Logo

Blockaid Partners with IPOR Fusion to Bring Onchain Threat Monitoring to Its Vault Ecosystem

Blog Post
IPOR

Executive Summary

Fusion is onchain vault infrastructure developed by IPOR Labs AG (Zug, Switzerland), built for institutional-grade yield strategies. Its modular architecture provides deterministic risk enforcement, per-client vault isolation, compliance-friendly configuration, and flexible setup through composable modules called Fuses, integrated with established DeFi protocols across more than 40 venues.

The infrastructure supports institutional vaults where every permission, venue and limit is set onchain before capital enters and readable by anyone afterwards. Independent operators build and run strategies on Fusion, while regulated entities reach onchain markets through it, among them Fortune 500 custodian BitGo and ETP issuer 21Shares.

Fusion has partnered with Blockaid to bring onchain threat monitoring across its vault ecosystem. Monitoring and post-transaction analysis are live for a selection of Fusion vaults, with proactive detection in development. Detections surface to the Fusion team, who raise material findings with the operator of the affected vault.

For teams building on Fusion, the integration adds a layer of monitoring they do not procure or integrate themselves, extending coverage from the vault contracts to the infrastructure around them.


The Partnership: Blockaid’s Coverage Across Fusion Vaults

Fusion's architecture puts controls into the stack itself, from Guardian roles for emergency actions to configurable market limits. The partnership adds a layer that watches how those controls hold as capital moves through them.

Each vault arrives with its own operator, its own fuse set and its own privileged addresses, so what needs watching varies from one deployment to the next. Blockaid's monitoring is built around that variety, adding an external layer of signals on covered vaults alongside the checks the Fusion team already runs. Coverage spans a defined set of contracts and addresses, with vaults added individually as the arrangement expands.

Onchain Monitoring works across four functions:

  • Monitor with an inventory that keeps pace. Contracts and privileged addresses in scope, from the vaults themselves to the factories that deploy them and the roles that operate them, are tracked as a single living inventory. Vaults are added to that inventory individually, so coverage grows as deployments are brought in. For product participants, a current inventory means the covered set stays accurate as deployments change.
  • Detect the failure modes of delegated asset management. Detection flags the behaviors that precede and accompany vault exploits, including exploit-contract deployment, malicious interactions with monitored contracts, unauthorized role and ownership changes, and unexpected proxy upgrades. For operators, that is an independent set of eyes on the role structure their vault runs on.
  • Investigate with the reconstruction already done. Incidents arrive decoded, with the call path, the addresses involved and the asset flow laid out, so the team's first minutes go to deciding what to do.
  • Respond before damage spreads. Alerts route into the channels the team already works in. Automated onchain actions, including pausing an affected contract, are in development and will follow. For non-custodial vaults, shortening the window between detection and decision is what containment depends on.

Learn more about Onchain Monitoring →


Real-Time Detection: A Whitehat Disclosure, Caught Live

In January 2026, a whitehat demonstrated a vulnerability in a single Fusion vault on Arbitrum. The path ran through execution authority the vault's administrator had delegated under EIP-7702, which allowed a fuse to be injected and a withdrawal flow to run custom logic inside that vault.

Blockaid was among the parties that flagged it while it was happening. Transaction by transaction the activity looked like ordinary administrative work, which is what makes this class of behaviour hard to catch on any platform built on delegated execution.

The vault held under 1% of funds across Fusion, and no other deployment shared the configuration. Every participant in that vault had their funds returned by the whitehat, and normal operations resumed within 17 hours. The full sequence is in their post-mortem.

That episode is one reason this monitoring layer exists in the form it does.


Looking Ahead: Vaults Are Becoming Institutional Infrastructure

The model Fusion runs is spreading across DeFi. Curators, professional teams that design and operate strategies, now package yield into vaults much the way traditional managers package funds, and white-label distribution carries those vaults to audiences that never touch the underlying protocols. Fusion's own trajectory reflects the shift, with more operators launching strategies on the platform and more of its infrastructure running under other brands.

The next wave of that audience is institutional. Funds, trading desks, and traditional finance entrants are engaging with curator-run vaults to access onchain yield without building execution infrastructure themselves. They arrive carrying the due-diligence standards of their home markets, which expect continuous monitoring, defined incident response, and evidence that someone is watching the assets full time. Underneath those checklists is operational trust, which is earned in production, one monitored transaction at a time, and building it is what the partnership is for.

Request a Demo →


About Fusion

Developed by IPOR Labs AG (Zug, Switzerland), Fusion is the onchain vault infrastructure built for institutional-grade onchain yield strategies. Its modular architecture provides deterministic risk enforcement, per-client vault isolation, compliance-friendly configuration, and flexible setup through composable modules called Fuses, integrated with established DeFi protocols.

Learn more at ipor.io, and follow them on Twitter and LinkedIn.

About Blockaid

Blockaid is the onchain security platform trusted by the largest companies operating in Web3. Built by veterans of elite intelligence and cybersecurity units, Blockaid provides end-to-end protection for financial institutions, protocols, and end users, combining direct wallet and dApp integrations with real-time monitoring, detection, and response across smart contracts, infrastructure, and externally owned accounts. Since 2025, Blockaid scanned over 6.3 billion transactions and blocked 585 million attacks. Blockaid is the security infrastructure behind Coinbase, MetaMask, Uniswap, Safe, and dozens of the most widely used platforms in the industry.

Learn more at blockaid.io, and follow us on Twitter and LinkedIn.


Blockaid is securing the biggest companies operating onchain

Get in touch to learn how Blockaid helps teams secure their infrastructure, operations, and users.