
Securing the core foundation of Web3 from blockchain execution layers and custom VMs to complex wallet ecosystems.




Define the audit scope based on your finalized codebase and design documentation. A detailed quotation will be prepared, tailored to the project's complexity and specific requirements. A non-disclosure agreement (NDA) can be signed if required.




Scope & Quotation
Define the audit scope based on your finalized codebase and design documentation. A detailed quotation will be prepared, tailored to the project's complexity and specific requirements. A non-disclosure agreement (NDA) can be signed if required.

Agreement & Scheduling
Confirm project terms, including payment details and a clear audit timeline with defined start and end dates.

Security Audit & Fix Review
Conduct a comprehensive security audit using advanced in-house tools (customized when necessary). Findings are shared and discussed with the customer, and corresponding fixes are reviewed. For complex projects, multiple audit-review rounds may be required.

Deliverables & Strategic Recommendations
Deliver a professionally signed report detailing all findings, risk assessments, and actionable remediation recommendations.

Our audits combine deep protocol understanding with proprietary in-house tools and advanced analysis methodologies to ensure complete coverage.

~$39.5M Lost: Allbridge, Wanchain & More | BlockSec Weekly
During the week of July 20-26, 2026, 8 notable security incidents resulted in approximately $39.5M in total losses across Solana, Ethereum, BNB Chain, Arbitrum, Zilliqa, and Cardano. The highlighted Allbridge Core incident (~$1.65M) exposed a Solana input validation flaw where the same Pool account was accepted in both swap roles, with analysis reconstructed entirely from the deployed program binary. Other analyzed incidents include Wanchain (~$500K, flawed message encoding in a Cardano bridge validator), Zilliqa (~$400K, flawed nonce generation in a Ledger app since 2019), and Lien Finance (~$542K, flawed validation logic in bond exchange).

Top 10 "Awesome" Security Incidents in 2025
To help the community learn from what happened, BlockSec selected ten incidents that stood out most this year. These cases were chosen not only for the scale of loss, but also for the distinct techniques involved, the unexpected twists in execution, and the new or underexplored attack surfaces they revealed.
Newsletter - December 2025
In December 2025, the DeFi sector encountered three significant security incidents, resulting in total losses of approximately $19.7 million. Yearn Finance faced nearly $10 million in losses due to vulnerabilities in its yETH pool and legacy contracts. Trust Wallet suffered a malicious backdoor attack on its Chrome extension, leading to losses of about $7 million. Ribbon Finance experienced a loss of $2.7 million due to improper access controls.