Cointelegraph Report: SlowMist Founder Cos on the Core of On-Chain Security — Speed and Coordination
Recently, the globally renowned blockchain media outlet Cointelegraph published a feature article titled “Meet the onchain crypto detectives fighting crime better than the cops,” focusing on on-chain investigators and researchers within the crypto security industry.
Cos, founder of SlowMist, was one of the interviewees and shared insights into the team’s response workflows during major security incidents, their product and service framework, as well as their observations on the broader security landscape of the industry.
Speed Is the First Imperative of Security
In the interview, Cos outlined SlowMist’s standardized incident response mechanism. He noted that on-chain attacks are often characterized by rapid propagation, cross-chain spread, and extremely short response windows, making speed a decisive factor in determining the ultimate scale of losses.
“Once an incident occurs, we immediately activate a war room. The goal is to track the attack as quickly as possible, contain the situation, and issue alerts.”
Within the war-room setup, the team rapidly divides responsibilities based on the attack path, covering areas such as on-chain fund tracing, infrastructure analysis, domain-related risk assessment, and secondary-attack monitoring. As the incident evolves, trusted project teams, exchanges, partner organizations, and affected victims gradually join the response effort, sharing intelligence and coordinating actions, while strictly controlling the risk of information leakage.
Cos also acknowledged that professional security teams must move first in the early stages of an incident:
“Law enforcement typically responds more slowly, as they need time to collect evidence. But attacks can cause massive losses within minutes. That’s why we need speed — we must act before greater damage occurs.”
This, he explained, is why security teams within the industry often bear the earliest and heaviest response burden during major on-chain incidents.
Such emergency response capabilities do not emerge overnight, but are the result of SlowMist’s long-term investment in its product ecosystem and intelligence infrastructure. As highlighted in the report, this includes tools such as MistTrack — SlowMist’s proprietary on-chain analytics and anti–money laundering platform, which tracks hacker fund flows, identifies risky addresses in real time, and supports compliance checks for both users and enterprises — and MistEye, a self-developed Web3 threat intelligence and dynamic security monitoring system that detects potential attack activities in real time and provides early warnings and protection for projects and exchanges.
Powered by these tools and combined with InMist Lab, the threat intelligence collaboration network led by SlowMist, the security team is able to rapidly identify attack chains during the critical post-incident window, prevent further losses, and deliver clear, actionable recommendations to exchanges, project teams, and partners — significantly improving overall response efficiency.
Industry Collaboration Remains Critical
The report not only highlights SlowMist’s defensive capabilities, but also presents a broader picture of industry-wide collaboration. Independent researchers such as ZachXBT, Saiyan, and Garcia, along with numerous professional security teams, play irreplaceable roles in on-chain security incidents. From tracing complex on-chain fund flows and analyzing phishing infrastructure to identifying potential malicious developers through OSINT (Open-Source Intelligence) and HUMINT (Human Intelligence) techniques, nearly every critical step relies on close cross-team, cross-regional cooperation and real-time intelligence sharing.
Cos emphasized:
“Attackers often leverage cross-chain and cross-platform tactics to strike quickly. It’s extremely difficult for a single team to fully grasp the entire picture. Only through real-time intelligence sharing and synchronized action across the industry can anomalies be detected early and losses effectively contained.”
In practice, this means that project teams, exchanges, independent researchers, and professional security firms must establish highly trusted communication channels. Such trust is precisely what enables all parties to open up resources and contribute collectively at critical moments.
At the same time, Cos cautioned that challenges in the security industry extend beyond technical complexity to include ethical judgment. His X handle, @evilcos, may appear tongue-in-cheek, but it carries a serious reminder:
“You must decide what kind of person you want to be. The technology in this industry can protect people, but it can also harm them. Never become the bad guy.”
Conclusion
This Cointelegraph feature not only sheds light on the day-to-day work of security practitioners, but also underscores the collective strength of industry collaboration in the face of risk. We extend our gratitude to all researchers, project teams, exchanges, partners, and community members who stand together and proactively share information. Security is a cross-ecosystem, long-term endeavor. Looking ahead, we will continue to strengthen our capabilities in on-chain tracing, intelligence analysis, and incident response, working alongside industry partners to help drive the Web3 ecosystem toward a more resilient and sustainable future.
Original article:
https://cointelegraph.com/magazine/meet-crypto-sleuths-fighting-crime-better-than-the-cops/
About SlowMist
SlowMist is a threat intelligence firm focused on blockchain security, established in January 2018. The firm was started by a team with over ten years of network security experience to become a global force. Our goal is to make the blockchain ecosystem as secure as possible for everyone. We are now a renowned international blockchain security firm that has worked on various well-known projects such as HashKey Exchange, OSL, MEEX, BGE, BTCBOX, Bitget, BHEX.SG, OKX, Binance, HTX, Amber Group, Crypto.com, etc.
SlowMist offers a variety of services that include but are not limited to security audits, threat information, defense deployment, security consultants, and other security-related services. We also offer AML (Anti-money laundering) software, MistEye (Security Monitoring), SlowMist Hacked (Crypto hack archives), FireWall.x (Smart contract firewall) and other SaaS products. We have partnerships with domestic and international firms such as Akamai, BitDefender, RC², TianJi Partners, IPIP, etc. Our extensive work in cryptocurrency crime investigations has been cited by international organizations and government bodies, including the United Nations Security Council and the United Nations Office on Drugs and Crime.
By delivering a comprehensive security solution customized to individual projects, we can identify risks and prevent them from occurring. Our team was able to find and publish several high-risk blockchain security flaws. By doing so, we could spread awareness and raise the security standards in the blockchain ecosystem.
