If your crypto gets stolen today, you usually have two options: pay a professional firm thousands of dollars, assuming they'll even take a small case, or just give up.
We built Trace AI to give you a third.
It runs on the same tracing tech behind @MetaSleuth, which our team has used on on-chain cases worth over a billion dollars. 8 chains, 10 languages, and it starts at $5.
https://t.co/yL7aMgYbDY
🚨 ALERT! We have observed a series of attack transactions targeting contracts on #Ethereum, including those associated with @Fetch_ai, @nunet_global, and @SingularityNET. Total losses exceed $2.1 million.
The incidents appear to stem from leaked private keys belonging to two privileged accounts (e.g., the deployer account). By controlling these accounts, the attacker was able to execute authorized privileged operations and drain valuable assets through direct transfers or token minting.
The attacker appears to be actively probing potential victims, with @SingularityNET’s AGIX token being the latest target. Stay vigilant!
Compromised accounts:
https://t.co/xsuJHqwA65
https://t.co/W62oa9Qdt0
Attackers rarely break the chain. They take over a channel you already trust — a real account, a real conversation, a real history.
BlockSec co-founder @yajinzhou and the Gate security team on how account takeovers, phishing and impersonation actually work, and what separation of identity, devices and permissions buys you.
.@nostrafinance was reportedly hit by a price-manipulation attack: approximately $3.5M was borrowed against NSTR collateral, though the final loss is not yet confirmed.
1. The attacker first created an NSTR/SolvBTC pool and added 1.5 SolvBTC as one-sided liquidity away from the active price: https://t.co/J2UlW5kkBV.
This increased the pool liquidity reported by GeckoTerminal, apparently influencing which pool supplied its Pragma NSTR price.
2. The attacker then added very little liquidity between the normal price and a much higher price; a small buy pushed the quote sharply upward: https://t.co/PnOEbY6gon.
At that point, Pragma had two contributing NSTR/USD prices: a normal AVNU quote of ~$0.00596118 (https://t.co/S1LgstVLn4) and a manipulated GeckoTerminal quote of ~$99.02439975 (https://t.co/hPxkeJnmjL).
Although the documentation describes a median of three sources, the second listed source did not provide a price in this instance. With only two available values, the median was their arithmetic average, approximately $49.51518, consistent with the borrow trace.
3. The attacker used another account holding NSTR collateral to borrow ETH, STRK, USDC, USDT, WBTC and DAIv1 at the inflated valuation: https://t.co/CWwgtIltJA
ALERT! Our system detected an attack that drained ~$7.8M from a Gnosis Safe wallet on Ethereum (0x40E93a52F6Af9fCD3b476aeDADD7FeABD9f7AbA8).
The root cause was a flawed authorization check in the executor contract (0x4f0055926c839D1d960a82CBF84E2eE933958ebC). Setting the supplied contract parameter to address(this) passed validation, allowing attacker-controlled calls to execute from the trusted executor through an enabled Safe module.
The exploit moved ~2,900 aEthrsETH into a Uniswap V4 pool paired with the worthless “Permissionless Attacker Token” (PAT), leaving the Safe with a worthless LP NFT.
The original attack transaction was front-run by the MEV bot yoink, which captured ~2,882 rsETH (~$7.8M) and routed it to 0xC70f00CD7E461686b04B0E912E309becA8b80ea0.
Original attack TX: https://t.co/O09PPt5M0E
Front-run TX: https://t.co/wJPxWdw6ap
🗓 Weekly Web3 Security Roundup | Aug 31 - Sep 06
🚨 Spotlight on 4 notable incidents | ~$9.4M lost this week
Featuring a vulnerability breakdown and in-depth analysis of selected key cases👇
https://t.co/3bIIrX88fV
BlockSec's blockchain penetration testing is now live, written up as a series: What it covers, where its boundaries sit, how it is authorized, and which attack surfaces it has to reach.
First four parts are live, more to come 🔜
Part 1: Why institutions need it: https://t.co/hlVBGJ8vPQ
Part 2: What it is, and its boundaries: https://t.co/BJGXsTUk8k
Part 3: Authorization and production safety: https://t.co/oHGzpjzCWW
Part 4: The attack surfaces it covers: https://t.co/Q6XWzVnyoq
A cloud and web pentest stops where the money starts moving.
Signing → approval → fund logic → on-chain transactions — we test that chain adversarially, in an agreed scope, with evidence for every confirmed path.
Blockchain Penetration Testing, now live at BlockSec!
Start here👇
https://t.co/rBJvuegLTe
A cloud and web pentest stops where the money starts moving.
Signing → approval → fund logic → on-chain transactions — we test that chain adversarially, in an agreed scope, with evidence for every confirmed path.
Blockchain Penetration Testing, now live at BlockSec!
Start here👇
https://t.co/rBJvuegLTe
Eleven security teams, one place for BNB Chain builders to find the support they need.
From contract audits to real-time monitoring and incident response, here’s what each team on the AvengerDAO marketplace brings to the table 🧵👇
Builders on @BNBCHAIN can now book BlockSec's security services through the AvengerDAO marketplace.
🔍 Audits — coverage spans the full stack: smart contracts, DeFi protocols, L1s, L2s and rollups, wallets, bridges, nodes and RPC infrastructure. Every audit evaluates implementation security, business logic and, where applicable, economic design, backed by our own static analyzer and LLM-assisted detection system. Alongside audits, we run dedicated blockchain penetration testing and security testing.
📡 Real-time monitoring — Phalcon keeps watching your protocol once it's live, so risk doesn't sit unnoticed between audits.
Our findings go beyond severity ratings. Each issue comes with clear, actionable remediation, and every report is built for real-world use: mainnet launches, public disclosures, exchange listing reviews and compliance processes.
Find us on the AvengerDAO marketplace 👇
https://t.co/OpMD2mLiLc
1/x @Liquid_BTC Liquid Network appears to have experienced a consensus divergence at block 4,050,336. Approximately 13 minutes later, a 3,996.01834922 L-BTC peg-out was recorded on the branch that continued beyond the divergent block.
Our preliminary analysis, informed by the findings shared by @stutxo, suggests that a potential issue in the rangeproof-verification cache mechanism in certain Elements Core builds may have contributed to the incident:
https://t.co/hGf1ZxSISy
Previously, the cache key for successful rangeproof verifications was derived only from the rangeproof and value commitment. It did not include the asset commitment or scriptPubKey, although both are inputs to full verification.
This could allow different verification contexts to map to the same cache entry. After a valid context populated the cache, a modified context might hit that entry and return true without undergoing full verification.
A recent patch adds the missing inputs to the cache key:
https://t.co/q63HEFBZwX
If reachable during consensus validation, this behavior could cause nodes with different cache states or implementations to reach different conclusions about the same transaction.
🗓 Weekly Web3 Security Roundup | Aug 24 - Aug 30
🚨 Spotlight on 5 notable incidents | ~$23M lost this week
Featuring a vulnerability breakdown and in-depth analysis of selected key cases👇
https://t.co/ceCWxWEnX8
🗓 Weekly Web3 Security Roundup | Aug 17 - Aug 23
🚨 Spotlight on 2 notable incidents | ~$10.26M lost this week
Featuring a vulnerability breakdown and in-depth analysis of selected key cases👇
https://t.co/xxGcDabOrC
It is alarming that @cosmoslabs_io Cosmos EVM v0.7.2 [1] appears to have publicly, yet quietly, included fixes for critical vulnerabilities while at least some affected chains may not have been promptly notified, according to @KiiChainio’s official post-mortem.
Only after multiple chains had been exploited did Cosmos Labs publicly acknowledge the incident [2], advise chains already in contact with them to halt, and ask other Cosmos EVM teams to reach out.
[1] https://t.co/PM7KA1Uk4S
[2] https://t.co/PRoh8gHuZ0
✅Audit Complete
DGrid’s $DGAI Staking Contracts have been audited by @BlockSecTeam. From staking and rewards to node operations, delegation, and the LLM pool, every critical path has been reviewed.
Security first. Building on #BNBChain.
📄 Report:
https://t.co/px1r7ceNCf
🗓 Weekly Web3 Security Roundup | Aug 10 - Aug 16
🚨 Spotlight on 5 notable incidents | ~$47M lost this week
Featuring a vulnerability breakdown and in-depth analysis of selected key cases👇
https://t.co/bodPL6ykEL
📢 Security Audit Update
HertzFlow's Perp contracts have been audited by @BlockSecTeam , covering trading, liquidation, fee and asset modules.
Your position deserves more than a promise.
Safety first. HertzFlow keeps building on #BNB Chain.
📃:https://t.co/3DsTD6wLbq