CertiK 블로그

Web3의 기관화가 본격화되는 흐름에 맞춰 보안 연구, 규제 동향 및 데이터 분석을 통해 업계 변화를 실행 가능한 의사결정 인사이트로 전환합니다.

JaredFromSubway MEV bot Incident Analysis

JaredFromSubway MEV bot Incident Analysis

On 20 June 2026, the JaredFromSubway MEV bot lost 4,424 ETH (~$7.5M) due to an approval hijacking flaw. The attacker deployed fake arbitrage pools and bait tokens that appeared to offer profitable trading opportunities, causing the bot’s automated strategy to interact with malicious contracts and grant token approvals.

GnosisPay Incident Analysis

GnosisPay Incident Analysis

On 01 June 2026 an attacker drained dozens of GnosisPay Safes on Gnosis Chain. The attack vector was a signature-verification flaw in the GnosisPay Delay module.

Quantum Computing Threats to the Blockchain Industry

Quantum Computing Threats to the Blockchain Industry

This report examines how future fault-tolerant quantum computers may compromise blockchain cryptography, and what protocols, validators, custodians, and ecosystem participants must do to migrate before the window closes.

SOC 2 and ISO 27001 for Crypto Companies
새로운 · 정책 펄스

SOC 2 and ISO 27001 for Crypto Companies

Read to learn about the requirements of SOC 2 and ISO 27001, how to choose between them, and how to get from your current state to a passed audit.

May 2026 Regulatory Recap: Significant Movement with the CLARITY Act

May 2026 Regulatory Recap: Significant Movement with the CLARITY Act

A massive turning point arrived in July 2025 when the Trump Administration’s pro-crypto stance coalesced into historic legislative action: the passage of both the stablecoin-focused GENIUS Act and the landmark CLARITY Act by the House.

Inside the CertiK x XDC Fireside Chat: Trade Finance, Tokenization, and AI Security

Inside the CertiK x XDC Fireside Chat: Trade Finance, Tokenization, and AI Security

CertiK Co-Founder and CEO, Rongui Gu, and XDC Foundation’s Billy Sebell discuss trade finance, tokenization, AI-driven cybersecurity risks, and the infrastructure needed for institutional blockchain adoption.

Advancing Sui: The Evolution of Sui’s Payment Pipeline

Advancing Sui: The Evolution of Sui’s Payment Pipeline

Explore how Sui's Address Balance layer powers gasless stablecoin transfers, providing a frictionless user experience while tackling complex engineering challenges at the execution and settlement level.

Security Considerations for Passkey-Based Web3 Wallets

Security Considerations for Passkey-Based Web3 Wallets

This article analyzes that security model across the full asset-control lifecycle. It traces a single transaction through Clave's open-source implementation, surveys past vulnerabilities in WebAuthn, FIDO2, and CTAP, maps them onto the lifecycle of a typical Passkey Wallet, and ends with implementation checks for teams building one.

Post-Quantum Signatures, Part 2: From Trees to Forests

Post-Quantum Signatures, Part 2: From Trees to Forests

XMSS builds on one-time signatures by organizing OTS keys into Merkle trees and hyper-trees, delivering a practical post-quantum signature scheme with compact proofs, fast verification, and a critical trade-off: strict state management.

CertiK Named Official Vendor for Hub71, Bringing Security and Compliance Support to Abu Dhabi's Startup Ecosystem
새로운 · 회사 소식 ·공지사항

CertiK Named Official Vendor for Hub71, Bringing Security and Compliance Support to Abu Dhabi's Startup Ecosystem

CertiK has been named an official vendor for Hub71, offering portfolio companies a 20% service discount, a $200K subsidy pool, and free access to the CertiK Compliance Tool for UAE licensing and compliance.

CertiK Skills: Bringing Blockchain Security Intelligence Into AI Agents

CertiK Skills: Bringing Blockchain Security Intelligence Into AI Agents

Discover CertiK's open-source AI Agent Skills for Claude Code, Codex, and Cursor. Easily plug in SkyInsights, Skylens, and Skynet Score to access real-time Web3 wallet screening, EVM forensics, and project security intelligence directly within your agent workflow.

Catch Runtime Bugs Before They Become Mainnet Incidents: CertiK Grey Box Chain Audit

Catch Runtime Bugs Before They Become Mainnet Incidents: CertiK Grey Box Chain Audit

CertiK's Grey Box Chain Audit catches runtime bugs before they become mainnet incidents, using fault injection and live network testing to surface chain-critical failures that static analysis alone cannot detect.