Full-Time
Blockchain security audits and ongoing monitoring
$120k - $180k/yr
Remote in USA
Remote
See people who can refer or advise you
CertiK is a security-focused platform that analyzes and monitors blockchain protocols and DeFi projects to improve their safety. It provides security audits, penetration testing, and continuous monitoring services for smart contracts and blockchain apps. The main products include ongoing monitoring tools like Skynet and SkyTrace, which are offered via subscriptions to help track threats and detect fraud in real time. Compared to competitors, CertiK emphasizes its role as a premier security-ranking platform with specialized audits and continuous surveillance, aiming to deliver ongoing protection rather than one-time checks. The company’s goal is to help blockchain developers, DeFi projects, and cryptocurrency platforms reduce smart contract vulnerabilities and prevent fraudulent activity by strengthening their security posture.
Company Size
201-500
Company Stage
Series B
Total Funding
$300.2M
Headquarters
New York City, New York
Founded
2018
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Medical, vision, and dental insurance
401(k) plan with company matching
Life and accidental death and dismemberment insurance
HSA (with high deductible plan)
FSA
Flexible paid time off
Holidays
CertiK Director Lau advances AI as net positive despite risks. In response to recent events where AI agents escaped their sandboxes and attacked real-world targets, Kaijern Lau, Senior Director of Engineering at CertiK, believes the industry must prepare by increasing its investment in AI security as the blockchain industry becomes intertwined with AI. Key takeaways. * An AI agent hacking Hugging Face proves autonomous cyber warfare is real, urging Web3 to adopt AI security. * While AI speeds up finding vulnerabilities, human experts must still verify their actual impact. * CertiK is developing defensive tools like AI Auditor to counter automated attacks and secure Web3 projects. CertiK's Kaijern Lau: AI will be positive for Web3 security, but also A 'double-edged sword' The world of blockchain security and auditing is rapidly changing as exploits and vulnerabilities are now being harnessed and discovered much faster due to the involvement of artificial intelligence (AI) in vulnerability discovery processes. Generalized concerns about the risks of the rising role of AI in these activities have risen with the Hugging Face incident, where an AI platform suffered a hack, which was the first intrusion "driven, end to end, by an autonomous AI agent system." The occurrence, later blamed on an OpenAI model escaping its testing sandbox, confirmed that agent-driven cybersecurity warfare is a reality and that institutions need to be prepared to face these risks now, not tomorrow. Concerns have also reached the Web3 ecosystem, where security is more passive than active, managed by audits and security considerations designed during the production phases and that oftentimes cannot be upgraded in real time before deploying new contracts. In an exclusive interview with Bitcoin.com News, Kaijern Lau, Senior Director of Engineering at CertiK, examined the role of AI in both these attacks and the process of auditing code to prevent them. Lau stresses that AI can be a useful tool for identifying a vulnerability and examining potential attack vectors on a platform. Nonetheless, the involvement of a human-in-the-middle is still necessary "to ensure that the AI has analyzed the code thoroughly and to verify that any reported vulnerabilities are genuine rather than false positives." Lau declared that recent research covering hardware-wallet attack surfaces illustrates the limitations of AI and the relevance of human involvement. "AI can help surface patterns and accelerate analysis, but experienced researchers are still needed to validate the findings and assess their actual impact," he assessed. Hugging Face incident isolated, not proof of "rogue agents" Lau stressed that the Hugging Face incident arose during a specific evaluation setting and that an instance of such a contingency does not mean that AI models are uncontrollable. Even so, he pointed out that the attack highlighted the current capabilities of AI agents, which are increasingly able to execute complex cybersecurity operations, including identifying and combining weaknesses that appear manageable in isolation, such as an exposed service, a misconfiguration, excessive permissions, or compromised credentials, and turning them into a coordinated attack path at machine speed. Consequently, this also shows how investing in AI for security purposes is becoming the norm for companies with code-based products, such as the Web3 and blockchain industry. "AI will make both attackers and defenders more capable. That is why blockchain companies should invest more in AI-driven security to protect their code and infrastructure. We are entering an era where the key question is no longer whether to use AI, but how many AI resources (or tokens) organizations invest in defending their systems compared with the resources attackers invest in launching increasingly sophisticated attacks," the expert declared. AI and blockchain security: where Dock Labs AG stand. While Lau is sure that AI and blockchain security will inevitably become intertwined, he acknowledges that it is still too early for vulnerability discovery and secure software development tasks to be completed without human intervention. CertiK even considers defensive agents and its tools as part of the surface attack, as they can be probed for prompt injection, malicious tool inputs, excessive permissions, data leakage, or unsafe automated remediation. In fact, the company has designed a tool, the AI Skill Scanner, to help identify risks in AI skills before deployment, increasing the controls exerted over AI agents. Lau revealed that CertiK will continue to invest heavily to build advanced AI-powered security. "Our in-house developers and security researchers are working around the clock to advance AI-driven blockchain security," he confirmed. CertiK has also developed AI Auditor, a tool that conducts an automatic analysis of blockchain projects, identifying common security risks. "This multi-model, multi-agent approach improves both the accuracy and reliability of security assessments," said Lau, describing how the company was developing its defensive capabilities against AI-assisted actors. AI's balancing act: where Dock Labs AG go from here. While AI lowers the barriers to attack, as threat actors are already leveraging agents to discover exploits and scan smart contracts for vulnerabilities, Lau ensures there are real advantages to using AI for defensive purposes. "AI dramatically elevates our threat detection efficiency and scope. CertiK has improved the efficiency of formal verification by integrating AI into its proprietary CertiK Prover engine," Lau specified. CertiK's contribution to the space, Lau said, goes beyond detecting vulnerabilities and aims to ensure that defensive security measures stay ahead of these emerging AI threats by also training and employing its AI models to secure its customers. "Overall, AI will be a net positive force for Web3 security, but it is undeniably a double-edged sword that requires a continuous balancing act," Lau concluded. Yesterday Fear Last Week Fear Last Month Extreme Fear How do you feel about the market today?
CertiK launches CertiK Hunt, the invite-only security platform for Web3 projects and top security researchers. Published: July 02, 2026 at 5:00 am Updated: July 02, 2026 at 8:39 am Edited and fact-checked: July 02, 2026 at 5:00 am CertiK announced the launch of CertiK Hunt, an invite-only platform connecting elite security researchers with Web3 projects. CertiK, the leading Web3 security firm, today announced the launch of CertiK Hunt, an invite-only platform connecting elite security researchers with Web3 projects. Through CertiK Hunt, projects can launch bug bounty programs, audit competitions, and AI challenges, with additional features planned in future releases. CertiK Hunt is intentionally exclusive, allowing only approved security researchers to participate. This approach is designed to combat one of the biggest challenges facing bug bounty programs today: large volumes of spam and low-quality submissions. Researchers are evaluated based on their technical expertise, previous findings, track record, and reputation within the security community. Projects joining the platform are also reviewed before launching programs to help ensure a trusted environment for both researchers and participating organizations. "We've seen too many cases across the industry where security researchers submit valid vulnerabilities only to face disputes or delayed payouts," said Margarita Kadochnikova, Head of Communications at CertiK. "CertiK Hunt is built to create a trusted environment where high-quality researchers can focus on finding impactful vulnerabilities, projects receive meaningful security insights, and both sides know the rules will be applied fairly." The launch comes at a pivotal moment for Web3 security. Following another year in which billions of dollars were lost to exploits, the industry is increasingly shifting toward continuous security rather than one-time audits. As digital asset markets mature, regulatory scrutiny increases, and protocols become more complex, the cost of undiscovered vulnerabilities continues to rise. CertiK Hunt addresses this challenge by connecting experienced security researchers with projects that require continuous, high-quality security testing. "CertiK Hunt is the next step in our mission to secure the Web3 ecosystem," said Hudson Jameson, Head of Ecosystem at CertiK. "By building a network defined by signal and quality rather than volume, we are creating a platform where the best researchers can do their most impactful work, while giving projects greater confidence in the security of their code." CertiK Hunt extends the traditional security audit by providing projects with continuous, researcher-driven testing throughout the lifecycle of their applications. By combining formal audits with ongoing bug bounty programs, audit competitions, and AI-powered security initiatives, the platform helps projects strengthen their security posture long after code is deployed. Disclaimer. In line with the Trust Project guidelines, please note that the information provided on this page is not intended to be and should not be interpreted as legal, tax, investment, financial, or any other form of advice. It is important to only invest what you can afford to lose and to seek independent financial advice if you have any doubts. For further information, Mpost Media Group suggest referring to the terms and conditions as well as the help and support pages provided by the issuer or advertiser. MetaversePost is committed to accurate, unbiased reporting, but market conditions are subject to change without notice. Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance. Alisa Davidson Hot Stories by Alisa Davidson July 02, 2026 by Alisa Davidson July 02, 2026 by Alisa Davidson July 02, 2026 by Alisa Davidson July 02, 2026 by Alisa Davidson July 02, 2026 by Alisa Davidson July 02, 2026 by Alisa Davidson July 02, 2026 by Alisa Davidson July 02, 2026
FinChip partners with CertiK to establish security audit standards for AI Skills code assets trading. - CertiK, the world's leading blockchain and smart contract security firm, will provide FinChip's platform with AI Skill security scanning capability, enabling both parties to co-build a trustworthy, compliant, and secure AI Skill trading ecosystem. HONG KONG and NEW YORK, June 12, 2026 (GLOBE NEWSWIRE) - FinChip.AI, an AI infrastructure platform dedicated to AI Skill encapsulation, distribution, and circulation, today announced a strategic partnership with CertiK (Certified Kernel Tech LLC), the world's leading blockchain and smart contract security institution. Through this partnership, CertiK's AI Skill Security Scan capability will be integrated into FinChip's skill publication and operational review processes. The two organizations will jointly establish security audit standards for AI Skills as an emerging "code asset" category, creating a trustworthy, compliant, and secure trading ecosystem. As AI Agents and reusable AI Skills enter a stage of scaled distribution, the security of the Skills themselves has become critical to whether the entire ecosystem can be trusted. When AI Skills can be packaged, owned, and freely traded, the prerequisite for "assetification" is "verifiable security." FinChip, as an AI infrastructure built on blockchain and smart contracts, is dedicated to enabling AI Skill encapsulation, encryption, and distribution across the full lifecycle - from publication and discovery to application and circulation. The platform leverages programmable ownership and controllable access mechanisms to enable enforceable Skill licensing, transfer, and settlement. In this partnership, FinChip will embed CertiK's security scanning API into its Skill publication and audit workflows. Scanning results, risk scores, and risk labels will serve as important reference data for FinChip's platform review and response processes. Additionally, the two parties will launch a joint security certification badge that will be displayed on FinChip's platform frontend for audited Skills, helping users and developers more intuitively identify AI Skills that have undergone professional security assessment. "In the AI Agent era, 'capability' becomes reusable and tradeable, which means security must be foundational design, not an afterthought," said Gary Yang, Incubation Investor of FinChip.AI. "We're thrilled to partner with CertiK, an industry leader, to embed world-class security audit capabilities into every step of Skill publication - this is our most basic commitment to users and developers." "AI Skill security is much like smart contract security - standards need to be established early in the circulation phase," said Professor Ronghui Gu, CEO and Co-Founder of CertiK. "We're pleased to bring our security scanning capabilities into FinChip's ecosystem and explore new security practices in the AI era together." Both parties state that this collaboration will continue to integrate brand and technical resources, enrich real-world application scenarios, and conduct deeper exploration at the intersection of AI and Web3 security. About FinChip FinChip.AI is an AI infrastructure company built on blockchain and smart contracts, dedicated to the encapsulation, encryption, and distribution of AI value. The platform enables reusable, monetizable AI capabilities to circulate securely in an open network, facilitating collaboration between human users and Agents. FinChip covers the full lifecycle of Skill publication, discovery, application, and circulation, and provides CLI tools for Agent-autonomous operations. About CertiK CertiK is the largest Web3 security provider, trusted by over 5,000 enterprise clients to secure $600+ billion in digital assets. Founded in 2017 by professors from Yale and Columbia University, CertiK is a premier risk management partner for regulators, institutions, and Web3 innovators worldwide. As AI reshapes cybersecurity, CertiK embeds AI into the development lifecycle to help clients identify and stop risks earlier. Its end-to-end solutions include infrastructure assessments, penetration testing, smart contract audits, formal verification, and compliance support. Media Contact FinChip: [email protected] Disclaimer: This content is provided by sponsor. The statements, views, and opinions expressed in this content are solely those of the content provider and do not necessarily reflect the views of this media platform or its publisher. We do not endorse, verify, or guarantee the accuracy, completeness, or reliability of any information presented. We do not guarantee any claims, statements, or promises made in this article. This content is for informational purposes only and should not be considered financial, investment, or trading advice.Investing in crypto and mining-related opportunities involves significant risks, including the potential loss of capital. It is possible to lose all your capital. These products may not be suitable for everyone, and you should ensure that you understand the risks involved. Seek independent advice if necessary. Speculate only with funds that you can afford to lose. Readers are strongly encouraged to conduct their own research and consult with a qualified financial advisor before making any investment decisions. However, due to the inherently speculative nature of the blockchain sector - including cryptocurrency, NFTs, and mining - complete accuracy cannot always be guaranteed.Neither the media platform nor the publisher shall be held responsible for any fraudulent activities, misrepresentations, or financial losses arising from the content of this press release. In the event of any legal claims or charges against this article, we accept no liability or responsibility.Globenewswire does not endorse any content on this page. Legal Disclaimer: This media platform provides the content of this article on an "as-is" basis, without any warranties or representations of any kind, express or implied. We assume no responsibility for any inaccuracies, errors, or omissions. We do not assume any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information presented herein. Any concerns, complaints, or copyright issues related to this article should be directed to the content provider mentioned above.
CertiK has published its Skynet 2026 Stablecoin Threat Intelligence Report, identifying two major security threats: opportunistic attacks on financial infrastructure and state-sponsored sanctions-evasion networks. Bridge-related incidents totalled over $328 million in losses during the first half of 2026, with the April Kelp DAO wallet compromise accounting for $291.3 million. The report examines A7A5, a Russian-ruble-backed stablecoin launched in January 2025, which processed more than $110 billion in cumulative transactions and captured approximately 43% of the global non-USD stablecoin market within one year. Despite becoming the first cryptocurrency explicitly named in an EU transaction ban, A7A5's user base grew from 13,000 to 29,000 holders between February 2025 and May 2026. The report highlights A7A5's expansion into Africa as the most urgent unresolved enforcement gap.
CertiK and Forcerta to host institutional digital asset Security and Compliance in Istanbul. CryptoWorld May 30, 2026 Businesses 2 minutes read CertiK, the leading Web3 security services provider, announced a full-day invitation-only workshop hosted in partnership with Istanbul-based risk management firm Forcerta. Taking place on June 5, 2026, from 10 AM to 4 PM TRT(UTC+3) at the Hilton Istanbul, the event, titled The Institutional Stakes: Security and Compliance in Digital Assets, brings together a curated group of traditional financial institutions, family offices, and financial leaders for a deep-dive session on the security and compliance realities shaping institutional digital asset adoption. Agenda highlights. The workshop opens with remarks from CertiK's senior leadership and the Director of TÜBİTAK BİLGEM Blockchain Lab. Sessions across the day cover Turkey's evolving CASP regulatory framework, the current Web3 threat landscape, digital asset custody and key management, stablecoin and RWA security considerations, and institutional incident response. Speakers include Jason Jiang (CBO), Peiyu Wang (Senior Audit Partner), Uzeyir Destan and Turgay Arda Usman (Senior Security Engineers), all from CertiK. Attendance information. Seats are strictly limited and subject to host approval. Confirmed attendees will receive the boardroom details and agenda in advance. Incrypted and BeInCrypto are serving as media partners. About CertiK. Founded in 2017 by professors from Yale University and Columbia University, CertiK was built on a single conviction: that the security of blockchain infrastructure should meet the same rigorous standards applied to the most critical systems in traditional finance. Today, CertiK is one of the leading Web3 security services providers in the world, offering formal verification, smart contract audits, penetration testing, and compliance-focused security engagements to more than 5,000 enterprise clients globally. With over $600 billion in digital assets secured and more than 180,000 vulnerabilities detected, CertiK is the trusted security partner for institutions operating at the frontier of digital finance. About Forcerta. Forcerta, founded in 2016 and headquartered in Istanbul, is a trusted partner for corporations seeking to manage risk with precision and foresight. Specializing in innovative, next-generation risk solutions for the financial services industry, Forcerta designs sustainable strategies that empower traditional institutions and fintech and crypto businesses to manage risk more effectively and intelligently.