Skip to content
On-chain security Live on 15 chains

On-chain capital has no perimeter. So we built one.

A protocol holding a billion dollars is a public address anyone can transact against, at any hour, with no gatekeeper and no reversal. Fuga Labs watches what happens, tells you what it is worth, and lets contracts you own refuse the transaction. We never hold your keys, your funds, or your authority.

Watch

15 chains, plus the signers, governance, domains and endpoints that never appear in a transaction.

Judge

What it is worth, to you and to everyone downstream, early enough to change anything.

Refuse

Optional, bounded in advance, executed by a contract you deploy, own and revoke in one transaction.

Bybit$1.46Ba signing interface showed the council one transaction and sent anotherRonin Bridge$624Man allowlist granted five months earlier and never revokedEuler Finance$197Mone transaction, opened and closedHarmony Horizon~$100Mtwo of five keys, on a threshold anyone could read in advanceCurve Finance~$70Ma lock that compiled to nothing in three versions of the compilerLedger Connect Kit5 hoursa phished package account, live inside hundreds of legitimate front-ends

What a missing perimeter costs.

Four losses. In each, the contracts were audited, the procedure was followed, and the money left through something the audit never looked at.

$$1.46BB

left in a single approved transaction, signed on hardware wallets

Bybit, February 2025

$$624MM

withdrawn from a bridge that nobody was watching for six days

Ronin Bridge, March 2022

~$~$100MM

moved by a minority of keyholders, on a structure published in advance

Harmony Horizon, June 2022

~$~$70MM

drained, and a larger position repriced on protocols never touched

Curve Finance, July 2023

One decision, and everything follows from it.

The obvious way to build automated protection is to give the vendor a privileged key. It demos beautifully, and it makes that vendor the most attractive target in the industry. We refused it. Read and attest, never custody and execute.

  1. Step 1

    We sign a statement.

    An alert is a signed, expiring claim: this subject, this severity, this evidence, valid until this time. It moves no value and it calls no contract of yours.

  2. Step 2

    Your contract decides.

    You deploy the policy contract, you own it, you configure it and you revoke it in one transaction. It reads the statement and applies your limits, your allowlist, your pause scope.

  3. Step 3

    Nothing is armed until you arm it.

    Every path that can write on chain ships disarmed. It rehearses against your real traffic first, and the action it may take is one you fixed in advance.

If Fuga Labs were completely compromised tomorrow, the attacker would gain the ability to publish an alert. Not to move a dollar. That is a bound by construction rather than by good intentions.

Detection tells you. The Circuit Breaker refuses.

A warning is worth a great deal, and nothing at all against an exploit that opens and closes inside one transaction. So the Circuit Breaker ships too, and every line below is a constraint on us rather than a capability of ours.

A constraint on us Not a capability of ours

You deploy it. You own it.

The policy contract is yours. You configure it, you call it from your own entrypoints, and you revoke it in one transaction without asking us. Fuga Labs signs a statement; your contract decides what to do about it.

It ships disarmed.

Nothing is armed by default. It first runs report-only against your real traffic, writing every decision it would have made to a durable record, until duration, volume and distinct subjects clear a bar you set.

One action, fixed in advance.

A module gets one pre-authorised, bounded action: pause this market, cap this outflow. You choose the action and its parameters before anything is armed, and nobody, including us, can substitute another later.

Authority over all three Fuga Labs Yours

15 chains, read into one model.

Detection behaves the same way on every one, which is why a multi-chain protocol reads one alert instead of 15. What differs is stated rather than averaged away: 14 run the EVM and are read at contract level.

Ethereum
Solana
Base
BNB Smart Chain
HyperEVM
Arbitrum One
Monad
Polygon PoS
Robinhood Chain
Unichain
Plasma
Avalanche C-Chain
OP Mainnet
Cronos
Gnosis Chain

The next breach is already being dug.

Every engagement is scoped to your protocol by the team: your attack surface, your chains, your response posture. Pricing follows that scope and is settled with you before anything is signed.