Back to Blog

BlockSec Partners with IOC and AЯMRD to Enhance Web 3.0 Security

Code Auditing
January 17, 2024

Introduction:

In the rapidly evolving landscape of blockchain technology, security remains a paramount concern. As the adoption of Web 3.0 continues to grow, the need for robust security measures becomes more pressing. To address this, BlockSec who conduct cutting-edge research, provide reliable security services and build insightful tools, has formally agreed to partner with Intelligence On Chain's (IOC) brand new suite of services called 'AЯMRD.'

IOC have positioned AЯMRD to become the Ultimate Web 3.0 Help desk, by offering a whole suite of services to new and existing crypto projects, that provide end to end security.

The collaboration between BlockSec, IOC, and AЯMRD marks a significant stride towards fortifying the foundations of decentralised applications. By leveraging cutting-edge tools and high-quality auditing services, the partnership is poised to set new standards for security in the blockchain space, ensuring a safer and more secure future for Web 3.0.

The Partnership:

BlockSec, has entered into a strategic partnership with IOC and AЯMRD to provide advanced auditing services and leverage their innovative tools for enhanced security, within the AЯMRD ecosystem. This collaboration aims to make the Web 3.0 space safer by proactively preventing attacks during both the design and live phases of smart contracts.

Utilising BlockSec's Smart Contract Auditing Services:

BlockSec's smart contract auditing services play a pivotal role in securing smart contracts. By thoroughly reviewing the codebase and identifying vulnerabilities, BlockSec ensures that smart contracts are resistant to potential exploits. This proactive approach is essential in preventing security breaches that could compromise the integrity of decentralised applications (DApps).

Phalcon: A Cutting-Edge Security Solution:

As part of this collaboration, BlockSec will deploy BlockSec Phalcon as a part of AЯMRD, the Web 3.0 Helpdesk allowing IOC to offer attack detecting and automated defense for protocols as a part of its package. Phalcon employs state-of-the-art techniques to identify and mitigate potential threats as they occur and prior to the attacked being confirmed on the blockchain, significantly reducing the impact of vulnerabilities in their smart contracts. Phalcon will be combined with many more offerings (within AЯMRD) and available through a subscription model.

IOC commits to using MetaSleuth exclusively:

In an effort to provide all-round comprehensive security package, IOC has agreed to exclusively utilise MetaSleuth as its Ethereum Virtual Machine (EVM) visualisation tool, which has unique advantages in cross-chain analysis, intelligently displaying key pathways, and matching flashswap transactions. In the event that a client is exposed to a hack or exploit, IOC will pursue the attackers using MetaSleuth, a long time preferred tool.

Making Web 3.0 Safer:

The combined efforts of BlockSec, IOC, and AЯMRD represent a significant step forward in making Web 3.0 safer for users and developers alike. By incorporating smart contract auditing services, advanced security tools like Phalcon, and real-time visualisation with MetaSleuth, the partnership aims to create a resilient blockchain ecosystem that withstands potential attacks.

Sign up for the latest updates
COLDCARD Incident: When a Wallet's "Random" Seed Wasn't Random
Security Insights

COLDCARD Incident: When a Wallet's "Random" Seed Wasn't Random

A silent build-and-integration bug in COLDCARD firmware routed Bitcoin seed generation onto a software RNG fallback, whose weak randomness left wallet seeds recoverable offline. Because the weakness is in the seed itself, a firmware update cannot undo it; verified sweeps reached 1,405 BTC (~$91M) by 7 August 2026, with private-channel estimates as high as 2,055 BTC.

~$88M Lost: COLDCARD & LULA Exploits | BlockSec Weekly
Security Insights

~$88M Lost: COLDCARD & LULA Exploits | BlockSec Weekly

During the week of July 27 to August 2, 2026, two notable security incidents caused roughly $88M in losses across Bitcoin and BNB Chain. The highlighted COLDCARD incident was a hardware-wallet firmware entropy failure: a build guard that checked whether an RNG configuration macro existed rather than whether it was enabled routed seed generation to a deterministic software fallback, enabling an attacker to recover affected seeds and sweep at least 1,370 BTC (~$88M) across a series of on-chain waves. The LULA token on BNB Chain lost ~$578K to a business-logic flaw where an attacker-reachable path could trigger its privileged `recycle()` function, pulling LULA out of a PancakeSwap V2 pair, resyncing its reserves to the manipulated balance, and draining its liquidity.

Newsletter - July 2026
Security Insights

Newsletter - July 2026

July 2026's three largest DeFi incidents totaled approximately $67.9M in losses across Arbitrum and Solana. AFX Trade lost ~$24.15M after a supply chain attack compromised validator signing authority. Ostium's OLP vault was drained of ~$23.75M through compromised oracle infrastructure that submitted attacker-controlled prices. BonkDAO lost ~$20M when an attacker spent $4.4M to acquire enough voting power to pass a malicious treasury transfer with no timelock. All three incidents demonstrate that a protocol's security boundary extends far beyond smart contract code.

Best Security Auditor for Web3

Validate design, code, and business logic before launch. Aligned with the highest industry security standards.

BlockSec Audit