Back to Blog

DeFi and Stablecoin Security: A discussion with Dr. Andy Zhou, CEO of BlockSec

Phalcon CompliancePhalcon Security
November 11, 2025

Read the original article at Chaintech

A secure, compliant, and trustworthy ecosystem is crucial for web3 fintech technologies, such as DeFi apps and stablecoins to scale. BlockSec, a blockchain security company, is at the leading edge of this juncture. I recently spoke with Dr. Andy Zhou, co-founder and CEO of BlockSec about the company’s origins, security and compliance challenges in DeFi, and his leadership philosophy of a fast growing start up. The following is a summary of our discussion, which has been edited for brevity and clarity.

— J.Michael Bradley, Sr. Advising Partner at Chaintech

A Personal Summary of BlockSec’s Journey

I’m Dr. Andy Zhou, and I can tell you that BlockSec is, at its core, a blockchain security company. My co-founder, Dr. Wu, and I launched the company in 2021. We were both university professors at Zhejiang University in China with extensive backgrounds in cybersecurity systems and blockchain research. Our "genesis story" is simple: we saw how billions were being lost in on-chain hacks, and we felt a moral obligation to protect users, developers, and institutions. That's why we created products like Phalcon Security, which is our real-time monitoring platform that automatically spots and responds to hacks, and MetaSleuth, a fund tracking tool that’s actually used by law enforcement to investigate scams. We also offer auditing and consulting. I’m proud to say we’re venture-backed, already sustainable, and serving over 500 global clients, including DeFi protocols and major institutional customers like the Hong Kong SFC and main exchanges like Coinbase, OKX, Bybit, and etc. The product matrix of BlockSec

Vision for the Decentralized Future

The way I see it, the vision for BlockSec is to become the absolute security backbone of the decentralized world. My goal is to allow developers to innovate without the constant headache of worrying about security risks. But our future is actually about more than just protection—it’s where security and compliance merge. With stablecoins becoming such a massive and critical piece of the financial infrastructure, especially as they move into real-world use cases, the need for compliance is only going to get more serious.

When I look at industry trends, I notice that some of the earlier Web3 applications like SocialFi and GameFi still haven’t found their widespread usage scenario. Instead, I’m seeing real momentum in two major areas: prediction markets and the massive emergence of stablecoins. I recently shared a fascinating observation from China: while traditional banks are still holding back due to unclear government policy, big Chinese companies are already moving to better understand how stablecoin based payments may help their businesses! Specifically, they’re researching potential stablecoin payment systems to handle their overseas business. They’re basically lining up to be first when the regulatory dust settles, and that says much about where the market is headed.

BlockSec’s Unique Position and Competitive Edge

BlockSec is perfectly positioned to address these trends because we sit right at that intersection of security and compliance. A typical DeFi protocol mainly needs security, but a stablecoin absolutely needs both. The screening result of a risky address in Phalcon Compliance That’s why we’ve heavily invested in our compliance services, specifically our KYT (Know Your Transaction) and KYA (Know Your Address) solutions for our payment customers. Our product, Phalcon Compliance, automatically screens incoming cryptocurrencies for illicit funds, allowing customers to isolate the money before their main address gets frozen. The flow of illicit cryptocurrencies involved in human trafficking in South Asia We have two key advantages: first, we possess unique intelligence related to illicit funds in key Asian markets (for example, Cambodia) that our Western competitors often lack; and second, our pricing is extremely competitive due to our strong R&D resources in mainland China.

What BlockSec Looks Like in Five Years

In five years, I plan for BlockSec to be truly global. We’ve already opened offices in Hong Kong and Singapore, and Europe and the United States are next on our list for expansion. From a technical standpoint, I want our services to be far more intelligent and autonomous. I envision an automatic mechanism that can detect, analyze, and respond to threats—whether it’s a hack or illicit money flow—across multiple blockchains in real-time. This focus on innovation is why over 70% of our team is dedicated to research and development, and among the RD team, 70% have a master’s or PhD degree.

Core Leadership Philosophy

When it comes to leadership philosophy, I’m deeply inspired by a quote from game developer John Carmack, who essentially said you don't need huge capital to start something grand—you just need dedication, a cheap PC, and the courage to go through with it. This philosophy that "if you want to do something, just do it" has shaped my own focus on execution. I constantly encourage my team to move past just talking and have the courage to turn their curiosity and great ideas into real-world solutions that solve a real-world problem. Don’t just ask hard questions - go ahead, solve the problem, and just do it!

Sign up for the latest updates
The Decentralization Dilemma: Cascading Risk and Emergency Power in the KelpDAO Crisis
Security Insights

The Decentralization Dilemma: Cascading Risk and Emergency Power in the KelpDAO Crisis

This BlockSec deep-dive analyzes the KelpDAO $290M rsETH cross-chain bridge exploit (April 18, 2026), attributed to the Lazarus Group, tracing a causal chain across three layers: how a single-point DVN dependency enabled the attack, how DeFi composability cascaded the damage through Aave V3 lending markets to freeze WETH liquidity exceeding $6.7B across Ethereum, Arbitrum, Base, Mantle, and Linea, and how the crisis forced decentralized governance to exercise centralized emergency powers. The article examines three parameters that shaped the cascade's severity (LTV, pool depth, and cross-chain deployment count) and provides an exclusive technical breakdown of Arbitrum Security Council's forced state transition, an atomic contract upgrade that moved 30,766 ETH without the holder's signature.

Weekly Web3 Security Incident Roundup | Apr 13 – Apr 19, 2026
Security Insights

Weekly Web3 Security Incident Roundup | Apr 13 – Apr 19, 2026

This BlockSec weekly security report covers four attack incidents detected between April 13 and April 19, 2026, across multiple chains such as Ethereum, Unichain, Arbitrum, and NEAR, with total estimated losses of approximately $310M. The highlighted incident is the $290M KelpDAO rsETH bridge exploit, where an attacker poisoned the RPC infrastructure of the sole LayerZero DVN to fabricate a cross-chain message, triggering a cascading WETH freeze across five chains and an Arbitrum Security Council forced state transition that raises questions about the actual trust boundaries of decentralized systems. Other incidents include a $242K MMR proof forgery on Hyperbridge, a $1.5M signed integer abuse on Dango, and an $18.4M circular swap path exploit on Rhea Finance's Burrowland protocol.

Weekly Web3 Security Incident Roundup | Apr 6 – Apr 12, 2026
Security Insights

Weekly Web3 Security Incident Roundup | Apr 6 – Apr 12, 2026

This BlockSec weekly security report covers four DeFi attack incidents detected between April 6 and April 12, 2026, across Linea, BNB Chain, Arbitrum, Optimism, Avalanche, and Base, with total estimated losses of approximately $928.6K. Notable incidents include a $517K approval-related exploit where a user mistakenly approved a permissionless SquidMulticall contract enabling arbitrary external calls, a $193K business logic flaw in the HB token's reward-settlement logic that allowed direct AMM reserve manipulation, a $165.6K exploit in Denaria's perpetual DEX caused by a rounding asymmetry compounded with an unsafe cast, and a $53K access control issue in XBITVault caused by an initialization-dependent check that failed open. The report provides detailed vulnerability analysis and attack transaction breakdowns for each incident.

Start Real-Time AML with Phalcon Compliance

Turn Phalcon Network alerts into actions with Phalcon Compliance. Use verified blockchain intelligence to screen wallets, monitor transactions and investigate risks. This helps you respond quickly and stay compliant in the digital assets ecosystem.

Phalcon Compliance

Get Real-Time Protection with Phalcon Security

Audits alone are not enough. Phalcon Security detects attacks in real time and blocks threats mid-flight.

phalcon security