🎆 New Year, New Luck! Join the Ultimate Lucky Draw Celebration!
🎉 Gate.io Community Honor Credits New Year Lucky Draw - Phase 6 is officially live!
Start the lucky draw now 👉 https://www.gate.io/activities/creditprize?now_period=6
🌟 How to Participate?
1️⃣ Go to the [Credits Center] in Gate Post and complete tasks like posting, commenting, and liking to earn Honor Credits.
2️⃣ Lower entry threshold: Earn 300 credits to get one entry into the lucky draw!
🎁 Enter the draw for a MacBook Air, exclusive merchandise, Points, Futures Voucher and more!
📅 Event Time: Dec 30, 2024, 07:00 AM - Jan
gate Research Institute: Security Incident Summary for November 2024
Summary
Security Event Overview
According to Slowmist data, there were a total of 21 hacking incidents in November 2024, resulting in a loss of approximately $76.86 million. This month's security incidents focused on contract vulnerabilities, account hacking, and attacks in various other ways. The number of security incidents and the scale of losses this month have significantly decreased compared to last month, reflecting the continuous improvement of the industry in security measures and raising security awareness to some extent. It is worth noting that contract vulnerabilities are still the main cause of attacks and losses. The 7 contract exploitation incidents that occurred this month resulted in a total loss of over $30 million, accounting for 39% of the total losses. Additionally, the official X account and official website of the encryption project remain the primary targets of hacking.
According to Scam Sniffer data, the distribution of security incidents on public chains this month shows that the losses are mainly concentrated on several mature and popular public chains, especially Ethereum and Polygon, which have experienced security incidents causing losses of over 6.91 million US dollars and 1.05 million US dollars respectively. This indicates that although the underlying security of public chains is relatively high, vulnerabilities in the Application Layer and Smart Contracts still pose significant risks to user funds.
Multiple blockchain projects encountered security incidents this month, resulting in significant financial losses. Major security incidents this month include Thala contract vulnerability leading to a theft of $25.5 million, DEXX Private Key leakage causing a loss of $21 million, and Polter Finance suffering a $12 million loss from a flash loan attack.
Major Security Incidents in November
According to official data, the projects with losses of over a million dollars in November are as follows. Multiple security incidents in November showed that contract vulnerabilities are still a major threat.
Thala
Project Introduction: Thala is a Decentralization stablecoin protocol based on Aptos, aiming to provide a stablecoin for yield generation and a Liquidity supply layer. The protocol supports various forms of Collateral, including Liquidity collateralized derivatives, Liquidity pool Tokens, deposit receipt Tokens, and assets pegged to real-world assets (RWA). This diversified Collateral design not only ensures Decentralization and anti-censorship characteristics but also takes into account capital efficiency.
Event Introduction:
On November 15, 2024, Thala, a Decentralized Finance project in the Aptos ecosystem, experienced a security incident, with a loss of $25.5 million. The attacker exploited vulnerabilities in the Smart Contract to carry out the attack. The project party promptly suspended the relevant contracts and froze a portion of the Token assets after the incident.【3】
After investigation, the project party successfully froze approximately $11.5 million in assets. Subsequently, the project party cooperated with law enforcement agencies and multiple blockchain security teams to actively handle the incident. Through negotiation, the project party recovered the stolen funds. According to the negotiated content, the attacker received a bounty of $300,000.
Reminder: After the event
DEXX
Project Overview: DEXX is an on-chain Token trading terminal application designed specifically for memecoin trading, providing comprehensive functional support. The platform integrates accurate data analysis tools, advanced trading strategies such as mobile take profit and stop loss, and is equipped with intelligent Wallet monitoring and real-time push functions to help users optimize trading experience and efficiently manage assets.
Event Introduction:
On November 16, DEXX platform encountered a major security incident, where the improper management of the official Private Key led to its leakage, resulting in the theft of user assets, with a total loss exceeding 21 million US dollars, affecting over 500 victims. The affected Tokens include BAN, Banana, and LUCE, among which BAN suffered the largest loss. [4]
The following is the timeline of the DEXX Hacker incident:
Reminder: After the event
Polter Finance
Project Introduction: Polter Finance is a non-custodial lending platform on FTM that focuses on Decentralization and aims to provide lenders with proportional Interest returns.
Event Introduction:
Here is a timeline of the Polter Finance incident:
Reminder: After the event
It is recommended that users be vigilant about the security of the platform when using Decentralization platforms, especially when it involves Cross-Chain Interaction operations and Decentralized Finance projects. Especially when there is a significant Fluctuation in the market, project parties should promptly conduct vulnerability detection and Risk Management to ensure the security of the platform's Smart Contracts and Cross-Chain Interaction bridges.
DeltaPrime
Project Introduction: DeltaPrime is a Decentralized Finance lending and investment platform aimed at releasing restricted Liquidity by improving capital efficiency. Users can easily deposit and borrow on the platform to enhance their Decentralized Finance investment capabilities. The platform's minimum loan-to-value ratio is 20%.
Event Introduction:
The DeltaPrime project was hacked in September, here is a complete summary:
Reminder: After the event
Decentralized Finance projects and platforms related to assets need to enhance security, especially strict input validation on key functions (such as reward claiming), to avoid similar attacks.
MetaWin
Project Introduction: MetaWin is an on-chain prediction gaming platform based on Blockchain technology. It offers various mini-games for user participation and provides rewards of up to 1 million US dollars.
Event Introduction:
Metawin encryption gambling platform suffered a Hacker attack on November 5, 2024, and lost over 4 million dollars in assets. The Hacker stole funds from ETH, Base, and Solana's hot Wallet, and transferred some of the proceeds to KuCoin, HitBTC, Binance, and ChangeNow. The attacker has transferred 331 ETH (about 800,000 dollars) in batches to different Wallets, with each transfer being 13, 19, and 21 ETH. In addition, 115 theft Addresses related to the attacker have been discovered, and these funds are still being transferred.
Reminder: After the event
The recent Metawin attack serves as a reminder for users to remain vigilant when using encryption platforms, especially when it comes to transferring funds involving Hot Wallet and Cross-Chain Interaction, ensuring that the platform's security measures are sufficient. Users should regularly check the platform's security announcements, avoid interacting with suspicious Addresses, and enhance account security settings (such as enabling multi-factor authentication) to mitigate the risk of drop. At the same time, platform operators should strengthen the protection of user funds, ensuring timely detection and response to potential security vulnerabilities.
Summary
In November 2024, multiple Decentralized Finance platforms were attacked by hackers, resulting in millions of dollars worth of assets being stolen. These incidents highlight the ongoing security risks of Decentralized Finance projects and remind the industry to pay more attention to security protection and vulnerability fixes. At the same time, platform security vulnerabilities and fund flow control issues have once again become a focus of attention, emphasizing the need to ensure the security of user assets and the stability of the platform while pursuing innovation and development. Gate reminds users to participate in the market cautiously and protect their funds.
Reference materials:
gate Research Institute Gate Research Institute is a comprehensive blockchain and cryptocurrency research platform that provides readers with Depth content, including Technical Analysis, hot insights, market reviews, industry research, trend forecasting, and macroeconomic policy analysis.
Click link to go now
Disclaimer Crypto Assets market investment involves high risks. It is recommended that users conduct independent research and fully understand the nature of the assets and products purchased before making any investment decisions. gate is not responsible for any losses or damages caused by such investment decisions.