Back to All Episodes
Season 4Episode 160

Securing Crypto with MatterFi and SwissFortress

April 18, 2025
47m
1 Guest

Listen Now

About This Episode

Michal "Mehow" Pospieszalski, the founder of MatterFi and SwissFortress, joins Narb on DevNTell to discuss innovative solutions for cryptocurrency security. Mehow highlights the persistent issues of phishing and internal custody hacks that have plagued the industry for years. He demonstrates how MatterFi's "sent-to-name" technology and off-chain cryptographic proofs can eliminate these vulnerabilities by automating secure transfers and removing the need for human intervention in custodial systems. The conversation also touches on his extensive background in software security and the roadmap for bringing these advanced privacy and security tools to the mainstream market.

Key Takeaways

1

Cryptocurrency security is currently undermined by phishing scams and internal vulnerabilities in custodial systems.

2

MatterFi's 'sent-to-name' system enhances privacy by generating unique, decentralized stealth addresses for every transaction.

3

By replacing human signers with off-chain cryptographic proofs, MatterFi aims to prevent massive thefts caused by compromised keys.

4

The SwissFortress wallet provides a user-friendly experience similar to traditional payment apps while maintaining full decentralization and privacy.

5

Future developments include expanding chain support and launching a US-compliant version of the MatterFi infrastructure.

Featured Guest

M"

Michal "Mehow" Pospieszalski

Founder of MatterFi

MatterFi

Episode Transcript

Narb

GM, GM. Welcome to what's going to be another great episode of DevNTell. So if you didn't know, DevNTell is a 30-minute podcast held every Friday allowing founders, hackers, and anyone in between to come on the show and showcase what they've built. And today, I'm ecstatic to welcome Mehow, who's founder of both MatterFi and SwissFortress. So MatterFi is an easy-to-use fintech infrastructure helping make finance more secure for humans and AI, while SwissFortress is a private universal solution enabling sent-to-name crypto wallets and custody systems to combat phishing. So if you stick around for today's episode, you'll see Mehow give us an overview of both MatterFi and SwissFortress, drop some crypto security alpha, and show us how he plans to combat crypto hacking. All right, let's get into it.

Narb

GM, GM. Welcome to the show, Mehow. Pleasure to have you on.

Mehow

Hey, hey. Good to be here. Little pump-pump intro music. I dig it.

Narb

Thank you, thank you. You got the Lord of the Rings behind you. You know it's going to be a great show, right?

Mehow

Yeah, I play D&D, I guess, few times a week. I'm running, I guess, some professionally DM'd groups. I just love it. I started playing in the '80s and then just recently I started doing it again. And it's like awesome, it's still way better than the first edition, I would say, the 2024.5 version. I don't know, do you RPG?

Narb

I haven't played D&D, but I did used to RPG video game-wise back in the day. But yeah, I've heard lots of great things about it.

Mehow

I mean, it's way better than computer games for you, I think. Like I used to be like a hardcore gamer and it just, yeah, it's not healthy. I just don't think computer games are healthy in general. They're just like, they get you anxious and twitchy, and I know a lot of, like so many people are into it, but ultimately it's just this highly addictive sort of thing. And then, you know, the great thing about just regular like human-to-human gaming is that it can, you know, you can't game all night. Like the game has to end. And it's like, you know, way more sort of, like I think healthy for your mind. But yeah, I was just curious because your background is obviously ultra-nerd, so I had to ask.

Narb

Yeah, excellent. So I guess when you're not cooking up a storm on the D&D table...

Mehow

I'm not the cook, I'm the player. I don't like cooking. I've never liked DMing because it's just kind of like, I'd rather just enjoy like really good, you know, like really good adventure-driven narratives that, so I'm like very picky with my DMs. They have to be like the best. So I have to be in groups that are just like phenomenal storytellers and just, you know, never been into like running games. I just, yeah, I just min-max the tunes, but yeah, just like how I min-max the software.

Narb

There you go. Awesome. Yeah, and I guess you also have quite the love for combating crypto security with you founding both MatterFi and SwissFortress. But before we get into that, you kind of revealed some of the lighter side of Mehow, but do you want to do a brief introduction for the technical side of Mehow as well?

Mehow

Sure, so you know, I've been a hacker since I was 15. I started on the IBM PCjr. And I've been like coding basically my whole life, mostly with a security focus. So like the first three companies that I worked for all got bought, and then after that I stopped working for companies. So like I was the first Chief Technology Officer of Intellebridge.us, which is a DC-based intelligence software company essentially, that also does, you know, some security work. And they're still around, you know, I was there like early 2000s, so I was like one of, you know, employee number five or something, or three even. And then I worked at Sigital and LACG, which were both software security houses. So we did some of the early pioneering work in software security and WhiteHat Security, where we would be hired by either the government or some corporation to essentially analyze their software from a WhiteHat point of view by looking at the code to find all the vulnerabilities, you know, quickly.

Mehow

So what that got me into is like, you know, how do you build software that's like hyper-secure, right? And then, you know, where that ended up in crypto is that, you know, once crypto came out, like the hackers, the black hats were like, 'Yay, all the money's online now!' Like before, it was just like, yeah, we're going to, you know, do some viruses, like the, you know, viruses were like a big deal where it might eat your machine, but it didn't like, you know, go and steal a ton of money, for example, right? Like not directly. Like maybe there was ransomware, maybe there was some data theft, right? That data got resold, like something that was really common was like credit card data being resold. You know, but obviously the stakes are way higher when the actual money is digital, right? And then that's why we've seen this huge, you know, culture of theft and fraud, it's almost tolerated, right? It's like none of these people really ever go to jail. They just, just steal. And it's normal, like 'Oh, if you got, you know, phished or scammed in crypto, that like happens to everybody,' you know?

Mehow

So we've kind of just got to this place where we just accept it. We just say this is, you know, a known risk with the space and if you're in the space, you're, you know, you just got to, you got to be more clever than the hackers. And obviously that's a, you know, from, so you know, my personal mission is to create safety, accessibility, and trust because I just don't want people to get robbed. I mean, and the other problem is, like obviously when you have that sort of environment where like, you know, like the first thing a new user in crypto thinks is like, 'Okay, how do I not lose my money?' Like that's their main thing that they think about because of the, you know, broken environment. Like how are we going to get new users? Like how are we going to get past, you know, guys with Lord of the Rings in their background and dudes playing D&D, right? Like how is it going to go past us? Because it's just, you know, right now what we're attracting is like geeks, because you have to be a geek to survive. Like if you don't understand what's going on, then, you know, you're likely to lose funds and whatnot, right?

Mehow

So, you know, and then the sort of mainstream popularity of it, like ETFs and stuff, they're really, that's not actually decentralized anything. That's just, you know, translating crypto into something that somebody can understand, but without the, you know, but the problem like an ETF solves for a Bitcoin investor is it solves their security problem for them, right? They're like, 'Well, if I trust like, you know, my Wells Fargo or my, you know, savings account or my, you know, IRA or whatever to hold my funds, then clearly I'm cool with an ETF because it's the same level of risk,' right? So, like, yeah, but that, that doesn't actually, that's not actually fixing the problem. That's, that's just kind of working around the problem. So that's why I'm, you know, that's why I started MatterFi. So SwissFortress is a client of MatterFi that was kind of one of our marquee clients. I am a co-founder at SwissFortress, but all the tech is, you know, made in America.

Mehow

And again, you know, the other reason we started in Switzerland was just because of regulatory. You know, there will be a US version of that product coming out fairly soon, I have to, which will be cool. And these are things that sort of just kill the phishing and make crypto super easy to use. It's like decentralized PayPal or Zelle or, you know, or Venmo for all of crypto, right? So it's like just an instant payment system. You pick whatever digital currency you want, and you send to a name, and it just works and everything is decentralized. And addresses are computed automatically and you know who your counterparty is, but no one else knows that like you sent the money or how much money they have or anything, right? So it's like fully private, decentralized PayPal for all of crypto. You know, if you, if I'm asked to, I was asked to summarize it in what I call 'Vitalik-speak,' which is like, because Vitalik never, never just tells you what the feature does, he always just says, you know, this spec and that spec and as technical as possible. Right? So in Vitalik-speak, it's auto-computed stealth address via one-way non-interactive cryptographic proof that's tied to names, thereby making it super easy to use and guaranteeing privacy on all the chains and tokens that the tech supports, which is basically everything.

Mehow

Like, and at this point we're actually getting adoption on, you know, most of the majors, I would say. So there is, you know, if you have a favorite chain, it's likely I'm already, I'm already adding the tech to that chain. So yeah, it's, that's the sort of summary of where I came from and why I'm here.

Narb

That's amazing. And yeah, like when you were mentioning only the nerds can use it, I was going to say, like even the nerds have their problems. Like whenever you're transferring a decently large chunk of money from one wallet to another, like I don't know about you, but I like triple, quadruple check the address to make sure that, oh, yeah, it's like, and you do a test transaction, right? And it's like for like a dollar or something. Yeah, if you deposit to Kraken, like first you're checking that EtherScan address and then you're making sure that the balance shows up in Kraken, and then you send the main funds. I mean, it's ridiculous, right? So, yeah, that's, that's what, you know, it's broken even for super nerdy people. So like, you know, the Bybit hack, for example, I mean, that's Ben-E from Bybit, CEO, I believe it's the second biggest exchange on earth and, you know, he signed the wrong transaction because he doesn't know how to read hex, right? And it's like, you know, if he falls for it, then you will too, right? So, you know, that said, they had, you know, very highly funded state-sponsored hackers going after them. But the problem that happened at Bybit is, you know, extremely, it affects everybody, right? That's just sort of an, you know, a fringe example, a min-maxed example, maxed example of like how much money can be stolen when, you know, somebody's really, really dedicated to exploiting the same vulnerability that affects everybody every day for lower, lower amounts.

Narb

So yeah, what, what else, which way do you want to go? Do you want me to show you the tech, talk about the Bybit hack, talk about security in general?

Narb

Yeah, I mean, before we get into the nitty-gritty of what you have prepared, kind of wanted to touch a little bit more on the security and just kind of find out, like was there any type of security hack that you might have unfortunately fallen for that kind of continued to inspire your journey to founding MatterFi and SwissFortress? I know you've had quite a tenured experience in security, but I'm sure you have some nice, quote-unquote, 'war stories' around it. I mean, for me, it's really hard to fall for a hack. I'm usually the one that's exposing the hack. But, you know, I wouldn't say there's any particular war story. I think the, the big story is that all the war stories are really the same story. It's generally phishing, and gen- in crypto anyway, it's generally phishing, either, you know, sending you to a website that's asking you to essentially, you know, give up your wallet credentials, or sending to a website that's asking you to send funds to an address you don't know, right? And or pretending to be something else and asking you to send funds to an address you don't know, or tricking your device into giving control of let's say a smart contract to an address you don't know.

Mehow

So as you can see, this, you know, ultimately it's, you know, some combination of steal your keys or, or, or address you don't know. But even the 'go to the website' thing, even that doesn't sound like it's an address you don't know problem, right? Because initially they're not like, 'Hey, by the way, randomly just send money to this thing because we're Binance and if you do, then you're going to make all this cash,' right? Like they're not doing that. They're doing that in, you know, they've got to somehow get you interacting with them, right? So but like Telegram hacks, you know, and Telegram group hacks and Telegram scams, which are almost int- they're always about this. It's like, you know, send this funds here because we're a terrific trading group and we'll trade for you. But when you try to pull the funds out, then, you know, there's nothing there because obviously they already spent it eons ago, right? So, but ultimately even the web hacks, like the reason they exist is because there is no easy way for wallets to connect to custody in any sort of like native protocol. Like you have to use this web interface and then you have to receive an address and then you're mathematically guaranteed to not know that that address, who the address belongs to. 100% of the time, right? Like it's literally 'trust me, bro' accounting. It's like we have this amazing decentralized crypto where like, okay, once the address is correct, then everything is infallible.

Mehow

But for some reason, you know, knowing whether the address is correct or not is mathematically impossible, right? Like literally it's just a, okay, this is a person I trust and then therefore they give me the address because the only person that knows that that address is correct is the guy that generated it. The second you give it to somebody, now that person has no direct proof that it's yours or in fact anybody's, they don't know whose it is. Because there is no off-chain crypto proof that ties that address to an identity in a way that preserves privacy, right? And that's, that's the problem that we solved. So like for me it's not one story, it's that all the stories ultimately have to do with the same thing, which is that the, you know, the fundamental architecture of how we use cryptocurrencies is still broken, you know, and it's been 15 years since the Satoshi white paper. So this is a problem that has to get solved.

Mehow

And now, I mean, there is, you know, a big narrative coming, so Vitalik just posted about this a week ago. It's like, 'Hey, by the way guys, let's, let's start throwing in privacy,' right? So I can break down kind of like what he's talking about because he wrote a blog post and the first thing was like start using mixers. And the second point was, you know, have a new address for every application. Well, that's exactly what our software does. It's like for every two people that interact, you have a new address that gets generated and it's automatically tracked. And that address, to compute that address, you have to have the private key of either the sender or receiver. Ergo, it's decentralized. Ergo, no one knows what the address is. So like if I'm sending money to Narb, then I compute, you know, your say BCH or Ethereum or Casper or whatever address as X.

Mehow

Now if somebody else is sending money to you using still your same name, Narb, they'll compute a different address Y. And the person computing X cannot know Y and vice versa. And that applies to the whole world, meaning that there is no central database of receive addresses anywhere. So then when you combine that, so that solves Vitalik's second point, which is freaking awesome because we're the only people that have it working in a sane way. There's been a few other attempts at doing this, but you know, they've all sort of either commercially or, or just technically failed. And obviously the centralized approach of like, 'Here's a master list of addresses and, you know, you got to put your address in here,' that only works if the entire chain is shielded. But then the other problem is all the shielded means that like third parties don't know, you know, who sent there. They can't see the, essentially like an EtherScan doesn't exist in those places, right? So if you have a shielded transaction like that.

Mehow

But very few chains support that and then even then, you still, you still got to deal with the address, like who's the address, right? Now if you have a static database, everybody sends to the same address. So even if the transaction's shielded, you as the recipient still don't know where the money came from, right? So so that's a huge problem because then, you know, like the accounting is like a year later you're like, 'Oh man, I don't remember, I mean, if you got to report like, you want a log that looks like PayPal or, you know, export my account history,' and what you get is if you export your account history is you get a bunch of addresses and then you have to explain every single one. It's not tenable, right? So, so it's, it's not tenable, right? So we're in this unique place where all of a sudden the privacy is the meta. And we've actually been working on the privacy and the ease, but more importantly the ease of use, you know, for, I've been doing this for five years at this company for three because MatterFi bought two other companies before to create the tech.

Mehow

And then I, you know, raised all the money, got most of the customers, built the team, and wrote nine patents. The only thing I don't really do is code, but I do, do a lot of the architecture. Not anymore. I mean, I used to code a lot, but not, not at this job in particular. So I think that's, you know, that's the answer to 'What's the big story?' The big story is that all the stories are the same story.

Narb

That's a wonderful answer. And yeah, I mean like everybody's, everybody's seen 'em, seen all the, all the stories come up on their Twitter/X feeds. It's like you say, usually the same thing over and over. Every other day, yeah. Every other day. That's right. New hack, you know, how many millions got stolen today? Right, so so that's like, and you know, the other, the other side of it is like the custody hacks, right? So what the custody hacks do is they amplify the brokenness of the system. And that's the other thing I can talk about because we do have another thing that's not sent-to-name that when you combine with sent-to-name makes custody super safe. So really like, you know, the big theft is always a combination of, you know, like Bybit essentially is fooling the signers into, because they have no sent-to-name and no clear crypto proofs for their cold wallets, meaning like there is no sign that says, 'Okay, you're, hey Benny from Bybit, you're transferring from wallet named X to wallet named Y,' right? And you're the signer and the other two signers are so-and-so and like everybody's identity's revealed to that signer but not to the public.

Mehow

Right? Like if that was the case, then, you know, every time you had a normal operation, that's what would happen in that cold wallet transfer. But then what the hackers did is they sent essentially what was from the wallet's point of view a random signature request for a random DeFi call, right? Which just replaced the, the code in the contract with the attacker's code, just based on one parameter being changed and the payload was obviously different because the payload was actually this new code. But it all looked like, you know, the regular hacks that they typically do. Now in our system, that wouldn't be the case, right? If they were using that, it wouldn't be the case. But they, and then if the attacker, you know, ran into our system while they're trying to execute that same hack, the Ledger would just say, 'Hey, this is a random contract call, you probably shouldn't sign it unless you're 100% confident that this hex is secure,' right? So obviously as a user of like your regular thing says, 'Transfer from A to B, sign here,' and plain English, right? And that's the actual cryptographic proof, meaning the wall- like nothing else can happen. Like the only thing that can happen when you sign that is that maybe the message doesn't make it to a node and nothing happens. But the money's not stolen, right?

Mehow

So you know, in that reality we would have, we would have defeated them and that speaks to off-chain crypto proofs, which not only can you use them to create this sort of sent-to-name scheme, which is a combination of on- and off-chain crypto proof, it's really what I would call a side- side-chain crypto proof. Not side because it doesn't use a chain but outside the chain crypto proof that's using some on-chain metadata to create this 100% accuracy of like who you're interacting with, right? So that's how we do it. But if you have full off-chain crypto proofs in your custody system, now you don't need signers at all on the custody side. So you don't need people with keys just sitting there like approving transactions and signing things. Like it's just not necessary, and I can explain why that is. So now you don't have the vulnerability at all of like the internal job. Right? So now like things like FTX and Mt. Gox, although still possible in our system, they're way less likely because you can create essentially ceremony around the keys that makes the op-sec extremely easy, because there aren't like a million people in your organization every day with the keys to the money. And that's like the thing that the, you know, Lazarus Group which is WazirX, Fhemex, Bybit obviously and a million other things they're constantly exploring. They're like, 'Well, I'm going to fool those, you know, two out of three guys or three out of five guys or whoever, you know, whatever the multi-sig sharding/sharing scheme is.'

Mehow

So that's the other story is that and that's something that's very esoteric people don't understand. Is that we, we use crypto proofs all the time on, on chains. Like like if you're signing a transaction for Bitcoin, then there isn't like some guy sitting on the Bitcoin miner approving your transaction, right? Or or like having to whip out his share of the key, you know, from a geek's point of view I'm talking about Shamir's Secret Sharing which is generally the architecture we use for multi-party computation schemes where you have like X out of Y people signing a transaction. So but no one has to whip out their share on that crypto miner. It just receives a crypto proof and it's like, 'Oh okay, everything's valid, correct, I'm just going to process the transaction.' So why doesn't custody work that way? Right? Why do you need people running custody? And the answer is not because you have to have them, it's because the thing that's holding your money at Fireblocks or BitGo or any of these things today completely has no idea who you are, what your wallet is. It's like essentially just a giant, you know, custodial wallet. It's like a wallet for the institution, but it has no relationship to your funds. Just like it doesn't know if your withdrawal address is correct, it certainly doesn't know what your like cryptographically what your intention is.

Mehow

So what we did is we made it so that like if you deposit your funds to an exchange, it actually goes to a name first of all. Like say, you know, Brinks is one of our partners, so we're deploying this custody system at Brinks. You deposit to a name, the name has a KYC proof so and all this happens in-wallet, there is no Web3 in this scenario at all because you don't need it anymore. So now that whole layer of like, 'Oh by the way, this is the real website or go here, blah blah,' it's like if you just take away 'go to this website' for, for, for you to do the fintech that you want, then the attackers can't leverage that anymore because it's just not part of the user's mental model. Like the user is just like, 'Well why would I go to a website? I don't do that anymore, right? I just send money to a name and then, and then I interact via this, you know, protocol inside my wallet with what I want to do with that money and everything's an end-to-end crypto proof.' Right? So like in our system what happens is the user, the same set of keys that's used to manage your funds online is used to manage your funds offline. So like you just tap your hardware wallet card, so here's like one of our hardware wallet cards for another customer, you tap this and you can say, 'Alright now I want to say bit-ask or I want to withdraw or I want to transfer to another user instantly off-chain,' and the hardware security module understands that.

Mehow

So the message from you to the thing controlling your funds in custody is just a straight cryptographic message from point A to point B. There, you don't- and when you do that you don't need people to operate that hardware security module at all. Like it can ask people like, 'Hey this transaction's over 10K, needs human review,' that's great, but now that human doesn't need to have the keys to anything. So now your entire security and ops problem just reduced to like you have backup keys and they're in actual deep cold storage. So the, you know, the Korean hackers have to break into your safe somehow or to your HSM somehow. Now note that in no, in none of the Lazarus cases has there been a break into the hardware security module. It's always been exploiting the people with the shares. So essentially, you know, when you do that, you solve that problem. And the other thing is how do you solve like FTX or Mt. Gox or these internal jobs with that? Well, you know, if you have a company and it's custodial and this is the policy that no one's running around with keys, the keys are always in a safe, it's way harder to do an internal job without, you know, anybody knowing what, what happened. Like at FTX it's just like, 'We don't really know who absconded with the money because they had a bunch of yahoos, you know, running around with keys as part of the thing.' So now they get to say that. But in my system they don't get to say that. It's like, you, for it to work you, you don't need a bunch of yahoos running around with keys. It doesn't, the system doesn't require that.

Mehow

So this is, you know, a way to prevent to make essentially insurability of digital assets way higher, it makes it so that internal jobs are way harder, and it makes it so that, you know, outside hacking is well-nigh impossible in custody. So it's kind of like the ultimate, you know, WazirX, Fhemex, Bybit, Lazarus group, you know, Kim Jong Un, rocket man, you know, ballistic missile funding program killer. Awesome. That sounds, that sounds amazing. And, uh, yeah, I'd love to see all of this in action. I know you have like a little demo prepped. I do, so let me just share screen real quick. So and unfortunately today we have an issue with our Ethereum accelerator so I don't see, I can send ETH but I can't see balances. I'm going to show this to you on BCH, it's basically the same thing but like right now if you download the beta wallet you're going to run into that bug. So here we go. Let's do window first. Okay, so I'm sharing this one you see this looks like a regular wallet, right? So I can go in here and generate a receive address. But that's not what we want you to do. What we want you to do is you send-to-name. So here like like I said there's a bug right now where I'm not getting Ethereum transaction history but...

Mehow

If you go into BCH you see it working, right? So like every transaction is to and from a name. So if I want to just, you know, send an asset like, you know, I want to send Rider let's do, you know, one testnet BCH and this is just another, you know, username, of somebody I know. Now all I have to do is just spell that correctly, it's case-insensitive meaning capital R and little R are still the same user, we did that deliberately so you don't have people, you know, essentially trying to steal from each other by exploiting like that, 'Oh you sent to the lower other capitalization therefore, you know, your money's mine, hahaha,' right? But anyway to send the crypto you just hit next, you just type in the name and hit next. That's it. And this works, this is the same name for all chains, right? So if I want to send Ethereum, you know, I already, already sent the crypto, right? So if I want to send Ethereum or any other asset I still just use the same name, right? So that's why I say, you know, it's cross-chain or it's multi-chain. Then when you add like atomic swap DeFi and then you have cross-chain sent-to-name. So that's one of the things that we're also going to be rolling out with clients, right? So all this is white label, so like SwissFortress is a customer of MatterFi. There will be a MatterFi-operated wallet in America though because the political environment has now changed and now it's okay to, you know, release this stuff.

Mehow

So like looking at it on-chain let me just change the share to full screen here. Let me just get rid of us from the background, right? So if now I take like, you know, let's go to as you can see we got this this particular wallet, like I it's one of our big test wallets or my personal test wallet it has hundreds of thou- tens of thou- not ten, thousands of transactions. So like just on this one chain I have 2400 test transactions. So yeah, it works, right? So like if I, you know, hold on let me look at this transaction, yeah to Rider. If I pull up explorer you'll see so how much was that transaction for? It was like for three testnet BCH. So let's see we should see a yeah, so here it is, right? This is the three testnet BCH. And you see this address, so how does my wallet know that this is Rider's address? And normally this address would be in some central like okay, so let's run through the typical scenarios. Is there some central service like Proton's, you know, Bitcoin sent-to-name that stacks a bunch of your addresses and then hands it out to wallets as they request it? The answer is no.

Mehow

The problem with that is obviously whoever controls that, whoever hacks into that now can reveal everybody's balance, but if they control it they can just steal money, right? So you don't want a central database. Is it, you know, a Friend.tech is the same thing so there was that Friend.tech hack a year ago where like all of a sudden, you know, 100,000 people's X IDs were tied to how much money they have, which now makes them, you know, huge targets for hackers because now the hackers have all this metadata they can use to then target this person and, you know, exploit them essentially via again phishing of some sort typically. So that's really bad, you know, Fireblocks Network the biggest complaint Fireblocks Network users have to me anyway is that 'Hey, I can look up everybody else's balance because they have names inside Fireblocks network and now like if you're a custodian you can just see how much the other guy processed today,' which is if you're a trading house not not great obviously, right? If you're ENS or Unstoppable then I can trivially look up your balance. Like in all of these cases essentially, most of them, you can look up somebody's balance if the address is static. If the address is not static there is some centralized thing computing it for you.

Mehow

So like Fluidkey has that issue, right? So what is this? This, you know, this is a stealth address, meaning that it's an address that only the two parties know. Like you can see it on-chain, like you can see it in this block, but no one knows that this is Mehow sending to Rider. And no one can possibly know that mathematically unless they're Mehow or Rider because they need Mehow or Rider's private key to compute this address, to know that this belongs to us. So there is no, there's a central database of it's actually I'll call it not central, it's a both centralized and decentralized database of the names and the metadata that's used to compute these things, but from that database all you get is just a list of the users and their names. But you can't correlate to anything that they're doing, you don't see any, like you don't know if they're using it a lot, using it a little, sending money on which chain, like none of that's possible. Timing attacks are also not possible. Um, so you basically you just don't know, right? At all, right? And this is the only such system in the world and that's why we're, you know, fairly proud of it because despite all this technical complexity to the user it's just, 'Hey I just sent money, you know, to a name.' That's it. So under the hood I have all this crazy tech going. And, you know, this is about to be the metadata the first host is meta is going to be Polygon, the second host is ICP, so we're like onboarding chains and we're getting all the major projects essentially to use this in some form.

Mehow

We're working with MetaMask, we're working with Midnight, Cardano, Hedera, Arbitrum, obviously BCH, some BTC L2s. And but it supports all the L2s plus L1, right? So like inside this wallet within the next six months you can expect to see a lot more chains. Like today we support Dash, eCash, Lite, BCH, BTC, Ethereum, one old customer of ours was Casper, actually one of the very first customers. Used to be a fairly famous project but then they rug pulled all their investors so they're not that famous anymore, but they did invest heavily in us early on and we made a really cool wallet for them. So that's that. And then the other thing I can show you is just so the custody system inside this wallet's not enabled because we're still working on the alpha but I can show you a diagram. Let me just pull up the one of our decks here and I'll show you.

Narb

Sure. And I guess as you're pulling it up, just a quick question from me. So every time if you were to send another test BCH to Rider, would the computed address be the same every time? The one in between?

Mehow

So that's a setting. And what we're going to do in production is just make it the same address. Because there's like in right now in our beta wallet on the Bitcoin-based, the UTXO-based chains, we generate a new address every time because there's no spend penalty to that. But it's not really useful and it creates more compute burden on the clients, right? So because if you're sending a new address every time, say on Ethereum, you're, and you receive, you know, a hundred transactions on Ethereum and once to every you essentially have a hundred accounts even though all that money's coming from the same person. You know, then when you try to spend that money the the fees are higher, right? So it's not really useful. And given that the first address is already super private, like the only way anybody's going to know is if they grab your keys, there is really not a whole lot of point to using a new address every time. Um, so that's something that's getting disabled in production because it just creates extra computational burden. But, you know, here's the Bybit hack breakdown so like I said there is essentially you've got these single shares like each in you haven't you haven't shared yet. Oh sorry, let me hit share screen, share screen, allow, share the screen. Cool. So this is the my Bybit hack breakdown so obviously one of the problems is the random address problem which we already talked about a lot, right? Like you don't know in either in custody or in person-to-person or person-to-robot, AI-to-AI, no one really knows who the address belongs to that they've been given, right? So we solved that problem. So that's like right away half the hacking be gone.

Mehow

The other problem we solve is the, you know, the problem of these humongous thefts, which is that you generally have, you know, people with keys say two out of three, they have key shares and the policy engine may also have some key shares and HSM has some key shares and in when you combine X out of Y you can magically just spend all the money and this happens a lot of times a day because that's how withdrawals get processed, right? So what we do in our system is we get rid of that. Like there there's no people here. And then even in a cold wallet where you may have people because, you know, even when you use our system it's still probably a good idea to have a hot and a cold, the cold wallet uses end-to-end crypto proofs therefore the the, you know, the rocket man hackers can't do the heist that they did. And then the way the custody system works is right here. Um, you see there's no people in this diagram. It's say, you know, three out of five nodes but the nodes are the only thing that have the shares. There's no people with shares except the backup share in case like a server goes completely belly up and you just gotta restore it. So like in our system only times you ever gotta touch the keys as a person is if you're reloading new firmware or the server blows up, which is ideally, you know, these things almost never happen, right? It's very rare, you know, once a quarter, once a month.

Mehow

So when you have the ability for, you know, these things to happen once a quarter, once a month, now like a regulator can be part of your key system. So that's how you prevent an internal job, right? Like it's all of a sudden possible that like you could actually have a third party that is is part of your key ceremony, which radically reduces the risk. And so, you know, and then we use end-to-end crypto proofs at all the steps. So like when you deposit to a name, you get an off-chain crypto proof back to straight to your wallet says, 'Okay, you just deposited, you know, 10 BTC. Now what do you want to do with it?' Maybe in step two you want to, you know, exchange it for Ethereum because say this is an exchange that's using our system, right? Say it's Coinbase or something, right? So, um, now you whip out your hardware card, you tap, and an off-chain crypto proof gets sent to the hardware security module and it's like, 'Oh, this is Mehow, you know, exchanging this for this, so I'm just going to do it. No people required.' And then the third step, I'm going to sign again an off-chain instrument which we obviously just call a withdrawal. That's like literally what it's called in our documentation. And when I do that, the HSM receives the withdrawal and says, 'Oh, this is Mehow doing the withdrawal.' And then all the other servers also receive the same request and they're like, 'Okay, this is Mehow doing the withdrawal.' Therefore, I can sign the the multi-party computation to release these funds back to Mehow. And by the way he's he has Ethereum, so how do I know what address to send? I know his name, so now I can compute his Ethereum address without asking him. So you can see how this is like far more secure, right?

Mehow

So that's the mission of MatterFi. We make software wallets, hardware wallets, AI agents and custody systems that just make fintech, you know, way more secure for people. And it's part of my personal mission to create safety, accessibility, and trust because you can also attach like identity to names, like KYC proofs and whatnot. But now I'm getting like pitching and technical and I really just want you to ask me questions. So but that's the stuff that I was like planning on sharing.

Narb

Wonderful. And yeah, I mean, we've gone over time but that's fine. Um, I guess a couple, couple questions from me is A, how can people get started with SwissFortress? Um, is there a like what's the sign-up process like? Do they have to pay to use it? Yeah, so SwissFortress is, you know, the only thing you have to pay for is the name in production, in beta it's totally free. So like the beta names it's a separate separate setup than the production. So if you go to swissfortress.com, um, you can go to launch.swissfortress.com and like reserve your name for when we're in production. We anticipate being there in like three months roughly. Um, we're basically doing the, like I said, the infrastructure work right now with some of the key providers that have given us grants to basically hold the infra on their on their ecosystem. And there is an L3 token that we have called Fortress Coin, um, but the users don't have to know anything about that. Like it's not like, you know, the traditional DeFi method would be like if I come up with something cool you every time you use it you gotta give me more of buy more of my token, right? And that just makes it super clunky. So we do have that token in the background and it's used to secure the metadata and compensate, you know, the L2s for securing it, yada yada, but the user does not have to know. The user just buys a name. Ultimately the price target for names is 10 bucks a year and for 10 bucks a year you get essentially what is unless you're super high volume, you know, unlimited decentralized sent-to-name like I just described.

Mehow

So, you know, it replaces banking, it replaces payment systems, it replaces, you know, everything. And it's incredibly affordable, right? So that's the business model at SwissFortress. Um, to get in on the beta, you know, we have like a Zealy campaign, we have rewards so you can, you know, earn some token for helping us find bugs, you can download the beta, um, all that's at swissfortress.com. And then, you know, MatterFi, which is the, you know, company that created it, you know, definitely pay attention to the X for the announcements that are coming because they'll be pretty big with some really big partners that, you know, about as big as partners can get on planet earth today.

Mehow

You know, we hope that the adoption, the adoption for us in the last, you know, five, six weeks since ETHDenver, because the project kind of went viral in ETHDenver and then we got some really good partners like DNA Fund, Michael Terpin, Lunar Digital Assets, so they the guys that made Polygon famous, um, did all their marketing, did their, you know, their first launch and everything. So they they wrote the whitepaper. Um, so you know, we have a really good team like promoting the the thing now. So what's happening is that there is a lot of adoption for the tech happening on the back end and, you know, as these things become official and you know we're near in production, you're going to see a lot more news about like, you know, hey you can ideally six months from now like most of the major wallets on earth, you know, can you sent-to-name and then there's also a bunch of other wallets that all use this Fortress Name standard, um, which is what we're calling it, to to send and receive crypto and and run your custody. So that's the answer to how you get involved. Um, and you can find all that on matterfi.com, swissfortress.com or in our X accounts.

Narb

Awesome. And yeah, um, all that is linked in our YouTube description below. And then my final question was around the roadmap for MatterFi but you kind of dropped the hint at some alpha that you got some big partners in the pipeline coming along. Um, so yeah, I mean, the yeah, the roadmap right now is to just get to production. Like we're at a place where the beta's essentially done, um, and now we're like fully decentralizing it because the beta is partially centralized, partially decentralized. Um, now we're just fully decentralizing it so like even if, you know, I have this problem that I had today which is, you know, I can't get balances, um, it shouldn't affect anything. Um, but that doesn't mean like, you know, like if there's an infrastructure problem within Infura or any of these things it doesn't mean you lost your money, it just means that you can't see how much you have like right this particular second. So it you know, so like these are all like we don't for our accelerators for Bitcoin are actually probably the best in the world, but to make that sort of UTXO level of privacy and then redundancy and apply it to an EVM chain is actually a ton more work which I hope to get to, but it's sort of like secondary priority. And what you're seeing with that bug today is essentially exactly that. It's that Ethereum uses Infura whereas Bitcoin uses decentralized accelerators, right? So so um, there is no like, you know, master RPC system that somebody can sit on and like, you know, see what you're doing. Um, so we solved that problem as well. Um, but yeah, the roadmap right now is just get to production with both the custody system and the wallets, and then get as much adoption as possible, um, you know, finish our Series A and then just grow grow grow, and you know, my mission is just get as much adoption for the MatterFi tech as possible for Fortress Names in general. Of course. Obviously.

Narb

Amazing, amazing. And yeah, like you've built a really great product from what you demonstrated and what you spoke about and it does solve a legitimate problem, one of the biggest problems beyond just UX for crypto, keeping people's money safe. And that's what majority of people want. So really looking forward to to seeing the product hit production. And yeah, just want to thank you again Mehow for taking the time to come on the show today. I felt like we could have gone on for another hour or two. Um, so really engaging talk. Awesome. Thanks Narb, great chatting with you and chat soon. Peace, bye.

Narb

Yeah, alright. And for folks who are who have watched us live, um, I'm going to drop a link for you to claim your BitBadges collectible. So if you are into that kind of thing, definitely keep that or check that out. Um, and with that, just want to wish everybody a very happy Friday, happy weekend wherever you may be and we will catch you back here for another great episode of DevNTell next week. Alright y'all, have a good one.

Listen On

Resources & Links

Share This Episode

Share on X

Watch Episodes Live!

Subscribe to our event calendar and never miss a live episode.

View Event Calendar