Monthly News | Total Web3 Security Incident Losses About $404 Million

Overview

According to statistics from the Slow Fog Blockchain Hacked Archive (https://hacked.slowmist.io), in February 2024, a total of 28 security incidents occurred, with a total loss of approximately US$404 million, involving contract vulnerabilities, DDoS attacks,Lightning loan attacks, private key leakage and account theft, etc.

Major Events

Phantom

On February 2, 2024, the crypto wallet Phantom said it was attacked by DDoS, and some people tried to overload their system, some services may be temporarily interrupted, and user assets are secure.Subsequently, Phantom posted on Twitter that all services have returned to normal and have been running smoothly again.

(https://twitter.com/phantom/status/1753100432145318116)

Starlay Finance

On February 8, 2024, Starlay Finance, the lending agreement of Polkadot Eco, was attacked, and lost about $2.1 million.On February 9, Starlay Finance tweeted that preliminary analysis showed that the attack was due to the use of liquidity index calculation errors, resulting in unauthorized withdrawals.

(https://twitter.com/starlay_fi/status/1755856271184654360)

PlayDapp

On February 10, 2024, the blockchain gaming platform PlayDapp was attacked, and the hacker’s address was added as a coin minter, minting 200 million PLA tokens (about 36.5 million US dollars).Shortly after the incident, PlayDapp sent a message to the hacker through an on-chain transaction, demanding the return of the stolen funds and providing a $1 million white hat reward, but the negotiations failed.On February 12, PlayDapp was attacked for a second time, and hackers minted another 1.59 billion PLA tokens (about $253.9 million) and began transferring them through cryptocurrency trading platforms.According to statistics, the hacking attack caused about $290 million in losses.

(https://twitter.com/playdapp_io/status/1756060784692736038)

Duelbits

On February 14, 2024, the hot wallet of the crypto-gambling platform Duelbits was attacked, losing about $4.6 million. The reason for the stolen was suspected to be the leakage of the private key.

(https://twitter.com/Duelbits/status/1758159495807541459)

FixedFloat

On February 17, 2024, according to on-chain data, cryptocurrency trading platform FixedFloat was attacked and lost about $26.1 million in Bitcoin and Ethereum.FixedFloat clarified against the attack: This hacker attack was caused by an external attack caused by a vulnerability in the security structure, not carried out by employees, and user funds were not affected by “external attacks”.On February 18, FixedFloat tweeted: “Confirm that there is indeed a hacker attack and funds theft, and we are not ready to comment on the matter publicly as we are working to eliminate all potential vulnerabilities, improve security and investigate.. FixedFloat’s service will be restored soon, and details about this event will be provided later. “

(https://twitter.com/FixedFloat/status/1759216185185288653?s=20)

Blueberry Protocol

On February 22, 2024, DeFi lending protocol Blueberry Protocol was attacked, with a loss of approximately 457.7 ETH (about $1.35 million) that was intercepted by a white hat hacker c0ffeebabe.eth, and 366 ETH was returned to Blueberry Protocol.According to the Blueberry Protocol event analysis report, the attack was caused by an oracle deployment error.

(https://medium.com/@blueberryprotocol/2-22-24-exploit-post-mortem-6f6be7c1dcc3)

BitForex

On February 23, 2024, the Hong Kong-based BitForex cryptocurrency trading platform suspected of running away, closing access to the platform after a suspicious capital outflow of about $56.5 million on multiple blockchains.On-chain detective ZachXBT was the first to notice the exchange’s withdrawal movement, noting that the trading platform has stopped processing withdrawals and has not responded to customers.The company faced regulatory scrutiny in mid-2023 for operating without a license and was accused of exaggerating transaction volumes.Its CEO resigned in January, promising to be taken over by a new team.

(https://twitter.com/zachxbt/status/1762028433574650347)

Jihoz

On February 23, 2024, Jihoz, co-founder of Axie Infinity, posted on Twitter that his two personal addresses have been leaked.The scope of this attack is only for their personal accounts and has nothing to do with the verification or operation of the Ronin chain.Additionally, the leaked key has nothing to do with Sky Mavis’ operations.He wanted to assure everyone that strict safety measures have been taken for all chain-related activities.According to statistics, the attack caused about $10 million in losses.

(https://twitter.com/Jihoz_Axie/status/1760845078757511562)

Seneca

On February 28, 2024, Seneca, the full-chain CDP protocol, was hacked due to a contract vulnerability.The hacker uses the constructed calldata parameter to call transferfrom to transfer the tokens authorized to the project contract to his own address and finally exchange it for ETH.Seneca was stolen by hackers over 1,900 ETHs, worth about $6.5 million.On February 29, Seneca hackers returned 1,537 ETHs (approximately $5.3 million) to the Seneca deployer address.

(https://twitter.com/SlowMist_Team/status/1762865505042645010)

Shido Network

On February 29, 2024, Shido Network, the decentralized cross-chain protocol on Ethereum, was suspected to have run away.The owner of the SHIDO token staking contract first upgraded the staking contract, then withdraws a large amount of SHIDO, and finally sold a large amount of SHIDO at 692 ETH (approximately $2.1 million).

Summarize

Among the 28 major security incidents this month, two projects (Blueberry Protocol and Seneca) recovered a total of about $6.38 million in stolen funds; the losses in the three private key leakage incidents this month reached about 304 million, accounting for approximately the capital.75% of the total loss of monthly security incidents. The Slow Fog Security Team recommends that users and project parties strengthen protection measures for private keys, such as using hardware wallets, offline storage, etc. to improve the security of private keys; four contract vulnerabilities have been exploited this month.The incident resulted in a loss of approximately $7.25 million, and the Slow Fog Security Team advised the project party to always be vigilant and conduct regular security audits to track and resolve new security threats and vulnerabilities to maximize the security of projects and assets.Finally, the events included in this article are the main security incidents this month, and theft incidents of individual users have not been included in the statistics.

  • Related Posts

    DeepSeek accelerates web3 transformation and changes corporate value and risk management models

    As a cutting-edge technology, DeepSeek is profoundly changing the digital transformation path of enterprises and the ecological pattern of decentralized applications, and changing the trial and risk management model of…

    Emily Parker: 2025 Web3 trends int and US and Asia

    Next, Emily Parker, an advisor to China and Japan for the Global Blockchain Business Council, will be invited to give a speech on the stage. His topic is “2025 Web3…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Historic Trend: Bitcoin is Being a Safe-Habiting Asset

    • By jakiro
    • April 19, 2025
    • 0 views
    Historic Trend: Bitcoin is Being a Safe-Habiting Asset

    What makes cryptocurrency rug pull events happen frequently?

    • By jakiro
    • April 18, 2025
    • 9 views
    What makes cryptocurrency rug pull events happen frequently?

    Wintermute Ventures: Why do we invest in Euler?

    • By jakiro
    • April 18, 2025
    • 9 views
    Wintermute Ventures: Why do we invest in Euler?

    Can Trump fire Powell?What economic risks will it bring?

    • By jakiro
    • April 18, 2025
    • 10 views
    Can Trump fire Powell?What economic risks will it bring?

    Glassnode: Are we experiencing a bull-bear transition?

    • By jakiro
    • April 18, 2025
    • 10 views
    Glassnode: Are we experiencing a bull-bear transition?

    The Post Web Accelerator’s first batch of 8 selected projects

    • By jakiro
    • April 17, 2025
    • 21 views
    The Post Web Accelerator’s first batch of 8 selected projects
    Home
    News
    School
    Search