All Solutions
11

Incident Response & Forensics

Blockchain incident response and forensics for protocols and exchanges after a hack. We reconstruct the attack path through your systems and trace stolen funds across chains.

REQUEST INCIDENT RESPONSE

THE CHALLENGE

Many teams cannot say how they were attacked.

After a hack, the first question is how the attacker got in. Until you know the entry point, you cannot close it, and the attacker may still have access. Evidence sits across cloud accounts, CI/CD systems, signing infrastructure and third-party vendors, and some of it disappears within days.

Blockchain incident response and forensics answers two questions. How did the attacker get in, and where did the funds go. The first comes from your logs, infrastructure, keys and code. The second comes from the chain.

HOW IT WORKS

Our Process

01

Triage and Containment

We confirm the incident, secure logs and system images before they are overwritten, and advise on stopping further loss.

02

Evidence Collection

We gather cloud audit trails, CI/CD history, endpoint data, access records and transaction history, and document who handled each item.

03

Attack Reconstruction

We build a timeline from first access to the final transaction and identify the entry point, the privilege escalation and the control that failed.

04

On-Chain Fund Tracing

We follow stolen funds across addresses, bridges, mixers and exchanges, and flag the deposit addresses where a freeze can be requested.

05

Reporting and Remediation

You receive a written report with the timeline, root cause and fund flow map, organized for law enforcement and exchange compliance teams, plus the fixes to close the gap.

Insight

Coming Soon: Incident Response Playbook for DeFi Teams

What to preserve in the first hour after a hack, and what destroys evidence.

COMING SOON

FAQ

Frequently Asked Questions

Ready to get started?

Tell us about your project and we'll scope the right engagement for your team.

REQUEST INCIDENT RESPONSE