月度安全评审:2024年10月

月度安全评审:2024年10月

安全一览 👀

Radiant: 5800 万美元

10 月 16 日,Radiant Capital 在 Arbitrum 和 BSC 上遭遇安全漏洞,损失金额超过 5000 万美元。虽然本次攻击的完整技术细节尚未披露,但协议团队确认攻击者利用了数个开发者钱包的漏洞。

阅读 Radiant 的事后分析报告了解更多详情

未知: 140 万美元

10 月 24 日,一个未知的 Compound 分叉协议在 Base 上遭到攻击,损失约 140 万美元。尽管事发时受影响的合约未经验证,但我们的分析表明,此次攻击很可能是由于其对 Uniswap 现货价格的脆弱价格依赖性所致。

通过 Phalcon 安全事件列表查看完整的攻击交易

EGA: 55.4 万美元

10 月 5 日,一个未经验证的合约在 BSC 上遭到攻击,造成 55.4 万美元的损失。根本原因是购买 EGA 代币的函数缺乏滑点保护,容易受到价格操纵攻击。

使用 Phalcon Explorer 追踪攻击详情

P719: 31.5 万美元

10 月 11 日,P719 代币在 BSC 上遭到攻击,损失 31.5 万美元。尽管受损合约未经验证,但我们怀疑根本原因是 P719 交易功能内的代币销毁机制存在缺陷。

订阅 Phalcon 以获取实时警报和自动化操作。

在攻击执行前阻止黑客行为,防止任何损失!

了解更多预约演示

BlockSec 出席 Better Web3 Forum 2024 🔥

观看 BlockSec 联合创始人周亚金在 Better Web3 Forum 2024 上的演讲,了解最新的安全趋势、过往事件的教训、为什么仅靠审计是不够的,以及项目方如何确保协议安全。

Sign up for the latest updates
Weekly Web3 Security Incident Roundup | Feb 9 – Feb 15, 2026

Weekly Web3 Security Incident Roundup | Feb 9 – Feb 15, 2026

During the week of February 9 to February 15, 2026, three blockchain security incidents were reported with total losses of ~$657K. All incidents occurred on the BNB Smart Chain and involved flawed business logic in DeFi token contracts. The primary causes included an unchecked balance withdrawal from an intermediary contract that allowed donation-based inflation of a liquidity addition targeted by a sandwich attack, a post-swap deflationary clawback that returned sold tokens to the caller while draining pool reserves to create a repeatable price-manipulation primitive, and a token transfer override that burned tokens directly from a Uniswap V2 pair's balance and force-synced reserves within the same transaction to artificially inflate the token price.

Top 10 "Awesome" Security Incidents in 2025

Top 10 "Awesome" Security Incidents in 2025

To help the community learn from what happened, BlockSec selected ten incidents that stood out most this year. These cases were chosen not only for the scale of loss, but also for the distinct techniques involved, the unexpected twists in execution, and the new or underexplored attack surfaces they revealed.

#10 Panoptic Incident: XOR Linearity Breaks the Position Fingerprint Scheme

#10 Panoptic Incident: XOR Linearity Breaks the Position Fingerprint Scheme

On August 29, 2025, Panoptic disclosed a Cantina bounty finding and confirmed that, with support from Cantina and Seal911, it executed a rescue operation on August 25 to secure roughly $400K in funds. The issue stemmed from a flaw in Panoptic’s position fingerprint calculation algorithm, which could have enabled incorrect position identification and downstream fund risk.