Back to Blog

BlockSec 完成对 Neo X 的安全审计

Code Auditing
August 1, 2024

在区块链快速发展的今天,众多区块链网络不断涌现。对于项目和用户来说,这些网络的安全性对于安全部署和链上互动至关重要,因此安全审计对于确保区块链安全至关重要。

我们非常高兴地宣布,BlockSec 已经完成了 Neo X 的安全审计,这是 Neo 的 EVM 兼容侧链,能够消除有毒的 MEV。我们通过系统化和以业务逻辑为重点的方法提供了全面的安全审计,为 Neo X 生态系统建立了强大的第一道防线。

您可以查看审计报告 此处

介绍尼欧 X:概述

尼欧X是一款兼容EVM的侧链,采用了尼欧独特的委托拜占庭容错(dBFT)共识机制。它的推出标志着自 Neo Legacy 升级到 Neo N3 以来,尼欧又向前迈进了一大步。

作为连接 Neo N3 和广泛使用的 EVM 网络的桥梁,Neo X 将在扩展 Neo 生态系统和为开发者提供更多创新机会方面发挥重要作用。如设计文件所述,dBFT 协议要求超过一半(即 1/2,而不是 2/3)作为投票的共识阈值。这意味着 4 个验证者就足以达成共识,因为每个纪元都将选出前 7 个候选者。

BlockSec 对 Neo X 的审计

该审计特别关注 Neo X 节点的安全性,它是基于以太坊协议执行层的 Golang 实现。审计范围包括原始Geth实现和分叉部分之间的差异。

总之,我们发现了几个需要关注的不同风险级别的问题。Neo 团队已及时响应并解决了这些问题,确保 Neo X 网络符合高安全标准,并为其未来发展奠定了坚实的基础。

关于BlockSec

BlockSec确保区块链生态系统在整个生命周期内的安全性。

我们提供全面的 EVM 链审计服务,以确保在发布前阶段的稳健安全性。凭借尖端的研究能力和系统化的审计方法,我们在区块链审计领域表现出色。我们在著名会议上多次发表区块链安全论文,并多次报告零日攻击事件,这些都证明了我们的专业知识。

我们的攻击监控和拦截平台 Phalcon,可确保区块链在发布后阶段的安全性。Phalcon 使受支持链的项目能够检测可疑交易、接收即时警报并自动阻止黑客攻击。此外,Phalcon 还包括一款可增强用户体验的支持工具:Phalcon Explorer是一个交易可视化工具,可帮助用户轻松查看和分析可疑交易。

我们尊敬的区块链客户包括 Neo X、Manta、Merlin、Polygon zkEVM、XAI、EOS 网络基金会、Kava、NEAR 基金会、Evmos、Aurora 等。

为您的项目安排一次全面的安全审计 此处

预订 Phalcon 快速演示 此处

Sign up for the latest updates
Drift Protocol Incident: Multisig Governance Compromise via Durable Nonce Exploitation
Security Insights

Drift Protocol Incident: Multisig Governance Compromise via Durable Nonce Exploitation

On April 1, 2026 (UTC), Drift Protocol on Solana suffered a $285.3M loss after an attacker exploited Solana's durable nonce mechanism to delay the execution of phished multisig approvals, ultimately transferring administrative control of the protocol's 2-of-5 Squads governance with zero timelock. With full admin privileges, the attacker created a malicious collateral market (CVT), inflated its oracle price, relaxed withdrawal protections, and drained USDC, JLP, SOL, cbBTC, and other assets through 31 rapid withdrawals in approximately 12 minutes. This incident highlights how durable nonce-based delayed execution can decouple signer intent from on-chain execution, bypassing the temporal assumptions that multisig security implicitly relies on.

Weekly Web3 Security Incident Roundup | Mar 23 – Mar 29, 2026
Security Insights

Weekly Web3 Security Incident Roundup | Mar 23 – Mar 29, 2026

This BlockSec weekly security report covers eight DeFi attack incidents detected between March 23 and March 29, 2026, across Ethereum and BNB Chain, with total estimated losses of approximately $1.53M. Incidents include a $679K flawed burn mechanism exploit on the BCE token, a $512K spot-price manipulation attack on Cyrus Finance's PancakeSwap V3 liquidity withdrawal, a $133.5K flash-loan-driven referral reward manipulation on a TUR staking contract, and multiple integer overflow, reentrancy, and accounting error vulnerabilities in DeFi protocols. The report provides detailed vulnerability analysis and attack transaction breakdowns for each incident.

Newsletter -  March 2026
Security Insights

Newsletter - March 2026

In March 2026, the DeFi ecosystem experienced three major security incidents. Resolv Protocol lost ~$80M due to compromised privileged infrastructure keys, BitcoinReserveOffering suffered ~$2.7M from a double-minting logic flaw, and Venus Protocol incurred ~$2.15M following a donation attack combined with market manipulation.

Best Security Auditor for Web3

Validate design, code, and business logic before launch. Aligned with the highest industry security standards.

BlockSec Audit