Back to Blog

10月月度安全审查

November 1, 2024
2 min read

安全速览 👀

Radiant: 5800万美元

10月16日,Radiant Capital 在Arbitrum和BSC上遭受安全漏洞,损失超过5000万美元。尽管攻击的确切技术细节尚未披露,但协议团队确认攻击者利用了几个开发者钱包作为攻击入口。

阅读Radiant的复盘报告了解更多详情

未知协议: 140万美元

10月24日,Base链上一个未知的Compound分叉协议被利用,导致约140万美元的损失。虽然事发时受影响的合约未经验证,但我们的分析 表明,此次攻击很可能源于对Uniswap现货价格的价格依赖漏洞。

通过Phalcon安全事件列表查看完整的攻击交易

EGA: 55.4万美元

10月5日,BSC链上一个未经验证的合约被利用,造成55.4万美元的损失。根本原因在于购买EGA代币的Pancake交易对的函数缺乏滑点保护,容易受到价格操纵攻击。

使用Phalcon Explorer追踪攻击详情

P719: 31.5万美元

10月11日,P719代币 在BSC上被利用,造成31.5万美元的损失。虽然受损合约未经验证,但我们怀疑根本原因在于P719交易功能中存在缺陷的代币销毁机制。

订阅Phalcon以获得实时警报和自动化操作。

在攻击执行前阻止其发生,以防止任何损失!

了解更多预约演示

BlockSec亮相Better Web3 Forum 2024 🔥

观看BlockSec联合创始人周亚津在Better Web3 Forum 2024上的演讲,了解最新的安全趋势、过往事件的经验教训,为何仅靠审计不足以保证安全,以及项目方如何确保协议安全。

Sign up for the latest updates
Newsletter - April 2026
Security Insights

Newsletter - April 2026

In April 2026, the DeFi ecosystem experienced three major security incidents. KelpDAO lost ~$290M due to an insecure 1-of-1 DVN bridge configuration exploited via RPC infrastructure compromise, Drift Protocol suffered ~$285M from a multisig governance takeover leveraging Solana's durable nonce mechanism, and Rhea Finance incurred ~$18.4M following a business logic flaw in its margin-trading module that allowed circular swap path manipulatio

~$7.04M Lost: GiddyDefi, Volo Vault & More | BlockSec Weekly
Security Insights

~$7.04M Lost: GiddyDefi, Volo Vault & More | BlockSec Weekly

This BlockSec weekly security report covers eight attack incidents detected between April 20 and April 26, 2026, across Ethereum, Avalanche, Sui, Base, HyperLiquid, and MegaETH, with total estimated losses of approximately $7.04M. The highlighted incident is the $1.3M GiddyDefi exploit, where the attacker did not break any cryptography or use a flash loan but simply replayed an existing on-chain EIP-712 signature with the unsigned `aggregator` and `fromToken` fields swapped out for a malicious contract, demonstrating how partial signature coverage turns any historical signature into a generic permit. Other incidents include a $3.5M Volo Vault operator key compromise on Sui, a $1.5M Purrlend privileged-role takeover, a $413K SingularityFinance oracle misconfiguration, a $142.7K Scallop cross-pool index injection, a $72.35K Kipseli Router decimal mismatch, a $50.7K REVLoans (Juicebox) accounting pollution, and a $64K Custom Rebalancer arbitrary-call exploit.

The Decentralization Dilemma: Cascading Risk and Emergency Power in the KelpDAO Crisis
Security Insights

The Decentralization Dilemma: Cascading Risk and Emergency Power in the KelpDAO Crisis

This BlockSec deep-dive analyzes the KelpDAO $290M rsETH cross-chain bridge exploit (April 18, 2026), attributed to the Lazarus Group, tracing a causal chain across three layers: how a single-point DVN dependency enabled the attack, how DeFi composability cascaded the damage through Aave V3 lending markets to freeze WETH liquidity exceeding $6.7B across Ethereum, Arbitrum, Base, Mantle, and Linea, and how the crisis forced decentralized governance to exercise centralized emergency powers. The article examines three parameters that shaped the cascade's severity (LTV, pool depth, and cross-chain deployment count) and provides an exclusive technical breakdown of Arbitrum Security Council's forced state transition, an atomic contract upgrade that moved 30,766 ETH without the holder's signature.