Back to Blog

10月月度安全审查

November 1, 2024
2 min read

安全速览 👀

Radiant: 5800万美元

10月16日,Radiant Capital 在Arbitrum和BSC上遭受安全漏洞,损失超过5000万美元。尽管攻击的确切技术细节尚未披露,但协议团队确认攻击者利用了几个开发者钱包作为攻击入口。

阅读Radiant的复盘报告了解更多详情

未知协议: 140万美元

10月24日,Base链上一个未知的Compound分叉协议被利用,导致约140万美元的损失。虽然事发时受影响的合约未经验证,但我们的分析 表明,此次攻击很可能源于对Uniswap现货价格的价格依赖漏洞。

通过Phalcon安全事件列表查看完整的攻击交易

EGA: 55.4万美元

10月5日,BSC链上一个未经验证的合约被利用,造成55.4万美元的损失。根本原因在于购买EGA代币的Pancake交易对的函数缺乏滑点保护,容易受到价格操纵攻击。

使用Phalcon Explorer追踪攻击详情

P719: 31.5万美元

10月11日,P719代币 在BSC上被利用,造成31.5万美元的损失。虽然受损合约未经验证,但我们怀疑根本原因在于P719交易功能中存在缺陷的代币销毁机制。

订阅Phalcon以获得实时警报和自动化操作。

在攻击执行前阻止其发生,以防止任何损失!

了解更多预约演示

BlockSec亮相Better Web3 Forum 2024 🔥

观看BlockSec联合创始人周亚津在Better Web3 Forum 2024上的演讲,了解最新的安全趋势、过往事件的经验教训,为何仅靠审计不足以保证安全,以及项目方如何确保协议安全。

Sign up for the latest updates
The Decentralization Dilemma: Cascading Risk and Emergency Power in the KelpDAO Crisis
Security Insights

The Decentralization Dilemma: Cascading Risk and Emergency Power in the KelpDAO Crisis

This BlockSec deep-dive analyzes the KelpDAO $290M rsETH cross-chain bridge exploit (April 18, 2026), attributed to the Lazarus Group, tracing a causal chain across three layers: how a single-point DVN dependency enabled the attack, how DeFi composability cascaded the damage through Aave V3 lending markets to freeze WETH liquidity exceeding $6.7B across Ethereum, Arbitrum, Base, Mantle, and Linea, and how the crisis forced decentralized governance to exercise centralized emergency powers. The article examines three parameters that shaped the cascade's severity (LTV, pool depth, and cross-chain deployment count) and provides an exclusive technical breakdown of Arbitrum Security Council's forced state transition, an atomic contract upgrade that moved 30,766 ETH without the holder's signature.

Weekly Web3 Security Incident Roundup | Apr 13 – Apr 19, 2026
Security Insights

Weekly Web3 Security Incident Roundup | Apr 13 – Apr 19, 2026

This BlockSec weekly security report covers four attack incidents detected between April 13 and April 19, 2026, across multiple chains such as Ethereum, Unichain, Arbitrum, and NEAR, with total estimated losses of approximately $310M. The highlighted incident is the $290M KelpDAO rsETH bridge exploit, where an attacker poisoned the RPC infrastructure of the sole LayerZero DVN to fabricate a cross-chain message, triggering a cascading WETH freeze across five chains and an Arbitrum Security Council forced state transition that raises questions about the actual trust boundaries of decentralized systems. Other incidents include a $242K MMR proof forgery on Hyperbridge, a $1.5M signed integer abuse on Dango, and an $18.4M circular swap path exploit on Rhea Finance's Burrowland protocol.

Weekly Web3 Security Incident Roundup | Apr 6 – Apr 12, 2026
Security Insights

Weekly Web3 Security Incident Roundup | Apr 6 – Apr 12, 2026

This BlockSec weekly security report covers four DeFi attack incidents detected between April 6 and April 12, 2026, across Linea, BNB Chain, Arbitrum, Optimism, Avalanche, and Base, with total estimated losses of approximately $928.6K. Notable incidents include a $517K approval-related exploit where a user mistakenly approved a permissionless SquidMulticall contract enabling arbitrary external calls, a $193K business logic flaw in the HB token's reward-settlement logic that allowed direct AMM reserve manipulation, a $165.6K exploit in Denaria's perpetual DEX caused by a rounding asymmetry compounded with an unsafe cast, and a $53K access control issue in XBITVault caused by an initialization-dependent check that failed open. The report provides detailed vulnerability analysis and attack transaction breakdowns for each incident.