Sunny Ray sits down with Siddharth, a second-year Georgia Tech computer engineering student who co-founded Kairo, a security layer for smart contract developers, about two months before this conversation. Siddharth explains how a failed local-rewards app project exposed him to the difficulty of building and securing smart contracts, which led him and his co-founder to pivot into blockchain security. He describes cold emailing his way into a relationship with the Federal Reserve around its stablecoin initiative, and shares the entrepreneurial philosophy behind that outreach, including his belief in the mom test and the importance of relentless confidence. They discuss how Kairo differs from one-time audit firms like OpenZeppelin by covering the full development lifecycle with static and dynamic testing, why AI tools alone are not enough for security, and how a past YC rejection motivated the team. The conversation closes with Siddharth's vision for Kairo becoming a compliance standard for smart contract security and his admission that social engineering attacks remain outside their scope.
A Georgia Tech sophomore explains how cold emails landed the Federal Reserve as a client for his smart contract security startup Kairo.
Can you give me the headline on what you're building?
I'm a second year Georgia Tech student studying computer engineering. About two months ago, my friend and I started a company called Kairo. We primarily build a security layer for smart contract developers, streamlining the whole process and securing it end to end throughout the development lifecycle.
How did you end up landing the Federal Reserve as a customer as a second year student with an early business?
Our go-to-market was LinkedIn and cold email outreach, we didn't care who we reached out to, we just wanted eyes on the product. I cold emailed people on the Federal Reserve's smart contract team. With their stablecoin initiative launching this year, they were impressed and said this is something they'd actually use.
You mentioned the mom test twice, what is that?
It's a book by Rob Fitzpatrick. The idea is you're not building a product for yourself, you're building it for clients who may not know exactly what they want but have a problem. People love to reciprocate what you want to hear, like your mom telling you your idea is great, but in business that's noise. You need to find the real problem and solve it.
Was there a specific exploit or hack in DeFi that hit you personally and pushed you toward this?
In November there was an exploit for around 300 million dollars, I forgot the company's name. It blew up across Twitter and the bug bounty community once people realized it was a very simple error, one that honestly anyone could have fixed. Being able to fully focus and catch things like that is a huge part of what we're solving.
What makes Kairo different from companies like OpenZeppelin?
Companies like OpenZeppelin provide a one-time audit that takes four to eight weeks. We focus on the period after that audit, when small code changes still happen before and after launch to mainnet, and those small changes are what actually lead to exploits. We wrap the entire development cycle from build to mainnet launch instead of just doing a single audit.
Why wouldn't someone just use Claude or ChatGPT to audit their code instead?
You honestly could try. What we specialize in is testing code in both a static and dynamic environment. Statically we look for exploits like re-entry bugs. Dynamically we place the code in an environment with agents actively trying to break it, which gives us a much better picture of real vulnerabilities.
What was your biggest setback before Kairo became what it is today?
It was a previous startup we were super passionate about. We applied to YC just two days after coming up with the idea, got the interview, then got rejected, so close and so far. It wasn't a breaking point, more a motivating factor that pushed us to keep going and eventually move to Florida full time on the next idea.
Where do you see smart contract security three years from now?
Companies are already spending millions every year on security because the need is that big, and that doesn't outweigh protecting the billions flowing through these contracts. We want to be the company that connects all these different auditors and gives clients a full guarantee that whatever they launch to mainnet is completely secure.
Building something daring? Sunny talks to founders like this every day. Fifteen minutes to see if your story belongs on the stage.
Claim your pre-interview