Build your free playbookFree playbook

Want more assets entrusted
to your DeFi protocol?

Prove you’re ready to protect them.

Build an incident response playbook you can execute under pressure.
Know who decides, who acts and who backs them up.

Complete in about 30 minutes · Launching first for vaults

Vault 1 · Exploit · First 15 minutesSample
T+3Pause withdrawalsSecurity lead · signer 3 unassignedGap
T+5Confirm the pause on-chainOn-call engineer · never a signerReady
T+8Open war room, engage SEAL 911CTO leads · Security lead backs upReady
T+12Pre-alert exchanges and issuersOps lead · verified contacts · TX hashesReady

It’s 3:00 A.M.
You get the call.
$50M stolen.
What do you do first?

We asked 212 founders and executives. Only 5 had an answer their team could act on.The decisions just hadn’t been made.

One-to-one interviews with founders and executives of DeFi protocols, 2026.

Ready to actNot ready

Asked what they would do first, most gave some version of this:

“My first move? Probably panic, cry, call my lawyer… in that order.”
Product Manager, Lending protocol
“The big pre-decision is: who is in charge to make quick important decisions? Teams with serious TVL need to know who owns the war room, who can make tough calls, and signs off on comms. You need a chain of command for these crises because there often isn’t time to debate these things on the fly.”
Leader, TheDAO Security Fund
“The moments after a hack can be chaotic. We learned that without one person coordinating the outside response, teams and their service providers hit the same exchanges, bridges and investigators with the same requests. This can be counterproductive. Coordination matters more than extra hands.”
CEO, Balancer Labs
“Our CTO had authority to pause the system after the exploit, but he was asleep in Canada at 2 A.M. Our CEO ended up sending a cab to ring his doorbell enough times to wake him. We knew who could take action. We just didn’t have enough redundancy.”
COO, Vault protocol

The clock starts when the money moves.

Every unanswered question burns time.

Act early
Act late
Losses contained
Losses spread
Exchanges and issuers can still freeze funds
The window for freezing funds closes

Readiness check

3 questions. See where you stand.

Answer for how your team works today.

01

The person authorized to pause withdrawals is unreachable during an active exploit. Who else has explicit authority to act?

Good. Confirm the backup is formally authorized and can act without another approval.

Partial authority can still stall containment. Define exactly when the backup may act and what approval, if any, is required.

You have a single point of failure. Name and authorize a backup before an incident.

02

Stolen funds are moving. Who is responsible for requesting freezes from exchanges, bridges and stablecoin issuers?

Good. Confirm the owner is authorized to act and knows what the request must include.

Define one accountable owner, a backup and the authority to send the request.

Assign an owner and backup for external freeze requests.

03

Your team reports the contracts are paused. Who independently confirms the pause actually worked?

Good. Confirm the verifier checks on-chain independently of the person or tool that executed the pause.

A failed pause can look successful. Name the verifier and define the exact on-chain check.

You have no independent confirmation that containment worked. Assign a verifier and verification step.

0 of 3 answered

Answer all three to see where you stand.

Build your free playbook

Inside the playbook

Every critical action, ready to execute.

Who decides. Who acts and how. Who backs them up. How completion is verified. Gaps are flagged.

Two signers can execute the pause. The unassigned 3rd signer is a resilience gap. HackReflex flags it.

Vault 1 · Exploit · Pause withdrawals

Sample
People
Decision-makerSecurity lead, UTC−5Ready
Backup decision-maker 1CTO, UTC+8Ready
Signer 1Security lead, UTC−5Ready
Signer 2Protocol engineer, UTC+1Ready
Signer 3Not assignedGap
VerifierOn-call engineer, never a signerReady
Procedure
Execution pathGuardian multisig · 2/3 signers · no timelockReady
VerificationTest withdrawal fails on-chainReady
If it failsFall back to the emergency upgrade multisigReady

How it works

30 minutes to your playbook.

Answer the guided questions

The wizard takes you through each critical action, one decision at a time.

See your gaps

Decisions you haven’t made yet are flagged, so you make them now, not during an exploit.

Print your playbook

Print, save as PDF, share with your team or for diligence.

Free: every critical containment action with its decision-makers, signers, backups, procedure and verification, plus your readiness gap assessment.

Build your free playbook

Before the wizard opens, we’ll publish exactly how it handles your data. Privacy policy

For investors and insurers

Capital and coverage come with questions.Answer them with evidence, not assurances.

Institutional LP diligence

ILPA DDQ 2.0
Documented cyber incident procedures?Covered
Clear roles and decision authority?Covered
Backups for key people in a crisis?Covered

Cyber insurance underwriting

Chubb application
Incident response plan?Covered
Named incident-response owner?Covered
Escalation path and external contacts defined?Covered

Built to map to frameworks your reviewers already use.

Playbook actions are organized around the incident-response areas these frameworks cover.

NIST CSF 2.0

Govern, Respond, Recover

SOC 2

CC7.3–CC7.5

ISO/IEC 27001:2022

Annex A 5.24–5.27

SEAL Frameworks

SEAL 911 War Room Guidelines

“We’ve been audited.”

An audit can find vulnerabilities in your code.It doesn’t decide who acts at 3:00 A.M.

You need both.

Build boldly.
Prepare ruthlessly.

DeFi works differently. The duty to protect other people’s money is the same.

Build your free playbook

Build your playbook.Build trust.Attract users and assets.

HackReflex launches soon, starting with vaults.Lending protocols, DEXs, stablecoins and exchanges will follow.

Enter your work email to gain access before public launch.

Privacy policy

Last updated: 6 October 2026

The short version

We collect the email address you give us to join early access, plus two optional answers about your work. We use them to tell you about HackReflex. We don’t sell your information or use it for third-party advertising. You can ask us to delete it at any time.

Who we are

HackReflex, Inc., a Delaware corporation (“HackReflex”, “we”, “us”).

What this policy covers

This website and our early-access list. The HackReflex product isn’t available yet. Before it is, we’ll update this policy or publish a separate notice explaining how product data is handled.

What we collect

Your email address, when you submit it. After you sign up, you can also tell us what kind of protocol you run and your role. Both are optional.

When you visit the site, our hosting provider automatically processes technical information such as your IP address and browser type to deliver the site and protect it from abuse. We may also measure how the site is used, such as which pages are visited. We don’t use advertising cookies, and we don’t track you across other websites.

How we use it

To tell you when early access opens, to send occasional updates about HackReflex, to understand who HackReflex is for and how the site is used, to protect the site, and to meet legal obligations.

Who we share it with

We don’t sell your personal information. We share it only with service providers that help us run the site and send email, who may use it only to provide those services to us. We may also disclose it when required by law, to protect the rights and safety of HackReflex or others, or as part of a merger, acquisition or sale of assets.

How long we keep it

While you’re on our list. If you ask us to remove you, we’ll delete your information, except for any record we need to honor your request or meet legal obligations.

Your choices and rights

Every email we send includes an unsubscribe link. To have your information deleted, or to exercise any other privacy rights you have where you live, such as access or correction, reply to any email from us. If you’re in the EU or UK, we process your information on the basis of your consent, which you can withdraw at any time.

Security

We use reasonable measures to protect your information. No system is completely secure.

Where your data is processed

HackReflex is a US company. We and our service providers may store and process your information in the United States and other countries.

Changes

We’ll post any changes here and update the date above. If we change how we use your information in a material way, we’ll tell you by email before it takes effect.