SlowMist
Blockchain security audits, threat intelligence, and on-chain AML tracking for Web3.
On-chain activity
SlowMist Security Services
SlowMist Security Services provides professional security assessments for blockchain ecosystems through smart contract, exchange, wallet, and blockchain source code audits, alongside red team simulations, security monitoring, defense deployment, incident response, security consulting, and blockchain threat intelligence sharing. Audit methodologies combine white-box, black-box, and gray-box analysis aligned with OWASP, CVSS, and HKSFC compliance frameworks, covering EVM chains, Solana, EOS, Fabric, Move-based chains, and enterprise consortium blockchain systems.
SlowMist
SlowMist
TLDR
SlowMist is a blockchain security company established in January 2018 by professionals with over a decade of network security experience. The firm provides smart contract audits, blockchain protocol assessments, anti-money laundering (AML) tooling, and threat intelligence to exchanges, DeFi protocols, and wallet providers worldwide. Its flagship compliance product, MistTrack, traces on-chain fund flows across 19 networks using a database of more than 300 million address labels. SlowMist has audited more than 1,500 smart contracts, served clients including Binance, OKX, and Crypto.com, and has helped freeze or recover over $112 million in stolen funds during 2024 alone. The firm holds ISO/IEC 27001:2022 certification and has been recognized by the Hong Kong Police Force and the United Nations.
What SlowMist Does
SlowMist describes its mission as making the blockchain ecosystem as secure as possible. In practice, that translates into four broad service lines: security auditing, threat intelligence, incident response, and compliance tooling.
Security auditing is the firm's core offering. SlowMist conducts white-box and gray-box assessments of smart contracts, exchange infrastructure, wallet implementations, and blockchain protocols themselves. The team has reviewed code across Ethereum, EVM-compatible chains, EOS, Fabric, Solana, Klaytn, and Aptos, accumulating documented experience with the distinct vulnerability patterns each platform produces. Its publicly searchable audit report archive and the SlowMist Hacked incident database — which catalogs known blockchain exploits — serve as reference resources for the broader security community.
Threat intelligence is delivered through the Blockchain Threat Intelligence (BTI) program and the MistEye monitoring service. MistEye provides Web3 projects with real-time alerting on unusual on-chain activity, phishing campaigns, and emerging attack vectors. BTI packages that intelligence for integration into project-level security operations.
Incident response involves hands-on support when a breach occurs. SlowMist teams help affected projects isolate losses, trace stolen assets, and coordinate with exchanges and law enforcement.
AML and compliance tooling is where SlowMist has built its most distinctive infrastructure.
MistTrack: On-Chain AML at Scale
MistTrack is SlowMist's crypto anti-money laundering and asset-tracing platform. Originally developed to support the firm's own investigations, MistTrack is now a standalone product available to law enforcement, exchanges, and compliance teams.
The platform currently spans 19 blockchain networks and has accumulated:
- Over 300 million address labels
- More than 1,000 entity profiles covering exchanges, mixers, and sanctioned services
- 500,000+ threat intelligence addresses
- 90 million+ flagged risky addresses
Three product tiers serve different user types. MistTrack Light is a free lightweight tracing tool for individual investigators. MistTrack Premium provides a professional compliance dashboard with deeper analytics and case management. SlowMist KYT (Know Your Transaction) is a real-time AML engine designed for institutional compliance teams at large exchanges and financial services firms.
MistTrack has been selected for Hong Kong Cyberport's Blockchain and Digital Asset Pilot Subsidy Scheme. It received the Gold Award in FinTech at the HKICT Awards 2025 and the Best FinTech Innovation Award at the HKMA/HKT Global Innovation Awards 2025/26. A formal partner program for MistTrack and SlowMist KYT launched in September 2026, extending the platform's reach to compliance-focused resellers and integrators.
Solana Coverage
SlowMist has established a dedicated Solana security practice. The Solana ecosystem presents distinct audit challenges relative to EVM chains: Solana programs use a different account model, ownership and authority structures require explicit validation checks, and cross-program invocation patterns introduce attack surfaces that do not exist on Ethereum.
SlowMist's published Solana Smart Contract Security Best Practices guide, updated in May 2025, details the vulnerability classes its auditors check for, including missing signer verification, incorrect account ownership validation, integer overflow in token arithmetic, and unsafe use of the invoke_signed instruction.
The firm has audited several Solana-ecosystem projects, including Particle Network, UniPassID, Crema Finance, Solyard.Finance, and Larix. In July 2025, SlowMist researchers publicly disclosed a malicious Solana trading bot that was draining user funds through approval manipulation — an example of the active threat monitoring the firm maintains across the Solana network.
SlowMist's threat intelligence data for the first half of 2025 placed Solana second behind Ethereum in aggregate security-incident losses, with approximately $5.8 million in H1 2025 attributed to Solana ecosystem incidents.
Scale and Impact
SlowMist's audit volume — more than 1,500 smart contracts reviewed — and its client roster reflect its position as one of the higher-volume security firms operating across multiple blockchain ecosystems. Major exchange clients include Binance, OKX, Bitget, and Crypto.com. Strategic partnerships have been announced with Sinohope, HashKey, and AgentOn.
Beyond audits, the firm's role in funds recovery has been substantial. In 2024, SlowMist assisted in freezing or recovering over $112 million in stolen cryptocurrency. In the first half of 2025, the figure was approximately $14.56 million, and in the first half of 2026, approximately $5.16 million.
SlowMist's AML investigations and intelligence have been cited in reports by the United Nations Security Council and the United Nations Office on Drugs and Crime. The firm received the Cyber Security Excellence Contribution Award at the Cyber Security Professionals Awards 2025, presented by the Hong Kong Police Force.
Credentials and Structure
SlowMist holds ISO/IEC 27001:2022 Information Security Management System certification, obtained in December 2024. The firm was recognized as a National High-tech Enterprise in China in 2019, and designated a "Specialized and Sophisticated" SME by Xiamen City as of 2024.
The company is a founding member of the Digital Asset Anti-Money Laundering Council (DAAMC) and a founding member of the Web4.0 and Agent Security Alliance at Hong Kong Cyberport. It is also an AWS APN Select Technology Partner. A first founding partnership with Singapore Management University supports its blockchain research engagement.
SlowMist is headquartered in Xiamen, China, with operational presence in Hong Kong. Its open-source research and tooling are published through its GitHub organization at github.com/slowmist.
Contents
- TLDR
- What SlowMist Does
- MistTrack: On-Chain AML at Scale
- Solana Coverage
- Scale and Impact
- Credentials and Structure
Solana Token Markets