Metaluxo
BLOCKCHAIN SECURITY

The security problems crypto companies actually fail at

Blockchain companies are rarely short of people who can read Solidity. What they lack is someone accountable for security across the whole organisation: the exchange accounts, the cloud, the staff laptops, the third parties, the regulator and the board.

Book a free 30-minute consultation
30–40HOURS A MONTH
~4 wksTO A GAP ASSESSMENT
12 hEMERGENCY RESPONSE
1NAMED PERSON, NOT A TEAM
01

What we do

Most losses at crypto companies are not exotic. They are compromised credentials, poor key handling, an insider with too much access, a supplier with too much trust. Those are governance failures, and governance is what we do.

Security leadership. The same virtual CISO function we provide elsewhere, applied to a company whose crown jewels are keys rather than a customer database.
Key management and custody governance. Policy and controls around cold storage, multisig, MPC and hardware security modules. We advise and review; your engineers implement.
Access and insider risk. Separation of duties, approval thresholds and joiner-mover-leaver processes for an environment where a single person with the wrong access can be catastrophic.
Third-party risk. Custodians, node providers, bridges, oracles and infrastructure vendors, assessed as the dependencies they are.
Compliance. ISO 27001 and SOC 2, which enterprise partners and banking counterparties increasingly require before they will work with a crypto business.
Incident readiness and response. Incident response planning, tabletop exercises and incident command, with the regulatory notification clocks tracked properly.
02

Where the regulation touches security

Two EU regimes put security squarely in scope for crypto businesses.

Crypto-asset service providers fall within DORA (Regulation (EU) 2022/2554), applicable across the EU since 17 January 2025, covering ICT risk management, incident reporting, resilience testing and third-party oversight.

MiCA (Regulation (EU) 2023/1114), applicable to crypto-asset service providers since 30 December 2024, connects to it directly. An authorisation application must describe the applicant’s ICT systems and security arrangements (Article 62(2)(j)), and a CASP’s governance must maintain resilient and secure ICT systems in line with DORA (Article 68).

Those technical and security sections are work we can do. The rest of MiCA is not ours. Authorisation strategy, white papers, licensing and the relationship with your national competent authority need a MiCA specialist or a law firm, and we expect to work alongside one rather than in place of one.

03

Commissioning an audit you can trust

We do not audit smart contracts. What we do is make sure the audit happens properly, which is a different job and one most companies buying their first audit have nobody to do:

Scope it before you ask for quotes. Which contracts, which commit, which dependencies, and whether the economic assumptions are in scope or out. Quotes are incomparable until this is written down.
Judge the auditor on published work. Contract auditing is a specialism with a public track record. Ask for reports on comparable systems and read the findings, not the client list.
Understand what the report does not cover. An audit is a point-in-time review of specific code. It says nothing about your keys, your cloud, your staff or the next deployment.
Act on the findings, and re-test. Findings get filed more often than fixed. We track remediation to closure and make sure the re-test actually happens.

We are familiar with the automated scanning tools in common use and where their limits lie. We also do not design cryptographic protocols or review consensus mechanisms — if that is your requirement, you need a cryptographer, and we will say so.

04

Our experience here

We are direct about this. Our depth is in security leadership, governance and compliance, applied to companies that happen to operate in blockchain. Alongside that practice, we have worked hands-on with a small blockchain payments project, running automated smart contract scanning and establishing its security policies and operating protocols from scratch.

If you need someone with a decade of protocol security behind them, that is not us, and we would rather tell you now. If you need the person who makes sure your company does not lose its keys to a phishing email, that is exactly us.

WHAT WE DO NOT DO Being told you need someone else is part of what you are paying for
Not a smart contract auditor A distinct specialism with its own tooling and its own public track record. Companies that claim it without the evidence are easy to spot. We scope the audit, help you choose the firm and hold the findings to closure.
Not cryptographers We do not design cryptographic protocols or review consensus mechanisms. If that is the requirement, you need a specialist and we will say so.
Not MiCA counsel We prepare the ICT and security sections your application must describe. Authorisation strategy, white papers and your competent authority need a MiCA specialist or a law firm.
FAQ

Questions we get asked

Can you audit our smart contracts? No. We help you select an auditor, scope the engagement and act on the findings.
Can you handle our MiCA authorisation? Only the security part. We can prepare the ICT systems and security arrangements your application has to describe. For the authorisation itself you need a MiCA specialist or a law firm, and we work alongside them.
Do you work with DeFi protocols? Our focus is regulated businesses: exchanges, custodians, wallet providers and payment firms. Unregulated protocol work sits outside what we do well.
Can you help us get ISO 27001? Yes. That work is the same as for any other company, and it is set out on the compliance page.
We have been hacked. Can you help right now? Possibly. See emergency response for how that works and what we commit to.
RELATED SERVICES Virtual CISO → Compliance → Emergency response →

Book a free 30-minute consultation

Tell us what your company does, who is asking you for security assurances, and what worries you most. We will tell you whether we are the right people for it.

blockchain@metaluxo.com
FIRST CALL 30 MIN
That did not go through. Please write to blockchain@metaluxo.com directly — we will still reply within a working day. Thank you — your message is on its way. Roberto replies within one working day. No slide deck, no discovery call chain — one conversation with Roberto.
Who it is for

Sectors we do this in

FintechPayments and financial data companies under DORA and ICT risk rules
Send us a message
Message us Book now