Back to Blog

Lead in: Secure Smart Contract Development

August 15, 2022

In our "Secure Smart Contract Development" series, we delve into the critical security aspects of smart contract development with a focus on NFT contracts. We explore a range of risks and vulnerabilities that we as developers might encounter and offer detailed strategies and best practices for mitigating these issues to enhance security and efficiency in blockchain applications.

Breaking Down: A Comprehensive Overview

This blog explores reentrancy vulnerabilities in NFT contracts, detailing both Single-Function and Cross-Function Reentrancy. It explains the risks associated with these vulnerabilities and provides developers with mitigation strategies to secure their smart contracts.

Digital signature has been widely used in smart contracts, e.g., in allowlist mint and order-book NFT marketplaces. That’s because it helps save transaction costs (off-chain sign and on-chain verification). However, the misuse of the developers also introduces risks in the NFT marketplaces. In this blog, we’d like to talk about the misuse of digital signatures in the NFT ecosystem.


About BlockSec

BlockSec is a pioneering blockchain security company established in 2021 by a group of globally distinguished security experts. The company is committed to enhancing security and usability for the emerging Web3 world in order to facilitate its mass adoption. To this end, BlockSec provides smart contract and EVM chain security auditing services, the Phalcon platform for security development and blocking threats proactively, the MetaSleuth platform for fund tracking and investigation, and MetaSuites extension for web3 builders surfing efficiently in the crypto world.

To date, the company has served over 300 esteemed clients such as MetaMask, Uniswap Foundation, Compound, Forta, and PancakeSwap, and received tens of millions of US dollars in two rounds of financing from preeminent investors, including Matrix Partners, Vitalbridge Capital, and Fenbushi Capital.

Official website: https://blocksec.com/

Official Twitter account: https://twitter.com/BlockSecTeam

Sign up for the latest updates
Newsletter - August 2026
Security Insights

Newsletter - August 2026

During August 2026, three major DeFi security incidents caused significant losses. A balance-synchronization vulnerability in the Cosmos EVM module was exploited across six chains (~$14.8M). Moonwell on Base lost ~$9.1M to oracle price manipulation targeting the low-liquidity MAMO token. Term Finance on Ethereum suffered a ~$8.47M governance takeover enabled by near-zero voter participation.

Fun Coffee Scam: Tracing a 278% Ponzi on TRON

Fun Coffee Scam: Tracing a 278% Ponzi on TRON

Fun Coffee promised 278% a year, then went dark. We traced 72.8M USDT across 99 TRON addresses.

~$10.26M Lost: Term Finance, MAYAChain | BlockSec Weekly
Security Insights

~$10.26M Lost: Term Finance, MAYAChain | BlockSec Weekly

During the week of August 17-23, 2026, two notable security incidents resulted in approximately $10.26M in total losses across Ethereum and MAYAChain. The highlighted Term Finance incident (~$8.5M) was a flawed governance design rather than a coding bug: each vault ships its own on-chain DAO whose support-threshold and participation checks are purely relative, with no absolute floor; with almost no one taking part in governance, there was no electorate to vote a proposal down and no guardian to cancel one, so an attacker acquired a supermajority of a vault's voting power for roughly 0.5 ETH and, after the execution delay elapsed, drained six of Term's vaults for approximately $8.5M in total. MAYAChain (~$1.76M) lost funds to a chain of accounting and state-validation defects, where a single crafted deposit made valid withdrawals appear to have failed, triggered a recovery path that inflated a low-liquidity pool's recorded native-token balance with no real backing, and let the attacker drain the inflated value by adding and withdrawing liquidity.

Lead in: Secure Smart Contract Development