Multi-Network Smart Contract Monitoring: Reliable Alert System for DeFi

We design and develop full-cycle blockchain solutions: from smart contract architecture to launching DeFi protocols, NFT marketplaces and crypto exchanges. Security audits, tokenomics, integration with existing infrastructure.
Showing 1 of 1All 1305 services
Multi-Network Smart Contract Monitoring: Reliable Alert System for DeFi
Medium
~3-5 days
Frequently Asked Questions

Blockchain Development Services

Blockchain Development Stages

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1357
  • image_web-applications_feedme_466_0.webp
    Development of a web application for FEEDME
    1250
  • image_websites_belfingroup_462_0.webp
    Website development for BELFINGROUP
    956
  • image_ecommerce_furnoro_435_0.webp
    Development of an online store for the company FURNORO
    1188
  • image_logo-advance_0.webp
    B2B Advance company logo design
    646
  • image_crm_enviok_479_0.webp
    Development of a web application for Enviok
    929

You manage a DeFi protocol deployed on Ethereum, Arbitrum, and Base. Funds move across bridges, and events in one network affect another. A delay in anomaly detection can cost millions — recall the Wormhole attack ($326M) or Ronin ($610M). There are no off-the-shelf solutions for cross-chain correlation — each protocol requires a custom architecture. Over 5 years, we have set up monitoring for 15+ DeFi protocols, processing up to 10,000 events per second with less than 1 second latency and guaranteed 99.9% uptime. Source: ERC-20 Token Standard Our certified team delivers a solution within 4–6 weeks, with setup costs typically ranging from $15,000 to $30,000 depending on complexity. Clients typically see a 50% reduction in critical incident response time, saving up to 40% on incident-related costs. Contact us to discuss your architecture.

How to Organize Smart Contract Monitoring Across Multiple Networks?

Data Sources — Monitoring System Development

RPC nodes — direct calls to EVM nodes via WebSocket for real-time events. Each network needs a reliable RPC with support for eth_subscribe:

const provider = new ethers.WebSocketProvider(RPC_WS_URL);
const contract = new ethers.Contract(address, abi, provider);

contract.on('Transfer', (from, to, value, event) => {
  emitEvent({
    network: 'arbitrum',
    block: event.log.blockNumber,
    txHash: event.log.transactionHash,
    type: 'Transfer',
    data: { from, to, value }
  });
});

Problem with a single RPC: public nodes are unreliable, they miss events under high load. Solution: at least 2 independent providers per network (Alchemy + QuickNode, or your own node). Deduplication of events by (chainId, txHash, logIndex).

The Graph / Subgraph — for historical data and complex queries. A mediation layer on top of raw RPC. Latency is 1–3 blocks, but ideal for analytical queries and cross-network balance reconciliation.

Network Block time Recommended RPC Finality
Ethereum ~12 sec Alchemy/Infura ~64 blocks (~13 min)
Arbitrum One ~0.25 sec Arbitrum RPC / Alchemy L1 finality
Polygon PoS ~2 sec Polygon RPC / QuickNode ~256 blocks
Base ~2 sec Base RPC / Alchemy L1 finality
Optimism ~2 sec Optimism RPC / Alchemy L1 finality
BNB Chain ~3 sec BSC RPC / NodeReal ~75 blocks

Event Processing Pipeline

Raw events cannot be analyzed directly — they need normalization and enrichment:

RPC Listener → Message Queue (Kafka/Redis Streams) → Event Processor → Alert Engine → Notification
                                                    ↓
                                              Time-series DB (InfluxDB/TimescaleDB)
                                                    ↓
                                              Analytics Dashboard

Event Processing Pipeline is the key element. Message Queue buffers spikes. During sudden spikes in on-chain activity (e.g., large liquidation cascades), events can arrive faster than they can be processed. Kafka with 24h retention allows replay if the processor crashes.

Event Processor — normalizes events from different networks into a unified format, decodes ABI, enriches (token prices, account metadata), and detects anomalies.

Alert Engine — rules applied to normalized events. Stateful rules require a state store (Redis). Example rules:

class LargeTransferAlert(AlertRule):
    def evaluate(self, event: NormalizedEvent) -> Optional[Alert]:
        if event.type != 'Transfer':
            return None
        usd_value = event.data['value'] * get_token_price(event.data['token'])
        threshold = self.get_dynamic_threshold(
            token=event.data['token'],
            window='24h',
            multiplier=10.0
        )
        if usd_value > threshold:
            return Alert(
                severity='HIGH',
                message=f'Large transfer: ${usd_value:,.0f} on {event.network}',
                context=event
            )

Cross-Chain Correlation

Cross-Chain Correlation is the most valuable feature for multi-network protocols. It links events between networks. Typical scenarios:

Bridge monitoring — a token is locked on Ethereum, should appear on Arbitrum. If it does not appear within N minutes, an alert is triggered. This requires a correlation engine:

class BridgeCorrelator:
    def __init__(self, redis_client):
        self.pending = {}

    def on_bridge_initiated(self, event):
        key = f"bridge:{event.src_chain}:{event.tx_hash}"
        self.redis.setex(key, 3600, json.dumps(event.to_dict()))

    def on_bridge_completed(self, event):
        key = f"bridge:{event.src_chain}:{event.bridge_nonce}"
        pending = self.redis.get(key)
        if not pending:
            alert(f"Bridge completion without initiation: {event}")
            return
        initiation = json.loads(pending)
        latency = event.timestamp - initiation['timestamp']
        if latency > EXPECTED_BRIDGE_LATENCY[event.bridge_protocol]:
            alert(f"Bridge latency anomaly: {latency}s")

TVL consistency check — total TVL on L2s should not exceed the locked amount on L1. Periodic check via subgraph queries with an alert if discrepancy > 5%.

Example of cross-chain correlation implementation For bridge monitoring, we use a correlator on Redis: on initiation, we store the event for one hour; on completion, we check the timeout. If the time exceeds the expected (e.g., 30 minutes for Arbitrum bridge), we generate an alert. This approach allows detecting stuck transactions before the user panics.

Which Smart Contract Events to Monitor First?

Security-critical events — those that must not be missed:

  • Ownership transfers — on any protocol contract
  • Upgrade proposals — events from Timelock (new proposals, execution)
  • Large withdrawals — withdrawal > 5% of TVL over a short period
  • Flash loan usage — obtaining a flash loan + interacting with the protocol contract in the same tx
  • Oracle price deviations — protocol price deviating from market by > 3%
  • Pause events — someone pauses the contract

Operational Metrics

  • Gas usage anomalies (sharp increase may indicate inefficient execution or an attack)
  • Failed transactions share (increase in failed tx for a router may indicate a UI/API bug)
  • Block inclusion latency for own transactions (keeper bots, liquidation bots)

Business Metrics

  • TVL dynamics per network
  • Volume per network
  • Unique active addresses
  • Protocol revenue (fees collected)

How to Choose Between OpenZeppelin Defender, Tenderly, and Custom Development?

Ready-made services provide a quick start, but cross-chain correlation is weak. Comparison:

Approach Advantages Limitations
OpenZeppelin Defender Quick start, built-in networks Weak cross-chain correlation
Tenderly Excellent dev environment, visualization Not suitable for production under high load
Custom system Full control, flexibility Development time 4-6 weeks

We recommend a combination: use Tenderly for operational monitoring of dev environment, Defender for basic production monitoring, and a custom layer for cross-chain correlation and specific rules.

Stack for a custom system:

  • Event ingestion: Node.js + ethers.js WebSocket listeners
  • Message queue: Redis Streams (for smaller projects) or Kafka (for high load)
  • Storage: TimescaleDB for time-series, PostgreSQL for event metadata
  • Alert rules: Python with rule engine
  • Notifications: PagerDuty/OpsGenie for critical, Telegram/Discord for operational
  • Dashboard: Grafana on TimescaleDB

Monitoring Development Process: From Audit to Deployment

  1. Audit of current infrastructure and requirements gathering — 1-2 days.
  2. Architecture design considering networks and load — 2-4 days.
  3. Setup of RPC, subgraph, and message queue.
  4. Development of custom alert rules and cross-chain correlation.
  5. Integration with notification systems (PagerDuty, Telegram, Discord).
  6. Documentation and team training.
  7. Post-launch support (optional).

What Is Included in the Work

  • Complete documentation of architecture and alert rules.
  • Source code for handlers and correlators.
  • Integration with your infrastructure (RPC, bridges, contracts).
  • Team training on dashboards and alert response.
  • Technical support for up to 3 months after launch.
  • Priority access to our support team via dedicated Slack channel.

Automatic Response to Alerts

Monitoring without automatic response is only half the system. We configure OpenZeppelin Defender Autotask or a custom keeper bot:

  • Anomalously large withdrawal > 5% of TVL → automatic contract pause (if pauser is set to keeper).
  • Oracle deviation > 3% → switch to fallback oracle.
  • Bridge stuck > 2 hours → notify bridge operator + create ticket.

Automatic response requires thorough auditing of the keeper bot itself. We ensure reliability and provide security certificates for our solutions. Get a consultation on monitoring your protocol — we will assess complexity and timeline within 1 day. Contact us to discuss your project.

Frequently Asked Questions

Which networks are supported in the monitoring system?

We connect any EVM-compatible networks: Ethereum, Arbitrum, Polygon, Optimism, Base, BNB Chain, Avalanche, and others. For each network, we configure reliable RPC and block finality settings.

How does the system handle high event load?

We use a message queue (Kafka or Redis Streams) to buffer peak loads. During sudden spikes in on-chain activity, such as large liquidations, all events are stored and processed asynchronously.

Can we integrate existing solutions like OpenZeppelin Defender?

Yes, we use ready-made services (Tenderly, Defender) for basic monitoring and layer custom logic for cross-chain correlation and specific business rules.

Which alerts are considered critical?

Critical alerts include: unauthorized transfer of ownership, execution of upgrade proposals, large TVL discrepancy between L1 and L2, anomalous oracle prices, and stuck bridge transactions.

Does the system include automatic response to alerts?

Yes, we configure automatic actions: contract pausing on anomalies, oracle switching, ticket creation. All keeper bots undergo security audits.

Blockchain Infrastructure Deployment: Nodes, RPC, Indexing

Subgraph fell at 3:47 AM. By morning users saw outdated balances, transactions "hung" in the UI, support received 47 tickets in an hour. Cause: the handler in the subgraph failed on a transaction with a non-standard event log — and the entire index stopped. We have encountered such situations dozens of times. Our experience shows: blockchain infrastructure does not forgive gaps in observability. Guaranteeing uptime without multi-layered monitoring and fault-tolerant architecture is impossible. Over 8 years working with Ethereum, Polygon, and Solana, we have developed an approach that allows predictable deployment of infrastructure of any scale — from a single node to a multichain grid with dozens of subgraphs.

RPC Layer Architecture

Every dApp interaction with the blockchain goes through RPC — the JSON-RPC API provided by a node. Three options:

Managed providers — Alchemy, QuickNode, Infura, Ankr. Minimal operational costs, SLA, built-in monitoring. Limits: rate limits (Alchemy Free: 300 RU/sec), vendor lock, potential downtime during provider incidents. For most projects — the right choice at the start.

Self-owned nodes — full control, no rate limits, no third-party dependence. Cost: archive Ethereum node requires 2.5–3TB SSD, a strong server, and DevOps support. Sync from scratch on Ethereum via Geth/Nethermind — 3–7 days. Justified under high load or latency requirements.

Hybrid — self-owned node as primary, managed provider as fallback. Standard for protocols with high TVL. Proper load balancing can reduce costs by 20–30% compared to pure managed setup. Under high monthly request volume, hybrid saves significantly.

Provider Strength Limitation
Alchemy Supernode, Enhanced APIs, webhooks Expensive on high-volume
QuickNode Low latency, multi-chain More expensive than Alchemy on basic plan
Infura Historical reliability Rate limits on free, one major incident halted half of DeFi
Ankr Cheap, 40+ chains Less stable

How to Set Up an RPC Layer Without a Single Point of Failure?

At least two providers, DNS round-robin with health check every 5 seconds, automatic fallback when latency >500 ms. In practice, this gives 99.99% availability during any provider failure. For protocols with high TVL, we recommend a custom HA-proxy (nginx or Envoy) in front of two managed providers.

Why Is a Hybrid RPC Scheme More Cost-Effective Than Pure Managed?

At high request volumes, managed providers can be very expensive; a hybrid using a self-owned node as primary and a managed fallback cuts costs significantly without losing SLA.

Ethereum Node Clients

Execution clients: Geth (most used), Nethermind (C#, fast sync), Besu (Java, enterprise), Erigon (fastest sync, efficient archive mode ~2TB instead of 3TB).

Consensus clients (post-Merge): Lighthouse (Rust), Prysm (Go), Teku (Java), Nimbus (Nim). Each node after The Merge requires a pair of execution + consensus clients.

For DevOps: eth-docker — Docker Compose configurations for all client combinations. Setting up monitoring via Grafana + Prometheus is mandatory; a standard dashboard is available in each client's repository.

The Graph: Event Indexing

The Graph Protocol — decentralized indexing. A subgraph describes which events from which contracts to index and how to transform them into a GraphQL schema.

Subgraph structure:

  • subgraph.yaml — manifest: contract addresses, startBlock, events to handle
  • schema.graphql — GraphQL schema of entities
  • src/mapping.ts — AssemblyScript event handlers
dataSources:
  - kind: ethereum
    name: UniswapV3Pool
    network: mainnet
    source:
      address: "0x88e6A0c2dDD26FEEb64F039a2c41296FcB3f5640"
      abi: UniswapV3Pool
      startBlock: 12370624
    mapping:
      eventHandlers:
        - event: Swap(indexed address,indexed address,int256,int256,uint160,uint128,int24)
          handler: handleSwap

AssemblyScript handlers — not TypeScript. No nullable types, no closures, no many standard APIs. An error in the handler stops the subgraph indexing on that transaction. Important: add try-catch for operations that can fail (e.g., store.get() for an entity that may not exist).

How to Avoid Subgraph Indexing Stops?

Graph Node logs are monitored in real-time; on hasIndexingErrors = true an alert fires and an automatic node restart (via systemd or Kubernetes). Typical downtime on error — 150–300 seconds to recover. Additionally, for production we set up a watchdog that restarts Graph Node if subgraph lag exceeds 50 blocks.

Choosing Between Hosted Service and Decentralized Network

Graph Hosted Service (free, centralized) is deprecated in favor of Subgraph Studio + Graph Network. For production: deploy on Graph Network with GRT curation signal — the subgraph gets indexers proportional to curation.

Alternatives to The Graph: Ponder (TypeScript, self-hosted, easier to debug), Envio (ultra-fast indexer, supports EVM + non-EVM), Subsquid (TypeScript, own network), Moralis Streams (managed, webhook-based). Our experience shows: for high-load projects with unique logic, Ponder or Envio are more effective — they give full control over the process and do not require GRT tokenomics.

Webhooks and Real-Time Notifications

Alchemy Webhooks and QuickNode Streams allow receiving events in real-time via HTTP webhook or WebSocket. For monitoring addresses, new transactions, mints — this is faster than polling RPC.

Tenderly — platform for monitoring and alerts. You can set up an alert for a specific contract event, balance change, function call with certain parameters. Transaction simulation via Tenderly API is invaluable for debugging.

Monitoring and Observability

Minimum monitoring stack for a protocol:

On-chain: OpenZeppelin Defender Sentinel — watches contract events, triggers webhook or Autotask when conditions are met. Forta Network — community-maintained bots detect anomalies (large withdrawals, flash loans, governance attacks).

Infrastructure: Grafana + Prometheus for nodes, Datadog or Grafana Cloud for managed metrics. Alerts on: node is 10+ blocks behind, RPC latency >500ms, subgraph lag >100 blocks.

Uptime: Better Uptime or PagerDuty on RPC endpoint and subgraph health endpoint (The Graph provides _meta { hasIndexingErrors, block { number } }).

Why Is Monitoring Without Tenderly Insufficient?

Tenderly provides transaction simulation and detailed traces — critical for debugging subgraph and smart contract errors. Forta focuses on network anomalies, not your infrastructure. The combination of Tenderly plus a custom Grafana dashboard covers 90% of incident scenarios.

Multichain Infrastructure

A protocol on 5 chains = 5 separate RPC endpoints, 5 subgraphs, 5 monitoring configs. Manageable but requires deployment automation.

For subgraph multi-network deployment: graph deploy --network mainnet, graph deploy --network arbitrum-one etc. with a unified codebase and network-specific addresses in separate config files.

Chainlink CCIP and LayerZero for cross-chain messaging require monitoring of both chains and transactions on intermediate relayers. A reorg on the source chain after a confirmed mint on the target chain is a classic bridge problem. Solution: wait for finality (on Ethereum ~15 minutes after Merge for economic finality) before confirming on the target chain.

Infrastructure Setup Process

  1. Audit current stack — determine chains, request volume, latency and availability requirements.
  2. Architecture design — select providers, load balancing, redundancy.
  3. Subgraph development — manifest → schema → handlers → testing on local Graph Node → deploy to testnet → mainnet.
  4. Monitoring configuration — Tenderly alerts, Grafana dashboard, PagerDuty integration.
  5. Documentation and runbook — what to do when: subgraph falls behind, RPC downtime, node desync.
  6. Handover to operations — team training, access transfer, first month support.

What's Included

  • Deployment of managed or self-hosted Ethereum, Polygon, BNB Chain nodes
  • RPC layer setup with primary/fallback and load balancing
  • Subgraph development and deployment for your protocol
  • Monitoring connection (Tenderly, Grafana, alerts)
  • Runbook and operations documentation
  • Team training (up to 4 hours online)
  • 30-day support after delivery

Timeline

Task Duration
RPC and basic monitoring setup 1–2 weeks
Subgraph for one protocol 2–4 weeks
Self-hosted node with monitoring 2–3 weeks
Full infrastructure (multi-chain, monitoring, runbooks) 6–10 weeks

All projects are managed in a GitHub/GitLab repository with CI/CD; configuration code stays with you. Order infrastructure deployment — we'll show how to cut costs by 20–30% without losing reliability. Get a consultation — we'll demonstrate how we deployed infrastructure for a protocol with large TVL on Ethereum and Arbitrum. Contact us.