CertiK Blog

Security research, regulatory insights, and data-backed analyses for the institutional Web3 era. Turning real-world signals into actionable intelligence.

Liquid Network Incident Analysis

Liquid Network Incident Analysis

On 6 September 2026, the Liquid Network was exploited through a vulnerability in the Elements codebase used to validate Confidential Transactions. The issue stemmed from an ambiguous cache-key encoding in the rangeproof verification cache, allowing two different validation inputs to produce the same cached entry.

Verus Incident Analysis

Verus Incident Analysis

On July 23, 2026, an attacker exploited the Verus Protocol’s Ethereum cross-chain bridge, draining approximately $7.44 million in ETH, tBTC, stablecoins, and MKR. The attack relied on a discrepancy in how Verus and Ethereum interpreted notarization data: malicious duplicate state-root entries were included in otherwise legitimate notarizations, signed by Verus notaries, and then relayed to Ethereum, where they overwrote the genuine trusted state root.

DefiTuna Incident Analysis

DefiTuna Incident Analysis

On 16 July 2026, DeFiTuna was exploited for approximately $569,601 USDC on Solana. The attackers created a highly illiquid TUNA/USDC pool and used it as the destination for borrowed USDC routed through Jupiter. Because the swap returned only a negligible amount of TUNA, DeFiTuna’s value calculation rounded the position’s total assets down to zero. The protocol then incorrectly treated the position as healthy, allowing the attackers to bypass the solvency check and withdraw the USDC through attacker-controlled liquidity positions.

Navigating "Regulation Crypto Assets": What the SEC's Proposed Framework Means for Web3 Projects
New · Policy Pulse

Navigating "Regulation Crypto Assets": What the SEC's Proposed Framework Means for Web3 Projects

The regulatory landscape for Web3 in the U.S. is undergoing a significant transformation, even in the absence of the long awaited CLARITY Act. On August 18, 2026, the U.S. Securities and Exchange Commission (SEC) issued a notice of proposed rulemaking titled Regulation Crypto Assets (Release No. 33-11434; File No. S7-2026-27).

Inside CertiK's Independent Security Research on Besu

Inside CertiK's Independent Security Research on Besu

CertiK independently discovered and disclosed five resource-exhaustion vulnerabilities in Besu (formerly Hyperledger Besu), now patched in version 26.7.1, through a proactive chaos-engineering-style testing methodology now productized as Chain Scan.

Why Brazil Is Becoming a Blueprint for Digital Asset Regulation

Why Brazil Is Becoming a Blueprint for Digital Asset Regulation

CertiK's CBO Jason Jiang joined the Central Bank of Brazil and Veirano Advogados at Blockchain.RIO to discuss how collaborative VASP regulation is turning Brazil into a global model for digital asset compliance.

Technical Insights

View All Technical Insights
Tolk Security Explained: From FunC’s Engineering Pain Points to New Audit Considerations

Tolk Security Explained: From FunC’s Engineering Pain Points to New Audit Considerations

This article compares FunC and Tolk through code, explains how typed schemas, automatic serialization, and lazy loading change TON contract security, and identifies the risks developers and auditors still need to review.

Where CIP-56 Security Actually Lives: A Guide for Institutions on Canton

Where CIP-56 Security Actually Lives: A Guide for Institutions on Canton

How Daml views, choices, factories, client-side construction, and operational permissions determine the security of CIP-56 assets.

What Is a Crypto-Asset Service Provider (CASP)?

What Is a Crypto-Asset Service Provider (CASP)?

A crypto-asset service provider (CASP) is any business offering any regulated “‘crypto-asset service” as defined under the EU's MiCA framework. Learn what qualifies, what compliance requires, and how to meet it.

From Warning Letters to Working Framework: CertiK and Brazil's Central Bank on Building the VASP Rulebook

From Warning Letters to Working Framework: CertiK and Brazil's Central Bank on Building the VASP Rulebook

CertiK's Jason Jiang and the Central Bank of Brazil's Nagel Paulino join Veirano Advogados' Marcos Rocha to trace Brazil's journey from cautious crypto warnings to a detailed VASP regulatory framework.

From Rulebook to Roadmap: CertiK and Coins.ph on Brazil's New Rules for Virtual Asset Service Providers

From Rulebook to Roadmap: CertiK and Coins.ph on Brazil's New Rules for Virtual Asset Service Providers

CertiK's Jason Jiang and Coins.ph's Daniel Hott join Livecoins to discuss how Brazil's new VASP framework is separating prepared crypto operators from unprepared ones.

AI Security Must Go Beyond the Model: CertiK Identifies Google EdgeTPU Vulnerabilities, Highlighting New Risks in AI Infrastructure

AI Security Must Go Beyond the Model: CertiK Identifies Google EdgeTPU Vulnerabilities, Highlighting New Risks in AI Infrastructure

CertiK researcher uncovered two vulnerabilities in Google's EdgeTPU, CVE-2026-0150 and CVE-2026-0153, acknowledged in Google's June 2026 Security Bulletin. Here's what the findings reveal about the future of AI security.

Ecosystem Analysis

View All Ecosystem Analysis
CEX H1 2026 Review: Volume Cools, Balance Sheets Decide

CEX H1 2026 Review: Volume Cools, Balance Sheets Decide

This H1 2026 review compares centralized exchanges by spot and futures volume, open interest, reserve depth, Bitcoin custody, and expansion into tokenized stocks and traditional financial products.

Asia’s Cross-Border Money Is Moving Onchain

Asia’s Cross-Border Money Is Moving Onchain

Asia’s payment rails are moving onchain as Ratio uses Kaia to provide stablecoin foreign exchange and settlement infrastructure for institutions.

TRON H1 2026 Review: Stablecoin Rails Meet the Agent Economy

TRON H1 2026 Review: Stablecoin Rails Meet the Agent Economy

TRON’s H1 2026 data shows stablecoin supply and transfer activity outperforming the market as the network expands toward AI-agent payments.