|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Independent Security Evaluators (ISE) による最近の調査により、未知の組織が脆弱な秘密キーを悪用して相当量の ETH を蓄積していることが明らかになりました。 「イーサコーミング」として知られる方法を通じて、この組織は600万ドル以上相当の約45,000 ETHを集めました。この研究は、秘密鍵を扱うシステムが標的型攻撃に対して脆弱であることを示唆しており、暗号資産を保護するための堅牢なセキュリティ対策の必要性を浮き彫りにしています。

Blockchain Bandit Exploits Weak Crypto Keys, Amassing Millions in Ethereum
ブロックチェーン強盗が弱い暗号鍵を悪用し、イーサリアムに数百万ドルを蓄積
In a groundbreaking study released on Tuesday by Independent Security Evaluators (ISE), a renowned security consulting firm, a nefarious entity has been identified as exploiting vulnerabilities in private keys to siphon tens of thousands of Ethereum (ETH) coins.
有名なセキュリティコンサルティング会社であるIndependent Security Evaluators(ISE)が火曜日に発表した画期的な調査では、極悪非道な組織が秘密鍵の脆弱性を悪用して数万枚のイーサリアム(ETH)コインを吸い上げていることが判明した。
Dubbed the "blockchainbandit," this clandestine actor has seized control of approximately 44,744 ETH, valuing roughly $6.1 million currently, from unsuspecting cryptocurrency holders. The study, titled "Ethercombing: Finding Secrets in Popular Places," delves into the intricate methods employed by the blockchainbandit to compromise weak private keys.
「ブロックチェーンバンディット」と呼ばれるこの秘密の攻撃者は、疑うことを知らない仮想通貨保有者から、約44,744 ETH(現在約610万ドル相当)の管理を掌握しました。 「Ethercombing: Finding Secrets in Popular Places」と題されたこの研究は、ブロックチェーンバンディットが弱い秘密鍵を侵害するために使用する複雑な手法を詳しく調査しています。
Private keys serve as the gatekeepers to cryptocurrency wallets, allowing users to authorize transactions. However, these keys can be vulnerable to compromise if generated using flawed code or random number generators. ISE's investigation focused on uncovering such compromised keys, leading to the discovery of 732 weak private keys responsible for over 49,000 ETH transactions.
秘密キーは暗号通貨ウォレットのゲートキーパーとして機能し、ユーザーがトランザクションを承認できるようにします。ただし、これらのキーは、欠陥のあるコードまたは乱数ジェネレーターを使用して生成された場合、侵害に対して脆弱になる可能性があります。 ISE の調査は、そのような侵害されたキーの発見に重点を置き、49,000 を超える ETH トランザクションに関与する 732 個の弱い秘密キーの発見につながりました。
"We aimed to identify keys that may have been generated using faulty code or random number generators," explained Adrian Bednarek, a researcher and analyst at ISE. "Our findings reveal that these keys are readily exploitable, and the blockchainbandit has taken advantage of this vulnerability."
「私たちの目的は、欠陥のあるコードまたは乱数生成器を使用して生成された可能性のあるキーを特定することです」と ISE の研究者兼アナリストである Adrian Bednarek 氏は説明します。 「私たちの調査結果では、これらのキーは容易に悪用可能であり、ブロックチェーン強盗がこの脆弱性を利用していることが明らかになりました。」
The study further unearthed 13,319 ETH transferred to either invalid destination addresses or wallets derived from weak keys. At the peak of the Ethereum market, these compromised funds had a combined value exceeding $18 million.
この調査では、無効な宛先アドレスまたは弱いキーに由来するウォレットに転送された 13,319 個の ETH がさらに発見されました。イーサリアム市場のピーク時には、これらの侵害された資金の価値は合計で 1,800 万ドルを超えていました。
Bednarek suspects the blockchainbandit employs automated processes to scour the blockchain for new wallets and identify vulnerable keys. "This individual or group is highly sophisticated, dedicating significant computing resources to sniffing out new wallets and testing them for weak keys," he said.
ベドナレク氏は、ブロックチェーン強盗が自動プロセスを利用してブロックチェーン内で新しいウォレットを探し、脆弱なキーを特定しているのではないかと疑っている。同氏は、「この個人またはグループは非常に洗練されており、新しいウォレットを嗅ぎ分けて脆弱なキーをテストするために大量のコンピューティングリソースを費やしている」と述べた。
ISE's report emphasizes the heightened threat posed by such targeted attacks, particularly for systems handling private keys. "It is evident that any system interacting with valuable private keys is vulnerable to exploitation," the report warns.
ISE のレポートでは、特に秘密鍵を扱うシステムに対して、このような標的型攻撃によってもたらされる脅威の増大を強調しています。 「貴重な秘密鍵を扱うシステムは、悪用に対して脆弱であることは明らかです」と報告書は警告している。
To mitigate these risks, developers are urged to implement robust defense mechanisms and explore innovative measures to counter evolving threats. "Software designers should prioritize incorporating all available defense principles to protect against present and future threats," the report concludes.
これらのリスクを軽減するために、開発者は堅牢な防御メカニズムを実装し、進化する脅威に対抗するための革新的な対策を検討することが求められています。 「ソフトウェア設計者は、現在および将来の脅威から保護するために、利用可能なすべての防御原則を優先的に組み込む必要がある」と報告書は結論づけています。
The blockchainbandit's exploits serve as a stark reminder of the importance of safeguarding private keys. Cryptocurrency users are advised to exercise extreme caution when generating and storing their private keys, employing strong security measures to prevent unauthorized access.
Blockchainbandit の悪用は、秘密鍵を保護することの重要性をはっきりと思い出させるものとして機能します。暗号通貨のユーザーは、秘密鍵を生成および保管する際に細心の注意を払い、不正アクセスを防ぐための強力なセキュリティ対策を講じることをお勧めします。
免責事項:info@kdj.com
提供される情報は取引に関するアドバイスではありません。 kdj.com は、この記事で提供される情報に基づいて行われた投資に対して一切の責任を負いません。暗号通貨は変動性が高いため、十分な調査を行った上で慎重に投資することを強くお勧めします。
このウェブサイトで使用されているコンテンツが著作権を侵害していると思われる場合は、直ちに当社 (info@kdj.com) までご連絡ください。速やかに削除させていただきます。

































