Back to Blog

Phalcon 2023 年度回顾

January 1, 2024

2023年,Web3不仅承载着技术突破的愿景,也面临着前所未有的安全挑战。在这一年里,Phalcon也从一个交易浏览器蜕变为一个全面的安全套件。Phalcon现已覆盖协议安全的整个链条,从上线前测试、上线后监控和攻击阻断,到事后分析。

通过Phalcon的故事,让我们一起回顾BlockSec在2023年为推进Web3安全所做的持续不懈的努力。

Phalcon 的安全理念:超越代码审计 🤔💡

自BlockSec成立以来,我们的立场一直坚定不移——单凭代码审计不足以应对Web3黑暗森林中无处不在的安全风险(尽管我们在代码审计方面做得非常出色)。一旦项目上线,主动防御和快速响应机制就变得至关重要。

传统的攻击监控系统会向我们发出威胁警报,但项目团队往往反应迟缓或不确定如何有效应对。我们开始思考:如何才能标准化我们的事件响应能力,以便更好地协助更广泛的项目? 这催生了BlockSec Phalcon的诞生,一个旨在自动阻止攻击的系统。

今年2月,当Platypus协议遭受攻击时,BlockSec Phalcon帮助挽回了240万美元的潜在损失。

一个月后,该系统再次证明了其价值,成功拦截了针对Paraspace的攻击,挽回了约500万美元的损失。🛡️💰

11月,在伊斯坦布尔举行的Devconnect大会上,BlockSec Phalcon的发布标志着一个重要的里程碑,这得益于我们两年来的不懈打磨。该系统是首个能够自动阻止黑客攻击的Web3安全产品。

我们的使命:推进Web3安全 🚀

一次又一次,项目团队和用户在遭受黑客攻击和网络钓鱼后主动联系我们寻求帮助,这更加坚定了我们提升Web3社区安全意识的决心。

今年,我们参与了包括DeFi Security SummitTOKEN 2049DevconnectETHBerlinACM CCS在内的一系列活动。我们分享了关于Web3易受攻击性的见解,强调了主动防御的重要性,讨论了事件响应策略,并介绍了实用的安全工具。

此外,我们还启动了🏆 BlockSec区块链安全奖🏆,这是一项为期三年的奖学金,旨在表彰在香港理工大学攻读区块链技术硕士学位的优秀学生。我们的目标是帮助行业培养更多具备扎实安全资质的合格安全专业人才和开发者。🎓

作为一家安全公司,我们认为培养人才和推进区块链安全是我们的责任和愿景,为行业的稳健发展贡献力量。

展望未来

随着新的一年即将到来,我们致力于持续创新,专注于将Phalcon打造成一个更加实用和全面的安全产品。我们也承诺将继续与更广泛的Web3社区分享我们的见解和安全愿景。

提前祝您新年快乐!🎉

愿您在新的一年里,Web3之旅一帆风顺,硕果累累。

愿新的一年里,您身体健康,万事如意。🥳

Sign up for the latest updates
Tether Freezes $6.76M USDT Linked to Iran's IRGC & Houthi Forces: Why On-Chain Compliance is Now a Geopolitical Battlefield
Security Insights

Tether Freezes $6.76M USDT Linked to Iran's IRGC & Houthi Forces: Why On-Chain Compliance is Now a Geopolitical Battlefield

Looking ahead, targeted freezing events like this $6.76M USDT action will only become more common. On-chain data analysis is improving. Stablecoin issuers are also working closely with regulators. As a result, hidden illicit financial networks will be exposed.

Weekly Web3 Security Incident Roundup | Mar 2 – Mar 8, 2026
Security Insights

Weekly Web3 Security Incident Roundup | Mar 2 – Mar 8, 2026

During the week of March 2 to March 8, 2026, seven blockchain security incidents were reported with total losses of ~$3.25M. The incidents occurred across Base, BNB Chain, and Ethereum, exposing critical vulnerabilities in smart contract business logic, token deflationary mechanics, and asset price manipulation. The primary causes included a double-minting logic flaw during full token deposits that allowed an attacker to exponentially inflate their balances through repeated burn-and-mint cycles, a price manipulation vulnerability in an AMM-based lending market where artificially inflated vault shares created divergent price anchors to incorrectly force healthy positions into liquidation, and a flawed access control implementation relying on trivially spoofed contract interfaces that enabled attackers to bypass authorization to batch-mint and dump arbitrary tokens.

Weekly Web3 Security Incident Roundup | Feb 23 – Mar 1, 2026
Security Insights

Weekly Web3 Security Incident Roundup | Feb 23 – Mar 1, 2026

During the week of February 23 to March 1, 2026, seven blockchain security incidents were reported with total losses of ~$13M. The incidents affected multiple protocols, exposing critical weaknesses in oracle design/configuration, cryptographic verification, and core business logic. The primary drivers included oracle manipulation/misconfiguration that led to the largest loss at YieldBloxDAO (~$10M), a crypto-proof verification flaw that enabled the FOOMCASH (~$2.26M) exploit, and additional token design and logic errors impacting Ploutos, LAXO, STO, HedgePay, and an unknown contract, underscoring the need for rigorous audits and continuous monitoring across all protocol layers.