Sitemap

Happy 8th Anniversary to SlowMist!

13 min readJan 26, 2026

--

Since its establishment on January 26, 2018, SlowMist has spent eight years deeply rooted in the field of blockchain security. Eight years may not seem long on a timeline, but in an industry defined by rapid evolution and constant innovation, it is long enough to witness multiple cycles of rise and fall, paradigm shifts in technology, and repeated escalations of security threats. Guided by the firm belief of “bringing a sense of security to the blockchain ecosystem,” SlowMist has consistently devoted itself to security research and real-world defense with unwavering passion, demonstrating its commitment to security through action. Through repeated encounters with real attacks and incident response, we have refined our technologies, and through the accumulation of time, gradually built the unique security value that defines SlowMist.

Press enter or click to view image in full size

Looking Back

Looking back over the past year, we continued to devote our energy to work that may not always be visible, but has always been essential.

Throughout the year, we consistently produced in-depth technical content focused on real-world attacks, scams, and systemic risks. For example:

Whether examining major security incidents, everyday threats faced by ordinary users, or risks rooted in underlying technologies, we have consistently sought to break down complex attack chains and clarify the critical details. Our goal is to help more people truly understand how risks emerge — rather than encountering them only after the fact as a cold loss figure — and to gradually transform “post-incident analysis” into “pre-incident awareness.”

As the boundaries of security continue to expand, we have also become increasingly aware that security issues no longer exist solely within code. Over the past year, we have continued to closely track topics related to regulation, sanctions, and anti-money laundering (AML/KYT), including:

We have sought to analyze how black- and gray-market operations, sanction networks, and underground financial systems function using real on-chain data, and we have actively participated in discussions on compliance and security governance. For us, security is not just about “blocking attackers”; it is equally about enabling projects and organizations to operate in a compliant and stable manner over the long term.

Against the backdrop of AI technologies rapidly permeating development, trading, and security scenarios, we have also turned our attention to new uncertainties. Focusing on MCP, the AI tool ecosystem, and the security boundaries of large models, we have published multiple security checklists and defense recommendations, including:

Our focus is not on how “new” the concepts themselves are, but on how security should be proactively designed when AI truly becomes part of the infrastructure, and which risks must be identified in advance.

Beyond continuously publishing content, over the past year we have also been refining and upgrading our products and services, including:

  • 2025–03–25: SlowMist Releases Japanese Version of the “Web3 Project Security Handbook”

On September 10, 2024, SlowMist’s security team officially released the bilingual Chinese-English version of the Web3 Project Security Handbook (commonly referred to as the “Red Handbook”), systematically summarizing best practices to help global developers establish robust security rules. The handbook received widespread attention across the industry.

With the rapid growth of the Web3 market in Japan, our friend @JackJia2021 graciously supported and completed the Japanese translation, ensuring accurate communication of the handbook’s content. The SlowMist security team would like to sincerely thank Jack for his effort and contribution.

The release of the Japanese version aims to help the Japanese Web3 community more effectively access professional security knowledge. Moving forward, the SlowMist security team will continue to collaborate with more high-quality partners to deliver multilingual security standards, promoting a healthy and sustainable global Web3 ecosystem.

  • 2025–04–29: Wallet Security Audit Update: Addition of MCP Wallet Security Audit Items

The SlowMist security team conducted an in-depth security study on the application of MCP in Web3 wallet management scenarios. The research found that securing Web3 MCP wallets requires not only safeguarding the key lifecycle, but also ensuring safe interactions between MCP, LLMs, clients, and hosts.

Based on these findings, we developed a set of MCP wallet security audit items. These items are designed from the perspective of MCP project teams, helping them conduct thorough security audits of MCP wallet applications, enhance overall MCP security, and enable both project teams and users to resist emerging attack techniques even during this “chaotic” phase.

  • 2025–05–12: Comprehensive Update: SlowMist’s Solana Smart Contract Security Best Practices

Since the release of the Solana Smart Contract Security Best Practices in 2021, the handbook has been widely recognized and recommended by developers and security researchers for its professionalism.

With the evolution of the Solana ecosystem and the continuous emergence of new vulnerabilities, the SlowMist security team has conducted a thorough update and supplement to the original security guide based on the latest audit practices.

The updated Solana Smart Contract Security Best Practices provides a detailed summary of common security issues and solutions in Solana smart contracts, covering aspects such as vulnerability descriptions, exploitation scenarios, and remediation recommendations. It is designed to serve as a one-stop security reference and operational guide for developers.

  • 2025–05–15: MistTrack MCP Goes Live, Ushering in a New AI Paradigm for On-Chain Tracing and Risk Analysis

MistTrack MCP (https://mcp.so/server/misttrackmcp/slowmist) is a server built on the Model Context Protocol (MCP) designed to further lower the barrier to using on-chain tracking tools while improving efficiency and accuracy. Users can directly access MistTrack’s on-chain analysis APIs in MCP-supported clients such as Claude and Cursor using natural language, enabling features like address profiling, risk scoring, and transaction graph construction for blockchain asset tracking, risk assessment, and transaction analysis.

This not only enhances the efficiency of on-chain data analysis but also lowers the entry threshold, injecting new possibilities into blockchain security analysis.

  • 2025–07–01: SlowMist, DeFiHackLabs, and Scam Sniffer Launch Web3 Phishing Simulation Platform “Unphishable”

SlowMist, in collaboration with DeFiHackLabs and Scam Sniffer, officially launched the Web3 phishing simulation platform Unphishable (https://unphishable.io/). The platform helps users learn to identify and defend against common Web3 phishing attacks by simulating social engineering, fake websites, malicious smart contracts, and other attack methods, enhancing overall security awareness.

Unphishable is freely available to all users, aiming to reduce the risk of phishing attacks and improve accessibility to security education resources.

In addition, SlowMist is about to launch its professional, real-time anti-money laundering engine for large institutional compliance teams — the SlowMist KYT Tool — focusing on deeper, more flexible risk fund screening and risk allocation capabilities.

We have also consolidated the practical experience gained over the past year into reusable, publicly accessible industry assets and research outputs, including:

We have continued to share our experience and methodologies with the industry through open-source or publicly released initiatives, aiming for these resources to serve not only immediate needs but also to be repeatedly used, validated, and refined over a longer term.

Over the past year, rather than seeking visibility, we have preferred to devote our time to scenarios that truly require assistance and collaboration, such as:

Behind these acknowledgments lie countless instances of rapid response and patient follow-up; behind every collaboration is a shared commitment to security responsibility.

At the same time, over the past year we have continued to engage in more open forums, sharing frontline security experience and insights, including:

Over the past year, we have also received recognition from the industry and the media, including:

Since its founding eight years ago, SlowMist has established five security bases worldwide, serving thousands of clients across multiple countries and regions. We have consistently adhered to a practice-driven approach, gradually building an integrated security capability system covering threat discovery, analysis, defense, and response. This system is first reflected in our long-cultivated professional service capabilities:

  • Through blockchain security audits, we systematically identify code- and architecture-level vulnerabilities for a wide range of projects, including CEXs, DEXs, DeFi, GameFi, NFTs, wallets, and public chains.
  • Through red teaming, we conduct comprehensive attack assessments from the perspective of real-world attackers, evaluating vulnerabilities in personnel, business processes, and office environments — not limited to traditional penetration testing.
  • Leveraging our MistEye-based security monitoring capabilities, we provide Web3 projects with continuous, dynamic on-chain and off-chain risk monitoring.
  • On the compliance side, our on-chain analysis–based anti-money laundering solutions help projects trace illicit fund flows and meet AML/CFT regulatory requirements.
  • When a security incident occurs, our Incident Response Service helps project teams quickly contain losses, investigate root causes, and restore systems.
  • Additionally, through security consulting services, we offer long-term guidance and improvement suggestions on technical architecture, risk management, and emergency mechanisms.

These capabilities do not exist in isolation; they are continuously validated, integrated, and evolved through long-term practical experience, gradually forming a holistic defense system that promotes the coordinated development of technical security, compliance security, and ecosystem security.

Press enter or click to view image in full size

While continuously deepening our service capabilities, we have further productized and systematized these repeatedly validated methodologies and hands-on experience, gradually forming a product portfolio centered on security and compliance.

For example, the SlowMist AML Tracking Tool is a comprehensive platform built on extensive real-world case-tracking experience. It supports address labeling queries, fund risk analysis, and visualized on-chain monitoring and tracing.

For institutional users with higher compliance requirements, we have introduced the SlowMist KYT Tool — a professional, real-time anti-money laundering engine focused on deep risk fund screening and flexible risk strategy configuration.

At the threat discovery layer, we integrate global Web3 threat intelligence and dynamic monitoring capabilities through our SlowMist Threat Intelligence Monitoring Tool, and further leverage InMist Lab to build a cross-regional, cross-organizational collaborative intelligence network.

Press enter or click to view image in full size

With the continuous introduction of AI capabilities, SlowMist is driving security capabilities toward greater automation, intelligence, and real-time responsiveness. We firmly believe that security should not be limited to one-off audits or post-incident emergency response, but should instead form a complete closed loop covering pre-incident prevention, in-incident detection, and post-incident handling.

Moving Forward

Looking back on eight years of practice and accumulation, we are steadily moving closer to what SlowMist set out to do — and must ultimately accomplish: not merely solving problems for a single project or a single incident, but becoming a long-term, reliable part of the security infrastructure of the global blockchain ecosystem.

This means maintaining a constant sense of respect for technology and risk, and upholding sound security principles amid rapid change. It also means placing real users and real needs first — creating security value that can stand the test of time through rigorous research, disciplined engineering, and sustained commitment.

For SlowMist, “Uphold justice” is the baseline, “innovate” is the capability, “Create value” is the process, and “Enjoy returns” is the most natural outcome of long-term commitment. We hope that the security capabilities we provide can be truly relied upon at critical moments, while quietly performing their role in everyday operations — continuously bringing a sense of security to the blockchain ecosystem.

The industry evolves, and attack techniques evolve, but the essence of security has never changed. Each milestone proven over time records our journey, while reminding us to remain humble and vigilant. SlowMist has always stood on the front line — striving to explain complex problems clearly, and to persist in doing what truly matters.

We extend our sincere gratitude to all the clients, partners, and friends who have walked this path with us. Going forward, we will continue to move ahead together, safeguarding the security and order of the blockchain ecosystem amid ever-changing technologies and risks, toward a future that is both longer-term and more sustainable.

Eight years together, our original intent remains unshaken. We are still on the road.

Press enter or click to view image in full size

About SlowMist

SlowMist is a threat intelligence firm focused on blockchain security, established in January 2018. The firm was started by a team with over ten years of network security experience to become a global force. Our goal is to make the blockchain ecosystem as secure as possible for everyone. We are now a renowned international blockchain security firm that has worked on various well-known projects such as HashKey Exchange, OSL, MEEX, BGE, BTCBOX, Bitget, BHEX.SG, OKX, Binance, HTX, Amber Group, Crypto.com, etc.

SlowMist offers a variety of services that include but are not limited to security audits, threat information, defense deployment, security consultants, and other security-related services. We also offer AML (Anti-money laundering) software, MistEye (Security Monitoring), SlowMist Hacked (Crypto hack archives), FireWall.x (Smart contract firewall) and other SaaS products. We have partnerships with domestic and international firms such as Akamai, BitDefender, RC², TianJi Partners, IPIP, etc. Our extensive work in cryptocurrency crime investigations has been cited by international organizations and government bodies, including the United Nations Security Council and the United Nations Office on Drugs and Crime.

By delivering a comprehensive security solution customized to individual projects, we can identify risks and prevent them from occurring. Our team was able to find and publish several high-risk blockchain security flaws. By doing so, we could spread awareness and raise the security standards in the blockchain ecosystem.

--

--

SlowMist
SlowMist

Written by SlowMist

SlowMist is a Blockchain security firm established in 2018, providing services such as security audits, security consultants, red teaming, and more.