CertiK Blog
Security research, regulatory insights, and data-backed analyses for the institutional Web3 era. Turning real-world signals into actionable intelligence.
Research
View All Research
Liquid Network Incident Analysis
On 6 September 2026, the Liquid Network was exploited through a vulnerability in the Elements codebase used to validate Confidential Transactions. The issue stemmed from an ambiguous cache-key encoding in the rangeproof verification cache, allowing two different validation inputs to produce the same cached entry.
Verus Incident Analysis
On July 23, 2026, an attacker exploited the Verus Protocol’s Ethereum cross-chain bridge, draining approximately $7.44 million in ETH, tBTC, stablecoins, and MKR. The attack relied on a discrepancy in how Verus and Ethereum interpreted notarization data: malicious duplicate state-root entries were included in otherwise legitimate notarizations, signed by Verus notaries, and then relayed to Ethereum, where they overwrote the genuine trusted state root.
DefiTuna Incident Analysis
On 16 July 2026, DeFiTuna was exploited for approximately $569,601 USDC on Solana. The attackers created a highly illiquid TUNA/USDC pool and used it as the destination for borrowed USDC routed through Jupiter. Because the swap returned only a negligible amount of TUNA, DeFiTuna’s value calculation rounded the position’s total assets down to zero. The protocol then incorrectly treated the position as healthy, allowing the attackers to bypass the solvency check and withdraw the USDC through attacker-controlled liquidity positions.
Policy Pulse
View All Policy Pulse
Navigating "Regulation Crypto Assets": What the SEC's Proposed Framework Means for Web3 Projects
The regulatory landscape for Web3 in the U.S. is undergoing a significant transformation, even in the absence of the long awaited CLARITY Act. On August 18, 2026, the U.S. Securities and Exchange Commission (SEC) issued a notice of proposed rulemaking titled Regulation Crypto Assets (Release No. 33-11434; File No. S7-2026-27).
Inside CertiK's Independent Security Research on Besu
CertiK independently discovered and disclosed five resource-exhaustion vulnerabilities in Besu (formerly Hyperledger Besu), now patched in version 26.7.1, through a proactive chaos-engineering-style testing methodology now productized as Chain Scan.
Why Brazil Is Becoming a Blueprint for Digital Asset Regulation
CertiK's CBO Jason Jiang joined the Central Bank of Brazil and Veirano Advogados at Blockchain.RIO to discuss how collaborative VASP regulation is turning Brazil into a global model for digital asset compliance.
Technical Insights
View All Technical Insights
Tolk Security Explained: From FunC’s Engineering Pain Points to New Audit Considerations
This article compares FunC and Tolk through code, explains how typed schemas, automatic serialization, and lazy loading change TON contract security, and identifies the risks developers and auditors still need to review.
Where CIP-56 Security Actually Lives: A Guide for Institutions on Canton
How Daml views, choices, factories, client-side construction, and operational permissions determine the security of CIP-56 assets.
What Is a Crypto-Asset Service Provider (CASP)?
A crypto-asset service provider (CASP) is any business offering any regulated “‘crypto-asset service” as defined under the EU's MiCA framework. Learn what qualifies, what compliance requires, and how to meet it.
Company Updates
View All Company Updates
From Warning Letters to Working Framework: CertiK and Brazil's Central Bank on Building the VASP Rulebook
CertiK's Jason Jiang and the Central Bank of Brazil's Nagel Paulino join Veirano Advogados' Marcos Rocha to trace Brazil's journey from cautious crypto warnings to a detailed VASP regulatory framework.
From Rulebook to Roadmap: CertiK and Coins.ph on Brazil's New Rules for Virtual Asset Service Providers
CertiK's Jason Jiang and Coins.ph's Daniel Hott join Livecoins to discuss how Brazil's new VASP framework is separating prepared crypto operators from unprepared ones.
AI Security Must Go Beyond the Model: CertiK Identifies Google EdgeTPU Vulnerabilities, Highlighting New Risks in AI Infrastructure
CertiK researcher uncovered two vulnerabilities in Google's EdgeTPU, CVE-2026-0150 and CVE-2026-0153, acknowledged in Google's June 2026 Security Bulletin. Here's what the findings reveal about the future of AI security.
Ecosystem Analysis
View All Ecosystem Analysis
CEX H1 2026 Review: Volume Cools, Balance Sheets Decide
This H1 2026 review compares centralized exchanges by spot and futures volume, open interest, reserve depth, Bitcoin custody, and expansion into tokenized stocks and traditional financial products.
Asia’s Cross-Border Money Is Moving Onchain
Asia’s payment rails are moving onchain as Ratio uses Kaia to provide stablecoin foreign exchange and settlement infrastructure for institutions.
TRON H1 2026 Review: Stablecoin Rails Meet the Agent Economy
TRON’s H1 2026 data shows stablecoin supply and transfer activity outperforming the market as the network expands toward AI-agent payments.