Services

Enhance your security with CORE3 Services

Transparent pricing with no hidden fees

DeFi Risk Scoring

Point-in-time due diligence reinforced by continuous live risk scoring, closing the gap between entry and exit risk.

Why It Matters

A one-time audit at entry is no longer enough. The DeFi sector lost $0.5 billion only for the last year. Protocols losing funds due to a single coding bug or visible vulnerabilities that have been there for months and years. Risk doesn't freeze after deployment. Our continuous live scoring tracks how a protocol's risk profile evolves between your entry and exit, so you're never caught blind.

Abstract CORE3 risk network visualization

Key Features

Web3 Security

Exploit risk at the smart-contract and protocol level.

  • Proxy upgrades
  • Flash-loan activity
  • Exploit patterns
  • TVL drain events
  • Audit relevancy

AML / CFT

Exposure to illicit or sanctioned counterparties.

  • Sanctioned addresses
  • Cybercrime wallets
  • Suspicious address clusters

Operational Security

Risk from privileged access and off-chain infrastructure.

  • Admin calls from EOAs
  • Multisig executions
  • Infra vulnerabilities (CVE/NIST)
  • Front-end compromise

Financial Anomaly

Abnormal economic behavior indicating stress or manipulation.

  • TVL change >X%
  • Liquidity shocks
  • Gas price spikes
  • Irregular fund flows

Sentiment

External trust and reputation risk signals.

  • Security-related social chatter
  • Scam reports
  • Negative sentiment spikes
  • Team-related alerts

Governance

Risk from privileged access and off-chain infrastructure.

  • Admin calls from EOAs
  • Authority concentration
  • Governance deviations
  • Low decision transparency
Example from project

Risk system section

Readiness Level

  • Smart Contracts securityStrong
  • Whitehats initiativesModerate
  • Protocol's Operational securityModerate
  • On-chain Monitoring solution analysisWeak
  • Research on team membersStrong
  • GovernanceWeak

Risk name

Severity

  • Protocol is fully centralised with no DAO in place
    High
  • Whitehats initiatives budget is inadequate
    High
  • 3 core smart contracts do not have relevant security audits
    Medium
  • Protocols administrators have privileges
    Medium
Average compliance score dashboard preview

Digital Assets Risk Monitoring

an clear and centralised view of a project's risk score

Aggregating real time on-chain and off-chain data, code audit results, AML/CFT analytics, and more into an intuitive risk score to ensure portfolio projects are adhering to standards and to catch early warning signs of hacks or financial risk.

Early risk detection

Comparable scoring

Smarter risk based allocation

Scalable oversight

Cybersecurity standpoints

Fiduciary support

CEX risk intelligence cube visualization

CEX Risk Intelligence

Institutional-grade due diligence designed to protect capital and reduce execution risk.

Why It Matters

The CEX market moves trillions in volume — but remains deeply opaque. Most participants lack the tools to independently assess whether an exchange is solvent, secure, or properly governed. That's a dangerous blind spot.

Among the top-10 hacks in 2025, centralized exchanges accounted for roughly 70% of total value stolen.

With 8 years of hands-on CEX assessment experience, we offer the institutional-grade intelligence needed to navigate this market with confidence — covering security posture, reserve transparency, regulatory standing, and operational risk — so capital decisions are made on evidence, not assumption.

Assessment Scope

Smart Contracts security
  • User security controls and protections
  • Infrastructure and server security assessment
  • Penetration testing coverage and maturity
  • Bug bounty program effectiveness
  • Security certifications and compliance standards
Solvency Analysis
  • Proof of Reserves audit quality and reliability
  • Merkle tree verification integrity
  • Risk assessment of reserve asset composition
Red Flags Identification
  • Exposure to money laundering activity
  • Compliance with OFAC and international sanctions lists
  • Links to cybercriminal or high-risk entities
  • Historical security incidents and breaches
  • Legal status and regulatory standing
Example from exchange

Summary

Strengths
  • User security
  • ISO
  • Bug Bounty
  • Insurance Fund
  • SOC 1 Type II
  • SOC 2 Type II
  • Penetration Tests
Concerns
  • CCSS
  • Third-party merkle tree
  • Server security
  • PoR audits

Security assessment

Server security
  • SSL /TLS
  • HTTP Headers
  • WAF & CDN
  • SPF & DNSSEC
  • Cookie Flags
  • Spam DB Presence
Certifications
  • ISO 27001
  • CCSS
  • SOC2
  • Insurance
User security
  • Captcha Presence
  • 2-Factor Authentication
  • Password Requirements
  • Device Management
  • Anti-Phishing Code
  • Withdrawal Whitelist
Bug Bounty
  • Reasonable Disclosure Policy
  • Third-party Hosted
  • Reasonable Payout Range
Penetration testing
  • Comprehensive Scope
  • Realistic Scenarios
  • External Testing
  • Cloud Testing
  • Web & API
  • Mobile
  • Testing Environment
  • Report Relevance
  • Remediation Guidance

Have questions about CORE3 Services?

Contact us, and we'll provide more information