Back to Blog

BlockSec 完成 Neo X 安全审计

Code Auditing
August 1, 2024
2 min read

在当今快速发展的区块链领域,各种区块链网络层出不穷。对于项目和用户而言,这些网络的安全对于安全部署和链上交互至关重要,因此安全审计在确保区块链安全方面必不可少。

我们非常激动地宣布,BlockSec 已为 Neo X 完成安全审计。Neo X 是 Neo 的一个兼容 EVM 的侧链,能够消除有毒 MEV。我们通过系统化和注重业务逻辑的方法,提供了全面的安全审计,为 Neo X 生态系统奠定了坚实的第一道防线。

您可以在 此处 查看审计报告。

Neo X 简介:简要概述

Neo X 是一个兼容 EVM 的侧链,融合了 Neo 独特的委托拜占庭容错 (dBFT) 共识机制。它的推出标志着 Neo 在从 Neo Legacy 升级到 Neo N3 之后迈出了重要一步。

Neo X 作为 Neo N3 和广泛使用的 EVM 网络之间的桥梁,将在扩展 Neo 生态系统和为开发人员提供更多创新机会方面发挥至关重要的作用。正如设计文档中所述,dBFT 协议在投票时所需的共识阈值超过一半(即 1/2 而非 2/3)。这意味着 4 个验证者足以达成共识,因为每个时期将选出前 7 名候选者。

BlockSec 对 Neo X 的审计

此次审计重点关注 Neo X 节点的安全性,该节点是基于以太坊协议执行层的 Golang 实现。审计范围涵盖了原始 Geth 实现与分叉部分之间的差异。

总而言之,我们发现了一些需要关注的、不同风险等级的问题。Neo 团队已及时响应并解决了这些问题,确保 Neo X 网络达到高安全标准,并为其未来增长奠定了坚实的基础。

关于 BlockSec

BlockSec 确保区块链生态系统在其整个生命周期中的安全性。

我们提供全面的 EVM 链审计服务,以确保在上线前阶段具有强大的安全性。凭借我们尖端的研发能力和系统化的审计方法,我们在区块链审计方面表现出色。我们在著名会议上发表了多篇区块链安全论文,并报告了无数零日攻击,这都证明了我们的专业知识。

我们的攻击监控和阻止平台 Phalcon 确保在上线后的阶段区块链安全。Phalcon 使支持链上的项目能够检测可疑交易,接收即时警报,并自动阻止黑客攻击。此外,Phalcon 还包含一个增强用户体验的支持工具:Phalcon Explorer,这是一个交易可视化工具,可帮助用户轻松查看和分析可疑交易。

我们尊贵的区块链客户包括 Neo X、Manta、Merlin、Polygon zkEVM、XAI、EOS Network Foundation、Kava、NEAR Foundation、Evmos、Aurora 等。

您可以在 此处 为您的项目安排一次全面的安全审计。

您可以在 此处 预约一次 Phalcon 的快速演示。

Sign up for the latest updates
~$15.9M Lost: Trusted Volumes & More | BlockSec Weekly
Security Insights

~$15.9M Lost: Trusted Volumes & More | BlockSec Weekly

This BlockSec bi-weekly security report covers 11 notable attack incidents identified between April 27 and May 10, 2026, across Sui, Ethereum, BNB Chain, Base, Blast, and Berachain, with total estimated losses of approximately $15.9M. Three incidents are analyzed in detail: the highlighted $1.14M Aftermath Finance exploit on Sui, where a signed/unsigned semantic mismatch in the builder-fee validation allowed an attacker to inject a negative fee that was converted into positive collateral during settlement; the $5.87M Trusted Volumes RFQ authorization mismatch on Ethereum; and the $5.7M Wasabi Protocol infrastructure-to-contract-control compromise across multiple EVM chains.

Newsletter - April 2026
Security Insights

Newsletter - April 2026

In April 2026, the DeFi ecosystem experienced three major security incidents. KelpDAO lost ~$290M due to an insecure 1-of-1 DVN bridge configuration exploited via RPC infrastructure compromise, Drift Protocol suffered ~$285M from a multisig governance takeover leveraging Solana's durable nonce mechanism, and Rhea Finance incurred ~$18.4M following a business logic flaw in its margin-trading module that allowed circular swap path manipulatio

~$7.04M Lost: GiddyDefi, Volo Vault & More | BlockSec Weekly
Security Insights

~$7.04M Lost: GiddyDefi, Volo Vault & More | BlockSec Weekly

This BlockSec weekly security report covers eight attack incidents detected between April 20 and April 26, 2026, across Ethereum, Avalanche, Sui, Base, HyperLiquid, and MegaETH, with total estimated losses of approximately $7.04M. The highlighted incident is the $1.3M GiddyDefi exploit, where the attacker did not break any cryptography or use a flash loan but simply replayed an existing on-chain EIP-712 signature with the unsigned `aggregator` and `fromToken` fields swapped out for a malicious contract, demonstrating how partial signature coverage turns any historical signature into a generic permit. Other incidents include a $3.5M Volo Vault operator key compromise on Sui, a $1.5M Purrlend privileged-role takeover, a $413K SingularityFinance oracle misconfiguration, a $142.7K Scallop cross-pool index injection, a $72.35K Kipseli Router decimal mismatch, a $50.7K REVLoans (Juicebox) accounting pollution, and a $64K Custom Rebalancer arbitrary-call exploit.

Best Security Auditor for Web3

Validate design, code, and business logic before launch. Aligned with the highest industry security standards.

BlockSec Audit