CertiK is a Web3 security company founded in 2018. It audits smart contracts and blockchain protocols, runs formal verification and penetration testing, monitors live projects through Skynet, and sells risk tools to projects, exchanges, wallets, institutions, developers, and investors trying to assess onchain risk. It is not a decentralized app platform, and it is not the same thing as the chain that used to be called CertiK Chain.
That chain was renamed Shentu Chain. Its coin is still CTK. CertiK the company and Shentu the chain share an origin story. They do not share a balance sheet.
Founded by computer-science researchers from Columbia and Yale, CertiK also offers KYC-style team checks, Proof of Reserves work, AI Auditor tools, and a public scoring and monitoring layer. This article explains what CertiK actually does, how its smart-contract and chain audits work, what its scores and monitoring can and cannot tell you, how CertiK compares with other auditors, and why exploits still happen after audits. Company materials and partner copy in 2026 put the book at thousands of enterprise clients, hundreds of billions of dollars in assets covered by audited code, and well over 100,000 findings across engagements. Those figures move with marketing pages. An audit badge is not a guarantee that a protocol cannot be exploited later.

Company. CertiK is still the large commercial auditor. 2026 product work includes a public AI Auditor, CertiK Skills that plug SkyInsights, Skylens, and Skynet Score into Claude Code, Codex, and Cursor, Grey Box Chain Audit for runtime faults, Skynet Enterprise for institutions, a validator service, and AML/CTF compliance solutions for VASPs; the company also says it has established regulatory relationships in six countries. It is also SOC 2® Type II compliant and ISO 27001 certified. Research output still includes Hack3D exploit tallies and policy reports. H1 2026 Hack3D put industry losses above $1.31 billion across 344 incidents. August 2026 alone was reported around $215 million.
Scale claims to treat as marketing, not GAAP. Recent partner and hiring copy cites roughly 4,900–5,000+ clients, about $557–600 billion in assets tied to audited code, and 18,000 to 119,000+ vulnerabilities depending on the page and whether the count is unique bugs, findings, or historical detections. Use the live CertiK site for the current line.
Capital. Public trackers put total raised near $240–297 million. The last widely cited priced round valued the firm around $2 billion in 2022. Investors have included Binance Labs, Sequoia, Coinbase Ventures, Tiger Global, SoftBank, and others. Binance appeared again in a January 2026 corporate-minority line. CEO Ronghui Gu discussed a public listing at Davos, then told CoinDesk there was no concrete IPO plan.
Trust issues. A CertiK “clean” report has not stopped later exploits on some clients. The firm also took public heat after work tied to a Huione-linked stablecoin and after OpenBounty, a Shentu-side bounty product, was accused of routing other platforms’ reports through CertiK-branded infrastructure. Those episodes matter if you treat a logo as due diligence.
CertiK launched in 2018 to bring academic formal verification into commercial blockchain security. Co-founder and CEO Ronghui Gu comes out of Columbia’s systems and verification work and has sat on technology advisory panels including MAS in Singapore. Zhong Shao is the other academic co-founder most often named in the origin story. Treat older bios that list extra C-suite names as stale unless the current CertiK team page confirms them.


Early clients and ecosystems still associated with the brand include large L1s and DeFi names such as BNB Chain, Aptos, Polygon, Aave, and later names that appear in current hiring copy such as OKX, Tether, Ripple, and PancakeSwap. The client list is a sales artifact. It is not a whitelist.


An audit is a scoped review of the source code that was delivered, and because smart contracts often control high-value assets and are immutable once deployed, they require thorough security evaluations rather than coverage of every future upgrade, admin key, or oracle. CertiK’s pitch is manual review, AI assistance, optional formal verification, and a report that lists findings and remediations. Such reviews can identify logic errors and complex vulnerabilities before deployment, including issues standard testing might miss in software. CertiK’s optional formal verification applies mathematical methods to detect vulnerabilities in code and assess correctness. Independent audits are crucial for protecting user funds from exploits.


Typical flow: CertiK’s multi-step process for auditing blockchain code and smart contracts covers intake and scope, automated scan, human review, optional proofs, report, then a fix-and-retest loop used to evaluate whether fixes actually resolve findings. Formal verification only helps if the specification is precise, because it uses mathematical methods to prove code correctness within that system. It does not invent missing business logic.

Layer-1 work covers consensus, networking, VM, and privileged modules, including checks for compatibility across modules and other mission-critical applications running on the chain. The published five-step outline is the same shape as a contract audit, with a larger surface.

Grey Box chain audit is the 2026 add-on: inject faults on a live or near-live network and watch what actually breaks.
Layer-1 work covers consensus, networking, VM, and privileged modules, including checks for compatibility across modules and other mission-critical applications running on the chain. The published five-step outline is the same shape as a contract audit, with a larger surface.


The score is a weighted mix of on-chain and off-chain signals. Its public security score can help evaluate project safety at a glance. CertiK says it is not for sale as a grade. Public audit reports and score pages add transparency and build trust among investors and users, reinforcing project accountability. Boost products exist to amplify verified signals, which is different from buying a letter. Read the modules: audit freshness, coverage of deployed code versus audited code, and whether critical findings are resolved or only “acknowledged,” while remembering that audits and scores are often treated as a signal of project security, not proof of safety.

CertiK Chain was the Cosmos SDK network launched around 2019. After the Shentu-2 upgrade it became Shentu Chain. CTK stayed the ticker. Shentu now runs as a separate public chain with its own site, validators, and foundation. CertiK still collaborates on research such as OpenMath. That does not make CTK a share of the audit firm.

The oracle was designed to put compressed audit or security scores on-chain so contracts could read a grade. A score is evidence from a past review. It is not a live proof that the contract is safe.
CertiKShield / ShentuShield was framed as a reimbursement pool, not a licensed insurer. Collateral providers and protection buyers sit on opposite sides of a claim vote. Check whether the pool is still funded and writing cover before you treat it as insurance.

DeepSEA is a formally oriented compiler line from CertiK’s research stack. The idea is to cut compiler-introduced bugs and keep proofs attached as source becomes bytecode (EVM or eWASM). It remains part of the academic toolkit. Most commercial audits still ship as reports, not as a DeepSEA proof artifact for every client.
CVM was the chain-side VM meant to consume certified compiler output. On the live Shentu stack, treat current docs and explorers as the source of truth, not the 2019 architecture diagram.

| Firm | Usual strength | Usual limit |
|---|---|---|
| CertiK | Volume, Skynet distribution, mixed AI + manual + optional proofs | Badge can be over-read; some clients were later exploited |
| Quantstamp | Heavy manual and formal work on complex protocols | Slower, often dearer |
| OpenZeppelin | Library standard plus line-by-line review | Less of a public score product |
| MythX / similar scanners | Fast automated findings in the IDE | Weak as a standalone audit |
Many exchanges require third-party audits before blockchain projects are listed for public trading. CertiK’s core focus is security for mission-critical applications.
No vendor replaces key hygiene: admin-key design, upgrade process, oracle risk, and operational security. Wallet compromise, not only Solidity bugs, drove a large share of 2026 losses in CertiK’s own reports.
CTK is the native token of Shentu Chain, a Cosmos SDK / CometBFT network. Uses: gas, staking, delegation, governance. Historical design also tied it to the security oracle and shield pool.

Early allocation in the old CertiK Chain materials: private sales, Launchpool, team, foundation, community, and shield pool. Circulating supply on 2026 market pages is on the order of 163 million, with a price far below the 2021 high near $4. That market is Shentu, not a claim on CertiK audit fees.
If you trade CTK on Gate, match the Shentu / CTK deposit network. Do not send it to a random “CertiK token” contract on another chain.
CertiK is still one of the largest paid security brands in Web3. The useful update is the split: company versus chain, score versus safety, AI tooling versus a finished guarantee. Use Skynet and the audit PDF as inputs. Do not stop at the logo.
No. CertiK is a company. The old CertiK Chain is Shentu Chain.
No. It means a scoped review happened. Upgrades, keys, oracles, and operations can still fail.
A CertiK composite rating from on-chain and off-chain signals. Useful for screening. Not a regulator grade.
Shentu Chain’s token. Not CertiK stock.
Gu discussed it. He later said there was no concrete IPO plan.
Scope, stale code, key theft, and economic attacks sit outside a one-time code review.
* The information is not intended to be and does not constitute financial advice or any other recommendation of any sort offered or endorsed by Gate.
* This article may not be reproduced, transmitted or copied without referencing Gate. Contravention is an infringement of Copyright Act and may be subject to legal action.





