Threat briefings

Know your adversary. Intelligence is armour.

Briefings for boards, security teams and financial-crime teams on the actors targeting crypto: who they are, how they operate, who they choose, what it looks like when they come for you, and where the money goes afterwards.

The first step to building your defences is understanding the threats you face.

Threat briefings

Three briefings, each in modules you can take together or separately

DPRK

The state-sponsored teams behind the largest thefts in crypto.

Book this briefing
  • Module 01 The organisation How the units are structured, who does what, and why it matters which one is at your door.
  • Module 02 Social engineering and intrusion Fake recruiters, poisoned coding tests, long-game personas, compromised developer machines and signing infrastructure.
  • Module 03 IT workers in your hiring pipeline How North Korean remote workers get hired, what they do once inside, and what to look for.
  • Module 04 Laundering and cash-out How stolen funds move after a hack, from the first swap to the last OTC desk.

The Com

A loose, largely English-speaking network of young cybercriminals. Less sophisticated than DPRK, far more prolific, and unusually good at getting people to do things.

Book this briefing
  • Module 01 How the network works Who's in it, how it organises, and how access, data and victims are traded.
  • Module 02 Support impersonation and help-desk attacks Fake support, fake staff, and the SIM swaps and resets that follow.
  • Module 03 Social account takeovers How X, Instagram and Discord accounts are taken, and how they're turned into money.
  • Module 04 Drainers and phishing Drainer-as-a-service kits, malicious approvals and signatures, address poisoning, and fake sites pushed through ads and social media.
  • Module 05 Breaches and extortion Data breaches, insider recruitment, doxxing and the extortion that follows.

Romance baiting

Industrialised investment fraud run from scam compounds. The largest fraud typology in crypto by volume, and the one most likely to be moving through your platform right now. This is commonly known as “pig butchering”.

Book this briefing
  • Module 01 The compounds Who runs them, who works in them, and how a campaign is organised.
  • Module 02 The grooming playbook How victims are found, groomed and coached, from first contact to the last deposit.
  • Module 03 What it looks like on-chain Victim deposits, consolidation wallets, and the cash-out routes through exchanges and OTC.
  • Module 04 Signals a platform can act on What to look for in your own flows, what to escalate, and how to warn customers before the money leaves.

Attack vectors

By method rather than by actor; add to any briefing

Exploits

How smart-contract and protocol vulnerabilities are found, weaponised and cashed out, and what the first minutes after an exploit look like.

Supply chain compromise

Compromised dependencies, build pipelines and developer tooling: how an attacker gets into what you ship, and the signals that give it away.

Signing and key-management attacks

How attackers subvert multisig and transaction-signing processes, and what good signing hygiene looks like.

DNS and front-end hijacking

Registrar and DNS account takeovers that turn a trusted domain against its own users, and the controls that close the gap.

Governance attacks

How voting power is bought, borrowed or captured to push through a hostile proposal, and the controls that make it harder.

MEV and the dark forest

Front-running, sandwich attacks and the bots that watch the mempool: what happens to a transaction between broadcast and inclusion, and what that means for you.

AI-enabled threats

Deepfaked calls, cloned voices, synthetic personas and phishing at scale: what has actually changed, and what hasn't.

How the money moves

How each of these groups launders what they take, what's detectable at each stage, what's freezable and when, and what the first hour after a theft should look like.

Bespoke

Something else? We'll build a briefing around your sector, your systems and what you've seen.

Tell us what you need

Who it's for

Boards & executives

What these actors want from a company like yours, in plain language, and the decisions that follow. Executive briefing, or a standing quarterly update.

Security & engineering teams

Tradecraft in detail: approaches, tooling and the signals that show up before and during an attack. DPRK and Com workshops.

Compliance & financial-crime teams

How stolen and defrauded funds move, what the typologies look like on your platform, and what to escalate. The romance-baiting briefing and the How the money moves module.

Whole organisation

Staff awareness built on how these actors actually approach people, not generic security training.

Formats

Four ways to run it

Executive briefing

60–90 minutes

For leadership and boards. Non-technical, focused on exposure and decisions.

Team workshop

Half a day

For security, engineering or compliance teams. Tradecraft, warning signs, detection and response.

Standing briefing

Quarterly

A regular update for a board or security team on what's changed: new tradecraft, new campaigns, and what it means for you.

Ask about a standing briefing

Written threat brief

Document

A tailored briefing document on the actors and tradecraft relevant to your organisation.

Remote, or in person. Pricing on request.

Delivered by

Pangolin Intelligence is led by tanuki42, a pseudonymous crypto security researcher and SEAL 911 contributor.

Know your adversary.