CertiK joins Linux Foundation initiative to strengthen blockchain security

By: crypto.news|09/24/2026 13:00:00

CertiK has joined LF Decentralized Trust, the Linux Foundation initiative for open source decentralized technologies, as the blockchain security firm plans to contribute research and audit expertise to projects used across enterprise and institutional systems.

  • CertiK has joined LF Decentralized Trust to contribute security research, formal verification and audit expertise to open source blockchain projects.
  • The company plans to participate in LFDT projects and working groups focused on enterprise and institutional decentralized infrastructure.
  • CertiK said security audits are now required directly or indirectly across several major crypto markets, while AML related fines and settlements topped $900 million in the first half of 2025.
  • The membership follows CertiK's earlier security research on LFDT hosted Ethereum client Besu, where researchers identified five vulnerabilities that were later patched.

According to CertiK's announcement shared with crypto.news, the company joined LF Decentralized Trust, or LFDT, as part of a new group of members entering the organization this quarter. LFDT develops open source infrastructure for decentralized systems across finance, banking, supply chains, healthcare and telecommunications.

CertiK plans to take part in LFDT open source projects and working groups, bringing experience in blockchain security, formal verification and auditing to the community. The company said it would work alongside enterprises, startups and technical teams developing interoperable decentralized infrastructure.

The membership follows previous work between CertiK researchers and Besu, an Ethereum execution client hosted by LF Decentralized Trust. In August, CertiK disclosed independent research that uncovered five vulnerabilities affecting Besu, including resource exhaustion issues capable of disrupting node availability.

As crypto.news previously reported, Besu patched all five CertiK reported vulnerabilities in version 26.7.1 on July 27 before technical advisories were made public on Aug. 14. The flaws affected peer to peer, RPC, WebSocket and consensus facing interfaces.

CertiK plans to bring security research into LFDT projects

LF Decentralized Trust operates as a vendor neutral community within the Linux Foundation, providing governance and development support for open source decentralized technologies. Its projects include Besu and other infrastructure designed for enterprise deployments.

CertiK said its membership would put its security research closer to the development process for systems being built by financial institutions, enterprises and governments.

"Security and compliance can't be treated as one-off exercises bolted on late in a project's lifecycle anymore; that's exactly the kind of thinking the current regulatory environment is punishing," CertiK co founder and CEO Ronghui Gu said.

Gu said open, vendor neutral and standards driven infrastructure had become central to how enterprises build blockchain systems. CertiK expects to contribute formal verification and security expertise directly to LFDT development work and participate in community and industry activities.

LFDT Executive Director Daniela Barbosa said contributions from security researchers could support the development and deployment of the organization's open source projects.

"The industry needs infrastructure that's built to standards from the start, not adapted to them after the fact," Barbosa said.

LFDT has continued adding organizations and projects during 2026. OpenWallet Foundation announced in September that it would move under LFDT from Jan. 1, 2027, bringing open source wallet and credential development into the organization. Linea became a premier LFDT member in May and contributed the Linea Stack as an open source project, while LFDT announced another 10 members in April.

CertiK membership follows earlier work on Besu security

CertiK's relationship with technology housed under LFDT predates its membership.

During independent research on Besu, the company deployed a private multi node testnet and used controlled adversarial testing to examine how the client handled hostile conditions. Researchers identified five vulnerabilities capable of degrading or crashing nodes through interfaces available under affected configurations.

The findings covered areas including block announcement processing, consensus proposals, WebSocket subscriptions and JSON RPC filters. Two were classified as Major severity issues, while the complete set ranged from Minor to Major.

CertiK privately disclosed the vulnerabilities to the Besu team and supplied proof of concept testing tools. Besu released version 26.7.1 with fixes on July 27 and published four security advisories covering the five findings on Aug. 14.

Besu supports both public Ethereum networks and enterprise private networks. The Java based execution client provides JSON RPC and plugin interfaces and has been used in institutional blockchain infrastructure.

Its enterprise footprint has continued to grow. The Linux Foundation said in July that Depository Trust & Clearing Corporation was using Besu for an AppChain supporting its tokenized collateral infrastructure. DTCC had begun limited production trades involving tokenized Russell 1000 equities, major exchange traded funds and U.S. Treasuries, with more than 50 firms participating.

Regulatory pressure has put audits and AML controls in focus

CertiK tied its LFDT membership to regulatory requirements facing digital asset companies across major markets.

The company's Skynet State of Digital Asset Regulations research found that independent smart contract audits had become mandated or indirectly required for licensing and token admission across several jurisdictions, including Hong Kong, the UAE and the EU, along with some U.S. state frameworks.

CertiK's research further found that anti money laundering enforcement had become a major source of regulatory penalties for crypto companies. AML related fines and settlements exceeded $900 million during the first half of 2025, according to the firm's regulatory analysis.

Rules applying to exchanges, custodians and issuers have meanwhile incorporated requirements common in traditional financial services, including capital adequacy, asset segregation, liquidity management and operational resilience.

CertiK said the regulatory environment had moved security and compliance closer to the development stage for blockchain infrastructure, creating demand for systems designed around technical and regulatory standards from the outset.

-- Price

--
--
--

CertiK has expanded work with public sector institutions

The LFDT membership follows CertiK's move into security work involving central banks and government backed digital asset infrastructure.

On Sept. 14, CertiK announced a memorandum of understanding with the National Bank of the Kyrgyz Republic covering the country's Digital Som project. The partnership includes work related to the security of the central bank digital currency as well as anti money laundering and counter terrorism financing oversight for digital assets.

CertiK said its services span blockchain infrastructure assessments, smart contract audits, formal verification, penetration testing, custody architecture reviews, system performance evaluations and compliance support.

The company was founded in 2017 and says it has worked with more than 5,500 enterprise clients. Its security research has covered smart contracts, blockchain infrastructure, DeFi exploits and threats targeting digital asset systems.

Under the LFDT membership, CertiK plans to participate in open source projects and working groups while contributing security research and audit experience as opportunities become available.

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

You may also like

iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:[email protected]
VIP Program:[email protected]