|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
分散型金融(DeFi)セクターは、銀行や規制のない将来が約束され、大幅な成長を遂げてきました。ただし、これらの仲介者がいないと、ユーザーは詐欺やハッキングなどのリスクにさらされます。

Decentralized finance (DeFi) is meant to be a future without banks and regulation. But the absence of these intermediaries also leaves users exposed.
分散型金融(DeFi)は、銀行や規制のない未来を目指しています。しかし、これらの仲介者が存在しないことにより、ユーザーは危険にさらされることになります。
Recently, cross-chain transaction aggregator LI.FI became the latest target of a hack, highlighting a vulnerability that has already cost users over $10 million in stablecoins. And, according to security experts, more user funds could still be at risk.
最近、クロスチェーントランザクションアグリゲーター LI.FI がハッキングの最新の標的となり、ユーザーにすでにステーブルコインで 1,000 万ドル以上の損害を与えている脆弱性が浮き彫りになりました。そして、セキュリティ専門家によれば、さらに多くのユーザー資金が依然として危険にさらされる可能性があるという。
Here's how the LI.FI protocol hack went down.
LI.FIプロトコルのハッキングがどのように起こったかは次のとおりです。
DeFi hacks are getting creative. On Tuesday, July 16, crypto security firm Cyvers reported a security breach in the LI.FI protocol, a major cross-chain transaction aggregator.
DeFiハックは創造的になってきています。 7月16日火曜日、暗号セキュリティ企業Cyversは、大手クロスチェーントランザクションアグリゲーターであるLI.FIプロトコルにおけるセキュリティ侵害を報告した。
The initial breach was detected on the Ethereum blockchain and later expanded to the Arbitrum network. The attack resulted in the theft of over $10 million in stablecoins, primarily USDC and USDT, which the attackers then began converting into ETH.
最初の侵害はイーサリアム ブロックチェーンで検出され、その後アービトラム ネットワークに拡大されました。この攻撃により、主に USDC と USDT である 1,000 万ドルを超えるステーブルコインが盗まれ、攻撃者はそれを ETH に変換し始めました。
The LI.FI protocol team confirmed the breach after the incident was reported by the security firm. According to the team, the main vulnerability stemmed from an infinite approval setting for transactions, which allowed the attackers to pilfer all the funds.
セキュリティ会社からインシデントが報告された後、LI.FIプロトコルチームは違反を確認した。チームによると、主な脆弱性はトランザクションの承認設定が無制限であることに起因しており、これにより攻撃者はすべての資金を盗むことができました。
How to protect yourself from the infinite approval exploit
無限承認エクスプロイトから身を守る方法
The infinite approval exploit occurs when users grant a smart contract unlimited permission to access their funds. This is convenient for repetitive transactions that don't require user confirmation every time, but it also introduces a major security risk. If the smart contract or platform is compromised, attackers can use it to drain all the funds from users.
無限承認エクスプロイトは、ユーザーが自分の資金にアクセスするための無制限の許可をスマート コントラクトに付与した場合に発生します。これは、毎回ユーザーの確認を必要としない反復的なトランザクションには便利ですが、重大なセキュリティ リスクも伴います。スマート コントラクトまたはプラットフォームが侵害されると、攻撃者はそれを利用してユーザーからすべての資金を抜き取ることができます。
Sponsored
スポンサー付き
Revoke approvals: LI.FI claims that no further funds are at risk, but the Cyvers security firm is urging users to immediately revoke approvals for the compromised addresses. This can be done easily using tools like Revoke.cash.
承認の取り消し:LI.FIは、これ以上資金が危険にさらされることはないと主張しているが、セキュリティ会社Cyversは侵害されたアドレスの承認を直ちに取り消すようユーザーに呼び掛けている。これは、Revoke.cash などのツールを使用して簡単に行うことができます。
Inspect approvals: Users should periodically review their token approvals and revoke any that are no longer needed or that could pose a risk.
承認を検査する: ユーザーは定期的にトークンの承認を確認し、不要になったものやリスクを引き起こす可能性のあるものを取り消す必要があります。
Set limits: Instead of granting infinite approval, users can specify a limit on the amount a smart contract can access. This way, even if there is a breach, the potential loss is capped.
制限を設定する: ユーザーは、無限に承認を与える代わりに、スマート コントラクトがアクセスできる量の制限を指定できます。これにより、たとえ侵害があったとしても、潜在的な損失は制限されます。
While DeFi protocols are responsible for ensuring strong security measures, users also bear responsibility for their own security settings. Taking these steps can help reduce the risk of falling victim to hacks.
DeFiプロトコルは強力なセキュリティ対策を確保する責任がありますが、ユーザーは自分のセキュリティ設定にも責任を負います。これらの手順を実行すると、ハッキングの被害に遭うリスクを軽減できます。
On the Flipside
裏返しに
Why This Matters
なぜこれが重要なのか
The LI.FI breach underscores the critical need for vigilance and proactive security measures in DeFi. Users must be cognizant of their security settings and take regular actions to manage permissions and safeguard their assets.
LI.FIの侵害は、DeFiにおける警戒と事前のセキュリティ対策の重要な必要性を浮き彫りにしました。ユーザーは自分のセキュリティ設定を認識し、権限を管理して資産を保護するために定期的な措置を講じる必要があります。
Learn more about protecting your funds:
資金の保護について詳しくは、こちらをご覧ください。
How to Stay Safe From Phishing in Crypto Mailing List Hack
暗号メーリングリストのハッキングでフィッシングから身を守る方法
Discover the Chromia Mainnet launch:
Chromia Mainnet のリリースをご覧ください:
Chromia Mainnet Launch Sets the Stage for Next-Gen Blockchain Networks
Chromia メインネットの立ち上げが次世代ブロックチェーン ネットワークの舞台を設定
免責事項:info@kdj.com
提供される情報は取引に関するアドバイスではありません。 kdj.com は、この記事で提供される情報に基づいて行われた投資に対して一切の責任を負いません。暗号通貨は変動性が高いため、十分な調査を行った上で慎重に投資することを強くお勧めします。
このウェブサイトで使用されているコンテンツが著作権を侵害していると思われる場合は、直ちに当社 (info@kdj.com) までご連絡ください。速やかに削除させていただきます。

































