Secure
Security across the lifecycle: assessments, contract assurance, security operations and incident response.
C'ROC is the Client Focus blockchain security operations center. It monitors Ethereum, Solana, BNB Chain, Avalanche, Polygon, Arbitrum, Optimism, Base and Sonic (formerly Fantom) continuously, validates every alert with a trained analyst, and notifies named client contacts on a published clock.
Coverage
Nine public blockchains, including Ethereum, Solana and Base
Validation
Every alert confirmed by a Watch Officer before it reaches the client
Notification
Within 10 minutes of detection for critical events, under the client's service agreement
Operating flow
Settlement on a public blockchain is final, so C'ROC is built around the interval between an event and a decision. Detection is automated; the decision to notify rests with a Watch Officer.
Client Focus does not take custody of client assets and does not hold client signing keys. It operates with monitoring and alerting rights and, where contracted, proposes actions that the client's authorized approvers execute.
Integrations are available to client SIEM, ticketing and paging tools, including Splunk, Microsoft Sentinel, ServiceNow and PagerDuty, so alerts arrive where the client's teams already work.
No alert reaches a client without a Watch Officer confirming it.
Detection categories
Chain Monitor is the C'ROC detection engine. Detection runs continuously across the monitored networks and is tuned to client policy.
Outflows matching known exploit signatures and abnormal contract drains.
Exposure to mixers, chain hopping and structured layering patterns.
Counterparties on sanctions lists and deposits to high-risk exchanges.
Liquidity removal, privileged mint activity and honeypot behavior.
Dormant wallet reactivation, approval abuse and anomalous transaction velocity.

Method
Chain Monitor is operated as a controlled service rather than a set of standing alerts.
Chain data is ingested from full nodes operated by Client Focus and from RPC providers across the monitored networks.
Detection rules are expressed as versioned, change-controlled policy per client, so every change to what is watched has an author, a date and an approver.
Baselines are held per wallet, contract and counterparty, so deviation from established activity is measurable rather than assumed.
Each alert is enriched with address history, counterparty context, sanctions and high-risk venue exposure before an officer reviews it.
Enriched alerts enter a Watch Officer validation queue. No alert reaches a client without an officer confirming it.
Detection, validation, notification and escalation are recorded with hop-by-hop timestamps and named owners.
Detection engine
The engine that classifies each event is operated by Client Focus inside an agreed boundary. Every event passes four layers of analysis before an officer determines what it is.
Live transaction data checked against security rules and client-specific operational policy.
Baselines of normal activity per wallet, contract and counterparty, so deviation is measurable.
Known-bad addresses, mixers, sanctioned entities and high-risk exchange exposure.
Privileged actions such as role grants and configuration flag changes, plus threshold and timing rules.
The engine is hosted within Client Focus infrastructure or the client's designated environment, and no client data leaves the agreed boundary. It uses open-weight models fine-tuned on labeled exploit patterns, malware corpora, identity attack signatures and MITRE ATT&CK techniques, with alert classification at sub-second latency under production load.
When an event involves a smart contract, the engine reads the contract code in the evidence map it builds for that event and evaluates it against known vulnerability and exploit patterns, across EVM chains and non-EVM networks including Solana. The same detection lineage powers pre-deployment contract analysis in Smart Contract Guard 360.
Each detection is paired with a generated standard operating procedure for analyst response, escalation and client notification. Model lineage is versioned and available for technical review under non-disclosure agreement.
Severity framework
Severity decides the notification path. The clock starts at detection and every hop is timestamped.
Activity that is new, unfamiliar or unexplained, and privileged actions such as role grants or configuration flag changes.
Notification within 10 minutes of detection. Escalation continues up the chain if client acknowledgment does not follow within 15 minutes (targets stated in the client's service agreement).
Known event types occurring outside the established daily pattern, or at unusual volume or timing.
Notified within the published service window and tracked to closure.
Routine expected operational activity, recognized wallets, and standard issuance and transfer flows.
Logged and summarized in the daily report.
Escalation
Each level has a defined responsibility and a named individual on duty, recorded with hop-by-hop timestamps.
Monitors the queue, validates alerts and discards false positives.
Investigates confirmed indicators, traces flows and opens the incident.
Owns containment, client communication and the response timeline.
Holds named accountability, regulator-facing reporting and post-incident review.
Client engagement
Client Focus operates the public blockchain security operations function for a Tier-1 global bank. The engagement covers multi-chain coverage across Layer 1 and Layer 2 networks including Ethereum and Base, continuous transaction monitoring, smart contract runtime security and invariant alerting, custody and treasury wallet surveillance, sanctions screening and Travel Rule integration, bridge and cross-chain monitoring, and regulatory reporting feeds with forensic case support. Alerts are delivered into the bank's existing security stack under banking service levels, 24/7/365.
| Tier | Scope | Target response | Coverage |
|---|---|---|---|
| S1 | Critical: new, unexplained or privileged action | Notification within 10 minutes of detection, escalation continues without acknowledgment within 15 minutes | 24/7/365 |
| S2 | High: known event outside the daily pattern | Published service window | 24/7/365 |
| S3 | Informational: routine expected activity | Daily report | 24/7/365 monitoring |
| IR | Incident response engagement | 1 hour to incident manager | 24/7/365 |
Illustrative values shown. Final severity definitions and response targets are agreed for each engagement.
Practice
C'ROC is delivered through the Client Focus Secure practice, alongside security assessments, incident response and Smart Contract Guard 360 for contract assurance before deployment.
Related
Security across the lifecycle: assessments, contract assurance, security operations and incident response.
Automated contract analysis and continuous compliance monitoring inside the client environment.
Instructions for existing clients reporting an active incident, with direct phone and email channels.
Discuss continuous security operations for your on-chain activity with the team that runs the C'ROC. Every request is reviewed by a principal of the firm.