Back to Blog

ポプシクル・ファイナンス攻撃の模倣者たち

Code Auditing
August 9, 2021

当社のシステムは、SorbettoFragolaコントラクトの「collectFees(0,0)」を呼び出すトランザクションをいくつか検出しました。その中には、(0xcd7dae143a4c0223349c16237ce4cd7696b1638d116a72755231ede872ab70fc) と同様の攻撃を仕掛けようとする模倣者も含まれています。幸いなことに、プール内のトークン数は限られています。

“2021–08–04T12:17:27Z” : [ “0xfdeb455027202aa1e82e0eef85075870db0fb4a2427e81bc3a01973024923c39” ],

“2021–08–07T07:33:36Z” : [ “0xdb5303b6e5aa0148bdd31fd5c51319243940755e956002b820033b1eba602ef6” ],

“2021–08–03T22:53:42Z” : [ “0xcd7dae143a4c0223349c16237ce4cd7696b1638d116a72755231ede872ab70fc” ],

“2021–07–21T22:06:24Z” : [ “0x631cdd776ceeb062a6c71ebddd7357a5d873182446382c03bd8abaf85deb69e4” ],

“2021–08–04T11:01:18Z” : [ “0xa4430da5cc039b84213b44e4ca6ade9750fab987fbab3da27a11bbd0c7d23ee6” ],

“2021–08–05T14:46:05Z” : [ “0xf7d36fff17b56d5396539c8573ffeb8abd4b67ee22f4a7c492f2bd0ddfba8272” ],

“2021–08–06T11:26:57Z” : [ “0xb25e3f872896a0fde22ce60b57553b5304aa4584c47bdb293589bdbd3317de65” ],

“2021–08–05T11:52:23Z” : [ “0x1af887449dac564272fa15a8d91012759e40c1356b6ffcd5c88d2ac50c8c8502” ],

“2021–08–04T10:22:49Z” : [ “0xe86742e4c6831c6a46278d9a0143adbc8885a6f56191c52045e775ee22f870b0” ],

“2021–08–02T05:36:13Z” : [ “0x2016024bcb3ab283f367dfb34fced088db170c3c6cd026aa9f5c968654fd0142” ],

“2021–07–31T01:56:50Z” : [ “0xf34d0039dc0b20174e77cec510d7a094a2e81b4161a2a537de95b1fd089ae6f9” ],

“2021–08–06T07:34:22Z” : [ “0x2810a6f9f158c4e463e165e0aee6fecb1e617295e2215e015ee03d7265bd1e5a” ],

“2021–08–04T08:39:46Z” : [ “0xcc5a321ac3897beae976bceeeb651fa62f9975df90dd6431e73a8416bdf723b9” ]

BlockSecについて

BlockSecは、世界的に著名なセキュリティ専門家グループによって2021年に設立された、先駆的なブロックチェーンセキュリティ企業です。当社は、Web3の世界の普及を促進するため、セキュリティとユーザビリティの向上に尽力しています。そのために、BlockSecはスマートコントラクトおよびEVMチェーンのセキュリティ監査サービス、セキュリティ開発と脅威のプロアクティブなブロックのためのPhalconプラットフォーム、資金追跡および調査のためのMetaSleuthプラットフォーム、そしてWeb3ビルダーが仮想通貨の世界を効率的にサーフィンするためのMetaSuites拡張機能を提供しています。

現在までに、MetaMask、Uniswap Foundation、Compound、Forta、PancakeSwapなど300社を超える著名なクライアントにサービスを提供し、Matrix Partners、Vitalbridge Capital、Fenbushi Capitalを含む有力な投資家から2回の資金調達で数千万米ドルを受け入れています。

公式ウェブサイト: https://blocksec.com/

公式Twitterアカウント: https://twitter.com/BlockSecTeam

Sign up for the latest updates
Tether Freezes $6.76M USDT Linked to Iran's IRGC & Houthi Forces: Why On-Chain Compliance is Now a Geopolitical Battlefield
Security Insights

Tether Freezes $6.76M USDT Linked to Iran's IRGC & Houthi Forces: Why On-Chain Compliance is Now a Geopolitical Battlefield

Looking ahead, targeted freezing events like this $6.76M USDT action will only become more common. On-chain data analysis is improving. Stablecoin issuers are also working closely with regulators. As a result, hidden illicit financial networks will be exposed.

Weekly Web3 Security Incident Roundup | Mar 2 – Mar 8, 2026
Security Insights

Weekly Web3 Security Incident Roundup | Mar 2 – Mar 8, 2026

During the week of March 2 to March 8, 2026, seven blockchain security incidents were reported with total losses of ~$3.25M. The incidents occurred across Base, BNB Chain, and Ethereum, exposing critical vulnerabilities in smart contract business logic, token deflationary mechanics, and asset price manipulation. The primary causes included a double-minting logic flaw during full token deposits that allowed an attacker to exponentially inflate their balances through repeated burn-and-mint cycles, a price manipulation vulnerability in an AMM-based lending market where artificially inflated vault shares created divergent price anchors to incorrectly force healthy positions into liquidation, and a flawed access control implementation relying on trivially spoofed contract interfaces that enabled attackers to bypass authorization to batch-mint and dump arbitrary tokens.

Weekly Web3 Security Incident Roundup | Feb 23 – Mar 1, 2026
Security Insights

Weekly Web3 Security Incident Roundup | Feb 23 – Mar 1, 2026

During the week of February 23 to March 1, 2026, seven blockchain security incidents were reported with total losses of ~$13M. The incidents affected multiple protocols, exposing critical weaknesses in oracle design/configuration, cryptographic verification, and core business logic. The primary drivers included oracle manipulation/misconfiguration that led to the largest loss at YieldBloxDAO (~$10M), a crypto-proof verification flaw that enabled the FOOMCASH (~$2.26M) exploit, and additional token design and logic errors impacting Ploutos, LAXO, STO, HedgePay, and an unknown contract, underscoring the need for rigorous audits and continuous monitoring across all protocol layers.