Bakkt operates in the crosshairs of two high-value attack surfaces: regulated financial infrastructure and digital asset custody. Founded in 2018, the company builds platforms that bridge traditional finance and the digital asset economy for institutional clients - meaning the threat model includes everything from API-layer exploits on trading systems to smart-contract risk and cross-border compliance gaps. Their stack spans AI-driven programmable finance, cross-border payment rails, and institutional-grade trading platforms, each carrying distinct security demands around transaction integrity, data sovereignty, and regulatory compliance.
The product portfolio breaks into three operational domains. Bakkt Agent combines AI-driven interfaces with compliant payment solutions to move money globally through banking partners - introducing adversarial ML and prompt-injection vectors alongside traditional payment-fraud concerns. Bakkt Markets handles institutional-grade trading, where latency-sensitive systems demand hardened infrastructure and real-time anomaly detection. Bakkt Marketplace provides digital asset services, anchoring the custody and settlement layer where key management and on-chain verification become core security primitives.
For a security team, this means working across multiple regulated domains simultaneously - fintech, consumer finance, and institutional capital markets - where a single misconfiguration or access-control failure can have cascading compliance and financial consequences. The company is U.S.-based, publicly traded, and serves financial institutions and fintechs, which imposes the kind of audit and regulatory scrutiny that shapes how engineering and security teams operate day to day: policy-driven, control-mapped, and built to withstand examination.




