9월 통계 그래프

研究与成果 Security Reports
9월 통계 그래프

Sep Stats Graphic (1) Sep-Top 7 Major Incidents Sep-Top 5 Flashloan Sep-Top 5 Rugpull Jan-Sep monthly total loss YTD-Sep

相关博客

Threshold Cryptography III: Binance tss-lib’s 9-Round Threshold ECDSA

Threshold Cryptography III: Binance tss-lib’s 9-Round Threshold ECDSA

This third post in the Threshold Cryptography series provides a bird’s-eye view of the 9-round threshold ECDSA protocol implemented in tss-lib [1]. Detailed exposition of the underlying MtA secret share conversion protocol and zero-knowledge proofs will follow in the next two posts.

Lucky Star Currency Exit Scam

Lucky Star Currency Exit Scam

On 9 October, the price of LSC token dropped by 99% due to a token dump carried out by externally owned address 0x9Ef72 which withdrew LSC tokens from two contracts owned by the Lucky Star Currency project. The tokens were then swapped for approximately $1.1 million making it the largest exit scam seen in October so far.

GMX Incident Analysis

GMX Incident Analysis

On 9 July 2025 GMX V1 vault was exploited by a white-hat for ~$42M due to a reentrancy issue. The funds were later returned to GMX who awarded the white-hat a 10% bounty. The whitehat had minted and then staked GLP before creating a short position directly from the vault contract through reentrancy. Executing in this order bypassed the ShortsTracker, and prevented the average short position price from being updated. This occurs when the market price exceeds the tracked average price, resulting in the protocol overestimating unrealized losses. As a result, the Assets Under Management (AUM) calculation was manipulated to inflate the apparent value of GLP.