Digital asset operations glossary
Definitions of the detection, escalation and custody terms used across these pages.
C'ROC is the Client Focus blockchain security operations center. It monitors Ethereum, Solana, BNB Chain, Avalanche, Polygon, Arbitrum, Optimism, Base and Sonic (formerly Fantom) continuously, validates every alert with a trained analyst, and notifies named client contacts on a published clock.
Context
According to Chainalysis, approximately $3.4 billion was stolen in cryptocurrency-related hacks in 2025 (Chainalysis, 2026 Crypto Crime Report). Settlement on a public blockchain is final, so the interval between an event and a decision determines the outcome more than any control applied afterwards.
Notification within 10 minutes of detection; client acknowledgment within 15 minutes (targets stated in the client's service description).

Client engagement
Client Focus operates the public blockchain security operations function for a Tier-1 global bank. The engagement covers multi-chain coverage across Layer 1 and Layer 2 networks including Ethereum and Base, continuous transaction monitoring, smart contract runtime security and invariant alerting, custody and treasury wallet surveillance, sanctions screening and Travel Rule integration, bridge and cross-chain monitoring, and regulatory reporting feeds with forensic case support. Alerts are delivered into the bank's existing security stack under banking service levels, 24/7/365.

Services
Blockchain security operations delivered 24/7. Automated detection raises events from live chain data, and Watch Officers validate each one before notification.
Contract, key management and infrastructure reviews, mapped to the controls that auditors and supervisors test.
Containment support, evidence capture, counterparty notification and post-incident review with corrective actions.
Detection categories
Detection runs continuously across the monitored networks and is tuned to client policy.
Outflows matching known exploit signatures and abnormal contract drains.
Exposure to mixers, chain hopping and structured layering patterns.
Counterparties on sanctions lists and deposits to high-risk exchanges.
Liquidity removal, privileged mint activity and honeypot behavior.
Dormant wallet reactivation, approval abuse and anomalous transaction velocity.
Method
Chain Monitor is the detection layer inside C'ROC. It is operated as a controlled service rather than a set of standing alerts.
Chain data is ingested from full nodes operated by Client Focus and from RPC providers across the monitored networks.
Detection rules are expressed as versioned, change-controlled policy per client, so every change to what is watched has an author, a date and an approver.
Baselines are held per wallet, contract and counterparty, so deviation from established activity is measurable rather than assumed.
Each alert is enriched with address history, counterparty context, sanctions and high-risk venue exposure before an officer reviews it.
Enriched alerts enter a Watch Officer validation queue. No alert reaches a client without an officer confirming it.
Detection, validation, notification and escalation are recorded in an evidence store with hop-by-hop timestamps and named owners.
Integrations are available to client SIEM, ticketing and paging tools, including Splunk, Microsoft Sentinel, ServiceNow and PagerDuty.
Method
The engine that classifies each event is operated by Client Focus inside an agreed boundary.
Chain Monitor is powered by a detection engine operated by Client Focus and hosted within Client Focus infrastructure or the client's designated environment. No client data leaves the agreed boundary.
The engine uses open-weight models fine-tuned on labeled exploit patterns, malware corpora, identity attack signatures and MITRE ATT&CK techniques, with alert classification at sub-second latency under production load.
Each detection is paired with a generated standard operating procedure for analyst response, escalation and client notification at the moment the alert is raised. Model lineage is versioned and available for technical review under non-disclosure agreement.
Analysis method
Every event passes through four layers of analysis before an officer determines what it is.
Live transaction data checked against security rules and client-specific operational policy.
Baselines of normal activity per wallet, contract and counterparty, so deviation is measurable.
Known-bad addresses, mixers, sanctioned entities and high-risk exchange exposure.
Privileged actions such as role grants and configuration flag changes, plus threshold and timing rules.
Boundary
Client Focus does not take custody of client assets and does not hold client signing keys. Key generation, storage and signing remain within the client's or its qualified custodian's environment. Client Focus operates with monitoring and alerting rights and, where contracted, proposes actions that the client's authorized approvers execute.
Severity framework
Activity that is new, unfamiliar or unexplained, and privileged actions such as role grants or configuration flag changes.
Notification within 10 minutes of detection. Escalation continues up the chain if client acknowledgment does not follow within 15 minutes (targets stated in the client's service description).
Known event types occurring outside the established daily pattern, or at unusual volume or timing.
Notified within the published service window and tracked to closure.
Routine expected operational activity, recognized wallets, and standard issuance and transfer flows.
Logged and summarized in the daily report.
Escalation
Each level has a defined responsibility and a named individual on duty, recorded with hop-by-hop timestamps.
Monitors the queue, validates alerts and discards false positives.
Investigates confirmed indicators, traces flows and opens the incident.
Owns containment, client communication and the response timeline.
Holds named accountability, regulator-facing reporting and post-incident review.
Engagement model
| Tier | Scope | Target response | Coverage |
|---|---|---|---|
| S1 | Critical: new, unexplained or privileged action | Notification within 10 minutes of detection, escalation continues without acknowledgment within 15 minutes | 24/7/365 |
| S2 | High: known event outside the daily pattern | Published service window | 24/7/365 |
| S3 | Informational: routine expected activity | Daily report | 24/7/365 monitoring |
| IR | Incident response engagement | 1 hour to incident manager | 24/7/365 |
Illustrative values shown. Final severity definitions and response targets are agreed for each engagement.
Related
Definitions of the detection, escalation and custody terms used across these pages.
The Digital Asset NOC holds availability to the targets set out in the client's service description under ITIL-based managed operations.
ISO 27001 certification, control frameworks and operating evidence.
Instructions for existing clients reporting an active incident, with direct phone and email channels.
Discuss continuous security operations for your on-chain activity with the team that runs the C'ROC. Every request is reviewed by a principal of the firm.