Gm Commiters,
As we wrap up another eventful month, we are excited to bring you our first-ever recap newsletter! This is a new initiative we’re thrilled to start, where we’ll be delivering updates on our activities, insights, and achievements in Web3 security every month.
We published several articles covering critical aspects of blockchain technology and security:
1. Maximal Extractable Value (MEV) - Delving into how MEV influences blockchain networks, including strategies and security concerns surrounding it.
2. Application Binary Interface (ABI) - A comprehensive look at ABI in Solidity, emphasizing its crucial role in smart contracts.
3. Blockchain Security - Exploring the key security challenges in the decentralized landscape and how we mitigate them.
We also released Twitter threads diving into various topics:
• Bitcoin Runes: Security Perspective - A detailed introduction to Bitcoin Runes and the potential vulnerabilities they face.
• Kujira Security Analysis - Thorough assessment of Kujira ecosystem and offered recommendations for improvement.
• Token Dispenser Smart Contracts - A review of vulnerabilities in token dispenser contracts and how to secure them.
• ABI in Solidity - A summary to our article explaining the importance of ABI in Solidity and how it ensures security.
• Encryption Techniques in Solidity - Discussing how encryption techniques can strengthen smart contract security.
Over the past month, we diligently monitored and analyzed several major hacks, gaining valuable insights to improve the overall security for our clients. Below is a summary of key incidents:
• Terra: Suffered a loss of approximately $5.3M.
• Convergence: Lost around $210K in a separate exploit.
• Ronin Network: Experienced a $12M breach, though the hacker returned $10M.
• Nexera: Lost around $1.76M due to an exploit.
• Vow Currency: Incurred losses totaling $1.2M.
• Around 50 Seif Wallet users had their wallets compromised because of a bug in the latest app version.
• AshPerp: Lost approximately $26K.
• Parcl: Faced a double breach with their frontend and Twitter accounts being compromised.
The fourth hack track consolidated the significant hacks of August 2024. It was one of the highest-loss months of the year, with $310.9M lost to various exploits, flash loan attacks, and exit scams, making it the second-highest monthly loss in 2024.
• Exploits led the way, accounting for $308.7M in losses.
• Flash loan attacks resulted in $1.2M in damages, showing the growing complexity of these attack vectors.
• Exit scams contributed $0.8M, a smaller but still impactful share of the total loss.
Additionally, on August 28, a periphery contract of the DeFi platform Aave was hacked due to an arbitrary call/logic error, leading to a $56K loss. However, no user funds were at risk, as assured by Aave’s founder, Stani Kulechov.
These incidents underscore the ongoing need for robust security measures and proactive defense strategies across the Web3 ecosystem.
We had the privilege of attending Confess Asia, a premier blockchain event where we discussed emerging trends in Web3 security and showcased our capabilities to a broader audience.
We are thrilled to announce our partnership with SOEX | Social Exchange, where we are conducting a comprehensive security audit for their smart contracts. This collaboration marks an important milestone in providing state-of-the-art security for decentralized platforms.
Our First Newsletter!
This marks the beginning of our exciting new idea to push a monthly newsletter and keep you all in the loop about our efforts, insights, and achievements. We are incredibly excited to have you with us on this journey as we aim to make Web3 a safer space.
Best regards,
The 0xCommit Team
Empowering Web3 Security
Website: 0xCommit.com
Telegram: 0xCommitAudits

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.