<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Web3 Security on 思安录 | Thinking&#39;s Security Notes</title>
    <link>https://blog.1sec.day/en-gb/tags/web3-security/</link>
    <description>Recent content in Web3 Security on 思安录 | Thinking&#39;s Security Notes</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-gb</language>
    <managingEditor>Thinking</managingEditor>
    <webMaster>Thinking</webMaster>
    <lastBuildDate>Thu, 03 Jul 2025 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.1sec.day/en-gb/tags/web3-security/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>A Popular Solana Bot on GitHub Was a Wallet Thief: Supply Chain Attack Analysis</title>
      <link>https://blog.1sec.day/en-gb/posts/2025-07-03-solana-bot-supply-chain-attack/</link>
      <pubDate>Thu, 03 Jul 2025 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2025-07-03-solana-bot-supply-chain-attack/</guid>
      
      <description></description>
      
    </item>
    
    <item>
      <title>Osiris Malicious Browser Extension Analysis: Download Link Hijacking Disguised as a Security Tool</title>
      <link>https://blog.1sec.day/en-gb/posts/2025-05-28-osiris-malicious-extension/</link>
      <pubDate>Wed, 28 May 2025 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2025-05-28-osiris-malicious-extension/</guid>
      
      <description></description>
      
    </item>
    
    <item>
      <title>ReachMe.io Vulnerability: Saying Hi to CZ on a Budget</title>
      <link>https://blog.1sec.day/en-gb/posts/2025-03-28-reachme-cz-vulnerability/</link>
      <pubDate>Fri, 28 Mar 2025 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2025-03-28-reachme-cz-vulnerability/</guid>
      
      <description>&lt;p&gt;Yesterday, while I was still sorting through APT attack materials, Brother Shan (@im23pds) suddenly rushed over to my desk, excited: &amp;ldquo;Thinking, I found an interesting project that CZ is using heavily — maybe we can say Hi to CZ for zero cost.&amp;rdquo; We quickly brainstormed several potential vulnerability points:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Hijacking CZ&amp;rsquo;s ReachMe account;&lt;/li&gt;
&lt;li&gt;Changing CZ&amp;rsquo;s ReachMe settings;&lt;/li&gt;
&lt;li&gt;Messaging CZ for free, bypassing the 1 BNB fee to send him a message.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;About 10 minutes later, we discovered a vulnerability that allowed sending messages to any user on ReachMe.io at low cost. We immediately contacted the project team with detailed vulnerability verification. The project team quickly fixed the vulnerability and reached back out to us for retesting. Kudos to the ReachMe team for taking security seriously!&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://blog.1sec.day/en-gb/posts/2025-03-28-reachme-cz-vulnerability/slowmist-tweet.png&#34; alt=&#34;SlowMist Team’s vulnerability disclosure tweet&#34;&gt;&lt;/p&gt;
&lt;p&gt;Additionally, the SlowMist Security Team was honoured to receive thanks from both CZ and the ReachMe project team.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://blog.1sec.day/en-gb/posts/2025-03-28-reachme-cz-vulnerability/cz-thanks.png&#34; alt=&#34;CZ’s thank-you tweet to SlowMist&#34;&gt;&lt;/p&gt;</description>
      
    </item>
    
    <item>
      <title>LinkedIn Recruitment Phishing Analysis: A Targeted Attack Against Blockchain Engineers</title>
      <link>https://blog.1sec.day/en-gb/posts/2025-03-15-linkedin-recruitment-phishing/</link>
      <pubDate>Sat, 15 Mar 2025 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2025-03-15-linkedin-recruitment-phishing/</guid>
      
      <description></description>
      
    </item>
    
    <item>
      <title>Celer Network cBridge Cross-Chain Bridge Incident Analysis: BGP Hijacking Attack</title>
      <link>https://blog.1sec.day/en-gb/posts/2022-08-20-celer-network-bgp-hijacking/</link>
      <pubDate>Sat, 20 Aug 2022 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2022-08-20-celer-network-bgp-hijacking/</guid>
      
      <description></description>
      
    </item>
    
    <item>
      <title>Solana Blockchain Mass Theft Analysis: Slope Wallet Sentry Leaks Mnemonic Phrases</title>
      <link>https://blog.1sec.day/en-gb/posts/2022-08-04-solana-massive-theft/</link>
      <pubDate>Thu, 04 Aug 2022 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2022-08-04-solana-massive-theft/</guid>
      
      <description></description>
      
    </item>
    
    <item>
      <title>MetaMask Browser Extension Wallet demonic Vulnerability Analysis</title>
      <link>https://blog.1sec.day/en-gb/posts/2022-06-17-metamask-demonic-vulnerability/</link>
      <pubDate>Fri, 17 Jun 2022 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2022-06-17-metamask-demonic-vulnerability/</guid>
      
      <description>&lt;p&gt;On 16 June 2022, MetaMask (MM) officially disclosed a security issue discovered by a white-hat researcher, dubbed the demonic vulnerability. The vulnerability affects versions &amp;lt; 10.11.3. Given MM&amp;rsquo;s large user base and the number of wallets developed based on MM, the impact is significant — MM generously awarded the white-hat researcher a $50,000 bounty. After the team synced me on this vulnerability, I began analysing and reproducing it.&lt;/p&gt;</description>
      
    </item>
    
    <item>
      <title>MetaMask Clickjacking Vulnerability Analysis: iframe Hijacking and Phishing Whitelist Bypass</title>
      <link>https://blog.1sec.day/en-gb/posts/2022-06-14-metamask-clickjacking/</link>
      <pubDate>Tue, 14 Jun 2022 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2022-06-14-metamask-clickjacking/</guid>
      
      <description>&lt;p&gt;On 3 June 2022, MetaMask (MM) publicly disclosed a severe Clickjacking vulnerability discovered by a white-hat researcher. The impact: when a user&amp;rsquo;s MM extension wallet is unlocked and they visit a malicious site, the site can use an iframe tag to embed the unlocked MM wallet page, hide it, and then guide the user to click on what appears to be the website — while the actual interaction happens on the unlocked MM page — thereby stealing the user&amp;rsquo;s cryptocurrency or NFTs. Given MM&amp;rsquo;s large user base and the number of projects that fork MetaMask, we immediately began reproducing the vulnerability and searching for its impact on other forked projects after MM&amp;rsquo;s disclosure.&lt;/p&gt;
&lt;p&gt;The SlowMist Security Team then notified affected project teams as much as possible and guided them through remediation. We are now publishing this Clickjacking vulnerability analysis to help future projects avoid the same pitfall.&lt;/p&gt;</description>
      
    </item>
    
    <item>
      <title>Sky-High Fee Analysis: ethjs-util Floating-Point Data Processing Flaw</title>
      <link>https://blog.1sec.day/en-gb/posts/2021-09-29-ethjs-util-high-gas-fee/</link>
      <pubDate>Wed, 29 Sep 2021 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2021-09-29-ethjs-util-high-gas-fee/</guid>
      
      <description></description>
      
    </item>
    
  </channel>
</rss>
