|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
이더 리움의 Pectra 업그레이드는 Sepolia Testnet의 취약성을 사용하여 알려지지 않은 공격자에 따라 다시 연기되었습니다.

The Pectra upgrade for Ethereum has been postponed yet again following an attack on the Sepolia testnet by an unknown attacker who exploited a vulnerability to execute an interesting attack that resulted in the production of empty blocks.
Ethereum의 Pectra 업그레이드는 공허한 공격을 수행하기 위해 취약점을 이용하여 빈 블록의 생산을 초래 한 미지의 공격자에 의한 Sepolia Testnet에 대한 공격으로 다시 연기되었습니다.
The problem was first brought to the attention of the community by Ethereum developer Marius Van Der Wijden, who noticed that the issue had started sometime after Pectra went live on March 5. Developers saw error messages and sporadic empty block mining, originating from an irregular event in the deposit contract. Instead of triggering a deposit event, the contract mistakenly triggered a transfer event, which was causing issues.
이 문제는 이더 리움 개발자 인 Marius van der Wijden에 의해 커뮤니티의 관심을 끌었습니다. 그는 3 월 5 일에 Pectra가 실시간이 지난 후 언젠가 문제가 시작되었다는 것을 알았습니다. 개발자들은 입금 계약의 불규칙한 사건에서 시작하여 오류 메시지와 산발적 인 빈 블록 채굴을 보았습니다. 예금 이벤트를 유발하는 대신 계약은 실수로 전송 이벤트를 유발하여 문제를 일으켰습니다.
The community began discussing potential causes and solutions, finally converging on a private fix that involved patching a limited number of DevOps nodes. The assumption was that the attacker was likely listening in on their communications, necessitating a stealthy method of deployment.
커뮤니티는 잠재적 인 원인과 솔루션에 대해 논의하기 시작했으며 마침내 제한된 수의 DevOps 노드를 패치하는 개인 수정으로 수렴했습니다. 공격자가 커뮤니케이션에 대해 듣고 있었을 가능성이 높으며 은밀한 배치 방법이 필요하다고 가정했습니다.
The goal was to solve fuller blocks in order to reach a point where deploying the fix would not leave any space for the attacker to continue the attack.
목표는 수정을 배치하면 공격자가 공격을 계속할 공간을 남기지 않는 지점에 도달하기 위해 풀러 블록을 해결하는 것이 었습니다.
Geth attempted to address the issue by rejecting bad logs of the deposit contract but overlooked an edge case of the ERC-20 standard. The attacker targeted it by executing zero-token transfers, rendering block creation useless. The network kept producing empty blocks until developers coordinated and rolled out a private fix, resuming full block production.
Geth는 예금 계약의 나쁜 로그를 거부 하여이 문제를 해결하려고 시도했지만 ERC-20 표준의 가장자리 사례를 간과했습니다. 공격자는 제로 토킨 전송을 실행하여 블록 생성을 쓸모없는 렌더링하여이를 목표로 삼았습니다. 네트워크는 개발자가 개인 수정을 조정하고 출시 할 때까지 빈 블록을 계속 생성하여 전체 블록 생산을 재개했습니다.
The incident did not affect Ethereum’s mainnet, and the network sustained finalization. The difference between deposit contracts on the Ethereum mainnet and Sepolia testnet was the most significant reason for the success of the attack.
이 사건은 이더 리움의 메인 넷에 영향을 미치지 않았으며 네트워크는 최종화를 유지했습니다. 이더 리움 메인 넷과 Sepolia Testnet의 예금 계약의 차이는 공격의 성공에 가장 중요한 이유였습니다.
After the attack was mitigated and the Pectra upgrade on Sepolia completed successfully, developers have decided to postpone the mainnet launch to allow more time for testing and debugging. This decision comes after a series of delays and testing phases.
공격이 완화되고 Sepolia의 Pectra 업그레이드가 성공적으로 완료된 후 개발자는 테스트 및 디버깅에 더 많은 시간을 허용하기 위해 Mainnet 런칭을 연기하기로 결정했습니다. 이 결정은 일련의 지연과 테스트 단계 이후에 발생합니다.
The Pectra upgrade introduces several changes to Ethereum, including new opcodes, testing for an edge case in the ERC-20 standard, and support for the AVM (Atomic Value Modules) standard. The upgrade is also designed to improve the efficiency and scalability of the Ethereum network.
Pectra 업그레이드는 새로운 Opcodes, ERC-20 표준의 에지 케이스 테스트 및 AVM (Atomic Value Modules) 표준을 포함하여 Ethereum에 몇 가지 변경 사항을 도입합니다. 업그레이드는 또한 이더 리움 네트워크의 효율성과 확장 성을 향상 시키도록 설계되었습니다.
As Pectra is set to bring several changes to the network, it is crucial that it is tested thoroughly to avoid any unforeseen issues. The Sepolia attack highlights the importance of vigilance and cooperation among developers in maintaining the security and stability of the blockchain ecosystem.
Pectra가 네트워크에 몇 가지 변경을 가져 오기 위해 설정되었으므로 예상치 못한 문제를 피하기 위해 철저히 테스트하는 것이 중요합니다. Sepolia 공격은 블록 체인 생태계의 보안 및 안정성을 유지하는 데있어 개발자들 사이의 경계와 협력의 중요성을 강조합니다.
부인 성명:info@kdj.com
제공된 정보는 거래 조언이 아닙니다. kdj.com은 이 기사에 제공된 정보를 기반으로 이루어진 투자에 대해 어떠한 책임도 지지 않습니다. 암호화폐는 변동성이 매우 높으므로 철저한 조사 후 신중하게 투자하는 것이 좋습니다!
본 웹사이트에 사용된 내용이 귀하의 저작권을 침해한다고 판단되는 경우, 즉시 당사(info@kdj.com)로 연락주시면 즉시 삭제하도록 하겠습니다.

































