
Source: Shenzhen Zero -time Technology
In December 2023, the loss of various safety incidents decreased compared to November.The total loss amount caused by hacking, fishing fraud and Rug Pull in December$ 24.94 million.The fishing fraud incident this month is still unabated, and users need to raise awareness of anti -fraud.
The following is a typical security event information
-
On December 5, 2023, ThirdWeb, the Web3 development platform, had security vulnerabilities, which affected multiple smart contracts. At least 3 items were attacked due to vulnerabilities.$ 21,000Essence[The Web3 Development Tool Platform Thirdweb said in its official blog that there were many web3 smart contracts (including some pre -constructed smart contracts of ThirdWeb) at 18:00 on November 20th..0.3 and higher versions), ERC721 (V1.0.4 and higher versions), ERC1155 (V1.0.4 and higher versions), etc.Except for the affected intelligent contracts, including wallets, payment and infrastructure services, they were not affected and operated normally..
-
On December 6, 2023, the BSC ecological project and decentralized reserve currency agreement Bearndao was attacked and obtained more than$ 700,000Increase.[The attacker address “0xce27b” uses errors in ConvertDusttoearned () and uses sandwiches to attack.
-
On December 12, 2023, OKX’s abandoned DEX was stolen as a city -based contract management authority, and the loss of losses$ 2.7 millionEssence[On December 13, OKX’s Chinese issued stated that after verification, the incident was caused by a abandoned OKX DEX commercial contract management authority that was no longer used, and 18 address assets authorized by the contract were transferred..
-
On December 14, 2023, Ledger Connect Kit, commonly used by the web3 project, was attacked by the supply chain and the attacker made a profit$ 600,000Essence
-
On December 16, 2023, the NFT Trader was attacked by the loophole and lost$ 3 millionThe stolen assets have been returned by the attacker, and the attacker retains 10%as a bounty.[News on December 16, the NFT Trader attacker posted on the chain that the stolen NFT assets were safe and eventually they would return to the user.The initial attacker of the vulnerability was 0x3DC115307C7B79E9E9FF0AFE4C1A0796C22E366A47B47ED2D82194BCD59BB4BD46.The attacker said that he was not an initial attacker and said the initial attacker was continuing to attack a new loophole..
-
On December 17, 2023, Flooring Protocol, the NFT trading market, was attacked by hackers and lost money$ 1.6 millionEssence
-
On December 20, 2023, the DEFI protocol Transit Finance was attacked by hackers and lost a loss$ 110,000.
-
On December 23, 2023, the DEX project Paraluni was attacked by price control and lost$ 330,000.[The attacker uses the Paraluni protocol to control the price of the vulnerability to make a profit of about 336,000 US dollars in the contract.According to previous news, the web3 security platform ANCILIA issued a text that the Paraluni project on the Binance Intelligent Chain Paraluni is undergoing price manipulation attacks.loss..
-
On December 26, 2023, the Telcoin wallet was attacked and lost$ 1.2 million.
-
From December 13th to 26th, 2023, Levana, a permanent trading agreement on the OSMOSIS chain, was attacked. The vulnerability exceeded 13 days.1.1 million US dollarsEssence
-
On December 27, 2023, Thunder, a multi -chain trading platform, was suspected to be attacked.86.5 ETHGo to Railgun.[Attack address: 0x2A2C200AF4E659348C4182dd9806a340851df42e.Thunder responded to this that the third -party service it used was suspected to be attacked, and 114 of more than 14,000 addresses were affected..
-
On December 30, 2023, Channels Finance on BSC was attacked by hackers, and the loss exceeded$ 320,000.
-
On December 1, 2023, the GROK-2 tokens on BNB Chain suspected of Rug Pull. The current token price has been100% downEssence
-
On December 1, 2023, the Rug Pull happened in QMYX,About 10 trillion QMYX switched to 57.18 WETHEssence[Myx Finance token QMYX has fallen 100%.Address 0x7634 … 168D has exchanged 9,999,999,999,999 QMYX to 57.18 WETH ($ 119,700)..
-
On December 5, 2023, Rug Pull, a CKD tokens on the BNB CKD token, the deployee made a profit contract$ 540,000Essence
-
On December 13, 2023, the address 0xebc5 was caught by the Internet, and the loss was about$ 94,500Essence[Address 0xebc5 becomes a victim of the Internet fishing plan, leading to 382.88 CRVCRVETH and 43.5 STETH (worth about 94,500 US dollars)]
-
On December 21, 2023, monitoring shows that a wallet hacker is related to Google search and online fishing activities on X advertising.$ 58 millionEssence
-
On December 24, 2023, the start address of 0xF8C was stolen due to zero transfer fishing attack710,000 USDC.Fishing address: 0x949d0dbe58C77EF31edab5e476F41E4F5EF861B.
-
On December 26, 2023, Rug Pull, Megaboteth, and the deployee made a profit contract.$ 74 millionEssence
-
On December 26, 2023, the two victims had a loss of losses due to online fishing fraud.More than 1500 million US dollarsAssets.
-
On December 29, 2023, a user signed a “Increase Allowance” transaction, which was attacked by online fishing.$ 4.4 millionLink.
? This month’s fishing fraud incident is still unabated, and there are many incidents of more than one million dollars stolen by a single address. Users need to increase their vigilance.
The following is the security incident in other aspects
Note: Time does not distinguish
-
On December 4, 2023, a cadre of Taixing City participated in the virtual currency MLM activities for 4 years and 6 months, and the amount involved in the case was reached.More than 37 million yuanEssence[A cadre in Taizhou, Jiangsu was charged with organizations and leading MLM activities, and the amount involved was more than 37 million yuan. In the previous trial, the cadre was sentenced to 4 years and 6 months and fined 300,000 yuan.It is reported that the MBI group participated by Zhao Group, Taixing City, Taizhou, Jiangsu Province, in the name of investing in financial management and required participants to pay a certain amount of each time and purchase the virtual currency “Easy currency” (M currency) issued by the relevant platform issued by the group.The number of people who identified Zhao’s development to the line reached 476 layers..
-
On December 6, 2023, the Henan Procuratorate disclosed a large virtual currency MLM case, which involved in the case.120 million yuanEssence[The Procuratorate of Xichuan County, Henan Province recently handled a virtual currency MLM case with a total amount of 120 million yuan involved in the case.NB Coin (Niu Coin) “, developed the corresponding Red Bull Fried Coin App, carried out MLM activities in the name of virtual currency and blockchain, and established the” Red Bull Business College Lecturer Group “to carry out offline promotion and publicity.In just one year, the gang involved in the case developed 2128 members and cheated more than 120 million yuan..
-
News on December 6, 2023, the encryption exchange Bitzlato Lianchuang acknowledged$ 700 millionCrime of money laundering.
-
According to the news on December 10, 2023, the Hong Kong police cracked the money laundering through virtual currency money30 million Hong Kong dollarsCriminal gang.
-
According to the news on December 13, 2023, the US Department of Justice accused two men’s operation$ 25 millionThe encrypted Ponzi scam.[Two people seduce the victims to invest in various transaction projects. The false commitments of these projects are promised to use artificial intelligence automatic transaction robots to trade in the cryptocurrency market and earn high returns, and promote investment projects in various names. The two misappropriate the victimsPay personal expenditure..
-
According to the news on December 15, 2023, the US Department of Justice disclosed that the four were accused of cryptocurrency fraud and money laundering, causing super$ 80 millionloss.[According to court documents, Lu Zhang, Justin Walker, Joseph Wong, and Hailong Zhu are suspected of opening up the shell company and bank account to clean up cryptocurrency investment scams (also known as “” kill pig plates “) and other victims of other fraud plans.Essence.
-
On December 30, 2023, Guangxi Public Security cracked a live broadcast and cargo APP MLM involved in the virtual currency.300 million yuanEssence[Guangxi Hechi City Public Security Bureau cracked a live broadcast and cargo APP MLM case involving virtual currencies. The suspect used an app named APP to build groups and live broadcasts to formulate MLM for the development level and online registered and rebate.Model, to promote virtual services through the software’s internal purchase function and distribute the reward dimension set by the platform settings. At the same time, in the publicity, the flags and labels of e -commerce, virtual currency, and national number projects are continuously advocated to cover up its development offlineThe essence of profitability]
In December 2023, the loss of various safety incidents decreased compared to November.The total loss amount caused by hacking, fishing fraud and Rug Pull in December$ 24.94 million.
In view of the frequent security incidents, the science and technology security team proposes the following security suggestions:
-
The project party establishes a strict private key management process and adopts multiple signing mechanisms to prohibit the use of private keys in the networking environment.
-
Before the project is launched, find a professional third -party security enterprise for a comprehensive security audit, and you can find a number of cross -audit.
-
The project party can release the vulnerability bounty plan, send the community white hat to help find problems, and find the vulnerability in the hacker.
-
Strengthen the safety monitoring and warning of the project, and try to issue warnings before hackers launch attacks to protect the safety of the project.
-
Smart contract developers should pay attention to the code logic in the contract must be rigorous, avoid historical loopholes, and strengthen code security.
-
Users carry out project background investigations carefully. Do not trust unbelievable project contracts, check the relevant audit reports to avoid asset loss.
-
Users should raise their awareness of anti -fraud. If they are unfortunately deceived, retain good evidence and file a case with the police as soon as possible.