Uppsala Security Joins Cyber Threat Alliance, Bridging Blockchain and Traditional Cyber Intelligence
Uppsala Security, a leader in blockchain intelligence, has become the first firm of its kind to join the Cyber Threat Alliance, aiming to integrate on-chain threat data with traditional cyber intelligence.

Singapore-based Uppsala Security has announced its admission as an Affiliate Member to the Cyber Threat Alliance (CTA), a significant move that marks the first time a blockchain intelligence company has been integrated into the alliance. The CTA is a collaborative non-profit organization dedicated to fostering the sharing of actionable threat intelligence among cybersecurity entities to enhance collective defenses and situational awareness against cyber adversaries.
This new membership is particularly timely as cybercrime increasingly blurs the lines between traditional digital infrastructure and blockchain networks. Many sophisticated attacks begin with conventional methods like phishing, ransomware, or compromised credentials. However, the trail of illicitly obtained assets often leads into the complex ecosystem of blockchain wallets, exchanges, and mixers, making a unified investigative approach challenging.
Traditionally, the analysis of the initial compromise and the subsequent movement of stolen funds have been handled by separate teams utilizing distinct data sources. This fragmentation can impede a comprehensive understanding of an incident's full lifecycle, from the initial breach to the final destination of stolen assets. Uppsala Security's entry into the CTA aims to bridge this gap.
Uppsala Security plans to contribute valuable on-chain threat intelligence to the CTA's shared knowledge base. This intelligence will include insights into malicious wallet activity, suspicious transaction patterns, and the flow of illicit funds across blockchain networks. By combining this on-chain data with traditional cyber threat indicators such as malicious infrastructure, malware artifacts, and compromised domains, investigators and security teams can achieve a more holistic view of cyber incidents.
"Cybercrime does not stop when an attacker leaves a network. Stolen assets can continue moving on-chain, and those movements may preserve important evidence about how an incident developed and where the proceeds are going," stated Patrick Kim, Founder and CEO of Uppsala Security. "Joining CTA gives us an opportunity to connect that on-chain perspective with the cyber threat intelligence already shared by its members. By bringing these two areas together, we can help the wider cybersecurity community understand incidents more completely and respond more effectively."
The CTA acknowledged that Uppsala Security brings a unique type of threat intelligence, distinct from that of typical cybersecurity firms. The alliance anticipates that integrating these diverse forms of intelligence will significantly amplify the value of information shared among its members. Concurrently, Uppsala Security aims to leverage the collective experience of CTA members to deepen its understanding of the infrastructure, tactics, and indicators employed by threat actors before stolen assets are moved on-chain.
This collaboration is expected to foster enhanced cooperation among cybersecurity companies, blockchain intelligence providers, financial institutions, digital asset businesses, and law enforcement agencies. Such partnerships are crucial for effectively responding to cross-border cyber and financial crimes that increasingly involve digital assets. Uppsala Security intends to utilize its CTA membership to expand international information sharing, exchange investigative expertise, and contribute to more coordinated global responses to cybercrime involving digital assets.
Founded in 2018, Uppsala Security specializes in blockchain intelligence and crypto forensics, offering threat intelligence, forensic technologies, and investigation services. The company assists various entities, including law enforcement, regulators, financial institutions, and enterprises, in identifying crypto-related threats, tracing illicit assets, and investigating financial crime. Their methodology integrates blockchain data, cyber threat intelligence, and investigative analysis to provide comprehensive insights into activities across digital asset networks.