Crypto & Web3
Protect signing infrastructure before the transaction is irreversible
The Bybit attack ($1.5B), Ronin Bridge ($625M), and FTX collapse all trace to infrastructure compromise and insider access that went undetected. ManySignal monitors hot wallet infrastructure, HSM access, signing service APIs, and developer credentials — detecting compromise before an irreversible transaction is signed.
$3.8B
Crypto stolen in 2022 — highest single year on record (Chainalysis)
$1.5B
Bybit exchange hack — February 2025
Lazarus
North Korean group responsible for 44% of 2023 crypto theft
MiCA
EU Markets in Crypto-Assets regulation — VASP cybersecurity requirements
How ManySignal protects crypto and Web3 companies
Private key and hot wallet infrastructure monitoring
Hot wallets, signing infrastructure, and HSM access are the highest-value attack targets in crypto — Ronin Bridge ($625M), FTX ($477M), and Bybit ($1.5B) were all enabled by infrastructure compromise. ManySignal monitors access to key management infrastructure, signing service APIs, and HSM systems — detecting access by non-approved accounts, unusual signing volumes, and API calls outside normal transaction windows.
- HSM and KMS access baselining per custodial team member
- Signing service API call volume anomaly detection
- Unusual transaction initiation from signing infrastructure
Private key and hot wallet infrastructure monitoring
Smart contract deployment and admin function monitoring
Smart contract upgrades, admin function calls (pauseContract, transferOwnership, withdrawFunds), and proxy implementation changes are irreversible and high-value attack vectors. ManySignal monitors the multisig and developer wallets that control admin functions, correlating on-chain governance events with the off-chain identity signals — detecting when an admin wallet is accessed from a compromised developer account before the on-chain transaction is signed.
- Admin wallet access correlated with developer credential anomalies
- Multisig signing key access outside governance vote process
- Proxy implementation change transaction monitoring
Smart contract deployment and admin function monitoring
Exchange and custodial platform security
Centralised exchanges and custodians hold billions in customer funds and face both external compromise (employee credential theft, third-party integrations) and insider risk (trading desk access to customer order flow, ops team access to withdrawal controls). ManySignal monitors all administrative and operational access to exchange infrastructure — flagging privileged access outside approved windows and fund movement above threshold without dual authorisation.
- Exchange admin access monitoring with time-of-day constraints
- Customer fund withdrawal system access outside dual-auth workflow
- Privileged access to customer order book data by trading-adjacent staff
Exchange and custodial platform security
Regulatory frameworks supported
Crypto and Web3 security questions
How does ManySignal prevent a Bybit or Ronin Bridge-style infrastructure compromise?
The Bybit attack (February 2025) compromised a Safe multisig interface to inject a malicious transaction during the signing process. The Ronin Bridge attack used compromised Sky Mavis validator node credentials. ManySignal detects the compromise phase that precedes both: developer workstation compromise (via EDR telemetry), unusual access to signing infrastructure (KMS, HSM, multisig interface), and anomalous API calls to bridge or withdrawal services — all before the malicious transaction is submitted.
Can ManySignal monitor on-chain transactions alongside off-chain infrastructure?
ManySignal focuses on the off-chain infrastructure layer — the developer workstations, signing services, cloud infrastructure, and identity systems that control the keys that control the contracts. For on-chain monitoring, ManySignal integrates with blockchain analytics platforms (Chainalysis, TRM Labs, Elliptic) that monitor transaction patterns. The integration correlates off-chain access anomalies with on-chain transaction events.
How does ManySignal help crypto companies meet FinCEN and VASP regulatory requirements?
Crypto exchanges operating as Virtual Asset Service Providers (VASPs) under FinCEN's BSA regulations must maintain AML controls and suspicious activity reporting. ManySignal's monitoring supports the cybersecurity aspect of BSA compliance: access controls over customer transaction and KYC data, incident detection and reporting capabilities, and audit trail evidence for FinCEN examinations. For EU MiCA compliance, ManySignal supports the ICSM (ICT Security Management) requirements.
Can ManySignal integrate with AWS KMS, HashiCorp Vault, or Fireblocks for signing infrastructure monitoring?
Yes. ManySignal integrates with AWS CloudTrail for KMS API monitoring, HashiCorp Vault audit log streaming, and Fireblocks' webhook audit events. Each integration provides access baselining per operator, key usage anomaly detection, and correlation of signing infrastructure events with the identity context of the operator initiating the action.
Does ManySignal provide monitoring for DeFi protocols with complex governance structures?
ManySignal can monitor the off-chain components of DeFi governance: Snapshot voting infrastructure, Gnosis Safe multisig operator accounts, and Discord/forum-based governance communication platforms (for social engineering pre-cursor detection). Correlation between governance votes passing and unusual developer wallet access can surface pre-execution attack preparation before the on-chain transaction confirms.
Demo signing infrastructure monitoring
See HSM access baselining, Bybit-pattern attack detection, and FinCEN compliance evidence export — in one session with our crypto security team.