BTC $64,717.08 +0.47%
ETH $1,921.16 +0.46%
BNB $588.34 +3.25%
XRP $1.08 +0.09%
SOL $74.14 +0.39%
TRX $0.3282 +0.49%
DOGE $0.0700 -0.62%
ADA $0.1640 +0.29%
BCH $210.83 -0.52%
LINK $8.44 +0.66%
HYPE $53.11 -3.21%
AAVE $98.32 +0.31%
SUI $0.6929 +0.66%
XLM $0.1727 -0.71%
ZEC $476.04 +3.46%
BTC $64,717.08 +0.47%
ETH $1,921.16 +0.46%
BNB $588.34 +3.25%
XRP $1.08 +0.09%
SOL $74.14 +0.39%
TRX $0.3282 +0.49%
DOGE $0.0700 -0.62%
ADA $0.1640 +0.29%
BCH $210.83 -0.52%
LINK $8.44 +0.66%
HYPE $53.11 -3.21%
AAVE $98.32 +0.31%
SUI $0.6929 +0.66%
XLM $0.1727 -0.71%
ZEC $476.04 +3.46%

certik

CertiK is a blockchain security company established in 2018. The company provides end-to-end blockchain security audit services by leveraging formal verification and AI technology. In addition, the company has developed "CertiK Chain," a security-focused blockchain designed to enhance the security of smart contracts.
All
Article
Flash

CertiK: The losses from wrench attacks have surged nearly 12 times, making operational security the new core of prevention

Web3 security company CertiK released the "2026 First Half Wrench Attack Report." The report shows that in the first half of 2026, a total of 52 publicly verified wrench attack incidents were recorded globally, an increase of 33.3% year-on-year; related losses amounted to approximately $124 million, an increase of about 11.8 times compared to the same period last year.The report points out that attackers are shifting from exploiting technical vulnerabilities to targeting asset holders and their real-world relationship networks, with home invasion incidents rising from 1 in the first half of 2025 to 20, accounting for 41% of the total incidents during the same period. Europe has become a high-frequency attack region, with 33 incidents occurring in France, accounting for 63.5% of global cases.CertiK states that as real-world risks become a significant challenge for digital asset security, businesses and high-value individuals need to establish a more comprehensive protection system. CertiK has launched operational security services to help identify risks related to the exposure of information such as identity, home, residence, and travel trajectory; at the same time, through CertiK Security Workspace, it correlates off-chain intelligence, on-chain transactions, and AML risk signals to support institutions in tracking and analyzing cybercrime activities.In addition, CertiK is strengthening cooperation with international law enforcement agencies such as Interpol and Europol to provide technical support for cross-border attack investigations and security policy research.

CertiK: In the first half of 2026, Web3 losses exceeded $1.3 billion, with attacks accelerating towards high-value targets

Web3 security company CertiK released the "Hack3D: First Half of 2026 Report." The report shows that in the first half of 2026, the Web3 ecosystem experienced a total of 344 security incidents, with cumulative losses of approximately $1.32 billion. Although this figure represents a 46.8% decrease compared to the same period last year, if we exclude the impact of the $1.45 billion security incident encountered by Bybit, the loss scale in the first half of this year has actually increased by about 28% year-on-year, indicating that the overall security environment in the industry has not seen substantial improvement.The report points out that wallet theft has become the largest type of attack causing financial losses, resulting in approximately $450 million in losses in the first half of the year; meanwhile, although the number of phishing attacks has decreased by over 50% year-on-year, the amount of losses has only decreased by about 10.8%, reflecting that attackers are increasingly targeting high-net-worth individuals and institutional targets, implementing more focused high-value attacks.In addition, code vulnerabilities remain the most frequently occurring type of attack, with related incidents reaching 204. CertiK believes that attackers are increasingly targeting long-running and outdated smart contracts that lack re-auditing.The report also shows that large-scale attack incidents continue to dominate industry losses, with the Kelp DAO and Drift Protocol incidents collectively causing approximately $577 million in losses, accounting for 44% of the total losses in the first half of the year. From the perspective of incident quantity, the impact of single attacks, and changes in attack patterns, the Web3 industry is facing increasingly complex and continuously escalating security challenges.

CertiK Report: North Korean hackers caused approximately 60% of digital asset thefts by 2025, with attack patterns shifting to "offline infiltration."

Web3 security company CertiK has released the "Skynet North Korea Cyber Threat Report." The data shows that since 2016, North Korean hacker groups have plundered approximately $6.75 billion in digital assets. In 2025 alone, the losses from thefts they orchestrated reached as high as $2.06 billion, accounting for nearly 60% of the total losses in the global cryptocurrency industry for the entire year (including the $1.5 billion Bybit theft case). As of early 2026, this threat trend continues, with losses accounting for about 55%.The report emphasizes that the attack patterns of North Korean hackers have undergone a fundamental shift, evolving from simple code vulnerability exploitation to a national-level attack system that combines social engineering, deep supply chain attacks, and "physical infiltration." In the recent Drift protocol incident, attackers even spent six months lurking at offline industry conferences, establishing trust through real funds and interpersonal interactions before executing their attack.CertiK security experts warn that in the face of such systemic attacks, simple technical defenses have become weak. Cryptocurrency institutions urgently need to fully implement a "zero trust" hiring model, strengthen third-party supply chains, establish fund circuit breaker mechanisms, and collaborate with professional security organizations to build a comprehensive lifecycle defense system covering code audits, round-the-clock risk monitoring, and on-chain anti-money laundering/KYT (Know Your Transaction) fund tracking.

CertiK: Surge in crypto "wrench attacks" in 2026, Europe becomes a hard-hit area, with France being particularly prominent

According to a report by The Block, the crypto security firm CertiK released a report today indicating that in the first four months of 2026, there have been 34 confirmed cases of crypto "ransom attacks" globally (i.e., offline physical assaults and extortion targeting crypto asset holders), an increase of 41% compared to the same period in 2025, with total losses for victims amounting to approximately $101 million. If the trend continues, the total number of incidents for the year is expected to reach around 130, with losses potentially soaring to hundreds of millions of dollars.In terms of geographical distribution, out of the 34 incidents, 28 (82%) occurred in Europe, with France being particularly notable, having recorded 24 incidents in just the first four months of 2026, surpassing the total of 20 incidents for the entire year of 2025. CertiK attributes this to France's hosting of flagship crypto companies like Ledger and Binance, frequent data breaches, and a prevalent culture of "showing off wealth and doxxing" within the community. In contrast, the number of reported incidents in the United States dropped from 9 in 2025 to 3 in the first quarter, while Asia saw a decrease from 25 to 2.Regarding attack patterns, CertiK pointed out that criminal groups have shifted to a "data-driven targeting" model, reducing the need for on-site reconnaissance by purchasing victims' names, addresses, and asset information from data intermediaries. This year, over half of the incidents involved threats or direct harm to victims' family members (spouses, children, elderly parents) as a means of exerting pressure. In terms of execution, small groups of 3 to 5 individuals typically operate through

CertiK released the 2026 Global Digital Asset Regulatory Report, highlighting the intensified enforcement of anti-money laundering measures, with smart contract audits becoming a prerequisite for entry

Web3 security company CertiK released the report "2026 Digital Asset Regulatory Status," systematically outlining global regulatory trends. The report indicates that by 2026, the regulatory frameworks in major jurisdictions will have basically been established, and the industry is entering a phase of full compliance. The report shows that anti-money laundering enforcement has replaced the definition of securities attributes as the primary regulatory risk, with global anti-money laundering-related fines exceeding $900 million in the first half of 2025, and transaction monitoring capabilities becoming a core compliance requirement.At the same time, smart contract security audits are evolving from industry best practices to entry requirements, becoming essential for license approval and token listings. Additionally, global stablecoin regulatory frameworks are becoming more consistent, generally establishing principles such as full reserves and licensed issuance; however, differences in cross-jurisdictional regulation still pose compliance challenges. The report points out that with regulatory convergence and strengthened enforcement, the industry has entered the "strong compliance era." CertiK states that the core issue facing enterprises is shifting from "Are we compliant?" to "Can we quickly build and implement compliance capabilities?" Licensing in multiple regions, investments in anti-money laundering, and ongoing security audits are becoming the foundational thresholds for institutional development.
app_icon
ChainCatcher Building the Web3 world with innovations.