Skip to content
Blueprints / BP-18 · CASPs, neobanks & brokers

On-Chain Threat Monitoring With Pre-Authorised Automated Response

A regulated institution holding crypto-assets on public chains sets a written matrix in advance: which signals trigger which responses, which of those execute with no human in the path, and the limits that bound them. A defined class of threat is then answered in seconds - and every response is bounded by authority the monitoring provider does not hold.

Maturity
Emerging
Model
Threat monitoring
Proven stack
Hypernative · Blockaid · Utila · Fireblocks
Last verified
August 2026

Reviewed by Andrei Yurkevich, Founding Member at Protofire

Trusted across 60+ networks and 95+ protocols
USD 19.3M saved, USD 128M lost

in the same incident: Balancer's automated controls paused all pausable v6 pools across nine chains within minutes on 3 Nov 2025, while losses fell in v5 pools whose pause windows had expired.

The automation worked exactly as configured; the loss came from a configuration that had expired, and detection itself did not fail. No named regulated EU institution is publicly evidenced running the full delegation configuration.

01. The regulatory position

DORA (Reg. 2022/2554) Art. 10 detection mechanisms with alert thresholds triggering incident response, tested under Art. 25; Arts. 17-19 incident management, classification and reporting with major incidents notified within 4 hours of classification and no later than 24 hours after detection, on the criteria in Del. Reg. (EU) 2024/1772; Arts. 28-30 for ICT third-party risk, with Del. Reg. (EU) 2024/1773 Arts. 8(2)(b) and 8(3) on subcontracting, pooled audits and the prohibition on sole reliance on certifications. MiCA (Reg. 2023/1114) Arts. 70 and 75 on safekeeping, segregation, custody policy and liability for loss - the boundary the delegation must respect - and continuity under Del. Reg. (EU) 2025/299. Real-time risk monitoring and automated response are not MiCA-named obligations; this is an operational-resilience control evidenced under DORA, and presenting it as a MiCA requirement is an overclaim.

02. Who's already done this

Market references, not our clients
kpk
Not a regulated financial institution - a digital-asset manager operating non-custodial mandates

An exit agent with bounded, auditable permissions, triggered by a Hypernative event calling the agent's API. During the Resolv exploit - undated in public sources - in which about 80 million USR was minted against near-zero collateral, the agent acted without human intervention. The cleanest public evidence of the full pattern rather than its detection half, and the clearest statement of the design constraint: the agents are logic-based programmes with limited permissions.

Balancer
None - a decentralised protocol with a security council · Live 3 Nov 2025

Automated emergency controls paused all pausable Composable Stable v6 pools across nine chains within minutes of first detection, protecting about USD 19.3 million. Instructive for what it did not protect: losses above USD 128 million fell in pools whose pause windows had expired.

Edge Capital Group
A market-neutral fund reported at over USD 700 million AUM, with partners including Swiss banks and US ETF providers; its own licence status was not established from public sources

Pre-transaction simulation and real-time policy enforcement across Fireblocks, Fordefi and internally managed wallets, at an average of about 300 transactions per day, replacing a manual spreadsheet framework of protocol-specific rules. The closest available analogue to an institutional operating model, running the pre-signature enforcement limb at daily volume rather than as an incident-only control.

Kraken (Payward Europe Solutions Limited)
MiCA CASP authorised by the Central Bank of Ireland, 25 June 2025; scope of services as recorded on the ESMA register

A named client of Blockaid's transaction screening, within a provider-reported set including Coinbase, MetaMask, Uniswap, Fireblocks and Safe. The only row with unambiguous EU regulatory footing, and it evidences the detection limb only - which configuration Kraken operates, and whether any response is automated, is not public.

03. Why this is on the agenda

On 3 November 2025, during the exploit of Balancer's Composable Stable pools, automated emergency controls paused every pausable v6 pool across nine chains within minutes of first detection, protecting about USD 19.3 million. Losses above USD 128 million fell in pools whose pause windows had expired.

The incident shows both halves of the pattern. The automation fired correctly, and the outcome then turned on whether the emergency controls it acted through were still alive, which is a configuration and lifecycle question the institution owns and no vendor does.

The obligation is now explicit. DORA has applied since 17 January 2025, and Article 10 requires mechanisms to promptly detect anomalous activities, with alert thresholds and criteria that trigger incident-response processes, tested under Article 25. A test that confirms an alert was raised but never exercises the automated action leaves the response half unevidenced.

04. Does it fit?

Yes, if the institution holds a MiCA CASP authorisation, a banking licence with crypto permissions or an e-money authorisation; operates its own custody or signing arrangement with an approval interface that can act on an external verdict; and has a management body prepared to approve a standing delegation of authority with named limits.

No, if the concern is counterparty identity rather than transaction behaviour (that is the compliance operating stack); if what is needed is a preventive gate on issuance against reserves (that is mint governance, where the contract-level invariant does the work); or if the management body will not delegate a business-stopping action to automated authority. That last case is the most common real blocker, and it is a governance question for the management body.

One caveat to weigh: an automated response is itself a source of loss. A false positive can unwind a position at a bad price or halt a service, and the institution's liability under MiCA Article 70 is the same whether the control fires, fails to fire, or fires wrongly. Neither anchor component publishes a liability cap, a service level, or any commitment as to detection efficacy, so the limits should be sized on the assumption that there is no recourse.

05. The stack, layer by layer

Most of these layers can be rented from a named vendor, and usually should be. The part that matters is the one layer you have to own yourself.

Yours

The authorisation, the signing arrangement and the delegation

The authorisation and the client-asset liability with it, a custody or signing arrangement with an approval interface, a management body able to grant a standing delegation, an incident process and supervisory reporting channel, and the risk appetite statement the limits derive from. The delegation decision - what the machine may do without a human - is the thing nobody rents.

Rented

Detection and pre-signature simulation

Continuous detection across contracts, positions and pending transactions, pre-signature simulation and a scored verdict over an API, and a risk-pattern catalogue maintained against a moving threat picture. Not included: no keys, no signing authority, no limits, no delegation, and no commitment that a threat will be detected - best-effort detection is the norm at this layer.

HypernativeBlockaidGauntletChaos Labs
Ours

The matrix, the execution path and the liveness check

The thresholds-to-actions matrix, with limits enforced where the provider cannot reconfigure them; the verdict-to-execution path and its behaviour when no verdict arrives; the liveness check that makes a silent failure visible; DORA Art. 25 testing and the evidence it produces; and out-of-hours cover for what the automation may not do. The institution keeps ownership of the policy and rents the detection engine underneath it.

Yours, never rentableRented from a named vendorBuilt and run by Protofire

06. Why this stack

Two components run detection wired to enforcement inside institutional custody arrangements, not only as an alerting feed, and both integrate into the same custody infrastructure, so in practice they can be swapped for each other. Detection state is held as rules and thresholds, so moving between providers is a re-implementation and running two of them at once is inexpensive.

The component no vendor supplies is the policy and limit engine. The limits have to be enforced by authority the detection provider does not hold, so they are built by the institution or configured inside a custody arrangement it already controls. This is also what holds the readiness rating where it is: enabling automated response turns a monitoring component into a privileged instruction source, and the only thing containing it is a limit the provider cannot change.

On the parameter-risk layer the institution keeps the policy and rents the engine. Chaos Labs was Aave's primary risk manager from November 2022 until its exit announced 6 April 2026. A risk mandate can be withdrawn for commercial reasons at short notice, and an architecture that assumed otherwise carries that as a single point of failure.

Request the full blueprint

This is the short version. The full blueprint is a single document your counsel and board can read cold, and a third-party-risk function can lift wholesale. Leave your work email and your personal link arrives in your inbox.

What is inside
  • The regulatory position, stated article by article
  • Proven options at each layer, with the vendors that hold up
  • The risk table with a named owner for each risk
  • The division of labour: what is rented, built, and operated
  • The third-party-risk pack a DORA governance function can lift
  • The delivery path, step by step, with the monitoring and incident model

FAQ

Is real-time risk monitoring with automated response a MiCA requirement?

No. In the Acting on an On-Chain Threat pattern, real-time risk monitoring and automated response are not MiCA-named obligations, and presenting them as a MiCA requirement is an overclaim. They are an operational-resilience control evidenced under DORA (Reg. 2022/2554), specifically Art. 10 detection mechanisms tested under Art. 25, and Arts. 17-19 incident management, which require major incidents to be notified within 4 hours of classification and no later than 24 hours after detection. MiCA Arts. 70 and 75 set the custody and liability boundary the delegation must respect.

What incident shows pre-authorised automated response working?

On 3 November 2025, Balancer's automated emergency controls paused all pausable Composable Stable v6 pools across nine chains within minutes of first detection, protecting about USD 19.3 million. In the same incident, losses above USD 128 million fell in pools whose pause windows had expired. The automation worked exactly as configured, and the loss was a configuration expiry rather than a detection failure. Separately, during the Resolv exploit an exit agent triggered by a Hypernative event acted without human intervention.

Who is pre-authorised automated response not for, and what does the institution build?

It is not for institutions concerned with who the counterparty is rather than what the transaction does, nor for those whose management body will not delegate a business-stopping action to automated authority, for whom the detection half is still worth building. The institution owns the authorisation, the signing arrangement and the standing delegation, which is the thing nobody rents. It rents detection and pre-signature simulation from providers such as Hypernative, Blockaid, Gauntlet or Chaos Labs. It builds the thresholds-to-actions matrix, the verdict-to-execution path, and the liveness check that makes a silent failure visible.

Already evaluating this for your institution?

When you are ready, we scope a business case on your own numbers: the costed build, the controls, the SLA and the ROI your board needs to approve it. Or talk it through first.

Run this pattern in production, or tried to and stopped? .

Related readingMint governance & reservesCrypto custody approachesManaged on-chain operations

Protofire 2026. All rights reserved

Message us on Telegram