|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
金曜朝、別のDeFiプロトコルが悪用の被害に遭った。 Dough Finance、非保管流動性市場を作成するためのオープンソース プロトコル

DeFi protocol Dough Finance fell victim to a flash loan attack on Friday morning, leading to the theft of nearly $2 million in user funds. The project’s team announced they are working to resolve the situation promptly.
DeFiプロトコルのDough Financeは金曜朝、フラッシュローン攻撃の被害に遭い、ユーザー資金200万ドル近くが盗まれた。プロジェクトチームは、この状況を速やかに解決するために取り組んでいると発表した。
According to Web3 blockchain security platform Cyvers, it detected multiple suspicious transactions involving Dough Finance. The attacker manipulated the protocol's smart contract and stole $1.8 million in USDC.
Web3 ブロックチェーン セキュリティ プラットフォームの Cyvers によると、Dough Finance に関連する複数の不審な取引が検出されました。攻撃者はプロトコルのスマートコントラクトを操作し、USDC の 180 万ドルを盗みました。
The attacker, funded through the zero-knowledge (ZK) protocol Railgun, swapped the misappropriated funds to Ethereum (ETH), initially obtaining 608 ETH.
ゼロ知識 (ZK) プロトコル Railgun を通じて資金を得た攻撃者は、不正流用した資金をイーサリアム (ETH) に交換し、最初に 608 ETH を取得しました。
However, further analysis by Web3 security provider Olympix revealed that the exploit occurred due to “calldata within the ConnectorDeleverageParaswap contract.” The report highlighted that the contract failed to adequately check the flash loan calls data.
しかし、Web3 セキュリティ プロバイダーである Olympix によるさらなる分析により、このエクスプロイトは「ConnectorDeleverageParaswap コントラクト内の呼び出しデータ」によって発生したことが明らかになりました。報告書は、契約がフラッシュローンの通話データを適切にチェックしていなかったことが強調された。
The unvalidated calldata allowed the exploiter to manipulate the contract's data and send the funds to an Externally Owned Account (EAO), enabling them to withdraw the stolen crypto.
未検証の通話データにより、悪用者は契約データを操作し、資金を外部所有アカウント (EAO) に送金し、盗んだ暗号通貨を引き出すことが可能になりました。
Following the initial reports, a second batch of attacks occurred, leading to the loss of another $141,000 in USDC, raising the total crypto heist to $1.96 million.
最初の報告に続いて、第 2 グループの攻撃が発生し、USDC でさらに 141,000 ドルが損失され、暗号通貨強盗の総額は 196 万ドルに増加しました。
However, lending protocol Aave's pools remained unaffected, according to Cyvers.
しかし、Cyvers氏によると、融資プロトコルAaveのプールは影響を受けなかったという。
After the initial reports, the DeFi protocol acknowledged the attack and urged users to withdraw their remaining funds from the protocol. Later, Dough Finance announced it had identified and closed the exploit.
最初の報告の後、DeFiプロトコルは攻撃を認め、ユーザーにプロトコルから残りの資金を引き出すよう促した。その後、Dough Finance はエクスプロイトを特定し、閉鎖したと発表しました。
The project confirmed that “a few early Dough DeFi Smart Accounts (DSAs)” were victim to a sophisticated exploit.
このプロジェクトでは、「いくつかの初期の Dough DeFi スマート アカウント (DSA)」が高度なエクスプロイトの被害に遭ったことが確認されました。
In a statement, Dough Finance assured that its team is actively working to address the incident, aiming to recover the funds and making investors whole.
ドー・ファイナンスは声明で、チームが資金の回収と投資家の健全化を目指してこの事件に積極的に取り組んでいることを保証した。
Online reports also revealed that the team reached out to the exploiter through an on-chain message, offering to discuss a bounty if they had “exploited this vulnerability as a white or grey hat.”
オンラインレポートでは、チームがオンチェーンメッセージを通じてエクスプロイト者に連絡し、「ホワイトハットまたはグレーハットとしてこの脆弱性を悪用した」場合に報奨金について話し合うことを提案したことも明らかになりました。
The message also included the address where the funds should be directly transferred if the exploiter wished to return the stolen crypto.
このメッセージには、悪用者が盗まれた暗号通貨を返却したい場合に資金を直接送金する必要があるアドレスも含まれていました。
The exploiter has until Monday, July 15, 2024, at 23:00 UTC to contact the DeFi protocol. If the team doesn't receive an answer, they will “assume you appropriated the funds with unlawful intent and will pursue all criminal, legal, and administrative avenues available” to recover the misappropriated funds.
エクスプロイト者は、2024 年 7 月 15 日月曜日の 23:00 UTC までに DeFi プロトコルに接続する必要があります。チームが回答を受け取らなかった場合、チームは「不正な意図を持って資金を流用したものとみなし、流用された資金を取り戻すために利用可能なすべての刑事、法的、行政手段を追求する」としている。
This incident highlights the ongoing threat posed by scammers to the DeFi sector. Earlier this week, several DeFi projects, including Compound Finance, were compromised in a phishing attack.
この事件は、詐欺師が DeFi セクターにもたらしている継続的な脅威を浮き彫りにしました。今週初め、Compound Financeを含むいくつかのDeFiプロジェクトがフィッシング攻撃で侵害されました。
The projects were reportedly victims of a DNS domain attack, which redirected users to a fake website. The copy website functioned as a drainer tool, capable of draining users' funds if they interacted with it.
これらのプロジェクトは、ユーザーを偽の Web サイトにリダイレクトする DNS ドメイン攻撃の被害を受けたと報告されています。コピー Web サイトは流出ツールとして機能し、ユーザーが操作すると資金を流出させることができました。
As a result, the teams of the affected projects quickly urged customers not to interact with the websites until further notice, to prevent any potential losses.
その結果、影響を受けたプロジェクトのチームは、潜在的な損失を防ぐために、追って通知があるまでウェブサイトを操作しないよう顧客にすぐに呼び掛けました。
免責事項:info@kdj.com
提供される情報は取引に関するアドバイスではありません。 kdj.com は、この記事で提供される情報に基づいて行われた投資に対して一切の責任を負いません。暗号通貨は変動性が高いため、十分な調査を行った上で慎重に投資することを強くお勧めします。
このウェブサイトで使用されているコンテンツが著作権を侵害していると思われる場合は、直ちに当社 (info@kdj.com) までご連絡ください。速やかに削除させていただきます。

































