602-725-2818Licensed, insured & bondedSchedule a Consultation
Call 602-725-2818Consultation

Cyber Services

Blockchain Consulting

Web3 development, security practice and routing guidance — short of investment advice.

SDVOSBCertified
9FNE2CAGE Code
24 / 7 / 365SOC Monitoring
In-HouseForensic Capability

Guidance on the technology, not on the trade

Organizations moving into digital assets face a security problem before they face a market one. Key custody, contract review, transaction routing and internal control are where losses actually occur, and they are engineering questions rather than financial ones.

That is the boundary we work inside. We advise on development practice, security architecture and routing, and we do not advise on what to buy, hold or sell. If you need investment advice, you need a licensed financial advisor, and we will say so.

What is included

Web3 Development Practice

Architecture and development guidance for teams building on-chain, with security designed in.

Security Practice

Key custody, wallet architecture, signing policy and internal control over transaction authority.

Routing Guidance

How transactions move, which intermediaries carry which risk, and where exposure concentrates.

Contract & Counterparty Review

Technical review of contracts and counterparties before funds or code are committed.

Who this is for

  • Startups building on-chain
  • Corporate treasury
  • Law firms
  • Family offices
  • Compliance teams

What this is, and what it explicitly is not

This is security and risk advisory for organisations that hold, accept, move or are exposed to digital assets. It covers custody and key management, controls, compliance exposure, vendor diligence and incident readiness.

It is not investment advice. We do not advise on what to buy, what to hold or what anything is worth. We do not manage assets, we do not take custody, we are not investment advisers or broker-dealers, and nothing here is a recommendation to transact. If your question is whether to be in this asset class at all, that is a conversation for a licensed financial professional and for your accountant.

The question we answer is narrower and, for most organisations, more urgent: given that you already hold this, or are about to accept it, or your treasury has exposure to it — how do you not lose it, and how do you not create a compliance problem in the process.

Custody, keys, and the failure that actually happens

Almost every catastrophic loss of digital assets is a key management failure. Not a broken cryptographic algorithm — a key that one person controlled, or that nobody could find, or that was signed away by an employee who was tricked into approving a transaction.

Custody decisions are the first thing we work through with a client. Self-custody means you hold the keys and the entire responsibility. Third-party custody means somebody else does, and your risk becomes their solvency, their security and their jurisdiction — which is a real risk with a well-documented history rather than a theoretical one. Most organisations end up with a mix, and the mistake is arriving at that mix by accident.

Where self-custody applies, the controls that matter are unglamorous and decisive: multi-signature or threshold arrangements so no single person can move funds alone; hardware-backed key storage; documented and tested key generation and backup procedures; geographically separated backups; and — the one nearly everyone gets wrong — a tested recovery process, including what happens when the person who set it up leaves, is incapacitated, or dies. An organisation that cannot describe how it would recover access without one named individual does not have custody; it has a dependency.

Alongside that: transaction approval workflow with limits and separation of duties, whitelisted destination addresses, test transactions before large transfers, and a hard rule that approval requests are verified out of band. Approval-based theft — where a user is induced to sign a transaction or grant a token allowance — is now one of the most common loss routes, and it defeats every control that assumes the attacker needs the key.

Compliance exposure, which arrives sooner than people expect

Sanctions. Sanctions obligations apply to digital asset transactions as they do to any other. Specific addresses and services are designated, and receiving funds from a sanctioned source is a problem for the recipient. Organisations accepting digital assets need screening at the point of receipt and a documented process for what happens on a hit — not discovered after one.

Money transmission. Depending on what an organisation does with customer funds, it may fall within federal or state money transmission regimes with registration and licensing consequences. This catches businesses that did not think of themselves as financial services at all. It is a legal determination, and our role is to flag the exposure early enough for counsel to make it.

Recordkeeping, tax and accounting. Transaction-level records, cost basis and reporting obligations. We are not your accountants and we will say so — but the systems and records have to support them, and that is a controls question.

Sector overlays. Where an organisation is already regulated, existing obligations reach the digital asset activity too rather than sitting beside it.

Counterparty and vendor diligence

The exchange, custodian, bridge or payment processor you rely on is a concentration of risk, and the last several years have provided a long list of examples. Diligence covers corporate structure and where it actually sits, ownership and principals, regulatory registrations and their real scope, proof-of-reserve claims and what they do and do not evidence, terms of service — specifically what happens to your assets in an insolvency — security posture and audit history, and the operational question of whether you could withdraw at scale on a bad day.

This runs alongside our corporate due diligence practice, and where source of funds matters, alongside blockchain analysis.

Incident readiness, because the response window is minutes

Digital asset incidents move faster than any other kind. Funds are irreversible and can be through a bridge and into a mixer within minutes of a compromise. That makes the pre-written plan disproportionately valuable.

Readiness work covers: who is authorised to declare an incident and act; the immediate containment steps for a compromised key or an over-permissive approval, including revocation; who contacts which exchanges and how, given that a freeze request at 3am on a weekend has to reach someone; preservation of evidence before anyone starts changing things; the notification path to counsel, insurer, regulators and customers; and — where the exposure is material — a tabletop exercise so the first attempt is not the real one.

Where an incident has already happened, the work moves to forensic tracing, cyber investigation for attribution, and digital forensics on any device or account involved.

How it is priced

Assessment engagements are quoted per engagement from the scope of activity, the number of custody arrangements and counterparties, and whether policy and procedure drafting is included. Ongoing advisory runs on a retainer. Incident readiness and tabletop facilitation are quoted separately.

Included: current-state assessment, a written report with prioritised findings, and recommendations with owners and cost bands. Quoted separately: policy and procedure drafting, counterparty diligence, tabletop facilitation, and any forensic or investigative work.

Investigative work in Arizona is licensed under A.R.S. Title 32, Chapter 24; Honeybadger holds Private Investigations Agency licence 1759795. Nothing on this page is legal, tax or investment advice.

Frequently asked questions

Will you tell us which assets to hold?

No. We are not investment advisers and this is not investment advice. Our work is custody, controls, compliance exposure, counterparty risk and incident readiness — how not to lose what you already hold and how not to create a regulatory problem holding it.

Should we self-custody or use a custodian?

It depends on amounts, frequency of movement, internal capability and your risk appetite — and most organisations should be deliberate about a mix rather than arriving at one by accident. Self-custody moves the risk to your key management; third-party custody moves it to their solvency and jurisdiction.

What is the most common way organisations lose funds?

Key management and transaction approval, not cryptography. A single person controlling a key, an untested recovery process, or an employee induced into signing a transaction or granting a token allowance. Approval-based theft defeats every control that assumes the attacker needs the key itself.

Do we need sanctions screening if we accept crypto?

Almost certainly. Sanctions obligations apply to digital asset transactions, specific addresses and services are designated, and receiving from a sanctioned source is the recipient’s problem. Screening at receipt and a documented process for a hit is the minimum defensible position.

Could we be a money transmitter without realising?

It happens, particularly for businesses that handle customer funds as part of a wider service and never thought of themselves as financial. It is a legal determination for your counsel — our role is to flag the exposure early enough that the question gets asked before a regulator asks it.

What if the person who set up our wallets leaves?

That is the test, and a great many organisations fail it. If recovery depends on one individual’s knowledge, device or presence, you have a dependency rather than custody. Documented, tested, multi-party recovery is the fix, and it should be tested rather than assumed.

Blockchain Solutions

Blockchain is quickly becoming the future; this is not strictly limited to cryptocurrency. Blockchain technology is used in VPNs (Virtual Private Networks), messengers, voice calls, encryption platforms, and is what Web3 is being built on. The idea is that decentralization enhances user privacy and security while offering complete transparency. That being said, there are several instances where blockchain is used for malicious purposes; the skill to interpret these activities needs to be more & far between.

WHY ASSESSING MANAGEMENT CAPABILITIES?

Blockchain Forensics Stolen assets utilizing bad actors are becoming increasingly common; it is a FACT that no world government can take on these crimes. This is a multi-billion dollar yearly industry and has destroyed families across the globe. Our services aim to track the flow of cryptocurrency, and we work with applicable law enforcement agencies. Currently, we mainly coordinate with the USSS (U.S. Secret Service), and in more significant cases, HSI (Homeland Security Investigations); for smaller cases, we work with local law enforcement.

Expert Witness Services In conjunction with the forensic aspect, expert witness services are almost a requirement in the industry; however, very rarely does a firm offer expert services in legal matters as well as the forensic aspect of cryptocurrency.

Blockchain Consulting We offer blockchain consulting, which effectively encompasses everything short of investment advice. We are experts in the inner workings of blockchain. Web3 development, proper security practices to avoid malicious incidents, and adequate routing are all examples of what we do.

Scope your requirement

Tell us what you are building or holding and what worries you about it. To be explicit: this engagement covers technology, security and process. It is not investment advice and does not substitute for a licensed financial advisor.