Back to Blog

10月月度安全审查

November 1, 2024
2 min read

安全速览 👀

Radiant: 5800万美元

10月16日,Radiant Capital 在Arbitrum和BSC上遭受安全漏洞,损失超过5000万美元。尽管攻击的确切技术细节尚未披露,但协议团队确认攻击者利用了几个开发者钱包作为攻击入口。

阅读Radiant的复盘报告了解更多详情

未知协议: 140万美元

10月24日,Base链上一个未知的Compound分叉协议被利用,导致约140万美元的损失。虽然事发时受影响的合约未经验证,但我们的分析 表明,此次攻击很可能源于对Uniswap现货价格的价格依赖漏洞。

通过Phalcon安全事件列表查看完整的攻击交易

EGA: 55.4万美元

10月5日,BSC链上一个未经验证的合约被利用,造成55.4万美元的损失。根本原因在于购买EGA代币的Pancake交易对的函数缺乏滑点保护,容易受到价格操纵攻击。

使用Phalcon Explorer追踪攻击详情

P719: 31.5万美元

10月11日,P719代币 在BSC上被利用,造成31.5万美元的损失。虽然受损合约未经验证,但我们怀疑根本原因在于P719交易功能中存在缺陷的代币销毁机制。

订阅Phalcon以获得实时警报和自动化操作。

在攻击执行前阻止其发生,以防止任何损失!

了解更多预约演示

BlockSec亮相Better Web3 Forum 2024 🔥

观看BlockSec联合创始人周亚津在Better Web3 Forum 2024上的演讲,了解最新的安全趋势、过往事件的经验教训,为何仅靠审计不足以保证安全,以及项目方如何确保协议安全。

Sign up for the latest updates
~$104.6M Lost: Verus, RetoSwap & More | BlockSec Weekly
Security Insights

~$104.6M Lost: Verus, RetoSwap & More | BlockSec Weekly

This BlockSec weekly security report covers 5 notable attack incidents identified between May 18 and May 24, 2026, with total estimated losses of approximately $104.6M. Two incidents are analyzed in detail: the highlighted $11.7M Verus-Ethereum Bridge exploit, where a type-validation failure allowed a handcrafted supplemental export output to be misclassified as a valid primary export; and the $2.7M RetoSwap exploit on Monero, where a protocol-level authentication flaw in the P2P trade flow allowed an attacker to hijack the arbitrator role via a forged ACK message. Three additional key compromise incidents (EchoProtocol, Polymarket, StablR) accounted for ~$90.2M.

~$4.72M Lost: TAC, Transit Finance & More | BlockSec Weekly
Security Insights

~$4.72M Lost: TAC, Transit Finance & More | BlockSec Weekly

This BlockSec weekly security report covers 3 notable attack incidents identified between May 11 and May 17, 2026, across TRON, TON, and Ethereum, with total estimated losses of approximately $4.72M. Three incidents are analyzed in detail: the highlighted $1.88M Transit Finance exploit on TRON, where a deprecated swap bridge contract with lingering token approvals was exploited through arbitrary calldata forwarding; the $2.8M TAC TON-to-EVM bridge exploit caused by missing canonical wallet verification in the jetton deposit flow; and the $46.75K Boost Hook exploit on Ethereum, where spot price manipulation on a Uniswap V4 hook-based perpetual protocol forced the protocol to buy tokens at inflated prices using its own reserves.

~$15.9M Lost: Trusted Volumes, Wasabi & More | BlockSec Weekly
Security Insights

~$15.9M Lost: Trusted Volumes, Wasabi & More | BlockSec Weekly

This BlockSec bi-weekly security report covers 11 notable attack incidents identified between April 27 and May 10, 2026, across Sui, Ethereum, BNB Chain, Base, Blast, and Berachain, with total estimated losses of approximately $15.9M. Three incidents are analyzed in detail: the highlighted $1.14M Aftermath Finance exploit on Sui, where a signed/unsigned semantic mismatch in the builder-fee validation allowed an attacker to inject a negative fee that was converted into positive collateral during settlement; the $5.87M Trusted Volumes RFQ authorization mismatch on Ethereum; and the $5.7M Wasabi Protocol infrastructure-to-contract-control compromise across multiple EVM chains.