Home Blog Page 23

Exclusive Interview with Johannes Kern: The Swiss Franc, Rebuilt for the Digital Age

For 250 years, the Swiss franc has done one thing better than almost any currency on earth: hold its value. While the dollar lost 80% of its purchasing power against the CHF over the last half century alone, the Swiss franc kept its head down and its reputation intact. It is the original store of value for the nervous, the cautious, and the long-term thinker. Johannes Kern wants to put it on a blockchain; and make it available to anyone in the world, no Swiss bank account required.

Kern is the Managing Director of the Frankencoin Association, the non-profit behind ZCHF, the largest Swiss franc stablecoin in existence. It’s an unusual title for an unusual project. There is no Frankencoin CEO. There is no Frankencoin headquarters in any meaningful sense. There is code, a blockchain, and an association in Zug that helps the thing grow without being in charge of it.

There’s a moment early in any good interview when you realise the person across from you is not going to play it safe. With Johannes Kern, it comes fast. Within minutes of sitting down at the Louvre Palace, he’s calling out Switzerland’s financial regulator, questioning why anyone trusts Tether, and matter-of-factly describing a future where the Swiss National Bank sits as a governance participant inside a decentralised protocol.

He came to Proof of Talk with one clear message. When we first reached out about the interview, his reaction was almost impatient: let’s talk about what it actually is. Not “a non-USD stablecoin.” Not “an alternative to dollar-denominated digital assets.” A Swiss franc stablecoin. The distinction matters to him; and by the end of the conversation, it will matter to you too.

The Dollar Is Losing. The Swiss Franc Has Been Winning For 250 Years.

The stablecoin market is a dollar monoculture. Over $300 billion in market cap, 99% of it denominated in USD. USDC, USDT are the plumbing of crypto. So why Swiss francs?

Kern doesn’t push back on dollar dominance for payments. He concedes it immediately. “If you talk about cross-border settlements, you’re really better off with just one currency. You want one currency that’s very liquid, that everyone can plug into. That’s why USDC and USDT are so strong. They’re this shared currency.”

But he draws a hard line between transacting and holding. And on holding, his case is blunt:

“The dollar lost about 80% of its value against the Swiss franc over the last 50 years. And if you go back 250 years, the Swiss franc has this historical strength as a store of value. That’s nothing new. large institutions in TradFi have always held Swiss francs because of that.”

The digital Swiss franc, in his framing, isn’t a crypto experiment. It’s just taking something that already exists in traditional finance, the CHF as a global safe-haven store of value, and making it available on-chain, to anyone in the world, without a bank.

The timing is not coincidental. The US dollar weakened significantly in 2025, and the geopolitical signal he points to is unusually concrete. The UAE leaving OPEC, he says, is “a very telling sign.” Large parts of the world are already looking for alternatives. The Swiss franc, and Frankencoin, are simply there waiting.

Who Actually Uses This Thing

When we ask who Frankencoin is actually for, Kern breaks it into three groups. And the third one is where his eyes light up.

First, domestic Swiss users who don’t want bank accounts. “We have quite a few users who don’t like banks and just live completely on-chain with Frankencoins,” he says, without any detectable irony. Switzerland has an estimated 4,000 people working in crypto who get paid in stablecoins. For them, ZCHF is a native currency.

Second, borrowers. Frankencoin offers some of the cheapest on-chain borrowing rates in the market, around 1.5% to borrow against Bitcoin. Because the Swiss franc carries historically low interest rates, the cost of minting ZCHF is structurally cheap. Compare that to a Swiss bank charging around 9% to borrow against Bitcoin, because of compliance overhead, and the efficiency case writes itself.

CrispyBull: “Frankencoin lets people hold, earn on, and spend Swiss francs without a bank account. That sounds almost too good. What’s the catch?”

Johannes Kern: “The much bigger market is the global market. It’s people with some assets who want to de-risk, who want an alternative to the dollar. This is also becoming a political question. There’s large parts of the world looking for alternatives, and the Swiss franc is just there, and on-chain is just there.”

The third group, then, is the one that makes this a multi-hundred-billion-dollar story in his telling: globally distributed capital looking for a non-dollar store of value that doesn’t require a Swiss bank account, a Swiss passport, or any relationship with Switzerland at all.

The Frankfurt Gut Punch — And Why He’s Fine With It

The most newsworthy exchange of the afternoon comes when we put a straightforward provocation to him. The first fully regulated Swiss franc stablecoin didn’t come from Switzerland. It came from Frankfurt. AllUnity, a joint venture backed by Deutsche Bank’s DWS Group, Flow Traders, and Galaxy Digital, launched a MiCA-compliant CHF stablecoin while Switzerland’s own regulator was busy tightening the screws on domestic crypto companies. Does it sting?

He’s not being theatrical. He describes a Swiss regulatory environment that has become “very hostile”, not specifically to decentralised finance, but to blockchain-based financial technology broadly. Companies in Swiss financial markets, he says, are spending their resources keeping up with constantly shifting compliance requirements rather than building anything. “It’s almost impossible to do business in Switzerland” is how he characterizes what he hears from the sector.

And then, mid-complaint, he drops something that turns the whole narrative sideways.

“We’re working quite closely with AllUnity,” Kern told us at Proof of Talk. A bridge between Frankencoin and AllUnity exists, accessible via Bitcoin Suisse, though for reasons best known to themselves, neither party has made any public noise about it.

Kern is characteristically unsentimental about why the collaboration makes sense. AllUnity, he explains, is not making money with their setup. It’s expensive to operate and their centralized, licensed structure limits what they can offer. Frankencoin, being fully decentralized, has no such constraints and can give them access to DeFi yield.

“We’re solving problems for both sides,” he says.

The Yield War Nobody Is Talking About

Frankencoin currently offers 3.5% annual yield on ZCHF. Swiss savings accounts offer materially less. Swiss banks, unsurprisingly, are lobbying against stablecoins being permitted to pay interest at all, arguing it threatens deposits.

Kern’s response is neither diplomatic nor especially worried. “The banks should just get better,” he says. He softens it slightly, but not much. His actual argument is more precise: banning yield doesn’t make yield disappear. It just moves it. Right now, he points out, stablecoin issuers who can’t pay yield directly are subsidizing kickbacks to exchanges and finding other ways to route the money. The user ends up worse off. Nothing else changes.

More importantly for Frankencoin specifically, he argues the whole debate is largely irrelevant to them. Yield restrictions are aimed at centralized issuers, entities that function like banks, taking in deposits and paying out returns. Frankencoin has no such issuer. It’s a peer-to-peer protocol.

Kern: “If you would want to prohibit that, you would have to prohibit DeFi effectively. That is a completely different can of worms, very similar to ‘let’s prohibit Bitcoin.’ Okay. You can try. What outcome does it bring you?”

The yield premium itself, he explains, comes from two structural differences versus banks. First, Frankencoin is backed by higher-volatility assets, primarily Bitcoin, which are more overcollateralized (currently around 230%) but carry a higher yield profile. Second, a decentraliszed protocol is structurally more efficient than a bank. “Banks are substantially more inefficient than a decentralized protocol by magnitudes,” he says flatly. “That’s where the difference comes from.”

Not All Stablecoins Are Created Equal

Before going further, it’s worth pausing on something the industry doesn’t always say clearly enough: Frankencoin and USDT or USDC are both called stablecoins, but the similarity largely ends there.

USDT and USDC are straightforward. For every token in circulation, the issuer holds an equivalent amount in cash, government bonds, or other fiat-equivalent assets. The peg is maintained by a centralised company with auditors, reserves, and ultimately a human being accountable for making sure one token equals one dollar. Simple, transparent in its own way, and battle-tested at scale.

Frankencoin works differently, and more complexly. ZCHF is minted when users deposit crypto assets, primarily Bitcoin, as collateral. That collateral currently sits at around 230% of the ZCHF in circulation, meaning the system is heavily overcollateralized as a buffer against volatility. There is no central issuer, no reserve account at a bank, and no single entity standing behind the peg. Stability comes from smart contracts, auction mechanisms, and the assumption that collateral values don’t fall faster than the system can respond.

That assumption has a limit. Bitcoin dropped sharply in the days following this interview, falling to an intraday low of $59,353 on June 5, briefly breaking below the $60,000 psychological support level for the first time since early 2026, and down over 45% from its October 2025 all-time high. Frankencoin’s TVL tells the story directly: it fell 43.8% in a single week, from $68.49M to $38.51M, as borrowers closed positions to avoid being liquidated. The protocol held its peg and TVL has since recovered to $63.32M. But the stress test was real. When crypto collateral loses value rapidly, the overcollateralization buffer shrinks. If it shrinks far enough, fast enough, the risk of a depeg becomes existential. This is not a flaw unique to Frankencoin. It is the inherent tradeoff of any decentralized, crypto-backed stablecoin.

Kern would argue — and does, in this interview — that the transparency of the on-chain system is precisely what makes it more trustworthy, not less. Every collateral position is visible in real time. There are no hidden risks, no opaque reserve reports. But visible risk is still risk, and readers should understand what they’re looking at before they decide whether 3.5% yield is worth it.

“Why Should You Trust Something Nobody Is In Charge Of?”

It’s the question that stops most people from ever engaging with decentralized finance. Tether has a CEO. Circle has auditors and GENIUS Act compliance. Frankencoin has code. For someone who’s never touched crypto, why would they trust it?

Kern’s first answer is a single word.

“Code.”

Then: “Turn the question around. Tether — for a very long time and still is — it’s not a very transparent company. So why do you trust them? Do you know Paolo? Is he a good guy?”

He’s not being glib. His point is that trust in centralized institutions is itself a kind of blind faith, one we’ve normalized through familiarity. With Frankencoin, “every block you can audit on-chain. There is no one who could take any decision, who could do something which you do not know about in advance. Everything is verifiable, everything is transparent.”

We push back. We grew up trusting banks. That’s just how we know finance.

“Exactly,” he says. “Core banking systems are a lot more fragile than blockchain, massively more fragile. And a lot more complex. Blockchain is reducing that complexity. It makes it actually verifiable. A person can go there and say: this is what is there. I can be sure this is actually there. It’s not just stale data from somewhere.”

The Dream: 100 Billion Francs, the SNB, and a Meta-Stablecoin

We close the conversation with the biggest question. If this works, if the digital Swiss franc becomes real financial infrastructure, what does it actually look like in ten years?

Kern is clear on what it isn’t. He doesn’t see Frankencoin as a domestic payment network. Centralized stablecoins, he says, are more efficient for that. Where he sees the real opportunity is in what he calls the “meta-stablecoin”: a decentralized, composable layer that anyone building on the Swiss franc plugs into.

He reaches for an analogy. “I like the term ‘Lego of moneys.’ You have Legos, you can combine them together frictionlessly. No written contracts with anyone. No silos, no islands. Just working together.”

In this vision, AllUnity might issue a regulated CHF stablecoin for institutions. UBS might issue one for private banking clients. A neobank might wrap it for retail. But underneath all of them, the shared fabric, the on-chain reserve layer, is Frankencoin.

And then he says the quiet part loud.

“If you paint the dream picture — 50 years down the line — 100 billion assets or more, the Swiss National Bank being one of the players actively shaping the development of Frankencoin, a governance token holder. It’s this meta-stablecoin that everyone who needs a Swiss franc on-chain just plugs into.”

The Swiss National Bank. A governance participant in a decentralized protocol built by a non-profit in Zug.

It’s an audacious vision. It’s also, in the logic of the conversation that preceded it, not entirely unreasonable. The Bank of England is already thinking about digital currencies that aren’t dollar-denominated. Kern is on a panel with them the following day. Switzerland, meanwhile, watches from the sidelines while a German consortium launches the first regulated Swiss franc stablecoin.

“I hope it stings them really hard,” he said at the beginning. By the end, it’s clear he’d rather they just showed up.

Checkout.com Partners With Coinbase to Bring Stablecoin Payments to Enterprise Merchants

Global payments provider Checkout.com has launched a new stablecoin acceptance capability for eligible merchants through a partnership with Coinbase.

The integration allows consumers to pay with USDC and USDT while merchants continue to settle transactions in U.S. dollars through Checkout.com’s existing payment infrastructure, eliminating the need for separate crypto integrations.

The move extends stablecoin payment access to Checkout.com’s network of more than 1,000 enterprise customers and reflects growing efforts by major payment providers to incorporate digital asset payment options into mainstream commerce.

New York Lawsuit Seeks Ownership of Dormant Bitcoin Wallets Holding $285B in BTC

TL;DR

  • A New York lawsuit seeks ownership of 39,069 dormant Bitcoin wallets using laws originally designed for lost property.
  • The case may hinge on whether publicly visible blockchain addresses can legally be considered “found” assets.
  • Even if the plaintiff succeeds, questions around private keys, ownership rights, and digital asset control would remain unresolved.

A New York lawsuit seeking ownership of thousands of inactive cryptocurrency wallets has attracted attention because of the extraordinary value associated with the addresses involved. The plaintiff, known as Noah Doe, is asking a court to declare him the owner of 39,069 dormant Bitcoin wallets that he claims were abandoned under New York law.

Several media outlets have reported that the wallets hold roughly 3.7 million BTC. At current market prices, they are worth a staggering $285 billion. Yet the most important question before the court may have little to do with Bitcoin’s value. Instead, the case could depend on whether publicly visible blockchain addresses can be treated as found property under laws originally written for lost watches, briefcases, and jewelry.

The Lawsuit’s Unusual Theory

According to the complaint, Doe developed an algorithm that identified Bitcoin wallets that had been dormant for at least five years. He argues that prolonged inactivity through multiple major market cycles suggests the owners abandoned their wallets.

After identifying the inactive wallets, Doe says he recorded their addresses and delivered the information to the New York Police Department. He then spent more than a year attempting to notify potential owners. The complaint states that thousands of wallets were removed from the original list after owners took action or were otherwise identified. That left 39,069 allegedly unclaimed wallets.

The lawsuit seeks a declaratory judgment confirming that ownership of those wallets vested in Doe under New York’s lost-property statute and was later transferred to two affiliated companies.

Are Wallets Property?

A central part of the complaint is the argument that digital wallets should be treated as property.

Doe compares a wallet to a bank account. The public wallet address functions like an account number. The private key serves as the authorization needed to move funds. Under this theory, a wallet remains property even if the private key has been lost, much like a bank account remains an asset even if its owner cannot immediately access it.

Courts have increasingly recognized cryptocurrency as property in bankruptcy, divorce, and fraud cases. The argument that digital wallets represent a form of property is not necessarily the most controversial aspect of the lawsuit.

The harder question may be whether the wallets were ever “found” in the first place.

Discovery Versus Finding

Traditional lost-property cases involve physical objects. Someone finds a watch in a park, a briefcase on a sidewalk, or jewelry left behind in a public place.

The complaint argues that Doe found the wallets in New York City using his personal computer after developing a method to identify dormant addresses on public blockchains.

However, blockchain wallet addresses are already publicly visible. Anyone can view them, along with their balances and transaction histories. The addresses were not hidden, misplaced, or inaccessible. Doe discovered a pattern among existing public records.

The court may need to determine whether identifying dormant Bitcoin wallets through data analysis is legally equivalent to finding lost property.

Ownership Versus Control

Even if the court accepts the plaintiff’s theory, a practical problem remains.

The lawsuit seeks ownership of the wallets, but it does not claim possession of their private keys. In Bitcoin and other cryptocurrencies, only these private keys allow the owners to move funds. A court order can establish legal rights, but it cannot generate the cryptographic authorization needed to transfer assets from a self-custodial wallet.

That creates an unusual situation. A favorable ruling could give the plaintiffs a legal ownership claim. This would still leave them unable to access the cryptocurrency held in the wallets because a judgment would not unlock self-custodial assets. But it could establish a legal basis for future recovery efforts or strengthen ownership claims if the assets later move through regulated financial institutions. The practical value of the ruling would therefore depend on events beyond the judgment itself.

Abandonment Is Not Easy to Prove

Even if the court accepts that Doe found the wallets, another hurdle remains.

The complaint argues that inactivity for five years or longer is strong evidence of abandonment. According to Doe, cryptocurrency owners are generally aware of market volatility. If they still maintained control over their wallets, they would likely have taken some action during major price movements.

Many cryptocurrency holders intentionally leave assets untouched for years. Others may have lost access to their private keys, passed away, or transferred ownership through private arrangements. Events like inheritance agreements or off-chain sales would not appear in blockchain records. A dormant Bitcoin wallet is not necessarily an abandoned wallet.

So, the lawsuit may also have to answer whether silence on the blockchain equals evidence of intent to relinquish ownership.

Who Argues the Other Side?

Another unusual feature of the case is that it may proceed with little or no meaningful opposition.

The defendants are listed as John Does 1 through 39,069, representing the wallet addresses of the unknown owners. If no owner appears to contest the claims, the plaintiff could ask the court to evaluate the legal theory without an identifiable party arguing against it.

That does not mean the lawsuit would automatically succeed. A judge would still need to determine whether the complaint establishes a valid claim under New York law before granting a declaratory judgment. The absence of active defendants places greater responsibility on the court to scrutinize questions involving property, jurisdiction, abandonment, and digital asset ownership.

New York’s Attorney General oversees various categories of unclaimed property in the state. The office could potentially take an interest in a private party seeking title to assets of this scale. Whether any government entity intervenes remains unclear.

Why the Case Matters

The immediate focus is on the wallets listed in the complaint. The broader implications could be far more significant.

If a court accepts the idea that dormant blockchain addresses can become legally abandoned property, similar arguments could eventually emerge in disputes involving other digital assets. Lost cryptocurrency, inactive wallets, and unclaimed on-chain property could all become subjects of future litigation.

The lawsuit is often described as an attempt to claim billions of dollars in dormant cryptocurrency. The court may never reach that question. Before it can decide who owns the wallets, it may first need to determine whether publicly visible blockchain addresses can be “found” at all, and whether identifying them through analysis of public blockchain data is enough to trigger centuries-old lost-property laws.

Whatever the outcome, the case is testing how legal concepts developed for physical property apply to decentralized digital assets. That question is likely to outlast this lawsuit and could shape future disputes involving ownership, abandonment, and control of cryptocurrency.

Mastercard Secures New York BitLicense to Expand Digital Asset Infrastructure

TL;DR

  • Mastercard secured a New York BitLicense from the NYDFS through its subsidiary Mastercard Transaction Services (U.S.) LLC.
  • The approval supports Mastercard’s expansion into stablecoins, tokenized deposits, and blockchain-based payment infrastructure.
  • The move highlights growing institutional investment in regulated digital finance infrastructure.

Mastercard subsidiary Mastercard Transaction Services (U.S.) LLC secured a BitLicense from the New York State Department of Financial Services. The approval expands the company’s regulated digital asset operations.

The approval also allows the Mastercard subsidiary to operate regulated virtual currency activities in New York. The state remains one of the strictest crypto regulatory jurisdictions in the United States.

The BitLicense approval expands Mastercard’s push into stablecoins, tokenized deposits, and blockchain-based settlement systems. The company has largely focused on payment infrastructure for financial institutions rather than retail crypto trading platforms.

Focus Shifts Toward Stablecoin Infrastructure

Mastercard said the license will support services for digital payments and regulated blockchain infrastructure. The license drew attention because of Mastercard’s stablecoin settlement ambitions and tokenized financial products.

Stablecoins are digital assets designed to maintain a stable value. They are typically tied to fiat currencies such as the U.S. dollar.

Banks and payment firms have been testing stablecoins to improve cross-border transfers and settlement speed. They also hope to reduce payment costs compared to traditional banking rails.

Mastercard is also expanding into tokenized deposits. Tokenized deposits are digital versions of commercial bank deposits issued on blockchain networks. They could allow institutions to move money more efficiently across programmable payment systems.

Mastercard Expands Existing Crypto Strategy

Mastercard has spent years building partnerships across the crypto and fintech sectors.

The company previously worked with crypto exchanges, wallet providers, and fintech firms. The partnerships supported crypto-linked payment cards and blockchain payment initiatives.

The new regulatory approval strengthens Mastercard’s ability to operate directly within New York’s regulated digital asset framework.

The state’s BitLicense framework remains one of the toughest crypto regulatory systems in the country. The rules include compliance, capital, reporting, cybersecurity, consumer protection, and anti-money laundering/know-your-customer (AML/KYC) requirements.

A BitLicense can also improve credibility with banks, fintech firms, and enterprise clients seeking regulated blockchain infrastructure providers.

The New York BitLicense may also improve Mastercard’s ability to support enterprise clients experimenting with stablecoin settlement or tokenized financial applications.

Traditional Finance Moves Deeper Into Blockchain Payments

Banks, payment firms, and fintech companies are investing more heavily in blockchain payment infrastructure. The focus is shifting away from speculative crypto trading activity.

Financial firms see stablecoins as a way to speed up settlements and reduce cross-border payment costs.

Regulators in several jurisdictions are also moving toward clearer frameworks for stablecoin oversight. That is encouraging larger financial firms to expand participation.

Rivalry in the digital payments sector is increasing as more firms invest in blockchain and stablecoin infrastructure. Payment companies want an early foothold in infrastructure that could support future blockchain payment networks.

Mastercard has repeatedly emphasized interoperability between traditional finance and blockchain systems. The company has focused heavily on regulated financial infrastructure instead of decentralized or unregulated crypto services.

Regulatory Positioning Remains Important

New York still holds significant regulatory influence across the digital asset industry. While some crypto companies previously criticized the BitLicense framework as restrictive, institutional firms often view the approval process as a sign of regulatory credibility.

Mastercard’s license arrives as stablecoins move deeper into mainstream financial infrastructure. Several governments and regulators globally are evaluating how blockchain-based payments may fit within existing financial infrastructure.

Mainstream adoption of stablecoin settlement infrastructure is still in its early stages. But the approval shows that major payment firms are building infrastructure for broader blockchain payment use.

CertiK Wants to Secure the Expanding AI Skill Ecosystem

TL;DR

  • CertiK launched Skill Scanner as a security layer for AI Skills following a wave of malicious tools spreading through public AI marketplaces.
  • The platform focuses on execution-stage threats, including data exfiltration, shell execution, and unauthorized network activity.
  • As AI agents gain access to wallets, APIs, and enterprise systems, security risks around third-party skills are becoming harder to ignore.

When attackers began uploading malicious skills to ClawHub in late January, the AI agent ecosystem received its first large-scale security wake-up call.

By mid-February, more than 1,180 poisoned skills had spread through OpenClaw’s public marketplace. The compromised listings accounted for roughly 12% of the entire registry. Skills with professional documentation and harmless-looking names such as “solana-wallet-tracker” were installing keyloggers on Windows machines and Atomic Stealer malware on macOS.

The underlying problem was simple. Anyone with a GitHub account older than one week could publish to ClawHub. There was no code review, no signing requirement, and no malware scanning.

Since February, the attack surface around AI agents and MCP infrastructure has widened considerably. A trojanized version of a legitimate MCP server, disguised as a Postmark integration, contained a single line of code that blind-copied outgoing emails to attackers. Internal memos, password resets, and invoices were quietly forwarded without user awareness.

Meanwhile, Microsoft patched a critical MCP server vulnerability in March through its Patch Tuesday release. The flaw, tracked as CVE-2026-26118, carried a CVSS severity score of 8.8. Separate analysis of more than 7,000 MCP servers found that over one-third were vulnerable to server-side request forgery attacks.

Traditional malware tools have also struggled to detect many of these threats. VirusTotal, which remains one of the industry’s most widely used malware scanning platforms, was not developed for agent-based execution environments.

Earlier software ecosystems went through the same cycle. Mobile app stores saw it. npm repositories saw it too. Adoption moved faster than security controls, and attackers moved in before platforms were ready.

CertiK now wants to become part of that infrastructure.

What CertiK Just Launched

CertiK launched Skill Scanner today, describing it as a purpose-built security layer for third-party AI Skills that evaluates risks before they reach user systems, wallets, or sensitive data.

The scanner evaluates five categories tied directly to emerging AI agent threats:

Users can submit a GitHub repository, URL, or ZIP file. The platform then returns a security score between 0 and 100 alongside pass, warn, or fail verdicts and a ranked list of findings.

According to CertiK, the system achieves up to 90.5% precision in identifying security risks.

One notable detail is the scanner’s focus on execution-stage behavior instead of relying only on static code analysis.

Several malicious AI skills appeared harmless during initial inspection and only activated dangerous behavior after installation or runtime execution. The Postmark MCP supply-chain attack is one example. The ClawHub malware campaign followed a similar pattern.

Static analysis alone probably would not have caught attacks like these.

CertiK said the scanner is designed for three primary groups:

  • AI skill marketplaces that want to screen submissions before publication
  • enterprises reviewing third-party tools before deployment
  • independent developers performing self-audits before releasing skills publicly

Consumer-facing access remains on the roadmap.

The company also said the scanner supports both Web2 and Web3 environments.

That makes sense given how AI agents are increasingly interacting with wallets, APIs, internal systems, and sensitive user data regardless of whether blockchain infrastructure is involved.

Why CertiK Is Expanding Into AI Security

CertiK’s expansion into AI security builds on its background in smart contract auditing and Web3 infrastructure protection. It now applies these lessons to AI Agents.

Smart contracts execute autonomously, mistakes can become irreversible, and users often have limited visibility into underlying code behavior. AI agents increasingly operate under similar conditions. They often gain access to financial tools, file systems, email accounts, or production infrastructure.

The Skill Scanner launch follows CertiK’s earlier release of AI Auditor in April. That system identifies vulnerabilities in blockchain code during development and before deployment.

According to CertiK, AI Auditor achieved an 88.6% cumulative hit rate across 35 real-world Web3 security incidents from 2026. The company also reported relatively low false-positive rates.

The Skill Scanner launches roughly three months after the ClawHub compromise exposed weaknesses in public AI skill marketplaces. Platforms added retroactive scanning and VirusTotal integrations afterward, though the underlying publishing model largely stayed the same. Unverified skills could still enter public marketplaces.

CertiK is effectively betting that AI agents are entering the same stage previously seen with app stores, browser extensions, and open-source package registries.

What Happens Next

AI agents are gradually receiving deeper access to financial systems, production environments, internal files, wallets, APIs, and enterprise infrastructure. At the same time, security controls governing third-party AI skills remain fragmented across much of the ecosystem.

The OWASP Agentic Skills Top 10, published earlier this year, formalized many of the risks researchers had already been tracking since January.

CertiK Skill Scanner does not fully solve the governance problem surrounding AI skills. Industry standards around code signing, behavioral sandboxing, marketplace review pipelines, and mandatory verification processes are still developing.

Even so, execution-focused scanning could become a baseline security requirement as AI agents gain broader autonomy.

The AI skill ecosystem is starting to face the same trust problems that shaped earlier software distribution platforms. Since many AI agents already have direct access to sensitive systems, financial infrastructure, and autonomous workflows, the stakes are considerably higher.

Readers’ frequently asked questions

What is Skill Scanner?

Skill Scanner is a security platform developed by CertiK to analyze AI Skills for malicious or risky behavior before they are deployed inside AI agent ecosystems. The system focuses on execution-stage threats such as data exfiltration, unauthorized shell commands, and suspicious network activity.

Why do AI Skills create security risks?

AI Skills can interact directly with wallets, APIs, enterprise systems, and sensitive data environments. If a malicious or compromised Skill gains access to these systems, it may execute harmful actions autonomously without immediate human oversight.

How is Skill Scanner different from traditional security scanning?

Traditional scanning tools often focus on static code analysis before deployment. Skill Scanner focuses more heavily on runtime and execution-stage behavior, helping detect threats that may only appear once an AI Skill is actively operating inside an agent environment.

What Is In It For You? Action items you might want to consider

Review third-party AI Skills before deployment

If your company is experimenting with AI agents or MCP integrations, review how third-party Skills are vetted before they gain access to internal systems, APIs, wallets, or sensitive workflows.

Monitor the security models of AI marketplaces

Public AI skill marketplaces are still developing their security standards. Pay attention to whether platforms use code signing, behavioral analysis, or verification systems before installing external Skills.

Treat AI agent security as an infrastructure issue

AI agents are increasingly connected to financial systems, enterprise tools, and autonomous workflows. That shifts AI security away from experimental tooling and closer to core infrastructure risk management.

- Advertisement -

FEATURED