GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar
CertiK

CertiK

Active

Blockchain security company

News Heat Trend

Project Overview

CertiK, a blockchain security company founded in 2018, utilizes formal verification and AI technology in collaboration for its end-to-end blockchain security audit services. It mathematically validates the safety of smart contracts through a combination of formal and manual verification. Additionally, the company has developed "CertiK Chain", a security-focused blockchain designed to enhance the security of smart contracts.

CertiK Report: Wrench Attacks Surge Nearly 12x in Losses, “Operational Security” Becomes New Core of Prevention

Odaily Odaily News, July 22nd - Web3 security firm CertiK released its "H1 2026 Wrench Attack Report." The report indicates that a total of 52 publicly verified wrench attacks were recorded globally in the first half of 2026, a year-over-year increase of 33.3%; related losses amounted to approximately $124 million, an increase of about 11.8 times compared to the same period last year.The report notes that attackers are shifting from exploiting technical vulnerabilities to targeting asset holders and their real-world social networks. Home invasion incidents increased from 1 case in H1 2025 to 20 cases, accounting for 41% of the total incidents in the period. Europe has become a high-incidence area for attacks, with 33 cases occurring in France alone, representing 63.5% of the global total.CertiK stated that as real-world risks become a significant challenge for digital asset security, enterprises and high-net-worth individuals need to establish more comprehensive protection systems. CertiK has launched operational security services to help identify exposure risks related to identity, family, residence, and travel routes. Simultaneously, through the CertiK Security Workspace, it correlates off-chain intelligence, on-chain transactions, and AML risk signals to support institutions in tracking and analyzing cybercrime activities. Furthermore, CertiK is strengthening cooperation with international law enforcement agencies such as Interpol and Europol, providing technical support for cross-border attack investigations and security policy research.

CLARITY Act could remove Section 604 or expose non-custodial developers to Bank Secrecy Act obligations

one year after the U.S. House of Representatives passed the Clarity for Digital Assets Act (CLARITY Act), the bill remains stalled in the Senate, facing opposition from the banking industry and partisan divisions. Supporters anticipate a potential vote before the Senate's August recess. Industry organizations Coin Center and the Blockchain Association have identified Section 604 as a key provision for protecting open-source innovation. This provision aims to prevent non-custodial blockchain developers, node operators, and validators from being classified as federal money transmitters. Stefan Muehlbauer, Head of U.S. Government Affairs at CertiK, stated that removing Section 604 could conflate software development with financial services, subjecting developers to the Bank Secrecy Act and triggering First Amendment-related constitutional challenges. Iana Dimitrova, CEO of Openpayd, noted that the expanding use of stablecoins for cross-border value transfer has made the need for a federal regulatory framework more apparent. The bill also addresses accounting standards, acknowledges the rescission of SEC Staff Accounting Bulletin SAB 121, and prohibits the SEC from reimposing equivalent crypto custody accounting requirements without a full notice-and-comment rulemaking process. Mark Zalan, CEO of Gomining, pointed out that Bitcoin still faces regulatory gaps, such as tax treatment.

CertiK: Wasabi Protocol Hacked, Approximately $2.9 Million Stolen

According to blockchain security firm CertiK (@CertiKAlert), Wasabi Protocol (@wasabi_protocol) has suffered a security breach, with approximately $2.9 million stolen so far. Preliminary investigations indicate that the attacker gained privileged access after compromising a wallet deployed by Wasabi, enabling the attack. The stolen funds are currently distributed across the following addresses: 0xb8Bb...70dB (approximately $677,000) and 0x6244...f906 (approximately $1.1 million). The incident remains under active investigation.

Syndicate Loses ~$330,000 Due to Attack on Commons Cross-Chain Bridge

According to CertiK, Syndicate Protocol suffered an exploit due to a security breach in the Commons cross-chain bridge. The attacker exploited the vulnerability to acquire approximately 18.5 million SYND tokens, which were subsequently sold for roughly $330,000. The related funds have already been transferred to the Ethereum network via the cross-chain bridge. Syndicate’s official response states that it is investigating the security incident involving the Commons bridge. The team is tracking the attack and collaborating with security firms. It is also evaluating various options to compensate affected users. Syndicate holds sufficient token reserves to assist users who lost SYND.

CertiK Releases 2026 Global Digital Asset Regulation Report: AML Enforcement Intensifies, Smart Contract Audits Become Access Condition

Odaily News, Web3 security company CertiK has released its "2026 State of Digital Asset Regulation" report, systematically reviewing global regulatory trends. The report indicates that as of April 2026, regulatory frameworks in major jurisdictions such as the United States, the European Union, Hong Kong SAR, and Singapore have been largely established, and the industry is entering a phase of comprehensive compliance.The report shows that anti-money laundering (AML) enforcement has replaced securities classification as the primary regulatory risk. In the first half of 2025, global AML-related fines exceeded $900 million, making transaction monitoring capabilities a core compliance requirement. Meanwhile, smart contract security audits are evolving from industry best practices into access conditions, becoming a prerequisite for license approval and token listings. Additionally, global stablecoin regulatory frameworks are converging, with principles such as full reserve backing and licensed issuance becoming widespread, though cross-jurisdictional regulatory differences still pose compliance challenges.The report states that with regulatory convergence and strengthened enforcement, the industry has entered an "era of strong compliance." CertiK indicated that the core challenge for enterprises is shifting from "whether to comply" to "how to quickly build and implement compliance capabilities." Multi-jurisdictional licensing, AML investment, and continuous security audits are becoming fundamental entry requirements for institutional development.

France charges 88 suspects in crypto "wrench attack" cases, including over a dozen minors

the French National Organized Crime Prosecutor's Office (PNACO) issued a statement on Friday stating that France has launched judicial investigations into 12 cryptocurrency kidnapping cases orchestrated by organized crime groups, and has indicted 88 suspects, including more than 10 minors.According to statistics, since 2023, France has recorded 135 cryptocurrency-related attacks, including 18 in 2024, 67 in 2025, and 47 so far in 2026. The accused individuals face charges including kidnapping, illegal detention, extortion, and money laundering. Recently, police arrested six suspects in two operations targeting kidnapping cases, and all individuals are currently in preventive detention. CertiK blockchain intelligence analyst Jonathan Riss stated that the masterminds behind such criminal gangs are typically located outside the European Union.

VerusCoin Ethereum Cross-Chain Bridge Attacked, Approximately $7.53 Million Transferred Out

According to CertiK Alert monitoring, a security incident occurred on VerusCoin's Ethereum cross-chain bridge, with approximately $7.53 million in assets transferred out. Preliminary analysis indicates that this issue may be related to the cross-chain bridge failing to sufficiently verify whether the Verus chain-side input supports the paid amount, similar to an incident that occurred in May this year.

CodexField's X account and website taken offline, previously accused of fraud

according to CertiK's monitoring, CodexField's X account and website have been taken offline. Earlier, on-chain analyst Specter had warned that the project might be a scam and exit scam, and tracked abnormal cross-chain fund transfers totaling over 17.3 million USDT.

Gravity Bridge attacker deposits 1,180 ETH into Tornado Cash again

According to on-chain security firm CertiK (@CertiKAlert), the Gravity Bridge attacker recently deposited another 1,180 ETH (approximately $2.06 million) into Tornado Cash. Earlier, on May 30, the attacker exploited the permissionless deployERC20() function by forging the Osmosis token string, tampering with the token registry, and mapping fake balances to real custodial assets—thereby stealing approximately 2,600 ETH (around $5.4 million) from Gravity Bridge. To date, 2,020 ETH of the stolen funds have been transferred to Tornado Cash via two externally owned accounts (EOAs); the remainder has been dispersed across centralized exchanges, making fund recovery significantly challenging.

France charges 88 suspects in crypto "wrench attack" cases, including over a dozen minors

the French National Organized Crime Prosecutor's Office (PNACO) issued a statement on Friday stating that France has launched judicial investigations into 12 cryptocurrency kidnapping cases orchestrated by organized crime groups, and has indicted 88 suspects, including more than 10 minors.According to statistics, since 2023, France has recorded 135 cryptocurrency-related attacks, including 18 in 2024, 67 in 2025, and 47 so far in 2026. The accused individuals face charges including kidnapping, illegal detention, extortion, and money laundering. Recently, police arrested six suspects in two operations targeting kidnapping cases, and all individuals are currently in preventive detention. CertiK blockchain intelligence analyst Jonathan Riss stated that the masterminds behind such criminal gangs are typically located outside the European Union.

Hyperbridge Gateway Contract Attacked; 1 Billion DOT Tokens Minted and Dumped on Ethereum

According to PeckShieldAlert monitoring, approximately 1 billion Polkadot (DOT) tokens have been minted and dumped on the Ethereum network. Details of the incident are still under further verification. According to CertiK monitoring, the Hyperbridge gateway contract was attacked; the attacker forged messages to tamper with the admin privileges of the Polkadot token contract on Ethereum, and profited approximately $237,000 by minting and selling 1 billion tokens.

VerusCoin Ethereum Cross-Chain Bridge Attacked, Approximately $7.53 Million Transferred Out

According to CertiK Alert monitoring, a security incident occurred on VerusCoin's Ethereum cross-chain bridge, with approximately $7.53 million in assets transferred out. Preliminary analysis indicates that this issue may be related to the cross-chain bridge failing to sufficiently verify whether the Verus chain-side input supports the paid amount, similar to an incident that occurred in May this year.

CertiK:2026 年上半年针对数字资产持有者的扳手攻击共记录 52 起,同比增长 33%

据彭博社报道,区块链安全公司 CertiK 最新报告显示,2026 年上半年全球针对数字资产持有者的暴力"扳手攻击"(即以人身威胁强迫受害者交出加密货币)事件共记录 52 起,同比增长 33%。其中法国以 33 起攻击案例独占近三分之二,成为全球最严重的受害国。报告指出,加密犯罪分子的攻击目标正从数字钱包转向现实中的持币个人,暴力手段日趋普遍。

CertiK Report: Wrench Attacks Surge Nearly 12x in Losses, “Operational Security” Becomes New Core of Prevention

Odaily Odaily News, July 22nd - Web3 security firm CertiK released its "H1 2026 Wrench Attack Report." The report indicates that a total of 52 publicly verified wrench attacks were recorded globally in the first half of 2026, a year-over-year increase of 33.3%; related losses amounted to approximately $124 million, an increase of about 11.8 times compared to the same period last year.The report notes that attackers are shifting from exploiting technical vulnerabilities to targeting asset holders and their real-world social networks. Home invasion incidents increased from 1 case in H1 2025 to 20 cases, accounting for 41% of the total incidents in the period. Europe has become a high-incidence area for attacks, with 33 cases occurring in France alone, representing 63.5% of the global total.CertiK stated that as real-world risks become a significant challenge for digital asset security, enterprises and high-net-worth individuals need to establish more comprehensive protection systems. CertiK has launched operational security services to help identify exposure risks related to identity, family, residence, and travel routes. Simultaneously, through the CertiK Security Workspace, it correlates off-chain intelligence, on-chain transactions, and AML risk signals to support institutions in tracking and analyzing cybercrime activities. Furthermore, CertiK is strengthening cooperation with international law enforcement agencies such as Interpol and Europol, providing technical support for cross-border attack investigations and security policy research.

DeFiTuna Suffers Attack, Losing 569,600 USDC

CertiK published an analysis stating that the Solana ecosystem protocol DeFiTuna was attacked on July 16, with losses of approximately 569,601 USDC. The attacker first created an extremely low-liquidity TUNA/USDC pool and swapped borrowed USDC into the pool via Jupiter routing. Since only a minimal amount of TUNA was ultimately obtained, the protocol experienced rounding down during the position asset value calculation, causing the total assets to be recorded as 0, thereby incorrectly passing the health and solvency checks.

Ostium Halts Trading; Oracle Vulnerability Causes Tens of Millions of Dollars in Losses

Decentralized trading protocol Ostium paused trading due to suspected exploitation of its oracle system, with security firms Blockaid and CertiK estimating losses between $18 million and $22 million.

CodexField's X account and website taken offline, previously accused of fraud

according to CertiK's monitoring, CodexField's X account and website have been taken offline. Earlier, on-chain analyst Specter had warned that the project might be a scam and exit scam, and tracked abnormal cross-chain fund transfers totaling over 17.3 million USDT.

VerusCoin Ethereum Cross-Chain Bridge Attacked, Approximately $7.53 Million Transferred Out

According to CertiK Alert monitoring, a security incident occurred on VerusCoin's Ethereum cross-chain bridge, with approximately $7.53 million in assets transferred out. Preliminary analysis indicates that this issue may be related to the cross-chain bridge failing to sufficiently verify whether the Verus chain-side input supports the paid amount, similar to an incident that occurred in May this year.

CertiK Report: Wrench Attacks Surge Nearly 12x in Losses, “Operational Security” Becomes New Core of Prevention

Odaily Odaily News, July 22nd - Web3 security firm CertiK released its "H1 2026 Wrench Attack Report." The report indicates that a total of 52 publicly verified wrench attacks were recorded globally in the first half of 2026, a year-over-year increase of 33.3%; related losses amounted to approximately $124 million, an increase of about 11.8 times compared to the same period last year.The report notes that attackers are shifting from exploiting technical vulnerabilities to targeting asset holders and their real-world social networks. Home invasion incidents increased from 1 case in H1 2025 to 20 cases, accounting for 41% of the total incidents in the period. Europe has become a high-incidence area for attacks, with 33 cases occurring in France alone, representing 63.5% of the global total.CertiK stated that as real-world risks become a significant challenge for digital asset security, enterprises and high-net-worth individuals need to establish more comprehensive protection systems. CertiK has launched operational security services to help identify exposure risks related to identity, family, residence, and travel routes. Simultaneously, through the CertiK Security Workspace, it correlates off-chain intelligence, on-chain transactions, and AML risk signals to support institutions in tracking and analyzing cybercrime activities. Furthermore, CertiK is strengthening cooperation with international law enforcement agencies such as Interpol and Europol, providing technical support for cross-border attack investigations and security policy research.

CLARITY Act could remove Section 604 or expose non-custodial developers to Bank Secrecy Act obligations

one year after the U.S. House of Representatives passed the Clarity for Digital Assets Act (CLARITY Act), the bill remains stalled in the Senate, facing opposition from the banking industry and partisan divisions. Supporters anticipate a potential vote before the Senate's August recess. Industry organizations Coin Center and the Blockchain Association have identified Section 604 as a key provision for protecting open-source innovation. This provision aims to prevent non-custodial blockchain developers, node operators, and validators from being classified as federal money transmitters. Stefan Muehlbauer, Head of U.S. Government Affairs at CertiK, stated that removing Section 604 could conflate software development with financial services, subjecting developers to the Bank Secrecy Act and triggering First Amendment-related constitutional challenges. Iana Dimitrova, CEO of Openpayd, noted that the expanding use of stablecoins for cross-border value transfer has made the need for a federal regulatory framework more apparent. The bill also addresses accounting standards, acknowledges the rescission of SEC Staff Accounting Bulletin SAB 121, and prohibits the SEC from reimposing equivalent crypto custody accounting requirements without a full notice-and-comment rulemaking process. Mark Zalan, CEO of Gomining, pointed out that Bitcoin still faces regulatory gaps, such as tax treatment.

DeFiTuna Suffers Attack, Losing 569,600 USDC

CertiK published an analysis stating that the Solana ecosystem protocol DeFiTuna was attacked on July 16, with losses of approximately 569,601 USDC. The attacker first created an extremely low-liquidity TUNA/USDC pool and swapped borrowed USDC into the pool via Jupiter routing. Since only a minimal amount of TUNA was ultimately obtained, the protocol experienced rounding down during the position asset value calculation, causing the total assets to be recorded as 0, thereby incorrectly passing the health and solvency checks.

CertiK Hack3D Report: Web3 Losses Exceed $1.3 Billion in the First Half of 2026, Attacks Accelerate Towards High-Value Targets

Odaily, Web3 security firm CertiK has released the "Hack3D: First Half of 2026 Report." The report shows that the Web3 ecosystem experienced 344 security incidents in the first half of 2026, with cumulative losses of approximately $1.32 billion. Although this figure represents a 46.8% decrease compared to the same period last year, excluding the impact of the $1.45 billion security incident involving Bybit, the scale of losses in the first half of this year actually increased by approximately 28% year-on-year, indicating that the overall security environment in the industry has not materially improved.The report points out that wallet theft has become the attack type causing the greatest financial loss, accounting for approximately $450 million in losses in the first half of the year. Meanwhile, although the number of phishing attacks fell by more than 50% year-on-year, the loss amount only decreased by approximately 10.8%, reflecting that attackers are shifting towards high-net-worth individuals and institutional targets, carrying out more targeted high-value attacks.Furthermore, code vulnerabilities remain the most frequent type of attack, with 204 related incidents. CertiK believes that attackers are increasingly targeting long-running legacy smart contracts that lack re-audits. The report also shows that mega-attacks continue to dominate industry losses, with the Kelp DAO and Drift Protocol incidents alone causing approximately $577 million in losses, accounting for 44% of the total losses in the first half of the year. Looking at the number of incidents, the impact of single attacks, and the changing attack patterns, the Web3 industry is facing more complex and continuously escalating security challenges.

The crypto industry suffered $68.3 million in security losses in May, a nearly 90% decrease month-on-month

data from blockchain security firm CertiK shows total losses in the crypto sector from hacks, vulnerabilities, and scams in May 2026 were approximately $68.3 million. This represents a nearly 90% decline from the over $650 million in losses recorded in April, making it the third month this year where losses fell below $100 million. Phishing attacks accounted for about $2.6 million of the losses.In April, industry losses surged due to two major attacks on Drift Protocol and KelpDAO, which together accounted for approximately 95% of the month's losses, making April one of the most devastating months for losses in recent years.The institution reminds that while large-scale protocol-level attacks have decreased, risks such as phishing, deepfakes, and credential leaks are on the rise, with the focus of attacks increasingly shifting towards personnel and identity systems. The decline in losses this time is merely due to the absence of major security incidents; the overall security risks in the industry have not been fundamentally eliminated. Cross-chain bridge vulnerabilities and insider threats remain primary risks. (Financefeeds)

Related news

USDD supply on TRON increases by $145 million in a single week, total supply surpasses $1.23 billion

According to data from CertiK Skynet, over the past week, the USDD supply on the TRON network increased significantly by approximately $145 million, with the total volume surpassing $1.23 billion, accounting for about 81.6% of the total USDD supply across the network. As of now, USDD's total network supply is $1.55 billion, and TVL exceeds $2.33 billion. Recently, with TRON DeFi Summer in full swing, liquidity in the TRON ecosystem has shown an explosive trend. Notably, USDD's TVL on JustLend exceeded $450 million. USDD's official Chinese account stated, "USDD's growth on TRON is unstoppable." This round of USDD growth further consolidated its leading position in the TRON ecosystem and its top status in the entire stablecoin sector.

VerusCoin Ethereum Cross-Chain Bridge Attacked, Approximately $7.53 Million Transferred Out

According to CertiK Alert monitoring, a security incident occurred on VerusCoin's Ethereum cross-chain bridge, with approximately $7.53 million in assets transferred out. Preliminary analysis indicates that this issue may be related to the cross-chain bridge failing to sufficiently verify whether the Verus chain-side input supports the paid amount, similar to an incident that occurred in May this year.

CertiK:2026 年上半年针对数字资产持有者的扳手攻击共记录 52 起,同比增长 33%

据彭博社报道,区块链安全公司 CertiK 最新报告显示,2026 年上半年全球针对数字资产持有者的暴力"扳手攻击"(即以人身威胁强迫受害者交出加密货币)事件共记录 52 起,同比增长 33%。其中法国以 33 起攻击案例独占近三分之二,成为全球最严重的受害国。报告指出,加密犯罪分子的攻击目标正从数字钱包转向现实中的持币个人,暴力手段日趋普遍。

CertiK Report: Wrench Attacks Surge Nearly 12x in Losses, “Operational Security” Becomes New Core of Prevention

Odaily Odaily News, July 22nd - Web3 security firm CertiK released its "H1 2026 Wrench Attack Report." The report indicates that a total of 52 publicly verified wrench attacks were recorded globally in the first half of 2026, a year-over-year increase of 33.3%; related losses amounted to approximately $124 million, an increase of about 11.8 times compared to the same period last year.The report notes that attackers are shifting from exploiting technical vulnerabilities to targeting asset holders and their real-world social networks. Home invasion incidents increased from 1 case in H1 2025 to 20 cases, accounting for 41% of the total incidents in the period. Europe has become a high-incidence area for attacks, with 33 cases occurring in France alone, representing 63.5% of the global total.CertiK stated that as real-world risks become a significant challenge for digital asset security, enterprises and high-net-worth individuals need to establish more comprehensive protection systems. CertiK has launched operational security services to help identify exposure risks related to identity, family, residence, and travel routes. Simultaneously, through the CertiK Security Workspace, it correlates off-chain intelligence, on-chain transactions, and AML risk signals to support institutions in tracking and analyzing cybercrime activities. Furthermore, CertiK is strengthening cooperation with international law enforcement agencies such as Interpol and Europol, providing technical support for cross-border attack investigations and security policy research.

CLARITY Act could remove Section 604 or expose non-custodial developers to Bank Secrecy Act obligations

one year after the U.S. House of Representatives passed the Clarity for Digital Assets Act (CLARITY Act), the bill remains stalled in the Senate, facing opposition from the banking industry and partisan divisions. Supporters anticipate a potential vote before the Senate's August recess. Industry organizations Coin Center and the Blockchain Association have identified Section 604 as a key provision for protecting open-source innovation. This provision aims to prevent non-custodial blockchain developers, node operators, and validators from being classified as federal money transmitters. Stefan Muehlbauer, Head of U.S. Government Affairs at CertiK, stated that removing Section 604 could conflate software development with financial services, subjecting developers to the Bank Secrecy Act and triggering First Amendment-related constitutional challenges. Iana Dimitrova, CEO of Openpayd, noted that the expanding use of stablecoins for cross-border value transfer has made the need for a federal regulatory framework more apparent. The bill also addresses accounting standards, acknowledges the rescission of SEC Staff Accounting Bulletin SAB 121, and prohibits the SEC from reimposing equivalent crypto custody accounting requirements without a full notice-and-comment rulemaking process. Mark Zalan, CEO of Gomining, pointed out that Bitcoin still faces regulatory gaps, such as tax treatment.

DeFiTuna Suffers Attack, Losing 569,600 USDC

CertiK published an analysis stating that the Solana ecosystem protocol DeFiTuna was attacked on July 16, with losses of approximately 569,601 USDC. The attacker first created an extremely low-liquidity TUNA/USDC pool and swapped borrowed USDC into the pool via Jupiter routing. Since only a minimal amount of TUNA was ultimately obtained, the protocol experienced rounding down during the position asset value calculation, causing the total assets to be recorded as 0, thereby incorrectly passing the health and solvency checks.