:23:21,120
evolved where they're using new 
services. 

405
00:23:22,120 --> 00:23:25,120
You know, for years North Korea 
used Tornado Cash, which is a 

406
00:23:25,120 --> 00:23:28,480
decentralized protocol mixing 
protocol on Ethereum. 

407
00:23:29,800 --> 00:23:33,120
Tornado Cash was sanctioned and 
then delisted. 

408
00:23:33,960 --> 00:23:36,200
And there's all kinds of 
interesting drama around that. 

409
00:23:36,440 --> 00:23:38,480
But they're looking to different
services now too. 

410
00:23:38,480 --> 00:23:42,080
You know what, what services can
they move funds through that 

411
00:23:42,080 --> 00:23:45,800
aren't going to freeze them? 
And you know, we highlight Thor 

412
00:23:45,800 --> 00:23:49,720
Chain as one example of that in 
the report that we put out 

413
00:23:49,720 --> 00:23:52,920
today. 
But there are there are plenty 

414
00:23:52,920 --> 00:23:55,320
more. 
Right. 

415
00:23:55,480 --> 00:23:59,720
That makes sense. 
And I, you know, so I wanted to 

416
00:23:59,720 --> 00:24:02,960
ask, you know, about looking at 
the report that you guys 

417
00:24:02,960 --> 00:24:06,560
released from January, there 
were some really interesting 

418
00:24:06,680 --> 00:24:11,160
takeaways in terms of ransomware
and kind of what you're seeing 

419
00:24:11,160 --> 00:24:14,200
there. 
Specifically, you know, what 

420
00:24:14,200 --> 00:24:17,680
would be in your opinion, some 
of the the biggest takeaways 

421
00:24:17,680 --> 00:24:20,560
with what you found having to do
with that? 

422
00:24:21,120 --> 00:24:24,280
You know, I think we're seeing 
more and more attacks. 

423
00:24:24,440 --> 00:24:27,160
You know, there's no question. 
And the attack surface seems to 

424
00:24:27,160 --> 00:24:28,720
be getting bigger and not 
smaller. 

425
00:24:29,880 --> 00:24:33,560
I think I testified last week 
actually before the House 

426
00:24:33,560 --> 00:24:37,320
Homeland Security Committee and 
there was a discussion of 

427
00:24:37,320 --> 00:24:42,520
ransomware one of my one of the 
other panelists talked about and

428
00:24:42,520 --> 00:24:45,400
I was a little taken back. 
They said about 50% of all 

429
00:24:45,400 --> 00:24:47,840
ransomware attacks are on health
systems. 

430
00:24:48,800 --> 00:24:51,840
And to me, you know, that was 
pretty extraordinary where 

431
00:24:51,840 --> 00:24:55,160
people, you know, ultimately 
could potentially die, who are 

432
00:24:55,160 --> 00:24:57,640
not getting the care that they 
need or the electricity is going

433
00:24:57,640 --> 00:25:00,000
out or, or these types of issues
are happening. 

434
00:25:00,000 --> 00:25:03,560
So I, that, that, that to me was
something, you know, kind of 

435
00:25:03,560 --> 00:25:07,680
recently to learn about. 
I, I think this idea of the use 

436
00:25:07,680 --> 00:25:11,400
of AI to scale these types of 
attacks potentially something 

437
00:25:11,400 --> 00:25:16,120
that we're thinking about very, 
very closely at TRM, but I think

438
00:25:16,120 --> 00:25:18,000
we're seeing the number of 
attacks go up. 

439
00:25:18,760 --> 00:25:21,880
We're certainly seeing the, the,
the size of these, the overall 

440
00:25:21,880 --> 00:25:24,640
ransom payments go up. 
I think it's interesting. 

441
00:25:24,640 --> 00:25:27,160
It's it's certainly a a 
concerning moment, but as bad 

442
00:25:27,160 --> 00:25:29,640
actors are scaling this type of 
activity, I think that's that's 

443
00:25:29,640 --> 00:25:32,400
the biggest concern through AI 
and other types of technology. 

444
00:25:33,840 --> 00:25:36,840
Yeah, that's what was really 
stood out to me at least was, 

445
00:25:36,880 --> 00:25:40,680
you know, you get you're able to
get a lot of good information 

446
00:25:40,680 --> 00:25:44,920
about ransomware operations 
after the initial attack that 

447
00:25:44,920 --> 00:25:47,960
actually happened. 
So you can see, you know, our 

448
00:25:47,960 --> 00:25:51,000
businesses paying the ransom, 
like what happens to that money,

449
00:25:51,000 --> 00:25:53,000
how it's moved and used over 
time. 

450
00:25:53,440 --> 00:25:57,120
So that's, that's really cool. 
And one thing that I that stood 

451
00:25:57,120 --> 00:26:00,600
out to me when I was looking at 
the report as well as, you know,

452
00:26:00,960 --> 00:26:06,080
these the points about major 
disruptions that did not fully 

453
00:26:06,080 --> 00:26:09,480
extinguish ransomware groups, 
but instead kind of had a little

454
00:26:09,480 --> 00:26:11,880
bit of like a scattering impact 
on them. 

455
00:26:13,360 --> 00:26:16,000
I always think that's 
fascinating because you know, 

456
00:26:16,000 --> 00:26:18,440
you see a lot of these 
disruption efforts being 

457
00:26:18,440 --> 00:26:23,400
announced and I always wonder 
what, you know, if they're going

458
00:26:23,400 --> 00:26:28,200
to have a near term impact or a 
long term impact and what's kind

459
00:26:28,200 --> 00:26:29,640
of going on behind the scenes 
there. 

460
00:26:29,640 --> 00:26:31,320
So I thought that stood out to 
me as well. 

461
00:26:31,320 --> 00:26:33,120
Yeah, it's a great question. 
It's interesting. 

462
00:26:33,120 --> 00:26:36,640
We had our public sector summit 
yesterday for TRM, which we 

463
00:26:36,640 --> 00:26:41,840
hosted about 200 federal law 
enforcement agencies, national 

464
00:26:41,840 --> 00:26:44,520
security leaders in in our 
space. 

465
00:26:45,000 --> 00:26:47,760
And I, I think one sort of major
theme was the idea of 

466
00:26:47,760 --> 00:26:50,800
disruption. 
And I think we have to change 

467
00:26:50,800 --> 00:26:53,160
the paradigm a little bit when 
it comes to sort of this new 

468
00:26:53,160 --> 00:26:56,240
world where everything is 
global, cross-border, North 

469
00:26:56,240 --> 00:26:58,840
Korea, Russia, China, right? 
Places where we might not 

470
00:26:59,160 --> 00:27:02,200
necessarily be able to 
prioritize arrests, putting 

471
00:27:02,200 --> 00:27:04,880
people in handcuffs and has to 
be like, what does disruption 

472
00:27:04,880 --> 00:27:06,680
look like? 
I think disruption certainly 

473
00:27:06,680 --> 00:27:10,400
looks like seizures. 
It looks like forfeitures, name 

474
00:27:10,400 --> 00:27:12,760
and shame. 
But disruption I think is a 

475
00:27:12,760 --> 00:27:14,200
little bit of what you're 
describing as well. 

476
00:27:14,200 --> 00:27:16,440
And that is sort of the whack a 
mole concept. 

477
00:27:16,440 --> 00:27:19,440
And whack A mole has a very sort
of negative conversation when it

478
00:27:19,440 --> 00:27:21,280
comes to law enforcement. 
But I I've always been a big 

479
00:27:21,280 --> 00:27:23,320
believer that you got to whack 
some moles every once in a 

480
00:27:23,320 --> 00:27:26,200
while. 
And whacking those moles adds a 

481
00:27:26,200 --> 00:27:29,400
little friction possibly to the 
laundering process. 

482
00:27:29,600 --> 00:27:31,800
You know, when you're 
reconstituting yourself as a new

483
00:27:31,800 --> 00:27:36,840
entity or a new group, that 
takes work, you know, are you 

484
00:27:36,840 --> 00:27:38,200
going out and getting new 
affiliates? 

485
00:27:38,200 --> 00:27:40,240
How are you? 
How are you what what you know, 

486
00:27:41,160 --> 00:27:43,680
is the deal not as sweet as it 
was because people are worried 

487
00:27:43,680 --> 00:27:45,960
about, you know, getting 
attacked themselves. 

488
00:27:46,800 --> 00:27:49,080
So I so I think that like, you 
know, adding friction to some of

489
00:27:49,080 --> 00:27:51,560
these processes is really 
useful. 

490
00:27:51,680 --> 00:27:54,040
We're not going to end 
ransomware, certainly not in 

491
00:27:54,040 --> 00:27:57,200
this sort of digital age we're 
we're now fully immersed in. 

492
00:27:57,880 --> 00:28:00,200
But I do think we can make it 
much harder for these groups to 

493
00:28:00,200 --> 00:28:04,200
ultimately launder and then off 
ramp the illicit proceeds and 

494
00:28:04,200 --> 00:28:10,000
for your viewers or your 
listeners, the the world of sort

495
00:28:10,000 --> 00:28:14,960
of crypto crime and blockchain 
tracing really comes down to how

496
00:28:14,960 --> 00:28:19,680
fast bad actors are able to move
the funds to off ramps, right. 

497
00:28:19,680 --> 00:28:25,120
You still need to convert those 
stolen funds into more usable 

498
00:28:25,440 --> 00:28:30,240
currencies, U.S., dollars, yuan,
whatever it ultimately is rubles

499
00:28:30,800 --> 00:28:35,120
to use them and it becomes this 
cat and mouse game that has 

500
00:28:35,120 --> 00:28:37,880
always gone on between law 
enforcement using tools like TRM

501
00:28:37,880 --> 00:28:40,840
to track and trace and then that
bad actor trying to off ramp 

502
00:28:40,840 --> 00:28:42,800
those funds. 
You know, you mentioned the buy 

503
00:28:42,800 --> 00:28:46,240
bit hack earlier in the wake of 
the buy bit hack last year, 

504
00:28:46,240 --> 00:28:52,560
February 21st, we about 1.5 
billion is the largest hack by 

505
00:28:52,560 --> 00:28:54,520
three times. 
You know that that's ever 

506
00:28:54,520 --> 00:28:59,400
happened before and we never 
also seen funds laundered and 

507
00:28:59,400 --> 00:29:02,640
moved as fast. 
Within the first few days fund 

508
00:29:02,720 --> 00:29:05,680
the entire 1.5 billion was 
converted from Ethereum to 

509
00:29:05,680 --> 00:29:08,200
Bitcoin and then that laundering
process began. 

510
00:29:09,120 --> 00:29:12,880
So what we realized was then 
that we need to move faster. 

511
00:29:13,320 --> 00:29:19,040
We really, we need to use AI to 
to supercharge our tracing 

512
00:29:19,040 --> 00:29:25,640
capabilities and, and we and we 
need to really, really wall off 

513
00:29:26,160 --> 00:29:29,440
that perimeter around those 
block chains to ensure that bad 

514
00:29:29,440 --> 00:29:31,440
actors aren't getting their 
funds back. 

515
00:29:32,080 --> 00:29:34,400
So a few months later in August,
we announced something called 

516
00:29:34,400 --> 00:29:37,760
the Beacon Network, which is our
answer to a lot of this. 

517
00:29:37,760 --> 00:29:41,800
And that is it's the largest 
information sharing initiative 

518
00:29:41,800 --> 00:29:48,120
in, in crypto. 
We have about, we have about 80%

519
00:29:48,160 --> 00:29:51,640
of all crypto transaction 
volume, centralized transaction 

520
00:29:51,640 --> 00:29:54,680
volume is part of Beacon. 
So think finance, Coinbase, 

521
00:29:54,680 --> 00:29:59,400
Kraken, OK, xblockchain.com, 
crypto.com, Ripple. 

522
00:29:59,680 --> 00:30:03,280
But then fintechs like Robin 
Hood and Stripe and PayPal and 

523
00:30:03,280 --> 00:30:06,800
we basically married them with 
about 70 global law enforcement 

524
00:30:06,800 --> 00:30:10,520
agencies who are flagging 
illicit proceeds and sending out

525
00:30:10,520 --> 00:30:13,640
real time alerts. 
Think Beacon Lighthouse, right? 

526
00:30:14,080 --> 00:30:17,480
And the exchange gets these 
alerts and before those funds 

527
00:30:17,480 --> 00:30:20,680
can move through the exchange to
that off ramp, they're being 

528
00:30:20,680 --> 00:30:24,160
blocked and then ultimately 
working with law enforcement to 

529
00:30:24,160 --> 00:30:27,880
seize back. 
So it's all about speed. 

530
00:30:28,440 --> 00:30:30,200
And that's the power of this 
technology, right? 

531
00:30:30,200 --> 00:30:33,520
Like the promise of crypto is 
cross-border value transfer at 

532
00:30:33,520 --> 00:30:36,080
the speed of the Internet. 
We can now move larger amounts 

533
00:30:36,080 --> 00:30:39,200
of funds faster than ever 
before, for good, for 

534
00:30:39,200 --> 00:30:42,320
humanitarian aid, for 
remittances, for payments. 

535
00:30:42,840 --> 00:30:45,240
And yet bad actors are trying to
do the same thing. 

536
00:30:45,240 --> 00:30:47,440
So we need to move as fast as 
they are. 

537
00:30:48,800 --> 00:30:50,760
That's yeah. 
That's really interesting. 

538
00:30:52,120 --> 00:30:55,560
I also had a question too, in 
terms of when we're talking 

539
00:30:55,560 --> 00:30:59,240
about law enforcement disruption
and how governments are kind of 

540
00:30:59,240 --> 00:31:02,000
approaching this, the issue of 
ransomware. 

541
00:31:02,720 --> 00:31:04,280
What do you think about 
sanctions? 

542
00:31:04,280 --> 00:31:07,120
Like how effective have those 
been and especially with kind of

543
00:31:07,120 --> 00:31:09,160
your your own background dealing
in that area? 

544
00:31:09,760 --> 00:31:14,040
Yeah, Look, I, I think sanctions
are one tool in a larger toolbox

545
00:31:14,040 --> 00:31:16,600
of national security tools that 
we should be implementing 

546
00:31:17,720 --> 00:31:20,880
against ransomware gangs, 
against these scam centers, 

547
00:31:20,880 --> 00:31:26,080
against Iran. 
You know, when I was at at 

548
00:31:26,080 --> 00:31:29,240
Treasury, we were talking almost
constantly about measuring the 

549
00:31:29,240 --> 00:31:31,560
impact of sanctions. 
And it's not always easy. 

550
00:31:32,520 --> 00:31:35,360
But I would say that sanctions, 
sanctions need to be deployed 

551
00:31:35,880 --> 00:31:38,800
against these groups and the 
states that sponsor them or 

552
00:31:38,800 --> 00:31:42,560
allow them to operate, you know,
pretty much unfettered. 

553
00:31:43,880 --> 00:31:45,600
But but we got to mix it with 
other tools. 

554
00:31:46,120 --> 00:31:49,880
And to me, the most powerful one
that we have today that we're 

555
00:31:49,880 --> 00:31:52,120
not using effectively is 
offensive cyber. 

556
00:31:53,040 --> 00:31:57,440
If if North Korea can steal 1.5 
billion from bibit or 285 

557
00:31:57,440 --> 00:32:01,000
million from drift, we should be
stealing it right back and more.

558
00:32:01,800 --> 00:32:05,640
And you know, it's interesting. 
I mean, we're in this really 

559
00:32:05,640 --> 00:32:08,840
interesting moment in human 
history where the private sector

560
00:32:08,840 --> 00:32:12,880
holds all of the data and the 
public sector has all of the 

561
00:32:12,880 --> 00:32:17,000
authorities. 
And our job is to provide the 

562
00:32:17,120 --> 00:32:20,560
public sector with all the data 
that they need to go after bad 

563
00:32:20,560 --> 00:32:22,720
actors. 
But I think it's also important 

564
00:32:22,720 --> 00:32:28,000
to empower the private sector to
go after bad actors similarly to

565
00:32:28,000 --> 00:32:29,800
the way we think about public 
sector. 

566
00:32:30,800 --> 00:32:32,960
You know, around the American 
Revolution and the, and the War 

567
00:32:32,960 --> 00:32:35,920
of 1812, we had these things 
called letters of Mark that 

568
00:32:35,920 --> 00:32:38,240
allowed us to go after pirates 
on the high seas. 

569
00:32:39,320 --> 00:32:43,400
I want cyber letters of Mark to 
allow us to go after these types

570
00:32:43,400 --> 00:32:46,680
of bad actors who operate on 
blockchains and in the digital 

571
00:32:46,680 --> 00:32:49,640
space today. 
So I think that sanctions are a 

572
00:32:49,640 --> 00:32:52,600
really powerful tool, but 
combined with law enforcement 

573
00:32:52,600 --> 00:32:55,360
authorities, national security 
capabilities like offensive 

574
00:32:55,360 --> 00:32:58,560
cyber and, you know, a host of 
other types of things, I think 

575
00:32:58,560 --> 00:33:03,240
we're more, I think we're 
starting to see the right, like 

576
00:33:03,240 --> 00:33:06,520
the, the right level of response
here from our government in the 

577
00:33:06,520 --> 00:33:10,320
US, from the White House. 
But there's still more work to 

578
00:33:10,320 --> 00:33:12,640
be done for sure. 
Yeah, definitely. 

579
00:33:12,640 --> 00:33:15,160
Absolutely. 
OK. 

580
00:33:15,160 --> 00:33:18,480
Well, is there anything else you
want to mention either about 

581
00:33:18,560 --> 00:33:22,000
kind of, you know, just 
cryptocurrency in general? 

582
00:33:22,000 --> 00:33:26,000
Yeah, you're in my sweet spot. 
I'll talk about all of it. 

583
00:33:26,320 --> 00:33:28,720
I think, Yeah. 
I mean, I think we covered a 

584
00:33:28,720 --> 00:33:31,120
lot. 
Yeah, I think we probably 

585
00:33:31,120 --> 00:33:34,320
covered a lot, but yeah, I don't
know anything else, any other 

586
00:33:34,320 --> 00:33:35,880
areas. 
I mean, obviously the ransomware

587
00:33:35,880 --> 00:33:38,560
piece is someplace that you're 
very focused and I, I feel like 

588
00:33:38,560 --> 00:33:42,600
we covered that pretty well. 
But yeah, no, I I felt pretty 

589
00:33:42,600 --> 00:33:44,400
good. 
Yeah, awesome. 

590
00:33:44,400 --> 00:33:47,680
Well, thank you so much, Arie. 
It was really nice to, you know,

591
00:33:47,680 --> 00:33:50,280
get some insight from you about 
what's going on in this space. 

592
00:33:50,280 --> 00:33:51,480
I really appreciate you coming 
on. 

593
00:33:51,840 --> 00:33:53,000
Hey, thanks so much for having 
me.

