# Hexagate Offer for Silo Finance - Proactive security against Web3 threats and exploits

**URL:** https://gov.silo.finance/t/hexagate-offer-for-silo-finance-proactive-security-against-web3-threats-and-exploits/446
**Category:** Proposal Discussion
**Created:** [February 12, 2024, 6:07pm UTC](https://gov.silo.finance/t/hexagate-offer-for-silo-finance-proactive-security-against-web3-threats-and-exploits/446 "2024-02-12T18:07:55Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![yaniv](https://avatars.discourse-cdn.com/v4/letter/y/5fc32e/32.png) [@yaniv](https://gov.silo.finance/u/yaniv)
#### Post date: [February 12, 2024, 6:07pm UTC](https://gov.silo.finance/t/hexagate-offer-for-silo-finance-proactive-security-against-web3-threats-and-exploits/446/1 "2024-02-12T18:07:55Z")

</div>

Hexagate is a Web3 security provider helping protocols, bridges, and chains to protect their smart contracts and users from financial losses and fund loss incidents caused by cyber exploits and Web3 threats. Hexagate offers a platform that detects all Web3 threats in real time and prevents them from causing any impact.

Hexagate’s Web3 security platform offers real-time monitoring solutions for all sorts of threats before they impact any digital assets and automated prevention tools for Silo Finance so team members can take on-chain action, when applicable.

This benefits Silo Finance users by safeguarding their funds from potential exploits on any Silo Finance contract and reduces the amount of funds lost in a possible incident.

Hexagate monitors malicious activity on-chain, including on any Silo Finance contracts, including all 1st party contracts, 3rd party dependencies, governance proposals, protocol invariants and so on.

Hexagate can partner with Silo Finance to provide the money market with real-time alerts on Web3 threats and exploits threatening Silo Finance contracts or governance participants and run automated workflows to remediate issues in real-time when Hexagate fires an alert. That will also allow rapid communication and response to threats that come up.

# Background

Hexagate monitors blockchains in real-time, and by leveraging ML, security heuristics, hybrid detection algorithms and invariant monitoring engine, it provides early detection of exploits, abnormal behavious and other Web3 threats. The Hexagate platform covers the detection of cyber and financial exploits on 1st and 3rd party code on mainnet deployments, governance and administration risks, suspicious fund movements, phishing, fraud, scams, and custom invariants.

Protocols, bridges, and chains that use Hexagate benefit from early and accurate detection of threats, remediation workflows, IR, and forensics.

The company already protects over $15B in TVL across multiple chains and is trusted by the biggest names in the industry like Polygon, Linea, Avalanche, Eigen Layer, GMX, QuickSwap and many others - it managed to detect ahead-of-time exploits that targeted Euler, iearn, Hundred Finance, Conic, and more.

Hexagate is a VC-funded company backed by leading VCs, founded by serial entrepreneurs who previously built companies that were acquired by Jfrog and Claroty. Their team brings vast experience in the cybersecurity realm.

Hexagate also helps the entire ecosystem by helping others in a time of need, participating in post-mortem analysis, war rooms aimed at unveiling exploiters and recovering funds, and by conducting research activities on protocols - here are a few examples:

- [Found and responsibly disclosed a vulnerability in the Polygon PoS](https://medium.com/immunefi/polygon-consensus-bypass-bugfix-review-7076ce5047fe) (Proof of Stake) system that enables bypassing of the consensus
- Listed in the Ledger Hall of Fame [for finding and reporting a bug in an old Ledger](https://donjon.ledger.com/hall-of-fame/)
- [Helped 0vix protocol throughout their incident response](https://0vixprotocol.medium.com/0vix-exploit-post-mortem-15c882dcf479) right after getting exploited
- [Helped Conic Finance throughout their incident response](https://medium.com/@ConicFinance/post-mortem-eth-and-crvusd-omnipool-exploits-c9c7fa213a3d) right after getting exploited
- [Helping Compound V2 and Compound V2 forks](https://www.comp.xyz/t/hundred-finance-exploit-and-compound-v2/4266) with a zero-day exploit to open markets safely
- [Curve incident post-mortem](https://twitter.com/hexagate_/status/1685691858628800513) right as it happened
- [Euler hack post-mortem](https://twitter.com/hexagate_/status/1635259129785876480) (also notified the team in real-time over Discord and helped in the war room)
- They are also part of the [Seal911 team](https://twitter.com/hexagate_/status/1688648564438695936), helping others in the ecosystem in stressed times

Everyone is welcome to follow Hexagate on this [official X (Twitter) account](https://twitter.com/hexagate_) to see live updates and posts.

# Detailed Proposal

Below is a summary of the Hexagate proposal, outlining the offering to Silo Finance:

1. Hexagate will provide access for Silo Finance to its Web3 security platform and Web3 threat intelligence feed, including its on-chain investigation engine.

2. Threats covered by the Hexagate platform:

3. Hexagate provides generic webhooks, Slack/telegram/email/discord/pagerduty/OpsGenie integrations for any type of alerts

4. Hexagate enables user-generated custom monitors so a user can set up alerts on specific wallets, whales, specific events, specific contract calls, and so on, enabling users to customize their monitoring to fit their needs

5. Hexagate provides a unique invariants monitoring engine which allows for invariants to be declared using proprietary DSL and can be monitored both on Testnet and Mainnet.

6. Phishing detection for governance participants - Hexagate surfaces any phishing attempt on Silo Finance governance participants

7. Connection to our network of partners and collaborators in which they have an open channel to such as Chainalysis, Binance, on-chain sleuths, and more to be able to notify them in real-time when an incident happens so they can tag the bad actors and prevent them from off-ramping on a big list of exchanges, uncover the attacker’s identity, help with crafting a post-mortem paper, and analyze the blast radius of the incident

8. Support:

9. Onboarding:

# Budget

Hexagate is asking the Silo Finance community to fund $21,483/year in SILO - 441,129 ( from the DAO treasury for onboarding, maintenance, and Support listed above), and the Silo Foundation will engage with Hexagate on a commercial agreement for a yearly license of the platform. Hexagate commits not to sell all SILO tokens at one time but in quarterly/monthly chunks.

The rationale is that the community is receiving support and maintenance while the Silo Foundation is in charge of operating the system, as security is top of mind.

---

<div class="post-metadata">

### Author: ![ayham.eth](https://yyz2.discourse-cdn.com/flex032/user_avatar/gov.silo.finance/ayham.eth/32/8_2.png) [@ayham.eth](https://gov.silo.finance/u/ayham.eth)
#### Post date: [March 6, 2024, 6:39pm UTC](https://gov.silo.finance/t/hexagate-offer-for-silo-finance-proactive-security-against-web3-threats-and-exploits/446/2 "2024-03-06T18:39:32Z")

</div>


