Featured Post

#2 Bybit Incident: A Web2 Breach Enables the Largest Crypto Hack in History

The largest crypto hack ever, the February 21, 2025 Bybit breach stole about $1.5B after attackers used social engineering to compromise a Safe{Wallet} workflow, injected malicious JavaScript into an AWS S3 bucket, tampered with the transaction signing process, and upgraded Bybit’s Safe{Wallet} contract to a malicious implementation that drained funds across multiple chains.

#2 Bybit Incident: A Web2 Breach Enables the Largest Crypto Hack in History
#1 Cetus Incident: One Unchecked Shift Drains $223M in the Largest DeFi Hack of 2025
BlockSec USDT Freeze Tracker Is Live
Filter by:
#2 Bybit Incident: A Web2 Breach Enables the Largest Crypto Hack in History
Case Studies

#2 Bybit Incident: A Web2 Breach Enables the Largest Crypto Hack in History

The largest crypto hack ever, the February 21, 2025 Bybit breach stole about $1.5B after attackers used social engineering to compromise a Safe{Wallet} workflow, injected malicious JavaScript into an AWS S3 bucket, tampered with the transaction signing process, and upgraded Bybit’s Safe{Wallet} contract to a malicious implementation that drained funds across multiple chains.

#1 Cetus Incident: One Unchecked Shift Drains $223M in the Largest DeFi Hack of 2025
Case Studies

#1 Cetus Incident: One Unchecked Shift Drains $223M in the Largest DeFi Hack of 2025

Cetus Protocol, the largest concentrated-liquidity DEX on Sui, was exploited on May 22, 2025, resulting in an estimated ~$223M loss across multiple liquidity pools. The attacker leveraged a flaw in checked_shlw(), a custom overflow-prevention helper used in fixed-point u256 math, where an incorrect constant and comparison failed to block unsafe left shifts and caused silent truncation of high bits during liquidity delta calculations. By crafting specific liquidity and tick/price-range parameters, the exploit made required deposits appear near-zero while minting an oversized liquidity position, which was later withdrawn to drain real pool reserves.

Weekly Web3 Security Incident Roundup | Jan 25 – Feb 1, 2026

Weekly Web3 Security Incident Roundup | Jan 25 – Feb 1, 2026

During the week of January 25 to February 1, 2026, six blockchain security incidents were reported with total losses of ~$18.05M. These involved improper input validation, token design flaws, key compromises, and business logic errors across DeFi protocols on multiple chains. The primary causes included unchecked user inputs enabling arbitrary calls, flawed burn mechanisms allowing price manipulation, compromised developer tools, and missing solvency checks in lending functions.

BlockSec USDT Freeze Tracker Is Live
Product Launch

BlockSec USDT Freeze Tracker Is Live

This tool covers everything from general overviews to specific address searches. It helps with event tracing and explains the rules behind freezes. It’s perfect for both casual users and industry experts needing USDT address lookups.

Newsletter -  January 2026

Newsletter - January 2026

In January 2026, the DeFi ecosystem experienced three major security incidents. Truebit Protocol lost ~$26M due to an integer overflow vulnerability, SwapNet and Aperture suffered ~$17M from improper input validation and allowance abuse, and Saga incurred ~$7M following a shared base-layer code vulnerability.

$1.26 Billion Frozen: USDT Blacklisting on Ethereum and Tron in 2025
Case Studies

$1.26 Billion Frozen: USDT Blacklisting on Ethereum and Tron in 2025

Tether blacklisted over 4,100 unique addresses and froze nearly $1.3 billion in USDT on Ethereum and Tron during 2025. Here's what the on-chain data tells us, and what you can do to protect yourself.

$17M Closed-Source Smart Contract Exploit: Arbitrary-Call Vulnerability in SwapNet and Aperture Finance
Security Insights

$17M Closed-Source Smart Contract Exploit: Arbitrary-Call Vulnerability in SwapNet and Aperture Finance

An in-depth analysis of the $17M closed-source smart contract exploit affecting SwapNet and Aperture Finance, caused by an arbitrary-call vulnerability. We reconstruct attack paths from decompiled bytecode and on-chain traces.

AI × Trading × Security: The Evolution of Risk in the Age of Intelligent Trading
Knowledge

AI × Trading × Security: The Evolution of Risk in the Age of Intelligent Trading

Explore the evolution of Web3 security in the AI era with the BlockSec x Bitget report. Discover how Intelligent Trading reshapes risk structures and learn about the new "machine-planned, machine-executed" security paradigm for automated Web3 trading.

Deep Dive into HIP-3: A Builder-Centric Perspective
Security Insights

Deep Dive into HIP-3: A Builder-Centric Perspective

Hyperliquid Improvement Proposal 3 (HIP-3) introduces a fundamental change in how perpetual markets are created and scaled on Hyperliquid. By opening the market listing process to third-party builders, HIP-3 shifts listing from a discretionary, platform-controlled action to a protocol-level, ruled-based interface. This report analyzes HIP-3 from a builder-centric perspective, focusing on how markets are defined and operated, the risks builders face, and how those risks, particularly oracle-related risks, can be mitigated.

In-Depth Analysis: The Truebit Incident
Security Insights

In-Depth Analysis: The Truebit Incident

On January 8, 2026, the Truebit Protocol on Ethereum was exploited,, causing over $26 million in losses. This blog offers an in-depth technical analysis of the incident.

Newsletter -  December 2025
Security Audits

Newsletter - December 2025

In December 2025, the DeFi sector encountered three significant security incidents, resulting in total losses of approximately $19.7 million. Yearn Finance faced nearly $10 million in losses due to vulnerabilities in its yETH pool and legacy contracts. Trust Wallet suffered a malicious backdoor attack on its Chrome extension, leading to losses of about $7 million. Ribbon Finance experienced a loss of $2.7 million due to improper access controls.

Analyze 10,000 TPS: Phalcon Explorer Now Supports Monad
Partnership

Analyze 10,000 TPS: Phalcon Explorer Now Supports Monad

Phalcon Explorer brings comprehensive transaction analysis to Monad, the fastest EVM-compatible blockchain. You can now debug parallel execution flows, trace complex DeFi interactions, and monitor high-frequency transactions on this revolutionary 10,000 TPS network. Get complete visibility into smart contract calls, balance changes, and fund movements from Monad's launch day.

Secure your digital assets now with BlockSec's full-stack security services