
Menu
Tuesday, 4th August
Chef’s Welcome
This is The Menu: the weekly briefing from the Web3 Dinner Club.
What the market is saying, and how the best builders and investors are making sense of it.
In this issue:
Public and Private Keys
Book review: Building a Story Brand 2.0
The New Finance Stack
Report: BullHound Capital The Dawn of Modern Banking
Signal, served weekly.
Partner Pairing
Novel Labs
The dinner club is proudly sponsored by Novel Labs.
A multi-award-winning London storytelling studio building the brands of the future in AI, blockchain, and emerging technologies.
Best known for the $100m expansion to the Bored Ape Yacht Club, The Mutant Cartel World.
If you’re a startup or scale-up building a brand and looking for real go-to-market impact from those who have repeatedly built unicorns and category kings as VCs and founders... ask for an intro at the table.
Amuse-bouche
What are Public and Private Keys?
Public and private keys are the foundation of how ownership and security work in crypto.
At a basic level, they’re a pair of mathematically linked codes. One is public and can be shared freely. The other is private and must be kept secret. Together, they allow you to securely receive assets, prove ownership, and authorise transactions without relying on an intermediary.
Think of it like this.
Your public key is your address. It’s what you give to others so they can send you funds or interact with you on-chain. Like an email address, it’s safe to share and designed to be visible.
Your private key is your control. It’s what proves that you own the assets linked to that address. If the public key is where things are sent, the private key is what lets you unlock and move them.
This is where crypto fundamentally differs from traditional systems.
In a bank, access is controlled by the institution. In Web3, access is controlled entirely by whoever holds the private key. That’s why the phrase “not your keys, not your coins” matters; if you don’t control the private key, you don’t truly control the assets.
A simple example:
If someone sends you ETH, they use your public key. But if you want to send that ETH onwards, you need your private key to sign the transaction. That signature acts as cryptographic proof that you authorised it, without ever revealing the key itself.
The trade-off is power versus responsibility.
There’s no password reset. No support desk. If a private key is lost or exposed, the assets tied to it are effectively gone.
That’s the core shift Web3 introduces: ownership without intermediaries, secured entirely by cryptography.
Starter
Bitcoin Didn’t Break. Faulty Code Did.
When the keys can be accessed, ownership fails with them. The recent Coldcard incident is a clear real-world example of that hard truth.
Attackers did not break Bitcoin or its core cryptography. They took advantage of a firmware flaw in certain Coldcard hardware wallets that caused those devices to create wallet seed phrases using weak, predictable randomness instead of the strong hardware-based randomness they were supposed to use. Once the private keys became guessable, the Bitcoin network treated the attacker as the rightful owner. The signatures checked out, so the funds moved. No questions asked. No way to reverse it.
What actually went wrong
Coldcard is a well-regarded hardware wallet designed to keep Bitcoin keys offline and secure. In early 2021, during a software update, a configuration mistake quietly switched how new wallet seeds were generated. Instead of pulling truly random numbers from the device’s dedicated hardware chip, the wallets fell back to a weaker software method that relied on more predictable information, like parts of the device’s serial number and internal clock.
The result was that some seeds looked normal (the usual 12- or 24-word recovery phrases) but were actually drawn from a much smaller set of possibilities than they should have been. On older models, the effective randomness dropped dramatically—enough that a determined attacker could systematically try the likely options offline, match them to real Bitcoin addresses holding funds, and drain those wallets without ever touching the physical device.
Newer models were less severely affected but still weaker than intended. The problem went unnoticed for more than five years until attackers began exploiting it in late July 2026.
The fallout
Hundreds of Bitcoin (tens of millions of dollars, and climbing as more activity was tracked) were swept from affected wallets in short, irreversible bursts. Because Bitcoin transactions cannot be undone and there is no central authority to step in, the money is gone for those users.
Firmware updates released after the discovery fix the randomness problem for new seeds. They do nothing for seeds that were already created with the weak method. Anyone who generated a seed on an affected Coldcard during the vulnerable period needs to move their funds to a freshly generated seed on updated firmware (or create one using strong external randomness, such as plenty of dice rolls).
The bigger point
Most major crypto losses are not caused by Bitcoin itself being hacked. They happen because private keys or seed phrases get compromised—through phishing, malware, bad storage habits, or, as in this case, a subtle manufacturing-level error in how the keys were first created.
Bitcoin’s rules still work exactly as designed. Whoever controls the private key controls the coins. That is both the system’s power and its unforgiving nature. The keys must be generated with genuine high-quality randomness and protected like physical gold. Hardware wallets are a big help, but only if the software that creates the seed does its job correctly.
The Coldcard case is a reminder: the Bitcoin protocol is solid. The real risks often live in the tools and processes around it.
Main
Book Review:
Building a Story Brand 2.0
Building a StoryBrand 2.0 by Donald Miller
A strong book for founders because it tackles one of the biggest reasons good businesses get ignored: unclear messaging.
Miller’s central argument is that if customers cannot quickly understand what you do, how you help them, and why it matters, they will move on.
The updated version makes that framework even more useful by sharpening the seven-part StoryBrand process and showing how to apply it in a world where attention is constantly split.
For founders, this matters because clarity is not just a marketing problem; it is a growth problem.
A business can have a strong product and still struggle if the message is muddy, overly clever, or too focused on the company rather than the customer’s problem.
This book is a useful reminder that the best brands do not try to impress people first; they try to help them understand.
W3DC: This is one of those books that every founder should read at least once, because it forces you to strip away the noise and get to the point.
Most companies do not have a branding problem in the creative sense; they have a clarity problem.
And in a crowded market, clarity is often the thing that makes people stop, understand, and buy.
Special
Web3 Dinner Club: 25th September (London)
A curated, seated dinner for a small group of builders working in crypto, AI, and frontier tech.
One table. No pitches. No panels. No ego contests.
Just the kind of conversation that doesn't show up in your LinkedIn feed. The relationships that move capital, talent, and ideas in Web3 don't start at conferences.
They start at a handful of dinners with the same people, repeated over time.
Seats are limited by design.
Proudly sponsored by Novel Labs.

Dessert
The Seven-Layer Stack:
Where Finance’s Real War Is Being Fought
Forget products. The next decade of finance will be won or lost at the stack level.
Seven layers are converging into a single operating system for money: finance, payments, crypto, trading, AI, licences, data, and distribution. The platforms that can integrate all seven, securely and at scale, will define the future. The rest will become features inside someone else’s app.
Finance is the core.
Deposits, lending, savings, credit. These are the foundational rails. Without them, you are a wrapper, not a bank.
Payments are the entry.
Daily behaviour drives adoption. But payments alone are a race to the bottom on margin. They are the hook, not the business model.
Crypto is the new rail.
On-chain access is no longer optional. It is about ownership, programmability, and reaching users who expect Web3 as the default. Ignore it and you cede an entire generation.
Trading is the new savings.
Retail no longer separates investing from everyday finance. Returns, risk, liquidity. Trading is now core behaviour, not a niche product.
AI is the interface.
Not a chatbot. A decision layer. The platform that builds the best AI-native financial interface will own the relationship. Everything else becomes commoditised.
Licences are the moat.
Banking, securities, crypto, payments. Each licence is a gate. Stack them and you build a legal architecture that competitors cannot easily replicate.
Data is the fuel.
Every transaction feeds the AI, improves the product, and deepens trust. Own the data, own the insight. Lose it, and you are blind.
Distribution is the scale.
Global reach is the multiplier. Local licences, partnerships, and localisation. Without distribution, even the best stack stays niche.
Security is the foundation.
None of this matters if you cannot protect keys, data, and assets. One major breach can erase years of trust. Security is not a feature. It is the price of admission.
W3DC:
The winners will not be the best single-product players. They will be the platforms that can pull all seven layers together, securely and at a global scale.
If you are building here, ask, 'Which layers do you control?' Where is your dependency? And where is your real moat?
The old bank was a branch.
The new bank is a stack.
And the race is already underway.
Digestif
Brand spice
📚 A report / thesis we’ve read:
The New Bank Is an Operating System
Bullhound looks at the Dawn of Modern Banking, otherwise know as Revolut…
Bullhound Capital’s July 2026 report on Revolut reads less like a fintech update and more like a thesis on the future of banking itself.
The core argument is simple:
Revolut is no longer just a payments app or a challenger bank. It is a diversified financial institution built around a proprietary technology stack and a global distribution network of around 75 million users.
The advantage is not one product. It is the architecture.
FX. Payments. Cards. Savings. Deposits. Lending. Wealth. Trading. Crypto. AI-driven financial services. All sitting inside a single app.
Bullhound calls this “complexity that feels simple”. Behind a clean, everyday interface lies a highly modular financial operating system. The goal is to hide the complexity of modern finance while deepening the relationship with each user.
That matters because distribution is becoming the real battleground.
Once a customer is already using Revolut for basic payments, the company can layer in higher-margin products into existing behaviour. The report describes this as a flywheel: each new product increases retention, lifts revenue per user, and helps fund the next launch.
AI is a key part of that stack.
Bullhound highlights Revolut’s foundation model, PRAGMA, and its AI-native interface, AIR, which began rolling out to UK customers in April 2026. AIR is designed to replace menu navigation with conversation, creating a single intelligence layer behind customer decisions.
The valuation assumptions are equally ambitious.
Bullhound supports a $115bn valuation for the current round, sets a target of $400bn+ by 2030, and outlines a long-term path to $1tn+ by 2035. Underlying this are projections of 165 million customers by 2030 and more than 270 million by 2035, with average revenue per user rising as Revolut shifts deeper into subscriptions, lending, wealth and business services.
For W3DC, the most interesting part is not the headline number. It is the direction of travel.
Revolut is becoming a clear example of the convergence we keep discussing:
Finance. Payments. Crypto. Trading. AI. Banking licences. Customer data. Global distribution.
The report also notes that Revolut’s legal architecture mirrors its technology architecture. Banking, securities, crypto, payments and insurance are structured as separate but connected parts of the wider machine, each wrapped in its own licences and regulatory requirements.
That feels like the model many financial platforms will now try to copy.
Not one product. Not one licence. Not one market. A modular financial operating system.
W3DC:
Revolut shows where modern finance may be heading. The winning platform may not be the one with the best single product. It may be the one that owns the customer relationship, hides the complexity, builds the infrastructure in-house and keeps adding financial services into the same trusted interface.
The old bank was a branch.
The new bank may be an operating system.
Why security is Key (no pun intended)
Security Is Not Optional
Founders: If you are building anything that touches money, data, or identity, security is not a feature you add later. It is the foundation you build on from day one.
If there is one thing that Web3 keeps reminding us, this week’s Bitcoin hack being the latest example, it is that security is key (no pun intended). The protocol held. The cryptography held. What failed was the human layer around it.
No amount of growth, funding, or traction can compensate for a single catastrophic breach. One compromised key, one exposed seed phrase, or one weak integration can erase years of work in hours. There is no customer support line. No reversal mechanism. No second chance.
Build with security as a first principle. Treat every key, every credential, every access point as critical infrastructure. Audit early. Test often. Assume you are a target. Use hardware wallets for meaningful amounts. Keep seed phrases offline. Never digitise private keys in notes, screenshots, or unencrypted files.
Because in Web3, security is not just key to what you are building. It is what allows you to keep building at all.

Until next time
Views expressed here are for informational purposes only and are not financial advice.
