|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
탈중앙화 금융 프로토콜인 Convergence는 8월 1일 스마트 계약 익스플로잇을 통해 해킹당했으며 해커가 2억 1천만 달러를 채굴하고 판매했음을 확인했습니다.

DeFi protocol Convergence has confirmed that it was hacked via a smart contract exploit on Aug. 1, with the attacker minting and selling $210 million in its native token, as well as stealing $2,000 in unclaimed staking rewards.
DeFi 프로토콜 Convergence는 8월 1일 스마트 계약 익스플로잇을 통해 해킹당했음을 확인했습니다. 공격자는 기본 토큰으로 2억 1천만 달러를 주조하고 판매했으며 청구되지 않은 스테이킹 보상으로 2,000달러를 훔쳤습니다.
According to a post-mortem from Wireshark, the pseudonymous founder of the Convergence protocol, the attacker exploited the protocol’s CvxRewardDistributor contract, allowing them to mint and sell 58 million CVG tokens for approximately $210,000.
Convergence 프로토콜의 가명 창립자인 Wireshark의 사후 분석에 따르면, 공격자는 프로토콜의 CvxRewardDistributor 계약을 악용하여 약 210,000달러에 5,800만 개의 CVG 토큰을 발행하고 판매할 수 있었습니다.
The attacker also stole approximately $2,000 of unclaimed rewards from Convex, a DeFi protocol designed to maximize rewards for Curve liquidity providers.
공격자는 또한 Curve 유동성 공급자에 대한 보상을 극대화하도록 설계된 DeFi 프로토콜인 Convex에서 청구되지 않은 보상 중 약 2,000달러를 훔쳤습니다.
According to Etherscan, the attack occurred on Aug. 1 at around 3:00 am UTC.
Etherscan에 따르면 공격은 8월 1일 오전 3시(UTC)쯤에 발생했습니다.
Blockchain security firm PeckShield noted that after minting the CVG tokens, the attacker quickly swapped it into 60 wrapped-Ether and 15,900 Curve.fi FRAX.
블록체인 보안 회사인 PeckShield는 공격자가 CVG 토큰을 발행한 후 이를 래핑된 Ether 60개와 Curve.fi FRAX 15,900개로 빠르게 교환했다고 밝혔습니다.
The movements have since led to a near-100% price wipeout of the CVG governance token, which is now trading at $0.0004 with a market cap of just $57,000, CoinMarketCap data shows.
이후 이러한 움직임으로 인해 CVG 거버넌스 토큰의 가격이 거의 100% 전멸되었으며, 현재 시가총액은 $57,000에 불과하며 $0.0004에 거래되고 있다고 CoinMarketCap 데이터가 보여줍니다.
Convergence said the attack was possible because the team accidentally removed an essential line of code in its smart contract, which distributes CVG staking rewards. They made the change after the smart contract code was audited four times.
컨버전스는 팀이 CVG 스테이킹 보상을 분배하는 스마트 계약에서 필수 코드 라인을 실수로 제거했기 때문에 공격이 가능했다고 말했습니다. 그들은 스마트 계약 코드를 4번 감사한 후에 변경했습니다.
“The modification (gas-optimization on the first hand) led us to remove the line of code that was checking the input given to the function,” it explained.
“수정(처음에는 가스 최적화)으로 인해 함수에 제공된 입력을 확인하는 코드 줄을 제거하게 되었습니다.”라고 설명했습니다.
The attacker used this to exploit the CvxRewardDistributor contract through the claimMultipleStaking function.
공격자는 이를 이용해 ClaimMultipleStake 함수를 통해 CvxRewardDistributor 계약을 악용했습니다.
This meant the staking contract couldn’t be validated, allowing the attacker to pass a separate malicious contract with the same signature as the claimCvgCvxMultiple function.
이는 스테이킹 계약을 검증할 수 없어 공격자가 ClaimCvgCvxMultiple 함수와 동일한 서명을 사용하여 별도의 악성 계약을 전달할 수 있음을 의미합니다.
The attacker then minted all tokens dedicated to staking emissions and then dumped them into CVG liquidity pools, Convergence said.
그런 다음 공격자는 배출 스테이킹 전용 토큰을 모두 발행한 다음 이를 CVG 유동성 풀에 버렸다고 Convergence는 말했습니다.
Convergence says that user funds are safe, but has recommended users withdraw assets from the platform.
컨버전스는 사용자 자금이 안전하다고 말하지만 사용자에게 플랫폼에서 자산을 인출할 것을 권장했습니다.
“Due to the exploit, the rewards contract for the Stake DAO integration is currently broken. It will be fixed, and stakers will be able to claim their rewards once it’s done. No rewards are lost for Stake DAO integration users," it said.
“악용으로 인해 Stake DAO 통합에 대한 보상 계약이 현재 중단되었습니다. 이 문제는 수정될 예정이며, 작업이 완료되면 스테이커는 보상을 청구할 수 있습니다. Stake DAO 통합 사용자에게는 보상이 손실되지 않습니다."라고 말했습니다.
Convergence works to aggregate liquidity, boost returns and enable liquid locking across the Curve Finance ecosystem.
컨버전스는 유동성을 집계하고 수익을 높이며 Curve Finance 생태계 전반에 걸쳐 유동성 잠금을 활성화합니다.
The total value locked on Convergence fell from $5.79 million to $3.69 million, DefiLlama data shows.
DefiLlama 데이터에 따르면 Convergence에 고정된 총 가치는 579만 달러에서 369만 달러로 감소했습니다.
The cryptocurrency ecosystem lost around $266 million to hacks in July, mostly coming from the $230 million hack of Indian trading platform WazirX on July 18.
암호화폐 생태계는 7월 해킹으로 약 2억 6,600만 달러의 손실을 입었으며, 대부분은 7월 18일 인도 거래 플랫폼 WazirX의 2억 3,000만 달러 해킹에서 발생했습니다.
부인 성명:info@kdj.com
제공된 정보는 거래 조언이 아닙니다. kdj.com은 이 기사에 제공된 정보를 기반으로 이루어진 투자에 대해 어떠한 책임도 지지 않습니다. 암호화폐는 변동성이 매우 높으므로 철저한 조사 후 신중하게 투자하는 것이 좋습니다!
본 웹사이트에 사용된 내용이 귀하의 저작권을 침해한다고 판단되는 경우, 즉시 당사(info@kdj.com)로 연락주시면 즉시 삭제하도록 하겠습니다.

































