Skip to main content Scroll Top

Blockchain App Development Company: Smart Contracts, dApps, Wallets and Tokenization Built to Pass an Audit

Updated September 2026 · Written and maintained by the Progression Agency strategy team

A blockchain app development company designs, writes, tests and ships software whose key records or transfers of value run on a blockchain: smart contracts, the web or mobile front end, wallets and key management, token systems, and the conventional backend that connects all of it to the rest of the business. Progression Agency builds on public Ethereum, its layer 2 networks and permissioned ledgers such as Hyperledger Fabric and Besu, and starts with the question many teams skip: whether the product needs a chain at all. Progression Agency is a New York City company working with clients across the United States and worldwide.

On this page · 18 sections
  1. Does your product need a blockchain?
  2. Public, layer 2 or permissioned: where should the contracts run?
  3. Smart contract development in Solidity
  4. What belongs on-chain in a dApp, and what does not?
  5. Who should hold the keys in a blockchain app?
  6. Tokenization: fungible tokens, NFTs and real-world assets
  7. Security and audits: the part that decides whether you launch
  8. Which US rules shape a blockchain build?
  9. What do Apple and Google allow in crypto and NFT apps?
  10. Enterprise blockchain app development
  11. Web3 app development for consumer products
  12. What does blockchain app development cost?
  13. From testnet to mainnet: delivery gates
  14. How founders ask AI assistants to recommend blockchain developers
  15. How to choose a blockchain app development company
  16. Blockchain software development services we provide
  17. Marketing a blockchain product after launch
  18. Related services

The short answerBlockchain app development is worth the cost when several parties that do not fully trust one another need one tamper-evident record, or when value must move under rules no single operator controls; otherwise a conventional database is cheaper and faster. The build covers Solidity smart contracts, a dApp or app front end, wallet and key management, indexing and oracles, and a security process that ends with an independent audit before mainnet. Design choices are checked against primary US sources: the SEC’s March 2026 interpretation of how securities law applies to crypto assets, FinCEN’s 2019 guidance on convertible virtual currency, OFAC’s sanctions guidance and the GENIUS Act on payment stablecoins. We price blockchain work against the software planning ranges we publish, from a $5,000-$15,000 technical assessment to $250,000-$500,000+ for a payments-grade platform, with a quote after a written scope.

Search volumes and costs per click are Ubersuggest data for the United States, September 2026. Technical statements are quoted from ethereum.org, the Solidity documentation, Ethereum Improvement Proposals, OWASP, NIST and the Hyperledger and Besu projects; regulatory statements from the SEC, FinCEN, OFAC and the text of Public Law 119-27, each linked where it appears. Price ranges are the development planning ranges we publish. Nothing on this page is legal, tax or investment advice.

Does your product need a blockchain?

Only if several parties must share one record that none of them controls, or users must hold and move value without asking you. NIST’s Blockchain Technology Overview (NIST IR 8202) describes blockchains as tamper evident and tamper resistant digital ledgers implemented in a distributed fashion, usually without a central authority, and that property is what you pay for.

When a shared ledger helps, and when a database is better
SituationBlockchain?Why
One company owns and edits all the dataNoA database is faster, cheaper and easier to correct
Several companies reconcile the same transactionsOftenOne shared, tamper-evident record replaces reconciliation between separate ledgers
Users must hold and transfer assets without your permissionYesSelf-custody and public settlement are the point
Records must be provably unchanged laterSometimesAnchoring a hash on a public chain may be enough, with the data kept off-chain
High-volume, low-latency internal workloadsRarelyConsensus adds cost and delay the workload does not need
Personal data that people may ask you to deleteKeep it off-chainOn-chain data is public and hard to remove; store references or hashes only

ethereum.org is candid about the trade-offs in its guide to dapps: code and data published to a blockchain are harder to modify, the performance overhead is large and scaling is hard, one busy application can congest the whole network, and practical designs can end up looking like centralized services anyway. When a brief fails the test above, we say so and build the product on a conventional stack with our custom software development team.

Public, layer 2 or permissioned: where should the contracts run?

Public Ethereum gives open settlement and composability, layer 2 networks cut fees while building on Ethereum, and permissioned ledgers keep participation and data among known parties. NIST draws the line simply: in a permissionless network anyone can read and write without authorization, while permissioned networks limit participation to specific people or organizations.

Where blockchain apps run
OptionWho participatesStrengthsTrade-offsTypical fit
Ethereum mainnetAnyoneMaximum openness, deep tooling, composable contractsFees vary with demand; everything is publicSettlement, high-value assets, public verifiability
Ethereum layer 2 networksAnyone, with each network’s own operatorsLower fees and faster confirmationSafety depends on each network’s technology and maturityConsumer apps and frequent small transactions
Permissioned EVM network, for example BesuApproved organizationsEthereum tooling with controlled membershipGovernance and hosting are your jobConsortiums that want Solidity skills and privacy
Hyperledger FabricKnown, identified membersChannels and private data; contracts in Go, Java or Node.js; no native cryptocurrency requiredA separate ecosystem from EthereumEnterprise record-sharing between companies
HybridA private system plus public anchorsPrivate data with public proofTwo systems to operateAudit trails, certificates, supply chain

Ethereum and its layer 2 networks

ethereum.org describes Ethereum as “no longer just a single network” now that hundreds of chains are built on top of it, and cautions that the safety of those layer 2 networks depends on the underlying technology, smart contract security and the maturity of each network. We choose a layer 2 on its security model and exit arrangements, not on fees alone.

Permissioned networks: Besu and Fabric

Besu is an open source Ethereum client, written in Java under the Apache 2.0 license, that runs on public and private networks, so a consortium can use Solidity and Ethereum tooling with approved members. Hyperledger Fabric is “an open-source enterprise-grade permissioned distributed ledger technology (DLT) platform” whose participants are known to each other, with pluggable consensus, channels and private data for confidentiality, and smart contracts written in general-purpose languages.

Hybrid designs

Some needs are met by keeping data in a private system and publishing only hashes or proofs to a public chain, which gives outsiders something they can verify without exposing the records themselves.

Where each network option is strong (1-5, editorial)Where each network option is strong (1-5, editorial)
Editorial scores. No option wins everywhere; the parties and the data decide.
Mainnet — Ethereum. Public settlement.
Layer 2 — Rollup networks. Lower fees on Ethereum.
Besu — Permissioned EVM. Approved members.
Fabric — Hyperledger. Channels, private data.
Hybrid — Private plus anchored. Proofs made public.
Database — No chain needed. When one party owns the data.

Smart contract development in Solidity

Smart contracts are small, public, hard-to-change programs, so the craft is writing as little on-chain code as possible and making every line of it provable.

ethereum.org defines a smart contract as “simply a program that runs on the Ethereum blockchain,” code and data at a specific address, and notes that contracts cannot be deleted by default, that interactions with them are irreversible, that they cannot retrieve off-chain data without oracles, and that a contract is limited to 24KB. The Solidity documentation describes the language as object-oriented, high-level and statically typed, designed to target the Ethereum Virtual Machine, and advises deploying with the latest released version because, apart from exceptional cases, only the latest version receives security fixes.

Keep on-chain logic minimal

Only the rules every party must trust go on-chain: balances, ownership, permissions and settlement. Search, reporting, notifications and anything involving personal data stay off-chain, where they are cheaper and can be changed.

Build on audited libraries

We use established libraries such as OpenZeppelin Contracts for token standards and access control, and follow its instruction to use the installed code as-is rather than copying or modifying it. Custom code is limited to what makes the product different.

Decide the upgrade policy before deployment

ethereum.org’s guide to upgrading smart contracts starts from the fact that contracts are immutable by design and describes the workarounds: migration, data separation, proxy patterns, the strategy pattern and the diamond pattern. Each trades some immutability for flexibility, so upgrade rights sit behind timelocks and multisig approval and are disclosed to users.

Treat gas as a product cost

Every operation costs gas, the unit ethereum.org uses to measure computational effort; the fee is the gas used multiplied by the protocol-set base fee plus a priority tip, and the base fee is burned. Storage-heavy designs cost users money on every call, so data structures are chosen for cost as well as clarity.

The rules the Solidity docs insist on

The security considerations chapter warns that everything in a contract is publicly visible, even state variables marked private, that the Checks-Effects-Interactions pattern guards against re-entrancy, that loops without a fixed bound can hit block gas limits, and never to use tx.origin for authorization. We treat those as build rules enforced in code review.

What belongs on-chain in a dApp, and what does not?

A dApp is mostly ordinary software around a thin on-chain core. ethereum.org says a dapp has its backend code running on a decentralized peer-to-peer network rather than centralized servers; in practice that backend is the contracts, while indexing, interfaces and storage run conventionally.

Layers of a typical dApp
LayerJobNotes
Smart contractsBalances, ownership, permissions, settlementMinimal, audited, with a stated upgrade policy
Indexer and APITurns contract events into fast queries and historyConventional backend engineering
OraclesBring prices and other off-chain facts on-chainDecentralized or well-governed feeds, with sanity checks
Front endWeb or mobile interface with transaction previewsExplains fees and outcomes before users sign
Wallet connectionSigning and account managementSelf-custody, hosted or smart accounts
Off-chain storageDocuments, media and personal dataOnly hashes or references go on-chain
MonitoringAlerts on unusual transactions and admin actionsTied to an incident plan with a pause switch

Oracles deserve their own risk review. ethereum.org describes oracles as applications that produce data feeds making off-chain sources available to smart contracts, and warns that a centralized oracle can go rogue, be hacked or stop serving data, leaving contracts to act on bad inputs; price-feed manipulation is second on OWASP’s list further down this page. The indexer and API layer is conventional engineering, built by our API development team like any production API.

Who should hold the keys in a blockchain app?

Decide who holds the keys before anything else: users (self-custody), you (a hosted wallet), or a smart account that pairs self-custody with recovery and sponsored fees. The choice changes the user experience, the security model and the regulatory position.

Wallet models compared
ModelWho controls the keysUser experienceRegulatory note
Self-custody, an externally owned accountThe user’s private keySeed phrases and signing prompts; full controlFinCEN: a person transacting through an unhosted wallet to buy goods or services for themselves is not a money transmitter
Hosted, or custodial, walletThe providerA familiar log-in; the provider can help with recoveryFinCEN treats hosted wallet providers as account-based money transmitters
Smart account under ERC-4337Contract rules, often with several signers or recoverySponsored gas, batched actions, social recoveryDepends on who can move funds; reviewed with counsel

Self-custody wallets

On Ethereum, externally owned accounts are controlled by whoever holds the private key, and ethereum.org is explicit that losing the key means losing access to the funds. Self-custody apps therefore invest in backup prompts, clear signing screens and warnings before irreversible transfers.

Hosted wallets

A hosted wallet feels like a normal account, but the provider holds the value. FinCEN’s 2019 guidance describes hosted wallet providers as account-based money transmitters that must identify and monitor customers under an anti-money-laundering program, and Apple’s guideline 3.1.5(i) allows wallet apps only from developers enrolled as an organization.

Smart accounts and sponsored gas

ERC-4337, a final Ethereum standard, delivers account abstraction without consensus-layer changes: users submit UserOperations that bundlers package for an EntryPoint contract, and paymaster contracts can pay fees for users or accept ERC-20 tokens for gas. That lets a consumer app hide gas and offer recovery without taking custody.

Recovery and support

Whatever the model, support needs a documented answer for lost devices, compromised keys and mistaken transfers, including what cannot be undone. Writing that answer early often changes the wallet model chosen.

Scoping a blockchain product?Tell us what must be shared, who the parties are and where value moves; we reply with a network recommendation, a contract outline and the rules that apply.

Get a blockchain scope

Tokenization: fungible tokens, NFTs and real-world assets

Tokens are contracts that follow shared standards, so wallets and exchanges can handle them without custom code; the legal character of a token depends on what it represents and how it is sold, not on the standard it uses.

ethereum.org’s token standards page lists ERC-20 for fungible tokens such as voting, staking or virtual currency tokens, ERC-721 for non-fungible tokens such as a deed for artwork or a song, and ERC-1155 for contracts that hold both kinds and bundle transfers to save costs.

Utility, loyalty and access tokens

Memberships, tickets, credentials and loyalty points map well to tokens because they need transfer rules and proof of ownership. The SEC’s March 2026 interpretation classes crypto assets that perform a practical function, such as a membership, ticket, credential, title instrument or identity badge, as digital tools that are not securities.

NFTs and digital collectibles

The same interpretation treats digital collectibles, such as rights to artwork, music, videos, trading cards or in-game items, as not securities. App stores add their own rules: Apple lets apps use in-app purchase for NFT services such as minting, listing and transferring, provided NFT ownership does not unlock app features, and Google Play requires apps that sell or let users earn tokenized digital assets to declare it and not promote potential earnings.

Tokenized securities and real-world assets

Tokenized stocks, bonds and fund interests remain securities: the SEC’s taxonomy lists digital securities, financial instruments represented by a crypto asset with ownership recorded on a crypto network, as securities. Builds for regulated assets use permissioned token standards such as ERC-3643, a final standard for security tokens that checks investor identity and compliance rules on each transfer. In September 2026 the SEC also granted temporary, conditional exemptive relief, set to expire five years after publication, to Tokenized Securities Venues trading tokenized NMS stock, with smart contracts that must be auditable, public and deployed on a public, permissionless ledger (SEC press release 2026-90).

Security and audits: the part that decides whether you launch

Plan security from the first design review, because deployed mistakes are public and often irreversible. ethereum.org’s security guide says the value stolen or lost to security defects in smart contracts is estimated at “easily over $1 billion.”

OWASP Smart Contract Top 10 (2025) and our standard response
RiskWhat goes wrongHow we address it
SC01 Access control vulnerabilitiesAnyone can call a privileged functionRole-based access from audited libraries; tests for every privileged path
SC02 Price oracle manipulationA manipulated price drains fundsRobust feeds, time-weighted prices, sanity bounds
SC03 Logic errorsThe code does what was written, not what was meantA written specification first, then property-based tests
SC04 Lack of input validationUnexpected values break invariantsExplicit checks on every external input
SC05 Reentrancy attacksAn external call re-enters before state is updatedChecks-Effects-Interactions and reentrancy guards
SC06 Unchecked external callsFailed calls go unnoticedChecked return values and safe transfer helpers
SC07 Flash loan attacksBorrowed capital distorts prices or votesSnapshots, delays and oracle design
SC08 Integer overflow and underflowArithmetic wraps aroundChecked arithmetic, with any unchecked block reviewed line by line
SC09 Insecure randomnessPredictable outcomes get gamedVerifiable randomness from an oracle
SC10 Denial of serviceA contract is blocked or made too costly to useBounded loops, pull payments, gas tests

The list is the OWASP Smart Contract Top 10, 2025 edition. ethereum.org’s smart contract security guidance adds the practices around it: access controls, require, assert and revert guards, testing with static and dynamic analysis and formal verification, independent audits and bug bounties, simple code built on audited libraries, and disaster recovery through upgrades, emergency stops and event monitoring.

The security path from design to mainnetThe security path from design to mainnet
The external audit is one gate among eight, not the whole security plan.

Testing before anyone else sees the code

Unit tests cover every function, property-based and fuzz tests hunt for broken invariants, static analysis runs on every commit, and a written specification states what must always be true, such as total supply never exceeding the cap.

Independent audit and bug bounty

An outside audit firm reviews the frozen code before mainnet, and every finding is fixed or answered in writing. After launch, a bug bounty gives researchers a legitimate way to report problems.

After launch: limits, monitoring and a pause switch

New contracts launch with value caps, alerts on unusual activity and admin actions, and a tested emergency stop controlled by a multisig, so an incident can be contained while it is investigated.

SC01 — Access control. OWASP 2025, first on the list.
SC05 — Reentrancy. Checks-Effects-Interactions.
SC02 — Oracle manipulation. Price feeds.
Audit — Independent review. Before mainnet.
Bounty — Bug bounty. After launch.
Pause — Emergency stop. Multisig controlled.

Which US rules shape a blockchain build?

Four federal sources settle most design questions: the SEC on whether a token is a security, FinCEN on money transmission, OFAC on sanctions and the GENIUS Act on payment stablecoins. We design within them and leave legal conclusions to your counsel.

SEC: the March 2026 token taxonomy

On March 17, 2026 the SEC issued an interpretive release, Application of the Federal Securities Laws to Certain Types of Crypto Assets and Certain Transactions Involving Crypto Assets, effective March 23, 2026, which the CFTC joined. Its fact sheet sorts crypto assets into digital commodities, digital collectibles and digital tools, which are not securities; stablecoins issued under the GENIUS Act, which are not securities; and digital securities, which are. It explains how a non-security crypto asset becomes subject to an investment contract under the Howey test and how that ends, and the staff’s 2019 framework for investment contract analysis is now marked withdrawn and superseded by it. A separate proposal announced on August 18, 2026, Regulation Crypto Assets, would add a startup exemption of up to $5 million over four years, a fundraising exemption of up to $75 million a year and an investment contract safe harbor; it is a proposal, not a rule (Chairman Atkins’ statement).

FinCEN: money transmission and DApps

FinCEN’s FIN-2019-G001, issued May 9, 2019, applies existing Bank Secrecy Act rules to convertible virtual currency business models without creating new requirements. It says the developer of a DApp is not a money transmitter for the mere act of creating it but becomes one if it uses or deploys the DApp to engage in money transmission; that when DApps perform money transmission, the definition applies to the DApp, its owners or operators, or both; that hosted wallet providers are money transmitters; and that anonymizing software providers are not, while anonymizing service providers are.

OFAC: sanctions screening

OFAC’s virtual currency FAQs say U.S. persons’ sanctions obligations are the same whether a transaction is in fiat or virtual currency, and that OFAC may add digital currency addresses to the SDN List. Its Sanctions Compliance Guidance for the Virtual Currency Industry notes that civil penalties can rest on strict liability, encourages technology companies and wallet providers, among others, to run a risk-based sanctions program, and recommends geolocation and IP blocking, screening customers at onboarding and screening transactions, wallet addresses included, with blockchain analytics tools where appropriate.

The GENIUS Act: payment stablecoins

The Guiding and Establishing National Innovation for U.S. Stablecoins Act, Public Law 119-27, was approved on July 18, 2025. It makes it unlawful for anyone other than a permitted payment stablecoin issuer to issue a payment stablecoin in the United States; requires reserves of at least 1 to 1 in listed assets such as U.S. currency, demand deposits and Treasury bills with 93 days or less to maturity; requires issuers to publish the monthly composition of their reserves; bars issuers from paying interest or yield solely for holding a stablecoin; and treats issuers as financial institutions under the Bank Secrecy Act. It takes effect on the earlier of 18 months after enactment or 120 days after the primary federal regulators issue final implementing rules.

What each source changes in the build
SourceWhat the product must handleWhere it shows up in the software
SEC interpretation, March 2026Which category each token falls into, and any investment-contract promisesToken design, disclosures, launch and marketing copy reviewed by counsel
FinCEN FIN-2019-G001Whether the business accepts and transmits value for othersCustody model, KYC and anti-money-laundering hooks, transaction monitoring
OFAC guidance and FAQsSanctioned persons, jurisdictions and wallet addressesOnboarding screening, IP geolocation blocks, address screening before transfers
GENIUS Act, P.L. 119-27Which payment stablecoins can be offered and how issuers operateStablecoin selection, reserve disclosures for issuers, no issuer yield on holdings
App Store and Google Play rulesWho may publish wallets, exchanges and NFT featuresDeveloper account type, regional availability, store declarations
The GENIUS Act in four numbersThe GENIUS Act in four numbers
Source: Public Law 119-27, approved July 18, 2025. It takes effect on the earlier of 18 months after enactment or 120 days after final regulations.
SEC — Token taxonomy. March 2026 release.
FinCEN — FIN-2019-G001. Money transmission.
OFAC — Sanctions. Strict liability.
GENIUS — Payment stablecoins. P.L. 119-27.
3.1.5 — App Store. Crypto apps.
Play — Google policy. Tokenized assets.

This section summarizes primary sources for engineering purposes; it is not legal advice. Crypto rules are changing quickly, and the SEC’s Crypto Task Force page lists current statements, so we check each source again at kickoff.

What do Apple and Google allow in crypto and NFT apps?

Both stores allow crypto apps with conditions, and those conditions decide how the company publishes the app and where it is available.

  • Apple 3.1.5(i): wallet apps may facilitate virtual currency storage if offered by developers enrolled as an organization.
  • Apple 3.1.5(ii): no mining on the device; processing must happen off-device.
  • Apple 3.1.5(iii): exchange features only in countries or regions where the app has appropriate licensing and permissions.
  • Apple 3.1.5(iv): ICOs, cryptocurrency futures and other crypto-securities trading must come from established banks, securities firms, futures commission merchants or other approved financial institutions.
  • Apple 3.1.5(v): no cryptocurrency rewards for tasks such as downloading other apps or posting to social networks.
  • Apple 3.1.1: in-app purchase may be used for NFT services such as minting, listing and transferring; NFT ownership may not unlock features.
  • Google Play: apps that sell or let users earn tokenized digital assets must declare it in Play Console, may not promote potential earnings from playing or trading, and, unless approved as gambling apps, may not take anything of monetary value for a chance at an NFT of unknown value.

Sources: Apple’s App Store Review Guidelines and Google Play’s blockchain-based content policy. Mobile web3 app development is planned around these rules from the first sprint, because they decide the developer account, the markets and sometimes the features.

Have contracts that need a second look?We review architecture, tests and key management before your external audit, and write down what we find.

Request a technical review

Enterprise blockchain app development

Enterprise projects are best served by a permissioned ledger that several organizations run together, integrated with ERP, identity and document systems, with public chains used only where proof or settlement must be public.

Provenance and supply chain records

Suppliers, carriers and buyers write shipment and certification events to a shared ledger, so each party sees the same history without reconciling spreadsheets. Our logistics software development team connects the ledger to the warehouse and transport systems that produce those events.

Inter-company reconciliation and settlement

Where companies settle obligations with one another, a shared ledger can replace duplicate records. Payment rails, custody and ledgers that touch money are built with our fintech software development practice.

Audit trails and document anchoring

Contracts, certificates and inspection reports stay in a document system while their hashes are anchored on a ledger, so anyone can later prove a document has not changed.

Integration with ERP and identity

Ledger events must reach ERP, CRM and identity systems, and users must sign in with company credentials. That integration layer is conventional work for our ERP development team.

An enterprise blockchain app development company should be judged on governance as much as code: who runs nodes, who approves members, how contracts are upgraded and how disputes are settled. We write that operating model with the members before any network goes live.

Web3 app development for consumer products

Consumer web3 apps are judged on onboarding: wallet creation, fees and recovery have to feel like any other app.

Smart accounts under ERC-4337, sponsored gas through paymasters, clear transaction previews and plain-language warnings do most of that work. A web3 app development company should also design for the store rules above, for users who arrive with no wallet at all, and for layer 2 networks where fees are low enough for everyday actions. For DeFi features, FinCEN’s point about DApp owners and operators applies directly: if the business deploys a DApp to accept and transmit value for others, it may be a money transmitter, so custody and control are settled with counsel before launch.

If energy use matters to your audience, ethereum.org cites an estimate by CCRI that The Merge reduced Ethereum’s annualized electricity consumption by more than 99.988% (ethereum.org on energy consumption).

What does blockchain app development cost?

We have not published a separate blockchain price list, so we scope blockchain builds against the development planning ranges we publish for comparable software, from $5,000-$15,000 for a technical assessment to $250,000-$500,000+ for a payments-grade platform. External audits, gas, node services and legal work are quoted by those providers.

Blockchain work mapped to our published planning ranges
Blockchain workClosest published rangeTimelinePublished on
Technical assessment of an existing chain project or codebase$5,000-$15,0002-4 weeksSoftware consulting
Architecture and roadmap$10,000-$40,0003-8 weeksSoftware consulting
Smart contract integration into an existing app$15,000-$40,000, as a single integration3-6 weeksAPI development
dApp or web3 MVP$60,000-$150,00012-24 weeksMVP development
Wallet or payments product on partner infrastructure$100,000-$200,0004-6 monthsFintech software
Exchange-style, tokenization or payments-grade platform$250,000-$500,000+8-12+ monthsFintech software
Enterprise permissioned network with integrations$250,000+6-12+ monthsSoftware development
Managed DevOps and node operations$3,000-$15,000 per monthOngoingDevOps services

The blockchain app development cost for a given product depends most on how much value the contracts will hold, which sets the depth of testing and audit, and on how many systems the chain must talk to. Every figure above is a planning range from our published pages; the quote follows a written scope.

From testnet to mainnet: delivery gates

Blockchain releases move through gates rather than dates: each needs evidence before the next begins, because a deployed contract cannot simply be patched.

Delivery gates for a blockchain product
GateEvidence requiredTypical timing
Need and modelA written case for a shared ledger, the chosen network, token and custody modelWeeks 1-3
Rules mapCounsel’s view on securities, money transmission, sanctions and stablecoin questionsWeeks 2-5
SpecificationInvariants, roles, upgrade policy and threat modelWeeks 3-6
Testnet buildContracts, indexer, front end and wallet flows passing testsWeeks 5-16
External auditFrozen code reviewed; findings fixed or answered in writingAfter code freeze
Guarded mainnetValue caps, monitoring, multisig admin and a live bug bountyLaunch
ScaleCaps raised while monitoring stays cleanMonths after launch

How founders ask AI assistants to recommend blockchain developers

Founders and product leaders can ask ChatGPT, Claude, Perplexity, Gemini, Microsoft Copilot or Google’s AI Overviews to name blockchain developers for a specific job, and the answers depend on what those assistants can read and verify.

US searches for blockchain development servicesUS searches for blockchain development services
US monthly searches, Ubersuggest, September 2026. Buyers search for companies and services more than for the technology.

What buyers type

The prompts are specific: “recommend a blockchain app development company for a tokenized real estate fund,” “who builds ERC-4337 wallets with sponsored gas,” “software development blockchain partner for a supply chain pilot on Hyperledger Fabric,” or “Solidity developers who have fixed audit findings before.” In Ubersuggest’s September 2026 figures, “blockchain app development companies” leads US demand at 260 searches a month, ahead of “blockchain app development services” and “blockchain app development company” at 210 each.

What the assistants tend to cite

Assistants lean on sources they can check: agency pages that state chains, languages and security process, public audit reports, code repositories, official documentation and, for shortlists, directory profiles and “top blockchain companies” roundups. A web search we ran on September 30, 2026 for “blockchain app development company” returned agency pages alongside roundups and directory listings of that kind.

What your protocol or app should publish

Once live, publish what assistants and careful users look for: verified contract addresses, audit reports and how findings were fixed, documentation, fee and risk disclosures, and who controls upgrade keys. Our AEO for crypto work covers how those pages get cited.

Reading the answer critically

Assistants can repeat marketing claims. Ask each firm named for audit reports on code it wrote, how it handles deployment keys and what it would refuse to put on-chain; the quality of those answers is the real shortlist.

How to choose a blockchain app development company

Choose the team that will argue you out of unnecessary on-chain code, shows its audit history openly and can explain the regulatory map for your model in plain English.

What to require from blockchain app development companies
RequirementHow to check it
A written case for or against a chainAsk for their recommendation on your idea, including a no-blockchain option
A security process before the auditAsk for their test, fuzzing and static-analysis setup and a sample specification
Audit experienceAsk for public audit reports on code they wrote and how each finding was resolved
Key and upgrade managementAsk who holds deployment and admin keys, and how multisig and timelocks are set up
Regulatory literacyAsk how the SEC taxonomy, FinCEN guidance, OFAC screening and the GENIUS Act affect your design
Conventional engineering depthAsk to see indexer, API and front-end work, not only contracts
Your ownershipConfirm you own the repositories, contract admin roles, domains and cloud accounts

Blockchain software development services we provide

We cover the full stack of blockchain software development, from the first feasibility call to operating a live network.

  • Feasibility and architecture reviews that start with whether a chain is needed.
  • Custom blockchain app development on Ethereum, its layer 2 networks and permissioned EVM networks.
  • Custom blockchain software development on Hyperledger Fabric for enterprise consortiums.
  • Smart contract development in Solidity with OpenZeppelin libraries, tests, fuzzing and static analysis.
  • dApp front ends for web and mobile, with clear transaction previews.
  • Wallets: self-custody, hosted and ERC-4337 smart accounts with sponsored gas.
  • Token systems: ERC-20, ERC-721, ERC-1155 and permissioned ERC-3643 tokens.
  • Indexers, APIs and integrations with ERP, CRM, identity and payment systems.
  • Audit preparation, remediation and post-launch monitoring with emergency controls.
  • Sanctions-screening and compliance hooks designed with your counsel.

Whether you need blockchain app development services for a single feature or a blockchain software development company to run the whole build, our blockchain software development services start from the same written scope.

Marketing a blockchain product after launch

Blockchain marketing has its own rules: securities law shapes what can be promised, ad platforms set their own conditions for crypto promotion, and trust is earned with audits and disclosures rather than slogans.

Questions about blockchain in marketing come in two kinds. One is using tokens inside a marketing program, such as loyalty points, tickets or credentials, which the SEC’s taxonomy treats as digital tools rather than securities when they perform a practical function. The other is marketing a blockchain product itself, which our crypto marketing agency team handles, alongside fintech marketing for regulated financial products and AEO for crypto for AI search. Blockchain marketing and PR land better when the launch team can point to audit reports, contract addresses and plain-language risk disclosures.

Scoping a blockchain product?

Tell us what must be shared, who the parties are and where value moves. We reply with a network recommendation, a contract outline, the rules that apply and a planning estimate.

Get a blockchain scope

Software and app development

Frequently asked questions

Can blockchain be used in marketing, or only in finance?
Both. Inside marketing programs, tokens can carry loyalty points, event tickets, memberships or credentials with transfer rules and proof of ownership, and the SEC’s March 2026 interpretation treats such practical-function tokens as digital tools, not securities. Marketing a blockchain product is a separate discipline, which our crypto marketing agency team covers with attention to securities and ad-platform rules.
Who should handle marketing and PR for a blockchain launch?
A team that knows both the product and the rules: what can be promised about a token under securities law, which ad platforms accept crypto promotion and on what terms, and how audits and disclosures build trust. We build the product; our crypto marketing and AEO for crypto teams handle launch, PR and visibility in AI search.
What does a blockchain app development company deliver besides smart contracts?
Most of the product. Contracts are the thin core; around them sit the web or mobile front end, wallet and key management, an indexer and API for fast queries, oracle integrations, off-chain storage for documents and personal data, monitoring with an emergency stop, sanctions-screening hooks, and the tests and specifications that prepare the code for an external audit.
Is a token we issue a security?
That is a legal question for your counsel, but the SEC’s March 2026 interpretation gives the framework: digital commodities, digital collectibles, digital tools and GENIUS Act stablecoins are not securities, while digital securities are, and a non-security asset can become subject to an investment contract through promises of essential managerial efforts under the Howey test. We design tokens and launch copy so counsel can apply it.
Does building a DApp make us a money transmitter?
Not by itself, according to FinCEN’s 2019 guidance: a DApp developer is not a money transmitter for the mere act of creating the application. It becomes one if it uses or deploys the DApp to engage in money transmission, and when a DApp performs money transmission the definition applies to the DApp, its owners or operators, or both. Hosted wallet providers are treated as money transmitters.
Do we need to screen wallet addresses for sanctions?
Plan on it. OFAC’s FAQs say sanctions obligations are the same for virtual currency as for fiat and that OFAC may list digital currency addresses on the SDN List, and its 2021 guidance recommends screening customers at onboarding, screening transactions including wallet addresses, and geolocation and IP blocking. Because civil penalties can rest on strict liability, screening hooks go in from the start.
Can our app pay interest on stablecoin balances?
The GENIUS Act bars permitted and foreign payment stablecoin issuers from paying holders any interest or yield solely for holding, using or retaining a payment stablecoin. Whether a reward program run by an app that is not the issuer falls inside that rule, or under other securities or banking rules, is a question for counsel before anything is built.
Which blockchain should we build on?
It depends on who must participate and what must be public. Public Ethereum suits open settlement and high-value assets, layer 2 networks suit frequent low-value transactions, and permissioned ledgers such as Besu or Hyperledger Fabric suit known organizations sharing private data. We recommend after mapping the parties, data sensitivity, transaction volume and the rules that apply.
What languages are smart contracts written in?
On Ethereum and other EVM networks, typically Solidity, which its documentation describes as an object-oriented, statically typed language designed to target the Ethereum Virtual Machine; ethereum.org also mentions Vyper. Hyperledger Fabric runs smart contracts in general-purpose languages such as Go, Java and Node.js. We choose the platform first, and the language follows.
Can a smart contract be changed after it is deployed?
Not directly: ethereum.org describes contracts as immutable by design. Teams add flexibility with proxy patterns, data separation, the strategy or diamond patterns, or by migrating to a new contract. Each weakens immutability, so upgrade rights should sit behind timelocks and multisig approval and be disclosed to users before they commit funds.
How are smart contract audits priced?
Independent audit firms quote their own fees based on code size, complexity and timeline, so we do not publish audit prices. What we publish is our own technical assessment of an existing codebase, a planning range of $5,000-$15,000 over two to four weeks, which prepares code for an audit but does not replace one. Audit time belongs in the schedule, not after it.
What timeline should we expect for a first dApp release?
Our published planning ranges put a marketplace or similarly complex MVP at 12-24 weeks and $60,000-$150,000, which is the closest match for a dApp MVP. Add time for an external audit after code freeze and for a guarded mainnet launch with value caps. Regulatory review runs in parallel from the first weeks rather than at the end.
What is account abstraction, and why does it matter to users?
Account abstraction lets a wallet be a smart contract with its own rules. ERC-4337, a final Ethereum standard, delivers it without consensus-layer changes: users submit UserOperations, bundlers pass them to an EntryPoint contract, and paymasters can sponsor gas or accept ERC-20 tokens for fees. For users that means fewer gas prompts, batched actions and recovery options.
Custodial or non-custodial wallet: which should we offer?
Non-custodial wallets leave keys with users, which suits products built on self-custody but makes recovery the user’s problem. Custodial wallets feel familiar but make you the holder of value, and FinCEN treats hosted wallet providers as money transmitters. Smart accounts sit in between. The right answer depends on your license position, your users and your support capacity.
Can personal data be stored on a blockchain?
It should not be. The Solidity documentation warns that everything in a smart contract is publicly visible, even variables marked private, and ethereum.org notes that data published to a blockchain is harder to modify. Personal data stays in conventional storage, and at most a hash or reference goes on-chain, so records can be corrected or deleted when the law or a user requires it.
Does Ethereum still use a lot of energy?
Far less than it did. ethereum.org cites an estimate by CCRI that The Merge, Ethereum’s move to proof of stake, cut its annualized electricity consumption by more than 99.988%. Energy use differs on other chains and layer 2 networks, so we include it in the network comparison when it matters to your customers or your reporting.
What is a permissioned blockchain?
NIST describes permissioned blockchain networks as ones that limit participation to specific people or organizations and allow finer-grained controls, unlike permissionless networks where anyone can read and write. Hyperledger Fabric is an example: its participants are known to each other, confidentiality comes from channels and private data, and no native cryptocurrency is needed.
Will Apple or Google reject a crypto wallet app?
Not if it follows their rules. Apple’s guideline 3.1.5 allows wallet apps from developers enrolled as an organization, bars mining on the device, limits exchange features to regions where the app is licensed, and reserves ICOs and crypto futures trading for established financial institutions. Google Play requires apps involving tokenized digital assets to declare it and not promote potential earnings.
What extra risks come with DeFi app development?
DeFi concentrates the risks on OWASP’s smart contract list: price oracle manipulation, flash loan attacks, reentrancy and access-control flaws. It also raises money-transmission and sanctions questions for whoever operates the front end or controls the contracts. We plan conservative launch caps, independent audits, monitoring and a tested pause mechanism, and map the regulatory questions with counsel first.
What does tokenizing a real-world asset involve?
Legal structuring first, then software: a token contract on a permissioned standard such as ERC-3643, which checks investor identity and compliance rules on every transfer, plus issuance, ownership records, investor onboarding and reporting. The SEC’s March 2026 taxonomy treats tokenized securities as securities, so the securities-law work matches that of the underlying asset.
Do you build for enterprises that are not crypto companies?
Yes. Enterprise blockchain work often has no public token at all: permissioned ledgers shared by suppliers, customers or partners, document anchoring for audit trails, and settlement between companies, integrated with ERP, identity and document systems. We also tell enterprises when a shared database or an API between partners would do the job better.
What do you need from us to scope a blockchain project?
A description of the parties involved and what they must share, where value moves and who controls it, any token you plan to issue, the jurisdictions and users you will serve, the systems the chain must connect to, and your counsel’s early view on the regulatory questions. With that we can recommend a network and custody model and send a written scope.
Can smart contracts read data from our existing systems?
Not directly: ethereum.org notes that smart contracts cannot retrieve off-chain data on their own. Data reaches contracts through oracles, which carry their own trust and availability risks, or through transactions your backend submits, and data leaving the chain goes through an indexer and API. We design both directions so your ERP or CRM stays the system of record.
Is the GENIUS Act already in force?
The Act was approved on July 18, 2025 and takes effect on the earlier of 18 months after enactment or 120 days after the primary federal payment stablecoin regulators issue final implementing regulations. Some provisions run on longer clocks, such as the three-year point after which digital asset service providers may not offer non-permitted payment stablecoins to people in the United States. Check the current rulemaking status before launch.

Scoping a blockchain product?Tell us what must be shared, who the parties are and where value moves; we reply with a network recommendation, a contract outline and the rules that apply.

Get a blockchain scope

Get a free marketing proposal

Tell us what you are trying to grow and we will come back with a plan, not a pitch deck. Same-day reply on weekdays.

Privacy Preferences
When you visit our website, it may store information through your browser from specific services, usually in form of cookies. Here you can change your privacy preferences. Please note that blocking some types of cookies may impact your experience on our website and the services we offer.
Contact Us