시가총액: $2.7727T 4.18%
거래량(24시간): $112.9877B 43.32%
  • 시가총액: $2.7727T 4.18%
  • 거래량(24시간): $112.9877B 43.32%
  • 공포와 탐욕 지수:
  • 시가총액: $2.7727T 4.18%
암호화
주제
암호화
소식
cryptostopics
비디오
최고의 뉴스
암호화
주제
암호화
소식
cryptostopics
비디오
bitcoin
bitcoin

$81131.293825 USD

4.61%

ethereum
ethereum

$2629.223982 USD

5.70%

tether
tether

$0.999644 USD

0.06%

bnb
bnb

$762.001372 USD

0.94%

xrp
xrp

$1.419903 USD

7.09%

usd-coin
usd-coin

$0.999900 USD

0.01%

solana
solana

$111.987892 USD

5.89%

tron
tron

$0.337691 USD

0.55%

zcash
zcash

$1568.013373 USD

5.10%

hyperliquid
hyperliquid

$93.260937 USD

6.24%

dogecoin
dogecoin

$0.087155 USD

3.41%

monero
monero

$565.955936 USD

6.55%

chainlink
chainlink

$12.346409 USD

4.60%

cardano
cardano

$0.223297 USD

4.51%

unus-sed-leo
unus-sed-leo

$8.875656 USD

-0.19%

암호화폐 뉴스 기사

Thorswap, Thorchain 및 Bounties : Wild West의 암호화 보안 탐색

2025/09/12 20:15

최근의 Thorswap 및 Thorchain 사건에 대한 깊은 다이빙, 현상금 프로그램과 암호화 보안에 대한 광범위한 영향.

Thorswap, Thorchain 및 Bounties : Wild West의 암호화 보안 탐색

THORSwap, THORChain, and Bounties: Navigating Crypto Security in the Wild West

Thorswap, Thorchain 및 Bounties : Wild West의 암호화 보안 탐색

The world of decentralized finance (DeFi) moves fast, and recent events surrounding THORSwap, THORChain, and their bounty programs highlight both the promise and the perils of this exciting frontier. With a $1.2 million exploit linked to THORChain's founder, the spotlight is once again on security.

분산 금융 (Defi)의 세계는 빠르게 움직이며, Thorswap, Thorchain 및 그들의 현상금 프로그램을 둘러싼 최근의 사건은이 흥미 진진한 국경의 약속과 위험을 모두 강조합니다. Thorchain의 창립자와 관련된 120 만 달러의 악용으로 Spotlight는 다시 한 번 보안에 있습니다.

The $1.2 Million Incident: A Personal Wallet Breach

120 만 달러 사건 : 개인 지갑 침해

Recently, THORSwap issued a bounty offer following a $1.2 million exploit. Initial reports suggested a THORChain protocol vulnerability, but it was later clarified that the attack targeted a personal wallet belonging to THORChain co-founder John-Paul Thorbjornsen.

최근 Thorswap은 120 만 달러의 착취 후 현상금 제안을 발표했습니다. 초기 보고서는 Thorchain 프로토콜 취약점을 제안했지만 나중에이 공격은 Thorchain의 공동 창립자 John-Paul Thorbjornsen의 개인 지갑을 목표로한다는 것이 명확 해졌습니다.

Blockchain security firm PeckShield flagged the incident, which sent ripples through the crypto community. According to on-chain messages, THORSwap offered a reward for the return of the stolen funds, promising no legal action if the assets were returned within 72 hours. The message was simple: “Bounty offer: Return $THOR for reward. Contact @thorswap.finance or THORSwap discord for OTC deal.”

블록 체인 보안 회사 인 Peckshield는이 사건을 신고하여 암호화 커뮤니티를 통해 잔물결을 보냈습니다. 온 체인 메시지에 따르면, Thorswap은 도난당한 자금의 반환에 대한 보상을 제공했으며, 자산이 72 시간 이내에 반환 된 경우 법적 조치를 약속하지 않았습니다. 메시지는 간단했습니다.“현상금 제안 : 보상을 위해 $ Thor를 반환하십시오. @Thorswap.finance 또는 Thorswap discord에 문의하십시오.”

Social Engineering and Security Lapses

사회 공학 및 보안이 랩입니다

The breach appears to have been the result of a sophisticated social engineering attack. Blockchain analyst ZachXBT suggested North Korean hackers were involved, alleging that $1.35 million was stolen from Thorbjornsen’s wallet via a Telegram scam involving a deepfake Zoom call.

이 위반은 정교한 사회 공학 공격의 결과 인 것으로 보입니다. 블록 체인 분석가 Zachxbt는 북한 해커가 관여했다고 제안했다.

Thorbjornsen admitted that the MetaMask wallet linked to the attack was unprotected and stored in a logged-out Chrome profile. This contained both staked assets and personal funds. He speculated that 0-day exploits may have been used to access his iCloud Keychain or Chrome profile.

Thorbjornsen은 공격과 연결된 메타 마스크 지갑이 보호되지 않고 로그 아웃 크롬 프로파일에 저장되었음을 인정했습니다. 여기에는 자산과 개인 자금이 모두 포함되어 있습니다. 그는 0 일의 익스플로잇이 그의 iCloud 키 체인 또는 크롬 프로파일에 액세스하는 데 사용되었을 수 있다고 추측했다.

THORSwap's Response and Clarification

Thorswap의 반응 및 설명

THORSwap was quick to clarify that the THORChain protocol itself was not compromised. CEO Paper X stated that the incident was isolated to a user's personal wallet and did not affect the THORChain or THORSwap infrastructure.

Thorswap은 Thorchain 프로토콜 자체가 손상되지 않았다는 것을 명확하게 설명했습니다. CEO Paper X는이 사건이 사용자의 개인 지갑으로 고립되었으며 Thorchain 또는 Thorswap 인프라에는 영향을 미치지 않았다고 밝혔다.

The focus shifted to recovering the stolen assets, which included $1.03 million in Kyber Network tokens and $320,000 in THORSwap tokens. The bounty offer was a proactive attempt to recover the funds without further complications.

이 초점은 도난 자산 회수로 이동했으며, 여기에는 Kyber Network 토큰에서 1,030 만 달러, Thorswap 토큰에는 320,000 달러가 포함되었습니다. 현상금 제안은 더 이상의 합병증없이 자금을 회수하려는 적극적인 시도였습니다.

Recurring Security Concerns with THORChain

Thorchain과의 반복 보안 문제

This isn't the first time THORChain has faced security challenges. THORChain has dealt with multiple exploits since 2021, including attacks that drained about $13 million in just a few weeks. There was also the network insolvency announcement earlier this year that revealed a $93 million shortfall and hundreds of millions in debts. These incidents raise questions about the robustness of the platform.

Thorchain이 보안 문제에 직면 한 것은 이번이 처음이 아닙니다. Thorchain은 2021 년 이후 몇 주 만에 약 1,300 만 달러의 공격을 포함하여 여러 가지 악용을 다루었습니다. 올해 초 네트워크 파산 발표도 9 천 9 백만 달러의 부족과 수억 달러의 부채를 나타 냈습니다. 이 사건들은 플랫폼의 견고성에 대한 의문을 제기합니다.

Cross-Chain Swaps and Inherent Risks

크로스 체인 교환 및 고유 위험

Cross-chain swaps, while innovative, introduce inherent security risks. These systems act as bridges between different blockchains, often becoming vulnerable points of attack. The Bybit exploit earlier this year saw roughly $1.2 billion in stolen Ethereum flow through ThorChain, highlighting how these platforms can be used to obfuscate illicit funds.

크로스 체인 스왑은 혁신적이지만 고유 한 보안 위험을 도입합니다. 이 시스템은 다른 블록 체인 사이의 다리 역할을하며 종종 취약한 공격 지점이됩니다. 올해 초 Bybit Exploit은 Thorchain을 통해 Stolen Ethereum Flow가 약 12 ​​억 달러를 보냈으며, 이러한 플랫폼이 어떻게 불법 자금을 난독 화하는 데 사용될 수 있는지 강조했습니다.

Broader Implications for Crypto Security

암호화 보안에 대한 광범위한 영향

This incident serves as a stark reminder of the importance of robust personal wallet security. As the crypto landscape evolves, so do the tactics of malicious actors. Thorbjornsen’s advice to avoid storing sensitive keys on cloud services like iCloud or Google Drive is crucial.

이 사건은 강력한 개인 지갑 보안의 중요성을 완전히 상기시켜줍니다. 암호화 환경이 발전함에 따라 악의적 인 배우의 전술도 발전합니다. Icloud 또는 Google 드라이브와 같은 클라우드 서비스에 민감한 키를 저장하지 않도록 Thorbjornsen의 조언은 중요합니다.

The industry is continually experimenting with security enhancements like zero-knowledge proofs, multi-party computation wallets, and AI-driven monitoring. However, attackers often stay one step ahead. The consensus is that users need to use multi-device threshold signature wallets, such as Vultisig, to protect assets more securely.

업계는 지속적으로 제로 지식 증명, 다당 계산 지갑 및 AI 중심 모니터링과 같은 보안 향상을 실험하고 있습니다. 그러나 공격자들은 종종 한 발 앞서 있습니다. 합의는 사용자가 자산을보다 안전하게 보호하기 위해 Vultisig와 같은 다중 장치 임계 값 서명 지갑을 사용해야한다는 것입니다.

Final Thoughts: DeFi's Ongoing Balancing Act

최종 생각 : Defi의 지속적인 균형 균형 행위

So, where does this leave us? DeFi is still a bit like the Wild West, full of potential but also fraught with risk. While million-dollar losses might seem modest compared to billion-dollar hacks, they send a clear message: proceed with caution. Keep those keys safe, stay vigilant, and remember that in the world of crypto, security is everyone's responsibility. Stay safe out there, folks!

그렇다면 이것이 우리를 어디에 남겨 두나요? Defi는 여전히 Wild West와 약간 비슷하며 잠재력으로 가득 차 있지만 위험이 있습니다. 백만 달러짜리 손실은 10 억 달러 규모의 해킹에 비해 겸손 해 보일 수 있지만, 명확한 메시지를 보냅니다. 이러한 열쇠를 안전하게 지키고 경계를 유지하며 암호화의 세계에서 보안은 모든 사람의 책임이라는 것을 기억하십시오. 안전하게 지내세요!

원본 소스:coincentral

부인 성명:info@kdj.com

제공된 정보는 거래 조언이 아닙니다. kdj.com은 이 기사에 제공된 정보를 기반으로 이루어진 투자에 대해 어떠한 책임도 지지 않습니다. 암호화폐는 변동성이 매우 높으므로 철저한 조사 후 신중하게 투자하는 것이 좋습니다!

본 웹사이트에 사용된 내용이 귀하의 저작권을 침해한다고 판단되는 경우, 즉시 당사(info@kdj.com)로 연락주시면 즉시 삭제하도록 하겠습니다.

2026年09月20日 에 게재된 다른 기사