Solutions · Digital Asset Operators

Know exactly where customer funds can leave.

We review signing, approval, and recovery paths for exchanges, custodians, wallets, and stablecoin operators.

When this fits

The moments where an operator's exposure changes.

Before the signing lifecycle changes

A new signer set, custody vendor, or automation path changes who can move funds.

Before a new product or listing goes live

New assets, chains, and flows widen the surface faster than the controls around them.

When recovery has never been rehearsed

A recovery model nobody has executed under pressure is a document, not a control.

After a near miss

Reconstruct what nearly worked, and what would have stopped it one step earlier.

Where it breaks

Four places operators lose control of value.

Deposits and treasury are rarely where funds go missing. The exits are hot wallets, approval, and payout, and the way in is usually identity.

Customer value moving through an operator from deposit to hot wallet, treasury, withdrawal approval and payout, with the three stages where funds can actually leave marked

Three of five stages are exits. The other two are how an attacker reaches them.

01

Deposit & crediting

Reorgs, wrong-chain deposits, double credits, and the accounting that trusts them.

02

Hot wallet & automated signing

Float sizing, key access, signing services, and what an attacker gets from one host.

03

Withdrawal approval

Quorum, allowlists, velocity limits, break-glass, and who can change any of them.

04

Recovery & key ceremony

Share custody, ceremony witnesses, and whether recovery has been executed end to end.

Recommended starting engagements

Choose the best starting point.

Typical engagement team

Who typically leads this work

Two of these three have run security inside an operating company rather than only reviewing one, starting with funding and custody at Kraken.

The exact team depends on the scope. Every engagement has a principal who owns it from scoping through delivery, joined by the specialists the system calls for, and whoever is assigned is named in your proposal.

Michal Bajor portrait

Michal Bajor

Specialist Advisor

Secured funding, custody, APIs, and on-chain systems at Kraken. Has reviewed 60+ Web3 projects across DeFi, L1s, bridges, oracles, and other critical infrastructure.

Piotr Cielas portrait

Piotr Cielas

Principal Advisor

Head of Security at Agora, responsible for security, data protection, and corporate IT risk. Earlier at EY, led assessments across financial services, healthcare, and government.

Currently

Head of Security, Agora

$45B+ in volume

Timur Güvenkaya portrait

Timur Güvenkaya

Founder & Partner

Led a security engineering practice for Rust and non-EVM systems across Substrate and NEAR. Earlier, built vulnerability-detection engines at Invicti used by Fortune 50 and public-sector organizations.

Meet the full team

Other organizations we work with

Tell us what you need to secure.

Share the signing model, custody vendors, approval flow, and volumes. We will reply with the next questions and a likely scope. If a review is not the right next step, we will say so.

Discuss your scope