Dialogue with OneKey Wang Yishi: In the AI Era, the Offensive and Defensive Battle for Hardware Wallets Has Only 'Two Weeks' Left?

Tapbit Wire - Tapbit NewsTapbit Wire·Source:PANews·
Share
Cover

In 2013, a junior majoring in civil engineering bought his first Bitcoin through a Taobao agent. Twelve years later, he became the founder of OneKey, one of the most important hardware wallet companies in the industry.

In this conversation, Wang Yishi @ohyishi talked about his judgments and trade-offs along the way, but we spent more time on these unavoidable topics in the industry recently: AI empowering both offense and defense simultaneously, what really went wrong behind the $1.5 billion theft at Bybit, why he made OneKey's recruitment process like "matchmaking" and what he is really screening for, and how he plans to use a "first-startup trial-and-error fund" to nurture his offspring.

1. Entering the Circle: From Civil Engineering to Bitcoin

Host Beca: You have a background in civil engineering. In 2013, as a junior, you bought your first Bitcoin on Taobao. What pulled you from the construction site onto the chain?

Wang Yishi: To put it bluntly—because the price went up.

2013 was a bull market. It had been rising since 2012, peaking at nearly 8,000 RMB in Q4. The first time I bought it, it was around $100, about 700 RMB.

Back then, you could directly buy Bitcoin and Ripple on Taobao—just click a link and pay. The transactions were very primitive. Domestic exchanges had also started appearing, like BTC China run by Yang Linke. The reason I bought coins was because the price had risen, and I noticed this thing. I saw Mr. Xiao Lei's article "When This Thing Appears, the World Turns Upside Down" and was very excited. Then I went to the 8BTC forum and Bitcointalk to read a lot of early posts.

So, the core reason was—it went up, so I bought.

Host Beca: From ByteDance to Bixin to OneKey, how did you make your decisions step by step?

Wang Yishi: When I joined ByteDance, the company had about 400 people. Now it probably has 100,000. At that time, ByteDance's most profitable business was Toutiao APP advertising, with a valuation of $1 billion—now it might be $500 billion or even trillions.

ByteDance is a typical "APP Factory": they release several new apps every month, use the main APP's tabs to funnel traffic to new products, and decide whether to continue investing or disband based on data—it's brutal. The AB testing and data-driven mindset was already very strong back then.

But big companies have an inherent problem: having too many resources can sometimes be a curse. If you need people, you hire; if you need budget, you submit an OA request; if you need traffic, you ask for it. In that environment, you're more like a component. You have to do your own job very well, but you inherently lack some "wilderness survival experience."

"Wilderness survival" means when you create something new, no one gives you traffic, and no one helps you solve problems outside the product itself. It's different from something that grows wild outside.

Later, why did I choose crypto? Because civil engineering is slow. The feedback cycle for civil engineering is measured in "several years": the design institute produces drawings, a senior colleague goes to the site to follow an entire bridge project—it takes years. The internet is fast, and crypto is even faster. You put money in, it goes up or down. If it goes up, you get strong positive feedback.

Also, when I was working at ByteDance, besides paying rent, I basically used all my income to buy coins. Since I was buying coins anyway, why not go all-in on the industry?

2. How OneKey Got Its "First Wave of Users"

Host Beca: In the hardware wallet track, Ledger and Trezor had already been around for six or seven years. How did OneKey stand out among so many competitors?

Wang Yishi: Actually, even now, OneKey hasn't really "stood out"—that term is a bit of an overstatement. OneKey is still working very hard on growth.

But if I had to point to one thing, the biggest growth node was the DeFi Summer in 2020. At that time, a huge amount of funds flowed from exchanges to the chain—because there were pools and high annualized yields on-chain. But what tool did you use? Metamask.

Metamask's security wasn't great back then. I remember when we did an audit at the end of 2020, we found that its method of storing seed phrases had security risks—it was relatively easy to get the source files and brute-force them.

Users with larger capital wanted to participate in DeFi but didn't want to lose all their money if their computer got a trojan or their browser was hacked. So they started using hardware wallets. But if you used a Ledger to mine on Uni, you had to install Ledger Live, install the Ethereum app, install Metamask, then use Metamask to connect to Ledger, and also close the Ledger client because they would compete for the same USB port—

It felt like using three remote controls to operate one TV. Very cumbersome.

At that time, OneKey made some user experience innovations, especially in localization and reducing friction—that was our first wave of users.

Host Beca: Besides improving user experience, what was another reason for achieving growth?

Wang Yishi: Open source.

Ledger is still not open source today. Our judgment was—a product makes you "believe" it is safe, versus giving you the ability to "verify" whether it is safe. In the long run, the latter is better. Just like with current AI models, I am also bullish on open source in the long term. Verifiability is very important.

After the first wave of growth, the rest was really about the competitors' problems—they didn't do well, they handed users over to us, and gradually the users came over.

Recently, Coldcard also had an incident. Coldcard is a wallet made by very professional, geeky Bitcoin OGs. But can you imagine? From 2021 to 2025, for nearly four years, a seed phrase generation vulnerability was hanging out in open source for four years, and they didn't fix it. So, are they really professional? I have my doubts.

Every time a competitor makes some low-level mistake, our user base increases a bit. That's basically it.

So it's not "standing out"—it's just surviving.

Host Beca: The high-growth phase of a company is also the phase where it's easiest to make mistakes. What detours have you taken?

Wang Yishi: Plenty. Thinking back now—it's just incredibly frustrating.

During the DeFi Summer period, our wallets were out of stock for nearly a year.

The reason was that we opened a new mold and wanted to build the firmware from scratch ourselves, underestimating the difficulty and R&D cycle of the whole thing. Once you touch hardware, it's different from software—hardware has a supply chain behind it. One problem leads to a hundred others. As a result, during the time we should have been aggressively capturing users, we had no products.

If you don't even have products—you're essentially giving away traffic.

There were also some issues with the technical architecture: premature design, premature optimization, over-design. Instead of "first do growth, let users use it, then gradually optimize." The order is very important. If I had figured this out back then, things would probably be much better than they are now.

3. Offense and Defense in the AI Era: From "Two Months" to "Two Weeks"

Host Beca: AI is becoming more and more efficient at finding vulnerabilities. What preparations have you made?

Wang Yishi: This is an industry-wide problem, not just for the crypto industry. People used to think iOS was very secure, but now with AI models, iOS also has many vulnerabilities.

Our own team has a security team called Anzen Labs ("Anzen" means "safety" in Japanese). This year at Black Hat, we released a USB vulnerability—from finding the vulnerability to reproducing it, to chaining several vulnerabilities into a complete supply chain attack, almost entirely using AI.

Before AI, to create such a complete attack chain, you would need about two to three relatively senior security researchers and two months. But this time, finding this vulnerability took only one security engineer and two weeks.

The speed has changed very quickly.

But if AI makes finding vulnerabilities easier, this "easiness" applies equally to the defenders.

Defenders have one advantage over attackers: you have code in your repository that hasn't been released yet. For an attacker to attack you, they first need to find your stuff. If you are open source, everyone can attack you en masse; but your product and code are constantly iterating, so there must be some parts that haven't been released yet—that's when you can attack yourself.

Previously, we did firmware security audits about twice a year, using two or more companies for cross-auditing. The frequency was very low. But now, with the help of AI tools, we can audit every release every week.

AI is, to put it bluntly, a kitchen knife—you can use it to kill people, or you can use it to cook. It depends on how the teams in the industry use it.

4. The $1.5 Billion Bybit Theft: No One Made a Mistake on the Entire Chain, Yet the Money Was Gone

Host Beca: Why have defense tools been getting stronger over the years, but incidents haven't decreased?

Wang Yishi: Tools are increasing, tools are getting stronger, and incidents keep happening—these three things are simultaneously true.

Common attack methods used to be finding contract vulnerabilities, flash loans, manipulating oracles—these still exist, but not as much as before. Why? Because now many protocol developers use audit tools and formal verification, which can block most of these vulnerabilities.

So attackers found that hacking code isn't cost-effective. They, you know, General Kim has so many people to support.

Then they realized: since it's hard to attack the code, they'll attack the people.

Host Beca: Take the Bybit $1.5 billion theft case as an example — it seems like no step went wrong?

Wang Yishi: Yes. This is a very typical example.

Bybit had $1.5 billion stolen from its Safe multisig at the time. Actually, each individual link was fine when viewed in isolation: the multisig contract itself had no bug; Bybit's cold wallet itself had no problem; the Ledger hardware device they used also had no bug.

So where was the problem? The problem was that a frontend engineer from the Safe protocol had his computer socially engineered by the North Korean hacker group Lazarus.

After being socially engineered, a piece of malicious code was implanted into Safe's official frontend, and this code only took effect for Bybit's specific address. So when the four people from Bybit (Ben and three others from finance/audit) signed, what they saw on the webpage was a completely normal transfer from the cold wallet to the hot wallet.

As luck would have it, the Ledger side was a blind sign — it didn't parse the Safe contract, didn't display the delegatecall, and didn't issue any warnings.

As a result, what they actually signed was a "delegate transfer" action — directly handing over the permissions of Bybit's Safe contract. The ownership was gone.

You see, every link seemed fine, the only thing that went wrong was that the Safe frontend engineer's computer was compromised. But all the conditions happened to be met, and that — is really painful.

In the past, people tried to hack your code; now they try to hack your people.

There's a saying in traffic safety — if you give a driver a seatbelt and an airbag, the driver will drive faster. It's the same in the industry. Everyone keeps adding more things: more audits, more multisigs, more passphrases, raising the bar for attacks. But often, the problem isn't where you can see it at a glance, but where you can't.

Your castle is impregnable, and then your security guard is strolling outside with the keys on him. Someone comes over and says, "Hey buddy, want a cigarette?" — you smoke, and the next thing you know, they've stolen your keys. That's the feeling.

5. Hacking Ledger: An "Olympic Spirit" Vulnerability Disclosure

Host Beca: You recently disclosed a transaction replacement vulnerability in Ledger in a very high-profile way, titled "we hacked Ledger." Why so public?

Host Beca: You recently disclosed a transaction replacement vulnerability in Ledger in a very high-profile way, titled "we hacked Ledger." Why so public?

Wang Yishi: First of all, that vulnerability has already been fixed.

When I posted that, the Ledger firmware was already at version 1.2.3; the vulnerability was in version 1.2.1, which had been fixed about two weeks prior. The phrase "we hacked Ledger" was indeed a bit clickbaity — but Ledger has always done that kind of thing too, so it's fine.

Technically, this vulnerability is called TOCTOU (time-of-check to time-of-use) — it exploits the time difference between the device and the computer. The user sees "transfer $1 million from address A to address B" on the device, and then they sign; but in that gap, I send transaction B in, and as a result, what you actually signed is transaction B, and I use transaction B to replace your transaction A.

In terms of defining the danger level of the vulnerability — this one is actually quite dangerous.

Our job at Anzen Labs every day is to hack ourselves. If I can't even hack myself, it proves that in my security capability, this thing you have, I can't crack it, I can't handle it.

But there is communication within the industry. We've previously submitted security bug reports to Keystone — we gave them about two months' notice, told them how to reproduce it, provided the complete solution, and only disclosed it together after they fixed it and forced an update. It's good. There should be this kind of positive Olympic spirit.

6. Hiring: An Interview is Two Actors Performing for Each Other

Host Beca: OneKey's hiring process is very unique — first, you pay candidates to complete a practical task, and after they pass, there's a paid adjustment period. Why?

Wang Yishi: The core reason is — we can't find suitable people.

All the "weird hiring methods" you see aren't actually weird; it's because conventional methods have a very low hit rate.

Hiring is very similar to dating. If you interview someone and you talk well, what does that prove? — It proves that this person is very good at interviewing. They anticipated your anticipation of their anticipation. A strong candidate will make the interviewer "come to the conclusion they want," making the interviewer think it was their own wisdom that discovered the trait in this person — it's a very subtle form of psychological control.

The interview process is actually more like both sides performing — the candidate performs as a very capable person, and I perform as a great company. Then the two actors watch each other's show and decide whether to get together.

But a two-to-three-day paid practical test is different. You can observe the candidate's problem-solving approach, completeness, and delivery quality — most importantly, whether they communicate actively when encountering problems, or keep quiet and eventually drop a bombshell on you. In work, we hope for timely communication.

Moreover, the problems are all designed by us, not "tricking candidates for solutions" using YC questions.

It's the same for the candidate — they can intuitively feel the company's way of working over two or three days. Because the person setting the problem is usually their direct colleague after joining. They will know if they like this person. This is very important.

Finally, there's the payment. Besides respecting the other person's time, paying also serves another purpose — if I suddenly throw a problem at you out of the blue, saying I want to test your ability, and you spend a day or two on it, you'll feel like I'm freeloading off you. If I pay you, you'll feel like I'm taking this seriously, so you should take it a bit more seriously too.

Host Beca: You once said, "I can't accept engineers in 2025 who can't efficiently use AI for coding." What is your ideal team like?

Wang Yishi: That statement of mine in 2025 was indeed a bit of a "radical statement." At that time, Codex hadn't even been released, and AI was just starting to improve efficiency in programming and text.

But this year, we've added a lot of new hardware-related things. For example, hardware testing — there are no test engineers in the office now, just four or five robotic arms.

For some tests on a phone, you can directly plug in a USB cable to read commands, but some things are external — like whether the sliding is smooth, the feel of the buttons — these require vision plus external hands to coordinate. Before this year, we had many test engineers in the office manually clicking over and over. Now it's robotic arms + high-definition cameras + models: every time a version is released, these things are automatically sent to the test backend, and the robotic arms go thump-thump-thump through the test cases one by one.

This thing wasn't created by a single hardware engineer or test engineer — it was done by two people working together. Because everyone has a consensus on "what the current strongest AI model can achieve." Based on this consensus, we believed this thing was possible. Then we tried it — and it turned out it could really be done.

The biggest change AI has brought is giving everyone a common boundary: turning things that "two professionals didn't understand each other and didn't think were possible" into a result where "1+1 is greater than 2, even far greater than 2."

7. The "Trial and Error Fund" for My Son: Let Him Lose This Money as Early as Possible

Host Beca: You've talked on Twitter about how you plan to raise your son — you want to open Binance and Robinhood accounts in your name for him and invest money into them every year. What kind of values are behind this?

Wang Yishi: I did want to open them at the time — but there were two problems: Robinhood requires you to be American, and my child isn't; Binance's Junior account requires you to be 6 or 13 years old, and my child was only 3 months old at the time. So it's still on my To-do list, but I will definitely open them later.

The founder of Dell opened an account for every newborn in the US and deposited $250, right — I thought that was quite interesting.

Why did I want to do this? Because I realized — the earlier you let your child get in touch with money, the better.

And this "money" isn't the kind of allowance — not the "Mom, Dad, I want to buy ice cream, give me 5 bucks, 30 bucks" kind. It's that once they can recognize numbers and do basic arithmetic, you can tentatively give them a savings account, or even an investment account. Let them learn how money in this world works.

And then — let them lose this money as early as possible.

If, before they become an adult, the family gives them ten thousand dollars, and they manage to lose all of it before adulthood — that's better than them graduating, working, having an income, and then one day losing much more money due to an investment mistake.

Fail cheap, fail early. That's its purpose. It also cultivates their understanding of money.

Host Beca: There's a saying: In the AI era, only "rich people's kids" won't have their imagination limited by AI. What do you think about the relationship between kids and AI?

Host Beca: There's a saying: In the AI era, only "rich people's kids" won't have their imagination limited by AI. What do you think about the relationship between kids and AI?

Wang Yishi: How could AI limit imagination? Shouldn't AI liberate imagination?

The progress of all human society boils down to one sentence — if the young don't listen to the old, humanity will progress.

With AI, kids can do so, so many things. They are builders from a young age — you don't necessarily need to learn programming to create a product; as long as you have a mouth and can speak, you can do it.

Look at many families now buying 3D printers, like Bambu Lab. They can print many small parts at home — not necessarily figurines or models, some are things for daily life: automatic switches, foldable pads for coffee machines. This is very interesting. It's hard for me to imagine how happy I would have been if I had this when I was young.

You can make apps, you can make websites, you can make things in the real physical world — and then you combine them in endless possibilities.

8. In Conclusion: Show Me the Product

Host Beca: You've come all the way from a field completely unrelated to this industry. What would you say to people who want to make something of themselves in this industry now?

Wang Yishi: I wouldn't call it advice. I'm not necessarily doing that well myself.

But if I must say—first of all, everyone's potential for growth is limitless. The major you study, the work you do after graduation, what you do at 20, what you do at 25, and what you do at 30—these four things can be completely different.

Whether you like something determines how much you invest in it. The perspective and understanding with which you view it determine the upper limit of its growth.

If you both like it and it has a long snow slope and a long track—then you are more likely to go further.

In the past, people didn't like to share what they were building in public; they preferred to work quietly—only saying "come try this thing I made" when it was released. But now you'll find that making something with AI is incredibly fast. If you have an idea, directing Codex, Grok, or Claude to help you do it might only take two resets to get it out.

Once it's out, you can absolutely send it out and let others use it—you can get feedback quickly: Is this a real need? Is it just you who needs it, or are many people like you but haven't said it? Can it make money? Can it get long-term user support?

The author who made Lovable built over thirty vibe coding apps before Lovable, and no one used them—until Lovable took off. This is a particularly typical case of fast trial and error.

When you're working on a new product, you connect the pros and cons of all the products you've made before—connecting the dots. AI can't replace you in that, because it's cognition, it's aesthetics, it's decision-making, all in your head.

It used to be "ideas are cheap, show me the code." Now you don't even need to show me the code—just show me the product.

So, right now is truly the best era.