時価総額: $2.2026T 0.80%
ボリューム(24時間): $38.3583B -35.30%
  • 時価総額: $2.2026T 0.80%
  • ボリューム(24時間): $38.3583B -35.30%
  • 恐怖と貪欲の指数:
  • 時価総額: $2.2026T 0.80%
暗号
トピック
暗号化
ニュース
暗号造園
動画
トップニュース
暗号
トピック
暗号化
ニュース
暗号造園
動画
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

暗号通貨のニュース記事

コンバージェンスプロトコルは、8月1日にスマートコントラクトエクスプロイトを介してハッキングされたことを確認し、ハッカーがネイティブトークンで2億1000万ドルを鋳造して販売した

2024/08/02 12:02

仮想通貨エコシステムは7月のハッキングにより約2億6,600万ドルを失い、そのほとんどはインドの取引プラットフォームWazirXの2億3,000万ドルのハッキングによるものでした。

コンバージェンスプロトコルは、8月1日にスマートコントラクトエクスプロイトを介してハッキングされたことを確認し、ハッカーがネイティブトークンで2億1000万ドルを鋳造して販売した

Decentralized finance (DeFi) protocol Convergence has confirmed that it was exploited via a smart contract vulnerability on Aug. 1, allowing a hacker to mint and sell $210,000,000 in its native token, as well as pilfer $2,000 in unclaimed staking rewards.

分散型金融(DeFi)プロトコルのコンバージェンスは、8月1日にスマートコントラクトの脆弱性を介して悪用され、ハッカーがネイティブトークンで2億1000万ドルを鋳造して販売し、請求されていないステーキング報酬として2000ドルを盗むことを可能にしたことを確認した。

According to a new post-mortem from Wireshark, the pseudonymous founder of the Convergence protocol, the attacker exploited the protocol’s CvxRewardDistributor contract, enabling them to mint and sell 58,000,000 CVG tokens for roughly $210,000.

Convergence プロトコルの仮名創設者である Wireshark の新たな事後分析によると、攻撃者はプロトコルの CvxRewardDistributor コントラクトを悪用し、5,800 万 CVG トークンを約 21 万ドルで鋳造して販売することができました。

The attacker also stole about $2,000 in unclaimed rewards from Convex, a DeFi protocol designed to maximize rewards for Curve liquidity providers.

攻撃者はまた、Curve流動性プロバイダーの報酬を最大化するように設計されたDeFiプロトコルであるConvexから、請求されていない報酬約2,000ドルを盗みました。

According to Etherscan, the attack occurred on Aug. 1 at around 3:00 am UTC.

Etherscan によると、攻撃は 8 月 1 日午前 3 時頃(協定世界時)に発生しました。

Blockchain security firm PeckShield noted that after minting the CVG tokens, the attacker quickly swapped it into 60 wrapped-Ether and 15,900 Curve.fi FRAX.

ブロックチェーンセキュリティ会社PeckShieldは、CVGトークンを鋳造した後、攻撃者がそれをすぐに60個のラップイーサと15,900個のCurve.fi FRAXに交換したと指摘した。

The movements have since led to a near-100% price wipeout of the CVG governance token, which is now trading at $0.0004 with a market cap of just $57,000, according to CoinMarketCap data.

その後、この動きによりCVGガバナンストークンの価格はほぼ100%下落し、CoinMarketCapのデータによると、CVGガバナンストークンは現在0.0004ドルで取引されており、時価総額はわずか57,000ドルとなっている。

Convergence said the attack was enabled by the team accidentally deleting a crucial line of code in its smart contract that distributes CVG staking rewards. They made the change after the smart contract code was audited four times.

Convergenceは、チームがCVGステーキング報酬を分配するスマートコントラクト内の重要なコード行を誤って削除したことによって攻撃が可能になったと述べた。彼らは、スマート コントラクト コードが 4 回監査された後に変更を加えました。

“The modification (gas-optimization on the first hand) led us to remove the line of code that was checking the input given to the function,” it explained.

「この変更(最初のガス最適化)により、関数に与えられた入力をチェックしていたコード行を削除することになりました」と説明されています。

The attacker used this to exploit the CvxRewardDistributor contract through the claimMultipleStaking function.

攻撃者はこれを利用して、claimMultipleStakeing 関数を通じて CvxRewardDistributor コントラクトを悪用しました。

This meant the staking contract couldn’t be validated, allowing the attacker to pass a separate malicious contract with the same signature as the claimCvgCvxMultiple function.

これは、ステーキング コントラクトを検証できないことを意味し、攻撃者がclaimCvgCvxMultiple 関数と同じ署名を持つ別の悪意のあるコントラクトを渡すことが可能になりました。

The attacker then minted all tokens dedicated to staking emissions and then dumped them into CVG liquidity pools, Convergence said.

その後、攻撃者は排出権ステーキング専用のすべてのトークンを鋳造し、それらをCVGの流動性プールに投入したとコンバージェンスは述べた。

Related: Over 70% of hacked funds are lost to CeFi entities — Cyvers

関連: ハッキングされた資金の 70% 以上が CeFi 団体に失われる — Cyvers

Convergence says that user funds are safe, but has advised users to withdraw assets from the platform.

コンバージェンスはユーザーの資金は安全だとしているが、プラットフォームから資産を引き出すようユーザーに勧告している。

“Due to the exploit, the rewards contract for the Stake DAO integration is currently broken. It will be fixed, and stakers will be able to claim their rewards once it’s done. No rewards are lost for Stake DAO integration users,” it said.

「エクスプロイトにより、ステーク DAO 統合の報酬契約は現在破棄されています。それは修正され、ステーカーは修正が完了すると報酬を請求できるようになります。 Stake DAO 統合ユーザーの報酬が失われることはありません」と述べています。

Convergence works to aggregate liquidity, boost returns and enable liquid locking across the Curve Finance ecosystem.

Convergence は、流動性を集約し、収益を向上させ、Curve Finance エコシステム全体での流動性ロックを可能にするために機能します。

The total value locked on Convergence fell from $5.79 million to $3.69 million, DefiLlama data shows.

DefiLlamaのデータによると、Convergenceにロックされた総額は579万ドルから369万ドルに減少した。

The cryptocurrency ecosystem lost around $266 million to hacks in July, largely due to the $230 million hack of Indian trading platform WazirX on July 18.

仮想通貨エコシステムは、7月のハッキングにより約2億6,600万ドルを失いましたが、その主な原因は、7月18日にインドの取引プラットフォームWazirXが2億3,000万ドルに上ったハッキン​​グによるものです。

Magazine: THORChain founder and his plan to ‘vampire attack’ all of DeFi

マガジン: THORChain創設者とDeFi全体を「吸血鬼攻撃」する彼の計画

オリジナルソース:cointelegraph

免責事項:info@kdj.com

提供される情報は取引に関するアドバイスではありません。 kdj.com は、この記事で提供される情報に基づいて行われた投資に対して一切の責任を負いません。暗号通貨は変動性が高いため、十分な調査を行った上で慎重に投資することを強くお勧めします。

このウェブサイトで使用されているコンテンツが著作権を侵害していると思われる場合は、直ちに当社 (info@kdj.com) までご連絡ください。速やかに削除させていただきます。

2026年07月27日 に掲載されたその他の記事