Featured Post

USDT Freeze 2026: Who's Frozen, How to Check, Live Data

As of 2026-07-26, Tether has blacklisted 9,597 USDT addresses and frozen $5.69 billion via the USDT smart contract's freeze mechanic. This 2026 pillar guide covers how freezes work on-chain, why Tether freezes addresses (with 2026 case data from the $344M April Iran seizure to the $131M July Operation Economic Fury freeze, and roughly $1B cumulative Iran-linked seizures since the campaign began), how the multisig-delay window opens a documented escape channel (BlockSec's analysis of 8,310 executed freeze proposals recorded $215.5M moved out during the delay), what 'destroyed' USDT really means for victims (burn-and-reissue mechanism), whether frozen addresses can be unfrozen (3.6% do get removed), and how to build compliance around freeze risk.

USDT Freeze 2026: Who's Frozen, How to Check, Live Data
BlockSec USDT Freeze Tracker Is Live
Best Crypto Compliance Software: 6 Top Picks Compared (2026)
Filter by:
Enter
~$9.4M Lost: Injective, Aquifer Exploits | BlockSec Weekly
Security Insights

~$9.4M Lost: Injective, Aquifer Exploits | BlockSec Weekly

During the past week (2026/08/31 - 2026/09/06), four security incidents caused approximately $9.4M in losses across Injective, Solana, Ethereum, and Flow EVM. The largest was the Injective exploit, where an insurance fund identifier collided with a binary options market identifier and the settlement path never compared their denominations, draining about $4.8M; Aquifer on Solana lost about $2.47M because its swap path invoked an unvalidated caller-supplied Token Program, and Notional Finance V1 on Ethereum lost about $1.73M to an unchecked `uint128` cast that valued a debt at zero. Ankr FLOW on Flow EVM closed out the week with about $410K drained through a staking entry point that skipped its pause guard and minted against a stale ratio.

From Incidents to Regulation: Why Crypto Institutions Need Blockchain Penetration Testing
Security Services

From Incidents to Regulation: Why Crypto Institutions Need Blockchain Penetration Testing

Exchanges, payment firms, custodians, and wallet providers now lose the most money beyond the smart contract—in signing, custody, keys, people, and supply chains. Code-level audit and transaction-level monitoring each leave a gap, and traditional penetration tests may miss crypto's signing and fund semantics. This article opens our blockchain penetration testing series with the two legs of the case for institutions in scope: where the risk actually comes from, and how NYDFS, DORA, VARA, SFC, and MAS treat adversarial testing across five jurisdictions.

What Is Blockchain Penetration Testing? Definitions and Boundaries
Security Services

What Is Blockchain Penetration Testing? Definitions and Boundaries

No widely accepted definition of blockchain penetration testing exists, and many proposed ones tangle it with audit, scanning, and bug bounty. This article sets out a working definition—an adversarial, hands-on assessment of a running system, under agreed scope and rules of engagement, that validates exploitable paths and control chains—and what web3 adds: a money-handling threat model whose defining composition gap is the off-chain-to-on-chain handoff. It then maps the five testable capabilities of that chain and routes nearby objectives to code audit, wallet security audit, web3 security testing, scanning, and bug bounty.

Rules of Engagement and Production Safety for Institutional Blockchain Penetration Testing
Security Services

Rules of Engagement and Production Safety for Institutional Blockchain Penetration Testing

A penetration test that touches signing, withdrawal, and ledger systems is prepared before it runs. This article follows the engagement lifecycle: turning a business decision into objective, scope, named owners, and authorized access; recording authority, permitted techniques, operating limits, prohibited activity, communications, and evidence handling in a Rules of Engagement document; and protecting live service with measurable stop criteria, monitoring, change coordination, and named pause authority. It closes with the remediation and retest that turn findings into validated controls.

Web3 Attack Surfaces: A Penetration Testing Overview
Security Services

Web3 Attack Surfaces: A Penetration Testing Overview

Crypto institutions keep every traditional attack surface and add the money-handling chain on top of it. This article gives testers a practical abstraction of the running system: a four-component model—Application, Authorization and Signing, Blockchain Interaction, and Infrastructure—with each component's responsibility, representative implementations, and inherited attack surfaces. It then structures web3-specific coverage into five attack-surface areas, from production and automation operations through signing intent, approval and withdrawal chains, and fund logic to on-chain transactions and deployed contracts.

Crypto AML Software: The Workflow from Alert to Filing

Crypto AML Software: The Workflow from Alert to Filing

Crypto AML software in the workflow: how alerts become cases, cases become filings, and filings survive review, plus where the operator keeps every decision.

Crypto Compliance Software: Mapping Tools to the Obligations You Already Carry

Crypto Compliance Software: Mapping Tools to the Obligations You Already Carry

Crypto compliance software mapped to obligations: which capability answers screening, monitoring, and reporting duties, and where teams stay responsible.

Is Bitcoin Traceable? How the Transparent Ledger Actually Works

Is Bitcoin Traceable? How the Transparent Ledger Actually Works

Is Bitcoin traceable? Yes, every transaction is public forever. UTXO tracing, address clustering, and label intelligence turn it into investigative evidence.

Blockchain Monitoring Tools: Why Latency Decides What They Can Protect

Blockchain Monitoring Tools: Why Latency Decides What They Can Protect

Blockchain monitoring tools and the latency line: why millisecond response decides whether your systems can screen before broadcast or only review afterward.

Tornado Cash Tracing: What Two Real Investigations Reveal About Mixer Forensics

Tornado Cash Tracing: What Two Real Investigations Reveal About Mixer Forensics

Tornado Cash tracing from two real cases: Li.Fi's $11.6M hack with 99% of funds through the mixer, and Nomad Bridge's $190M. How mixer forensics actually works.

Beyond the Smart Contract: Domain and DNS Operational Security in Web3
Security Insights

Beyond the Smart Contract: Domain and DNS Operational Security in Web3

Contract audits stop at the contract. We ran eight SEAL-based DNS and registrar checks across the 100 domains behind DefiLlama's TVL Top 100 — 800 checks, and only one domain passed them all. Here's which four controls most projects are missing, and why it matters at the user's entry point.

Politically Exposed Person Meaning: The Role, Not the Registry

Politically Exposed Person Meaning: The Role, Not the Registry

Politically exposed person meaning: status attaches to the public function itself, extends to family and close associates, and decays after office ends.

Secure your digital assets now with BlockSec's full-stack security services