시가총액: $2.2006T 0.82%
거래량(24시간): $38.5475B -31.41%
  • 시가총액: $2.2006T 0.82%
  • 거래량(24시간): $38.5475B -31.41%
  • 공포와 탐욕 지수:
  • 시가총액: $2.2006T 0.82%
암호화
주제
암호화
소식
cryptostopics
비디오
최고의 뉴스
암호화
주제
암호화
소식
cryptostopics
비디오
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

암호화폐 뉴스 기사

컨버전스 프로토콜은 해커가 기본 토큰으로 2억 1천만 달러를 주조하고 판매하면서 8월 1일 스마트 계약 악용을 통해 해킹당했음을 확인했습니다.

2024/08/02 12:02

암호화폐 생태계는 7월 해킹으로 인해 약 2억 6,600만 달러의 손실을 입었으며, 이는 대부분 인도 거래 플랫폼 WazirX의 2억 3,000만 달러 해킹에서 발생했습니다.

컨버전스 프로토콜은 해커가 기본 토큰으로 2억 1천만 달러를 주조하고 판매하면서 8월 1일 스마트 계약 악용을 통해 해킹당했음을 확인했습니다.

Decentralized finance (DeFi) protocol Convergence has confirmed that it was exploited via a smart contract vulnerability on Aug. 1, allowing a hacker to mint and sell $210,000,000 in its native token, as well as pilfer $2,000 in unclaimed staking rewards.

탈중앙화 금융(DeFi) 프로토콜 Convergence는 8월 1일 스마트 계약 취약점을 통해 악용되어 해커가 기본 토큰으로 2억 1천만 달러를 발행하고 판매할 수 있을 뿐만 아니라 청구되지 않은 스테이킹 보상으로 2,000달러를 훔칠 수 있음을 확인했습니다.

According to a new post-mortem from Wireshark, the pseudonymous founder of the Convergence protocol, the attacker exploited the protocol’s CvxRewardDistributor contract, enabling them to mint and sell 58,000,000 CVG tokens for roughly $210,000.

Convergence 프로토콜의 가명 창립자인 Wireshark의 새로운 사후 분석에 따르면, 공격자는 프로토콜의 CvxRewardDistributor 계약을 악용하여 약 210,000달러에 58,000,000개의 CVG 토큰을 발행하고 판매할 수 있었습니다.

The attacker also stole about $2,000 in unclaimed rewards from Convex, a DeFi protocol designed to maximize rewards for Curve liquidity providers.

공격자는 또한 Curve 유동성 공급자에 대한 보상을 극대화하도록 설계된 DeFi 프로토콜인 Convex에서 청구되지 않은 보상으로 약 2,000달러를 훔쳤습니다.

According to Etherscan, the attack occurred on Aug. 1 at around 3:00 am UTC.

Etherscan에 따르면 공격은 8월 1일 오전 3시(UTC)쯤에 발생했습니다.

Blockchain security firm PeckShield noted that after minting the CVG tokens, the attacker quickly swapped it into 60 wrapped-Ether and 15,900 Curve.fi FRAX.

블록체인 보안 회사인 PeckShield는 공격자가 CVG 토큰을 발행한 후 이를 래핑된 Ether 60개와 Curve.fi FRAX 15,900개로 빠르게 교환했다고 밝혔습니다.

The movements have since led to a near-100% price wipeout of the CVG governance token, which is now trading at $0.0004 with a market cap of just $57,000, according to CoinMarketCap data.

이후 이러한 움직임으로 인해 CVG 거버넌스 토큰의 가격이 거의 100% 전멸되었습니다. CoinMarketCap 데이터에 따르면 CVG 거버넌스 토큰은 현재 시가총액 57,000달러에 0.0004달러에 거래되고 있습니다.

Convergence said the attack was enabled by the team accidentally deleting a crucial line of code in its smart contract that distributes CVG staking rewards. They made the change after the smart contract code was audited four times.

Convergence는 팀이 CVG 스테이킹 보상을 분배하는 스마트 계약에서 중요한 코드 라인을 실수로 삭제함으로써 공격이 가능해졌다고 말했습니다. 그들은 스마트 계약 코드를 4번 감사한 후에 변경했습니다.

“The modification (gas-optimization on the first hand) led us to remove the line of code that was checking the input given to the function,” it explained.

“수정(처음에는 가스 최적화)으로 인해 함수에 제공된 입력을 확인하는 코드 줄을 제거하게 되었습니다.”라고 설명했습니다.

The attacker used this to exploit the CvxRewardDistributor contract through the claimMultipleStaking function.

공격자는 이를 이용해 ClaimMultipleStake 함수를 통해 CvxRewardDistributor 계약을 악용했습니다.

This meant the staking contract couldn’t be validated, allowing the attacker to pass a separate malicious contract with the same signature as the claimCvgCvxMultiple function.

이는 스테이킹 계약을 검증할 수 없어 공격자가 ClaimCvgCvxMultiple 함수와 동일한 서명을 사용하여 별도의 악성 계약을 전달할 수 있음을 의미합니다.

The attacker then minted all tokens dedicated to staking emissions and then dumped them into CVG liquidity pools, Convergence said.

그런 다음 공격자는 배출 스테이킹 전용 토큰을 모두 발행한 다음 이를 CVG 유동성 풀에 버렸다고 Convergence는 말했습니다.

Related: Over 70% of hacked funds are lost to CeFi entities — Cyvers

관련: 해킹된 자금의 70% 이상이 CeFi 기업에 손실됩니다 — Cyvers

Convergence says that user funds are safe, but has advised users to withdraw assets from the platform.

컨버전스는 사용자 자금은 안전하지만 사용자에게 플랫폼에서 자산을 인출할 것을 권고했다고 밝혔습니다.

“Due to the exploit, the rewards contract for the Stake DAO integration is currently broken. It will be fixed, and stakers will be able to claim their rewards once it’s done. No rewards are lost for Stake DAO integration users,” it said.

“악용으로 인해 Stake DAO 통합에 대한 보상 계약이 현재 중단되었습니다. 이 문제는 수정될 예정이며, 작업이 완료되면 스테이커는 보상을 청구할 수 있습니다. Stake DAO 통합 사용자에게는 보상이 손실되지 않습니다.”라고 말했습니다.

Convergence works to aggregate liquidity, boost returns and enable liquid locking across the Curve Finance ecosystem.

컨버전스는 유동성을 집계하고 수익을 높이며 Curve Finance 생태계 전반에 걸쳐 유동성 잠금을 활성화합니다.

The total value locked on Convergence fell from $5.79 million to $3.69 million, DefiLlama data shows.

DefiLlama 데이터에 따르면 Convergence에 고정된 총 가치는 579만 달러에서 369만 달러로 감소했습니다.

The cryptocurrency ecosystem lost around $266 million to hacks in July, largely due to the $230 million hack of Indian trading platform WazirX on July 18.

암호화폐 생태계는 7월 해킹으로 인해 약 2억 6,600만 달러의 손실을 입었습니다. 이는 주로 7월 18일 인도 거래 플랫폼 WazirX의 2억 3천만 달러 해킹으로 인해 발생했습니다.

Magazine: THORChain founder and his plan to ‘vampire attack’ all of DeFi

매거진: THORChain 창립자와 DeFi 전체를 '뱀파이어 공격'하려는 그의 계획

원본 소스:cointelegraph

부인 성명:info@kdj.com

제공된 정보는 거래 조언이 아닙니다. kdj.com은 이 기사에 제공된 정보를 기반으로 이루어진 투자에 대해 어떠한 책임도 지지 않습니다. 암호화폐는 변동성이 매우 높으므로 철저한 조사 후 신중하게 투자하는 것이 좋습니다!

본 웹사이트에 사용된 내용이 귀하의 저작권을 침해한다고 판단되는 경우, 즉시 당사(info@kdj.com)로 연락주시면 즉시 삭제하도록 하겠습니다.

2026年07月27日 에 게재된 다른 기사