CertiK
品类领导地位真实,溢价估值区间也有依据;但私营公司信息仍过于不透明,还不足以让人无条件相信这个价格。
CertiK 的品类相关性、产品宽度和客户证据足以支撑继续尽调,但现有公开材料仍只能支撑“继续研究”,不能只靠信任为历史 $2B 标记买单。
封面要素
公司概况
CertiK 是一家总部位于纽约的 Web3 安全平台,由与 Yale 和 Columbia 有关联的学者创立,业务已从智能合约审计扩展到形式化验证、监控、储备证明、AML / 合规和 AI 安全工作流。公开证据支持这样一家公司画像:后期私营公司,机构叙事真实,历史估值锚为 20 亿美元,累计融资约 2.96 亿美元,并声称拥有数千家企业客户;但当前经营经济性和治理深度仍留下重大问题。
- 成立时间
- 2017-01-01
- 创始人
- Ronghui Gu, Zhong Shao
- 创立地点
- New York City, USA
- 总部
- New York City, USA
- 产品
- CertiK 销售智能合约审计、形式化验证、渗透测试、Skynet 监控、SkyInsights 合规与风险分析、储备证明服务,以及更新的 AI 技能安全工具。
- 客户
- 需要 Web3 安全背书或持续风险监控的协议团队、钱包、交易所、托管机构、金融机构和生态项目。
- 商业模式
- 以项目制审计和保障收入为基础,叠加监控、合规、分析和相邻安全产品的经常性变现。
- 阶段
- Late-stage private / pre-IPO
- 融资情况
- 最近一轮清晰定价融资是 2022 年 3 月估值 20 亿美元的 Series B3;公开数据库显示累计融资约 2.96 亿美元,2026 年战略动作带来新的投资人与生态信号,但没有披露新的定价轮。
执行摘要
主要优势
- CertiK 在 web3 安全里有真实品牌,产品覆盖审计、监控、合规、储备证明和 AI 安全工具。
- 客户和渠道证据横跨协议、钱包、交易所和生态伙伴,不只是纸面市场位置。
- 历史融资支持充足,公开估值锚点为 $2B,累计融资约 $296M。
主要风险
- 公开估值支撑仍依赖未经审计的 ARR 代理,而不是经审计的经常性收入、利润率或留存披露。
- Kraken 时期争议和其他公开批评造成品牌与信任损耗,可能直接拖累企业采购和 IPO 准备。
- 清算优先权、稀释和其他股权条款未公开,投资者回报测算仍缺关键变量。
- CertiK 的经济模型可能仍更偏项目制、也更受加密周期影响,难以直接匹配高端软件倍数。
未决问题
- 需要经审计的 ARR 或收入、服务与订阅收入拆分,以及毛利率披露。
- 需要 NRR、GRR、流失率、头部客户集中度和附加率证据,证明经常性经济模型足够稳。
- 需要股权权利、优先权、期权池数据,以及任何结构化融资条款。
- 需要比愿景表态更清晰的 IPO 准备度、内控成熟度和治理深度证据。
目录
01公司概览
1.1 身份、范围与商业模式
CertiK 把自己定位为总部位于纽约的 Web3 安全平台,而不是单一服务的审计公司。官方关于页面把公司根基放在 Columbia 和 Yale 的研究上,并称业务由两校教授于 2017 年创立;主页则把叙事扩展成一整套工具,覆盖智能合约审计、形式化验证、渗透测试、监控、AML、KYC 和事件响应。平台化定位很关键,因为它把 CertiK 从按项目交付的服务商,推向协议、交易所、钱包以及越来越多机构用户的经常性风险基础设施。World Economic Forum 和 CB Insights 的独立资料大体支持身份和总部叙事,但对确切创立年份并不一致,对公司经营范围的描述也略有差异。最终的商业模式图景是清楚的:CertiK 在 Web3 开发生命周期中变现信任和技术保障,但投资人若要做基准分析,仍需先校准外部资料中的不一致数据。[CO001, CO002, CO005, CO010, CO027, CO029]
| 指标 | 数值 / 状态 | 日期 | 置信度 | 缺口 |
|---|---|---|---|---|
| 创立年份 | 官方口径 2017 / 部分第三方资料 2018 | 2026 视角 | 中 | 注册日期与实际运营启动时间仍需核实 |
| 总部 | New York City;CB Insights 显示地址为 1001 Avenue of the Americas | 2026 视角 | 中 | 官方网站未突出街道地址 |
| 最近一次已确认估值 | $2B | Mar 2022 / Jan 2026 参考 | 高 | 未公开披露更新的定价轮 |
| 累计融资额 | ~$296M 累计 | 2026 第三方资料 | 中 | 2022 B3 轮官方公布总额仅为 $230M |
| 企业客户 | 声称 5,000+ | Jan 2026 | 中 | 以往说法在 1,800 到 2,500 之间 |
| 受保护资产 | 声称 $600B+ | Jan 2026 | 中 | 未经独立审计 |
| 员工人数 | 205(Tracxn) | Jun 2026 | 中 | 公司未公布官方员工人数 |
| 月活用户 | Skynet 用户 1.8M+ | 2026 首页 | 中 | 适用于平台使用量,不必然等于付费客户 |
| IPO 状态 | 已表态为目标,但没有具体申报计划 | Jan 2026 | 高 | 没有公开时间表或招股书草案 |
官方与第三方快照混合;各行列出最新公开数据点,以及披露仍未验证的位置。
[CO001, CO007, CO009, CO013, CO021, CO024]这家公司把学术信任、审计产品、监控工具和机构分销接到一起,拼成一个安全平台。
[CO002, CO012, CO029, CO030]公开 KPI 显示已有规模,但大多数来自公司口径,并非独立审计。
这里混合了官方说法和第三方画像数据,因为 CertiK 没有发布定义经对齐的完整 KPI 看板。
[CO009, CO013, CO020, CO021, CO024]1.2 创始人、领导梯队与治理信号
公开领导层顶部学术色彩异常浓,下面则越来越偏运营。Ronghui Gu 和 Zhong Shao 以深厚形式化验证履历托住创始故事;Jason Jiang、Kang Li、Denise Benattar、Stefan Muehlbauer、Hudson Jameson 等高管显示公司有意补强商业化、企业安全运营、法律流程、公共事务和生态分发。这种组合支持一个判断:CertiK 正试图摆脱 crypto-native 审计品牌,专业化为机构基础设施提供商。即便如此,按后期私营公司标准看,治理披露仍偏薄。公开材料没有给出当前董事会名单、委员会结构、投票动态,也没有详细解释接班规划。Ronghui Gu 仍主导融资、政策和 IPO 相关沟通,关键人依赖已经是实质问题。关键人依赖本身不必然负面,但一旦市场环境、监管或另一场公开争议迫使管理层迅速重配领导层曝光度,执行敏感性会更高。[CO003, CO004, CO024, CO031, CO032, CO034]
| 人物 | 职务 | 背景 | 职能覆盖 | 关键人物依赖 |
|---|---|---|---|---|
| Ronghui Gu | 联合创始人兼 CEO | Columbia 计算机科学教授;Yale 博士;CertiKOS 和 SeKVM 设计者 | 学术背书、产品愿景、IPO / 融资门面 | 很高 |
| Zhong Shao | 联合创始人 | Yale 计算机科学系主任;CertiKOS 研究负责人 | 形式化验证根基 | 高 |
| Jason Jiang | 首席商务官 | 曾在科技和工业企业担任 COO、CEO 和运营职务 | 企业商业化和收入扩张 | 中高 |
| Kang Li | 首席技术官 | 前 Baidu 首席安全科学家;前 UGA 教授 | 应用安全研究和智能合约之外的技术深度 | 高 |
| Hudson Jameson | 生态负责人 | 前 Ethereum Foundation 和 Polygon Labs 贡献者 | 协议 / 社区分发和标准能见度 | 中高 |
| Denise Benattar | 法务负责人 | 前 Latham & Watkins 律师,曾任科技公司总法律顾问 | 公司法务执行和并购准备度 | 中 |
| Stefan Muehlbauer | 美国政府事务负责人 | 具备上市公司、游说和银行业背景 | 面向机构推进的政策 / 监管接口 | 中 |
仅包括公开披露的高级领导层;CertiK 未公布完整董事会或完整管理组织图。
[CO003, CO004, CO005, CO032]| 利益相关方 | 角色 | 经济 / 控制相关性 | 证据 | 尽调问题 |
|---|---|---|---|---|
| Ronghui Gu | 创始人兼 CEO、主要发言人 | 控制融资、政策和 IPO 叙事的核心口径 | 官方关于页面及 2026 IPO 访谈 | 澄清投票控制权和继任计划 |
| Binance / YZi Labs | 战略投资者和分发伙伴 | 现被称为最大投资者;同时导入孵化器项目 | 官方 2026 博客及 Yahoo 访谈 | 确认安全独立性防火墙和经济条款 |
| Goldman Sachs | 机构投资者 | 向传统金融受众释放可信度信号 | TechCrunch 和官方 2022 融资文章 | 理解其参与是被动财务投资还是战略参与 |
| Sequoia / Lightspeed / Tiger | 多轮参与的风投支持者 | 支撑私营市场验证和增长资本 | 官方融资文章和 Tracxn | 澄清按比例跟投权、优先权和二级交易历史 |
| 机构 / 监管方 | 企业采用目标 | 产品路线图现在明确转向机构级工具 | 2026 前进路径文章 | 管线中机构客户与加密原生客户各占多少? |
| 客户和交易所 | 品牌放大器和声誉传导者 | 审计争议可能迅速外溢成需求风险 | 首页、客户证言和负面报道 | 审查头部客户集中度和续约质量 |
这是一张具备经济重要性的利益相关方地图,不是股权结构表;公开资料没有披露持股比例和优先权条款。
[CO011, CO012, CO013, CO031, CO032, CO035]1.3 融资形成、投资人基础与阶段
CertiK 的融资路径显示,2021 年中至 2022 年初资本形成速度异常快,公司在数月内从约独角兽状态跃升至 20 亿美元估值。官方融资稿和 TechCrunch 报道都指向关键的 B3 轮;Tracxn 则补充了 2022 年 4 月后续 Series B 融资,并把累计融资额提高到约 2.96 亿美元。投资人组合几乎和金额同样重要:Goldman Sachs、SoftBank、Advent 等传统金融名字,与 Sequoia、Tiger Global、Coinbase Ventures 和 Binance 关联资本并列。2026 年 1 月,管理层又给阶段叙事加了两块拼图:明确称 Binance 在追加八位数美元支票后已成为最大投资人,并提出战略性而非临近落地的 IPO 目标。这支撑后期私营 / IPO 前公司的分类;但没有已审计财务报表、当前现金披露或已知二级交易条款,公开证据仍无法充分承销资本充足性或投资人抛压风险。[CO006, CO007, CO008, CO009, CO011, CO012]
1.4 里程碑、规模主张与负面事件
CertiK 公开叙事中最强的正面信号,是它把学术安全起点做成规模化商业品牌的速度。管理层连续发布客户服务量、识别漏洞数和产品发布的跃升,2024 年和 2026 年更新又把故事拓展到风险投资、企业监控和监管定位。但同一条时间线也包含公司最重要的尽调警报。独立记者和前客户质疑过 CertiK 审计的一致性和深度;Kraken 在一场漏洞赏金争议后公开指控公司敲诈;甚至公司自己的 X 账号也在钓鱼事件中被攻破。这些事件不会抹掉产品市场契合,但意味着公司走向 IPO 或获得私募溢价估值,既取决于原始审计量,也取决于信誉修复和控制成熟度。因此,里程碑记录支持一个平衡判断:CertiK 已明显做出规模,但还没有对争议免疫。[CO014, CO015, CO016, CO017, CO018, CO019]
| 日期 | 事件 | 类型 | 金额 / 状态 | 参与方 | 含义 |
|---|---|---|---|---|---|
| 2017 | 当前关于页面呈现的创立故事 | 创立 | 官方叙事 | Ronghui Gu;Zhong Shao | 学术起源故事锚定品牌 |
| 2018-07 | Tracxn 数据集中的首次披露融资轮 | 融资 | 种子融资启动 | 早期风投投资人 | 标记商业化启动阶段 |
| 2021-12-01 | B2 轮宣布估值接近 $1B | 融资 | $80M / 接近 $1B 估值 | Sequoia China、Tiger、Coatue 与 GL Ventures | 确认跃升独角兽 |
| 2022-03-31 | B3 轮将估值翻倍至 $2B | 融资 | $88M / $2B 估值 | Insight;Tiger;Advent;Goldman | 确立当前标题估值 |
| 2022-04-22 | Tracxn 记录的后续 Series B 融资 | 融资 | $60M | Tiger Global;SoftBank | 暗示融资额不止公开标题轮次 |
| 2024-01 | X 账号钓鱼入侵被报道 | 负面事件 | 运营事件 | CertiK 员工被定向攻击 | 凸显内部控制风险 |
| 2024-06 | Kraken 白帽争议公开化 | 负面事件 | $3M 漏洞利用 / 资金已返还 | Kraken;CertiK 研究人员 | 留下声誉包袱 |
| 2024-09-19 | CertiK Ventures 推出 $45M 计划和免费工具 | 产品 | $45M 投资计划 | CertiK Ventures | 从服务扩到生态投资 |
| 2026-01-06 | 宣布 YZi Labs 合作和 $1M 审计资助 | 合作 | $1M 资助池 | YZi Labs;CertiK | 加深面向创始人的分发渠道 |
| 2026-01-23 | CEO 公开称 IPO 仍是目标,估值约 $2B | 治理 | 没有具体 IPO 计划 | Ronghui Gu;Davos 媒体 | 释放上市前诉求,但准备度未跑完 |
仅列出最重要的公开里程碑;私下运营里程碑和未披露融资可能缺失。
[CO001, CO006, CO007, CO009, CO012, CO013]公开里程碑显示,公司快速融资后,转向机构化建设和争议管理。
[CO006, CO007, CO012, CO013, CO018, CO019]1.5 展示项
02市场分析
2.1 市场边界与纳入支出
CertiK 所处市场可以用两种很不同的方式界定。最宽口径下,Web3 安全包括用于保护去中心化应用、节点、钱包、基础设施和受监管数字资产运营的软件、硬件和服务。这个口径纳入云端或本地工具、威胁情报、分析、咨询和合规。窄口径下,更相关的类别是智能合约审计和安全公司市场,预发布代码审查、修复、漏洞赏金和上线后监控,更贴近 CertiK 当下的日常收入模式。这个区别很重要,因为它改变投资人对 TAM 的解读。宽口径市场规模可以说明生态方向,但仍可能夸大 CertiK 实际可捕获的支出部分。尽调中更合适的工作边界应是分层的:用广义 Web3 安全理解品类背景,用以服务为主的审计、监控和合规预算判断今天真实采购行为。[CM001, CM003, CM004, CM005, CM008, CM029]
| 细分 / 品类 | 纳入支出 | 排除支出 | 买方 / 付款方 | 相关性 |
|---|---|---|---|---|
| 广义 web3 安全 | 软件、硬件、服务、合规、监控、咨询 | 与数字资产无关的通用企业网络安全 | 协议、交易所、企业、政府 | 可用于判断品类方向 |
| 智能合约审计市场 | 上线前审计、修复、形式化验证、漏洞赏金搭建 | 通用 SOC 工具、硬件钱包、广义网络安全咨询 | 协议创始人、CTO、工程负责人 | 最接近 CertiK 的传统核心 |
| 持续监控 | 链上告警、钱包筛查、威胁看板、事件响应预付服务 | 没有实时遥测的静态代码审查 | 安全、运营、风险、信任与安全团队 | 经常性收入潜力高 |
| 合规 / AML / 监管准备 | 交易监控、KYC、筛查、监管咨询 | 纯代码审查 | VASP、交易所、机构、法务团队 | 将买方集合扩到 DeFi 之外 |
| 企业 DLT 安全 | 节点安全、架构审查、许可链审计 | 面向散户的代币安全扫描 | 银行、企业、公共部门 | 更接近机构邻域,不是加密原生核心 |
本表按支出类别划定可用市场边界;各行把第三方市场地图与 CertiK 产品覆盖合并来看。
[CM003, CM005, CM008, CM017, CM029]2.2 规模测算口径与市场量级
公开市场规模来源都同意,安全仍是 Web3 技术栈中增长更快的层之一;但它们并不一致地定义被统计的内容。最宽的商业研究口径把 2026 年市场价值放在约 28.6 亿美元,并指向 2030 年接近 68.4 亿美元。更窄的审计公司口径把 2026 年机会收缩到约 10.2 亿美元,因为它剔除了硬件和部分相邻安全软件。两个视角都有用。宽口径解释了为什么大企业、政策参与者和跨链基础设施提供商越来越关心这一领域。窄口径更接近那些仍以代码审查和信任背书起步变现的公司的实际收入池。对 CertiK 来说,现实中位数应是一个 SAM:包括审计、渗透测试、链上监控、节点安全和合规分析,但不包括市场研究机构贴上 Web3 安全标签的每一类硬件或通用网络安全支出。[CM001, CM002, CM004, CM006, CM007, CM025]
| 发布方 | 年份 | 地域 | 数值 | CAGR | 方法 / 注意事项 | 置信度 | 局限 |
|---|---|---|---|---|---|---|---|
| The Business Research Company | 2026 | 全球 | $2.86B | 24.1% 2025→2026 | 广义 web3 安全市场,包含软件、硬件和服务 | 中 | 因纳入硬件和广义服务,夸大了 CertiK 可获得的特定市场 |
| The Business Research Company | 2030 | 全球 | $6.84B | 24.3% 2026→2030 | 广义 web3 安全口径的预测外推 | 中 | 预测值,不是已观察到的支出 |
| Intel Market Research 数据 | 2026 | 全球 | $1.02B | 23.2% 2026→2034 | 狭义智能合约审计和安全公司市场 | 低至中 | 商业细分研究,方法透明度较低 |
| Intel Market Research 数据 | 2025 | 全球 | $0.82B | n/a | 狭义审计公司口径的向后参考点 | 低至中 | 并非直接针对 CertiK |
| 内部尽调视角 | 2026 | 全球 / 偏重加密原生与受监管买方 | 广义 TAM 与狭义审计细分之间的中点 | n/a | 将 CertiK 的 SAM 视为审计 + 监控 + 合规,排除无关硬件支出 | 低 | 需要管理层披露才能细化 |
商业分析报告的品类边界并不一致;这些行应作为方向性视角使用,而不是单一事实来源。
[CM001, CM002, CM004, CM029, CM033, CM034]广义 web3 安全 TAM 很大;把视角收窄到 CertiK 现实可追逐的审计 + 监控服务池后,规模明显缩小。
只有最上面两层有来源支持的数字;下层是概念性拆分,因为没有公开来源单独拆出 CertiK 专属 SAM 或 SOM。
[CM001, CM004, CM008, CM029, CM033, CM034]各个公开视角下市场都不小,但是否纳入硬件和广义服务,会显著改变规模。
中点是尽调中在引用的低值和高值之间插值,不应被误认成已发布预测。
[CM001, CM002, CM004, CM019, CM020, CM027]2.3 买方分层、预算主人与采用路径
买方地图高度异质,而这种异质性塑造了 CertiK 的 go-to-market 经济性。早期协议和代币项目通常购买安全服务,以获得上线可信度、安抚投资人并降低发布风险;工程负责人和创始人往往直接拥有这些决策。成熟 DeFi 团队、交易所和钱包会购买更宽的栈,可能包括持续监控、漏洞赏金、事件响应和合规工具。持牌 VASP 和面向机构的加密公司则走完全不同的采购路径,因为法务、风控、AML 和监管相关方会进入购买中心。企业侧的许可链或代币化资产项目不那么在意零售信任徽章,更在意可审计性、形式化验证,以及能通过采购和合规审查的控制。CertiK 的产品宽度因此重要:窄审计卖家只能捕获发布事件,平台型卖家可以随客户进入运营、监控和高监管负载的工作流。[CM006, CM017, CM018, CM024, CM025, CM026]
| 细分客群 | 购买方 | 用户 | 付款方 / 预算负责人 | 工作流 | 采用触发因素 | 备注 |
|---|---|---|---|---|---|---|
| 启动阶段协议 | 创始人 / CTO | 智能合约工程团队 | 创始人 + 工程预算 | 主网上线前 | 交易所上线、融资、上线可信度 | 初期,审计证书比监控深度更重要 |
| 成熟 DeFi 协议 | 安全负责人 / DAO 运营 | 协议开发者和金库管理人 | 金库 / 协议预算 | 升级周期和事件准备度 | 重复部署、治理变更、TVL 上升 | 监控和漏洞赏金计划开始重要 |
| 交易所 / 钱包 / VASP | 风险、安全、合规负责人 | 运营、AML、信任与安全团队 | 安全 / 风险 / 法务预算 | 交易筛查和生产环境监控 | 牌照、用户增长、事件减少 | 合规和监控可能比代码审计更重要 |
| 企业区块链 / 代币化团队 | CISO、产品、法务 | 内部平台团队 | 创新、安全和采购预算 | 架构评审和控制验证 | 受监管上线或机构客户要求 | 形式化验证和文档很关键 |
| 公共部门 / 监管相关 | 政府机构项目负责人 | 审计人员和监督团队 | 项目预算 | 评估或采购审查 | 政策现代化和安全试点 | 短期收入较小,但信号价值高 |
买方角色因细分市场差异很大;因此 CertiK 需要多个预算切入口,而不是只靠一套统一的 GTM 话术。
[CM006, CM017, CM018, CM024, CM025, CM030]当客户从加密原生上线走向受监管运营,预算负责人和采用触发因素都会变化。
[CM006, CM017, CM018, CM024, CM025, CM030]2.4 驱动因素、约束与 ROI 逻辑
需求很容易解释:攻击损失仍然巨大、可见且反复发生。Immunefi 称,2025 年第一季度单季损失就超过 16 亿美元;CertiK 自己的 2026 年上半年研究则认为,即便表面比较看起来更好,底层环境已经恶化。这些损失数据支撑了预防性审查和实时监控的 ROI 逻辑。不过,价格数据也解释了买方为何仍会谨慎比价。简单合约的审计可以便宜,但复杂多链系统会很贵;紧急程度和特定链人才稀缺还会进一步抬价。与此同时,市场受制于资深审计师稀缺、方法碎片化,以及买方对品牌证书和真正穷尽式审查之间深度差异的怀疑。实践中,最耐久的提供商是能把发布期保障、上线后监控、合规情报,以及在投资人或交易所处的声誉连接起来的公司。今天 CertiK 的战略逻辑在这个区域最强,但这恰好也是品类中竞争最激烈的部分。[CM009, CM010, CM011, CM012, CM013, CM014]
| 驱动因素 / 约束 | 方向 | 时间 | 影响 | 尽调问题 |
|---|---|---|---|---|
| 漏洞利用损失仍大且可见 | 正向 | 当前 | 支撑审计和监控的预防性支出 ROI | 重大事件后能带来多少销售管线转化? |
| 监管和 AML 要求持续加码 | 正向 | 当前 / 中期 | 推动买方转向监控和合规产品 | 当前收入有多少来自合规驱动的买方? |
| 混合评审 + 持续监控逐渐成为标配 | 正向 | 当前 | 相比一次性顾问,更利好更宽的平台 | CertiK 客户中有多少比例购买多个模块? |
| 高级审计员短缺 | 负向 | 当前 | 带来积压风险和薪酬通胀 | CertiK 如何招聘并留住稀缺评审人员? |
| 审计方法受质疑、品牌稀释 | 负向 | 当前 | 可能挤压定价权,并增加采购审查 | 各项目有哪些 QA 或二次评审控制? |
| 多链复杂度与非 EVM 增长 | 混合 | 中期 | 提高付费意愿,也加重执行负担 | 收入有多少集中在 EVM,又有多少来自跨链? |
各行把需求增长同实际采购摩擦连起来;多项影响在承销前需要管理层确认。
[CM009, CM011, CM014, CM019, CM021, CM023]支出通常从上线时的信任背书开始;项目活到规模化后,会扩展到月费监控和合规。
[CM016, CM017, CM019, CM026, CM027, CM035]2.5 展示项
03竞争对手
3.1 格局形态与同业集合
CertiK 周边竞争场很宽,结构上也碎片化。仅发现类来源就浮现几十个替代者,广义市场地图仍列出一大批具名公司,而不是一个集中的双寡头。但在实践中,对严肃协议和机构来说,心智名单会压缩成更小的一组品牌:CertiK、Quantstamp、Trail of Bits、OpenZeppelin、Consensys Diligence、Sigma Prime、Halborn 和 Hacken 反复出现在排名、市场地图和买方指南中。这个同业篮子比长尾目录更重要,因为智能合约审计和监控的信任市场高度由声誉驱动。即便如此,竞争对手并不可互换。有些公司以深度安全工程或协议研究领先,有些靠生态标准工具或与 Ethereum 的接近性领先,还有一些主打更宽的信任、合规和监控平台。当买方需要宽度和可见规模时,CertiK 最有竞争力;当买方只需要最窄的专家审查时,它并非最佳形态。[CP001, CP002, CP013, CP018, CP023, CP033]
| 公司 | 核心定位 | 核心范围 | 目标客户 | 战略方向 |
|---|---|---|---|---|
| CertiK | 平台型信任服务商 | 审计 + 监控 + 渗透测试 + 合规 | 协议、交易所、钱包、机构 | 扩大经常性安全和公开信任触点 |
| Quantstamp | 审计 + 持续安全 + 保险 | 审计、监控、Chainproof | Web3 团队和机构相关项目 | 扩大托管安全覆盖面 |
| Trail of Bits(专家) | 研究驱动的安全工程公司 | 审计、研究、工具、链下安全 | 复杂协议、密码学密集型建设者 | 靠深度和跨学科安全专长取胜 |
| OpenZeppelin | 链上金融安全标准 | 审计 + 标准库 | 主要 Ethereum 协议和机构 | 借生态标准工具切入服务 |
| Consensys Diligence | Ethereum 原生设计评审伙伴 | 智能合约审计和安全评审 | Ethereum 协议、L2、机构 | 占住高信任 Ethereum 评审关系 |
| Sigma Prime | 基础设施和协议专家 | 区块链审计 + 协议工程 | L1/L2 建设者、验证者运营方 | 从 Ethereum 核心基础设施延伸护城河 |
| Hacken / Halborn | 合规或广义数字资产安全伙伴 | 审计加更广的安全 / 合规服务 | 交易所、Web3 项目、企业 | 靠广度、进攻性安全和保障能力竞争 |
各行概括主要竞争原型,而不是逐项列出每家公司公开提供的所有服务线。
[CP002, CP003, CP005, CP006, CP008, CP009]这个赛道分成广义信任平台和专精深度玩家;CertiK 在广度上最强,但严谨性并非无人挑战。
轴是定性判断(x 轴为广度,y 轴为专精深度),反映公开定位,而非实测分数。
[CP003, CP005, CP006, CP008, CP009, CP011]3.2 直接竞争者画像
直接同业分属不同战略原型。Quantstamp 把审计与持续监控、保险式风险转移结合,吸引想要安全项目而非单份报告的团队。Trail of Bits 销售研究深度、工具和更广泛的应用安全能力,在复杂密码学、链下和基础设施范围内具备可信度。OpenZeppelin 受益于其标准库和长期协议关系的引力;Consensys Diligence 在 Ethereum-native 设计审查和面向机构的可信度上尤其强。Sigma Prime 借 Lighthouse 等产品带来基础设施和验证者深度;Hacken 更偏合规和证明导向的保障。Halborn 更接近广义数字资产安全咨询公司。在这个背景下,CertiK 突出的原因并不是它在每个范围内都显然是最深的专家,而是它把审计工作与 Skynet、渗透测试和公共信任界面结合起来,能在客户上线后继续扩展。[CP003, CP004, CP005, CP006, CP007, CP008]
| 能力 | CertiK | Quantstamp | Trail of Bits(专家) | OpenZeppelin | Consensys Diligence | Sigma Prime |
|---|---|---|---|---|---|---|
| 智能合约审计 | 强 | 强 | 强 | 强 | 强 | 强 |
| 持续监控 / 实时安全 | 强 | 强 | 中等 | 中等 | 中等 | 中等 |
| 形式化验证定位 | 强 | 强 | 中等 | 中等 | 中等 | 中等 |
| 链下 / 基础设施深度 | 中等 | 中等 | 强 | 中等 | 中等 | 强 |
| 合规 / 机构匹配度 | 强 | 中等 | 中等 | 强 | 强 | 中等 |
| 工具 / 生态锁定 | 中等 | 中等 | 强 | 强 | 强 | 强 |
能力强弱是基于公开定位的方向性总结,不是实验室测试基准。
[CP003, CP005, CP006, CP008, CP009, CP011]当买方需要审计加上线后项目时,CertiK 和 Quantstamp 最强;OpenZeppelin、Consensys 和 Sigma Prime 则靠工具或协议深度锚定信任。
这些值是基于公开定位和产品界面归纳出的定性层级。
[CP003, CP005, CP006, CP008, CP009, CP011]3.3 能力、定价与分发力量
这个市场的竞争力不只来自审计数量。官方页面和买方指南指向三条耐久护城河:技术深度、分发和信任带动。技术深度体现在协议或基础设施专长、形式化验证,以及保护非 EVM 或密码学系统的能力。分发来自库、工具生态、验证者产品、合作伙伴关系,以及在协议生命周期中成为默认安全触点的能力。信任带动则出现在审计报告上的一个 logo 能实质改善融资、上所或机构采购时。最后一点也解释了定价权。公开指南显示报价范围极宽,从低端代币审计到超过六位数美元的高端多链审查都有。多数官方竞争对手不发布菜单价,因此品牌、范围复杂度和速度成了事实上的定价杠杆。CertiK 在这里拥有最清楚的宽度故事;但 OpenZeppelin 和 Consensys 往往有更强生态分发,而 Trail of Bits 和 Sigma Prime 在实践中可以收取专家深度溢价。[CP014, CP015, CP016, CP017, CP019, CP021]
| 维度 | 观察 | 对 CertiK 的影响 | 来源依据 | 尽调问题 |
|---|---|---|---|---|
| 标价 | 多数头部公司不公布固定菜单价 | 品牌和谈判仍是赢单率核心 | 官方网站与 Sherlock 指南 | 收集 3-5 家供应商真实报价 |
| 价格区间 | 智能合约审计价格从约 $5K 到 $250K+ | 复杂或机构项目上,CertiK 可以守住溢价 | Sherlock 定价参考 | 按范围复核 CertiK ASP |
| 复审经济性 | 修复复审通常增加 $5K-$20K | 标价更低,不一定总成本更低 | Sherlock 定价参考 | 检查后续复审附加率 |
| 层级效应 | 顶级证书带来融资和上币价值 | 声誉可以支撑溢价定价 | Sherlock 定价参考 | 验证 CertiK 品牌带来的转化提升 |
| 打包差距 | 附加经常性监控或合规可以拉大 ACV | CertiK 的平台宽度可以压过只做审计的同行 | CertiK 与竞争对手产品页 | 衡量多产品 ACV 提升 |
官方竞争对手网站大多基于报价,因此打包观察依赖市场参考指南和产品版图,而不是公开价目表。
[CP016, CP017, CP024, CP025, CP026, CP035]最耐久的竞争信号,是定价权、分发能力、产品宽度,以及上线后仍能持续创造价值的能力。
竞争对手集合没有披露标准化财务 KPI,因此这里混合使用计数、价格区间和方向性的覆盖宽度标记。
[CP001, CP004, CP007, CP009, CP017]3.4 转换成本、多供应商并用与护城河风险
竞争分析中最大的误判,是假设审计买方一次合作后就会被永久锁住。现实中,多供应商并用很常见:蓝筹协议会把具名公司审计与竞赛、漏洞赏金和持续监控混合使用,许多团队也会轮换审查方以减少盲区。这削弱了每个主要供应商的硬锁定,包括 CertiK。最能守住价值的公司,是那些能在初始报告之后继续销售基础设施、合规、实时监控或嵌入式工作流影响力的公司。CertiK 平台扩张的战略意义就在这里。它在一定程度上抬高转换摩擦,尤其是在 Skynet 或其他上线后工具被嵌入运营时。但同一策略也带来暴露。如果买方开始把 CertiK 视为宽泛、默认或打勾选项,专家品牌可以从上方用严谨度进攻,低价替代者则从下方用价格蚕食。公开的审计后事件案例也强化了一个事实:没有哪个领先品牌能对声誉风险免疫。[CP025, CP026, CP029, CP030, CP031, CP032]
| 风险或护城河 | 方向 | 重要性 | 谁给 CertiK 施压 | 监控信号 |
|---|---|---|---|---|
| Skynet 和上线后工具 | 护城河 | 把切换摩擦抬高到一次性报告之外 | Quantstamp、Hacken 和其他监控供应商 | 多产品续约率 |
| 生态标准工具 | 风险 | OpenZeppelin 和 Consensys 可把信任与工作流标准打包 | OpenZeppelin、Consensys | 企业 / Ethereum 原生交易流失率 |
| 研究深度型专家溢价 | 风险 | 深度专家能赢下最复杂项目 | Trail of Bits 与 Sigma Prime | ZK、协议和基础设施审计胜率 |
| “打勾式审计”印象 | 风险 | 规模会引来对深度和质量的质疑 | 精品专家公司和批评者 | 客户访谈、审计后事故提及 |
| 商品化代币审计 | 风险 | 低端项目面临价格竞争和大量替代者 | 长尾审计机构 | 简单项目平均售价 |
| 公开客户证据带来的声誉 | 护城河 | 客户证言和公开规模指标提升入围转化 | 所有主要同行 | 具名客户新增和推荐质量 |
该清单关注战略耐久度,不只看技术实力;多项信号需要私有管线数据确认。
[CP011, CP012, CP019, CP025, CP029, CP031]3.5 展示项
04财务
4.1 资本历史与披露规模
CertiK 的公开财务记录,最强在融资里程碑,最弱在已审计经营报表。公司自己披露,2021 年末 B2 轮把总投资推高到 1.4 亿美元以上;几个月后又称 B3 融资将公司估值推到 20 亿美元,并把九个月融资额提高到 2.3 亿美元。独立媒体补充了有用确认和背景:TechCrunch 将 2022 年融资描述为一轮 8,800 万美元融资,参与方包括 Goldman Sachs;Yahoo Finance 和 The Block 的 2026 年报道则把 CertiK 描述为一家反复融资的公司,自成立以来融资约 2.96 亿美元,并获得 Binance 支持的新一轮数千万美元后续投资。合在一起,这些证据支持一个画像:公司在 2021-2022 周期成功为快速增长融资,并在 2026 年仍保有战略投资人支持。它没有提供的,是干净的当前股权表、当前现金余额,或 2022 年估值锚之后更新的定价轮估值。[CI001, CI002, CI003, CI004, CI005, CI033]
| 时期 | 公开数据点 | 含义 | 来源依据 | 置信度 |
|---|---|---|---|---|
| 2021 B2 轮 | 总投资额 > $140M | 2022 年估值跃升前,资本规模已经不小 | CertiK 官方文章 | 中 |
| 2022 B3 轮 | 估值 $2B;此前 9 个月融资 $230M | web3 基础设施高峰周期里,投资人迅速上调估值 | CertiK 官方文章 | 中 |
| 2022 媒体确认 | Goldman 参与的 $88M 融资 | 传统金融入局验证了品类兴趣 | TechCrunch | 中 |
| 2024 Ventures 基金 | 宣布 $45M 生态基金 | 资本用于战略部署,而不只是防守 | Crypto Economy | 中 |
| 2026 后续融资 | 据报道,Binance 支持了一笔数千万级投资 | 现有战略投资者仍支持公司 | The Block / Yahoo | 中 |
表仅总结公开里程碑;不是完整 cap table,也不是法律意义上的完整融资历史。
[CI001, CI002, CI003, CI004, CI005, CI006]资本里程碑在公开资料中可见,但经营报表不可见。
KPI 值来自公开公告和媒体报道,不是经审计财务报表。
[CI001, CI002, CI004, CI005, CI006]4.2 收入模式与定价机制
公开材料强烈暗示,CertiK 已不再只是审计店。公司自己的文章把收入增长同时归因于核心审计业务和 Skynet 等产品线;当前产品界面显示,变现横跨智能合约审计、监控、以合规为核心的数据工具和渗透测试。这很重要,因为每条线的收入行为不同。审计工作仍是报价制,很可能波动较大,定价取决于范围、紧急程度、链和专家深度。Sherlock 的市场基准给出了区间:小合约可以在几千美元低段成交,标准 DeFi 工作通常在数万美元,复杂多链或 ZK 重范围在后续修复复审前就可能超过 25 万美元。经常性监控和数据产品应更可重复,也更少依赖一次性发布周期。合规内容和形式化验证叙事还指向更高价值的机构预算,因为客户关心的是保障连续性,而不只是一份 PDF 报告。[CI010, CI011, CI012, CI013, CI014, CI015]
| 收入线 | 模式形态 | 公开材料证据 | 可能经济性 | 关键未知 |
|---|---|---|---|---|
| 智能合约审计 | 项目制服务 | 审计产品页和方法论文章 | ASP 高,但对利用率敏感 | 平均交易规模和利润率 |
| 复审 / 修复 | 后续服务 | 市场参考显示额外复审常见单独收费 | 抬高实际合同价值 | 每次初始审计的附加率 |
| Skynet 监控 | 经常性订阅或平台收入 | Skynet 页面和 2021 年增长表述 | 比上线审计更可复用 | ARR、流失率和定价层级 |
| SkyInsights / 数据 API | 经常性数据或企业工具 | 文档和 demo 显示产品化数据界面 | 毛利率可能接近软件 | 付费用户数和定价 |
| 合规 / 渗透测试 | 咨询加持续保障 | SOC 2 内容和渗透测试页面 | 可以拉大 ACV,并提升企业相关性 | 非 crypto 原生买方收入占比 |
经济性是方向性判断,因为 CertiK 不公布分部收入或定价层级。
[CI010, CI012, CI013, CI014, CI015, CI031]| 指标 | 低 | 基准 / 中点 | 高 | 尽调用途 |
|---|---|---|---|---|
| 初始审计价格 | $5K | $25K-$100K | $250K+ | 按范围对标 CertiK 可能 ASP 区间 |
| 修复复审 | $5K | $12.5K | $20K | 估算实际合同总价值 |
| 加急溢价 | 20% | 30% | 40% | 建模加急产能的定价权 |
| 相对 EVM 的专项溢价 | 25% | 60% | 120% | 建模 Rust、Cairo、Move、ZK 项目的组合影响 |
| 成熟协议年度安全预算 | $150K | $325K | $500K | 估算初次上线之外的客户预算份额 |
多数数字来自 Sherlock 2026 年市场参考,是全市场基准,不是 CertiK 专属报价卡。
[CI016, CI017, CI018, CI019, CI020, CI021]CertiK 核心服务的财务边界,可能会随范围和紧急程度大幅变化。
中位数是根据已发布市场低位和高位参考做出的尽调插值,不应被误认为 CertiK 的标价。
[CI016, CI017, CI018, CI019, CI020, CI021]CertiK 似乎正把经常性产品叠在服务之上,向更高质量收入迁移。
矩阵基于产品界面和市场惯例做出分析推断,不是披露的内部分部模型。
[CI012, CI013, CI014, CI015, CI024, CI031]4.3 增长耐久性与公开市场故事
对 CertiK 财务故事的乐观解读是,公司用风险资金从劳动密集型审计扩展成更宽的安全平台,并获得更好的扩张经济性。公司声称的指标——收入增长 20x、年度收入增长 12x、2022 年初同比收入增长 4x、Skynet 预订收入增长 2,300%——显然带有宣传性,但方向上符合观察到的产品扩张和融资节奏。即便只有部分准确,也意味着 CertiK 在加密基础设施建设期获得了强经营杠杆。2026 年 IPO 叙事建立在这个平台化框架之上:管理层和媒体报道把公司呈现为首个上市 Web3 网络安全公司的候选者,而不是单周期咨询公司。不过,这个故事面临真实摩擦。公开争议、缺失的已审计报表和没有分部披露,使投资人无法区分经常性软件收入与项目服务,也无法把耐久利润率和牛市抬升拆开。Circle 最近的 S-1/A 也显示了公开市场投资人现在期待的披露标准。结论是:股权叙事有吸引力,但按公开市场质量看,证据仍偏薄。[CI006, CI007, CI008, CI009, CI021, CI024]
| 维度 | 公开信号 | 帮助在哪里 | 信心仍卡在哪里 | 净判断 |
|---|---|---|---|---|
| 品类叙事 | 首个公开 web3 网络安全叙事 | 支撑差异化投资者叙事 | 小众品类筛选时仍可能被当作加密 beta | 正面但未证实 |
| 规模叙事 | 过往大额融资与老股东持续支持 | 传递机构背书 | 无经审计收入或利润率披露 | 参半 |
| 经常性收入叙事 | Skynet 与数据产品暗示有订阅收入 | 可能支撑更高质量的估值倍数 | 分部结构与留存未披露 | 参半 |
| 治理 / 声誉 | 媒体报道让管理层保持曝光 | 有助于公众认知 | 争议会加重尽调负担 | 负面抵消 |
| 交易准备度 | 管理层公开谈 IPO 目标 | 保留该选项 | 未披露申报、时间表或投行 | 早期 |
该评分卡汇总公开准备度指标,不构成承销意见。
[CI025, CI026, CI027, CI028, CI035, CI036]CertiK 有可信的 IPO 叙事,但公开披露质量仍低于公开市场预期。
这些值是基于媒体报道、SEC 申报基准和产品证据形成的定性尽调判断,而非任何正式准备度评估。
[CI025, CI026, CI027, CI028, CI029, CI035]4.4 仍未建模的内容
最大的尽调挑战不是缺少增长信号,而是缺少分母数据。公开来源没有披露积压订单、续约、流失、毛利率、客户集中度、平均审计周期,或从审计附着到监控与合规的比例。即便公司资料网站给出基础收入估计,也要么无法访问、要么方法说明很轻、要么没有已审计文件支撑。这意味着现实模型仍必须自上而下,用价格区间、人员假设和产品采用假设来搭建。实际结论很直接:CertiK 可能比纯审计精品店拥有更好的业务,因为它销售更多界面并能扩展到经常性工具;但外部观察者不应把这种定性优势误当成精确度。管理层披露分部组合、利润率结构和客户队列行为之前,财务章节应被视为有边界的推断练习,而不是完整预测。[CI022, CI029, CI030, CI031, CI032, CI035]
4.5 展示项
05产品与技术
5.1 套件地图与客户工作流
CertiK 已不再像单产品审计公司。公开界面现在描述的是一套产品:从代码安全审计开始,延伸到渗透测试和持续监控,再叠加合规、交易风险和 AI 安全产品。这个宽度重要,因为它改变了公司嵌入客户工作流的方式。早期协议或钱包可以先做智能合约审计,用渗透测试加固链下界面,通过 Skynet 评分接受社区审视,随后采用 SkyInsights 处理 AML 或交易监控工作流。YZi 合作把形式化验证、Skynet boost 和 AI 扫描打包成组合支持方案,进一步强化了这种捆绑姿态。Gem Wallet 审计公告等客户证据显示,产出既是内部工程交付物,也会作为外部信任信号运作。实际结论是,CertiK 正把自己设计成 Web3 项目的生命周期安全层,而不只是一次性审查提供商。[CE001, CE003, CE006, CE022, CE026, CE027]
| 模块 | 主要用户 | 当前状态 / 成熟度 | 差异化 | 尽调缺口 |
|---|---|---|---|---|
| 智能合约审计 | 协议、钱包、交易所 | 成熟旗舰服务 | 形式化验证品牌与大型审计样本库 | 需要当前人员结构与交付周期数据 |
| 渗透测试 | 应用、钱包、交易所 | 已成型的相邻服务 | 将覆盖延伸到链下和应用层安全 | 需要方法论深度与重复采购节奏 |
| Skynet / Top Board | 社区、投资者、风控团队 | 广泛的公开情报入口 | 项目评分加研究打包 | 需要评分治理与可靠性细节 |
| SkyInsights | 合规、AML、风控团队 | 需认证的 API 产品 | 实体标签、风险评分、筛查、交易分析 | 需要价格档位与使用指标 |
| CertiK Skills | 开发者、研究员、agent | 活跃开源集成入口 | agent 原生封装,接入门槛低 | 需要仓库活跃度与发布节奏细节 |
| Skill Scanner | AI 市场、企业、开发者 | 新相邻产品 | 执行阶段 AI 技能风险评估 | 需要外部验证与采用证据 |
这些行仅汇总公开可见的模块入口,不是完整内部 SKU 目录。
[CE001, CE003, CE006, CE010, CE022, CE031]| 用户任务 | 当前工作流 | CertiK 方案 | 可衡量收益 | 限制 |
|---|---|---|---|---|
| 上线前代码加固 | 发布前审查智能合约 | 智能合约审计 | 找出漏洞并发布信任信号 | 时间与范围仍由销售牵引 |
| 应用 / 链下加固 | 评估 API、钱包和应用层 | 渗透测试 | 覆盖非合约攻击面 | 公开方法论深度有限 |
| 持续项目审查 | 持续检查协议安全态势 | Skynet 评分与报告 | 持续公开评分与行业研究 | 公开评分模型仍有部分专有逻辑 |
| AML / 合规审查 | 筛查地址和交易 | SkyInsights | 实体标签、风险、筛查、交易分析 | 需要凭证;价格未公开 |
| agent 工作流中的攻击事件 / 代币分诊 | 快速调查交易或代币合约 | Skylens、Token Scan、Skynet Score 技能 | 开发者或分析师可快速集成 | 依赖公开端点与工具在线率 |
收益是基于公开产品描述得出的工作流层面解读,不是结果研究。
[CE003, CE008, CE012, CE013, CE015, CE016]产品套件沿客户路径展开:先做上线前加固,再进入持续监控、合规和调查。
流程展示的是公开资料最能支撑的生命周期;个别客户可能只购买其中一部分模块。
[CE003, CE006, CE015, CE016, CE026, CE031]5.2 架构与开发者触点
公开材料中最强的技术证据来自 CertiK 的 API 和 GitHub 界面。SkyInsights 显然是一个认证企业 API,具备版本化 base URL、明确认证头、标准响应码,以及标签、地址风险、筛查和交易风险等端点族。基于 GitHub 的 CertiK Skills 仓库增加了第二层重要能力:它把 CertiK 数据转成 agent-native 工具,配有定义好的命令、脚本入口点,以及用于 Skynet Score、Skylens 和 Token Scan 的公共端点。这不只是营销文案。Skylens 暴露 trace、state、balance、nonce 和源文件操作;Token Scan 暴露结构化合约风险检查;SkyInsights 则为需要凭证的运营筛查接好线。合在一起,这些界面暗示其架构由评分引擎、监控管线、认证合规数据和轻量开发者适配器组成。它让套件比以 PDF 为中心的服务业务更容易集成,但也意味着产品故事取决于 API 可用性、数据质量,以及多个界面的集成维护。[CE008, CE009, CE010, CE011, CE012, CE013]
| 层 / 组件 | 作用 | 依赖 | 风险 |
|---|---|---|---|
| 审计方法论 + 形式化验证 | 部署前保障引擎 | 安全研究员、审查工作流 | 人员配置与吞吐数据不透明 |
| Skynet 评分层 | 公开项目评估与 Top Board 研究 | 专有评分逻辑与受监测项目数据 | 模型治理不透明 |
| SkyInsights API | 需认证的合规与风险分析 | api.skyinsights.certik.com、凭证、标签库 | API 可用性与数据质量依赖 |
| Skylens 取证工具 | 交易级事件调查 | skylens.certik.com 与 zstd 工具 | 相比简单评分产品,运营复杂度更高 |
| Token Scan 公开 API | 面向开发者和 agent 的合约风险检查 | open.api.certik.com token-scan 端点 | 公开端点限制与数据新鲜度 |
| 市场数据增强 | 为 Skynet 输出补充背景 | CoinGecko API 集成 | 第三方数据依赖 |
| GitHub skills 封装 | 开发者与 agent 采用层 | 公开仓库维护 | 发布节奏与支持可见度 |
架构根据产品页面、文档和 GitHub 界面重建;CertiK 没有发布单一权威技术图。
[CE009, CE010, CE012, CE013, CE014, CE016]公开资料支持一个分层架构:从面向客户的服务一路向下,延伸到 API、评分引擎和开发者适配器。
产品栈基于多个公开界面综合而成;CertiK 没有发布覆盖所有模块的统一产品架构图。
[CE001, CE009, CE010, CE017, CE028, CE035]除审计专长外,CertiK 的技术叙事还依赖 API、数据合作伙伴、公开开发者界面和外部信任循环。
DAG 只聚焦外部可见依赖,不覆盖每个内部模型、供应商或数据源。
[CE014, CE017, CE018, CE027, CE028, CE030]5.3 差异化、信任控制与产品化
CertiK 的差异化不只是产品多,而是这些产品似乎共享同一层信任与情报能力。主页强调形式化验证和大规模审计产出,SkyInsights 聚焦结构化风险标签和交易监控。Skynet 再把这种安全姿态包装成公开排名和面向市场的研究。CoinGecko 案例研究把设计讲得更具体:Skynet 将安全数据与外部市场数据融合,让用户同时评估风险和市场背景。2026 年预测市场报告和 AI-agent leaderboard 说明,CertiK 能把底层机器转化为可重复的行业产品,而不只是定制项目。信任控制让故事更厚。公开的 SOC 2 Type II 和 ISO 27001 凭证,加上关于企业尽调预期的指引,显示公司知道买方越来越关心产品周围的控制环境,而不只是产品内部的漏洞发现。整体上,这支持平台论点——但这一论点仍主要经由较高层级的公开证据传递,而不是深度工程披露。[CE002, CE004, CE005, CE017, CE018, CE019]
| 控制 / 认证 | 状态 | 范围 | 缺口 |
|---|---|---|---|
| SOC 2 Type II | 公开展示 | 企业尽调 / 控制鉴证 | 公开报告本体未纳入材料集 |
| ISO 27001 | 公开展示 | ISMS 与国际买家信任 | 此处未呈现证书细节 |
| SkyInsights 认证模型 | 已有文档 | 凭证门控的企业 API | 无公开限流或正常运行时间承诺 |
| 标准化 API 响应 | 已有文档 | 文档说明成功 / 错误行为 | 除 v4 基础 URL 外,无公开 schema 版本策略 |
| 公开合作伙伴集成 | 由 CoinGecko 合作伙伴确认 | 为 Skynet 注入市场数据增强 | 依赖连续性未知 |
本表聚焦外部可见的控制与信任机制,不覆盖未公开记录的内部 QA 流程。
[CE009, CE017, CE028, CE029]CertiK 在审计、监控和 API 产品上成熟度看起来最强;AI 技能安全较新,外部验证也更少。
矩阵值是基于公开证据形成的定性尽调判断;CertiK 没有为每个模块发布标准化成熟度记分卡。
[CE004, CE005, CE007, CE010, CE022, CE025]5.4 成熟度信号与技术缺口
公开成熟度信号有意义,但不均衡。正面看,CertiK 暴露了审计发现、监控项目、活跃用户、地址标签和事件检测等指标;发布当前文档;维护面向开发者的 Skills 仓库;并持续推出相邻产品和垂直报告。这些都是活平台的迹象。缺口同样重要。公开指标界面在不同资产之间并未完全统一,没有按模块发布的详细公开路线图,这组来源也没有浮现状态页、公开 SLA 或详细可靠性历史。结果是一个宽、活跃且可信的产品与技术故事,但在企业尽调团队希望看到更深运营证据的地方,仍部分不透明。尽调的关键问题已不再是 CertiK 是否拥有产品宽度,而是这份宽度底下,是否配有足够成熟的运营纪律、可观测性和发布严谨度。[CE007, CE023, CE024, CE025, CE033, CE034]
| 日期 / 阶段 | 功能或里程碑 | 状态 | 含义 | 来源 |
|---|---|---|---|---|
| 2026 年当前 | CertiK Skills 仓库公开 | 已上线 | 释放 agent 原生 GTM 与开发者分发信号 | CertiK 博客 + GitHub |
| 2026 年当前 | Skill Scanner 发布 | 已上线 / 新品 | 显示向 AI 技能安全相邻扩张 | Skill Scanner 博客 |
| 2026 年当前 | Prediction Markets Top Board 报告发布 | 已上线 / 经常性研究入口 | 显示行业打包与可复用评分输出 | Skynet 报告 + 媒体 |
| 2026 年当前 | AI-agent Top 10 排行榜出现 | 已上线垂直应用 | 将 Skynet 延伸到新品类排名 | BlockchainReporter |
| 2026 年当前 | YZi 合作把形式化验证、Skynet 提升和 AI 扫描打包 | 已上线合作动作 | 显示孵化场景下的多模块打包 | CertiK 合作文章 |
公开路线图证据来自事件和营销展示;没有可用的带日期发布待办清单。
[CE021, CE022, CE024, CE025, CE026, CE034]5.5 展示项
06客户
6.1 客户是谁
CertiK 的客户群已不能简单描述为“需要审计的项目”。公开记录指向几个不同分层:需要代码审查和上市可信度的发布期协议;需要更深安全评估或储备证明的钱包和交易所;需要 AML 与交易风险工具的机构或合规驱动买方;以及希望把可信安全供应商嵌入创始人支持的生态项目。这个组合很重要,因为套件里的买方、用户和付款方并不总是同一方。协议创始人可能购买审计,钱包运营团队可能使用持续监控,合规负责人可能采购 SkyInsights。公司也似乎正在 AI-agent 开发者和市场中打开一个更新的分层,尤其通过 Skills 和 Skill Scanner。多样性的上行是,CertiK 可以参与 Web3 生命周期的多个环节。代价是,公开证据必须按分层细分,而不能当作一个无差别客户故事处理。[CU001, CU003, CU004, CU017, CU018, CU025]
| 客群 | 买方 / 用户 / 付款方 | 用例 | 规模信号 | 战略价值 | 缺口 |
|---|---|---|---|---|---|
| 启动阶段协议 | 创始人 / CTO / 财库 | 上线前智能合约审计与上币信任背书 | 审计页显示 6,159+ 个已审计项目 | 客户 logo 数量多,能播种销售管线 | 无平均合同规模或复购率 |
| 钱包 | 安全负责人 / 产品 / 公司 | 应用和钱包安全评估,加公开信任信号 | Gem Wallet 与 Bitget Wallet 案例 | 公开证据较强,并带来下游用户信任 | 未披露钱包客户收入占比 |
| 交易所 / 托管场所 | 风险、平台安全、管理层 | 储备证明、交易所审计、钱包安全、合规界面 | Gate Dubai 与 OKX 案例 | 战略价值高,与机构信任高度相关 | 具名案例少,缺少经济性 |
| 机构 / 合规买家 | 合规、AML、风控团队 | SkyInsights 筛查、标签、交易风险工作流 | SkyInsights 定位与 Hub71 合规工具 | 可能带来经常性企业支出 | 无客户名称或价格档位 |
| 生态 / 孵化器渠道 | 项目经理、创业平台、投资者 | 补贴审计、合规工具访问、合作伙伴转介 | Hub71 与 YZi 项目 | 高效播种未来客户 | 从项目转为付费账户的转化未知 |
| AI-agent 开发者 / 市场 | 开发者、企业、市场 | Skills、Skill Scanner、链上 agent 安全检查 | OKX AI 与 Skill Scanner 发布 | 新的相邻需求池 | 太新,缺少持久采用证据 |
买方、用户和付款方往往因模块而异,因此分群基于最有公开支撑的工作流,而不是单一 CRM 分类法。
[CU001, CU003, CU014, CU016, CU017, CU024]| 路径 | 进入界面 | 为何带动采用 | 什么会阻碍扩张 | 来源依据 |
|---|---|---|---|---|
| 头部交易所推荐效应 | 审计页面声誉和交易所推荐 | 提升新代币或协议上线时的短名单转化 | 品牌受损会迅速反转信任背书 | 审计页面 + Yahoo |
| 生态孵化器项目 | Hub71 与 YZi 的创业公司支持动作 | 降低获客成本,并提前培育未来账户 | 项目采用未必转化为付费工作 | Hub71 + YZi 帖文 |
| 合规驱动的企业销售 | SOC 2、ISO 27001 和 SkyInsights 工作流 | 打开银行、VASP 和机构客户入口 | 需要长尽调周期和控制证据 | SOC 2/ISO 指南 + SkyInsights 页面 |
| 嵌入式数据集成 | OKX 内的 Skynet 评分,以及 OKX AI 内的服务 | 让 CertiK 进入客户工作流,而不是停留在外部供应商 | 依赖伙伴分发和 API 可靠性 | OKX 文章 + TechCrunch |
采购路径根据公开部署界面和买方指引推断,并非来自直接销售流程披露。
[CU012, CU013, CU014, CU016, CU018, CU019]CertiK 最强的公开客户路径,是从上线安全切入,延伸到监控、信任背书,最终走向合规或平台级扩张。
旅程基于具名客户案例和产品界面综合而成,并非来自披露了转化率的转化漏斗。
[CU001, CU010, CU012, CU014, CU019, CU022]6.2 具名客户验证与采用质量
最强的采用证据来自具名客户案例:CertiK 的工作可见,客户也说明交付内容。Gem Wallet 是最好的例子之一,因为结果具体:2026 年 4 月发布的 iOS 和 Android 评估,零个严重或高危发现,六个已解决中危问题,以及 Skynet 上的公开实时档案。Gate Dubai 提供了另一个高质量验证点,因为范围是运营性的,而不只是叙事:CertiK 用 Merkle-tree 流程验证负债,并通过十种范围内资产的链上交易验证储备控制。OKX 展示的是账户扩张,而不是一次战术项目,覆盖交易所、钱包、智能合约和产品集成界面。Hub71 和 YZi 式合作带来另一类证明:不是深度部署细节,而是 CertiK 被用作生态基础设施伙伴,用来获取并塑造未来客户。整体看,这些例子支持真实采用,但证据在整个客户群上仍是选择性的,而非系统性的。[CU005, CU006, CU007, CU008, CU009, CU010]
| 指标 | 数值 | 日期 | 来源 | 置信度 | 含义 | 缺失分母 |
|---|---|---|---|---|---|---|
| 服务客户数 | 5,500 | 当前客户证言页 | 官方客户证言 | 中 | 客户覆盖广是真实的 | 未区分活跃与历史客户 |
| 已评估市值 | $472B | 当前客户证言页 | 官方客户证言 | 中 | 证明服务覆盖经济价值较大的项目 | 不是收入指标 |
| 检出问题数 | 117,000 | 当前客户证言页 | 官方客户证言 | 中 | 大型审查样本库支撑模式学习优势 | 无单项目发现项分布 |
| 已审计项目 | 6,159+ | 当前审计页 | 官方审计页 | 中 | 审计客户体量大 | 无重复项目占比 |
| 形式化验证项目 | 1,227+ | 当前审计页 | 官方审计页 | 中 | 高级保障工作在客户基数中并不小众 | 无付费范围占比 |
| Skynet MAU | 1.8M+ | 当前首页 | 官方首页 | 中 | 面向社区的采用规模可观 | 与付费客户的重叠度未知 |
这些采用数据来自公司口径,只能作为方向性参考;公开记录没有对历史用户、活跃用户和付费账户数做口径调和。
[CU002, CU003, CU004]| 客户 | 客群 | 部署 / 使用场景 | 生产 / 试点 | 结果 | 局限 |
|---|---|---|---|---|---|
| Gem Wallet | 消费者钱包 | 覆盖 iOS 和 Android 的移动钱包安全评估,另有上线的 Skynet 画像 | 生产环境安全服务 | 0 个严重、0 个高危;6 个中危在发布前修复 | 单一客户案例,不是留存证明 |
| Gate Dubai | 受监管交易所 | 覆盖 10 种资产的独立储备证明验证 | 生产运营证明 | 审计日范围内资产抵押率 100%+;Merkle 树和钱包控制权验证 | 仅为时点证明;不是完整财务审计 |
| OKX | 交易所 / 钱包平台 | 安全框架合作、钱包和交易所审查,以及 Skynet 集成 | 生产关系,并带扩展要素 | 证明 CertiK 数据嵌入客户产品界面 | 公开材料未披露商业条款和确切扩展范围 |
| Hub71 | 生态 / 创业平台 | 数字资产生态中安全和合规服务的优先供应商 | 项目型渠道,不是单一部署 | 20% 折扣、$200K 补贴池、免费合规工具访问 | 渠道证明,不是直接终端客户收入 |
| Bitget Wallet | 消费者钱包 | 公开的 CertiK 钱包安全画像,以及审计 / 渗透测试定位 | 生产环境公开信任界面 | 显示 CertiK 与大型钱包品牌绑定 | 页面未量化付费关系深度 |
表中只保留最清晰的具名公开证据;许多首页客户标识缺少足够部署细节,达不到证据门槛。
[CU005, CU006, CU007, CU008, CU009, CU011]具名客户证明显示,多个切入路径可以汇入持久信任或工作流集成。
流程按证据排序,不是量化漏斗。公开材料展示了步骤,但没有披露转化率。
[CU005, CU008, CU011, CU014, CU016, CU020]公开证据在结果具体时最强;若只看到品牌标识或伙伴形象,证据就较弱。
矩阵取值是基于公开证据的时效性和具体度作出的定性尽调判断,不是内部账户评分。
[CU005, CU008, CU011, CU014, CU024, CU028]6.3 耐久性、扩张与采购摩擦
公开记录给出了一些理由相信客户关系可以延续,但还不足以有把握承销留存。客户证言提到至少一段可追溯到 2018 年的关系,以及另一个使用两次审计加 Skynet 的账户,说明 CertiK 可以从发布审查扩展到重复或持续服务。Gem Wallet 关于未来独立评估的计划,也强化了这种可能性。产品架构在纸面上同样支持扩张故事:审计可以导向监控、合规产品、储备证明工作或 AI 安全附加项。但这些大多仍是方向性信号。本文语料中没有公开 NRR、GRR、流失、合同期限或集中度数据。公司上行到更高端市场后,采购也似乎更复杂。CertiK 自己关于 SOC 2 和 ISO 27001 的指引明确说明,银行和企业买方会在尽调中要求控制证据;Yahoo 的报道也显示,信任争议可能变成真实账户摩擦。这意味着,同一个打开大门的品牌,在敏感客户分层中也会制造问题。[CU019, CU020, CU021, CU022, CU023, CU028]
| 指标 | 值 / null | 客群 | 置信度 | 尽调追问 |
|---|---|---|---|---|
| 公开 NRR | null | 所有企业客群 | 低 | 要求按审计、监控和合规产品拆分 NRR |
| 公开 GRR / 流失率 | null | 所有客群 | 低 | 要求按队列提供客户留存和流失率 |
| 重复合作信号 | 至少一个公开客户关系从 2018 年延续至今 | 协议 / 生态伙伴 | 中 | 询问有多少头部账户购买过 2+ 项服务或重复审计 |
| 交叉销售信号 | 有两个审计加 Skynet 的公开案例 | 协议客户 | 中 | 要求提供从审计到 Skynet / 合规工具的附加率 |
| 未来复购意向 | Gem Wallet 称计划定期开展独立评估 | 钱包客户 | 中 | 确认 CertiK 是否留住该项周期性工作 |
| 公开满意度评分 | null | 所有客群 | 低 | 要求正式 CSAT / NPS 或客户访谈摘要 |
null 值是刻意保留:公开记录有一些关于客户关系持续性的轶事,但没有严格的留存指标。
[CU021, CU022, CU023, CU029]| 扩展驱动因素 | 集中度风险 | 影响 | 尽调路径 |
|---|---|---|---|
| 审计转 Skynet 增购 | 头部客户的收入集中度未知 | 少数标杆账户过重,可能抵消产品广度优势 | 要求前 10 大客户收入占比和附加率 |
| 交易所和受监管场所业务 | 声誉事件会拖慢敏感账户采购 | 可能拉长销售周期或压低赢单率 | 要求提供 2024-2026 年争议后销售管线流失原因 |
| 通过 Hub71 等渠道分发合规工具 | 渠道转化可能弱于合作新闻看起来的效果 | 可能高估未来经常性收入 | 要求补贴或资助项目的付费转化数据 |
| AI 安全产品和 OKX AI 分发 | 新客群变现可能慢于发布声量暗示 | 若近期收入回报不足,可能分散焦点 | 要求 AI 邻近产品的签约额和活跃客户数据 |
| 储备证明和受监管工作流 | 监管关系可能集中在少数司法辖区或锚定账户 | 区域集中度可能推高续约波动 | 要求地域收入拆分和受监管客户占比 |
本表关注客户质量如何传导到商业耐久性和集中度风险,而不只看品牌背书光环。
[CU014, CU016, CU019, CU025, CU026, CU028]6.4 客户质量的底线
概括 CertiK 客户故事最好的方式是:“广、真实,但只能部分衡量。”公司显然拥有真实 logo、具名部署、公开证言和产品集成,不只是空洞主页品牌。它似乎也能在安全生命周期的多个节点触达客户,从初创公司和钱包,到交易所和机构合规买方。这种宽度有战略价值,因为它降低了对单一狭窄产品动作的依赖。但当前公开证据更擅长证明存在感,而不是证明耐久性或收入质量。投资人可以合理相信 CertiK 有有意义的市场采用;仅靠公开来源,无法量化最佳账户有多粘、收入基础可能多集中,或一次性审计之外有多少经常性支出。[CU002, CU004, CU028, CU029, CU033, CU035]
6.5 展示项
07风险
7.1 监管与法律风险
CertiK 所处市场的监管正在变得更具体,而不是更少。UAE 证据尤其重要,因为它展示了“Web3 机构化”现在在实践中意味着什么。VARA 围绕消费者保护和风险保障设计制度;ADGM 则持续细化可接受资产标准、资本预期、AML 框架,甚至加密挖矿指引。CertiK 自己的 Hub71 内容证实,许可准备度和合规支持已经进入早期客户对话,而不只是企业采购环节。这为 SkyInsights 和合规工具创造了真实机会,但也抬高了法律风险底线。CertiK 现在必须向这样的客户环境销售:范围免责声明、监管对齐和文档质量,和技术检测同样重要。Hunt 条款进一步强化了这种复杂性:CertiK 是一个承担法律边界责任的平台运营方,不只是专业服务供应商。简言之,监管不再只是需求顺风;一旦产品、主张或客户预期偏离一致性,它也会成为执行负担和潜在责任来源。[CR001, CR002, CR003, CR004, CR005, CR006]
| 规则 / 案件 | 司法辖区 | 状态 | 可能性 | 严重性 | 缓释措施 | 剩余暴露 | 尽调路径 |
|---|---|---|---|---|---|---|---|
| ADGM 数字资产框架变化 | Abu Dhabi | 已实施,仍在演进 | 中高 | 高 | CertiK 将产品对齐合规驱动的客户需求 | 规则变化仍可能快过产品声明或覆盖范围 | 将每一项面向 UAE 的产品声明映射到现行 ADGM 要求 |
| VARA 虚拟资产监管 | Dubai | 活跃监管机构,重点保护消费者 | 中 | 高 | 储备证明和合规工具契合监管方向 | 客户预期可能超过实际保证范围 | 确认哪些 CertiK 产品用于 VARA 监管工作流 |
| CertiK Hunt 条款 / 平台责任边界 | 美国 / 全球用户 | 现行法律框架有效 | 中 | 中 | 条款对赞助方与研究员之间的责任和范围作出免责声明 | 争议仍可能外溢为声誉或法律风险 | 审查漏洞赏金争议处理、赔偿安排和索赔历史 |
| PoR 免责声明错配风险 | 跨境交易所客户 | 当前 | 中 | 中高 | CertiK 明确声明这不是完整财务审计 | 客户或媒体仍可能把安全性过度归因于品牌 | 审查客户沟通和报告使用护栏 |
| 受限资产或禁用代币暴露 | UAE 及其他受监管市场 | 当前 | 中 | 中 | 合规工具和监管监测 | 部分客户或产品请求可能无法服务 | 按现行规则手册跟踪已服务代币类别 |
各行按产品声明、客户匹配度和责任的下游实际严重性排序,而不是按抽象法律类别排序。
[CR001, CR002, CR004, CR005, CR006, CR009]声誉 / 流程失误和监管复杂性看起来是最严重的剩余风险,因为它们会同时冲击信任、客户和融资。
矩阵单元是根据公开证据中影响程度和剩余暴露作出的定性判断,不来自内部风险管理系统。
[CR002, CR011, CR019, CR029, CR040]7.2 运营与声誉风险
Kraken 事件仍是最清楚的公开证据,说明 CertiK 最大的下行往往不是原始技术无能,而是压力下的流程纪律。CertiK 自己承认判断和沟通有误;外部报道显示,局面多快就会演变成伦理和执法争议。Huione 反弹也因同样原因重要。它表明市场越来越期待安全公司筛查合作对象、监控报告使用方式,并像准机构守门人那样行事。公司似乎已通过收紧 KYC、使用外部专家和引入外部律师来回应,但这些修复既是改善证据,也是先前缺口的证据。由于 CertiK 大规模发布信任界面,风险被进一步放大。当它公开附着在项目评分、审计报告或行业排名上时,未来任何失误都可能比低调的精品审计公司扩散更快。这里的声誉不是软问题;它直接影响交易所、钱包、机构乃至公开市场投资人是否愿意依赖这个品牌。[CR009, CR010, CR011, CR012, CR013, CR014]
| 失效模式 | 可能性 | 严重性 | 缓释成熟度 | 剩余暴露 | 未解决缺口 |
|---|---|---|---|---|---|
| 披露流程失效(Kraken 式) | 中 | 高 | 改善中——已宣布引入外部律师并调整流程 | 高 | 需要证据证明流程重设计已在后续事件中经受测试 |
| 客户筛选失效 / 与有害客户关联 | 中 | 高 | 改善中——据称收紧 KYC,并引入外部专家 | 中高 | 没有关于筛选控制或假阳性 / 假阴性率的公开细节 |
| 涉及 CertiK 自有账户或渠道的品牌事件 | 中 | 中高 | 公开证据不清楚 | 中 | 需要事件历史和社交账户控制证据 |
| 威胁模型超出代码漏洞 | 高 | 高 | 部分到位——管理层称公司在适应 | 高 | 需要证明密钥、deepfake 和价格源风险已有效产品化 |
| 过度解读 PoR / 评分输出 | 中 | 中高 | 部分到位——已有免责声明 | 中高 | 需要证据证明用户和客户理解范围限制 |
本登记表聚焦最可能损害客户信任或迫使昂贵补救的失效模式。
[CR009, CR010, CR011, CR012, CR013, CR014]| 角色 / 职能 | 依赖或缺口 | 可能性 | 严重性 | 缓释措施 | 尽调路径 |
|---|---|---|---|---|---|
| 安全研究领导层 | 必须在激进测试和负责任披露规范之间拿捏平衡 | 中 | 高 | Kraken 事件后引入外部律师并调整流程 | 审查升级预案和事后治理 |
| 合规 / 法务运营 | 必须把快速变化的监管转化为产品声明和合同 | 中高 | 高 | 合规工具权重上升 | 要求按地区提供人数和外部律师支持 |
| 客户筛选运营 | 必须防止与有害客户或误用场景绑定 | 中 | 高 | Huione 之后据称收紧 KYC | 审查入驻和强化尽调流程 |
| 平台 / API 可靠性团队 | 必须同时支撑企业 API、公开端点和智能体工具 | 中 | 中高 | 已有信任中心控制和文档 | 要求可用性、事件和值班指标 |
| 产品领导层 | 必须从审计中心型公司转向多产品安全平台 | 中 | 中高 | 产品扩张已经可见 | 复核路线图优先级和产品淘汰标准 |
公司从人工交付审计扩展到平台化和 AI 关联产品后,执行风险上升。
[CR011, CR012, CR014, CR020, CR023, CR031]多项风险会沿同一通道传导:信任受损会同时影响客户、融资和估值。
该 DAG 映射公开风险路径,不是量化内部模型。
[CR011, CR013, CR019, CR025, CR029, CR030]7.3 依赖与平台风险
CertiK 从审计扩展到 API、评分、AI 工具和伙伴分发后,拾起了另一类风险:依赖风险。一部分是技术性的。CoinGecko 数据增强 Skynet。SkyInsights 依赖凭证安全、正常运行时间和准确实体归因。公共 Skills 和 agent 集成扩大触达,但也创造了更多可能出错、误导用户或被滥用的界面。一部分是商业性的。OKX AI、Hub71 和 YZi 式项目可以加速采用,但也让部分增长故事依赖 CertiK 无法控制的外部生态和补贴渠道。这不一定是缺陷——平台公司往往需要这类渠道——但它实质改变了风险地图。合作伙伴的监管麻烦、采用不足或声誉问题,现在都可能传导到 CertiK 的管线和品牌。CertiK 越深嵌入客户工作流和伙伴技术栈,护城河可能越强;但下行也越紧密地绑定到交易对手、数据提供商和端点可靠性。[CR019, CR020, CR021, CR022, CR023, CR024]
| 依赖项 | 交易对手 | 角色 | 集中度 | 失效场景 | 严重性 | 缓释措施 | 剩余暴露 |
|---|---|---|---|---|---|---|---|
| 市场数据增强 | CoinGecko | 向 Skynet 输入价格和市场背景 | 中等 | 宕机、数据错误或合同变更会削弱评分背景 | 中 | 可更换供应商,或优雅降级 | 仍依赖外部市场数据质量 |
| AI 智能体分发 | OKX AI | CertiK 服务进入伙伴市场的渠道 | 当前集中度低,但战略重要性高 | 伙伴采用不及预期,或伙伴监管环境变化 | 中 | 分散 AI 渠道,并保留直接分发 | 早期生态依赖仍在 |
| 创业生态管线 | Hub71 | 补贴渠道和合规分发 | 在 UAE 叙事中为中等 | 转化不佳或监管放缓会削弱漏斗质量 | 中 | 跟踪付费转化,并分散地域 | 渠道观感可能夸大收入质量 |
| 孵化资助 | YZi Labs | 面向早期项目的审计资助管线 | 当前低 | 对外披露规模大,但变现弱 | 中 | 以阶段门槛筛选后续合作 | 资助转付费转化未知 |
| 公开开发者界面 | GitHub / 开放 API | 分发和集成层 | 分布较广 | 封装工具失效、文档陈旧或误用会损害信任 | 中高 | 版本管理、监控和支持基础维护 | 公开故障可见度很高 |
集中度只是方向性判断,因为 CertiK 未公开披露对交易对手的收入依赖。
[CR019, CR020, CR023, CR025, CR026, CR027]除自有研究引擎外,CertiK 还依赖监管机构、数据伙伴、渠道伙伴和公开分发触点。
该图突出外部可见、最可能影响信任、增长或合规的关键依赖。
[CR019, CR020, CR025, CR026, CR027, CR034]7.4 模型风险与终止标准
最后一类风险是模型风险:外部观察者仍看不清足够多业务,因此会出错。公开证据强力支持需求和战略宽度,但无法精确支持留存、集中度或经常性收入质量。这很重要,因为 CertiK 的估值和融资选项会越来越取决于市场把它看成耐久安全平台,还是波动大、声誉敏感的服务公司。客户预期上升也意味着交付成本更高:机构级测试、更清晰报告、更多合规工作,以及对 deepfake 或密钥管理失败等新威胁向量的更快响应。正确结论不是公司风险太高、完全无法承销;而是推翻投资论点的主要触发因素可观察:另一场重大披露流程争议、渠道无法转化为经常性收入的证据、监管对可服务资产或客户类型施加限制,或公共信任信号跑赢实际控制纪律的证据。这些指标应主导尽调和定价纪律。[CR029, CR030, CR031, CR032, CR035, CR040]
| 风险 | 可监测触发因素 | 阈值 / 事件 | 行动含义 |
|---|---|---|---|
| 披露流程失效 | 围绕负责任披露或资金处理爆发重大公开争议 | 任何类似 Kraken 规模的争议重演 | 下调信任溢价,立即重做法律和流程尽调 |
| 监管压缩 | 关键司法辖区收窄可接受资产范围,或大幅提高 VASP 要求 | 产品限制冲击核心客户用例或主要销售管线细分 | 下调增长假设,重估市场宽度 |
| 渠道质量失效 | Hub71 / YZi / 合作伙伴渠道无法转化为可持续付费账户 | 赠款转付费或补贴转续约转化差的证据 | 下调扩张预期和估值中的渠道价值 |
| 平台可靠性 / 数据质量失效 | 重大 API 中断、评分完整性问题或市场数据损坏 | 事件反复发生,或整改透明度不足 | 将平台护城河叙事打折,并上调支持成本假设 |
| 声誉修复失败 | 公开市场或企业客户继续把既有争议列为阻碍 | 流失分析显示,信任事件导致大客户滑单 | 将建议转向跟踪 / 继续研究 |
否决标准聚焦会直接传导到信任、分销或融资能力的事件,而不是泛化的行业波动。
[CR019, CR023, CR025, CR026, CR030, CR040]7.5 展示项
08估值
8.1 估值背景与价格支撑
CertiK 的估值,标题叙事容易讲清,真正进入投资定价却难得多。标题故事很干净:上一轮公开定价是 March 2022 的 Series B3,估值 $2 billion;后续 IPO 报道仍重复这个标记,二级数据库也显示公司融资底子厚、客户和产品覆盖面广。问题在于,标题下面的证据仍偏薄。本语料里唯一公开的经常性收入数字,是二级来源估算的 ARR,不是经审计的管理层披露。这很关键:即便标题价格看似合理,投资人如果无法核对收入质量、服务与订阅组合、毛利率或留存,估值也会很脆。公开资料确实显示,CertiK 已从一次性审计扩到监控、合规和较新的 AI 安全产品,上行故事还没断。但创投基金或 YZi 资助计划这类公开动作,更像生态信号,不足以证明核心经营业务自 2022 年以来已经重新上调定价。所以起点应该是:承认 $2 billion 是真实历史,同时拒绝把它自动当成 2026 年的公允价值。[CV001, CV002, CV003, CV004, CV005, CV006]
| 立场 | 核心论点 | 什么会增强该论点 | 什么会削弱该论点 |
|---|---|---|---|
| 正方论点 | CertiK 有机会从受认可的审计品牌,演进为服务 web3 和 AI agent 工作流的持续安全、监控与合规平台。 | 经审计的经常性收入、强留存和企业客户占比证据。 | 证据显示大部分收入仍来自一次性审计项目,或声誉继续限制向高端客户转化。 |
| 反方论点 | 公司可能仍被按高端软件平台定价,但收入质量和耐久性还没有足够证据配得上这种待遇。 | 续约弱、经常性收入低于预期,或融资低于上一轮标记的证据。 | 经常性经济模型持久,以及权利结构比公开记录更清晰的证据。 |
估值争议的关键不在于 CertiK 有没有需求,而在于这些需求到底有多持久、多像软件收入。
[CV022, CV023, CV041]推荐结论从真实市场证据出发,经披露缺口,最后落到价格纪律。
这条流程是基于章节证据合成的承销顺序,不是管理层流程图。
[CV001, CV007, CV019, CV021, CV024, CV026]8.2 倍数逻辑与可比公司框架
压力测试 CertiK,最干净的办法是先把它隐含的私营市场倍数,与披露透明的上市网络安全公司对齐,再为不透明度打折。如果二级来源给出的 $87 million ARR 大方向没错,上一轮估值对应约 23x 收入。这个倍数很高,但在网络安全板块并非数学上说不通:CrowdStrike、Palo Alto 等优质网络安全公司当前公开市场倍数更丰厚,CyberArk 也仍因身份安全质量拿到强估值;同时,23x 也高于 SentinelOne 和 Zscaler 所代表区间的低端。这里的结论不是 CertiK 配得上上市公司平均倍数,而是市场有时确实会为具备增长、任务关键性和经常性收入的安全龙头支付很高价格。真正决定结果的是折价问题。与上市可比公司不同,CertiK 不披露经审计增长、利润率、留存或股权结构经济条款。Circle 的申报历史在这里有参考价值:它说明加密相关 IPO 窗口是开的,也说明真正走向公开市场需要多大披露强度。因此,CertiK 可以用公开网络安全估值带作参照,但在披露追上来之前,仍应承受私营公司的折价。[CV010, CV012, CV013, CV014, CV015, CV016]
| 可比对象 | 指标 | 倍数 / 估值状态 | 相关性 | 主要限制 |
|---|---|---|---|---|
| CrowdStrike | 2026 年市值 / 2026 年收入 | 约 42.9x 收入 | 高溢价网络安全龙头显示,公开市场愿意为品类赢家把估值拉到多远。 | 规模大得多、业务更多元,且完全公开上市。 |
| Palo Alto Networks | 2026 年市值 / 2025 年收入 | 约 30.7x 收入 | 安全大平台参照,体现业务宽度和战略价值。 | 成熟上市公司,财务经审计,且拥有 CertiK 未披露的规模。 |
| CyberArk | 2026 年市值 / 2024 年收入 | 约 20.6x 收入 | 高质量专业安全业务的有用基准。 | 身份 / 安全组合不同,披露质量也好得多。 |
| Zscaler / SentinelOne | 2026 年市值 / 2025 年收入 | 约 8.3x-9.3x 收入 | 说明即便是有分量的安全软件公司,当增长或情绪没那么亢奋时,交易区间也会低很多。 | 上市云安全模式仍不同于私营加密安全组合。 |
| CertiK 上一轮估值标记 | 2022 年 $2B 估值 / 约 $87M ARR 代理值 | 约 23.0x 隐含收入倍数 | 帮助判断这个私营估值标记落在公开网络安全参照区间内还是之外。 | ARR 来自二手资料且未经审计;股权结构权利未知。 |
本表抓住本章使用的主要公开参照点;用途是搭框架,不是在声称这些公司在所有运营层面都可直接比较。
[CV007, CV014, CV015, CV016, CV017, CV018]收入或倍数的小幅变化,都会显著改变公开证据能够支撑的企业价值。
柱状图只是以十亿美元计、用收入 × 倍数推算的示意,不是 DCF,也不是管理层正式展望。
[CV031, CV032, CV033, CV034, CV035]基于公开证据,诚实答案是一组熊市、基准、牛市情形区间,而不是单一数字。
区间是以十亿美元计的企业价值情景,绑定明确假设,不是当前定价的隐含值。
[CV027, CV028, CV029, CV030, CV034, CV035]8.3 情景分析与投资建议
对 CertiK 的建议,应框定为价格敏感型决策,而不是对公司质量给一个简单判决。牛市情景是:公司广泛的安全覆盖、庞大的公开证明基础和合规导向产品,确实转化成超过 $120 million 的经常性收入引擎,而且韧性足以支撑优质网络安全倍数。基准情景更克制:CertiK 真实、重要,也可能很有价值,但披露仍太轻,投资人很难不打折就承销 2022 年标题估值。熊市情景是:审计占比过高的经济模型,或新的信任损伤,把估值暴露为周期高点溢价,随后大幅压缩。这个结构指向一条有纪律的建议:继续尽调,把公司留在可投资名单上,但不要盲目锚定上一轮私营市场估值。实操上,上行应来自证据改善或入场价格纪律,而不是乐观插值。如果管理层能证明经审计经常性收入和客户耐久性,估值支撑会很快增强;如果不能,上一轮估值更多只是历史参照,不是当下真相。[CV022, CV023, CV024, CV025, CV026, CV027]
| 维度 | 当前立场 | 理由 |
|---|---|---|
| 建议 | 继续研究 / 严守入场纪律 | 公司有真实业务且有战略价值,但公开证据还不足以支撑不计价格地买入。 |
| 置信度 | 中 | 现有证据足以做区间式承销,不足以给出精确公允价值点。 |
| 风险评级 | 中高 | 变现质量、声誉修复和股权结构不透明,都可能显著改写结果。 |
| 估值立场 | $2B 可作为上行情景参照,但还不是经过验证的基准情形 | 这个 $2B 标记确有历史依据,但要支撑当下价格,还缺关键输入。 |
| 决策含义 | 只有拿到经审计指标或价格缓冲,才推进尽调 | 投资人要看到更强证据,或拿到更好的入场条款,才适合加码。 |
建议受制于证据质量和价格支撑,而不是怀疑品类需求。
[CV024, CV025, CV026, CV027, CV042]| 情景 | 核心假设 | 估值传导 | 概率信号 |
|---|---|---|---|
| 乐观 | 经常性收入超过约 $120M,企业 / 合规收入占比上升;IPO 窗口保持开放,信任也维持稳定。 | 若采用网络安全高端倍数,$1.8B-$3.0B 的支撑开始可信。 | 有可能,但仍需要超出当前公开材料的证据。 |
| 基准 | 收入接近当前代理值,增长延续,但披露仍不完整,投资人给予私营公司折价。 | $0.8B-$1.5B 比 $2B 标示估值更容易辩护。 | 这是今天公开证据最能支撑的情景。 |
| 悲观 | 收入基数小于代理值暗示,或又一次信任事件削弱增长和定价权。 | 如果基本面和情绪同时收缩,低于 $1B 的支撑就变得合理。 | 关键承销指标仍未公开,不能排除。 |
情景表刻意采用区间,因为公开记录不支持单点估值精度。
[CV028, CV029, CV030, CV031, CV032, CV033]CertiK 在品类相关性和产品宽度上得分最高,在透明度和回报可见度上最弱。
评分是基于公开证据缺口和优势得出的定性 IC 式判断,不是管理层 KPI。
[CV021, CV022, CV024, CV025, CV027, CV037]8.4 退出准备度与最终尽调判断
最终估值判断是:CertiK 更接近「值得继续做功课」,而不是「已经可以给高置信定价」。公司有足够的市场位置和产品宽度,理论上可以走向公开市场或吸引战略资本,但公开证据仍落后于野心。缺口并不花哨:经审计收入、经常性收入组合、利润率结构、客户集中度和股权结构权利。这些缺失会直接影响价格支撑和投资人回报,也关系到 IPO 准备度,因为公开市场投资人奖励的不只是品类领导力,还有披露质量和治理信心。未来一轮如果低于 $2 billion 参照点,或出现新的信任争议,都会迅速挑战溢价叙事。反过来,强经常性经济性和更清晰的权利可见度,也可能支撑更高出价。在此之前,正确姿态是有条件的兴趣:如果尽调包能补上核心缺口,或价格足以补偿这些缺口,就推进;如果管理层坚持让投资人不看更新证据就接受 2022 年标题估值,就暂停。[CV037, CV038, CV039, CV040, CV041, CV042]
| 触发因素 | 阈值 / 事件 | 为何重要 | 行动含义 |
|---|---|---|---|
| 收入质量不达标 | 经审计经常性收入显著低于公开代理值,或利润率太弱,撑不起高端倍数。 | 会从根基上削弱软件化估值叙事。 | 用更低收入和倍数区间重新承销。 |
| 新的信任争议 | 又一次高曝光争议、与漏洞利用相关的反弹,或信誉事件打击品牌。 | 会同时削弱获客和公开市场可选性。 | 暂停,或扩大折价,直到影响可衡量。 |
| 降价轮或结构化融资 | 新融资低于参考估值,或附带重偏好权利。 | 即便运营稳定,也会重置价格支撑并改写回报计算。 | 将上一轮标记视为过期,重建股权结构模型。 |
| 耐久性指标偏弱 | NRR、流失率或集中度数据显示重复经济性脆弱。 | 会显示 CertiK 更像项目驱动,而非平台型公司。 | 下调目标倍数,重新审视建议。 |
| IPO 准备缺口持续 | 尽管有公开市场野心,披露质量和治理仍过薄。 | 会限制退出路径,并降低稀缺价值。 | 倾向采用私营公司折价承销,并放慢尽调节奏。 |
否决标准聚焦会直接打破高端倍数叙事的证据或事件,而不是普通市场波动。
[CV025, CV026, CV038, CV039, CV041]| 主题 | 缺失证据 | 为何重要 | 负责人 / 尽调路径 |
|---|---|---|---|
| 经审计收入与 ARR 桥接 | 董事会批准的收入、ARR,以及服务与订阅组合。 | 判断上一轮标记是否落在可支撑的收入框架内。 | 索取 CFO 材料包或经审计财务摘录。 |
| 毛利率与现金状况 | 毛利率、贡献利润率、现金消耗和续航期。 | 区分高端软件经济性和高端叙事。 | 索取财务尽调材料包。 |
| 留存与集中度 | NRR、GRR、流失率、前十大客户占比,以及从审计到经常性产品的附加率。 | 判断耐久性,以及平台叙事是否真实。 | 索取客户分群表,并安排客户访谈。 |
| 股权结构权利 | 优先权、清算顺位、期权池、按比例跟投权和附函。 | 如果权利负担重,回报结果可能与企业价值大幅偏离。 | 索取股权结构模型和领投方条款摘要。 |
| IPO 准备度与治理 | 审计准备、法律工作流、内控,以及董事会对公开市场的态度。 | 澄清 IPO 叙事是近期可选性,还是远期定位。 | 索取治理检查清单和投行 / 律师准备度评估。 |
这些请求是把合理区间转化为可投资价格所需的最低材料包。
[CV037, CV038, CV039, CV040, CV042]8.5 图表
免责声明
本报告基于截至 2026-08-03 的公开信息,是分析性尽调材料,不构成投资建议。
证据索引
| 编号 | 陈述 | 可信度 | 来源 |
|---|---|---|---|
| CO001 | CertiK's current official about page describes the company as a New York-based Web3 security leader founded in 2017 by professors from Columbia and Yale. | 高 | SO001, SO012 |
| CO002 | Official CertiK materials position the company as the largest Web3 security platform combining formal verification, audits, monitoring, compliance, and incident-response tooling. | 中 | SO001, SO002 |
| CO003 | The current public leadership bench includes co-founder and CEO Ronghui Gu, cofounder Zhong Shao, chief business officer Jason Jiang, CTO Kang Li, head of legal Denise Benattar, and government affairs lead Stefan Muehlbauer. | 中 | SO001 |
| CO004 | Hudson Jameson leads ecosystem efforts at CertiK after prior roles at the Ethereum Foundation and Polygon Labs, indicating deeper protocol-network relationships than a pure audit boutique would usually have. | 中 | SO001 |
| CO005 | CertiK's homepage highlights SOC 2 Type II compliance, ISO 27001 certification, and regulatory engagement across the United States, Singapore, Hong Kong, Japan, Abu Dhabi, and Korea. | 中 | SO002 |
| CO006 | The December 2021 B2 announcement said Sequoia Capital China led an $80 million investment round that valued CertiK at nearly $1 billion and brought total funding to just over $140 million. | 中 | SO005 |
| CO007 | The March 2022 B3 announcement said Insight Partners, Tiger Global, and Advent International led an $88 million round that lifted CertiK's valuation to $2 billion. | 高 | SO004, SO009 |
| CO008 | TechCrunch reported that the April 2022 raise brought disclosed capital to $230 million and quoted Ronghui Gu saying the business was profitable and had not spent cash from the prior four rounds. | 中 | SO009 |
| CO009 | Tracxn's current company profile shows a higher lifetime total of roughly $296 million across nine rounds, including a later April 2022 $60 million Series B financing. | 中 | SO020, SO021 |
| CO010 | World Economic Forum and CB Insights profile pages both present CertiK as a New York-based blockchain-security infrastructure provider rather than a token issuer or exchange. | 中 | SO012, SO022 |
| CO011 | Official 2026 materials say Binance is now CertiK's largest investor after a follow-on multi-eight-figure investment disclosed alongside the company's public-market positioning narrative. | 中 | SO007, SO013 |
| CO012 | CertiK's January 2026 partnership with YZi Labs pairs strategic distribution with a $1 million audit-grant program for incubation participants, extending CertiK deeper into founder onboarding. | 中 | SO006, SO025 |
| CO013 | At Davos in January 2026, Ronghui Gu said CertiK's valuation was about $2 billion and that an IPO remained a goal, but he also said there was no concrete listing plan yet. | 高 | SO010, SO011 |
| CO014 | Yahoo Finance's syndicated DL News interview framed the proposed IPO against reputational setbacks tied to Kraken, prior client criticism, and the compromise of CertiK's X account. | 中 | SO013, SO023 |
| CO015 | CertiK's official post on the Kraken vulnerability admitted errors in judgment and poor communication, showing the company chose partial public contrition rather than a full defense of its process. | 中 | SO008 |
| CO016 | CoinDesk reported Kraken accused the researchers of extortion after approximately $3 million was withdrawn through the exploit, making the episode a material governance and reputation event for CertiK. | 中 | SO015, SO016 |
| CO017 | The Defiant reported former clients and researchers alleged that some CertiK audits relied too heavily on automated checks and missed material review depth, challenging the durability of the company's market reputation. | 中 | SO014 |
| CO018 | Blockchain.News reported that CertiK's X account was compromised in a phishing scam in January 2024, underscoring operational-security embarrassment even for a security specialist. | 中 | SO023 |
| CO019 | Crypto Economy reported CertiK Ventures launched a $45 million investment plan in September 2024 alongside free Token Scan and Wallet Scan community tools. | 中 | SO024 |
| CO020 | CertiK's homepage claims 117,000-plus vulnerabilities detected, 90,000-plus audit findings, 21,000-plus projects monitored, and 1.8 million-plus monthly active users. | 中 | SO002 |
| CO021 | CertiK's January 2026 institutional narrative claims more than 5,000 enterprise clients, over $600 billion in assets secured, and more than 180,000 vulnerabilities identified to date. | 中 | SO007 |
| CO022 | The December 2021 funding post said CertiK had supported security audits for more than 1,800 clients by that point, illustrating a rapid scale-up before the later 5,000-client claim. | 中 | SO005 |
| CO023 | TechCrunch quoted CertiK as protecting more than $300 billion in crypto assets for roughly 2,500 enterprise clients in April 2022, offering a midpoint between older and newer scale disclosures. | 中 | SO009 |
| CO024 | Tracxn currently lists CertiK at 205 employees as of June 2026, while the company itself emphasizes global hiring without publishing a current official headcount. | 中 | SO020, SO001 |
| CO025 | The 2021 and 2022 official funding posts claimed revenue surged 20x in the year before the B2 round and 12x during 2021, implying unusually fast growth but without audited base numbers. | 中 | SO004, SO005 |
| CO026 | The March 2022 company post further said first-quarter 2022 Web3-security revenue had grown 4x year over year despite a crypto-market downturn. | 中 | SO004 |
| CO027 | CB Insights and the World Economic Forum profile both list 2018 as CertiK's founding year, conflicting with the company's current about page and Tracxn, which cite 2017. | 中 | SO012, SO020, SO022 |
| CO028 | The coexistence of 2017 and 2018 founding-year disclosures means diligence should verify incorporation date versus operating launch date before relying on tenure-based comparisons. | 中 | SO001, SO020, SO022 |
| CO029 | CertiK's public profile has broadened from smart-contract auditing into ongoing monitoring, AML, incident response, KYC, and enterprise tooling, which supports a platform rather than point-solution story. | 中 | SO002, SO007 |
| CO030 | The YZi Labs partnership and Davos IPO messaging both show management is prioritizing institutional distribution and public-company readiness over a purely crypto-native positioning. | 中 | SO006, SO010, SO011 |
| CO031 | Public investor lists now span traditional finance names such as Goldman Sachs and SoftBank alongside crypto-native backers including Binance and Coinbase Ventures. | 中 | SO009, SO020, SO022 |
| CO032 | The company's stakeholder map is unusually founder-centric because Ronghui Gu remains the main public face across funding, policy, and IPO communications. | 中 | SO001, SO010, SO013 |
| CO033 | CertiK's public credibility benefits from affiliations with Columbia, Yale, and the World Economic Forum, but those same affiliations raise the reputational cost of any future audit controversy. | 中 | SO001, SO012, SO014 |
| CO034 | Public evidence does not disclose board composition, secondary transactions, debt facilities, or current cash balance, leaving major governance and capital-structure questions unanswered. | 中 | |
| CO035 | The combination of fast capital formation, broad product expansion, and recurring controversy makes CertiK look more like a scaled but still maturing infrastructure company than a de-risked late-stage software issuer. | 中 | SO007, SO013, SO014 |
| CM001 | The Business Research Company sizes the global web3 security market at $2.31 billion in 2025 and $2.86 billion in 2026, implying 24.1% year-over-year growth. | 中 | SM001, SM002 |
| CM002 | The same market lens projects web3 security revenue reaching $6.84 billion by 2030, indicating a multiyear high-growth category rather than a short-lived crypto cycle niche. | 中 | SM001, SM002 |
| CM003 | The broad web3 security market definition includes software, hardware, and services, meaning CertiK participates in only part of the total category when it sells audits and monitoring rather than hardware. | 中 | SM001 |
| CM004 | A narrower smart-contract-audit and security-firm market lens values the category at roughly $0.82 billion in 2025 and $1.02 billion in 2026, which is materially smaller than the broad web3-security TAM. | 中 | SM003 |
| CM005 | The narrow audit-firm lens implies that CertiK competes in a services-heavy segment where audits, monitoring, bug bounties, and consulting are bundled rather than sold as one homogeneous product. | 中 | SM003, SM017 |
| CM006 | The broad market model identifies banking, financial services, healthcare, government, telecom, retail, gaming, and other enterprises as end-user verticals, widening CertiK's potential buyer set beyond DeFi teams. | 中 | SM001 |
| CM007 | North America was the largest web3-security region in 2025 while Asia-Pacific is forecast to grow fastest, matching CertiK's own emphasis on global regulatory relationships and multi-jurisdiction buyers. | 中 | SM001, SM011 |
| CM008 | The Business Research Company explicitly identifies smart-contract security, cloud security, and application security as distinct subsegments, so CertiK's TAM is influenced by how much buyer spend shifts from code review into continuous monitoring and compliance. | 中 | SM001, SM009, SM010 |
| CM009 | Immunefi reported Q1 2025 losses of about $1.636 billion, making it the worst quarter for hacks in crypto history and reinforcing security spend as a reaction to visible economic pain. | 中 | SM005 |
| CM010 | Immunefi found BNB Chain and Ethereum were the most-targeted chains in Q1 2025, which helps explain why audit demand and monitoring demand concentrate around EVM ecosystems. | 中 | SM005 |
| CM011 | CertiK's Hack3D H1 2026 report says $1.315 billion was lost across 344 incidents, and it argues the threat environment worsened on a like-for-like basis once the anomalous Bybit hack is normalized out. | 中 | SM007 |
| CM012 | CertiK says wallet compromise was the most costly attack vector in H1 2026 at more than $444 million, signaling buyer demand beyond smart-contract auditing into key management and transaction monitoring. | 中 | SM007 |
| CM013 | The same H1 2026 report shows code vulnerability remained the most common attack vector by incident count, keeping pre-deployment audits relevant even as post-deployment monitoring expands. | 中 | SM007 |
| CM014 | Chainalysis estimates illicit cryptocurrency addresses received at least $154 billion in 2025 and says stablecoins accounted for 84% of illicit transaction volume, which enlarges the compliance-monitoring opportunity for firms like CertiK. | 高 | SM023, SM024 |
| CM015 | Chainalysis says DPRK-linked hackers alone stole roughly $2 billion in 2025, strengthening the national-security and enterprise-control arguments for higher security budgets. | 中 | SM023 |
| CM016 | CertiK's Skynet product page positions the buyer problem as continuous evaluation of projects, exchanges, and wallets rather than a one-time audit certificate, indicating a recurring-revenue adjacency within the market. | 中 | SM009 |
| CM017 | SkyInsights expands the addressable market into AML, transaction monitoring, and VASP compliance, which means CertiK is selling into risk and compliance budgets as well as engineering or protocol-launch budgets. | 中 | SM010, SM011 |
| CM018 | The VARA page shows regulators and licensed virtual-asset businesses can act as both buyer and gatekeeper, making regulatory readiness a demand driver rather than just a cost center. | 中 | SM011 |
| CM019 | Sherlock's 2026 pricing guide says audit engagements range from roughly $5,000 for simple token scopes to above $250,000 for enterprise-grade multi-chain systems. | 中 | SM017 |
| CM020 | Sherlock says mid-complexity DeFi audits often land between $60,000 and $120,000 once remediation review is included, providing a practical budget anchor for CertiK's core pre-launch market. | 中 | SM017 |
| CM021 | Pricing is driven mainly by codebase size, chain or language, firm tier, and urgency, with Rust or Solana scopes carrying a 25% to 40% premium and Cairo or Move scopes 30% to 45% above EVM equivalents. | 中 | SM017 |
| CM022 | Intel Market Research says hybrid auditing that combines manual review and automated scanning is the leading service approach, while formal verification is increasingly treated as a premium add-on for high-value protocols. | 中 | SM003 |
| CM023 | Intel Market Research also flags a shortage of fewer than 5,000 certified blockchain security experts worldwide, making talent scarcity a structural constraint on industry throughput. | 中 | SM003 |
| CM024 | The same source says DeFi remains the dominant application segment because protocols managing large liquidity pools face catastrophic breach consequences and intense scrutiny before launch. | 中 | SM003 |
| CM025 | Enterprises and financial institutions are described as a rapidly growing end-user cohort as tokenized assets and settlement use cases move security buying toward regulated organizations. | 中 | SM003, SM018 |
| CM026 | SmartContractAudit.com and QuillAudits both describe the category as shifting from one-time pre-deployment review toward continuous monitoring, bug bounties, and retainer-style advisory relationships. | 中 | SM016, SM020 |
| CM027 | Sherlock argues that mature protocols increasingly combine firm audits, contest audits, and bug bounty programs, with total annual security budgets for meaningful TVL often reaching $150,000 to $500,000 or more. | 中 | SM017, SM006 |
| CM028 | Formal verification is being marketed to institutional buyers as a differentiator because it offers mathematical correctness claims that informal reviews cannot provide. | 中 | SM018, SM019 |
| CM029 | CertiK's product set covers smart-contract audits, pentesting, KYC, blockchain-node services, and compliance solutions, so its practical SAM is larger than a pure audit shop but smaller than the full web3-security TAM. | 中 | SM012, SM013, SM014, SM015, SM025 |
| CM030 | Buyer budgets are fragmented because a launch-stage DeFi team buys audits mainly through engineering or founder budgets, while an exchange or VASP buys monitoring and compliance through risk, security, or legal owners. | 中 | SM010, SM011, SM017 |
| CM031 | Switching costs are moderate rather than absolute because protocols can multi-home across audits, bug bounties, and monitoring vendors, but top-tier brand certification still matters for listings and fundraising. | 中 | SM017, SM020 |
| CM032 | The market remains fragmented, with CertiK, ConsenSys, Halborn, Quantstamp, OpenZeppelin, Blockaid, Hacken, and others all named across broad or narrow market maps, which limits monopoly pricing power. | 中 | SM001, SM003 |
| CM033 | Market-sizing confidence is limited because commercial analysts segment the category differently, sometimes bundling hardware, analytics, consulting, and auditing into one market and sometimes isolating just audit firms. | 中 | SM001, SM003, SM004 |
| CM034 | No public source cleanly isolates CertiK-specific SAM or SOM by buyer type, chain, or service line, so any market-share conclusion beyond directional positioning remains an estimate rather than a fact. | 中 | |
| CM035 | Overall, market conditions support ongoing demand for CertiK, but the best opportunities appear in recurring monitoring, compliance, and institution-facing services rather than commodity one-off audits alone. | 中 | SM007, SM009, SM010, SM017 |
| CP001 | Alchemy lists 92 alternatives to CertiK in blockchain auditing, indicating a fragmented competitive field rather than a winner-take-all market. | 中 | SP013 |
| CP002 | The Business Research Company names CertiK, ConsenSys, Halborn, Quantstamp, OpenZeppelin, Hacken, Blockaid, and others as key players in web3 security, confirming a crowded upper tier. | 中 | SP025 |
| CP003 | Quantstamp positions itself as a post-deployment security and monitoring provider in addition to audits, with managed security services and an insurance product called Chainproof. | 中 | SP001 |
| CP004 | Quantstamp says it has worked with recognized web3 names since 2017 and audited Layer 1s, Layer 2s, DeFi protocols, NFT marketplaces, and exchanges. | 中 | SP001, SP002 |
| CP005 | Trail of Bits competes from a research-heavy security-engineering position that spans audits, research, tools, and talks rather than a pure trust-badge offering. | 中 | SP003, SP004 |
| CP006 | OpenZeppelin markets itself as the security standard for onchain finance and couples audit services with the halo of its widely used smart-contract libraries. | 中 | SP005, SP006 |
| CP007 | OpenZeppelin's audit page highlights extensive work across DEXs, lending, L1-L2s, account abstraction, stablecoins, and financial institutions, indicating unusually broad capability coverage. | 中 | SP006 |
| CP008 | Consensys Diligence positions itself as a gold-standard audit partner for Ethereum protocols and institutions, emphasizing broad scope, rigorous challenge, and collaborative review. | 中 | SP009 |
| CP009 | Sigma Prime says it has been established since 2016, protected more than $57 billion in TVL, audited 400-plus projects, and found over 6,500 issues. | 中 | SP011 |
| CP010 | Hacken markets itself as a blockchain security and compliance partner, making its posture closer to a platform and assurance advisor than a pure code-review boutique. | 中 | SP012 |
| CP011 | CertiK differentiates from many audit-first rivals by pairing smart-contract audits with Skynet monitoring and broader pentest or risk services. | 中 | SP019, SP020, SP021 |
| CP012 | CertiK testimonials and public product pages support a scale-and-continuity pitch rather than a narrow one-off engagement story. | 中 | SP020, SP022 |
| CP013 | Datawallet ranks CertiK, Hacken, Trail of Bits, Quantstamp, Halborn, OpenZeppelin, and Consensys in one peer group but assigns each a distinct specialty, reinforcing that buyers segment by workflow not just brand. | 中 | SP014 |
| CP014 | Datawallet tags CertiK with formal verification, Trail of Bits with security engineering, Quantstamp with institutional DeFi, Halborn with offensive security, and OpenZeppelin with standard libraries. | 中 | SP014 |
| CP015 | Goodfirms and Procur3 both frame evaluation around methodology, public artifacts, exploit history, and named strengths, suggesting enterprise buyers increasingly scrutinize depth rather than logo alone. | 中 | SP008, SP010 |
| CP016 | Sherlock's market reference says firm tier has economic value independent of technical depth because top-tier audit certificates matter in fundraising, exchange listings, and institutional review. | 中 | SP023 |
| CP017 | Sherlock also shows audit pricing ranging from roughly $5,000 to over $250,000, which implies top firms can preserve premium positioning when complexity or brand risk is high. | 中 | SP023 |
| CP018 | Quantstamp, CertiK, and Hacken all pitch broader post-audit or compliance adjacencies, while Trail of Bits and Sigma Prime lean harder into specialist engineering depth. | 中 | SP001, SP011, SP012, SP020 |
| CP019 | OpenZeppelin and Consensys Diligence enjoy distribution advantages from ecosystem-standard tooling and protocol proximity, which are harder for audit-only firms to replicate. | 中 | SP006, SP009 |
| CP020 | Sigma Prime gains additional moat from operating Ethereum infrastructure products such as Lighthouse, giving it credibility with protocol and validator operators. | 中 | SP011 |
| CP021 | Trail of Bits competes on offchain, cryptographic, and infrastructure breadth, which matters when buyers want one reviewer for smart contracts plus surrounding security architecture. | 中 | SP003, SP004 |
| CP022 | Halborn is commonly grouped with the top audit brands in independent rankings, but its official surface emphasizes broader digital-asset security solutions more than a single signature methodology. | 中 | SP007, SP014, SP018 |
| CP023 | Gitnux, WorldMetrics, and Snap Innovations all place Trail of Bits, OpenZeppelin, Quantstamp, Halborn, and CertiK in the top competitive set, indicating strong consensus on the peer basket even when order varies. | 中 | SP015, SP016, SP017, SP018 |
| CP024 | Because most official competitor sites do not publish list prices, buyers often use reputation, references, and specialty fit as proxies when narrowing vendor shortlists. | 中 | SP006, SP009, SP023 |
| CP025 | Multi-homing is common because mature protocols combine named firm audits, contest audits, and bug bounty programs rather than relying on a single provider. | 中 | SP023 |
| CP026 | That multi-homing pattern reduces absolute lock-in for any one audit firm, even when brand-name reviews remain useful trust signals. | 中 | SP013, SP023 |
| CP027 | OpenZeppelin and Consensys appear strongest where Ethereum-native design review and institutional comfort matter most, while CertiK and Quantstamp compete more on breadth and commercialization. | 中 | SP001, SP006, SP009, SP020 |
| CP028 | Specialist firms with formal verification, ZK, or infrastructure depth can capture higher-value scopes even if they have smaller public customer counts than broad audit brands. | 中 | SP003, SP011, SP023 |
| CP029 | Commodity pressure is highest on simple token or standard EVM audits, where pricing transparency and abundant alternatives make differentiation harder. | 中 | SP013, SP023 |
| CP030 | Security-market urgency remains high because crypto crime and state-linked theft stayed elevated through 2025, preserving willingness to pay for credible vendors. | 中 | SP024 |
| CP031 | Datawallet's post-audit incident examples show that even highly ranked firms carry reputational exposure when audited projects later suffer material losses. | 中 | SP014 |
| CP032 | CertiK's own scale can cut both ways: it supports procurement confidence, but it also invites checkbox-audit expectations and criticism that boutique reviewers do deeper work. | 中 | SP014, SP022 |
| CP033 | The field contains at least three distinct strategic clusters: research-led specialists, ecosystem-tooling incumbents, and platform-style trust providers. | 中 | SP003, SP006, SP009, SP020 |
| CP034 | No public evidence in this set provides a consistent apples-to-apples scorecard for pricing, audit quality, exploit history, and renewal economics across all major firms, so any hard ranking remains partly judgmental. | 中 | |
| CP035 | CertiK is competitively credible but not unassailable; its best defense is breadth and public scale, while its main risks come from specialist technical brands above it and cheaper commoditized alternatives below it. | 中 | SP014, SP020, SP023 |
| CI001 | CertiK said in late 2021 that total investment had passed $140 million after its B2 round, providing a disclosed funding base before the 2022 step-up round. | 中 | SI007 |
| CI002 | CertiK said in April 2022 that its B3 financing valued the company at $2 billion and brought capital raised over the prior nine months to $230 million. | 中 | SI006 |
| CI003 | TechCrunch reported the 2022 round as an $88 million financing with Goldman Sachs joining existing backers, confirming outside institutional investor interest in the company. | 中 | SI008 |
| CI004 | Yahoo Finance wrote in 2026 that CertiK had collected $296 million in funding since 2018, indicating the company continued adding capital after the earlier disclosed 2021-2022 rounds. | 中 | SI013 |
| CI005 | The Block reported in 2026 that Binance recently made a multi-eight-figure investment into CertiK, suggesting new capital support without a newly disclosed headline valuation. | 中 | SI015 |
| CI006 | Crypto Economy reported CertiK Ventures launched a $45 million fund in 2024, and CertiK later said it paired that ecosystem posture with $1 million of audit grants through the YZi Labs partnership, implying part of CertiK's capital and go-to-market effort is being used to shape ecosystem development as well as core operations. | 中 | SI017, SI026 |
| CI007 | CertiK claimed in 2021 that revenue had increased 20x over the prior year, signaling very rapid early commercialization during the prior bull-market cycle. | 中 | SI007 |
| CI008 | CertiK also claimed in 2022 that 2021 revenue surged 12x and profits surged 3,000x, which if directionally accurate points to sharp operating leverage during its initial scale-up phase. | 中 | SI006 |
| CI009 | The same 2022 post said CertiK's Q1 2022 year-over-year web3 security revenue grew 4x, reinforcing that demand persisted even as crypto markets became more volatile. | 中 | SI006 |
| CI010 | CertiK said in 2021 that Skynet booked revenue had grown 2,300% since the end of 2020, supporting the view that the company was building recurring software-style revenue rather than living only on one-off audits. | 中 | SI007 |
| CI011 | The 2021 funding post also linked strong growth in Security Leaderboard users with Skynet expansion, suggesting CertiK uses free visibility surfaces to feed paid product conversion. | 中 | SI007 |
| CI012 | CertiK's current smart-contract-audit page is quote-based rather than self-serve, which implies audit revenue remains negotiated service revenue instead of standardized SaaS list pricing. | 中 | SI023 |
| CI013 | CertiK's product pages for Skynet, SkyInsights, and pentesting show three monetization lanes: project-based assurance, recurring monitoring or data subscriptions, and broader security consulting. | 中 | SI003, SI024, SI025 |
| CI014 | SkyInsights documentation and a live demo surface suggest CertiK is productizing risk data through APIs and dashboards, which is structurally more repeatable than custom audit labor. | 中 | SI003, SI004, SI005 |
| CI015 | CertiK's SOC 2 and ISO 27001 content shows the company is intentionally selling into compliance-led security budgets, not only crypto-native engineering teams. | 中 | SI002 |
| CI016 | Sherlock's 2026 market reference says smart-contract audit prices range from roughly $5,000 for simple scopes to more than $250,000 for enterprise-grade multi-chain systems. | 中 | SI018 |
| CI017 | Sherlock further says most DeFi protocol audits land between $25,000 and $100,000, which offers a useful benchmark for CertiK's likely core engagement economics. | 中 | SI018 |
| CI018 | Sherlock says remediation rounds typically add $5,000 to $20,000 per pass, meaning realized deal value can materially exceed the initial audit quote. | 中 | SI018 |
| CI019 | Sherlock also argues urgency can add 20% to 40% to base fees, implying senior-capacity allocation is an explicit pricing lever for firms like CertiK. | 中 | SI018 |
| CI020 | Sherlock says Rust, Cairo, Move, and ZK-related work can command 25% to 120% pricing premiums versus baseline EVM audits, supporting the idea that specialty mix meaningfully affects gross margin and ASP. | 中 | SI018 |
| CI021 | Sherlock describes mature protocol security budgets of roughly $150,000 to $500,000 annually when audits, contests, and bounties are combined, indicating CertiK competes for a broader wallet share than one launch audit. | 中 | SI018 |
| CI022 | Ancilar and QuillAudits both frame audit effort around codebase complexity, architecture, and integration scope, reinforcing that utilization and staffing—not just brand—drive cost of delivery. | 中 | SI020, SI021 |
| CI023 | ChainScore Labs argues formal verification is becoming non-negotiable for institutional use cases, implying that premium assurance work should remain one of the highest-value service buckets in CertiK's mix. | 中 | SI022 |
| CI024 | Because CertiK increasingly spans audits, monitoring, compliance, and pentesting, its financial profile should be less cyclical than a pure audit boutique even though it is still exposed to crypto activity levels. | 中 | SI002, SI023, SI024, SI025 |
| CI025 | Yahoo, Cointelegraph, The Block, and CoinCentral all frame a future IPO as an active ambition rather than a filed process, so public-market readiness remains strategic intent, not transaction certainty. | 中 | SI013, SI014, SI015, SI016 |
| CI026 | Yahoo says going public is a natural next step as CertiK scales its products and technology, which implies management wants investors to value the company as security infrastructure rather than as cyclical consulting alone. | 中 | SI013 |
| CI027 | The Block says CertiK wants to become the first public web3 cybersecurity firm, which could help positioning if public investors reward category leadership but also heightens scrutiny on governance and incident handling. | 中 | SI015 |
| CI028 | Yahoo's coverage of controversies around Huione-linked auditing, the Kraken episode, and the company's compromised X account suggests reputational noise could weigh on IPO timing or public-market multiple quality. | 中 | SI013 |
| CI029 | The absence of audited financial statements, segment disclosures, backlog, and churn data means no outside observer can yet build a reliable bottom-up forecast for CertiK from public materials alone. | 中 | SI009, SI010, SI011, SI013 |
| CI030 | Even supportive public profiles like Tracxn and CB Insights mostly summarize status, investors, and company description rather than detailed financial statements, underscoring how sparse hard operating data remains. | 中 | SI009, SI010, SI011 |
| CI031 | Public materials support a plausible mix of one-time audit fees plus recurring monitoring and data products, but they do not reveal the share of revenue coming from each stream. | 中 | SI003, SI023, SI024 |
| CI032 | No current public source in this set provides verified gross margin, free cash flow, or retention data, so claims about software-like economics remain provisional. | 中 | |
| CI033 | The latest public valuation anchor still traces back to the 2022 $2 billion mark, which means any 2026 valuation discussion rests on secondary reporting and strategic commentary rather than a new priced round. | 中 | SI006, SI015, SI016 |
| CI034 | A company with CertiK's breadth can potentially raise contract value over time through follow-on monitoring, re-audits, compliance work, and pentests even if initial audit pricing becomes more competitive. | 中 | SI002, SI018, SI024, SI025 |
| CI035 | Overall, public evidence portrays CertiK as a venture-backed, high-growth security platform with some recurring revenue characteristics, but still too opaque for precise modeling without management data. | 中 | SI013, SI015, SI018, SI024 |
| CI036 | Circle's 2025 S-1 and S-1/A filings illustrate the level of financial and risk disclosure public investors now expect from crypto-adjacent issuers, highlighting how much more detail CertiK would need to provide before an IPO could be underwritten conventionally. | 中 | SI027, SI028, SI030 |
| CE001 | CertiK currently presents itself as an all-in-one Web3 security and compliance suite spanning smart-contract audits, on-chain monitoring, AML, incident response, and adjacent security services rather than a single-point audit vendor. | 高 | SE001, SE004, SE010, SE011 |
| CE002 | The homepage positions formal verification as a core element of CertiK's security approach, tying the brand to correctness-oriented review rather than checklist auditing alone. | 中 | SE001, SE024 |
| CE003 | CertiK's audit product is the pre-deployment entry point in the workflow, while pentesting extends the product set into off-chain and application-layer security. | 中 | SE010, SE011 |
| CE004 | The homepage says the code-security practice has detected 117,000-plus vulnerabilities, assessed $472 billion in market cap, and produced 90,000-plus audit findings. | 中 | SE001 |
| CE005 | The same homepage says Skynet monitors 21,000-plus projects across 100-plus ecosystems and serves 1.8 million-plus monthly active users, indicating a large community-facing intelligence surface. | 中 | SE001 |
| CE006 | SkyInsights is positioned for exchanges, DeFi protocols, financial institutions, and custodians, showing that CertiK has built a product specifically for compliance-led and regulated workflows. | 中 | SE004, SE005 |
| CE007 | SkyInsights says it offers 300 million-plus address labels, 4,000-plus incidents detected since 2020, and full or lite support across multiple chains, making it one of the most data-heavy modules in the suite. | 中 | SE004 |
| CE008 | The SkyInsights introduction describes four core endpoint groups—address labels, address risk, address screening, and transaction risk—which map directly to AML and investigative use cases. | 中 | SE005 |
| CE009 | The SkyInsights docs expose a versioned REST base URL at api.skyinsights.certik.com/v4 and require X-API-Key and X-API-Secret headers, indicating an authenticated enterprise API rather than a public playground-only product. | 中 | SE006 |
| CE010 | The public CertiK Skills repository ships four agent-facing modules—SkyInsights, Skylens, Skynet Score, and Token Scan—giving CertiK an unusually explicit developer surface for integrating security data into AI workflows. | 高 | SE008, SE013 |
| CE011 | The repository is intentionally lightweight: it says the skills are self-contained, use Python 3.10-plus with standard-library-first tooling, and require no authentication for three of the four modules. | 中 | SE008, SE013 |
| CE012 | The Skynet Score skill hits a public project endpoint and returns an overall score plus component scores for code security, community, fundamentals, governance, market, and operations. | 中 | SE014 |
| CE013 | The Skylens skill supports trace retrieval, balance changes, state changes, nonce changes, and source-file extraction, so the product reaches well beyond simple dashboards into transaction-level forensics. | 中 | SE015 |
| CE014 | Skylens also depends on outbound HTTPS to skylens.certik.com and a zstd backend, implying this module is a genuine investigative toolchain rather than a thin wrapper over a static report. | 中 | SE015 |
| CE015 | The SkyInsights GitHub surface shows command support for KYA, labels, screening, and KYT across a long chain list, confirming that the authenticated compliance product is also designed for agent-based operational use. | 中 | SE016 |
| CE016 | The Token Scan module provides contract-level risk analysis with alert severity ordering, holder concentration, LP lock signals, and real buy-sell tax data across multiple supported chains. | 中 | SE017 |
| CE017 | CoinGecko says CertiK integrated CoinGecko API data into Skynet so users can assess projects using both security signals and market-performance context, broadening the product from security scoring into due-diligence intelligence. | 中 | SE021 |
| CE018 | The CoinGecko case study says Skynet uses real-time price feeds, project metadata, market-cap data, volume data, and exchange references to enrich project evaluations. | 中 | SE021 |
| CE019 | The 2026 Skynet prediction-markets report says its Top Board evaluates projects across code security, fundamental health, operational resilience, community trust, governance strength, and market stability. | 中 | SE009, SE018, SE019, SE020 |
| CE020 | That report also frames hybrid Web2/Web3 architecture risk, admin keys, oracle manipulation, and front-running as first-class analysis topics, showing CertiK's product scope extends beyond source-code defects into operating-model risk. | 中 | SE009, SE018 |
| CE021 | BlockchainReporter shows Skynet applying its scoring framework to AI-agent projects on BNB Chain, which suggests CertiK is willing to package sector-specific rankings as reusable product outputs. | 中 | SE022 |
| CE022 | The Skill Scanner product broadens CertiK beyond blockchain protocols into AI-agent security, indicating active adjacent expansion rather than only deeper specialization inside crypto-native audits. | 中 | SE007, SE025 |
| CE023 | Skill Scanner evaluates five specific risk categories—malicious behavior, data exfiltration, unauthorized network activity, shell execution, and file-system misuse—so its detection lens is operational and behavior-focused. | 中 | SE007 |
| CE024 | Skill Scanner accepts a GitHub repo, URL, or ZIP file and returns a 0-100 score with pass, warn, or fail verdicts plus a severity-organized findings list. | 中 | SE007 |
| CE025 | CertiK says Skill Scanner reaches up to 90.5% precision and is built to plug into publishing pipelines, enterprise compliance review, and pre-submission developer workflows. | 中 | SE007 |
| CE026 | The YZi Labs partnership specifies formal verification, Skynet Boosting, and AI scanning services, indicating the company is already packaging multiple technical modules together in incubation-style deployments. | 中 | SE025 |
| CE027 | Gem Wallet's customer post shows CertiK audits functioning as a public trust signal for downstream wallet adoption, not only as internal developer QA. | 中 | SE023 |
| CE028 | CertiK publicly displays SOC 2 Type II and ISO 27001 credentials on its homepage, and its own guidance says these controls help satisfy enterprise, bank, and regulator diligence gates. | 中 | SE001, SE012 |
| CE029 | The SOC 2 and ISO 27001 guide emphasizes a combined control program, a roughly year-long path to a bank-acceptable report, and explicit documentation boundaries around customer-facing systems. | 中 | SE012 |
| CE030 | Because SkyInsights requires credentials while Skynet Score, Skylens, and Token Scan expose public endpoints, CertiK appears to segment the suite into community-accessible trust surfaces and enterprise-grade authenticated intelligence. | 中 | SE008, SE013, SE014, SE015, SE016, SE017 |
| CE031 | Public product evidence supports a customer workflow that starts with code review, extends to penetration testing and continuous monitoring, and then adds risk analytics or compliance tooling for ongoing operations. | 高 | SE001, SE004, SE010, SE011 |
| CE032 | The open-source skills make CertiK easier to embed into agent and developer workflows than many security vendors that only expose marketing pages or sales-led APIs. | 中 | SE008, SE013, SE014, SE015, SE016, SE017 |
| CE033 | The available evidence shows strong product breadth but comparatively weak public reliability detail: no uptime dashboard, public SLA, or incident-history source appears in this chapter's corpus. | 中 | |
| CE034 | Public roadmap evidence is incremental rather than comprehensive: new AI skills, a new Skill Scanner, new Skynet sector reports, and bundled incubation services are visible, but a dated multi-quarter module roadmap is not. | 中 | SE007, SE008, SE009, SE022, SE025 |
| CE035 | CertiK's product architecture depends materially on public APIs, proprietary scoring logic, external market-data feeds, and partner or customer trust loops, creating a richer moat than audits alone but also more integration points to manage. | 中 | SE013, SE014, SE015, SE016, SE017, SE021, SE023 |
| CU001 | CertiK's customer-facing proof spans protocols, wallets, exchanges, incubators, and enterprise-compliance buyers rather than a single narrowly defined customer class. | 中 | SU001, SU002, SU003, SU005, SU022 |
| CU002 | The testimonials page says CertiK has serviced 5,500 clients, assessed $472 billion of market cap, and detected 117,000 findings, which provides broad but company-claimed evidence of scale. | 中 | SU001 |
| CU003 | The smart-contract-audit page says CertiK has audited 6,159-plus projects and 1,227-plus formally verified projects, indicating a large installed base of launch-stage and post-launch audit customers. | 中 | SU005 |
| CU004 | The homepage says Skynet monitors 21,000-plus projects across 100-plus ecosystems and serves 1.8 million-plus monthly active users, showing that CertiK also reaches a large community and due-diligence audience beyond direct paying customers. | 中 | SU006 |
| CU005 | Gem Wallet said its first independent CertiK assessment, published April 8 2026, found zero critical and zero high issues across its iOS and Android wallet apps. | 中 | SU010, SU011 |
| CU006 | The Gem Wallet materials say six medium issues were resolved before publication and four low-severity recommendations were acknowledged, giving one of the clearest public examples of CertiK's audit output translating into customer hardening work. | 中 | SU010, SU011 |
| CU007 | Gem Wallet positions the audit as a community trust asset and says the live security profile remains visible on CertiK Skynet, showing how CertiK's work can extend past a private deliverable into ongoing user-facing reassurance. | 中 | SU010, SU011 |
| CU008 | CertiK said its Gate Dubai proof-of-reserves engagement verified that the exchange's on-chain reserves fully backed in-scope customer liabilities across ten digital assets as of December 31 2025. | 高 | SU003, SU012, SU013 |
| CU009 | The Gate Dubai materials show CertiK independently rebuilt the Merkle tree and verified control of reserve wallets through transaction-based proof, indicating the customer relationship included operational verification work rather than a lightweight attestation. | 高 | SU003, SU012, SU013 |
| CU010 | Because Gate Dubai is VARA-licensed, the proof-of-reserves case also demonstrates CertiK selling into regulated exchange workflows where customer trust and compliance evidence are intertwined. | 中 | SU003, SU012 |
| CU011 | The OKX security-framework announcement says the partnership covers the exchange platform, mobile applications, wallet security, and smart-contract audits, showing CertiK can expand from a point engagement into a broader account relationship. | 中 | SU014, SU015 |
| CU012 | The same OKX coverage says CertiK's Skynet Security Score was integrated into OKX's Web3 Earn DeFi aggregator, which is a stronger deployment signal than a logo alone because it embeds CertiK data inside a customer product surface. | 中 | SU014, SU015 |
| CU013 | TechCrunch reported in 2026 that CertiK is one of the early builders on OKX AI, where its service lets AI agents assess wallet or token security before executing transactions. | 中 | SU027 |
| CU014 | The Hub71 partnership gives portfolio startups a 20% discount on CertiK services, a $200,000 subsidy pool, and free access to the CertiK Compliance Tool, showing a channel strategy aimed at early-stage customer acquisition. | 中 | SU002, SU016 |
| CU015 | Hub71's own site describes a dedicated digital-assets program in Abu Dhabi, which makes CertiK's vendor role more meaningful as an embedded ecosystem provider rather than a one-off promo partner. | 中 | SU002, SU016 |
| CU016 | The YZi Labs partnership similarly packages formal verification, Skynet boosting, and AI scanning with a $1 million audit-grant pool, indicating CertiK uses ecosystem programs to seed future customers before they become mature enterprises. | 中 | SU020 |
| CU017 | SkyInsights is explicitly designed for exchanges, DeFi protocols, financial institutions, and custodians, which implies buyer personas now include compliance and risk teams in addition to protocol founders or CTOs. | 中 | SU022 |
| CU018 | The SkyInsights auth gate and API credential model imply that this product is sold as an enterprise or controlled-access service rather than as a purely community-facing free tool. | 中 | SU022, SU023 |
| CU019 | CertiK's SOC 2 and ISO 27001 guidance says banks and enterprise procurement teams request these credentials at predictable points in diligence, indicating enterprise sales cycles depend on control evidence as well as technical capability. | 中 | SU021 |
| CU020 | The testimonials corpus shows customers using CertiK not only for code review but also as a gatekeeper or verification signal for users, investors, exchanges, and partner protocols. | 中 | SU001, SU005 |
| CU021 | One testimonial says the customer had been working with CertiK since 2018, offering at least one explicit public signal that some relationships are durable rather than single-project transactions. | 中 | SU001 |
| CU022 | Another testimonial says the customer completed two audits with CertiK and enabled Skynet, which suggests CertiK can expand accounts from one audit into recurring monitoring or repeated reviews. | 中 | SU001 |
| CU023 | The Gem Wallet post says the company plans to conduct regular independent security assessments going forward, creating a plausible repeat-engagement pattern if the first CertiK audit met expectations. | 中 | SU010 |
| CU024 | Bitget Wallet's CertiK page describes a wallet with over 80 million users, 130-plus supported blockchains, and a $300 million-plus user-protection fund, showing CertiK also serves high-scale consumer wallet brands. | 中 | SU007 |
| CU025 | The skills repository and Skill Scanner launch show a newer customer segment emerging around AI-agent developers, marketplaces, and enterprises evaluating third-party skills. | 中 | SU024, SU025, SU027 |
| CU026 | Skill Scanner is marketed to AI-skill marketplaces, enterprises, and independent developers, while OKX AI shows a live distribution channel where CertiK can reach that segment. | 中 | SU025, SU027 |
| CU027 | Because CertiK sells both public trust surfaces and controlled-access tools, the buyer-user-payer split likely varies by module: founders buy audits, operations teams use monitoring, and compliance teams procure risk analytics. | 中 | SU005, SU006, SU022 |
| CU028 | The public customer proof is strongest for named deployments and partner announcements, but much weaker for retention, satisfaction scores, or customer concentration by revenue. | 中 | SU001, SU010, SU012, SU014 |
| CU029 | No public source in this set discloses NRR, GRR, churn, renewal rates, average contract length, or top-customer concentration, so durability still has to be inferred from anecdotes. | 中 | |
| CU030 | The Yahoo Finance report says CertiK has come under criticism for controversies including the Kraken bug episode and prior auditing decisions, which could increase procurement friction for customer accounts that care about reputation. | 中 | SU026 |
| CU031 | The existence of restricted or promotional source surfaces around customer adoption means some of CertiK's proof remains marketing-led, especially outside the clearest named examples like Gate Dubai and Gem Wallet. | 中 | SU017, SU018, SU019, SU026 |
| CU032 | Gate Dubai, Hub71, and OKX together indicate CertiK has material customer or channel traction in the Middle East, a region where regulatory build-out and institutional adoption are accelerating. | 中 | SU002, SU003, SU016 |
| CU033 | CertiK's customer base appears broad across maturity stages: startups get subsidized access through Hub71 or YZi-style programs, while larger wallets and exchanges buy audits, monitoring, or proof-of-reserves work. | 中 | SU002, SU003, SU007, SU020 |
| CU034 | The audit page's statement that CertiK is the recommended auditor by top exchanges reinforces that exchange distribution and listing influence likely matter in how new projects choose a security vendor. | 中 | SU005 |
| CU035 | Overall, public evidence supports real adoption across several segments, but it does not yet prove how much revenue comes from recurring enterprise accounts versus one-off launch audits. | 中 | SU001, SU005, SU022, SU026 |
| CR001 | VARA describes its framework as consumer-protection- and risk-assurance-oriented, highlighting that virtual-asset service providers in Dubai operate under a regulator explicitly focused on safe market adoption. | 中 | SR004 |
| CR002 | ADGM said it implemented amendments to its digital-asset framework covering accepted-virtual-asset processes, capital requirements, fee changes, product-intervention powers, and explicit bans on privacy tokens and algorithmic stablecoins. | 高 | SR007, SR031 |
| CR003 | ADGM's public-consultation docket shows that AML rules, crypto-mining guidance, and other digital-asset questions were still being revised in 2026, so the regulatory baseline around crypto infrastructure remains a moving target. | 中 | SR031 |
| CR004 | CertiK's Hub71 announcement says licensing and compliance have become early-stage requirements for digital-asset startups in the UAE, implying that regulatory friction can arrive earlier in the sales cycle than founders expect. | 中 | SR015, SR016 |
| CR005 | CertiK Hunt's terms of use are a legally binding agreement under Delaware law and warn that the platform is not tailored for regulated regimes such as HIPAA, FISMA, or GLBA. | 中 | SR003 |
| CR006 | The same terms say CertiK is not a party to sponsor-researcher reward agreements and does not guarantee program-rule accuracy or reward payment, showing that its bug-bounty platform introduces legal and process boundaries that can still create disputes. | 中 | SR003 |
| CR007 | CertiK's trust center says Skyharbor completed ISO 27001 and SOC 2 Type I and Type II examinations, which is a real mitigation for enterprise trust and internal-control risk. | 高 | SR002, SR013 |
| CR008 | However, CertiK only offers those reports and certificates on request, which means outside observers cannot fully inspect scope, exceptions, or control maturity from public materials alone. | 中 | SR002 |
| CR009 | CertiK's own Gate Dubai proof-of-reserves report says the work is a point-in-time attestation of specified assets and liabilities as of 31 December 2025, not a comprehensive financial audit or regulatory endorsement. | 高 | SR014, SR008 |
| CR010 | The same proof-of-reserves report says the scope excludes out-of-scope assets and does not represent an ongoing guarantee of reserves, so customers or users could over-interpret the comfort CertiK provides. | 中 | SR014 |
| CR011 | In its own Kraken statement, CertiK admitted that it made errors in judgment and communicated poorly, turning a security discovery into a public dispute. | 中 | SR001 |
| CR012 | CertiK also said it partnered with outside counsel to improve internal bug-bounty processes after the Kraken episode, which suggests the prior process was materially insufficient for the situation it faced. | 中 | SR001 |
| CR013 | Yahoo Finance says critics targeted CertiK over a Huione-linked audit, the Kraken incident, and the compromise of its X account, showing that multiple controversy types have accumulated around the brand. | 中 | SR009 |
| CR014 | TheNewsCrypto reported that after the Huione backlash CertiK tightened KYC, added outside risk experts, and increased post-audit monitoring of how reports are used. | 中 | SR012 |
| CR015 | Those Huione-related process changes imply that client screening and downstream-use monitoring were previously underbuilt relative to the standards large institutions now expect. | 中 | SR009, SR012 |
| CR016 | Coinpaper reported that Kraken characterized CertiK's handling of the exploit as extortion rather than ethical hacking and said law enforcement was involved in recovery efforts. | 中 | SR033 |
| CR017 | Blockchain Intelligence Group traced exploited Kraken funds through Tornado Cash and ChangeNOW, demonstrating how incident handling can create additional compliance and reputational exposure beyond the original bug itself. | 中 | SR028 |
| CR018 | The same on-chain investigation warned that the episode could blur the line between ethical hacking and exploitation, which risks weakening trust between customers and security researchers more broadly. | 中 | SR028 |
| CR019 | CoinGecko says CertiK depends on its API for real-time price and market data inside Skynet, so a portion of CertiK's public risk analysis depends on third-party data availability and quality. | 中 | SR017 |
| CR020 | CertiK's public GitHub skills repo and agent integrations turn its intelligence into widely distributable tooling, which is strategically useful but also widens the support, misuse, and public-failure surface. | 中 | SR018, SR019 |
| CR021 | Skill Scanner is explicitly built to catch malicious behavior, data exfiltration, unauthorized network activity, shell execution, and file-system misuse, which shows CertiK is entering a product area where false negatives can be especially reputationally costly. | 中 | SR021 |
| CR022 | Skill Scanner's stated precision of up to 90.5% is directionally strong but still leaves residual model-error risk that matters when enterprises use the tool as a trust signal. | 中 | SR021 |
| CR023 | SkyInsights requires API keys and secrets, and its docs define explicit 401, 429, and 500-style failure modes, which highlights both credential-management risk and service-availability risk for enterprise customers. | 中 | SR023, SR024 |
| CR024 | Because SkyInsights spans address risk, labels, screening, and transaction analysis across many chains, its value depends materially on data quality, entity attribution accuracy, and chain coverage staying current. | 中 | SR023, SR024 |
| CR025 | TechCrunch reported that CertiK is an early builder on OKX AI, where its service lets agents assess wallet or token security before transactions, creating a platform dependency on a partner ecosystem that CertiK does not control. | 中 | SR020 |
| CR026 | Hub71 creates a channel dependency of a different kind: it can seed customers efficiently, but its value depends on subsidy economics, regional regulatory momentum, and conversion from ecosystem support into paid work. | 中 | SR015, SR016 |
| CR027 | YZi Labs audit grants similarly expand distribution but can also produce low-quality or non-converting pipeline if founders take subsidized audits without becoming durable customers. | 中 | SR022 |
| CR028 | The audit page's claim that CertiK is recommended by top exchanges suggests exchange relationships are meaningful distribution assets, but it also means reputation damage with gatekeeper customers could cascade through new-logo acquisition. | 中 | SR025 |
| CR029 | Public reporting still does not disclose NRR, GRR, customer concentration, or segment revenue mix, leaving a material model risk around how much of CertiK's revenue is durable versus one-off. | 中 | |
| CR030 | Yahoo framed the planned IPO narrative as one that depends on regaining trust after several blunders, so reputational repair is now directly tied to financing and public-market optionality. | 中 | SR009 |
| CR031 | The Huione and institution-grade-risk commentary reported by TheNewsCrypto implies CertiK may face rising delivery costs as large customers demand deeper testing, stronger proof, and clearer reports for regulators. | 中 | SR012, SR013 |
| CR032 | The trust center and Hunt terms show that CertiK is no longer just an audit firm; it is also a platform operator and control custodian, which increases legal, operational, and governance complexity. | 中 | SR002, SR003 |
| CR033 | Gate Dubai and VARA together show that regulated exchange customers will expect standardized and independently verifiable assurance mechanisms, making quality failures in these products especially high stakes. | 中 | SR004, SR008, SR014 |
| CR034 | ADGM and VARA both emphasize evolving rules and explicit asset restrictions, which means some product ideas or customer requests may become unserviceable or less attractive in certain jurisdictions. | 中 | SR004, SR007, SR031 |
| CR035 | TheNewsCrypto quotes Ronghui Gu saying risks are shifting toward private-key handling, deepfakes, and price-feed manipulation, implying CertiK must continuously adapt beyond traditional smart-contract review. | 中 | SR012 |
| CR036 | Because CertiK increasingly sells compliance and regulated-assurance services, any gap between marketing comfort and legal disclaimer language could create client-expectation or mis-selling risk. | 中 | SR003, SR014, SR024 |
| CR037 | The proof-of-reserves disclaimer that CertiK's work is not regulatory approval means customers, users, or media may still over-attribute safety to the CertiK brand and blame it when later issues surface. | 中 | SR014 |
| CR038 | CertiK's public trust surfaces—Skynet scores, published audits, and sector reports—create leverage when the brand is strong, but they also amplify mistakes because the company is visibly attached to many downstream outcomes. | 中 | SR018, SR025, SR026 |
| CR039 | Partner channels such as Hub71, OKX AI, CoinGecko, and regulated exchange references make CertiK's pipeline and brand increasingly sensitive to counterparties' own stability and reputational issues. | 中 | SR017, SR020, SR022 |
| CR040 | Overall, CertiK's top risks cluster around reputation and process discipline, regulatory complexity, partner dependence, and the public evidence gap on financial durability rather than around a lack of market demand. | 中 | SR001, SR007, SR009, SR017, SR029 |
| CV001 | CertiK's last clear public priced equity mark is the March 2022 Series B3 round that the company and TechCrunch described at a $2 billion valuation. | 高 | SV001, SV003, SV023 |
| CV002 | The prior December 2021 financing was presented at nearly a $1 billion valuation, showing the company's headline mark doubled within a few months before the 2022 peak. | 高 | SV002, SV024 |
| CV003 | Tracxn says CertiK has raised about $296 million over nine rounds from 43 institutional investors, which indicates a heavily venture-backed cap table even though preferences are undisclosed. | 中 | SV023, SV024 |
| CV004 | 2026 IPO coverage from Yahoo Finance, The Block, Cointelegraph, and CoinCentral still anchors CertiK around a $2 billion valuation, implying the public narrative has not yet established a clearly higher current mark. | 高 | SV004, SV005, SV006, SV007 |
| CV005 | The new $45 million CertiK Ventures fund and the 2026 YZi Labs audit-grant partnership show ecosystem expansion and distribution activity, but neither source discloses a new financing valuation for the parent company. | 中 | SV008, SV030 |
| CV006 | Latka lists CertiK at roughly $87 million ARR for 2025, but that figure is secondary-database data rather than audited company disclosure. | 中 | SV022 |
| CV007 | If the $87 million ARR proxy is directionally right, the last $2 billion mark implies roughly a 23.0x revenue multiple. | 中 | SV001, SV022 |
| CV008 | That implied multiple is highly sensitive because public evidence does not disclose audited ARR, gross margin, recurring-revenue mix, or retention metrics for CertiK. | 中 | SV004, SV022, SV023 |
| CV009 | CertiK's audit, SkyInsights, AI-security, and CoinGecko case-study materials support a real scale narrative, but they prove product demand more clearly than they prove monetization quality. | 中 | SV025, SV026, SV027, SV028 |
| CV010 | Sherlock's 2026 market reference says most DeFi protocol audits land between $25,000 and $100,000, the broader market spans roughly $5,000 to $250,000 per engagement, and serious protocols often spend $150,000 to $500,000 annually on security programs. | 中 | SV029 |
| CV011 | Those audit-pricing bands imply that a $2 billion valuation likely requires either very high engagement volume, meaningful recurring monitoring/compliance revenue, or both. | 中 | SV026, SV029 |
| CV012 | Circle filed an S-1 in August 2025 and an amended S-1 in 2025, showing that the public market window for crypto infrastructure listings reopened during this cycle. | 高 | SV009, SV010, SV011 |
| CV013 | Circle's filing cadence also illustrates how disclosure-heavy a crypto-related IPO process is, which makes CertiK's thinner current public disclosure a real valuation handicap. | 中 | SV009, SV010, SV011, SV004 |
| CV014 | As of August 2026 CrowdStrike carried about $206.23 billion of market cap against roughly $4.812 billion of annual revenue, or about 42.9x sales. | 中 | SV017, SV036 |
| CV015 | As of August 2026 Palo Alto Networks carried about $282.91 billion of market cap against roughly $9.222 billion of annual revenue, or about 30.7x sales. | 中 | SV018, SV032 |
| CV016 | As of August 2026 SentinelOne carried about $6.85 billion of market cap against roughly $821 million of annual revenue, or about 8.3x sales. | 中 | SV019, SV033 |
| CV017 | As of August 2026 CyberArk carried about $20.63 billion of market cap against roughly $1.001 billion of annual revenue, or about 20.6x sales. | 中 | SV020, SV034 |
| CV018 | As of August 2026 Zscaler carried about $24.97 billion of market cap against roughly $2.673 billion of annual revenue, or about 9.3x sales. | 中 | SV021, SV035 |
| CV019 | This selected public-cyber comp set spans roughly 8.3x to 42.9x sales, with a median around 20.6x and a simple average around 22.4x. | 中 | SV017, SV018, SV019, SV020, SV021, SV032, SV033, SV034, SV035, SV036 |
| CV020 | CertiK's roughly 23.0x implied multiple sits above the lower-growth public names and below the richest premium leaders, so it is not impossible on sector math alone but it is demanding for an opaque private company. | 中 | SV001, SV022, SV017, SV018, SV019, SV020, SV021, SV032, SV033, SV034, SV035, SV036 |
| CV021 | Because public cyber leaders publish audited revenue, margins, and growth while CertiK does not, investors should still demand a private-company opacity discount relative to the cleaner public comps. | 中 | SV004, SV014, SV015, SV016, SV031 |
| CV022 | The investment thesis is that CertiK owns a credible web3-security brand, broad installed proof points, and an expanding product set that could support durable recurring revenue if enterprise and compliance products scale. | 中 | SV025, SV026, SV027, SV028, SV030 |
| CV023 | The anti-thesis is that CertiK may still be over-indexed to project-driven audit revenue and reputation-sensitive crypto cycles, while the public record is too thin to prove the quality of the recurring base. | 中 | SV004, SV022, SV025, SV029 |
| CV024 | On public evidence alone, the most supportable recommendation is research-more with strict entry discipline rather than an unconditional buy at the last headline mark. | 中 | SV004, SV007, SV020, SV021, SV023 |
| CV025 | Confidence should be medium because enough evidence exists to frame a range, but not enough exists to defend a precise fair-value number. | 中 | SV004, SV022, SV023 |
| CV026 | Risk rating should be medium-high because valuation support depends on closing evidence gaps around monetization quality, reputation repair, and cap-table economics. | 中 | SV004, SV021, SV023 |
| CV027 | The valuation stance should treat $2 billion as a plausible upside reference point or ceiling case, not as a fully validated present-tense fair value. | 中 | SV001, SV004, SV020, SV021 |
| CV028 | A reasonable bull case requires evidence that recurring revenue is above roughly $120 million, enterprise/compliance mix is rising, and public-market appetite for crypto-adjacent security remains open. | 中 | SV012, SV019, SV026, SV030 |
| CV029 | A reasonable base case assumes revenue is closer to the current secondary estimate, growth continues but disclosure remains partial, and the company trades at a discounted multiple to premium public cyber leaders. | 中 | SV004, SV022, SV019, SV021 |
| CV030 | A reasonable bear case assumes the revenue base is materially smaller than the proxy suggests or that another trust shock compresses growth and multiples at the same time. | 中 | SV004, SV022 |
| CV031 | At $80 million of revenue and a 10x multiple, enterprise value support would be about $0.8 billion. | 中 | SV022, SV019, SV021 |
| CV032 | At $80 million of revenue and a 15x multiple, enterprise value support would be about $1.2 billion. | 中 | SV022, SV017, SV018, SV020 |
| CV033 | At $100 million of revenue and a 15x multiple, enterprise value support would be about $1.5 billion. | 中 | SV022, SV018, SV020 |
| CV034 | At $100 million of revenue and a 20x multiple, enterprise value support would be about $2.0 billion. | 中 | SV017, SV018, SV020, SV022 |
| CV035 | At $150 million of revenue and a 20x multiple, enterprise value support would be about $3.0 billion. | 中 | SV017, SV018, SV020 |
| CV036 | The comparable set is most useful as a ceiling-floor framework rather than as a direct like-for-like peer exercise because CertiK mixes private crypto-security exposure with products that resemble both services and software. | 中 | SV020, SV021, SV023, SV029 |
| CV037 | There is still not enough public evidence to map liquidation preferences, investor rights, or option-pool dilution, so return underwriting remains incomplete even if the enterprise value range looks reasonable. | 中 | |
| CV038 | There is also no public NRR, GRR, cohort retention, or gross-margin disclosure to prove that CertiK deserves to trade near the premium end of the public-cyber range. | 中 | |
| CV039 | Despite IPO ambition, the current public record supports viewing CertiK as IPO-aspirational rather than obviously IPO-ready today. | 中 | SV004, SV005, SV012 |
| CV040 | Final diligence should prioritize audited ARR or revenue, gross margin, recurring-versus-services mix, customer concentration, and cap-table rights before any investor accepts the last mark as fair value. | 中 | SV022, SV023, SV024 |
| CV041 | Thesis-break triggers include a new trust controversy, evidence of weak renewal quality, a materially lower internal revenue base, or a financing event below the $2 billion reference point. | 中 | SV004, SV022, SV023 |
| CV042 | The bottom-line verdict is that CertiK merits continued diligence because the category, product scope, and brand are real, but valuation conviction should improve only if management proves recurring revenue quality or offers entry terms below the most optimistic public narrative. | 中 | SV004, SV020, SV022, SV023, SV029 |