On-Chain Threat Monitoring With Pre-Authorised Automated Response
A regulated institution holding crypto-assets on public chains sets a written matrix in advance: which signals trigger which responses, which of those execute with no human in the path, and the limits that bound them. A defined class of threat is then answered in seconds - and every response is bounded by authority the monitoring provider does not hold.
- Maturity
- Emerging
- Model
- Threat monitoring
- Proven stack
- Hypernative · Blockaid · Utila · Fireblocks
- Last verified
- August 2026
Reviewed by Andrei Yurkevich, Founding Member at Protofire
in the same incident: Balancer's automated controls paused all pausable v6 pools across nine chains within minutes on 3 Nov 2025, while losses fell in v5 pools whose pause windows had expired.
The automation worked exactly as configured; the loss came from a configuration that had expired, and detection itself did not fail. No named regulated EU institution is publicly evidenced running the full delegation configuration.
01. The regulatory position
02. Who's already done this
An exit agent with bounded, auditable permissions, triggered by a Hypernative event calling the agent's API. During the Resolv exploit - undated in public sources - in which about 80 million USR was minted against near-zero collateral, the agent acted without human intervention. The cleanest public evidence of the full pattern rather than its detection half, and the clearest statement of the design constraint: the agents are logic-based programmes with limited permissions.
Automated emergency controls paused all pausable Composable Stable v6 pools across nine chains within minutes of first detection, protecting about USD 19.3 million. Instructive for what it did not protect: losses above USD 128 million fell in pools whose pause windows had expired.
Pre-transaction simulation and real-time policy enforcement across Fireblocks, Fordefi and internally managed wallets, at an average of about 300 transactions per day, replacing a manual spreadsheet framework of protocol-specific rules. The closest available analogue to an institutional operating model, running the pre-signature enforcement limb at daily volume rather than as an incident-only control.
A named client of Blockaid's transaction screening, within a provider-reported set including Coinbase, MetaMask, Uniswap, Fireblocks and Safe. The only row with unambiguous EU regulatory footing, and it evidences the detection limb only - which configuration Kraken operates, and whether any response is automated, is not public.
03. Why this is on the agenda
On 3 November 2025, during the exploit of Balancer's Composable Stable pools, automated emergency controls paused every pausable v6 pool across nine chains within minutes of first detection, protecting about USD 19.3 million. Losses above USD 128 million fell in pools whose pause windows had expired.
The incident shows both halves of the pattern. The automation fired correctly, and the outcome then turned on whether the emergency controls it acted through were still alive, which is a configuration and lifecycle question the institution owns and no vendor does.
The obligation is now explicit. DORA has applied since 17 January 2025, and Article 10 requires mechanisms to promptly detect anomalous activities, with alert thresholds and criteria that trigger incident-response processes, tested under Article 25. A test that confirms an alert was raised but never exercises the automated action leaves the response half unevidenced.
04. Does it fit?
Yes, if the institution holds a MiCA CASP authorisation, a banking licence with crypto permissions or an e-money authorisation; operates its own custody or signing arrangement with an approval interface that can act on an external verdict; and has a management body prepared to approve a standing delegation of authority with named limits.
No, if the concern is counterparty identity rather than transaction behaviour (that is the compliance operating stack); if what is needed is a preventive gate on issuance against reserves (that is mint governance, where the contract-level invariant does the work); or if the management body will not delegate a business-stopping action to automated authority. That last case is the most common real blocker, and it is a governance question for the management body.
One caveat to weigh: an automated response is itself a source of loss. A false positive can unwind a position at a bad price or halt a service, and the institution's liability under MiCA Article 70 is the same whether the control fires, fails to fire, or fires wrongly. Neither anchor component publishes a liability cap, a service level, or any commitment as to detection efficacy, so the limits should be sized on the assumption that there is no recourse.
05. The stack, layer by layer
Most of these layers can be rented from a named vendor, and usually should be. The part that matters is the one layer you have to own yourself.
The authorisation, the signing arrangement and the delegation
The authorisation and the client-asset liability with it, a custody or signing arrangement with an approval interface, a management body able to grant a standing delegation, an incident process and supervisory reporting channel, and the risk appetite statement the limits derive from. The delegation decision - what the machine may do without a human - is the thing nobody rents.
Detection and pre-signature simulation
Continuous detection across contracts, positions and pending transactions, pre-signature simulation and a scored verdict over an API, and a risk-pattern catalogue maintained against a moving threat picture. Not included: no keys, no signing authority, no limits, no delegation, and no commitment that a threat will be detected - best-effort detection is the norm at this layer.
The matrix, the execution path and the liveness check
The thresholds-to-actions matrix, with limits enforced where the provider cannot reconfigure them; the verdict-to-execution path and its behaviour when no verdict arrives; the liveness check that makes a silent failure visible; DORA Art. 25 testing and the evidence it produces; and out-of-hours cover for what the automation may not do. The institution keeps ownership of the policy and rents the detection engine underneath it.
06. Why this stack
Two components run detection wired to enforcement inside institutional custody arrangements, not only as an alerting feed, and both integrate into the same custody infrastructure, so in practice they can be swapped for each other. Detection state is held as rules and thresholds, so moving between providers is a re-implementation and running two of them at once is inexpensive.
The component no vendor supplies is the policy and limit engine. The limits have to be enforced by authority the detection provider does not hold, so they are built by the institution or configured inside a custody arrangement it already controls. This is also what holds the readiness rating where it is: enabling automated response turns a monitoring component into a privileged instruction source, and the only thing containing it is a limit the provider cannot change.
On the parameter-risk layer the institution keeps the policy and rents the engine. Chaos Labs was Aave's primary risk manager from November 2022 until its exit announced 6 April 2026. A risk mandate can be withdrawn for commercial reasons at short notice, and an architecture that assumed otherwise carries that as a single point of failure.
Request the full blueprint
This is the short version. The full blueprint is a single document your counsel and board can read cold, and a third-party-risk function can lift wholesale. Leave your work email and your personal link arrives in your inbox.
- The regulatory position, stated article by article
- Proven options at each layer, with the vendors that hold up
- The risk table with a named owner for each risk
- The division of labour: what is rented, built, and operated
- The third-party-risk pack a DORA governance function can lift
- The delivery path, step by step, with the monitoring and incident model
FAQ
Is real-time risk monitoring with automated response a MiCA requirement?
No. In the Acting on an On-Chain Threat pattern, real-time risk monitoring and automated response are not MiCA-named obligations, and presenting them as a MiCA requirement is an overclaim. They are an operational-resilience control evidenced under DORA (Reg. 2022/2554), specifically Art. 10 detection mechanisms tested under Art. 25, and Arts. 17-19 incident management, which require major incidents to be notified within 4 hours of classification and no later than 24 hours after detection. MiCA Arts. 70 and 75 set the custody and liability boundary the delegation must respect.
What incident shows pre-authorised automated response working?
On 3 November 2025, Balancer's automated emergency controls paused all pausable Composable Stable v6 pools across nine chains within minutes of first detection, protecting about USD 19.3 million. In the same incident, losses above USD 128 million fell in pools whose pause windows had expired. The automation worked exactly as configured, and the loss was a configuration expiry rather than a detection failure. Separately, during the Resolv exploit an exit agent triggered by a Hypernative event acted without human intervention.
Who is pre-authorised automated response not for, and what does the institution build?
It is not for institutions concerned with who the counterparty is rather than what the transaction does, nor for those whose management body will not delegate a business-stopping action to automated authority, for whom the detection half is still worth building. The institution owns the authorisation, the signing arrangement and the standing delegation, which is the thing nobody rents. It rents detection and pre-signature simulation from providers such as Hypernative, Blockaid, Gauntlet or Chaos Labs. It builds the thresholds-to-actions matrix, the verdict-to-execution path, and the liveness check that makes a silent failure visible.
Already evaluating this for your institution?
When you are ready, we scope a business case on your own numbers: the costed build, the controls, the SLA and the ROI your board needs to approve it. Or talk it through first.
Run this pattern in production, or tried to and stopped? .


