Skip to content

Coverage

What We Watch For

Nine risk surfaces. Dedicated detection logic. A defined CROC response on every match.

  • 9 surfaces
  • Real-time
  • Defined response

Detection catalog

Nine risk surfaces, one continuous watch

Each category maps to Chain Monitor logic and a watch-floor playbook.

01

Exploit-related fund movement

  • Large or rapid outflows from monitored contracts and treasury wallets
  • Transfers to unfamiliar destinations right after an exploit signature
  • Breaks from an address's historical transaction pattern
  • Watch Officer escalation within minutes of the first suspicious hop

02

Money laundering & mixer interactions

  • Interactions with mixers, tumblers, or flagged laundering infrastructure
  • Layering hops and structured splits that mimic wash patterns
  • Risk-intelligence match on known mixer and flagged-address sets
  • Audit-ready trail for ongoing AML / transaction monitoring

03

Sanction & high-risk exchange exposure

  • Direct transfers to sanctioned or high-risk exchange addresses
  • Indirect exposure a few hops through risky counterparties
  • Screening against sanctions and weak-KYC exchange datasets
  • Logged tx hash and address trail for Travel Rule / sanctions evidence

04

Flash loan attacks

  • Abnormal borrow volumes inside a single block
  • Price-oracle manipulation and multi-protocol attack shapes
  • Patterns that diverge from legitimate arbitrage or liquidation
  • Immediate post-execution response: freeze, alert, and fund-trace

05

Rug pulls & scam patterns

  • Sudden, complete liquidity removal from a monitored pool
  • Malicious minting or ownership abuse ahead of a sell-off
  • Trading functions disabled for everyone but the deployer
  • Baseline correlation so legitimate migrations are not misread as rugs

06

Suspicious wallet behavior

  • Dormant wallets that suddenly reactivate
  • Rapid-fire transfers across many addresses in a short window
  • New links to previously flagged counterparties
  • Human analyst judgment on every flag, AI only prioritizes the queue

07

Unauthorized transfers & privileged actions

  • New admin roles, config changes, and owner-only calls
  • Anything unfamiliar in this class treated as Critical by default
  • Immediate call and contextualized email at T0
  • Escalation timers armed the moment the action is detected

08

Cross-chain laundering patterns

  • Fund hops across bridges used to break a single-chain trail
  • Cross-network correlation so history does not reset at the bridge
  • Exploit-linked flows still recognized after the chain hop
  • Same fund movement treated as one story, not a fresh wallet

09

Smart-contract ownership & upgrade changes

  • Admin transfers, proxy upgrades, and permission changes
  • Each event scored against the contract's operational policy
  • Scheduled multisig upgrades distinguished from unexplained transfers
  • Early signal of key compromise or governance abuse
Around-the-clock global coverage

Security operations around the world.

No matter where your team or your customers are, someone at CROC is already watching.

Talk to the CROC team