Before the signing lifecycle changes
A new signer set, custody vendor, or automation path changes who can move funds.
Solutions · Digital Asset Operators
We review signing, approval, and recovery paths for exchanges, custodians, wallets, and stablecoin operators.
When this fits
A new signer set, custody vendor, or automation path changes who can move funds.
New assets, chains, and flows widen the surface faster than the controls around them.
A recovery model nobody has executed under pressure is a document, not a control.
Reconstruct what nearly worked, and what would have stopped it one step earlier.
Where it breaks
Deposits and treasury are rarely where funds go missing. The exits are hot wallets, approval, and payout, and the way in is usually identity.
Three of five stages are exits. The other two are how an attacker reaches them.
Reorgs, wrong-chain deposits, double credits, and the accounting that trusts them.
Float sizing, key access, signing services, and what an attacker gets from one host.
Quorum, allowlists, velocity limits, break-glass, and who can change any of them.
Share custody, ceremony witnesses, and whether recovery has been executed end to end.
Recommended starting engagements
Start here. This is the review that follows a key from generation to recovery and challenges every gate on the way.
Explore service → Also relevantUse this when the question is what an attacker reaches from the outside, or from one compromised employee.
Explore service → Also relevantUse this to rehearse recovery and break-glass with the people who would actually run them.
Explore service →Typical engagement team
Two of these three have run security inside an operating company rather than only reviewing one, starting with funding and custody at Kraken.
The exact team depends on the scope. Every engagement has a principal who owns it from scoping through delivery, joined by the specialists the system calls for, and whoever is assigned is named in your proposal.

Specialist Advisor
Secured funding, custody, APIs, and on-chain systems at Kraken. Has reviewed 60+ Web3 projects across DeFi, L1s, bridges, oracles, and other critical infrastructure.

Principal Advisor
Head of Security at Agora, responsible for security, data protection, and corporate IT risk. Earlier at EY, led assessments across financial services, healthcare, and government.
Currently
Head of Security, Agora
$45B+ in volume

Founder & Partner
Led a security engineering practice for Rust and non-EVM systems across Substrate and NEAR. Earlier, built vulnerability-detection engines at Invicti used by Fortune 50 and public-sector organizations.
Other organizations we work with
Share the signing model, custody vendors, approval flow, and volumes. We will reply with the next questions and a likely scope. If a review is not the right next step, we will say so.
Discuss your scope