CertiK Blog

Security research, regulatory insights, and data-backed analyses for the institutional Web3 era. Turning real-world signals into actionable intelligence.

Verus Incident Analysis

Verus Incident Analysis

On July 23, 2026, an attacker exploited the Verus Protocol’s Ethereum cross-chain bridge, draining approximately $7.44 million in ETH, tBTC, stablecoins, and MKR. The attack relied on a discrepancy in how Verus and Ethereum interpreted notarization data: malicious duplicate state-root entries were included in otherwise legitimate notarizations, signed by Verus notaries, and then relayed to Ethereum, where they overwrote the genuine trusted state root.

DefiTuna Incident Analysis

DefiTuna Incident Analysis

On 16 July 2026, DeFiTuna was exploited for approximately $569,601 USDC on Solana. The attackers created a highly illiquid TUNA/USDC pool and used it as the destination for borrowed USDC routed through Jupiter. Because the swap returned only a negligible amount of TUNA, DeFiTuna’s value calculation rounded the position’s total assets down to zero. The protocol then incorrectly treated the position as healthy, allowing the attackers to bypass the solvency check and withdraw the USDC through attacker-controlled liquidity positions.

JaredFromSubway MEV bot Incident Analysis

JaredFromSubway MEV bot Incident Analysis

On 20 June 2026, the JaredFromSubway MEV bot lost 4,424 ETH (~$7.5M) due to an approval hijacking flaw. The attacker deployed fake arbitrage pools and bait tokens that appeared to offer profitable trading opportunities, causing the bot’s automated strategy to interact with malicious contracts and grant token approvals.

From Speculation to Infrastructure: CertiK and OKJ on the Future of Crypto in Japan and Beyond
New · Policy Pulse

From Speculation to Infrastructure: CertiK and OKJ on the Future of Crypto in Japan and Beyond

CertiK and OKJ discuss the future of crypto regulation, security, and institutional adoption in a fireside chat covering stablecoins, RWAs, AML compliance, and Japan's regulatory model.

SOC 2 and ISO 27001 for Crypto Companies

SOC 2 and ISO 27001 for Crypto Companies

Read to learn about the requirements of SOC 2 and ISO 27001, how to choose between them, and how to get from your current state to a passed audit.

May 2026 Regulatory Recap: Significant Movement with the CLARITY Act

May 2026 Regulatory Recap: Significant Movement with the CLARITY Act

A massive turning point arrived in July 2025 when the Trump Administration’s pro-crypto stance coalesced into historic legislative action: the passage of both the stablecoin-focused GENIUS Act and the landmark CLARITY Act by the House.

Technical Insights

View All Technical Insights
How to Prepare for a CCSS Audit

How to Prepare for a CCSS Audit

Institutional counterparties ask crypto businesses a hard question: how do you safeguard your private keys? A bank wants evidence before it opens an account. A fund wants it before it deposits assets. The CryptoCurrency Security Standard (CCSS) exists to answer that question with an audit instead of a claim. This guide explains what the standard covers, how certification works and how you prepare for it.

What Is a Zero-Knowledge Virtual Machine (zkVM)?

What Is a Zero-Knowledge Virtual Machine (zkVM)?

A zkVM is a computational system designed to verify that a program executed correctly, without revealing the program's internal data. By combining zero-knowledge proofs (ZKPs) with virtual machine (VM) technology, zkVMs enable verifiable computation across blockchain and Web3 ecosystems, boosting transparency, privacy, and scalability all at once.

The Summer Regulatory Crunch: All Eyes on the CLARITY Act

The Summer Regulatory Crunch: All Eyes on the CLARITY Act

An overview of notable crypto regulatory developments that happened in June 2026.

AI Security Must Go Beyond the Model: CertiK Identifies Google EdgeTPU Vulnerabilities, Highlighting New Risks in AI Infrastructure

AI Security Must Go Beyond the Model: CertiK Identifies Google EdgeTPU Vulnerabilities, Highlighting New Risks in AI Infrastructure

CertiK researcher uncovered two vulnerabilities in Google's EdgeTPU, CVE-2026-0150 and CVE-2026-0153, acknowledged in Google's June 2026 Security Bulletin. Here's what the findings reveal about the future of AI security.

CertiK Named Official Vendor for Hub71, Bringing Security and Compliance Support to Abu Dhabi's Startup Ecosystem

CertiK Named Official Vendor for Hub71, Bringing Security and Compliance Support to Abu Dhabi's Startup Ecosystem

CertiK has been named an official vendor for Hub71, offering portfolio companies a 20% service discount, a $200K subsidy pool, and free access to the CertiK Compliance Tool for UAE licensing and compliance.

Introducing CertiK Hunt, The Invite-Only Security Platform for Web3 Projects and Top Security Researchers

Introducing CertiK Hunt, The Invite-Only Security Platform for Web3 Projects and Top Security Researchers

CertiK Hunt is an invite-only platform connecting elite security researchers with web3 projects through bug bounty programs, audit competitions, and AI challenges.