GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar
CertiK

CertiK

Active

Blockchain security company

News Heat Trend

Project Overview

CertiK, a blockchain security company founded in 2018, utilizes formal verification and AI technology in collaboration for its end-to-end blockchain security audit services. It mathematically validates the safety of smart contracts through a combination of formal and manual verification. Additionally, the company has developed "CertiK Chain", a security-focused blockchain designed to enhance the security of smart contracts.

CertiK Report: Brazil's Crypto Market Enters Full Regulatory Phase, Independent Proof Becomes Key to Market Access

Odaily News, August 11 - Web3 security firm CertiK has released its report "Intel3D: PSAV and Brazil's New Security Standards." The report notes that as the deadline for authorization applications set by the Central Bank of Brazil (October 30 this year) approaches, local Virtual Asset Service Providers (PSAVs) are facing a wave of concentrated compliance adjustments. Independent third-party compliance and security certifications are also transitioning from industry best practices to critical requirements for market access. According to the report, CertiK has already begun conducting independent external audits in accordance with Central Bank of Brazil Normative Instruction No. 701.As one of the markets with the highest crypto adoption rates globally, the impact of Brazil's regulatory transformation may extend far beyond its domestic market. The report shows that Brazil currently ranks fifth globally in actual crypto adoption rates. Between June 2024 and June 2025, Brazil received $318.8 billion in on-chain asset value, accounting for nearly one-third of South America's on-chain activity during the same period. Stablecoins have become a critical infrastructure in the local digital asset market, representing approximately 80% of the trading volume in crypto asset transactions reported to Brazil's Federal Revenue Service.

CertiK Report: Wrench Attacks Surge Nearly 12x in Losses, “Operational Security” Becomes New Core of Prevention

Odaily Odaily News, July 22nd - Web3 security firm CertiK released its "H1 2026 Wrench Attack Report." The report indicates that a total of 52 publicly verified wrench attacks were recorded globally in the first half of 2026, a year-over-year increase of 33.3%; related losses amounted to approximately $124 million, an increase of about 11.8 times compared to the same period last year.The report notes that attackers are shifting from exploiting technical vulnerabilities to targeting asset holders and their real-world social networks. Home invasion incidents increased from 1 case in H1 2025 to 20 cases, accounting for 41% of the total incidents in the period. Europe has become a high-incidence area for attacks, with 33 cases occurring in France alone, representing 63.5% of the global total.CertiK stated that as real-world risks become a significant challenge for digital asset security, enterprises and high-net-worth individuals need to establish more comprehensive protection systems. CertiK has launched operational security services to help identify exposure risks related to identity, family, residence, and travel routes. Simultaneously, through the CertiK Security Workspace, it correlates off-chain intelligence, on-chain transactions, and AML risk signals to support institutions in tracking and analyzing cybercrime activities. Furthermore, CertiK is strengthening cooperation with international law enforcement agencies such as Interpol and Europol, providing technical support for cross-border attack investigations and security policy research.

CLARITY Act could remove Section 604 or expose non-custodial developers to Bank Secrecy Act obligations

one year after the U.S. House of Representatives passed the Clarity for Digital Assets Act (CLARITY Act), the bill remains stalled in the Senate, facing opposition from the banking industry and partisan divisions. Supporters anticipate a potential vote before the Senate's August recess. Industry organizations Coin Center and the Blockchain Association have identified Section 604 as a key provision for protecting open-source innovation. This provision aims to prevent non-custodial blockchain developers, node operators, and validators from being classified as federal money transmitters. Stefan Muehlbauer, Head of U.S. Government Affairs at CertiK, stated that removing Section 604 could conflate software development with financial services, subjecting developers to the Bank Secrecy Act and triggering First Amendment-related constitutional challenges. Iana Dimitrova, CEO of Openpayd, noted that the expanding use of stablecoins for cross-border value transfer has made the need for a federal regulatory framework more apparent. The bill also addresses accounting standards, acknowledges the rescission of SEC Staff Accounting Bulletin SAB 121, and prohibits the SEC from reimposing equivalent crypto custody accounting requirements without a full notice-and-comment rulemaking process. Mark Zalan, CEO of Gomining, pointed out that Bitcoin still faces regulatory gaps, such as tax treatment.

CertiK: Wasabi Protocol Hacked, Approximately $2.9 Million Stolen

According to blockchain security firm CertiK (@CertiKAlert), Wasabi Protocol (@wasabi_protocol) has suffered a security breach, with approximately $2.9 million stolen so far. Preliminary investigations indicate that the attacker gained privileged access after compromising a wallet deployed by Wasabi, enabling the attack. The stolen funds are currently distributed across the following addresses: 0xb8Bb...70dB (approximately $677,000) and 0x6244...f906 (approximately $1.1 million). The incident remains under active investigation.

Syndicate Loses ~$330,000 Due to Attack on Commons Cross-Chain Bridge

According to CertiK, Syndicate Protocol suffered an exploit due to a security breach in the Commons cross-chain bridge. The attacker exploited the vulnerability to acquire approximately 18.5 million SYND tokens, which were subsequently sold for roughly $330,000. The related funds have already been transferred to the Ethereum network via the cross-chain bridge. Syndicate’s official response states that it is investigating the security incident involving the Commons bridge. The team is tracking the attack and collaborating with security firms. It is also evaluating various options to compensate affected users. Syndicate holds sufficient token reserves to assist users who lost SYND.

CertiK Releases 2026 Global Digital Asset Regulation Report: AML Enforcement Intensifies, Smart Contract Audits Become Access Condition

Odaily News, Web3 security company CertiK has released its "2026 State of Digital Asset Regulation" report, systematically reviewing global regulatory trends. The report indicates that as of April 2026, regulatory frameworks in major jurisdictions such as the United States, the European Union, Hong Kong SAR, and Singapore have been largely established, and the industry is entering a phase of comprehensive compliance.The report shows that anti-money laundering (AML) enforcement has replaced securities classification as the primary regulatory risk. In the first half of 2025, global AML-related fines exceeded $900 million, making transaction monitoring capabilities a core compliance requirement. Meanwhile, smart contract security audits are evolving from industry best practices into access conditions, becoming a prerequisite for license approval and token listings. Additionally, global stablecoin regulatory frameworks are converging, with principles such as full reserve backing and licensed issuance becoming widespread, though cross-jurisdictional regulatory differences still pose compliance challenges.The report states that with regulatory convergence and strengthened enforcement, the industry has entered an "era of strong compliance." CertiK indicated that the core challenge for enterprises is shifting from "whether to comply" to "how to quickly build and implement compliance capabilities." Multi-jurisdictional licensing, AML investment, and continuous security audits are becoming fundamental entry requirements for institutional development.

CertiK:与 Coldcard Wallet 攻击相关资金经 THORChain 跨链后转入 Tornado Cash

CertiK 表示,其监测系统发现两笔各 200 ETH 的交易转入 Tornado Cash,相关资金与正在进行的 Coldcard Wallet 攻击事件有关。上述资金此前通过 THORChain 由 BTC 跨链转入以太坊地址,随后再被转入 Tornado Cash。

VerusCoin Ethereum Cross-Chain Bridge Attacked, Approximately $7.53 Million Transferred Out

According to CertiK Alert monitoring, a security incident occurred on VerusCoin's Ethereum cross-chain bridge, with approximately $7.53 million in assets transferred out. Preliminary analysis indicates that this issue may be related to the cross-chain bridge failing to sufficiently verify whether the Verus chain-side input supports the paid amount, similar to an incident that occurred in May this year.

CodexField's X account and website taken offline, previously accused of fraud

according to CertiK's monitoring, CodexField's X account and website have been taken offline. Earlier, on-chain analyst Specter had warned that the project might be a scam and exit scam, and tracked abnormal cross-chain fund transfers totaling over 17.3 million USDT.

Gravity Bridge attacker deposits 1,180 ETH into Tornado Cash again

According to on-chain security firm CertiK (@CertiKAlert), the Gravity Bridge attacker recently deposited another 1,180 ETH (approximately $2.06 million) into Tornado Cash. Earlier, on May 30, the attacker exploited the permissionless deployERC20() function by forging the Osmosis token string, tampering with the token registry, and mapping fake balances to real custodial assets—thereby stealing approximately 2,600 ETH (around $5.4 million) from Gravity Bridge. To date, 2,020 ETH of the stolen funds have been transferred to Tornado Cash via two externally owned accounts (EOAs); the remainder has been dispersed across centralized exchanges, making fund recovery significantly challenging.

France charges 88 suspects in crypto "wrench attack" cases, including over a dozen minors

the French National Organized Crime Prosecutor's Office (PNACO) issued a statement on Friday stating that France has launched judicial investigations into 12 cryptocurrency kidnapping cases orchestrated by organized crime groups, and has indicted 88 suspects, including more than 10 minors.According to statistics, since 2023, France has recorded 135 cryptocurrency-related attacks, including 18 in 2024, 67 in 2025, and 47 so far in 2026. The accused individuals face charges including kidnapping, illegal detention, extortion, and money laundering. Recently, police arrested six suspects in two operations targeting kidnapping cases, and all individuals are currently in preventive detention. CertiK blockchain intelligence analyst Jonathan Riss stated that the masterminds behind such criminal gangs are typically located outside the European Union.

Hyperbridge Gateway Contract Attacked; 1 Billion DOT Tokens Minted and Dumped on Ethereum

According to PeckShieldAlert monitoring, approximately 1 billion Polkadot (DOT) tokens have been minted and dumped on the Ethereum network. Details of the incident are still under further verification. According to CertiK monitoring, the Hyperbridge gateway contract was attacked; the attacker forged messages to tamper with the admin privileges of the Polkadot token contract on Ethereum, and profited approximately $237,000 by minting and selling 1 billion tokens.

Brazil's $318.8 Billion Crypto Market Faces Licensing Deadline: Service Providers Must Apply by October 30, 2026

Odaily News: Brazil's crypto market has recorded $318.8 billion in on-chain transaction value over the past 12 months, ranking fifth globally in cryptocurrency adoption, with nearly one-third of Latin America's related activity conducted through Brazilian wallets and platforms. Blockchain security firm CertiK stated that virtual asset service providers must submit authorization applications to the Central Bank of Brazil (BCB) by October 30, 2026, accompanied by independent audit reports. On November 10, 2025, the Central Bank of Brazil issued three resolutions clarifying the licensing scope, minimum capital requirements, and foreign exchange rules for virtual asset service providers. Minimum capital requirements for different license categories range from approximately R$10.8 million to R$37.2 million. Among the current approximately 120 service providers, most have not yet obtained formal licenses, and overseas operators must relocate their operations to Brazil within 270 days. Approximately 80% of Brazil's declared cryptocurrency transaction volume is settled via dollar-pegged tokens, with USDT accounting for 88.7% of that share. Total stablecoin transaction volume from 2019 to 2025 reached R$1.13 trillion. CertiK statistics show that the crypto industry suffered losses of $1.32 billion due to hacker attacks and exploit incidents in the first half of 2026, involving 344 events. (Decrypt)

CertiK:与 Coldcard Wallet 攻击相关资金经 THORChain 跨链后转入 Tornado Cash

CertiK 表示,其监测系统发现两笔各 200 ETH 的交易转入 Tornado Cash,相关资金与正在进行的 Coldcard Wallet 攻击事件有关。上述资金此前通过 THORChain 由 BTC 跨链转入以太坊地址,随后再被转入 Tornado Cash。

VerusCoin Ethereum Cross-Chain Bridge Attacked, Approximately $7.53 Million Transferred Out

According to CertiK Alert monitoring, a security incident occurred on VerusCoin's Ethereum cross-chain bridge, with approximately $7.53 million in assets transferred out. Preliminary analysis indicates that this issue may be related to the cross-chain bridge failing to sufficiently verify whether the Verus chain-side input supports the paid amount, similar to an incident that occurred in May this year.

CertiK:2026 年上半年针对数字资产持有者的扳手攻击共记录 52 起,同比增长 33%

据彭博社报道,区块链安全公司 CertiK 最新报告显示,2026 年上半年全球针对数字资产持有者的暴力"扳手攻击"(即以人身威胁强迫受害者交出加密货币)事件共记录 52 起,同比增长 33%。其中法国以 33 起攻击案例独占近三分之二,成为全球最严重的受害国。报告指出,加密犯罪分子的攻击目标正从数字钱包转向现实中的持币个人,暴力手段日趋普遍。

CertiK Report: Wrench Attacks Surge Nearly 12x in Losses, “Operational Security” Becomes New Core of Prevention

Odaily Odaily News, July 22nd - Web3 security firm CertiK released its "H1 2026 Wrench Attack Report." The report indicates that a total of 52 publicly verified wrench attacks were recorded globally in the first half of 2026, a year-over-year increase of 33.3%; related losses amounted to approximately $124 million, an increase of about 11.8 times compared to the same period last year.The report notes that attackers are shifting from exploiting technical vulnerabilities to targeting asset holders and their real-world social networks. Home invasion incidents increased from 1 case in H1 2025 to 20 cases, accounting for 41% of the total incidents in the period. Europe has become a high-incidence area for attacks, with 33 cases occurring in France alone, representing 63.5% of the global total.CertiK stated that as real-world risks become a significant challenge for digital asset security, enterprises and high-net-worth individuals need to establish more comprehensive protection systems. CertiK has launched operational security services to help identify exposure risks related to identity, family, residence, and travel routes. Simultaneously, through the CertiK Security Workspace, it correlates off-chain intelligence, on-chain transactions, and AML risk signals to support institutions in tracking and analyzing cybercrime activities. Furthermore, CertiK is strengthening cooperation with international law enforcement agencies such as Interpol and Europol, providing technical support for cross-border attack investigations and security policy research.

DeFiTuna Suffers Attack, Losing 569,600 USDC

CertiK published an analysis stating that the Solana ecosystem protocol DeFiTuna was attacked on July 16, with losses of approximately 569,601 USDC. The attacker first created an extremely low-liquidity TUNA/USDC pool and swapped borrowed USDC into the pool via Jupiter routing. Since only a minimal amount of TUNA was ultimately obtained, the protocol experienced rounding down during the position asset value calculation, causing the total assets to be recorded as 0, thereby incorrectly passing the health and solvency checks.

CertiK Report: Brazil's Crypto Market Enters Full Regulatory Phase, Independent Proof Becomes Key to Market Access

Odaily News, August 11 - Web3 security firm CertiK has released its report "Intel3D: PSAV and Brazil's New Security Standards." The report notes that as the deadline for authorization applications set by the Central Bank of Brazil (October 30 this year) approaches, local Virtual Asset Service Providers (PSAVs) are facing a wave of concentrated compliance adjustments. Independent third-party compliance and security certifications are also transitioning from industry best practices to critical requirements for market access. According to the report, CertiK has already begun conducting independent external audits in accordance with Central Bank of Brazil Normative Instruction No. 701.As one of the markets with the highest crypto adoption rates globally, the impact of Brazil's regulatory transformation may extend far beyond its domestic market. The report shows that Brazil currently ranks fifth globally in actual crypto adoption rates. Between June 2024 and June 2025, Brazil received $318.8 billion in on-chain asset value, accounting for nearly one-third of South America's on-chain activity during the same period. Stablecoins have become a critical infrastructure in the local digital asset market, representing approximately 80% of the trading volume in crypto asset transactions reported to Brazil's Federal Revenue Service.

Brazil's $318.8 Billion Crypto Market Faces Licensing Deadline: Service Providers Must Apply by October 30, 2026

Odaily News: Brazil's crypto market has recorded $318.8 billion in on-chain transaction value over the past 12 months, ranking fifth globally in cryptocurrency adoption, with nearly one-third of Latin America's related activity conducted through Brazilian wallets and platforms. Blockchain security firm CertiK stated that virtual asset service providers must submit authorization applications to the Central Bank of Brazil (BCB) by October 30, 2026, accompanied by independent audit reports. On November 10, 2025, the Central Bank of Brazil issued three resolutions clarifying the licensing scope, minimum capital requirements, and foreign exchange rules for virtual asset service providers. Minimum capital requirements for different license categories range from approximately R$10.8 million to R$37.2 million. Among the current approximately 120 service providers, most have not yet obtained formal licenses, and overseas operators must relocate their operations to Brazil within 270 days. Approximately 80% of Brazil's declared cryptocurrency transaction volume is settled via dollar-pegged tokens, with USDT accounting for 88.7% of that share. Total stablecoin transaction volume from 2019 to 2025 reached R$1.13 trillion. CertiK statistics show that the crypto industry suffered losses of $1.32 billion due to hacker attacks and exploit incidents in the first half of 2026, involving 344 events. (Decrypt)

VerusCoin Ethereum Cross-Chain Bridge Attacked, Approximately $7.53 Million Transferred Out

According to CertiK Alert monitoring, a security incident occurred on VerusCoin's Ethereum cross-chain bridge, with approximately $7.53 million in assets transferred out. Preliminary analysis indicates that this issue may be related to the cross-chain bridge failing to sufficiently verify whether the Verus chain-side input supports the paid amount, similar to an incident that occurred in May this year.

CertiK Report: Wrench Attacks Surge Nearly 12x in Losses, “Operational Security” Becomes New Core of Prevention

Odaily Odaily News, July 22nd - Web3 security firm CertiK released its "H1 2026 Wrench Attack Report." The report indicates that a total of 52 publicly verified wrench attacks were recorded globally in the first half of 2026, a year-over-year increase of 33.3%; related losses amounted to approximately $124 million, an increase of about 11.8 times compared to the same period last year.The report notes that attackers are shifting from exploiting technical vulnerabilities to targeting asset holders and their real-world social networks. Home invasion incidents increased from 1 case in H1 2025 to 20 cases, accounting for 41% of the total incidents in the period. Europe has become a high-incidence area for attacks, with 33 cases occurring in France alone, representing 63.5% of the global total.CertiK stated that as real-world risks become a significant challenge for digital asset security, enterprises and high-net-worth individuals need to establish more comprehensive protection systems. CertiK has launched operational security services to help identify exposure risks related to identity, family, residence, and travel routes. Simultaneously, through the CertiK Security Workspace, it correlates off-chain intelligence, on-chain transactions, and AML risk signals to support institutions in tracking and analyzing cybercrime activities. Furthermore, CertiK is strengthening cooperation with international law enforcement agencies such as Interpol and Europol, providing technical support for cross-border attack investigations and security policy research.

CLARITY Act could remove Section 604 or expose non-custodial developers to Bank Secrecy Act obligations

one year after the U.S. House of Representatives passed the Clarity for Digital Assets Act (CLARITY Act), the bill remains stalled in the Senate, facing opposition from the banking industry and partisan divisions. Supporters anticipate a potential vote before the Senate's August recess. Industry organizations Coin Center and the Blockchain Association have identified Section 604 as a key provision for protecting open-source innovation. This provision aims to prevent non-custodial blockchain developers, node operators, and validators from being classified as federal money transmitters. Stefan Muehlbauer, Head of U.S. Government Affairs at CertiK, stated that removing Section 604 could conflate software development with financial services, subjecting developers to the Bank Secrecy Act and triggering First Amendment-related constitutional challenges. Iana Dimitrova, CEO of Openpayd, noted that the expanding use of stablecoins for cross-border value transfer has made the need for a federal regulatory framework more apparent. The bill also addresses accounting standards, acknowledges the rescission of SEC Staff Accounting Bulletin SAB 121, and prohibits the SEC from reimposing equivalent crypto custody accounting requirements without a full notice-and-comment rulemaking process. Mark Zalan, CEO of Gomining, pointed out that Bitcoin still faces regulatory gaps, such as tax treatment.

DeFiTuna Suffers Attack, Losing 569,600 USDC

CertiK published an analysis stating that the Solana ecosystem protocol DeFiTuna was attacked on July 16, with losses of approximately 569,601 USDC. The attacker first created an extremely low-liquidity TUNA/USDC pool and swapped borrowed USDC into the pool via Jupiter routing. Since only a minimal amount of TUNA was ultimately obtained, the protocol experienced rounding down during the position asset value calculation, causing the total assets to be recorded as 0, thereby incorrectly passing the health and solvency checks.

Related news

CertiK Report: Brazil's Crypto Market Enters Full Regulatory Phase, Independent Proof Becomes Key to Market Access

Odaily News, August 11 - Web3 security firm CertiK has released its report "Intel3D: PSAV and Brazil's New Security Standards." The report notes that as the deadline for authorization applications set by the Central Bank of Brazil (October 30 this year) approaches, local Virtual Asset Service Providers (PSAVs) are facing a wave of concentrated compliance adjustments. Independent third-party compliance and security certifications are also transitioning from industry best practices to critical requirements for market access. According to the report, CertiK has already begun conducting independent external audits in accordance with Central Bank of Brazil Normative Instruction No. 701.As one of the markets with the highest crypto adoption rates globally, the impact of Brazil's regulatory transformation may extend far beyond its domestic market. The report shows that Brazil currently ranks fifth globally in actual crypto adoption rates. Between June 2024 and June 2025, Brazil received $318.8 billion in on-chain asset value, accounting for nearly one-third of South America's on-chain activity during the same period. Stablecoins have become a critical infrastructure in the local digital asset market, representing approximately 80% of the trading volume in crypto asset transactions reported to Brazil's Federal Revenue Service.

Brazil's $318.8 Billion Crypto Market Faces Licensing Deadline: Service Providers Must Apply by October 30, 2026

Odaily News: Brazil's crypto market has recorded $318.8 billion in on-chain transaction value over the past 12 months, ranking fifth globally in cryptocurrency adoption, with nearly one-third of Latin America's related activity conducted through Brazilian wallets and platforms. Blockchain security firm CertiK stated that virtual asset service providers must submit authorization applications to the Central Bank of Brazil (BCB) by October 30, 2026, accompanied by independent audit reports. On November 10, 2025, the Central Bank of Brazil issued three resolutions clarifying the licensing scope, minimum capital requirements, and foreign exchange rules for virtual asset service providers. Minimum capital requirements for different license categories range from approximately R$10.8 million to R$37.2 million. Among the current approximately 120 service providers, most have not yet obtained formal licenses, and overseas operators must relocate their operations to Brazil within 270 days. Approximately 80% of Brazil's declared cryptocurrency transaction volume is settled via dollar-pegged tokens, with USDT accounting for 88.7% of that share. Total stablecoin transaction volume from 2019 to 2025 reached R$1.13 trillion. CertiK statistics show that the crypto industry suffered losses of $1.32 billion due to hacker attacks and exploit incidents in the first half of 2026, involving 344 events. (Decrypt)

CertiK:与 Coldcard Wallet 攻击相关资金经 THORChain 跨链后转入 Tornado Cash

CertiK 表示,其监测系统发现两笔各 200 ETH 的交易转入 Tornado Cash,相关资金与正在进行的 Coldcard Wallet 攻击事件有关。上述资金此前通过 THORChain 由 BTC 跨链转入以太坊地址,随后再被转入 Tornado Cash。

USDD supply on TRON increases by $145 million in a single week, total supply surpasses $1.23 billion

According to data from CertiK Skynet, over the past week, the USDD supply on the TRON network increased significantly by approximately $145 million, with the total volume surpassing $1.23 billion, accounting for about 81.6% of the total USDD supply across the network. As of now, USDD's total network supply is $1.55 billion, and TVL exceeds $2.33 billion. Recently, with TRON DeFi Summer in full swing, liquidity in the TRON ecosystem has shown an explosive trend. Notably, USDD's TVL on JustLend exceeded $450 million. USDD's official Chinese account stated, "USDD's growth on TRON is unstoppable." This round of USDD growth further consolidated its leading position in the TRON ecosystem and its top status in the entire stablecoin sector.

VerusCoin Ethereum Cross-Chain Bridge Attacked, Approximately $7.53 Million Transferred Out

According to CertiK Alert monitoring, a security incident occurred on VerusCoin's Ethereum cross-chain bridge, with approximately $7.53 million in assets transferred out. Preliminary analysis indicates that this issue may be related to the cross-chain bridge failing to sufficiently verify whether the Verus chain-side input supports the paid amount, similar to an incident that occurred in May this year.

CertiK:2026 年上半年针对数字资产持有者的扳手攻击共记录 52 起,同比增长 33%

据彭博社报道,区块链安全公司 CertiK 最新报告显示,2026 年上半年全球针对数字资产持有者的暴力"扳手攻击"(即以人身威胁强迫受害者交出加密货币)事件共记录 52 起,同比增长 33%。其中法国以 33 起攻击案例独占近三分之二,成为全球最严重的受害国。报告指出,加密犯罪分子的攻击目标正从数字钱包转向现实中的持币个人,暴力手段日趋普遍。