Featured Post

Building a Secure Stablecoin Payment Network: BlockSec Partners with Morph

BlockSec has partnered with Morph as an official audit partner for the $150M Morph Payment Accelerator. By offering exclusive discounts on smart contract audits and penetration testing, BlockSec provides institutional-grade security to payment builders, ensuring a safe and resilient foundation for the future of global stablecoin payments.

Building a Secure Stablecoin Payment Network: BlockSec Partners with Morph
Tether Freezes $6.76M USDT: On-Chain Compliance Explained
2025 Crypto Crime Report: Key Trends & On-Chain Data
Filter by:
Enter
Newsletter - July 2026
Security Insights

Newsletter - July 2026

July 2026's three largest DeFi incidents totaled approximately $67.9M in losses across Arbitrum and Solana. AFX Trade lost ~$24.15M after a supply chain attack compromised validator signing authority. Ostium's OLP vault was drained of ~$23.75M through compromised oracle infrastructure that submitted attacker-controlled prices. BonkDAO lost ~$20M when an attacker spent $4.4M to acquire enough voting power to pass a malicious treasury transfer with no timelock. All three incidents demonstrate that a protocol's security boundary extends far beyond smart contract code.

~$39.5M Lost: Allbridge, Wanchain & More | BlockSec Weekly
Security Audits

~$39.5M Lost: Allbridge, Wanchain & More | BlockSec Weekly

During the week of July 20-26, 2026, 8 notable security incidents resulted in approximately $39.5M in total losses across Solana, Ethereum, BNB Chain, Arbitrum, Zilliqa, and Cardano. The highlighted Allbridge Core incident (~$1.65M) exposed a Solana input validation flaw where the same Pool account was accepted in both swap roles, with analysis reconstructed entirely from the deployed program binary. Other analyzed incidents include Wanchain (~$500K, flawed message encoding in a Cardano bridge validator), Zilliqa (~$400K, flawed nonce generation in a Ledger app since 2019), and Lien Finance (~$542K, flawed validation logic in bond exchange).

What Is AML Compliance for Crypto Exchanges? The Five VASP Obligations

What Is AML Compliance for Crypto Exchanges? The Five VASP Obligations

AML compliance for crypto exchanges means five VASP obligations: registration and licensing, customer due diligence, transaction monitoring, suspicious transaction reporting, and record-keeping. Learn the framework and where on-chain monitoring fits.

What Is Crypto Address Risk Screening: The Four-Step Mechanism Explained

What Is Crypto Address Risk Screening: The Four-Step Mechanism Explained

Crypto address risk screening evaluates a wallet address for AML and CFT risk in a single pass. Learn the four-step mechanism, six risk levels, and seventeen risk indicators that shape the output.

What Is Illicit Crypto and How Is It Flagged: A Compliance Primer

What Is Illicit Crypto and How Is It Flagged: A Compliance Primer

Illicit crypto is cryptocurrency tied to crime or sanctioned entities. Learn the two categories, three flagging layers, and why detection must be continuous.

What Is Anti-Money Laundering (AML)? The Five-Pillar Framework Explained

What Is Anti-Money Laundering (AML)? The Five-Pillar Framework Explained

Anti-money laundering (AML) is the framework institutions use to detect, block, and report illicit funds. Learn AML and the FinCEN BSA five-pillar program.

What Is Enhanced Due Diligence (EDD) for Crypto Addresses: Triggers, Process, and Documents

What Is Enhanced Due Diligence (EDD) for Crypto Addresses: Triggers, Process, and Documents

Enhanced Due Diligence (EDD) is the heightened AML check a VASP runs on a high-risk crypto address. Learn what EDD is, what triggers it, the document checklist, and where on-chain risk evidence fits.

Define Money Laundering: The Legal Definition Under 18 U.S.C. §1956

Define Money Laundering: The Legal Definition Under 18 U.S.C. §1956

Money laundering is defined under 18 U.S.C. §1956 as knowingly conducting a financial transaction involving proceeds of a specified unlawful activity with intent to conceal, promote, or evade reporting. Learn the three offense types and four elements.

OTC Desk USDT Freeze Playbook: SLA + Response
Knowledge

OTC Desk USDT Freeze Playbook: SLA + Response

A field playbook for OTC desks handling USDT: why OTC desks are uniquely exposed to Tether freeze risk (bilateral settlement, T+0 timelines, reputation cost), pre-transaction address screening with sub-5-second SLA, real-time webhook monitoring for freeze events on active addresses, a post-freeze response playbook, and a compliance program checklist. Written for compliance officers at OTC desks operating on the Tron rail, where 2,116 of 2026 H1's roughly 2,500 total USDT freezes occurred.

How Tether Burns USDT and Reissues to Victims
Knowledge

How Tether Burns USDT and Reissues to Victims

A code-level walkthrough of Tether's `destroyBlackFunds` function: what it does on-chain, who can call it, why 55.6% of blacklisted USDT value ($698M in 2025) was destroyed via this mechanism, and how the burn is typically paired with a fresh mint of equivalent USDT to a court-designated or victim address — the 'burn-and-reissue' recovery primitive. Includes actual Solidity code from the USDT contract, official recovery policy details, and 2026 case studies (April $344M Iran freeze, Drift Protocol $148M victim recovery).

USDT Freeze Explained: How Tether Blocks Any Address (2026)
Knowledge

USDT Freeze Explained: How Tether Blocks Any Address (2026)

As of 2026-07-26, Tether has blacklisted 9,597 USDT addresses and frozen $5.69 billion via the USDT smart contract's freeze mechanic. This 2026 pillar guide covers how freezes work on-chain, why Tether freezes addresses (with 2026 case data from the $344M April Iran seizure to the $131M July Operation Economic Fury freeze, and roughly $1B cumulative Iran-linked seizures since the campaign began), how the multisig-delay window opens a documented escape channel (BlockSec's analysis of 8,310 executed freeze proposals recorded $215.5M moved out during the delay), what 'destroyed' USDT really means for victims (burn-and-reissue mechanism), whether frozen addresses can be unfrozen (3.6% do get removed), and how to build compliance around freeze risk.

How to Check if a USDT Address Is Frozen (Free 30s)
Knowledge

How to Check if a USDT Address Is Frozen (Free 30s)

A step-by-step guide to checking any USDT address for a freeze in under 30 seconds. Covers the free BlockSec USDT Freeze Checker workflow, alternative direct-query methods via Etherscan and Tronscan, what "frozen" actually means on-chain (versus destroyed, versus unfrozen), and the three scenarios where checking matters most: after receipt, before sending, and for pre-transaction due diligence.

Secure your digital assets now with BlockSec's full-stack security services