YouTube transcripts

From Accountant in India to Crypto Millionaire in 18 Months (Zero Technical Background): video thumbnail

From Accountant in India to Crypto Millionaire in 18 Months (Zero Technical Background) transcript

Immunefi · @immunefi

Published June 18, 202627:335.4K views

Watch this video on YouTube

Transcript analysisComputed from the caption text

Words

4,442

Runtime

27:33

Speaking pace

161wpm

Reading time

19min

161 words per minute, between the 160 25th percentile and the 181 median of 349 measured videos. That distribution comes from the 349-video hook study.

Opening (first 30 seconds)

Hey everybody, welcome back to the Immunify show. Today we have a very exciting participant. We have Vivek, one of the latest Immunify millionaires, and we're going to learn about his journey, about his process, and how he's got to where he is, inclusive of everything from how he handles AI to how he handles the hunting up and down, and what's his view on the overall future. So, thank you so much for joining us. Vivek, why don't we start

81 words, the words spoken in the first 30 seconds at 161 words per minute.

Sentence shape

MeasureThis transcript
Sentences371
Average words per sentence12.0
Longest sentence63 words
Questions asked66
Sentences containing a number24

Most used terms

  • security22
  • ai21
  • uh17
  • mhm16
  • vivek16
  • bug15
  • bounties13
  • immunify13
  • white13
  • hunting12
  • lot12
  • people11

Filler phrases

100 in total: like 41 · you know 25 · uh 17 · kind of 6 · right? 6 · I mean 2 · basically 2 · actually 1.

A literal whole-word count of the same phrase list the Prepublish browser extension uses, so a phrase inside another word is not counted and a phrase used in its ordinary sense still is. It is a count and not a judgement.

What this transcript is

Every word below is the caption track YouTube publishes for this video, pulled from the video itself and reproduced unchanged. It is not Prepublish's writing, not a summary, and not a re-transcription: it is the video's own published captions. English captions, generated automatically by YouTube, in the video’s original language. Source: the video on YouTube. A channel that would rather this page did not exist can ask for its removal through the contact page, and it is removed.

Transcript

Hey everybody, welcome back to the Immunify show. Today we have a very exciting participant. We have Vivek, one of the latest Immunify millionaires, and we're going to learn about his journey, about his process, and how he's got to where he is, inclusive of everything from how he handles AI to how he handles the hunting up and down, and what's his view on the overall future. So, thank you so much for joining us. Vivek, why don't we start from the beginning, since for a lot of people they're not going to be familiar with your work, even though you've done really exciting stuff.

Who is Vivek? Tell us about who you are and where you come from. >> Hi Mitchell. I am Vivek. So, I am a chartered accountant. Before I coming into security, I had a CA firm for around 8 months. And a friend came to me for filing his taxes in in 2020 at the peak of the lockdown. He was trading in cryptocurrencies. And there was a bull market, so I got interested in it. And as my portfolio grew, I became worried about the security hearing about all the hacks.

So, I also started diving into security in June 2024. Actually, today is the second anniversary of my joining security space. Uh for a year I didn't get any results, and since which I was doing public contest, and since switching to bounties, I have been a consistent performer. >> I see. So, that's interesting for two reasons. Number one is you got worried about hacks and security, and so your conclusion was I should become a hacker.

Right? >> No, I said become a defender. >> Well, white hat hackers are defenders. You could be both. You know, the white hats are also hackers. They just use them for good. So, it's a funny way to look at it. And then the the the second part of this question is unlike most people, you kind of break the stereotype. You did audit competitions, but then you found more success, more luck doing bug bounties than you do with audit competitions.

Is that right? >> Yes. >> I see. I see. I would love to understand a little bit more about that. That is like a really common misconception that the security researchers who focus on audit competitions feel. Like they feel like bug bounties are super hard mode, that they're nightmare mode. Okay? And that they it's just not realistic unless you're the best of the best of the best. And then other people prove every day otherwise, but they don't understand how to make this jump.

So, you know, how would you define or how would you consider the differences between these two approaches? And why is it that you're finding more success and more luck with bug bounties than you find with audit competitions? >> So, yes, bug bounties are difficult, but like they are not difficult in the technical sense. They are difficult from a psychological point of view. Like in audit contest, you have a fixed payout.

The payout is not fixed, but it is certain that you will get a payout. In bug bounties, there is no certainty about that. And when you receive a payout, there is a big payout. So, there is a lot of variance in this. That's third only difference, I would say. >> I see. So, you think it's not technical. It's not a matter of technical skill at all. It's a matter of do you have the grit? Do you have the psychological ability?

Do you have the will to survive the risk? Right? And the the challenge of bug bounties. Is that correct? >> Yes. So, I switched to bounties in uh Oc- uh September 2025. So, basically Alex uh from Recon did an experiment. He was running a white hat mastermind. And there were 10 of us around in the mastermind. He asked all of us what we were working on. So, this was a period when there was a There were a lot of contests, and nearly half of us were working on the one contest with the lowest scope and the lowest payout. >> Mhm. >> So, he explained that uh we always want certainty.

We want fast results, and that's when I switched to bounties. >> I see. What was your conclusion? What was the key insight? So, yes, you guys were chasing certainty and fast results, but then why did you switch? >> So, So, I realized that I was also always working on the easiest target, which will pay the payout the fastest. So, I was also avoiding this uncertainty. I don't think that bug bounties are difficult in the technical sense, but they are uh they take a heavy toll on your psyche. >> I see.

I tell you when you realize that you're like, "I can take it. I'm an accountant. I did debits and credits. I'm ready for heavy tolls on my psyche. Okay, I know how to deal with heavy tolls on my psyche. I can handle this." Is that right? >> Yes. >> [laughter] >> Just a little accounting joke for the people who >> So, at the time I was just saying that bug bounties bug bounty hunters are paid handsomely for dealing with uncertainty. >> Mhm.

I guess your economics and your finance background made a big difference here because it allowed you to think more clearly than the more traditional technical people would. They didn't understand that they're discounting the value of their work by chasing certainty so much. >> Yes. >> Interesting. And just uh to give it an in a context, you know, Vivek here is the latest Immunify bug bounty millionaire. So, he has done an incredible job over this time that he's he's been engaged with us.

I mean, really congratulations on that. Uh how does it feel? Tell us what it's like. You're You're You're in the promised land. We want to understand what your glory is like. >> It feels great. Now, the uncertainty of bug bounties doesn't have a impact so much. Like, we can relax and do our work. >> Mhm. So, do you think with the relaxing of that uncertainty, that is that going to enhance your hunting or is that going to diminish it?

How do you think about it? >> It has already enhanced my hunting. So, earlier I wasn't getting consistent results. I was always under pressure to perform. Now, I can be relaxed. Even if I don't have a payout or any results for a month or 3 months, I can be relaxed. >> Sure. Sure. That's really interesting. And And maybe that explains why we have this kind of power law effect in bug bounties, where there's like the the guys who earn the most, they earn a lot more than most people.

And part of it is just because they have the the stability and the the comfortability with uncertainty and the outcome independence to just hunt and hunt and hunt and tolerate the the dry spells and continue onwards. I would love to hear how you think about that and how you think of managing the volatility and the ups and downs and the kind of roller coaster experience of the bug bounty hunting process. >> Uh since October, I haven't had a dry spell, but before that, whenever I had a dry spell, I used to listen to listen to podcasts of white hats like lonely sloth, white hat mage.

So, even if they even even they have dry spells, then who am I? >> Well, it's funny that we're here talking about it now, Vivek, because now people are going to listen to your own podcast when they [laughter] have a dry spell, and they're going to want to know how you felt about it. >> [laughter] >> That's really cool. You should be very proud. You should be very proud of that. I I want to understand a little bit about, you know, you know, what's changed for you.

So, now that you've crossed that divide and become, you know, a a kind of millionaire bug bounty hunter, how has that changed how you think about your work? And how has that changed how you hunt it? And is there any Is there any shifts in that psychological game? Because remember all of our colleagues who are listening now who want to who want to jump uh to that scene and get to that level, you know, if you can explain to them what to do, maybe they can take that step with even before having made that that big uh step forward. >> So, in terms of inputs, there is no difference.

Earlier also, I used to work the same way I am working now. But, I was always in a hurry earlier. Now, I'm more relaxed. That's the only difference. >> I see. And do you think that makes a difference in the hunting process? >> Yes, it definitely makes a big difference. Like earlier, you will go through a line of code and not go deep into it, then you will miss obvious bugs. >> I see. So, counterintuitively, being able to relax and commit to what's right in front of you and go slowly and go deep into the code itself is giving you an advantage in finding more vulnerabilities and improving your skills.

Is that right? >> Yes. >> Hmm. An interesting lesson for our peers to hear. Don't be in a rush, you guys. There's lots to do. Going back, you know, to to the question of process, I would love to understand a little bit more about your process. Like in terms of getting into the head state, you mentioned that it's the bigger psychological game than technical. What type of mindset do you adopt and what kind of mental principles are you using to guide your research or how you're thinking about the hunting process? >> So, basically, nowadays, I use AI for everything, like for hunting.

So, uh I give the AI the target and during the when the AI is hunting, during that same time, I am taking a high-level understanding of the protocol. And once AI comes with issues, I am validating the issues and submitting it. >> I see. I see. And like what How does that relationship look between you and the AI in the way that you're doing the work? Like is it Is it 80/20? Is it 50/50? How would you define it? Like what is separating your approach, which is clearly working very well and very effective, Vivek, from everybody else's? >> Yes.

So, right now, AI is doing most of the heavy lifting. I am doing the target selection and the report submission. >> I see. I see. >> I see. And and is that because you feel like there's more of an art or like what what is the part why is the human element on the on the parts that you just mentioned so important there? Why why not automate that, too? >> So, AI is not good at understanding what is intended behavior. Like if there is there is anything that is unusual, it flags it.

So, it gives a lot of false positives. Our job is to reduce those false positives. >> Mhm. And how do you do that? Is that Is that where the manual review comes in or the target selection comes in? Like how What are your chief ways of reducing the false positives and making sure that your your approach to hunting is going to be high signal, high accuracy by default? >> Yes, so the triaging is done by me. >> I see. So, it's almost like you're running your agents across these codebases and then you're the triager who's deciding where to double-click on all of this and where to go deep dive on all of this.

Is that right? >> Yes. >> Mhm. Do you think that using the the the agents to do this, is that atrophying your your your skills in reading code or is it sharpening your vulnerability hunting skills in order to do it this way? >> So, it's a combination of both. So, if you rely 100% on AI and never read any code, then your reading skills will definitely be affected. But if you are doing both, then I think it helps you. >> I see.

Are you still reading the code yourself and checking in and diving in and doing the manual stuff, too? >> Yes, I'm doing it, but not as much as as I used to do. >> How much? Like if you were to you know put it on a on a percentage basis compared to how much you used to do, how would that stack up? >> So earlier I 100% of the hunting was done manually only. AI was not good enough or I was not good enough to use the AI.

And nowadays around 70-80% of the issues are found by AI itself. >> Mhm. Mhm. Well, that's pretty remarkable. And and are you doing you know 70 to 80% with AI, 20% manual code review too? Is that how that breakup shakes out? >> Yes. >> Interesting. Interesting. Interesting. So it's really like a you kind of flipped the workflow that you've been doing on its head entirely. >> Yes. So the earlier road for improvement was read audit reports.

Read recent hacks. Now it also includes read AI news. >> Mhm. >> Experiment with AI. >> I got you. I got you. And so you in addition in order to to hunt very well in this way, it sounds like not only do you have to be a savvy hunter, but you also have to know how to use these AI tools really really well. >> Yes. >> Got you. Interesting. Where do you think about how do you think about AI and the future of bug hunting?

Do you think AI is going to replace human security researchers or is that the wrong way to think about this entirely? >> Uh I don't think that it will replace human security researchers. Like suppose you are handling a protocol having 500 million TVL. Would you be comfortable relying on only on AI even if it finds a 99% of the issues? >> Mhm. >> don't know. That's a tough question. But it's a difficult question. I'll have to think about it. >> So So the AI has the technical capabilities, but it is not able to find 100% of the issues.

And here in our industry, even if one vulnerability vulnerability is there, it can drain millions. So I don't think that it will replace human security researchers. But human security researchers can use it to amplify and speed up their work. >> I see. Well, here's a question. Do you think human beings can find 100% of the vulnerabilities? >> They're not necessarily, but they are definitely able to find the vulnerabilities that AI has not been able to find. >> Ah, I see.

So even if we can't find 100% even if we can't get get to total vulnerability coverage, the overlap of human and machine together is going to create more comprehensive coverage than either one of those would alone. Is that your thesis? >> Yes. >> Well, in crypto, it makes sense. So I gave this example uh in previous chats I say, you know, it used to be that 99 out of 100 is a losing grade, but now it's like 999 out of 1,000 vulnerabilities found is a losing grade in a world where anybody, if they throw enough money at the problem, can find that one out of 1,000 vulnerabilities.

And so you really do need to optimize for total code coverage, no matter the cost. Especially cuz you could have hundreds of millions of billions of dollars. And an attacker can afford to spend years and millions of dollars on computing token costs in order to find that vulnerability if it makes sense there's enough money locked up there. So, in that world, does it make sense to do absolutely everything possible to expand code coverage?

And if your thesis is correct, Vivek, then the human security researcher will never go out of style. >> Yes. >> Very bold. Very bold claim. Now, looking Let's look forward a little bit. If you were to to to talk to a future Vivek, so imagine another accounting who is just getting into crypto right now, realizes right now the market is bearish, it's great opportunity, stable coins getting bigger, the market even though it's extremely bearish, the market is booming in terms of how it's growing, and he wants to get involved.

What do you recommend that he be learning and studying right now so that he's relevant in 3 or 5 years time? >> So, the basic fundamentals. Like what is distributed ledger technology, the basics, very basics. Like the the flavor of the season can change, but the basics will always remain. And also it it is good to be adaptable till you haven't found what you want to do. >> Sure. Sure. And what is what is what is being adaptable look like in this context?

Like for all the newbies who are starting out, who are looking, maybe hoping that they can replicate some of your success in the amazing career you've been on, Vivek. You know, what would you recommend that they they do or how should they think about this? That we should be >> now there is a lot of talk about ZK and formal verification. So, if someone is new, they should be adaptable enough to dive deep into those. >> Mhm.

Mhm. And what are the what are the preconditions? I mean, I think a a lot of the reasons people were afraid of zero knowledge proofs and formal verification in the past is that both of them are very math intensive and and highly specialized skills. Do you think that's a a real barrier today or not so much? >> It's a barrier, but then maths is the basics that I talked about. >> I see. So, you think that security researchers should have strong math abilities by default? >> Yes. >> I completely understand. >> And if they don't have it, they should be willing to develop it. >> Mhm.

And did you do that? Did you go back and start studying your math again and brushing up on that when you were building up your skills? >> Yes. >> Interesting. >> So, right now I will be diving into ZK myself. So, I need to do it. >> I completely understand. That is an exciting concept. We've got a number of of top-class white hats of Immunify all-stars who have mentioned this idea that being strong at math is really a competitive advantage for dealing with complex protocols and systems and gives you access to a whole bunch of tools that you would otherwise not be able to use.

And here you are confirming that again, guys. It's like, you know, math is the universal language of reality and physics you should be leveraging heavily. >> Yes. >> Go figure. I have one other question and then I want to open the floor to you, Vivek, to comment on whatever you wish, which is, you know, if you had to think about what separates the very best white hat hackers, the very best security researchers on Immunify, from everybody else, what do you think that would be? >> So, number one is work ethic.

So, this field is like completely independent. You have to maintain your own discipline. Many people may not be able to do it. There is also like technical background. Many people also come into this field expecting fast results seeing the payouts on Twitter. >> Mhm. >> Like they should use it for inspiration, but they should not compare the it with their situation. Like someone may have been in this field for 2 years, 3 years, 4 years.

If they are comparing their payouts with themself when they have just started, then they it will only lead to anxiety. >> Mhm. >> But they can use it as fuel for what is possible. But they shouldn't expect that they will also get those payouts within the first month or the first 3 months. >> I see. And what what is, you know, flipping that around, what is the mental game or the mental attitude that they should be having that that will make them the very best?

You know, if guys wanted to try and and follow that path today, what would that look like? >> Personally, I would say that don't expect any results for first 12 months. Focus on the inputs only. >> Mhm. Mhm. Got it. Is there any >> So, if you do the If you do the right things, the results will follow. >> I see. Do you think this is the most important thing? >> Yes. And also don't get distracted by other shiny objects. >> That's hard. >> That's [laughter] hard. >> Oh man, that's really hard.

Okay, this is great. You know, you've shared a lot of wisdom here. There's going to be a lot of other security researchers who are in your position who haven't had the fortune of making their first million dollars or or or huge success under their under their belt yet. If you were to give them any overall guidance or anything else that you would like to share with our listeners here before you wrap up, you know, floor's open.

What do you have to say? Believe me, they all want to hear from you. They want to hear what you have to share with them. >> I would say come with a long-term mindset and don't quit when things go tough. >> Okay. Well, you heard it here first, you guys. Vivek, latest Immunify millionaire. Well done reaching in the very top echelon of the 2026 leaderboard. You should be very proud, Vivek. Is there anything else you want to add before we wrap up today? >> No. >> Okay.

Well, I have one other thing I want to add, which is I'm looking forward to more of your great exploits in the future. >> White hat only, okay? White hat exploits only. >> Responsible disclosures, you guys. We're protecting society here. The way you talk about it is like so many of the other champions, so many of the other Immunify all-stars that I've had a chance to meet and talk to over the years. I'm very sure that you're going to be a long-term winner at this game and that you have a lot of value to contribute.

Uh the you know, everything you said here is is thoughtful, it's disciplined, it's mature, it's long-term oriented. You can create a lot of value for the community over time. You've already done a lot of good for the industry and for the the the overall on-chain community. So, thank you again for those contributions. And really thanks thanks again for joining. I'm sure this won't be our last chat, but uh I'm you know, we're going to we're going to see how your adventure shapes up and if there's, you know, anything of course we can do at Immunify to support that and to help you make sure to ask whatever you need because we want you doing your best to protect the industry.

You're doing God's work. Okay? >> Thank you, Mitchell. Thanks for having me. >> Awesome. And And just so you know, a little bit of commentary from the peanut gallery, you know, as we're as we're doing this, we have interesting guys like of course other legendary white hats like White Hat Mage who want to thank you for protecting the economy of our industry, for protecting people's money and value. The other white hats respect what you've been achieving, what you've been doing.

It's really really really noble. Now, looking into the future in terms of what's coming next as we wrap up here today, I just want to point out a few minor things. Number one, of course, you know, if you want to get involved, please head over to immunify.com and hunt, you know, Vivek has given you the tools here. A mindset, the most important thing, the mental game for how to think about becoming a world-class security researcher and becoming a white hat millionaire yourself.

And And it's entirely possible for you to achieve. And the second thing is we just launched Immunify Iron Score today. And Iron Score is a completely new system for doing security risk assessment against protocols. We took hundreds of Immunify protocol customers and then we analyzed their security postures, okay, to see how fresh is their security posture, how comprehensive is their posture, how transparent is their security posture.

Are they using best practice tools? Do they have a built-out security stack? And then we ranked them on a log scale so that you can have a a feeling for how secure your funds may be, your tokens may be if you're engaged or if you're working with any of these. Of course, as security researchers, it's directly relevant because it'll show you who needs your help the most, who's likely to have a strong security posture or not.

We'll post a link to Immunify Iron Score. You can go and try it out. You can test it against your own wallets to see how safe your funds are and you can go check out hundreds of protocols there afterwards. Final thing, thanks again everybody for tuning in. It is always our pleasure to share this with you and I hope you all join Vivek and I and the rest of the immunify team in protecting the industry. There is so much more for us to do.

SR Summer 2026 is really just beginning and uh I hope you guys are all going to be on for the ride with us. So thank you and give a big round of applause for Vivek and I hope you guys all really had a blast on this one. Thank you everybody. >> Bye.

The words are the caption track's own and nothing is reworded or re-transcribed. Paragraph breaks are placed between sentences so the text reads as prose.

Use this transcript

Three free tools that work on the material around a video like this one. No signup, no login.