Back to Blog

BlockSec 完成 Neo X 安全审计

Code Auditing
August 1, 2024
2 min read

在当今快速发展的区块链领域,各种区块链网络层出不穷。对于项目和用户而言,这些网络的安全对于安全部署和链上交互至关重要,因此安全审计在确保区块链安全方面必不可少。

我们非常激动地宣布,BlockSec 已为 Neo X 完成安全审计。Neo X 是 Neo 的一个兼容 EVM 的侧链,能够消除有毒 MEV。我们通过系统化和注重业务逻辑的方法,提供了全面的安全审计,为 Neo X 生态系统奠定了坚实的第一道防线。

您可以在 此处 查看审计报告。

Neo X 简介:简要概述

Neo X 是一个兼容 EVM 的侧链,融合了 Neo 独特的委托拜占庭容错 (dBFT) 共识机制。它的推出标志着 Neo 在从 Neo Legacy 升级到 Neo N3 之后迈出了重要一步。

Neo X 作为 Neo N3 和广泛使用的 EVM 网络之间的桥梁,将在扩展 Neo 生态系统和为开发人员提供更多创新机会方面发挥至关重要的作用。正如设计文档中所述,dBFT 协议在投票时所需的共识阈值超过一半(即 1/2 而非 2/3)。这意味着 4 个验证者足以达成共识,因为每个时期将选出前 7 名候选者。

BlockSec 对 Neo X 的审计

此次审计重点关注 Neo X 节点的安全性,该节点是基于以太坊协议执行层的 Golang 实现。审计范围涵盖了原始 Geth 实现与分叉部分之间的差异。

总而言之,我们发现了一些需要关注的、不同风险等级的问题。Neo 团队已及时响应并解决了这些问题,确保 Neo X 网络达到高安全标准,并为其未来增长奠定了坚实的基础。

关于 BlockSec

BlockSec 确保区块链生态系统在其整个生命周期中的安全性。

我们提供全面的 EVM 链审计服务,以确保在上线前阶段具有强大的安全性。凭借我们尖端的研发能力和系统化的审计方法,我们在区块链审计方面表现出色。我们在著名会议上发表了多篇区块链安全论文,并报告了无数零日攻击,这都证明了我们的专业知识。

我们的攻击监控和阻止平台 Phalcon 确保在上线后的阶段区块链安全。Phalcon 使支持链上的项目能够检测可疑交易,接收即时警报,并自动阻止黑客攻击。此外,Phalcon 还包含一个增强用户体验的支持工具:Phalcon Explorer,这是一个交易可视化工具,可帮助用户轻松查看和分析可疑交易。

我们尊贵的区块链客户包括 Neo X、Manta、Merlin、Polygon zkEVM、XAI、EOS Network Foundation、Kava、NEAR Foundation、Evmos、Aurora 等。

您可以在 此处 为您的项目安排一次全面的安全审计。

您可以在 此处 预约一次 Phalcon 的快速演示。

Sign up for the latest updates
The Decentralization Dilemma: Cascading Risk and Emergency Power in the KelpDAO Crisis
Security Insights

The Decentralization Dilemma: Cascading Risk and Emergency Power in the KelpDAO Crisis

This BlockSec deep-dive analyzes the KelpDAO $290M rsETH cross-chain bridge exploit (April 18, 2026), attributed to the Lazarus Group, tracing a causal chain across three layers: how a single-point DVN dependency enabled the attack, how DeFi composability cascaded the damage through Aave V3 lending markets to freeze WETH liquidity exceeding $6.7B across Ethereum, Arbitrum, Base, Mantle, and Linea, and how the crisis forced decentralized governance to exercise centralized emergency powers. The article examines three parameters that shaped the cascade's severity (LTV, pool depth, and cross-chain deployment count) and provides an exclusive technical breakdown of Arbitrum Security Council's forced state transition, an atomic contract upgrade that moved 30,766 ETH without the holder's signature.

Weekly Web3 Security Incident Roundup | Apr 13 – Apr 19, 2026
Security Insights

Weekly Web3 Security Incident Roundup | Apr 13 – Apr 19, 2026

This BlockSec weekly security report covers four attack incidents detected between April 13 and April 19, 2026, across multiple chains such as Ethereum, Unichain, Arbitrum, and NEAR, with total estimated losses of approximately $310M. The highlighted incident is the $290M KelpDAO rsETH bridge exploit, where an attacker poisoned the RPC infrastructure of the sole LayerZero DVN to fabricate a cross-chain message, triggering a cascading WETH freeze across five chains and an Arbitrum Security Council forced state transition that raises questions about the actual trust boundaries of decentralized systems. Other incidents include a $242K MMR proof forgery on Hyperbridge, a $1.5M signed integer abuse on Dango, and an $18.4M circular swap path exploit on Rhea Finance's Burrowland protocol.

Weekly Web3 Security Incident Roundup | Apr 6 – Apr 12, 2026
Security Insights

Weekly Web3 Security Incident Roundup | Apr 6 – Apr 12, 2026

This BlockSec weekly security report covers four DeFi attack incidents detected between April 6 and April 12, 2026, across Linea, BNB Chain, Arbitrum, Optimism, Avalanche, and Base, with total estimated losses of approximately $928.6K. Notable incidents include a $517K approval-related exploit where a user mistakenly approved a permissionless SquidMulticall contract enabling arbitrary external calls, a $193K business logic flaw in the HB token's reward-settlement logic that allowed direct AMM reserve manipulation, a $165.6K exploit in Denaria's perpetual DEX caused by a rounding asymmetry compounded with an unsafe cast, and a $53K access control issue in XBITVault caused by an initialization-dependent check that failed open. The report provides detailed vulnerability analysis and attack transaction breakdowns for each incident.

Best Security Auditor for Web3

Validate design, code, and business logic before launch. Aligned with the highest industry security standards.

BlockSec Audit