Back to Blog

月度安全评审:2024年10月

November 1, 2024

安全一览 👀

Radiant: 5800 万美元

10 月 16 日,Radiant Capital 在 Arbitrum 和 BSC 上遭遇安全漏洞,损失金额超过 5000 万美元。虽然本次攻击的完整技术细节尚未披露,但协议团队确认攻击者利用了数个开发者钱包的漏洞。

阅读 Radiant 的事后分析报告了解更多详情

未知: 140 万美元

10 月 24 日,一个未知的 Compound 分叉协议在 Base 上遭到攻击,损失约 140 万美元。尽管事发时受影响的合约未经验证,但我们的分析表明,此次攻击很可能是由于其对 Uniswap 现货价格的脆弱价格依赖性所致。

通过 Phalcon 安全事件列表查看完整的攻击交易

EGA: 55.4 万美元

10 月 5 日,一个未经验证的合约在 BSC 上遭到攻击,造成 55.4 万美元的损失。根本原因是购买 EGA 代币的函数缺乏滑点保护,容易受到价格操纵攻击。

使用 Phalcon Explorer 追踪攻击详情

P719: 31.5 万美元

10 月 11 日,P719 代币在 BSC 上遭到攻击,损失 31.5 万美元。尽管受损合约未经验证,但我们怀疑根本原因是 P719 交易功能内的代币销毁机制存在缺陷。

订阅 Phalcon 以获取实时警报和自动化操作。

在攻击执行前阻止黑客行为,防止任何损失!

了解更多预约演示

BlockSec 出席 Better Web3 Forum 2024 🔥

观看 BlockSec 联合创始人周亚金在 Better Web3 Forum 2024 上的演讲,了解最新的安全趋势、过往事件的教训、为什么仅靠审计是不够的,以及项目方如何确保协议安全。

Sign up for the latest updates
Drift Protocol Incident: Multisig Governance Compromise via Durable Nonce Exploitation
Security Insights

Drift Protocol Incident: Multisig Governance Compromise via Durable Nonce Exploitation

On April 1, 2026 (UTC), Drift Protocol on Solana suffered a $285.3M loss after an attacker exploited Solana's durable nonce mechanism to delay the execution of phished multisig approvals, ultimately transferring administrative control of the protocol's 2-of-5 Squads governance with zero timelock. With full admin privileges, the attacker created a malicious collateral market (CVT), inflated its oracle price, relaxed withdrawal protections, and drained USDC, JLP, SOL, cbBTC, and other assets through 31 rapid withdrawals in approximately 12 minutes. This incident highlights how durable nonce-based delayed execution can decouple signer intent from on-chain execution, bypassing the temporal assumptions that multisig security implicitly relies on.

Weekly Web3 Security Incident Roundup | Mar 23 – Mar 29, 2026
Security Insights

Weekly Web3 Security Incident Roundup | Mar 23 – Mar 29, 2026

This BlockSec weekly security report covers eight DeFi attack incidents detected between March 23 and March 29, 2026, across Ethereum and BNB Chain, with total estimated losses of approximately $1.53M. Incidents include a $679K flawed burn mechanism exploit on the BCE token, a $512K spot-price manipulation attack on Cyrus Finance's PancakeSwap V3 liquidity withdrawal, a $133.5K flash-loan-driven referral reward manipulation on a TUR staking contract, and multiple integer overflow, reentrancy, and accounting error vulnerabilities in DeFi protocols. The report provides detailed vulnerability analysis and attack transaction breakdowns for each incident.

Newsletter -  March 2026
Security Insights

Newsletter - March 2026

In March 2026, the DeFi ecosystem experienced three major security incidents. Resolv Protocol lost ~$80M due to compromised privileged infrastructure keys, BitcoinReserveOffering suffered ~$2.7M from a double-minting logic flaw, and Venus Protocol incurred ~$2.15M following a donation attack combined with market manipulation.