BNB Smart Chain

Build web3 dApps effortlessly

BNB 信標鏈

Sunset soon

BNB Chain 生態系的質押與治理層

文件GitHubFaucetStake BNBBscScanBSCTraceDev ToolsLearn more about Fusion文件信標鏈瀏覽器質押 BNB文件GitHubFaucet跨鏈橋GreenfieldScanDCellarDev Tools文件GitHubFaucet跨鏈橋opBNBScanDev Tools文件GitHub

開發人員


Submit dApps

BNB Smart ChainBNB GreenfieldopBNBzkBNBTrading Volume Incentive ProgramDAU Incentive ProgramTVL Incentive Program開始MVB 加速器計畫Space BMEME Innovation Program查看所有計畫

生態系

社群

聯繫我們開始建構
聯繫我們開始建構

AvengerDAO September 21st Weekly Report

2023.9.21  •  4 min read
Blog post image.

Disclaimer: The information provided through the BNB Chain community does not constitute advice or recommendation for investment or trading. Projects are listed in no particular order below. BNB Chain does not take responsibility for any of your investment decisions. Please seek professional advice before taking financial risks.

AvengerDAO is a community-driven initiative created to protect the users and projects on BNB Chain from malicious actors and activity. AvengerDAO publishes a list of risk projects and addresses on DappBay Red Alarm every Friday. By actively identifying and flagging such items through DappBay’s Red Alarm, AvengerDAO can help users identify high-risk BNB Chain dApps with the level of risk, the risk description, and other important risk details. Web3 users can safely navigate BNB Chain dApps while staying safe.

Security Incidents

HashDit is an industry-leading blockchain security company that focuses on building a safe ecosystem for both protocol users and smart contract developers on BNB Chain. HashDit is member of AvengerDAO. HashDit’s analysis shows that there were 11 security incidents that happened in the week of September 12th.

Attack Vector

Protocol / Contract Name

Loss

Hot wallet compromised

@coinexcom's hot wallets

6,200,000

Rugpull

BananaGun

114,000

Price Manipulation

OxODexPool

61,000

Reserves Manipulation

BFCToken

38,000

Rugpull

NESE

30,000

Rugpull

$LMO token

20,000

Rugpull

$NOAH token

20,000

Rugpull

$PYME token

5,000

Rugpull

Fake NEXT

1,000

Rugpull

Fake OrionX

1,000

Reserves Manipulation

Fake PATEX

304

Lessons Learned

In the past week, we have seen 2 cases of Hot Wallets getting compromised, namely the @Stake and @CoinEx incidents. This is a growing security trend as scammers are utilizing more complex social engineering methods which have proven to be successful against corporations.

As such, in general, we recommend self-custody and ensuring funds are kept in a decentralized wallet, like using TrustWallet.

This ensures that as long as you maintain proper security measures and wallet hygiene, your funds will always be safe.

Red Alarm Weekly Highlights

AvengerDAO publishes a list of risk projects and addresses on DappBay Red Alarm every Friday. If you have questions or feedback for below risk highlights, please contact here.

Newly Detected High-Risk dApp Projects

Category

Description

Spotted Project This Week

Ponzi or potential Ponzi dApps

Ponzi schemes lure investors with the false promise of extremely high returns.

Phishing dApps

Phishing usually forges legitimate web pages to trick you into entering your private keys or authorizing transactions that you don't understand. 

Newly Detected High-Risk Address

AvengerDAO members offer APIs to check the security of a contract to be interacted with or get relevant information such as potential risks of a specific address to perform due diligence. AvengerDAO API gives a comprehensive evaluation of each address. We advise you to regularly check with these APIs when receiving an airdrop for a certain token, or interacting with the contracts that they want to invest in. https://dappbay.bnbchain.org/risk-scanner is integrated with these APIs. Please have a try!

The latest high-risk addresses detected from Weekly Scan.

No.

BSCScan Link 

WAT

1

https://bscscan.com/address/0x2eeff21c71ae38f9c34496cd9250c0d186dcd988

130902

2

https://bscscan.com/address/0x45c36b3ee5f6c9b4b494515b21a59b8b78336536

94739

3

https://bscscan.com/address/0xfa500178de024bf43cfa69b7e636a28ab68f2741

66301

4

https://bscscan.com/address/0xc198c3b7b970cbac315614cf27a1b7eb332048d6

63312

5

https://bscscan.com/address/0xffe811714ab35360b67ee195ace7c10d93f89d8c

55662

6

https://bscscan.com/address/0x98f39d0f8c67885071cc99c5af1d4cacbcc89b0c

54965

7

https://bscscan.com/address/0xdc35505fbf46605f61014b9b2ac96826c47017d5

52697

8

https://bscscan.com/address/0x346668d355f22aaddda10eef35f9ba86ec558652

51785

9

https://bscscan.com/address/0x2d1cfbb3468f78f916cca25f050d44b6115392e0

48798

10

https://bscscan.com/address/0xe01806f66abcd460a7eb38ec723cc644c3e5833c

46057

All the addresses are listed here.

Stay Safe - DYOR (Do Your Own Research)

BNBChain community has published detailed guides for crypto users to identify scam projects. Here are some tips:

  • Do not rely solely on social media channels and forums for information. You should search for a new project on Red Alarm before interacting.
  • A thorough DYOR process includes studying the project’s whitepaper, checking its codebase, engaging with its community, and assessing its market potential.
  • Use reliable tools and sources to aid your research, such as CoinGecko, CoinMarketCap, Etherscan, reputable news outlets, project websites and blogs, and academic articles.
  • Protecting your investment from scammers is as important as identifying the next lucrative crypto project. Always err on the side of caution when in doubt.

About AvengerDAO

AvengerDAO is a community driven initiative that protects users from possible exploits, scams and malicious actors on BNB Chain. The founding members of AvengerDAO started this because BNB Chain is the largest public chain today, and the larger the community, the greater the responsibility. Our goal is to protect users from financial losses and malicious contracts. Deter malicious actors and notify BNB Chain’s users. We aim to enhance further adoption by setting an industry standard for safe practices and raise awareness on safety and security in the ecosystem.

Share