時価総額: $2.882T -1.49%
ボリューム(24時間): $102.5955B -0.51%
  • 時価総額: $2.882T -1.49%
  • ボリューム(24時間): $102.5955B -0.51%
  • 恐怖と貪欲の指数:
  • 時価総額: $2.882T -1.49%
暗号
トピック
暗号化
ニュース
暗号造園
動画
トップニュース
暗号
トピック
暗号化
ニュース
暗号造園
動画
bitcoin
bitcoin

$84577.234968 USD

-1.56%

ethereum
ethereum

$2680.004128 USD

-1.70%

tether
tether

$0.999808 USD

0.02%

bnb
bnb

$765.682454 USD

-1.34%

xrp
xrp

$1.484099 USD

-2.46%

usd-coin
usd-coin

$0.999988 USD

0.00%

solana
solana

$119.429084 USD

-1.45%

tron
tron

$0.335308 USD

0.33%

zcash
zcash

$1313.504956 USD

-4.56%

hyperliquid
hyperliquid

$88.248433 USD

-1.74%

dogecoin
dogecoin

$0.092877 USD

-2.97%

chainlink
chainlink

$14.020892 USD

-2.26%

monero
monero

$548.883836 USD

0.03%

cardano
cardano

$0.244660 USD

-3.58%

unus-sed-leo
unus-sed-leo

$9.010719 USD

0.45%

暗号通貨のニュース記事

SlowMist が安全なウォレットを排出する FlashLoopAdapter の欠陥を発見: DeFi 統合への警鐘

2026/10/03 08:05

SlowMist は、サードパーティの Aave 統合である FlashLoopAdapter に重大な脆弱性があり、2 つの Safe マルチシグ ウォレットから 114 ETH が流出することを報告しました。このインシデントは、Safe のような堅牢なコア プロトコルであっても、外部 DeFi モジュールに内在するリスクを浮き彫りにしました。

SlowMist が安全なウォレットを排出する FlashLoopAdapter の欠陥を発見: DeFi 統合への警鐘

In the ever-evolving landscape of decentralized finance (DeFi), security is paramount, yet a recent incident brought to light by blockchain security firm SlowMist serves as a stark reminder that even the most fortified systems can be vulnerable through their external connections. A flaw in a third-party integration, dubbed FlashLoopAdapter, allowed an attacker to siphon approximately 114 ETH (valued around $305,000 at the time of reporting) from two Safe multisig wallets.

進化し続ける分散型金融 (DeFi) の状況では、セキュリティが最も重要ですが、ブロックチェーン セキュリティ会社 SlowMist によって明るみに出た最近の事件は、最も強化されたシステムでも外部接続を通じて脆弱になる可能性があることをはっきりと思い出させてくれます。 FlashLoopAdapter と呼ばれるサードパーティ統合の欠陥により、攻撃者は 2 つの Safe マルチシグ ウォレットから約 114 ETH (報告時点で約 305,000 ドル相当) を吸い上げることができました。

The Achilles' Heel: FlashLoopAdapter's Access Control

アキレス腱: FlashLoopAdapter のアクセス制御

SlowMist's investigation pinpointed FlashLoopAdapter as the weak link. This component, designed to manage leveraged Aave v3 positions, was an external adapter, not a core part of the Safe multisig wallet protocol or the Aave v3 itself. This distinction is crucial: the core Safe contracts remained uncompromised. The vulnerability lay in FlashLoopAdapter's access control mechanisms for its open() and close() functions. These functions merely checked if a module was enabled by calling ISafe(msg.sender).isModuleEnabled(address(this)), a check that was unfortunately spoofable.

SlowMist の調査により、FlashLoopAdapter が脆弱なリンクであることが特定されました。このコンポーネントは、レバレッジされた Aave v3 ポジションを管理するように設計されており、外部アダプターであり、安全なマルチシグ ウォレット プロトコルや Aave v3 自体のコア部分ではありません。この違いは非常に重要です。Safe のコア契約は妥協されていません。この脆弱性は、FlashLoopAdapter の open() および close() 関数のアクセス制御メカニズムに存在します。これらの関数は、ISafe(msg.sender).isModuleEnabled(address(this)) を呼び出してモジュールが有効になっているかどうかをチェックするだけでしたが、残念ながらこのチェックはなりすまし可能でした。

The attacker cleverly exploited this by deploying a fake Safe contract that would always return 'true' to this module enablement query. Furthermore, the _swap() function within FlashLoopAdapter allowed the caller to dictate the swap router and its data. The attacker leveraged this to set the router to one of the victim Safe wallets and then, through the execTransactionFromModule function (a legitimate Safe function for enabled modules), executed unauthorized transactions. The consequence? Collateral locked in Aave v3 positions via FlashLoopAdapter was drained.

攻撃者は、このモジュール有効化クエリに対して常に「true」を返す偽の Safe コントラクトを展開することで、これを巧妙に悪用しました。さらに、FlashLoopAdapter 内の _swap() 関数を使用すると、呼び出し元がスワップ ルーターとそのデータを指示できるようになりました。攻撃者はこれを利用して、ルーターを被害者の Safe ウォレットの 1 つに設定し、execTransactionFromModule 関数 (有効なモジュールに対する正規の Safe 関数) を通じて、未承認のトランザクションを実行しました。その結果は? FlashLoopAdapter 経由で Aave v3 ポジションにロックされていた担保が排出されました。

A Pattern of Peripheral Vulnerabilities

周辺機器の脆弱性のパターン

This isn't SlowMist's first rodeo in identifying vulnerabilities stemming from peripheral integrations. The firm has a consistent track record of tracing significant losses back to adjacent components rather than core protocols. This incident echoes previous findings, such as the Liquid Network exploit that minted 3,998 L-BTC, where a similar attack vector bypassed core defenses through an external module. These cases collectively underscore a critical trend: while core protocols may be robust, the security perimeter often expands with every third-party integration.

これは、SlowMist が周辺機器の統合に起因する脆弱性を特定する最初の取り組みではありません。同社には、重大な損失がコア プロトコルではなく隣接コンポーネントにまで遡るという一貫した実績があります。このインシデントは、同様の攻撃ベクトルが外部モジュールを介してコア防御を回避した、3,998 L-BTC を鋳造したリキッド ネットワークのエクスプロイトなど、以前の調査結果を反映しています。これらのケースは、総合的に重要な傾向を強調しています。コア プロトコルは堅牢である一方で、サードパーティとの統合が行われるたびにセキュリティ境界が拡大することがよくあります。

The Broader Implications for Safe Wallets and DeFi

安全なウォレットと DeFi の広範な影響

Safe wallets are widely celebrated for their enhanced security in DeFi, particularly through their multisig capabilities. However, the FlashLoopAdapter incident highlights a fundamental truth: security is only as strong as its weakest link. When users grant third-party adapters interaction privileges with their wallets, these adapters inherit significant execution power. A flaw in the adapter's logic, even if the wallet itself functions perfectly, can be weaponized.

安全なウォレットは、特にマルチシグ機能を通じて、DeFi のセキュリティが強化されていることで広く知られています。しかし、FlashLoopAdapter のインシデントは、セキュリティの強さは最も弱いリンクによって決まるという根本的な真実を浮き彫りにしました。ユーザーがサードパーティのアダプタにウォレットとの対話権限を付与すると、これらのアダプタは重要な実行能力を継承します。アダプターのロジックに欠陥があると、ウォレット自体が完全に機能する場合でも、武器化される可能性があります。

This serves as a potent reminder for anyone engaging with DeFi strategies that involve external modules. Authorizing an adapter is not a trivial decision; it entails trusting the adapter's code as much as, if not more than, the core protocol. The true blast radius of this exploit—how many other wallets had authorized FlashLoopAdapter before the flaw was discovered—remains an open question, underscoring the ongoing challenge of securing the interconnected DeFi ecosystem.

これは、外部モジュールを伴う DeFi 戦略に取り組む人にとって、強力なリマインダーとして機能します。アダプターを認可することは簡単な決定ではありません。これには、コア プロトコルと同等かそれ以上にアダプターのコードを信頼することが必要です。このエクスプロイトの本当の爆発範囲、つまり欠陥が発見される前に他のウォレットがどれくらいの数のウォレットでFlashLoopAdapterを承認していたのかは未解決のままであり、相互接続されたDeFiエコシステムを保護するという継続的な課題が浮き彫りになっています。

Looking Ahead: A Call for Scrutiny and Enhanced Vigilance

将来に向けて: 精査と警戒強化の呼びかけ

While the attacker's identity remains unknown and remediation steps are not publicly detailed, this incident provides valuable lessons. It's a clear call for increased scrutiny of third-party integrations and robust access control mechanisms. As DeFi continues to innovate, the onus is on both developers and users to prioritize comprehensive security audits and understand the full implications of every integration. In the end, staying safe in the digital frontier often comes down to paying attention to the fine print—and the code behind it. Let's keep those wallets safe and sound, one secure integration at a time!

攻撃者の身元は依然として不明であり、修復手順の詳細は公表されていませんが、このインシデントは貴重な教訓を提供します。これは、サードパーティの統合と堅牢なアクセス制御メカニズムの精査を強化することを明らかに要求しています。 DeFi が革新を続ける中、包括的なセキュリティ監査を優先し、あらゆる統合の影響を完全に理解する責任は開発者とユーザーの両方にあります。結局のところ、デジタルのフロンティアで安全を保つには、多くの場合、細かい文字とその背後にあるコードに注意を払う必要があります。一度に 1 つずつ安全な統合を行って、ウォレットを安全かつ健全に保ちましょう。

オリジナルソース:coinmarketcap

免責事項:info@kdj.com

提供される情報は取引に関するアドバイスではありません。 kdj.com は、この記事で提供される情報に基づいて行われた投資に対して一切の責任を負いません。暗号通貨は変動性が高いため、十分な調査を行った上で慎重に投資することを強くお勧めします。

このウェブサイトで使用されているコンテンツが著作権を侵害していると思われる場合は、直ちに当社 (info@kdj.com) までご連絡ください。速やかに削除させていただきます。

2026年10月03日 に掲載されたその他の記事