Canary tokens and digital tripwires (Interview) artwork

Canary tokens and digital tripwires (Interview)

The Changelog: Software Development, Open Source

July 21, 2026

Haroon Meer is back! Haroon is the Founder of Thinkst, the ~50-person bootstrapped company behind Canary and Canarytokens — honeypots and tripwires you sprinkle inside your network and forget about until an attacker touches one.
Speakers: Adam Stacoviak, Lachlan Donald, Haroon Meer
**SPEAKER_1** (0:00)
What's up, friends?

**Adam Stacoviak** (0:01)
We'll go back. This is The Changelog. This week on The Changelog, we have Haroon Meer back.
Haroon is the founder of Thinkst, the 50-person bootstrap company behind Canary and Canary Tokens. They are honeypots and trip bars you sprinkle inside your network and forget about until an attacker touches one. We talk about the AWS API key. Token attackers just can't resist trying the real credit card token they have that's backed by an actual bank partnership. They have Breadcrumbs, their brand new feature that leads intruders straight to your canaries, a live demo where a hardware canary becomes a Synology NAS in one click and how a company with zero outbound sales and no price increase in 10 years, quietly passed $22.5 million in annual recurring revenue. Baller, a massive thank you to our friends and our partners at fly.io. That is the home of changelog.com. Learn more at fly.io.

**Lachlan Donald** (1:05)
OK, let's do this.

**Adam Stacoviak** (1:27)
Well, friends, we're back. Haroon is back. It's been a few years, Haroon. A big fan of your tiny little company.
And I don't want to say tiny like a pejorative, but just how much impact. And I mean that in a loving way. A 40-person company just having massive impact in the cybersecurity world. We talked to you before about Thinkst and Canary and Canarytokens.
Take us back into the world because we now have AI, where the last time we talked, I mean, we probably had the burgeoning early beginnings and the early endings of it. I mean, if you could even call that probably like the farm league to keep going with the baseball analogy. But we're now in a world where the attackers have the same tools we have, which has always been the case. But these tools we have give us versions of superpowers. I can imagine this world you're in right now is just insane. One massive ARR, if you want to mention, you can't think TechCrunch did it for you, but you can certainly as well. I just want to paint the picture for who you are, where you work, what you do, and just a massive impact in monetary value, because hey, capitalist, we run businesses, right? But at the same time, you're giving away a lot for free too. You could be making more. Is that enough of an intro for you? What do you think?

**Haroon Meer** (2:44)
I think that's great. So company-wise, like you said, we are pretty small company. People-wise, we're just over 50 people now, which feels pretty big to us.
But product-wise...

**Adam Stacoviak** (3:01)
50, okay, not 40 I'm mistaken.

**Haroon Meer** (3:04)
Yeah, so we've just hit 50 and we feel that's huge.
But the company is almost entirely technical. And we've done a few things pretty unusually. So for one thing, we still do zero outbound sales. So last year, we hit 10 years of selling things to Canary. And we still never reach out to customers. So everything's happened just with word of mouth. Like we initially made something that a few customers like, and they said nice things about us. And we just try to not let them down. And for the most part, I like to think that we almost the poster children for doing business this way, which is like do good things and good things will happen to you and it makes you do good things.
And so I think like the model is a sustainable one. Like we didn't raise money. And fundamentally, we make two products. So for people who are new, Canary initially were hardware devices. So they were hardware honey pots. And our insight, we had two of them. One was that honey pots almost always got a bad name because people used to use honey pots for research projects, like put one up on the Internet and say that a thousand IPs from China attacked this honey pot. And we said, what if instead you put honey pots inside your network where nobody should be touching them? And then every time someone touched them, you basically got a high quality signal that bad stuff was happening. And so we made these hardware honey pots and we made them really easy to deploy, like two minutes to deploy.
And again, our whole pitch was that if we made it simple enough and cheap enough, then why wouldn't you do it? So even if you had lots of other security projects going on, just take a few of these, sprinkle them, forget about them. And if they get touched, then you know you've got to change your plans.
And those ended up working really nicely. So we started off doing hardware versions.

96 more minutes of transcript below

Feed this to your agent

Try it now — copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/1000777793635