Coinlive- We Make Blockchain Simpler
Download and install the Coinlive app
Open

SlowMist | Blockchain Security and Anti-Money Laundering Report for the First Half of 2024

Foreword

SlowMist Technology released the "Blockchain Security and Anti-Money Laundering Report for the First Half of 2024" (hereinafter referred to as the "Report"). This report summarizes the key regulatory compliance policies and trends of the blockchain industry in the first half of 2024, including but not limited to the multi-angle regulatory stance on cryptocurrencies and a series of core policy adjustments. We reviewed and outlined the blockchain security incidents and anti-money laundering trends in the first half of 2024, interpreted some common money laundering tools and phishing theft techniques, and proposed effective prevention methods and response strategies for such problems. In addition, we also disclosed and analyzed the major phishing criminal organizations Wallet Drainers and the hacker group Lazarus Group, in order to provide a reference for preventing such threats.

1. Background

According to CoinMarketCap data, as of June 30, 2024, the total market value of the global cryptocurrency market has reached approximately US$2.34 trillion, fully demonstrating the increasingly strong growth momentum of the global blockchain market. However, with its development momentum comes the increasingly severe challenges facing blockchain security. As blockchain applications expand and deepen, attackers have become more sophisticated and complex, constantly breaking through and exploiting vulnerabilities in blockchain systems to attack, resulting in huge losses.

Against this background, this report focuses on two aspects: blockchain ecosystem security and anti-money laundering (AML) security, so that everyone can have a comprehensive understanding of the current and future security risks of blockchain.

2. Blockchain Security Situation

2.1 Overview of Blockchain Security Incidents

According to incomplete statistics from the SlowMist Hacked Archive, there were 223 security incidents in the first half of 2024, with losses of up to $1.43 billion. Compared with the first half of 2023 (a total of 185 incidents, with losses of approximately $920 million), the losses increased by 55.43% year-on-year. (Note: This report does not include personal losses in the statistics)

(https://hacked.slowmist.io/)

From the perspective of ecology, Ethereum suffered the highest loss, reaching $400 million. It was followed by Arbitrum, with about $72.46 million, and then Blast, with about $70 million. In addition, BSC had the most security incidents, reaching 57, with a loss of about $32.12 million.

From the perspective of project tracks, DeFi is the most frequently attacked area. In the first half of 2024, there were 158 DeFi-related security incidents, accounting for 70.85% of the total number of incidents, with losses of up to $659 million. Compared with the first half of 2023 (a total of 111 incidents, with losses of approximately $480 million), the losses increased by 37.29% year-on-year. Secondly, the losses from security incidents on trading platforms reached $524 million, of which the DMM Bitcoin incident accounted for $305 million, which was also the security incident with the largest loss in the first half of 2024.

In terms of losses, two incidents had losses of over 100 million US dollars. The following are the top 10 security attack incidents with the highest losses in the first half of 2024:

In terms of the causes of security incidents, contract vulnerability incidents accounted for the most, reaching 56 incidents, with a loss of approximately 104 million US dollars. The second largest number was security incidents caused by running away, reaching 50 incidents.

2.2 Phishing/Theft Methods

This section extracts some of the phishing and theft methods disclosed by SlowMist in the first half of 2024:

  • Same first and last number phishing

  • Malicious extensions

  • Malicious Trojans

  • Malicious bookmark phishing

  • Signature authorization phishing

III. Anti-Money Laundering Situation

3.1 Anti-Money Laundering and Regulatory Dynamics

This section will focus on the major developments in Anti-Money Laundering (AML) and regulatory dynamics in the cryptocurrency field:

  • Chinese Courts

  • Hong Kong, China

  • Singapore

  • US Regulation

  • European Parliament

  • Middle East

3.2 Anti-Money Laundering in Security Incidents

  • Fund freezing data

Tether: In the first half of 2024, a total of 374 ETH addresses were blocked, and the USDT-ERC20 assets on these addresses were frozen and could not be transferred.

Circle: In the first half of 2024, a total of 28 ETH addresses were blocked, and the USDC-ERC20 funds on these addresses were frozen and could not be transferred.

With the strong support of SlowMist InMist intelligence network partners, SlowMist assisted customers, partners and public hacking incidents in freezing funds of approximately US$24.39 million in the first half of 2024.  

  • Funds Return Data

In the first half of 2024, there were 16 incidents in which all or part of the lost funds were recovered after the attack. In these 16 incidents, the total amount of stolen funds was about 113 million US dollars, of which nearly 98.64 million US dollars were returned, accounting for 87.3% of the stolen funds.

3.3 Hacker Group Profile and Dynamics

This section provides a detailed analysis of the modus operandi of the hacker group Lazarus Group and the phishing service Drainers.

  • Lazarus Group

  • Drainers

3.4 Money Laundering Tools

This section conducts a statistical analysis of the capital flow and direction of the money laundering tools Tornado Cash and eXch.

(Tornado Cash: https://dune.com/misttrack/first-half-of-2024-stats)

(eXch: https://dune.com/misttrack/first-half-of-2024-stats)

Fourth, Write at the end

In general, we hope that this report can provide readers with an analysis and interpretation of the current security status of the blockchain industry, help readers to have a more comprehensive understanding of the security and anti-money laundering status of the blockchain industry, and contribute to the development of blockchain ecological security.

Finally, thanks to every ecological partner. This includes our service customers, media partners, Black Manual contributors, and SlowMist zone partners. It is your great help that has strengthened our determination to keep making progress and continue to be a good guardian of the blockchain. We hope that we will continue to join forces and work side by side to bring more light to the dark forest of blockchain.

Disclaimer

The content of this report is based on our understanding of the blockchain industry, the SlowMist Hacked archive of the SlowMist blockchain, and the data support of the anti-money laundering tracking system MistTrack. However, due to the "anonymous" nature of the blockchain, we cannot guarantee the absolute accuracy of all data here, nor can we be held responsible for errors, omissions, or losses caused by the use of this report. At the same time, this report does not constitute any investment advice or other analysis.

If there are omissions and deficiencies in this report, please feel free to criticize and correct them.

This is the end of the introduction. For the full version, please read and share

https://www.slowmist.com/report/first-half-of-the-2024-report(CN).pdf

More news about slowmist

  • Jul 12, 2024 2:47 pm
    SlowMist: Please beware of fake SlowMist employees who actively chat with you privately
    Security company Slowmist posted a message on X saying that it found that user X @jeazy_eth claimed to be a Slowmist employee in the personal information notes, and the user also invited the party to private chat under some security-themed posts. Slowmist emphasized that the user has no relationship with Slowmist, please beware of potential fraud.
  • Jun 07, 2024 10:40 am
    SlowMist: Potentially suspicious activity related to Steam Swap has been detected
    SlowMist posted on the X platform that it had detected potentially suspicious activity related to Steam Swap.
  • May 14, 2024 6:27 pm
    SlowMist: Suspicious activities at Predy Finance
    According to SlowMist monitoring, Predy finance has related potential suspicious activities, please remain vigilant.
  • May 07, 2024 1:11 pm
    SlowMist CISO Warns Mac Users About Cuckoo Malware Threat
    SlowMist's Chief Information Security Officer (CISO), known online as 23pds, has issued a warning to Mac users about a new strain of malware called Cuckoo. Posted on the X platform, the notice mentions how Cuckoo poses a significant risk to Intel and ARM-based Macs, primarily focusing on stealing data from cryptocurrency wallets and messaging applications. Cuckoo distinguishes itself through a unique propagation method. It spreads across systems via music streaming channels, making detection and isolation more challenging. Mac users are urged to exercise heightened caution to protect their digital assets and data from this invasive malware. Frequent system scans, careful online behavior, and regular updates to the latest OS versions are some of the recommended measures to fend off potential Cuckoo infiltration. 
  • Mar 06, 2024 5:29 pm
    Founder of SlowMist Warns of Scam Targeting X Platform Users
    According to Foresight News, the founder of SlowMist, Yu Xian, has issued a warning to users of the X platform about a scam involving Cyber Rescue (@CCyber_rescue). The scammers claim to help users recover stolen funds, using a known wallet bug to make it appear as if the lost funds have been returned. SlowMist is considering exposing the scam, but in the meantime, users are advised to be cautious to avoid falling victim to the scheme.
  • Feb 05, 2024 11:42 am
    SlowMist: Potentially suspicious activity related to Burnedfi has been detected
    SlowMist has issued a security alert on the X platform and has detected potentially suspicious activities related to Burnedfi. Please stay vigilant.
  • Dec 26, 2023 11:15 am
    SlowMist Founder Addresses Avascriptions Wallet Network Switch Issue
    According to Foresight News, SlowMist founder Yu Xian recently tweeted about an issue faced by some users of Avascriptions. They reported that their wallets failed to switch to the correct network, resulting in assets being sent to other EVM chains. Yu Xian assured users that the assets sent to Avascriptions on other EVM chains can be retrieved. To do so, the project team needs to deploy relevant contracts on the other EVM chains and users should exercise caution while performing these operations. Although the core contracts on Avalanche have not been open-sourced yet, the platform has reserved an asset retrieval function.
  • Dec 21, 2023 4:13 pm
    Atomicals Assets Lost Due to Burning Mechanism, Says SlowMist Founder
    According to Foresight News, SlowMist founder Yu Xian recently stated on social media that the loss of users' Atomicals assets was due to the burning mechanism in the official protocol. He explained that if a wallet or platform does not perfectly support the new protocol, the corresponding assets could be lost accidentally. The official transfer rules for Atomicals state that the normal operation for ARC20 token transfers is that the sum of all input values should be completely or cleanly allocated to available outputs. In cases where there is not enough output value, or one of the subsequent outputs would result in over-allocation (i.e., token unit inflation), the remaining balance will be permanently destroyed or burned.
  • Dec 06, 2023 2:33 pm
    SlowMist Founder Believes Fixing Bitcoin Core Vulnerability Is Unnecessary
    According to Foresight News, SlowMist Technology founder Yu Xiang recently expressed his opinion on social media that fixing the Bitcoin Core vulnerability mentioned by Bitcoin core developer Luke Dashjr is unnecessary. Yu Xiang stated that the introduction of Taproot has not only brought a bunch of spam but also increased activity in the Bitcoin ecosystem. He believes that the ecosystem is not just about serial numbers and inscriptions, and if a compatible solution can be found to better open up the Bitcoin ecosystem, it would be better to endure short-term pain rather than long-term suffering.
  • Nov 14, 2023 12:33 pm
    Fake Journalists Caught Stealing Coins Through Deceptive Tactics: Slowmist
    The post Fake Journalists Caught Stealing Coins Through Deceptive Tactics: Slowmist appeared first on Coinpedia Fintech News According to the Slowmist, journalists have been exposed for stealing coins from unsuspecting victims. The hackers posed as journalists to gain trust, tricking victims into opening a malicious JavaScript script embedded in a bookmark on the friend tech page. This script was designed to deceive and steal both passwords and valuable tokens. Slowmist promptly uncovered the scheme, warning the public to be cautious of such tactics. The incident highlights the need for increased cybersecurity measures and user vigilance to protect against online threats. Stay informed and exercise caution when interacting online to safeguard personal information and digital assets.

More news about slowmist

0 Comments
Earliest
Load more comments