Web3 Security M&As and IPOs

How consolidation is reshaping the web3 security market, and what the wave of acquisitions and public listings means for protocols choosing an auditor.

· 5 MIN READ · DECURITY
The state of VC funded zombie companies
The state of VC funded zombie companies

In the last blogpost about the web3 security business, we’ve discussed how it’s hard to create products in this space: https://www.decurity.io/research.

Today, let’s review a few acquisitions that have been made in the DeFi/web3 security space focusing on security service/SaaS providers, we’re not including e.g. custodial providers which are security-adjacent but also serve a core operational function.

Acqui-hires

MythX acquired by Consensys Diligence

Date: 12 November 2019 Link: https://diligence.security/blog/2019/11/stepping-into-the-light/ Valuation: $0(?)

Mythril is an open source tool developed by Bernhard Mueller with some funding from Consensys. It was brought under the umbrella of Consensys Diligence in 2019 as a SaaS smart contract SAST product MythX. Later the product was sunset.

Chainsecurity acquired by PwC

Date: 6 January 2020 Link: https://www.greaterzuricharea.com/en/news/pwc-switzerland-taking-over-chainsecurity-ag Valuation: $0(?)

The Swiss boutique audit firm’s team was brought into PwC during the bear market and then later it spun off and became independent again.

This is not an acquisition, strictly speaking, but still is an example of a merger in the web3 security space and probably the only widely known transaction involving a boutique smart contract auditing firm?

Acquisitions

Wallet Guard acquired by Consensys

Date: 3 July 2024 Link: https://consensys.io/blog/consensys-acquires-wallet-guard-to-enhance-metamask-security Valuation:$40M (unofficial)

Wallet Guard is one of the dozens of wallet anti-fraud tools, and it was acquired by Metamask. It was pre-seeded by Consensys, but the size of the round was not disclosed. Probably the round was not big and if that’s true, the exit is quite good.

Blowfish acquired by Phantom

Date: 19 November 2024 Link: https://phantom.com/learn/blog/phantom-acquires-blowfish Valuation:$55M (unofficial)

One more wallet protection startup raised $11.8M in 2022 from Paradigm and naturally was acquired by a wallet startup Phantom shortly before the latter announced $150M series C at $3B valuation.

The acquisition cost is unofficial and rumored quite low, even lower than the seed valuation? The founders probably got $2–6M net upfront each.

Code4rena acquired by Zellic

Date: 22 August 2024 Link: https://www.theblock.co/post/312583/zellic-code4rena Valuation:~$1M(?)

Code4rena is a pioneer in the world of web3 security contests. They had excessive costs and failed to raised funds, falling into a liquidity crisis. Zellic picked them up and co-branded a new arm called Zenith.

Hexagate acquired by Chainalysis

Date: 18 December 2024 Link: https://www.chainalysis.com/blog/chainalysis-hexagate-announcement/ Valuation:$60M (unofficial)

Hexagate is the main rival of the biggest player in the real-time threat detection field (Hypernative). The startup raised $8.6M before and it’s rumored that the acquisition price was $60M, so most likely the exit price matched the pre-seed valuation.

The market is quite thin and there was no viable path to becoming a unicorn, so this was probably a write-off for most VCs. As for the founders, based on industry norms, they likely netted around $3.5–9M each in cash after taxes, liq prefs and other costs. Presumably, they remained with Chainalysis and received a vesting package for the rest of their shares.

Fuzzland acquired by Solayer

Date: 8 January 2025 Link: https://x.com/solayer_labs/status/1877055730890715539 Valuation:N/A

Fuzzland is a true hacker company that built awesome open-source tool ityFuzz and some paid solutions for continuous fuzzing of smart contracts. They’ve raised $3M at seed in early 2024.

Since the acquisition happened less than a year after the seed, it’s likely that it was an acqui-hire targeting the team and tech but not the business itself. The valuation could therefore be quite low.

Alterya acquired by Chainalysis

Date: 13 January 2025 Link: https://www.chainalysis.com/blog/chainalysis-alterya-announcement/ Valuation:$150M

Seems like anti-fraud is the favourite M&A subcategory in web3 security. Alterya raised north of $9.8M in 2022, and based on the numbers, it looks like one of the few acquisitions in the space that wasn’t a failure in terms of VC and delivered some returns to the investors.

Cyberscope acquired by TAC

Date: 17 February 2025 Link: https://in.marketscreener.com/quote/stock/TAC-INFOSEC-LIMITED-167693836/news/TAC-Infosec-Limited-completedacquisition-of-60-stake-in-CyberScope-Europe-49082014/ Valuation:$2.3M

Cyberscope is a rubber-stamp web3 security company focused on auditing tokens. They’ve been trying to sell the company for a couple years on marketplaces and reported exceptional 98% (!!) margins (1.38M gross profit on $1.4 TTM revenue), evidently because the audits are mostly automated and the only cost is marketing. This was a really lucrative business during the 2021 bull market but obviously not very sustainable.

They’ve been acquired by a really weird web2 cybersecurity company TAC which is somehow public with only $3.6M reported revenue.

IPOs

There were no IPOs in web3 security yet but they’re coming! Curiously, all the currently planned IPOs are IPOs of mass-market security auditing firms. These are not software product companies and not boutique R&D firms.

Hacken IPO

Announcement Date:4 August 2025 Link: https://hacken.io/hacken-news/8th-hackenversary/ Planned Valuation: N/A

Hacken is a large-scale security audit firm with very good marketing and presence in both DeFi and CeFi security fields. It is one of the first companies that announced their IPO plans. They’ve restructured as HAI Group and are probably going to go public in Abu Dhabi.

Interestingly, they had their ICO previously. The last tokensale was announced in 2023 and put the company at $23.9M valuation at that moment.

Cyberscope IPO

Announcement Date:8 December 2025 Link:https://www.renaissancecapital.com/IPO-Center/News/116367/CyberScope-Web3-Security-nearly-quadruples-shares-offered-ahead-of-$19-mill Planned Valuation: $119M

Shockingly, the first web3 security company to actually IPO on NASDAQ is a tiny rubber-stamping company, recently acquired by another tiny public company.

The IPO size and the valuation are absolutely ridiculous for a declining business. They are trying to IPO at x52 of their acquisition cost. The listing and underwriting alone would cost more than the company is actually worth. Not sure how to read into this case of financial engineering.

CertiK IPO

Announcement Date:23 January 2026 Link: https://www.theblock.co/post/386882/certik-ipo-2-billion-valuation-first-public-web3-cybersecurity-listing Planned Valuation: $2B

The most famous and controversial web3 mass-market security firm officially announced its IPO plans in early 2026. The planned valuation is $2B, the same as during their previous public funding round in 2022.

In the past, CertiK gained an extremely toxic reputation because of repetitive hacks of audited projects (at least 9 according to rekt.news), for working with known scammers and rug pulls, for hacking Kraken and laundering stolen money (they’ve later settled this case out of court, so it was not prosecuted).

They did a great job at SEO and washing the reputation, the Google search is now flooded with positive or neutral content. Also, apart from doing cheap low-effort audits, they actually have some good engineers as well and had a few interesting research blogposts.

What can we take from all this? I think it is important to understand the outcomes of the web3 security businesses to properly invest both time and money into this field. It is vital that the financial results in web3 security are aligned for the projects, service providers (both individual and businesses), and users.

Web3 Security M&As and IPOs was originally published in Decurity on Medium, where people are continuing the conversation by highlighting and responding to this story.

Need this expertise on your protocol?

The researchers who write this are the ones who run the audits.

REQUEST FORM