|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
分散型金融プロトコルのコンバージェンスは、8月1日にスマートコントラクトのエクスプロイトを介してハッキングされ、ハッカーが2億1000万ドルを鋳造して売却したことを確認した

DeFi protocol Convergence has confirmed that it was hacked via a smart contract exploit on Aug. 1, with the attacker minting and selling $210 million in its native token, as well as stealing $2,000 in unclaimed staking rewards.
DeFiプロトコルConvergenceは、8月1日にスマートコントラクトのエクスプロイトを介してハッキングされ、攻撃者がネイティブトークンで2億1000万ドルを鋳造して販売し、請求されていないステーキング報酬2000ドルを盗んだことを確認した。
According to a post-mortem from Wireshark, the pseudonymous founder of the Convergence protocol, the attacker exploited the protocol’s CvxRewardDistributor contract, allowing them to mint and sell 58 million CVG tokens for approximately $210,000.
Convergence プロトコルの仮名創設者である Wireshark の事後分析によると、攻撃者はプロトコルの CvxRewardDistributor コントラクトを悪用し、5,800 万 CVG トークンを約 21 万ドルで鋳造して販売することができました。
The attacker also stole approximately $2,000 of unclaimed rewards from Convex, a DeFi protocol designed to maximize rewards for Curve liquidity providers.
攻撃者はまた、Curve流動性プロバイダーの報酬を最大化するように設計されたDeFiプロトコルであるConvexから、請求されていない報酬約2,000ドルを盗みました。
According to Etherscan, the attack occurred on Aug. 1 at around 3:00 am UTC.
Etherscan によると、攻撃は 8 月 1 日午前 3 時頃(協定世界時)に発生しました。
Blockchain security firm PeckShield noted that after minting the CVG tokens, the attacker quickly swapped it into 60 wrapped-Ether and 15,900 Curve.fi FRAX.
ブロックチェーンセキュリティ会社PeckShieldは、CVGトークンを鋳造した後、攻撃者がそれをすぐに60個のラップイーサと15,900個のCurve.fi FRAXに交換したと指摘した。
The movements have since led to a near-100% price wipeout of the CVG governance token, which is now trading at $0.0004 with a market cap of just $57,000, CoinMarketCap data shows.
CoinMarketCapのデータによれば、この動きによりCVGガバナンストークンの価格はほぼ100%下落し、現在時価総額は0.0004ドルで取引されており、その時価総額はわずか57,000ドルとなっている。
Convergence said the attack was possible because the team accidentally removed an essential line of code in its smart contract, which distributes CVG staking rewards. They made the change after the smart contract code was audited four times.
Convergenceは、チームがCVGステーキング報酬を分配するスマートコントラクト内の重要なコード行を誤って削除したために攻撃が可能になったと述べた。彼らは、スマート コントラクト コードが 4 回監査された後に変更を加えました。
“The modification (gas-optimization on the first hand) led us to remove the line of code that was checking the input given to the function,” it explained.
「この変更(最初のガス最適化)により、関数に与えられた入力をチェックしていたコード行を削除することになりました」と説明されています。
The attacker used this to exploit the CvxRewardDistributor contract through the claimMultipleStaking function.
攻撃者はこれを利用して、claimMultipleStakeing 関数を通じて CvxRewardDistributor コントラクトを悪用しました。
This meant the staking contract couldn’t be validated, allowing the attacker to pass a separate malicious contract with the same signature as the claimCvgCvxMultiple function.
これは、ステーキング コントラクトを検証できないことを意味し、攻撃者がclaimCvgCvxMultiple 関数と同じ署名を持つ別の悪意のあるコントラクトを渡すことが可能になりました。
The attacker then minted all tokens dedicated to staking emissions and then dumped them into CVG liquidity pools, Convergence said.
その後、攻撃者は排出権ステーキング専用のすべてのトークンを鋳造し、それらをCVGの流動性プールに投入したとコンバージェンスは述べた。
Convergence says that user funds are safe, but has recommended users withdraw assets from the platform.
コンバージェンスはユーザーの資金は安全だとしているが、ユーザーに対しプラットフォームから資産を引き出すことを推奨している。
“Due to the exploit, the rewards contract for the Stake DAO integration is currently broken. It will be fixed, and stakers will be able to claim their rewards once it’s done. No rewards are lost for Stake DAO integration users," it said.
「エクスプロイトにより、ステーク DAO 統合の報酬契約は現在破棄されています。それは修正され、ステーカーは修正が完了すると報酬を請求できるようになります。 Stake DAO 統合ユーザーの報酬が失われることはありません」と述べています。
Convergence works to aggregate liquidity, boost returns and enable liquid locking across the Curve Finance ecosystem.
Convergence は、流動性を集約し、収益を向上させ、Curve Finance エコシステム全体での流動性ロックを可能にするために機能します。
The total value locked on Convergence fell from $5.79 million to $3.69 million, DefiLlama data shows.
DefiLlamaのデータによると、Convergenceにロックされた総額は579万ドルから369万ドルに減少した。
The cryptocurrency ecosystem lost around $266 million to hacks in July, mostly coming from the $230 million hack of Indian trading platform WazirX on July 18.
仮想通貨エコシステムは7月にハッキングにより約2億6,600万ドルを失い、そのほとんどは7月18日にインドの取引プラットフォームWazirXに対する2億3,000万ドルのハッキングによるものでした。
免責事項:info@kdj.com
提供される情報は取引に関するアドバイスではありません。 kdj.com は、この記事で提供される情報に基づいて行われた投資に対して一切の責任を負いません。暗号通貨は変動性が高いため、十分な調査を行った上で慎重に投資することを強くお勧めします。
このウェブサイトで使用されているコンテンツが著作権を侵害していると思われる場合は、直ちに当社 (info@kdj.com) までご連絡ください。速やかに削除させていただきます。

































