Phalcon 2023 年度回顾

Phalcon 2023 年度回顾

2023年,Web3不仅承载着技术突破的愿景,也面临着前所未有的安全挑战。在这一年里,Phalcon也从一个交易浏览器蜕变为一个全面的安全套件。Phalcon现已覆盖协议安全的整个链条,从上线前测试、上线后监控和攻击阻断,到事后分析。

通过Phalcon的故事,让我们一起回顾BlockSec在2023年为推进Web3安全所做的持续不懈的努力。

Phalcon 的安全理念:超越代码审计 🤔💡

自BlockSec成立以来,我们的立场一直坚定不移——单凭代码审计不足以应对Web3黑暗森林中无处不在的安全风险(尽管我们在代码审计方面做得非常出色)。一旦项目上线,主动防御和快速响应机制就变得至关重要。

传统的攻击监控系统会向我们发出威胁警报,但项目团队往往反应迟缓或不确定如何有效应对。我们开始思考:如何才能标准化我们的事件响应能力,以便更好地协助更广泛的项目? 这催生了BlockSec Phalcon的诞生,一个旨在自动阻止攻击的系统。

今年2月,当Platypus协议遭受攻击时,BlockSec Phalcon帮助挽回了240万美元的潜在损失。

一个月后,该系统再次证明了其价值,成功拦截了针对Paraspace的攻击,挽回了约500万美元的损失。🛡️💰

11月,在伊斯坦布尔举行的Devconnect大会上,BlockSec Phalcon的发布标志着一个重要的里程碑,这得益于我们两年来的不懈打磨。该系统是首个能够自动阻止黑客攻击的Web3安全产品。

我们的使命:推进Web3安全 🚀

一次又一次,项目团队和用户在遭受黑客攻击和网络钓鱼后主动联系我们寻求帮助,这更加坚定了我们提升Web3社区安全意识的决心。

今年,我们参与了包括DeFi Security SummitTOKEN 2049DevconnectETHBerlinACM CCS在内的一系列活动。我们分享了关于Web3易受攻击性的见解,强调了主动防御的重要性,讨论了事件响应策略,并介绍了实用的安全工具。

此外,我们还启动了🏆 BlockSec区块链安全奖🏆,这是一项为期三年的奖学金,旨在表彰在香港理工大学攻读区块链技术硕士学位的优秀学生。我们的目标是帮助行业培养更多具备扎实安全资质的合格安全专业人才和开发者。🎓

作为一家安全公司,我们认为培养人才和推进区块链安全是我们的责任和愿景,为行业的稳健发展贡献力量。

展望未来

随着新的一年即将到来,我们致力于持续创新,专注于将Phalcon打造成一个更加实用和全面的安全产品。我们也承诺将继续与更广泛的Web3社区分享我们的见解和安全愿景。

提前祝您新年快乐!🎉

愿您在新的一年里,Web3之旅一帆风顺,硕果累累。

愿新的一年里,您身体健康,万事如意。🥳

Sign up for the latest updates
Weekly Web3 Security Incident Roundup | Feb 9 – Feb 15, 2026

Weekly Web3 Security Incident Roundup | Feb 9 – Feb 15, 2026

During the week of February 9 to February 15, 2026, three blockchain security incidents were reported with total losses of ~$657K. All incidents occurred on the BNB Smart Chain and involved flawed business logic in DeFi token contracts. The primary causes included an unchecked balance withdrawal from an intermediary contract that allowed donation-based inflation of a liquidity addition targeted by a sandwich attack, a post-swap deflationary clawback that returned sold tokens to the caller while draining pool reserves to create a repeatable price-manipulation primitive, and a token transfer override that burned tokens directly from a Uniswap V2 pair's balance and force-synced reserves within the same transaction to artificially inflate the token price.

Top 10 "Awesome" Security Incidents in 2025

Top 10 "Awesome" Security Incidents in 2025

To help the community learn from what happened, BlockSec selected ten incidents that stood out most this year. These cases were chosen not only for the scale of loss, but also for the distinct techniques involved, the unexpected twists in execution, and the new or underexplored attack surfaces they revealed.

#10 Panoptic Incident: XOR Linearity Breaks the Position Fingerprint Scheme

#10 Panoptic Incident: XOR Linearity Breaks the Position Fingerprint Scheme

On August 29, 2025, Panoptic disclosed a Cantina bounty finding and confirmed that, with support from Cantina and Seal911, it executed a rescue operation on August 25 to secure roughly $400K in funds. The issue stemmed from a flaw in Panoptic’s position fingerprint calculation algorithm, which could have enabled incorrect position identification and downstream fund risk.