Case Study: Chia achieves a 70% reduction in open security alerts with Socket
Key results
The challenge
Chia operates one of the most popular open source projects on GitHub and needed to manage security for a large, highly visible codebase widely used in the cryptocurrency and blockchain community. Its primary pain points were the extensive manual oversight required to manage third-party libraries and a high volume of security alerts that often included false positives, with prior tools forcing engineers to work across multiple platforms.
The solution
Chia switched to Socket, choosing it for an intelligence-based approach to validating libraries and scanning code, and consolidated security work into a single pane within GitHub. Engineers handle roughly 90% of what they need directly inside their existing git workflow, with defaults that worked effectively out of the box.
“Our number of open security alerts in GitHub from across all tools is down 70 percent, due to fewer false positives and faster identification of actual threats, which gives us the ability to focus on alerts that matter.”
JEJustin EnglandVP of Platform and Security, Chia
The results, in context
Chia reported that open security alerts in GitHub across all tools fell 70%, driven by fewer false positives and faster identification of actual threats, letting the team focus on alerts that matter. The company also reported cost savings and increased developer productivity since implementing Socket, with engineers handling about 90% of their security tasks directly within GitHub.