Hacken
Tallinn-based blockchain security firm providing smart contract audits, penetration testing and proof-of-reserves services to web3 protocols and exchanges.
Visit Website ↗ + Add to Compare Claim This CompanyOverview
Hacken, founded in 2017 by Dyma Budorin, Yevheniia Broshevan, Vladimir Taratushka and Andrew Matiukhin, is a blockchain security and compliance company headquartered in Tallinn, Estonia, with roots in Ukraine’s security research community. Its services span smart contract auditing, blockchain protocol and dApp audits, proof-of-reserves attestations, tokenomics audits, bug bounty management and incident response for web3 projects.
The company says it has served more than 1,500 blockchain clients, including named customers such as the European Commission, MetaMask, the Ethereum Foundation and Bybit, and reported roughly $6.7 million in annual revenue. Hacken has disclosed relatively modest external funding of about $2.5 million, having grown primarily through revenue from its audit and security services business, which it says makes it the largest European web3 cybersecurity firm by revenue and market share.
What differentiates Hacken is its breadth: rather than offering only point-in-time smart contract audits, it combines audits with ongoing bug bounty programs, proof-of-reserves attestations and a public repository of published security assessment reports, giving clients and their users an auditable trail of security work.
Innovation Matrix Assessment
Has steadily expanded its service line since 2017 (audits, bug bounty, proof-of-reserves, CCSS audits), a pattern of incremental rather than rapid reinvention.
Smart contract and protocol audits materially reduce exploit risk before code is deployed, a concrete operational benefit for web3 protocols and exchanges handling user funds.
Named enterprise-grade clients (Ethereum Foundation, MetaMask, European Commission, Bybit) and reported $6.7M revenue are independently meaningful signals of real market traction, achieved with minimal outside capital.
Smart contract auditing is now an established, competitive category with many incumbents; Hacken is a leading operator rather than a category redefiner.
Named, independently verifiable major clients (Ethereum Foundation, MetaMask) and a public archive of published audit reports provide unusually concrete evidence of real-world use versus typical vendor claims.
Blockchain/web3 security remains relevant to a meaningful and persistent, if narrower and more cyclical, segment of the market than core enterprise cybersecurity.
Why CISOs Should Care
For organizations building or holding assets on blockchain infrastructure, independent smart contract audits and proof-of-reserves attestations are a baseline trust requirement before launch or listing.
What Makes It Different
Pairs point-in-time smart contract audits with ongoing bug bounty management and proof-of-reserves attestations, and publishes its audit reports publicly for independent scrutiny.
The Matrix Verdict
55/100 — INCREMENTAL INNOVATOR
Hacken is an Incremental Innovator: a profitable, revenue-funded leader in blockchain security with credible named customers, operating in a category that is useful but narrower and less disruptive than core enterprise application security.
Editorial Note: Claims vs. Verified Findings
Named clients, revenue and founding details are independently corroborated (Latka, PitchBook, LinkedIn); Hacken's claim of being the largest European web3 security firm by revenue is a company-stated ranking not independently audited.
Sources
Alternatives to Hacken
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…