英文_慢雾科技_区块链安全趋势与反洗钱格局报告_79页_18mb
报告摘要
SLUJIMIST 2025 Mid-year Blockchain Security and AML Report Summary
I. Introduction
In the first half of 2025, the blockchain industry saw continued growth alongside a rise in complex security threats and compliance challenges. Key issues include:
- Active hacker attacks: APT groups used more modular and systematic techniques, while phishing and social engineering attacks became more prevalent, leading to significant asset losses and a decline in user trust.
- Regulatory evolution: Governments and international organizations rapidly introduced new AML, sanctions, and consumer protection rules.
- Stablecoins as critical infrastructure: They are increasingly used as bridges between traditional and on-chain finance.
- Blockchain tracing and intelligence collaboration: These technologies have advanced, aiding in asset freeze and recovery efforts, which serve as a deterrent to on-chain crime.
II. Blockchain Security Trends
2.1 Overview of Blockchain Security Incidents
- Total incidents: 121 in H1 2025, resulting in losses of approximately $2.373 billion.
- Loss comparison: H1 2024 had 223 incidents with about $1.43 billion in losses.
- Loss increase: Total losses increased by 65.94% year-over-year.
By Ecosystem
- Ethereum: Most affected, with losses of $38.59 million.
- Solana: Losses of $5.8 million.
- BSC: Losses of $5.49 million.
By Project Type
- DeFi: Most targeted, with 92 incidents accounting for $470 million in losses.
- Centralized exchanges: 11 incidents, with $1.883 billion in losses.
- Notable case: Bybit was hit by a single incident causing $1.46 billion in losses.
By Loss Scale
- Top 10 attacks: Total losses of $2.018 billion.
- Two incidents: Losses exceeding $100 million.
By Attack Vector
- Account compromises: 42 incidents.
- Smart contract vulnerabilities: 35 incidents.
2.2 Fraud Tactics
2.2.1 Phishing Using EIP-7702
- Case: A user lost $146,551 via a phishing attack exploiting the EIP-7702 delegation mechanism.
- Mechanism: Attackers used a legitimate MetaMask EIP-7702 Delegator address to perform bulk token approvals.
- Risks:
- Private key leakage: Even with delegation, private keys must be protected.
- Inconsistent contract code: Different chains may have different implementations of the same contract address.
- Permission verification: Developers should verify permissions during wallet initialization.
- Redelegation risks: Incompatible storage structures can lead to account lockups or fund loss.
- Recommendations: Users should be cautious with delegation, understand the target, and avoid using anti-phishing tools that only block transfers, not approvals.
2.2.2 Deepfakes
- New trend: Scammers use deepfake technology to create realistic audio and video content to manipulate public trust.
- Common scenarios:
- Fake celebrity endorsements: Scammers use deepfakes of politicians and influencers to promote fraudulent platforms.
- Virtual identity investment scams: Scammers set up fake personas and simulate trustworthy platforms to lure victims into investing.
- Deepfake Zoom meetings: Scammers impersonate Zoom to trick users into downloading malware and stealing data.
- Impact: These attacks exploit users' trust and are difficult to detect due to their high level of realism.
- Recommendations:
- Be cautious of "official videos" with disabled comments.
- Avoid unfamiliar contacts redirecting to third-party platforms.
- Do not download unknown software from chat platforms.
- Perform asset operations on isolated devices.
2.2.3 Telegram Fake Safeguard Scam
- Scam overview: Users were tricked into executing malicious code from their clipboard, often under the guise of airdrops or fake KOL posts.
- Process:
- Users are prompted to "verify" via a fake Safeguard bot.
- The malicious code is hidden in the clipboard and executed when users paste it.
- Consequences: Users' devices are infected with remote access trojans (RATs), leading to the theft of wallet files, private keys, and passwords.
- Recommendations:
- Replace hot wallets and transfer assets to new addresses.
- Reset all passwords and 2FA for affected accounts.
- Reinstall the operating system and use antivirus software.
2.2.4 Malicious Browser Extensions
- Common tactic: Extensions are disguised as "Web3 security tools" or tampered with to steal data.
- Notable case: SwitchyOmega was compromised, potentially affecting 2.6 million users.
- Attack method:
- Phishing emails tricked developers into authorizing a malicious OAuth app.
- Malicious code was injected into the published extension.
- Automatic updates propagated the malicious version to users.
- Malicious code functionality:
- Connects to a C&C server to download configuration data.
- Monitors user activity and uploads sensitive data to attacker-controlled servers.
- Other compromised extensions:
- VPNCity, Parrot Talks, Uvoice, Internxt VPN, Bookmark Favicon Changer, Castorus, Wayin AI, Search Copilot AI Assistant, VidHelper, AI Assistant - ChatGPT and Gemini, Cyberhaven security extension V3, GraphQL Network Inspector, GPT 4 Summary with OpenAI, Vidnoz Flex, YesCaptcha assistant, Proxy SwitchyOmega (V3), ChatGPT App, Web Mirror, Hi AI, EditThisCookie.
- Total users affected: 2.65 million.
- Recommendations:
- Download extensions only from official sources.
- Be cautious of permission requests.
- Regularly check and remove suspicious extensions.
- Install antivirus software.
III. Anti-Money Laundering Landscape
- Regulatory developments: Rapid global changes in AML, sanctions, and consumer protection laws.
- Frozen & Recovered Funds: The number of asset freeze and recovery cases has increased significantly.
- Threat Actor Developments:
- Lazarus Group: Continued to be a major threat in the AML space.
- Drainers: Exploited vulnerabilities in blockchain systems to drain funds.
- HuionePay: A new player in the AML threat landscape.
- Mixing Services:
- Tornado Cash: A major mixing service used for laundering funds.
- eXch: Another mixing service that has been targeted for regulatory scrutiny.
IV. Summary
- The blockchain industry faces growing security and compliance challenges.
- DeFi remains the most targeted sector, but centralized exchanges have seen the highest losses.
- EIP-7702 delegation mechanism introduces new risks, especially through phishing and misuse of permissions.
- Deepfake technology is increasingly used to create trust-based scams.
- Telegram fake safeguard scams and malicious browser extensions are significant threats to user assets.
- Regulatory actions and blockchain tracing have improved the ability to freeze and recover illicit funds.
V. Disclaimer
- The data in this report is based on token prices at the time of each incident and may not reflect the actual losses due to price fluctuations, unreported cases, and individual user losses.
VI. About Us
- SlowMist is a pioneer in blockchain security, focusing on threat intelligence, attack monitoring, on-chain tracing, and compliance support.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载