|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Solana ミームコイン プラットフォームの Pump.fun は、元従業員が「ボンディング カーブ」攻撃を通じてプラットフォームを 190 万ドルで悪用したと主張しています。犯人は特権アクセスを利用してプロトコルの流動性を操作し、Raydium から資金を借りてpump.fun でコインを購入するために使用し、取得した流動性でローンを返済しました。

Solana Memecoin Platform Pump.fun Alleges $2 Million Exploitation by Former Employee
Solana Memecoin プラットフォーム Pump.fun、元従業員による 200 万ドルの搾取を主張
In a startling revelation, Solana-based memecoin creation tool, Pump.fun, has publicly accused a former employee of exploiting the platform for approximately $2 million through a meticulously executed "bonding curve" attack.
驚くべき事実として、Solana ベースのミームコイン作成ツール、Pump.fun は、細心の注意を払って実行された「ボンディング カーブ」攻撃を通じてプラットフォームを約 200 万ドル悪用したとして元従業員を公に告発しました。
Details of the Exploit
エクスプロイトの詳細
According to Pump.fun's official statement released on May 16, the perpetrator, allegedly an ex-employee, exploited their privileged access to a "withdraw authority" mechanism, enabling them to manipulate the platform's internal systems.
Pump.funが5月16日に発表した公式声明によると、元従業員とされる犯人は「権限の撤回」メカニズムへの特権アクセスを悪用し、プラットフォームの内部システムを操作できるようにしたという。
The attack unfolded strategically. The individual leveraged flash loans from Raydium, a Solana lending protocol, to acquire a substantial amount of Solana tokens. These tokens were then utilized to purchase as many memecoins as possible on Pump.fun.
攻撃は戦略的に展開された。この人物は、Solana 融資プロトコルである Raydium のフラッシュ ローンを利用して、相当量の Solana トークンを取得しました。これらのトークンは、Pump.fun でできるだけ多くのミームコインを購入するために利用されました。
As these memecoins reached their maximum value on their respective bonding curves, the exploiter accessed the liquidity within the bonding curves to repay the flash loans, leaving them with a net profit of approximately 12,300 SOL, valued at $1.9 million at the time of the incident. The entire operation was confined to a short window between 3:21 pm and 5:00 pm UTC on May 16.
これらのミームコインがそれぞれの結合曲線で最高値に達すると、悪用者はフラッシュ ローンを返済するために結合曲線内の流動性にアクセスし、事件当時の価値で 190 万ドルに相当する約 12,300 SOL の純利益を残しました。作戦全体は、協定世界時で 5 月 16 日の午後 3 時 21 分から午後 5 時までの短い時間枠に限定されていました。
Platform Response and Investigations
プラットフォームの対応と調査
Following the discovery of the attack, Pump.fun promptly suspended trading on its platform. However, trading has since resumed. The platform has provided assurances that its smart contracts remain intact and that affected users will receive a full refund of their liquidity within 24 hours.
攻撃の発見後、Pump.fun は直ちにプラットフォームでの取引を停止しました。しかし、その後取引は再開された。このプラットフォームは、スマートコントラクトがそのまま残り、影響を受けるユーザーが24時間以内に流動性の全額を返金されることを保証しています。
Igor Igamberdiev, Head of Research at Wintermute, a prominent cryptocurrency market maker, initially suggested that the hack could be attributed to the leak of an internal private key, implicating a specific Pump.fun user known as "STACCoverflow." A series of cryptic posts by STACCoverflow seemingly acknowledged their involvement, expressing a nonchalant attitude towards the consequences and stating that they were "already fully doxxed."
著名な仮想通貨マーケットメーカーであるウィンターミュート社の研究責任者であるイゴール・イガンベルディエフ氏は当初、このハッキングは内部秘密鍵の漏洩に起因する可能性があり、「STACCoverflow」として知られる特定のPump.funユーザーが関与している可能性があると示唆した。 STACCoverflowによる一連の不可解な投稿は、彼らの関与を認めているようで、その結果に対する平然とした態度を表明し、彼らは「すでに完全に特定されている」と述べた。
Pump.fun has confirmed that it is closely collaborating with law enforcement authorities in their investigation but has refrained from disclosing the identity of the former employee involved. The platform has also not responded to immediate requests for further clarification.
Pump.fun は、捜査において法執行機関と緊密に協力していることを認めたが、関与した元従業員の身元を明らかにすることは控えている。同プラットフォームはさらなる説明を求める即時要請にも応じていない。
Market Impact and Lessons Learned
市場への影響と学んだ教訓
The Pump.fun exploit has sent shockwaves through the cryptocurrency community, highlighting the ongoing vulnerabilities associated with DeFi (decentralized finance) platforms. The incident underscores the critical need for comprehensive security measures and stringent internal controls within DeFi protocols.
Pump.fun エクスプロイトは暗号通貨コミュニティに衝撃を与え、DeFi (分散型金融) プラットフォームに関連する現在進行中の脆弱性を浮き彫りにしました。この事件は、DeFiプロトコル内の包括的なセキュリティ対策と厳格な内部統制の重要な必要性を浮き彫りにしました。
As the investigation continues, it is imperative that lessons are learned to enhance the overall security posture of the emerging DeFi ecosystem. Robust risk management frameworks, thorough code audits, and robust governance mechanisms are crucial to prevent similar incidents in the future.
調査が続くにつれて、新興の DeFi エコシステムの全体的なセキュリティ体制を強化するための教訓を学ぶことが不可欠です。将来の同様のインシデントを防ぐには、堅牢なリスク管理フレームワーク、徹底的なコード監査、および堅牢なガバナンス メカニズムが不可欠です。
免責事項:info@kdj.com
提供される情報は取引に関するアドバイスではありません。 kdj.com は、この記事で提供される情報に基づいて行われた投資に対して一切の責任を負いません。暗号通貨は変動性が高いため、十分な調査を行った上で慎重に投資することを強くお勧めします。
このウェブサイトで使用されているコンテンツが著作権を侵害していると思われる場合は、直ちに当社 (info@kdj.com) までご連絡ください。速やかに削除させていただきます。

































