Halborn in 2026: Crypto’s Coroner Goes to Wall Street
Halborn built its name auditing code, but in 2026 the Miami-born firm is better known for writing crypto's autopsies. Now a new CEO is selling that expertise to Wall Street.
When the autopsy arrives before the funeral
On 18 April 2026, roughly 116,500 rsETH, worth about $292 million, drained out of Kelp DAO’s cross-chain bridge in a matter of hours, leaving wrapped ether stranded across some twenty chains and briefly ranking as the single largest crypto theft of the year, according to CoinDesk. Before the funds were fully traced, before Kelp had finished moving its restaking token onto a different bridge, a detailed post-mortem appeared under a now-familiar banner: Explained: The Kelp DAO Hack (April 2026). The author was not Kelp. It was Halborn, a Miami-born blockchain security firm that has quietly become the outfit crypto calls when it needs someone to read the body.
The revealing part of the Kelp autopsy was what it did not find. There was no clever flaw in Kelp’s smart contracts. The attacker, later tied by multiple analytics firms to North Korea’s Lazarus Group, socially engineered a developer at bridge provider LayerZero, harvested session keys, and poisoned the infrastructure that verified cross-chain messages, so a single compromised verifier could wave a fraudulent withdrawal through. OpenZeppelin, reviewing the same incident, published its own note under a title that read like an epitaph for a decade of audit marketing: $292 Million Lost, Zero Bugs Found.
Halborn is usually filed under the label auditor. In 2026 that description is too narrow. The firm is closer to a red team and a coroner: it breaks systems before attackers do, and when prevention fails, it dissects the wreckage in public. And now, under a chief executive recruited from the traditional security industry, it is trying to sell both services to banks. This is the story of how a bootstrapped offensive-security shop became crypto’s default post-mortem author, what its 2026 caseload says about where the money is actually being stolen, and why its move toward Wall Street is a bet on the next phase of on-chain risk.
Who Halborn actually is
Halborn was founded in 2019 by Steven Walbroehl and Rob Behnke, two security practitioners who, by their own account, spent roughly three years bootstrapping the company before taking a dollar of outside money. That changed in July 2022, when Halborn announced a $90 million Series A led by growth investor Summit Partners, with participation from Castle Island Ventures, Digital Currency Group, Brevan Howard, Third Prime, Sky Vision Capital, and Fenwick. It was the firm’s first external raise, and it landed at the top of the last bull market, when demand for anything labeled Web3 security looked bottomless.
The company that money built is more specialized than the headline suggests. Halborn is fully remote, still runs a comparatively lean bench of senior engineers rather than a mass-market audit factory, and, per the partnership materials it published in 2026, has now completed more than 4,000 security assessments. Its client base spans layer-1 foundations, infrastructure providers, exchanges, and, increasingly, regulated finance; the announcement of its leadership change named the Solana Foundation, Circle, and BNY Mellon among its customers. Its coverage is deliberately broad across virtual machines: EVM chains such as Ethereum, Polygon, and Avalanche, plus Solana, Cosmos, the Move-based chains Sui and Aptos, and Algorand.
The mission statement on its own site is unglamorous and telling: to identify and rectify vulnerabilities in blockchain applications, ensuring the safety and integrity of blockchain projects at every stage of development, per Halborn. Note the phrase every stage. Halborn does not sell a single report; it sells a relationship that spans design review, code audit, offensive testing, and, when the worst happens, incident response.
A red team first, an auditor second
Most people meet Halborn through its smart-contract audits, but the firm’s center of gravity has always been offensive security. Its engineers come from penetration testing and red-team backgrounds, and its service menu reflects that. Alongside a manual code security audit, Halborn sells web-application and cloud-infrastructure penetration testing, full red-team exercises that simulate a determined adversary, layer-1 protocol assessments, and custody and key-management reviews for the wallets and signing setups that hold the actual money.
That breadth matters because, as its own caseload keeps proving, the contract is rarely the weakest link. A reviewer who only reads Solidity would have missed almost every marquee heist of the past two years. Halborn’s published assurance and advisory lines are built to look at the whole attack surface, not just the on-chain slice of it.
| Service line | What it covers | Why it matters in 2026 |
|---|---|---|
| Smart contract and code audit | Manual review of on-chain logic across EVM, Solana, Cosmos, and Move | Catches the most common exploit class, but not the most costly |
| Red team exercises | Simulated end-to-end attacks on people, process, and infrastructure | Targets the social-engineering and key-theft vectors behind the biggest losses |
| Penetration testing | Web application and cloud infrastructure testing | Covers the off-chain systems (RPC nodes, dashboards, pipelines) attackers pivot through |
| Custody and key-management review | Assessment of wallet, multisig, and signing architecture | Directly addresses the stolen-key vector that dominates 2026 losses |
| AI security and AI red teaming | Testing of AI models and agent systems for adversarial failure | New for 2026 as protocols wire language models into on-chain workflows |
| Advisory and CISO-as-a-service | Architecture review, compliance readiness, ongoing security leadership | The wedge into institutional and regulated clients |
The newest addition is the AI line. As protocols bolt large language models and autonomous agents onto trading, treasury, and support workflows, Halborn now offers AI security assessments and AI red teaming, probing those systems for prompt injection, data leakage, and the adversarial failure modes that classic audits never contemplated. It is a small business today, but it signals where the firm thinks the next attack surface is opening.
Rab13s: the disclosure that made the name
If one piece of research put Halborn on the map, it was Rab13s. In March 2022, the firm was hired to review the Dogecoin codebase. Led by senior offensive security engineer Hossam Mohamed, the team found several exploitable bugs, then realized the same flaws lived in the shared lineage of code that Dogecoin descends from. The conclusion was startling: the vulnerabilities affected more than 280 networks, including Litecoin and Zcash, putting over $25 billion in digital assets at risk, according to Halborn’s disclosure.
The most serious of the Rab13s issues sat in the peer-to-peer layer: a crafted consensus message could crash a node, opening a path toward the kind of denial-of-service that can soften a network up for a 51% attack. A separate remote-code-execution bug, unique to Dogecoin’s RPC interface, could let an attacker run code on an individual miner. Halborn worked quietly with Dogecoin, Litecoin, and Zcash to patch before going public in a March 2023 coordinated disclosure; many smaller forks never applied the fix. Rab13s was a marketing coup as much as a security one, but it was earned the hard way, and it established the template Halborn still runs on: find the deep, cross-ecosystem bug nobody else is looking for, then tell the story well.
The Explained series: crypto’s public coroner
Somewhere along the way, Halborn turned the incident post-mortem into a product. Its blog runs a steady series of Explained pieces (Explained: The Balancer Hack, Explained: The Kelp DAO Hack, Explained: The Humanity Protocol Hack) alongside a monthly Month in Review roundup of the largest DeFi exploits. The autopsies are fast, technical, and free, and they are read far beyond the victim’s own community.
There is a reason the genre matters so much in crypto specifically. When a bank loses customer money, a chain of regulators, insurers, and courts eventually assigns blame and arranges recovery. When a decentralized protocol is drained, often none of that machinery applies. Victims of a DeFi exploit rarely have a complaint desk to call; the code executed as written, and the counterparties are pseudonymous. Into that vacuum steps the public post-mortem, which has become crypto’s substitute for a regulatory finding: the closest thing to an official account of what went wrong and who, if anyone, should have caught it. Whoever writes the definitive autopsy shapes the narrative, and Halborn has made sure that is frequently Halborn.
The business logic is elegant. Each autopsy demonstrates competence to the exact audience most likely to be shopping for a security partner: protocol teams who just watched a peer get robbed. It is content marketing that doubles as a public good, and it is far more persuasive than any sales deck.
A year of autopsies: what the 2026 caseload shows
Read Halborn’s 2026 output next to the industry’s incident data and a clear pattern emerges. The biggest losses are not clever math bugs; they are compromised humans, keys, and infrastructure. The table below collects marquee incidents the firm and its peers have dissected over the past year and a half.
| Incident | Date | Approx. loss | Root cause | Code bug or operational? |
|---|---|---|---|---|
| Kelp DAO | Apr 2026 | $292M | Compromised cross-chain bridge verifier via a social-engineered developer | Operational / infrastructure |
| Drift Protocol | Apr 2026 | $285M | Admin transactions pre-signed after a months-long social-engineering con | Operational / human |
| Balancer V2 | Nov 2025 | $128M | Rounding error in Composable Stable Pools exploited via crafted batch swaps | Code bug |
| Humanity Protocol | Jun 2026 | $36M | Private keys pulled from a malware-infected employee laptop | Operational / key theft |
| Cetus (Sui) | May 2025 | $223M | Faulty integer-overflow check in a third-party math library | Code bug |
Take the two biggest. Drift Protocol, a Solana perpetuals venue, lost about $285 million on 1 April 2026 in what TRM Labs and Chainalysis describe as the payoff of a months-long North Korean social-engineering operation. The attackers spent time cultivating members of Drift’s security council, used Solana’s durable-nonce feature to get them to unknowingly pre-sign transactions that handed over admin control, then whitelisted a worthless token as collateral and borrowed the treasury against it, draining real assets in roughly twelve minutes. Not one line of that involved a Solidity or Rust vulnerability. The exploit was the trust between colleagues.
Kelp DAO’s $292 million loss followed the same shape a few weeks later, hitting the LayerZero bridge that moved its rsETH liquid restaking token. rsETH is one of a crowded field of staked-ether derivatives; readers weighing that market can see our breakdown of Lido, Rocket Pool, and Frax. The Kelp attacker did not care which token it was. It compromised the plumbing, not the product.
Balancer is the exception that proves the rule. Its November 2025 loss of about $128 million was a genuine code bug, a rounding error in the V2 Composable Stable Pools that an attacker amplified with dozens of crafted micro-swaps until the discrepancy reached double digits per operation, draining pools across six chains in under half an hour, as Check Point Research documented. Even here the lesson bites: Balancer’s vault had been audited many times over by multiple top firms, and the bug survived every review. Humanity Protocol, meanwhile, lost about $36 million in June 2026 when malware on a single developer laptop exposed seven private keys, handing an attacker control of a hot wallet and two sets of bridge admin keys, per Decrypt. One laptop.
The costliest hack is never in the code
The aggregate data makes the pattern undeniable. In its report on the first half of 2026, TRM Labs counted 207 hacks, a record for any six-month stretch, yet total losses fell to about $972 million, less than half of the $2.3 billion stolen a year earlier. More than a hundred of those incidents were small smart-contract exploits. But infrastructure and operational compromises, only around 15% of incidents, accounted for roughly 76% of the dollars lost. North Korea-linked actors alone were responsible for about $643 million, close to two-thirds of the total, driven almost entirely by Drift and Kelp.
2025 told the same story at larger scale. Chainalysis put total theft above $3.4 billion, with at least $2.02 billion attributed to North Korea, much of it from the $1.5 billion Bybit heist in February 2025, still the largest single crypto theft on record and, again, a case of stolen signing access rather than broken contract logic.
This is the strategic backdrop to Halborn’s whole business. If the money is leaving through keys, people, and infrastructure, then the firm best positioned to matter is not the one with the tidiest Solidity checklist; it is the one that also runs red teams, tests custody setups, and shows up after the breach. It is why the industry keeps relearning that stolen keys beat broken code, and why a security firm that only audits contracts is fighting the last war.
Incident response: the number you call after the money is gone
The post-mortems are the visible tip of a less visible practice: incident response. When a protocol is being drained, or has just been, Halborn is one of a small set of firms it can call to run forensics, trace funds on-chain, coordinate with exchanges and law enforcement to freeze what can be frozen, and contain the damage. The autopsy that shows up on the blog a week later is the sanitized public output of that emergency work.
The Kelp case shows what good containment looks like even inside a catastrophic loss. After the initial theft, defenders paused contracts fast enough to block a second withdrawal of roughly $95 million, and the Arbitrum Security Council, working with law enforcement, froze more than 30,000 ETH of the attacker’s downstream funds, as documented in Halborn’s post-mortem. In the Humanity Protocol incident, forensic reconstruction of exactly which seven keys leaked, and how, is what let responders and the community understand the blast radius and argue over whether it was really an outside attacker or an inside job.
Incident response is also where crypto’s strange culture of on-chain negotiation plays out, the ritual, pioneered in cases like the 2023 Euler Finance exploit, in which defenders message the attacker directly and offer a bounty to return most of the funds. Firms like Halborn increasingly sit in the middle of those conversations, part investigator, part hostage negotiator. It is a service with no clean analog in traditional software security, and it is fast becoming the reputational core of the modern crypto security firm.
Audited, and hacked anyway
None of this means audits are worthless. It means they are necessary and nowhere near sufficient, and the industry has been slow to say so out loud. An audit is a snapshot in time, usually squeezed into a two-to-four-week window, scoped to the code in front of the reviewers, and blind by definition to what happens after: a later unaudited patch, a misconfigured bridge, a signer who gets phished, an economic design that only breaks under live market conditions.
The Cetus hack on Sui in May 2025 is the cleanest example of code that was in scope and still slipped through. The roughly $223 million exploit traced to a faulty integer-overflow check in a third-party math library, and it had passed through the hands of several auditors before it blew up. Balancer’s vault had been reviewed more than ten times. Other 2026 victims never had a code bug at all: the Arbitrum perpetuals venue Ostium was drained through a compromised oracle key, and a chain of derivatives protocols lost funds to operational failures rather than logic errors. Several of the year’s audited-yet-hacked names sat squarely in the fast-growing world of on-chain derivatives, a market we cover in our guide to perp DEXs.
Some practitioners are blunt about it. After the Balancer loss, Suhail Kakar, a developer-relations lead at TAC Blockchain, noted that the vault had been audited three separate times by different firms and still got hacked, arguing that the space needs to accept that being audited by a big name means almost nothing, because, as he put it, code is hard and DeFi is harder. That is not an argument against audits. It is an argument for treating the audit badge as one control among many rather than a guarantee, which is precisely the case Halborn’s broader offensive-and-response model makes.
What a Halborn engagement costs
Halborn does not publish a rate card, and prices vary enormously with scope, chain, and urgency. Public market references give a sense of the range. Sherlock’s 2026 pricing reference puts simple token audits as low as a few thousand dollars and enterprise-grade, multi-chain systems above $250,000, with a typical DeFi protocol audit landing somewhere between $50,000 and $100,000. Rushing the timeline adds a premium, and an emergency turnaround of under a week can more than double the bill; formal verification, the most rigorous mathematical technique, can add tens of thousands on its own.
Halborn sits at the premium end of that market, and it sells more than a single report. For a serious protocol, the real number is not one audit but a security budget, and the leading teams now treat it that way. When Aave prepared its V4 lending upgrade, it stood up a layered program reportedly worth around $1.5 million, spanning multiple audits, competitions, and formal methods. That is the tier of spending Halborn’s institutional pitch assumes, and it is a world away from the token project that buys a $10,000 checkbox audit to satisfy an exchange listing.
Where Halborn sits in a crowded field
Halborn is one name in a competitive and consolidating market. The table below sketches the main categories and where the firm fits.
| Firm or platform | Reputation and niche |
|---|---|
| OpenZeppelin | Author of the contract libraries much of DeFi is built on; broad audit and tooling practice |
| Trail of Bits | Deep research and cryptography; open-source tools such as Slither and Echidna |
| Halborn | Offensive security, red teaming, incident response, and an institutional pivot |
| CertiK | High volume and on-chain monitoring; also the most controversy-dogged of the majors |
| Zellic, OtterSec | Specialists in Solana and Rust-heavy systems |
| Certora | Formal verification, proving properties of code mathematically |
| Immunefi, Sherlock, Cantina | Bug-bounty and competitive-audit platforms offering crowdsourced coverage |
The competitive layer is shifting under everyone. The contest platform Code4rena, which popularized crowdsourced audits with cash prize pools, wound down in May 2026, with bug-bounty leader Immunefi absorbing its clients and researchers. That consolidation leaves a market with two poles: fixed-fee expert firms like Halborn on one side, and crowdsourced bounty-and-contest platforms on the other, with protocols increasingly buying from both. Halborn’s answer to the commoditization pressure is to move up the value chain, toward the offensive, incident-response, and institutional work that a prize pool cannot easily replicate.
Boschung’s bet: from crypto-native to Wall Street’s security desk
The clearest signal of where Halborn is heading is who runs it. In September 2024 the founders handed the chief-executive role to Jacques Boschung, a veteran of the traditional cybersecurity industry who had most recently led Kudelski Security. Rob Behnke became executive chairman and president; Steven Walbroehl stayed on as chief technology officer. On announcing the change, Boschung said he was thrilled to join Halborn at such a pivotal moment in the company’s journey, while Behnke reflected that it had been an honor to lead and build Halborn over the previous five years. The subtext was explicit: the firm cast itself as a facilitator of enterprise adoption of distributed-ledger technology and tokenization, not just a DeFi auditor.
That pivot became concrete in 2026. Halborn partnered with The Vault, an institutional custody and treasury infrastructure provider, to launch a joint advisory program for banks and financial institutions building digital-asset infrastructure. The division of labor is telling: The Vault designs the custody, compliance, and treasury architecture across a four-to-six-week engagement, and Halborn independently validates the security and risk framework behind it, per the partnership announcement. Boschung framed the fit in a single line: Halborn brings deep experience at the intersection of TradFi and DeFi, and will provide independent risk and security validation for firms implementing the Vault blueprint.
The logic is the same one drawing the rest of finance on-chain. As banks move toward tokenized cash, collateral, and settlement, and as real-world-asset lending pulls Wall Street into DeFi credit, the institutions doing it need someone to test the plumbing before regulators and shareholders ask hard questions. Much of that plumbing is exactly what keeps failing in the exploit data: multisig and key-management setups, the kind of smart-account architecture we unpack in our guide to what smart accounts let you do. Halborn is also positioning around longer-horizon threats and courting this audience directly, hosting ACCESS, a digital-asset security summit staged at the New York Stock Exchange for banks, security executives, and technology leaders.
Who watches the watchmen: regulation and accountability
Here is the uncomfortable fact underneath the whole industry: no US regulator accredits smart-contract auditors, and none mandates a code audit in the first place. There is no PCAOB for Solidity, no licensing board, no statutory liability regime of the kind that governs financial auditors. An audit firm’s quality is policed almost entirely by reputation, which is one more reason the public post-mortem carries so much weight; it is the closest thing the market has to a scoreboard.
Nor is that likely to change soon. The SEC under chair Paul Atkins has spent 2026 pulling in a deregulatory direction. Its Project Crypto agenda is aimed at clarifying which tokens are securities through a formal taxonomy and a reworked application of the Howey test, not at setting engineering standards for how those tokens’ code is reviewed. The regulatory conversation is about classification and disclosure; the security of the code itself remains a private-market matter, negotiated between protocols, their auditors, and their insurers.
That gap cuts to the heart of the accountability problem. Audit contracts almost universally disclaim financial liability, so a firm that misses a bug is rarely on the hook for the loss. When a Cetus or a Balancer is drained despite passing review, the only real sanction is reputational, and even that is muted, because the biggest 2026 losses were operational rather than code-level and easy to argue fell outside any audit’s scope. The market’s answer, for now, is not regulation but layering: audits plus red teams plus bug bounties plus insurance plus a fast, credible post-mortem when it all fails. Halborn is betting its future on selling as many of those layers as possible.
What Halborn’s rise says about crypto security in 2026
Halborn’s arc mirrors the maturation of crypto security itself. The firm started as an offensive-security boutique that made its name on a spectacular cross-chain bug, grew on the back of a bull-market raise, and then discovered that its most durable asset was not the audit report but the autopsy: the credibility that comes from being the team that explains, clearly and quickly, how the money left the building.
The 2026 data has handed it a thesis. As smart-contract tooling improves and the common bugs get harder to find, attackers have moved up the stack to people, keys, and infrastructure, where the real money now sits. That plays to Halborn’s offensive and incident-response strengths and away from the commoditized checkbox audit. And the pivot to institutions is a bet that the next great pool of value at risk is not a memecoin’s liquidity pool but a bank’s tokenized settlement rail.
Whether Halborn can be both crypto’s punk-rock red team and Wall Street’s buttoned-up validation partner is the open question. The two cultures do not always mix. But the underlying insight is sound, and increasingly hard to argue with: in crypto, an audit was never going to be enough, and the firms that thrive will be the ones that can break a system, defend it, and, when it breaks anyway, tell the world exactly what happened.
Frequently Asked Questions
What is Halborn?
Halborn is a blockchain security firm founded in Miami in 2019 by Steven Walbroehl and Rob Behnke. It offers smart-contract audits, offensive red-team and penetration testing, incident response, and security advisory across chains including Ethereum, Solana, Cosmos, and the Move ecosystem. It raised a $90 million Series A led by Summit Partners in 2022.
Who is the CEO of Halborn?
Jacques Boschung has been chief executive since September 2024, brought in from the traditional cybersecurity industry after leading Kudelski Security. Co-founder Rob Behnke became executive chairman and president, and co-founder Steven Walbroehl remained chief technology officer.
What was the Rab13s vulnerability?
Rab13s was a set of vulnerabilities Halborn found while auditing the Dogecoin codebase in March 2022. The same flaws affected more than 280 networks, including Litecoin and Zcash, putting over $25 billion in assets at risk, and could enable denial-of-service or remote code execution. Halborn disclosed the issues publicly in March 2023 after the main chains were patched.
Can a protocol still be hacked after a Halborn audit?
Yes. An audit is a point-in-time review scoped to specific code, so it cannot cover a later unaudited change, a misconfigured bridge, a phished signer, or an economic flaw that only surfaces in live markets. In 2026 most stolen value came from key theft and operational compromise, which fall outside what a code audit examines.
How much does a crypto security audit cost in 2026?
Prices range widely, from a few thousand dollars for a simple token contract to more than $250,000 for complex multi-chain systems, with a typical DeFi protocol audit costing roughly $50,000 to $100,000. Rushed or emergency timelines and add-ons such as formal verification raise the price further.
By Nathan Reeves, HOGE Wire Security and Exploits desk.