How BOLTS Technologies Brings Crypto Agility to Blockchain Security
Tech Talks DailyJuly 31, 2026
3664
37:1134.03 MB

How BOLTS Technologies Brings Crypto Agility to Blockchain Security

What happens to digital asset ownership when the cryptography proving that ownership can no longer be trusted?

In this episode of Tech Talks Daily, I speak with Yoon Auh, cofounder of BOLTS Technologies, about quantum computing, blockchain security, and the need for crypto agility. Yoon brings an unusual perspective to the subject. Before moving into applied cryptography, he spent years building and operating high-performance trading systems at firms including Credit Suisse, Goldman Sachs, Geode Capital, and Magnetar Capital.

Yoon explains that blockchain ownership ultimately depends on digital signatures and public keys. Most major blockchain systems use variants of elliptic curve cryptography because it has historically offered speed, compact signatures, and dependable protection. However, sufficiently powerful quantum computers could eventually challenge the mathematics supporting that protection.

The risk does not begin when such a quantum computer arrives. Yoon describes how attackers can collect encrypted traffic today, store it, and attempt to decrypt it later. This creates an immediate concern for governments, financial institutions, and businesses holding information that must remain private for many years.

We also discuss QFlex, the post quantum ready API developed by BOLTS Technologies. The company describes its approach as cryptographic logistics, allowing different cryptographic methods to be selected at the transaction level. Yoon argues that a small payment and a multimillion dollar asset transfer should not automatically receive identical protection, particularly when stronger cryptography may require additional processing, storage, and cost.

Another concern is uncertainty around the available post quantum algorithms. Yoon explains that cryptographic methods can survive years of examination before a weakness is discovered. His argument is that organizations need the ability to change algorithms quickly if one becomes vulnerable, rather than making a permanent choice and hoping it survives every new attack.

The conversation also examines digital asset sovereignty. Who decides how a transaction is protected: the platform, the protocol, or the asset holder? BOLTS Technologies believes that choice should return to the holder, while QFlex aims to provide that control without hard forks, network downtime, or protocol changes. The interview also covers the company's research background and its pilot work with the Canton Foundation.

Yoon closes with a lesson from his trading career. Backup and failover exercises often failed because they were treated as occasional events. His advice is to make exceptional processes routine, ensuring that the organization has already practiced changing systems before the moment arrives when it has no other option.

Should digital asset holders control the cryptography protecting every transaction, or should platforms continue making that decision for them? Listen to the episode and share your thoughts with me.

Useful Links

[00:00:00] It's not your fault that your agentic AI systems are acting outside of compliance. There are just too many data sets to guardrail them all. But with Denodo, you can now organize your hundreds of data sources into one layer and govern your agents with a single approach. Try it now with Denodo by visiting denodo.com to learn more.

[00:00:25] What happens when the cryptography protecting trillions of dollars in digital assets is no longer secure? Well, my guest today believes the answer isn't just choosing one lock. It's about building systems that can change the locks whenever needed. And my guest is the founder of BOLTS Technologies.

[00:00:52] And today we'll discuss quantum threats, digital asset sovereignty, crypto agility, and why preparing for failure should become part of everyday operations. And if you find that space intimidating, don't. Because we're going to talk about it today in a language that everyone can understand.

[00:01:11] So buckle up because it's time to beam your ears all the way to Chicago and learn more about the way the future of security could depend on our ability to change the locks. You're going to like this one. But let me introduce you to him now. So thank you for joining me on the podcast today. Can you tell everyone listening a little about who you are and what you do?

[00:01:36] My name is Yoon Ao and I'm the founder of BOLTS Technologies. And we founded it last year to bring crypto agility to the blockchain world. And right now there's a massive problem with most blockchains of any worth.

[00:01:58] And that they've been locked into a very, very peculiar type of cryptography for their transaction authentication. And they need to move quickly. But due to architectural constraints, many of them are finding it to be a multi-year process. So where we come into play is we develop technologies that allow you to very quickly change cryptography.

[00:02:26] And in this case for blockchains, we call it digital signatures on a per transaction basis. And so that is a relatively new technology. And we've been doing this for now about 10 years. And so we know how this works, why it works. And, you know, many in the business are just learning about it. And we want to bring it out to many of the blockchains out there. And so that's our mission.

[00:02:56] My background is I started in financial programming where, you know, I used to code systems for trading baskets of stocks on Wall Street. I did that for about 10 years and then got a chance to trade for a living initially at Credit Suisse. And then eventually I became head trader of the domestic portfolio trading desk, went to work for subdivision of Fidelity, set up their index advisory, you know, business.

[00:03:26] And now that's called Geo Capital. And they manage all the Fidelity Spartan funds or the index-based funds. I think that's the only business that Geo Capital is doing now, about probably over a trillion dollars assets under management. And then my last gig as a trader was at Magnetar Capital that brought me to Illinois in Evanston, Illinois. And I was their global head trader for about five years.

[00:03:55] And then I started embarking on this data privacy and data management, you know, tech route. And it caught my curiosity because I realized that there's so many things in our daily lives with computerized devices

[00:04:16] that makes it incredibly hard to keep your stuff very private and very portable under your control without having to give away all your information. And that's what started as a, we called it Nuts Technologies at the time. And then last year we were able to take one of the technologies we call Structured Data Folding with Transmutations or SDFT.

[00:04:43] We rebranded that to be called QFlex. And then we spun off Bolts Technologies to address the problem of blockchain cryptographic transitions. That's facing them because of the advances in quantum computing. So hopefully that's my background. Perfect. And a question I've got to ask before we get into the nitty-gritty here is for people listening and hearing about you guys

[00:05:12] for the first time on what we're talking about. Can you just tell us a little about why the existing approaches to protecting digital assets just aren't enough anymore? Because I think that sets the scene up perfectly. Well, so we've enjoyed this incredible lull in cybersecurity and cryptography in that we've been enjoying this two main sets of cryptography called RSA and elliptic curve cryptography or ECC.

[00:05:42] And they've been around now for several decades, 30, 40 years. And they've been very stable, very tested by everybody, by adversaries and friendlies. And they've stood the test of time. Now, back in the late 90s, it was theorized that if a quantum computer of sufficient strength existed, at the time they didn't have anything,

[00:06:12] a gentleman by the name of Peter Shore, he devised an algorithm based upon how a theoretical quantum computer would operate. And he created an algorithm that's right now, it's called Shor's algorithm that can break RSA cryptography and ECC cryptography. And so that was done in like the like probably like 1996 or 1997.

[00:06:39] And then in a little more than 15 years later, you're starting to hear like, you know, advances in quantum computing. So they've been able to prove that the elementary functions of a quantum computer can be made physically. And now, you know, like 30 years later, they're trying to scale this thing so that, you know, it can become a very, very powerful government got wise to it.

[00:07:09] And now we have the acceleration of governments trying to mandate that we have to move to cryptography other than RSA and elliptic curve. And they are called post-quantum cryptography. It's quantum resilient cryptography. And they've been, you know, canvassing and devising these, you know, post-quantum cryptography is shorthanded as PQC.

[00:07:36] These PQC algos for better part of a decade. And back in 2024, the National Institutes of Standards and Technology in the U.S. came up with the first three PQC standards for cryptography. And then just maybe a couple of weeks ago, you know, our president signed two executive orders.

[00:08:03] One, committing to generating the best quantum computers in America and putting funds towards it. And then the second one, second executive order was to accelerate our timeline for PQC adoption within the federal government. And as you know, even though the executive order is for the federal government, for the intelligence agencies and the military,

[00:08:30] anything that the federal government does will trickle down into all regulatory agencies and then eventually into any of the commercial industries, because so much business is being done by the defense industrial base that interfaces with the federal government. That if the federal government changes their goals, that entire defense industrial base is forced to adapt.

[00:08:57] And then anybody that they do business with will eventually adopt the methodologies as well. So that is the kind of the shorthand version of like what is going on with quantum computing and why it's so important that we have to address this change of, you could call it changing of the locks.

[00:09:20] You know, so if you imagine if everybody's houses, all the doors were, you know, one type of lock and we got very comfortable with it because nobody could really pick it. But all of a sudden somebody came up with a lock pick that works and we see it coming. And now we've got to change all the locks to something that is, you know, no longer applicable.

[00:09:44] I love that. Such a great analogy about changing the locks, because we will have many business leaders listening that still see quantum computing as almost a distant problem. Of course, you and I know very differently there. So, again, just to drill down on why what we're talking about here is so important. What can you maybe expand on other risks that already exist for financial institutions, blockchain networks and digital asset holders that could be listening and and why they should be preparing now?

[00:10:12] They should be preparing now because there is an attack called hold now, decrypt later. And what that means is that, you know, relatively speaking, maybe prior to about a year ago, this drives and memory was incredibly cheap. Right. Not anymore, but it's still relatively cheap for how much data that you could save.

[00:10:38] Right. I mean, you know, if this drives went up and cost like two or three times, it's still pretty cheap to be able to save, you know, 14 terabytes of data on a three and a half inch drive. Right. So the fear there is that anybody who's committed and determined like nation states can easily listen in on the open Internet.

[00:11:03] The Internet is free to listen to and you could actually record the traffic. Right. So I don't know if you've ever spoken to a network analyst analyst, but they have these things called network sniffers. Right. And you could literally put network sniffers on any of the major country routers and suck in all the data.

[00:11:27] And then you could reorganize it and you could take all the encrypted traffic and store that. And eventually, if you believe that there will be a powerful enough quantum computer, you could crack those encryptions. And harvest secrets. And so this is backwards looking.

[00:11:49] But if if a organization, whether they're government, military or commercial, if you have long live secrets, that that's going to be very, very dicey. Because if you ever transferred it to the cloud or you transferred it to via email or any any other form of communication and somebody took a copy of it by listening in on the public Internet,

[00:12:18] it is probably going to be exposed at some point in the future when we have the technologies available. And when I was researching you guys, I was also reading you said that sovereignty shouldn't be a property of the system rather than a promise made by a platform. And I love that line. So what does genuine digital asset sovereignty mean in practice? And why should businesses and asset holders care about the distinction here? Because it is an important distinction, right?

[00:12:46] So I think when you look at cryptocurrencies and digital assets and tokenization, you know, that that includes NFTs and any other any other thing that they want to tokenize. If you look at, you know, there's there's a whole bunch of different business models and different gimmicks of governance, you know, reward systems,

[00:13:12] who can participate, whether it's a closed or open system, you know, what currencies that they're going to natively mine and mint. So, you know, there's all of these different factors that describe different crypto or tokenized ecosystems. And, you know, them all, you know, it's like the Ethereum, Bitcoin, Canton, you know, JP Morgan's, Connexus.

[00:13:40] You just name it. There's a ton of these guys. But almost all of them have one thing in common. And that is somewhere along the line when the original Bitcoin stack, the tech stack was developed. If you look at the Bitcoin paper, the original paper, you know, that started the whole thing, there is no mention of what type of cryptography.

[00:14:08] It's just some sort of digital signature and authentication method. And at the time that that was written, RSA and ECC, there were no questions that that was the reigning methods of doing it. And somehow when they developed this tech stack, they decided that ECC, elliptic curve cryptography, was going to be the digital signature of choice, mainly because it's the smallest in size to save in a memory.

[00:14:36] And then also it's the fastest. And so they were like, you know, we're going to use ECC. It was by default. And every major tokenized ecosystem that came out, Ethereum included, Cardano, Midnight, you know, you look at all of these things,

[00:14:56] including Canton and the DTCC blockchain, they're all using variants of elliptic curve cryptography digital signatures to protect the transaction. So a typical blockchain transaction, what it what it includes is, you know, it'll say something like,

[00:15:19] youn is identified by this number, I'm going to give Neil, you know, half of whatever coin it is. And here it is. And here's the proof that this was you. And then I put in something called the public key, and the digital signature that I generated for this transaction that says that if you use elliptic curve validation methods, using the public key, the digital signature that's in the transaction,

[00:15:48] and the transaction data, the, you know, the, the nodes that are that are part of this network can say, oh, youn's key did validate that he is giving Neil half of whatever. And, and then they'll say, okay, you know, that sounds good. And if enough nodes agree, then there we built the consensus. And that goes into the into the blockchain as being a done deal.

[00:16:18] So that is how the value and ownership of an asset is expressed. And literally every blockchain is purely by this thing called the digital signature, and something called a public key. So the strength and security of the digital signature is tantamount to your digital asset ownership.

[00:16:46] And that's where, you know, if you're looking for that one little narrow pass that can jam everything up, this is it, right? It's the digital signature and the strength of the digital signature and the methodology that you're using. And right now, 99.9% of the world's digital assets are being protected by one type of cryptography. It's called elliptic curve cryptography.

[00:17:15] On the other side, you got quantum computers that are advancing in sophistication almost every, every month. And, and when they get powerful enough, the first type of cryptography that they're going to be able to break, and which is known to be the easiest type for quantum computers is going to be elliptic curve cryptography.

[00:17:40] So how's that for whether you're going to be able to, you know, so if, if, if your net worth is tied to digital assets, and it's all protected by one type of algorithm, which is called elliptic curve, what happens when elliptic curve no longer is secure? What are you going to do? That's the main problem.

[00:18:04] And that feels like a perfect moment to introduce Bolt's quantum resilient software product called QFlex, which introduced what you call cryptographic logistics. So can you tell me more about that concept in simple terms and how it changes who controls the security of a digital asset? Right. So there is something that most cryptographers will not tell you in the very first sentence after meeting you.

[00:18:32] What they won't tell you right away, but they'll admit to it is that none of this stuff is provably secure. So cryptography is kind of a, is a hodgepodge of mathematics and also computer programming. And it's kind of melded together. And it's a very complex thing to even prove that something is going to be secure.

[00:18:57] But, you know, in the history of modern cryptography, there's always only been one algorithm that's ever been mathematically proven to be secure. And that is called the one time pad. Now, the one time pad is so, you know, it has, it has so many constraints and so much limitations that is virtually unusable for modern Internet commerce.

[00:19:24] And you'll see some versions of it in the movies. Right. You'll see it when they, when they have to launch, you know, nuclear codes or whatever nuclear missiles, they'll, they'll rip out some cards and they'll break it open. And they'll read, read some codes to each other. Right. That is a example of a variant of a one time pad. A very limited use, but very secure and proven to be secure. RSA, ECC.

[00:19:55] These are our stalwart, you know, dependable cryptography for the last few decades. And every version of post quantum cryptography that's been proposed or standardized. None of those have formal proofs of security. So, in other words, they're all best guesses.

[00:20:16] Now, luckily, RSA and ECC stood the test of time for several decades, but no longer because quantum computing is coming around and it says that it could break it. Now we come up with new algorithms called PQC aldos to replace these two. But there's no road wear for any of them. And there's no proof. So, if you look at the number of post quantum cryptography.

[00:20:45] So, quantum resilient cryptography that is coming out of our, the National Institute of Standards and Technology. It's unbelievable. They have three standards. It comes in 18 variants. Right. And they're proposing another six variants. Plus, they're continuing to look for new algos.

[00:21:05] And within five years, we may be staring at over 30, 40 variants from the United States NIST agency alone. That's a lot to choose from when you only had like, you know, two and then they had like three key sizes each. So, it's like, you know, you had like half a dozen variants of RSA and ECC to choose from.

[00:21:30] Now you're going to have, you're going to be awash in a sea of PQC algo variants. And how do you choose which is what? When you know the underlying foundation is that none of this stuff is provably secure. So, our proposition with cryptographic logistics is that the answer is not to just pick one and say that that is the best in your view.

[00:21:58] If you don't have a proof, then it doesn't matter. Right. Now, if we did have a proof, I guarantee you we wouldn't have these many variants. Right. That doesn't that that makes sense. So, so we say that unless somebody has a proof, what you need to do is to be able to change on the fly.

[00:22:23] If if something is shown to be vulnerable and during the eight years that the NIST ran the post chronic cryptography selection program for the first three standards, they had two major algorithms contenders that failed overnight, very, very late stages of the selection process.

[00:22:46] So they survived many, many years of scrutiny by the world's leading cryptologists. So so these things do happen. The uncertainty is there. And there's many, many failure points for any of these, you know, quantum resistant cryptographic algos.

[00:23:07] And that is why we believe our approach is that don't be fixated, be flexible and be able to change on a dime and just switch it, switch it around. And when it comes to blockchains, you have to start wondering, like, like when we go back to the analogy of the the locks on our houses, on our doors.

[00:23:36] You know, do you protect? Think about when you're protecting something of value. Do you protect a, you know, a $20 bill the same way you protect a pound of gold? Right. I think I think the logic is very, you know, it's very common sense that no, a $20 bill, you may just stick it into your wallet. A pound of gold, you're not going to carry that around. Right.

[00:24:04] And so I think you have to look at blockchain the same way in that when you're doing, you know, a Bitcoin transaction to buy a cup of coffee, you shouldn't protect that the same way that you you protect a purchase of a car. And so you should be able to choose different types of cryptography, depending upon the transaction value.

[00:24:32] And because ultimately, every blockchain charges you for everything. There is no free ride in the blockchain world. The the ultimate payer of blockchain mechanisms is the digital asset owner. They're going to be charged something every step of the way. There is no free free ride in blockchain.

[00:24:57] And they're going to start charging you explicitly for the cryptography and the type that you use based upon the size of the keys, the size of the signature, how long it takes to process it and how much storage that they're going to have to accommodate before. And it's going to get very expensive and people are going to be shot by it. And I think you need this flexibility that not everybody on Bitcoin is a million dollar holder. Right.

[00:25:26] And if you hold a few thousand, you shouldn't be forced to use very expensive cryptography that are used by, you know, multimillionaires doing very, very high value transactions. So that that is that is kind of the basis for crypto logistics is be able to change things on the fly, be flexible.

[00:25:48] And when I was doing a little research on you, I was also reading how your technology has been tested through work involving NIST, the U.S. Air Force and the U.S. Navy, and is being piloted with the Canton Foundation. So incredible here. But I've got to ask, what did those high stakes environments, what do they teach you about building security technology that that must work against very real adversaries rather than simply what look good on paper?

[00:26:16] Because I've seen that in a lot of other solutions. But tell me more about that. Well, you know, it's like any anything that people do is a new thing is usually not something that is like a genius thing. It's more a fresh insight. Right. Because the way we train people is by accepting and doing things in a customary way.

[00:26:46] And you kind of train people that way within entire industries. And that's been the same for applied cryptography as well. And so when I developed this stuff earlier on, it was with a very, very fresh, fresh eye. I mean, I am not a cryptographer. I've taught myself how to do applied cryptography.

[00:27:08] And, you know, in terms of computer science, if you want to learn about computer science, you know, it's the easiest thing to go and find out how to do because everything is available on the Internet. But what I did notice is that I'm not going to turn myself into an overnight cryptographer. That's a very, very niche, very specialized field.

[00:27:33] But what I do know is the principles of how these things work and the interfaces that must be presented for them to be applied to actual data and to actual systems. And I found that there is a lack of there. There's too much assumption going on that certain methods are always going to be secure.

[00:27:55] And I started questioning that and design systems that did not rely on those assumptions. And that's what happened was when we went to the at the time was called the DOD and put in for grants and show them that this is actually possible. They wanted to see it. And then one of these grants that came out was from the NIST and the NIST.

[00:28:22] We had no idea at the time that they were so exclusive in giving out these what's called a CIBIR phase ones, which is small business innovation research grants. And apparently they only hand out like 10 or 12 of these a year across all of their science fields. So NIST doesn't just do cryptography. They do material science, measurement science, chemical science. They do all the things that require standards for a nation.

[00:28:51] And to be selected for one of these apparently is a very big thing. And we were told by that by a former Air Force colonel. And and, you know, when we met with our project overseers, they were the actual cryptographers on the committee to select post quantum cryptography standards. And we asked them, like, why did you pick our project?

[00:29:20] Right. Because we're we're kind of like we don't come from, you know, the big company called RSA or any of the big cybersecurity companies or we weren't former NSA people or, you know, military cryptography.

[00:29:35] And they said that they wanted to see our our crypto agility technology because they didn't think that that level of crypto agility was actually possible and they wanted to see it. And so we showed it to them in six months.

[00:29:55] They gave us that grant and we we embedded all the standard and candidate post quantum cryptographic algos on the board that we could find. And we we did it across like four different library implementations. And we showed it to them that every message we could change it on the fly without any problems. And they were very happy with it.

[00:30:18] And in fact, at the end of the project, it was one of the overseers who mentioned to us, we should look into helping blockchains because blockchains actually have this particular problem. And that fits our technology at the time called SDFT. But we rebranded as QFlex because you guys might be able to help them out because they need this type of solution.

[00:30:44] And that's how in 2025, we decided we went back to our investors and nuts and told them, hey, you know, we did this project. This is their recommendation that we should look into blockchain. And that's how we formed Bolts. And with a little bit of help from our investors.

[00:31:02] And on a personal level, looking at your origin story there, you've spent what part of your career in high performance trading environments, everywhere from Goldman Sachs to Credit Suisse before moving into applied cryptography. How was those experiences shaped the way you think about ownership, insider threats and protecting digital assets? Any lessons that financial institutions could apply today to?

[00:31:28] Because it feels like you must have learned and seen so much throughout your career. Well, I mean, the way I think about it is that, you know, you can teach old dog new tricks, right? And, you know, I think it's always a mistake to trust systems implicitly.

[00:31:52] You have to come up with a method that works for you and that is always conservative. And, you know, that's what I learned over the years is that if you rely on systems to be there for you and you haven't tested it, then it's a major problem.

[00:32:13] So one of the things that I found in large companies, you know, when I work for Magnetar, Geode or Credit Suisse and Goldman is that every year you have like an exercise, right? And they call it off-site emergency, you know, failover. So you take part of your desk and you tell them to go to New Jersey, right? And sit in this like, you know, giant data center.

[00:32:41] And, you know, we're going to switch over in the middle of they pretend that, you know, the New York office is down. And, you know, and this happened a lot after 9-11, right? And so what you learn from these exercises, most of the time they fail, right? The switchover is never perfect. There's missing data. It takes half a day to get anything up and running again.

[00:33:09] And then you start asking like, okay, you know, what's going on with this? What's going on is that we're not like the lions in the plains of Africa, okay? We're not like, we don't, we can't, our systems are like people. We can't just sit around for 20 hours after a meal and then up and run 45 miles an hour to catch the next meal. We can't do that. We need to exercise.

[00:33:38] We need to train our bodies and our minds to do something in a repetitive way. And that is the same thing with computer systems. If they are not designed to repeatedly do things, but only occasionally, most of the time, that one occasion where you needed to work, it will fail.

[00:34:01] So that is what I learned over the years is that if you don't design systems to make that exceptional process unexceptional and routine, that exceptional process will ultimately probably not work when you most need it.

[00:34:22] And so that's how we designed all our systems for bolts and nuts is that we make the exceptional process normal. And we flip the script on it so that when you need it, it's always been working, right? And so it's a different way of thinking, but it does make sense, I hope, right? Yeah. And I think that is a powerful moment to end on today.

[00:34:51] But for anybody listening that wants to learn anything more about Bolt Technologies, your flexible cryptography, how it's helping not just protect systems today, but also preparing them for some of those quantum threats tomorrow that we've been talking about today. And not only that, keep up to speed with announcements throughout the year, et cetera. Where would you like me to point everyone? It's www.boltstechnologies.xyz.

[00:35:19] They could find out about our blockchain solutions for crypto logistics. And then if they want data privacy solutions, they could take a look at nutstechnologies.com and find out more about our solution space there. Awesome.

[00:35:37] Well, for anyone listening that wants to learn more about securing blockchain and digital assets against some of the emerging threats, including quantum computing and everything we talked about today, I'd urge them to check you out. I'll include links in the show notes, so please check that out and feedback. But more than anything, just a big thank you to yourself for sitting down with me today and talking about all this in a language everyone can understand. Really appreciate your time today. It's been a pleasure, Neil.

[00:36:04] Very nice talking to you and, you know, it's a great way to wake up. I think Yoon left us with a session that goes far beyond blockchain and quantum computing. Ultimately, if an emergency process is rarely tested, there's a good chance it will fail you when you need it the most. And whether that be changing cryptography on the fly or preparing digital assets for quantum threats,

[00:36:29] this conversation today I think was a reminder that resilience comes from making exceptional processes routine. So, are businesses preparing for the threats already heading their way? Or still trusting systems that have never truly been tested? Lovely to hear your thoughts. TechTalksNetwork.com. Drop by, let me know. Other than that, we'll have another topic tomorrow morning and I'll meet you here. Same time, same place, inside your podcast feed.

[00:36:59] Speak with you then. Bye for now. Bye for now. Bye. Bye.