Web3 field

Slow Fog: Last week, there were 10 security incidents in the Web3 field, with an increase in DNS hijacking attacks and Discord hacking incidents

ChainCatcher news, according to the Slow Mist blockchain hacking archive statistics, from October 1 to October 7, 2023, a total of 10 security incidents occurred, with an increase in DNS hijacking attacks and Discord hacking incidents. The specific events are as follows:Galxe (2023-10-06): Unauthorized access obtained through DNS hijacking led to the misappropriation of visitor funds, affecting 1,120 users. Loss: approximately $270,000;MCT (2023-10-06): DNS domain hijacking allowed private keys to be uploaded to a fraudulent domain. Preventive measures are recommended. Loss: not specified;Fake CommEx tokens (2023-10-06): A large amount of liquidity was removed in a rug pull, with the deployer extracting approximately $154,000;friend.tech (2023-10-05): Four users faced SIM swap attacks, resulting in significant losses. Loss: approximately $385,000;Stars Arena (2023-10-05): The platform's smart contract had a major security vulnerability, leading to the theft of a large amount of funds. Loss: approximately $3 million;DePay (2023-10-05): The platform faced a flash loan attack, resulting in relatively small theft. Loss: $827;Metropolis World (2023-10-05): The platform's Discord server was hacked. Loss: unspecified;GEMIE (2023-10-02): The Discord server was hacked, leading to phishing links being shared. Users are advised not to interact. Loss: not specified;VendX (2023-10-02): Another instance of a Discord server being hacked. Loss: not specified;Fake EigenLayer tokens (2023-10-01): A fake token exit scam that brought huge profits to the deployer. Loss: approximately $300,000.

Beosin: The total loss caused by various security incidents in the Web3 field in the first half of 2023 reached 655.61 million USD

ChainCatcher news reports that, according to monitoring by blockchain security auditing company Beosin, the total losses in the Web3 sector due to hacker attacks, phishing scams, and project Rug Pulls reached 655.61 million USD in the first half of 2023. Among them, there were 108 attack incidents, with total losses of approximately 471.43 million USD; phishing scams had total losses of about 108 million USD; and there were 110 project Rug Pull incidents, resulting in total losses of around 75.87 million USD.The total loss amount from hacker attacks in the Web3 sector has significantly decreased compared to last year. In the first half of 2022, the total losses from attacks were approximately 1.91 billion USD, and in the second half of 2022, about 1.69 billion USD, while in the first half of 2023, this figure dropped to 470 million USD.In terms of the types of attacked projects, DeFi remains the most frequently attacked type with the highest loss amount. The total loss from 85 DeFi security incidents reached 292 million USD, accounting for 62% of the total loss amount.From the perspective of blockchain platforms, 75.6% of the loss amount came from Ethereum, approximately 356 million USD, ranking first among all blockchain platforms.In terms of attack methods (statistical by root cause), the most frequent and damaging attack method was contract vulnerability exploitation. 60 contract vulnerability incidents caused losses of 264 million USD, accounting for 56% of all loss amounts.Regarding the flow of funds, approximately 215 million USD of stolen assets were recovered, accounting for 45.5% of all stolen assets. Additionally, about 113 million USD of stolen assets were transferred to Tornado Cash and other mixers.In terms of auditing, among the attacked projects, about 49% of the projects had not undergone an audit.In contrast to the decreasing trend of hacker attack incidents compared to 2022, phishing scams and project Rug Pull incidents became more frequent for ordinary users in the first half of 2023. According to incomplete statistics, these two types of incidents involved a total amount of at least 184 million USD. The decrease in the technical threshold for phishing (for example, malicious toolkits can be purchased from certain channels to profit and then share the earnings) has led to a significant increase in phishing scams in the first half of 2023, becoming a major threat to the safety of Web3 users.
ChainCatcher Building the Web3 world with innovators