Incident Response & Forensics
Blockchain incident response and forensics for protocols and exchanges after a hack. We reconstruct the attack path through your systems and trace stolen funds across chains.
REQUEST INCIDENT RESPONSETHE CHALLENGE
Many teams cannot say how they were attacked.
After a hack, the first question is how the attacker got in. Until you know the entry point, you cannot close it, and the attacker may still have access. Evidence sits across cloud accounts, CI/CD systems, signing infrastructure and third-party vendors, and some of it disappears within days.
Blockchain incident response and forensics answers two questions. How did the attacker get in, and where did the funds go. The first comes from your logs, infrastructure, keys and code. The second comes from the chain.
HOW IT WORKS
Our Process
Triage and Containment
We confirm the incident, secure logs and system images before they are overwritten, and advise on stopping further loss.
Evidence Collection
We gather cloud audit trails, CI/CD history, endpoint data, access records and transaction history, and document who handled each item.
Attack Reconstruction
We build a timeline from first access to the final transaction and identify the entry point, the privilege escalation and the control that failed.
On-Chain Fund Tracing
We follow stolen funds across addresses, bridges, mixers and exchanges, and flag the deposit addresses where a freeze can be requested.
Reporting and Remediation
You receive a written report with the timeline, root cause and fund flow map, organized for law enforcement and exchange compliance teams, plus the fixes to close the gap.
Coming Soon: Incident Response Playbook for DeFi Teams
What to preserve in the first hour after a hack, and what destroys evidence.
FAQ
Frequently Asked Questions
Ready to get started?
Tell us about your project and we'll scope the right engagement for your team.
REQUEST INCIDENT RESPONSE