BTC
ETH
HTX
SOL
BNB
View Market
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

Wang Yishi on "100 People in Blockchain": Everyone's growth potential is limitless

币安广场
特邀专栏作者
This article is about 7374 words, reading the full article takes about 11 minutes
In 2013, a junior majoring in civil engineering bought his first Bitcoin through a purchasing agent on Taobao. Twelve years later, he became the founder of OneKey, one of the most important hardware wallet companies in the industry.
AI Summary
Expand
  • Core viewpoints: OneKey founder Wang Yishi reviewed his entrepreneurial journey from civil engineering to crypto hardware wallets, pointing out that the industry's security attack-defense landscape has undergone dramatic changes due to AI empowerment, and that the root cause of incidents has shifted from code vulnerabilities to attacks on people. He also emphasized the value of rapid trial and error and product validation.
  • Key elements:
    1. He entered the space in 2013 because of Bitcoin's price rise, moving from ByteDance to going all in on crypto, and believes that crypto's feedback cycle is far faster than those of civil engineering and the internet.
    2. DeFi Summer in 2020 was a growth inflection point for OneKey. It acquired its first batch of users through localized experience and an open-source, verifiable strategy, but once missed the opportunity to seize the moment because hardware was out of stock.
    3. AI has shortened the construction of attack chains from two or three researchers taking two months to one engineer taking two weeks. Defenders have a self-attack advantage because they have access to unreleased code.
    4. In the Bybit $1.5 billion theft case, there were no bugs in the multisig contract, cold wallet, or Ledger device. The problem was that a Safe front-end engineer's computer was social engineered, and malicious code was implanted into the front end that only took effect on Bybit addresses. Combined with Ledger blind signing, a proxy transfer action was ultimately signed.
    5. OneKey adopts paid real-world tasks plus a paid trial period for hiring to solve the problem of low hit rates in conventional interviews.
    6. He advocates exposing children to investment accounts as early as possible, cultivating their understanding of money through failing cheap and failing early.
    7. In the AI era, entrepreneurs should quickly use AI to build products and obtain feedback, shifting from show me the code to show me the product.

In 2013, a third-year civil engineering student bought his first Bitcoin on Taobao through a proxy purchasing service. Twelve years later, he became the founder of OneKey, one of the most important hardware wallet companies in the industry.

In this conversation, Wang Yishi @ohyishi talked about the judgments and trade-offs he made along the way, but we spent more time on topics the industry can't seem to avoid these days: how AI is empowering both attackers and defenders, what exactly went wrong behind the Bybit $1.5 billion heist, why he designed OneKey's hiring process to be like "matchmaking" and what he's really screening for, and how he plans to use a "first-startup trial-and-error fund" to cultivate his own children.

1. Entering the Space: From Civil Engineering to Bitcoin

Host Beca: You come from a civil engineering background and bought your first Bitcoin on Taobao as a junior in 2013. What pulled you from the construction site to the chain?

Wang Yishi: To put it bluntly — because it went up.

2013 was a bull market. It had been rising since 2012, and by Q4 it peaked at nearly 8,000 RMB. My first purchase was around $100, about 700 RMB.

Back then you could buy Bitcoin and Ripple directly on Taobao — just click a link and pay. The trading was very primitive. Domestic exchanges were also starting to emerge, like BTC China run by Yang Linke. The reason I bought was simply that the price went up and I noticed it. When I read Teacher Xiao Lei's article "When This Thing Emerges, the World Rebels," I was thrilled, and then I went to the Babbitt forum and Bitcointalk to read a lot of early posts.

So the core reason was — it went up, so I bought.

Host Beca: From ByteDance to Bixin to OneKey, how did you make your decisions step by step?

Wang Yishi: When I joined ByteDance, the company had about 400 people. Now it should have 100,000. At the time, ByteDance's most profitable product was Toutiao APP advertising, valued at $1 billion — now it might be $500 billion or even over a trillion.

ByteDance was a classic "APP factory": every month it would release several APPs, use tabs in the main APP to funnel traffic to new products, and look at the data to decide whether to keep investing or shut them down — extremely brutal. The AB test, data-driven mindset was already very strong back then.

But big companies have an inherent problem: too many resources can sometimes be a curse. You're short-staffed, so you hire; you need budget, so you submit an OA request; you need traffic, so you ask for it — in that environment you're more like a component. You have to do your job very well, but you inherently lack some "wilderness survival experience."

What I mean by "wilderness survival" is when you build something new, no traffic is funneled to you, and no one helps you handle problems outside the product itself. It's different from something that's growing wild out there.

Why did I choose crypto later? Because civil engineering is slow. The feedback cycle in civil engineering is measured in "years": the design institute produces drawings, your senior goes to the site to work on a bridge project for several years. The internet is fast, and crypto is even faster — you put money in, it goes up, and you get strong positive feedback.

And when I was working at ByteDance, aside from paying rent, basically all my income went into buying crypto. So either way I was buying crypto — why not just go all in on the industry?

2. How OneKey Got Its "First Wave of Users"

Host Beca: In the hardware wallet space, Ledger and Trezor had already been at it for six or seven years. How did OneKey break out among so many competitors?

Wang Yishi: Actually, even now, OneKey hasn't "broken out" — that word is a bit of an overstatement. OneKey is still working very hard on growth.

But if I had to point to one thing, the biggest growth moment was DeFi Summer in 2020. At that time, a massive amount of capital flowed from exchanges onto the chain — because there were pools on-chain with very high annualized yields. But what tool were you using? MetaMask.

MetaMask's security wasn't great at the time. I remember when we did an audit at the end of 2020, we found that the way it stored seed phrases posed security risks — relatively easy to obtain the source file and brute-force it.

Users with larger amounts of capital wanted DeFi but didn't want their money to vanish one day because their computer got a trojan or their browser got hacked. They started using hardware wallets. But if you used Ledger to farm on Uni, you had to install Ledger Live, install the Ethereum APP, install MetaMask, then connect MetaMask to Ledger, and also close the Ledger client because they'd fight over the same USB port —

It felt like using three remote controls to operate one TV. Very hard to use.

OneKey made some UX innovations at the time, especially around localization and reducing friction — that was our first wave of users.

Host Beca: Besides improving user experience, what was another reason for achieving growth?

Wang Yishi: Open source.

Ledger still isn't open source to this day. Our judgment was — a product that asks you to "trust" it's secure versus one that gives you the ability to "verify" whether it's secure — in the long run, the latter is better. Just like AI models today, I'm also bullish on open source long-term. Verifiability is very important.

After the first wave of growth, the rest was really about competitors — they didn't do well, they handed us opportunities, and users gradually came over.

Coldcard also had an incident recently. Coldcard is a wallet made by very professional, very geeky Bitcoin OGs. But can you imagine — they had a seed phrase generation vulnerability sitting openly on the internet for nearly four years, from 2021 to 2025, and didn't fix it. So are they really that professional? I have my doubts.

Every time a competitor makes a basic mistake, our user base grows a little. That's basically how it goes.

So it's not "breaking out" — it's just surviving.

Host Beca: The high-growth phase is also when companies are most prone to mistakes. What detours did you take?

Wang Yishi: Way too many. Looking back now — absolutely speechless.

During DeFi Summer, our wallets were out of stock for nearly a year.

The reason was we'd opened new molds, wanted to build the firmware ourselves from scratch, and underestimated the difficulty and R&D cycle. Once you touch hardware, it's different from software — hardware has a supply chain behind it, and one problem leads to a hundred more. As a result, during the time we should have been capturing a massive number of users, we had no inventory.

If you don't even have inventory — you're essentially giving away traffic.

There were also some technical architecture issues: premature design, premature optimization, over-design. Instead of "let's focus on growth first, let users actually use it, then optimize gradually." That order matters. If we'd thought that through clearly back then, we'd be doing much better than we are now.

3. Attack and Defense in the AI Era: From "Two Months" to "Two Weeks"

Host Beca: AI is becoming more and more efficient at finding vulnerabilities. What preparations have you made?

Wang Yishi: This is an industry-wide problem, not just in crypto. People used to think iOS was very secure, but now with AI models, iOS has plenty of vulnerabilities too.

Our team has a security team called Anzen Labs (Anzen means "safety" in Japanese). This year we published a USB vulnerability at Black Hat — from finding the vulnerability to reproducing it, to chaining several vulnerabilities into a complete supply chain attack, almost entirely using AI.

Before AI, to build such a complete attack chain, you'd need about two to three fairly senior security researchers and two months. But this time, finding this vulnerability took just one security engineer and two weeks.

The speed change is very fast.

But AI making it easier to find vulnerabilities — that "easier" applies to the defensive side too.

Defenders have one advantage over attackers: you have unpublished code in your repository. For an attacker to attack you, the prerequisite is that they can find your stuff. If you're open source, then everyone can gang up on you; but your product and code are constantly iterating, and there's definitely a portion that hasn't been released yet — at that point you can attack yourself.

Previously, we did firmware security audits basically twice a year, hiring two or more companies for cross-auditing. Very low frequency. But now with AI tools assisting, you can audit every week, every release.

AI is basically a kitchen knife — you can use it to kill people, or you can use it to cook. It depends on how teams in the industry use it.

4. The Bybit $1.5 Billion Heist: Every Link in the Chain Was Fine, Yet the Money Was Gone

Host Beca: Why haven't incidents decreased even as defensive tools keep getting stronger?

Wang Yishi: More tools, stronger tools, and incidents that keep happening — these three things are true simultaneously.

The common attack methods used to be finding contract vulnerabilities, flash loans, manipulating oracles — these still exist, but not as many as before. Why? Because many protocol developers now use auditing tools and formal verification, which can block most of these vulnerabilities.

So attackers realized — going after code isn't cost-effective. Right? General Kim needs to feed so many people.

They found: if code is hard to attack, then go after the people.

Host Beca: Take the Bybit $1.5 billion heist as an example — every link seemed to be fine?

Wang Yishi: Exactly. This is a particularly typical example.

Bybit's Safe multisig was hacked for $1.5 billion, and each link individually was fine: the multisig contract itself had no bugs; Bybit's cold wallet itself was fine; the Ledger hardware devices they used had no bugs either.

So where was the problem? In a frontend engineer at Safe, whose computer was socially engineered by North Korean hackers Lazarus.

After being social engineered, malicious code was injected into Safe's official frontend, and this code only activated for Bybit's specific address. So when the four Bybit people (Ben and three others from finance and audit) signed, what they saw on the webpage was a perfectly normal transfer from cold wallet to hot wallet.

As luck would have it, Ledger was doing blind signing — it didn't parse the Safe contract, didn't display the delegatecall, and didn't give any warning.

What they actually signed was a "proxy transfer" action — handing over the permissions of the Bybit Safe contract directly. Ownership was gone.

You see, every link seemed fine, and the only thing that went wrong was the Safe frontend engineer's computer being compromised. But all conditions happened to be met simultaneously, and then — it really hurts.

Previously they tried to hack your code; now they try to hack your people.

There's a saying in traffic safety — if you install seatbelts and airbags for drivers, they'll drive faster. Same in the industry. Everyone keeps adding more: more audits, multisig, passphrases, raising the attack threshold. But often what gets you isn't the places you can see at a glance, but the places you can't see.

Your castle is impregnable, and then your security guard is wandering outside with the keys on him. Someone comes up and says "Hey buddy, want a cigarette?" — you smoke, and next thing you know your keys are stolen. That's the feeling.

5. Hacking Ledger: A Vulnerability Disclosure in the "Olympic Spirit"

Host Beca: You recently disclosed a Ledger transaction replacement vulnerability with "we hacked Ledger." Why so high-profile?

Wang Yishi: First of all, that vulnerability has already been fixed.

When I posted that, Ledger's firmware was already at version 1.2.3; the vulnerability was in 1.2.1 and had been fixed about two weeks earlier. The "we hacked Ledger" phrasing is indeed a bit clickbait-y — but Ledger has always done this too, so it's fine.

This vulnerability is technically called TOCTOU (time-of-check to time-of-use) — it exploits the time gap between the device and the computer. The user sees on the device "transfer $1 million from address A to address B," and then signs it; but in that gap I inject transaction B, so what you actually signed is transaction B, and I use transaction B to replace your transaction A.

In terms of the danger level of the vulnerability — this is actually quite dangerous.

Our Anzen Labs' daily mission is to hack ourselves. If I can't even hack myself, that proves that in my security capabilities, there's something I can't crack, something I can't handle.

But there is exchange within the industry. We previously also reported some security bugs to Keystone — giving them about two months' notice, telling them how to reproduce, providing the complete solution, and after they fixed it and forced an update, we disclosed it together. That's great. There should be this kind of healthy Olympic spirit.

6. Hiring: An Interview Is Two Actors Performing for Each Other

Host Beca: OneKey's hiring process is quite unique — first paying candidates to do a real-world task, and after passing, there's a paid trial period. Why?

Wang Yishi: The core reason is — we can't find suitable people.

All the "strange hiring methods" you see aren't actually strange — it's because conventional methods have a very low hit rate.

Hiring is a lot like matchmaking. If you interview someone and have a great conversation, what does that prove? — It proves this person is very good at interviewing. He's predicted your prediction of his prediction. A strong candidate will make the interviewer "arrive at the conclusion he wants on their own," making the interviewer think it was their own astute insight that discovered this person's qualities — this is a very sophisticated form of psychological manipulation.

The interview process is actually more like both sides performing — the candidate performs being a very capable person, and I perform being a great company. Then the two actors watch each other's performance and decide whether to get together.

But a two-to-three-day paid practical task is different. You can observe the other person's problem-solving approach, completeness, delivery quality — and most importantly, whether they actively communicate when they hit problems, or hold it in and then drop a bombshell. At work, we want problems communicated promptly.

And the questions are all made by us, not "fishing for solutions" by taking questions from YC.

It's the same for candidates — they can intuitively experience how the company does things in two to three days. Because the person who sets the questions is usually their direct colleague after joining. They'll know whether they like this person. That's very important.

Finally, we pay. Besides respecting the other person's time, payment serves another purpose — if I suddenly give you a task out of nowhere and say I want to test your abilities, and you spend a day or two on it, you'd feel I'm exploiting you for free. If I pay, you'll feel I'm taking this seriously, so you'll be a bit more serious too.

Host Beca: You once said — "I can't accept engineers who still can't use AI coding efficiently in 2025." What does your ideal team look like?

Wang Yishi: That statement in 2025 was indeed a bit of a "hot take." Codex hadn't even come out then, and AI could just barely improve efficiency in coding and text.

But this year we've brought in a lot of new hardware-related things. For example, hardware testing — now there are no test engineers in the office, just four or five robotic arms.

Some tests on phones you can just plug in a USB cable and read commands, but some things are external — like whether there's lag when swiping, the feel of buttons — requiring vision plus external hands to coordinate. Before 2026, we had many test engineers in the office clicking through by hand, over and over. Now it's robotic arms + high-def cameras + models: every release, these things automatically feed into the testing backend, and the robotic arms tap-tap-tap through each test case one by one.

This wasn't built by a hardware engineer or a test engineer alone — it was built by two people together. Because everyone has a consensus on "what the strongest AI models can achieve now," and based on that consensus, we believed this could be done. Then we tried — and it proved it really could be done.

AI's biggest change is giving everyone

wallet
Welcome to Join Odaily Official Community