OneKey founder Yishi Wang on AI-driven security, the Bybit hack, and how hardware wallets stay alive

OneKey founder Yishi Wang on AI-driven security, the Bybit hack, and how hardware wallets stay alive

N
News Editor
2026-09-18 01:37:12
OneKey founder Yishi Wang used a wide-ranging interview to map out how he entered crypto, how OneKey found its first users during DeFi Summer, and why he thinks AI has sharply compressed the timeline for both attackers and defenders. Speaking with Beca in an interview published by MarsBit, Wang said he first bought Bitcoin in 2013 while studying civil engineering, then later moved from ByteDance into crypto after deciding the industry offered faster feedback loops and a stronger personal conviction. He said OneKey’s early traction came in 2020, when larger on-chain users wanted hardware protection but found existing wallet setups cumbersome. Wang argued that local user experience improvements and open-source design helped OneKey win those users. He also described mistakes during the company’s growth phase, including nearly a year of product shortages and what he called premature design and over-optimization. A large part of the discussion focused on security. Wang said AI has cut the time needed to build a full attack chain from roughly two months with two or three senior researchers to two weeks with one security engineer in one recent case handled by OneKey’s Anzen Labs. He also walked through his reading of the $1.5 billion Bybit theft, saying the failure was not in the multisig contract, cold wallet, or Ledger device itself, but in a compromised Safe frontend engineer and a blind-signing flow that failed to show the real action being approved.

MarsBit published a long interview with OneKey founder Yishi Wang, and he walked through how he got into crypto, what pushed OneKey forward, how AI is reshaping security work, and what he thinks about hiring, education, and building products.

OneKey founder Yishi Wang on AI-driven security, the Bybit hack, and how hardware wallets stay alive 2

The piece, written by Beca for Blockchain 100, starts with Wang’s own timeline. Back in 2013, when he was still a junior studying civil engineering, he bought his first Bitcoin on Taobao. Twelve years on, he is one of the founders of OneKey, the hardware wallet company that has grown into one of the better-known names in the business.

From civil engineering to Bitcoin

When asked what dragged him from construction sites into crypto, Wang did not dress it up: “To put it plainly — because it was going up.” He said 2013 was a bull market. Prices had been climbing since 2012, and by the fourth quarter of 2013 Bitcoin was close to RMB 8,000. His first buy was a little above $100, or about RMB 700.

Back then, he said, Taobao users could buy Bitcoin and XRP directly through simple product links and payment flows. Domestic exchanges were starting to show up too, including BTC China, which he mentioned by name. Wang said he first noticed the asset because the price was rising, then read Xiao Lei’s article “When This Thing Appears, the World Will Be Turned Upside Down,” spent time on Babite and Bitcointalk reading early posts, and only then decided to buy.

Later, he moved into tech and joined ByteDance when the company had around 400 employees. He contrasted that with what he said is now a workforce of about 100,000. At the time, he said, ByteDance’s most profitable business was advertising inside the Jinri Toutiao app, and the company was valued at about $1 billion. In his view, that number today could be $500 billion or even above the trillion-dollar line.

He described ByteDance then as an “app factory.” New apps came out every month. Traffic from the main app was pushed into them. Data decided who kept getting resources and who got shut down. A/B testing. Data-first thinking. Already baked in.

But big companies have their own trap, he said. Too many resources can turn into a curse. Need people? Hire them. Need budget? File for it. Need traffic? Ask for it. In that setup, a person can end up feeling more like a part in a machine than a builder. And that makes it harder to develop what he called “wild survival experience” — creating something from scratch without traffic being poured on top and without somebody else cleaning up all the ugly non-product problems around it.

Crypto pulled him in partly because of speed. Civil engineering runs on feedback cycles measured in years, he said. A bridge can take years from design to execution. The internet is faster. Crypto is faster still. As he put it, if you put money in and it goes up, it goes up, and the positive feedback comes right away. He added that while he was at ByteDance, after paying rent, he put almost all of his income into crypto. So. Since he was buying coins anyway, he decided to go all in on the industry too.

How OneKey found its first users

Wang pushed back on the idea that OneKey had already truly “broken out.” He said the company is still grinding for growth. Still, if he had to name the biggest turning point, he picked DeFi Summer in 2020.

That was the moment large pools of capital moved off exchanges and onto the chain, pulled by liquidity pools and high annualized yields. The main tool people used was MetaMask. Wang said MetaMask’s security at the time was not good enough. During an audit at the end of 2020, he said, OneKey found that the way MetaMask stored seed phrases created security risk because source files could be obtained and brute-forced more easily.

For bigger users, the issue was obvious. They wanted DeFi exposure. They did not want a trojan on a laptop or a hacked browser to wipe them out. So they moved toward hardware wallets. But Ledger’s flow was clunky. Wang said a user farming on Uniswap with Ledger had to install Ledger Live, install the Ethereum app, install MetaMask, connect Ledger through MetaMask, and then close the Ledger client because both pieces of software would fight over the same USB port. His comparison was blunt: it was like using three remote controls for one TV.

OneKey’s first batch of users came from trying to cut that friction out. Wang said the company focused on improving user experience, especially localization and smoother flows.

He also pointed to open source as another reason the company was able to gain users. Ledger, he said, still is not open source. OneKey sees a real difference between asking users to trust that a product is secure and giving them a way to verify whether it is secure. Over the long haul, he said, the second model is better. He applied the same logic to AI models too, saying he stays positive on open source because verifiability matters.

After that first growth phase, Wang said, part of the rest was just competitors making mistakes. He brought up Coldcard as a recent example. In his telling, Coldcard is a wallet built by highly technical Bitcoin OGs, yet a seed-generation flaw sat there publicly visible in open-source form from 2021 to 2025 — nearly four years — without being fixed. That, he said, made him question how professional the product really was.

Whenever competitors make basic mistakes, he said, OneKey’s user count usually ticks up a bit. So he would not say OneKey “won.” His version is narrower. It survived.

What went wrong during growth

Wang said the company made plenty of mistakes during its faster-growth stretch. Looking back, one of the biggest was supply. During DeFi Summer, OneKey was out of stock for nearly a year.

Why? He said the team opened a new mold and wanted to build the firmware end to end by itself, while badly underestimating both the difficulty and the development cycle. Hardware is not software, he said. Once hardware gets involved, the supply chain shows up too, and one problem can quickly become a hundred.

The result hurt. Right when the company should have been grabbing market share, it had no inventory. In his words, if you do not even have product to sell, you are basically handing traffic away.

He also pointed to architecture mistakes: premature design, premature optimization, and over-design. The better order, he said, would have been simple — focus first on growth and getting the product into users’ hands, then optimize over time. Had the team understood that sequence more clearly, he said, the result could have been much better than where the company is now.

AI has cut attack-chain timelines from months to weeks

On security, Wang said the pressure from AI is not some crypto-only problem. It hits every industry. People used to think iOS was highly secure, he said, but with AI models in the mix, iOS also has many holes.

He said OneKey has an internal security team called Anzen Labs, with “Anzen” meaning “safety” in Japanese. This year, the team disclosed a USB vulnerability at Black Hat. From finding the bug to reproducing it to chaining several issues into a full supply-chain attack, he said, AI was used through almost the whole process.

Wang made the comparison directly. Before AI, building a full attack chain like that would usually take two or three fairly senior security researchers and about two months of work. This time, he said, it took one security engineer and two weeks.

That speed change is huge. But he argued the same “easier” effect helps defenders too. Defenders get one edge attackers do not have: access to unpublished code sitting in internal repositories. Attackers first have to find the target. If a project is open source, everyone can attack it in parallel. But products and codebases keep changing, and part of that code has not been released yet. That gives teams a shot to attack themselves first.

He said OneKey used to audit firmware security roughly twice a year, usually with at least two firms doing cross-audits. Slow cadence. With AI-assisted tools, he said, audits can now happen every week and with every release.

Wang boiled it down to a simple metaphor: AI is a kitchen knife. It can be used to kill, or it can be used to cook. What matters is how teams in the industry use it.

The $1.5 billion Bybit theft and the shift from code to people

Asked why incidents have not fallen even though defensive tools are more numerous and more powerful, Wang said all three things can be true at the same time: tools are improving, there are more of them, and accidents still happen.

He said older attack patterns like contract exploits, flash loans, and oracle manipulation still exist, just not at the same volume as before. One reason, he said, is that many protocol developers now use audit tools and formal verification, which can block a big share of those vulnerabilities.

Attackers respond by chasing better economics. If code is harder to exploit, they move up the stack and target people.

Wang used the $1.5 billion Bybit theft as the cleanest example. In his reading, each part looked fine on its own. The Safe multisig contract had no bug. Bybit’s cold wallet had no issue. The Ledger hardware device involved had no bug either.

The point of failure, he said, was a frontend engineer working on the Safe protocol. According to Wang’s account, that engineer’s computer was compromised through social engineering by North Korean hackers from Lazarus. Malicious code was then inserted into Safe’s official frontend, and it was configured to affect only one Bybit address.

So when Bybit’s four signers — Ben and three other finance and audit staff, as Wang described them — approved the transaction, what they saw in the web interface looked like a normal transfer from a cold wallet to a hot wallet.

Ledger, though, was running in blind-signing mode. It did not parse the Safe contract, did not display the delegatecall, and did not show any warning. What the signers actually approved, Wang said, was a delegated transfer of authority that effectively handed over control of the Bybit Safe contract. Ownership was gone.

That is what made the case so striking to him. Every visible layer looked intact. The only thing that failed was the Safe frontend engineer’s machine. But once all the conditions lined up, the money was gone.

He compared it to road safety. Give drivers seat belts and airbags, he said, and they may drive faster. Crypto works like that too. Teams add more audits, more multisigs, more passphrases, and raise the attack threshold. Yet the break often happens somewhere other than the obvious place everyone is staring at. It happens in the part nobody sees.

OneKey founder Yishi Wang on AI-driven security, the Bybit hack, and how hardware wallets stay alive 3

Why OneKey publicly disclosed a Ledger flaw

Wang also addressed OneKey’s recent disclosure of a Ledger transaction-replacement flaw under the line “we hacked Ledger.” First, he stressed that the issue had already been fixed.

By the time he made the post, he said, Ledger firmware was already at version 1.2.3. The flaw had existed in version 1.2.1 and had been fixed about two weeks earlier. He admitted “we hacked Ledger” makes for a good headline, though he added that Ledger has often used similar framing itself.

Technically, he said, the issue was a TOCTOU bug — time-of-check to time-of-use — that exploited the timing gap between the device and the computer. A user might see “send $1 million from address A to address B” on the device and sign it. In the gap before execution, an attacker could push through another transaction, causing the user to sign something different while the original transaction was displaced.

By the usual severity definitions, Wang said, the flaw was quite dangerous.

He said Anzen Labs spends its days trying to hack OneKey’s own products. If the team cannot break its own systems, that means its security ability is still not good enough. He added that the industry does share findings. OneKey has previously sent Keystone reports on security bugs, usually notifying the company about two months in advance, giving reproduction steps and a full fix path, then waiting until the issue is patched and a forced update is in place before disclosing it together. That, he said, is the kind of healthy “Olympic spirit” the sector should have.

Hiring as a paid trial, not a performance

Wang said OneKey’s unusual hiring process — paying candidates to complete practical tasks and then moving successful applicants into a paid trial period — comes from a very simple problem: the company struggles to find the right people.

What looks odd from the outside, he said, is just a response to the low hit rate of normal hiring methods. He compared recruiting to matchmaking. If an interview goes extremely well, that may only mean the candidate is extremely good at interviewing. Strong candidates can predict what interviewers want and steer them toward the conclusion they want them to reach.

That is why he sees standard interviews as a mutual performance. The candidate performs competence. The company performs being a great place to work. Two actors watch each other, then decide whether to stay together.

A paid practical assignment over two or three days shows more. Wang said it lets the company watch how a person thinks through a problem, how complete the work is, and what the delivery quality actually looks like. Most of all, it shows whether the person communicates actively when problems come up or stays quiet and then dumps a big issue at the end. At OneKey, he said, problems should be surfaced early.

He also stressed that the assignments are written internally, not copied from Y Combinator prompts to squeeze free ideas out of candidates. Candidates get something from it too, because the person setting the task is usually the person they would work with directly after joining. In two or three days, they can get a real sense of how that person works and whether they want that relationship.

And pay matters for another reason. Beyond respect for the candidate’s time, Wang said, payment signals seriousness. Without it, a company risks looking like it is just trying to get free labor.

AI coding, robotics, and hardware testing

Wang also came back to a line he had used before: that he could not accept engineers in 2025 who still could not use AI coding tools efficiently. He said that statement was a bit extreme at the time, especially because Codex had not yet been released and AI was only starting to improve programming and text workflows.

Still, he said, this year brought big changes in hardware-related work. In OneKey’s office, there are no test engineers doing that work by hand anymore. Instead, he said, there are four or five robotic arms.

Some phone tests can run directly through USB commands, he said, but others rely on external action and visual judgment — whether a swipe stutters, how a button feels, and similar checks. Before 2026, many test engineers in the office still had to tap through those flows by hand. Now the setup combines robotic arms, high-definition cameras, and models. With each release, test items are automatically sent to the testing backend, and the robotic arms run through the cases one by one.

He said this was not built by a hardware engineer alone or a test engineer alone. It took two people working together. The key was a shared understanding of what the strongest AI models can currently do. Once they had that common boundary, the team could decide the task was feasible, try it, and then prove it worked.

For Wang, that is AI’s biggest effect: it gives teams a shared frontier. Things that once looked impossible because two specialties did not understand each other can now produce results where 1 + 1 is greater than 2, or much greater.

Giving his son money to lose early

On parenting, Wang said he had previously talked on X about opening Binance and Robinhood accounts for his son under his own name and adding money to them each year.

That plan is still sitting on his to-do list for now. He named two obstacles. Robinhood requires a U.S. person, and his child is not one. Binance’s Junior account requires the child to be at least 6 or 13 years old, while his son was only three months old at the time. He said he still plans to do it later.

Wang referred to the founder of Dell opening an account for newborns in the U.S. and depositing $250, saying he found the idea interesting. The reason he wants to do something similar is simple: he believes children should encounter money as early as possible.

He was careful to separate this from pocket money. He was not talking about giving a child RMB 5 or RMB 30 to buy ice cream. He meant that once a child can recognize numbers and handle addition, subtraction, multiplication, and division within 100, parents can try giving them a savings account or even an investment account so they can learn how money works in the real world.

Then comes the part he emphasized most: let them lose it early. If a family gives a child RMB 10,000 and the child loses all of it before adulthood, Wang said, that is better than losing a larger amount later in life after graduation and employment. He summed it up in English: fail cheap, fail early. In his view, that is part of building a real understanding of money.

AI, imagination, and “show me the product”

Wang rejected the idea that AI will limit children’s imagination, or that only wealthy children will escape that limit. His view was the opposite. AI should free imagination, not box it in.

He framed it more broadly: human progress, he said, comes from younger people not always listening to older people. With AI, children can build all kinds of things. They can become builders early. They do not necessarily need to learn programming before making a product. If they can speak and express what they want, they can start building.

He pointed to the spread of 3D printers in households, including Bambu Lab devices, which can print small practical items at home rather than just figurines. He mentioned examples such as automatic switches and foldable pads for coffee machines. He said it is hard for him to imagine how happy he would have been if tools like that had existed when he was young.

Children can make apps, websites, and physical objects in the real world, he said, then combine them in countless ways.

At the end of the interview, Wang was asked what he would say to people who want to build something in crypto today, especially since he came from an unrelated academic background. He said he was not in a position to give grand advice and did not think he had done everything especially well. But he did say a person’s growth potential can be enormous. What someone studied, what they did after graduation, what they did at 20, 25, and 30 — all of those can be completely different things.

Whether a person likes something determines how much they will invest in it, he said. How they see it and understand it determines the ceiling of that growth. If they both like it and the field itself has a long slope and a long runway, they are more likely to go far.

He contrasted the current environment with an older one where builders often kept their work private until launch. Now, he said, AI can produce things so fast that if you have an idea, you can direct Codex, Grok, or Claude to help build it, and after a couple of resets you may already have something usable.

Once it exists, you can put it in front of users right away and get feedback fast: is it a real need, or just your own need? Do many others want it too but have not said so? Can it make money? Can it win long-term user support?

He cited Lovable as an example. Before building Lovable, its creator had made more than 30 vibe-coding apps that nobody used. Then Lovable took off. To Wang, that is a textbook case of rapid trial and error.

When someone builds a new product, he said, they connect the strengths and weaknesses of everything they built before — connecting dots. AI cannot replace that, because it lives in human judgment, taste, and decision-making.

He ended by updating an old startup line. It used to be “idea is cheap, show me the code.” Now, he said, you do not even need to show the code. “Just show me the product.” In his view, this really is the best era.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
3200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.