CertiK Signs Digital Som (CBDC) Security MoU With Kyrgyz Central Bank on Sept. 9

CertiK and Kyrgyzstan's central bank NBKR signed a Sept. 9 MoU covering Digital Som CBDC security, AML/CFT oversight and digital asset supervision.

(07:07 PM UTC)
4 min read
AI SummaryAI
  • CertiK and NBKR signed a Digital Som security MoU in Bishkek on Sept. 9, 2026
  • NBKR board member Sanzhar Abdygaziev signed the memorandum for the Kyrgyz central bank
  • Web3 losses reached $3.35 billion in 2025, per CertiK's Hack3D reporting
  • First-half 2026 Web3 losses totaled $1.31 billion across 344 incidents
k7rq2fdm

Digital Som Security Pact

The National Bank of the Kyrgyz Republic (NBKR) and blockchain security firm CertiK signed a Memorandum of Understanding on Sept. 9, 2026, in Bishkek, creating a cooperation framework for the security of the Digital Som — the central bank's digital currency (CBDC) initiative — and for wider digital asset supervision. Sanzhar Abdygaziev, a member of the NBKR board, signed the document for the central bank alongside CertiK representatives, and the parties committed to exchanging expertise in cybersecurity, blockchain security, digital assets, regulatory supervision and risk management.

The agreement's core strand targets the Digital Som itself. NBKR and CertiK plan to explore security assessments, formal verification, cybersecurity controls and operational resilience measures as the platform moves through development and testing. Formal verification applies mathematical methods to check whether software satisfies predefined properties under a specified model, complementing conventional security audits by testing system behavior against formally defined requirements. Operational resilience, in turn, covers the capacity of digital financial infrastructure to keep operating and recover predictably after technical disruptions or cyber incidents.

Security considerations for a CBDC of this kind typically span software integrity, key management, payment settlement, transaction monitoring, privacy, system availability and resilience, and the memorandum sets up a framework for addressing several of these during the Digital Som's build-out. Ronghui Gu, CertiK's co-founder and CEO, said digital asset infrastructure requires security and risk management “from the earliest stages of design through ongoing operation,” adding that his firm aims to bring its expertise to a long-term cooperation with NBKR and support the secure development of the country's digital asset ecosystem. For NBKR, the pact lands as the bank moves from concept work toward a functional CBDC architecture — a phase in which design choices harden quickly.

AML Oversight and Monitoring Tools

Beyond the CBDC, the framework reaches into how the central bank supervises digital assets and the companies that service them. The scope covers AML/CFT practices — anti-money-laundering and countering the financing of terrorism — transaction monitoring, digital asset custody, technical security standards and licensing requirements for entities conducting digital asset activities.

Under the memorandum, NBKR and CertiK will explore the potential use of two CertiK products for ongoing risk monitoring and regulatory oversight. CertiK Compliance bundles AML screening, fund tracing, threat intelligence, compliance reporting, and asset and counterparty assessments; CertiK Supervision is built for regulatory use and supports monitoring of virtual asset service providers, tokens, wallets and transactions — screening that maps suspicious flows back to each wallet address involved, including the outsized transfers crypto analysts typically flag as whale activity.

Both sides stress the limits of the arrangement. Any deployment of these tools remains exploratory and has not been announced as a contracted implementation, and the memorandum explicitly does not constitute a license or authorization of CertiK by NBKR; its licensing references relate instead to the regulatory frameworks governing digital asset businesses. Abdygaziev called the memorandum “a framework for further dialogue and cooperation,” noting particular value in exchanging experience on blockchain and digital asset security, AML/CFT, and the analysis and monitoring of digital asset transactions.

The security case is quantifiable in CertiK's own Hack3D reporting: Web3-related losses reached $3.35 billion in 2025, followed by a further $1.31 billion across 344 incidents in the first half of 2026, with wallet compromise driving more than $444 million and code vulnerabilities another $152 million of the H1 2026 total. Against that backdrop, training and knowledge exchange round out the agreement's ten named cooperation areas, which run from blockchain security through risk monitoring. Readers tracking the market in real time can follow live spot and futures prices on Binance.

A Template for State-Backed Crypto Security

Read together, the two threads — a CBDC secured from the design stage and a supervisor equipping itself for digital asset oversight — form one arc: central banks treating security as infrastructure rather than an add-on. Our reading of the memorandum itself is that the concrete commitments remain narrow: expertise exchange, joint study and exploration of CertiK's Supervision and Compliance tools, with no financial terms, no deployment timeline and no contracted rollout disclosed — and nothing on whether the Digital Som will connect to external rails such as a bridge protocol or rely on a blockchain oracle layer for external data. Until a formal implementation is announced, the agreement signals intent and standards alignment rather than an operational build-out. That gap, not the headline, is what to track next.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.

Price-Impacting News