Blockchain & Crypto Asset Forensics
Wallet and asset verification before deals, mediation, or escrow closes. Broader on-chain fraud investigation (rug pulls, fake tokens) and technical litigation support with chain-of-custody discipline.
0DCyber Sagl is a Switzerland-based cybersecurity and GRC consultancy built on forty years across the full stack: from writing code to running boards. We work as an external advisor, and as fractional C-level security leadership for organisations that need senior authority without a full-time hire.
Forty years across the full stack, from writing code to running boards, taught one thing: real risk hides in flawed assumptions and in the relationships between systems, not in isolated technical flaws. Checklists catch what was already anticipated. They don't catch what nobody thought to ask.
0DCyber brings offensive insight, defensive capability, and governance into one coherent view. We design controls grounded in how attackers actually operate and in how risk propagates through an organisation, not in checklist theory. The name reflects the arc the work is built on: from the lowest layer of the stack to the boardroom. Right now that means particular depth in two areas: blockchain and crypto-asset risk, and how organisations actually use AI, the two surfaces changing fastest.
A point of view formed by having actually built, broken, investigated, governed, and navigated new terrain, in that order.
Built from the ground up in software development: C/C++, assembly, Unix, networking. Working at the lowest layers of the stack taught the core lesson early: systems rarely fail at visible controls, they fail at flawed assumptions.
Adversarial analysis came next: understanding how systems are actually exploited, not how they're assumed to be secure. A direct grasp of attacker methodology has driven a defensive-by-design approach ever since.
Digital investigations and forensics work, including consulting for law enforcement, added a third discipline: treating data as evidence that requires integrity and traceability, not just availability.
All three disciplines consolidated into governance leadership: vCISO for a Tier-1 international bank, group-wide security risk governance in healthcare, and board-level reporting that translates technical risk into business decisions.
The same rigor extended to the newest attack surface: on-chain forensics for crypto assets and smart contracts, and risk controls for how organisations actually use AI. Same discipline, applied to terrain that didn't exist when this arc started.
Wallet and asset verification before deals, mediation, or escrow closes. Broader on-chain fraud investigation (rug pulls, fake tokens) and technical litigation support with chain-of-custody discipline.
Deep technical audits of smart contract logic to identify vulnerabilities before deployment, ensuring assumptions match mathematical reality on-chain.
Assessing how teams use LLMs and AI tools. Implementing guardrails to prevent proprietary data or source code from becoming public training data.
Mapping the reality of your infrastructure against frameworks like ISO 27001 or NIS2. Identifying gaps between written policies and actual technical implementations.
Senior security leadership on an ongoing, part-time basis. Translating technical risk into business terms for the board, managing incident response, and steering security strategy.
Practical, non-theoretical training programs designed to change behavior, not just tick compliance boxes. Built on experience training over 20,000 employees.
In 2026 I was personally targeted by a social-engineering campaign built around a fake job interview: a convincing counterfeit of an AI coding-assistant installer as the delivery vector, aimed at reaching cryptocurrency wallet data. I caught it early, verified exactly what it touched against threat-intel reporting on the same campaign, confirmed no persistence, and closed it out without loss. Human trust, AI tooling, and crypto custody: the same three pressure points are where most organisations are least prepared, because most people assume this only happens to someone else.
0DCyber works two ways: as an external advisor brought in for a defined engagement, and as fractional or contract C-level security leadership for organisations that need senior authority on an ongoing basis without a full-time hire.
Every engagement starts with a short scoping conversation: what's actually at stake, what the board or counterpart needs to see, and what a realistic outcome looks like, before any scope or commitment is fixed.
To start a scoping conversation, send us a message.