시가총액: $2.2006T 0.82%
거래량(24시간): $38.5475B -31.41%
  • 시가총액: $2.2006T 0.82%
  • 거래량(24시간): $38.5475B -31.41%
  • 공포와 탐욕 지수:
  • 시가총액: $2.2006T 0.82%
암호화
주제
암호화
소식
cryptostopics
비디오
최고의 뉴스
암호화
주제
암호화
소식
cryptostopics
비디오
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

암호화폐 뉴스 기사

Dough Finance Protocol, 플래시 대출 공격으로 196만 달러 손실

2024/07/13 13:00

또 다른 DeFi 프로토콜은 금요일 아침에 공격의 희생양이 되었습니다. 비수탁 유동성 시장을 창출하기 위한 오픈 소스 프로토콜인 Dough Finance

Dough Finance Protocol, 플래시 대출 공격으로 196만 달러 손실

DeFi protocol Dough Finance fell victim to a flash loan attack on Friday morning, leading to the theft of nearly $2 million in user funds. The project’s team announced they are working to resolve the situation promptly.

DeFi 프로토콜인 Dough Finance는 금요일 아침 플래시 대출 공격의 희생양이 되어 거의 200만 달러에 달하는 사용자 자금을 도난당했습니다. 프로젝트 팀은 상황을 즉시 해결하기 위해 노력하고 있다고 발표했습니다.

According to Web3 blockchain security platform Cyvers, it detected multiple suspicious transactions involving Dough Finance. The attacker manipulated the protocol's smart contract and stole $1.8 million in USDC.

Web3 블록체인 보안 플랫폼 Cyvers에 따르면 Dough Finance와 관련된 의심스러운 거래가 여러 건 감지되었습니다. 공격자는 프로토콜의 스마트 계약을 조작하여 USDC에서 180만 달러를 훔쳤습니다.

The attacker, funded through the zero-knowledge (ZK) protocol Railgun, swapped the misappropriated funds to Ethereum (ETH), initially obtaining 608 ETH.

영지식(ZK) 프로토콜 레일건(Railgun)을 통해 자금을 조달한 공격자는 유용된 자금을 이더리움(ETH)으로 교환하여 처음에 608 ETH를 획득했습니다.

However, further analysis by Web3 security provider Olympix revealed that the exploit occurred due to “calldata within the ConnectorDeleverageParaswap contract.” The report highlighted that the contract failed to adequately check the flash loan calls data.

그러나 Web3 보안 제공업체 Olympix의 추가 분석에 따르면 "ConnectorDeleverageParaswap 계약 내의 호출 데이터"로 인해 악용이 발생한 것으로 나타났습니다. 보고서는 계약이 플래시 대출 통화 데이터를 적절하게 확인하지 못했다는 점을 강조했습니다.

The unvalidated calldata allowed the exploiter to manipulate the contract's data and send the funds to an Externally Owned Account (EAO), enabling them to withdraw the stolen crypto.

확인되지 않은 호출 데이터를 통해 악용자는 계약 데이터를 조작하고 자금을 외부 소유 계정(EAO)으로 보내 훔친 암호화폐를 인출할 수 있었습니다.

Following the initial reports, a second batch of attacks occurred, leading to the loss of another $141,000 in USDC, raising the total crypto heist to $1.96 million.

초기 보고에 이어 두 번째 공격이 발생하여 USDC에서 추가로 141,000달러의 손실이 발생하여 총 암호화폐 강도 금액이 196만 달러로 증가했습니다.

However, lending protocol Aave's pools remained unaffected, according to Cyvers.

그러나 Cyvers에 따르면 대출 프로토콜 Aave의 풀은 영향을 받지 않은 상태로 유지되었습니다.

After the initial reports, the DeFi protocol acknowledged the attack and urged users to withdraw their remaining funds from the protocol. Later, Dough Finance announced it had identified and closed the exploit.

초기 보고 이후 DeFi 프로토콜은 공격을 인정하고 사용자에게 프로토콜에서 남은 자금을 인출할 것을 촉구했습니다. 나중에 Dough Finance는 이 공격을 식별하고 종료했다고 발표했습니다.

The project confirmed that “a few early Dough DeFi Smart Accounts (DSAs)” were victim to a sophisticated exploit.

이 프로젝트는 "초기 Dough DeFi 스마트 계정(DSA) 몇 개"가 정교한 공격의 희생양이 되었음을 확인했습니다.

In a statement, Dough Finance assured that its team is actively working to address the incident, aiming to recover the funds and making investors whole.

성명을 통해 Dough Finance 팀은 자금을 회수하고 투자자를 온전하게 만드는 것을 목표로 이 사건을 해결하기 위해 적극적으로 노력하고 있다고 확신했습니다.

Online reports also revealed that the team reached out to the exploiter through an on-chain message, offering to discuss a bounty if they had “exploited this vulnerability as a white or grey hat.”

온라인 보고서에 따르면 팀은 온체인 메시지를 통해 공격자에게 연락하여 "이 취약점을 흰색 또는 회색 모자로 악용"한 경우 보상금을 논의하겠다고 제안했습니다.

The message also included the address where the funds should be directly transferred if the exploiter wished to return the stolen crypto.

메시지에는 공격자가 훔친 암호화폐를 반환하려는 경우 자금을 직접 이체해야 하는 주소도 포함되어 있습니다.

The exploiter has until Monday, July 15, 2024, at 23:00 UTC to contact the DeFi protocol. If the team doesn't receive an answer, they will “assume you appropriated the funds with unlawful intent and will pursue all criminal, legal, and administrative avenues available” to recover the misappropriated funds.

공격자는 2024년 7월 15일 월요일 23:00 UTC까지 DeFi 프로토콜에 접속할 수 있습니다. 팀이 답변을 받지 못하면 "귀하가 불법적인 의도로 자금을 충당했다고 가정하고 유용된 자금을 회수하기 위해 가능한 모든 형사, 법률 및 행정적 수단을 모색할 것입니다".

This incident highlights the ongoing threat posed by scammers to the DeFi sector. Earlier this week, several DeFi projects, including Compound Finance, were compromised in a phishing attack.

이 사건은 사기꾼들이 DeFi 부문에 가하는 지속적인 위협을 강조합니다. 이번 주 초,Compound Finance를 포함한 여러 DeFi 프로젝트가 피싱 공격으로 손상되었습니다.

The projects were reportedly victims of a DNS domain attack, which redirected users to a fake website. The copy website functioned as a drainer tool, capable of draining users' funds if they interacted with it.

해당 프로젝트는 사용자를 가짜 웹사이트로 리디렉션하는 DNS 도메인 공격의 피해자인 것으로 알려졌습니다. 카피 웹사이트는 사용자가 상호 작용할 경우 자금을 고갈시킬 수 있는 배수 도구 역할을 했습니다.

As a result, the teams of the affected projects quickly urged customers not to interact with the websites until further notice, to prevent any potential losses.

결과적으로, 영향을 받은 프로젝트 팀은 잠재적인 손실을 방지하기 위해 추후 공지가 있을 때까지 웹사이트와 상호 작용하지 말 것을 고객에게 재빨리 촉구했습니다.

원본 소스:bitcoinist

부인 성명:info@kdj.com

제공된 정보는 거래 조언이 아닙니다. kdj.com은 이 기사에 제공된 정보를 기반으로 이루어진 투자에 대해 어떠한 책임도 지지 않습니다. 암호화폐는 변동성이 매우 높으므로 철저한 조사 후 신중하게 투자하는 것이 좋습니다!

본 웹사이트에 사용된 내용이 귀하의 저작권을 침해한다고 판단되는 경우, 즉시 당사(info@kdj.com)로 연락주시면 즉시 삭제하도록 하겠습니다.

2026年07月27日 에 게재된 다른 기사