Named actors, not “the adversary”
DPRK, criminal APTs, cryptonative attackers, and insiders each have different objectives and ways in. Knowing which ones are interested in you is how you build defenses that matter.
Senior, hands-on security leadership for blockchain teams, shaped by how your organization really operates and who is coming for it. We model your entire system, dependencies, people, and processes to isolate the few paths that could be existential, and turn those into prioritized security controls, training, incident plans, and rehearsed response.
Two protocols with the same architecture do not share the same crown jewels, the same adversaries, or the same worst day. The work is finding what is genuinely existential for your organization, matching it against how threat actors are operating right now, and building controls in that order.
The threat surface keeps moving, and your defenses have to move with it. Each of these attacks came through a path nobody had thought to model.
Forged messages arrived through LayerZero, verified by a quorum too thin to catch a lie. Almost nobody’s threat model had a line for the provider you silently inherit trust from. Fewer still had one for the threshold that decides whether you believe it.
Covered in BlockThreat - Week 16, 2026$1.43 billion, taken by subverting what the signers saw before they approved. Radiant had lost $58 million to that same pattern months earlier, with a published post-mortem anyone could read. The intelligence existed. Acting on it was nobody’s job.
Covered in BlockThreat - Week 8, 2025Signers were worked in person, at conferences, over six months. Nothing looked like an attack until the signing request arrived. No one in this industry had previously had to treat a handshake at a side event as an intrusion path. Now everyone does.
Covered in BlockThreat - Week 14, 2026Instead of checking controls one by one, we rank findings against who attacks projects like yours and how they operate. The result is a short list ordered by what could be existential for you.
DPRK, criminal APTs, cryptonative attackers, and insiders each have different objectives and ways in. Knowing which ones are interested in you is how you build defenses that matter.
Malicious npm packages, fake recruiter pipelines, image-based exploits delivered over Slack, signing requests forged on the way to a hardware wallet. BlockThreat publishes weekly, so the intelligence your threat model is built from is days old, not quarters.
Every finding anchors to a real incident at a comparable project: the specific misconfiguration, the specific process gap, the specific assumption that failed. Run a lending market and you get Radiant, UwU, Euler, and Sonne dissected against your own contracts, not a generic line item about validating inputs.
Most teams run all five. Training is regularly delivered on its own, and a standalone tabletop works too, though it is sharper once a threat model exists to build the scenario from. Scope is agreed before anything is signed.
Less a module than the layer the other four run on. Current threat actor profiles, their live tactics, and the incidents at comparable projects are delivered as briefings your whole team attends and used as the input that ranks every finding the engagement produces. Built from your stack, not a generic deck.
Technical interviews across smart contracts, infrastructure, key management, and personnel, plus a review of your documentation, dependencies, and past audits. The output maps every threat to your architecture, with severity, probability, and the mitigations that answer each one.
An honest assessment of whether you could detect, triage, and contain a live incident today. Monitoring coverage, alerting, escalation paths, who holds the pause key, and how long it actually takes to use it.
Closer to a Dungeons & Dragons session than an exam, and deliberately so. Four to five hours of guided scenario built against your own architecture, with timed injects that escalate: a malicious governance proposal, a social media meltdown, an attacker negotiating onchain, a compromised insider, a call from the FBI. You find the gaps here rather than at three in the morning.
Everything learned, turned into a prioritized 30/60/90 day roadmap with cost estimates, owners, and a shortlist of the specific vendors worth buying for each gap. The thing you present to your board, not a list of complaints.
Scope is tailored to your architecture. We examine the onchain, operational, and human systems an attacker could use to create an existential loss.
Core protocol, privileged controls, and asset movement.
Consensus, validators, and production network operations, where applicable.
How high-impact decisions are authorized and independently verified.
Trust inherited from integrations and external providers.
The systems that build, host, operate, and monitor the product.
The access, endpoints, and processes attackers target around the technology.
Not a slide deck and a goodbye. These are working documents, written to be maintained by your team long after the engagement closes.
A living map of every component, threat, and mitigation, prioritized using current incident data. It guides future audit scopes, hiring, policy, and incident response long after the engagement.
Severity guidelines, triage process, incident roles, war room procedure, and a contact book. Shipped with an incident template and a playbook template so your team can keep writing playbooks for scenarios only you know about.
The scenario as run, what your team did, where the response stalled, and what to fix. Usually the single most uncomfortable and most useful artifact of the engagement.
Each mitigation tied back to the threat it answers, sorted by urgency and cost, with concrete monitoring heuristics and named vendors where buying beats building.






Keep running them. The three incidents above are what happens when a whole industry gets good at auditing. An audit certifies the code in front of it at a moment in time. It does not cover the laptop that signs your multisig transactions, the Discord message that carried the spell address, the contractor you hired last month, or how long it takes your team to reach a signer at 3am on a Sunday. That is what this covers.
An OPSEC audit typically tests a known set of controls at a point in time. This engagement models the whole system: how contracts, keys, governance, infrastructure, people, and dependencies interact, where one failure can compound another, and which risks matter most given current attacker behavior. The result is a prioritized security program, not a longer checklist.
Close, but a different shape. A fractional or virtual CISO is usually a standing part-time seat on your org chart, billed monthly for as long as you want one. This is a scoped engagement with a defined end: agreed modules, a fixed maximum number of hours, and four documents your team owns afterwards. Teams that want the relationship to continue move to an advisory retainer once the roadmap exists, which is the point where a part-time CISO finally has something to run.
Yes. Engagements have covered L1 and L2 chains, wallets and wallet infrastructure, custodians and exchanges, staking and restaking protocols, node operators, DAOs and foundations, and the offchain infrastructure behind all of them. The modules do not change. The threat model does, because a chain’s validator set and a custodian’s key ceremony fail in entirely different ways.
Advisory. No deployment, no configuration changes, no signing duties, no access to your production systems or keys. It is not a retained incident response service either, though the tabletop is built to make that call go better when you need it. You get the analysis, the plan, and the priorities; your team keeps control of everything that touches production. Where a mitigation is better bought than built, the plan names the vendors worth evaluating.
It does not. Teams have started this with nothing but audited contracts and a group chat, and teams have started it with a full security function wanting a second opinion on their threat model. What matters is that someone on your side can own the follow-through, because the roadmap is only worth what gets done with it.
Hourly, against a capped number of hours per module, agreed before anything starts. The total depends on scope, system complexity, and how many modules you want. Send the form below and you will get a written proposal with the hours, the modules, and the fixed maximum.
What you have built, whether a protocol, a chain, a wallet, or the infrastructure under them. What worries you, and when you need it done by. You will get an honest read on whether this is the right thing to spend money on, including if it is not.