|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
블록체인 전반에 걸쳐 디지털 자산을 연결하고 교환하는 데 사용되는 API인 Li.Fi 프로토콜의 1,160만 달러 규모의 익스플로잇에 이어 Li.Fi 팀은 다음을 출시했습니다.

An exploit of the Li.Fi protocol resulted in the theft of $11.6 million in digital assets, prompting the Li.Fi team to release an update on the technical aspects of the breach.
Li.Fi 프로토콜의 악용으로 인해 1,160만 달러의 디지털 자산이 도난당했고, Li.Fi 팀은 위반의 기술적 측면에 대한 업데이트를 발표하게 되었습니다.
The breach occurred during the deployment of a new smart contract facet, which contained a vulnerability that enabled users calling the smart contract to initiate calls to any contract without prior validation.
이 침해는 새로운 스마트 계약 측면을 배포하는 동안 발생했습니다. 여기에는 스마트 계약을 호출하는 사용자가 사전 검증 없이 모든 계약에 대한 호출을 시작할 수 있는 취약점이 포함되어 있습니다.
This function stemmed from code taken from the LibSwap library, which facilitates calls between decentralized exchanges, service providers, and clients to coordinate the asset bridging and swapping processes.
이 기능은 자산 연결 및 교환 프로세스를 조정하기 위해 분산형 거래소, 서비스 제공자 및 클라이언트 간의 호출을 용이하게 하는 LibSwap 라이브러리에서 가져온 코드에서 비롯되었습니다.
Normally, these calls are screened against whitelisted addresses to ensure validation. However, human error in deploying the offending smart contract facet resulted in these checks being bypassed, rendering the protocol vulnerable to exploitation.
일반적으로 이러한 통화는 유효성 검사를 위해 허용 목록에 있는 주소와 비교하여 검사됩니다. 그러나 문제가 되는 스마트 계약 측면을 배포할 때 사람의 실수로 인해 이러한 검사가 우회되어 프로토콜이 악용에 취약해졌습니다.
The Li.Fi team confirmed that the attack occurred on the Ethereum and Arbitrum networks and affected 156 wallets that had the “infinite approvals” option turned on. Those who did not enable this option were not affected by the exploit.
Li.Fi 팀은 공격이 Ethereum 및 Arbitrum 네트워크에서 발생했으며 "무한 승인" 옵션이 설정된 156개 지갑에 영향을 미쳤음을 확인했습니다. 이 옵션을 활성화하지 않은 사람들은 공격의 영향을 받지 않았습니다.
In statements to Cointelegraph, spokespeople for Li.Fi said they contained the exploit, addressed the critical vulnerability, and contacted the proper law enforcement authorities to trace the stolen funds. At the time of this writing, the issue has been fixed, and Li.Fi is operating normally.
Li.Fi 대변인은 Cointelegraph에 보낸 성명에서 공격을 억제하고 심각한 취약점을 해결했으며 도난당한 자금을 추적하기 위해 적절한 법 집행 기관에 연락했다고 밝혔습니다. 이 글을 쓰는 시점에서는 문제가 해결되어 Li.Fi가 정상적으로 작동하고 있습니다.
Related: Lazarus is moving millions from $305M DMM Bitcoin hack — ZachXBT
관련 항목: Lazarus는 3억 5천만 달러 규모의 DMM 비트코인 해킹에서 수백만 달러를 이동하고 있습니다 — ZachXBT
This is not the first time that a vulnerability in the Li.Fi protocol has been exploited. In March 2022, a similar exploit affected users who had the “infinite approval” option turned on, allowing hackers to drain $600,000 from the protocol from 29 wallets before the vulnerability was addressed.
Li.Fi 프로토콜의 취약점이 악용된 것은 이번이 처음이 아닙니다. 2022년 3월에도 유사한 익스플로잇이 "무한 승인" 옵션을 켠 사용자에게 영향을 미쳐 해커들이 취약점이 해결되기 전에 29개 지갑의 프로토콜에서 60만 달러를 빼낼 수 있었습니다.
The protocol was quick to reimburse investors for their losses, refunding 24 wallets directly from its treasury and offering the remaining five wallets a voluntary compensation plan akin to that received by early angel investors of Li.Fi.
프로토콜은 투자자의 손실을 신속하게 보상하여 24개의 지갑을 재무부에서 직접 환불하고 나머지 5개의 지갑에는 Li.Fi의 초기 엔젤 투자자가 받은 것과 유사한 자발적인 보상 계획을 제공했습니다.
Crypto hacks put the damper on the industry in 2024
암호화폐 해킹으로 인해 2024년 업계에 타격이 가해졌습니다.
Hacks and exploits continue to plague the crypto industry and the decentralized financial sector, in particular.
해킹과 악용은 특히 암호화폐 산업과 분산형 금융 부문을 계속해서 괴롭히고 있습니다.
A recent report from security firm Cyvers showed that 2024 losses from crypto exploits are nearing $1.4 billion, driven primarily by phishing attacks, and have risen sharply since 2023.
보안 회사인 Cyvers의 최근 보고서에 따르면 2024년 암호화폐 공격으로 인한 손실은 주로 피싱 공격으로 인해 거의 14억 달러에 달했으며 2023년 이후 급격히 증가했습니다.
Magazine: Best and worst countries for crypto taxes — plus crypto tax tips
매거진: 암호화폐 세금에 대한 최고 및 최악의 국가 — 그리고 암호화폐 세금 팁
부인 성명:info@kdj.com
제공된 정보는 거래 조언이 아닙니다. kdj.com은 이 기사에 제공된 정보를 기반으로 이루어진 투자에 대해 어떠한 책임도 지지 않습니다. 암호화폐는 변동성이 매우 높으므로 철저한 조사 후 신중하게 투자하는 것이 좋습니다!
본 웹사이트에 사용된 내용이 귀하의 저작권을 침해한다고 판단되는 경우, 즉시 당사(info@kdj.com)로 연락주시면 즉시 삭제하도록 하겠습니다.

































