NewsCryptoCertiK Joins LF Decized Trust to Bolster Open-Source Blockchain Security

CertiK Joins LF Decized Trust to Bolster Open-Source Blockchain Security

Author: CoinTrust·

Key Takeaways

  • •CertiK has joined LF Decentralized Trust and will contribute security research, formal verification, and auditing expertise to its open-source projects and working groups.
  • •Prior to joining, CertiK researchers identified five vulnerabilities in the Besu Ethereum client, all of which were remediated in version 26.7.1 released July 27, ahead of public advisories on Aug. 14.
  • •Besu has become institutional infrastructure, with DTCC using the client for an AppChain supporting tokenized collateral transactions involving more than 50 firms.
  • •CertiK's research found that independent smart-contract audits are mandatory or indirectly required for licensing and token admission in Hong Kong, the UAE, the European Union, and certain U.S. state frameworks.
  • •AML-related fines and settlements for crypto businesses exceeded $900 million in the first half of 2025, according to CertiK's analysis of regulatory enforcement.
CertiK Joins LF Decized Trust to Bolster Open-Source Blockchain Security

CertiK, the blockchain security company, has joined LF Decentralized Trust (LFDT), deepening its participation in open-source infrastructure built for decentralized systems spanning finance, banking, supply chains, healthcare, and telecommunications.

Under the membership, CertiK plans to take part in LFDT projects and working groups, contributing expertise in security research, formal verification, and auditing. The move is expected to place the firm in closer collaboration with enterprises, startups, and technical teams developing interoperable decentralized infrastructure. Because LFDT's projects are open source, security improvements and fixes developed within them are available to any organization building on the shared stack.

According to CertiK, its primary objective is to integrate security research and formal verification more closely into the development of open-source blockchain infrastructure, allowing potential vulnerabilities and compliance considerations to be addressed earlier in the development cycle.

Besu research preceded formal membership

CertiK's engagement with LFDT technology began before it formally joined the organization. The membership builds on earlier work between CertiK researchers and Besu, the Ethereum execution client hosted by LF Decentralized Trust.

In August, CertiK disclosed research identifying five vulnerabilities in Besu, including resource-exhaustion weaknesses that could affect node availability under certain conditions. The flaws involved peer-to-peer, remote procedure call, WebSocket, and consensus-facing interfaces. Besu remediated all five issues in version 26.7.1, released on July 27, ahead of the public disclosure of technical advisories on Aug. 14.

During its independent Besu research, the company operated a private multi-node testnet and ran controlled adversarial testing to examine how the Ethereum client responded to hostile conditions. Researchers identified five vulnerabilities that could degrade or crash nodes through interfaces exposed under affected configurations, with issues involving block announcement processing, consensus proposals, WebSocket subscriptions, and JSON-RPC filters. Two of the vulnerabilities were categorized as major severity, while the overall findings ranged from minor to major.

CertiK privately disclosed the issues to the Besu team and provided proof-of-concept testing tools. Besu subsequently released fixes and published four security advisories covering the five findings. The sequence — private reporting, patched releases, then public advisories — was a coordinated-disclosure process that let users update before technical details became public.

The Java-based execution client supports both public Ethereum networks and private enterprise deployments through JSON-RPC and plugin interfaces. Besu has also gained a role in institutional blockchain infrastructure: the Linux Foundation said in July that the Depository Trust & Clearing Corporation was using Besu for an AppChain supporting tokenized collateral infrastructure. DTCC had begun limited production transactions involving tokenized Russell 1000 equities, major exchange-traded funds, and U.S. Treasuries, with more than 50 firms participating. For institutions tracking that work, the Besu episode offers a concrete reference point for how vulnerabilities in shared execution clients are found, patched, and disclosed.

Regulatory requirements sharpen security focus

CertiK has tied its LFDT membership to growing regulatory requirements surrounding digital assets. Its Skynet State of Digital Asset Regulations research indicated that independent smart-contract audits had become mandatory or indirectly required for licensing and token admission in several jurisdictions, including Hong Kong, the United Arab Emirates, and the European Union, as well as under certain U.S. state frameworks.

The company also reported that anti-money-laundering enforcement has become a significant source of regulatory penalties for crypto businesses. Its analysis found that AML-related fines and settlements exceeded $900 million during the first half of 2025 — a figure that shows how directly compliance failures can translate into financial penalties for digital-asset businesses.

Regulatory frameworks covering exchanges, custodians, and issuers have increasingly incorporated requirements associated with traditional financial services, including capital adequacy, asset segregation, liquidity management, and operational resilience. CertiK said these developments are shifting security and compliance from late-stage checks toward requirements that must be incorporated during the design and development of blockchain infrastructure.

Broader expansion into institutional digital assets

The LFDT membership also follows CertiK's growing involvement with public-sector digital-asset initiatives. On Sept. 14, the company announced a memorandum of understanding with the National Bank of the Kyrgyz Republic concerning the country's Digital Som project. The arrangement covers security work related to the central bank digital currency, along with anti-money-laundering and counter-terrorist-financing oversight for digital assets.

Founded in 2017, CertiK provides blockchain infrastructure assessments, smart-contract audits, formal verification, penetration testing, custody architecture reviews, performance evaluations, and compliance support. The company says it has worked with more than 5,500 enterprise clients.

LFDT operates as a vendor-neutral community under the Linux Foundation, providing governance and development support for open-source decentralized technologies. Its membership and project base continued to expand during 2026: the OpenWallet Foundation is scheduled to move under LFDT on Jan. 1, 2027; Linea became a premier LFDT member in May and contributed the Linea Stack as an open-source project; and LFDT announced 10 additional members in April.

Through its new membership, CertiK to contribute security research, auditing expertise, and formal-verification capabilities to LFDT projects and working groups, potentially bringing security considerations closer to the core development of enterprise blockchain systems.