About CertiK

Building the Trust Infrastructure for the Digital Economy

Security and compliance, built in from the start and sustained across the digital asset lifecycle.

Brand film

The journey of trust, moving forward together.

Our story

The internet moved information. Digital assets move value.

But there is a fundamental difference between a network for information and a network for value.

When information is compromised, it can often be recovered. When value is compromised, the loss may be irreversible.

As digital assets become part of the global economy, security and compliance must move beyond one-time checks and extend across the entire lifecycle.

CertiK is building the trust infrastructure for this new economy through formal verification, AI-driven security, continuous risk monitoring, and global compliance capabilities.

CertiK also advocates for greater transparency in security practices, including the publication of full audit reports. Transparency is a foundation for trust.

Where we’re headed

To become the global risk management and trust platform for the digital economy, enabling value to move securely and reliably at scale.

Origins

Built on formal verification research.

  • Why CertiK exists

    CertiK was founded in 2017 on the belief that security and compliance must be built into digital asset systems from the very beginning.

    That is why CertiK brings together formal verification, security auditing, continuous monitoring, risk intelligence, and compliance capabilities within a unified risk management framework.

    Our goal is not simply to identify vulnerabilities. It is to reduce risk exposure across the digital asset lifecycle, moving organizations from reactive patching toward proactive and continuous risk management.

  • Our technology foundation

    CertiK grew out of breakthroughs in formal verification achieved by professors from Yale University and Columbia University.

    Formal verification rigorously proves that software behaves as specified. It has long been used in aerospace and chip design, and CertiK was among the first to apply it to digital assets at scale.

    Since 2017, CertiK has built one of the industry's largest Web3 security knowledge bases. This body of security data, research, and real-world experience provides the foundation for the next generation of AI-powered security systems.

A consistently leading share of the global Web3 security market.

Vulnerability findings
0+
Research and analysis published
0+
Clients served
0+
Digital assets assessed
$0B+
Countries and regions covered
0+

Regulatory contributions

Contributing to digital asset policy across jurisdictions.

0+ jurisdiction consultations

The growth of the digital economy requires more than technological innovation. It also requires regulatory trust, institutional participation, and industry collaboration.

That is why CertiK works with regulators, financial institutions, ecosystem builders, and developer communities around the world.

  • Monetary Authority of Singapore Technology advisory panel
  • Hong Kong SAR Web3 Development Task Force Policy contributions
  • Abu Dhabi Global Market Stablecoin policy dialogue
  • Financial Services Agency Technical collaboration
  • Busan Digital Asset Exchange Security cooperation
  • Members of the U.S. Congress Industry dialogue
  • National Bank of the Kyrgyz Republic Memorandum of understanding
  • UN Global Fraud Summit 2026 Fraud prevention commitment

Industry recognition

  • CB Insights Top 50 Blockchain Companies
  • World Economic Forum Global Innovator
  • Mental Health America's Bell Seal at the Gold level

Security & compliance credentials

  • SOC 2® Type II Compliance
  • ISO 27001 Certification

CertiK Brand Guidelines

Logos, visual assets, and guidance for consistent use.

CertiK

Our team

A global team of researchers, engineers, and security experts.

Leadership

Business team

  • Danni Liu Business Development Director
  • Xuesong Ma Sr. BD Manager
  • Mikhail Yerganjiev Sr. BD Manager
  • Nurtilek Taalaibekov Head of EU BD
  • Angus Lee Business Development Director
  • John Kiew Business Development Manager
  • Magnus Chung Business Development Manager
  • Joe Suzuki Business Development Manager
  • Chenglong Ji BD Representative
  • Lakshya Kanyakubja BD Representative
  • Pedro Araujo BD Manager

FAQ

Common questions about CertiK.

  • Founded in 2017 and headquartered in New York, CertiK is the largest Web3 security services provider. Based on breakthroughs in formal verification technology achieved by professors from Yale University and Columbia University, CertiK focuses on providing the most comprehensive security protection for digital assets.

    Over the years, CertiK has grown into a trusted risk management partner for global regulators, institutions, and Web3 innovative enterprises, and is committed to building the trust infrastructure for the digital economy.

  • CertiK helps clients identify, manage, and mitigate risk across the digital asset lifecycle, shifting security and risk management from reactive patching to proactive governance.

    CertiK’s core products include Skynet, a risk decision platform for digital asset research, token listing risk assessment, and continuous monitoring; CertiK Compliance, which supports licensing, AML, and ongoing compliance operations; and CertiK Supervision, which helps regulators continuously monitor licensed entities, digital assets, and related risks. CertiK also provides AI Auditor for automated Web3 code security analysis, CertiK Prover for formally proving that critical code properties hold, and CertiK Hunt, its bug bounty platform and security researcher network.

    These products are complemented by expert services including Smart Contract Audit, Chain Audit, Penetration Testing, Expert Formal Verification, Proof of Reserves, Validator Services, and Advisory & Consulting.

    Together, these capabilities enable CertiK to address risk across different stages of the digital asset lifecycle, from code development and pre-launch security validation to continuous asset monitoring, AML and compliance operations, regulatory supervision, and ongoing infrastructure security.

  • Formal verification is at the core of CertiK’s technical foundation. Building on formal verification research from Yale University and Columbia University, CertiK brings mathematically provable security into real-world, production-grade code through engineering-driven automation, spanning complex systems including smart contracts, protocol layers, and zero-knowledge proofs.

    CertiK’s formal verification capabilities have been deployed across multiple leading Web3 ecosystems, including zkWasm, TON, and Move-based projects. Beyond Web3, these technologies are also applied to foundational infrastructure such as Ant Group’s HyperEnclave TEE, the Asterinas operating system, and the SGX TRTS SDK.

    Concurrently, CertiK has improved the efficiency of formal verification by integrating AI into its proprietary CertiK Prover engine. This technological breakthrough was published in OSDI 2023 and ASPLOS 2026, two top-tier computer science academic conferences, and honored with the ASPLOS 2026 Best Paper Honorable Mention award.

  • CertiK was co-founded by Prof. Ronghui Gu of Columbia University and Prof. Zhong Shao of Yale University, two computer science professors whose research spans formal verification, cybersecurity, operating systems, and certified software.

    Prof. Ronghui Gu is Co-Founder and CEO of CertiK and an Associate Professor of Computer Science at Columbia University. He is a primary designer and developer of CertiKOS, and serves as an International Technology Advisor to the Monetary Authority of Singapore (MAS). He also served as an inaugural member of Hong Kong’s Task Force on Promoting Web3 Development.

    Prof. Zhong Shao is the Thomas L. Kempner Professor at Yale University. Together with his Yale FLINT group, he developed CertiKOS, the world’s first hacker-resistant and concurrent operating system.

  • CertiK serves more than 5,500 enterprise and institutional clients and its services cover more than 150 countries and regions worldwide. The company has assessed more than $600 billion in digital assets and discovered more than 119,000 security vulnerabilities.

    Based on 2024 statistics, CertiK holds approximately 65% of the global market share.

  • Since its inception, CertiK has secured investments from 12 top-tier funds, including Binance, Sequoia, Hillhouse, Goldman Sachs, and SoftBank Vision Fund, with a valuation of more than $2 billion.

  • CertiK has worked with more than 5,500 enterprise clients including Binance, Ant Group, and numerous leading banks in Europe and Singapore. It also works closely with regulators, actively participating in digital asset policy development across multiple jurisdictions, including the United States, Hong Kong, Singapore, the UAE, South Korea, Brazil, the UK, and the EU.

  • CertiK is applying AI to move security earlier in the development lifecycle through AI Auditor, its AI-powered smart contract security analysis product. AI Auditor embeds security intelligence directly into development workflows, helping teams identify vulnerabilities before deployment and strengthen audit verification with high signal and low noise.

    Rather than relying on a single model or static training data, AI Auditor combines multiple AI scanners and agents with continuously evolving security intelligence drawn from real-world exploits, audit findings, and emerging attack patterns. Its multi-stage validation process cross-checks findings, filters duplicates and false positives, and helps teams focus on the issues that matter most. The system can also adapt its scanning scope and analysis depth to different codebases and risk profiles.

    AI Auditor is designed to complement, rather than replace, expert security audits. By surfacing vulnerabilities earlier and turning raw findings into prioritized, actionable results, it allows security teams and auditors to focus their expertise where it has the greatest impact.

  • CertiK Reports are CertiK’s security research and intelligence publications, built on years of real-world experience. Having discovered more than 119,000 code vulnerabilities, CertiK has translated this experience into more than 700 pieces of technical research and vulnerability analysis.

    • Hack3D Reports. Security research and incident data from CertiK. Quarterly and annual Hack3D reports tracking exploits, vulnerabilities, and losses across Web3.
    • Intel3D Reports. Web3 security intelligence from CertiK Skynet, reporting on fraud, threats, ecosystem risk, and emerging security trends across the digital asset landscape.
    • CertiK Blog. Security research, regulatory insights, and data-backed analyses for the institutional Web3 era. Turning real-world signals into actionable intelligence.
    • Security Dashboard. A continuously updated data dashboard providing visibility into Web3 security incidents, losses, attack types, and evolving threat trends.

    Representative publications include the CertiK Hack3D: H1 2026 Report and the CertiK Intel3D: H1 2026 Wrench Attacks Report. Findings and data from CertiK reports have been cited and covered by leading global media including Forbes and Bloomberg, as well as major crypto media outlets such as CoinDesk and Cointelegraph.

  • CertiK’s services cover more than 150 countries and regions worldwide. In key markets such as the United States, the Asia-Pacific region, Brazil, South Korea, Turkey, the UAE, and Europe, CertiK has established localized teams.

  • CertiK maintains SOC 2 Type II and ISO 27001 credentials for the platform supporting its services, reflecting its commitment to information security and operational controls. CertiK also maintains expertise across major digital asset regulatory frameworks, including ADGM, FSC, MiCA, and MAS, helping institutional clients stay aligned with evolving regulatory requirements.

  • CertiK’s compliance solutions primarily serve financial institutions, digital asset businesses, virtual asset service providers (VASPs), and regulators.

    For institutional clients, CertiK Compliance brings together counterparty and asset ratings, licensing-readiness assessments, threat intelligence, AML screening, fund tracing, and compliance reporting. It helps clients identify compliance gaps before entering regulated markets and continuously monitor security and compliance risks throughout their operations. The platform’s monitoring capabilities cover more than 20 blockchains, draw on over 400 million address labels, and have identified more than 3,000 security incidents.

    For regulators, CertiK Supervision provides a jurisdiction-wide view of digital asset risk. It enables unified monitoring of VASPs, tokens, wallets, and transactions, while assessing regulated entities across on-chain activity, AML and sanctions risks, and cybersecurity. The system can also turn risk alerts into investigation cases and inspection-ready reports, with rules, risk thresholds, risk categories, and reporting requirements configurable to different regulatory frameworks. The platform currently monitors more than 200 licensed VASPs and over 17,000 tokens.

    CertiK also provides security consulting and risk management support across institutional digital asset use cases, including stablecoins, RWAs, and other blockchain-based applications.

  • Founded in December 2017, CertiK is the largest Web3 security service provider and the trusted risk management partner for global regulators, institutions, and Web3 innovative enterprises.

    Since 2020, CertiK has detected more than 119,000 code vulnerabilities, assessed over $600 billion in digital assets, and translated these experiences into more than 700 technical research papers and vulnerability analyses.

    Based on 2024 statistics, CertiK holds approximately 65% of the global market share.

    CertiK became the first Web3 security company to achieve SOC 2 Type I and II assurance for the platform supporting its services, which also holds ISO 27001 certification.

    In 2024, CertiK received public acknowledgments from 12 global tech giants, including Apple, Alibaba, ByteDance, and Xiaohongshu (RedNote), within two months for identifying critical vulnerabilities.

    CertiK engineers were recognized for their outstanding security contributions, with one added to the Ledger Hall of Fame in 2025 and others honored in the Samsung Mobile Security Hall of Fame for 2023.

    In 2025, CertiK received two research grants in the zkEVM formal verification competition organized by the Ethereum Foundation.

    In 2026, CertiK identified two security vulnerabilities in Google's EdgeTPU: CVE-2026-0150 and CVE-2026-0153. Both flaws have been acknowledged by Google and included in the June 2026 Security Bulletin.

  • Build the trust infrastructure for the digital economy.

Tell us what you are building.