Hacken
Hacken is a Tallinn-based blockchain cybersecurity firm providing smart-contract audits, Proof-of-Reserves verification, AI-driven threat monitoring via its Extractor platform, and regulatory advisory across MiCA, DORA, and VARA frameworks for centralized exchanges, L1/L2 protocols, DeFi platforms, and government regulators.
- Company typePrivate
- Founded2017
- HeadquartersTallinn, Estonia
- Headcount101–250
- GTM typeB2B
- OfferingServices
What Hacken does
Hacken (legal entity Hacken OÜ) is a private blockchain cybersecurity and compliance firm founded in 2017 and headquartered in Tallinn, Estonia. The company delivers end-to-end security across the digital asset lifecycle, spanning pre-launch services (smart contract audits, blockchain infrastructure audits, dApp audits, tokenomics audits, penetration testing, red teaming, AI/LLM security audits), regulatory compliance advisory (MiCA, DORA, VARA, ISO 27001, CCSS), and continuous post-launch monitoring. Its proprietary Extractor platform provides real-time threat detection with 60+ on-chain and off-chain detectors, AI-powered threat signals, and automated defense actions including transaction firewalls, while its HackenProof crowdsourced platform connects projects to 45,000+ security researchers for ongoing bug discovery. The company holds ISO 27001:2022 certification and maintains a public REST API exposing structured audit data.
Hacken's client base is concentrated but diversified across the Web3 stack: tier-1 centralized exchanges including Bybit, OKX, KuCoin, MEXC, WhiteBIT, and Toobit (with multi-year recurring Proof of Reserves mandates such as KuCoin's 39+ consecutive monthly reports); foundational protocols including the Ethereum Foundation, Base, Polygon, Avalanche, Sui, Near, and the newly added Canton Network; DeFi protocols including Uniswap and 1inch; wallet providers including MetaMask; and government regulators including the Bermuda Monetary Authority. The firm has delivered 2,057+ public security assessments, discovered 26,095+ vulnerabilities, and verified $430B+ in digital asset reserves. Hacken operates as a sales-led enterprise business with global reach, distributing through direct enterprise sales, 180+ ecosystem partnerships, listing-platform integrations (CoinGecko, CoinMarketCap, CER.live), and the Mastercard Crypto Partner Program.
Hacken monetizes through a mix of one-time project audits ($500–$15,000+ per engagement), recurring subscriptions (Extractor monitoring, retainer programs, monthly Proof of Reserves), and higher-value compliance and advisory mandates. Strategic positioning emphasizes regulatory co-creation: the firm holds technical-partner MoUs with ADGM, the Qatar Financial Centre, and the European Blockchain Sandbox, advising on MiCA and DORA best-practice mapping. A 2025 equity-tokenization initiative with Brickken allocated 10% of company equity to $HAI token holders. Founded by Yevheniia Broshevan (CEO) and Dmytro Budorin (Chairman / HAI Group CEO), the company has not disclosed external funding beyond a $2.5M 2017 round, indicating a largely bootstrapped operating history.
Hacken firmographics
Firmographics- Name
- Hacken
- Legal name
- Hacken OÜ
- Website
- https://hacken.io
- Company type
- Private
- Founded year
- 2017
- Operating status
- Operating
- Headcount range
- 101–250 employees
- Short description
- Hacken is a Tallinn-based blockchain cybersecurity firm providing smart-contract audits, Proof-of-Reserves verification, AI-driven threat monitoring via its Extractor platform, and regulatory advisory across MiCA, DORA, and VARA frameworks for centralized exchanges, L1/L2 protocols, DeFi platforms, and government regulators.
- Ownership category
- akta.pro rank
Hacken industry classification
Industry- Product category
- Blockchain Security & Compliance
- NAICS
- Security Systems Services (except Locksmiths) (561621)
- SIC
- Finance Services (6199)
- akta.pro primary industry
- Digital Asset Risk, Security & Audit Tooling (Smart Contract Audit, Threat Monitoring) (FSAGAMAJ)
- akta.pro secondary industries
- Smart Contract Security Tooling (static/dynamic analysis, formal verification) (FSAPABAI), On-Chain Monitoring, Threat Detection & Incident Response (FSAPAJAB)
Keywords
Where Hacken is headquartered
LocationHeadquarters
- HQ city
- Tallinn
- HQ country
- Estonia
- HQ region
- Europe
Offices1 record
Markets served
Hacken business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Others
Revenue model
- Security Audits: Professional security audit services including smart contract audits, blockchain infrastructure audits, dApp audits, penetration testing, tokenomics audits, and cryptography audits. Pricing varies by scope and complexity from $500 to over $15,000 depending on project requirements.
- Extended Security Coverage: Ongoing security services including DualDefense (combining expert audits with crowdsourced reviews), Retainer Services (fixed-fee access to Hacken services), Hacken Extractor (real-time monitoring), and Bug Bounty programs.
- Compliance & Advisory: Regulatory compliance services covering DORA, VARA, CCSS audits, vCISO virtual consulting, and ISO 27001 certification support for digital asset businesses.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom pricing based on audit complexity and scope |
Go-to-market motion1 record
Distribution channels5 records
Marketing channels10 records
Hacken product offering
Product offeringCore offering
Hacken provides end-to-end blockchain security and compliance services for Web3 projects, exchanges, protocols, and institutional clients, including smart contract audits, blockchain infrastructure audits, Proof of Reserves audits, penetration testing, red teaming, AI/LLM security audits, CCSS and tokenomics audits, supported by the proprietary Extractor real-time threat detection platform and the HackenProof crowdsourced bug bounty network. The company also delivers regulatory compliance advisory across MiCA, DORA, VARA, ISO 27001, and CCSS, plus ongoing monitoring through DualDefense, retainer services, and the A3 digital asset risk management product.
Product overview
Hacken is an end-to-end blockchain security and compliance platform offering a comprehensive suite of audit services and security products. The core offerings include Smart Contract Audits, Proof of Reserves Audits, Blockchain Infrastructure Audits, dApp Audits, Penetration Testing, Red Teaming, AI Security Audits, CCSS Audits, and Tokenomics Audits. The platform integrates with complementary security tools including Hacken Extractor (real-time AI-powered threat detection with automated defense), HackenProof Bug Bounty (crowdsourced security testing with 45k+ researchers), and DualDefense (combining expert audits with crowdsourced reviews). Additional offerings include Compliance & Advisory services (MiCA, DORA, VARA, ISO 27001), vCISO virtual security leadership, and A3 digital asset risk management. The $HAI token powers the Hacken ecosystem. The company operates across 30+ blockchain ecosystems including Ethereum, Bitcoin, Avalanche, Polygon, Solana, Base, Arbitrum, and Optimism.
Differentiator
Problem solved
Functional benefit
Products and services
- Smart Contract Audit Comprehensive security review of smart contracts to identify vulnerabilities before deployment, covering code quality, architecture, and security scoring using Hacken's 4-stage audit methodology. Used by blockchain projects, DeFi protocols, exchanges, and foundations before mainnet deployment.
- Proof of Reserves Audit Cryptographic verification that cryptocurrency exchanges and custodians maintain reserves exceeding user liabilities using Merkle Tree technology, with monthly recurring attestation reports. Used by centralized exchanges to demonstrate 1:1 backing and user trust.
- Blockchain Infrastructure Audit Security assessment of Layer 1 and Layer 2 protocol infrastructure, including consensus mechanisms, network architecture, and node security. Used by protocol foundations and core development teams to harden infrastructure.
- dApp Audit Security review of decentralized applications interacting with blockchain networks, covering web2/web3 integration points and application logic. Used by DeFi, NFT, and GameFi application teams.
- Penetration Testing Simulated attacks on web, mobile, APIs, cloud, and infrastructure to identify exploitable weaknesses before attackers do. Used by Web3 companies and exchanges to validate external attack surface.
- Red Teaming Full-scope adversary simulation to test detection, response, and resilience capabilities of organizations against advanced persistent threats. Used by mature Web3 organizations and institutional clients.
- AI Security Audit Specialized security assessment for AI and LLM systems, including prompt injection, tool abuse, and MCP deployment testing. Used by organizations deploying AI agents and LLM-integrated Web3 applications.
- CCSS Audit Assessment of cryptocurrency custody services against the Cryptocurrency Security Standard for institutional-grade key management and wallet infrastructure. Used by custodians, exchanges, and digital asset service providers.
- Tokenomics Audit Validation of token economy design, including token distribution, vesting schedules, incentive structures, and economic sustainability. Used by token-issuing projects before launch.
- Hacken Extractor Real-time threat detection and response platform with AI-powered monitoring, 60+ detectors for on-chain and off-chain risks, and automated defense actions including transaction firewall for blocking malicious transactions, contract pause, address blacklisting, and signer removal. Used by Web3 protocols, exchanges, and asset managers for continuous security monitoring.
- HackenProof Bug Bounty Crowdsourced security testing platform connecting projects with 45,000+ trusted security researchers for bug discovery with pay-for-verified-findings model. Used by Web3 projects for ongoing vulnerability discovery.
- DualDefense Combined expert audit with crowdsourced reviews from HackenProof bug hunters, integrating manual auditor review with 45,000+ researcher community testing. Used by Web3 projects seeking layered audit coverage.
- Compliance & Advisory Regulatory compliance guidance through MiCA, DORA, VARA, ISO 27001, and CCSS audits with controls, evidence, and remediation support. Used by digital asset businesses seeking regulatory licensing and certification.
- vCISO (Virtual CISO) Flexible access to Hacken's security expertise as an alternative to hiring a full-time internal CISO, providing strategic security leadership on a fractional basis. Used by Web3 companies that need CISO-level guidance without a full-time hire.
- A3 (Digital Asset Risk Management) Continuous risk scoring for institutional digital asset portfolios between due diligence cycles, providing ongoing security posture visibility for assets under management. Used by asset managers and institutional investors managing digital asset portfolios.
- $HAI Token Hacken ecosystem token powering trust and transparency in Web3, providing governance utilities and access to platform services, with an equity tokenization initiative linking token holdings to company equity.
Quantifiable outcome
- 2,057+ public security assessments delivered since 2017
- +5 more outcomes
Companies that use Hacken
Customer profileNamed customers20 records
Segments9 records
Ideal customer profiles4 records
Hacken technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability4 records
Feature6 records
Hacken partnerships and signals
Strategic signalPartnerships
Twelve partnerships are on record, tiered core and flagship.
- Canton NetworkcoreHacken became ecosystem auditing provider for Canton Network, a privacy-enabled blockchain for institutional finance. Hacken will support financial institutions, tokenized asset issuers, payment providers, and ecosystem builders in securing Canton-based applications with Daml smart contract audits and specialized security research.
- ChainlinkcorePartnership for Bermuda Monetary Authority's Embedded Supervision Solution. Chainlink provides policy enforcement via Automated Compliance Engine (ACE), reserves verification via Proof of Reserve and Secure Mint capability, and cross-chain interoperability via CCIP. Combined with Hacken's real-time monitoring and Extractor for complete supervisory solution.
- Apex GroupcorePartnership for BMA Embedded Supervision providing independent reserve data from third-party custodian as part of the regulatory compliance solution. Apex Group contributes authenticated reserve data while Hacken provides real-time monitoring layer.
- BlupryntcorePartnership for BMA Embedded Supervision where Bluprynt provides Know Your Issuer (KYI) credential issuance, issuer identity authentication, on-chain credentials, and policy logic. Combined with Hacken's credential behavior monitoring.
- MastercardflagshipHacken is part of Mastercard's Crypto Partner Program, a global initiative bringing together 100+ crypto-native companies, payments providers, and financial institutions to facilitate collaboration on integrating digital assets with established card rails and global commerce flows.
- BrickkencorePartnership for Hacken's equity tokenization initiative allowing $HAI token holders to transition to equity shareholders. Brickken manages the legal and regulatory complexity of tokenizing 10% of company equity through 100 slots at 1 million $HAI tokens each (0.1% ownership).
- AlephiumcoreStrategic MoU partnership under which Hacken provides comprehensive security services to Alephium ecosystem projects including smart contract audits, blockchain protocol audits, penetration testing, dApp audits, bug bounty programs via HackenProof, Proof of Reserves, CCSS audits, and Tokenomics audits. Alephium projects receive 20% discount on core services and 30% discount on Extractor.
- CoinGeckocoreCoinGecko recognizes Hacken audits as valid for their bug bounty program integration, positioning Hacken audits as a trusted security indicator in the crypto community. Hacken audits appear on CoinGecko project pages.
- CoinMarketCapcoreCoinMarketCap integrates Hacken audit status as a security indicator for listed projects, providing marketing exposure and credibility validation for audited projects.
- CER.livecoreCER.live certification platform recognizes Hacken audits as valid security assessments, with Hacken audits integrated into exchange security ratings.
- European Blockchain Sandbox (EBSI)coreHacken is advising MiCA and DORA best-practice mapping as part of the European Blockchain Sandbox initiative, contributing to regulatory framework development for blockchain in Europe.
- ADGM (Abu Dhabi Global Market)coreMoU to draft DLT security-compliance standards. Hacken serves as technical partner shaping Web3 oversight for Abu Dhabi's regulatory framework.
Scale indicators10 records
Recent moves10 records
Expansion highlights6 records
Hacken competitors and assessment
Company assessmentDirect peers
- CertiK: CertiK is the largest smart contract auditor and blockchain security firm, founded in 2018 by professors from Columbia and Yale. It competes head-to-head with Hacken on smart contract audits, formal verification, Skynet monitoring, and serves many of the same CEX, DeFi, and L1/L2 customers.
- OpenZeppelin: OpenZeppelin is a leading smart contract security and developer platform, known for its open-source libraries and security audit services. It directly competes with Hacken for Ethereum, DeFi, and L2 protocol audit engagements, and also offers Defender for ongoing monitoring.
- Trail of Bits: Trail of Bits is a well-established cybersecurity firm with a strong blockchain security practice offering smart contract audits, formal verification, and security tooling. It competes with Hacken for high-end audit and applied cryptography engagements, particularly among protocol teams.
- Quantstamp: Quantstamp is a smart contract security company providing audits and continuous security monitoring for DeFi, NFTs, and enterprise blockchain applications. It competes with Hacken in the same audit and assurance market with similar product positioning.
- SlowMist: SlowMist is a blockchain security firm specializing in smart contract audits, threat intelligence, and incident response. Founded in 2018, it competes with Hacken across audit, on-chain monitoring, and exchange security assessments, especially in Asian markets.
- Consensys Diligence: Consensys Diligence is the smart contract audit arm of Consensys, focused on Ethereum and EVM-based protocols. It competes with Hacken for protocol-level audits across DeFi and L2 ecosystems.
- ChainSecurity: ChainSecurity (acquired by PwC) provides smart contract audits and formal verification, with a strong focus on DeFi and Ethereum protocols. It is a direct competitor in the same high-end audit and formal verification market.
Emerging players
- BlockSec: BlockSec provides smart contract audits and an on-chain monitoring/incident response product (Phalcon). It overlaps with Hacken's audit and Extractor offerings, with growing strength in DeFi and exploit-blocking tooling.
- Zellic: Zellic is a high-end smart contract security firm founded by former Trail of Bits and Facebook security researchers, focused on audits and formal verification for cutting-edge protocols. It competes with Hacken for premium audit engagements.
- Runtime Verification: Runtime Verification provides formal verification and security audits for smart contracts and mission-critical systems. It competes with Hacken in the audit and formal verification tier, particularly for L1 protocol clients.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
Hacken social profiles
Digital presenceHacken compliance and trust
Trust signalCompliance2 records
Hacken financial estimates
Financial estimateRevenue estimate
Valuation estimate
Hacken leadership team
Management profileNumber of profiles
Profiles7 records
Hacken funding detail
Funding detailFunding overview
Funding rounds1 record
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Hacken M&A and investment
M&A and investmentM&A
Investments1 record
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Hacken
What does Hacken do?
Hacken provides end-to-end blockchain security and compliance services for Web3 projects, exchanges, protocols, and institutional clients, including smart contract audits, blockchain infrastructure audits, Proof of Reserves audits, penetration testing, red teaming, AI/LLM security audits, CCSS and tokenomics audits, supported by the proprietary Extractor real-time threat detection platform and the HackenProof crowdsourced bug bounty network. The company also delivers regulatory compliance advisory across MiCA, DORA, VARA, ISO 27001, and CCSS, plus ongoing monitoring through DualDefense, retainer services, and the A3 digital asset risk management product.
Is Hacken a public or private company?
Hacken is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Hacken founded?
Hacken was founded in 2017. It employs 101 to 250 people.
Where is Hacken based?
Hacken is headquartered in Tallinn, Estonia, in the Europe region.
How does Hacken make money?
Three revenue lines are on record. Security Audits are the primary driver. The others are extended Security Coverage and compliance & Advisory.
Who are Hacken's main competitors?
Direct peers on record are CertiK, OpenZeppelin, Trail of Bits, Quantstamp, SlowMist, Consensys Diligence and ChainSecurity. Emerging players are BlockSec, Zellic and Runtime Verification.
Does Hacken have an API?
Yes. Hacken provides a public REST API endpoint at https://hacken.io/api/audits that allows retrieval of audit information without authentication. The API returns structured audit data including audit name, client name, audit date, scope parameters (repository, commit, assets audited), audit type, labels, platforms, languages, report links, total findings, project links, audit description, issues with status and severity, and audited contracts with chain, chainId, address, repository, commit, filePath, and contractName. Developer documentation is at docs.hacken.io/rest-apis/get-audits.
What industry is Hacken in?
Hacken's product category is Blockchain Security & Compliance. Its primary akta.pro industry code is FSAGAMAJ, Digital Asset Risk, Security & Audit Tooling (Smart Contract Audit, Threat Monitoring), with a secondary code of FSAPABAI, Smart Contract Security Tooling (static/dynamic analysis, formal verification). Its NAICS code is 561621 and its SIC code is 6199.