CertiK报告:扳手攻击损失暴增近12倍,“运营安全”成防范新核心
Related
Websea's security rating remains high, and CertiK's three-round penetration test reinforces its long-term security credibility.
According to ChainCatcher, the latest data from CertiK Skynet shows that Websea's security rating has remained in the 80+ A range after completing its third round of professional penetration testing. Its overall ranking has steadily improved, continuing to rank among the top in the global exchange security rankings. This assessment covered core dimensions such as smart contract security, system architecture stability, risk control mechanisms, and asset protection capabilities. The comprehensive assessment results further confirm that Websea possesses a highly mature and robust security system, with its overall security performance at a high level in the industry. As a leading third-party security organization, CertiK's continuous audits and penetration test results further strengthen Websea's long-term industry endorsement of its transparency and credibility in global exchange security, and further enhance market recognition of Websea's security and credibility.
CertiK Hack3D Report: Web3 Losses Exceed $1.3 Billion in the First Half of 2026, Attacks Are Accelerating Towards High-Value Targets
Odaily Odaily reports that Web3 security company CertiK released its "Hack3D: First Half of 2026 Report." The report shows that 344 security incidents occurred in the Web3 ecosystem in the first half of 2026, resulting in a total loss of approximately $1.32 billion. While this figure represents a 46.8% decrease compared to the same period last year, if the impact of the $1.45 billion security incident involving Bybit is excluded, the actual loss in the first half of this year increased by approximately 28% year-on-year, indicating that the overall security environment of the industry has not seen substantial improvement. The report points out that wallet theft has become the type of attack causing the biggest financial loss, resulting in approximately $450 million in losses in the first half of the year. Meanwhile, although the number of phishing attacks decreased by more than 50% year-on-year, the amount of losses only decreased by about 10.8%, reflecting that attackers are shifting their focus to high-net-worth individuals and institutions, launching more targeted and high-value attacks. Furthermore, code vulnerabilities remain the most frequent type of attack, with 204 related incidents. CertiK believes that attackers are increasingly targeting long-running smart contracts that lack re-auditing. The report also shows that large-scale attacks continue to dominate industry losses, with the Kelp DAO and Drift Protocol incidents causing approximately $577 million in losses, accounting for 44% of total losses in the first half of the year. In terms of the number of incidents, the impact of individual attacks, and changes in attack patterns, the Web3 industry is facing increasingly complex and continuously escalating security challenges.
Lambda256 and CertiK have entered into a strategic partnership to jointly develop the Asia-Pacific digital asset security and compliance market.
According to Odaily Odaily, Lambda256, a blockchain technology subsidiary of Dunamu, announced a strategic partnership with Web3 security company CertiK and signed a Memorandum of Understanding (MOU). The two companies will jointly expand the construction of digital asset security and compliance infrastructure in South Korea and the Asia-Pacific region. According to the agreement, Lambda256 will serve as the official channel partner for CertiK's security and compliance products, promoting solutions including SkyInsights and AI Auditor. The two companies plan to combine CertiK's capabilities in on-chain security intelligence, smart contract auditing, and risk management with Lambda256's experience in blockchain infrastructure and compliance ecosystems to provide integrated security and compliance services for enterprises, financial institutions, and virtual asset service providers (VASPs). It is understood that in the first phase, both parties will focus on promoting local enterprise-level application scenarios in South Korea, including consortium blockchains, localized deployments, and the construction of digital asset infrastructure related to the public sector, and will further carry out joint marketing, industry activities, and research cooperation in the Asia-Pacific region.
CertiK launches Skill Scanner to establish a standardized security audit layer for AI Agent applications.
Odaily Odaily that Web3 security company CertiK has officially launched "CertiK Skill Scanner," an AI Agent ecosystem security product applicable to both the Web3 ecosystem and the traditional Web2 market. Primarily targeting the AI Skill market, enterprises, and developers, it identifies risks such as malicious behavior, data breaches, unauthorized access, and autonomous execution before a Skill is executed. Unlike traditional AI scanning tools, CertiK Skill Scanner not only supports static code analysis but also assesses the risks of Skills during actual operation, making it particularly suitable for scenarios involving financial transactions and fund transfers. Currently, the tool has been integrated into AI Agent platforms such as Pieverse.
CertiK's 2026 Stablecoin Threat Report: The stablecoin ecosystem is facing dual challenges of technological security and regulatory compliance.
According to Foresight News , Web3 security company CertiK recently released its "2026 Stablecoin Threat Report," highlighting that the stablecoin ecosystem faces dual challenges in terms of technological security and regulatory compliance. The report shows that since 2026, cross-chain bridge-related security incidents have resulted in losses exceeding $328 million, with the Kelp DAO wallet breach alone causing a loss of $291 million. This underscores that cross-chain bridges, custody systems, and payment infrastructure have become key targets for hackers. The report also focuses on the development of the Russian ruble-based stablecoin A7A5. On-chain data shows that since its launch in 2025, A7A5 has accumulated over $110 billion in transaction volume, accounting for approximately 43% of the global non-USD stablecoin market. The report argues that A7A5 demonstrates a new model for building cross-border settlement networks using stablecoins and has become a key focus for regulatory agencies. Despite ongoing sanctions from the US and Europe, the number of A7A5 holding addresses continues to grow, reflecting the new challenges faced by traditional sanctions systems when dealing with on-chain financial networks. CertiK stated that stablecoin risks have expanded from smart contract vulnerabilities to financial infrastructure and geopolitical levels, and are becoming an important issue in global financial system risk management.
Safeheron and RD Technologies have entered into a strategic partnership to jointly build a bank-grade Web3 payment security infrastructure.
Odaily Odaily reports that Safeheron has announced a strategic partnership with Hong Kong-based digital financial technology group RD Technologies, providing underlying security support for its digital wallet and account systems. The collaboration will initially focus on acquiring scenarios, building stablecoin payment channels for merchants and enterprises, and will later extend to more Web3 payment scenarios. Safeheron will create a bank-grade security system covering the entire chain from key management and asset aggregation to transaction execution, eliminating single points of failure. The two companies will also engage in in-depth cooperation in AI-enabled financial areas such as intelligent risk control and AI-driven compliance monitoring.