The Station70 Podcast is live. 🎙️
Real conversations with founders on building in Web3 and AI. Episode 1 features @dschwed, COO at SVRN, with his take on crypto security and institutional infrastructure.
Now on Spotify & YouTube.
https://t.co/CJLZxGldZG
https://t.co/85MffypWfF
@dan__rosenthal Good list.
You are missing a critical component though. How do you track the sensitive data passing through all these?
We had the same issue at @station_70 so we built https://t.co/U55lYtdHpW
Do you know what actually happens when you hit "Connect" on a Claude integration?
I looked into it.
Here's what most people don't realize: When you connect an app to Claude — Slack, Google Drive, GitHub, whatever — you're not just granting access.
You're handing credentials to a system that has no native concept of "need to know."
In 2025 alone, 28.6 million secrets were leaked from config files and environment variables.
That number went up 34% year over year. And that was before most companies started rolling out AI agents at scale.
The way most of these integrations work today:
• Your API keys and tokens get stored in a config file
• The AI agent reads them at runtime
• The agent holds them in memory while it works
• There's no scoping. No time limits. No revocation.
Here's the part that should make any CTO uncomfortable:
Prompt injection, where malicious content tricks an agent into doing something unintended, isn't just a jailbreaking trick anymore. In agentic systems, it's a credential exfiltration mechanism.
The agent doesn't know it's happening. No alert fires. The credentials leave through approved channels.
As long as an AI agent can see your credentials, it can lose them.
Companies aren't banning AI because they're paranoid.
They're banning it because nobody's solved the credential question yet.
I went to São Paulo for @Fireblocks IGNITE thinking I'd have to explain why infrastructure matters.
I didn't have to explain it once.
Brazil's crypto regulators aren't asking surface questions.
They're asking about zero-knowledge architecture, functional redundancy, BCR compliance.
They've drawn a hard line between crypto companies and on-chain businesses, and they're examining the layer underneath.
Firms I sat down with weren't starting from scratch. They already knew @Station_70. They already understood zero-knowledge backups. The conversations skipped the education phase entirely and went straight to evaluation.
That caught me off guard. In most markets, the first meeting is "here's what disaster recovery means for key custody." In São Paulo, the first meeting was "here's our timeline."
Huge thanks to Jorge Borges, @mikeshaulov, and @thoughtsofsteve at Fireblocks for putting together an event that brought the right people into the room.
And to Nickole Dysk for being an amazing host and filling @rangoldi's shoes.
The other thing that needs updating: the stablecoin narrative in Brazil. Pix is everywhere.
100% domestic card penetration.
Street vendors, hole-in-the-wall restaurants, cabs.
Crypto for everyday payments is not the opportunity here.
Cross-border settlements and international B2B flows are.
Local rails are solved. The use case that remains is strictly cross-jurisdictional.
One expensive personal lesson: check your visa 30 days out. Not 7.
A day that will live in Miami 🌴 traffic infamy.
Friday March 27th, 2026 🗓️
4:00 pm - @Ultra Music Festival Begins 🎛️
5:00 pm - @MiamiOpen 🎾 Men's Singles Semifinals, Doubles Semifinals
5:30 pm - Trump 🇺🇸 speaks at @FaenaMiami Forum in Miami Beach
7:10 pm - @Marlins home opener ⚾️
8:00 pm - Mana @manaoficial 🇲🇽 concert at @KaseyaCenter (literally down the street from Ultra)
Advice?
Get a scooter 🛴