total loss

OKLink Security Monthly Report: Zero major Rug Pull incidents in November, with total losses across the network amounting to approximately 203 million USD

OKLink released the November 2024 Security Report, which indicates that on-chain security incidents across the network have resulted in a total loss of approximately $203 million. Phishing scams alone accounted for 64.80% of the total losses, amounting to about $131 million, with no significant Rug Pull incidents reported. REKT incidents accounted for 22.06% of the losses, totaling approximately $45 million.On November 13, a user copied an incorrect address from contaminated transaction history, resulting in a loss of $129 million. An hour later, the attacker returned all the assets. On November 15, the v1 liquidity pool contract of the Aptos ecosystem project Thala was attacked due to a security vulnerability, causing a loss of $25.5 million. Subsequently, Thala negotiated with the attacker to recover all user assets through a $300,000 bounty.OKLink reminds everyone to carefully verify the receiving address when performing on-chain operations. Some users have lost over $100 million by copying incorrect addresses from contaminated transaction records. It is essential to double-check the recipient's address when conducting on-chain operations and avoid the habit of directly copying addresses from transaction records or chat logs. Additionally, learn to use Web3 on-chain tools to mitigate risks. OKLink provides tools for on-chain address queries, token authorization checks, and large transfer monitoring, ensuring on-chain security and keeping you informed of market trends, helping you overcome on-chain anxiety.

OKLink Security Monthly Report: In October, the total losses across the network amounted to approximately $181 million, an increase of 38.9% month-on-month

ChainCatcher news, OKLink released the October 2024 security monthly report, stating that the cumulative losses from on-chain security incidents across the network amount to approximately $181 million. Losses from phishing scams account for 23.94% of the total losses, totaling about $43.53 million. REKT incidents account for 35.92% of the losses, totaling about $65.32 million.On October 11, a user on Blast lost 15,079 fwDETH after signing a phishing "permit" signature, worth approximately $35 million. On October 16, multiple multi-signature wallets of Radiant Capital were attacked, with the attacker injecting malware into hardware wallets, compromising several developers' hardware wallets. The attack process was so covert that the front end of the Gnosis Safe multi-signature wallet displayed legitimate transaction data, while the back end was simultaneously signing and executing tampered transactions, ultimately leading to losses of about $58 million.In this month's security incidents, the methods of attack are constantly evolving. OKLink reminds users to be particularly vigilant against phishing attacks involving "permit" and "approve" authorizations on social platforms, as these types of attacks have occurred frequently this month. When performing on-chain operations, it is essential to carefully verify the receiving address and not to easily trust the addresses in transaction records, as they may have been replaced by hackers. For multi-signature wallets, it is crucial to strictly protect the security of private keys, and when handling emails related to crypto assets, carefully verify the sender's identity and the authenticity of the content, and learn to use Web3 on-chain tools to mitigate risks.

Beosin: In Q3 2024, the total losses in the Web3 sector due to hacker attacks, phishing scams, and project rug pulls reached 730 million dollars

ChainCatcher news, according to Beosin Alert monitoring and early warning, as of September 25, the total loss in the Web3 sector due to hacker attacks, phishing scams, and project Rug Pulls in Q3 2024 has reached $730 million. Among them, there were 23 major attack incidents, with a total loss of approximately $430 million; 3 project Rug Pull incidents, with a total loss of about $4.24 million; and total losses from phishing scams amounting to approximately $295 million.In terms of the types of attacked projects, the highest losses were incurred by CEX, with 3 attacks on CEX causing approximately $297 million in losses, accounting for about 40.6% of all attack losses.In terms of losses by chain, Ethereum remains the chain with the highest loss amount and the most attack incidents. 21 attacks and phishing incidents on Ethereum caused losses of $348 million, accounting for about 47.6% of the total losses.Regarding attack methods, there were 5 private key leakage incidents in Q3, resulting in losses of $305 million, accounting for about 41.7% of the total attack losses, making it the most prevalent type of attack.In terms of the flow of funds, only about $16.9 million of the stolen funds have been frozen or recovered. The vast majority (approximately 78.9%) of the stolen funds are still stored in the attackers' on-chain addresses.Compared to the same period in 2023, the total losses due to hacker attacks, phishing scams, and project Rug Pulls in Q3 2024 have slightly decreased to $730 million (the figure for Q3 2023 was $889 million). Factors such as the decline in cryptocurrency prices in Q3 2024 have had some impact on the reduction of the total amount, but overall, the situation in the Web3 security sector remains grim. Among the more than twenty attack incidents in Q3, 18 were still due to contract vulnerabilities, suggesting that project parties should seek professional security companies for audits before going live.

OKLink Security Monthly Report: In July, the total losses across the network amounted to approximately $290 million, with losses due to private key leaks accounting for 88.31% of the total losses

ChainCatcher news, OKLink released the July 2024 security report, stating that the cumulative losses from on-chain security incidents across the network amount to approximately $290 million. Losses due to private key leaks account for 88.31% of the total losses, phishing incidents account for 3.03%, REKT incidents account for 7.33%, and RugPull incidents account for 1.31%.On July 18, the private key of the WazirX exchange's multi-signature wallet was leaked, resulting in a loss of approximately $235 million, making it the largest security incident in July. On July 16, the LiFi Protocol cross-chain bridge aggregation protocol was attacked, leading to a loss of about $10 million. The attacker exploited a vulnerability that allowed arbitrary calls to steal assets authorized by users of this contract.In addition, there were a total of 14 incidents of scams and phishing on official social media, resulting in losses of approximately $3.89 million, a decrease of 81.34% compared to June. OKLink reminds users not to disclose your private keys or mnemonic phrases to anyone, not to click on unverified links, and to learn how to use Web3 on-chain tools to mitigate risks. This is an important line of defense in protecting yourself in the Web3 world.

OKLink Security Monthly Report: In June, the total losses across the network amounted to approximately $210 million, with losses from phishing scams decreasing by 75.69% month-on-month

ChainCatcher news, OKLink released the June 2024 security monthly report, which indicates that the cumulative losses from on-chain security incidents across the network amount to approximately $210 million. Among these, phishing incidents account for 9.91% of the losses, REKT incidents account for 20.83%, and RugPull incidents account for 3.53%.The largest security incident in terms of REKT losses occurred on June 10, when UwU Lend was attacked, resulting in losses of approximately $22.7 million. The attacker exploited a vulnerability in the contract related to oracle price manipulation, causing losses of about $19 million, and on June 13, they attacked again by taking advantage of the project's governance operation errors, profiting $3.7 million.In addition, there were a total of 31 incidents of scams and phishing on official social media, primarily concentrated on X, Discord, and various phishing websites. OKLink reminds users not to click on unverified links, not to disclose your private keys or seed phrases to anyone, and to maintain a skeptical attitude towards projects that promise abnormally high returns. Before investing, be sure to conduct thorough research on the project and the team. Security awareness is your strongest shield in the Web3 world.

Beosin: In the first half of 2024, the total losses in the Web3 sector due to hacker attacks and other factors reached 1.54 billion dollars

According to ChainCatcher news, monitoring and early warning from Beosin Alert shows that in the first half of 2024, the total losses in the Web3 field due to hacker attacks, phishing scams, and project rug pulls reached 1.54 billion USD. Among them, there were 78 major attack incidents, with 43 stemming from contract vulnerabilities, resulting in total losses of approximately 1.193 billion USD; there were 64 project rug pull incidents, with total losses of about 119 million USD; and phishing scams accounted for total losses of approximately 232 million USD.In the first half of 2024, there were 3 security incidents with losses exceeding 100 million USD. The total loss in May reached 450 million USD, making it the month with the highest losses in the first half of 2024.In terms of the types of attacked projects, the highest losses were from CEX, with 4 attacks on CEX causing approximately 392 million USD in losses, accounting for 32.8% of all attack losses.Regarding losses by chain, Ethereum remains the chain with the highest losses and the most attack incidents. 32 attack incidents on Ethereum resulted in losses of 470 million USD, accounting for 39.4% of the total losses.In terms of attack methods, there were a total of 22 private key leakage incidents in the first half of the year, causing losses of 894 million USD, which accounted for about 75% of the total attack losses, making it the most prevalent attack type.In terms of fund flow, approximately 470 million USD (39.3%) of the stolen funds were frozen or recovered. This proportion has significantly increased compared to 2023.
ChainCatcher Building the Web3 world with innovators