Cedra Talks: Inside Web3 Security with HackenProof

Exploits, phishing attacks, and infrastructure breaches continue to hit the Web3 industry almost daily. That’s why security has become one of the most critical conversations for builders today.

In this episode of Cedra Talks, Diana King from Cedra sat down with Dmytro Matviiv, CEO of HackenProof, to discuss the current state of Web3 security, recent exploits across the industry, bug bounty programs, AI-driven development risks, operational security, and the growing sophistication of attackers.

The conversation explored why so many projects continue to underestimate security risks, how AI is changing both development and hacking, and what teams should prioritize from day zero before launching products publicly.

Diana King: Welcome everyone to Cedra Talks. Today we’re diving deep into one of the biggest challenges in Web3: security. Our guest is Dmytro Matviiv, CEO of HackenProof. Thank you for joining us today.

Dmytro Matviiv: Thank you for inviting me. Happy to be here.

Diana King: Before we begin, could you briefly introduce yourself and tell us more about HackenProof?

Dmytro Matviiv: I’m the CEO of HackenProof, a bug bounty platform and crowdsourced security marketplace. I’ve spent almost 15 years in cybersecurity, focusing on cryptography and security research. Our team has been operating for over nine years, helping projects strengthen their security and better protect their infrastructure.

Diana King: We’ve recently seen several major exploits across the industry, and incidents seem to happen almost daily. Why do you think this keeps happening in Web3?

Dmytro Matviiv: The industry is moving extremely fast. Teams are trying to reduce costs, ship products faster, and increasingly rely on AI tools for development and automation. At the same time, attackers are improving their own methods and capabilities. This combination creates an environment where vulnerabilities appear constantly, especially when security is not treated as a core priority from the beginning.

Diana King: What are the most common attack methods you see today?

Dmytro Matviiv: Most attacks fall into three categories: team compromises, operational security failures, and vulnerabilities in smart contracts or infrastructure.

A major issue today is private key compromise. Attackers increasingly use phishing, social engineering, compromised devices, or operational weaknesses to gain access. In many cases, the smart contract itself is not the main issue.

Diana King: What security mistakes do even experienced teams continue to make?

Dmytro Matviiv: Many teams believe that completing a smart contract audit is enough. But security goes far beyond smart contracts.

Projects also need to secure their infrastructure, backend systems, frontend applications, internal operations, and key management processes. Teams often prioritize speed and cost reduction over long-term security planning, especially early-stage startups operating with small teams and limited budgets.

Diana King: How has the rise of AI and “vibe coding” changed the security landscape?

Dmytro Matviiv: AI significantly accelerates development, but it also introduces new risks. Developers can now generate large amounts of code very quickly without fully understanding what’s happening under the hood.

This creates situations where products launch faster but with hidden vulnerabilities, weak architecture, or poorly reviewed logic. AI is useful for experimentation and prototyping, but relying on it blindly for production systems can become dangerous.

Diana King: We constantly hear about North Korea-linked groups in reports around major crypto exploits. Why do these groups continue appearing so often in large-scale incidents?

Dmytro Matviiv: These groups are highly motivated, organized, and patient. In many cases, they spend months building trust, integrating into ecosystems, or targeting operational weaknesses rather than directly attacking smart contracts.

Defenders need to protect every part of their infrastructure all the time, while attackers only need one successful entry point. That imbalance creates enormous pressure on security teams.

Diana King: How do bug bounty programs work in practice today, and are they still effective?

Dmytro Matviiv: Bug bounty programs remain extremely important, but the landscape has changed dramatically because of AI.

Previously, projects might receive a few hundred reports per year. Now they can receive hundreds per day. The challenge today is filtering valuable reports from noise while still responding quickly to legitimate findings.

Ignoring security researchers is risky because vulnerabilities will eventually be discovered by malicious actors instead.

Diana King: If you were launching a new crypto project tomorrow, what would be your top security priorities from day zero?

Dmytro Matviiv: First, I would establish clear operational security processes and internal checklists.

Second, I would focus heavily on key management and access control.

Third, I would build a culture where security is treated as an ongoing responsibility, not a one-time audit before launch.

Security has to become part of the entire product lifecycle.

Don’t miss the next Cedra Talks sessions, and join the Cedra ecosystem to stay connected with builders and core contributors.

Explore more here: https://linktr.ee/cedranetwork. 

← All posts