시가총액: $2.2006T 0.82%
거래량(24시간): $38.5475B -31.41%
  • 시가총액: $2.2006T 0.82%
  • 거래량(24시간): $38.5475B -31.41%
  • 공포와 탐욕 지수:
  • 시가총액: $2.2006T 0.82%
암호화
주제
암호화
소식
cryptostopics
비디오
최고의 뉴스
암호화
주제
암호화
소식
cryptostopics
비디오
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

암호화폐 뉴스 기사

중국 트레이더, 바이낸스 해킹 사기로 100만 달러 손실

2024/06/04 05:20

한 중국 거래자는 Aggr이라는 홍보용 Google Chrome 플러그인과 관련된 해킹 사기의 피해를 입은 후 100만 달러를 잃었습니다.

중국 트레이더, 바이낸스 해킹 사기로 100만 달러 손실

A Chinese cryptocurrency trader has lost $1 million in a hacking scam perpetrated through a promotional Google Chrome plugin called Aggr. The plugin reportedly stole cookies from users, enabling hackers to bypass password and two-factor authentication (2FA) verification to access the victim’s Binance account.

중국의 암호화폐 거래자는 Aggr이라는 홍보용 Google Chrome 플러그인을 통해 발생한 해킹 사기로 인해 백만 달러를 잃었습니다. 이 플러그인은 사용자로부터 쿠키를 훔쳐 해커가 비밀번호와 2단계 인증(2FA) 확인을 우회하여 피해자의 바이낸스 계정에 접근할 수 있게 한 것으로 알려졌습니다.

The trader, who goes by the handle CryptoNakamao on social media platform X, recounted the incident, which occurred on May 24. He noticed unusual trading activity in his Binance account after checking the Bitcoin price on the Binance app. By the time he sought assistance, the hacker had already withdrawn all the funds.

소셜 미디어 플랫폼 X에서 CryptoNakamao라는 이름을 사용하는 트레이더는 5월 24일에 발생한 사건에 대해 설명했습니다. 그는 바이낸스 앱에서 비트코인 ​​가격을 확인한 후 자신의 바이낸스 계정에서 비정상적인 거래 활동을 발견했습니다. 그가 도움을 구했을 때 해커는 이미 모든 자금을 인출했습니다.

The trader claimed that the hackers accessed his web browser cookie data through the Aggr Chrome plugin. He had installed the plugin to gain insights from prominent traders, unaware that it was designed to steal browsing data and cookies. The hackers used the stolen cookies to hijack active user sessions without needing passwords or authentication, enabling them to carry out multiple leveraged trades and profit by manipulating low liquidity trading pairs.

거래자는 해커가 Aggr Chrome 플러그인을 통해 자신의 웹 브라우저 쿠키 데이터에 접근했다고 주장했습니다. 그는 저명한 거래자들로부터 통찰력을 얻기 위해 플러그인을 설치했지만, 이 플러그인이 검색 데이터와 쿠키를 훔치도록 설계되었다는 사실을 알지 못했습니다. 해커는 훔친 쿠키를 사용하여 비밀번호나 인증 없이 활성 사용자 세션을 하이재킹하여 유동성이 낮은 거래 쌍을 조작하여 여러 레버리지 거래를 수행하고 수익을 얻을 수 있도록 했습니다.

Despite the hacker's inability to directly withdraw funds due to 2FA, they used the cookies and active login sessions to execute trades. The hacker bought several tokens in the Tether (USDT) trading pair with high liquidity and placed limit sell orders at inflated prices in Bitcoin (BTC), USD Coin (USDC), and other low liquidity trading pairs. They then opened leveraged positions, bought large amounts, and completed cross-trading. Cross-trading involves offsetting buy and sell orders for the same asset without recording the trade on the exchange.

2FA로 인해 해커가 직접 자금을 인출할 수 없음에도 불구하고 그들은 쿠키와 활성 로그인 세션을 사용하여 거래를 실행했습니다. 해커는 유동성이 높은 테더(USDT) 거래 쌍에서 여러 토큰을 구입하고 비트코인(BTC), USD 코인(USDC) 및 기타 유동성이 낮은 거래 쌍에서 부풀려진 가격으로 제한 판매 주문을 했습니다. 그런 다음 레버리지 포지션을 개설하고 대량 구매하고 교차 거래를 완료했습니다. 교차 거래에는 거래소에 거래를 기록하지 않고 동일한 자산에 대한 매수 및 매도 주문을 상쇄하는 것이 포함됩니다.

Accusations Against Binance

바이낸스에 대한 비난

The trader accused Binance of failing to implement necessary security measures despite the unusually high trading activity on his account. He also claimed that the exchange did not take timely action even after he reported the issue. According to the trader, Binance was aware of the fraudulent plugin and was conducting an internal investigation but did not inform users or take preventive measures.

거래자는 바이낸스가 자신의 계정에서 비정상적으로 높은 거래 활동에도 불구하고 필요한 보안 조치를 구현하지 못했다고 비난했습니다. 그는 또한 자신이 문제를 보고한 후에도 거래소가 적시에 조치를 취하지 않았다고 주장했다. 거래자에 따르면 바이낸스는 사기성 플러그인을 인지하고 내부 조사를 진행 중이었지만 사용자에게 알리거나 예방 조치를 취하지 않았습니다.

“Binance did nothing even though it knew of the theft and frequent cross-trading. Hackers manipulated accounts for over an hour, causing extremely abnormal transactions in multiple currency pairs without any risk control; Binance failed to freeze the funds of the obvious hacker’s single account on the platform in time,” the trader wrote.

“바이낸스는 도난과 잦은 교차 거래를 알고도 아무 조치도 취하지 않았습니다. 해커들은 한 시간 넘게 계정을 조작하여 위험 통제 없이 여러 통화 쌍에서 극도로 비정상적인 거래를 일으켰습니다. 바이낸스는 플랫폼에서 해커의 단일 계정 자금을 적시에 동결하지 못했습니다.”라고 거래자는 썼습니다.

Binance’s Response

바이낸스의 답변

Yi He, co-founder of Binance, refuted CryptoNakamao's claims and clarified the situation on social media, stating, “Look closely; this user's account was breached because their own computer was hacked; they are a lost cause. After the hack, the hacker could not withdraw funds, so the hacker sold the victim’s coins, which led to trading losses.”

바이낸스 공동 창업자인 허 이씨는 크립토나카마오의 주장을 반박하고 소셜미디어를 통해 “자세히 살펴보세요. 이 사용자의 계정은 자신의 컴퓨터가 해킹되었기 때문에 침해되었습니다. 그들은 잃어버린 원인입니다. 해킹 이후 해커는 자금을 인출할 수 없어 해커가 피해자의 코인을 매도해 거래 손실이 발생했다”고 설명했다.

“We sympathize with your experience, but according to the information we have learned so far, the reason for your asset loss is that your related devices were manipulated because of the installation of malicious plug-ins. Unfortunately, we have no way to compensate for such cases that have nothing to do with Binance,” the exchange stated.

“귀하의 경험에 공감하지만, 지금까지 파악한 정보에 따르면 자산 손실의 원인은 악성 플러그인 설치로 인해 관련 장치가 조작되었기 때문입니다. 아쉽게도 바이낸스와 무관한 사건에 대해서는 보상해드릴 방법이 없습니다.”라고 거래소는 밝혔다.

Nakamao, however, disputed Binance's assessment, alleging that the exchange had been aware of the malicious plugin for some time and had even encouraged a key opinion leader (KOL) to gather more information from the hacker.

그러나 나카마오는 바이낸스의 평가에 대해 이의를 제기하며 거래소가 한동안 악성 플러그인을 알고 있었으며 KOL(핵심 오피니언 리더)에게 해커로부터 더 많은 정보를 수집하도록 독려했다고 주장했습니다.

On her part, Yi He warned users about the dangers of logging into accounts with active cookie plugins to avoid the inconvenience of typing their passwords each time. “Binance is not able to compensate users when their own login devices are compromised,” she stated.

Yi He는 매번 비밀번호를 입력해야 하는 불편함을 피하기 위해 활성 쿠키 플러그인을 사용하여 계정에 로그인할 때의 위험성에 대해 사용자에게 경고했습니다. “바이낸스는 사용자의 로그인 장치가 손상되었을 때 사용자에게 보상할 수 없습니다.”라고 그녀는 말했습니다.

부인 성명:info@kdj.com

제공된 정보는 거래 조언이 아닙니다. kdj.com은 이 기사에 제공된 정보를 기반으로 이루어진 투자에 대해 어떠한 책임도 지지 않습니다. 암호화폐는 변동성이 매우 높으므로 철저한 조사 후 신중하게 투자하는 것이 좋습니다!

본 웹사이트에 사용된 내용이 귀하의 저작권을 침해한다고 판단되는 경우, 즉시 당사(info@kdj.com)로 연락주시면 즉시 삭제하도록 하겠습니다.

2026年07月27日 에 게재된 다른 기사