Emergency Incident Response

A direct triage path for suspected exploits, critical vulnerabilities, suspicious transactions, and urgent remediation review. Availability is confirmed during triage.

How it works

Calm decisions under time pressure

The first objective is to establish facts, preserve evidence, and evaluate containment without introducing another failure. Availability and the exact response scope are confirmed during triage.

Engagement coverage

Built around the questions that matter

The final work is defined against the exact code, system model, and security objective supplied during scoping.

Transaction analysisCode reviewContainment reviewRemediation verification
01

Initial triage

Establish what happened, what remains active, which systems are affected, and what evidence is available.

02

Transaction analysis

Trace relevant transactions, contract calls, privileges, and state changes around the suspected event.

03

Root-cause review

Inspect the implicated code and system assumptions to identify the technical failure path.

04

Containment review

Evaluate proposed pauses, upgrades, configuration changes, or other containment actions for additional risk.

05

Remediation verification

Review the proposed fix and re-test the paths implicated by the incident before redeployment.

06

Post-incident record

Document technical cause, affected assumptions, remediation, and follow-up security work when included in scope.

Active concern

Contact the security team directly.

Send the affected chain, contract addresses, transaction hashes, concise timeline, and a safe technical contact. Never send a private key or seed phrase.

FAQ

Incident Response FAQ

What should we send first?

Share a concise timeline, affected contracts and chains, relevant transaction hashes, deployed addresses, suspected code paths, and a safe technical contact. Never send private keys or seed phrases.

Can Kann Audits guarantee fund recovery?

No. Incident response can support investigation, containment, and remediation, but it cannot guarantee recovery of assets or a particular outcome.

How quickly will the team respond?

Contact the security team through the listed Telegram channel. Availability and response timing are confirmed during triage unless an existing engagement states otherwise.

Should we disclose the incident immediately?

Disclosure decisions depend on active risk, affected users, legal obligations, and containment status. Coordinate with technical, legal, and communications teams.

Need urgent triage?

When something goes wrong, speed and clarity matter.

Share your scope, target date, and architecture. The security team will review the details and respond with the next steps.