|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
分散型金融(DeFi)プロトコルのペンピーは最近、数百万ドル相当のいくつかの暗号資産を奪うエクスプロイトの被害者になりました。

A DeFi protocol based on Pendle, Penpie, recently fell victim to an exploit that saw millions of dollars worth of several crypto assets being drained from the protocol. Pendle addressed the incident in a post-mortem post, revealing that its quick response prevented further losses to the tune of over $100 million in users’ funds.
最近、Pendle をベースとした DeFi プロトコルである Penpie が悪用の被害に遭い、数百万ドル相当のいくつかの暗号資産がプロトコルから流出しました。ペンドルは事後投稿でこの事件について言及し、迅速な対応によりユーザーの資金がさらに1億ドル以上損失することを防いだことを明らかにした。
According to reports, the crypto heist took place on Tuesday, with the malicious actor exploiting a vulnerability in Penpie’s reward distribution mechanism. The vulnerability stemmed from a Penpie-only feature that permitted permissionless listing of Pendle markets on Penpie.
報道によると、仮想通貨強盗は火曜日に発生し、悪意のある攻撃者はPenpieの報酬分配メカニズムの脆弱性を悪用した。この脆弱性は、Penpie 上で Pendle マーケットの許可なしのリストを許可する Penpie のみの機能に起因していました。
The attacker used an “evil market” contract to inflate the staking balance and claim unwarranted rewards. As a result, they were able to drain $7.87 million in wstETH, $2.51 million in sUSDe, $3.4 million agETH, $2.22 million in rswETH, and four other Pendle-related Yield tokens from the protocol.
攻撃者は「悪の市場」契約を利用してステーキング残高をつり上げ、不当な報酬を請求しました。その結果、彼らはプロトコルからwstETHで787万ドル、sUSDeで251万ドル、agETHで340万ドル、rswETHで222万ドル、および他の4つのペンドル関連のイールドトークンを流出させることができました。
Following the exploit, the hacker swapped the crypto assets for 11,113 ETH using the Li.fi protocol. The stolen funds, worth $27.3 million, were later transferred to crypto mixer Tornado Cash.
エクスプロイトの後、ハッカーは Li.fi プロトコルを使用して暗号資産を 11,113 ETH と交換しました。盗まれた2,730万ドル相当の資金は、後に暗号通貨ミキサーのトルネード・キャッシュに送金された。
The Penpie Team sent a message to the attacker, asking them to “amicably” resolve the incident. The protocol recognized the project’s vulnerability and the exploit’s role in bringing it forward, proposing a white hat bounty for the safe return of the funds.
ペンピーチームは攻撃者にメッセージを送り、事件を「友好的に」解決するよう求めた。このプロトコルは、プロジェクトの脆弱性とそれを前進させる上でのエクスプロイトの役割を認識し、資金を安全に返還するためにホワイトハット報奨金を提案しました。
Additionally, they offered the attacker an opportunity to “transition into a white-hat role, where your skills will be acknowledged and rewarded.” The team assured that the hacker’s identity would remain confidential and they would not pursue any legal action against them.
さらに、攻撃者に「あなたのスキルが認められ報酬が得られるホワイトハットの役割に移行する」機会を提供しました。チームは、ハッカーの身元は機密のままであり、ハッカーに対していかなる法的措置も取らないことを保証した。
As of this writing, there are no reports of a resolution between the exploiter and the protocol’s team.
この記事の執筆時点では、エクスプロイト者とプロトコルのチームの間で解決策が見つかったという報告はありません。
免責事項:info@kdj.com
提供される情報は取引に関するアドバイスではありません。 kdj.com は、この記事で提供される情報に基づいて行われた投資に対して一切の責任を負いません。暗号通貨は変動性が高いため、十分な調査を行った上で慎重に投資することを強くお勧めします。
このウェブサイトで使用されているコンテンツが著作権を侵害していると思われる場合は、直ちに当社 (info@kdj.com) までご連絡ください。速やかに削除させていただきます。

































