On-chain activity
Skynet
Skynet is a real-time security monitoring with on-chain and off-chain data analysis, providing security scores and risk assessment for Web3 projects. The system aggregates blockchain data while maintaining comprehensive project evaluation through continuous monitoring infrastructure.
CertiK Security Suite
The CertiK Security Suite provides blockchain security through smart contract audits, KYC verification, formal verification, penetration testing, and real-time monitoring, helping Web3 projects maintain robust security from development through deployment and operations.
SkyInsights
SkyInsights is an AML/CFT compliance monitoring with real-time transaction analysis, providing risk assessment and regulatory reporting for virtual asset service providers. The system processes blockchain transactions while maintaining compliance workflow integration through structured labeling and scoring.
Certik
CertiK is the largest Web3 security platform, built on the premise that blockchain projects cannot earn user trust without rigorous, independently verified security. Founded in 2017 by Ronghui Gu, a professor at Columbia University, and Zhong Shao, a professor at Yale University, CertiK brings the discipline of formal verification — a mathematical technique used in aerospace and critical infrastructure — into the blockchain security space. The company is headquartered in New York and has grown into one of the most recognized security firms in the crypto industry.
What CertiK Does
CertiK's core offering is the security audit: a structured, expert-led review of a project's smart contract code, infrastructure, and protocol logic to identify vulnerabilities before they are exploited. But CertiK goes well beyond the point-in-time audit. Its platform integrates static analysis, automated tooling, manual expert review, and formal verification methods — combining computer science rigor with real-world threat intelligence — to give a comprehensive picture of a project's security posture.
Formal verification, a key differentiator, allows CertiK to mathematically prove that a smart contract behaves as specified under all possible inputs. Where traditional audits find known vulnerability patterns, formal verification can demonstrate correctness properties that no fuzzer or code review alone can guarantee.
Product Suite
Smart Contract Audits remain the flagship product, covering Solidity contracts on Ethereum, Rust programs on Solana, and code across more than a dozen other chains. Audits cover logic flaws, access control, reentrancy, integer overflow, and protocol-level design weaknesses.
Skynet is CertiK's continuous on-chain monitoring platform, extending security beyond the initial audit. Skynet tracks live contract behavior, governance actions, token movements, and anomalous on-chain activity, alerting projects and the public to emerging threats in real time. CertiKAlert, the project's public threat intelligence account on X, surfaces active exploits and suspicious transactions as they happen — including cross-chain bridge attacks, wallet drains, and mixer activity tied to ongoing incidents.
SkyInsights targets compliance and institutional risk. It provides AML screening, transaction monitoring, sanctions compliance, and risk scoring for exchanges, custodians, and asset managers navigating regulatory environments such as the EU's MiCA framework, Dubai's VASP licensing requirements under VARA, and the EU's DORA operational resilience rules. CertiK also offers Proof of Reserves audits for exchanges seeking independent verification of their asset backing.
CertiK Hunt is the company's invite-only bug bounty platform, connecting vetted security researchers with projects willing to pay for vulnerability disclosures before attackers find them.
CertiK AI Auditor, launched in April 2025, brings real-time vulnerability detection directly into the development workflow. The tool analyzes Solidity, Vyper, and Rust smart contracts inline as developers write code, surfacing issues before they reach the audit or deployment stage.
Solana Ecosystem
CertiK has a meaningful footprint in the Solana ecosystem through both project audits and protocol-level security research. In February 2026, CertiK researchers disclosed a critical denial-of-service vulnerability in Solana's core architecture. The flaw resided in the big_mod_exp syscall — a built-in function handling large-number modular exponentiation — where the compute unit cost was benchmarked in bytes rather than bits, causing the system to budget roughly 8,043 compute units for operations that actually required approximately 508,400. An attacker could have deployed programs to repeatedly invoke this oversized function, stalling legitimate validator throughput at minimal cost. Following CertiK's responsible disclosure, the Solana Foundation re-benchmarked the operation and deployed a patch. CertiK also tracks Solana-specific incidents in its published research, including the July 2026 DefiTuna liquidity pool manipulation that drained $569,601 in USDC on Solana.
Scale and Track Record
CertiK has raised approximately $290 million across nine funding rounds from investors including Sequoia Capital, SoftBank Vision Fund 2, Tiger Global, Goldman Sachs, Binance, Coinbase Ventures, and Lightspeed Venture Partners. The company reports approximately $360 billion in value guarded across its audit and monitoring portfolio.
CertiK publishes the Hack3D series of security reports, providing industry-wide loss tracking across chains. Its H1 2026 report documented $1.31 billion in losses across 344 incidents. Wallet compromise was the costliest attack category at $444.5 million across 33 incidents, while code vulnerabilities were the most frequent at 204 cases. Phishing volume fell 52% year-over-year, but losses declined only 11%, reflecting a shift toward high-value targeted attacks on institutions and wealthy individuals. Solana suffered $315 million in losses during the period, driven primarily by the Drift Protocol breach.
The company holds SOC 2 Type II certification and ISO 27001 certification, reflecting enterprise-grade internal security standards. CertiK has been recognized by Cybersecurity Ventures as a "Company to Watch," named a Global Innovator by the World Economic Forum, and included in CB Insights' top blockchain companies list.
Team
CertiK's leadership combines academic computer science with industry security expertise. Ronghui Gu serves as Co-founder and CEO. CTO Dr. Kang Li previously served as Chief Security Scientist at Baidu. Chief Security Scientist Alexey Malanov comes from Kaspersky. The firm draws staff from top research universities and major technology companies globally.
Strategic Direction
CertiK's 2025-2026 roadmap emphasizes two major technical bets: zero-knowledge proof auditing and AI-assisted security analysis. The company is developing audit methodologies for ZK proof systems — an increasingly important layer in privacy-preserving blockchain applications — while its AI Auditor represents a broader push toward integrating machine learning into vulnerability detection pipelines. CertiK also launched a Global Web3 Compliance Suite in early 2026 targeting asset managers, custodians, and exchanges navigating multi-jurisdiction regulatory requirements.
Contents
Note: inclusion in Solana Compass directory does not indicate a recommendation or endorsement of this project, its token(s) or its products. Data sourced with thanks from The Grid to aid in building these pages.Solana Token Markets