
In the last blogpost about the web3 security business, we’ve discussed how it’s hard to create products in this space: https://www.decurity.io/research.
Today, let’s review a few acquisitions that have been made in the DeFi/web3 security space focusing on security service/SaaS providers, we’re not including e.g. custodial providers which are security-adjacent but also serve a core operational function.
Date: 12 November 2019 Link: https://diligence.security/blog/2019/11/stepping-into-the-light/ Valuation: $0(?)
Mythril is an open source tool developed by Bernhard Mueller with some funding from Consensys. It was brought under the umbrella of Consensys Diligence in 2019 as a SaaS smart contract SAST product MythX. Later the product was sunset.
Date: 6 January 2020 Link: https://www.greaterzuricharea.com/en/news/pwc-switzerland-taking-over-chainsecurity-ag Valuation: $0(?)
The Swiss boutique audit firm’s team was brought into PwC during the bear market and then later it spun off and became independent again.
This is not an acquisition, strictly speaking, but still is an example of a merger in the web3 security space and probably the only widely known transaction involving a boutique smart contract auditing firm?
Date: 3 July 2024 Link: https://consensys.io/blog/consensys-acquires-wallet-guard-to-enhance-metamask-security Valuation:$40M (unofficial)
Wallet Guard is one of the dozens of wallet anti-fraud tools, and it was acquired by Metamask. It was pre-seeded by Consensys, but the size of the round was not disclosed. Probably the round was not big and if that’s true, the exit is quite good.
Date: 19 November 2024 Link: https://phantom.com/learn/blog/phantom-acquires-blowfish Valuation:$55M (unofficial)
One more wallet protection startup raised $11.8M in 2022 from Paradigm and naturally was acquired by a wallet startup Phantom shortly before the latter announced $150M series C at $3B valuation.
The acquisition cost is unofficial and rumored quite low, even lower than the seed valuation? The founders probably got $2–6M net upfront each.
Date: 22 August 2024 Link: https://www.theblock.co/post/312583/zellic-code4rena Valuation:~$1M(?)
Code4rena is a pioneer in the world of web3 security contests. They had excessive costs and failed to raised funds, falling into a liquidity crisis. Zellic picked them up and co-branded a new arm called Zenith.
Date: 18 December 2024 Link: https://www.chainalysis.com/blog/chainalysis-hexagate-announcement/ Valuation:$60M (unofficial)
Hexagate is the main rival of the biggest player in the real-time threat detection field (Hypernative). The startup raised $8.6M before and it’s rumored that the acquisition price was $60M, so most likely the exit price matched the pre-seed valuation.
The market is quite thin and there was no viable path to becoming a unicorn, so this was probably a write-off for most VCs. As for the founders, based on industry norms, they likely netted around $3.5–9M each in cash after taxes, liq prefs and other costs. Presumably, they remained with Chainalysis and received a vesting package for the rest of their shares.
Date: 8 January 2025 Link: https://x.com/solayer_labs/status/1877055730890715539 Valuation:N/A
Fuzzland is a true hacker company that built awesome open-source tool ityFuzz and some paid solutions for continuous fuzzing of smart contracts. They’ve raised $3M at seed in early 2024.
Since the acquisition happened less than a year after the seed, it’s likely that it was an acqui-hire targeting the team and tech but not the business itself. The valuation could therefore be quite low.
Date: 13 January 2025 Link: https://www.chainalysis.com/blog/chainalysis-alterya-announcement/ Valuation:$150M
Seems like anti-fraud is the favourite M&A subcategory in web3 security. Alterya raised north of $9.8M in 2022, and based on the numbers, it looks like one of the few acquisitions in the space that wasn’t a failure in terms of VC and delivered some returns to the investors.
Date: 17 February 2025 Link: https://in.marketscreener.com/quote/stock/TAC-INFOSEC-LIMITED-167693836/news/TAC-Infosec-Limited-completedacquisition-of-60-stake-in-CyberScope-Europe-49082014/ Valuation:$2.3M
Cyberscope is a rubber-stamp web3 security company focused on auditing tokens. They’ve been trying to sell the company for a couple years on marketplaces and reported exceptional 98% (!!) margins (1.38M gross profit on $1.4 TTM revenue), evidently because the audits are mostly automated and the only cost is marketing. This was a really lucrative business during the 2021 bull market but obviously not very sustainable.
They’ve been acquired by a really weird web2 cybersecurity company TAC which is somehow public with only $3.6M reported revenue.
There were no IPOs in web3 security yet but they’re coming! Curiously, all the currently planned IPOs are IPOs of mass-market security auditing firms. These are not software product companies and not boutique R&D firms.
Announcement Date:4 August 2025 Link: https://hacken.io/hacken-news/8th-hackenversary/ Planned Valuation: N/A
Hacken is a large-scale security audit firm with very good marketing and presence in both DeFi and CeFi security fields. It is one of the first companies that announced their IPO plans. They’ve restructured as HAI Group and are probably going to go public in Abu Dhabi.
Interestingly, they had their ICO previously. The last tokensale was announced in 2023 and put the company at $23.9M valuation at that moment.
Announcement Date:8 December 2025 Link:https://www.renaissancecapital.com/IPO-Center/News/116367/CyberScope-Web3-Security-nearly-quadruples-shares-offered-ahead-of-$19-mill Planned Valuation: $119M
Shockingly, the first web3 security company to actually IPO on NASDAQ is a tiny rubber-stamping company, recently acquired by another tiny public company.
The IPO size and the valuation are absolutely ridiculous for a declining business. They are trying to IPO at x52 of their acquisition cost. The listing and underwriting alone would cost more than the company is actually worth. Not sure how to read into this case of financial engineering.
Announcement Date:23 January 2026 Link: https://www.theblock.co/post/386882/certik-ipo-2-billion-valuation-first-public-web3-cybersecurity-listing Planned Valuation: $2B
The most famous and controversial web3 mass-market security firm officially announced its IPO plans in early 2026. The planned valuation is $2B, the same as during their previous public funding round in 2022.
In the past, CertiK gained an extremely toxic reputation because of repetitive hacks of audited projects (at least 9 according to rekt.news), for working with known scammers and rug pulls, for hacking Kraken and laundering stolen money (they’ve later settled this case out of court, so it was not prosecuted).
They did a great job at SEO and washing the reputation, the Google search is now flooded with positive or neutral content. Also, apart from doing cheap low-effort audits, they actually have some good engineers as well and had a few interesting research blogposts.
What can we take from all this? I think it is important to understand the outcomes of the web3 security businesses to properly invest both time and money into this field. It is vital that the financial results in web3 security are aligned for the projects, service providers (both individual and businesses), and users.
Web3 Security M&As and IPOs was originally published in Decurity on Medium, where people are continuing the conversation by highlighting and responding to this story.
The researchers who write this are the ones who run the audits.