|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
MPC(다자간 계산) 지갑 제공업체 Liminal은 7월 18일 WazirX 해킹에 대한 사후 보고서를 7월 19일 발표했습니다.

Multiparty computation (MPC) technology provider Liminal has released a July 19 post-mortem report on the July 18 WazirX hack, disputing the exchange’s claim that its user interface was responsible for the attack.
다자간 계산(MPC) 기술 제공업체인 Liminal은 7월 18일 WazirX 해킹에 대한 사후 보고서를 7월 19일 발표하여 자사 사용자 인터페이스가 공격에 책임이 있다는 거래소의 주장을 반박했습니다.
According to Liminal's report, the hack occurred because three WazirX devices were compromised. The devices were used to initiate transactions that were then modified by the attacker before being sent to Liminal's servers for approval.
Liminal의 보고서에 따르면 해킹은 세 개의 WazirX 장치가 손상되었기 때문에 발생했습니다. 이 장치는 승인을 위해 Liminal 서버로 전송되기 전에 공격자가 수정한 트랜잭션을 시작하는 데 사용되었습니다.
Liminal also claimed that its multisignature wallet was set up to provide a fourth signature if WazirX provided the other three. This meant that the attacker only needed to compromise three devices to perform the attack. The wallet was set up this way at the behest of WazirX, the wallet provider claimed.
Liminal은 또한 WazirX가 나머지 3개를 제공하는 경우 다중 서명 지갑이 네 번째 서명을 제공하도록 설정되었다고 주장했습니다. 즉, 공격자는 공격을 수행하기 위해 3개의 장치만 손상시키면 됩니다. 지갑 제공업체는 WazirX의 요청에 따라 지갑이 이런 방식으로 설정되었다고 주장했습니다.
In a July 18 social media post, WazirX claimed that its private keys were secured with hardware wallets. However, WazirX said the attack “stemmed from a discrepancy between the data displayed on Liminal’s interface and the transaction’s actual contents.”
7월 18일 소셜 미디어 게시물에서 WazirX는 개인 키가 하드웨어 지갑으로 보호된다고 주장했습니다. 그러나 WazirX는 이번 공격이 "Liminal의 인터페이스에 표시된 데이터와 거래의 실제 내용 사이의 불일치에서 비롯됐다"고 밝혔습니다.
According to the Liminal report, one of WazirX’s devices initiated a valid transaction involving the Gala Games (GALA) token. In response, Liminal’s server provided a “safeTxHash,” verifying the transaction's validity. However, the attacker then replaced this transaction hash with an invalid one, causing the transaction to fail.
Liminal 보고서에 따르면 WazirX의 장치 중 하나가 Gala Games(GALA) 토큰과 관련된 유효한 거래를 시작했습니다. 이에 대한 응답으로 Liminal의 서버는 거래의 유효성을 확인하는 "safeTxHash"를 제공했습니다. 그러나 공격자는 이 트랜잭션 해시를 유효하지 않은 해시로 교체하여 트랜잭션이 실패하게 만들었습니다.
In Liminal’s view, the fact that the attacker was able to change this hash implies that the WazirX device had already been compromised before the transaction was attempted.
Liminal의 관점에서 공격자가 이 해시를 변경할 수 있었다는 사실은 거래가 시도되기 전에 WazirX 장치가 이미 손상되었음을 의미합니다.
The attacker then initiated an additional two transactions: one GALA and one Tether (USDT) transfer. In each of these three transactions, the attacker used a different WazirX admin account, for a total of three accounts used. All three of the transactions failed.
그런 다음 공격자는 GALA 전송 하나와 Tether(USDT) 전송 하나라는 두 개의 추가 거래를 시작했습니다. 이 세 가지 거래 각각에서 공격자는 서로 다른 WazirX 관리자 계정을 사용하여 총 3개의 계정을 사용했습니다. 세 가지 거래가 모두 실패했습니다.
After initiating these three failed transactions, the attacker extracted signatures from the transactions and used them to initiate a new, fourth transaction. The fourth transaction “was crafted in such a way that the fields used to verify policies were using legit transaction details” and “used the Nonce from the failed USDT transaction because that was the latest transaction.”
세 번의 실패한 트랜잭션을 시작한 후 공격자는 트랜잭션에서 서명을 추출하고 이를 사용하여 새로운 네 번째 트랜잭션을 시작했습니다. 네 번째 거래는 “정책을 확인하는 데 사용되는 필드가 합법적인 거래 세부 정보를 사용하는 방식으로 제작되었으며” “최신 거래이기 때문에 실패한 USDT 거래의 Nonce를 사용했습니다.”
Because it used these “legit transaction details,” the Liminal server approved the transaction and provided a fourth signature. As a result, the transaction was confirmed on the Ethereum network, resulting in a transfer of funds from the joint multisig wallet to the attacker’s Ethereum account.
이러한 "합법적인 거래 내역"을 사용했기 때문에 Liminal 서버는 거래를 승인하고 네 번째 서명을 제공했습니다. 그 결과 이더리움 네트워크에서 거래가 확인됐고, 공동 다중서명 지갑에서 공격자의 이더리움 계정으로 자금이 이체됐다.
Liminal denied that its servers caused incorrect information to be displayed through the Liminal UI. Instead, it claimed that the incorrect information was provided by the attacker, who had compromised WazirX computers. In an answer to the posed question “How did the UI show a different value from the actual payload within the transaction?” Liminal said:
Liminal은 서버로 인해 Liminal UI를 통해 잘못된 정보가 표시되었다는 사실을 부인했습니다. 대신 WazirX 컴퓨터를 손상시킨 공격자가 잘못된 정보를 제공했다고 주장했습니다. "UI가 트랜잭션 내 실제 페이로드와 다른 값을 어떻게 표시했습니까?"라는 질문에 대한 답변에서 리미날은 이렇게 말했습니다.
Liminal also claimed that its servers were programmed to automatically provide a fourth signature if WazirX admins provided the other three. “Liminal only provides the final signature once the required number of valid signatures are received from the client’s side,” it stated, adding that in this case, “the transaction was authorised and signed by three of our client’s employees.”
Liminal은 또한 WazirX 관리자가 나머지 3개의 서명을 제공하면 자사 서버가 자동으로 네 번째 서명을 제공하도록 프로그래밍되었다고 주장했습니다. "Liminal은 고객 측으로부터 필요한 수의 유효한 서명을 받은 후에만 최종 서명을 제공합니다."라고 밝혔으며, 이 경우 "거래는 고객 직원 3명이 승인하고 서명했습니다."라고 덧붙였습니다.
The multisig wallet “was deployed by WazirX as per their configuration well before onboarding with Liminal,” and was “imported” into Liminal “per WazirX's request.”
다중 서명 지갑은 "Liminal에 온보딩하기 훨씬 전에 구성에 따라 WazirX에 의해 배포"되었으며 "WazirX의 요청에 따라" Liminal로 "가져왔습니다".
Related: WazirX breach post-mortem: Dismantling the $230M attack
관련 항목: WazirX 침해 사후 분석: 2억 3천만 달러 규모의 공격 해체
WazirX’s post claimed that it had implemented “robust security features.” For example, it had required that all transactions be confirmed by four out of five keyholders. Four of these keys belonged to WazirX employees and one to the Liminal team. In addition, it required three of the WazirX keyholders to use hardware wallets. All destination addresses were required to be added to a whitelist ahead of time, WazirX stated, which was “earmarked and facilitated on the interface by Liminal.”
WazirX의 게시물에서는 "강력한 보안 기능"을 구현했다고 주장했습니다. 예를 들어 모든 거래는 키 보유자 5명 중 4명이 확인하도록 요구했습니다. 이 키 중 4개는 WazirX 직원의 것이었고 하나는 Liminal 팀의 것이었습니다. 또한 하드웨어 지갑을 사용하려면 WazirX 키홀더 3개가 필요했습니다. WazirX는 모든 목적지 주소를 미리 화이트리스트에 추가해야 했으며, 이는 "Liminal이 인터페이스에 지정하고 촉진했습니다."라고 밝혔습니다.
Despite taking all of these precautions, the attacker “appear[s] to have possibly breached such security features, and the theft occurred.” WazirX called the attack a “a force majeure event beyond [its] control.” Even so, it vowed that it was “leaving no stone unturned to locate and recover the funds.”
이러한 모든 예방 조치를 취했음에도 불구하고 공격자는 "그러한 보안 기능을 침해했을 가능성이 있는 것으로 보이며 도난이 발생했습니다." WazirX는 이번 공격을 "통제할 수 없는 불가항력 사건"이라고 불렀습니다. 그럼에도 불구하고 “자금을 찾아서 회수하는 데 모든 노력을 다하겠다”고 다짐했습니다.
An estimated $235 million was lost in the WazirX attack. It was the largest centralized exchange hack since the DMM exploit of May 31, which resulted in even greater losses of $305 million.
WazirX 공격으로 인해 약 2억 3,500만 달러의 손실이 발생했습니다. 이는 5월 31일 DMM 공격 이후 최대 규모의 중앙 집중식 거래소 해킹으로, 3억 500만 달러의 더 큰 손실을 입혔습니다.
Magazine: WazirX hackers prepped 8 days before attack, swindlers fake fiat for USDT: Asia Express
매거진: WazirX 해커들은 공격 8일 전에 준비했고, 사기꾼들은 USDT에 대한 가짜 화폐를 사용했습니다: Asia Express
부인 성명:info@kdj.com
제공된 정보는 거래 조언이 아닙니다. kdj.com은 이 기사에 제공된 정보를 기반으로 이루어진 투자에 대해 어떠한 책임도 지지 않습니다. 암호화폐는 변동성이 매우 높으므로 철저한 조사 후 신중하게 투자하는 것이 좋습니다!
본 웹사이트에 사용된 내용이 귀하의 저작권을 침해한다고 판단되는 경우, 즉시 당사(info@kdj.com)로 연락주시면 즉시 삭제하도록 하겠습니다.

































