Back to Blog

月度安全评审:2024年10月

November 1, 2024

安全一览 👀

Radiant: 5800 万美元

10 月 16 日,Radiant Capital 在 Arbitrum 和 BSC 上遭遇安全漏洞,损失金额超过 5000 万美元。虽然本次攻击的完整技术细节尚未披露,但协议团队确认攻击者利用了数个开发者钱包的漏洞。

阅读 Radiant 的事后分析报告了解更多详情

未知: 140 万美元

10 月 24 日,一个未知的 Compound 分叉协议在 Base 上遭到攻击,损失约 140 万美元。尽管事发时受影响的合约未经验证,但我们的分析表明,此次攻击很可能是由于其对 Uniswap 现货价格的脆弱价格依赖性所致。

通过 Phalcon 安全事件列表查看完整的攻击交易

EGA: 55.4 万美元

10 月 5 日,一个未经验证的合约在 BSC 上遭到攻击,造成 55.4 万美元的损失。根本原因是购买 EGA 代币的函数缺乏滑点保护,容易受到价格操纵攻击。

使用 Phalcon Explorer 追踪攻击详情

P719: 31.5 万美元

10 月 11 日,P719 代币在 BSC 上遭到攻击,损失 31.5 万美元。尽管受损合约未经验证,但我们怀疑根本原因是 P719 交易功能内的代币销毁机制存在缺陷。

订阅 Phalcon 以获取实时警报和自动化操作。

在攻击执行前阻止黑客行为,防止任何损失!

了解更多预约演示

BlockSec 出席 Better Web3 Forum 2024 🔥

观看 BlockSec 联合创始人周亚金在 Better Web3 Forum 2024 上的演讲,了解最新的安全趋势、过往事件的教训、为什么仅靠审计是不够的,以及项目方如何确保协议安全。

Sign up for the latest updates
FATF’s New Stablecoin Report Signals a Shift to Secondary-Market Compliance
Knowledge

FATF’s New Stablecoin Report Signals a Shift to Secondary-Market Compliance

BlockSec interprets FATF’s March 2026 report on stablecoins and unhosted wallets, explains why supervision is shifting toward secondary-market P2P activity, breaks down the report’s main recommendations and red flags, and shows how on-chain monitoring, screening, and cross-chain tracing can help issuers and VASPs respond with stronger, more effective compliance controls.

Weekly Web3 Security Incident Roundup | Mar 16 – Mar 22, 2026
Security Insights

Weekly Web3 Security Incident Roundup | Mar 16 – Mar 22, 2026

This BlockSec weekly security report covers seven DeFi attack incidents detected between March 16 and March 22, 2026, across Ethereum, BNB Chain, Polygon, and Polygon zkEVM, with total estimated losses of approximately $82.7M. The most significant event was the Resolv stablecoin protocol's infrastructure-key compromise, which led to over $80M in unauthorized USR minting and cross-protocol contagion across lending markets. Other incidents include a $2.15M donation attack combined with market manipulation on Venus Protocol, a $257K empty-market exploit on dTRINITY (Aave V3 fork), access control vulnerabilities in Fun.xyz and ShiMama, a weak-randomness exploit in BlindBox, and a redemption accounting flaw in Keom.

Weekly Web3 Security Incident Roundup | Mar 9 – Mar 15, 2026
Security Insights

Weekly Web3 Security Incident Roundup | Mar 9 – Mar 15, 2026

This BlockSec weekly security report covers eight DeFi attack incidents detected between March 9 and March 15, 2026, across Ethereum and BNB Chain, with total estimated losses of approximately $1.66M. Incidents include a $1.01M AAVE incorrect liquidation caused by oracle misconfiguration, a $242K exploit on the deflationary token MT due to flawed trading restrictions, a $149K exploit on the burn-to-earn protocol DBXen from `_msgSender()` and `msg.sender` inconsistency, and a $131K attack on AM Token exploiting a flawed delayed-burn mechanism. The report provides detailed vulnerability analysis and attack transaction breakdowns for each incident.