What it does
Cinder is the threat intelligence layer of Hearth. It aggregates exploit signals across Ethereum, Solana, Bitcoin L2s, and major sidechains; correlates them with on-chain forensic patterns; and publishes a continuously updated risk score for every protocol it tracks.
Threats it catches
- Pre-exploit reconnaissance (suspicious approval grants, unusual address clustering)
- Repeat-attacker fingerprints surfaced from prior incidents
- Cross-chain bridge anomalies (in/out volume mismatch, atypical relay timing)
- Governance-attack precursors
How it works
Cinder ingests 30+ data sources every block. A scoring model weighted on historical exploit outcomes assigns each event a severity tier. High-severity events fan out as alerts within 100ms of detection; lower-severity events accrue context until they cross a threshold.
Integrations
Webhooks · Slack · Telegram · PagerDuty · Custom signing · GraphQL feed
