$1,000,000 in security audit grants are live now, Apply here →

← Blog

Guardian Commits $5,000,000 to Digital Asset Security Pilots

5 min read

A security pilot for the institutions bringing digital assets into the global financial system.

Guardian is committing $5,000,000 to fund digital asset security pilots.

Digital assets are entering the global financial system.

Stablecoins, tokenized funds and onchain settlement are moving from experiments to programs with client assets behind them.

The institutions running these programs inherit a security model unlike anything they have operated before.

Custody, issuance and the operators around them all become attack surface, and the threat actors targeting them now have frontier AI.

Enter: The Digital Asset Security Pilot

The Digital Asset Security Pilot is an engagement designed for regulated firms building on digital assets.

Guardian works with your organization to assess your architecture and design against secure best practices and regulated standards.

We bring the hands-on experience and lessons from hundreds of prior engagements to your digital assets program, and to your table before the code is finished.

Five Modules, Structured to Your Roadmap

Each module is self contained and pilot ready.

Your pilot is designed with the modules most impactful for your roadmap:

  • Architecture assessment
  • Standards alignment
  • Assurance engineering
  • Smart contract audit
  • Offchain pentests

Architecture assessment

A digital asset system is mostly not onchain.

It is a custody arrangement, an issuance path, a reserve ledger and the operators around it.

The architecture assessment covers every piece of it: custody and the key ceremony, the privileged control surface, every route value can take, and the operational security model that runs it day to day.

The result is a threat model written against your design, mapping every way funds can be moved or the system can fail.

Standards alignment

MiCA, DORA and their equivalents make specific demands of custody, resilience, incident handling and third-party risk.

Almost all of them are architectural rather than administrative.

Guardian reads each regime as a demand on the design, and maps CCSS, ISO 27001, NIST CSF, NYDFS Part 500, the FCA regime, MAS and VARA onto the actual key ceremony and change control.

A reporting deadline you cannot meet is a design problem found at the worst moment. The pilot puts your legal and regulatory requirements into practice at an engineering level.

Assurance engineering

A design is only as good as what holds it up between releases.

Guardian builds the invariant suites that prove your properties still hold, the review gates that stop a change that breaks them, and the deployment checks that confirm what reached the chain is what you staged.

All of it is built with your engineers, and left running after the engagement ends.

Smart contract audit

Guardian performs a full audit of the contracts in scope, on the approach every Guardian engagement runs on.

Two competing teams cover the same code in parallel, one driving expert manual analysis and one leveraging frontier AI, with an exhaustive invariant suite fuzzing underneath both.

Same reviewers, same methodology, same report. The pilot decides how much goes in scope, not how carefully it is read.

Offchain pentests

Most of what can move value in a digital asset program is ordinary infrastructure: consoles, APIs, signing services and the cloud account holding them.

Guardian tests it the way somebody trying to reach your keys would:

  • Infrastructure
  • Webapps
  • APIs
  • Browser extensions
  • SDKs
  • Offchain automation

Every finding is reproduced by an engineer before it reaches you.

From Design to Live and Scaling

The pilot meets your program wherever it is today.

In design, while the custody model and operator roles are still being decided, it starts with the architecture assessment and standards alignment.

In build, assurance engineering goes in alongside the contracts and services being written.

Before launch, the smart contract audit and offchain pentests cover what is about to hold client assets.

And once live, standards alignment and offchain pentests keep pace as regimes phase in and new chains arrive.

Built for Your Vendor Process

The pilot is deliberately structured to be low commitment and easy for your vendor process to accept.

It is professional services rather than software, so the vendor review is a short one.

Guardian’s own controls are aligned to NIST CSF 2.0 and CCSS, and our SOC 2 Type II is underway with an auditor engaged.

This is a bounded way to work with Guardian and see what digital asset security looks like for your organization.

Hundreds of Systems Already Pressure Tested

Guardian has secured more than $45B in digital assets across our engagements, and reported and resolved more than 300 critical vulnerabilities.

Over 150 teams trust Guardian with their contracts, including LayerZero and USDT0.

Every pilot brings the failure modes from those engagements to your design, before they reach production.

$5,000,000 in Funded Pilots

Guardian is committing $5,000,000 to fund digital asset security pilots for the institutions and teams moving the needle on adoption of digital assets in the global financial system.

Institutions and teams selected for their impact on digital asset adoption can receive a funded pilot from Guardian.

Programs interested in a funded pilot can start with a pilot overview call, and the full program is at guardian.security/digital-asset-security-pilot.

Ready to pressure test your digital asset program?

Guardian provides institutional-grade digital asset security to the teams bringing it into the global financial system.