Web3 Security

A security program that survives mainnet

We design and run continuous security programs for protocols, bridges, and L2 teams - from pre-mainnet threat modeling to long term security strategies, integrated with your engineering rhythm.

See the program

What usually breaks Web3 protocols

KEY COMPROMISE

Opsec inaccuracies

Deployer keys, hot signers, and admin EOAs are the modal root cause of nine-figure losses.

CONTRACT BUGS

The contract works as designed

Most exploits don't break a line of code - they use the paths the team built, in ways nobody added up.

BRIDGES & CROSS-DOMAIN

Failures live in the seams

L2-to-L1 trust assumptions, oracle stalls, sequencer outages - the contract is fine; the seam isn't.

UPGRADE & GOVERNANCE

Temporary solutions

Timelock skipped "just this once". Guardian role never rotated after the early team left.

OFF-CHAIN REACH

Web2 Classics

Domain hijacks, frontend supply-chain (NPM, CDN), Discord takeover, S3 IAM weakness - lots of successful attack leverage Web2 attack paths.

DETECTION LAG

Tens of minutes vs one block

Human reactions take much longer than a single block exploits. Most critical attack paths should be monitored and have a scripted time-buying on-chain response: pause, freeze, blacklist.

How we work

  1. Discover

    Threat-model the protocol: invariants, choke points, cross-domain assumptions, and where the keys actually live.
  2. Prioritize

    Order the work by blast radius - pre-mainnet must-haves first, post-mainnet rolling improvements after. Owners and dates, not aspirations.
  3. Implement

    Invariants in Foundry CI, detectors in Forta/Tenderly, signer & deploy ceremonies on Safe, freeze runbooks committed to the repo.
  4. Prove

    Rehearse before mainnet - invariant suite green, monitor catalog firing, signer rotation executed, freeze playbook run end-to-end on a fork.
  5. Evolve

    Quarterly invariant refresh, monthly access review, on-chain change audit every release, board-ready risk delta each month.

Outcomes you can expect

  • Roadmap timeline with milestones and budget

    Security strategy, roadmap and budget planning.

  • Policy document with interlocking gears

    Opsec processes, rules, policies, and automations implementing them.

  • Monitor with radar targeting on-chain and off-chain assets

    Monitoring covering on-and-offchain high-risk areas.

  • Open binder with stopwatch and rehearsal loop

    Incident playbooks and rehearsals.

  • Magnifying glass over contract document with bug and bounty badge

    Regular audits, bug bounties, and help with the mitigation efforts and its coordination.

FAQ

Do we need all five layers, or can we engage just one?

All five are designed to run as a program - but each layer also stands alone. Most teams start with 2–3 tied to a trigger (pre-mainnet launch, post-incident hardening, enterprise deal) and add the rest as scope grows.

Can you work with our existing auditors?

Yes. We prepare you (Audit-Ready Pack), coordinate with auditors, and run a post-audit fix sprint.

Do you handle cross-chain/bridge risks?

We model cross-domain threats, add limits/timelocks, and build freeze playbooks with rehearsals.

What if we don’t have a SOC?

Start with decentralized monitors and targeted detections; add a SOC later if needed - we can help with that too (see SOC).

Is this for pre-mainnet protocols or post-mainnet ones?

Both. Pre-mainnet programs are scoped to launch day - threat model, invariants, ceremonies, monitor catalog, day-1 runbook. Post-mainnet hardening runs as a retainer - invariant refresh, access review, on-chain change audit, sized to your release rhythm.

How is this different from hiring an in-house security team?

Faster to stand up, broader skill mix (you’d need 3–5 hires to cover all five layers), and scalable with your stage. Many engagements run long-term; others run alongside while you build internal capacity.

Ready for mainnet-grade security?

  • Harden
  • Monitor
  • Drill
  • Ship with confidence