Uppsala Security Becomes First Blockchain Intelligence Firm to Join Cyber Threat Alliance
Key Takeaways
- •Uppsala Security is the first blockchain intelligence company to join the Cyber Threat Alliance, expanding the organization's scope into digital asset threat intelligence.
- •The company will contribute on-chain threat indicators including malicious wallet activity, suspicious transaction patterns, and illicit fund movements to CTA's intelligence-sharing community.
- •CTA stated that Uppsala Security's distinct intelligence type can enhance the overall value of information shared among its member organizations.
- •The membership is expected to foster closer cooperation among cybersecurity firms, blockchain intelligence providers, financial institutions, digital asset businesses, and law enforcement agencies.
- •Uppsala Security also intends to learn from fellow CTA members about the infrastructure, tactics, and indicators associated with cyber incidents before stolen assets move on-chain.

Uppsala Security, a Singapore-based blockchain intelligence and crypto forensics company, has joined the Cyber Threat Alliance (CTA) as an Affiliate Member, making it the first blockchain intelligence company to participate in the organization.
CTA is a nonprofit that unites cybersecurity organizations to share actionable threat intelligence, enhance situational awareness, and strengthen collective defenses against malicious actors. Its membership has historically drawn from traditional cybersecurity vendors and research teams, making Uppsala Security's entry a notable expansion of the alliance's scope into digital asset–related threat intelligence.
Uppsala Security's addition brings an on-chain dimension to CTA's intelligence-sharing community at a time when cybercrime increasingly spans both traditional digital infrastructure and blockchain networks. Ransomware operators, fraud rings, and state-linked groups have routimely used cryptocurrencies to collect and launder proceeds, creating a demand for intelligence that connects conventional network indicators with blockchain activity.
Bridging the Gap Between Traditional Cyber Threats and On-Chain Activity
Many cyber incidents originate through phishing, ransomware, malware, compromised credentials, or unauthorized access. Stolen assets may subsequently move through blockchain wallets, exchanges, bridges, mixers, and other digital asset services. Although these activities can be part of the same incident, evidence from the initial compromise and the subsequent movement of assets is frequently analyzed by separate teams using different data sources. This fragmentation has persisted partly because blockchain analytics emerged as a distinct discipline, served by specialist firms, while most security operations centers focus on network, endpoint, and identity telemetry.
Through its CTA membership, Uppsala Security intends to contribute on-chain threat intelligence, including malicious wallet activity, suspicious transaction patterns, illicit fund movements, and other blockchain-based indicators. When combined with traditional cyber threat indicators such as malicious infrastructure, malware artifacts, domains, and IP addresses, on-chain intelligence can help investigators and security teams develop a more complete picture of an incident.
Leadership Commentary
"Cybercrime does not stop when an attacker leaves a network. Stolen assets can continue moving on-chain, and those movements may preserve important evidence about how an incident developed and where the proceeds are going," said Patrick Kim, Founder and CEO of Uppsala Security.
"Joining CTA gives us an opportunity to connect that on-chain perspective with the cyber threat intelligence already shared by its members. By bringing these two areas together, we can help the wider cybersecurity community understand incidents more completely and respond more effectively," Kim added.
CTA's Perspective and Future Collaboration
In its official membership announcement, CTA stated that Uppsala Security brings a type of threat intelligence distinct from that of a typical cybersecurity company. CTA also noted that combining different forms of intelligence and insight can enhance the value of information shared among its members.
Uppsala Security will also leverage the expertise of fellow CTA members to better understand the infrastructure, tactics, and indicators associated with cyber incidents before stolen assets move on-chain.
The membership is expected to foster closer cooperation among cybersecurity firms, blockchain intelligence providers, financial institutions, digital asset businesses, and law enforcement agencies dealing with cross-border cyber and financial crimes. As regulators and enforcement bodies worldwide increase scrutiny of illicit crypto flows, intelligence-sharing frameworks that bridge traditional and on-chain domains may become a more central part of incident response workflows.
Uppsala Security plans to use its CTA membership to expand international information sharing, exchange investigative experience with other members, and contribute to more coordinated responses to cybercrime involving digital assets.