|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
탈중앙화 금융(DeFi) 프로토콜 Penpie는 최근 수백만 달러 상당의 암호화폐 자산을 탈취하는 공격의 희생양이 되었습니다.

A DeFi protocol based on Pendle, Penpie, recently fell victim to an exploit that saw millions of dollars worth of several crypto assets being drained from the protocol. Pendle addressed the incident in a post-mortem post, revealing that its quick response prevented further losses to the tune of over $100 million in users’ funds.
Pendle을 기반으로 한 DeFi 프로토콜인 Penpie는 최근 수백만 달러 상당의 여러 암호화폐 자산이 프로토콜에서 유출되는 공격의 희생양이 되었습니다. Pendle은 사후 사후 게시물에서 이 사건을 다루면서 빠른 대응으로 사용자 자금 중 1억 달러가 넘는 추가 손실을 방지했다고 밝혔습니다.
According to reports, the crypto heist took place on Tuesday, with the malicious actor exploiting a vulnerability in Penpie’s reward distribution mechanism. The vulnerability stemmed from a Penpie-only feature that permitted permissionless listing of Pendle markets on Penpie.
보도에 따르면 암호화폐 강도 사건은 화요일에 발생했으며 악의적인 공격자는 Penpie의 보상 분배 메커니즘의 취약점을 악용했습니다. 이 취약점은 Penpie에서 Pendle 시장의 무허가 목록을 허용하는 Penpie 전용 기능에서 발생합니다.
The attacker used an “evil market” contract to inflate the staking balance and claim unwarranted rewards. As a result, they were able to drain $7.87 million in wstETH, $2.51 million in sUSDe, $3.4 million agETH, $2.22 million in rswETH, and four other Pendle-related Yield tokens from the protocol.
공격자는 스테이킹 잔액을 부풀리고 부당한 보상을 요구하기 위해 "사악한 시장" 계약을 사용했습니다. 그 결과, 그들은 wstETH에서 787만 달러, sUSDe에서 251만 달러, agETH에서 340만 달러, rswETH에서 222만 달러 및 기타 Pendle 관련 Yield 토큰 4개를 프로토콜에서 빼낼 수 있었습니다.
Following the exploit, the hacker swapped the crypto assets for 11,113 ETH using the Li.fi protocol. The stolen funds, worth $27.3 million, were later transferred to crypto mixer Tornado Cash.
익스플로잇 이후 해커는 Li.fi 프로토콜을 사용하여 암호화폐 자산을 11,113 ETH로 교환했습니다. 2,730만 달러 상당의 도난 자금은 나중에 암호화폐 믹서인 Tornado Cash로 이체되었습니다.
The Penpie Team sent a message to the attacker, asking them to “amicably” resolve the incident. The protocol recognized the project’s vulnerability and the exploit’s role in bringing it forward, proposing a white hat bounty for the safe return of the funds.
펜파이팀은 공격자에게 메시지를 보내 사건을 '우호적으로' 해결해 줄 것을 요청했습니다. 이 프로토콜은 프로젝트의 취약성과 이를 추진하는 데 있어 익스플로잇의 역할을 인식하고 자금의 안전한 반환을 위해 하얀 모자 포상금을 제안했습니다.
Additionally, they offered the attacker an opportunity to “transition into a white-hat role, where your skills will be acknowledged and rewarded.” The team assured that the hacker’s identity would remain confidential and they would not pursue any legal action against them.
또한 그들은 공격자에게 "당신의 기술이 인정받고 보상받을 수 있는 화이트 해커 역할로 전환"할 수 있는 기회를 제공했습니다. 팀은 해커의 신원은 기밀로 유지되며 해커에 대해 어떠한 법적 조치도 취하지 않을 것이라고 확신했습니다.
As of this writing, there are no reports of a resolution between the exploiter and the protocol’s team.
이 글을 쓰는 시점에서 공격자와 프로토콜 팀 사이의 해결에 대한 보고는 없습니다.
부인 성명:info@kdj.com
제공된 정보는 거래 조언이 아닙니다. kdj.com은 이 기사에 제공된 정보를 기반으로 이루어진 투자에 대해 어떠한 책임도 지지 않습니다. 암호화폐는 변동성이 매우 높으므로 철저한 조사 후 신중하게 투자하는 것이 좋습니다!
본 웹사이트에 사용된 내용이 귀하의 저작권을 침해한다고 판단되는 경우, 즉시 당사(info@kdj.com)로 연락주시면 즉시 삭제하도록 하겠습니다.

































