Web3 Operational Security Services
Your digital assets are a target. Opsek helps you stay untouchable with cutting-edge security strategies.
Trusted by 100+ founders & UHNWI
Vault services
Each vault contains detailed information about our specialized offerings designed to protect your digital assets and operations.THREAT MODELING
What are you protecting? Who are you protecting it from? What can go wrong? What are you doing about it?
Understanding your organization's structure, operations, and assets enables us to create a tailored threat model and set clear audit priorities. This step ensures the audit focuses on what matters most.
THREAT MODELING
Risk assessment, Asset protection, Audit priorities
GENERAL SECURITY AWARENESS TRAINING
Theory, Practice, Quiz, Walkthrough
Security training is vital to protecting your company against modern threats. Designed around real-world incidents, including social engineering attacks, it will give your team practical knowledge and hands-on skills to recognize and respond effectively to attacks.
GENERAL SECURITY AWARENESS TRAINING
Theory, Practice, Quiz, Walkthrough
PHYSICAL SECURITY TRAINING
Transportation choice, passphrase, location sharing, tamper-evident bags
Our physical security sessions help Web3 individuals stay safe in real life scenarios like traveling to conferences and events. Delivered as a live session with a handbook, it provides clear, practical steps to protect yourself both physically and digitally.
PHYSICAL SECURITY TRAINING
Transportation choice, passphrase, location sharing, tamper-evident bags
TAILORED SECURITY TRAINING
Developers, C-Level, signers, business developers, HR (fake jobs & applicants), finance and marketing
Tailored Security Trainings are designed for specific teams: Finance, Engineering, Marketing and more, focusing on the unique threats each area faces. Each session is built around real, recent attack scenarios that highlight vulnerabilities relevant to their roles and how to protect from them.
TAILORED SECURITY TRAINING
Developers, C-Level, signers, business developers, HR (fake jobs & applicants), finance and marketing
MULTISIG AUDIT
Safe, Fordefi, Fireblocks
The goal is to identify and mitigate existential threats that could lead to financial loss either from your treasury or organization . We assess failure scenarios based on real-world incidents, and we develop security policies to eliminate single points of failure.
MULTISIG AUDIT
Safe, Fordefi, Fireblocks
OSINT RESEARCH
Email, passwords, phone numbers, SIM swap risks, passport, postal address
We conduct an Open-Source Intelligence (OSINT) investigation on your company and team to uncover exposures that could be exploited by attackers. This analysis provides a clear picture of individual and company-wide risks.
OSINT RESEARCH
Email, Passwords, Phone numbers, SIM swap risks, Passport, Postal address
OPERATIONAL SECURITY AUDIT FOR YOUR COMPANY
Domain, DNS, Google Workspace, Cloud, Github, Password manager, Slack and more...
Instead of simply sharing checklists, we work directly with your team to review, configure, and secure the company's infrastructure together, making sure every step is understood and applied correctly to harden the complete attack surface.
OPERATIONAL SECURITY AUDIT FOR YOUR COMPANY
Domain, DNS, Google Workspace, Cloud, Github, Password manager, Slack and more...
OPERATIONAL SECURITY FOR TEAM MEMBERS
Devices, accounts, password manager, 2FA implementation, backup strategies and more...
The OpSec audit for your team members is delivered in small groups through a series of 2-hour sessions. Working in small groups ensures that every participant is actively engaged: sharing screens, applying remediations, asking questions, and completing tasks together.
OPERATIONAL SECURITY FOR TEAM MEMBERS
Devices, accounts, password manager, 2FA implementation, backup strategies and more...
SECURITY AS A SERVICE
To maintain the highest level of protection, we offer a subscription-based service that ensures your company stays secure beyond the initial audits.
24/7 Expert Support, Monthly office hours, Employee Onboarding, Incident Response, Dedicated Communication, Signers.
SECURITY AS A SERVICE
First point of contact for security. The audit is just the beginning
OPSEK AS A SIGNER
On demand, our team joins your multisig as either a signer or as supervisor
Signing ceremony creation from scratch, policies, signers onboarding, rotating policies, live transaction verification and signing ceremonies.
OPSEK AS A SIGNER
On demand, our team joins your multisig as either a signer or as supervisor
Free & Open Source tools for the Web3 community
We believe in public goods to make the dark forest a safer placeSAFECHECK APP
Harden your online presence, stop SIM swaps, and enable strong 2FA
ZEROTRUST GAME
Interactive social-engineering game.
Can you spot all red flags and score 100%?
OSs-Security
Harden your macOS, Linux and Windows devices with simple but powerful hardening scripts.
INCIDENT RESPONSE GUIDE
Isolate and factory reset compromised devices.
$15B+
TVL Protected
15+ years
WEB2 + WEB3 security experience
OpSec for web3 organizations
Identification and mitigation of risks in processes, access controls, and governance to protect funds and protocol operations.
Assessment and hardening of internal workflows, data access, and investment-related communications to safeguard sensitive deal information and treasury assets.
Strengthening operational controls, key-management procedures, and infrastructure monitoring to prevent unauthorized access, fraud, and system-level compromise.
Securing validator operations, network governance processes, and infrastructure integrity to reduce attack surfaces and ensure protocol reliability.
Protection of digital assets, personal data, and transaction workflow, device security, and operational-risk reduction, ensuring the highest level of security standards expected for high-net-worth individuals.
Enhancement of internal processes, client-data handling, and system permissions to prevent leaks, misuse, and operational vulnerabilities.
Implementation of rigorous controls over custody flows, compliance workflows, and internal permissions to maintain asset security and operational integrity.
Blog
VIEW MORETeam leadership
Experienced. Proven. Relentless in securing your Web3 future.
Pablo Sabbatella
Founder - Security Researcher
Web3 operational security researcher, founder of Opsek, and member of SEAL (Security Alliance), dedicated to protecting web3 teams and individuals from sophisticated threat actors. Pablo is also an active signer in the Optimism security council, Polygon protocol council and Everclear security council.
He also hosts the Blockchain Security Series podcast, where he discusses the future of Web3 security with the ecosystem leaders. His research is usually presented in conferences like Devcon, EthCC, DeFi Security Summit, Labitconf, Ekoparty and many more.
Louis Marquenet
Head of Operations - Security Researcher
Cybersecurity expert turned Web3 protector, specializing in securing online and offline accounts for users, crypto investors, and founders.
More than 98% of stolen funds in the Web3 ecosystem are stolen without breaking code but by breaking people.
We help your team to become paranoid, protect you assets and image so you don't end up on 🐸 rekt.news.


Security experts ready to listen and help you find the right solution.




