85. How Companies Lose $197 Million in Seconds (with Channi Greenwall, Olympix)
35m 1s
In this podcast interview, Hany Greenwall, founder and CEO of Olympix, discusses the critical differences and heightened risks in Web3 security compared to Web2. Key differentiators include the inability to easily patch deployed smart contracts, complete transparency of on-chain code, and direct access to liquidity, meaning exploits can drain millions in seconds. Greenwall highlights the inadequacy of traditional, expensive human audits, noting that 90% of exploited contracts had been audited. Olympix addresses this by automating security tooling for developers, aiming to detect the majority of vulnerabilities programmatically and embed security early in development. The primary clients are crypto protocols with substantial value at stake, as security becomes non-negotiable when significant liquidity is involved. Greenwall's passion for high-stakes security problems, akin to medical device or aviation security, drove the company's founding. The discussion underscores that Web3 expands the attack surface, requiring a layered security approach that encompasses both Web2 and Web3 stacks to protect users' assets and company viability.
Hello everyone and welcome to another episode of the security podcast of Silicon Valley. I'm one of the host John McLaughlin. I'm joined the other host Sasha Sinkovich. And today we have an amazing guest to share with everyone, Hany Greenwall, the founder and CEO of a new security startup Olympics. Welcome to the show. Thank you for having me. So share with our listeners a little bit about Olympics. What is Olympics out to do? Do you think of yourself as a security person? Do I think of myself as a security person? Yes, I think it's very much twisted into my DNA. I have a technical background. So masters in security engineering, I worked in that field for a little bit before moving on full time to product and then to starting Olympics. I guess maybe be helpful then to go a little bit into the genesis of Olympics and where it came from. We'd love that. Okay, great. So like I said, traditional technical background started at Olympics after I personally deployed a side project on chain. I love security for context just because it's so much more fun to break than to build. And it's very dynamic, which I also as an ADHD highly stimulated person gravitate to things that are constantly moving evolving. There's nothing monotonous about it. So I started Olympics because personally deployed a project on chain. I thought, wow, this is such a unique attack surface. For context, just looking at Web 2 versus Web 3, you have three kind of key differentiators. The first being in Web 2, we live patch re deploy patch re deploy, you know, as Mark Zuckerberg famously says, move quick and break things, which you have the luxury of being able to do in the Web 2 traditional ecosystem. User wants to change on that. No problem. Fix, fix, fix, fix, Web 3 just deploying or changing your source code is such another animal. The second piece is the transparent nature. So again, in Web 2, we have the luxury of firewall and so many security systems that overlay and protect our underlying code. In the Web 3 ecosystem, everything's on chain. So you can deduce it at a source or provide code level. So essentially, it's transparent. And the third reason is direct access to liquidity. And I think this is the most interesting reason. So again, in the Web 2 ecosystem, if you undergo an exploit, they steal your data. Of course, regulatory comes down and the reputational damage and the payout sucks. It's a huge industry is to stop those things happening, right? Really sucks. It's horrible. It's fueled the 300 billion plus security market. However, it's nothing in comparison to if your entire company goes under via an exploit. So right now, you know, you get hacked in the Web 3 ecosystem and 12 billion in strain 27 37 197 million like that in a matter of a second. So security is so critical. And I found this really interesting because I always had a personal fascination and like these attack surfaces that have such high stakes. So something to compensate to would be like medical device security. If your medical device fails, insulin pumps, something like that. There's no coming back, right? So those are the stakes or, you know, if, for example, your airplane fails, you're gone. So these are like critical systems. So the same attack surface kind of translates, you know, three courses and it's a critical system because it can kill your company millions of people's money could just be drained in a matter of a second. So it was really fascinating. I was like, wow, there's hundreds of billions circulating here. There must be the most insane security second. I just want to see what people were building because I've always been fascinated by like these critical system attack surfaces and what people build there. And historically, it's always been like formal verification or like an interditional industries. I know it's really nailed it. And it turns out that the Web 3 ecosystem hadn't as well, which was surprising to me, given how much money was there. But it just shows the urgency for this technology that like people are building despite critical security infrastructure being in place. When we started Olympics in 2022, over 16 billion had been exploited to date, 90% of all exploited contracts. So I'm referring to smart contracts had undergone an audit, which is the only kind of security unlock that existed in the ecosystem. And to explain an audit, it is exactly like having a third party come in like a consultant. Look at your code. Tell you what's wrong. You make the changes and you implement them. Sounds good and dandy. If we had better numbers behind it, but when I tell you 90% of exploit contracts under with this audit, it becomes a little bit problematic there, right? Like those numbers aren't in the builder's favor aren't in the CEO of the company that's trying to play on trying to favor when if I get one audit, not necessarily bullet proof if I get to. And then let's just dial it back a little bit to the cost. Like people are paying anywhere from 25k to 250k for each audit. And they're having to undergo multiple. And still, it's not full proof. Some companies were getting 10 plus audits and still losing money. So a human, as we know, can only find so much. And there's always going to be something smarter or a layered approach when it comes to security that that needs to be embedded. In 2022, a lot of security companies actually saw this problem. Like a lot is getting hacked. We need to do something. No one except Olympics said, let's solve it by giving security tools to developers embedding security first. Majority of companies either did like some type of like architecture chaos engineering tool that they sell directly to the business or through doubt, or they did on chain monitoring, which was probably the most popular, which is like, Hey, inevitably everyone's going to get hacked. Let's alert you when you do. And then you can do something about it and hopefully we can mitigate the losses, which again is so important and critical part of the stack. But what if we could just bring that number down altogether, that experience to hack? And so our north star from the engineering standpoint is what percent of historically was done by humans can we automate? Not to say we're going to replace this human, but why does the human need to be finding everything? Why can't we find 90% and we leave that 10% for the human and then lower the stakes and lower the chances that you actually get exploited in the first place. So yeah, that's a long one answer to like what a levyx does in our genesis. Are we mainly talking about public, private or permission chains? What is the biggest customer that you see the engagement with? Who's our biggest customer? Circle. Where are they launching on Solidity? We're seeing the most. I think it's like 90% of development is on Solidity. We're seeing a bit of a move towards Lana, which is rust, but historically it's been primarily like EVM compatible chains where majority the liquidity is on and like wherever there's money, there's hackers and wherever a hacker security needs to be the first step in development. Okay, and I think that answers my following question, which is what type of assets have we protected? Because with blockchain, you can not only store the currency assets or assets that can translate into the currencies. We can also talk about data storage. That's what blockchain is good for is just to store lots of data, but it sounds like the specific use case that we are addressing here is the asset protection. Yeah, I think they're saying interesting here. So like in traditional Web 2, security is mandated by regulatory, meaning whatever we're told we have to do, we do. Not necessarily because we care about security. The Web 3 goes to stem, there's no one telling you have to just think besides like maybe one audit by good audit firm and what people will do that, but anything additional or any additional layer, there's no really incentive to implement unless you have a large amount of liquidity at stake that could be compromised. And that's where we see majority of our customers coming from. So once they hit, you know, about like five million in volume within their protocol or moving through their protocol, they start to engage with us. You know, we have companies that are moving tens of billions every day. And then we have companies that are as small as, you know, five, 20 million. That to be said, like it's just as important that security is implemented in the small teams and big teams because as soon as one x, what happens to a small team that's very vulnerable like their company's gone under. And those first couple years of starting company are the most critical to get everything right. And no one believes in you whatever. So like they finally get the traction. And we've seen this happen so many times. Like these teams finally get the traction. And then they get exploited because obviously bad actors see like, okay, a lot of money is here. And this contract, which is on chain and public is vulnerable. Let me go after that. And then like there goes the six, seven years of hard work that these founders put in. Right. So it's really, really crazy. Yeah. There's a lot of stake. And like these are people's dreams. People are putting everything that they've got behind these companies, trying to do the zero to one thing. I have all the respect in the world for that. Right. And like forget the founders even. It's also about everyone globally who's distributing their capital here. So in America, we're so used this luxury of trusting our dollar and putting our money in the bank and we're not worried anything is going to happen to it, right? And when has their thoughts on politics and the general economy push comes to shove, no one's worried that they're not going to get their four percent back or their money isn't safe in the bank in Venezuela and Brazil. These isn't the case at all. And they rely on these decentralized modes of training, staking, borrowing, lending. Like if one of these protocols failed, that could be their life savings. And by the flip side, if they're working and they have good security infrastructure, that could allow them financial autonomy. But there's two sides to the story and they play out very differently depending on how securities embedded into the development of these crypto companies. Yeah. So let's pretend I'm a crypto founder for a second. I'm doing some on-chain stuff when I've got like a smart contract out there. And I'm listening to this and I'm thinking to myself, wow, maybe I could take a closer look at this. Even before I get big, can I go to olympics.ai? Yeah, you can go to our website. It's not self-service. We have a free tool that about 30 percent of salinity developers use. That automates about I'd say like 20 percent of what historically is found by external audits where we see like the mover that gets you more to like 60 or 80 percent are paid tools. So we have different hearing there, but you can always just reach out directly on our website or to us on LinkedIn and we on board. Well, that's incredible. You have 30 percent market penetration into this smart contract space without a dollar. Yes, spent on any advertising. Congratulations. That's huge. And I see that you've been doing this for just over three years now. Yeah, just about three. Did something happen? You did your own on-chain adventure and you were a founder and it looks like you started the 10,000 hearts NFT. Was there a moment where you were like, uh-huh? So I think it was like a rabbit hole. So first of all, I was just living in Miami because I worked directly for a founder of Late Stage Cybersecurity Company. And I didn't know many people there. So I was just, I was anyone's working nine to nine, but you need something to do nine kilograms to one a.m. And I don't personally like TV. So and I didn't know anyone really there. So I was like, I'll just work on a side project like a lot of smart people. I know I'm moving full time into the web three ecosystem. I don't know much about it and I personally learned best by doing. So I'm like, let me just launch a project like everyone's launching out a few of the fun, grab some interns worked on that. I'll preface it with just like a night project side project in doing so again is when I realized the differentiation and the tax surface. And like I said, I've always been so drawn to the type of the tax surface that has such high stake more because I just like see what people are building, how you solve for that to make the technology accessible despite the high stakes. And that's such an interesting security question. Like I always want to start a medical device security company because of that reason, but just from a business perspective, it's a very hard thing to actually implement and scale given regulatory, given hardware. There's so many pieces there like all models are so different. So it never made sense for me to pursue that dream, but like it kind of paralleled in the sense of like high stakes, the tax surface, really interesting problem. And then as I began, like I said crawling down that Robin, like I just want to see what people are building. Why can't I try building something? And it was hard for me definitely because I really loved my job at the time. So it's not that I wanted to leave my job at all. It was more that this problem was riding my face. I thought how incredible if I get this opportunity to try and solve it. And you know, each day I feel grateful because as we begin to unlock like how to solve it and how that actually looks. It's like we're the ones doing this. It's so interesting. We're building symbolic execution machines buzzers like we're automating formal verification. Something historically that was so hard, so manual and so easy to get wrong every day. It's so fascinating to like climb down this to solve for each of these hard technological problems. Is Web 3 security any different than Web 2 security and how? Yeah. So like I said, there are three reasons Web 2 security comes down to like what is regulatory pushing. So three big differentiators in terms of attack surface like I highlighted to one is in Web 2 you consistently are patching redeploying patching redeploying like you have that freedom to consistently build change build change ship ship ship ship ship in Web 3 because the systems are so subject to error and things can go so wrong. You have to be so careful and so aggressive with the testing before deploying. So that's like the first differentiator. The second differentiator is the transparent nature. So when you deploy on chain, you're looking at anyone being able to see it. So like there's beauty to that and that's part of this ecosystem is like everything's transparent. On the flip side, any bad actor can go and see any hole or flaw in your code. Whereas in the Web 2 ecosystem, we have so many layers and fortresses of protection sitting in front of us. Like there's so much more going on before someone can even access the source code with Web 3. It's just sourced our bike code in a flash. We can have it. And the third thing is again, like I said probably the biggest is direct tax liquidity versus data on Web 2. You're always compromising your data. Of course, regulatory comes down. Of course, reputation. There are components that are huge and that fuels a 300 billion plus industry of companies that operate there. But it's not the same as losing 12 million 27,997 million in one shot. I just say that tax surface if I was spoiled down to two things, tax surface is larger and the stakes are higher. You say the biggest risk with Web 3 security is the intricacies of the contract that you define and then you essentially publish on the chain and everywhere can use that contract. And there is very little room for making errors in the definition of the contract because then it becomes public and you can exploit the contract itself. I think what you're referring to is like contract logic that it meets the law that I'm supposed to. And I think that's a component of Web 3 security and smart contract security. But it's not the only piece. There's also like you miss a reentering cigar and you have a certain pattern within your code that can lead to major funds being drained. And like that doesn't necessarily break the logic. It's just if someone changes one thing from five to zero, the study and an external call are can drain. So like I think it's part of it. But I think the larger thing is just that the general tax surface is so much greater and that requires a greater amount of spend, a greater amount of testing and people are still adapting to that reality that like it can't look like. For example, the spend for the same size Web 2 startup is not going to be comparable at all to someone deploying on chain because they don't have the same risk. I think that's where I was leading the Web 3 in general is a fairly you mass product. It's not a new technology, but it recently has seen mass adoption. But there is not enough expertise in Web 3 and understanding how Web 3 works in order to secure it. And so you have this disbalance of security talent on Web 2 versus understanding how to secure Web 3. Yeah, I think that's absolutely right. And I think people underscore how much going back to the spend needs to be allocated for deploying on chain. For example, like there's a very notorious hack that happened this year. The Bybit hack. It's well over a billion dollars and it was actually classical like Web 2 exploit. It just they happened to operate on chain. So like part of their responsibility is securing both the Web 2 and the Web 3 stack because they deployed both. However, like they can actually get the consequences of the on chain component, meaning like liquidity being drained. Be a Web 2 so people can come in this way. So there's like a lot more when when you think of a tax surface red just refers to the amount of space that's vulnerable. There's just so much more vulnerable space and the solutions can be so much more layered and irresponsible for exponentially in turn. And so like you have to both have a Web 2 security expert and a Web 2 security expert and you need to understand where they overlap and where you're vulnerable and where like those holes are that someone can weave from like Web 2, you know, interface into into your Web 3 stack. So it sounds like the problem statement is still the same. How do I protect and you have to answer questions of what am I protecting and against who and then you go into standard logical flow of identifying the attack surface, which you have mentioned many times, then you answer the questions and you still have to protect infrastructure. You still have to protect the Web 2 infrastructure and some of the logic and then you have to think in depth about securing the Web 3 component of that stack. So just additional layer. So I love your story. You built those nights and weekends and you had your job at the same time and you're kind of like probably burning both ends of the week. So to speak and you're in Miami and then you mentioned that you had a couple of interns and you just built and you just threw yourself into this hard problem and you took a stab at this and you built this up. Sorry, sorry, I want to clarify. The intern project worked on with the NFT project. I didn't actually start Olympics full time until I left security scorecard. So that was just like a side project. Yeah. So you've been in security and your passion is clearly security. I love that. I love that you're tackling hard problems. So thank you. Thank you for that. That helps make the security community better. That helps make our futures more secure. Whether they go on chain or in traditional space, it's a win across the board for the community. And I'm super curious like when you were you're grinding and you're heads down and you're focused and you're building this up. Did ever crush your mind to maybe think about having a co-founder? I have a technical background and no problem built the out the first version. Of course, you always hire people smarter and better than you and push yourself out of as many roles as you can except for the roles you extremely excel at. So I was very quick to hire and scale the engineering team after and our team is mostly engineers. But at the time I didn't have someone that I wanted to tackle this problem with. And since that and since validating our idea, we brought on key employees. They own significant equity stakes. They operate as business partners. But ultimately like I found it the company. So I'd say it's not that I was like opposed or four or whatever. There just wasn't someone. Yeah, I was doing it with or without someone with or without funding. Like there was nothing stopping me from solving this problem along the way you find the pieces and the people. Did you raise money? We did. We raised a seed round. Where do you see the next level of adoption of Web 3's technology across all of the industries that are right for the adoption of Web 3? You know, it's so hard to say because I'm constantly in awe of the solutions that my customers are providing. I say like I have the most unsexy. Like obviously me, it's like the sexiest thing in the world. Like security and the problem we're solving is so cool. It's so interesting, so novel. Every day it's like the hardest problem. However, in most people like they do not care. But the ideas or customers come up with and the amount of people that come behind and begin deploying on chain and begin interacting with their apps is crazy. I actually just got off the phone earlier today with a company and their belief is like you shouldn't think of Web 3 versus Web 2. You should like developers because by coding in the convergence of AI is becoming so widespread, you should think of everyone as a developer. And in the future, everyone can develop and we've been able to create like a platform where everyone can deploy on chain. The market size is huge. So it's really hard for me to stay like obviously gaming's right. Obviously you're seeing like these bigger moves of stripe requiring multiple Web 3 companies of circle going public. There's the payment side like every major bank is moving RWA's real world assets. I wish I could like point one thing be like this is the biggest mover. And probably if you read a VCs website every couple months, they'll cite something else. But ultimately to cross the board, it's a matter of 10 years that everything is on chain. What do you think drives this adoption? Is it the efficiency that chain allows you to have for what is the main driver? For like mass developers, it's usability from like the economic standpoint. Of course, it's efficiency and money-shaped. It's like, why doesn't it cost $100 when it could cost $1 to move money? There's a lot of different applications there. We would think it's like silly applications, but they make a lot of sense. I know companies and it's for wine collectors. Apparently that's a huge market. They've created NFTs of every single line. So you can validate that this is like a true real legitimate bottle. And I guess there's a huge market for fakes out there. Like by the save token art, right? Like people are tokenizing art a lot. And like these aren't markets where I think would move on chain just wouldn't come to mind first. However, people are operating building there. There's huge markets and a lot of people behind it. So like, it's hard for me to say like a word of point to one. Of course, like the financial industry as a whole, just moving and off-boarding trillions of dollars into the ecosystem. But like it's so much more than the I can see. The use cases are beyond what you can imagine. Like I'm an entrepreneur who is tokenizing meditation. Like I guess some companies like to create this benefits and want to incentivize their employees to meditate. And so like they do that by when you meditate, you receive tokens. And I'm just like, that's an interesting idea. It seems kind of hard to execute, right? In my head. And she's like, I have 1000 users already and ex-thousand companies onboard. And I'm like, wow, I would have never thought like this application would be on chain. So I guess from saying it's like why it's so compelling to me is like the problems that people are solving and like using our technology as the underlying barrier to like get there or beyond my wildest imagination. So like there's so many ideas. And like me, the three of us cannot even fathom what people are thinking of right now. Like I was so again, like a children off this company. I was speaking to this morning where they're just like the futures of conversion. There's not developer, regular person. There's vibe coding for all. And like if we can make it easy for them to deploy on chain. And they have thousands of users every month. People who are not technical deploying on chain. Who would have thought, right? Especially even a year ago, especially two years go and have tax collapse. Everyone thought it was done. So I could tell you with a very strong conviction that then 10, 15 years, everything's going to be on chain. I look forward to it. I look forward to it being just as secure as ever with folks like yourself thinking through all of the tough security problems too. So who knows what's going to be in the future? And vibe coding is now changing things and opening up possibilities for folks that it was out of reach and it's changing the way engineering is working. I'm super curious. You started in Miami. And for the benefit of all of our listeners, I think you're in New York now. That's New York City behind you. Right. Yeah. So I was working for time in Miami to work directly with my boss. I do believe it in person work is the best work. But I've been in New York for over 10 years. And so I always kept my apartment here and moved very quickly back. I don't think Miami is the place to start a company. Where did you grow up in California in San Francisco? We grew up in San Francisco. Wow, you're San Francisco native. Yeah, it's well. But New York is just very crypto centric. And so just started crypto company in New York is best. And like I've been kind of hunkered down here for a long time. So made sense for me. And so also you have to think about like where you're bringing canned employees and you want to bring them to a major city they're excited about. And New York happens to be a city that people get very excited about and love to live it. Very exciting city. Lots happening. Well, congratulations on hitting your escape velocity from San Francisco. That's that takes skill. What's been the proudest day so far on your entrepreneurial journey? I think the goal post always moves there. First, it's taking the risk to start a company. Then it's you get people behind you. Then your product works. Then it gains adoption. Then you're selling. Then you can't even take on the scale of the people that want it. And then people who used to laugh at you are trying to copy that goal post moves every day for me. You want it to keep moving right like when I think about like what's the next thing I'm proud of it? Like I want it to be we onboard the next 10 million users and they're able to deploy contracts securely and quickly and cheaply and efficiently because of us. I definitely can't point to one moment. I could say like every day if you ask me or if like they look forward to it changes. I think that's where exciting. Sounds like every day is the proudest day. Every day something great happens, right? Like some day suck. Some day suck. I mean speaking of days that suck, I know being a founder can be filled with super high highs and then super low lows. Those are very vulnerable moments for founders. You see people's true colors like in those days. Have you had a most difficult day on your journey? You know, this question's really hard to answer because I feel like they happen at such a regular cadence. And when you look back, it's like in retrospect, that wasn't that bad. Like I learned this and this thing doesn't feel like such a big deal anymore to me. And like if this happened to me today, it wouldn't be a big deal. So I think Elon Musk famously says it's like starting a company is like consistently chewing glass. And I think that's very apt. They have been very regularly. And like it couldn't point to one day, but like I will say when you look back at the ones that you thought were like chewing glass, like now it's like eating paper for me. Like I could do that kind of day any day now. And so I guess by the same token as like proudest moments, like the goal post keeps moving for like how hard or how sucky they can get. They always suck, but they always like in retrospect like become easier as you continuously go through a hard times. That's good and bad. It's like you said highs and lows all the time. I think one of the most incredible pieces about being a founder, specifically in the security community is like you have the superpowers to be able to look into the future and you see something different. You see something that most people don't see. And I'm curious if you look into the future, what do you see in terms of maybe the greatest security challenge that we're going to face as a community? Like the way things are going, the way things are changing on chain AI. I mean, obviously I think that's what we're building. Here's what the world looks like today. A lot of people are trying to play on chain. The current solution is broken. 90% of x-pload contracts are audited. That's the current solution. And yet they're still 90% fail right there. If I see the future as everyone's going to be on chain in the next 10 to 15 years, it will not happen unless our solution becomes like a mass scale opportunity for people to deploy securely on chain, which means we have to be able to build something that automates what historically was done manually better, not just better like five 10x better and gives people the freedom to deploy on chain. And so it on boards the next 10 million users like I genuinely think the problem we're solving is the hardest problem, but I'm not exposed to other problems of other industry. So it's kind of it's it's a very biased answer, right? Like I'm sure if I sat down and like looked at other like deep tech security companies, their problem is also very inherently hard and difficult and I might have the same sentiment, but because I'm biased and facing this every day, I do think it's obviously so important to me, so critical and the ecosystem and world will not scale without it. Let's play out that game, right? Like we're going to get hundreds of thousands of auditors and they're all going to have 100% success rate as humans know that that's not feasible. So like you believe in a future where everything's on chain, there's needs to be an automated security infrastructure approach. And inevitably we're the only people positioned to do it right now because we're the only people betting on that and we're the only company with major adoption there. Do you feel like it's just crazy that the AWS is of the world and that Google GCPs of the world, the deserves and maybe even a central banking system is not taking this more seriously, this change that's coming. I think it'd be surprised. I think Coinbase came out with a report a couple quarters ago that the average Fortune 500 has at least a $1,500 million dollar budget for on-chain initiatives. I think again, that's all experimentation and that's very small in comparison to like their overall budget for every other initiative they have, but like no one's really thinking of a joke and I think Stripes Acquisitions recently just went to show like people are beginning to delve here at whether it's this year next year. I mean mastercards about to deploy something on-chain, gold men, JP Morgan. I'd say like the top 50 top 500 companies definitely have budget and resources going towards on-chain initiatives. They're not blind to but like, of course, yeah, it'll speed up and become exponentially large-rast time goes by. And the decentralization of compute, of storage, and of money, it's going to disrupt the way that we think about those things, right? Everything, yeah, yeah. But I mean, like if you think about any like other disruptive technology, chat, GPT was the thing that kind of spun off. Everyone's crazy obsession with AI, all these AI companies. I don't even think like I know that was the moment, but there were of course early believers like open ads start eight years before that huge boom in rush of users and so with anything like people kind of push it off or like kind of semi-ignology, but they don't realize the scale until it happens. And that's that like escape velocity moment. And I think right now we're like three, four years before like that initial wave of escape velocity five, six years before like mass mass adoption. So I think it's coming sooner than you think, but it's in token we're also still in the early days. So early, we haven't even seen like early adoption yet. I think Coinbase just joined the S&P 500. These crypto companies are growing faster than you think. It's a good thing. It's going to help bring positive change. Right 100% especially globally. Have you thought about what legacy you want to leave? I know you're still very young and so it's like maybe a silly question. Are you just getting started really? I guess that I never shrunk myself to what people think should be the status quo or should go around like obviously. I think that just plays like being able to see something and chase after it despite how many obstacles knows rejections come after you. It's an important quality, but I guess it's like in terms of legacy, I think the most important thing to me is what I bring and pull out of others. I think it's also like one of my best qualities is that I'm able to find the best people and then I'm able to extract and push them to their highest level of greatness and things they might not have been themselves aware that they were capable of. So I think that's probably most important to me because I feel really great when I'm able to do that. I think it's really impactful and then by the same token, the products that we create as a team or deploy it also touches the customer. Who does it make the customer become? Now this customer is a security first, they're a security engineer. They went from developer to security engineer because they have all these tools like we're able to again extract the next level from that. So whether it be me being there personally and extracting that level from people and demanding greatness so they build these great things or the products themselves transforming individuals into their next level that they never knew they would have access to. I think that's probably the most powerful thing you can do. And just to play off that a little bit more, what is your most memorable day on the journey so far with Olympics? Just to scope it down a little bit. I think memorable comes back down to like that question about what was your biggest success. And I did like that goal post keeps moving. But I think like the first memorable moment was when someone collected a bug bounty using our tool. I thought that was really cool. Like our tool was able to get them money because like we've got security fuss. So that told us how powerful our tool was. It's replacing some security researcher and is able to find holes. And then recently one of the top audit firms, one of our customers underwent an audit from the top audit firm and our tool automated 100% of the findings at the audit firm found. So that just again validates to us. You know when you start a company you kind of think like I have an 80% shot that this will work or 70 like even kind of 60s enough convictions to start and that conviction grows as you begin to deploy product and adoption whenever like when those technical milestones hit. I think for me like right now I'm at like 95 97 percent conviction that could work which means I should be moving faster like when you get to that it kind of crazy like it's almost that's maybe when you're too late. And like it's good because we start early and like it'd be very hard to catch up with us now. But it's funny because I also think about the future when I think about memorable like I envision what will happen in the future. And like it feels like it's already happened. It sounds silly. But I think you envision it so much that it's like becomes a memory of like you seeing something as true. And I think you have to be like that psychotic to like do something like this where you see something as true and it needs to have this change in order to be true. And that drives you to build it every single day. You have to be crazy to be a founder. There's no way around that one. Yeah you have to really really believe that that what you're going to do is going to change the world. Otherwise why would you be investing your time and resource? I guess if you're really young then like maybe it's just like a fun experiment for you. But like I think at a certain age when you have a family when you have kids like you're making no money and you're really sacrificing on a lot of levels. You're sacrificing time with family. You're sacrificing so much that you would be doing with anything. But you have to believe the tradeoff is worth it. And I believe the tradeoff is worth at a million fold. And I believe we can execute on this a million fold. And so with that being true like no other reality exists to me besides building Olympics with full conviction, full energy with 100% of me in it. Going back in time a little bit. If you had an opportunity to meet your younger self, would you take that opportunity? And if you would, what sort of advice would you have for your younger self? I think I would just say trust your gut. I think when I look back at anything that I feel like was regret or I would even say like I move too slowly because usually I get there but sometimes I move too slowly or historically and like probably the biggest lesson that I've learned as a founder and as a human is like just move faster and trust your gut and usually you're right sometimes you're wrong like when you're wrong it's okay just move quickly and get there so I'd probably just say trust your gut. I love that intuition and it works it's right there. I think you know a lot more than you think you know yeah and by the so does everyone. As everyone who works at Olympics, I often defer to them like what does your gut tell you? Often they know better than me because they're sitting and sunk into this problem. And when you push that question usually the answer and ends up being so meaningful. I love that. You know we have a lot of entrepreneurs, aspiring entrepreneurs, folks running small companies, folks thinking about their next idea who listen to the show. And so this is a little bit of a leading question. Always super fun to ask but is there just one tool or service that you wish someone would just go out there and build already because you've bumped into this problem over and over and it's not your area of expertise so you don't have time to solve it and you just wish this problem would just go away and you'd be willing to pay money to have this thing solved. Does it have to be security related? No no it could be anything. I would love for there to be a good swimwear shapewear. I think that would be amazing. No one's built like a nice looking swimwear that shapewear. And I feel like it's the most simple in your face thing. It's very easy to execute on from a consumer perspective. Everyone knows how to build good shapewear at this point. Everyone knows how to build swimwear like you just need a layer of the two and like create a good line. And I think that the revenue opportunity and the huge there. I think that's like that that would be a huge consumer facing company but I have no external consumer issues like deep tech. But like as a girl, I would love that. I think that would be awesome. I need major businesses that are built off that right like spank shapewear, skim shapewear. I don't know if you've read that book but like the whole thing is like there's nothing for a woman like buying a new pair of shoes like there's the emotional and psychological piece of clothing that plays into like female psychology that I think is very powerful and that can drive a lot of revenue. And I think if you could build gorgeously executed shapewear, swim brand, people would enjoy that and make them feel good and make a lot of money. Thank you so much for sharing. This has been an absolutely spectacular, very educational episode on web 3.0 security Olympics. It sounds like you're making incredible strides, helping build a more secure future for all of us. I'm one of the host John McLaughlin joined with our other host Sasha Sinkovich and for all of our listeners, honey green wall, the founder and CEO of Olympics. Thank you so much. John and Sasha. And thank you both of you and to all of our listeners for turning into another episode of the security podcast of Silicon Valley. This has been a why security production. Please stay tuned for the next show and if you feel so compelled, please give us a rating. Drop some comments and share on your socials.
Podcast Summary
Key Points:
Web3 security presents unique challenges compared to Web2, including immutable deployments, transparent on-chain code, and direct access to liquidity, making exploits potentially catastrophic.
Traditional security audits in Web3 are costly, human-reliant, and insufficient, with 90% of exploited smart contracts having undergone one.
Olympix aims to automate security for developers by embedding it into the development process, targeting a high percentage of vulnerability detection to reduce reliance on manual audits.
The primary customer base includes crypto protocols with significant liquidity (from ~$5M upwards), as the financial stakes drive the need for robust security.
The motivation stems from the high-stakes nature of Web3, where security failures can instantly destroy companies and wipe out users' financial assets.
Summary:
In this podcast interview, Hany Greenwall, founder and CEO of Olympix, discusses the critical differences and heightened risks in Web3 security compared to Web2. Key differentiators include the inability to easily patch deployed smart contracts, complete transparency of on-chain code, and direct access to liquidity, meaning exploits can drain millions in seconds. Greenwall highlights the inadequacy of traditional, expensive human audits, noting that 90% of exploited contracts had been audited.
Olympix addresses this by automating security tooling for developers, aiming to detect the majority of vulnerabilities programmatically and embed security early in development. The primary clients are crypto protocols with substantial value at stake, as security becomes non-negotiable when significant liquidity is involved. Greenwall's passion for high-stakes security problems, akin to medical device or aviation security, drove the company's founding.
The discussion underscores that Web3 expands the attack surface, requiring a layered security approach that encompasses both Web2 and Web3 stacks to protect users' assets and company viability.
FAQs
Olympics is a security startup focused on Web3, aiming to automate security testing for smart contracts to reduce exploits by embedding security tools directly into the development process.
Web3 security involves a larger attack surface with higher stakes, as code is transparent on-chain and exploits can directly drain liquidity instantly, unlike Web2 where data breaches are more common and patches can be deployed continuously.
Challenges include the inability to easily patch deployed contracts, transparent code that exposes vulnerabilities, and direct access to high-value liquidity, making pre-deployment testing and automation critical.
Olympics primarily serves crypto companies with significant liquidity, such as those moving millions to billions in assets, with engagement often starting when protocols handle around $5 million in volume.
Olympics provides both free and paid tools that automate security checks, with the free tool used by about 30% of Solidity developers and paid options offering more comprehensive coverage.
Traditional audits are manual, costly, and not foolproof, as evidenced by 90% of exploited contracts having undergone audits; automation is needed to cover more vulnerabilities and reduce reliance on human review alone.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.