A signing laptop used for everything
Email, browsing and signing on one machine. One malicious extension or download and the keys are exposed.
Blockchain & Web3
There is no chargeback, no fraud department and no undo. We build hardened signing environments, key handling procedures, node infrastructure and identity controls for Web3 companies that understand what one bad click costs.
Overview
Almost nothing in this industry is lost to broken cryptography. It is lost to a signing machine that also had a browser extension, or a phone number that got ported.
Start with signing. A machine used to authorize transactions should do nothing else: a clean operating system, no email client, no browser extensions, no messaging apps, application allowlisting so unexpected code cannot run, full disk encryption, and a limited set of network destinations. For higher-value operations that machine should be physically separate and, where the workflow supports it, air-gapped with transactions moved by QR code or removable media under a controlled process. The compromise pattern we see repeatedly is a general-purpose laptop used for signing because it was convenient.
Key handling is a procedure problem more than a product problem. Hardware wallets, multisignature arrangements and threshold or multi-party signing all reduce single points of failure, but only if the surrounding process is real: quorum requirements that cannot be satisfied by one person, seed material recorded on metal rather than paper and stored in geographically separated locations, documented recovery drills that have actually been rehearsed, and a clear rule that no seed phrase is ever typed into a computer, photographed or stored in a password manager. We help design and document those procedures alongside your team, and we implement the technical controls around them.
Social engineering is the dominant threat and it is targeted rather than opportunistic. Fake recruiters sending malware-laden take-home assignments, Discord and Telegram administrator takeovers, support impersonation, and voice or video impersonation of a founder authorizing an urgent transfer. Mobile number porting is a specific and severe risk: anyone using SMS as a second factor is one carrier social-engineering call away from account takeover. We move every account we can to FIDO2 hardware security keys, remove SMS as a recovery method, help you set port-out protection and account PINs with your carrier, and run realistic phishing exercises against your team.
Node and infrastructure operations need ordinary engineering discipline applied carefully. Validators and RPC nodes require predictable uptime, monitored resource usage, redundant network paths, hardened remote access with no exposed management ports, tight key separation between operational and withdrawal functions, and alerting that reaches a human quickly. Registrar and DNS security matters more here than almost anywhere, because a hijacked domain pointing at a lookalike front end is a direct path to user funds, so registrar locks, strong registrar account protection and DNSSEC where supported are part of the baseline.
Treasury operations deserve separation of duties. Cold, warm and hot tiers with defined limits, address allowlisting, a maintained internal address book so nobody pastes an address from a chat window, mandatory small test transactions before large transfers, and dual approval that is enforced technically rather than culturally. We are an IT and security firm. We do not hold keys, take custody or offer financial advice. What we do is build the environment those controls run in. Our full stack is described under Pod Guard, with more at our blockchain IT microsite.
Orca IT does not hold keys, seed material or signing authority, and we do not provide financial or investment advice. We design, harden and monitor the infrastructure your own controls operate inside.
What We Handle
Concrete controls, not a list of buzzwords.
Single-purpose machines with clean builds, application allowlisting, no browser extensions, encrypted disks and restricted network access.
Multisignature and threshold arrangements, quorum rules, metal seed storage, geographic separation and rehearsed recovery drills.
SMS removed as a factor and as recovery, FIDO2 hardware keys deployed, carrier port-out locks and account PINs set for every key holder.
Realistic simulations covering fake recruiters, support impersonation and community platform takeovers, plus a verification rule for urgent requests.
Uptime monitoring, redundant paths, hardened remote access with no exposed management ports, and alerting that reaches an on-call human.
Registrar locks, hardened registrar accounts, DNSSEC where supported, and monitoring for lookalike domains targeting your users.
Attack Patterns
None of these involve breaking cryptography.
Email, browsing and signing on one machine. One malicious extension or download and the keys are exposed.
SMS-based recovery hands over accounts. Hardware keys and carrier port-out locks close it.
A convincing recruiter sends a repository that executes on open. Isolated environments and allowlisting stop it.
An admin account posts a drainer link to your users. Hardware keys and role separation limit the blast radius.
Users authorize transactions on a site that looks exactly right. Registrar locks and monitoring are the defense.
Impersonation of a founder, timed for a Friday evening. Dual approval and callback verification remove the single point of failure.
No, never. We do not hold private keys, seed material or signing authority, and we do not provide financial or investment advice. Our role is designing and securing the environment your controls operate in: endpoints, identity, network, monitoring and process documentation. Custody stays entirely with you or a licensed custodian you choose.
Removing SMS as an authentication and recovery method and moving every account to FIDO2 hardware security keys, combined with carrier port-out protection. SIM swapping and phishing of one-time codes account for a large share of real losses, and hardware keys are resistant to both because they are bound to the legitimate domain.
For high-value operations, yes, where the workflow supports it. Transactions get moved across the gap by QR code or controlled removable media. For lower-value operational wallets, a dedicated hardened machine that does nothing else is usually a reasonable balance. The important rule is that no machine used for signing is also used for email and browsing.
Technical controls plus rehearsed process. Technically: application allowlisting, isolated environments for running untrusted code, endpoint detection, and hardware key authentication that cannot be phished. Procedurally: a rule that any urgent or unusual request involving funds or credentials is verified through a separate channel, regardless of who appears to be asking.
We manage the infrastructure and operational security around them: hardened operating systems, remote access without exposed management ports, monitoring and alerting, redundant connectivity, patching and backup of configuration. Protocol-specific operational decisions and the economic responsibilities that come with running a validator remain with your team.
With enforced separation. Cold, warm and hot tiers with defined limits per tier, multisignature or threshold approval so no single person can move significant funds, a maintained internal address book instead of addresses pasted from chat, small test transactions before large transfers, and allowlisting where the platform supports it. We help design and implement the technical enforcement.
Yes. Remote support covers all 50 states and our management tooling works wherever your people are. For distributed teams the emphasis shifts to identity, device management and hardware key distribution, since there is no office network to rely on. Onsite work is available in the Phoenix metro if you have a physical location here.
We will tell you plainly what we do and do not know on the first call. Our expertise is operational security, endpoints, identity, infrastructure and process design, applied to a threat model where losses are irreversible. We are not protocol engineers or smart contract auditors, and for that work you should engage a specialist audit firm.
Book a hardening review of your signing, identity and node environment.
Talk to Your Pod
We will review your signing environment, endpoint posture, identity controls and node infrastructure, and give you a written hardening plan.
(602) 677-0779Family owned in Gilbert, AZ since 2015 · onsite across the Phoenix metro · remote support nationwide · never outsourced
A few details and your pod gets right back to you, usually the same business day.