Crypto is becoming a significant component of financial infrastructure. That was the central theme of a recent fireside chat hosted by Yukie Kamimoto, CEO of NADA News, featuring CertiK CEO and Co-Founder Ronghui Gu alongside Shusaku Fujino, Chief Compliance Officer of OKJ, one of Japan's leading crypto asset exchanges.
The conversation gave Professor Gu the opportunity to explain how CertiK sees the security landscape evolving as institutions enter the space, why Japan's regulatory rigor is a preview of what other markets will eventually face, how AML has to work as both a compliance function and a threat intelligence function, and what will separate the winning platforms in the next wave of adoption.
Institutions Are Entering the Space, and the Attack Surface Is Changing With Them
Professor Gu opened by describing just how quickly institutional interest in digital assets has accelerated. "Two months ago, I attended a conference hosted by UBS in Hong Kong, and on that panel, all the panelists basically shared a feeling that it's hard to believe we can talk about digital assets on the main stage of a UBS conference," he said. "It marks that more and more traditional financial institutions start to enter the space and embrace this new technology."
Professor Gu pointed to a trend CertiK has observed directly: fewer smart contracts being deployed overall, but the ones tied to traditional institutions holding significantly higher value and carrying lower tolerance for error. "They're regulated, they have licenses, they're going to have a huge stake on chain," he said. "The system can be more complex, but they can't tolerate risk."
That is pushing CertiK's own products upmarket. "We need to move and evolve our solutions and products to institutional grade," Professor Gu said. "We have to offer beyond just code auditing. We have to provide techniques like formal verification to give a security guarantee, rather than just an audit report. And we need to provide whole life cycle security solutions, starting from code development to code deployment, then on-chain and off-chain monitoring, and then compliance solutions."
For context on where that institutional interest is flowing, Fujino noted that OKJ is prioritizing tokenization of real-world assets, institutional investor services, and yen-denominated stablecoins, an area where he said megabanks in Japan have already announced plans for joint issuance.
Japan as a Preview of Global Regulation
Professor Gu was direct in describing Japan's regulatory environment as a model for where the rest of the industry is headed. "Japan always has the most rigorous compliance framework for most of the financial sectors, and that also applies to the digital asset sector," he said. "I personally view it as a pressure test. I think what Japan's government is facing will be faced by many other regions in the future."
He drew on CertiK's work across other major markets to make the point. "I also want to make this a great opportunity to announce that CertiK officially enters the Japan market, because we believe there are lots of things we can help with," Professor Gu said, citing CertiK's work with regulators in Hong Kong, Singapore, the US, the UAE, Brazil, and Turkey.
He was specific about how Japan's requirements differ. "When we talk to regulators here, they actually have more requirements, like operational security. How you manage keys. How you do internal risk control. What kind of on-chain AML solution you have been using," Professor Gu said. "Definitely more challenging, and I think we're ready to help with the entire life cycle of security and compliance."
Fujino offered a window into what that rigor looks like in practice at OKJ, describing how compliance, systems, and risk management teams work in parallel from the earliest stage of any listing decision, a structure he credited for OKJ's ability to list assets quickly, including a same-day listing announced during the conversation.
AML as Threat Intelligence
Asked what separates a secure exchange from an unsecure one, Professor Gu reframed the question around a single idea. "For digital assets or blockchain, people always emphasize decentralization, but I feel the key concept should be trust," he said. "This entire technology is being built for establishing trust among entities who don't even need to know each other."
He was candid about how technically difficult on-chain AML actually is. "Blockchain introduces new challenges. It's very hard to do on-chain AML, there are lots of transactions, it's very hard to collect labels, and the blockchain itself is semi-anonymous," Professor Gu said. "It requires exchanges, and us, to keep investing in it. It's not a one-time action, it's continuous monitoring, continuous effort to improve it."
That challenge is driving new product development at CertiK. "Previous solutions focused on per-transaction AML, but in many cases, in the eyes of a regulator, they want to see a bigger picture, a macro image of an exchange's overall on-chain AML posture," Professor Gu said. "We want to give a risk profile for all inflow and outflow, an overall picture of the risk control for an entity like a licensed exchange."
Fujino described how that kind of monitoring fits into OKJ's own operations, layering blockchain analysis tools with internal compliance review and a dedicated team handling risk calculation and response on an ongoing basis.
What Institutional-Grade Security Actually Requires
Professor Gu broke down what institutions need differently from earlier, retail-driven waves of adoption. "Institutions have much higher requirements because they have higher stakes. Their systems are also very complicated and integrated with lots of other components, so institutions need a more comprehensive, full life cycle security solution," he said.
He laid out the categories of risk that now have to be managed together. "When we talk about risk in the digital asset system, it first includes what we call on-chain risk: smart contract vulnerabilities, blockchain vulnerabilities, validator issues, oracle risk," Professor Gu said. "Then we have off-chain risk, mostly operational risk. And then we have compliance risk, on-chain per-transaction AML, and the overall risk profile for the entity. For institutions, they need to cover all of this risk and work with experts to monitor it and then mitigate it."
Fujino added that OKJ sees this institutional wave as inevitable, pointing to large corporations and legacy financial players moving into the market, while stressing that expansion has to move in step with compliance rather than ahead of it.
What Will Define the Winning Platforms
Closing the conversation, Professor Gu laid out four capabilities he sees as essential for any digital asset security platform going forward. "First is cybersecurity capability," he said. "Second is formal verification. Cybersecurity techniques help you find bugs, but formal verification can help prove your system is bug free." The third is risk profiling, including on-chain labeling and tracing. The fourth, he said, is AI. "Hackers are now using frontier AI models to find bugs in systems, and security platforms need to understand the power of AI and use it to make systems more secure."
Beyond capability, Professor Gu pointed to a second requirement: working directly with regulators. "Infrastructure providers and regulators are intertwined," he said. "We want to use our technical expertise to inform regulators, and at the same time we want to understand regulators' concerns and build that into our products and solutions."
Fujino closed with his own outlook, describing the next one to two years as a critical window as Japan's new legal framework takes effect, and pointing to OKJ's group-wide experience as a source of differentiation as legacy financial institutions move into the space.
Taken together, the conversation made the case that trust, not decentralization, is the organizing principle of this next phase of crypto, and that the platforms built to earn it, technically, operationally, and regulatorily, will be the ones that lead.



