BlockThreat Enterprise

Your attacker’s scope, mapped monthly.

You audit the contracts. You harden the keys. So did KelpDAO, until forged messages arrived through the RPC nodes it trusted. So did Drift, until two signers were social engineered in person over six months. The next path in is one nobody has scoped yet. Enterprise closes that gap.

A lookout on a bluff watches through a spyglass as riders approach a frontier town from the far side
What is included

Four things a newsletter plan cannot provide.

The engagement opens by mapping your stack, dependencies, and threat model, then runs on a monthly cadence. Defined before you sign.

  1. 01

    Monthly private briefing

    Your team sits down with the researcher behind BlockThreat to walk the month’s findings and adjust priorities.

  2. 02

    Written brief, fully cited

    Every theme sourced to the primary post-mortems and research, so your team can check the reasoning and go deeper.

  3. 03

    Priority communication

    A direct line and dedicated support for clarifying intelligence and coordinating the account.

  4. 04

    Organization-wide licensing

    Every edition, with rights to circulate internally across teams instead of one reader per subscription.

What you receive

Two or three themes a month, and what to do about each one.

Analysis lands at four dimensions: tactical, operational, strategic, and technical. It ranges from a hash your EDR can use tonight to the trend that reshapes next quarter. Every theme ends in prioritized action items.

Executive summary

What changed, in a page you can forward

The month compressed to the few developments that actually move your risk, written so it survives being sent to leadership unedited.

DPRK tradecraft escalated sharply, and three supply chain attacks landed in one month: Trivy, Resolv, and Axios. Here is what each one changes for you.

Priority threat themes

Each incident traced to your architecture

Not a recap of what happened to somebody else. Every theme names the route into your systems, and which assumption you already made no longer holds.

The Drift compromise materially expands the threat model: an operator in constant contact with node operators, DeFi teams, and vendors must now treat all relationships as intrusion paths to privileged staff.

Action items

Work you can assign this week

Grouped by owner: threat hunting, personnel, policy, security controls, supply chain, monitoring. Specific enough to drop straight into a sprint.

Identify every contract compiled with Solidity 0.8.28–0.8.33 under --via-ir. Sweep the endpoint fleet for a Contagious Interview RAT payload hash.

Watchlist

What is not urgent yet

Developments tracked before they become action items, so the month they start to matter is not the month you first hear about them.

Quantum risk timelines pulled forward to 2029. Chain-killer bugs still surfacing, including arbitrary struct hijacking in the Aptos Move VM.

Frequently asked questions

What to expect from Enterprise.

We already run audits and maintain a threat model. Why do we need this?

Both are point-in-time. An audit certifies the code in front of it; a threat model enumerates threats you knew about when you wrote it. Neither covers the build pipeline that ships a vulnerable artifact, the RPC provider you inherit trust from, or a threat actor who spends six months at conferences earning the trust of your business development team. Briefs close those gaps monthly, and a recurring category of action item is an explicit update to your threat model.

Why not use the Team plan?

For many teams, that is the right call, so start there. The Team plan licenses every edition for one team as it publishes. Enterprise exists for three things it cannot do: license that intelligence across your whole organization rather than a single team, shape the analysis around your specific stack and threat model, and put your team in a room with the researcher every month.

Do we need a mature security program for this to be worth it?

No. What matters is having someone who can own the follow-through, not how far along your security program already is. Enterprise fits organizations with real value on the line and a team that can act on what arrives: a two-person security function that assigns the action items gets more out of it than a large team that files the brief and moves on.

What happens during the monthly briefing?

The agenda is shaped around the technologies and risks identified during onboarding. We walk through the month’s most relevant findings, why they matter to your systems, and take questions from your team.

How many people can access Enterprise?

Licensing is defined around your organization’s needs. It can cover multiple internal teams, while subsidiaries, affiliates, clients, and external distribution require explicit inclusion.

Is this an incident response service?

No. Enterprise provides intelligence and insight only. It does not replace continuous monitoring, audits, consulting, or an incident response provider.

BlockThreat Enterprise

Tell us what your team is defending.

Send your stack, your security priorities, and the questions you need answered. If Enterprise is not the right fit, we will say so.

enterprise@blockthreat.com