|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
融資プロトコル Sonne Finance がサイバー攻撃の被害に遭い、2,000 万ドルの仮想通貨が盗まれました。攻撃者は Sonne の Compound v2 フォークのバグを悪用し、Wrapped Ether (WETH)、VELO、soVELO、および Wrapped USDC を盗みました。ハッカーが盗まれた資金を取り戻すためのバグ報奨金の検討など、捜査が進行中である。努力にもかかわらず、ハッカーはすでに盗まれた資産のかなりの部分を洗浄しており、回復は困難です。

Sonne Finance Hack Exposes $20 Million Cryptocurrency Theft, Raising Concerns About Security Practices
Sonne Finance のハッキングで 2,000 万ドルの暗号通貨盗難が明らかになり、セキュリティ慣行に対する懸念が高まる
In a brazen cyberattack that has sent shockwaves through the cryptocurrency community, lending protocol Sonne Finance has been forced to suspend operations after suffering a hack that siphoned $20 million worth of digital assets from the market. The incident has raised serious questions about the security protocols employed by cryptocurrency platforms and the potential risks faced by investors.
暗号通貨コミュニティに衝撃を与えた厚かましいサイバー攻撃で、融資プロトコルのゾンネ・ファイナンスは、市場から2000万ドル相当のデジタル資産を吸い上げるハッキング被害を受け、業務停止を余儀なくされた。この事件は、暗号通貨プラットフォームで採用されているセキュリティプロトコルと投資家が直面する潜在的なリスクについて深刻な疑問を引き起こしました。
On May 14th, around 10:30 pm UTC, Web3 security firm Cyvers detected a sophisticated attack targeting Sonne Finance's USD Coin (USDC) and Wrapped Ether (WETH) contracts. However, by the time Sonne Finance became aware of the situation 25 minutes later, the hacker had already stolen a substantial amount of cryptocurrency, including $20 million in WETH, VELO, soVELO, and Wrapped USDC.
5 月 14 日、協定世界時午後 10 時 30 分頃、Web3 セキュリティ会社 Cyvers は、Sonne Finance の USD Coin (USDC) および Wrapped Ether (WETH) 契約をターゲットとした高度な攻撃を検出しました。しかし、Sonne Finance が 25 分後に状況に気づいたときには、ハッカーはすでに WETH、VELO、soVELO、Wrapped USDC の 2,000 万ドルを含む相当量の暗号通貨を盗んでいました。
"All markets on Optimism have been paused," Sonne Finance announced on Twitter shortly after learning of the breach. The protocol immediately partnered with Cyvers to investigate the incident and determine the extent of the damage.
ゾンネ・ファイナンスは侵害を知った直後、「オプティミズム上のすべての市場が停止された」とツイッターで発表した。プロトコルは直ちにサイバースと提携して事件を調査し、被害の程度を特定しました。
Stolen Funds Disappear into the Blockchain
盗まれた資金はブロックチェーンに消える
Sonne Finance is actively exploring all options to recover the stolen funds, including negotiating a bug bounty with the hacker. In such arrangements, the hacker typically returns the majority of the stolen funds and keeps a portion as a reward for discovering a security flaw.
Sonne Finance は、ハッカーとバグ報奨金の交渉を行うなど、盗まれた資金を取り戻すためのあらゆる選択肢を積極的に検討しています。このような取り決めでは、ハッカーは通常、盗んだ資金の大部分を返し、セキュリティ上の欠陥を発見した報酬として一部を保持します。
However, the hacker behind the Sonne Finance attack appears uninterested in negotiations. According to blockchain investigator PeckShield, the exploiter has already moved $7.8 million of the stolen funds to a new wallet address.
しかし、Sonne Finance 攻撃の背後にいるハッカーは交渉に興味がないようです。ブロックチェーン調査官ペックシールドによると、悪用者はすでに盗まれた資金のうち780万ドルを新しいウォレットアドレスに移動させているという。
The hacker then exchanged 59 WBTC for approximately 1,185 ETH and 183,000 Dai. This move suggests an attempt to launder the stolen funds through a privacy protocol like Tornado Cash, making them difficult to trace.
その後、ハッカーは 59 WBTC を約 1,185 ETH と 183,000 Dai に交換しました。この動きは、Tornado Cashのようなプライバシープロトコルを通じて盗まれた資金を洗浄しようとする試みを示唆しており、追跡を困難にしています。
Sonne Finance's Security Lapses Questioned
Sonne Finance のセキュリティー失効に疑問の声
A post-mortem analysis conducted by Sonne Finance revealed that a donation attack was executed against the protocol's Compound v2 forks, which reportedly had a known vulnerability. Community member PoorBabyCorn accused Sonne Finance of using Compound v2 despite being aware of these risks and questioned whether this constituted "a premeditated backdoor."
Sonne Finance が実施した事後分析により、既知の脆弱性があると伝えられているプロトコルの Compound v2 フォークに対して寄付攻撃が実行されたことが明らかになりました。コミュニティメンバーのPoorBabyCorn氏は、Sonne Financeがこうしたリスクを承知していたにもかかわらずCompound v2を使用していると非難し、これが「計画的なバックドア」にあたるのではないかと疑問を呈した。
BlockTower Capital Hedge Fund Also Targeted
ブロックタワー・キャピタル・ヘッジファンドも標的に
Concurrently with the Sonne Finance attack, reports emerged that the main hedge fund of crypto institutional investment firm BlockTower Capital had also been exploited and partially drained. The stolen funds, whose value has not been disclosed, have not been recovered.
Sonne Finance 攻撃と同時に、仮想通貨機関投資家 BlockTower Capital の主要ヘッジファンドも悪用され、一部資金が流出したとの報告が浮上した。盗まれた資金は価値が明らかにされていないが、まだ回収されていない。
BlockTower has enlisted the services of blockchain forensic analysts to trace the stolen funds and investigate the security breach. The exploiter remains at large, according to Bloomberg, citing sources familiar with the situation.
BlockTower は、ブロックチェーンフォレンジックアナリストのサービスを利用して、盗まれた資金を追跡し、セキュリティ侵害を調査しました。ブルームバーグが状況に詳しい情報筋の話として伝えたところによると、搾取者は依然として逃走中だという。
BlockTower's Previous Exploit
BlockTower の以前の悪用
In February 2022, BlockTower reportedly lost around $1.5 million in an exploit targeting the multichain exchange aggregator Dexible. On-chain intelligence platform Arkham Intelligence linked a wallet drained of $1.5 million to BlockTower, suggesting that the firm was significantly impacted by the Dexible attack.
2022年2月、BlockTowerはマルチチェーン取引所アグリゲーターのDexibleを標的としたエクスプロイトで約150万ドルを失ったと伝えられている。オンチェーンインテリジェンスプラットフォームのArkham Intelligenceは、150万ドルが流出したウォレットをBlockTowerにリンクしており、同社がDexible攻撃によって大きな影響を受けたことを示唆している。
Industry Concerns and Lessons Learned
業界の懸念と学んだ教訓
The Sonne Finance and BlockTower Capital hacks serve as stark reminders of the ongoing cybersecurity threats faced by the cryptocurrency industry. These incidents highlight the need for robust security protocols, thorough due diligence, and constant vigilance against malicious actors.
Sonne Finance と BlockTower Capital のハッキングは、仮想通貨業界が直面している継続的なサイバーセキュリティの脅威をはっきりと思い出させます。これらのインシデントは、堅牢なセキュリティ プロトコル、徹底したデュー デリジェンス、悪意のある行為者に対する継続的な警戒の必要性を浮き彫りにしています。
As the cryptocurrency ecosystem continues to grow and evolve, it is imperative for exchanges, protocols, and institutional investors to invest in state-of-the-art security measures to protect their assets and the trust of their customers. The industry must also prioritize collaboration and information sharing to enhance collective preparedness against cyberattacks.
暗号通貨エコシステムが成長と進化を続ける中、取引所、プロトコル、機関投資家にとって、資産と顧客の信頼を保護するために最先端のセキュリティ対策に投資することが不可欠です。業界はまた、サイバー攻撃に対する集団的な備えを強化するために、コラボレーションと情報共有を優先する必要があります。
The consequences of security breaches can be severe, not only in terms of financial losses but also in reputational damage and erosion of investor confidence. By adopting best practices, implementing robust security frameworks, and promoting a proactive approach to cybersecurity, the cryptocurrency industry can mitigate these risks and maintain its long-term viability.
セキュリティ侵害の影響は、経済的損失だけでなく、風評被害や投資家の信頼の低下という点でも深刻になる可能性があります。ベスト プラクティスを採用し、堅牢なセキュリティ フレームワークを実装し、サイバーセキュリティへの積極的なアプローチを促進することで、暗号通貨業界はこれらのリスクを軽減し、長期的な存続可能性を維持できます。
免責事項:info@kdj.com
提供される情報は取引に関するアドバイスではありません。 kdj.com は、この記事で提供される情報に基づいて行われた投資に対して一切の責任を負いません。暗号通貨は変動性が高いため、十分な調査を行った上で慎重に投資することを強くお勧めします。
このウェブサイトで使用されているコンテンツが著作権を侵害していると思われる場合は、直ちに当社 (info@kdj.com) までご連絡ください。速やかに削除させていただきます。

































