Hacker (Non)Court: Seymore, Inc. v. ThinkIz, Inc.
Andrea Matwyshyn, Carole Fennelly, Jonathan Klein, Elizabeth Wharton, Jessica Wilkerson, Desirae Satterlee
ShmooCon XX (Final) · Day 3 · Bring It On
Overview
This ShmooCon talk, "Hacker (Non)Court: Seymore, Inc. v. ThinkIz, Inc.," presents a captivating mock arbitration that delves into the complex legal and ethical ramifications of cybersecurity failures in a joint venture. The session features a panel of legal and industry experts who role-play a dispute between a traditional eyewear giant, Seymour Inc., and a fledgling AI software startup, ThinkEyes Inc., following a catastrophic product failure. The core of the arbitration revolves around assigning liability for severe user injuries and fatalities caused by a security breach in their jointly developed "Cyberware" — AI-enabled eyewear.

Key moments
- 0:00 Introduction to 'Hacker (Non)Court' and the case
- 2:00 Details of the AI-enabled 'Cyberware' product features
- 3:00 Napkin deal and internet-sourced indemnification clause
- 4:00 Open-source vulnerability, North Korean actor, and user injuries
- 6:00 Arbitrator convenes the binding arbitration and outlines procedure
- 7:30 Seymour highlights Think Eyes' security failures and misrepresentations
Hacker (Non)Court: Seymore, Inc. v. ThinkIz, Inc.
Speakers: Andrea Matwyshyn, Carole Fennelly, Jonathan Klein, Elizabeth Wharton, Jessica Wilkerson, Desirae Satterlee
Conference: ShmooCon
YouTube: https://www.youtube.com/watch?v=tPbbMPjFKjA
Overview
This ShmooCon talk, "Hacker (Non)Court: Seymore, Inc. v. ThinkIz, Inc.," presents a captivating mock arbitration that delves into the complex legal and ethical ramifications of cybersecurity failures in a joint venture. The session features a panel of legal and industry experts who role-play a dispute between a traditional eyewear giant, Seymour Inc., and a fledgling AI software startup, ThinkEyes Inc., following a catastrophic product failure. The core of the arbitration revolves around assigning liability for severe user injuries and fatalities caused by a security breach in their jointly developed "Cyberware" — AI-enabled eyewear.
The talk masterfully uses this fictional scenario to illuminate critical real-world challenges faced by companies integrating emerging technologies, particularly those impacting human safety. It highlights the often-overlooked necessity of robust legal due diligence, comprehensive cybersecurity practices, and stringent supply chain management, even when partnering with seemingly minor vendors. By dissecting the arguments from both sides and culminating in an arbitrator's binding decision, the session provides invaluable insights into how legal systems might apportion blame when technological innovation outpaces responsible development and oversight.
The relevance of this discussion is particularly acute in an era where software permeates every aspect of life, from consumer electronics to medical devices. As technology advances, the line between software and hardware blurs, and the potential for cyber vulnerabilities to cause physical harm becomes increasingly tangible. This arbitration serves as a stark reminder for businesses, developers, and legal professionals alike that the pursuit of innovation must be tempered with an unwavering commitment to security and user safety, backed by clear contractual agreements and rigorous oversight.
Background
▶ Watch: Introduction to 'Hacker (Non)Court' and the case (0:00)
The genesis of the "Cyberware" joint venture between Seymour Inc. and ThinkEyes Inc. was a seemingly innocuous conversation between two CEOs, sketched out on a napkin over coffee. Seymour Inc., a century-old publicly traded company renowned for traditional eyewear, sought to enter the burgeoning AI-enabled eyewear market to stay "cool" and monetize data. They partnered with ThinkEyes Inc., a six-month-old, entrepreneurial software startup, to develop the necessary AI software. The product, "Cyberware," promised two "killer functionalities": "I-Spy Cash," a blink-twice-to-pay stored payment system, and "Calendarize," an augmented reality feature displaying the user's calendar directly in their field of vision.
The initial deal, made quickly and informally by Seymour's standards due to its perceived low dollar amount, notably lacked a thorough legal review by Seymour's in-house counsel. Instead, it included an indemnification provision found "on the internet." This foundational oversight set the stage for future disputes. The catastrophic incident that brought the companies to arbitration involved an exploitable open-source library vulnerability within the Cyberware's software, allegedly introduced or exploited by someone working remotely for ThinkEyes from North Korea. This vulnerability caused the calendar app to pop up unexpectedly, leading to black screens, numerous injuries, and fatalities among users who were driving, operating on patients, or performing other critical tasks.
The arbitration aimed to resolve the dispute over liability attribution under their joint venture agreement. Seymour Inc. argued that ThinkEyes Inc. betrayed trust through egregious failures, misrepresentations, and breaches of duty, specifically citing ThinkEyes' negligence in software security, substandard background checks, and inadequate incident response. ThinkEyes Inc., conversely, contended that Seymour Inc., a large, resource-rich company, ignored its own security and QA policies, failed to perform due diligence on the integrated software, and sought to offload all liability onto a small startup to keep profits high and costs low. The case highlights a common tension between rapid innovation, cost-cutting, and the critical need for robust security and legal frameworks in modern product development.
Key Findings
▶ Watch: Napkin deal and internet-sourced indemnification clause (3:00)
The arbitrator, Jessica Wilkerson, delivered a nuanced decision, ultimately assigning 70% liability to Seymour Inc. and 30% liability to ThinkEyes Inc. This shared liability reflects a "multicausal event" and acknowledges critical failures on both sides, with Seymour bearing a larger portion due to its established size, resources, and regulatory responsibilities.
For Seymour Inc., the arbitrator found several significant failings:
- Insufficient Legal Review: Seymour's CEO admitted to foregoing a full legal review of the joint venture agreement to keep down costs, an act deemed especially unreasonable for a 100-year-old public company.
- Inadequate Supplier Management: Seymour failed to exercise sufficient oversight of ThinkEyes, treating them as a "low-tier vendor" and relying solely on questionnaires without on-site visits or code review.
- Responsibility for Third-Party Components: As a product manufacturer, Seymour was held ultimately responsible for all third-party components integrated into its product, including software and cybersecurity.
- Lack of Cyber Awareness: In 2025 (the setting of the mock arbitration), there is "no reasonable argument to be made that modern companies could make that they could be unaware of cyber needs," especially when venturing into software and emerging tech.
- Medical Device Manufacturer Obligations: Seymour's status as a manufacturer of glasses, legally defined as a medical device, imposed a higher standard of care under acts like the Federal Food, Drug, and Cosmetic Act. Its failures were deemed "especially unreasonable" given these established regulatory responsibilities.
For ThinkEyes Inc., the arbitrator identified these critical shortcomings:
- Failure in Staff Due Diligence: ThinkEyes failed to perform reasonable background checks on its development staff, relying on social media recommendations (LinkedIn) for vetting, which led to the hiring of a North Korean national whose involvement was linked to the breach.
- Inadequate Open-Source Software Review: ThinkEyes adopted an unreasonable "mini eyes model" for open-source security, believing that community review was sufficient and thus not performing intensive security reviews on the open-source library itself. This was deemed particularly negligent in an age post-Heartbleed and Log4j.
- Over-reliance on Social Media: ThinkEyes repeatedly used social media presences (LinkedIn) as indicators of quality and expertise for both its staff and partner vetting, which the arbitrator found to be an "unreasonable" practice in 2025 given the prevalence of misinformation.
- Unpreparedness for Human Safety Context: ThinkEyes, despite being an indispensable driver of innovation, was unprepared to step into supplying components for products affecting human physical safety and health.
- Represented Competence Not Met: While it was not fully unreasonable for ThinkEyes to rely on a larger company for some areas, it failed to properly perform tasks it had represented itself as competent for, particularly within the Software Development Life Cycle (SDLC).
In summary, the decision underscores that both parties had a duty of care, but Seymour's greater resources, longer history, and specific regulatory obligations amplified the unreasonableness of its failures.
Technical Deep Dive
▶ Watch: Open-source vulnerability, North Korean actor, and user injuries (4:00)
The "Cyberware" product at the heart of the dispute was described as AI-enabled eyewear, combining traditional glasses/contact lenses with advanced software functionalities. The two primary features were:
- I-Spy Cash: A stored payment system activated by blinking twice. This implies integration with payment processing systems and secure handling of financial data.
- Calendarize: An augmented reality feature that projects the user's calendar directly into their vision, allowing for "stealthy" perusal. This requires sophisticated display technology, potentially real-time data synchronization, and robust user interface management to avoid distractions.
The catastrophic failure stemmed from an exploitable open-source library vulnerability. This vulnerability, exploited by a "North Korean threat actor" working remotely for ThinkEyes, caused the eyewear to "shut down and go black," rendering users blind and leading to accidents. The specific nature of the vulnerability was not detailed (e.g., a CVE), but it was severe enough to cause "black screen of death" scenarios. The mention of open-source libraries highlights the pervasive supply chain risk inherent in modern software development, where components from external sources can introduce critical security flaws.
ThinkEyes Inc. claimed to follow a Standard Security Framework for Development, specifically mentioning OWASP (Open Web Application Security Project). Their asserted SDLC practices included:
- Using a combination of open-source and in-house developed software.
- Performing all work on a CSA (Cloud Security Alliance) certified Cloud platform.
- Employing experienced in-house developers and outside consultants.
- Conducting code reviews.
- Performing security vulnerability assessments.
- Regular static code reviews and dynamic testing against the OWASP standard to find and remediate security vulnerabilities.
However, despite these claims, ThinkEyes admitted that they did not perform the same intensive level of review for the open-source library as they did for their in-house code. Their justification was the "thousand eyes" model, believing open-source code inherently benefits from broad community review. This was a critical failure identified by the arbitrator.
Furthermore, ThinkEyes' due diligence on its personnel and partners was severely lacking. They used "Fly by Night Industries background check services," which they found on LinkedIn, and this process failed to identify that one of their "highly recommended" consultants was a North Korean national. Their general reliance on social media (LinkedIn) for vetting both individuals and companies was a consistent theme of their negligence.
Seymour Inc., on the other hand, demonstrated a profound lack of internal cybersecurity expertise. They admitted to not having a CISO (Chief Information Security Officer) or CIO (Chief Information Officer), relying instead on "firewall administrators," "system administrators," and "outside companies" for limited security support. They considered information security "not our business." Seymour's review of ThinkEyes' risk profile was minimal, treating them as a "low tier vendor" and only reviewing a questionnaire without any on-site visits or direct code inspection. Their argument was that they "relied on [ThinkEyes] to have the smarts" for software and security.
After the breach, ThinkEyes hired a third-party forensic firm named "Clown Derp," which reportedly discovered a "hacker was bragging on the dark web about backdooring Seymour's Hardware software to use to steal customers iash assets." This finding, however, did not provide direct proof of the backdoor code within Seymour's environment, leading to questions about the thoroughness of the investigation. Seymour also hired a "top-notch forensics firm" whose name escaped their CEO, which confirmed a "hole in the software." The lack of specific, verifiable technical findings regarding the actual backdoor in Seymour's deployed hardware/software solution further complicated the liability assessment.
Demo / Proof of Concept
▶ Watch: Arbitrator convenes the binding arbitration and outlines procedure (6:00)
This ShmooCon presentation was a mock arbitration, a legal role-play designed to explore the implications of cybersecurity failures in a fictional business scenario. As such, there was no technical demonstration or proof of concept of the "Cyberware" product, its functionalities, or the exploited vulnerability. The focus was entirely on the legal arguments, witness testimonies, and the arbitrator's decision regarding liability.
Defensive Implications
▶ Watch: Seymour highlights Think Eyes' security failures and misrepresentations (7:30)
The mock arbitration provides a wealth of defensive implications for companies navigating the complexities of modern technology, particularly in joint ventures and supply chain relationships:
- Comprehensive Legal and Contractual Due Diligence:
- Full Legal Review: Even for seemingly small ventures, a full legal review of joint venture agreements and contracts is paramount. Relying on "internet language" or skipping counsel to save costs can lead to catastrophic, unmitigated liabilities.
- Specific Allocation of Responsibilities: Contracts must explicitly define who is responsible for what, including software development, security testing, updates, and incident response. Ambiguity, such as relying on "Zoom calls" for critical instructions, is insufficient.
- Indemnification Clauses: Understand the scope and enforceability of indemnification provisions. They are not a silver bullet against all liability.
- Robust Third-Party and Supply Chain Risk Management (TPRM):
- Beyond Questionnaires: Companies, especially large ones, cannot rely solely on vendor questionnaires and "checking boxes." Deeper diligence, including on-site reviews, code audits, and interviews, is essential, particularly for critical components or vendors impacting human safety.
- Tiering Vendors Appropriately: The "low tier vendor" approach based on initial perceived impact can be disastrous if the vendor's component becomes central to the product's function or safety.
- "Thousand Eyes" is Insufficient for Open Source: The belief that open-source software is inherently secure due to community review (the "thousand eyes" model) is outdated and dangerous. Events like Heartbleed and Log4j have demonstrated that open-source components require the same, if not more, rigorous security review as proprietary code.
- Diligent Background Checks: Relying on social media (e.g., LinkedIn recommendations) for vetting employees, consultants, or even partners is unreasonable and can introduce critical insider threats or supply chain vulnerabilities. Comprehensive, professional background checks are non-negotiable.
- Internal Cybersecurity Expertise and Culture:
- Dedicated Leadership: Companies integrating software into their products must have dedicated cybersecurity leadership (e.g., a CISO or CIO) and staff. Claiming "information security is not our business" is no longer a viable defense, especially for product manufacturers.
- Cyber Awareness: In the current technological landscape, all companies are expected to be aware of and prepared for cybersecurity risks, particularly when moving into software and emerging tech spaces.
- Prioritize Safety Over Profits: Cost-cutting should never compromise security or human safety. Decisions driven purely by profit margins at the expense of robust QA and security are legally indefensible and ethically reprehensible.
- Regulatory Compliance and Product Liability:
- Medical Device Regulations: For manufacturers of products that could be classified as medical devices (like eyewear), understanding and complying with regulations like the Federal Food, Drug, and Cosmetic Act is critical. The FDA gained explicit regulatory authority for medical device cybersecurity in 2022, requiring "reasonable assurance of cyber security" for certain devices.
- HIPAA Implications: Products collecting health-related or personal data (like eye movements, calendar info) will likely fall under regulations like HIPAA. The proposed 2025 HIPAA rewrite emphasizes mandatory rather than "addressable" controls, increasing compliance burdens.
- Totality of the Device: In tort suits, liability will be assessed from the perspective of the harmed person, considering the "totality of the device" – including both hardware and software design decisions (e.g., "fail-closed" mechanisms).
- Ethical Conduct and Transparency:
- Don't Overpromise/Oversell: Startups should be realistic about their capabilities and not "get ahead of their skis" by overpromising in areas like security or complex software development.
- Document Concerns: Engineers and employees at all levels should document concerns about security, safety, or due diligence. This can be critical evidence in future disputes.
- Honest Incident Response: Misleading partners or third parties about the nature of a breach only exacerbates harm and further erodes trust. Transparency and effective incident response are crucial.
A useful shorthand for assessing potential liability, as mentioned by the speakers, is CHI: consider the Context of deployment, the maximal level of Harm that can occur, and the Intent (or knowledge) of the parties involved.
Key Takeaways
- Shared Responsibility is the Norm: In complex tech failures, liability is rarely 100% on one party. Both large corporations and small startups have significant duties of care.
- Due Diligence Must Be Comprehensive: Relying on questionnaires, social media, or "internet language" for contracts and vendor vetting is grossly insufficient, especially when human safety is at stake.
- Cybersecurity is Everyone's Business: No company, regardless of its primary industry, can claim ignorance of cybersecurity needs when integrating software into its products. Dedicated expertise (CISO/CIO) is essential.
- Open Source is Not Inherently Secure: The "thousand eyes" model for open-source security is outdated. All software components, including open-source libraries, require rigorous security review and management.
- Regulatory Context is Critical: Products impacting human health (like medical devices) carry heightened regulatory obligations (e.g., FDA, HIPAA), imposing a higher standard of care and liability.
- Document Everything: From contractual agreements to internal security concerns and incident response, thorough documentation is vital for demonstrating due diligence and defending against liability claims.
About the Speaker(s)
The mock arbitration panel consisted of a diverse group of legal and security experts:
- Andrea Matwyshyn: One of the organizers and likely the conceptual lead for the mock arbitration.
- Carole Fennelly: Played the role of Electra Cass, the CEO of ThinkEyes Inc.
- Jonathan Klein: Played the role of Seymour Buns, the CEO of Seymour Inc.
- Elizabeth Wharton: Played the role of counsel for ThinkEyes Inc. She also clarified her real-world role as the medical device cybersecurity team lead at the Food and Drug Administration (FDA), in the Division of Medical Device Cybersecurity.
- Jessica Wilkerson: Served as the arbitrator, delivering the binding decision.
- Desirae Satterlee: Played the role of counsel for Seymour Inc.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Let's be clear, this isn't a talk about a zero-day or some clever shellcode. If you came here for that, you're in the wrong room. This is about what happens after the zero-day hits, when the lawyers get involved, and people are dead. The scenario itself – AI-enabled eyewear with "blink-to-pay" and calendar integration, built on a napkin deal with an open-source vulnerability and a North Korean threat actor – is so painfully plausible it hurts. It's the kind of over-hyped, under-secured product I see vendors push every day, and this talk ripped into the consequences with brutal efficiency. The fact that the FDA is now explicitly regulating medical device cybersecurity makes this not just…
Heather Calloway (CISO) — MUST SEE
This mock arbitration is a critical case study for every CISO and board member. It brilliantly exposes the catastrophic consequences of governance failures, inadequate supply chain due diligence, and a fundamental misunderstanding of cyber risk in joint ventures. The session dissects how informal agreements and a lack of dedicated security leadership can lead to devastating business impact, regulatory non-compliance, and severe human cost, underscoring that liability in complex tech failures is rarely simple but always rooted in executive decisions and institutional accountability.