# BlockSec Website Index This file contains an index of pages and blog posts from blocksec.com ## About BlockSec BlockSec is the leading full-stack blockchain security and compliance provider, dedicated to ensuring a secure and seamless Web3 world. Established in 2021 by globally distinguished security experts, BlockSec offers end-to-end Web3 protection from pre-launch to post-launch, trusted by global enterprises and institutions. **Key Statistics:** - Assets Protected: $50B+ - Global Clients: 500+ - Hacks Blocked: 20+ - Funds Rescued: $20M+ BlockSec serves over 500 esteemed clients including MetaMask, Uniswap Foundation, Compound, Forta, and PancakeSwap, and has received tens of millions of US dollars in funding from preeminent investors including Matrix Partners, Vitalbridge Capital, and Fenbushi Capital. ## Products & Services BlockSec provides a comprehensive suite of security and compliance solutions: **Security Auditing**: Smart contract and EVM chain audits covering technical, business, and financial aspects. Comprehensive audits for smart contracts and EVM chains with actionable solutions and trusted quality. **Phalcon Security**: Proactively detect threats, alert what matters, and block attacks in real-time. Features early detection at mempool stage, precise detection with 200+ attack characteristics, and automated actions using gas-bidding strategy to block attacks and prevent loss. **Phalcon Compliance**: Identify illicit activities, manage risks, and ensure alignment with global crypto AML/CFT standards. Provides transaction screening (KYT), address screening (KYA), and real-time AML/CFT screening with risk scoring. **STOP**: Sequencer-level defense platform for L2 chains, identifying and blocking malicious transactions to protect the ecosystem. **Phalcon Explorer**: Visualize, simulate, and debug on-chain transactions with an intuitive interface for advanced transaction analysis. **MetaSuites**: Enhance your blockchain explorer with 20+ integrated tools for advanced capabilities, supporting multiple blockchains including Solana. **Safe{wallet} Monitor**: Monitor Safe{wallet} transactions and provide security alerts for multi-sig wallet operations. **Research & Intelligence**: BlockSec conducts cutting-edge research in blockchain security, publishes security insights, and maintains a comprehensive security incident library. ## Pages [Home](https://blocksec.com): Safeguard your DeFi protocols with end-to-end Web3 security solutions. From smart contract audits to 24/7 threat monitoring, we detect risks, automate exploit prevention, and ensure compliance. [About Us](https://blocksec.com/about-us): We combine advanced security research with real-world experience in cyber defense and financial compliance. Meet the team at BlockSec. [Smart Contract Security Audits](https://blocksec.com/audit): Full-scope code review to fix all security issues in smart contracts. [Audit Reports](https://blocksec.com/audit-report): Discover BlockSec's audit services for protocols and blockchains. Find detailed audit reports for Radiant V2, Puffer pufETH, Magpie Radpie, Ref Exchange, EOS EVM and more. [Blockchain Bridge Audit](https://blocksec.com/blockchain-bridge-audit): Secure cross-chain crypto bridges with a blockchain bridge audit that delivers deep code review and security analysis to prevent exploits and asset loss. [Blockchain Security Audit](https://blocksec.com/blockchain-security-audit): Our comprehensive blockchain security audit rigorously verifies your DApp's underlying logic. This eliminates critical vulnerabilities, ensuring a robust protocol that meets elite industry benchmarks. [In-Depth Web3 Security Insights](https://blocksec.com/blog): Explore our blog for the latest on security incidents, root cause analysis, and updates on Web3 events and product developments. [Certificate Verification](https://blocksec.com/certificate-verification): Verify the authenticity of certificates issued by BlockSec training programs. Ensure the credential is valid and officially recognized by BlockSec. [Blockchain Infrastructure Audit](https://blocksec.com/chain-audit): Strengthen the reliability and resilience of your blockchain infrastructure. [Crypto Payment Compliance: Crypto AML/CFT, KYT/KYA Guide](https://blocksec.com/compliance-handbook): Download BlockSec's handbook on our form. Grasp Crypto AML/CFT rules, KYT/KYA methods, and safeguard your Web3 project from compliance risks. [BlockSec 2025 Crypto Crime Report](https://blocksec.com/crypto-crime-report): Download BlockSec's Crypto Crime Report on our form. Know the big picture of cryptocurrency crime in 2025. It also covers the main features, structure, and trends in this field. [Customers & Partners](https://blocksec.com/customers): BlockSec proudly serves a diverse clients and forms strategic partnerships with leading protocols, blockchains, exchanges, and liquidity providers. [Dapp Security Audit](https://blocksec.com/dapp-security-audit): We conduct deep-dive dapp security audit to scrutinize every layer of your DApp's logic. This delivers a battle-tested, reliable protocol aligned with the highest security standards. [Important Disclaimer on Third-Party Software Risks](https://blocksec.com/disclaimer): Explore BlockSec's disclaimer on third-party software risks. Understand potential dangers before downloading software. Your safety first! [Verify Employee Contact](https://blocksec.com/employee-verification): Confirm if the person contacting you is a verified BlockSec employee. Stay safe from scams and unauthorized communications. [Ethereum Smart Contract Audit](https://blocksec.com/ethereum-smart-contract-audit): Make Your DApp Strong and Safe. Use our Ethereum smart contract audit to fix logic errors. We ensure your code works perfectly and meets the top safety standards in the industry. [Talk to Blockchain Security Experts - Custom Plans](https://blocksec.com/expert-contact): Connect with BlockSec's team for security audits, enhanced hack prevention and crypto AML services. Trusted for securing billions in crypto. [Guides | Crypto Compliance, Security, Audits & Risk Intelligence by BlockSec](https://blocksec.com/guides): Explore expert guides on crypto compliance, security audits, illicit fund detection, risk intelligence, and more. Access resources across the crypto ecosystem with BlockSec. [MetaSuites (formerly MetaDock): The Builder's Swiss Army Knife by BlockSec](https://blocksec.com/metasuites): Generate fund flow, display address labels, download data with one click, simulate transactions, view storage, and proxy upgrades on over ten blockchain explorers. [Latest in Web3 Security Updates](https://blocksec.com/newsroom): Stay informed with BlockSec's newsroom: your source for the latest media coverage on our security analysis, collaborations, and product updates. [Arbitrum Explorer for Higher-level Execution](https://blocksec.com/phalcon/arbitrum-explorer): An advanced Arbitrum Explorer built for you to understand what really happens inside optimistic rollup transactions. [Avalanche Explorer for High-Throughput Multi-Chain Execution and Transactions](https://blocksec.com/phalcon/avalanche-explorer): An advanced and well-designed Avalanche Explorer built for you to understand what really happens on a fast, multi-chain network. [Base Explorer for Deep-Dive Transactions Analyses](https://blocksec.com/phalcon/base-explorer): A professional, investigation-grade Base explorer built for you to trace real transactions on a Coinbase-backed OP Stack chain and understand how Base transactions actually behave. [Blockchain Compliance](https://blocksec.com/phalcon/blockchain-compliance): Achieve blockchain compliance with real-time blockchain risk management, wallet screening, and ensure AML/CFT regulatory adherence. [Phalcon Explorer](https://blocksec.com/phalcon/blockchain-explorer): A professional, investigation-grade blockchain explorer, allowing you to delve into transactions and act wisely [Blockchain Security Services](https://blocksec.com/phalcon/blockchain-security-services): BlockSec stops web3 threats before they do any damage with the most accurate real-time advanced warning system and connection to automated onchain actions. [Blockchain Security Software](https://blocksec.com/phalcon/blockchain-security-software): Institutional-grade Web3 security platform protecting protocols and L1/L2 chains. Stop Web3 hacks before they cause damage. [BSC Explorer for Real Transaction Insight](https://blocksec.com/phalcon/bsc-explorer): Analyze real BSC execution with invocation flow, fund flow, balance and state changes, plus simulator and debugger. Search any BSC transaction or address. [Crypto Compliance](https://blocksec.com/phalcon/compliance): Achieve crypto compliance with real-time blockchain risk management, wallet screening, and ensure AML/CFT regulatory adherence. [Crypto AML Compliance](https://blocksec.com/phalcon/crypto-aml-compliance): Achieve crypto AML compliance with real-time blockchain risk management, wallet screening, and detect threats early. [Crypto Address Screening & Transaction Monitoring - Phalcon Compliance](https://blocksec.com/phalcon/crypto-compliance): Comprehensive compliance solution for VASPs: address screening, real-time transaction monitoring, and one-click STR generation to combat illicit activities, financial crime, and ensure AML/CFT regulatory adherence. [Crypto Wallet Screening](https://blocksec.com/phalcon/crypto-wallet-screening): BlockSec Crypto Wallet Screening detects and blocks risky wallets instantly to safeguard crypto operations, build a better customer experience, and detect threats early. [Ethereum Explorer for Deep Transaction Analysis](https://blocksec.com/phalcon/ethereum-explorer): A professional Ethereum Explorer that reveals invocation flow, fund flow, balance changes, state updates, and execution behavior through built-in simulation and debugging. [Dive into Transaction to Act Wisely](https://blocksec.com/phalcon/explorer): Phalcon Explorer helps developers, traders, and researchers understand complicated transactions to make better decisions. It supports ETH, BNB Chain, Arbitrum, Polygon, and more. [Gnosis Explorer for DAO-Native Execution and In-Depth Transaction Analyses](https://blocksec.com/phalcon/gnosis-explorer): A trustworthy Gnosis Explorer built for you to track DAO transactions and governance execution with real clarity. [Hyperliquid Explorer for Order-Driven Trading](https://blocksec.com/phalcon/hyperliquid-explorer): A sophisticated Hyperliquid Explorer built for you to see what really happens on a high-speed, order-driven trading system running on HyperEVM. [KYT Compliance](https://blocksec.com/phalcon/kyt-compliance): Achieve KYT compliance with real-time blockchain risk management, wallet screening, and ensure AML/CFT regulatory adherence. [A Sophisticated Linea Explorer for Deep-Dive Transaction Analysis](https://blocksec.com/phalcon/linea-explorer): A pivotal toolkit built for you to follow zkEVM execution flow, track internal calls and asset movement, and make safe decisions on Linea with full confidence. [Manta Explorer for Modular Execution and Deep Analyses](https://blocksec.com/phalcon/manta-explorer): An Advanced Manta Explorer, built for you to track Manta transactions in full details. [Mantle Explorer for Native Execution Insight](https://blocksec.com/phalcon/mantle-explorer): An investigation-grade mantle explorer, built for you to follow modular transactions in full details and make confident decisions. [Monad Explorer for Detailed Transaction Analyses](https://blocksec.com/phalcon/monad-explorer): An advanced Monad Explorer built for you to see what really happens on a high-speed, parallel EVM chain. [Phalcon Network | Real-Time Crypto Crime Response Network](https://blocksec.com/phalcon/network): Join the industry’s public intelligence network from BlockSec. Get real-time alerts and stop illicit transactions before they happen. Sign up today. [Optimism Explorer Built for In-Depth Transaction Analyses](https://blocksec.com/phalcon/optimism-explorer): A High-Performance Optimism Explorer, built for you to trace EVM execution in full details and understand how Optimism transactions really work. [Plasma Explorer for In-Depth Transaction Analysis](https://blocksec.com/phalcon/plasma-explorer): A high-performance Plasma Explorer built for you to trace EVM execution in full details and understand how Plasma transactions really work. [Polygon Explorer for High-Volume On-Chain Activities](https://blocksec.com/phalcon/polygon-explorer): An advanced Polygon Explorer built for you to understand what really happens on a fast, low-cost, and highly interactive EVM chain. [Scroll Explorer for zkEVM-Equivalent Execution and Advanced Transaction Analyses](https://blocksec.com/phalcon/scroll-explorer): A sophisticated Scroll Explorer, built for you to see how Ethereum-level execution really works and how transaction details unfold on Scroll. [A Platform to Monitor and Block Hacks](https://blocksec.com/phalcon/security): Phalcon helps protocols, liquidity providers/traders, L1/L2 Chains, and exchanges detect attacks, get instant alerts, and take automatic actions. [Sepolia Explorer Built for Further Transaction Analyses on Ethereum Testnet](https://blocksec.com/phalcon/sepolia-explorer): A focused Sepolia Explorer built to help you follow real Ethereum testnet execution and understand how transactions behave before they moves to mainnet deployment. [Solana Blockchain Explorer for Instruction-Level Execution](https://blocksec.com/phalcon/solana-blockchain-explorer): See how Solana transactions really run. Follow invocation flow, track fund movement across accounts, and view clear balance changes to make fast, confident decisions. [Privacy Policy](https://blocksec.com/privacy-policy): BlockSec webpage inquiries & submission privacy policy. [Frontier of Blockchain Security](https://blocksec.com/research): Explore BlockSec's cutting-edge blockchain security research featured at top conferences like ISSTA, ACM TOSEM, USENIX Security, and more. [Rust Smart Contract Audit](https://blocksec.com/rust-smart-contract-audit): Build Logic You Can Trust. Don't let bugs break your DApp. Our Rust smart contract audit checks your core rules to make sure they are reliable and follow the best security practices. [Safe{Wallet} Security Monitor](https://blocksec.com/safe-wallet-monitor): Simulates the outcome of transactions while alerting you to associated risks at each step of initiation, signing, and execution. Our solution helps ensures robust protection for your Safe{Wallet}. [Crypto Security Incidents Library](https://blocksec.com/security-incident): Find major blockchain attack cases, learn key vulnerabilities and root causes, and arm yourself with the knowledge to enhance your project’s protection. [Smart Contract Audit](https://blocksec.com/smart-contract-audit): Our thorough smart contract audit dives deep into your DApp's core architecture. This ensures a battle-tested protocol that aligns with the highest global security standards. [Solana Audit](https://blocksec.com/solana-audit): Verify that your Solana DApp's program logic is secure, dependable, and built to meet strict security expectations across the ecosystem. [Solidity Audit](https://blocksec.com/solidity-audit): Make your investors feel safe and make your code work better. We use a proven plan to check your Solidity smart contracts and fix any problems before you launch. [Centralized Exchange Solutions](https://blocksec.com/solutions/centralized-exchanges): BlockSec protects your exchange at every level: vet new listings, monitor core assets, and ensure global compliance. [Crypto Payment Solutions](https://blocksec.com/solutions/crypto-payment): BlockSec protects illicit funds in real-time and meets global compliance standards, building trust in every transaction. [DeFi Protocol Solutions](https://blocksec.com/solutions/defi-protocols): BlockSec secures your code pre-launch and blocks attacks in real-time, safeguarding both user assets and your reputation. [L1/L2 Chain Solutions](https://blocksec.com/solutions/l1l2-chain): BlockSec protects your infrastructure before launch, and blocks attacks at the source to shield your ecosystem and reputation. [RWA Solutions](https://blocksec.com/solutions/rwa): BlockSec builds investor trust and secures your platform at every layer: audit your tokenization contracts, screen every transaction, and protect your treasury. [Stablecoin Issuer Solutions](https://blocksec.com/solutions/stablecoin-issuer): BlockSec secures your contracts pre-launch and monitors transactions in real-time, safeguarding both asset stability and regulatory trust. [Stablecoin Issuer Freeze Risk Whitepaper](https://blocksec.com/stablecoin-freeze-risk-whitepaper): Download BlockSec’s whitepaper on stablecoin issuer freeze risk. Learn the four freeze triggers, why self-custody isn’t enough, how treasuries get tainted, and how to respond and speed up recovery. [STOP Attacks at L2 Sequencer Level - Phalcon STOP](https://blocksec.com/stop): The Sequencer Threat Overwatch Program (STOP) utilizes Phalcon's detection engine to prevent attacks for L2 chains at the sequencer level, ensuring users engage securely and confidently. [Terms of Service](https://blocksec.com/terms-of-service): BlockSec webpage inquiries & submission terms of service. [Web3 Audit](https://blocksec.com/web3-audit): Secure your DApp with our deep-dive web3 audit and architectural verification. Gain a battle-tested codebase that guarantees reliability and full compliance with industry standards. ## Audit Reports [Security Audit Report for Alpaca Delta Neutral Vault](https://blocksec.com/audit-report/security-audit-report-for-alpaca-delta-neutral-vault): The Alpaca Finance is a leveraged yield farming and liquidity providing protocol running on Binance Smart Chain (BSC) and Fantom. [Security Audit Report for Aura](https://blocksec.com/audit-report/security-audit-report-for-aura): Aura Network is a high performance Layer1 ecosystem with built-in modularity, leading the mass adoption of Web3 in emerging markets. [Security Audit Report for Bitget's bgw-swap-aggregator-evm](https://blocksec.com/audit-report/audit-report-bitget-s-bgw-swap-aggregator-evm): BWAggregator is a DEX aggregator that enables swaps across Uniswap and its fork protocols through specialized router and handler actions. [Security Audit Report for Bitway Labs's Bitway App Chain](https://blocksec.com/audit-report/audit-report-bitway-labs-s-bitway-app-chain): The Bitway App Chain of the Bitway Lab is a L1 blockchain, facilitating to unlock the value of underutilized Bitcoins. To support full Bitcoin compatibilities, the Bitway App Chain is designed to… [Security Audit Report for BridgeV2 Contracts](https://blocksec.com/audit-report/security-audit-report-for-bridge-v2-contracts): Spherium Bridge utilizes LayerZero framework to bridge tokens from source chain to target chain. [Security Audit Report for BurrowLand](https://blocksec.com/audit-report/security-audit-report-for-burrow-land): Burrowland is a decentralized lending and borrowing platform based on the NEAR blockchain. Burrowland allows users to lend tokens and earn interest, as well as borrow tokens by providing collateral… [Security Audit Report for Cakepie Contracts](https://blocksec.com/audit-report/security-audit-report-for-cakepie-contracts): Cakepie is a yield optimization protocol built upon PancakeSwap. It enables users to manage PancakeSwap V2/V3 positions and claim rewards and convert their CAKE token or locked CAKE positions from… [Security Audit Report for DeltaTrade](https://blocksec.com/audit-report/security-audit-report-for-delta-trade): DeltaTrade is a multi-chain decentralized trading protocol that enhances user capabilities with sophisticated on-chain trading strategies such as Grid Trading, DCA, Rebalancing Grid, MultiChain… [Security Audit Report for EOS EVM](https://blocksec.com/audit-report/security-audit-report-for-eos-evm): The EOS EVM serves as an implementation of the Ethereum Virtual Machine (EVM). It is implemented in C++ and compiled to a WASM binary to be executed within the EOS blockchain. [Security Audit Report for Halo](https://blocksec.com/audit-report/security-audit-report-for-halo): Halo is a social monetization platform for the AI era. Earn passive rewards from posts, transactions, and engagements with 1M+ pioneers. [Security Audit Report for LiNEAR](https://blocksec.com/audit-report/security-audit-report-for-li-near-1): LiNEAR Protocol is a liquid staking solution built on the NEAR Protocol. LiNEAR unlocks liquidity of the staked NEAR by creating a staking derivative to be engaged with various DeFi protocols on NEAR… [Security Audit Report for Lista's Lista Lending](https://blocksec.com/audit-report/audit-report-lista-s-lista-lending): This audit focuses on the smart contracts located in the src/folder of the repository, excluding the following directories: src/moolah/mocks/* src/moolah-vault/mocks/* src/vault-allocator/mocks/* [Security Audit Report for Magpie Radpie](https://blocksec.com/audit-report/security-audit-report-for-magpie-radpie): Magpie launched Radpie, a yield optimization protocol built upon Radiant. Users could deposit their assets on Radpie to earn enhanced yields. [Security Audit Report for Mantle's Fiat24 Contracts](https://blocksec.com/audit-report/audit-report-mantle-s-fiat24-contracts): Fiat24 is a digital banking platform built on blockchain technology that bridges banking services with the crypto ecosystem. [Security Audit Report for Mellow Vaults](https://blocksec.com/audit-report/security-audit-report-for-mellow-vaults): The Mellow project provides an open platform for liquidity providers to earn rewards from their liquidities and strategists to earn performance fees by implementing active liquidity management… [Security Audit Report for Morph Emerald upgrade](https://blocksec.com/audit-report/audit-report-morph-emerald-upgrade): The target of this audit is the code repositories of Morph Emerald upgrade. The Morph Emerald upgrade introduces alternative fee transactions, enabling native multi-token gas payments on the Morph L2… [Security Audit Report for Multichain veMULTI Contracts](https://blocksec.com/audit-report/security-audit-report-for-multichain-ve-multi-contracts): Multichain is the ultimate Router for web3. It is an infrastructure developed for arbitrary cross-chain interactions. [Security Audit Report for Neo X](https://blocksec.com/audit-report/audit-report-neo-x): Neo X is an EVM compatible sidechain incorporating Neo’s distinctive dBFT consensus mechanism. Serving as a bridge between Neo N3 and the widely used EVM network, Neo X will play a crucial role in… [Security Audit Report for Noah-DAO](https://blocksec.com/audit-report/security-audit-report-for-noah-dao): Noah DAO is a decentralized exchange built on the EOS EVM. It introduces a mechanism to incentivize liquidity provision and active governance participation by rewarding users with protocol tokens and… [Security Audit Report for Octopus Restaking](https://blocksec.com/audit-report/security-audit-report-for-octopus-restaking): The NEAR Restaking project is launched by Octopus Team, and aims at enhancing the utilization of NEAR. Any user can deposit NEAR assets into the Restaking protocol, which provides proof of stake to… [Security Audit Report for OKX's OKX Smart Wallet](https://blocksec.com/audit-report/audit-report-okx-s-okx-smart-wallet): The project implements an Account Abstraction (AA) wallet implementation on the Ethereum Virtual Machine (EVM) compatible chains, allowing users to deploy AA smart contract wallets. [Security Audit Report for OKX's Smart Wallet Recovery](https://blocksec.com/audit-report/audit-report-okx-s-smart-wallet-recovery): The project implements a cross-chain recovery system for unified smart accounts, focusing on the Ethereum Virtual Machine (EVM) stack implementation. [Security Audit Report for OKX's smart-wallet-recovery & groth16-solana](https://blocksec.com/audit-report/audit-report-okx-s-smart-wallet-recovery----groth16-solana): This project is a smart account recovery system deployed on Solana. It combines ZK-Email zero-knowledge proofs, ECDSA signature verification, and a DKIM registry to provide scalable, low-interaction… [Security Audit Report for PancakeSwap Cross Farming Contracts](https://blocksec.com/audit-report/security-audit-report-for-pancake-swap-cross-farming-contracts): PancakeSwap launched a cross farming project. It involves allowing users to deposit LP tokens on EVM-compatible chains to the MasterChefV2 contract on the Binance Smart Chain network using the cBridge… [Security Audit Report for PancakeSwap VECake](https://blocksec.com/audit-report/security-audit-report-for-pancake-swap-ve-cake): Pancake launched a governance project VECake for voting. VECake enables users to acquire voting powers by depositing their CAKE tokens. [Security Audit Report for Phoenix Bonds](https://blocksec.com/audit-report/security-audit-report-for-phoenix-bonds): Phoenix Bonds is a principal-protected bonding platform that helps protocols with liquidity-bootstrapping, provides perpetually-boosted yield to users and works with all yield bearing assets. [Security Audit Report for Poly Contracts](https://blocksec.com/audit-report/security-audit-report-for-poly-contracts): Poly Network is a global cross-chain protocol for implementing blockchain interoperability and building Web3.0 infrastructure. [Security Audit Report for Puffer Finance pufETH Contracts](https://blocksec.com/audit-report/security-audit-report-for-puffer-finance-puf-eth-contracts): Puffer is a decentralized native liquid restaking protocol (nLRP) built on Eigenlayer. It makes native restaking on Eigenlayer more accessible, allowing anyone to run an Ethereum Proof of Stake (PoS)… [Security Audit Report for PumpBTC Contracts](https://blocksec.com/audit-report/security-audit-report-for-pump-btc-contracts): The audit focuses on PumpBTC Contracts, enabling users to stake Wrapped Bitcoin tokens into the PumpStaking contract and mint pumpBTC tokens at a 1:1 ratio. [Security Audit Report for Rabby Wallet's swap-router-v1](https://blocksec.com/audit-report/audit-report-rabby-wallet-s-swap-router-v1): The protocol is a decentralized exchange (DEX) router that facilitates efficient token swaps by integrating multiple aggregators through a flexible adapter pattern, while ensuring robust fee… [Security Audit Report for Ref Exchange](https://blocksec.com/audit-report/security-audit-report-for-ref-exchange): Ref-Exchange is a decentralized exchange (DEX) deployed on the NEAR blockchain by Ref Finance. The protocol implements different types of trading pairs based on token characteristics, such as simple… [Security Audit Report for Side Protocol](https://blocksec.com/audit-report/security-audit-report-for-side-protocol): Side Protocol serves as the extension layer of Bitcoin. At its core is Side Chain, the first high-performance, fully Bitcoin-compatible dPoS Layer 1 blockchain, designed to shape the future of Bitcoin… [Security Audit Report for SoSoValue Index](https://blocksec.com/audit-report/Security-Audit-Report-for-SoSoValue-Index): The SoSoValue Index Protocol is a cutting-edge spot index solution designed to make crypto investments simple and secured. [Security Audit Report for StakeTogether st-v1-contracts](https://blocksec.com/audit-report/security-audit-report-for-stake-together-st-v1-contracts): StakeTogether is an Ethereum staking protocol designed especially for communities. It allows users to deposit ETH into staking pools and receive stpETH tokens as collateral. [Security Audit Report for Stratos Chain and Stratos Decentralized Storage (SDS)](https://blocksec.com/audit-report/security-audit-report-for-stratos-chain-and-stratos-decentralized-storage-sds): Stratos is a decentralized data architecture. Stratos provides scalable, reliable, and self-balanced storage, database, and computation networks, creating a robust foundation for data processing. [Security Audit Report for WenCore](https://blocksec.com/audit-report/security-audit-report-for-wen-core): WEN Protocol is a decentralized, censorship-resistant, and community-owned protocol that enables users to secure loans using Liquidity Staking Derivatives (LSDs) as collateral. [Security Audit Report for Windranger Auction Contract](https://blocksec.com/audit-report/security-audit-report-for-windranger-auction-contract): Windranger facilitates the growth of mantle and web3 ecosystems by partnering with builders to architect extraordinary cultures globally. [Security Audit Report for YPool Smart Contract](https://blocksec.com/audit-report/security-audit-report-for-y-pool-smart-contract): XY Finance is a cross-chain interoperability protocol aggregating DEXs & Bridges. With the ultimate routing across multi-chains, borderless and seamless swapping is just one click away. [Security Testing Report for MegaETH: MegaEVM, Stateless Validator & SALT](https://blocksec.com/audit-report/audit-report-megaeth--megaevm--stateless-validator---salt): The security testing was conducted over a six-week period, from October 11, 2025 to November 28, 2025, and focused on: MegaETH EVM (MegaEVM), Small Authentication Large Trie (SALT), and Stateless… [Security Testing Report for Radiant V2](https://blocksec.com/audit-report/security-testing-report-for-radiant-v2): Radiant V2 is a cross-chain DeFi lending protocol developed by Radiant Capital. Radiant Capital has engaged us to perform security testing (as the red team) on the smart contracts of Radiant V2 to… ## Blog posts [Crypto Compliance Tools: A Practical Guide for Web3 and TradFi Integration](https://blocksec.com/blog/crypto-compliance-tools-web3-tradfi-guide): Manual audits can't keep up with on-chain throughput. See how Web3 and TradFi teams deploy KYA, KYT, AML scoring, and STR tools to stay compliant at scale. (May 28 2026) [How to Choose a Blockchain Compliance Platform Suitable for Your Business](https://blocksec.com/blog/how-to-choose-blockchain-compliance-platform): Stablecoins now move $36T a year, and so does illicit capital. Learn how to choose a blockchain compliance platform built for cross-chain AML at scale. (May 28 2026) [Crypto Compliance Software Guide: Technical Frameworks & Top Tools](https://blocksec.com/blog/crypto-compliance-software-guide): Sanctions lists keep expanding and MiCA is now in force. Learn how VASPs deploy crypto compliance software for KYA, KYT, and automated SAR reporting at scale. (May 28 2026) [~$104.6M Lost: Verus, RetoSwap & More | BlockSec Weekly](https://blocksec.com/blog/web3-security-verus-bridge-retoswap-more): ~$104.6M lost: Verus $11.7M bridge type-validation exploit, RetoSwap $2.7M arbitrator hijack on Monero, plus three key compromises totaling $90.2M. (May 27 2026) [BlockSec’s Retrospective on DeFi Protocol Security in 2023](https://blocksec.com/blog/blocksec-retrospective-on-defi-protocol-security-in-2023): New trends in DeFi protocol security in 2023 and BlockSec's perspective on how to secure DeFi protocols (May 27 2026) [#7: ParaSpace Incident: A Race Against Time to Thwart the Industry's Most Critical Attack Yet](https://blocksec.com/blog/7-para-space-incident-a-race-against-time-to-thwart-the-industry-s-most-critical-attack-yet): Discover how the ParaSpace attack exposed critical blockchain vulnerabilities and learn key mitigation strategies to protect your DeFi assets today. (May 25 2026) [Bybit $1.5B Hack: In-Depth Analysis of the Malicious Safe Wallet Upgrade Attack](https://blocksec.com/blog/bybit-1-5-b-hack-in-depth-analysis-of-the-malicious-safe-wallet-upgrade-attack): This blog offers a comprehensive technical breakdown of the attack process and essential security lessons for digital asset protection. Learn effective strategies to bolster blockchain security and prevent similar exploits. (May 25 2026) [BlockSec Phalcon 2.0 Unleashed: A New Era of Hack Prevention and Protocol Security Begins](https://blocksec.com/blog/blocksec-phalcon-2-0-unleashed-new-era-hack): Discover BlockSec Phalcon 2.0, the leading Web3 security platform for crypto hack prevention and protocol protection. Secure your blockchain now! (May 25 2026) [How the U.S. Traced $110M Crypto Money Laundering Cases](https://blocksec.com/blog/how-the-us-traced-110-m-crypto-money-laundering-cases-blocksec): Learn how U.S. authorities traced $110M in crypto money laundering tied to pig-butchering scams, and what BlockSec's on-chain analysis revealed about compliance gaps. (May 25 2026) [Blockchain Transaction Security Monitoring Tool with the Lowest False Positive Rate](https://blocksec.com/blog/blockchain-transaction-security-monitoring-tool-with-the-lowest-false-positive-rate): This article explains the importance of low false positive rates in hack monitoring systems and introduces Phalcon, a platform known for its accuracy in threat monitoring and attack-blocking capabilities. (May 25 2026) [BonqDAO Exploited on Polygon: $120M Stolen Due to Flawed Logic](https://blocksec.com/blog/bonq-dao-exploited-on-polygon-120-m-stolen-due-to-flawed-logic): BonqDAO on Polygon suffered a $120M attack due to flawed logic, resulting in significant losses and highlighting the importance of DeFi security. (May 25 2026) [Crypto Compliance for AI Agents: Build KYA/KYT with X402](https://blocksec.com/blog/agent-native-crypto-compliance-build-kya-kyt-with-x402): Learn how X402 lets AI agents run KYA/KYT compliance checks via per-request crypto payments—no API keys, no subscriptions. Build agent-native compliance today. (May 25 2026) [Basics of Blockchain legal Issues in 2026](https://blocksec.com/blog/basics-of-blockchain-legal-issues-in-2026): Blockchain legal issues can stall growth. Learn how to spot AML, sanctions, and fund flow risks in real time with one-click compliance reports. (May 25 2026) [~$4.72M Lost: TAC, Transit Finance & More | BlockSec Weekly](https://blocksec.com/blog/weekly-web3-security-roundup-2026-05-17): ~$4.72M lost: Transit Finance $1.88M legacy calldata exploit on TRON, TAC $2.8M bridge verification bypass on TON, Boost Hook $46.75K V4 spot price manipulation (May 19 2026) [~$15.9M Lost: Trusted Volumes, Wasabi & More | BlockSec Weekly](https://blocksec.com/blog/weekly-web3-security-roundup-2026-05-10): Trusted Volumes $5.87M RFQ authorization mismatch, Wasabi Protocol $5.7M infrastructure compromise, Aftermath Finance $1.14M signed/unsigned fee exploit. Full analysis inside. (May 17 2026) [Tether Freezes $6.76M USDT: On-Chain Compliance Explained](https://blocksec.com/blog/tether-freezes-6-76-m-usdt-linked-to-iran-s-irgc-and-houthi-forces-why-on-chain-compliance-is-now-a-geopolitical-battlefield): Tether freezes $6.76M USDT linked to IRGC-tied networks, spotlighting stricter 2026 stablecoin sanctions. See how real-time KYT blocks sanctioned funds. (May 8 2026) [6 Best Blockchain and Crypto Compliance Software Solutions](https://blocksec.com/blog/6-best-blockchain-and-crypto-compliance-software-solutions): Compare the best crypto compliance software in 2026. Block dirty money in real time, cut sanctions risk, and scale safely with fast KYT and multichain coverage. (May 8 2026) [Newsletter - January 2026](https://blocksec.com/blog/newsletter-january-2026): In January 2026, the DeFi ecosystem experienced three major security incidents. Truebit Protocol lost ~$26M due to an integer overflow vulnerability, SwapNet and Aperture suffered ~$17M from improper input validation and allowance abuse,… (May 3 2026) [Newsletter - April 2026](https://blocksec.com/blog/newsletter-april-2026): Top DeFi incidents in April 2026: learn how KelpDAO, Drift, and Rhea Finance lost $593M+ and what these exploits mean for DeFi security (Apr 30 2026) [~$7.04M Lost: GiddyDefi, Volo Vault & More | BlockSec Weekly](https://blocksec.com/blog/weekly-web3-security-roundup-2026-04-26): ~$7.04M lost: GiddyDefi $1.3M EIP-712 signature replay, Volo Vault $3.5M operator key leak, Purrlend $1.5M, SingularityFinance $413K oracle misconfig. (Apr 29 2026) [EigenLayer Restaking: Security Risks and How to Mitigate Them](https://blocksec.com/blog/examining-eigenlayer-restaking-security-perspective): EigenLayer's restaking model hit $15.3B TVL — but it introduces new security risks like malicious operators and AVS exploits. Learn the threats and how to defend against them. (Apr 24 2026) [The Decentralization Dilemma: Cascading Risk and Emergency Power in the KelpDAO Crisis](https://blocksec.com/blog/the-decentralization-dilemma-cascading-risk-and-emergency-power-in-the-kelp-dao-crisis): This BlockSec deep-dive analyzes the KelpDAO $290M rsETH cross-chain bridge exploit (April 18, 2026), attributed to the Lazarus Group, tracing a causal chain across three layers: how a single-point DVN dependency enabled the attack, how… (Apr 22 2026) [Weekly Web3 Security Incident Roundup | Apr 13 – Apr 19, 2026](https://blocksec.com/blog/weekly-web3-security-incident-roundup-apr-13-apr-19-2026): This BlockSec weekly security report covers four attack incidents detected between April 13 and April 19, 2026, across multiple chains such as Ethereum, Unichain, Arbitrum, and NEAR, with total estimated losses of approximately $310M. (Apr 22 2026) [Why Is Automated Incident Response Crucial in Web3 Security?](https://blocksec.com/blog/automated-incident-response-crucial-web3-security): Discover why automated incident response is essential for Web3 security. Learn how blockchain projects can quickly mitigate attacks and protect DeFi assets. (Apr 21 2026) [Weekly Web3 Security Incident Roundup | Apr 6 – Apr 12, 2026](https://blocksec.com/blog/weekly-web3-security-incident-roundup-apr-6-apr-12-2026): This BlockSec weekly security report covers four DeFi attack incidents detected between April 6 and April 12, 2026, across Linea, BNB Chain, Arbitrum, Optimism, Avalanche, and Base, with total estimated losses of approximately $928.6K. (Apr 16 2026) [Weekly Web3 Security Incident Roundup | Mar 30 – Apr 5, 2026](https://blocksec.com/blog/weekly-web3-security-incident-roundup-mar-30-apr-5-2026): This BlockSec weekly security report covers nine DeFi attack incidents detected between March 30 and April 5, 2026, across Solana, BNB Chain, Arbitrum, and Polygon, with total estimated losses of approximately $287M. (Apr 9 2026) [Tracing $1.6B in TRON USDT: Inside the VerilyHK Ponzi Infrastructure](https://blocksec.com/blog/tracing-16-b-in-tron-usdt-inside-the-verily-hk-ponzi-infrastructure): An on-chain investigation into VerilyHK, a fraudulent platform that moved $1.6B in TRON USDT through a multi-layered fund-routing infrastructure of rotating wallets, paired payout channels, and exchange exit funnels, with traced connections… (Apr 8 2026) [Drift Protocol Incident: Multisig Governance Compromise via Durable Nonce Exploitation](https://blocksec.com/blog/drift-protocol-incident-multisig-governance-compromise-via-durable-nonce-exploitation): On April 1, 2026 (UTC), Drift Protocol on Solana suffered a $285.3M loss after an attacker exploited Solana's durable nonce mechanism to delay the execution of phished multisig approvals, ultimately transferring administrative control of… (Apr 3 2026) [Weekly Web3 Security Incident Roundup | Mar 23 – Mar 29, 2026](https://blocksec.com/blog/weekly-web3-security-incident-roundup-mar-23-mar-29-2026): This BlockSec weekly security report covers eight DeFi attack incidents detected between March 23 and March 29, 2026, across Ethereum and BNB Chain, with total estimated losses of approximately $1.53M. (Apr 2 2026) [Newsletter - March 2026](https://blocksec.com/blog/newsletter-march-2026): In March 2026, the DeFi ecosystem experienced three major security incidents. Resolv Protocol lost ~$80M due to compromised privileged infrastructure keys, BitcoinReserveOffering suffered ~$2.7M from a double-minting logic flaw, and Venus… (Apr 1 2026) [FATF Stablecoin Report: A Shift to Secondary-Market Compliance](https://blocksec.com/blog/fatf-s-new-stablecoin-report-signals-a-shift-to-secondary-market-compliance): FATF's March 2026 report targets P2P stablecoin risks via unhosted wallets. Learn the key AML/CFT recommendations and how on-chain monitoring tools can help you stay compliant. (Mar 27 2026) [MAS Crypto Compliance in Singapore: A Guide for Payment Firms](https://blocksec.com/blog/mas-shapes-crypto-compliance-in-singapore): Learn how MAS shapes crypto payment compliance in Singapore — what PSA and tech risk rules demand, and how KYT and monitoring build trust. (Mar 26 2026) [Weekly Web3 Security Incident Roundup | Mar 16 – Mar 22, 2026](https://blocksec.com/blog/weekly-web3-security-incident-roundup-mar-16-mar-22-2026): This BlockSec weekly security report covers seven DeFi attack incidents detected between March 16 and March 22, 2026, across Ethereum, BNB Chain, Polygon, and Polygon zkEVM, with total estimated losses of approximately $82.7M. (Mar 25 2026) [Weekly Web3 Security Incident Roundup | Mar 2 – Mar 8, 2026](https://blocksec.com/blog/weekly-web3-security-incident-roundup-mar-2-mar-8-2026): During the week of March 2 to March 8, 2026, seven blockchain security incidents were reported with total losses of ~$3.25M. (Mar 25 2026) [VARA Compliance Guide for Crypto Payment Companies](https://blocksec.com/blog/what-is-vara-and-why-does-it-matter-for-payment-companies): Your guide to VARA compliance for crypto payment firms in Dubai: licensing, AML/KYC, sanctions, cybersecurity, governance, and building an audit-ready program. (Mar 23 2026) [Weekly Web3 Security Incident Roundup | Mar 9 – Mar 15, 2026](https://blocksec.com/blog/weekly-web3-security-incident-roundup-mar-9-mar-15-2026): This BlockSec weekly security report covers eight DeFi attack incidents detected between March 9 and March 15, 2026, across Ethereum and BNB Chain, with total estimated losses of approximately $1.66M. (Mar 18 2026) [Venus Thena (THE) Incident: What Broke and What Was Missed](https://blocksec.com/blog/venus-thena-donation-attack): On March 15, 2026, an attacker bypassed the THE (Thena) supply cap on Venus Protocol (BNB Chain) through a donation attack, inflating a collateral position to 3.67x the intended limit and borrowing ~$14.9M in assets. (Mar 18 2026) [Building a Secure Stablecoin Payment Network: BlockSec Partners with Morph](https://blocksec.com/blog/building-a-secure-stablecoin-payment-network-blocksec-partners-with-morph): BlockSec joins Morph to bring institutional-grade audits, pentesting, and protection to global stablecoin payments through the $150M Morph Payment Accelerator. (Mar 18 2026) [DeFi Compliance in 2026: A Technical Framework for Protocol Resilience](https://blocksec.com/blog/defi-compliance-in-2026-a-technical-framework-for-protocol-resilience): DeFi compliance in 2026: build a compliant-by-design framework to meet AML/KYC, unlock institutional capital, enhance security, and avoid regulatory shutdowns. (Mar 11 2026) [KYT Definition: What Know Your Transaction Means](https://blocksec.com/blog/kyt-definition-what-know-your-transaction-means-and-why-it-matters-in-crypto-and-finance): Know Your Transaction (KYT) monitors risk in real time to stop fraud and sanctions, helping crypto and fintech stay compliant with clear, auditable decisions. (Mar 9 2026) [Blockchain Regulations: From Legal Frameworks to Enforcement](https://blocksec.com/blog/a-strategic-guide-to-blockchain-regulations-from-legal-frameworks-to-on-chain-enforcement): Crypto's Wild West era is over. Learn how MiCA, US rules, and FATF shape blockchain regulations — and how Phalcon Compliance automates screening and reporting. (Mar 5 2026) [Weekly Web3 Security Incident Roundup | Feb 23 – Mar 1, 2026](https://blocksec.com/blog/weekly-web3-security-incident-roundup-feb-23-mar-1-2026): During the week of February 23 to March 1, 2026, seven blockchain security incidents were reported with total losses of ~$13M. (Mar 4 2026) [MSO vs VA OTC in Hong Kong: Crypto Licensing Guide](https://blocksec.com/blog/mso-vs-va-otc-in-hong-kong-what-crypto-payment-companies-must-know-in-2026): 2026 Hong Kong crypto: master dual licensing. Understand MSO vs VA OTC, C&ED vs SFC oversight, who needs each, application steps, and bank-ready compliance. (Mar 4 2026) [Navigating DeFi Regulation: AML/CFT Compliance Guide](https://blocksec.com/blog/navigating-de-fi-regulation-in-2026): Learn how to meet DeFi regulation requirements with Phalcon Compliance — real-time screening, on-chain monitoring, and automated AML/CFT reporting across jurisdictions. (Mar 3 2026) [Web3 Compliance Essentials for Exchanges & Institutions](https://blocksec.com/blog/web3-compliance-essentials-for-exchanges-payment-platforms-and-financial-institutions): Learn how Web3 compliance works for exchanges, payment platforms, and financial institutions — from real-time AML screening to cross-chain fund tracing. (Mar 3 2026) [Newsletter - February 2026](https://blocksec.com/blog/newsletter-february-2026): February 2026 saw three major DeFi security incidents: YieldBlox DAO lost ~$10M due to oracle price manipulation, IoTeX’s ioTube bridge suffered ~$4.4M from a private key compromise, and CrossCurve incurred ~$2.8M after a cross-chain… (Mar 2 2026) [Weekly Web3 Security Incident Roundup | Feb 16 – Feb 22, 2026](https://blocksec.com/blog/weekly-web3-security-incident-roundup-feb-16-feb-22-2026): During the week of February 16 to February 22, 2026, three blockchain security incidents were reported with total losses of ~$6.22M. (Feb 27 2026) [YieldBlox DAO Incident on Stellar: Oracle Misconfiguration Enabled a $10M+ Drain](https://blocksec.com/blog/yieldblox-dao-incident-on-stellar-oracle-misconfiguration-enabled-a-10m-drain): In-depth analysis of the YieldBlox DAO pool exploit on Blend V2 (Stellar), showing how USTRY/USDC price manipulation and oracle misconfiguration enabled a $10M+ drain. (Feb 27 2026) [2025 Crypto Crime Report: Key Trends & On-Chain Data](https://blocksec.com/blog/blocksec-releases-the-2025-crypto-crime-report): Explore BlockSec's 2025 Crypto Crime Report: Ethereum & TRON trends, $100B sanctions surge, $1.5B Lazarus exploit, stablecoin enforcement. Download now. (Feb 27 2026) [Weekly Web3 Security Incident Roundup | Feb 9 – Feb 15, 2026](https://blocksec.com/blog/weekly-web3-security-incident-roundup-feb-9-feb-15-2026): During the week of February 9 to February 15, 2026, three blockchain security incidents were reported with total losses of ~$657K. All incidents occurred on the BNB Smart Chain and involved flawed business logic in DeFi token contracts. (Feb 18 2026) [The Hidden Truths of Blockchain Legal Compliance in 2026](https://blocksec.com/blog/the-hidden-truths-of-blockchain-legal-compliance-in-2026): Blockchain legal compliance in 2026: learn the 10 hidden risks, from DAO liability to sanctions screening, before gaps turn into fines. (Feb 13 2026) [Crypto Exchange Compliance: Real-Time AML/CFT Control](https://blocksec.com/blog/crypto-exchange-compliance-with-emphasis-on-real-time-aml-cft-control-in-2026): Is your crypto exchange truly compliant? Learn how real-time screening, live monitoring, and one-click STR/SAR reporting close the AML/CFT gap. (Feb 13 2026) [How to Get a Canada MSB License for Crypto Payments](https://blocksec.com/blog/how-to-get-a-canada-msb-license-for-crypto-payments-in-2026): Launching crypto payments in Canada 2026? MSB registration isn't enough. Build FINTRAC-ready, real-time KYT/Travel Rule compliance to secure banking and scale. (Feb 12 2026) [Weekly Web3 Security Incident Roundup | Feb 2 – Feb 8, 2026](https://blocksec.com/blog/weekly-web3-security-incident-roundup-feb-2-feb-8-2026): During the week of February 2 to February 8, 2026, six blockchain security incidents were reported with total losses of ~$3.8M. (Feb 12 2026) [Top 10 "Awesome" Security Incidents in 2025](https://blocksec.com/blog/top-10-awesome-security-incidents-in-2025): Top 10 crypto security incidents of 2025 by BlockSec: losses, root causes, novel techniques, and detailed follow-up analyses to strengthen Web3 defenses. (Feb 11 2026) [#10 Panoptic Incident: XOR Linearity Breaks the Position Fingerprint Scheme](https://blocksec.com/blog/panoptic-incident-xor-linearity-breaks-the-position-fingerprint-scheme): Aug 25, 2025: White hats secured ~$400K from Panoptic after exposing an XOR-based s_positionsHash flaw enabling forged IDs and collateral withdrawal. (Feb 11 2026) [#9 1inch Incident: From Calldata Corruption to Forged Settlement: Binary Exploitation Goes On-Chain](https://blocksec.com/blog/1inch-incident-from-calldata-corruption-to-forged-settlement-binary-exploitation-goes-on-chain): Deep dive into the March 2025 1inch Fusion V1 resolver exploit: $5M lost via calldata underflow and trust boundary flaws, blending DeFi low-level ABI attacks (Feb 11 2026) [#7 Trust Wallet Incident: A Stolen API Key Turns the Official Update Channel into a Backdoor](https://blocksec.com/blog/trust-wallet-incident-a-stolen-api-key-turns-the-official-update-channel-into-a-backdoor): Dec 25, 2025: Trust Wallet Chrome v2.68 backdoored via supply chain attack, exfiltrating seed phrases and enabling ~$8.5M theft across multiple chains. (Feb 11 2026) [#6 Cork Protocol Incident: Two Independent Flaws Combine into One Devastating Exploit Chain](https://blocksec.com/blog/cork-protocol-incident-two-independent-flaws-combine-into-one-devastating-exploit-chain): Cork Protocol exploited on Ethereum, $12M lost due to HIYA manipulation and missing access control in Uniswap v4 hook; CT/DS drained from reserves. (Feb 11 2026) [#8 Bunni Incident: Repeated Small Withdrawals Compound a Rounding Error into an $8.4M Drain](https://blocksec.com/blog/bunni-incident-repeated-small-withdrawals-compound-a-rounding-error-into-an-8.4m-drain): On Sept 2, 2025, Bunni V2 was exploited via idle-balance rounding, draining ~$8.4M from USDC/USDT and weETH/ETH pools; protocol declared bankruptcy Oct 23. (Feb 11 2026) [#4 GMX Incident: Cross-Contract Reentrancy Bypasses a Four-Year-Old Guard](https://blocksec.com/blog/gmx-incident-cross-contract-reentrancy-bypasses-a-four-year-old-guard): GMX V1 Arbitrum exploit (July 9, 2025): cross-contract reentrancy skewed global shorts, inflated GLP price, draining $42M before a 10% bounty refund. (Feb 11 2026) [#3 Balancer V2 Incident: A Rounding Inconsistency Breaks the Invariant and Propagates Across Chains](https://blocksec.com/blog/balancer-v2-incident-a-rounding-inconsistency-breaks-the-invariant-and-propagates-across-chains): Nov 3, 2025 Balancer V2 exploit: rounding inconsistency broke the invariant, deflated BPT pricing, spread across chains; $125M lost, $45M recovered. (Feb 11 2026) [#5 Yearn Finance Incident: Unsafe Arithmetic in the Invariant Solver Earns Its Name](https://blocksec.com/blog/yearn-finance-incident-unsafe-arithmetic-in-the-invariant-solver-earns-its-name): Deep dive into Yearn yETH $9M exploit: unsafe arithmetic and bootstrap flaw. Step-by-step simulations, loss breakdown, root-cause reclassification, fixes. (Feb 11 2026) [DeFi Safety: Real-Time Risk Intelligence for On-Chain Finance](https://blocksec.com/blog/de-fi-safety-build-real-time-risk-intelligence-for-on-chain-finance): DeFi is growing fast—and so are its risks. Learn how Phalcon Compliance delivers real-time AML/CFT monitoring, deep risk insights, and pre-execution protection to help you scale safely. (Feb 10 2026) [#2 Bybit Incident: A Web2 Breach Enables the Largest Crypto Hack in History](https://blocksec.com/blog/bybit-incident-a-web2-breach-enables-the-largest-crypto-hack-in-history): Bybit lost ~$1.5B on Feb 21, 2025 after a Safe{Wallet} S3 code injection let an attacker swap the Safe multisig proxy's masterCopy and drain assets. (Feb 9 2026) [#1 Cetus Incident: One Unchecked Shift Drains $223M in the Largest DeFi Hack of 2025](https://blocksec.com/blog/cetus-incident-one-unchecked-shift-drains-223m-largest): On May 22, 2025, Cetus Protocol on Sui was exploited, draining multiple pools and ~$223M, via a flawed u256 shift check that let attackers mint fake liquidity. (Feb 9 2026) [Blockchain Regulatory Compliance: A Practical Guide](https://blocksec.com/blog/blockchain-regulatory-compliance-making-it-practical-for-your-business): Struggling with blockchain regulatory compliance? Phalcon Compliance delivers real-time KYT/KYA, global rule coverage, and sub-100ms risk scoring to keep your crypto platform compliant. (Feb 5 2026) [Weekly Web3 Security Incident Roundup | Jan 25 – Feb 1, 2026](https://blocksec.com/blog/weekly-web3-security-incident-roundup-jan-25-feb-1-2026): During the week of January 25 to February 1, 2026, six blockchain security incidents were reported with total losses of ~$18.05M. (Feb 4 2026) [BlockSec USDT Freeze Tracker Is Live](https://blocksec.com/blog/block-sec-usdt-freeze-tracker-is-live): USDT Freeze Tracker: real-time freeze/unfreeze/destroy checks on Ethereum and Tron. Search addresses, trace events, and review governance proposals. (Feb 4 2026) [Ryan Wedding Crypto Crime Network: BlockSec On-Chain Analysis](https://blocksec.com/blog/fall-olympian-blocksec-tracks-ryan-wedding-crypto-crime): BlockSec traces $200M+ in USDT laundered by ex-Olympian Ryan Wedding's cartel-linked network. See our on-chain analysis of the sanctioned crypto crime ring. (Feb 3 2026) [USDT Blacklisting in 2025: $1.26B Frozen on Ethereum & Tron](https://blocksec.com/blog/1-26-billion-frozen-usdt-blacklisting-on-ethereum-and-tron-in-2025): Tether blacklisted 4,163 USDT addresses in 2025, freezing $1.26B on Ethereum and Tron. See on-chain trends, risks, and how to protect your wallets. (Feb 2 2026) [DeFi KYC and AML: Balancing Compliance & Decentralization](https://blocksec.com/blog/de-fi-kyc-and-de-fi-aml-balancing-compliance-and-decentralization): DeFi KYC and AML don't have to kill decentralization. Learn how risk-based, on-chain KYT lets protocols stay compliant without gatekeeping users. (Feb 2 2026) [$17M Closed-Source Smart Contract Exploit: Arbitrary-Call Vulnerability in SwapNet and Aperture Finance](https://blocksec.com/blog/17m-closed-source-smart-contract-exploit-arbitrary-call-swapnet-aperture): An in-depth analysis of the $17M closed-source smart contract exploit affecting SwapNet and Aperture Finance, caused by an arbitrary-call vulnerability. We reconstruct attack paths from decompiled bytecode and on-chain traces. (Jan 28 2026) [AI Trading Security: How Risk Evolves in Web3](https://blocksec.com/blog/ai-trading-security-the-evolution-of-risk-in-the-age-of-intelligent-trading): How do AI agents reshape Web3 trading — and its risks? BlockSec and Bitget explore the new security paradigm for automated crypto trading. (Jan 27 2026) [DeFi Risk Management: How to Stay Safe and Compliant](https://blocksec.com/blog/managing-de-fi-risk-a-complete-guide-to-staying-safe-and-compliant): DeFi risk doesn't stop at smart contract bugs. Learn how to detect tainted funds, track cross-chain exposure, and stay compliant with real-time on-chain tools. (Jan 26 2026) [Deep Dive into HIP-3: A Builder-Centric Perspective](https://blocksec.com/blog/deep-dive-into-hip-3-a-builder-centric-perspective): Hyperliquid Improvement Proposal 3 (HIP-3) introduces a fundamental change in how perpetual markets are created and scaled on Hyperliquid. (Jan 18 2026) [In-Depth Analysis: The Truebit Incident](https://blocksec.com/blog/in-depth-analysis-the-truebit-incident): On January 8, 2026, the Truebit Protocol on Ethereum was exploited,, causing over $26 million in losses. This blog offers an in-depth technical analysis of the incident. (Jan 14 2026) [Newsletter - December 2025](https://blocksec.com/blog/newsletter-december-2025): In December 2025, the DeFi sector encountered three significant security incidents, resulting in total losses of approximately $19.7 million. (Jan 6 2026) [Analyze 10,000 TPS: Phalcon Explorer Now Supports Monad](https://blocksec.com/blog/analyze-10-000-tps-phalcon-explorer-now-supports-monad): Analyze Monad’s 10,000 TPS EVM with Phalcon Explorer: debug parallel execution, trace complex DeFi interactions, and monitor smart contract fund flows. (Dec 24 2025) [Track Stablecoin Payments on Plasma with Phalcon Explorer](https://blocksec.com/blog/track-stablecoin-payments-on-plasma-with-phalcon-explorer): Phalcon Explorer supports Plasma: analyze payment flows, debug smart contracts, and trace funds on a stablecoin‑native L1 with real-time monitoring (Dec 24 2025) [#1: Harvesting MEV Bots by Exploiting Vulnerabilities in Flashbots Relay](https://blocksec.com/blog/harvesting-mev-bots-by-exploiting-vulnerabilities-in-flashbots-relay): MEV bots were exploited due to Flashbots relay vulnerability, the number one security incident in the top ten "awesome" security incidents in 2023. (Dec 15 2025) [Phalcon Compliance 3.1: Faster Crypto AML & Flexible Pricing](https://blocksec.com/blog/instant-crypto-compliance-software-blocksec-phalcon-3-1): Speed up crypto AML/KYT with Phalcon Compliance 3.1: instant wallet/tx screening, lite sharing, multi-chain insights, and flexible pay‑as‑you‑go pricing. (Dec 15 2025) [Web3 Smart Contract & EVM Chain Audits | BlockSec](https://blocksec.com/blog/web3-smart-contract-evm-chain-audits-blocksec): BlockSec secures Web3 with attacker-driven audits, chain reviews, and zero-day detection - battle-tested, blocking 20+ hacks and $20M+ losses. (Dec 4 2025) [DeFi and Stablecoin Security: BlockSec CEO Prof. Andy Zhou](https://blocksec.com/blog/de-fi-and-stablecoin-security-a-discussion-with-dr-andy-zhou-ceo-of-bloc-sec): BlockSec CEO Dr. Andy Zhou discusses DeFi security, stablecoin compliance, and how real-time monitoring protects protocols from on-chain threats. Key insights from Chaintech. (Nov 19 2025) [BlockSec Phalcon Secures Solana Ecosystem with Enhanced Real-Time Protection](https://blocksec.com/blog/blocksec-phalcon-supports-solana): Enhance Solana security with Phalcon's real-time threat detection and proactive measures. Protect your blockchain protocols today with BlockSec. (Nov 13 2025) [In-Depth Analysis: The Balancer V2 Exploit](https://blocksec.com/blog/in-depth-analysis-the-balancer-v2-exploit): On November 3, 2025, Balancer V2 and several forked projects were exploited, causing over $125 million in losses. This blog offers an in-depth technical analysis of the incident. (Nov 5 2025) [Phalcon Security: The Proactive Defense Ending Zero-Day Web3 Attacks](https://blocksec.com/blog/phalcon-security-the-proactive-defense-ending-zero-day-web3-attacks): Discover how Phalcon Security spots and stops attacks in the mempool automatically. This shifts Web3 defense from reacting to being proactive. (Nov 4 2025) [Stablecoin Regulatory Fragmentation: FSB 2025 Assessment](https://blocksec.com/blog/fsb-2025-assessment-stablecoin-regulatory-fragmentation-intensifies-arbitrage-risks): The FSB's 2025 review exposes dangerous gaps in global stablecoin regulation. Learn how fragmentation fuels regulatory arbitrage and what it means for crypto compliance. (Oct 30 2025) [Drainer-as-a-Service: Inside Ethereum's $135M Phishing Economy](https://blocksec.com/blog/inside-ethereum-s-shadow-economy-new-research-unmasks-the-135-m-drainer-as-a-service-industry): New research reveals how Drainer-as-a-Service industrialized crypto phishing on Ethereum, stealing $135M from 76K+ victims. Explore the full on-chain analysis. (Oct 21 2025) [Crypto ATMs Under Fire: FinCEN & AUSTRAC Tighten AML Rules](https://blocksec.com/blog/crypto-atms-under-global-scrutiny-fincen-austrac-tighten): Crypto ATMs face a global crackdown. Learn how FinCEN and AUSTRAC are targeting fraud and money laundering risks — and what it means for Web3 compliance. (Oct 17 2025) [Crypto Crime Crackdown: DOJ Seizes $15B in Bitcoin](https://blocksec.com/blog/doj-seizes-15b-bitcoin-in-global-crypto-crime-crackdown): The DOJ seized $15B in Bitcoin tied to pig-butchering scams. Learn how the Prince Group and Huione network were exposed—and how to screen your wallets. (Oct 15 2025) [Phalcon Compliance: Self-Service On-Chain AML for All](https://blocksec.com/blog/phalcon-compliance-launches-self-service-platform-making-on-chain-aml-accessible-for-all): Phalcon Compliance now offers self-service on-chain AML screening. Run instant KYT/KYA checks, trace fund flows, and generate STR reports — no setup required. (Oct 14 2025) [USDT and Illicit Finance: New Criminal Tactics and Compliance Solutions](https://blocksec.com/blog/usdt-and-illicit-finance-new-criminal-tactics-and-compliance-solutions): Criminals exploit USDT for laundering, scams, and fraud across chains. Learn six emerging tactics and how Phalcon Compliance detects and blocks illicit flows. (Sep 26 2025) [Tracking Illicit Crypto Funds from Human Trafficking](https://blocksec.com/blog/block-sec-and-fbi-tracking-illicit-funds-from-human-trafficking): Learn how crypto "guarantee platforms" fuel human trafficking with USDT escrow — and how BlockSec's Phalcon Compliance helps trace illicit funds in real time. (Sep 23 2025) [Phalcon Explorer: Next-Gen Web3 Transaction Analysis Tool](https://blocksec.com/blog/phalcon-explorer-next-gen-web3-transaction-analysis-tool-1): BlockSec's Phalcon Explorer upgrades Web3 blockchain transaction analysis with call traces, debugger, simulator, fuzzy/event search, 26+ chains, 100K+ users (Sep 19 2025) [Interlace Boosts Crypto Payment Compliance with BlockSec](https://blocksec.com/blog/interlace-boosts-crypto-payment-compliance-with-block-sec): Interlace boosts crypto payment compliance with BlockSec's Phalcon Compliance: real-time KYA/KYT screening, tiered risk controls, safer deposits & withdrawals. (Sep 16 2025) [In-depth Analysis and Reflections on the Resupply Protocol Attack Incident](https://blocksec.com/blog/in-depth-analysis-and-reflections-on-the-resupply-protocol-attack-incident): This article will provide a more detailed analysis on the resupply stable coin security incident. (Sep 16 2025) [Following the Frozen: An On-Chain Analysis of USDT Blacklisting and Its Links to Terrorist Financing](https://blocksec.com/blog/following-the-frozen-an-on-chain-analysis-of-usdt-blacklisting-and-its-links-to-terrorist-financing): This report analyzes USDT blacklisting patterns and their links to terrorist financing, revealing laundering loops, cross-chain flows, and enforcement delays. (Jul 11 2025) [What Are Instant Crypto Exchanges, and Why Have They Become the Hotspot for Money Laundering?](https://blocksec.com/blog/instant-crypto-exchanges-money-laundering): While ICE offers efficiency and convenience, it has also quietly opened the door to illicit activities such as money laundering. (Jun 24 2025) [Oracle Monitoring Feature Now Live in BlockSec Phalcon!](https://blocksec.com/blog/phalcon-oracle-monitor): Mango Markets lost $116 million, Venus lost $11.2 million, and Rho Markets lost $7.6 million—but all of these losses could have been completely avoided. (May 28 2025) [Phishing Contracts: How 37K Scams Work and How to Stop Them](https://blocksec.com/blog/phishing-contracts): BlockSec researchers uncovered 37K+ phishing contracts that stole $190M on Ethereum. Learn how these scams work and how to defend your crypto assets. (May 19 2025) [BlockSec Introduces the World's First "Compliance + Security" Management Platform](https://blocksec.com/blog/phalcon-compliance-app): Phalcon Compliance APP is now live! (Apr 24 2025) [BlockSec Launches Safe{Wallet} Security Monitoring Solution](https://blocksec.com/blog/safe-wallet-security-monitor): Displaying transaction information comprehensively, analyzing transaction risks, and simulating transaction outcomes to prevent asset loss. (Mar 6 2025) [How to Play Four.meme Without Getting “Sandwiched”](https://blocksec.com/blog/how-to-play-four-meme-without-getting-sandwiched): How to use BlockSec Anti-MEV RPC to avoid getting “sandwiched” when playing Four.meme. (Feb 21 2025) [zkLend Exploit Post-Mortem: Unraveling the Details and Clarifying Misunderstandings of the $10M Flash Loan Attack](https://blocksec.com/blog/zklend-exploit-post-mortem-unraveling-the-details-and-clarifying-misunderstandings-of-the-10m-flash-loan-attack): This blog provides a detailed analysis of the zkLend incident to clarify the misunderstandings. (Feb 20 2025) [BlockSec Phalcon Safeguards Yei Finance's $140M+ Assets in Real Time](https://blocksec.com/blog/blocksec-phalcon-safeguards-yei-finance-140m-assets-in-real-time): BlockSec Phalcon provides Yei Finance with 24/7 real-time monitoring and automated intervention against attacks and other risks. (Feb 12 2025) [How is the performance of BSC after full implementation of PBS?](https://blocksec.com/blog/performance-bsc-after-full-implementation-pbs): Explore BSC’s PBS upgrade, validator-builder dynamics, 0 Gwei risks, rising MEV, and BlockSec’s MEV-protected RPC delivering safer BNB Smart Chain trades. (Jan 17 2025) [BTC Cross-Chain Monitoring & Chainlink PoR API: Setting a New Standard for BTCFi Security](https://blocksec.com/blog/btc-cross-chain-monitoring-por): Enhance BTCFi security with BlockSec's solutions. Learn about BTC-wrapped asset risks like depegging and cross-chain vulnerabilities, and how Chainlink PoR and (Jan 10 2025) [BlockSec and OKX Explorer Partner to Enhance On-Chain Data Security and Compliance](https://blocksec.com/blog/on-chain-data-security): BlockSec and OKX Explorer unite to boost on-chain security, compliance, and analytics, integrating threat intel and APIs for a safer, more transparent Web3 (Nov 18 2024) [Monthly Security Review: October 2024](https://blocksec.com/blog/monthly-security-review-october-2024): Stay updated with October's security trends and our recent developments. 🙌 (Nov 1 2024) [DeFi Security Landscape: 50 Key Players You Need to Know](https://blocksec.com/blog/defi-security-landscape): Explore 50 key players shaping DeFi security — from smart contract audits and attack detection to hack blocking and fund tracking. Your complete guide. (Aug 30 2024) [BlockSec Supports The BTC Ecosystem!](https://blocksec.com/blog/blocksec-supports-btc-ecosystem): Discover how BlockSec boosts Bitcoin ecosystem security with advanced blockchain solutions. Safeguard your BTC projects today with our expert Web3 tools. (Aug 7 2024) [BlockSec Completed Security Audit for Neo X](https://blocksec.com/blog/blocksec-neo-x-audit-collaboration): BlockSec has completed the security audit for Neo X, the EVM-compatible and MEV-resistant sidechain of Neo. (Aug 1 2024) [Phalcon Supports Mantle Network: Pioneering Unbreakable Ecosystem Security](https://blocksec.com/blog/phalcon-enhances-mantle-security): Phalcon enhances Mantle Network by offering advanced attack monitoring and automatic blocking capabilities, ensuring robust post-launch security for the ecosystem and its participants. (Jul 31 2024) [Stablecoins Explained: Is Ethena the Upgraded Luna?](https://blocksec.com/blog/ethena-upgraded-luna-walk-stablecoins): Explore stablecoins, their security risks, and how Ethena's USDe offers a new approach. Learn more about stablecoin mechanisms and protection strategies. (Jul 26 2024) [Lead in: Solana Simplified](https://blocksec.com/blog/solana-guide): The series offers a concise guide to mastering Solana's core concepts, smart contract development in Rust, and transaction analysis with Phalcon Explorer, empowering you to participate in Solana's ecosystem. (Jul 12 2024) [Can Symbiotic Challenge EigenLayer in Restaking?](https://blocksec.com/blog/eigenlayer-competitor-symbiotic): Explore how Symbiotic competes with EigenLayer in restaking. Discover key differences, features, and which blockchain restaking platform leads in 2024. Read now (Jul 11 2024) [Monthly Security Review: June 2024](https://blocksec.com/blog/monthly-security-review-june-2024-1): Stay updated with June's security trends and our recent developments. 🙌 (Jul 9 2024) [DeFi Risk Mitigation Guide 04: Security Practices for DeFi Project Team](https://blocksec.com/blog/de-fi-risk-mitigation-guide-04-security-practices-for-de-fi-project-team-1): This part introduce conduct thorough audits, adopt multi-signature wallets, establish bug bounty programs, and communicate transparently with the community to ensure the security of the platform For DeFi project teams (Jul 5 2024) [DeFi Risk Mitigation Guide 03: Safety Tips for DeFi Users](https://blocksec.com/blog/de-fi-risk-mitigation-guide-03-safety-tips-for-de-fi-users): This part introduce security tips for DeFi Users to staying Defi safety (Jul 5 2024) [DeFi Risk Mitigation Guide 02: How DeFi Users Can Assess Risks](https://blocksec.com/blog/de-fi-risk-mitigation-guide-02-how-de-fi-users-can-assess-risks): This part aims to reveal the importance of reading audit reports, researching project teams, analyzing liquidity and token economics and so on, to effectively assess the risks of DeFi projects (Jul 5 2024) [DeFi Risk Mitigation Guide 01: Identifying Types of Risks DeFi Users Face](https://blocksec.com/blog/de-fi-risk-mitigation-guide-01-identifying-types-of-risks-de-fi-users-face-1): This part aims to enhance DeFi Users safety awareness through real-life cases, helping users protect their private keys and wallet assets. (Jul 5 2024) [Lead in: DeFi Risk Mitigation Guide](https://blocksec.com/blog/lead-in-de-fi-risk-mitigation-guide-2): In this series, explore detailed main DeFi risk types, how to assess project risk, user security tips, and how DeFi Project teams can ensure security (Jul 5 2024) [Revolutionizing L2 Chains: Building Intrinsic Security from Sequencers](https://blocksec.com/blog/revolutionizing-l2-chains-building-intrinsic-security-from-sequencers): This article introduces the Sequencer Threat Overwatch Program (STOP), a groundbreaking Layer 2 security solution initiated by BlockSec and Manta. (Jul 5 2024) [Solana Simplified 03: Understand Solana Transactions in 5 Minutes](https://blocksec.com/blog/solana-simplified-03-understand-solana-transactions-5-minutes): Master Solana transactions in 5 minutes! Learn about Solana token implementation and analyze a real transaction step-by-step using BlockSec's Phalcon Explorer. (Jun 27 2024) [Solana Simplified 02: Writing Your First Solana Smart Contract from Scratch](https://blocksec.com/blog/solana-simplified-02-writing-your-first-solana-smart-contract-from-scratch): Master writing Solana programs with just this one article! Covering everything from environment setup, contract logic, to program testing. (Jun 21 2024) [Best Blockchain Transaction Explorer for Solana](https://blocksec.com/blog/phalcon-explorer-now-fully-supports-solana): Simplify Solana transactions for users & a boon for developers. (Jun 20 2024) [What Are the Security Risks Faced by DeFi Protocols and How to Ensure Protocol Security?](https://blocksec.com/blog/what-are-the-security-risks-faced-by-de-fi-protocols-and-how-to-ensure-protocol-security): This article focuses on mitigating risks to ensure robust DeFi protocol security, covering aspects such as code vulnerabilities, operational threats, and external dependencies. (Jun 12 2024) [Monthly Security Review: May 2024](https://blocksec.com/blog/monthly-security-review-may-2024): Stay updated with May's security trends and our recent developments. 🙌 (Jun 10 2024) [Solana Simplified 01: Master Solana Core Concepts in One Read](https://blocksec.com/blog/solana-simplified-master-solana-core-concepts-in-one-read): In just 10 minutes, understand Solana's operating mechanism, account model, and transactions, and uncover the reasons behind its explosive growth. (Jun 7 2024) [Reflecting on Reflection Tokens: A Security Perspective](https://blocksec.com/blog/reflecting-on-reflection-tokens-a-security-perspective): In this blog, our primary focus is on sharing security-related insights from our research on the reflection token mechanism. (Jun 6 2024) [What Is the Best DeFi Hack Detection and Prevention System?](https://blocksec.com/blog/what-is-the-best-de-fi-hack-detection-and-prevention-system): Exploring vulnerabilities, attack types, and preventative strategies in DeFi protocols. (May 31 2024) [MetaSuites 5.0 Boosts Solana Scans with Full Support](https://blocksec.com/blog/metasuites-5-0-extends-full-support-solana-scans): Discover how MetaSuites 5.0 enhances Solana scans with cross-platform local labels and Phalcon Explorer integration. Upgrade your blockchain security now! (May 29 2024) [How to Choose the Right Security Monitoring Platform for Your Protocol?](https://blocksec.com/blog/how-to-choose-the-right-security-monitoring-platform-for-your-protocols): Discover the importance of security monitoring for blockchain projects and the factors worth considering when choosing a security monitoring platform for your protocol (May 22 2024) [Join Our Free Hack Defense Game and Block REAL Attacks with Phalcon](https://blocksec.com/blog/phalcon-virtual-experience-join-our-free-hack-defense-game-and-block-real-attacks-with-phalcon): Ready for a LIFE-AND-DEATH battle against hackers? (May 17 2024) [Enhancing Web3 Security: Exploring the Top 5 Security Monitoring Platforms in 2024](https://blocksec.com/blog/enhancing-web3-security-exploring-the-top-5-security-monitoring-platforms-in-2024): Discover the top 5 security monitoring platforms in blockchain and experience the advantages of BlockSec Phalcon. With early attack detection and customizable rules, Phalcon secures web3 applications effectively. (May 14 2024) [How to Track a Solana Wallet](https://blocksec.com/blog/how-to-track-a-solana-wallet): How to Track a Solana Wallet or account using MetaSleuth (May 2 2024) [Monthly Security Review: April 2024](https://blocksec.com/blog/monthly-security-review-april-2024): Stay updated with April's security trends and our recent developments. 🙌 (May 1 2024) [Major Upgrades to BlockSec Phalcon's Storage Analysis and Monitoring Functions](https://blocksec.com/blog/major-upgrades-to-block-sec-phalcon-s-storage-analysis-and-monitoring-functions): BlockSec is pleased to announce a significant upgrade to our crypto hack monitoring and blocking system Phalcon's storage analysis and monitoring capabilities. (Apr 30 2024) [How Can BlockSec Phalcon Prevent Hacker Attacks on DeFi Protocols by Using Front-Running Techniques?](https://blocksec.com/blog/how-can-block-sec-phalcon-prevent-hacker-attacks-on-de-fi-protocols-by-using-front-running-techniques): Explore how front-running techniques can be used to prevent hacker attacks and enhance the security of DeFi protocols. (Apr 29 2024) [Lead in: Secure Smart Contract Development](https://blocksec.com/blog/lead-in-secure-smart-contract-development): Our series explores essential security practices for developing secure, efficient smart contracts, especially NFTs. (Apr 26 2024) [Lead in: Uniswap V4 Hook Risks](https://blocksec.com/blog/lead-uniswap-v4-hook-risks): Deep dive into Uniswap v4 hook risks: flawed access control and input validation, exploits, and mitigations to harden DeFi security on Ethereum and L1/L2. (Apr 26 2024) [Lead in: Phalcon's Hack Blocking Saga](https://blocksec.com/blog/lead-in-phalcon-s-hack-blocking-saga): In this series, explore how BlockSec Phalcon, the world's first crypto hack monitoring and blocking system, innovatively saved millions in assets. (Apr 26 2024) [Lead in: Secure the Solana Ecosystem](https://blocksec.com/blog/secure-the-solana-ecosystem): In this series, explore detailed insights into securing Solana through deployment, upgrades, and complex functionalities. (Apr 26 2024) [Security Practices in Move Development (2): Aptos Coin](https://blocksec.com/blog/security-practices-in-move-development-2-aptos-coin): Create and manage your own coin: Discover how to easily create and manage your own coin using the official standard module, coin.move, in Aptos. (Apr 24 2024) [Secure the Solana Ecosystem (4) — Account Validation](https://blocksec.com/blog/secure-the-solana-ecosystem-4-account-validation): The article discusses access control related problems in the context of Solana's programming environment, focusing on the importance of proper account validation and the potential security risks. (Apr 24 2024) [Secure the Solana Ecosystem (7) — Type Confusion](https://blocksec.com/blog/secure-the-solana-ecosystem-7-type-confusion): The article discusses the Type Confusion security issue in Solana, highlighting its impact on account deserialization/serialization and the potential for exploitation by attackers. (Apr 23 2024) [Revisiting the Wormhole Attacks](https://blocksec.com/blog/revisiting-the-wormhole-attacks): An in-depth analysis of the Wormhole attack reveals vulnerabilities in the signature verification process, allowing an attacker to mint 120,000 ETH on Solana without locking any assets on Ethereum. (Apr 23 2024) [Security Practices in Move Development (1): Hello World](https://blocksec.com/blog/security-practices-in-move-development-1-hello-world): Learn secure development practices in Move and create an Aptos application with this comprehensive guide (Apr 23 2024) [How to Choose the Ideal Security Audit Company for Your Protocol: A Comprehensive Guide](https://blocksec.com/blog/how-to-choose-the-ideal-security-audit-company-for-your-protocol-a-comprehensive-guide): Discover the key factors to consider when choosing a security audit company for your blockchain project and explore how BlockSec offers unique security audit solutions and security products Phalcon to ensure the life-cycle safety of… (Apr 22 2024) [What Is BlockSec Phalcon? How Does Phalcon Accurately Identify and Rapidly Block Hacker Attacks?](https://blocksec.com/blog/what-is-block-sec-phalcon-how-does-phalcon-accurately-identify-and-rapidly-block-hacker-attacks): What is BlockSec Phalcon? Why Protocols Need Phalcon? How Phalcon Works Technically? How Can I Subscribe to Phalcon? This article will tell you the answer. (Apr 22 2024) [Secure the Solana Ecosystem (5) — Multi-Sig](https://blocksec.com/blog/secure-the-solana-ecosystem-5-multi-sig): In this post, we explore the implementation of multi-signature functionality in Solana, highlighting its significance in decentralized applications for bolstering security and safeguarding against private key exposure. (Apr 20 2024) [[Not All Tokens Are Good] The Quick Analysis of the Paraluni Attack](https://blocksec.com/blog/not-all-tokens-are-good-the-quick-analysis-of-the-paraluni-attack): The article provides a detailed analysis of an attack on the Paraluni project, highlighting vulnerabilities related to token verification and reentrancy, and emphasizing the importance of security measures in the emerging Web3 world. (Apr 20 2024) [The Informal Security Review of the Patch to Fix the Vulnerability of the Poly Network Hack](https://blocksec.com/blog/the-informal-security-review-of-the-patch-to-fix-the-vulnerability-of-the-poly-network-hack): This blog presents an informal security review of the patch implemented to fix the recent vulnerability in Poly network, highlighting the use of allow lists and the resulting security properties. (Apr 20 2024) [How a Vulnerability Is Silently Fixed by Coin98](https://blocksec.com/blog/how-a-vulnerability-is-silently-fixed-by-coin98): The article highlights a recent attack on the Coin98 smart contract on the Binance Smart Chain (BSC) and the subsequent fix implemented by the project owner to address the vulnerability. (Apr 20 2024) [The Analysis of Indexed Finance Security Incident](https://blocksec.com/blog/the-analysis-of-indexed-finance-security-incident): Learn secure development practices in Move and create an Aptos application with this comprehensive guide (Apr 20 2024) [How to Evaluate Project Security through Security Audit Report?](https://blocksec.com/blog/how-to-evaluate-project-security-through-security-audit-report): Explore the power of security audit reports in ensuring blockchain project security, and how BlockSec's comprehensive methodology delivers accurate assessments through automated scans, manual verification, and business logic analysis. (Apr 20 2024) [Best Practices for Smart Contract Security: Ensuring Trust and Confidence](https://blocksec.com/blog/best-practices-for-smart-contract-security-ensuring-trust-and-confidence): Discover the best practices and innovative solutions provided by BlockSec, a leading blockchain security company, to safeguard your smart contracts from potential hacks and ensure trust in the blockchain ecosystem. (Apr 20 2024) [How to Avoid Smart Contract Hacks with Fuzzing Technology?](https://blocksec.com/blog/how-to-avoid-smart-contract-hacks-with-fuzzing-technology): Explore how fuzzing technology and BlockSec's expertise in blockchain security can help prevent smart contract hacks and protect your assets in the ever-evolving blockchain ecosystem. (Apr 19 2024) [How to Verify a Signature in a Wrong Way — The AssociationNFT Case](https://blocksec.com/blog/how-to-verify-a-signature-in-a-wrong-way-the-association-nft-case-1): The article discusses a serious vulnerability in the NBA's Association NFT sale contract, highlighting the importance of implementing proper security measures in popular blockchain projects. (Apr 18 2024) [How We Recover the Stolen Funds for TransitSwap (and BabySwap)](https://blocksec.com/blog/how-we-recover-the-stolen-funds-for-transit-swap-and-baby-swap): BabySwap and TransitSwap on BSC experienced attacks on October 1, with a vulnerable bot being front-run and its private key recovered, resulting in the successful transfer of funds to a secure account. (Apr 18 2024) [Our Short Analysis of the Accusation of the Wintermute Project](https://blocksec.com/blog/our-short-analysis-of-the-accusation-of-the-wintermute-project-1): BlockSec's investigation challenges the accusations made in the report analyzing the Wintermute Hack, questioning the solidity of the claims against the Wintermute project. (Apr 18 2024) [Rustle: the First Automatic Auditor for NEAR Community](https://blocksec.com/blog/rustle-the-first-automatic-auditor-for-near-community): Rustle, developed by BlockSec, is an automatic auditor for NEAR smart contracts, offering comprehensive vulnerability detection and analysis. (Apr 18 2024) [Tracing the Stolen Fund of the Ronin Bridge](https://blocksec.com/blog/tracing-the-stolen-fund-of-the-ronin-bridge): Ronin Bridge security incident: Compromised private keys led to the theft of 173,600 ETH and 25,500,000 USDC. Stolen USDC swiftly swapped for ETH, with 6,250 ETH already transferred out. (Apr 18 2024) [Flash Loan Attack on Plouto Vault](https://blocksec.com/blog/flash-loan-attack-on-plouto-vault): BlockSec Team analyzes a malicious attack on Plouto Vault, where flash loans were utilized to manipulate liquidity, resulting in a gain of $698,775.32 USD. (Apr 18 2024) [Secure the Solana Ecosystem (6) — Multi-Sig2](https://blocksec.com/blog/secure-the-solana-ecosystem-6-multi-sig2): The article discusses a general implementation of multisig on Solana, enabling on-chain transaction signing and providing code review and deployment details. (Apr 18 2024) [When MetaDock Met GPT: See Through Every Transaction Like an OG!](https://blocksec.com/blog/when-meta-dock-met-gpt-see-through-every-transaction-like-an-og): MetaDock is a powerful browser plugin that enhances blockchain exploration with useful tools and explanations for address labels, fund flows, and transaction analysis. (Apr 18 2024) [Copycats of the Popsicle Finance Attack](https://blocksec.com/blog/copycats-of-the-popsicle-finance-attack): The article presents a list of transactions that have called the "collectFees(0,0)" function of the SorbettoFragola contract, along with their corresponding timestamps and transaction hashes. (Apr 18 2024) [MetaDock Breaks Through 6K Users!](https://blocksec.com/blog/meta-dock-breaks-through-6-k-users): MetaDock, a web3 browser extension, reaches 6000 users, enhancing blockchain explorers with seamless integration and prioritizing user privacy and security. (Apr 18 2024) [BlockSec September Business Travel Plans](https://blocksec.com/blog/block-sec-september-business-travel-plans): BlockSec announces its travel itinerary for September, with visits to Singapore, Berlin, and Shanghai, where they will be participating in various events and conferences to share their expertise in Web3 security and usability. (Apr 18 2024) [BlockSec Has Closed the Seed Funding Raising](https://blocksec.com/blog/block-sec-has-closed-the-seed-funding-raising): BlockSec has closed the seed funding raising that was led by Fenbushi Capital, with participation from A&T Capital, Qulian, Impossible Finance, Incuba Alpha and NEAR MetaWeb Ventures. (Apr 18 2024) [Secure the Solana Ecosystem (3) — Program Upgrade](https://blocksec.com/blog/secure-the-solana-ecosystem-3-program-upgrade): This article provides a guide on program upgrade in Solana, covering the deployment of upgradable programs, code review of a sample contract, sending transactions, performing upgrades, and verifying the upgraded program. (Apr 18 2024) [BlockSec Closes Seed Plus Funding Round with $8M Raised](https://blocksec.com/blog/block-sec-closes-seed-plus-funding-round-with-8-m-raised): Blockchain security provider BlockSec has raised $8 million in a funding round led by Vitalbridge Capital and Matrix Partners, aiming to enhance decentralized application security. (Apr 18 2024) [Revisiting the CashioApp Security Incident](https://blocksec.com/blog/revisiting-the-cashio-app-security-incident): CashioApp was exploited due to insufficient input account validation, resulting in the unauthorized minting of $CASH tokens using fake collateral and Saber accounts. (Apr 18 2024) [BlockSec’s Perspective on the Jump “Counter Exploit”: Does the Vulnerability Really Exist?](https://blocksec.com/blog/block-sec-s-perspective-on-the-jump-counter-exploit-does-the-vulnerability-really-exist): The article provides a detailed analysis of the Jump counter exploit, explaining the steps involved and highlighting the fundamental differences between this exploit and the Platypus case. (Apr 18 2024) [The Initial Analysis of the bZx Security Incident](https://blocksec.com/blog/the-initial-analysis-of-the-b-zx-security-incident): The article discusses the hacking incident on the bZX protocol, attributing it to a compromised developer's private key and emphasizing the significance of protecting private keys in DApp security. (Apr 18 2024) [[The Butterfly Effect] The Compound Security Incident Caused by a Bugfix](https://blocksec.com/blog/the-butterfly-effect-the-compound-security-incident-caused-by-a-bugfix): The article describes two bugs in the Compound protocol and their impact on the distribution of COMP tokens to users. (Apr 18 2024) [The Retrospection of the Poly Network Hack from a Security Researcher Perspective](https://blocksec.com/blog/the-retrospection-of-the-poly-network-hack-from-a-security-researcher-perspective): An analysis of the Poly Network Hack and the lessons learned regarding security vulnerabilities in decentralized finance projects. (Apr 18 2024) [Enhancing Security and Trust in EVM-Compatible Chains: Insights from BlockSec's 2024 Audits](https://blocksec.com/blog/enhancing-security-and-trust-in-evm-compatible-chains-insights-from-block-sec-s-2024-audits): Gain valuable insights into BlockSec's 2024 audits for enhancing security and trust in EVM-compatible chains, including proactive measures, specialized expertise, and advanced countermeasures. (Apr 15 2024) [How to Mitigate Smart Contract Risks: A Comprehensive Guide to Secure Blockchain Operations](https://blocksec.com/blog/how-to-mitigate-smart-contract-risks-a-comprehensive-guide-to-secure-blockchain-operations): Learn to mitigate smart contract risks and protect your blockchain operations with BlockSec's comprehensive solutions and expertise. (Apr 15 2024) [How to Check the Security of Cosmos Bridge: A Comprehensive Guide](https://blocksec.com/blog/how-to-check-the-security-of-cosmos-bridge-a-comprehensive-guide): Explore the significance of securing Cosmos Bridge, learn how to assess Cosmos Bridge's security and discover BlockSec's expertise in providing tailored security audits for cross-chain transactions. (Apr 15 2024) [The Top 5 Solidity Audit Vendors in 2024: A Comprehensive Review](https://blocksec.com/blog/the-top-5-solidity-audit-vendors-in-2024-a-comprehensive-review): Explore the top 5 Solidity audit vendors in 2024 and BlockSec's advantages in offering unparalleled expertise, tailored solutions, and comprehensive security assessments for smart contracts. (Apr 15 2024) [BlockSec: Enhancing Blockchain Security Audits with Fuzzing Techniques](https://blocksec.com/blog/block-sec-enhancing-blockchain-security-audits-with-fuzzing-techniques): Explore the application of fuzzing in blockchain security audits and how BlockSec utilizes this technique to proactively identify and mitigate vulnerabilities in smart contracts and EVM chains, ensuring comprehensive assessments for… (Apr 8 2024) [Key Highlights of EVM Chain Audits in 2024 - Insights from BlockSec](https://blocksec.com/blog/key-highlights-of-evm-chain-audits-in-2024-insights-from-block-sec): Discover the key trends in EVM Chain audits for 2024 —— BlockSec provides comprehensive solutions to address security concerns and provide actionable recommendations, ensuring the robustness and reliability of blockchain projects. (Apr 8 2024) [The Top 5 Smart Contract Auditors: BlockSec Leading the Way](https://blocksec.com/blog/the-top-5-smart-contract-auditors-block-sec-leading-the-way): Explore the evolving landscape of smart contract audits in 2024 and discover the top five audit firms, including BlockSec, known for their comprehensive evaluations, professional reports, EVM chain expertise, and exceptional client… (Apr 8 2024) [Monthly Security Review: March 2024](https://blocksec.com/blog/security-report-PrismaFi-Munchables-ParaSwap): Stay updated with March's security trends and our recent developments. 🙌 (Apr 1 2024) [How L2 Blockchains Can Do Better to Protect Their Users](https://blocksec.com/blog/how-L2-blockchains-can-do-better-to-protect-their-users): How layer 2 (L2) chains can implement several measures to enhance the security of top protocols and protect users' assets on the chain. (Mar 27 2024) [BlockSec and Blockscout Join Forces for Advanced Transaction Analysis](https://blocksec.com/blog/blocksec-blockscout-metasuites-phalcon-partnership): We are thrilled to announce our partnership with Blockscout! 🎉 (Mar 26 2024) [New Website Unveiled | BlockSec Safeguards Protocol's Lifecycle Security](https://blocksec.com/blog/new-website-unveiled-block-sec-safeguards-protocol-s-lifecycle-security): BlockSec launches the new website, unveiling a new era of full-stack, lifecycle blockchain security services.🙌 (Mar 18 2024) [BlockSec and Tokenlon Reached Strategy Partnership](https://blocksec.com/blog/block-sec-and-tokenlon-reached-strategy-partnership): BlockSec and Tokenlon join forces to enhance crypto assets security and risk management (Mar 5 2024) [The Analysis of the Zerogoki Attack](https://blocksec.com/blog/the-analysis-of-the-zerogoki-attack): Investigating Zerogoki Attack: How Crafted Token Numbers Led to a Hefty Theft (Mar 4 2024) [Security Incident on Seal Finance](https://blocksec.com/blog/security-incident-on-seal-finance): Seal Finance Protocol Compromised, Attacker Nets 80.97 ETH Worth $48,849 (Mar 4 2024) [How BlockSec Rescued Stolen DeFi Funds: 3 Case Studies](https://blocksec.com/blog/how-blocksec-rescued-stolen-funds-from-technical-perspectives-of-three-representative-cases): Learn how BlockSec recovered millions in stolen DeFi funds through pure technical methods — including Platypus Finance, TransitSwap, and Saddle Finance rescues. (Mar 4 2024) [Secure Smart Contract Development (2) — How to Use Digital Signature and Use It Right in NFT (Markets)](https://blocksec.com/blog/mastering-digital-signatures-in-nft-smart-contracts-for-enhanced-security-and-efficiency): Ensuring NFT Authenticity with Digital Signatures: Learn how digital signatures provide authenticity and integrity in NFT smart contract development (Mar 4 2024) [The Race Against Time and Strategy: About the AnySwap Rescue and Things We Have Learnt](https://blocksec.com/blog/AnySwap-Rescue-Analysis-Lessons-from-a-DeFi-Security-Triumph): Discover the critical insights from AnySwap's emergency rescue operation against a smart contract attack and the lessons learned for DeFi security (Mar 4 2024) [The Real Root Cause of the Vee Finance Security Incident](https://blocksec.com/blog/the-real-root-cause-of-the-vee-finance-security-incident): Vee Finance Report Misidentifies Root Cause of Security Breach (Mar 4 2024) [Our Short Analysis of the Profanity Tool Vulnerability](https://blocksec.com/blog/our-short-analysis-of-the-profanity-tool-vulnerability): Exploring the Profanity Tool's Role in Wintermute's $160M Crypto Vulnerability (Mar 4 2024) [Monthly Security Review: February 2024](https://blocksec.com/blog/monthly-security-review-february-2024): Stay updated with February's security trends and our recent developments. 🙌 (Mar 1 2024) [Loopring(LRC) Protocol Incident](https://blocksec.com/blog/loopring-lrc-protocol-incident): Discover how the Loopring LRC protocol incident led to a $48K loss. Learn key details, impact, and security insights. Stay informed and secure your assets today (Feb 29 2024) [#10: ThirdWeb Incident: Incompatibility Between Trusted Modules Exposes Vulnerability](https://blocksec.com/blog/10-third-web-incident-incompatibility-between-trusted-modules-exposes-vulnerability): Discover how ThirdWeb's trusted modules incompatibility led to a critical security vulnerability. Learn key insights and protect your Web3 projects today. (Feb 22 2024) [#5: Platypus Finance: Surviving Three Attacks with a Stroke of Luck](https://blocksec.com/blog/5-platypus-finance-surviving-three-attacks-with-a-stroke-of-luck): We show the three attacks to Platypus Finance and how BlockSec rescued 2.4 Million USDC for the protocol. (Feb 22 2024) [#9: MEV Bot 0xd61492: From Predator to Prey in an Ingenious Exploit](https://blocksec.com/blog/9-mev-bot-0xd61492-from-predator-to-prey-in-an-ingenious-exploit): On August 3, 2023, an MEV Bot on Arbitrum was attacked, resulting in $800K in loss. The root cause of this attack was **Insufficient User Input Verification**. (Feb 21 2024) [#8: SushiSwap Incident: A Clumsy Rescue Attempt Leads to a Series of Copycat Attacks](https://blocksec.com/blog/8-sushi-swap-incident-a-clumsy-rescue-attempt-leads-to-a-series-of-copycat-attacks): On April 9, 2023, SushiSwap became the target of an exploit due to an Unverified External Parameter. The total loss is about $3.3 million. (Feb 18 2024) [Security Audit Report for LiNEAR](https://blocksec.com/blog/security-audit-report-for-li-near): This is the security audit report that we conducted for LiNEAR in April 2022. (Feb 18 2024) [Security Audit Report for NearOinDao](https://blocksec.com/blog/security-audit-report-for-near-oin-dao): This is the security audit report that we conducted for NearOinDao in December 2021. (Feb 18 2024) [#6: Hundred Finance Incident: Catalyzing the Wave of Precision-Related Exploits in Vulnerable Forked Protocols](https://blocksec.com/blog/6-hundred-finance-incident-catalyzing-the-wave-of-precision-related-exploits-in-vulnerable-forked-protocols): On April 16th, 2023, Hundred Finance, a Compound V2 fork, was attacked, leading to a loss of about $7.4 million. (Feb 16 2024) [#4: Curve Incident: Compiler Error Produces Faulty Bytecode from Innocent Source Code](https://blocksec.com/blog/curve-incident-compiler-error-produces-faulty-bytecode-from-innocent-source-code): Curve Incident: Compiler Error Produces Faulty Bytecode from Innocent Source Code (Feb 14 2024) [#3: KyberSwap Incident: Masterful Exploitation of Rounding Errors with Exceedingly Subtle Calculations](https://blocksec.com/blog/kyberswap-incident-masterful-exploitation-of-rounding-errors-with-exceedingly-subtle-calculations): KyberSwap Incident: Masterful Exploitation of Rounding Errors with Exceedingly Subtle Calculations (Feb 12 2024) [#2: Euler Finance Incident: The Largest Hack of 2023](https://blocksec.com/blog/euler-finance-incident-the-largest-hack-of-2023): Euler Finance Incident: The Largest Hack of 2023 (Feb 8 2024) [Puffer Protocol: Why Does Access Control Mechanism Matter and How to Improve Its Security](https://blocksec.com/blog/demystify-the-access-control-mechanism-in-puffer-protocol): We reviewed the whole architecture of the access control mechanism and its current configuration in the Puffer protocol. (Feb 8 2024) [How We Recovered the Stolen Funds for TransitSwap and BabySwap](https://blocksec.com/blog/how-we-recover-the-stolen-funds-for-transitswap-and-babyswap): Swift Recovery of Stolen Funds: How we efficiently recovered stolen funds from the TransitSwap and BabySwap attack on the BSC network using a vulnerability in the attacker's bot (Feb 8 2024) [Secure the Solana Ecosystem (1) — Hello Solana](https://blocksec.com/blog/secure-the-solana-ecosystem-1-hello-solana): BlockSec's Mission for a Secure DApp Ecosystem: Discover how BlockSec aims to enhance the security of the DApp ecosystem with a focus on Solana smart contract security. (Feb 7 2024) [Our Short Analysis of the Accusation Against the Wintermute Project](https://blocksec.com/blog/our-short-analysis-of-the-accusation-of-the-wintermute-project): Analyzing the Wintermute Hack: No Concrete Evidence of an Inside Job (Feb 7 2024) [The Analysis of FEGtoken Security Incident: Devil’s in the Details](https://blocksec.com/blog/the-analysis-of-fegtoken-security-incident-devils-in-the-details): How a Subtle Contract Flaw Led to a Million-Dollar FEGtoken Heist on Multiple Blockchains (Feb 7 2024) [Secure Smart Contract Development — Code Reentrancy in NFT Contracts](https://blocksec.com/blog/secure-smart-contract-development-code-reentrancy-in-nft-contracts-1): Explore the critical security concerns in NFT smart contracts, focusing on the reentrancy vulnerability and its impact on the Ethereum ecosystem (Feb 7 2024) [Top 10 "Awesome" Security Incidents in 2023](https://blocksec.com/blog/top-ten-awesome-security-incidents-in-2023): In this series of articles, we will illustrate the top ten security incidents that are worth mentioning in 2023 and their reasons. (Feb 5 2024) [Exploring the Tradeoff Between Convenience and Security in Unlimited Approval ERC20 Tokens](https://blocksec.com/blog/exploring-the-tradeoff-between-convenience-and-security-in-unlimited-approval-erc-20-tokens): Discover the delicate balance between ease of use and security in the world of ERC20 tokens with unlimited approval and its impact on the blockchain ecosystem (Feb 5 2024) [Enhancing Blockchain Security: The Role of Smart Contract Auditors](https://blocksec.com/blog/enhancing-blockchain-security-the-role-of-smart-contract-auditors): Discover the crucial role of smart contract auditors in blockchain security, safeguarding DeFi and NFT platforms from vulnerabilities and financial losses (Feb 5 2024) [LI.FI Attack: a Cross-chain Bridge Vulnerability? No, It’s Due to Unchecked External Call!](https://blocksec.com/blog/li-fi-attack-a-cross-chain-bridge-vulnerability-no-it-s-due-to-unchecked-external-call): "LI.FI's Cross-Chain Bridge Vulnerability: A Lesson in External Call Security for DeFi" - Offering insights into the need for better security practices in DeFi coding (Feb 4 2024) [Beyond the Market Risk: A Logic Bug Identified in SushiSwap's KashiPairMediumRiskV1 Contract](https://blocksec.com/blog/a-logic-bug-identified-in-sushiswaps-kashi-pair-medium-risk-v1-contract-1): Understanding the Impact of SushiSwap's Contract Flaw: Dozens of pools on Ethereum and BSC were at risk due to the KashiPairMediumRiskV1 contract's logic bug (Feb 4 2024) [Attack Analysis | How Unchecked Mapping Makes $200,000,000 Losses of Nomad Bridge](https://blocksec.com/blog/how-unchecked-mapping-makes-200-M-losses-of-nomad-bridge): How Nomad Bridge's Security Was Compromised: Analysis of the code that led to Nomad Bridge's vulnerability and the subsequent exploit of nearly $200M (Feb 4 2024) [The Analysis of the Sanshu Inu Security Incident](https://blocksec.com/blog/the-analysis-of-the-sanshu-inu-security-incident): Ethereum Blockchain Exploit: Sanshu Inu Suffers Smart Contract Attack Revealed by DeFiRanger (Feb 4 2024) [The Analysis of the Array Finance Security Incident](https://blocksec.com/blog/the-analysis-of-the-array-finance-security-incident): Exploring the Array Finance Exploit: A Step-by-Step Attack Analysis" - A detailed breakdown of the malicious transactions that compromised Array Finance, offering insights into DeFi vulnerabilities (Feb 4 2024) [Revest Finance Vulnerabilities: More than Re-entrancy](https://blocksec.com/blog/revest-finance-vulnerabilities-more-than-re-entrancy): Securing the Future of DeFi: Lessons Learned from Revest Finance's Vulnerabilities (Feb 4 2024) [Podcast: How BlockSec Intercepted $15M of Web3 Exploits in Real Time](https://blocksec.com/blog/podcast-how-block-sec-intercepted-15-m-of-web3-exploits-in-real-time-1): Andy Zhou, as a guest on the Scraping Bits podcast, discusses how to block attacks in the Web3 area. (Feb 2 2024) [BlockSec’s Perspectives and Solutions on the Security of L2 Blockchains](https://blocksec.com/blog/blocksec-perspectives-and-solutions-on-the-security-of-l2-blockchains): We will first systematically review the security challenges of L2 blockchains and then propose our solutions. (Feb 1 2024) [The Analysis of the DAOMaker Attack](https://blocksec.com/blog/the-analysis-of-the-dao-maker-attack): Explore the step-by-step breakdown of the DAOMaker attack, examining the smart contract vulnerabilities that led to unauthorized admin role assignments and illicit fund withdrawals (Jan 29 2024) [Our Take on the Inverse Finance Security Incident: Price Manipulation Attack](https://blocksec.com/blog/our-take-on-the-inverse-finance-security-incident-price-manipulation-attack): Flashloan Exploit in Inverse Finance: Attacker Profits Nearly $100k USDT and 53.2 WBTC (Jan 29 2024) [A New Memory Overwrite Vulnerability Discovered in Wyvern Protocol](https://blocksec.com/blog/a-new-memory-overwrite-vulnerability-discovered-in-wyvern-protocol): Wyvern Protocol Vulnerability Alert: Potential for Exploit Leads to Security Concerns (Jan 29 2024) [A Short Analysis of the Wild Exploitation of CVE-2021–39137](https://blocksec.com/blog/a-short-analysis-of-the-wild-exploitation-of-cve-2021-39137): Explore the security breakdown of the CVE-2021-39137 exploit and its impact on Ethereum's blockchain (Jan 29 2024) [Deposit Less, Get More: yCREDIT Attack Details](https://blocksec.com/blog/deposit-less-get-more-y-credit-attack-details): Exploiting yCREDIT: How Attackers Minted Excess Tokens for Profit" – Discover the vulnerability that disrupted yCREDIT's token balance (Jan 29 2024) [How to Become a Smart Contract Auditor: Your Guide to Mastering Blockchain Security](https://blocksec.com/blog/how-to-become-a-smart-contract-auditor-your-guide-to-mastering-blockchain-security): Discover the essential steps to mastering smart contract audits with our comprehensive guide. Learn the skills, tools, and best practices needed to excel in blockchain security and become a pivotal player in the world of DeFi and NFTs (Jan 27 2024) [How to Exploit the Same Vulnerability of MetaPool in Two Different Ways (Nerve Bridge / Saddle Finance): What You See Is Not What You Get](https://blocksec.com/blog/how-to-exploit-the-same-vulnerability-of-meta-pool-in-two-different-ways-nerve-bridge-saddle-finance-what-you-see-is-not-what-you-get): Exploring the Repeat Exploitation of MetaPool's Flaw in Nerve Bridge and Saddle Finance Incidents" – uncovering the persistence of a crypto vulnerability (Jan 25 2024) [Secure the Solana Ecosystem (2) — Calling Between Programs](https://blocksec.com/blog/secure-the-solana-ecosystem-2-calling-between-programs): Master the art of cross-program invocation in Solana with our comprehensive guide and hands-on examples, taking your smart contract development to the next level (Jan 25 2024) [When "SafeTransfer" Becomes Unsafe: Lessons from the QBridge Security Incident](https://blocksec.com/blog/when-safe-transfer-becomes-unsafe-lessons-from-the-q-bridge-security-incident): QBridge hack analysis: learn how a safeTransfer flaw helped enable an $80M theft on Jan 28, plus key fixes to reduce smart contract risk. (Jan 25 2024) [How the Mirror Protocol got Exploited](https://blocksec.com/blog/how-the-mirror-protocol-got-exploited): Revealing How an Attacker Exploited Mirror Protocol by Manipulating mETH and USTC Values (Jan 25 2024) [The Further Analysis of the Poly Network Attack](https://blocksec.com/blog/the-further-analysis-of-the-poly-network-attack): Delve into the attack flow on Ethereum, revealing a cross-chain exploit spanning Ontology, Poly, and Ethereum chains (Jan 25 2024) [Public Transfer Vulnerability of the Tether Gold Smart Contract](https://blocksec.com/blog/public-transfer-vulnerability-of-the-tether-gold-smart-contract): Describe a public transfer vulnerability in Tether Gold smart contract (Jan 21 2024) [How Akutar NFT Loses $34,000,000 USD](https://blocksec.com/blog/how-akutar-nft-loses-34-m-usd): Uncovering serious logic vulnerabilities in @AkuDreams contracts, leading to a potential DoS attack and permanent locking of project funds (Jan 20 2024) [Reveal the “Message’’ Replay Attacks on EthereumPoW](https://blocksec.com/blog/reveal-the-message-replay-attacks-on-ethereum-po-w): Learn about recent attacks on EthereumPoW involving message replay, highlighting the vulnerability in the Omni bridge and the need for chainId verification (Jan 19 2024) [Price Manipulation Attack in Reality (Again): RariCapital Incident](https://blocksec.com/blog/price-manipulation-attack-in-reality-again-rari-capital-incident): Exploring Indirect Price Manipulation: Understanding the Attack on RariCapital (Jan 19 2024) [The Analysis of the Popsicle Finance Security Incident](https://blocksec.com/blog/the-analysis-of-the-popsicle-finance-security-incident): Attack Flow Unveiled: The Steps Taken by the Attacker to Exploit Popsicle Finance (Jan 19 2024) [Security and Privacy Concerns of Private Transaction Services on Binance Smart Chain](https://blocksec.com/blog/the-two-sides-of-the-private-tx-service-on-binance-smart-chain): The article explores privacy and security challenges of private transaction technologies in protecting users (Jan 19 2024) [Tiny Rounding Down, Big Fund Losses: An in-depth analysis of the recent Balancer incident](https://blocksec.com/blog/tiny-rounding-down-big-fund-losses-an-in-depth-analysis-of-the-recent-balancer-incident): A comprehensive analysis of the Balancer attack, which occurred on August 27 2023 (Jan 19 2024) [BlockSec Partners with IOC and AЯMRD to Enhance Web 3.0 Security](https://blocksec.com/blog/block-sec-partners-with-ioc-and-a-ya-mrd-to-enhance-web-3-0-security): BlockSec and Intelligence On Chain (IOC) have partnered to provide the 'AЯMRD' suite, delivering robust security solutions for Web 3.0 projects in the evolving blockchain landscape. (Jan 17 2024) [Security Audit Report for Cakepie Contracts](https://blocksec.com/blog/security-audit-report-for-cakepie-contracts): This is the security audit report that we conducted for Cakepie Contracts in November 2023. (Jan 16 2024) [Phalcon | Overview of the Web3 Security Landscape in 2023](https://blocksec.com/blog/phalcon-overview-of-the-web3-security-landscape-in-2023): In 2023, losses ranging from $100K to $200M occurred across 69 hacking incidents caused by the exploitation of vulnerabilities. (Jan 16 2024) [How a Critical Bug in Solana Network was Detected and Timely Patched](https://blocksec.com/blog/how-a-critical-bug-in-solana-network-was-detected-and-timely-patched): Solana Vulnerability: Contract Execution Path Affected by rBPF Bug (Jan 15 2024) [The Analysis of Nerve Bridge Security Incident](https://blocksec.com/blog/the-analysis-of-nerve-bridge-security-incident): Exploring the similarities between the Nerve Bridge and Synapse incidents, shedding light on the attacker's modus operandi (Jan 15 2024) [When “SafeMint” Becomes Unsafe: Lessons from the HypeBears Security Incident](https://blocksec.com/blog/when-safe-mint-becomes-unsafe-lessons-from-the-hype-bears-security-incident): Understanding the security vulnerability of the 'SafeMint' function in ERC721 contracts. (Jan 12 2024) [The Short Analysis of the Flashloan Attack to the APE AirDrop](https://blocksec.com/blog/the-short-analysis-of-the-flashloan-attack-to-the-ape-air-drop): Analysis of an attack that manipulated the spot price of assets to profit from an APE token airdrop (Jan 12 2024) [The Initial Analysis of the PolyNetwork Hack](https://blocksec.com/blog/the-initial-analysis-of-the-poly-network-hack): PolyNetwork Hack: Exploit Analysis of the Root Cause of the 300 Million USDs Attack on Multiple Chains (Jan 12 2024) [Tradeoff Between Convenience and Security: Unlimited Approval in ERC20](https://blocksec.com/blog/tradeoff-between-convenience-and-security-unlimited-approval-in-erc-20): Exploring the Risks of Unlimited Approval in Ethereum's ERC20 Token Standard. (Jan 12 2024) [Blocked Loot Attack: How Phalcon Saved $1.2M from Malicious Proposal](https://blocksec.com/blog/how-phlacon-block-helped-loot-block-1-m-usd-hack): The comprehensive process of how Phalcon saved more than 1 Million USD for Loot. (Jan 11 2024) [Telcoin Security Incident Post-mortem and In-Depth Analysis](https://blocksec.com/blog/telcoin-security-incident-in-depth-analysis): A comprehensive post-mortem and analysis of the security breach Telcoin experienced on Christmas Day 2023. (Jan 11 2024) [Recent DeFi Hacks: How BlockSec Phalcon Could Protect User Assets Worth Millions](https://blocksec.com/blog/recent-de-fi-hacks-how-phalcon-block-could-protect-user-assets-worth-millions): Recent Hacks Highlight Need for Around-the-Clock Blockchain Security Through Automation (Jan 9 2024) [Security Testing Report for Radiant V2](https://blocksec.com/blog/security-testing-report-for-radiant-v2): This is the security testing report that we conducted for Radiant V2 in March 2023. (Jan 9 2024) [New Integer Overflow Bug Discovered in Solana rBPF](https://blocksec.com/blog/new-integer-overflow-bug-discovered-in-solana-r-bpf): Integer Overflow Bug Found in Solana's Virtual Machine That Puts the Network at Risk (Jan 8 2024) [DeFi Exploit Analysis: The Root Cause of Euler's $200M Loss](https://blocksec.com/blog/defi-exploit-analysis-root-cause-euler-s-200m): Explore the Euler Finance exploit that led to a $200M DeFi loss. Learn the root causes, attack methods, and how to protect your blockchain assets today. (Jan 5 2024) [Security Check: Do EVM-Compatible Chains Hold Up?](https://blocksec.com/blog/security-check-do-evm-compatible-chains-hold-up): Revealing Hidden Security Risks in the EVM: How BlockSec's Automated Tool Helps Take a Closer Look (Jan 5 2024) [Phalcon's 2023 Year-End Recap](https://blocksec.com/blog/phalcon-s-2023-year-end-recap): Through the story of Phalcon, let's explore the relentless efforts made by BlockSec to advance Web3 security in 2023. (Dec 29 2023) [Blocked Paraspace Attack: Industry's Most Important Block that Rescued $5,000,000](https://blocksec.com/blog/blocked-paraspace-attack-industry-s-most-important-block-that-rescued-5-000-000): Let's take a look at the industry's industry's most important block that rescued $5,000,000. (Dec 22 2023) [Blocked Platypus Attack: Industry's First Counter-Exploitation of a Hacker's Contract](https://blocksec.com/blog/blocked-platypus-attack-industry-s-first-counter-exploitation-of-a-hacker-s-contract): Let's take a look at the industry's first counter-exploitation of a hacker's contract. (Dec 21 2023) [Blocked TransitSwap Attack: Industry's First "Hacking Back" to Rescue $300,000](https://blocksec.com/blog/blocked-transit-swap-attack-industry-s-first-hacking-back-to-rescue-300-000): Let's take a look at the industry's first "hacking back" that rescued $300,000. (Dec 20 2023) [Blocked Saddle Finance Attack: Industry's First Influential Blocking to Rescue $3,800,000](https://blocksec.com/blog/blocked-saddle-finance-attack-industry-s-first-influential-blocking-to-rescue-3-800-000): Let's take a look at the industry's first influential blocking that rescued $3,800,000. (Dec 19 2023) [Blocked HomeCoin Attack: Industry's First Successful Blocking Story](https://blocksec.com/blog/blocked-home-coin-attack-the-industry-s-first-successful-blocking-story): Let's learn about the game-changing story in Web3: the industry's first successful defense against hacks. (Dec 18 2023) [Ten Most Frequently Asked Questions About BlockSec Phalcon](https://blocksec.com/blog/ten-most-frequently-asked-questions-about-phalcon-block): We have found that users are particularly interested in the following questions about BlockSec Phalcon... (Dec 15 2023) [Yet Another Tragedy of Precision Loss: An In-Depth Analysis of the KyberSwap Incident](https://blocksec.com/blog/yet-another-tragedy-of-precision-loss-an-in-depth-analysis-of-the-kyber-swap-incident-1): This article dives deep into the attacks targeting KyberSwap and gives a detailed analysis of the root cause of the issue: precision loss. (Dec 5 2023) [TxPhishScope: Detecting Transaction-Based Phishing on Ethereum](https://blocksec.com/blog/unveiling-block-sec-s-large-scale-tx-phish-website-detection-system): BlockSec's TxPhishScope detected 33,130+ phishing websites on Ethereum. Learn how transaction-based phishing works and how to defend against it. (Nov 24 2023) [Lethal Integration: Vulnerabilities in Hooks Due to Risky Interactions](https://blocksec.com/blog/lethal-integration-vulnerabilities-in-hooks-due-to-risky-interactions): In this article, we explore the vulnerabilities that arise during hook interaction logic, specifically concentrating on two scenarios: flawed access control and improper input validation. (Nov 20 2023) [BlockSec Launches Phalcon: The World's First Crypto Hack Blocking System for Web3 Security](https://blocksec.com/blog/block-sec-launches-phalcon-block-the-world-s-first-crypto-hack-blocking-system-for-web3-security): BlockSec Phalcon will revolutionize the fight against hackers in the Web3 world. (Nov 15 2023) [As an LP, How to Withdraw Funds Timely Before Protocol Pauses](https://blocksec.com/blog/as-an-lp-how-to-withdraw-funds-timely-before-protocol-pauses): BlockSec and Cobo have collaborated to develop a solution that assists LPs in withdrawing funds before the protocol pauses and the liquidity pool freezes. (Nov 14 2023) [Thorns in the Rose: Exploring Security Risks in Uniswap v4's Novel Hook Mechanism](https://blocksec.com/blog/thorns-in-the-rose-exploring-security-risks-in-uniswap-v4-s-novel-hook-mechanism): This is the first article of our series exploring security risks in Uniswap v4’s hook mechanism! In this article, we provide a comprehensive overview and foundational understanding for our readers. (Nov 6 2023) [Unlocking Web3 Security: How BlockSec Combats DeFi Hacks](https://blocksec.com/blog/unlocking-web3-security-battling-the-dark-side-1): In the ever-evolving world of Web3, the significance of security cannot be overstated. Despite bear market conditions, the alarming surge in DeFi hacks and scams has raised concerns. (Sep 5 2023) [Factors Making Web3 More Vulnerable to Hacks and Our Mitigation Strategies](https://blocksec.com/blog/factors-making-web3-more-vulnerable-to-hacks-and-our-mitigation-strategies): In a world where blockchain hacks and capital exploitation seem to occur almost weekly, the question arises: Can we effectively prevent these security breaches? (Aug 30 2023) [BlockSec Phalcon Explorer: Empowering TVL Growth for the EVM Chain](https://blocksec.com/blog/blocksec-phalcon-explorer-empowering-tvl-growth-evm-chain): Discover how Phalcon Explorer drives TVL growth on EVM chains. Explore DeFi analytics and boost your blockchain insights today with BlockSec. (Aug 24 2023) [What Are the 7 Key Features of Transaction Simulation Phalcon Explorer 1.0](https://blocksec.com/blog/beyond-7-days-exploring-the-endless-possibilities-of-phalcon-beyond-7-days-exploring-the-endless-possibilities-of-phalcon): We were thrilled to receive so much positive feedback and engagement from both longtime users and new followers after launching our 7 Days of Phalcon journey on Twitter. (May 31 2023) [Phalcon Debug Transaction: Step-by-Step Guide to Analyze Efficiently](https://blocksec.com/blog/use-phalcon-debug-dive-transaction): Learn how to use Phalcon debug transaction features to analyze blockchain transactions efficiently. Explore debug mode, console, and sharing tools now. (Mar 29 2023) [Systematic Approach to Maintaining EVM Compatibility and Security](https://blocksec.com/blog/systematic-approach-to-maintaining-evm-compatibility-and-security-1): EVM (Ethereum Virtual Machine) compatible blockchains are designed to be compatible with the Ethereum blockchain’s smart contract functionality, programming language (Solidity), and tooling ecosystem. (Mar 27 2023) [How did BlockSec Save $5M Worth of Crypto Assets in Successful ParaSpace Attack Blocking](https://blocksec.com/blog/proactive-threat-prevention-a-new-web3-security-paradigm-1): On 2023–03–17 05:48:59 (UTC), BlockSec successfully blocked an attack attempt on ParaSpace (a top NFT lending protocol) and protected crypto assets worth $5M. (Mar 17 2023) [Securing Web3 Through Proactive Threat Prevention](https://blocksec.com/blog/securing-web3-through-proactive-threat-prevention-1): In the past three years, we have observed several security incidents in the DeFi ecosystem. To defend the threats, code-centric methods, e.g., static code auditing, smart contract scanning tool, or dynamic fuzzing, are adopted by the… (Jan 28 2023) [How to Master DeFi Transaction Analysis with Phalcon Explorer 2.0](https://blocksec.com/blog/getting-started-with-phalcon-2-0-2): Phalcon is a powerful transaction explorer designed for DeFi community. It provides comprehensive data on invocation flow, balance changes, and fund flows for transactions. It also supports transaction simulation. (Jan 5 2023) [How to Make Blockchain Attacks Blockable: 5 Proven Strategies](https://blocksec.com/blog/make-blockchain-attack-blockable): Learn how to make blockchain attacks blockable with proven DeFi security strategies. Protect your smart contracts now with expert blockchain solutions. (Mar 7 2022) ## Optional - [robots.txt](https://blocksec.com/robots.txt) - [sitemap.xml](https://blocksec.com/sitemap.xml)