CertiK Blockchain Security Expands With LF Decentralized Trust Membership

Add as a preferred source on Google

CertiK has joined LF Decentralized Trust to contribute security research, audits, and formal verification to open-source blockchain projects. The move expands CertiK blockchain security work across enterprise infrastructure and builds on its earlier research that uncovered five vulnerabilities in the Besu Ethereum client.

CertiK has joined LF Decentralized Trust, adding its audit, formal verification, and research expertise to open-source blockchain projects. The membership connects its security work with decentralized infrastructure used by enterprises and institutions worldwide.

Who Is Joining LFDT?

According to a press release, CertiK joins the Linux Foundation Decentralized Trust Initiative (LFDT), with a fresh membership cohort to the Linux Foundation-backed initiative for Q1 2025. 

LFDT promotes open-source technology solutions spanning finance, banking, healthcare, telecoms, and logistics supply chains.

Per the announcement, CertiK teams will participate in LFDT initiatives, leveraging their blockchain cybersecurity expertise on audits, verifications, and testing processes alongside developer and enterprise teams. 

Also Read: Ondo BlackRock Partnership 2026: Amazing Exclusive Debut

This arrangement positions LFDT as a vendor-neutral forum facilitated by the Linux Foundation, providing governance and technical support for decentralized technology implementations.

Ronghui Gu, a CertiK co-founder, said that the open, vendor-neutral, and standards-driven infrastructure is vital for enterprise blockchain development. He added that CertiK will be contributing its security skills to LFDT projects.

“Security and compliance can’t be treated as one-off exercises bolted on late in a project’s lifecycle anymore,” Ronghui Gu said.

LFDT Executive Director Daniela Barbosa noted that security researchers can aid open source development. She also cited their role in LFDT projects.

“The industry needs infrastructure that’s built to standards from the start, not adapted to them after the fact,” Barbosa added.

What Will CertiK Blockchain Security Contribute?

CertiK membership confers official status upon CertiK for any projects contributing to decentralized infrastructure development. Scheduled activities will encompass security research, audits, formal verification, and participation in technical groups.

The move follows earlier research on Besu, an Ethereum execution client hosted by LFDT. CertiK blockchain security researchers independently tested the client and discovered five vulnerabilities that could affect the node availability on affected configurations.

The research team created a private multi-node testnet and applied controlled adversarial testing. These discoveries included block announcement processing, consensus proposals, WebSocket subscriptions, JSON-RPC filterings, and network-facing functions.

The full set of issues varied from minor to major, and two of these were deemed major. CertiK reported the vulnerabilities to the Besu team and provided proof-of-concept testing tools.

Besu fixed all five vulnerabilities in version 26.7.1 on July 27. Four security advisories covering the findings were published on Aug. 14 after the patches became available.

The vulnerabilities have been found on peer-to-peer, RPC, WebSocket, and consensus places interfaces. The coordinated disclosure is to give technical background to CertiK blockchain security activities in LFDT.

When Did the Relationship Develop?

The relationship between CertiK and LFDT technology has deepened further. In particular, CertiK’s research on Besu shows the significance of external auditing prior to publication of technical documentation.

During 2026, LFDT also saw expansion of its memberships and portfolio of projects. In September, the OpenWallet Foundation announced relocating under the LFDT from 1 January 2027, incorporating developments in wallets and credentials under its remit.

Linea became a flagship LFDT member in May, contributing its open-source project “Linea Stack.” In April, LFDT had already welcomed ten additional members.

In September, CertiK blockchain security operations expanded outside LFDT itself. Specifically, on 14 September, CertiK signed a memorandum of understanding with the National Bank of the Kyrgyz Republic concerning the “Digital Som” initiative.

The partnership encompasses security for CBDCs, along with supervision on anti-money laundering and counter-terrorism financing for cryptoassets.

Where Is LFDT Infrastructure Being Used?

Besu offers blockchain interoperability across public Ethereum blockchains and privately run enterprise networks. The Besu Java client offers JSON-RPC and plugin APIs suitable for corporate blockchain environments.

In July, the Linux Foundation reported Depository Trust & Clearing Corporation deploying Besu for its AppChain offering tokenized collateral infrastructure services. The DTCC had already initiated limited-production trading with tokenized Russell 1000 stocks, major ETFs, and US Treasuries.

More than 50 organizations were involved, according to the Linux Foundation. ‎Deployment shows how the CertiK blockchain security research can interface ‎with traditional financial market infrastructure.

The LFDT projects include banking, logistics, telecommunication, health care, and other ‎enterprise sectors. Membership would enable CertiK’s ‎security offerings to become proximate to development teams working in ‎those areas.

CertiK offers smart contract auditing, formal verification, pentesting, ‎infrastructure security review, blockchain custodian assessment, ‎performance analysis, and compliance assistance. These services apply ‎institutionally to blockchain deployment.

Why Does the Membership Matter Now?

CertiK has correlated greater protection with stricter regulation of digital assets in the major markets. According to its Skynet State of Digital Asset Regulations research, a number of licensing and token admission frameworks call for independent smart contract audits directly or indirectly.

The company pointed to regulations in Hong Kong, the European Union, the United Arab Emirates, and certain US state jurisdictions. Anti-money laundering enforcement also emerged as a significant area of penalties for crypto companies, according to the company.

AML-related fines and settlements have surpassed $900 million in the last six months of 2025, as reported by CertiK. This trend gets closer to the development step to move over to security and compliance.

This change puts more emphasis on technical controls for the digital asset infrastructure set-up. CertiK blockchain security teams can now contribute that expertise through LFDT projects and working groups.

The membership builds on CertiK’s previous efforts with Besu in the expanded open-source ecosystem. CertiK blockchain security specialists will provide research and audit experience as opportunities emerge across LFDT.

Also Read: Hedera Partnership Expands IBM Enterprise Reach Through IDTrust

Yahya Raza Sherazi

Yahya Raza Sherazi

Yahya Raza is a Technology Analyst at Tronweekly, covering cryptocurrency markets, blockchain-related developments, and digital asset regulations. He has over one year of experience reporting on Bitcoin, altcoins, and broader crypto market trends.

His reporting focuses on market movements, crypto scams and hacks, security-related incidents, and regulatory developments, examining how technological risks and policy actions impact the crypto ecosystem. Yahya tracks ongoing market activity and industry updates using verified data and official sources.

Yahya’s work is written for both beginners and experienced readers, with an emphasis on clear, accurate reporting on crypto markets, technology-related risks, and regulatory changes, without speculation or investment guidance.

Articles: 1093