Blockchain Security Firm BlockSec Closes 50 Million Yuan Angel+ Round | Led by Oasis Capital

Blockchain architecture security specialist **BlockSec** recently completed its angel+ funding round. The round was **led by Oasis Capital**, with follow-on investments from Matrix Partners China, Mirana Ventures (Bybit's investment arm), CoinSummer, and YM Capital, raising nearly RMB 50 million. **Dr. Yajin Zhou, co-founder of BlockSec**

BlockSec, a company focused on blockchain architecture security, recently completed its angel+ funding round. The round was led by Oasis Capital, with participation from Matrix Partners China, Mirana Ventures (Bybit's investment arm), CoinSummer, and YM Capital, raising nearly RMB 50 million. Dr. Yajin Zhou, co-founder of BlockSec, said: "Oasis Capital balances taste, passion, and rationality. They have unique insights and judgment about investment targets — they're not spray-and-pray investors. They're genuinely passionate about the directions and sectors they invest in, not just chasing hot trends. They communicate for mutual benefit, reaching win-win outcomes through thorough exchange with teams. At the same time, they've keenly grasped future industry trends, and their advice on development strategy and direction has been illuminating for our team. They also anticipated the current industry winter early on, and reminded us to prepare accordingly."

An investment principal at Oasis Capital said: "The information security challenges brought by digital penetration, new technology iteration, and system complexity have given rise to a new generation of security service providers. BlockSec's solid research background and insight into industry and market demands offer a unique perspective and solution for the next generation of internet security architecture. Oasis looks forward to working with BlockSec, which has a global vision, to pioneer new territories in enterprise data and personal digital asset security."

From an industry perspective, like traditional banking, the basic unit of the blockchain world is also individual accounts with different balances, and users can manually transfer funds between accounts. With the proliferation of new blockchain technologies like ETH, smart contracts — which automate transfers by executing open-source code — have also gained widespread attention from developers and users. Smart contracts have decentralized characteristics, making them more trustworthy to some users. For example, for a shared public account among three people, a smart contract can stipulate that at least two of the three must sign off to transfer funds out, and this signature verification step is executed automatically through running code without relying on a third party like a bank. But on the other hand, the security of smart contracts themselves demands serious attention from developers. Because smart contracts are open-source, hackers can also see the code, and if there are vulnerabilities, hackers will exploit them for profit. Therefore, blockchain security companies focused on this area have emerged accordingly.

BlockSec is precisely a blockchain security company, with its current business primarily centered on smart contract security. Speaking about smart contract security, BlockSec co-founder Yajin Zhou explained that using the deployment time of smart contracts on-chain as a dividing point, BlockSec provides code audit services before deployment, and after deployment, conducts real-time monitoring of blockchain data. Once an attack is detected, corresponding attack blocking and loss recovery actions are taken.

For smart contract code audits, Zhou introduced that there are currently different approaches in the industry to achieve this goal. One method is formal verification, which pre-defines security rules and then proves that the client's code complies with these rules, thereby avoiding security vulnerabilities that violate these rules. However, BlockSec found that many security vulnerabilities are related to the specific business scenarios of smart contracts, and merely ensuring code correctness does not guarantee the overall security of the smart contract. Therefore, in practice, BlockSec conducts code audits with an "attacker's mindset," using techniques including fuzzing. In implementation, due to the differences between DeFi and traditional security, BlockSec provides unique technology in areas such as automated understanding of DeFi semantics to ensure the precision of fuzzing.

After code audit, clients typically make multiple rounds of code revisions and re-audits based on BlockSec's recommendations. Once security standards are met, the smart contract is deployed to the blockchain. At this point, the smart contract code becomes visible to everyone and is executed by users. Simultaneously, BlockSec monitors pending transactions. If a suspected hacker attack transaction is discovered, attack blocking is initiated. BlockSec then requests the blockchain to execute a hedging transaction, transferring the balance from the smart contract address to another secure address to prevent hackers from stealing funds. For clients, this becomes a race against time — if the hacker's transaction is executed first, the funds may become the hacker's property. BlockSec employs corresponding technical measures, on one hand detecting attack behavior as early as possible, and on the other hand accelerating the execution speed of hedging transactions, to ensure client fund security.

In the worst-case scenario where user funds have already been transferred to hackers, BlockSec's loss recovery service analyzes on-chain data to trace the hacker's fund chain. If hacker funds flow to exchanges, BlockSec rapidly negotiates with police and the relevant exchange platforms, provides evidence, and works to freeze hacker funds to recover losses. The company stated that BlockSec's attack blocking system has successfully blocked several hacker attacks. For example, when Saddle Finance previously suffered a hacker attack, BlockSec issued warnings and successfully blocked the attack. To date, BlockSec has recovered over $5 million in assets for multiple project parties including Saddle and HomeDao.

Regarding pricing models, Zhou stated that code audit fees are typically charged per project based on size. For the data monitoring portion after smart contract deployment, a subscription model is used, such as annual fees. For loss recovery services, in addition to the subscription model, fees are also charged as a percentage of recovered amounts.

BlockSec has been profitable since its founding. On market prospects and growth speed, Zhou noted that smart contracts remain in a stage of rapid development, with both the number and volume of smart contracts continuing to grow, thus increasing demand for audit services. Throughout the entire lifecycle of smart contracts, there will be multiple modifications and upgrades, requiring multiple audits. Additionally, some project parties invite multiple audit companies to audit the same code to maximize security assurance.

Companies currently focused on smart contract security auditing and blockchain security services include CertiK, among others. Data monitoring and loss recovery services will also become more challenging and more market-promising as transaction numbers and volumes increase. A DappRadar report stated that in Q1 2022, the number of active blockchain decentralized application (Dapp) addresses reached 2.38 million, while the amount of stolen funds in that quarter reached $1.2 billion. This demonstrates Dapps' genuine need for security.

On the team side, BlockSec's two co-founders — Dr. Yajin Zhou and Dr. Lei Wu — both received their PhDs from North Carolina State University in the United States, and are currently a professor and associate professor at Zhejiang University, respectively. The two have conducted academic research in blockchain security for many years since 2018. Additionally, both previously served as senior security researchers at Qihoo 360. Overall, BlockSec's team members come not only from computer science but also include experts with backgrounds in finance, mathematics, and other fields. They conduct manual analysis for specific business scenarios, and their research backgrounds allow them to keep pace with cutting-edge industry developments while also providing more comprehensive security services for clients both on-chain and off-chain from financial, mathematical, and other perspectives.

Speaking about the company's next steps after this funding round, Zhou mentioned that the team is currently in continuous expansion. Presently, BlockSec values candidates' curiosity about emerging things and practical development experience with blockchain or security products. Technically, they hope candidates have some background in security or blockchain. In the future, the company also plans to expand its business, converting new security technologies into products for clients and providing security infrastructure for blockchain.

Source: 36kr, author Ray, editor Zhen Zi


Vitality

What do you think vitality is?

We believe the track we've chosen has unlimited potential and will trigger fundamental and structural changes in related fields including finance. It's a direction with vitality, with promising future prospects.

Whether for an industry or a company, growth will inevitably involve highs and lows. But regardless, once the direction is set, one must have the courage to overcome difficulties and unwavering conviction, building a team with vitality and continuing to grow.

— Dr. Yajin Zhou, Co-founder of BlockSec

Oasis Capital is a new-generation venture capital firm in China, dedicated to discovering the most vital entrepreneurs of the next decade and growing alongside them to create long-term value. "Vitality" is Oasis's vision and mission. This vitality is both the direction of structural transformation of the era and the resilience and evolutionary power of entrepreneurs.

Oasis Capital focuses on early and growth-stage investments, with individual investments ranging from $3 million to $30 million, concentrating on technology-enabled services in healthcare, enterprise services, and other sectors, supporting China's technology-driven new service upgrade.