Peer-to-Peer: An Interview with Yakuhito on the TibetSwap Rescue and Future Plans

Peer-to-Peer is a series of Q&A style interviews with members of the Chia community. This interview is with Yakuhito, creator of the TibetSwap AMM, XCHandles, and warp.green bridge amongst other projects. This is the second XCH.today interview with Yak, the first one was in September 2025.

Editor’s note: Embedded links below were added by XCH.today for context.

In the past, DeFi protocols being immutable and often open-source was considered an advantage. With the recent surge of AI-powered exploits, these characteristics have been proven to be a liability as well. Do you think it’s possible to have a fully secure immutable protocol?

I think being open is still incredibly important for trust. Transparency is one of DeFi’s most important promises. There is nothing suddenly preventing protocols from being fully secure – it’s just that the game has changed. Whereas professionals with extensive security knowledge were mostly the ones to find bugs in the past, now everyone can point an AI model at a codebase, and, if a vulnerability is found, even get a tool created to exploit it. I think blockchain will be one of the few fields to suffer from this “democratization of knowledge,” as on-chain code controls how funds move. Immutable protocols will have to adapt – that is, try to be the first to point models at their own code, and then rescue funds if something is found. It won’t be easy, and it will require even more effort towards security matters.

As to the premise, I think there’s a very narrow gap between open-source and closed-source projects. We’re already seeing models get increasingly good at reverse-engineering binary applications – if there is a bug, I expect it will eventually be found, no matter if the human-readable code is public or not. Keeping the code public will probably just accelerate timelines a little.

You left a note in the now-archived TibetSwap repo noting that the Chialisp code is not safe for mainnet deployment in its current state. If a team wanted to relaunch a fixed version of the protocol, would you recommend it? What other advice would you give them?

My recommendation would be reading both post-mortems and the farewell closely. Even with all the warnings (TibetSwap was the most risk-forward AMM I’m aware of – every time you added liquidity, a big warning was displayed informing you of puzzle risk and impermanent loss), the protocol manages money. As I said above, you’re signing up for a lot of work to minimize puzzle risk.

Another recommendation would be to prepare, as much as possible, for a potential rescue. Even a few minutes can make a difference – as I mentioned in the post-mortem, someone other than me managed to drain a few TibetSwap pairs before I could, so we were a few blocks away from the damage being greater (note: the address did return the funds, but you can’t assume that will always be the case). Prepare a checklist – who should be contacted, what code could be repurposed fast for a rescue, as well as how you’ll communicate with the public.

Apart from that, I think we’ve made big advances in terms of efficiency, and a new AMM could gain from them. So, if the team is open to writing more code as opposed to just fixing the issues described in the now-archived TibetSwap repository, I would recommend they use the same overall design but make use of the action layer and the CAT maker pattern.

Lastly, write the Rue code by hand. AI has indeed made huge improvements, but I don’t think it’s ready to write on-chain code just yet. Designing and building a dApp requires many considerations that might not be apparent at first – each affecting cost (efficiency) and security. This code is the most high-stakes part of your project, and the effort to write it yourself is worth it. 

What’s next for Yak? Does this mean you are taking a break from the Chia ecosystem or will you still be actively supporting your other projects? (XCHandles, warp.green)

First off, I’m committed to fully resolving all incidents. TibetSwap has recently sent back recovered LP funds, marking the end of a successful rescue operation. I also ran a fundraiser to pay a bounty to Aurélien Mora (Eal) for responsibly disclosing the bug. Without that ethical report, we would probably be in a much worse situation right now – I am very glad the community came together and raised more than 600 XCH to reward Eal.

The warp.green bridge will relaunch this month. I am incredibly grateful that we will be able to make all users whole thanks to the support of Chia Network, Inc.

I will also continue actively working on XCHandles, at least for a bit. There are a few more things I want to see through to ensure handles are distributed well, the biggest being on-chain auctions, which Rigidity is diligently working on. I also think wallet support is an essential focus in these early days for the protocol. Resolving handles to addresses will probably be the most important functionality for users in the near term, and I can’t wait to use handles inside Sage, which is the most used wallet in the community from what I’ve seen. Lastly, I’m also working on making sure the on-chain registry continues functioning and being relevant if I and xchandles.com were to disappear.

That’s the true measure of decentralization. Beyond the open-source CLI and drivers (the latter of which can be used by anyone through chia-wallet-sdk), I’m excited to say that MintGarden, SpaceScan, and the XCHPool Blockchain Explorer all run independent resolvers – that is, they decode handle data directly by parsing the blockchain, without relying on any API. It’s really powerful to know that the protocol can run long after I’m gone – and that there’s no way for me to prevent that even if I wanted to (there is no private key to leak!).

I know you have been working on v3 for some time and that led to primitives for dApps like action layer and slots. Do you hope to return to building v3 in the future or do you think the complexity introduces too much surface to secure? (aka What would have to be true for you to consider a v3?)

After my Chia Toronto 2025 presentation, I got into the weeds of v3 (concentrated liquidity, plus a lot of additional logic for a DAO) and realized it would be much more complex than v2. I soon came to the realization that I would not be comfortable launching something so intricate without at least one external paid audit. With the action layer/slots now refined and working well, a v3 is possible, but would likely need a lot of financial resources to roll out securely.

So you think there’s still a lot of value in an external paid audit from a reputable firm beyond what developers and community members with frontier AI models can offer? 

Yes, definitely. A useful model to think about bugs is in terms of filters. The initial one is the design itself – not overcomplicating a dApp, using safe/tested patterns, and so on can minimize the attack surface a lot and prevent most bugs. The problem with these filters is how independent (or correlated) they are with previous ones. For example, even though I review my apps, I’m aware I have certain biases when I review them myself – because I designed them, I keep thinking about why parts were designed the way they were, which leads to me potentially missing some important issues. This is why, since the early days of TibetSwap and up until now, I’ve asked community members for reviews – they are not so biased by the initial design, bringing a fresh perspective. AI tools now make up good filters too – there’s a lot to be said about prompting, using different models, making multiple attempts with the same prompt, and so on, but the main idea is that they’ve become a good pair of (artificial) eyes that can scan your codebase.

This brings us to external auditors. Assuming they’re good, they bring yet another layer of new perspective (an independent filter). They’re not ‘tied’ to one chain, but instead have seen very useful (and recent) bug patterns across many dApps built on many stacks. They also have a security-first mindset and a lot of experience in the field. They’re not infallible, but a very wise investment if the funds are available.

What are your thoughts on Offers and the ability to create efficient and liquid markets through Offer files alone without a stateful protocol? Is the Partial Offers CHIP (finalized in May this year) critical to this?

I think partial offers are the ideal version of offers for CAT/XCH trading – if you’re swapping fungible assets, there’s no reason to not want partial fills. My main concern with them is that they don’t “adapt” to market conditions out of the box like an AMM does – instead, the price is set at creation. This means that you usually need to have a bot online, which requires maintenance, and, more importantly, a strategy. The security of your operation depends on the strategy – if you set a price that’s too low or too high, someone will take advantage of it, and you’ll lose money. So, to rephrase, my concern is that offers (for market-making) extend your security exposure to the off-chain strategy, which is not something that’s easy to get right.

Aside from your own, what upcoming primitives/projects in the Chia ecosystem are you most excited by? What else do you wish to see built in the Chia ecosystem?  

Much like everyone, I am looking forward to Permuto’s AC/DC product being launched. It has high potential to bring a lot of value on-chain, which I expect will lead to the ecosystem blooming.

I was also recently very excited to read about a new Druid Garden full-node implementation. As I said right when I heard it the first time, a new full node is probably the most important thing you can do from a blockchain security/decentralization perspective right now. That’s because the implementations are independent – if one codebase contains a bug, it’s much less likely the other one contains the same mistake. It allows the network to progress, and I’m glad we’re seeing such an initiative sooner rather than later.

After such an eventful and stressful week, what did you do to unwind?

It’s actually been around 4 full weeks – after all the rescues/immediate incident handling, there is a lot still left to do. Post-mortems, negotiations, planning the TibetSwap refund, figuring out fixes, on-chain investigation, etc. are all involved processes that are important to get right. I’ve had very long work days to say the least. The dust has finally started settling, and I am almost back to my normal work schedule.

To answer your initial question, I finally had the time to join a session of Factorio: Space Age last weekend with Jakub (on a world we built with Rigidity) – we’re close to escaping the Solar System, which I knew I wanted to do since the Space Age expansion was launched almost 2 years ago.

Thanks for taking time to answer my questions, and as always thank you for your many important contributions to the Chia community!
Share the alpha
Avatar photo
Slowest Timelord
Articles: 218

Leave a Reply

Your email address will not be published. Required fields are marked *