|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
カエルのクリエーターであるマット・フリーにリンクされたプロジェクトをターゲットにした最近のハックと、イランの暗号交換nobitexのエクスプロイトは、複雑なスキームと潜在的なDPRKの関与を明らかにします。

Matt Furie, Hacking, and DPRK: A Tangled Web in the Web3 World
Matt Furie、Hacking、およびDPRK:Web3の世界のもつれたウェブ
The crypto world moves fast, and sometimes it takes unexpected turns. Recently, the intersection of meme culture, NFT projects, and alleged North Korean cyber activity has created a particularly bizarre and concerning narrative. Let’s dive in.
暗号の世界は速く動き、時には予期せぬターンがかかることがあります。最近、ミーム文化、NFTプロジェクト、および北朝鮮のサイバー活動の交差点は、特に奇妙で物語に関するものを生み出しました。飛び込みましょう。
The Replicandy Debacle and the Matt Furie Connection
Replicandyの大失敗とMatt Furie Connection
Matt Furie, the artist behind the iconic Pepe the Frog meme, hasn't had the best luck lately with his NFT ventures. His 'Replicandy' collection, launched in June, suffered a major blow when a hacker exploited a vulnerability, minting thousands of new NFTs and tanking the floor price by a staggering 97%. Ouch.
象徴的なペペ・ザ・カエル・ミームの背後にあるアーティストであるマット・フーリーは、彼のNFTベンチャーで最近最高の運を持っていませんでした。 6月に発売された彼の「Replicandy」コレクションは、ハッカーが脆弱性を悪用し、何千もの新しいNFTを鋳造し、97%の驚異的な価格をタンクしたときに大きな打撃を受けました。痛い。
But it gets weirder. Blockchain investigator ZachXBT uncovered a potential link between the Replicandy exploit and a broader hacking campaign, pointing fingers at... North Korea.
しかし、それは奇妙になります。ブロックチェーンの調査員Zachxbtは、Replicandy Exploitとより広範なハッキングキャンペーンとの間の潜在的なリンクを明らかにし、北朝鮮に指を指しています。
DPRK IT Workers and the Web3 Infiltration
DPRK ITワーカーとWeb3浸潤
ZachXBT's investigation suggests that North Korean IT workers, likely hired unknowingly as developers, may be behind the attacks on Replicandy, as well as other projects like Favrr, Hedz and Zogz. The attacker gained control of the key contracts and initiated a second token issuance and dumped them into the liquidity pool, causing a sharp collapse in the floor price.
Zachxbtの調査によると、開発者として知らないうちに雇用された北朝鮮のIT労働者は、Favrr、Hedz、Zogzなどの他のプロジェクトと同様に、Replicandyへの攻撃の背後にある可能性があることが示唆されています。攻撃者は主要な契約の制御を獲得し、2回目のトークン発行を開始し、流動性プールに投棄し、フロア価格が急激に崩壊しました。
The Favrr project, a Web3 marketplace, experienced a similar exploit, with over $680,000 siphoned off. Funds were traced to addresses associated with potential payments to DPRK IT specialists. GitHub profiles with suspicious activity – Korean language settings, VPN usage, mismatched time zones – further fueled the suspicion.
Web3マーケットプレイスであるFAVRRプロジェクトは、同様のエクスプロイトを経験し、680,000ドル以上が吸い上げられました。資金は、DPRK ITスペシャリストへの潜在的な支払いに関連する住所に追跡されました。疑わしいアクティビティを備えたGithubプロファイル - 韓国語の設定、VPNの使用、不一致のタイムゾーン - は、疑いをさらに促進しました。
On-Chain Evidence and the Nobitex Hack
オンチェーンの証拠とnobitexハック
The investigation revealed a network of addresses used to consolidate and route funds to centralized exchanges, with some flows indicating a persistent compensation system for the alleged ITW group. Also, Iranian cryptocurrency exchange Nobitex suffered a breach, with onchain data revealing that around $82 million was siphoned from its reserves. A hacker collective calling itself Predatory Sparrow has claimed responsibility for the coordinated hit on the centralized exchange (CEX).
調査では、資金を集中交換に統合してルーティングするために使用される住所のネットワークが明らかになり、一部のフローはITWグループの持続的な補償システムを示しています。また、イランの暗号通貨交換Nobitexは違反に苦しんでおり、Onchainデータは約8,200万ドルが埋蔵量から吸い上げられたことを明らかにしています。略奪的なスパロウ自体と呼ばれるハッカー集団は、集中交換(CEX)の調整されたヒットに対する責任を主張しています。
Why This Matters
なぜこれが重要なのか
This situation highlights the growing threat of sophisticated cyberattacks targeting the Web3 space. With more money flowing into crypto, it's becoming an increasingly attractive target for malicious actors, including nation-state-backed groups. The alleged involvement of North Korean hackers demonstrates a systemic approach to infiltrating projects by posing as developers. So, the web3 builders must be extremely vigilant when designing security architectures, and calls users to exercise maximum caution.
この状況は、Web3空間をターゲットにした洗練されたサイバー攻撃の脅威の増大を強調しています。暗号に流れるお金が増えているため、国民国家が支援するグループを含む悪意のある俳優にとって、ますます魅力的なターゲットになりつつあります。北朝鮮のハッカーの関与の疑いは、開発者を装ってプロジェクトに浸透するための体系的なアプローチを示しています。したがって、セキュリティアーキテクチャを設計する際には、Web3ビルダーが非常に警戒している必要があり、ユーザーに最大限の注意を払うように呼びかけます。
Final Thoughts
最終的な考え
From Pepe memes to potential North Korean hacking rings, the crypto world is never short on surprises. It's a wild, wild west out there, folks. So buckle up, stay vigilant, and maybe double-check who you're hiring as a developer. You never know where they might actually be logging in from!
ペペのミームから潜在的な北朝鮮のハッキングリングまで、暗号の世界は驚きに欠けていません。それはそこにある野生の野生の西です、人々。だから、あなたが開発者として雇っている人をダブルチェックするかもしれません。彼らが実際にログインしている可能性があるのは決してわかりません!
免責事項:info@kdj.com
提供される情報は取引に関するアドバイスではありません。 kdj.com は、この記事で提供される情報に基づいて行われた投資に対して一切の責任を負いません。暗号通貨は変動性が高いため、十分な調査を行った上で慎重に投資することを強くお勧めします。
このウェブサイトで使用されているコンテンツが著作権を侵害していると思われる場合は、直ちに当社 (info@kdj.com) までご連絡ください。速やかに削除させていただきます。

































