|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
대출 프로토콜 Sonne Finance는 사이버 공격의 희생양이 되어 암호화폐 2천만 달러를 도난당했습니다. 공격자는 Sonne의 컴파운드 v2 포크의 버그를 악용하여 WETH(Wrapped Ether), VELO, soVELO 및 Wrapped USDC를 훔쳤습니다. 해커가 훔친 자금을 회수할 수 있도록 버그 현상금을 조사하는 등 조사가 진행 중입니다. 노력에도 불구하고 해커는 이미 도난당한 자산의 상당 부분을 세탁해 복구가 어려워졌습니다.

Sonne Finance Hack Exposes $20 Million Cryptocurrency Theft, Raising Concerns About Security Practices
Sonne Finance Hack, 2천만 달러 규모의 암호화폐 도난을 폭로해 보안 관행에 대한 우려 제기
In a brazen cyberattack that has sent shockwaves through the cryptocurrency community, lending protocol Sonne Finance has been forced to suspend operations after suffering a hack that siphoned $20 million worth of digital assets from the market. The incident has raised serious questions about the security protocols employed by cryptocurrency platforms and the potential risks faced by investors.
암호화폐 커뮤니티에 충격을 준 뻔뻔한 사이버 공격에서 대출 프로토콜인 Sonne Finance는 시장에서 2천만 달러 상당의 디지털 자산을 빼돌린 해킹을 겪은 후 운영을 중단해야 했습니다. 이 사건은 암호화폐 플랫폼에서 사용하는 보안 프로토콜과 투자자가 직면한 잠재적 위험에 대한 심각한 의문을 불러일으켰습니다.
On May 14th, around 10:30 pm UTC, Web3 security firm Cyvers detected a sophisticated attack targeting Sonne Finance's USD Coin (USDC) and Wrapped Ether (WETH) contracts. However, by the time Sonne Finance became aware of the situation 25 minutes later, the hacker had already stolen a substantial amount of cryptocurrency, including $20 million in WETH, VELO, soVELO, and Wrapped USDC.
5월 14일 오후 10시 30분(UTC) Web3 보안 회사 Cyvers는 Sonne Finance의 USD Coin(USDC) 및 Wrapped Ether(WETH) 계약을 표적으로 삼은 정교한 공격을 감지했습니다. 그러나 Sonne Finance가 25분 후 상황을 인지했을 때 해커는 이미 WETH, VELO, soVELO 및 Wrapped USDC에서 2천만 달러를 포함하여 상당한 양의 암호화폐를 훔쳤습니다.
"All markets on Optimism have been paused," Sonne Finance announced on Twitter shortly after learning of the breach. The protocol immediately partnered with Cyvers to investigate the incident and determine the extent of the damage.
Sonne Finance는 침해 사실을 알게 된 직후 트위터를 통해 "Optimism의 모든 시장이 일시 중지되었습니다"라고 발표했습니다. 프로토콜은 즉시 Cyvers와 협력하여 사건을 조사하고 피해 규모를 파악했습니다.
Stolen Funds Disappear into the Blockchain
도난당한 자금은 블록체인 속으로 사라집니다
Sonne Finance is actively exploring all options to recover the stolen funds, including negotiating a bug bounty with the hacker. In such arrangements, the hacker typically returns the majority of the stolen funds and keeps a portion as a reward for discovering a security flaw.
Sonne Finance는 해커와의 버그 현상금 협상을 포함하여 도난당한 자금을 복구하기 위한 모든 옵션을 적극적으로 모색하고 있습니다. 이러한 방식으로 해커는 일반적으로 도난당한 자금의 대부분을 반환하고 보안 결함을 발견한 대가로 일부를 유지합니다.
However, the hacker behind the Sonne Finance attack appears uninterested in negotiations. According to blockchain investigator PeckShield, the exploiter has already moved $7.8 million of the stolen funds to a new wallet address.
그러나 Sonne Finance 공격의 배후에 있는 해커는 협상에 관심이 없는 것으로 보입니다. 블록체인 조사 기관인 PeckShield에 따르면, 공격자는 이미 훔친 자금 중 780만 달러를 새 지갑 주소로 옮겼습니다.
The hacker then exchanged 59 WBTC for approximately 1,185 ETH and 183,000 Dai. This move suggests an attempt to launder the stolen funds through a privacy protocol like Tornado Cash, making them difficult to trace.
그런 다음 해커는 59 WBTC를 약 1,185 ETH 및 183,000 Dai로 교환했습니다. 이러한 움직임은 도난당한 자금을 Tornado Cash와 같은 개인 정보 보호 프로토콜을 통해 세탁하여 추적을 어렵게 만들려는 시도를 암시합니다.
Sonne Finance's Security Lapses Questioned
Sonne Finance의 보안 오류에 대한 의문
A post-mortem analysis conducted by Sonne Finance revealed that a donation attack was executed against the protocol's Compound v2 forks, which reportedly had a known vulnerability. Community member PoorBabyCorn accused Sonne Finance of using Compound v2 despite being aware of these risks and questioned whether this constituted "a premeditated backdoor."
Sonne Finance가 실시한 사후 분석에 따르면 알려진 취약점이 있는 것으로 알려진 프로토콜의 컴파운드 v2 포크에 대해 기부 공격이 실행된 것으로 나타났습니다. 커뮤니티 회원인 PoorBabyCorn은 Sonne Finance가 이러한 위험을 알고 있음에도 불구하고 컴파운드 v2를 사용하고 있다고 비난하고 이것이 "계획된 백도어"에 해당하는지 의문을 제기했습니다.
BlockTower Capital Hedge Fund Also Targeted
BlockTower Capital 헤지펀드도 표적이 됐다
Concurrently with the Sonne Finance attack, reports emerged that the main hedge fund of crypto institutional investment firm BlockTower Capital had also been exploited and partially drained. The stolen funds, whose value has not been disclosed, have not been recovered.
Sonne Finance 공격과 동시에 암호화폐 기관 투자 회사인 BlockTower Capital의 주요 헤지 펀드도 악용되어 부분적으로 유출되었다는 보고가 나왔습니다. 가치가 공개되지 않은 도난 자금은 회수되지 않았습니다.
BlockTower has enlisted the services of blockchain forensic analysts to trace the stolen funds and investigate the security breach. The exploiter remains at large, according to Bloomberg, citing sources familiar with the situation.
BlockTower는 도난당한 자금을 추적하고 보안 침해를 조사하기 위해 블록체인 포렌식 분석가의 서비스를 요청했습니다. 상황에 정통한 소식통을 인용해 블룸버그에 따르면 악용자는 여전히 큰 규모로 활동하고 있다고 전했습니다.
BlockTower's Previous Exploit
BlockTower의 이전 공격
In February 2022, BlockTower reportedly lost around $1.5 million in an exploit targeting the multichain exchange aggregator Dexible. On-chain intelligence platform Arkham Intelligence linked a wallet drained of $1.5 million to BlockTower, suggesting that the firm was significantly impacted by the Dexible attack.
2022년 2월 BlockTower는 멀티체인 거래소 애그리게이터 Dexible을 표적으로 한 익스플로잇으로 인해 약 150만 달러의 손실을 입은 것으로 알려졌습니다. 온체인 인텔리전스 플랫폼인 Arkham Intelligence는 150만 달러의 유출된 지갑을 BlockTower에 연결했는데, 이는 해당 회사가 Dexible 공격으로 인해 상당한 영향을 받았음을 시사합니다.
Industry Concerns and Lessons Learned
업계의 우려사항과 교훈
The Sonne Finance and BlockTower Capital hacks serve as stark reminders of the ongoing cybersecurity threats faced by the cryptocurrency industry. These incidents highlight the need for robust security protocols, thorough due diligence, and constant vigilance against malicious actors.
Sonne Finance 및 BlockTower Capital 해킹은 암호화폐 산업이 직면한 지속적인 사이버 보안 위협을 극명하게 상기시켜줍니다. 이러한 사고는 강력한 보안 프로토콜, 철저한 실사, 악의적인 행위자에 대한 지속적인 경계의 필요성을 강조합니다.
As the cryptocurrency ecosystem continues to grow and evolve, it is imperative for exchanges, protocols, and institutional investors to invest in state-of-the-art security measures to protect their assets and the trust of their customers. The industry must also prioritize collaboration and information sharing to enhance collective preparedness against cyberattacks.
암호화폐 생태계가 지속적으로 성장하고 발전함에 따라 거래소, 프로토콜 및 기관 투자자는 자산과 고객의 신뢰를 보호하기 위해 최첨단 보안 조치에 투자하는 것이 필수적입니다. 또한 업계는 사이버 공격에 대한 집단적 대비를 강화하기 위해 협업과 정보 공유를 우선시해야 합니다.
The consequences of security breaches can be severe, not only in terms of financial losses but also in reputational damage and erosion of investor confidence. By adopting best practices, implementing robust security frameworks, and promoting a proactive approach to cybersecurity, the cryptocurrency industry can mitigate these risks and maintain its long-term viability.
보안 위반의 결과는 금전적 손실뿐만 아니라 평판 손상 및 투자자 신뢰 저하 측면에서도 심각할 수 있습니다. 모범 사례를 채택하고, 강력한 보안 프레임워크를 구현하고, 사이버 보안에 대한 사전 예방적 접근 방식을 장려함으로써 암호화폐 산업은 이러한 위험을 완화하고 장기적인 생존 가능성을 유지할 수 있습니다.
부인 성명:info@kdj.com
제공된 정보는 거래 조언이 아닙니다. kdj.com은 이 기사에 제공된 정보를 기반으로 이루어진 투자에 대해 어떠한 책임도 지지 않습니다. 암호화폐는 변동성이 매우 높으므로 철저한 조사 후 신중하게 투자하는 것이 좋습니다!
본 웹사이트에 사용된 내용이 귀하의 저작권을 침해한다고 판단되는 경우, 즉시 당사(info@kdj.com)로 연락주시면 즉시 삭제하도록 하겠습니다.

































