Past Attacks
- Private key theft
- Phishing
- Malware
- Direct intrusion
SignPath verifies transaction intent, execution path, signer authority, and policy context before digital assets move.
Built for exchanges, custodians, financial institutions, DeFi protocols, and treasury teams exposed to signer manipulation and operational workflow attacks.
Protect the path to signing — not just the key.
Why Now
Even legitimate signers and trusted systems can approve dangerous transactions through manipulated paths.
A large asset movement that appeared to pass normal approval procedures still resulted in catastrophic loss.
Exchanges, DeFi services, bridges, RPC node operators, analytics firms, VASPs.
The key may be secure, but the request reaching the signer may not be.
Source: FBI / IC3 Public Service Announcement on the Bybit incident (TraderTraitor).
Core Perspective
Once a valid signature is generated, prevention ends and incident response begins.
SignPath is the final control point before assets move.
Product Identity
We sit in front of HSM, MPC, Fireblocks, Safe, Squads, and internal signers to verify the path and intent of signing requests.
We are not a company that stores keys. We verify the path right before keys are used.
Customers
Any organization that moves digital assets or executes privileged onchain operations can be exposed to unsafe signing risk.
Independent verification before withdrawals and wallet movements.
Audit-ready signing control for institutional assets.
Protect admin, oracle, treasury, vault, governance execution.
Add a pre-sign gate to the signing workflow you already operate.
Use Cases · Exchanges
The biggest exchange risk is a large asset movement that appears to have passed normal approval procedures.
Before funds move, SignPath independently verifies the transaction, signer, path, and policy context.
Use Cases · DeFi Protocols
Audits protect contracts. SignPath protects the operational path before privileged transactions are signed.
Privileged operations protected before signing
SignPath interprets privileged EVM transactions before multisig execution.
Use Cases · Custody & Financial Institutions
Institutional digital asset operations need evidence, accountability, and control before signatures are executed.
How It Works
A transaction is signed only when the request, path, and signer are all verified.
tx_payload_hashruntime_provenance_digestsigner_idpolicy_hashNo trusted path, no signature.
Decision Outcomes
SignPath decides before signer execution — not after the transaction is broadcast.
Trusted request and path verified.
Needs manual review before execution.
Unsafe context or manipulation detected.
Fail-closed by default when trust is missing.
Before / After
Unsafe request may reach signer.
Unsafe request is held before signing.
The difference is not who signs. The difference is whether the path can be trusted.
Architecture
SignPath combines transaction payload, runtime provenance, signer identity, and policy context into one signing authorization decision.
External signer (HSM/MPC/Fireblocks/Safe/Squads/internal) that SignPath sits in front of — not a SignPath layer.
Integration
No replacement. No migration. Add a pre-sign gate to the workflow you already use.
For internal signer or hot wallet signer workflows.
Before signing API calls or MPC signing requests.
Evaluate transaction payload and context before callback approval.
Pre-sign or pre-execution verification for Safe transactions.
Interpret Solana instructions and authority changes before execution.
For exchanges, custody platforms, and internal wallet systems.
Threat Brief
DPRK-linked attackers increasingly target people, developers, infrastructure, and signing workflows — not just contracts.
Malicious repositories, fake interviews, developer environment compromise.
Social engineering through investment, partnership, or due diligence conversations.
Account takeover, CI/CD abuse, package or deployment path manipulation.
Legitimate signers approving manipulated requests.
Withdrawal requests, multisig approvals, admin actions, and treasury movements disguised as normal operations.
SignPath turns threat intelligence into pre-sign control.
Audit & Evidence
SignPath records why a request was allowed, held, or rejected.
Audit evidence is not an afterthought. It is part of the signing decision.
Pilot Program
A SignPath pilot can begin in shadow mode without interrupting production operations.
observe, no block
Start in shadow mode. Enforce only when the customer is ready.
Contact
Tell us about your signing workflow. We will help assess where SignPath can reduce unsafe signing risk before assets move.
SignPath helps exchanges, custodians, DeFi protocols, and treasury teams stop unsafe signing requests before assets move.
The safest signature is the one that never gets executed when the path is wrong.