|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Solana memecoins 플랫폼 Pump.fun은 전 직원이 "결합 곡선" 공격을 통해 플랫폼을 190만 달러에 악용했다고 주장합니다. 가해자는 프로토콜의 유동성을 조작하기 위해 권한 있는 액세스를 사용했으며, Raydium에서 자금을 빌려 이를 사용하여 Pump.fun에서 코인을 구매한 다음 획득한 유동성으로 대출금을 상환했습니다.

Solana Memecoin Platform Pump.fun Alleges $2 Million Exploitation by Former Employee
Solana Memecoin 플랫폼 Pump.fun, 전 직원에 의해 200만 달러 착취 주장
In a startling revelation, Solana-based memecoin creation tool, Pump.fun, has publicly accused a former employee of exploiting the platform for approximately $2 million through a meticulously executed "bonding curve" attack.
놀랍게도 솔라나 기반 밈코인 생성 도구인 Pump.fun은 전직 직원이 꼼꼼하게 실행된 "결합 곡선" 공격을 통해 약 200만 달러에 플랫폼을 악용했다고 공개적으로 비난했습니다.
Details of the Exploit
익스플로잇 세부정보
According to Pump.fun's official statement released on May 16, the perpetrator, allegedly an ex-employee, exploited their privileged access to a "withdraw authority" mechanism, enabling them to manipulate the platform's internal systems.
5월 16일 발표된 Pump.fun의 공식 성명에 따르면, 전직 직원으로 추정되는 가해자는 "권한 철회" 메커니즘에 대한 권한 있는 액세스를 이용하여 플랫폼의 내부 시스템을 조작할 수 있었습니다.
The attack unfolded strategically. The individual leveraged flash loans from Raydium, a Solana lending protocol, to acquire a substantial amount of Solana tokens. These tokens were then utilized to purchase as many memecoins as possible on Pump.fun.
공격은 전략적으로 전개됐다. 해당 개인은 솔라나 대출 프로토콜인 레이디움(Raydium)의 플래시 대출을 활용해 상당한 양의 솔라나 토큰을 획득했습니다. 이 토큰은 Pump.fun에서 가능한 한 많은 밈코인을 구매하는 데 사용되었습니다.
As these memecoins reached their maximum value on their respective bonding curves, the exploiter accessed the liquidity within the bonding curves to repay the flash loans, leaving them with a net profit of approximately 12,300 SOL, valued at $1.9 million at the time of the incident. The entire operation was confined to a short window between 3:21 pm and 5:00 pm UTC on May 16.
이러한 밈코인이 각각의 본딩 곡선에서 최대 가치에 도달함에 따라 악용자는 플래시 대출을 상환하기 위해 본딩 곡선 내의 유동성에 접근하여 사건 당시 190만 달러 상당의 약 12,300 SOL의 순이익을 남겼습니다. 전체 작업은 5월 16일 오후 3시 21분부터 오후 5시(UTC) 사이의 짧은 기간으로 제한되었습니다.
Platform Response and Investigations
플랫폼 대응 및 조사
Following the discovery of the attack, Pump.fun promptly suspended trading on its platform. However, trading has since resumed. The platform has provided assurances that its smart contracts remain intact and that affected users will receive a full refund of their liquidity within 24 hours.
공격이 발견된 후 Pump.fun은 즉시 플랫폼 거래를 중단했습니다. 그러나 이후 거래가 재개됐다. 플랫폼은 스마트 계약이 그대로 유지되고 영향을 받은 사용자가 24시간 이내에 유동성을 전액 환불받을 수 있다는 보장을 제공했습니다.
Igor Igamberdiev, Head of Research at Wintermute, a prominent cryptocurrency market maker, initially suggested that the hack could be attributed to the leak of an internal private key, implicating a specific Pump.fun user known as "STACCoverflow." A series of cryptic posts by STACCoverflow seemingly acknowledged their involvement, expressing a nonchalant attitude towards the consequences and stating that they were "already fully doxxed."
저명한 암호화폐 시장 메이커인 Wintermute의 연구 책임자인 Igor Igamberdiev는 처음에 해킹이 내부 개인 키 유출로 인해 발생했을 수 있으며 "STACCoverflow"로 알려진 특정 Pump.fun 사용자가 연루되어 있을 수 있다고 제안했습니다. STACCoverflow의 일련의 비밀스러운 게시물은 그들의 참여를 인정한 것으로 보이며 결과에 대해 무심한 태도를 표현하고 "이미 완전히 신상 털기"를 당했다고 말했습니다.
Pump.fun has confirmed that it is closely collaborating with law enforcement authorities in their investigation but has refrained from disclosing the identity of the former employee involved. The platform has also not responded to immediate requests for further clarification.
Pump.fun은 조사에 있어 법 집행 기관과 긴밀히 협력하고 있음을 확인했지만 관련 전직 직원의 신원은 공개하지 않았습니다. 플랫폼은 또한 추가 설명을 위한 즉각적인 요청에 응답하지 않았습니다.
Market Impact and Lessons Learned
시장 영향과 교훈
The Pump.fun exploit has sent shockwaves through the cryptocurrency community, highlighting the ongoing vulnerabilities associated with DeFi (decentralized finance) platforms. The incident underscores the critical need for comprehensive security measures and stringent internal controls within DeFi protocols.
Pump.fun 익스플로잇은 암호화폐 커뮤니티를 통해 충격파를 보내 DeFi(분산 금융) 플랫폼과 관련된 지속적인 취약점을 부각시켰습니다. 이번 사건은 DeFi 프로토콜 내에서 포괄적인 보안 조치와 엄격한 내부 통제가 필요하다는 점을 강조합니다.
As the investigation continues, it is imperative that lessons are learned to enhance the overall security posture of the emerging DeFi ecosystem. Robust risk management frameworks, thorough code audits, and robust governance mechanisms are crucial to prevent similar incidents in the future.
조사가 계속됨에 따라 신흥 DeFi 생태계의 전반적인 보안 태세를 강화하기 위한 교훈을 얻는 것이 필수적입니다. 향후 유사한 사고를 방지하려면 강력한 위험 관리 프레임워크, 철저한 코드 감사, 강력한 거버넌스 메커니즘이 중요합니다.
부인 성명:info@kdj.com
제공된 정보는 거래 조언이 아닙니다. kdj.com은 이 기사에 제공된 정보를 기반으로 이루어진 투자에 대해 어떠한 책임도 지지 않습니다. 암호화폐는 변동성이 매우 높으므로 철저한 조사 후 신중하게 투자하는 것이 좋습니다!
본 웹사이트에 사용된 내용이 귀하의 저작권을 침해한다고 판단되는 경우, 즉시 당사(info@kdj.com)로 연락주시면 즉시 삭제하도록 하겠습니다.

































