시가총액: $2.882T -1.49%
거래량(24시간): $102.5955B -0.51%
  • 시가총액: $2.882T -1.49%
  • 거래량(24시간): $102.5955B -0.51%
  • 공포와 탐욕 지수:
  • 시가총액: $2.882T -1.49%
암호화
주제
암호화
소식
cryptostopics
비디오
최고의 뉴스
암호화
주제
암호화
소식
cryptostopics
비디오
bitcoin
bitcoin

$84577.234968 USD

-1.56%

ethereum
ethereum

$2680.004128 USD

-1.70%

tether
tether

$0.999808 USD

0.02%

bnb
bnb

$765.682454 USD

-1.34%

xrp
xrp

$1.484099 USD

-2.46%

usd-coin
usd-coin

$0.999988 USD

0.00%

solana
solana

$119.429084 USD

-1.45%

tron
tron

$0.335308 USD

0.33%

zcash
zcash

$1313.504956 USD

-4.56%

hyperliquid
hyperliquid

$88.248433 USD

-1.74%

dogecoin
dogecoin

$0.092877 USD

-2.97%

chainlink
chainlink

$14.020892 USD

-2.26%

monero
monero

$548.883836 USD

0.03%

cardano
cardano

$0.244660 USD

-3.58%

unus-sed-leo
unus-sed-leo

$9.010719 USD

0.45%

암호화폐 뉴스 기사

SlowMist, 안전한 지갑을 배수하는 FlashLoopAdapter 결함 발견: DeFi 통합에 대한 경종

2026/10/03 08:05

SlowMist는 타사 Aave 통합인 FlashLoopAdapter의 심각한 취약점을 보고했으며 이로 인해 두 개의 Safe 다중서명 지갑에서 114 ETH가 유출되었습니다. 이 사건은 Safe와 같은 강력한 핵심 프로토콜을 사용하더라도 외부 DeFi 모듈에 내재된 위험이 있음을 강조합니다.

SlowMist, 안전한 지갑을 배수하는 FlashLoopAdapter 결함 발견: DeFi 통합에 대한 경종

In the ever-evolving landscape of decentralized finance (DeFi), security is paramount, yet a recent incident brought to light by blockchain security firm SlowMist serves as a stark reminder that even the most fortified systems can be vulnerable through their external connections. A flaw in a third-party integration, dubbed FlashLoopAdapter, allowed an attacker to siphon approximately 114 ETH (valued around $305,000 at the time of reporting) from two Safe multisig wallets.

끊임없이 진화하는 탈중앙화 금융(DeFi) 환경에서는 보안이 가장 중요합니다. 그러나 블록체인 보안 회사인 SlowMist가 최근에 밝혀낸 사건은 가장 강화된 시스템이라도 외부 연결을 통해 취약할 수 있다는 사실을 극명하게 상기시켜 줍니다. FlashLoopAdapter라고 불리는 타사 통합의 결함으로 인해 공격자는 두 개의 Safe 다중 서명 지갑에서 약 114 ETH(보고 당시 약 $305,000 가치)를 빼낼 수 있었습니다.

The Achilles' Heel: FlashLoopAdapter's Access Control

아킬레스건: FlashLoopAdapter의 액세스 제어

SlowMist's investigation pinpointed FlashLoopAdapter as the weak link. This component, designed to manage leveraged Aave v3 positions, was an external adapter, not a core part of the Safe multisig wallet protocol or the Aave v3 itself. This distinction is crucial: the core Safe contracts remained uncompromised. The vulnerability lay in FlashLoopAdapter's access control mechanisms for its open() and close() functions. These functions merely checked if a module was enabled by calling ISafe(msg.sender).isModuleEnabled(address(this)), a check that was unfortunately spoofable.

SlowMist의 조사에서는 FlashLoopAdapter를 약한 링크로 지적했습니다. 활용된 Aave v3 위치를 관리하도록 설계된 이 구성 요소는 Safe 다중 서명 지갑 프로토콜이나 Aave v3 자체의 핵심 부분이 아닌 외부 어댑터였습니다. 이러한 구별은 매우 중요합니다. 핵심 안전 계약은 타협되지 않은 상태로 유지됩니다. 취약점은 open() 및 close() 기능에 대한 FlashLoopAdapter의 액세스 제어 메커니즘에 있습니다. 이러한 함수는 단지 ISafe(msg.sender).isModuleEnabled(address(this))를 호출하여 모듈이 활성화되었는지 확인했는데, 이 검사는 불행하게도 스푸핑이 가능했습니다.

The attacker cleverly exploited this by deploying a fake Safe contract that would always return 'true' to this module enablement query. Furthermore, the _swap() function within FlashLoopAdapter allowed the caller to dictate the swap router and its data. The attacker leveraged this to set the router to one of the victim Safe wallets and then, through the execTransactionFromModule function (a legitimate Safe function for enabled modules), executed unauthorized transactions. The consequence? Collateral locked in Aave v3 positions via FlashLoopAdapter was drained.

공격자는 이 모듈 활성화 쿼리에 항상 'true'를 반환하는 가짜 안전 계약을 배포하여 이를 교묘하게 악용했습니다. 게다가 FlashLoopAdapter 내의 _swap() 함수를 사용하면 호출자가 스왑 라우터와 해당 데이터를 지시할 수 있습니다. 공격자는 이를 활용하여 라우터를 피해자의 안전 지갑 중 하나로 설정한 다음 execTransactionFromModule 기능(활성화된 모듈에 대한 합법적인 안전 기능)을 통해 승인되지 않은 거래를 실행했습니다. 결과는? FlashLoopAdapter를 통해 Aave v3 위치에 고정된 담보가 유출되었습니다.

A Pattern of Peripheral Vulnerabilities

주변기기 취약점의 패턴

This isn't SlowMist's first rodeo in identifying vulnerabilities stemming from peripheral integrations. The firm has a consistent track record of tracing significant losses back to adjacent components rather than core protocols. This incident echoes previous findings, such as the Liquid Network exploit that minted 3,998 L-BTC, where a similar attack vector bypassed core defenses through an external module. These cases collectively underscore a critical trend: while core protocols may be robust, the security perimeter often expands with every third-party integration.

이는 주변기기 통합으로 인한 취약점을 식별하는 SlowMist의 첫 번째 로데오가 아닙니다. 이 회사는 핵심 프로토콜이 아닌 인접한 구성 요소로 인해 상당한 손실이 발생했다는 일관된 추적 기록을 보유하고 있습니다. 이 사건은 유사한 공격 벡터가 외부 모듈을 통해 핵심 방어를 우회한 3,998 L-BTC를 생성한 Liquid Network 익스플로잇과 같은 이전 조사 결과를 반영합니다. 이러한 사례는 전체적으로 중요한 추세를 강조합니다. 핵심 프로토콜은 강력할 수 있지만 보안 경계는 모든 타사 통합으로 확장되는 경우가 많습니다.

The Broader Implications for Safe Wallets and DeFi

안전한 지갑과 DeFi에 대한 더 넓은 의미

Safe wallets are widely celebrated for their enhanced security in DeFi, particularly through their multisig capabilities. However, the FlashLoopAdapter incident highlights a fundamental truth: security is only as strong as its weakest link. When users grant third-party adapters interaction privileges with their wallets, these adapters inherit significant execution power. A flaw in the adapter's logic, even if the wallet itself functions perfectly, can be weaponized.

안전한 지갑은 특히 다중서명 기능을 통해 DeFi의 향상된 보안으로 널리 알려져 있습니다. 그러나 FlashLoopAdapter 사건은 근본적인 진실을 강조합니다. 보안은 가장 약한 링크만큼만 강력하다는 것입니다. 사용자가 타사 어댑터에 지갑과의 상호 작용 권한을 부여하면 이러한 어댑터는 상당한 실행 능력을 상속받습니다. 지갑 자체가 완벽하게 작동하더라도 어댑터 논리의 결함이 무기화될 수 있습니다.

This serves as a potent reminder for anyone engaging with DeFi strategies that involve external modules. Authorizing an adapter is not a trivial decision; it entails trusting the adapter's code as much as, if not more than, the core protocol. The true blast radius of this exploit—how many other wallets had authorized FlashLoopAdapter before the flaw was discovered—remains an open question, underscoring the ongoing challenge of securing the interconnected DeFi ecosystem.

이는 외부 모듈과 관련된 DeFi 전략에 참여하는 모든 사람에게 강력한 알림 역할을 합니다. 어댑터 승인은 간단한 결정이 아닙니다. 이는 핵심 프로토콜만큼은 아니더라도 어댑터의 코드를 신뢰하는 것을 수반합니다. 이 익스플로잇의 실제 폭발 범위(결함이 발견되기 전에 얼마나 많은 다른 지갑에서 FlashLoopAdapter를 승인했는지)는 여전히 공개된 질문으로 남아 있으며, 이는 상호 연결된 DeFi 생태계를 보호해야 하는 지속적인 과제를 강조합니다.

Looking Ahead: A Call for Scrutiny and Enhanced Vigilance

미래를 내다보며: 정밀 조사와 강화된 경계가 요구됩니다.

While the attacker's identity remains unknown and remediation steps are not publicly detailed, this incident provides valuable lessons. It's a clear call for increased scrutiny of third-party integrations and robust access control mechanisms. As DeFi continues to innovate, the onus is on both developers and users to prioritize comprehensive security audits and understand the full implications of every integration. In the end, staying safe in the digital frontier often comes down to paying attention to the fine print—and the code behind it. Let's keep those wallets safe and sound, one secure integration at a time!

공격자의 신원은 아직 알려지지 않았고 문제 해결 단계도 공개적으로 자세히 알려지지 않았지만 이번 사건은 귀중한 교훈을 제공합니다. 이는 타사 통합과 강력한 액세스 제어 메커니즘에 대한 조사가 강화되어야 한다는 분명한 요구입니다. DeFi가 지속적으로 혁신함에 따라 개발자와 사용자 모두 포괄적인 보안 감사의 우선순위를 정하고 모든 통합의 전체 의미를 이해해야 할 책임이 있습니다. 결국 디지털 개척지에서 안전을 유지하려면 작은 글씨와 그 뒤에 숨은 코드에 주의를 기울이는 것이 중요합니다. 한 번에 하나의 보안 통합으로 지갑을 안전하고 건전하게 유지합시다!

원본 소스:coinmarketcap

부인 성명:info@kdj.com

제공된 정보는 거래 조언이 아닙니다. kdj.com은 이 기사에 제공된 정보를 기반으로 이루어진 투자에 대해 어떠한 책임도 지지 않습니다. 암호화폐는 변동성이 매우 높으므로 철저한 조사 후 신중하게 투자하는 것이 좋습니다!

본 웹사이트에 사용된 내용이 귀하의 저작권을 침해한다고 판단되는 경우, 즉시 당사(info@kdj.com)로 연락주시면 즉시 삭제하도록 하겠습니다.

2026年10月03日 에 게재된 다른 기사