Cointime

Download App
iOS & Android

SharkTeam: Enhancing Web3 Security with Smart Contract Auditing and On-Chain Analysis Services

Cointime Official

The Web3 ecosystem is a dark forest, where both opportunities and dangers coexist.

Unfortunately, financial crimes, hacking attacks, fraudulent extortion, and money laundering incidents are all too common in Web3, with significant financial and societal impacts. Attack methods such as contract loophole exploits, flash loan attacks, phishing attacks, and rug pulls are emerging constantly, and evolving at an alarming pace.  

As the Web3 ecosystem continues to grow and innovate, the battle between attackers and security firms will only intensify. In this article, we will introduce Web3 security service provider SharkTeam. Through smart contract audits, on-chain security analysis, and on-chain asset tracking, SharkTeam is working to enhance the safety and security of Web3 assets.

Smart Contract Audit

Smart contracts are a fundamental part of the blockchain ecosystem, providing a transparent and immutable way to execute transactions. However, this transparency also means that any security risks associated with smart contracts are highly visible. Once a smart contract is deployed, it cannot be tampered with or stopped. Any vulnerabilities in the code can be exploited by hackers in real-time, potentially resulting in significant financial losses.

ChainAegis, an on-chain analysis platform under SharkTeam, released Web3 Security Report Q1 2023. According to the report, a total of 211 security incidents occurred in the Web3 field in the first quarter of 2023, with a total loss of more than US$383 million. Among them, there were a total of 25 security incidents caused by contract vulnerbilities, resulting in a cumulative loss of more than US$362 million. On March 13, the DeFi lending agreement Euler Finance suffered a lightning loan attack incident with a loss of 197 million US dollars, which was the most serious security loss due to contract loopholes this quarter.

Source: https://app.chainaegis.com/home/news/detail?contentId=290

The security provider SharkTeam offers smart contract auditing services, with both manual and automated auditing options. Its library of more than 200 smart contract security vulnerabilities covers the most common security incidents, attack detection and blocking technologies, and anti-phishing attacks. SharkTeam supports multi-chain smart contract auditing and covers popular smart contract languages such as Solidity, Rust, Move, Cadence, and more.

It's important to note that passing a security audit from an audit company does not guarantee absolute safety. For example, the DEX Merlin on the zkSync network suffered a Rug Pull shortly after passing an audit, resulting in a direct loss of $1.82 million. 

On-chain security analysis and asset tracking

To fully understand a Web3 project, three types of analysis are must-haves, which are: fundamental analysis, technical analysis, and on-chain analysis.

Fundamental analysis involves examining a project's finances, team, source code, announcements, features, and token-related news. Technical analysis entails observing charts and price trends of encrypted assets based on specific indicators to predict market trends and potential future price changes. Finally, on-chain analysis involves monitoring the activities and transactions of various projects on the blockchain.

SharkTeam provides analysis services for all three types of analysis. Its analysis team manually analyzes projects and produces research reports, which users can utilize to gain a more comprehensive understanding of project fundamentals and data performance. Moreover, SharkTeam's project leaderboard sorts projects based on their market capitalization, and shows project-related token prices, holdings, lock-up ratio, 24H change rate, and other data, enabling users to better perform technical analysis.

Most notably, SharkTeam also offers on-chain security analysis. The ability to track state changes over time is critical on blockchains such as Bitcoin (BTC) and Ethereum (ETH). For DeFi projects, tracking the flow of funds is crucial. Although blockchains are transparent, hackers can make it a maze.

SharkTeam launched the ChainAegis on-chain risk analysis platform in April 2022. The platform employs artificial intelligence and big data analysis technology to provide encrypted asset monitoring and online analysis services, encompassing DeFi, NFT, OTC, and other formats.

Source: https://www.sharkteam.org/

One of the unique features of the ChainAegis platform is its collection of over 1 billion on-chain risk tag libraries. These libraries enable the platform to discover and identify multiple tags of on-chain information, predict malicious attacks and crimes in advance, and track them afterward. ChainAegis also leverages correlation analysis, knowledge graphs, and other technologies to perform multi-link analysis and tracking of funds. By combining these capabilities with its risk data tag library, ChainAegis can perform visual analysis on transaction paths and predict capital flows.

In addition, ChainAegis offers real-time risk monitoring and risk alerting services. It can monitor transactions on the chain in real-time and provide alerts for price fluctuations, liquidity warnings, flash loan identification, contract vulnerability warnings, RugPull warnings, and more. Currently, SharkTeam can provide early warning services for nearly 10 mainstream public chains, including Bitcoin (BTC), Ethereum (ETH), and Binance Smart Chain (BNBChain).

The common challenge for Web3 security service providers

Web3 security service providers, such as Consensys, Certik, and Quantstamp, face a common challenge in the rapidly evolving landscape of Web3 security threats.

Recent attacks against Web3 infrastructure, such as the robbery of 2 million BNB from Binance in October 2022, serve as a reminder of the importance of effective security measures.

Moreover, hackers are increasingly leveraging artificial intelligence tools, such as ChatGPT, to automate network attacks and identify vulnerable targets.

As hackers' attack techniques continue to evolve, SharkTeam and other Web3 security service providers must work together to form a comprehensive security ecosystem that can effectively protect the Web3 world.

Comments

All Comments

Recommended for you

  • UXUY Completes $7 Million Pre-A Round of Financing, with Investments from Binance Labs, Bitcoin Magazine, and Other Institutions

    UXUY, the next-generation decentralized multi-chain trading platform incubated by Binance Labs, announced the completion of a $7 million Pre-A round of financing. Since its establishment, its total financing amount has exceeded $10 million. UXUY is an important builder of the Bitcoin ecosystem, and more than 100,000 traders use Bitcoin Lightning Network services through UXUY. UXUY's current round of financing has received investment from well-known institutions in Asia, North America, and Europe, such as Binance Labs, UTXO Management (Bitcoin Magazine), JDI Ventures, Bixin Ventures, SWC Global, Matrix Partners, CMS Holdings, Dewhales Capital, Comma3 Ventures, Satoshi Labs, YBB Capital, GBV Capital, Web3Vision, Pentos Ventures, NGC Ventures, Alti5, Metalpha, and GSR. The funds raised by UXUY in this round will be used for the construction of the Bitcoin ecosystem infrastructure, and will be committed to promoting the efficient and low-cost trading of Lightning Network Taproot Assets, Ordinals BRC-20, Runes, and other assets. Jordan, co-founder of UXUY, said: "We are pleased to be strategic partners with all investors! This year, we have successfully built a bridge between the Bitcoin Lightning Network and the multi-chain ecosystem. UXUY will continue to promote the use cases and popularization of the Lightning Network in trading scenarios, and make more contributions to the Bitcoin ecosystem." According to RootData, a Web3 asset data platform, UXUY is a next-generation decentralized multi-chain trading platform based on MPC wallets. UXUY actively participates in the construction of the Bitcoin Layer2 ecosystem, fully integrates into the Bitcoin Lightning Network and Taproot ecosystem, provides Lightning Address DID services to users, and becomes an important bridge connecting the Bitcoin and Ethereum ecosystems. As a decentralized multi-chain trading platform, UXUY provides immediate cross-chain trading services for Coin, Token, and Inscription among public chains through the establishment of uPool.

  • Taiwan's administrative agency passed four new anti-fraud laws to bring cryptocurrency traders under control

    It was announced that Taiwan's administrative management agency has passed the "New Anti-Fraud Law" to regulate cryptocurrency traders. In the future, businesses or individuals providing virtual asset services or third-party payment services must complete anti-money laundering measures and register their services or log in. Failure to do so may result in a maximum of 2 years in prison or a fine of up to NT$5 million. Businesses or individuals outside of Taiwan providing virtual asset or third-party payment services must register their companies or branches according to company law and complete anti-money laundering measures and service registration or login. Otherwise, they are not allowed to provide virtual asset services or third-party payment services in Taiwan. Qiu Shuzhen, the deputy chairman of Taiwan's financial regulatory agency, stated that there are currently around 60 to 70 cryptocurrency traders in the market, of which 25 have passed the anti-money laundering review by the financial regulatory agency. In the future, all traders will be required to declare and undergo review, and a cryptocurrency traders' association will be established for legal, administrative, and association management. Accounting professionals will also be enlisted to assist with internal control.

  • EigenLayer TVL falls back to $14.794 billion

    According to DefiLlama data, the total value locked (TVL) in Ethereum's re-staking protocol EigenLayer has fallen below $15 billion, currently at $14.794 billion.

  • The EU is considering including cryptocurrencies in the 12 trillion euro investment market, and its impact may far exceed that of US ETFs

    The European Securities and Markets Authority (ESMA) is consulting with the investment product advisory industry and experts on whether cryptocurrency assets should be included. This move could open up a broader market for cryptocurrencies, far exceeding the market size of spot Bitcoin ETFs. The plan aims to expand the scope of UCITS (EU Transferable Securities Collective Investment Scheme), with the UCITS market reaching as high as €12 trillion. If successful, this would be a key step in mainstreaming cryptocurrency assets in Europe.

  • SlowMist: The hacker who stole 1,155 WBTC may be from Hong Kong

    According to SlowMist analysis , the IP address associated with the theft of 1155 WBTC has been traced to Hong Kong (VPN use cannot be ruled out). Earlier reports indicated that a certain address was suspected to be a victim of phishing attacks and lost 1155 WBTC, worth 71 million USD. Subsequently, the fraudsters sold all 1155 WBTC and exchanged them for 22960 ETH, and used a large number of wallet addresses to send and launder the funds.

  • Web3 game developer Seeds Labs completes $12 million seed round of financing, with participation from Solana Foundation and others

    According to Cointelegraph, Web3 game developer Seeds Labs has announced the completion of a $12 million seed round financing, with participation from Avalanche's Blizzard Fund, Solana Foundation, Krust, Hashkey Capital, UOB Ventures, Signum Capital, IVC, and Emoote.It is reported that Seeds Labs, a Solana ecosystem game infrastructure developer, was established in 2021, and its Web3 game Bladerite is scheduled to be released this month.

  • The total subscription volume of Hong Kong Bitcoin ETF yesterday was 101.6, and the Ethereum ETF showed net redemption for two consecutive days

    The Hong Kong Bitcoin spot ETF had a net purchase of 101.6 bitcoins and a total holding of 4350 bitcoins on May 8th. The daily trading volume was 2.67 million US dollars, and the total net assets were 270 million US dollars. The daily BTC purchase came from Bosera HashKey and Huaxia Bitcoin ETF.

  • Trump announces he will accept cryptocurrency donations for his presidential campaign

    Donald Trump announced that he is accepting cryptocurrency as a form of donation for his presidential campaign.

  • Barcelona-based Web3 Video Games Startup GFAL Raises $3.2M in Seed Funding to Expand Team and Accelerate Production Plans

    Barcelona-based startup GFAL has secured $3.2 million in seed funding from investors including Supercell Ltd and Mitch Lasky. The company plans to use the funds to expand its team and accelerate its game production plans, which leverage AI and Web3 technology for immersive gameplay. GFAL's Elemental Raiders mobile game soft-launched in March 2023, with plans to build on this for a 2024 launch. CEO Manel Sort expressed gratitude for the investment and excitement to work with former colleagues from Digital Chocolate.

  • Wu Jiezhuang, a member of the National Committee of the Chinese People's Political Consultative Conference, suggested that Hong Kong refer to IPO to provide innovative financing models for Web3

    Wu Jiezhuang, a member of the National Committee of the Chinese People's Political Consultative Conference and a member of the Hong Kong Legislative Council, wrote an article in the Hong Kong Wen Wei Po titled "Leading the Digital Economy by Adapting to the Web3 Trend". The article pointed out that developing Web3+ has both advantages and new challenges. The Hong Kong government has taken an important step in the direction of developing Web3 and the digital economy by formulating a short- to medium-term strategic development blueprint, ensuring that policies and resources are in place, and promoting the construction of Web3+ application scenarios. Focusing on Web3, establishing an international innovation financing platform can not only help Hong Kong leverage its traditional financial advantages, but also help it become a global digital technology center. It is suggested to refer to the mature mode of existing enterprises' IPOs in Hong Kong, provide an innovative financing model for Web3, and create a market trend and service competitive advantage to promote the development of the industry and attract upstream and downstream of the industry chain at home and abroad to gather in Hong Kong.