THE SECURITY FILE
SEP 2026: zkWasm verification research announced · Digital Som cooperation framework signed · LF Decentralized Trust membership

Company / Crypto security Proof / Trust / Risk

CertiK and the expensive art of being certain

Two computer scientists brought mathematical proof to crypto security. CertiK’s harder assignment is teaching a market that an audit is the beginning of trust, rather than the end of doubt.

A smart contract can obey every instruction it has been given and still produce a disaster. The instructions may be wrong. The person holding the administrator key may be compromised. The website asking for a wallet signature may be an impostor. For a company selling certainty, this is an awkward opening proposition. For CertiK, it is also the reason the business has grown beyond checking code.

The useful version / 30 seconds
  • What it sells: code audits, mathematical verification, infrastructure testing and ongoing risk intelligence.
  • Who buys: blockchain builders, exchanges, wallets and institutions. Ordinary users can read public reports and Skynet profiles.
  • What to remember: the review has a scope. A badge does not erase unresolved findings or protect stolen keys.

Two professors and a very literal promise

CertiK dates its founding to December 2017. Its founders, Zhong Shao of Yale and Ronghui Gu of Columbia, came from computer science research rather than the usual crypto procession of trading desks and token launches. Their work included CertiKOS, an operating-system project built around formal verification. The ambition was unusually concrete: make claims about software that a machine can check.

Most testing asks whether a program behaves correctly in selected circumstances. Formal verification starts by writing down a property precisely, then proving that the modeled system satisfies it under stated assumptions. Think of a token transfer: can the accounting obey its rules for every covered execution, including the troublesome corner cases? A proof makes that question answerable with more than a collection of successful demonstrations.

CertiK co-founder and CEO Ronghui GuCertiK co-founder Zhong Shao
The professors brought their homework. Ronghui Gu, left, and Zhong Shao turned systems-verification research into a business inspecting software that moves money. Portraits: CertiK.

That is useful expertise for a market in which a software error may empty a pool of funds. CertiK’s verification work extends beyond token contracts: its published examples include TON’s Masterchain contract, the Cosmos SDK Bank module and Ant Group’s HyperEnclave. The underlying idea travels across systems, even when the engineering does not.

There is a catch, and it is the catch worth keeping. A proof establishes specified properties within its model. Choose an incomplete specification and an important danger may remain outside the result. CertiK’s own audit offering makes formal verification an optional additional step alongside manual review and automated analysis. “Audited” and “formally verified” describe different work.

The buyer pays. The public reads.

CertiK has two audiences. A project team commissions the security work. A prospective user reads its evidence. One wants weaknesses found before launch; the other wants to know whether connecting a wallet is sensible. The company’s business sits between these interests, with a report doing double duty as an engineering document and a public signal.

The audit report is where that arrangement becomes useful. Findings receive severity classifications and suggested fixes. A corrected issue is marked resolved. An acknowledged issue can remain unresolved, accompanied by an explanation. That distinction is less decorative than a badge and considerably more informative. It lets a reader see what the reviewer found and what the customer chose to do.

Skynet organizes the public side. It combines project profiles, security ratings, token risk analysis, leaderboards and monitoring. Its product page reports more than 17,000 projects monitored and over 1.8 million monthly active users. Those are company-reported platform figures; a monitored project is not automatically a paying audit customer.

The audience is larger than the client list17,000+

Projects monitored on Skynet, according to CertiK’s product page. Monitoring coverage is a different measure from completed audits.

The score is assembled from several kinds of evidence, including code security, operational resilience and governance. This breadth explains both its appeal and its limits. A convenient number compresses information that deserves examination. CertiK’s methodology says that no score can guarantee immunity from security incidents. Treat the rating as a route into the details.

Other products address other doors. Penetration testing examines applications, APIs, networks and cloud infrastructure. KYC checks project-team identities. SkyInsights labels blockchain addresses and analyzes transaction risk for exchanges, custodians and compliance teams. A sound contract does little to protect a careless frontend or explain suspicious money movements.

The commercial model combines scoped professional services with software and data tools. Teams request quotes for audits and testing; the public audit page does not offer one universal fee. Price comparisons therefore need an agreed scope: which contracts, which version, which infrastructure and whether custom verification is included. A cheap review of the wrong thing is an expensive souvenir.

OpenZeppelin, Trail of Bits and Hacken offer alternatives in smart contract security. Formal methods also exist outside CertiK. Its distinctive proposition is the combination of research-heavy verification, a public intelligence platform and a wider service menu. A buyer should compare the proposed work and the specialists doing it, rather than conduct a beauty contest among logos.

The $3 million lesson in manners

In June 2024, CertiK researchers found a flaw in Kraken’s deposit system. Kraken said nearly $3 million had been withdrawn through the vulnerability. The exchange and CertiK disputed how the research and disclosure had been handled. Kraken subsequently confirmed the funds were returned, minus a small amount lost to fees.

The technical discovery mattered. So did the conduct surrounding it. In its August statement, CertiK acknowledged “errors in judgment” and poor communication. It said it had worked with outside counsel to improve internal processes so bug bounty operations would follow industry best practices. The public dispute supplied a very practical reason to change procedures.

“errors in judgment”

CertiK’s own description of its conduct in the Kraken episode, August 2024

This was a failure of judgment and communication around a successful vulnerability discovery, by CertiK’s own account. The reported sum describes funds withdrawn and later returned; it does not establish a final financial loss to Kraken or a published cost to CertiK. The lesson is procedural: permission, testing boundaries, escalation and repayment handling belong in security work before anyone touches a live system.

Certainty moves upstream

Investors had already made a substantial bet on this business. An $88 million Series B3 announced in April 2022 valued CertiK at $2 billion. Insight Partners, Tiger Global and Advent International co-led it, with Goldman Sachs among the participants. Two weeks later, CertiK announced another $60 million from SoftBank Vision Fund 2 and Tiger Global. The valuation belongs to that financing moment; it is not a fresh appraisal.

April 2022 / disclosed investment
Series B3
$88m
Additional
$60m

Two announcements, fifteen days apart. Dollars invested, not revenue.

By April 2026, CertiK was putting more review into the development process itself. It announced AI Auditor, originally an internal tool, alongside open-source integrations for AI coding agents. Specialized scanners work in parallel and draw on an evolving knowledge base of exploits and findings. The intended jobs include pre-deployment review, upgrade comparisons and pre-audit triage. Human auditors still have a role in complex and unfamiliar risks.

September brought a reminder of the academic thread. CertiK announced machine-checked proofs for zkWasm, using the Coq proof assistant to reason about circuit logic. It reported that the work had been accepted at ACM CCS 2026. Here the question is especially consequential: can a system accept a convincing proof of a computation that was actually wrong? Verification targets the machinery on which other assurances depend.

The audience is widening, too. On September 9, 2026, CertiK and the National Bank of the Kyrgyz Republic signed a memorandum concerning Digital Som security and digital asset oversight. The framework covers potential cooperation on verification, resilience and related risk work. It is a cooperation framework, with deployment of supervisory tools still exploratory. CertiK also announced membership in LF Decentralized Trust that month.

Read the finding, then read the fine print

For a builder, the useful sequence starts early: define what must be protected, agree the review scope, fix findings and check that the deployed code matches what was reviewed. Bring application and custody controls into the conversation. Continue monitoring when the system changes. CertiK’s catalogue makes sense when each service answers a particular question, rather than when every service becomes another badge.

For a user, the copyable habit is simpler. Open the report. Look for major findings and their resolution status. Check the reviewed version and administrator powers. Use Skynet to explore risk signals over time. These tools are less useful when the deployed system has changed, the relevant threat sits outside the review or a team declines to repair a known weakness.

CertiK’s story begins with the appealing idea that software claims can be proved. It has grown into a business surrounded by people, permissions and institutions. A machine-checked theorem remains valuable. Knowing exactly what the theorem promises is how that value survives contact with a wallet.