CertiK Blog
Security research, regulatory insights, and data-backed analyses for the institutional Web3 era. Turning real-world signals into actionable intelligence.
Research
View All Research
Verus Incident Analysis
On July 23, 2026, an attacker exploited the Verus Protocol’s Ethereum cross-chain bridge, draining approximately $7.44 million in ETH, tBTC, stablecoins, and MKR. The attack relied on a discrepancy in how Verus and Ethereum interpreted notarization data: malicious duplicate state-root entries were included in otherwise legitimate notarizations, signed by Verus notaries, and then relayed to Ethereum, where they overwrote the genuine trusted state root.
DefiTuna Incident Analysis
On 16 July 2026, DeFiTuna was exploited for approximately $569,601 USDC on Solana. The attackers created a highly illiquid TUNA/USDC pool and used it as the destination for borrowed USDC routed through Jupiter. Because the swap returned only a negligible amount of TUNA, DeFiTuna’s value calculation rounded the position’s total assets down to zero. The protocol then incorrectly treated the position as healthy, allowing the attackers to bypass the solvency check and withdraw the USDC through attacker-controlled liquidity positions.
JaredFromSubway MEV bot Incident Analysis
On 20 June 2026, the JaredFromSubway MEV bot lost 4,424 ETH (~$7.5M) due to an approval hijacking flaw. The attacker deployed fake arbitrage pools and bait tokens that appeared to offer profitable trading opportunities, causing the bot’s automated strategy to interact with malicious contracts and grant token approvals.
Policy Pulse
View All Policy Pulse
Navigating "Regulation Crypto Assets": What the SEC's Proposed Framework Means for Web3 Projects
The regulatory landscape for Web3 in the U.S. is undergoing a significant transformation, even in the absence of the long awaited CLARITY Act. On August 18, 2026, the U.S. Securities and Exchange Commission (SEC) issued a notice of proposed rulemaking titled Regulation Crypto Assets (Release No. 33-11434; File No. S7-2026-27).
Inside CertiK's Independent Security Research on Besu
CertiK independently discovered and disclosed five resource-exhaustion vulnerabilities in Besu (formerly Hyperledger Besu), now patched in version 26.7.1, through a proactive chaos-engineering-style testing methodology now productized as Chain Scan.
Why Brazil Is Becoming a Blueprint for Digital Asset Regulation
CertiK's CBO Jason Jiang joined the Central Bank of Brazil and Veirano Advogados at Blockchain.RIO to discuss how collaborative VASP regulation is turning Brazil into a global model for digital asset compliance.
Technical Insights
View All Technical Insights
Where CIP-56 Security Actually Lives: A Guide for Institutions on Canton
How Daml views, choices, factories, client-side construction, and operational permissions determine the security of CIP-56 assets.
What Is a Crypto-Asset Service Provider (CASP)?
A crypto-asset service provider (CASP) is any business offering any regulated “‘crypto-asset service” as defined under the EU's MiCA framework. Learn what qualifies, what compliance requires, and how to meet it.
Post-Quantum Signatures, Part 3: Inside FIPS 205 Through Quranium’s SLH-DSA Adoption
In this post, we use the structure of FIPS 205 to explain how SLH-DSA works and why it matters for real protocol implementations. We start with Forest of Random Subsets (FORS), the few-time signature component that signs part of the randomized message digest, then build up the hypertree that authenticates the reconstructed FORS public key to the public root. Finally, we examine how FIPS 205 defines the concrete SLH-DSA algorithm used by interoperable implementations.
Company Updates
View All Company Updates
From Warning Letters to Working Framework: CertiK and Brazil's Central Bank on Building the VASP Rulebook
CertiK's Jason Jiang and the Central Bank of Brazil's Nagel Paulino join Veirano Advogados' Marcos Rocha to trace Brazil's journey from cautious crypto warnings to a detailed VASP regulatory framework.
From Rulebook to Roadmap: CertiK and Coins.ph on Brazil's New Rules for Virtual Asset Service Providers
CertiK's Jason Jiang and Coins.ph's Daniel Hott join Livecoins to discuss how Brazil's new VASP framework is separating prepared crypto operators from unprepared ones.
AI Security Must Go Beyond the Model: CertiK Identifies Google EdgeTPU Vulnerabilities, Highlighting New Risks in AI Infrastructure
CertiK researcher uncovered two vulnerabilities in Google's EdgeTPU, CVE-2026-0150 and CVE-2026-0153, acknowledged in Google's June 2026 Security Bulletin. Here's what the findings reveal about the future of AI security.
Ecosystem Analysis
View All Ecosystem Analysis
TRON H1 2026 Review: Stablecoin Rails Meet the Agent Economy
TRON’s H1 2026 data shows stablecoin supply and transfer activity outperforming the market as the network expands toward AI-agent payments.
Robinhood Chain: From Brokerage to an Onchain Capital Market
Robinhood Chain connects Robinhood's brokerage distribution, Stock Tokens, wallet, and DeFi infrastructure in an emerging onchain capital market.
Aptos Confidential APT: Verifiable Encrypted Transfers on Mainnet
Aptos Confidential APT brings encrypted balances and transfers to Aptos mainnet while using zero-knowledge proofs, governance controls, and optional auditor access to keep state transitions verifiable.