The Risk Moved From the Key to the Path
Why pre-sign security matters now — the threat landscape, the irreversible moment, and the attacks SignTrail is built for.
Why Now
02Attackers Do Not Just Steal Keys
Even valid signers and trusted systems can approve dangerous transactions when the path is manipulated.
Past Attacks
- Private key theft
- Phishing
- Malware
- Direct intrusion
New Attacks
- Valid approver
- Manipulated signing request
- Fake UI
- Compromised developer environment
- Valid signature
- Asset theft
Bybit
$1.5B Incident
A large asset movement that looked approved still led to catastrophic loss.
Source: FBI / IC3 Public Service Announcement on the Bybit incident (TraderTraitor).
Signing Is the Final Moment
Once a valid signature is generated, prevention ends and incident response begins.
- Intervention Possible
- Irreversible
- Request
- Approval
- Pre-Sign Check
- Signingpoint of no return
- Broadcast
- Settlement
SignTrail is the final control point before assets move.
A Different Question, Right Before Signing
Existing tools each guard one angle. SignTrail adds the missing one — was this signing request created on a trusted execution path? — and enforces it before the signer runs.
EDR / eBPF
Is process or system behavior abnormal?
Custody policy
Does wallet policy allow this withdrawal?
KYT / AML
Is the address or transaction risky?
- Verifies before the signer runs and stops unverified requests — not after the transaction is broadcast.
Runtime path as a signing precondition
Binds each request to the runtime evidence it came from. No verified path, no signature.In front of your signers
Sits ahead of HSM / MPC / Fireblocks / Safe. No replacement, no migration.
Built for DPRK-Style Web3 Attacks
DPRK-linked attackers increasingly target people, developers, infrastructure, and signing workflows — not just contracts.
Fake Hiring
Malicious repositories, fake interviews, developer environment compromise.TV-01Fake Investor/Partner
Social engineering through investment, partnership, or due diligence conversations.TV-02Developer Compromise
Account takeover, CI/CD abuse, package or deployment path manipulation.TV-03Signer Manipulation
Legitimate signers approving manipulated requests.TV-04Operational Workflow Abuse
Withdrawal requests, multisig approvals, admin actions, and treasury movements disguised as normal operations.TV-05
SignTrail turns threat intelligence into pre-sign control.