Back to Home

Stablecoins are critical financial infrastructure: CertiK Skynet report

CertiK Skynet report calls stablecoins critically important financial infrastructure. Losses from hacks in six months exceeded $328 million, and the Russian stablecoin A7A5 occupied 43% of the non-dollar asset market, creating new risks for banks and regulators.

CertiK: stablecoins have become critical infrastructure, threatening banks
Advertisement 728x90

CertiK's Skynet Report Calls Stablecoins Critical Financial Infrastructure

At the Proof of Talk conference, CertiK presented its latest Skynet report, defining stablecoins as critical and growing financial infrastructure in global markets requiring heightened security attention.


Headline: CertiK called stablecoins critical infrastructure. Why this should scare bankers more than hackers

Author: Independent financial analyst, digital asset cybersecurity specialist

Google AdInline article slot

Date: 2026-06-12


[The Gist]: What's really happening

When the world's largest Web3 auditor, CertiK, at the prestigious Proof of Talk conference at the Louvre, calls stablecoins "critical financial infrastructure," most readers see it as mere confirmation of the obvious. But they miss the point: this statement is not just a fact. It is a direct warning to regulators, banks, and corporations that old methods of security and compliance no longer work.

The Skynet 2026 Stablecoin Threat Intelligence Report, published by CertiK, contains two shocking figures that should have dominated news feeds but somehow remained on the periphery.

Google AdInline article slot

First: in just the first half of 2026, hacks and attacks on cross-chain bridges and wallets led to losses of over $328 million. The key word here is "wallets." For the first time in crypto history, attacks on private key vulnerabilities and access management systems have surpassed traditional smart contract hacks in damage volume. This means the problem has shifted from "bugs in code" to "human factors and operational security."

The second, much more alarming figure is $110 billion (by some estimates, over $110 billion) that passed through the Russian stablecoin A7A5, backed by rubles and used to circumvent international sanctions. This asset was launched by the group Old Vector LLC (Kyrgyzstan), controlled by sanctioned oligarch Ilan Shor and the Russian state bank Promsvyazbank (PSB). A7A5 already holds 43% of the global non-dollar stablecoin market.

Insider info that is being hushed up: The world's largest banks, including those that signed up for tokenization with Franklin Templeton and JPMorgan, are absolutely unprepared to deal with A7A5. Their compliance systems are set up to check names (Sanctions List), but not to analyze on-chain flows of stablecoins that are technically indistinguishable from legitimate USDC or USDT unless you dig at the graph database level. CertiK effectively stated: if you cannot analyze stablecoin addresses for links to A7A5, you could become an accomplice in capital flight from sanctions. And this is not a technical problem. It is a reputational bomb for any bank operating in global markets.

Google AdInline article slot

Timeline and Context

To understand why CertiK's report sounded so harsh and came now, we need to look at the timeline of events in 2025-2026. This is a story of how stablecoins turned from "trader coins" into geopolitical weapons.

Date Event Significance for Stablecoin Market
January 2025 Launch of A7A5 (Russian ruble stablecoin) Emergence of the first "state-affiliated" stablecoin outside US/EU control
March 2025 Closure of Garantex exchange by US authorities A7A5 instantly fills the liquidity vacuum, becoming the main settlement channel
October 2025 Central Bank of Russia recognizes A7A5 as a "digital financial asset" Legalization within Russia, creation of a parallel financial system
November 2025 19th EU sanctions package: A7A5 is the first crypto asset under direct transaction ban Failure: no addresses in sanctions lists, the asset continues to thrive
April 2026 Kelp DAO hack for $291 million (via wallet compromise) Largest incident of the year, proving the weak link is people and keys
June 4, 2026 Publication of CertiK Skynet report "Moment of truth": the industry gets a diagnosis
June 9-12, 2026 Report presentation at Proof of Talk in the Louvre Legitimization of problems at the highest institutional level

Table 1: Timeline of escalating threats to stablecoins (2025–2026)

Key context: a year ago, Moody's issued a report calling stablecoins "growing infrastructure." June 2026 showed that this infrastructure has already been hacked by geopolitical adversaries. A7A5 is a proof of concept of how to build a global settlement network completely ignoring SWIFT, the dollar, and US sanctions. This is no longer "Russian USDT." This is an alternative financial world, growing 43% faster than dollar stablecoins in non-aligned jurisdictions.


Who Wins and Who Loses

Traditional analysis says: "USDC and USDT win because they are legitimate." But reality is much more complex and cynical.

Winners:

  1. CertiK and other security auditors (Hacken, Trail of Bits): Their services move from "optional insurance" to "mandatory licensing requirement." When a stablecoin is recognized as critical infrastructure, its code must be certified by the world's best specialists. Companies that can conduct "Grey Box Chain Audits" — testing the network under real load with error injection — will become golden. I expect CertiK's revenue to double in 2026.

  2. Regulated stablecoins from TradFi (USDC, EURC from Circle, and tokenized deposits like JPM Coin): The CertiK report is an ideal argument for Circle's lobbyists in Washington: "Ban A7A5 and tighten reserve requirements because unregulated stablecoins are a national security hole." Circle and Paxos will see accelerated adoption of the GENIUS legislation (licensing stablecoin issuers in the US) as regulators are scared.

  3. Chainlink (LINK) and on-chain data providers: To detect A7A5 and similar schemes, banks need oracles and graph databases that track fund flows. Chainlink (via its services) and TRM Labs (a partner mentioned in the report) become not just "useful software" but a mandatory compliance element, like KYC in the 2000s.

Losers:

  1. Tether (USDT) and unregulated stablecoins without strict issuer oversight: USDT is not subject to strict US rules (issuer is in the British Virgin Islands), and its reserves are not always transparent. If the US starts mass demands to ban A7A5, "gray" stablecoins could be next in line. Tether could become collateral damage in the war on sanctions, causing capital flight to USDC.

  2. Financial intermediaries in Africa and the Middle East: CertiK directly pointed out that A7A5 is actively expanding in Nigeria, Zimbabwe, and Madagascar. Local banks that process transactions with this stablecoin (even unknowingly) risk secondary US/EU sanctions. Their correspondent dollar accounts could be blocked. The risk of de-dollarization through a back door becomes real.

  3. Low-security DeFi protocols (many cross-chain bridges): A loss of $328 million in half a year is a monstrous sum that makes bridge insurance economically unviable. Institutional capital that just started entering DeFi through tokenized funds will see these numbers and say, "No thanks, we'll stay in BlackRock's BUIDL on a private blockchain." Bridges like Wormhole or Stargate will lose institutional clients.


What the Media Isn't Saying

News is full of headlines: "CertiK sounds alarm on stablecoins." But there are three things CertiK didn't say directly, or that editors omitted.

Insider #1: A7A5 is the first stablecoin that technically cannot be fully blocked. Note the detail: OFAC (US Treasury) did not add A7A5 smart contracts to its SDN list. Why? Because if the US officially recognizes an A7A5 address as sanctioned, any USDC wallet that interacted with it via a decentralized exchange (DEX) automatically becomes "tainted." This would cause a collapse in DeFi. The US is paralyzed by fear of collateral damage.

Insider #2: The Kelp DAO hack for $291 million occurred via a compromised transaction signing key, not a code bug. This is perfect proof of CertiK's thesis: the stablecoin problem today is operational security (OpSec). If the keys to a stablecoin treasury are on a server connected to the internet or with an employee who fell for phishing, any code audits are useless. Attacks are shifting to social engineering and IT infrastructure. This threatens not only startups but also large exchanges holding stablecoins on hot wallets.

Insider #3 (most alarming): The growth of A7A5 shows that the "crypto iron curtain" is already built. No need to wait for 2030. Russia, through this stablecoin, already has the ability to trade with Africa, the Middle East, and Asia without the dollar. If oil starts being sold for A7A5 and then exchanged for yuan or rupees, the dollar will lose part of its reserve currency status. American bankers who laughed at crypto in 2021 must now realize: the battle for dollar hegemony is no longer in Fed boardrooms, but in smart contracts and blockchain explorers. And they are currently losing it.


Forecast: Next 30 Days and 90 Days

Next 30 days (July 12, 2026):

I expect emergency decision-making at the US Treasury level (FinCEN and OFAC). They cannot ignore the CertiK report for long. Within the next 2-3 weeks, an emergency advisory will be issued, requiring all US financial institutions to check USDC and USDT transactions for hidden links to A7A5. This will drive demand for analytical tools (TRM Labs tokens are not publicly traded yet, but Chainlink and other security services will rise in value). DEX trading volumes may temporarily drop by 15-20% as users fear wallet "contamination."

Next 90 days (September 2026):

There will be a structural split of the stablecoin market into two camps. The first camp — "White" (USDC, EURC, JPM tokenized deposits). They will be actively used by institutions and regulated exchanges. The second camp — "Gray" (USDT, DAI, FRAX, and especially A7A5). They will go into the shadows, onto unregulated platforms and geopolitical "gray zones." The price difference between USDC on a regulated exchange and USDT on an unregulated one could reach 2-3%, creating constant arbitrage.

Key date — September 2026, when a full-scale investigation of A7A5 assets in Africa is expected to begin. If it turns out that A7A5 is used to purchase military equipment or raw materials, sanctions pressure on local banks will be immediate. Consequences for the crypto market: liquidity outflow from non-dollar stablecoins into bitcoin and gold as "neutral safe-haven assets."

Stablecoin / Infrastructure Sanction/Hack Risk Institutional Demand (next 3 months) Key Driver
USDC (Circle) Low (under US oversight) Sharp increase Flight from A7A5 and GENIUS adoption
USDT (Tether) Medium (risk of "contamination" via secondary market) Decrease (move to shadows) Pressure from USDC + gray zones
A7A5 (Russia) High (under EU sanctions, not US) Growth in Asia/Africa Creation of alternative SWIFT
Chainlink / TRM Low (Infrastructure) Exponential growth Mandatory compliance for banks

Table 2: Forecast for the stablecoin and security infrastructure sector


Editorial Forecast

Asset: Circle (its equity in private deals, as well as the USDC token on secondary markets via indirect investments) — trust increase. Directly on the spot crypto market — the USDC/USDT pair may show a divergence.

Key levels: USDC will trade at a premium of 0.1-0.3% to USDT on major exchanges, as traders flee potentially "tainted" USDT for "clean" USDC. We fix levels: USDC = $1.001, USDT = $0.998.

Confidence level: medium (60%), as the market may decide that "sanction risks for USDT are exaggerated" and the arbitrage will close quickly.

Main risk: A sudden announcement by Tether itself about freezing addresses linked to A7A5 (if they do this, the USDC premium will collapse). But so far, Tether has not publicly shown readiness for such strict filtering.

Editorial opinion is not investment advice.

— Editorial Team

Advertisement 728x90

Read Next

Partner News