Clearer Crypto Rules Could Push Firms to Strengthen Security: CertiK

24 July 2026 - 21:04 CEST
By Jona Jaupi

As the US Congress moves closer to setting rules for the crypto industry, companies will need to treat security as a core part of their business rather than simply a technical issue, according to blockchain security firm CertiK.

Stefan Muehlbauer, head of US government affairs at CertiK, told Sandmark that the CLARITY Act working its way through Congress, along with the already-passed GENIUS Act for stablecoins, shows the crypto industry is moving closer to the standards expected of traditional financial institutions.

"Everything in this industry is really starting to point more to a maturity and being treated more like a grown-up financial institution," Muehlbauer said. 

His comments come as Senate Republicans and Democrats continue negotiating the CLARITY Act ahead of Congress's 7 Aug recess. The CLARITY Act would establish a clear regulatory framework for digital assets by defining when the Securities and Exchange Commission (SEC) or the Commodity Futures Trading Commission (CFTC) oversees different parts of the crypto market.

Security in the spotlight

Although the CLARITY Act does not include cybersecurity requirements, Muehlbauer said clearer rules should give companies more confidence to invest in security, governance and compliance. 

"I think it will give everybody a much more even playing field," he said. "It gives people confidence that what they're doing aligns with what's expected." 

He said crypto companies should expect to meet many of the same standards as banks and other regulated financial institutions. "That brings KYC, AML, all of those things," Muehlbauer said. "But on top of it, of course, brings the requirement of, let's not be hacked."

That push towards bank-like standards comes as the industry continues to suffer costly security attacks.

Three separate exploits disclosed on 23 Jul drained more than $35mn from decentralized finance (DeFi) protocols. Layer 1 blockchain AFX lost about $24.2mn after attackers exploited its bridge contract on Arbitrum. BSquared, a Bitcoin Layer 2, separately lost $3.9mn after attackers drained 8.59 million B2 tokens, while the VerusCoin network lost $7.5mn after attackers exploited a flaw in its Ethereum bridge.

Meanwhile CertiK's latest research found physical attacks targeting crypto investors are also becoming more common. CertiK recorded 52 verified "wrench attacks" -  physical attacks or coercion to steal crypto assets - during the first half of 2026, up from 39 during the same period a year earlier, with recorded financial exposure rising to about $124mn.

More institutions are entering the market

Muehlbauer said the blockchain security firm is seeing growing demand from banks and other traditional financial institutions exploring blockchain technology. While declining to discuss specific clients, he said more established financial firms are preparing to launch digital asset products and understand they must protect customer assets.

That shift is putting more financial assets on blockchain infrastructure. The value of tokenized assets on public blockchains reached $36.7bn on 24 Jul, up from $16.5bn a year earlier, according to RWA.xyz. The growth does not establish that tokenization is causing more attacks, but it means more financial value depends on smart contracts, bridges, wallets and digital key-management systems, increasing the potential cost of a security failure.

Over the past few years alone, JPMorgan has expanded its tokenization efforts through Kinexys, Bank of America recently appointed a new head of digital assets, and some of the world's largest asset managers, such as BlackRock, Fidelity and Franklin Templeton, continue to grow their tokenized offerings.

Meanwhile, the Depository Trust & Clearing Corporation (DTCC), which provides the central infrastructure for the US financial market, this month completed tokenized securities transactions using assets held at its Depository Trust Company as it prepares to launch its tokenization platform later this year.

"The institutions are definitely realizing the value of blockchain," Muehlbauer said. "They know that you need to be a good steward of client funds." 

He added that shift is becoming increasingly visible across the industry. "Three or four years ago, most companies were names you could barely pronounce, or were very small startups," Muehlbauer said. "Meanwhile, when you glance around, you see quite a few more household names." 

Thinking beyond audits

As more institutions enter the market, Muehlbauer said companies need to seriously think beyond smart contract audits and build security into every stage of a product, from writing code and testing it before launch to monitoring it after it goes live. 

A smart contract audit typically only checks blockchain code for security issues and coding mistakes before it is deployed. But because hacks are getting more sophisticated, smart contract audits should not be a company's only line of defense.  

Muehlbauer added that with crypto maturing and regulation becoming clearer, companies should expect to be held to the same standards as traditional financial firms, especially when it comes to protecting customer assets and managing risk.

"Be prepared to be treated like financial institutions, because that's just the way it's going to go," Muehlbauer said.