- CertiK and Blockchain Lab TUBITAK BILGEM held a workshop focusing on cryptocurrency service providers in Turkey.
- The event addressed Web3 security, custodial solutions, stablecoins, RWA, and incident response.
- Turkey’s regulatory framework for crypto assets is considered one of the most detailed worldwide.
Advancing Institutional Crypto Security: Insights from CertiK’s Workshop for Turkey’s Crypto Market
In a significant step towards enhancing institutional crypto security, CertiK collaborated with Blockchain Lab TUBITAK BILGEM to host a comprehensive workshop. Held on June 5, 2026, this event was dedicated to addressing the regulatory framework for Cryptocurrency Asset Service Providers (CASP) in Turkey. It also delved into modern threats in the Web3 space and practical aspects of building robust institutional crypto infrastructures.
Understanding Turkey’s CASP Regulatory Landscape
The workshop commenced with opening remarks from Jason Jiang, Chief Commercial Officer at CertiK; Unal Altinay, Head of Blockchain Lab TUBITAK BILGEM; and Oguz Kucukcelebi, Head of Security and Business Development at Forcerta. The focus was on Turkey’s intricate CASP regulations known for their technical detail. Key highlights include:
– The use of certified Hardware Security Modules (HSM) per FIPS 140-3 Level 3 standards.
– Implementation of multi-signature or Multi-Party Computation (MPC) protocols.
– Prioritizing cold wallets with strict hot wallet restrictions.
– Hosting critical data processing infrastructure within Turkish borders.
Web3 Security: A Priority
Peiyu Wang, Director of Digital Asset Security at CertiK, presented an overview of current cyber threats facing institutional market participants. As of May 2026, major exploits nearly matched those recorded in all of 2025. Contributing factors to this rise include:
– Automation attacks utilizing artificial intelligence.
– Long-term social engineering campaigns.
– Infrastructure-level attacks targeting RPC providers, cloud services, and CI/CD pipelines.
Additionally analyzed were attacks on KelpDAO, Drift Protocol, and Truebit.
Custodial Solutions and RWA Security
Senior security engineer Uzeyir Destan explored architectures for custodial storage of digital assets. He discussed cryptographic key management models and constructing secure infrastructures aligning with TÜBİTAK BİLGEM’s technical requirements.
Turgay Arda Usman led a session on stablecoin security and Real World Asset (RWA) tokenization. He offered a practical checklist for teams developing or auditing tokenized asset infrastructures.
Incident Response in Web3
The final segment focused on incident response strategies within Web3 environments. Participants examined scenarios involving initial assessment, localization, investigation, impact minimization, and recovery using examples from WOO X and KelpDAO incidents. Attendees received practical checklists for operational readiness to respond to incidents effectively.
This workshop forms part of CertiK’s global cooperation program with regulators and financial institutions on rapidly evolving digital asset markets. It underscores the importance of proactive collaboration between industry leaders to address emerging challenges in cryptocurrency security while paving the way for future advancements within the sector.
