|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
大規模な暗号通貨ハッキングが SwapNet を襲い、Matcha Meta ユーザーに影響を与え、何百万ものお金が吸い上げられました。このデジタルドラマは、スマートコントラクトのセキュリティとステーブルコイン発行者の説明責任に関する議論を再燃させています。

Alright, listen up, folks. It seems like every other week, there's another digital kerfuffle shaking up the crypto scene, and this time, it's a real head-scratcher involving decentralized exchange aggregator Matcha Meta and liquidity provider SwapNet. What's the deal? A vulnerability in SwapNet's smart contract led to millions getting siphoned off, leaving users—and even big players like stablecoin issuer Circle—in a bit of a pickle.
さて、聞いてください、皆さん。隔週のように、仮想通貨シーンを揺るがす新たなデジタル大騒動が起きているようだが、今回は分散型取引所アグリゲーターの Matcha Meta と流動性プロバイダーの SwapNet が関与する、まさに大混乱だ。どういうことですか? SwapNet のスマート コントラクトの脆弱性により、数百万ドルが吸い上げられ、ユーザー、さらにはステーブルコイン発行会社である Circle のような大手企業さえも、少々窮地に陥りました。
The SwapNet Shenanigans: A Technical Knockout
SwapNet の悪ふざけ: 技術的なノックアウト
It all went down when a chink in SwapNet's smart contract armor, specifically an 'arbitrary call' vulnerability, was exploited. For those not fluent in blockchain babble, this essentially meant attackers could bypass security checks and help themselves to funds from users who'd previously given 'token approvals.' Think of it like giving someone permission to automatically pay your bills, only for them to start emptying your bank account. Matcha Meta, while quick to point out the flaw wasn't in their own infrastructure, was caught in the crossfire due to their integration with SwapNet. They're telling folks to revoke those approvals ASAP, like pulling your hand out of a hot oven.
SwapNet のスマート コントラクトの脆弱性、特に「任意の呼び出し」の脆弱性が悪用されたとき、すべてが失敗しました。ブロックチェーンの話に詳しくない人にとって、これは本質的に、攻撃者がセキュリティチェックを回避して、以前に「トークン承認」を与えたユーザーから資金を得ることができることを意味していました。これは、請求書を自動的に支払う許可を誰かに与え、その人だけがあなたの銀行口座を空にし始めるようなものだと考えてください。 Matcha Meta は、欠陥が自社のインフラストラクチャにあるわけではないとすぐに指摘しましたが、SwapNet との統合が原因で集中攻撃に巻き込まれました。彼らは人々に、熱いオーブンから手を引き抜くようなもので、できるだけ早くこれらの承認を取り消すように言っています。
Counting the Digital Coffers (and Losses)
デジタル金庫 (および損失) を数える
When it comes to the damage, the numbers are flying around like pigeons in Times Square. Blockchain security firm CertiK initially pegged the losses at around $13.3 million. But then PeckShield swooped in, claiming the tally was closer to $16.8 million, mostly in USDC on the Base network. The attacker, no slouch, then apparently swapped a hefty $10.5 million of that USDC for about 3,655 Ethereum (ETH), before doing the digital equivalent of catching a flight to another blockchain. Classic smash-and-grab, just with more code and less getaway car.
被害に関して言えば、その数字はタイムズスクエアのハトのように飛び回っている。ブロックチェーンセキュリティ会社CertiKは当初、損失額を約1,330万ドルと見積もっていた。しかしその後、PeckShield が急襲し、その総額は 1,680 万ドルに近く、そのほとんどが Base ネットワーク上の USDC にあると主張しました。その後、攻撃者は、前かがみではなく、別のブロックチェーンへのフライトに乗るのと同等のデジタル行為を行う前に、その USDC の 1,050 万ドルという多額の資金を約 3,655 イーサリアム (ETH) と交換したようです。古典的なスマッシュアンドグラブですが、コードが増えて逃走車が減りました。
Circle Under the Spotlight: Frozen Assets, Frozen Trust?
スポットライトを浴びるサークル: 凍結された資産、凍結された信託?
Now, here's where it gets interesting, and a little contentious. Stablecoin issuer Circle, the folks behind USDC, found themselves in the hot seat. Critics, including blockchain investigator ZachXBT, were quick to call them out for not freezing over $3 million of the stolen USDC for hours. This isn't just a minor squabble; it reignites a fiery debate about what centralized stablecoin issuers should do when a hack goes down. Unlike decentralized assets, USDC can be frozen, a feature often touted as a safety net. But if that net isn't deployed swiftly, what's the point? While Tether has frozen billions in USDT, Circle's track record on this front, according to some, has been less robust. It makes you wonder, in this wild west of digital finance, who's really got your back?
さて、ここからが興味深いところですが、少し議論の余地があります。 USDC の背後にあるステーブルコイン発行会社の Circle は、自分たちが有利な立場にあることに気づきました。ブロックチェーン研究者のZachXBTを含む批評家は、盗まれたUSDCの300万ドル以上を何時間も凍結しなかったことをすぐに非難した。これは単なる小さな口論ではありません。ハッキングが失敗したときに集中型ステーブルコイン発行者が何をすべきかについての激しい議論が再燃することになる。分散型資産とは異なり、USDC は凍結することができ、これはセーフティ ネットとしてよく宣伝される機能です。しかし、その網が迅速に展開されなければ、何の意味があるでしょうか?テザーは数十億ドルのUSDTを凍結したが、一部の人によると、この面でのサークルの実績はそれほど堅調ではないという。このデジタル金融の荒野で、本当に自分を支えてくれているのは誰なのか、疑問に思うでしょう。
A Recurring Headache for DeFi
DeFiにとって繰り返し起こる頭痛
This whole SwapNet fiasco isn't an isolated incident; it's part of a larger, unfortunate trend. Just a couple of weeks prior, another smart contract vulnerability cost Truebit a reported $26 million. Security firms are waving red flags, noting that smart contract exploits are a leading cause of crypto losses. Even AI is getting in on the act, reportedly helping both sides—attackers finding flaws faster, and researchers trying to patch them up. It's a never-ending digital cat-and-mouse game, played out in the high-stakes arena of decentralized finance.
この SwapNet の大失敗全体は、単独の事件ではありません。それはより大きな不幸な傾向の一部です。ほんの数週間前、別のスマート コントラクトの脆弱性により、Truebit は 2,600 万ドルの損害を被ったと報告されています。セキュリティ会社は、スマートコントラクトの悪用が暗号通貨損失の主な原因であると指摘し、危険信号を振っている。 AIさえもこの活動に参加しており、攻撃者がより早く欠陥を発見し、研究者が欠陥を修正しようとしているという双方を支援していると報告されている。これは、分散型金融という一か八かの舞台で繰り広げられる、終わりのないデジタルいたちごっこです。
What's a User to Do?
ユーザーは何をすればよいでしょうか?
So, what's the takeaway from this latest saga? If you've ever granted token approvals to SwapNet, the advice is clear: revoke 'em, and revoke 'em now. It’s like changing the locks after a break-in. In the grand scheme of things, this incident is another loud reminder that in the fast-paced, sometimes chaotic world of crypto, vigilance isn't just a good idea—it's practically a superpower. Fuhgeddaboudit? Not a chance. We'll be here next week, probably with another story of digital daring, and hopefully, a few less dollars gone astray.
では、この最新作から得られる教訓は何でしょうか? SwapNet にトークンの承認を与えたことがある場合、アドバイスは明確です。それらを取り消し、今すぐ取り消してください。侵入後に鍵を交換するようなものです。大局的に見ると、この事件は、ペースが速く、時には混沌とした仮想通貨の世界において、警戒することは単なる良い考えではなく、事実上超大国であることを改めて大声で思い出させてくれます。フゲッダボウディット?チャンスではない。私たちは来週ここで、おそらくデジタルの大胆さに関する別の話をするつもりです、そしてできれば、迷走したお金が少しでも減ることを願っています。
免責事項:info@kdj.com
提供される情報は取引に関するアドバイスではありません。 kdj.com は、この記事で提供される情報に基づいて行われた投資に対して一切の責任を負いません。暗号通貨は変動性が高いため、十分な調査を行った上で慎重に投資することを強くお勧めします。
このウェブサイトで使用されているコンテンツが著作権を侵害していると思われる場合は、直ちに当社 (info@kdj.com) までご連絡ください。速やかに削除させていただきます。

































