CertiK's Bug Bounty and Audit Practices Face Mounting Scrutiny
Blockchain security firm CertiK is facing a wave of criticism following a controversial episode involving Kraken, with researchers now raising separate concerns about how the company runs its bug bounty aggregator and conducts its audits.
01The Kraken Episode

CertiK drew backlash after it exploited a vulnerability it discovered on Kraken and held roughly $3 million of the exchange's funds, describing the action as "research." The firm later returned the money once the criticism mounted, but the episode had already damaged its standing.
Following Rekt News's original coverage of that incident, security researcher Tayvano published findings pointing to a broader pattern of questionable conduct tied to the company. What began as fallout from a single exploit has since expanded into accusations spanning bug bounty practices and audit quality, prompting a wider conversation about who is supposed to hold security auditors accountable.
02Allegations of Front-Running Bug Bounties
Much of the newer controversy centers on OpenBounty, a bug bounty aggregator incubated by Shentu Chain — the network formerly known as CertiK Chain before it was rebranded in 2021. CertiK originally founded that chain, and although CertiK and the Shentu Foundation are now presented as separate entities, their shared origins have fueled questions about conflicts of interest.
Security researcher h0wlu was the first to flag the problem. After registering a test account expecting OpenBounty to be a simple aggregator of publicly listed bounties, h0wlu instead found that the platform hosted its own submission forms for bounty programs run by other organizations, with vulnerability reports funneled to CertiK-linked API servers rather than sent directly to the affected project.
Among the programs OpenBounty was soliciting submissions for were ImmuneFi-hosted bounties, along with self-hosted programs belonging to Uniswap and Ethereum — despite Uniswap's own bug bounty rules explicitly requiring reports to be sent directly to the project rather than through a third party.
Critics argue the setup could let CertiK see critical vulnerability disclosures before the affected protocols do, creating an information advantage that could theoretically be used commercially or as leverage to sell CertiK's services. h0wlu added that the API behind OpenBounty was hosted on a subdomain that itself contained the word "CertiK," reinforcing the link between the two.
PopPunk, co-founder of Gaslite and a longtime CertiK critic, echoed the concern, noting that submitting a bounty report through OpenBounty triggered requests to a CertiK-branded domain — behavior he said amounted to front-running the bounty process itself, and one that could put OpenBounty in violation of the terms of service governing many of the programs it was quietly funneling reports from.
Matters escalated further when, according to PopPunk, CertiK began removing blog posts referencing OpenBounty and switched the API over to a domain no longer bearing the CertiK name — a move critics read as an attempt to obscure the connection rather than address it.
03Questions Over Audit Quality
Separately from the OpenBounty allegations, former clients and researchers have accused CertiK of favoring volume over rigor in its audit work.
Matías Barrios, an offensive security engineer at Halborn, described CertiK's typical process to The Defiant as stopping at automated static analysis rather than progressing through the manual review and testing stages that a full three-layer audit would normally include. In his account, CertiK commonly runs code through automated tooling and issues a brief report, without going further.

Barrios pointed to the April 2023 breach of Merlin, a DEX built on zkSync, as an illustration of the risk: roughly $1.8 million was drained through a flaw that CertiK's own audit had previously marked as resolved. He also suggested that much of CertiK's market dominance stems less from audit quality and more from brand recognition, telling The Defiant that many companies pursue a CertiK audit simply to be able to display its seal of approval.
04An Open Question
The controversy has left the industry weighing what it means when the firms responsible for vetting protocol security are themselves accused of the practices they're meant to guard against. CertiK has not moved quickly to respond to the allegations, and it remains unclear whether the OpenBounty practices — or the audit shortcuts described by former clients — will change as a result.
As the saying goes, the question now facing the industry is a simple one: who audits the auditors?
Get new scam files the moment we publish them — usually 2–3 emails a week.