|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
ブロックチェーン間でデジタル資産のブリッジや交換に使用される API である Li.Fi プロトコルの 1,160 万ドルの悪用を受けて、Li.Fi チームはリリース

An exploit of the Li.Fi protocol resulted in the theft of $11.6 million in digital assets, prompting the Li.Fi team to release an update on the technical aspects of the breach.
Li.Fi プロトコルの悪用により 1,160 万ドルのデジタル資産が盗難され、Li.Fi チームは侵害の技術的側面に関する最新情報をリリースすることになりました。
The breach occurred during the deployment of a new smart contract facet, which contained a vulnerability that enabled users calling the smart contract to initiate calls to any contract without prior validation.
この違反は、新しいスマート コントラクト ファセットの展開中に発生しました。このファセットには、スマート コントラクトを呼び出すユーザーが事前の検証なしに任意のコントラクトへの呼び出しを開始できる脆弱性が含まれていました。
This function stemmed from code taken from the LibSwap library, which facilitates calls between decentralized exchanges, service providers, and clients to coordinate the asset bridging and swapping processes.
この関数は、LibSwap ライブラリから取得したコードから派生しており、分散型取引所、サービス プロバイダー、クライアント間の呼び出しを容易にして、資産のブリッジングとスワッピングのプロセスを調整します。
Normally, these calls are screened against whitelisted addresses to ensure validation. However, human error in deploying the offending smart contract facet resulted in these checks being bypassed, rendering the protocol vulnerable to exploitation.
通常、これらの呼び出しは、検証を確実にするために、ホワイトリストに登録されたアドレスに対してスクリーニングされます。しかし、問題のあるスマート コントラクト ファセットを展開する際の人的ミスにより、これらのチェックがバイパスされ、プロトコルが悪用されやすくなりました。
The Li.Fi team confirmed that the attack occurred on the Ethereum and Arbitrum networks and affected 156 wallets that had the “infinite approvals” option turned on. Those who did not enable this option were not affected by the exploit.
Li.Fiチームは、攻撃がイーサリアムとアービトラムのネットワーク上で発生し、「無限承認」オプションがオンになっていた156のウォレットに影響を与えたことを確認した。このオプションを有効にしなかった人は、エクスプロイトの影響を受けませんでした。
In statements to Cointelegraph, spokespeople for Li.Fi said they contained the exploit, addressed the critical vulnerability, and contacted the proper law enforcement authorities to trace the stolen funds. At the time of this writing, the issue has been fixed, and Li.Fi is operating normally.
Li.Fiの広報担当者はコインテレグラフへの声明で、エクスプロイトを封じ込め、重大な脆弱性に対処し、盗まれた資金を追跡するために適切な法執行機関に連絡したと述べた。この記事の執筆時点では、問題は解決されており、Li.Fi は正常に動作しています。
Related: Lazarus is moving millions from $305M DMM Bitcoin hack — ZachXBT
関連: Lazarus が 3 億 500 万ドルの DMM ビットコイン ハッキングから数百万ドルを移動 — ZachXBT
This is not the first time that a vulnerability in the Li.Fi protocol has been exploited. In March 2022, a similar exploit affected users who had the “infinite approval” option turned on, allowing hackers to drain $600,000 from the protocol from 29 wallets before the vulnerability was addressed.
Li.Fi プロトコルの脆弱性が悪用されるのはこれが初めてではありません。 2022 年 3 月にも、同様のエクスプロイトが「無限承認」オプションをオンにしているユーザーに影響を及ぼし、脆弱性が解決される前にハッカーが 29 のウォレットからプロトコルから 60 万ドルを流出させることができました。
The protocol was quick to reimburse investors for their losses, refunding 24 wallets directly from its treasury and offering the remaining five wallets a voluntary compensation plan akin to that received by early angel investors of Li.Fi.
このプロトコルは投資家の損失を迅速に補填し、24のウォレットを財務省から直接返金し、残りの5つのウォレットにはLi.Fiの初期のエンジェル投資家が受け取ったものと同様の自主補償プランを提供した。
Crypto hacks put the damper on the industry in 2024
2024 年の暗号通貨ハッキングは業界に水を差す
Hacks and exploits continue to plague the crypto industry and the decentralized financial sector, in particular.
ハッキングやエクスプロイトは、特に暗号通貨業界と分散型金融セクターを悩ませ続けています。
A recent report from security firm Cyvers showed that 2024 losses from crypto exploits are nearing $1.4 billion, driven primarily by phishing attacks, and have risen sharply since 2023.
セキュリティ会社Cyversの最近のレポートによると、暗号通貨エクスプロイトによる2024年の損失は主にフィッシング攻撃によるもので14億ドル近くに達しており、2023年以降急激に増加している。
Magazine: Best and worst countries for crypto taxes — plus crypto tax tips
マガジン: 仮想通貨税に最適な国と最悪の国 — および仮想通貨税に関するヒント
免責事項:info@kdj.com
提供される情報は取引に関するアドバイスではありません。 kdj.com は、この記事で提供される情報に基づいて行われた投資に対して一切の責任を負いません。暗号通貨は変動性が高いため、十分な調査を行った上で慎重に投資することを強くお勧めします。
このウェブサイトで使用されているコンテンツが著作権を侵害していると思われる場合は、直ちに当社 (info@kdj.com) までご連絡ください。速やかに削除させていただきます。

































