CertiK has joined LF Decentralized Trust (LFDT), expanding its involvement in open-source infrastructure designed for decentralized systems across finance, banking, supply chains, healthcare, and telecommunications.
The blockchain security company plans to participate in LFDT projects and working groups, contributing expertise in security research, formal verification and auditing. The membership is expected to bring CertiK into closer collaboration with enterprises, startups and technical teams working on interoperable decentralized infrastructure.
CertiK said its primary objective is to integrate security research and formal verification more closely into the development of open-source blockchain infrastructure, allowing potential vulnerabilities and compliance considerations to be addressed earlier in the development cycle.
The membership builds on earlier work between CertiK researchers and Besu, the Ethereum execution client hosted by LF Decentralized Trust. In August, CertiK disclosed research identifying five vulnerabilities in Besu, including resource-exhaustion weaknesses that could affect node availability under certain conditions.
Besu addressed all five vulnerabilities in version 26.7.1, released on July 27, before the technical advisories were publicly disclosed on Aug. 14. The vulnerabilities involved peer-to-peer, remote procedure call, WebSocket, and consensus-facing interfaces.
Besu research precedes CertiK membership
CertiK’s involvement with LFDT technology predates its formal membership. During its independent Besu research, the company used a private multi-node testnet and controlled adversarial testing to examine how the Ethereum client responded to hostile conditions.
Researchers identified five vulnerabilities that could degrade or crash nodes through interfaces exposed under affected configurations. The findings included issues involving block announcement processing, consensus proposals, WebSocket subscriptions, and JSON-RPC filters.
Two vulnerabilities were categorized as major severity, while the overall findings ranged from minor to major. CertiK privately disclosed the issues to the Besu team and provided proof-of-concept testing tools.
Besu subsequently released fixes and published four security advisories covering the five findings. The Java-based execution client supports both public Ethereum networks and private enterprise deployments through JSON-RPC and plugin interfaces.
The platform has also gained a role in institutional blockchain infrastructure. The Linux Foundation said in July that Depository Trust & Clearing Corporation was using Besu for an AppChain supporting tokenized collateral infrastructure. DTCC had begun limited production transactions involving tokenized Russell 1000 equities, major exchange-traded funds and U.S. Treasuries, with more than 50 firms participating.
Regulatory requirements increase focus on security
CertiK has linked its LFDT membership to growing regulatory requirements surrounding digital assets. Its Skynet State of Digital Asset Regulations research indicated that independent smart-contract audits had become mandatory or indirectly required for licensing and token admission in several jurisdictions, including Hong Kong, the United Arab Emirates and the European Union, as well as certain U.S. state frameworks.
The company also reported that anti-money-laundering enforcement had become a significant source of regulatory penalties for crypto businesses. Its analysis found that AML-related fines and settlements exceeded $900 million during the first half of 2025.
Regulatory frameworks covering exchanges, custodians and issuers have increasingly incorporated requirements associated with traditional financial services, including capital adequacy, asset segregation, liquidity management and operational resilience.
The company said these developments are shifting security and compliance from late-stage checks toward requirements that need to be incorporated during the design and development of blockchain infrastructure.
Broader expansion into institutional digital assets
CertiK’s LFDT membership also follows its growing involvement with public-sector digital-asset initiatives. On Sept. 14, the company announced a memorandum of understanding with the National Bank of the Kyrgyz Republic concerning the country’s Digital Som project.
The arrangement covers security work related to the central bank digital currency, along with anti-money-laundering and counter-terrorist-financing oversight for digital assets.
CertiK, founded in 2017, provides blockchain infrastructure assessments, smart-contract audits, formal verification, penetration testing, custody architecture reviews, performance evaluations, and compliance support. The company says it has worked with more than 5,500 enterprise clients.
LFDT operates as a vendor-neutral community under the Linux Foundation, providing governance and development support for open-source decentralized technologies. Its membership and project base have continued to expand during 2026.
OpenWallet Foundation is scheduled to move under LFDT on Jan. 1, 2027, while Linea became a premier LFDT member in May and contributed the Linea Stack as an open-source project. LFDT also announced 10 additional members in April.
Through its new membership, CertiK intends to contribute security research, auditing expertise, and formal-verification capabilities to LFDT projects and working groups, potentially bringing security considerations closer to the core development of enterprise blockchain systems.







