MiCA / DORA compliance · July 2026 deadline

Stops the attack.
Files the evidence.

POLARIS intercepts a malicious transaction before your wallet signs it, then auto-generates a regulator-ready DORA/MiCA evidence package — in one step. The only tool that stops the hack and does the regulator's homework.

polaris / pre-sign threat engine / live
ACTIVE
Destination / RuleSimulationVerdict
0x722122dF5b6967Transfer · ETH
OFAC-sanctioned — Tornado Cash mixer
approve() → blocked spender
BLOCK
0xBC4CA0Ed36f13DNFT contract · ERC-721
setApprovalForAll — unknown operator
Full collection access granted
REVIEW
0xd8dA6BF2A96045Transfer · USDC
vitalik.eth · no policy violations
State delta nominal
PASS
3 transactions screened · evidence_hash: sha256:a4f8c2…DORA Art. 16(1)(d) · 187ms
$1.73B
Lost to pre-sign deception attacks — Bybit, WazirX, Radiant, Dec 2025
~900
Pre-MiCA VASPs need AX05/AX50 evidence before July 2026
<200ms
Simulation p99 — verdict before your hardware wallet signs
4–10×
Cheaper than Chainalysis (€199K ACV) — for more coverage
The Problem

$1.73B. One attack class. Every tool missed it.
And none of them generate the evidence your regulator needs.

Bybit ($1.4B), WazirX ($235M), Radiant Capital ($53M), a $50M address poisoning in December 2025. Same root cause: pre-sign payload deception that hardware wallets, Tenderly simulation, and monitoring tools all missed. TRM+Hypernative now block pre-sign — but produce zero compliance documentation. AX05/AX50 — the mandatory MFSA annex for MiCA authorisation — is still unaddressed by every competitor.

Bybit-class drainer
Unlimited ERC-20 approve to sanctioned spender — POLARIS blocks before the hardware wallet even sees the request.
R3 · R5
Tornado Cash deposits
OFAC-listed mixer destinations — blocked with sanctions evidence hash appended to the compliance log.
R1 · R6
NFT setApprovalForAll
Full collection access to unknown operator — flagged for manual review with full simulation trace.
R4 · R7
Address poisoning
Look-alike destination addresses detected via simulation state delta — not retrospective OSINT.
R8 · R12
How POLARIS works

Three seconds between
intent and signature.

A sandboxed pre-flight check runs in <200ms. Enterprise deployments support on-prem simulation nodes for maximum data residency control.

01

Intercept

POLARIS hooks into the signing flow via your wallet SDK or API gateway. The pending transaction is captured before it reaches any signer.

Dfns MPC · Safe{Core} · ERC-7579 hooks · direct API

02

Simulate

A sandboxed EVM (revm) replays the transaction against the live chain state. Approvals are decoded, destinations cross-checked against threat intel.

Verdict in <200ms · on-prem node available for enterprise

03

Evidence

Every decision — BLOCK, REVIEW, or PASS — is SHA-256 hashed, chain-linked, and stored in an append-only evidence log. One-click PDF export.

DORA Art. 16(1)(d) · MiCA Art. 68 · SOC 2 Type II ready

Regulatory coverage

The only tool that stops the hack
and does the regulator's homework.

TRM+Hypernative now block pre-sign transactions — but produce zero compliance documentation. Chainalysis costs €199K/year and tells you what happened after the fact. POLARIS intercepts before signing and auto-generates the AX05/AX50 evidence package your regulator reads on page 1 of your CASP licence application — at 4–10× lower cost.

~900 pre-MiCA VASPs need to demonstrate DORA compliance before July 2026. Annex AX05 (Digital Operational Resilience Assessment) is mandatory at application. No competitor produces it. POLARIS does.

DORA
Regulation (EU) 2022/2554
  • Art. 16(1)(d) — ICT security tools & anomaly detection
  • Art. 17 — ICT incident management & evidence retention
  • Art. 19 — Incident classification & NCA reporting
  • Art. 28 — Third-party ICT provider risk monitoring
MiCA + AX05/AX50
Regulation (EU) 2023/1114 + MFSA Circular 2025
  • Annex AX05 — Digital Operational Resilience Assessment (mandatory at application)
  • Annex AX50 — ICT security evidence for NCA submission
  • Art. 68 — CASP ICT security & operational requirements
  • Art. 64 — Authorisation evidence (security controls)
SOC 2
AICPA Type II (observation Q1 2027)
  • CC6.1 — Logical access controls
  • CC7.3 — Incident monitoring & response
  • CC9.2 — Vendor / third-party risk management
  • Continuous CloudTrail + GuardDuty evidence trail
Pricing

A fraction of traditional compliance tooling.

Annual subscription. No tokens. No per-transaction fees. No setup cost. 60-day compliance pilot included.

Starter
€18K/year
  • 1 EVM chain
  • Up to 10K tx/month
  • DORA PDF export
  • Email support
  • 60-day compliance pilot
Get started
Most popular
Growth
€48K/year
  • 3 EVM chains
  • Up to 100K tx/month
  • MiCA + DORA export
  • Slack + API support
  • SOC 2 evidence package
  • 60-day compliance pilot
Request access
Enterprise
€120K+/year
  • Unlimited chains
  • On-prem simulation nodes
  • Custom policy rules
  • SLA 99.9%
  • Dedicated compliance engineer
  • 60-day compliance pilot
Talk to us
July 2026 deadline approaching

~900 pre-MiCA VASPs.
One compliance deadline.

POLARIS provides the ICT security evidence NCAs require for CASP authorisation. Schedule a 30-minute call to see the live demo.

Schedule a callOpen Live Console