Oak Security logo

Oak Security

Oak Security is a Web3 security firm providing multi-expert audits, operational security reviews, continuous audit services, vCISO support, penetration testing, training, and security and economic advisory. It serves Web3 protocols, blockchain teams, investors, and ecosystem foundations.
Distributed

Pre-Audit Agent


Project Links


Description

Pre-Audit Agent is an Oak Security private-beta platform for teams preparing codebases for security audits. It returns an audit-readiness score, likely risk hotspots, a complexity assessment, off-chain security signals such as multisig and key handling, and a recommended audit tier. It scopes audit readiness and explicitly does not replace an audit or function as a vulnerability scanner.

Category: AI Agent

AiTM


Project Links


Description

AiTM is a downloadable AI-assisted threat-modelling tool for macOS, Windows, and Linux, currently in private beta. It runs TRACE phases over user-provided white papers, specifications, architecture documents, and code to create source inventories, TRACE models, STRIDE-ranked threats, attack trees, collusion and coordination analysis, and a prioritised report and roadmap. Projects and encrypted API keys remain on the user’s machine; AI calls use the user-selected OpenAI or Anthropic provider.

Category: Developer Tooling

Web3 Security Dashboard


Project Links


Description

Web3 Security Dashboard is an Oak Security Research dashboard that provides a filterable audit-side view of findings by year, severity, category, and technology stack, alongside a Rekt incident view of cleaned exploit records. It includes incident KPIs, vulnerability types, annual incident trends, and top incidents by loss, with data current through Q1 2026.

Category: Risk Assessment

OpSec Academy


Project Links


Description

OpSec Academy provides free PDF and HTML operational-security guidance for Web3 teams, covering device hardening, wallets and key management, multisig operations, infrastructure hygiene, access management, incident response, communications, physical safety, and security architecture. Its OpSec Agent answers operational-security questions using Oak Security’s knowledgebase and, when necessary, an attributed SEAL framework fallback. The Academy is presented as Oak Security’s free layer, separate from its paid Operational Security Review and Training services.

Category: Uncategorized

TRACE


Project Links


Description

TRACE is an open threat modelling methodology developed by Oak Security. It converts source material such as specifications, architecture documents, interviews, access reviews, and code into a structured, evidence-traceable model of threat actors, roles, assets, critical invariants, and trust edges. The methodology supports protocol, system, and organisational analysis through sequential stages including source ingestion, model construction, STRIDE threat identification and ranking, attack-tree development, collusion analysis, and a prioritised mitigation roadmap. Its methodology materials are licensed under CC BY 4.0 and available through its public repository.

Category: Developer Tooling