Building a Safer Future: Navigating Digital Currencies in the Modern World

RSA Conference 2024 · Track Session

Overview

The rapid evolution of digital currencies and blockchain technology presents both unprecedented opportunities for financial innovation and significant challenges for security and law enforcement. This panel discussion, "Building a Safer Future: Navigating Digital Currencies in the Modern World," brought together leading experts from traditional finance, cryptocurrency exchanges, and federal law enforcement to dissect the complex landscape of digital assets. Hosted by Tashiana Bright from the FBI, the session featured Ajoy Kumar of Wells Fargo, Philip Martin of Coinbase Global, and Claudia Quiroz of the U.S. Department of Justice's National Cryptocurrency Enforcement Team (NCET).

Watch on YouTube

Visual summary for Building a Safer Future: Navigating Digital Currencies in the Modern World
Visual summary for Building a Safer Future: Navigating Digital Currencies in the Modern World

Key moments

  1. 0:00 Introduction and panelist introductions
  2. 2:10 First question: Illicit activity and financial services landscape
  3. 3:40 Wells Fargo's view on programmable money and regulated markets
  4. 6:20 Coinbase's perspective: blockchain transparency and fighting crime
  5. 10:07 Second question: Most significant threats to the industry
  6. 10:50 DOJ's view on evolving threats and NCET creation

Building a Safer Future: Navigating Digital Currencies in the Modern World

Speakers: Tashiana Bright (Host, Section Chief, Federal Bureau of Investigation), Ajoy Kumar (Head of Application Security, Wells Fargo), Philip Martin (Chief Security Officer, Coinbase Global), Claudia Quiroz (Director, U.S. Department of Justice National Cryptocurrency Enforcement Team and Deputy Chief, Computer Crime and Intellectual Property Section)

Conference: RSAC 2024

YouTube: https://www.youtube.com/watch?v=IHE2_Ijl79Y

Overview

The rapid evolution of digital currencies and blockchain technology presents both unprecedented opportunities for financial innovation and significant challenges for security and law enforcement. This panel discussion, "Building a Safer Future: Navigating Digital Currencies in the Modern World," brought together leading experts from traditional finance, cryptocurrency exchanges, and federal law enforcement to dissect the complex landscape of digital assets. Hosted by Tashiana Bright from the FBI, the session featured Ajoy Kumar of Wells Fargo, Philip Martin of Coinbase Global, and Claudia Quiroz of the U.S. Department of Justice's National Cryptocurrency Enforcement Team (NCET).

The discussion provided a multi-faceted perspective on how their respective organizations view the burgeoning digital currency market, the inherent risks, and the collaborative strategies being deployed to combat illicit activities. From the perspective of a global financial institution exploring regulated digital payment solutions to a major cryptocurrency platform navigating security for millions of users, and a federal agency spearheading enforcement, the panel underscored the critical need for robust security frameworks, proactive regulatory engagement, and strong public-private partnerships to foster a secure and compliant digital financial ecosystem.

The talk is particularly relevant for anyone involved in financial services, cybersecurity, regulatory compliance, and law enforcement, offering a comprehensive look at the current state and future trajectory of digital currencies. It highlights the dynamic interplay between technological advancement, market adoption, criminal exploitation, and the concerted efforts to mitigate these threats, ultimately striving for a safer and more trustworthy digital economy.

Background

▶ Watch: Introduction and panelist introductions (0:00)

The emergence of digital currencies can be traced through the evolutionary stages of the internet itself. As Ajoy Kumar of Wells Fargo articulated, the journey began with Web 1.0, characterized by basic interfaces and static information retrieval. This evolved into Web 2.0, which introduced dynamic data exchange and user interaction, but also led to the centralization of data and services, raising significant security and privacy concerns. The current paradigm, Web 3.0, aims to address these issues by promoting decentralized ownership, distributed trust, and rich user experiences, expanding the innovation space exponentially.

Within this Web 3.0 framework, digital currencies have gained prominence, presenting a fundamental shift from traditional money to programmable money. This concept allows for automated execution of financial logic, opening doors for innovative payment and settlement use cases. However, this innovation also attracts criminal elements who follow the money, adapting their tactics to exploit new technologies. Historically, the misuse of cryptocurrency first gained significant public attention with the rise of darknet markets like Silk Road, leading to early law enforcement interventions. Over time, criminal methodologies evolved, incorporating sophisticated schemes such as Business Email Compromises (BEC) and, more recently, large-scale pig butchering and other crypto confidence scams.

The inherent characteristics of blockchain — its transparency and traceability — offer unique advantages for law enforcement compared to tracing traditional cash, especially across international borders. Yet, services designed to obscure these trails, such as mixing and tumbling services, quickly emerged, complicating investigative efforts. Recognizing the escalating threat, the U.S. Department of Justice established the National Cryptocurrency Enforcement Team (NCET) two years prior to this talk, creating a centralized "nerve center" to identify, investigate, and prosecute criminal misuse of digital assets. This initiative, coupled with the Digital Asset Coordinator Networks comprising over 150 specialized prosecutors, underscores a concerted governmental effort to build expertise and address the evolving threat landscape in this rapidly developing financial frontier.

Key Findings

▶ Watch: Wells Fargo's view on programmable money and regulated markets (3:40)

The panel discussion brought forth several critical findings regarding the current state of digital currencies and the efforts to secure them:

  • Programmable Money and Web 3.0 as Innovation Drivers: Ajoy Kumar highlighted that digital money today is fundamentally "programmable money," a counter-thesis to traditional currency. This, coupled with the distributed ownership and trust models of Web 3.0, has dramatically expanded the innovation landscape, particularly in payments, deposits, and settlement use cases for regulated markets. Wells Fargo, for instance, has already tokenized cross-border payments and is actively participating in public-private partnerships like RLM to explore multi-currency settlements.
  • Criminals Follow the Money, but Blockchain Offers Traceability: Philip Martin from Coinbase acknowledged that the thriving digital currency ecosystem inevitably attracts bad actors. However, he emphasized that blockchain assets are often "transparent" and "traceable" in ways traditional fiat currency is not, especially for international movements. He believes that as the infrastructure matures, tools like blockchain explorers will become superior for tracing criminal activity compared to traditional methods.
  • Escalating and Evolving Threats: Claudia Quiroz of the DOJ NCET outlined the significant threats currently facing the industry. These include:
  • Scams and Fraud: Massive losses from schemes like pig butchering and other crypto confidence scams, affecting thousands of victims and resulting in millions of dollars in losses.
  • Hacks and Heists: Persistent and sophisticated attacks targeting digital asset platforms.
  • Nation-State Actors: The increasing involvement of state-sponsored groups, notably North Korea's Lazarus Group, in cryptocurrency theft and laundering.
  • Ransomware: A significant increase in ransomware incidents, often demanding payment in cryptocurrency.
  • Intersection with AI: A nascent but growing concern regarding the intersection of blockchain and artificial intelligence, potentially leading to new forms of exploitation.
  • DOJ's Proactive Enforcement and Successes: The NCET, launched two years prior, has centralized expertise and strategy to combat crypto crime. Quiroz cited several recent high-profile successes within the last six to seven months, including:
  • The takedown of the cryptocurrency mixing service Sinbad in November, used by the Lazarus Group.
  • The prosecution and 25-year sentence of Sam Bankman-Fried in the FTX case.
  • The indictment of Samurai Wallet, another mixing service.
  • Upcoming trials, such as the widely anticipated Tornado Cash case.
  • Crucial Role of Public-Private Partnerships: All panelists echoed the importance of collaboration between government and the private sector. Quiroz stressed that knowing who to call and having established relationships with companies is critical for rapid response during incidents like hacks, enabling quicker freezing and seizure of funds. She emphasized that "if you don't help us, we can't help you," encouraging open communication even for victimized entities concerned about regulatory scrutiny or private lawsuits.
  • Proactive Security by Design and Compliance: Quiroz also highlighted the need for developers building new Web 3.0 companies and systems to consider functionality and integrate "guide rails" at the outset. This includes implementing screening tools to prevent interactions with sanctioned activities and incorporating robust audit functions to ensure compliance and prevent money laundering and commingling of funds, especially in decentralized finance (DeFi) environments.

Technical Deep Dive

▶ Watch: Coinbase's perspective: blockchain transparency and fighting crime (6:20)

The discussion touched upon several key technical concepts and their implications for security and financial services. At its core, the shift towards programmable money signifies a profound technical change. Unlike traditional fiat currency, which is typically controlled by central banks and transferred through established banking rails, programmable money (often implemented via smart contracts on a blockchain) can embed rules and logic directly into the asset itself. This allows for automated execution of financial transactions or conditions without intermediaries, facilitating innovations like tokenized cross-border payments. Wells Fargo's involvement in tokenizing international payments, and its participation in initiatives like RLM (presumably a reference to a Regulated Liability Network or similar interbank settlement system), showcases how traditional finance is leveraging blockchain to streamline operations and reduce settlement times and costs, all within regulated frameworks. These systems often utilize private or permissioned blockchains to maintain control and meet compliance requirements, contrasting with the public, permissionless nature of many cryptocurrencies.

The evolution from Web 1.0 to Web 3.0 underpins much of this technological shift. Web 3.0 aims to decentralize the internet, moving away from centralized platforms that control user data and services. Technically, this involves technologies like blockchain, decentralized identifiers (DIDs), and peer-to-peer networks. This distributed ownership and trust model means that instead of relying on a central authority for security, trust is distributed across a network of participants, verified cryptographically. While this enhances resilience and user control, it also introduces new attack vectors and challenges for oversight and regulation.

For cryptocurrency platforms like Coinbase, securing these assets involves a multi-layered approach. Philip Martin mentioned the inherent transparency and traceability of many blockchain networks. Every transaction on a public blockchain is recorded in an immutable ledger, accessible to anyone. Tools like blockchain explorers (e.g., Etherscan, Blockchair) allow users and investigators to view transaction details, wallet balances, and network activity. This technical characteristic, while a privacy concern for some, is a powerful investigative tool for law enforcement. Investigators can follow the flow of funds through a series of transactions, often leading to exchanges or other centralized entities where identities might be linked to addresses.

However, adversaries have developed sophisticated techniques to obfuscate these trails. Cryptocurrency mixing and tumbling services (e.g., Sinbad, Tornado Cash, Samurai Wallet) are designed to break the link between the sender and receiver of funds. Technically, mixers aggregate funds from multiple users, shuffle them, and then redistribute them to their respective recipients from a common pool, making it extremely difficult to trace the original source or destination of specific coins. These services often employ techniques like CoinJoin (a method of combining multiple payments from multiple senders into a single transaction to obscure the flow), or simply large pools of assets that are constantly mixed. The DOJ's focus on taking down such services, as exemplified by the Sinbad and Samurai Wallet indictments and the upcoming Tornado Cash trial, highlights the technical challenge they pose to financial investigations and the concerted effort to dismantle their operations.

The rise of Decentralized Finance (DeFi) introduces another layer of technical complexity. DeFi applications, built on blockchain platforms (primarily Ethereum), use smart contracts to automate financial services like lending, borrowing, and trading without traditional intermediaries. While offering unprecedented access and innovation, DeFi protocols often lack the centralized controls, Know Your Customer (KYC), and Anti-Money Laundering (AML) checks present in traditional financial institutions or regulated exchanges. This makes DeFi a fertile ground for illicit activities, as funds can be moved rapidly and anonymously across various protocols. The lack of "visibility" for organizations into commingling of funds and money laundering in DeFi, as noted by Claudia Quiroz, is a significant technical and regulatory hurdle.

To combat these threats, the panel emphasized the need for advanced screening tools and audit functions. Technically, screening tools involve real-time analysis of blockchain transactions against databases of known illicit addresses (e.g., sanctioned entities, addresses linked to hacks or scams). These tools often leverage graph analysis and machine learning to identify suspicious patterns and flag high-risk transactions. Audit functions, on the other hand, involve systematic review of smart contract code, protocol logic, and transaction histories to ensure compliance, identify vulnerabilities, and detect anomalous behavior. For new Web 3.0 developers, integrating these "guide rails" at the design phase means building smart contracts with upgradability mechanisms, access controls, and transparent logging, as well as incorporating oracle services that can pull in off-chain data for compliance checks where necessary. This proactive "security by design" approach is crucial for building a more resilient and compliant digital currency ecosystem.

Demo / Proof of Concept

▶ Watch: Second question: Most significant threats to the industry (10:07)

As this session was a panel discussion and not a technical presentation, no live demonstration or proof of concept was conducted. The speakers focused on sharing insights, strategies, and high-level technical considerations rather than showcasing specific tools or implementations.

Defensive Implications

▶ Watch: DOJ's view on evolving threats and NCET creation (10:50)

The insights shared by the panel have profound defensive implications for financial institutions, cryptocurrency platforms, and even individual users navigating the digital currency landscape. The primary directive for all stakeholders is to adopt a proactive and collaborative stance against evolving threats.

For traditional financial institutions like Wells Fargo, the defensive strategy involves a careful balance of innovation and regulation. As they explore tokenized cross-border payments and participation in initiatives like RLM, robust application security practices are paramount. This includes rigorous code audits for smart contracts, secure key management for digital assets, and comprehensive risk assessments for new blockchain-based services. Furthermore, integrating blockchain analytics tools into existing AML/KYC frameworks is essential to monitor the flow of funds entering or leaving regulated systems, ensuring compliance with sanctions and anti-money laundering regulations. The emphasis on operating within "regulated markets" means adhering to existing financial laws while adapting them to new digital asset classes.

For cryptocurrency exchanges and Web 3.0 developers, the defensive posture must be multifaceted. Philip Martin's acknowledgment of the traceability of blockchain assets suggests that leveraging blockchain explorers and advanced analytics tools is a fundamental defensive measure. Implementing sophisticated transaction monitoring systems that can detect unusual patterns, large transfers to mixing services, or interactions with known illicit addresses is crucial. For developers building new Web 3.0 protocols and DeFi applications, "security by design" is non-negotiable. This means:

  • Smart Contract Audits: Before deployment, smart contract code must undergo thorough independent security audits to identify vulnerabilities that could lead to hacks or exploits.
  • Decentralized Identity (DID) Solutions: While challenging in decentralized environments, exploring DID solutions could help in verifying participants without centralizing control, enhancing accountability.
  • Oracle Security: If DeFi protocols rely on external data feeds (oracles), securing these feeds against manipulation is vital to prevent economic exploits.
  • Incident Response Plans: Establishing clear, rapid-response protocols for hacks or exploits, including mechanisms to freeze or recover funds where technically feasible and legally permissible.
  • Proactive Engagement with Law Enforcement: As Claudia Quiroz stressed, establishing open lines of communication with agencies like the DOJ NCET and FBI is a critical defensive measure. This fosters trust and enables rapid information sharing in the event of an incident, allowing for faster fund tracing and seizure, ultimately improving the chances of victim recovery.

Law enforcement and regulatory bodies are bolstering their defenses through specialization and collaboration. The creation of the NCET and Digital Asset Coordinator Networks signifies a commitment to developing specialized expertise in crypto investigations. Defenders in this space should:

  • Invest in Training: Continuously train investigators and prosecutors on the latest blockchain technologies, attack vectors (e.g., pig butchering techniques, ransomware payment flows), and forensic tools.
  • International Cooperation: Strengthen partnerships with foreign law enforcement agencies to combat cross-border crypto crime, as illicit funds often move globally. The takedown of Sinbad, involving international partners, serves as a prime example.
  • Target Illicit Infrastructure: Focus on disrupting the infrastructure that enables crypto crime, such as mixing and tumbling services (e.g., Sinbad, Samurai Wallet, Tornado Cash), and platforms facilitating scams.

Finally, for individual users, defensive implications include:

  • Education: Understanding common scam tactics like pig butchering and phishing.
  • Secure Practices: Using strong, unique passwords, enabling two-factor authentication (2FA), and being wary of unsolicited investment opportunities.
  • Due Diligence: Thoroughly researching any platform or service before committing funds, especially in the unregulated DeFi space.

The overarching defensive implication is that no single entity can tackle the challenges alone. The evolving nature of digital currencies and their misuse necessitates a unified, adaptive, and collaborative defense strategy across the public and private sectors to build a truly safer future.

Key Takeaways

  • Digital Currencies are Programmable Money, Driving Web 3.0 Innovation: The shift to programmable money and decentralized Web 3.0 architectures is fundamentally changing financial services, enabling innovations like tokenized cross-border payments and new settlement mechanisms within regulated frameworks.
  • Blockchain Offers Unique Traceability, Despite Mixer Challenges: While criminals are drawn to digital assets, the inherent transparency and traceability of many public blockchains, facilitated by tools like blockchain explorers, can make tracing illicit funds more effective than with traditional cash. However, services like Sinbad and Tornado Cash actively work to obscure these trails.
  • Threat Landscape is Dynamic and Sophisticated: The industry faces escalating threats from sophisticated scams (e.g., pig butchering), hacks, nation-state actors (e.g., North Korea's Lazarus Group), and ransomware, with emerging concerns at the intersection of blockchain and AI.
  • Public-Private Partnerships are Critical for Enforcement: Effective combat against crypto crime relies heavily on robust collaboration between law enforcement (like the DOJ NCET and FBI) and the private sector, enabling rapid response to incidents and facilitating fund recovery.
  • Proactive Security by Design is Essential for New Ventures: Developers building Web 3.0 companies and DeFi protocols must integrate security "guide rails," robust screening tools, and audit functions from the outset to ensure compliance and mitigate risks of exploitation.
  • DOJ is Achieving Significant Successes: The U.S. Department of Justice, through the NCET, has demonstrated notable successes in prosecuting high-profile cases (e.g., FTX's Sam Bankman-Fried, Sinbad takedown, Samurai Wallet indictment) and is actively pursuing legal action against other illicit services like Tornado Cash.

About the Speaker(s)

Tashiana Bright serves as a Section Chief with the Federal Bureau of Investigation (FBI), demonstrating her expertise and leadership in federal law enforcement. In her role, she is deeply involved in navigating the complex challenges presented by digital currencies and ensuring a safer financial ecosystem.

Ajoy Kumar is the Head of Application Security for Wells Fargo, a diversified financial services company providing a wide array of banking, insurance, investment, and consumer finance services globally. His perspective highlights how traditional financial institutions are approaching digital assets, focusing on regulated markets and innovative use cases like tokenized cross-border payments.

Philip Martin is the Chief Security Officer (CSO) for Coinbase Global, Incorporated, a leading secure online platform for buying, selling, transferring, and storing cryptocurrency. With eight years of experience at Coinbase, his insights offer a crucial perspective from a major cryptocurrency exchange on securing digital assets and combating illicit activity within the burgeoning blockchain ecosystem.

Claudia Quiroz holds the dual roles of Director of the U.S. Department of Justice's National Cryptocurrency Enforcement Team (NCET) and Deputy Chief of the Computer Crime and Intellectual Property Section. The NCET identifies, investigates, supports, and pursues the department's cases involving the criminal use of digital assets, with a particular focus on virtual currency exchanges, mixing services, and other entities enabling misuse. Her extensive experience, including 10 years with the Department of Justice, provides a critical law enforcement perspective on prosecuting crypto crime and building national expertise in this specialized field.

All talks from RSA Conference 2024