時価総額: $2.2391T 1.66%
ボリューム(24時間): $47.003B 22.54%
  • 時価総額: $2.2391T 1.66%
  • ボリューム(24時間): $47.003B 22.54%
  • 恐怖と貪欲の指数:
  • 時価総額: $2.2391T 1.66%
暗号
トピック
暗号化
ニュース
暗号造園
動画
トップニュース
暗号
トピック
暗号化
ニュース
暗号造園
動画
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

暗号通貨のニュース記事

Liminal、7月のハッキングでWazirXを非難、UIには責任がなかったと主張

2024/07/20 02:00

マルチパーティコンピューテーション (MPC) ウォレットプロバイダーである Liminal は、7 月 18 日の WazirX ハッキングに関する事後報告書を 7 月 19 日に発表し、そのユーザーインターフェイスに問題があると主張しました。

Liminal、7月のハッキングでWazirXを非難、UIには責任がなかったと主張

Multiparty computation (MPC) technology provider Liminal has released a July 19 post-mortem report on the July 18 WazirX hack, disputing the exchange’s claim that its user interface was responsible for the attack.

マルチパーティコンピューテーション (MPC) 技術プロバイダーである Liminal は、7 月 18 日の WazirX ハッキングに関する事後報告書を 7 月 19 日に発表し、ユーザー インターフェイスが攻撃の原因であるという取引所の主張に異議を唱えました。

According to Liminal's report, the hack occurred because three WazirX devices were compromised. The devices were used to initiate transactions that were then modified by the attacker before being sent to Liminal's servers for approval.

Liminal のレポートによると、ハッキングは 3 台の WazirX デバイスが侵害されたために発生しました。これらのデバイスはトランザクションを開始するために使用され、承認のために Liminal のサーバーに送信される前に攻撃者によって変更されました。

Liminal also claimed that its multisignature wallet was set up to provide a fourth signature if WazirX provided the other three. This meant that the attacker only needed to compromise three devices to perform the attack. The wallet was set up this way at the behest of WazirX, the wallet provider claimed.

Liminalはまた、WazirXが他の3つの署名を提供した場合に、そのマルチシグネチャウォレットが4番目の署名を提供するように設定されていると主張した。これは、攻撃者が攻撃を実行するために必要なデバイスが 3 台だけであることを意味します。ウォレットプロバイダーは、ウォレットはWazirXの命令でこのように設定されたと主張した。

In a July 18 social media post, WazirX claimed that its private keys were secured with hardware wallets. However, WazirX said the attack “stemmed from a discrepancy between the data displayed on Liminal’s interface and the transaction’s actual contents.”

WazirX は 7 月 18 日のソーシャル メディアへの投稿で、秘密鍵はハードウェア ウォレットで保護されていると主張しました。しかしWazirXは、この攻撃は「Liminalのインターフェースに表示されるデータとトランザクションの実際の内容との不一致から生じた」と述べた。

According to the Liminal report, one of WazirX’s devices initiated a valid transaction involving the Gala Games (GALA) token. In response, Liminal’s server provided a “safeTxHash,” verifying the transaction's validity. However, the attacker then replaced this transaction hash with an invalid one, causing the transaction to fail.

Liminal のレポートによると、WazirX のデバイスの 1 つが Gala Games (GALA) トークンを含む有効なトランザクションを開始しました。これに応じて、Liminal のサーバーは「safeTxHash」を提供し、トランザクションの正当性を検証しました。しかし、攻撃者はこのトランザクション ハッシュを無効なハッシュに置き換え、トランザクションを失敗させました。

In Liminal’s view, the fact that the attacker was able to change this hash implies that the WazirX device had already been compromised before the transaction was attempted.

Liminal の見解では、攻撃者がこのハッシュを変更できたという事実は、トランザクションが試行される前に WazirX デバイスがすでに侵害されていたことを意味します。

The attacker then initiated an additional two transactions: one GALA and one Tether (USDT) transfer. In each of these three transactions, the attacker used a different WazirX admin account, for a total of three accounts used. All three of the transactions failed.

その後、攻撃者はさらに 2 つのトランザクション (1 つは GALA、もう 1 つはテザー (USDT) 転送) を開始しました。これら 3 つのトランザクションのそれぞれで、攻撃者は異なる WazirX 管理者アカウントを使用し、合計 3 つのアカウントが使用されました。 3 つのトランザクションはすべて失敗しました。

After initiating these three failed transactions, the attacker extracted signatures from the transactions and used them to initiate a new, fourth transaction. The fourth transaction “was crafted in such a way that the fields used to verify policies were using legit transaction details” and “used the Nonce from the failed USDT transaction because that was the latest transaction.”

これら 3 つの失敗したトランザクションを開始した後、攻撃者はトランザクションから署名を抽出し、それらを使用して新しい 4 番目のトランザクションを開始しました。 4 番目のトランザクションは、「ポリシーの検証に使用されるフィールドが正当なトランザクションの詳細を使用するように作成され」、「失敗した USDT トランザクションの Nonce を使用しました。これは最新のトランザクションだったためです。」

Because it used these “legit transaction details,” the Liminal server approved the transaction and provided a fourth signature. As a result, the transaction was confirmed on the Ethereum network, resulting in a transfer of funds from the joint multisig wallet to the attacker’s Ethereum account.

これらの「正当なトランザクションの詳細」を使用したため、Liminal サーバーはトランザクションを承認し、4 番目の署名を提供しました。その結果、トランザクションはイーサリアム ネットワーク上で確認され、共同マルチシグ ウォレットから攻撃者のイーサリアム アカウントに資金が送金されました。

Liminal denied that its servers caused incorrect information to be displayed through the Liminal UI. Instead, it claimed that the incorrect information was provided by the attacker, who had compromised WazirX computers. In an answer to the posed question “How did the UI show a different value from the actual payload within the transaction?” Liminal said:

Liminal は、サーバーが原因で Liminal UI に誤った情報が表示されたことを否定しました。その代わりに、WazirX コンピュータに侵入した攻撃者によって誤った情報が提供されたと主張しました。 「トランザクション内の実際のペイロードとは異なる値が UI に表示されたのはなぜですか?」という質問に対する答えです。リミナル氏はこう語った。

Liminal also claimed that its servers were programmed to automatically provide a fourth signature if WazirX admins provided the other three. “Liminal only provides the final signature once the required number of valid signatures are received from the client’s side,” it stated, adding that in this case, “the transaction was authorised and signed by three of our client’s employees.”

Liminal はまた、WazirX 管理者が他の 3 つの署名を提供した場合、サーバーは自動的に 4 つ目の署名を提供するようにプログラムされていると主張しました。 「Liminalは、顧客側から必要な数の有効な署名を受け取った場合にのみ最終署名を提供する」と述べ、このケースでは「取引は当社の顧客の従業員3人によって承認され、署名された」と付け加えた。

The multisig wallet “was deployed by WazirX as per their configuration well before onboarding with Liminal,” and was “imported” into Liminal “per WazirX's request.”

マルチシグ ウォレットは「Liminal にオンボーディングするかなり前に、WazirX によって設定に従って展開され」、「WazirX の要求に従って」Liminal に「インポート」されました。

Related: WazirX breach post-mortem: Dismantling the $230M attack

関連: WazirX 侵害の事後分析: 2 億 3,000 万ドルの攻撃を解体する

WazirX’s post claimed that it had implemented “robust security features.” For example, it had required that all transactions be confirmed by four out of five keyholders. Four of these keys belonged to WazirX employees and one to the Liminal team. In addition, it required three of the WazirX keyholders to use hardware wallets. All destination addresses were required to be added to a whitelist ahead of time, WazirX stated, which was “earmarked and facilitated on the interface by Liminal.”

WazirX の投稿では、「堅牢なセキュリティ機能」を実装していると主張されていました。たとえば、すべての取引はキーホルダーの所有者 5 人中 4 人によって確認されることが求められていました。これらのキーのうち 4 つは WazirX の従業員に属し、1 つは Liminal チームに属していました。さらに、WazirX キーホルダーのうち 3 つはハードウェア ウォレットを使用する必要がありました。 WazirX によれば、すべての宛先アドレスは事前にホワイトリストに追加する必要があり、これは「Liminal によってインターフェイス上で割り当てられ、容易にされた」とのことです。

Despite taking all of these precautions, the attacker “appear[s] to have possibly breached such security features, and the theft occurred.” WazirX called the attack a “a force majeure event beyond [its] control.” Even so, it vowed that it was “leaving no stone unturned to locate and recover the funds.”

これらすべての予防措置を講じたにもかかわらず、攻撃者は「そのようなセキュリティ機能を侵害した可能性があり、盗難が発生したようです」。 WazirX はこの攻撃を「制御不能な不可抗力事象」と呼んだ。それでも、同社は「資金を見つけて回収するためにあらゆる手段を講じる」と誓った。

An estimated $235 million was lost in the WazirX attack. It was the largest centralized exchange hack since the DMM exploit of May 31, which resulted in even greater losses of $305 million.

WazirX 攻撃では推定 2 億 3,500 万ドルが失われました。これは、5 月 31 日の DMM エクスプロイト以来最大の集中型取引所ハッキングであり、3 億 500 万ドルというさらに大きな損失をもたらしました。

Magazine: WazirX hackers prepped 8 days before attack, swindlers fake fiat for USDT: Asia Express

マガジン: WazirX ハッカーは攻撃の 8 日前に準備、詐欺師は USDT のために法定通貨を偽装: Asia Express

オリジナルソース:cointelegraph

免責事項:info@kdj.com

提供される情報は取引に関するアドバイスではありません。 kdj.com は、この記事で提供される情報に基づいて行われた投資に対して一切の責任を負いません。暗号通貨は変動性が高いため、十分な調査を行った上で慎重に投資することを強くお勧めします。

このウェブサイトで使用されているコンテンツが著作権を侵害していると思われる場合は、直ちに当社 (info@kdj.com) までご連絡ください。速やかに削除させていただきます。

2026年07月27日 に掲載されたその他の記事