|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
탈중앙화 금융(DeFi) 부문은 은행과 규제가 없는 미래에 대한 약속으로 상당한 성장을 경험했습니다. 그러나 이러한 중개자가 부족하면 사용자는 사기 및 해킹을 포함한 위험에 노출됩니다.

Decentralized finance (DeFi) is meant to be a future without banks and regulation. But the absence of these intermediaries also leaves users exposed.
탈중앙화 금융(DeFi)은 은행과 규제가 없는 미래를 의미합니다. 그러나 이러한 중개자가 없으면 사용자도 노출됩니다.
Recently, cross-chain transaction aggregator LI.FI became the latest target of a hack, highlighting a vulnerability that has already cost users over $10 million in stablecoins. And, according to security experts, more user funds could still be at risk.
최근 크로스체인 거래 수집업체인 LI.FI가 해킹의 최신 표적이 되었으며, 이는 이미 사용자에게 스테이블 코인으로 천만 달러 이상의 비용을 초래한 취약점을 강조했습니다. 그리고 보안 전문가에 따르면 더 많은 사용자 자금이 여전히 위험에 처할 수 있습니다.
Here's how the LI.FI protocol hack went down.
LI.FI 프로토콜 해킹이 어떻게 진행되었는지 살펴보겠습니다.
DeFi hacks are getting creative. On Tuesday, July 16, crypto security firm Cyvers reported a security breach in the LI.FI protocol, a major cross-chain transaction aggregator.
DeFi 해킹이 점점 창의력을 발휘하고 있습니다. 7월 16일 화요일, 암호화폐 보안 회사인 Cyvers는 주요 크로스체인 거래 수집업체인 LI.FI 프로토콜의 보안 위반을 보고했습니다.
The initial breach was detected on the Ethereum blockchain and later expanded to the Arbitrum network. The attack resulted in the theft of over $10 million in stablecoins, primarily USDC and USDT, which the attackers then began converting into ETH.
초기 위반은 Ethereum 블록체인에서 감지되었으며 나중에 Arbitrum 네트워크로 확장되었습니다. 이 공격으로 인해 주로 USDC와 USDT 등 1,000만 달러가 넘는 스테이블코인이 도난당했고, 이후 공격자들은 이를 ETH로 전환하기 시작했습니다.
The LI.FI protocol team confirmed the breach after the incident was reported by the security firm. According to the team, the main vulnerability stemmed from an infinite approval setting for transactions, which allowed the attackers to pilfer all the funds.
LI.FI 프로토콜 팀은 보안 회사에서 사건을 보고한 후 위반 사실을 확인했습니다. 팀에 따르면 주요 취약점은 거래에 대한 무한한 승인 설정에서 비롯되었으며, 이로 인해 공격자가 모든 자금을 훔칠 수 있었습니다.
How to protect yourself from the infinite approval exploit
무한 승인 악용으로부터 자신을 보호하는 방법
The infinite approval exploit occurs when users grant a smart contract unlimited permission to access their funds. This is convenient for repetitive transactions that don't require user confirmation every time, but it also introduces a major security risk. If the smart contract or platform is compromised, attackers can use it to drain all the funds from users.
무한 승인 악용은 사용자가 스마트 계약에 자금 액세스에 대한 무제한 권한을 부여할 때 발생합니다. 이는 매번 사용자 확인이 필요하지 않은 반복적인 거래에 편리하지만 심각한 보안 위험도 발생합니다. 스마트 계약이나 플랫폼이 손상되면 공격자는 이를 사용하여 사용자로부터 모든 자금을 빼앗을 수 있습니다.
Sponsored
후원
Revoke approvals: LI.FI claims that no further funds are at risk, but the Cyvers security firm is urging users to immediately revoke approvals for the compromised addresses. This can be done easily using tools like Revoke.cash.
승인 취소: LI.FI는 더 이상 자금이 위험하지 않다고 주장하지만 Cyvers 보안 회사는 사용자에게 손상된 주소에 대한 승인을 즉시 취소할 것을 촉구하고 있습니다. 이는 Revoke.cash와 같은 도구를 사용하여 쉽게 수행할 수 있습니다.
Inspect approvals: Users should periodically review their token approvals and revoke any that are no longer needed or that could pose a risk.
승인 검사: 사용자는 정기적으로 토큰 승인을 검토하고 더 이상 필요하지 않거나 위험을 초래할 수 있는 승인을 취소해야 합니다.
Set limits: Instead of granting infinite approval, users can specify a limit on the amount a smart contract can access. This way, even if there is a breach, the potential loss is capped.
제한 설정: 사용자는 무제한 승인을 부여하는 대신 스마트 계약이 액세스할 수 있는 금액에 대한 제한을 지정할 수 있습니다. 이렇게 하면 위반이 발생하더라도 잠재적인 손실이 제한됩니다.
While DeFi protocols are responsible for ensuring strong security measures, users also bear responsibility for their own security settings. Taking these steps can help reduce the risk of falling victim to hacks.
DeFi 프로토콜은 강력한 보안 조치를 보장할 책임이 있지만 사용자는 자신의 보안 설정에 대한 책임도 집니다. 이러한 조치를 취하면 해킹의 피해를 입을 위험을 줄이는 데 도움이 될 수 있습니다.
On the Flipside
플립사이드에서
Why This Matters
이것이 중요한 이유
The LI.FI breach underscores the critical need for vigilance and proactive security measures in DeFi. Users must be cognizant of their security settings and take regular actions to manage permissions and safeguard their assets.
LI.FI 위반은 DeFi에 대한 경계와 사전 예방적 보안 조치의 중요성을 강조합니다. 사용자는 자신의 보안 설정을 인지하고 권한을 관리하고 자산을 보호하기 위한 정기적인 조치를 취해야 합니다.
Learn more about protecting your funds:
자금 보호에 대해 자세히 알아보세요:
How to Stay Safe From Phishing in Crypto Mailing List Hack
암호화폐 메일링 리스트 해킹에서 피싱으로부터 안전을 유지하는 방법
Discover the Chromia Mainnet launch:
Chromia 메인넷 출시를 알아보세요:
Chromia Mainnet Launch Sets the Stage for Next-Gen Blockchain Networks
Chromia 메인넷 출시로 차세대 블록체인 네트워크의 무대 마련
부인 성명:info@kdj.com
제공된 정보는 거래 조언이 아닙니다. kdj.com은 이 기사에 제공된 정보를 기반으로 이루어진 투자에 대해 어떠한 책임도 지지 않습니다. 암호화폐는 변동성이 매우 높으므로 철저한 조사 후 신중하게 투자하는 것이 좋습니다!
본 웹사이트에 사용된 내용이 귀하의 저작권을 침해한다고 판단되는 경우, 즉시 당사(info@kdj.com)로 연락주시면 즉시 삭제하도록 하겠습니다.

































