Catenaa, Saturday, August 29, 2026-Cryptocurrency exchange LBank has launched a security initiative with blockchain cybersecurity company CertiK, adding penetration testing and bug-bounty work to its defenses against increasingly sophisticated digital asset attacks.
The Singapore-based exchange announced the Crypto Resilience Initiative on Aug. 10.
Under the program, CertiK will conduct penetration testing on LBank systems, while the exchange will participate in CertiK’s bug-bounty program.
The initiative expands an existing relationship between the two companies rather than creating a new cybersecurity provider arrangement.
LBank said the program is designed to identify weaknesses before attackers can exploit them and to bring outside security specialists into its testing process.
Penetration testing involves security specialists attempting to find vulnerabilities by using techniques similar to those employed by attackers.
Unlike automated security scans, such testing can examine how multiple weaknesses interact and whether internal controls can be bypassed.
Bug-bounty programs take a different approach.
They allow independent security researchers to report vulnerabilities under established disclosure rules, often in exchange for financial rewards.
For cryptocurrency exchanges, both methods can complement internal monitoring because attackers frequently target weaknesses beyond a platform’s main trading software.
Those can include application programming interfaces, authentication systems, wallet infrastructure, administrative tools and third-party services.
LBank said CertiK’s role will include technical assessments aimed at strengthening the exchange’s existing security practices.
The initiative comes as crypto companies face attacks that increasingly combine several techniques.
Cross-chain bridges have repeatedly been targeted because they control assets moving between separate blockchain networks.
Smart contracts can also expose funds when programming errors allow transactions that developers did not intend.
More recently, cybersecurity companies have warned that artificial intelligence can help attackers automate reconnaissance, generate malicious code and identify potential weaknesses more quickly.
AI can also help defenders analyze abnormal behavior and detect suspicious activity.
LBank said its internal security framework already uses AI-assisted risk detection alongside behavioral analytics and continuous monitoring.
The exchange also listed cold-wallet custody and multisignature authorization among its existing safeguards.
Cold wallets generally keep private keys away from internet-connected systems, reducing exposure to remote attacks.
Multisignature systems require more than one authorization before certain transactions can be completed.
Neither system eliminates cybersecurity risk, but both can limit the damage caused by the compromise of a single credential or device.
LBank presented the CertiK collaboration as part of a broader shift toward shared cybersecurity responsibilities in digital assets.
That approach reflects the increasingly interconnected structure of crypto markets.
An exchange may secure its own systems but still depend on blockchain networks, wallet providers, bridges, smart contracts and other outside infrastructure.
A vulnerability in one component can expose users elsewhere in the system.
Recent crypto exploits have repeatedly demonstrated that security failures do not always begin at the point where assets are ultimately lost.
Attackers may first compromise software dependencies, administrator credentials or infrastructure used to validate transactions.
That makes external testing more relevant for exchanges handling assets across many blockchain networks.
CertiK was founded in 2017 and provides blockchain security audits, monitoring and other risk-management services.
The company said it has identified more than 119,000 vulnerabilities during its operations and has worked with projects representing more than $600 billion in digital assets.
Those figures come from CertiK and have not been independently verified by Catenaa.
The company operates under SOC 2 Type II and ISO 27001 standards, according to the announcement.
CertiK has increasingly expanded beyond smart-contract auditing into broader institutional cybersecurity services.
Its work now includes penetration testing, monitoring and risk-management systems intended to cover more of a client’s software development and operating environment.
That broader approach reflects the changing attack surface facing crypto companies.
An exchange may operate securely written smart contracts while remaining vulnerable through web applications, internal systems or operational procedures.
LBank was founded in 2015 and operates a centralized cryptocurrency exchange serving users across multiple markets.
The company said it has more than 25 million registered users in 160 countries and regions.
Those figures were supplied by LBank.
The exchange also promoted a record of operating without a security incident during its first 10 years.
Such claims are difficult to verify independently because exchanges differ in how they classify and disclose cybersecurity events.
For users, the more relevant test will be whether the new initiative leads to measurable improvements in vulnerability discovery and response.
Penetration testing and bug-bounty programs can identify weaknesses, but their effectiveness depends on how quickly findings are addressed.
Security programs also require repeated testing because software, infrastructure and attacker methods continue to change.
The security issue has become more pressing as cryptocurrency exchanges expand beyond basic spot trading.
Many now operate staking services, lending products, institutional custody, derivatives and tokenized asset platforms.
Each additional service can create new technical connections and operational dependencies.
The result is a larger attack surface.
LBank said it plans to continue working with CertiK as the Crypto Resilience Initiative develops.
The companies did not disclose the cost of the program, testing schedule or the value of rewards available through the bug-bounty effort.
Those details will help determine how extensive the program becomes.
For now, the initiative places LBank among exchanges increasingly treating outside security researchers and independent testing as permanent parts of their defenses rather than measures used only after an attack.
