지금 프로젝트를 보호하세요
최대 규모의 웹3 보안 제공업체로 프로젝트를 강화하세요.
CertiK 보안 전문가가 귀하의 요청을 검토 후 곧 연락드리겠습니다.

AllianceBlock and CertiK's Audit Procedure

기술 블로그 ·교육적인 ·
AllianceBlock and CertiK's Audit Procedure

AllianceBlock provides the bridge between traditional and digital capital markets for all participants, reflecting how traditional finance would be designed today with current technology.

The Alliance Block DeFi Ecosystem is designed as a multi-sided protocol that enables its members to issue, transfer, own tokenized/ digitized asset, trade, in another word all services that exist in the traditional capital market, while being fully compliant with regulations. It allows any entity to create assets and applications without the need for approvals from centralized “trust” authorities. The objective is to create the world's first globally compliant decentralized capital market

The CertiK team was contracted by the AllianceBlock team to audit the design and implementation of their smart contracts, and its compliance with the EIPs it’s meant to execute on. The audited source code link can be found here.

Code Review Overview

The goal of the audit was to review the Solidity implementation for its business model, study potential security vulnerabilities, its general design and architecture, and uncover bugs that could compromise the software in production.

CertiK’s Auditing Process

A comprehensive examination has been performed, utilizing Dynamic Analysis, Static Analysis and Manual review techniques. The auditing process pays special attention to the following considerations:

  1. Testing the smart contracts against both common and uncommon attack vectors
  2. Assessing the codebase to ensure compliance with current best practices and industry standards
  3. Ensuring contract logic meets the specifications and intentions of the client
  4. Cross referencing contract structure and implementation against similar smart contracts produced by industry leaders
  5. Thorough line-by-line manual review of the entire codebase

Summary and Recommendations

The project's codebase is a typical EIP token implementation, along with batch token transfer and vesting mechanisms. The codebase strictly adheres to the standards and interfaces imposed by the OpenZepellin open-source libraries and as such its typical ERC-20 functions can be deemed to be secure.

During the audit process, CertiK and AllianceBlock worked together to remediate all issues found in the process. Although certain optimization steps CertiK pinpointed in the source code mostly referred to coding standards and inefficiencies, the minor flaw that was identified was remediated to ensure the security of the contracts.

“Smart Contract Security is imperative to the blockchain ecosystem. When you invest in a token, you want to ensure the Smart Contracts are secure in every way. CertiK, the leading blockchain security company, has an outstanding reputation and together with their great attention to detail and deep knowledge we made sure to achieve exactly that.” -- Matthijs de Vries, Founder & CTO of AllianceBlock.

About AllianceBlock

AllianceBlock is building the first globally compliant decentralized capital market. Incubated by three of Europe’s most prestigious incubators: Station F, L39, and Kickstart Innovation in Zurich, and led by a heavily experienced team of ex-JP Morgan, Barclays, BNP Paribas, Goldman Sachs investment bankers, and quants, AllianceBlock is on the path to disrupt the $100 trillion securities market with its state-of-the-art and globally compliant decentralized capital market.

Twitter: https://twitter.com/allianceblock

Telegram: https://t.me/allianceblock

Website: www.allianceblock.io

About CertiK

CertiK is a technology-led blockchain security company founded by Computer Science professors from Yale University and Columbia University built to prove the security and correctness of smart contracts and blockchain protocols.

CertiK’s mission of every audit is to apply different approaches and detection methods, ranging from manual, static, and dynamic analysis to ensure that the project is checked against known attacks and potential vulnerabilities. CertiK leverages a team of seasoned engineers and security auditors to apply testing methodologies and verifications on the project, in turn creating a more secure and robust software system.

CertiK has serviced more than 100 clients with high quality auditing and consulting services, ranging from stablecoins such as Binance’s BGBP and Paxos Gold to decentralized oracles such as Band Protocol and Tellor.

Stay connected!

Remember to follow us on the platforms below to stay up-to-date with our latest updates and announcements.

Consult with one of our experts at [email protected]

Stay connected!

Website|Twitter|Linkedin|GitHub

관련 블로그

CertiK Completes Proof of Reserves  Verification for Gate Dubai
새로운 · 소식 ·공지사항

CertiK Completes Proof of Reserves Verification for Gate Dubai

CertiK has completed an independent Proof of Reserves (PoR) audit for Gate Technology FZE, the Dubai-based entity of the Gate Group. Gate Dubai exchange is licensed by the Virtual Assets Regulatory Authority (VARA). The audit verified that the platform's on-chain reserves fully back its user liabilities across all in-scope assets as of December 31, 2025.

CertiK and WEMADE Join Forces to Form the Global Korean Stablecoin Alliance

CertiK and WEMADE Join Forces to Form the Global Korean Stablecoin Alliance

CertiK has recently joined hands with Korean gaming giant WEMADE to launch the Global Alliance of KRW Stablecoin (GAKS), to provide comprehensive security audit services for StableNet, Korea's first dedicated mainnet infrastructure for the entire lifecycle of KRW stablecoins.

March's Major Private Key Compromises

March's Major Private Key Compromises

From 12 March to 16 March we have seen nine private key compromises (PKC) that have led to a combined loss of at least $22.96 million in March, with five of those incidents incurring losses over $1 million. These incidents showcase the continued devastation that private key leakages can have on the Web3 ecosystem which has already seen approximately $239 million lost to this type of attack in 2024.