|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
블록체인 사이버 보안 회사인 Asymmetric Research는 Circle이 해결하지 않을 경우 막대한 손실을 초래할 수 있는 버그를 식별하는 데 도움을 주었습니다.

Blockchain cybersecurity firm Asymmetric Research has helped Circle identify a critical vulnerability that could've led to massive losses if not addressed. The vulnerability resided in Circle's Cross-Chain Transfer Protocol (CCTP) deployed on the Cosmos network, enabling the bridging of the firm's USDC stablecoin.
블록체인 사이버 보안 회사인 Asymmetric Research는 Circle이 해결하지 않을 경우 막대한 손실을 초래할 수 있는 중요한 취약점을 식별하는 데 도움을 주었습니다. 이 취약점은 Cosmos 네트워크에 배포된 Circle의 CCTP(Cross-Chain Transfer Protocol)에 존재하여 회사의 USDC 스테이블코인 연결을 가능하게 했습니다.
Asymmetric discovered the vulnerability in the noble-cctp module of the CCTP, which is used for cross-chain USDC transfers on the Cosmos-based Noble chain. The vulnerability allowed anyone to send a message to the CCTP, instructing it to burn (destroy) a specific amount of USDC tokens on the Cosmos Hub.
Asymmetric은 Cosmos 기반 Noble 체인에서 크로스체인 USDC 전송에 사용되는 CCTP의 Noble-cctp 모듈에서 취약점을 발견했습니다. 이 취약점으로 인해 누구나 CCTP에 메시지를 보내 코스모스 허브에서 특정 양의 USDC 토큰을 소각(파괴)하도록 지시할 수 있었습니다.
However, due to a faulty verification process, the CCTP would instead mint (create) the specified amount of USDC tokens on the Noble chain. This vulnerability could've been exploited to mint an "infinite" amount of USDC tokens on the Noble chain, as observed by Asymmetric.
그러나 잘못된 검증 프로세스로 인해 CCTP는 대신 Noble 체인에서 지정된 양의 USDC 토큰을 발행(생성)합니다. Asymmetric에서 관찰한 바와 같이 이 취약점은 Noble 체인에서 "무한한" 양의 USDC 토큰을 발행하는 데 악용될 수 있었습니다.
“We privately disclosed a vulnerability to Circle via their bug bounty program,” the security firm noted in its report. “Notably, no malicious exploitation took place, and no user funds were lost. Circle promptly took action, once notified, to fix the bug.”
보안 회사는 보고서에서 “우리는 버그 현상금 프로그램을 통해 Circle의 취약점을 비공개적으로 공개했습니다.”라고 밝혔습니다. “특히 악의적인 착취가 발생하지 않았으며 사용자 자금 손실도 없었습니다. Circle은 알림을 받은 후 즉시 버그 수정을 위한 조치를 취했습니다.”
The vulnerability could've enabled malicious actors to exploit the message sender verification process of the Noble Bridge, which is designed to ensure that only authorized parties (such as the TokenMessenger) can trigger USDC burns on the Cosmos Hub.
이 취약점으로 인해 악의적인 행위자가 Noble Bridge의 메시지 발신자 확인 프로세스를 악용할 수 있었습니다. 이는 승인된 당사자(예: TokenMessenger)만 Cosmos Hub에서 USDC 소각을 실행할 수 있도록 설계되었습니다.
This verification process is crucial to prevent unauthorized mints of USDC on the Noble chain. However, the verification was not being performed correctly, allowing anyone to send a message to the CCTP, instructing it to burn USDC on the Cosmos Hub.
이 검증 프로세스는 Noble 체인에서 USDC의 무단 발행을 방지하는 데 중요합니다. 그러나 검증이 올바르게 수행되지 않아 누구나 CCTP에 메시지를 보내 코스모스 허브에서 USDC를 소각하도록 지시할 수 있었습니다.
As a result, an attacker could've exploited this vulnerability and triggered malicious USDC mints by sending a fake BurnMessage directly through a CCTP MessageTransmitter contract, using the noble-cctp module address and noble's chainid as the CCTP destination.
결과적으로 공격자는 이 취약점을 악용하고 noble-cctp 모듈 주소와 noble의 체인 ID를 CCTP 대상으로 사용하여 CCTP MessageTransmitter 계약을 통해 직접 가짜 BurnMessage를 보내 악성 USDC 민트를 트리거할 수 있었습니다.
“However, we did not identify any evidence of exploitation,” Asymmetric stated in its findings, adding that the vulnerability was patched quickly by Circle.
Asymmetric은 조사 결과에서 “그러나 우리는 악용의 증거를 확인하지 못했습니다.”라고 밝혔으며 Circle은 해당 취약점을 신속하게 패치했다고 덧붙였습니다.
Infinite Money Glitch at First Assumption
첫 번째 가정에서 무한한 돈 결함
Asymmetric initially observed that attackers could've exploited this vulnerability to mint as many USDC tokens as they wanted, which seemed like an "infinite money glitch" at first glance.
Asymmetric은 처음에 공격자가 이 취약점을 악용하여 원하는 만큼 많은 USDC 토큰을 발행할 수 있다는 것을 관찰했는데, 이는 언뜻 보기에 "무한한 자금 결함"처럼 보였습니다.
However, upon further investigation, they discovered that Noble enforced a mint limit of around 35 million USDC, preventing attackers from minting an unlimited amount of tokens. While this mint limit significantly reduced the potential impact of the vulnerability, it remained a critical issue that needed to be addressed promptly.
그러나 추가 조사를 통해 Noble이 약 3,500만 USDC의 발행 한도를 적용하여 공격자가 무제한의 토큰을 발행하는 것을 방지한다는 사실을 발견했습니다. 이 민트 한도는 취약점의 잠재적 영향을 크게 줄였지만 즉시 해결해야 하는 중요한 문제로 남아 있습니다.
Fortunately, thanks to Asymmetric's discovery and Circle's swift response, the vulnerability was patched before any malicious exploitation occurred. Additionally, no tokens were minted out of thin air, and no Noble Bridge users lost their funds.
다행히 Asymmetric의 발견과 Circle의 신속한 대응 덕분에 악의적인 공격이 발생하기 전에 취약점이 패치되었습니다. 또한, 어떤 토큰도 허공에서 발행되지 않았으며 Noble Bridge 사용자는 자금을 잃지 않았습니다.
This incident highlights the importance of regular security audits and vulnerability scanning to identify and address potential risks in blockchain protocols and applications, especially those handling large volumes of user funds.
이 사건은 블록체인 프로토콜 및 애플리케이션, 특히 대규모 사용자 자금을 처리하는 애플리케이션의 잠재적 위험을 식별하고 해결하기 위해 정기적인 보안 감사 및 취약성 검색의 중요성을 강조합니다.
부인 성명:info@kdj.com
제공된 정보는 거래 조언이 아닙니다. kdj.com은 이 기사에 제공된 정보를 기반으로 이루어진 투자에 대해 어떠한 책임도 지지 않습니다. 암호화폐는 변동성이 매우 높으므로 철저한 조사 후 신중하게 투자하는 것이 좋습니다!
본 웹사이트에 사용된 내용이 귀하의 저작권을 침해한다고 판단되는 경우, 즉시 당사(info@kdj.com)로 연락주시면 즉시 삭제하도록 하겠습니다.

































