July 17, 2026

#120 AI, Bitcoin Security & Self-Custody: How Casa Protects Your Wealth | Paul Brower

#120 AI, Bitcoin Security & Self-Custody: How Casa Protects Your Wealth | Paul Brower
The Crypto Podcast
#120 AI, Bitcoin Security & Self-Custody: How Casa Protects Your Wealth | Paul Brower

In this episode of The Crypto Podcast, Roy sits down with Paul Brower, Director of Engineering at Casa — the gold standard in Bitcoin self-custody — where he leads a 12-person team building AI-first workflows to protect billions of dollars in Bitcoin. Before Casa, Paul spent seven years building the first FDA-approved digital pill software, was an early Bitcoin adopter since 2011 (including a Mt. Gox close call), and even spent three episodes on an MTV reality dating show.

Paul breaks down how Casa's multi-sig self-custody system works (2-of-3, 3-of-5), how attackers are now using AI-powered spearphishing and deepfakes to impersonate support staff, and how cryptographic PIN verification protects users from social engineering. He also covers key loss prevention (health checks, hardware redundancy, YubiKeys vs. Trezor/Ledger), Casa's inheritance system for passing on Bitcoin securely, the risks of giving AI agents access to financial accounts, and why physical air-gapped hardware remains one of the strongest defenses against an increasingly AI-powered threat landscape.

Video Chapters

0:00 – Introduction & Welcome

0:23 – Meet Paul Brower: Director of Engineering at Casa

1:20 – Reality TV Detour: Paul's MTV Dating Show Story

2:12 – Why Psychology + Computer Science? Understanding How People Work

2:55 – Building the FDA-Approved Pill with a Potato Battery

12:15 – Career Path: From Pegasystems to Springpad to Casa

15:59 – Bitcoin Since 2011: The Mt. Gox Days & Surviving Every Crash

27:27 – The Problem with PayPal (and Why Bitcoin Is Different)

12:15 – What Is Casa and How Does It Work?

16:01 – Casa's Multi-Sig Setup Explained: 2-of-3 and 3-of-5 Vaults

16:01 – AI-Powered Spear Phishing: How Attackers Are Targeting Crypto Holders 21:21 – Seed Phrases, Floods, Kids, and Why You Need Redundancy

29:23 – Cold Wallets: Trezor vs Ledger vs YubiKey — What Casa Recommends

33:01 – Casa Inheritance Planning: What Happens to Your Bitcoin When You Die? 39:01 – KYC, Privacy & Buying Bitcoin Without Giving Up Your Identity

41:23 – AI Agents + Bitcoin: The Most Exciting Frontier in Crypto

Contact Details

🔗 About Your Host (Roy Coughlan)

Guest:
Paul Brower — Director of Engineering, Casa
🌐 paulbrower.codes
🌐 casa.io

#CryptoPodcast #Bitcoin #BitcoinSecurity #SelfCustody #Casa #MultiSig #CryptoSecurity #AIAgents #Spearphishing #DeepfakeScams #BitcoinInheritance #CryptoScams #DigitalAssetSecurity #BTC #CryptoNews

Welcome to The Crypto Podcast. You can find all our episodes on thecryptopodcast.org. What happens when you put artificial intelligence inside one of the most secure and high stakes environments on the planet, a system protecting billions of dollars in Bitcoin? Today's guest has been living that question every single day. Paul Brouwer is a director of engineering at CASA, the gold standard in Bitcoin self custody, where he leads a 12 person team building AI-first workflows in an industry where a single mistake doesn't just crash a server, it can wipe out someone's life savings forever.

Before CASA, he spent seven years building mobile software so secure and precise that the FDA approved it as a medical device, the first of its kind. He's an early Bitcoin adopter, a psychology and computer science graduate, father of four, a guy who literally built his own home and a TV reality veteran. Paul, welcome to The Crypto Podcast.

Thank you, Roy. Thank you so much for having me on. Yeah, no problem.

I mean, there's a few things there that grab our attention. The TV veteran, you have to tell us about that. Sure.

Yeah, this was, it was 2009. And I was living in San Diego, California for a summer, just kind of spending my savings and surfing and living by the beach. And I just applied on a whim to a reality dating show on MTV, just to fill out an application.

I was just bored. I did it. And I went through the long interview process, talked to producers, and they ended up casting me on the show.

It lasted three episodes. It was a reality TV dating show. So this is 16, 17 years ago.

So it's a long time ago, but it was a lot of fun. It's just one of those things, serendipity, just I don't know how it ended up there. I don't know if I'd do it again, but it was a very fun experience.

So you studied psychology and computer science. That's kind of most people wouldn't do them. So how did that come about? Yeah, the overlap.

I like learning how things work. And I don't have a limit on learning what things fall under that subject. And so figuring out how people work, it was just another thing that I added to why does my computer do this thing? How does the heating work in my house? Why do people spend the time on the things they do? Why do they care about this? Why do they react this way? It was all just, I wanted to figure out how things work and people, the most interesting topic you could possibly have.

So the FDA approves. How did that come about? I mean, you were doing a software development for years. Yeah.

Yes. Yeah. It was a project.

We worked as a consultant. It's just a very quick how it works. It's for pill adherence.

So when you take a pill, it has this little potato battery in it. And so when it goes into your stomach, the stomach acid activates it and it sends a radio signal through your skin to a patch that you wear through the nervous system. And then that transmits to a Bluetooth radio that talks to your mobile phone.

And that would talk to a server and that would register you to take a pill. And that would help you track your biomarkers, kind of like people wear Fitbits and stuff today. This was a much more intense, more regulated way of understanding of whether people are taking their medication.

And it's for people who struggle to take their medication, forget to, or get in a different mind where they decide not to do it. And it helps them and care providers understand that. And that was a very interesting project.

It's one of the first times I had built software where if you don't get it right, people can get hurt or die. And so it was a stressful time, but it was a very rewarding time. And it challenged me a lot to really think about how secure, how good, how solid my software skills are, how to build a process where you're very confident of the code that you're building.

And so that was a wonderful experience for me. And as you said, the battery, let's say, how come that's not having an effect? Because you'd hear when a child swallows a battery, how the damage that it does, obviously, is a different type of battery. Yeah, yeah, yeah.

It's a little transistor. So the pill, it's tiny. And so you have just a little antenna, really.

And then your stomach is the actual battery. So your acid in your stomach, just like you would stick in, it's like a potato. You stick little leaves in potatoes and it'll light up a light bulb.

It's kind of the same thing. There's acidity in your stomach and the electrical connection, the circuit would get completed and then the transistor would transmit that, or that little radio transmitter would activate and talk to your nervous system. So your nervous system is a very rudimentary electrical circuit.

So you can talk to the different parts of your body and that's how your body does it. So you can talk to a little patch on your skin. It wasn't harmful or anything like that.

It's teeny, teeny tiny. It looks like an aspirin. So it was really interesting.

It was a really fun project. So I suppose before CASA, you might just kind of take me through the careers. Did you just do that and then the CASA or did you have other professions during that time? Yeah, after school, I went to, I lived in Cambridge, Mass.

And I worked at a company called Pegasus in the business process software, which is, I wouldn't say it's the most exciting software, but it certainly paid the bills. It was nice to have a job out of college. After that, I took a break.

And then I worked at a company called Spring Pad. It was sort of, it's like Instagram or a couple other, like a Pinterest, but not as successful, which is how startups go. Sometimes they work out, sometimes they don't.

And after that, I worked for a professional services company working on different large, large apps. And that's where I ended up working for that FDA approved mobile app. Then after that, it was at CASA.

I sort of got the Bitcoin bug, I think, 2011 or so. And I really wanted to work in the industry. And I ended up doing that, you know, several years later.

So it's really, crypto was the place I always wanted to work. So you said 2011, so how did it come about? And you weren't saving it in mongox or anything like that? No. Oh, yes, I was.

I had an email. I have the email from Mt. Gox that says, your funds are maybe at risk and you can go into the start the legal process to return them.

At that point, I only didn't have much in there. I had moved to a self-custodial wallet. I really got interested in Bitcoin because of the times as a software engineer.

And if you remember back 2011, software engineering and the tech industry goes through hype cycles and there's changes all the time and how software is built. There was the social revolution around 2006, 2009, where everything was going to be built on, everything was going to be a Facebook app or a Twitter app or something was built within a walled garden. Mobile came along and it was more walled garden.

And some of that stuff was incredible. You can leverage a network, you can leverage an SDK and tools and distribution channels, really interesting ways to build software, get rich, like all those different things. And I, like lots of other people's building apps on those things, I found them interesting.

I found them powerful. I kept running into the walls of the walled garden constantly, bumping my head against terms of service, legal departments saying like, yeah, technically the SDK can do that or the API can do that, but we don't want you to do that. Facebook has banned me, I've been banned by PayPal, I've been banned by Twitter.

So at some point, you start to get the idea that you're not in it together with those folks. You are either helping them or you're out and they hold all the power. Bitcoin comes along and it's the complete opposite.

There's no permission, there's no authority, there's no centrality. If you talk the protocol, you're in, that's it. What you build after that is your concern and the concern of people who may be or may not be interested in it.

You can't ruin somebody else's day, you can't ruin a company or anything like that, then no one's going to come after you. As long as you're doing anything not illegal, you're good. That was so powerful.

For me, it was really an empowerment as a technologist to be able to do certain things. I built tons of apps, I found them very interesting. You can monetize on small scales, you could work with zero trust with different people, you can interact in ways that you could never before.

You can find a real community that was really interested in those things and ethos that I found very attractive. I still do to the day. I find it a very interesting way to approach problems that was not present before in a way that was not open.

That was my beginning in my journey. As an early investor, I remember I've gone through all of the ups and downs, every crash, every boom. At this point, I'm very much an investor still and it's quite a ride.

How do you deal with your emotions when you see it's 4 to X and then it's like, you know, I don't know, maybe one-tenth of X? You get numb after number three or four. You're just sort of like, oh, I've felt this before and I felt the euphoric after it. Just hold on.

I don't have a lot of investment advice for people, but if I was pressed, I would say just hold on. Be patient. I've been rewarded for patience many times over.

You mentioned PayPal. I've been censored with all loads of stuff, but PayPal is my pet peeve because they're the slimmiest company around because you have to set your currency at a certain one. If you're getting paid, I mean, it's different if you're in the States and you're only getting paid in dollars, but a lot of people, they get paid in sterling or they get paid in euros or something else and they do the currency exchange for you and they're taking like three and a half percent.

Then they're taking sometimes 6% from the money that's actually just being paid into you. Then when you're paying somebody, they're taking more, so they're getting 12% sometimes. You're like, what did he do? When you compare that to crypto, it's like, and unfortunately, I don't know, are they losing market share? What I find strange as well, like Revolut or Wise, if you bring in a customer, they'll say, oh, we'll give you a hundred bucks or we'll give you... PayPal is $10 and you're like, you're making that in one transaction.

I mean, they could give a thousand and still come in head, you know, but yeah, I wish somebody came in and knocked them out of the water. I've talked to so many people that have run up against PayPal. Either they've been banned or something's been frozen and they've got to hire a lawyer or something like that to get their money out.

Yeah, the stories are endless and it is hard when you're a crypto person and you say, well, it doesn't have to be this way. It doesn't have to. So Casa, tell me all about it.

Casa, you know, we are been in the industry now for about eight years, which for a crypto company is ages. You know, they come and go, but Casa sticks around and we've done that because we've provided a service that was not present in the market when we got there. If you talk self-custodial seven years ago, you were looking at hardware wallets, you know, Trezor and Ledger, or you had a seed phrase on a piece of paper, and you didn't have a lot of support and you didn't have a lot of durability and resiliency in your setup and you didn't have somebody to guide you.

Casa came around and we solved that problem in that order. The way we set it up is we guide you in a curated experience to self-custody your funds. So Casa doesn't hold your funds.

It cannot move your funds without your signatures. And that's at the protocol level. So there's no sort of like synthetic layer on top that is security.

You're working with the Bitcoin security protocol. It's a multi-save. There's a two or three and a three or five, and you've got a hot wallet.

And then there's services around that we found that people really, really needed. And one of those is just actual personal support. At Casa, you can buy a tier and then you can call somebody.

We have a phone line. You call us and we pick up, which is wild. Even just not even the crypto, just in the regular industry, like you'd want to call a PayPal like we're just talking about, like, good luck.

They're not on their other end of the phone. They're not even on the other end of their email. So Casa filled out that actual personal touch for people.

And people felt very, very secure and taken care of. When you can talk to somebody, you know their name and you've spoken to them before, they've guided you through the process. They've guided you through the onboarding, helped moving your funds from an unsecure setup to a secure setup.

It is a really great feeling. And at Casa, I really found a kinship with a lot of people who shared my ethos on the Bitcoin and the crypto ecosystem and its future. And so helping people secure their funds is kind of a solemn, you know, task where you are really being entrusted.

They're putting their trust in you. And this is securing somebody's hundred bucks worth of Bitcoin and securing their familial wealth and everything in between. And so it can be a very emotional and personal experience with people.

And they rely on us more and more as security landscape has changed quite a bit. The attacks that our customers see and that we see six years ago are totally different than what we see today. And there's very, very interesting things that we work on.

I mean, just from the different guests that I've had on, and it's like the amount, like even sometimes people, they're doing interviews and on Zoom or something like that. And the people are planting code on us so that they can then access the wallets, but reach out to who the people are and then get them to log in pretending they're working for the company. So I suppose, I mean, obviously, you know, you might kind of tell me some of the current ones that people should become aware of, because there's always people trying to take your money, unfortunately, usually the government, but there's more mafia as well.

Yeah, well, sometimes it's different governments. We are working a lot recently with clients and customers who are seeing an increase in spearphishing attacks. And often those spearphishing attacks come with an AI component.

Can you explain spearphishing? Yeah, spearphishing is, you know, phishing is sort of like when you're talking about a security issue is you send out a bunch of emails and you're going fishing and you're trying to find someone who's going to bite on that bait. You don't get a lot of responses. You just need a couple.

And then you'll take those and try and develop those. An attacker will try and develop those. Elevating access, gaining trust, all the typical ways to do that.

Spearphishing is you take a targeted group. Maybe that was an email link and you cross-reference those with Casa customers that you or you might think they're Casa customers. Maybe somebody has in their profile that they're crypto or they post about Bitcoin or something like that.

You get a targeted group and then you spearphish those. And so it's a similar setup. Send an email or a phone call or something like that, hoping that they'll bite.

And what we're seeing a lot is that these attackers will pretend to be support, which is not a new way for attackers to try and gain your trust and elevate privileges. They'll say they're Casa support, just like they would do that for Coinbase support or Wells Fargo support. And they'll try and get you to do certain things.

They'll try and get you into a panic. And they'll say things like, your funds are at risk, or there was a breach. Your funds are safe right now, but we need to go through some security measures.

Security measures are orthogonal to what we'd always prescribe for people. And they'll pretend to be somebody at Casa. They'll try and take their likeness or they'll use AI to sort of transplant their face onto their avatar voice.

All the typical things you would see in a security setup an attacker would do, they're now elevated because attackers now have a leverage. It used to be attacker can only be on so many phone calls at one time, can only be on so many video calls at one time. With the prevalence of AI tools, AI fakes, all that stuff, they can be in many places at once.

They may have a low-hanging fruit and they'll try and get you on a phone call with an AI agent, but they'll do that for a thousand people. Or they'll try and get a video call and then once they think that you are a good target, they'll switch into a more personal touch. They'll bring the actual human on and try and do the next step.

But they can spread out their efforts in a way that was never possible before. And is there anyone that's actually catching these people? Because I mean, I see the scammers and I see pierogi for just normal scams, but for the blockchain world, is there anybody that's actually out there getting them and stopping them? I wish it was higher. There's always a couple of nice stories where somebody, a large ring or something like that, gets busted and people get dragged in, but the number that are getting caught is far less than the people perpetrating.

And I don't see it really turning around. Some of them, most of them, are going to be overseas, totally different jurisdictions. If we have somebody who's attacked, we encourage them to file a report, knowing that it's probably not going to help them.

It might help others for a larger target. Law enforcement is probably quite overwhelmed with a lot of these things. So the place that the energy is best spent is training people, understanding what these attacks look like, who to trust, how to sniff out a scammer.

We spend a lot of time training people to sense what something is off, to trust their gut, to trust their nose, and say, this doesn't sound right. And then we give them very clear steps. It's like, here's how you figure out whether this is legit or not.

And so it's training, which, again, also requires a personal touch and a relationship. And I think the problem with some of them, some people, they've got the Discord group from Facebook. They all have kind of groups.

And I mean, somebody then just has their, as if they're like a customer, and they're getting in. And that's the problem. It's nice to have a community where people are engaging and just building up.

But the problem is they come in and then they see, okay, now I've got my victims, and they think that it's somebody that's on their site. Yeah. They go to extreme lengths.

They are inventive. They are fast. And with new tooling, they're able to do things.

They're just hoping you're going to download something. We have, there's a lot of different ways to get into somebody's system to elevate privileges. And we are constantly, constantly fighting an evolving security landscape, and fast-moving and motivated attackers.

So with like the seed phase then, because I'm like this one company now, I'm after, they're helping people to, when they forget it. And like you showed me one person, the daughter, the way he left it out, the daughter had scribbled all over it that it was illegible. And I was like, but have you any kind of advice? And like somebody told me recently that I know, I won't say who it is, but made a poll and knows exactly the words from the poll.

And I thought, okay, that's clever. I haven't heard of somebody doing that. But like, because you're, unfortunately, if you lose it or forget it, yeah, you could, if you have a hundred grand or even more, it's goodbye.

So have you got ways that you can kind of tell people good ways of protecting it? Yes. And the systems we've set up are specifically for that. There's lots of different ways to lose your coins.

You know, the flashier ways you hear about, you know, somebody getting kidnapped and kidnapped for forcing their seed phrase or something or forcing the sign, those happen. That's more of a headline than it is actual reality and how people typically lose funds. What we find a lot is that people forget, you know, you got your seed phrase written down.

That's great. But like, you know, your office floods, the sprinklers wash it away. There are fires.

Your kid draws on it. You forget where it is. These setups are meant to a lot of be cold storage.

So you can't trust yourself to be like, I remember what my plan was 12, 24 months ago, three years ago. It's really hard to say I'm going to be able to trust myself. And none of us are going to live forever.

You know, what's your plan for when you go? And do you know what that is? I don't. For many people, it's earlier than they planned and they expect. And so there's all these different places to not just get your coin stolen, but just lose your coins because you forgot the key material.

So Casa builds a system that's resilient and redundant. Two or three or three or five. If your seed phrase does get eaten by the dog, that's only one of the five keys or one of the three keys.

You have remediation for those things. You can replace that key. You can make your your key set and your coins healthy again.

And we have a way to sort of upkeep them to check as are my keys healthy. We have health checks. So if you're like, OK, I've got a treasure and that's one of my keys.

But man, you know, it's been a while and I just don't quite feel confident that it's this is the one that I was thinking it was. Maybe it's the old one. Maybe it's the one that was in the other drawer.

You went through a move. You have a way to go and bring it to the system and say, yes, this is the one is a cryptographic verification called health checks where you can sign a message that's a useless message. But it does allow you to to show that you have the key that signs your coins.

So if you lose one, we have a way to replace it. We have systems set up where if you do pass away at a time that you did not plan, we have a plan for inheritance. So you have someone who can be a sort of an executor of your estate or sort of like a key helper, someone who you trust, who will call us at the time.

And that's what a lot of people want is they want to be able to have someone like this person. I'm putting a burden on them and they're going to meet a tough time in their life when I pass. And I want someone to be there for them to do this thing.

And, you know, their Bitcoin represents a large portion of their inheritance that we're passing on or their net worth or something like that. And they would hate for it to just disappear on people. So, yeah, there's lots of different ways to lose your coins and people do it in creative ways.

They often we have a sort of a backstop called a cost of recovery key where we hold on to the key and it's gated by either a video call or personal information that you're expected to know. So it's really hard to lose that key. You know, we won't be losing that key and it's always going to be there.

So there's one of those three or one of those five is in there. We have other ways to keep keys in ephemeral storage, backups, all different ways to do that. And we work with people according to their needs.

Do they need something that's spread across different people geographically? Depending on how much you're storing, you can change your setup. So it's really a personal decision and we work with people in an advisory capacity to help them build it out. And, you know, like you were talking about, like when somebody passes on and yeah, usually you have somebody, executor of your estate and assets.

But sometimes, unfortunately, even they can be kind of, you know, they realize, oh, he's got, you know, a couple of million in assets. Oh, he's passed on. Is there, like, do they have to provide a debt certificate or is there a validation? Because I'm sure, I mean, when it comes to money, everybody is always trying to trick the system.

Yeah, there is, we have several safeguards in your system for our current inheritance setup. And one of those is the time lock. So what happens is you have to request that these funds be signed by the CASA key because, you know, we don't custody them.

So we're not going to, we can't just give them to you because you're very convincing. It's, you have to, you know, convince us to sign a recovery transaction. And so you have a key that you've always had as an inheritance recipient and you need the other key to complete the quorum.

What it does is it kicks off a long process, six months, that starts with a bunch of warnings to, you know, someone who we're assuming is not there but we're going to check. And so we send out emails and phone calls and other things that says your inheritance recipient has begun the inheritance process. If this is an error or, you know, you need to, you know, protest it, here's how you go through that.

And so somebody who is alive or with access to their account, that's what they'd be able to do. They'd be able to say, no, actually, I'm just fine. And I should, will now be removing them as inheritance recipients.

So there's a lot of safeguards in order to make sure it doesn't go away and a good system is set up there that it's never locked away forever, that your recipient can't ever get to it. And I suppose for those that haven't started and they're considering it, what's the process, what's the best way to get started and get involved with yourself? You had mentioned if somebody's got like a hundred, there's no limit that somebody gets involved? What's the size that they should be investing? Yeah, I don't know, you know, as far as how much people should be investing, but I do recommend that everyone secures it appropriately. Casa has a free tier.

So he has a pay wallet with a hotkey in there. And we recommend not to put more than, you know, a thousand dollars in there. And if you do do that, we put in warnings that says, you should upgrade or move this to your already available vault.

That's a multi-sig. We have different tiers, but it really depends on your tolerance. How much you, how secure do you want to feel? You can secure as much or as little in any one of these things.

We try and guide people for those things. So, yeah, there's offerings for everybody along there. And there's a curated and guided experience for each one of them.

And with the cold wallets, you mentioned Transcend Ledger. Is there any that you have found better than the others? You know, Transcend Ledger sort of go neck and neck all the time. What we recommend is to not hitch your pony to any one of them because we found that they pivot a lot.

We try and use them as sort of a plug into our system. So we try and get people to have a variety of keys because there really is no guarantee that every one of these things is completely immune to supply chain attacks, completely immune to just a change in their business solutions. And they just, all of a sudden, you're no longer supported and you're just sort of like out of luck.

We also have things like a YubiKey, too, that adheres to actual just open standards where Trezor and Ledger, they work on different standards, but they're not sort of swappable. Something like a YubiKey where the key is stored on the Yubi allows you to sort of... What do you mean by Yubi? Okay. Yeah.

YubiKey. YubiKey is like a, I've got one here. Hold on.

Let me see if I can do it. So the YubiKey, let's see if I put it for my face, that's much better. This is the tiny one.

They're pass keys and they're security keys or key fobs. They're used oftentimes for just logging into systems. You can use them for 2FA or anything like that.

The YubiKeys are nice because they're a separate piece of hardware. All the cryptographic operations happen on the YubiKey. So if you want to log into a system, you don't need to have key material, leave the Yubi to do X, Y, Z. That's their passkey setup.

Our seed phrases, we can store them on the YubiKey and you can sign in the browser. And the nice thing is that YubiKey, adhering to sort of an open standard for auth, is likely to be supported long into the future. So that's why we use YubiKeys as one option.

And we recommend that as part of your mix, also to use Trezor and Ledger. But yeah, generally there's not a one that's a winner or better because sticking with one, you're not spreading your risk around. And with the YubiKey, because I mean I know that even if you do break your Ledger or whatever, once you've got the seed phrase, you're okay.

But with the YubiKey, I mean with external drives, I mean I've had a few over the years that just break. Have you come across them? Are they can they just go? Yeah, any piece of hardware is susceptible to bit rot. So we found oftentimes that Ledgers and Trezor, sometimes the screen is the first thing that goes.

These sort of LED screens or LCD screens, they're not meant to live forever. There's no such screen that will last forever. So having something that you can swap out, we do recommend some people hold on to seed phrases in certain situations and keep those secure.

A lot of times you can for Trezor and Ledger, I think if you put in your pin too many times wrong, it will brick your device or wipe your seed as a security measure. And we find that like people forget their pin. It's a hard thing to remember.

Writing it down, you know like forgot where you write it down. It's just a hard thing. And so you have to be able to set up a system that allows you to not have to worry about those things and accept them and expect them in a normal course of self-custody.

So the UB can break. The USB can break. The screen can break.

That's okay. When that happens and you are alerted by doing regular health checks, we have sort of a nag there. It's like every six months it's like, check on your keys.

Make sure they can do the thing that you expect them to do. They don't. It's like, that's okay.

We caught it when we needed to. Not in a moment when you, you know, five years later when you're like, hi, I'm ready to do a thing. And it turns out it's not ready for you.

You have a health check. You're ready. If that thing breaks, that's not a problem.

We have a process to swap it out for a new one, for upgrades, for anything of those things. A guided process. And so people often start those processes in a very scary place.

You know, you get the cold sweats. Your UB or your Trezor ledger doesn't turn on. Or you forgot the pin.

This might mean a lot of real big heartbreaks. With a multi-sig setup that's resilient and durable, it's more of an errand than it is a heartbreak. And with your own system then, because obviously with all these hackers, spammers, what security systems have you in place to protect? Yeah.

One of the big issues that we're seeing right now is that people's own security setups have a varying range of security hygiene. So your email, you know, if you haven't secured your email, an attacker can get in there. Maybe your email and password is part of a leak.

Lots of different ways for people to get into your email. If you haven't secured it, people can kind of pretend that there's somebody else. They can pretend to be a cost of support.

They can buy a domain name that's close or proximal to ours. And they'll pretend to be a support person. And what we do for that is we rely on a cryptographic verification.

And so again, it's part of our training with users and clients is you go into the app and you can have a screen that says, is this a KASA employee that I'm speaking to right now? And it's a PIN code. And you are allowed and you're able to both verify your PIN code and their PIN code. And it comes straight from our servers.

So when you start talking to them and you go into the app and the attacker, and you ask the attacker for the PIN code, it's not going to match what the app shows. They're not going to be able to say like, oh, it's one, two, three, four, five, six. They won't be able to tell you.

They're going to try and tell you that like, oh, we're not doing that anymore or that's broken. And that's part of the sniff test that we tell people. But we fall back to a cryptographic verification because we found that that's really going to be the backstop eventually.

There's the tooling and the playbook that these attackers use is going to get more and more sophisticated, but they're not going to be able to spoof keys. No matter how good they are, no matter what AI access, how good their deep fakes are, they cannot pretend to have a cryptographic key that they don't. Like the hot topic at the moment now is people having AI agents.

And I find it strange. Some people are giving access to their banks and giving it a lot of information. I mean, just thinking out loud, I'm sure that some of these are probably offering services cheaper that they'll create the AI agent for you that could probably have some stuff that's doing it.

Is that happening or like how dangerous it is given too much access to your AI agent? We should be talking about it much more as part of the conversation. I think these tools are moving very quickly and they're offering really great services. But yeah, they are giving access to places that may not break right now, but it may break in the future.

And attackers are hoping that you've given your agent access to certain things. The nice thing about Kasa is there is a physical component to a lot of things. Those physical hardware devices, they are air gaps.

You can't connect to them. No matter how sophisticated your AI agent is, whatever integrations or permissions you've given it, it can't stand up and walk across the room and go to the drawer. It can't go to the safe deposit box at the bank.

So we rely on cryptographic things for verification and we rely on physical things for security of your keys. We tell people and we train people, the physical way you put this physically and how you physically access it is very important, both for a security and for a loss and for accidental things. If you have it sitting on your desktop or another internet connected machine, those things are accessible and agents may be able to get into them, maybe not in a malicious way, but those access may be open, sitting, waiting for an attacker to co-opt.

So a physical separation is really, really important. It's going to be more and more important in the future as the AI agent spread out to all digital places. There's still going to be a place where they can't get up and go to the drawer.

And with all the data breaches, like most, you know, Binance, all these different ones, they all want KYC, you know, so you're given passport and all your information. Is there ones that you don't have to do that? Because like when there's a breach, they have a lot of information. Plus you don't really want big brother who's pushing war and stuff like that to be kind of knowing what you're doing.

Because I think that was the purpose of this whole thing, that you kind of, if I want to send you something, I can and vice versa. And why should the government know everything that we're doing? So is there any way that you can actually get the Bitcoin without having to do KYC? Purchase it. I don't know of a, there's gray areas to purchase it.

Custody it. Yes. You can still do that without a KYC experience.

Casa offers a way to, you can sign up with an email. We don't ask for address or other KYC information. There is an exchange feature in the app.

And if you'd like to use that exchange feature, you will have to go through KYC, which is just, I don't know of any exchange that doesn't allow, that allows non-KYC access. So in and out of the Bitcoin USD, especially in US jurisdiction or US affiliated, it's going to be hard to find a way to go in and out. I have in my past done local Bitcoins since defunct service where I met somebody in person and gave them cash and they transferred me Bitcoin.

That was a long, that was a while ago. And I don't know if there's any sort of in-person offering anymore for that. So I don't really know.

I haven't looked at Bitcoin ATMs. I'm not sure if they ask for KYC. Well, there's a kind of, you're allowed to up to a thousand dollars because you can even take out your money and you can do like 20 transactions if you want to do 20 grand.

But like technically, no, I could, there's a lot of them in Poland, go in and put in the money and then I'd have the account, just say your account would there. So you would transfer the Bitcoin to your place. But the problem is, you know, the spread is like 4% or something like that.

But if you're in it for the long haul, because I mean, 4%, I mean, there's been times if it's up 4%, you would have been extremely happy. So I think, yeah. But you know, like when I see 4%, I think PayPal.

Yeah, there's a fee for those things. But I wish there was more ways to access it for people who, you know, may not have a passport or, you know, maybe they don't have a jurisdiction that's supported. I wish there were more ways to access it.

Yeah. Is there anything else that you're doing that we haven't covered? Ah, geez. I mean, there's so much going on.

I could talk about AI agents and AI development all day. And I love, it's a really exciting time in the industry for software developers and for crypto. We're moving into a very interesting world.

And I think the coalescence of those two things is sort of a realization of something, a small personal philosophy that I really enjoy. One of the reasons why I really got involved in blockchain technology is one of them is one of the real unlocks for Bitcoin when I had thought about it for a very long time is that it really was a zero to one moment that Bitcoin white paper and allowed it to do a thing that was never possible before. And it really changed a category of problems that I found, which was if you wanted to build a currency in 2005, the first thing you'd do would not be write code.

And that was really the revolutionary thing is that when Satoshi built the system and wrote the white paper, he built a currency via code. If previously you wanted to do that, you would need lobbyists and banks and a big vault full of gold to back it or something like that. Writing code to build a currency is wild.

It's bonkers that it works, but it took a whole category of problems, which are coordination problems. A currency is a coordination problem. You've got to get people to believe in it and use it and develop it and save in it.

And it turned that coordination problem, a real meat space problem into a engineering problem. And engineering problems are a totally different class of problems. And they're really interesting because they have two properties is that they are always solvable with time and resources.

And they're accessible to many, many people. So as long as you have time and resources, if there's an engineering problem, you can solve it. And so we all of a sudden turned making money or turning or developing money into a software engineering problem.

And it started opening up different doors in the AI. Agents, once they have this sort of, you know, some level of intelligence, they can work in engineering problems. They're incredibly good at engineering problems.

So the intersect of a world that's now an engineering problem, a currency that's an engineering problem and agents, which are really good at engineering problems, they marry really well together. So I'm really excited about the future of where we're going with those things. I don't know what it looks like.

I just know it's going to be enabled by blockchain technology. It's going to be enabled by Bitcoin. It's going to be enabled by these agents.

And hopefully that empowers people and brings them in and gives them, you know, a really exciting thing to work on and look forward to and improve lives and shape our future. Excellent. Well, listen, totally enjoyed it, Paul.

You might let the listeners know where they can find you. Yeah, you can see my personal site at paulbrower.codes. I'm sure we'll put in the show notes. Or you can see Kasa at kasa.io. Okay.

Yeah. Yeah. As you said, it'll be in the show notes, but on the audio and the video.

Thank you very much, Paul. Roy, thank you so much. So that's all for the Crypto Podcast.

You'll find all our episodes on the cryptopodcast.org. Find everything about me, scan the QR code or go to roycoughlan.com. And if you're looking for virtual assistance, go to va.world. Make sure to give us a thumbs up, like that rating, share with maybe three friends. Until next week, take care.

Roy Coughlan Profile Photo

Podfather

Serial Entrepreneur and host of 6 Podcasts. All 6 got to the Top 5%. 5 got to Top 1% and 4 to Top 0.5%.

I am a podcast coach so can help you do the same.

I can help you get on other successful Podcasts.

Paul Brower Profile Photo

Director of Engineering @ Casa

See podmatch bio