Someone is already studying your team.

Crypto losses begin with a person. A message. A signature given to the wrong screen. Ormos secures the layer attackers move through, and brings your operation into safe harbour before they reach it.

Book a threat briefing
1The threat

The incentives are gargantuan.

An attacker will spend weeks before they spend a cent, because the prize is enormous. When nine or ten figures sit behind a wallet, it pays to study your team, read their posts, learn who signs and who travels, and build a face you already trust. Then they ask for one small thing, on a quiet afternoon, from someone who sounds exactly right. Crypto is an incentives game. Once you see the size of the payoff, every other move makes sense.

This is the ground you already operate on. Most teams never see the work that goes into taking them.
2The math

The money leaves through people.

$3.4B
stolen across crypto in 2025, near a record high
55%
of exploit value taken through social engineering, the human layer
$1.4B
the Bybit theft, the largest ever, with zero contract bugs
$285M
drained from Drift on Solana in 2026, called a people problem by its own foundation
Source · Chainalysis, Sentora & Elliptic, 2025-26
3The harbour

We have mapped the dark water.

Ormos works the same ground the attackers do, the human and operational layer, and closes it before anyone tests it for real. I have been targeted, studied, and deepfaked. I learned the attacker's playbook from the wrong end of it, so I know the route in and how to hold the door.

An anchorage is the place a ship rides out the storm. That is the entire job.

4Engagements

What we do.

1

OPSEC Audit

We map your real attack surface: key custody, signer and multisig practice, device hygiene, comms, vendor trust, and the social-engineering paths into your people. You get a risk-rated report, a remediation plan ordered by what an attacker reaches first, and a re-test once the fixes land.

2

In-House Training

Live sessions run by us, on-site or remote. We put your team through the real attacks in role-play: the pretext call, the deepfake approval, the job-offer file, the signing screen that lies. They feel the con, then learn to break it. Everyone walks out with a playbook they keep.

3

Executive & HNW Advisory

Protection for the people attackers name and study. We lock down personal accounts, devices, and comms, harden custody of personal holdings, and build your defence against impersonation, deepfakes, and the call that sounds exactly like someone you trust.

5Case files

Every one passed an audit. None passed a phone call.

BYBIT2025$1.4Bcentralized exchange

Signers opened a routine cold-wallet transfer and approved it. The wallet interface, served from a compromised vendor machine, had quietly swapped the payload. What three people signed handed full control of the wallet to the attacker.

The failure was human and operational. One developer machine at a third party, a screen that lied, and signers trusting what they saw. The contracts were never touched.
DRIFT2026$285Msolana defi

Over weeks, the attacker worked into Drift's multisig, pre-signed transactions using a routine Solana feature, then seized the Security Council's admin powers and drained the vaults with a fake collateral token. The Solana Foundation's own leaders said the target was people.

Social engineering and operational failure, with the code intact. A human path into the keys, charted over weeks, on the largest DeFi protocol on Solana.
RONIN2022$625Mbridge

An engineer was walked through a fake job interview and sent an offer file. The file carried malware. From one laptop, the attacker reached the validator keys that secured the bridge.

The failure was a single person, courted for weeks. No exploit in the bridge logic. A job offer that was never real.
RADIANT2024$50Mdefi lending

A message from a "former contractor" on Telegram carried a file dressed as a PDF. It planted malware on developer machines. Three signers saw a normal transaction on screen and signed a hostile one to their hardware wallets without seeing the swap.

The team did everything right and still lost. Hardware wallets, simulations, distributed signers. The attacker went through the people and their devices, and left the code alone.
Careful teams. Audited code. The way in was human, every time.
6Method

Four moves.

1

Chart

We map your operation the way a raider studies a coastline, from open water in.

2

Sound

We run the real attacks under control, and find the rocks before they do.

3

Breakwater

We close the gaps where the waves would break, hardest first.

4

Watch

We come back, test again, and stand watch. Proof, written and logged.

7Provenance
The credential

Ormos Certified, written on-chain.

Every completed program issues a verifiable on-chain credential. Anyone can check it, your team owns it, and it cannot be quietly faked. Proof of training that travels with the people who earned it.

On the record

From the team behind Scam Chronicles.

The web3 security podcast that has hosted the people defending this industry.

ConsensysMetaMaskTrust WalletQuantstamp
8Founder
Patrick
Velleman
Founder · Ormos
WEB3 · OPSEC

I have spent years inside web3, building brands for some of its biggest names and watching the industry lose fortunes the same way every time. Through people.

I host Scam Chronicles, the security podcast where the people defending this space walk me through how the attacks really work. I have been targeted, studied, and deepfaked myself, so I know what it looks like from the other side of the screen.

For a decade my job was making hard things land with an audience. Security training needs exactly that and rarely gets it. Ormos is that, turned into a defence: real threats, taught so they stick, by someone who has been in the line of fire.

9Contact

Start with a 20-minute briefing. We show you the first three ways we would come at you, and you keep that list whether or not we end up working together.

A few engagements each quarter, taken by application.

1 · You are
Protocol / Foundation Exchange / Custodian Fund / VC Founder / Exec DAO
2 · Where you are
Hardening before a launch or raise Scaling fast and exposed Had a close call Recovering from an incident
3 · Reach you on
Encrypted channels preferred. We reply within one business day.
Briefing request prepared. Your mail client should be open. If not, reach us at hello@ormos.io.