h hoge.gg
Subscribe
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
● Security & Exploits

CertiK’s CBDC Bet: Auditing Kyrgyzstan’s Digital Som

CertiK just signed on to help secure Kyrgyzstan's Digital Som, a national CBDC. We unpack what a crypto auditor can, and cannot, promise a central bank.

On 15 September 2026, the National Bank of the Kyrgyz Republic (NBKR) and CertiK signed a memorandum of understanding to help secure the Digital Som, the central bank’s planned digital currency. For CertiK, a New York firm best known for stamping smart contracts with a security score, it is a landmark: a private, crypto-native auditor invited into the machinery of a sovereign monetary system. For anyone watching crypto’s security industry grow up, it is a test of a much larger question. Can you audit a nation’s money, and does an audit secure the risks that actually drain it?

The honest answer, on the evidence of 2026, is uncomfortable. CertiK publishes the industry’s most-cited loss data, and that data shows the money is no longer leaking out of the place auditors look hardest. Code bugs were the cheapest and most common category of loss in the first half of the year; stolen keys and compromised operations did the real damage. A central bank digital currency (CBDC) inherits exactly that risk shape, only with legal tender and a treasury attached. Layer on CertiK’s own scandal-marked record and Kyrgyzstan’s sanctions-tinged crypto reputation, and the Digital Som deal becomes a useful lens on what the word “audited” is worth right now.

The Deal on Paper

The memorandum is short on legal weight and long on intent. According to the joint announcement, the NBKR and CertiK will cooperate on blockchain and digital-asset security, security assessments, formal verification, cybersecurity and operational resilience, plus AML/CFT compliance, digital-asset custody, security standards and licensing, and the deployment of CertiK’s Supervision and Compliance tooling for real-time risk monitoring. There is a training-and-knowledge-transfer clause too, the kind of language that signals a central bank buying a capability it does not have in house.

Ronghui Gu, CertiK’s co-founder and chief executive, framed the deal around the whole software lifecycle: “Digital asset infrastructure requires security and risk management to be considered from the earliest stages of design through ongoing operation.” Sanzhar Abdygaziev, a member of the NBKR’s management board, said the bank sees “particular value in exchanging experience and expertise in blockchain and digital asset security, cybersecurity, AML/CFT, and the analysis and monitoring of digital asset transactions.” Jason Jiang, CertiK’s chief business officer, signed for the firm.

Two caveats matter before anyone reads this as a done deal. First, as Crowdfund Insider noted, the memorandum does not itself launch the Digital Som or impose new laws; it opens a structured channel for assessment and possible tooling as the bank moves from design toward deployment, and it is “designed as an enduring partnership rather than a one-off audit.” Second, an MOU is a statement of direction, not a contract. What CertiK has actually won is a foot in a door most of its rivals have not found, plus a reference client none of them can match: a sovereign central bank.

Who CertiK Is

CertiK is not a typical bug shop, and that is the point of the story. It grew out of academic formal-methods research: co-founders Ronghui Gu, now a professor at Columbia, and Zhong Shao, chair of computer science at Yale, built CertiKOS, the first fully formally verified concurrent operating-system kernel, before turning the same prove-the-code-cannot-misbehave discipline on blockchains. The name is a contraction of “Certified Kernel.” That pedigree is precisely why a central bank might take the call: formal verification, done properly, is the closest thing software security has to a mathematical guarantee, and it is exactly what you want beneath code that must not fail.

Commercially, CertiK is one of the largest names in the field. By its own reckoning the firm has served more than 5,000 clients, and its reviews cover code securing hundreds of billions of dollars in value. Its product line runs well past one-off audits: a Smart Contract Audit that blends manual review, formal-verification engines and, increasingly, machine learning; Skynet, a continuous on-chain monitoring layer that assigns each project a running Skynet Score; SkyInsights for KYC and AML transaction monitoring; penetration testing; and a bug-bounty platform. It is the Skynet and SkyInsights side, the monitoring and compliance tooling, not the point-in-time audit, that the NBKR deal leans on hardest.

The money behind it is heavyweight. CertiK has raised more than $240 million and carries a valuation reported at around $2 billion, according to CoinDesk. Its first and largest backer was Binance, joined over successive rounds by Coinbase, SoftBank, Insight Partners, Tiger Global and Advent International. Gu has said the firm holds more cash than it has raised, a rare profitability signal in crypto infrastructure, and one that feeds an ambition we will return to: a public listing.

CertiK at a glanceDetail
Founded / base2018, New York City
FoundersRonghui Gu (Columbia) and Zhong Shao (Yale)
Academic originCertiKOS, first fully formally verified concurrent OS kernel
Funding / valuationMore than $240M raised; valued near $2B
Lead backersBinance (first and largest), Coinbase, SoftBank, Insight, Tiger Global, Advent
Core productsSmart Contract Audit, Skynet monitoring, SkyInsights (AML), pen testing, bug bounty
Scale (self-reported)5,000+ clients; code securing hundreds of billions in value

What the Digital Som Actually Is

The Digital Som is Kyrgyzstan’s central bank digital currency, a state-issued digital form of the national currency rather than a private token or a stablecoin. The central bank frames it as a way to modernize payments, widen financial inclusion and harden the resilience of the national payment system, the standard CBDC pitch heard from Beijing to Brussels. Kyrgyzstan already treats the Digital Som as legal tender, and it has set itself an aggressive timetable: finish initial platform testing by the end of 2026, run live trials in 2027, and only then weigh a national rollout, again per Crowdfund Insider.

The design is a two-tier, phased build, and the phasing is where the security story lives. A first phase runs interbank settlement through commercial banks; a second targets the Central Treasury for government and social payments; a third tackles offline and low-connectivity use before any nationwide launch. Each phase widens the attack surface and changes its character, a point worth holding onto for the section on where a CBDC actually bleeds.

Kyrgyzstan is a small country making outsized crypto moves, which is part of why this deal drew notice. In October 2025 it launched KGST, a national stablecoin pegged one-to-one to the som on BNB Chain, and Changpeng Zhao, Binance’s founder, has advised the country’s broader digital-asset agenda, as reported at the time. The Digital Som is the sovereign-money end of the same strategy, and hiring a crypto-native auditor to help secure it fits the playbook: move fast, borrow expertise from the industry, and manage the optics later.

That speed is what makes the project notable. Most of the world’s central banks are studying digital currencies, but the overwhelming majority remain parked in research and small pilots, wary of the operational, privacy and financial-stability questions a live CBDC raises. A lower-income country pushing toward production, and outsourcing a chunk of the hard security work to a private crypto firm rather than building it inside a national cyber agency, is a different model from the cautious, in-house approach favored by larger economies. It is faster and cheaper, and by definition more dependent on the vendor it hires.

The Audit Paradox

Here is the problem at the center of this deal, and of CertiK’s whole business in 2026. The firm’s own Hack3d report for the first half of the year counted more than $1.31 billion lost across 344 incidents, and the breakdown is the real headline. Wallet and private-key compromise was the costliest category by value, roughly $445 million across 33 incidents, per figures carried by Forbes. Phishing came second at about $366 million across 63. Code vulnerabilities, the thing a smart-contract audit is built to catch, were the most frequent category at 204 incidents but the cheapest, at around $152 million.

The two biggest events of the half make the case even more bluntly. Kelp DAO, near $291 million in April, and Drift Protocol, around $285 million on 1 April, together accounted for close to 44% of all H1 losses, and neither was a contract bug in the traditional sense; both were operational and infrastructure compromises, stolen access rather than broken logic. Gu said it directly in Forbes: “What stood out most was the shape of the losses,” and “attackers are getting more return by going after key management, multisig governance, and operational infrastructure than by hunting for bugs in code.” Or, in the line that should hang over the NBKR deal: “A protocol can pass a flawless code audit and still lose millions because of a compromised admin key.”

H1 2026 losses by vector (CertiK Hack3d)AmountIncidentsCharacter
Wallet / private-key compromise~$445M33Costliest per event; outside a code audit’s scope
Phishing~$366M63Social engineering; no contract bug involved
Code vulnerability~$152M204Most common, cheapest; the one vector an audit targets
Kelp DAO + Drift (context)~$576M combined2~44% of all H1 losses; both operational, not code bugs

That is the audit paradox in one table. The audit is the most visible, most heavily marketed part of crypto security, and it addresses the smallest and cheapest slice of the actual loss surface. Nothing about hiring CertiK to review the Digital Som’s code is wrong. It is just that the code is not where a modern attacker expects to win, and pretending otherwise is how a central bank talks itself into a false sense of security.

A Central Bank’s Real Attack Surface

Apply that lesson to a CBDC and the risk map redraws itself. The Digital Som’s most dangerous exposure is not a reentrancy bug in a smart contract; it is the set of keys that authorize issuance, the signing infrastructure at the central bank and every commercial bank plugged into it, and the humans with privileged access. A stolen issuance key is a Kelp-scale disaster with a national balance sheet behind it. This is the same class of risk that has pushed the entire industry toward hardware-backed and smart-account key management, the subject of our field guide to smart accounts, and it sits squarely outside what a one-time code review examines.

The phased rollout adds specific hazards. The Treasury phase, routing government and social payments, is a high-value, high-visibility target in a region where nation-state adversaries are a live concern rather than a theoretical one. The offline phase raises the oldest hard problem in digital cash: how do you stop double-spending when a device cannot check a live ledger? That is a question of secure-element design, cryptographic protocol and tamper resistance, not Solidity review. And the two-tier model means the central bank’s security is only ever as strong as the weakest integration at the weakest commercial bank, none of which CertiK is contracted to audit.

Rollout phaseFunctionPrimary exploit exposureIn a code audit’s scope?
Phase 1: interbankCommercial banks settle transfersSigning infrastructure, key custody, integration seamsPartly (protocol yes; banks’ infra no)
Phase 2: TreasuryGovernment and social paymentsHigh-value target, insider access, admin-key compromiseNo for keys and insiders
Phase 3: offlinePayments without connectivityDouble-spend, secure-element cloning, hardware tamperingRarely; hardware and protocol design

There is also the automation frontier to reckon with. Modern payment rails increasingly delegate decisions to software agents, and Gu himself has warned that an AI agent with wallet access is “essentially a new kind of privileged key holder.” As central-bank plumbing acquires automated components, the failure modes we track in pieces like our look at AI agents running DeFi stop being a niche curiosity and start being sovereign-infrastructure risk. A code audit does not touch a single one of these surfaces, which is why the monitoring and compliance half of this deal matters more than the review half.

The human layer deserves its own line. Some of 2026’s most expensive compromises began not with a flaw in code but with a person: a social-engineered employee, a malicious insider, or, as investigators have repeatedly documented, operatives who talk their way onto payrolls to reach privileged systems from the inside. A central bank and its network of commercial banks are exactly the kind of high-value, multi-vendor target where one compromised administrator or one planted contractor can undo months of formal verification. No smart-contract review, however rigorous, inspects the background checks at a partner bank or the phishing resistance of a treasury operator.

The Year Audited Code Kept Losing Money

If you want proof that “audited” and “safe” are different words, 2026 supplied it on a schedule. The year’s signature exploit was not a novel zero-day but an old trick industrialized: manipulate the price an on-chain lending market reads, borrow against the inflated collateral, and walk away. TRM Labs counted a record 32 price-manipulation exploits in 2026, up from 12 in all of 2025, which works out to roughly one in eight of all hacks. Moonwell on Base lost about $8.7 million on 27 August; Tectonic on Cronos lost roughly $75 million on 30 August, severe enough that validators halted and rolled back the chain; and Nostra on Starknet was drained of about $3.5 million on 17 September, two days before the CertiK-NBKR announcement.

Several of these protocols had been through audits. The common thread was not a bug in reviewed code but a design that trusted a thin-market spot price, often the protocol’s own governance token, as collateral. Flash loans, the one-block, uncollateralized borrowing we unpacked in our flash-loan explainer, are the amplifier, not the flaw. Suhail Kakar, developer-relations lead at TAC, summed up the industry’s hard lesson after a separate nine-figure exploit: “audited by X means almost nothing. Code is hard, DeFi is harder.”

A CBDC will not have a governance token to pump, so the direct read-across is limited. But the deeper pattern travels. As state money starts touching tokenized-asset and programmable-payment rails, it inherits the same composability risk and the same gap between a clean audit and a safe system, the gap that took down the Liquid Network’s $320 million bridge despite serious engineering behind it. Every one of these incidents is a reminder that the certificate on the wall describes a moment in a codebase’s life, not the security of the running system three months later.

CertiK’s Own Ledger of Scandals

Trusting a firm with a nation’s money invites a fair question: how has that firm behaved with everyone else’s? CertiK’s record is not spotless. In June 2024 its researchers exploited a deposit-crediting bug at Kraken and withdrew roughly $3 million of real customer funds, then, the exchange alleged, hesitated to return them without first discussing a reward. Kraken’s chief security officer, Nick Percoco, was blunt in CoinDesk: “This is not white-hat hacking, it is extortion.” CertiK countered that it was doing legitimate research and that Kraken had threatened its staff; the funds were eventually returned, some routed through Tornado Cash along the way, which did nothing for the optics.

The heavier case is Huione. CertiK completed an audit of USDH, a stablecoin linked to the Cambodian marketplace Huione Guarantee, in December 2024. Blockchain analysts later described Huione as the largest illicit online marketplace ever measured, with tens of billions of dollars in flows and tooling for pig-butchering scams and forced-labor compounds; in May 2025 the US Treasury’s FinCEN designated it a “financial institution of primary money laundering concern”, the enforcement mechanism we break down in our piece on Huione and Section 311. CertiK apologized: “We sincerely apologise to the community… CertiK does not support or condone any of the activities undertaken by Huione.” In mitigation, the engagement reached the firm through a third party that passed KYC, and when its concerns went unaddressed CertiK listed the token at the lowest Skynet score with a warning and donated the fee to charity, per DL News. Real nuance. A good look, no.

Then there is the recurring genre of the audited-yet-hacked project. Swaprum, a CertiK-audited DEX on Arbitrum, pulled a roughly $3 million rug in 2023 after its deployer swapped the audited contract for a malicious one, prompting CertiK’s now-standard line that, as an auditor, it “cannot force projects to implement our recommendations.” That defense is fair, and it is also the whole point: the badge certifies a snapshot of a codebase, not the behavior of the people who control it. A central bank contemplating a legal-tender currency should read every one of these episodes as a spec sheet for what the vendor is and is not promising.

Kyrgyzstan’s Crypto Shadow

The counterparty carries its own baggage, and it is impossible to write about this deal honestly without naming it. In a widely cited 2025 analysis, TRM Labs called Kyrgyzstan “Moscow’s crypto backdoor”, describing how the country’s light-touch, fast-growing exchange sector has been used to move value around Western sanctions. The clearest thread runs through A7A5, a ruble-linked stablecoin issued by the Kyrgyz firm Old Vector, which analysts tied to the flow of funds between the sanctioned Russian exchange Garantex and its successor, Grinex. On 14 August 2025 the US Treasury’s OFAC sanctioned Grinex and Old Vector alongside Garantex figures; Grinex later suspended operations after a roughly $13 million hack in April 2026, per Chainalysis and CoinDesk.

The crucial distinction, and one worth stating clearly to avoid smearing a legitimate public institution, is that these sanctions target private actors, not the National Bank or the Digital Som. A central bank building a CBDC is not Garantex, and nothing in the TRM reporting alleges otherwise. But the environment sharpens the stakes. Ari Redbord, TRM Labs’ global head of policy, has warned that “gaps in compliance don’t just pose a reputational risk, they can become national-level economic vulnerabilities.” That is precisely the gap the NBKR is hiring CertiK’s SkyInsights and Supervision tooling to close, and precisely why this deal is more than a technical footnote. If the Digital Som is to be trusted across borders, the AML/CFT and monitoring half of the partnership may end up mattering more than any code review.

Fighting AI With AI

CertiK is selling the NBKR a 2026 product suite, not a 2021 one, and the newest pieces are machine-driven. In April 2026 the firm launched an AI Auditor it says reached an 88.6% cumulative exact-hit rate against 35 real-world incidents that year, pitched as a low-noise complement to human reviewers rather than a replacement. It followed with an AI Skill Scanner that scores third-party AI-agent “skills” before they are deployed, flagging hidden data access and, notably, fund-movement risk.

The logic tracks the threat. Gu’s framing of an AI agent as a new privileged key holder whose decisions can be steered through crafted inputs describes a real and growing surface, and a central bank layering automation onto payments will eventually meet it. Whether an 88.6% hit rate is reassuring or alarming depends on your standard: for a consumer app it is a strong baseline; for sovereign money the missing 11.4% is the whole ballgame. The genuine value of continuous, AI-assisted monitoring is that it narrows the danger window a point-in-time audit leaves wide open. It does not close it, and CertiK, to its credit, does not claim it does.

The IPO Backdrop

None of this is philanthropy. CertiK has made no secret of wanting to be the first publicly listed Web3 cybersecurity firm; at Davos in January 2026 Gu told The Block, “We still do not have a very concrete IPO plan. But this is definitely the goal we are pursuing.” A central-bank contract is close to the ideal pre-IPO credential. It says “institutions trust us” in a way no volume of DeFi audits can, and it advances the trust-rebuild narrative CoinDesk documented after the Huione episode. The firm’s roughly $2 billion valuation and unusual cash position only make the listing story more plausible.

It also sharpens a conflict worth naming out loud. The auditor is chosen and paid by the party being audited, here a central bank, which is the same issuer-pays structure that let credit-rating agencies stamp AAA on subprime mortgage bonds in the run-up to 2008. The difference is that rating agencies are registered and supervised; smart-contract auditors are not. A public listing would add securities-law liability and disclosure, a genuine improvement, but it would also stack share-price growth pressure on top of a model that already rewards volume and rewards saying yes. Anyone weighing a “secured by CertiK” label should keep both facts in view at once.

The United States Took the Opposite Bet

For an American reader, the most striking thing about the Digital Som may be that the United States has decided not to build anything like it. On 23 January 2025 an executive order, “Strengthening American Leadership in Digital Financial Technology,” barred federal agencies from establishing, issuing or promoting a central bank digital currency, citing financial-stability and privacy concerns, and instead directed the government to support dollar-backed stablecoins, as summarized by Reed Smith. Congress took the same fork: the GENIUS Act, signed on 18 July 2025, built the first federal framework for privately issued payment stablecoins rather than a public digital dollar, per Skadden.

So Kyrgyzstan and the United States have placed opposite bets on the shape of digital money: a state-run CBDC on one side, privately issued stablecoins on the other. Neither escapes the security question this article is really about. A GENIUS-Act stablecoin still needs its smart contracts and reserve attestations secured; a CBDC still needs its keys, ledgers and integrations secured. And on the auditor question, US law is silent in a telling way. No American regulator, not the SEC, the OCC nor the Federal Reserve, accredits or licenses smart-contract auditors. “Audited by CertiK” carries no more official standing in Washington than in Bishkek. It is a private opinion, sold by a private firm, about one slice of the risk.

What an Audit Can and Cannot Promise a Central Bank

It would be unfair to caricature what CertiK brings to the table. Formal verification, its academic core, is arguably the right tool for high-assurance sovereign code; if any part of a CBDC deserves a mathematical proof that it behaves as specified, it is the settlement logic. Continuous monitoring through Skynet can compress detection times from days to minutes. SkyInsights and the AML/CFT workstream address exactly the sanctions-and-laundering exposure that a Central Asian CBDC most needs to manage. Incident response and red-teaming are real capabilities the NBKR plainly lacks in house. This is a serious firm doing serious work, and the deal is not a stunt.

The limits are equally real, and CertiK’s own executives have named them. An audit is a photograph, not a live feed; Gu has said the danger window does not close after launch, which is at once an argument for the monitoring contract and an admission about the audit. The review does not cover the central bank’s key custody, its hardware security modules, its operational infrastructure, its staff, its governance, or the security of the commercial banks in the two-tier design. It cannot price the political risk of a validator set that could, as Cronos showed in August, decide to rewrite history after an exploit. The correct way to read this partnership is not “the Digital Som will be secure because CertiK audited it,” but “CertiK will secure the code layer, which is the smallest and best-understood part of the problem.”

Who Watches the Auditor?

That leaves the oldest question in assurance: who audits the auditor? There is no regulator anywhere that certifies a smart-contract firm as competent, independent or honest. The market’s only substitute is reputation, which is exactly why CertiK’s Kraken and Huione episodes are not gossip but material information. When the paying client is a sovereign, reputational discipline both intensifies and weakens at the same time. It intensifies because getting a CBDC wrong is a headline in every capital. It weakens because very few auditors will publicly fail a central bank that is also a marquee reference and a set piece for the IPO roadshow.

Accountability, for now, comes from three thin sources: the firm’s reputation, the eventual public post-mortem if something breaks, and, should CertiK list, the securities-law liability that arrives with disclosing to investors. None of those is a regulator, and none of them helps a citizen on the day an issuance key is stolen. For a currency that carries legal-tender status, that governance gap is worth watching at least as closely as the code, because it is the part of the arrangement with no independent check at all.

There are partial fixes the industry already knows how to build. Published audit reports with a clearly defined scope, on-chain proof that the deployed bytecode matches the reviewed commit, bug bounties that pay independent researchers to keep probing after launch, and monitoring dashboards a central bank’s own staff can read without taking the vendor’s word for it. None of these turns a private opinion into a public guarantee, but together they move a CBDC from trust-us assurance toward something a regulator, a legislature or a citizen could actually inspect. Whether the NBKR insists on that level of transparency, or settles for a logo and a quarterly report, will say more about the Digital Som’s security than the audit ever will.

What to Watch Next

Three markers will tell you whether this is substance or signaling. First, the end-of-2026 platform-testing milestone and the 2027 live trials: slippage there is normal for CBDC programs and would say more about Kyrgyzstan’s execution than about CertiK. Second, whether the monitoring actually catches something in public, a flagged anomaly, a frozen illicit flow, a disclosed near-miss, because a Supervision-and-Compliance deal that never surfaces a single catch is hard to distinguish from a logo on a slide. Third, whether CertiK parlays this into other central banks; the firm’s ambition and the CBDC pipeline across emerging markets both point that way.

The larger trend is the one to hold onto. Crypto-native security firms are moving off DeFi dashboards and into sovereign infrastructure, and the assurance model they bring, private, issuer-paid, unregulated and centered on a code review that catches the cheapest failures, is being asked to carry weight it was never designed for. The Digital Som will be a live test of whether “secured by CertiK” is a standard or a sticker. On the evidence of 2026, treat it as a starting point rather than a seal, and watch the keys, the operations and the post-mortems, because that is where the money actually goes.

Frequently Asked Questions

What did CertiK and Kyrgyzstan’s central bank actually agree to?

On 15 September 2026 the National Bank of the Kyrgyz Republic and CertiK signed a memorandum of understanding covering security assessments, formal verification, cybersecurity, AML/CFT compliance, digital-asset custody and licensing for the Digital Som. Crowdfund Insider reported it is designed as an enduring partnership rather than a one-off audit, and the memorandum itself does not launch the currency or change any law.

When will the Digital Som launch?

There is no firm launch date. Kyrgyzstan already treats the Digital Som as legal tender and aims to finish initial platform testing by the end of 2026, with live trials expected in 2027. A full national rollout would follow the pilot phases, so the earliest realistic public use is 2027 at the soonest.

Does a CertiK audit mean the Digital Som is safe?

No. An audit and continuous monitoring can catch flaws in the code, but CertiK’s own 2026 data shows most crypto losses now come from stolen keys, phishing and operational failures that sit outside a code review’s scope. An audit is a starting point for security, not a guarantee of it.

Why is CertiK’s move into Kyrgyzstan controversial?

Two reasons. CertiK’s record includes the 2024 Kraken dispute and its 2024 audit of a stablecoin tied to the Huione marketplace, later designated by US authorities as a major money-laundering concern. Separately, TRM Labs has called Kyrgyzstan a crypto backdoor for sanctions evasion, though those findings target private firms, not the central bank or the Digital Som itself.

Does the United States have a CBDC like the Digital Som?

No. A January 2025 executive order bars US federal agencies from issuing a central bank digital currency, and the GENIUS Act signed in July 2025 instead built a framework for privately issued dollar stablecoins. The United States and Kyrgyzstan have taken opposite bets on the future of digital money.

Anneke de Vries is HOGE Wire’s security desk editor.

Share 𝕏 Post Telegram