Web3 Incident Response & Recovery Advisory
Authorized defensive response to an on-chain incident: reconstructing what happened from public transaction data, containing further loss, preserving evidence and coordinating with exchanges and providers — without ever promising funds back.
Verified Solvex Specialist
Verified by SolvexDirect specialist contact for Solvex engagements
What this means. An authorized Solvex administrator registered and approved this exact public identity. What it does not. Solvex has not inspected the account on the platform, and this is not the platform's own verification.
Solvex specialists never ask for your passwords, recovery phrases, one-time codes, or payments to a personal account. Work, scope and invoices are agreed in writing through the official channels on this site.
Signed authorization required. This engagement is performed only against systems you own or are contractually authorized to have tested, under an agreed scope. See the responsible testing policy.
What's covered
- Incident reconstruction from public on-chain data
- Transaction tracing and movement analysis across the affected addresses
- Wallet and contract exposure analysis for continuing risk
- Smart-contract incident analysis where a contract was involved
- Containment planning: what to pause, revoke, rotate or move, and in what order
- Evidence preservation suitable for law enforcement or insurers
- Coordination guidance for exchanges, bridges and infrastructure providers
- Post-incident hardening recommendations
What you receive
- Incident timeline reconstructed from verifiable on-chain evidence
- Traced movement analysis with transaction references
- Containment action list, prioritised by what stops loss soonest
- Evidence package suitable for law enforcement or an insurer
- Exchange and provider coordination guidance
- Post-incident hardening plan
Evidence and reporting
How the work is kept honest- Evidence, frozen at issuanceFindings tie to something observed. When the report is issued, the evidence behind it is frozen in the same transaction and cannot be edited afterwards.
- A signed reportAn Ed25519 signature covers both the report content and the delivered file. Alter a byte of either and verification fails.
- Signed scope firstTesting starts only after written scope and signed authorization for systems you own or are entitled to have tested.
Anyone holding a Solvex report can verify it publicly without seeing its contents.
Our boundaries
What this engagement does not do, stated before it starts.
- We never take custody of wallets, keys or funds, and never ask for a seed phrase
- No promise of recovery — on-chain transactions are final, and most stolen funds are not returned
- We do not hack back, seize assets or interfere with third-party wallets
- Legal action and law-enforcement outcomes are outside our control
How this engagement runs
- 01
Intake
Tell us the system, the goal and the constraints. If the work is not a good fit, we say so before anyone is invoiced.
- 02
Scope and authorization
Written scope and signed authorization before anything is touched. Security testing runs only against systems you own or are contractually entitled to have tested.
- 03
Investigation or build
Specialists matched to the work. Findings are proven by hand — scanner output is a lead, never a finding.
- 04
Evidence
Every finding ties to something observed. When a report is issued, its evidence is frozen in the same transaction, so what backed the report cannot change afterwards.
- 05
Delivery
A signed report: an Ed25519 signature over both the content and the file, with a short verification reference you can read down a phone.
- 06
Verification and retest
Anyone holding the report can verify it publicly without seeing its contents. Fixes are retested as part of the engagement — “fixed” means we confirmed it.
Questions we are asked
- Can you get our funds back?
- Almost certainly not, and we will say so before you engage rather than after. On-chain transfers are final. What genuinely helps is speed on containment, credible tracing, and an evidence package that exchanges and law enforcement can act on. Anyone guaranteeing recovery is exploiting a bad day.
- What should we do in the first hour?
- Stop the bleeding before investigating: revoke approvals, pause what can be paused, move remaining assets to a wallet whose keys were never on the compromised machine, and stop using that machine. Preserve everything — do not wipe and reinstall. Then call us.
- Do you work with law enforcement?
- We prepare evidence in a form they can use and support your counsel in submitting it. We are not law enforcement and cannot compel any exchange to freeze anything, though a well-documented, promptly filed report materially improves the odds of a freeze landing in time.
Related services
DFIR & Forensics
24/7 Incident Response Retainer
When an incident hits, every minute counts — and you don't want to be finding a responder then. A retainer gives you a pre-agreed expert team on standby, guaranteed response times, and people who already know your environment.
DFIR & Forensics
Digital Forensics Investigation
When you need to know exactly what happened — and prove it — our forensic examiners recover and analyse digital evidence with rigorous chain of custody. Findings that stand up to scrutiny, whether for internal, regulatory or legal use.
Web3 & Emerging
Token Launch & Web3 Security Readiness
A pre-launch readiness review covering the things that go wrong on day one — admin privileges, upgradeability, oracle dependencies, deployment process and whether anyone is actually watching after the launch window closes.