Our founder and CEO on how the industry has changed, why most traders today gamble instead of trade, how our safety desk works - something almost no firm has - and how we withstood a coordinated cyberattack this week that went straight for our data.
Michal Król needs little introduction in the trading community. Over the years he has moved from active trader, through publicly verified results, to building Dolvero - a prop firm that positions itself as the opposite of what most of the industry does. We sat down with him the day after an incident that would have floored many a company, and talked about where prop trading has ended up, why so many firms fail, and what Dolvero does differently.
You have been in prop trading for years. How has the industry changed?
Fundamentally, and unfortunately not entirely for the better. When I started, a prop firm was a partner. It gave you capital, clear rules, and expected you to trade consistently, because it lived off your consistency. Today, a large part of the industry has turned into a vending machine for challenge-fee revenue.
More and more often I see that people have stopped trading and started gambling. A trader buys several challenges at once, tries to pass them in a single day, throws maximum risk at it, and if they happen to pass, the moment they are funded they go for the biggest possible profit. No plan, no risk management, no consistency. It is a roll of the dice. And that approach doesn't just hurt the trader, it hurts the whole industry.
Why does it hurt the whole industry?
Because a lot of prop firms go under because of it. And here I get to something people rarely talk about. A prop firm that is serious does not live off traders failing. It lives off being able to replicate their results - mirroring their trades with real capital in the market. But when your accounts are full of gamblers who make 40 percent one day and blow up the next, you have nothing to replicate. Not a single consistent curve you could put real capital behind.
So firms fall into a trap. They collect challenge fees, pay random winners out of those fees, and hope it works out. That is not a business model, that is Ponzi logic. And that is exactly why so many of them collapse. We replicate, and that is why consistency isn't a nice marketing word for us, it is an existential necessity.
And don't get me wrong, challenge fees are not a bad thing in themselves. They are an integral part of how any prop firm operates. They cover evaluation, technology and risk, and the industry couldn't function without them. The problem isn't that they exist. The problem begins when they become the main, or even the only, source of revenue. At that point a firm stops earning when its traders succeed and starts earning when they fail. And that conflict of interest sooner or later brings down the firm and its client alike.
So how do you support consistency among traders?
In several ways, but the strongest is a path most prop firms cannot offer, simply because they don't have it. We have our own algorithmic firm, Divitae Assets, which manages real capital and licenses its systems to institutional clients and funds. And for our best traders, Dolvero is the gateway to exactly that.
When a trader holds consistency, manages risk and month after month shows a real curve, the institutional path with Divitae opens up to them. That is something entirely different from a challenge split. It is working with real capital, real responsibility and completely different numbers. And it is remarkable to see how many traders this vision attracts. Those people don't want to gamble, they want to be professionals. And the results we have because of it speak for themselves.
Just to give you an idea. Through our public, verifiable payout ledger we have paid traders over 249 thousand dollars across 136 verified payouts. Every single payout has its own unique verification code that anyone can check. We hide nothing, because we have nothing to hide. And the speed isn't a marketing phrase. While a large part of the industry pays out in three to five days, and at some firms you wait weeks, our average is 2.2 hours. Not days. Hours. And we hold our 24-hour commitment 100 percent of the time. No firm that lives off traders losing could afford to publish that.
"While much of the industry pays out in days or weeks, our average is 2.2 hours. That is roughly 43x faster than the market average."
And what does that consistency do to an account? The institutional path in numbers
The best way to explain why consistency pays off for us is to show what happens to a trader who really holds it. With us, a funded account doesn't stop at one size. For every three consecutive profitable months, we move the trader up a size, from 100k through 125, 150 and 200 all the way to 250 thousand dollars. In practice that means a hundred-thousand-dollar account scales to 250,000 dollars within a single year, without the trader paying a single dollar more.
And for the very best, the doors to Divitae Assets, our algorithmic firm, open up. It manages 12.4 million dollars today, its assets under management grew 12.8 percent in this year alone, and it has a documented track record going back to 2022. This is not a hypothetical vision for a brochure. This is real capital and real numbers a trader can genuinely work their way up to.
You mentioned a safety desk. What is it? I haven't seen that at other prop firms.
And that is exactly why we introduced it. As far as I know, we are pretty much the only prop firm that has something like it. The safety desk is a team that actively monitors trader behavior on accounts. Not to catch them breaking a rule, but to protect them from themselves.
When our system detects that a trader is taking excessive risk, burning challenge after challenge, or that their behavior is starting to show signs of gambling, a dedicated specialist reaches out. Not a salesperson, not a script. A person who sits down with the trader, goes through their trading, points out the risk they are running into, and openly discusses whether they might be sliding into gambling. And if needed, we also offer specialized help.
I know how it sounds. A prop firm telling a trader "hey, slow down, this isn't healthy." But that is exactly the difference between a fee vending machine and a partner. We make money on a trader when they are good over the long term, not when they blow up fast. So it is only logical that we want them to last. Yes, it is above standard. But we don't want to be a standard prop firm. We want to be the one that moves the industry forward.
You bet heavily on your own technology. Why?
Because whoever doesn't have their own solution is dependent on outside firms, and that comes back to bite you sooner or later. We have practically the entire stack in-house. Besides Divitae Assets we also run TTerminal, our own institutional trading terminal. It is a tool you would normally only find behind the paywall of expensive professional terminals - order flow, a conviction score across hundreds of instruments, geopolitical risk analysis, verified mentors who publish every entry, stop and target live inside the terminal. Just so it is clear what tool we are talking about: TTerminal re-scores 765 instruments every ten minutes, pulls news from more than fifty sources and evaluates its impact, and offers over 250 professional tools. This is the kind of kit the market charges around 24,000 dollars a year for. Our funded traders get it for free.
Let's get into it. This week you were hit by a cyberattack. What happened?
On the seventeenth of July at two in the morning, a coordinated, multi-vector cyberattack began against our infrastructure. It wasn't a single attempt, it was an entire campaign. Over fourteen hours the attacker sent us more than 55 thousand malicious requests and cycled through practically the whole arsenal - SQL injection and XSS attempts, credential stuffing against login and reset endpoints, tampering with order parameters, attempts to forge payment webhooks, brute-force against the admin interface, and systematic enumeration of our APIs. This was not the random scan that flies across the internet every day. This was a targeted attack run by someone who knew exactly what they were looking for.
And how did they hide?
Professionally, credit where it's due. They hid behind a two-layer anonymization, a combination of a commercial VPN and a residential proxy network, which let them rotate roughly 250 IP addresses and geographically shape-shift so it looked like they were coming from dozens of different countries at once. They ran the traffic through custom-scripted automated tools just to generate that volume. On paper, they were invisible.
Did you know right away that something was happening?
From the first second. The whole team was on alert from the start and we monitored the attack in real time through our own systems. And this is exactly where the vertical integration we talked about paid off. Because our entire stack runs in-house, we saw every move, every request, every vector. We didn't have to wait for some external security firm to wake up in the morning and look at the logs. Our defenses also responded automatically - server-side validation instantly killed the price-tampering attempts, rate-limiting and our application firewall filtered out the brute force, and our fingerprint-based auto-ban started blocking his automated tools right at the server level, based on a signature he was unknowingly carrying with him.
You also deployed a honeypot. How did that work?
We decided not to stop at defense. That would be like locking the door and hoping. We turned the hunter into the prey. We set a honeypot on the attacker, a controlled environment that looked like a real target. We laid out exactly what he was after - fake admin passwords, and even a fake payout script where all you had to do was enter a crypto address and an amount. It was all honeytokens, decoys that trigger a silent alarm the moment he reaches for them.
And he took the bait. He opened the payout script and left again - it was a dead end, there was no real money behind it. The core of his effort was getting into the admin panel with those fake passwords. And that is exactly where he made his fatal mistake. He ran the vast majority of the attack through curl, an automated tool with no browser. But the moment he tried to push those fake passwords into the admin login, he opened a real browser. And that is precisely how we got him. Big thanks for that go to Dominika on our team, who set the whole trap.
And how exactly did the browser give him away?
A browser gives away far more about you than a bare command-line tool, and that is exactly what proved fatal for him. An automated attack over curl is essentially anonymous; it leaves almost no trace. But the moment he opened a real browser, he started dragging behind him an entire layer of identifying fingerprints that most people don’t even know exist.
We ran multi-layer fingerprinting on him. At the browser level we captured the canvas fingerprint, the graphics-card signature via WebGL, screen resolution and color depth, the number of CPU cores, the set of installed fonts, and the timezone and language preferences in the Accept-Language header. At the network level we took a JA3 and JA4 TLS fingerprint, the exact order of offered ciphers and extensions during the handshake, plus the so-called JA4H, a fingerprint of the order and composition of the HTTP headers. Each of those traces is common on its own. But their combination forms a fingerprint with such high entropy that it is practically unique, like a digital fingerprint.
And this is where his anonymity began to collapse. No matter how he rotated those 250 IP addresses, the combined fingerprint stayed identical, so we reliably tied all 250 addresses to a single actor. On top of that, two things didn’t add up. His browser reported the Europe/Prague timezone and a language set to Czech, while his IP addresses claimed he was sitting on the other side of the world. That is a classic configuration slip, where the attacker guards the IP but forgets the local settings of his own device.
He dealt himself the final blow. His browser had WebRTC enabled, and during connection setup, through the so-called STUN, it leaked his real, local IP address, the one assigned by his own internet provider, entirely outside the VPN. The anonymization layer cracked. And what spilled out of it made it clear: the attacker was not sitting in some remote server room on the other side of the world. He was sitting in the Czech Republic, in Prague to be precise.
What happened next?
Full forensic processing. We preserved all the evidence, sealed each piece with a cryptographic hash to maintain the integrity of the chain of custody, and immediately handed the whole matter to law enforcement. I can't say more about the ongoing proceedings right now.
Do you have a suspicion of who is behind it?
We do, and it follows directly from what the attacker was after. And this may be the most interesting part of the whole case. Because he was not going after our traders’ money at all; he never even got close to their accounts. He was not there to steal. He was there for information. And not just any information, it was very specific, surgically selected data.
He wanted four things. First, how much we actually hold in accounts, the volume of capital flowing through the firm. Second, how much we have paid out in total, which is a direct measure of how much we really pay and how fast we are growing. Third, the real success rate of our traders, the core of our entire business model and the most valuable know-how we have. And fourth, which countries most of our clients come from, which is effectively an exact map of where we are strong and where to aim.
Think about that for a second. This is not data an ordinary hacker or someone looking for a quick score goes after. Transactions, passwords, card numbers, none of that interested him. He wanted business intelligence. He wanted our business plan, read straight from the numbers. And that is exactly what only one type of person in the world wants to know: a competitor. Someone who operates in the same industry and needs to find out how big we really are, how much we make, how good our traders are, and where they can attack us. That is why we have reasonable grounds to suspect a competing prop firm is behind the attack. We will keep the names for law enforcement until the investigation is over, but the trail is fairly clear.
And the almost amusing part is that the whole thing makes no logical sense to us. If he really wanted that data, all he had to do was ask. We would have told him. Transparency is one of Dolvero’s main pillars: our payouts are publicly verifiable and our rules are open. Breaking into a system for something we would gladly have shared is perhaps the best testament to how that kind of competition thinks.
How did it all end?
Exactly as a professionally managed defense should. The attacker broke through nothing. Not a single byte of sensitive data. Zero. Not the account balances, not the payouts, not the trader data, nothing. For fourteen hours he hammered our systems with everything he had, burned who knows how many resources across 250 IP addresses, and left completely empty-handed. We, on the other hand, left with his real identity, his fingerprint and a complete trail for the police.
And to be completely precise, it did not end that day. The attack continued the following day, this time from different infrastructure, a foreign server. But the result was exactly the same. Again, he got nowhere.
And I want to say this clearly and without any hedging. We have not recorded a single security incident in which any data leaked or anyone gained unauthorized access to any of our systems. Not one. Our traders’ data, their funds and our internal systems remained completely untouched the entire time.
For me it was, paradoxically, one of the best proofs of how elite a team we have and how professional a prop firm Dolvero is. It is not about never being attacked. You will be, sooner or later it comes for everyone. It is about how prepared you are when the moment arrives. And we were prepared down to the last detail. It also just confirmed how crucial it is to own everything and not rely on outside firms. If our infrastructure ran on third-party solutions, this attack would have ended very differently.
What's next? What is Dolvero's vision for the future?
The vision is simple but ambitious. We want to be the prop firm that sets a new standard for the industry. Not the cheapest, not the loudest, but the most honest and the most professional.
Specifically, we want to keep expanding the institutional path with Divitae Assets, so that Dolvero becomes a real springboard from a funded account to working with institutional capital. We want to keep developing TTerminal, because we believe a trader with better tools makes better decisions. And we want to expand the safety desk, because looking after the trader is a competitive advantage for us, not a cost.
It all rests on one idea. Over the years, prop trading drifted toward gambling and quick fee revenue. We are going the other way. Back to consistency, to partnership, and to both sides profiting from a trader's success. This week someone spent two days straight proving to us that we are big enough for the competition to mind. And they did it chasing numbers we would happily have told them ourselves. I take that as a compliment.
Risk warning: Trading financial markets, including currencies, CFDs, futures and crypto assets, carries a high level of risk and may not be suitable for everyone. Leverage magnifies both gains and losses. Analytical tools, conviction scores and mentor signals are informational aids, not trade recommendations. Past results are no guarantee of future performance. Never trade with funds you cannot afford to lose.




