A profile of blockchain auditing service CertiK, which inspects smart contracts to help clients like Yuga Labs avoid critical bugs that can lead to lost crypto
but hackers are eating Web3.” - Ronghui Gu, CertiK's Co-Founder & CEO 📰 @techreview https://www.technologyreview.com/ ...
Context & Ripple Effects
The MIT Technology Review profile lands at the end of a steep climb for CertiK: from a $37M Series B in mid-2021 with 1,000+ clients including Binance, through an $80M Series B2 at a near-$1B valuation, to an $88M Series B3 led by Insight, Tiger Global and Advent at $2B — $230M raised in under a year. The bet VCs made is that smart-contract auditing becomes mandatory plumbing for anyone deploying code that holds money.
The profile's timing also coincides with CertiK's own loss accounting showing the market working: over $1.8B lost across 751 crypto hacks in 2023, down 51% YoY from $3.7B in 2022, which co-founder Ronghui Gu frames as a positive development for blockchain security. Clients like Yuga Labs sit on the demand side of that story.
First-order effects
- Clients such as Yuga Labs now treat a CertiK audit as a pre-deployment gate for contracts holding user funds, making CertiK's inspection capacity a direct input into how fast Web3 teams can ship.
- CertiK's $2B valuation is underwritten by this audit demand, so its revenue base tracks the volume of new smart-contract deployments rather than token prices alone.
Second-order effects
- Rivals like Certora, which raised a $36M Series B led by Jump Crypto to sell pre-deployment analysis tools to developers, are pushed to compete on methodology rather than price, splitting the market between manual audits and automated formal-verification tooling.
- VC appetite follows the threat: CB Insights counted $257M invested in crypto auditing and security companies in 2022, up from $185M across 2021 after high-profile bridge hacks, meaning more funded entrants are chasing the same client base.
Third-order effects
- If the 51% drop in 2023 hack losses holds, third-party auditing hardens into baseline trust infrastructure for Web3 — the equivalent of payment-card compliance — where unaudited code becomes effectively unshippable.
- That consolidation around auditors as gatekeepers concentrates systemic risk in a few firms: a missed bug at a dominant auditor would implicate every project it cleared, likely drawing regulatory attention to who certifies the certifiers.
The trend: Crypto security is professionalizing from ad-hoc incident response into a funded audit industry, with CertiK's valuation and falling hack losses marking the shift from reacting to breaches to gating deployments.