‹ BackNewsBlockSec

BlockSec

BlockSec
2026-09-22 03:02:12

BlockSec hosts Hong Kong closed-door forum on security and compliance in crypto institutionalization

BlockSec held its Harbouring Trust closed-door seminar in Hong Kong on Sept. 16, with support from East Asia, Jumio and TiDB, bringing together about 50 decision-makers and business leads from exchanges, wallets, payment and stablecoin firms, licensed traditional financial institutions, public blockchain teams and professional service providers. The event focused on how security frameworks, compliance boundaries and business execution are changing as crypto becomes more institutionalized. Opening remarks from Michele Fung, a board member of the Fintech Association of Hong Kong and APAC lead at Unlimit, framed security and compliance as an ongoing system spanning law, technology and accountability rather than a static checklist. In the keynote, BlockSec co-founder and Chinese University of Hong Kong associate professor Zhou Yajin said institutionalization is reshaping market structure and changing the nature of risk, with AI improving attack efficiency and multi-hop transfers making traditional one-hop AML screening easier to evade. The program also included survey findings from 41 pre-event questionnaires and two panel discussions covering compliance decision-making, talent shortages, supply-chain risk, multisig signing visibility, AI-assisted red teaming, wallet payment controls, RWA product expansion and how traditional financial institutions can enter the sector through third-party service providers.

450
BlockSec hosts Hong Kong closed-door forum on security and compliance in crypto institutionalization
BlockSec Phalcon says Ethereum attack spree hit multiple projects for over $2.1 million
MEV Bot Yoink Front-Runs $7.81 Million rsETH Exploit Targeting Safe Wallet on Ethereum
Gate
2026-09-14 10:15:04

Gate and BlockSec map out social-engineering threats, account takeovers and exchange-side defenses

Gate and blockchain security firm BlockSec used the first installment of Gate Security Classroom to break down one of crypto’s most common loss vectors: social engineering. The discussion focused on account theft, phishing, identity impersonation and insider-style abuse, arguing that attackers often do not need to break blockchains, smart contracts or cryptography. Instead, they exploit trust, hijack communication channels, or pressure victims into signing transactions, changing payment addresses, installing malware or sending funds. BlockSec co-founder and Chinese University of Hong Kong associate professor Zhou Yajin outlined common attack paths, including social-media account takeovers, SIM-swap-driven Telegram fraud, long-term relationship building before fake investment pitches, and malware delivered through Web3 job interviews or business outreach. Gate’s security team said these patterns closely match what it sees in support tickets and investigations, adding that high-frequency cases often involve ordinary users rather than headline-making celebrity hacks. The piece also details practical defenses: cross-channel verification for token announcements and payment changes, strict separation between account identity and message authenticity, 24- to 48-hour cooling-off periods for new withdrawal addresses, anti-phishing codes, Passkey support, Gate Ukey, dynamic withdrawal checks, security-score guidance, and faster incident reporting for fund tracing and law-enforcement coordination. Both sides stressed the same point: once an attacker controls a trusted channel, users should stop responding inside that channel and verify through an independent one.

540
Gate and BlockSec map out social-engineering threats, account takeovers and exchange-side defenses
BlockSec Phalcon launches blockchain penetration testing service
BlockSec to host Hong Kong closed-door session on crypto security and compliance on Sept. 16
Phalcon says Cosmos EVM quietly patched a critical bug, with some chains possibly left uninformed
Hong Kong dol
2026-08-14 14:00:00

Hong Kong dollar stablecoin race opens with HKDAP and HSBC taking opposite routes

Hong Kong’s licensed stablecoin market has entered its opening phase, but the contest over distribution and user access is still wide open. On Aug. 12, Anchorpoint Financial, led by Standard Chartered, began the institutional-phase issuance of HKDAP, a Hong Kong dollar stablecoin pegged 1:1 to HKD. HashKey Exchange and OSL Group were named as the first distributors, and HashKey completed the first HKDAP mint and redemption transaction. HSBC, which received a license on the same day as Anchorpoint in April, has chosen a very different path by integrating its stablecoin offering into PayMe and the HSBC HK App, aiming at direct retail reach in the second half of the year. HKDAP is positioned as a non-interest-bearing payment and settlement instrument backed by 100% reserves of high-quality, highly liquid assets held in segregated trust accounts. At the same time, a Aug. 14 review by blockchain security firm BlockSec raised questions about the quality of HKDAP’s Ethereum mainnet contracts, citing flaws in KYC revocation logic, concentration of high-risk permissions under a single key in some cases, no timelock in the governance engine, and overlap between execution and audit roles. Those findings did not allege losses, attacks, or reserve problems, but they introduced a new variable into the market: whether the underlying smart-contract infrastructure can keep up with regulatory and security scrutiny as distribution expands.

700
Hong Kong dollar stablecoin race opens with HKDAP and HSBC taking opposite routes