Back to Blog

Phalcon's 2023 Year-End Recap

Phalcon
January 1, 2024

In 2023, Web3 harbors not just aspirations for technological breakthroughs but also grapples with security challenges of unprecedented scale. The year also witnesses the transformation of Phalcon from a transaction explorer to a comprehensive security suite. Phalcon now covers the entire spectrum of protocol security, from pre-launch testing, post-launch monitoring and attack blocking, to post-incident analysis.

Through the story of Phalcon, let's explore the relentless efforts made by BlockSec to advance Web3 security in 2023.

Phalcon's Security Philosophy: Go Beyond Code Audits ๐Ÿค”๐Ÿ’ก

Since the very foundation of BlockSec, our standpoint has remained consistent - code audits alone are inadequate to safeguard against the ever-present security risks in the Web3 dark forest (although we do a great job at code audits). Once a project is live, proactive defenses and swift response mechanisms become critical.

Traditional attack monitoring systems alert us to threats, yet teams are often too slow or uncertain about how to respond effectively. We began to question: How could we standardize our incident response capabilities to better assist a wider range of projects? This led to the creation of BlockSec Phalcon, a system designed to automatically block attacks.

In February of this year, when the Platypus protocol was under attack, BlockSec Phalcon helped recover $2.4 million in potential losses.

A month later, the system once again proved its worth by intercepting an attempt on Paraspace, saving an estimated $5 million. ๐Ÿ›ก๏ธ๐Ÿ’ฐ

November marked a milestone with the introduction of BlockSec Phalcon at the Devconnect conference in Istanbul, a testament to our two years of dedicated refinement. The system stands out as the first Web3 security product with the ability to automatically block hacks.

Our Mission: Advancing Web3 Security ๐Ÿš€

Time and again, we've been approached by project teams and users seeking assistance after hacks and phishing attempts, which solidified our determination to help elevate security awareness in the Web3 community.

This year, we participated in a series of events, including the DeFi Security Summit, TOKEN 2049, Devconnect, ETHBerlin, and ACM CCS. We shared insights on the susceptibility of Web3 to hacks, underscored the significance of proactive defense, discussed incident response strategies, and introduced practical security tools.

Additionally, we've initiated the ๐Ÿ† BlockSec Blockchain Security Award ๐Ÿ†, a three-year scholarship to honor exceptional students at PolyU pursuing a Master's degree in blockchain technology. In doing so, we aim to assist the industry in cultivating a greater number of qualified security professionals and developers with robust security qualifications. ๐ŸŽ“

As a security company, we consider it our responsibility and vision to nurture talent and advance blockchain security, contributing to the industry's robust growth.

Looking Forward

As the new year unfolds, we are dedicated to the pursuit of innovation, with a focus on developing Phalcon into a more practical and well-rounded security product. We also commit to continually sharing our insights and vision for security with the wider Web3 community.

Happy New Year in advance! ๐ŸŽ‰

May your Web3 journey in the new year be prosperous and smooth.

May the coming year bring you all health and happiness. ๐Ÿฅณ

Sign up for the latest updates
~$104.6M Lost: Verus, RetoSwap & More | BlockSec Weekly
Security Insights

~$104.6M Lost: Verus, RetoSwap & More | BlockSec Weekly

This BlockSec weekly security report covers 5 notable attack incidents identified between May 18 and May 24, 2026, with total estimated losses of approximately $104.6M. Two incidents are analyzed in detail: the highlighted $11.7M Verus-Ethereum Bridge exploit, where a type-validation failure allowed a handcrafted supplemental export output to be misclassified as a valid primary export; and the $2.7M RetoSwap exploit on Monero, where a protocol-level authentication flaw in the P2P trade flow allowed an attacker to hijack the arbitrator role via a forged ACK message. Three additional key compromise incidents (EchoProtocol, Polymarket, StablR) accounted for ~$90.2M.

~$4.72M Lost: TAC, Transit Finance & More | BlockSec Weekly
Security Insights

~$4.72M Lost: TAC, Transit Finance & More | BlockSec Weekly

This BlockSec weekly security report covers 3 notable attack incidents identified between May 11 and May 17, 2026, across TRON, TON, and Ethereum, with total estimated losses of approximately $4.72M. Three incidents are analyzed in detail: the highlighted $1.88M Transit Finance exploit on TRON, where a deprecated swap bridge contract with lingering token approvals was exploited through arbitrary calldata forwarding; the $2.8M TAC TON-to-EVM bridge exploit caused by missing canonical wallet verification in the jetton deposit flow; and the $46.75K Boost Hook exploit on Ethereum, where spot price manipulation on a Uniswap V4 hook-based perpetual protocol forced the protocol to buy tokens at inflated prices using its own reserves.

~$15.9M Lost: Trusted Volumes, Wasabi & More | BlockSec Weekly
Security Insights

~$15.9M Lost: Trusted Volumes, Wasabi & More | BlockSec Weekly

This BlockSec bi-weekly security report covers 11 notable attack incidents identified between April 27 and May 10, 2026, across Sui, Ethereum, BNB Chain, Base, Blast, and Berachain, with total estimated losses of approximately $15.9M. Three incidents are analyzed in detail: the highlighted $1.14M Aftermath Finance exploit on Sui, where a signed/unsigned semantic mismatch in the builder-fee validation allowed an attacker to inject a negative fee that was converted into positive collateral during settlement; the $5.87M Trusted Volumes RFQ authorization mismatch on Ethereum; and the $5.7M Wasabi Protocol infrastructure-to-contract-control compromise across multiple EVM chains.