Logo

Inside the Midas Tokenization Engine: Live Security for Strategy Execution with Blockaid

Blog Post
Midas + Blockaid Case Study

Overview

Midas Case Study Stats

Summary 

  • Midas oversees onchain investment strategies run by 10+ appointed strategy managers, with all transaction signing routed through MPC workspaces via Fordefi and Fireblocks.
  • Policy-based allowlists alone couldn't detect all threats, while managing those policies became a growing operational burden as the business scaled.
  • With a purpose-built Fordefi integration, Blockaid's Cosigner now secures 100% of Midas contracts, providing real-time threat protection around all sensitive admin functions and events. 
  • Onchain Monitoring gives strategy managers continuous visibility into risk across the DeFi protocols their strategies touch.
  • Blockaid exploit detections are a defined trigger in Midas's Standard Incident Response Protocol, with Blockaid's threat intel team investigating jointly whenever an alert fires.

About Midas

Midas is a tokenization platform for composable onchain investment products. It gives investors exposure to institutional strategies — which are run by professional strategy managers — through its performance-linked mTokens. These tokens offer full transparency, instant redemptions, and native composability across DeFi.

To-date, Midas has tokenized over $2Bn in assets and partners with risk managers, custodians, and chains for secure, scalable access. Flagship tokenized products include mGLOBAL (asset-backed credit), mTBILL (short-dated U.S. Treasuries), mHYPER (market-neutral crypto), and others such as mF-ONE, mM1-USD, mAPOLLO, mRe7YIELD, mBASIS, covering asset-backed credit, basis trades, T-Bills and various DeFi strategies.


The Challenge: Manual Overhead and Detection Gaps

As the infrastructure layer that serves asset managers, Midas employs technical and operational "guardrails" around investment products, whose underlying strategies are managed by 10+ strategy managers who are responsible for driving performance-linked strategies across DeFi.

Midas provides the technical oversight for these onchain strategies, handling core operations including oracle updates, contract deployments, access control changes, and subscription and redemption processing. All strategy execution occurs within a designated MPC (Multi-Party Computation) Workspace, where all assets and smart contracts are protected by industry-leading MPC key management solutions provided by Fordefi and Fireblocks.

Transaction security in MPC wallet setups has traditionally relied on strict policy enforcement: a deny-by-default model in which any action not explicitly authorized is blocked. Fordefi's own setup demonstrates the depth of this approach, with more than 75 policy rules, including policies governing over 100 recipients and more than 200 approved assets.

While this provides a strong foundation, policy enforcement and transaction threat detection serve different security functions.

  • Comprehensive transaction coverage. Highly granular policies require careful configuration and ongoing manual review of role assignments, recipients, assets, functions, and parameters. Blockaid adds an automated security layer that analyzes 100% of transactions, while Midas continues to apply high-quality manual review and approval to policy changes and specific use cases.
  • A threat detection gap. An allow-list can verify that a transaction complies with predefined permissions, but it cannot independently determine whether the transaction is malicious. Blockaid complements the existing policy framework by analyzing transaction behavior, simulation results, counterparties, and threat intelligence. This helps detect risks such as manipulated transaction outcomes, assets compromised after being approved, or counterparties subsequently linked to attacker infrastructure.

The Solution: Real-Time Threat Protection for Midas Contracts; Ecosystem-Wide Monitoring & Exploit Detection For Strategy Managers

Midas evaluated Cosigner against other transaction security vendors and found Blockaid's automatic detection as operationally superior to approaches that lean on manual review. As an additional level of operational support for Midas, Blockaid committed to and delivered on building a direct Fordefi-Cosigner integration (completed in November 2025), alongside the existing Fireblocks integration.

Today, Cosigner now secures 100% of Midas’ contracts by providing real-time visibility over all sensitive admin functions and events. Every transaction initiated inside Midas' MPC workspaces is simulated and validated by Blockaid before a signature is released. Cosigner evaluates what a transaction actually does and who it actually touches at the moment of signing, layering in the real-time threat intel into transaction-level screening (simulation, verdicts, app/token scanning) to complement Fordefi’s policy enforcement. 

While Cosigner enhanced transaction level support at the point of signing, both Midas and its external strategy managers still needed continuous risk monitoring for threats emerging elsewhere in the ecosystem. As recent security incidents have shown that a stablecoin depeg or an exploit at a DeFi protocol can have downstream effects on other participants that can result in financial losses. For Midas’ appointed strategy managers who leveraged complex investment strategies involving multiple assets across DeFi protocols, effective monitoring required extensive mapping of indicators including across all asset-market pairs that their strategies touched. 

Blockaid’s Onchain Monitoring offered pre-configured monitor lists across various DeFi lending protocols, equipping strategy managers with better detection, resulting in faster deployment of investment products. Further,  Blockaid detections are a defined activation trigger for Midas' Standard Incident Response Protocol — a structured framework for responding to potential security threats, third-party exploits, or market anomalies. When an alert fires, Blockaid's threat intel team investigates jointly with Midas to confirm the incident and activate the safety response. 


The Results

In the first year of the partnership, Cosigner saw more than 30,000 transactions across Midas' workspaces, flagging any that did not fall within configured policies. Each detection came with a decoded simulation and joint investigation.

The operational load of delegation dropped with it as automatic approval of benign transactions replaced manual, address-by-address explorer verification as the default path, letting the ops team focus on the small set of transactions that actually warrant scrutiny. As Midas has onboarded new strategy managers, added chains, and stood up a dedicated security organization, the monitoring layer has scaled alongside it, from custom contract rules to ecosystem-wide threat intelligence mapped against Midas' public transparency reporting.


Outlook

Blockaid addressed the detection gap that Midas set out to close. Midas now offers asset managers on its platform real-time transaction validation at the point of signing, paired with continuous exposure monitoring across positions. As Midas onboards new strategy managers, adds chains, and builds out its own security organization, that same layer of automated detection is built to grow with it.

Ready to see how Blockaid can protect your platform? Request a Demo →


Blockaid is securing the biggest companies operating onchain

Get in touch to learn how Blockaid helps teams secure their infrastructure, operations, and users.