|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
一名中國交易員在成為駭客騙局的受害者後損失了 100 萬美元,該騙局涉及名為 Aggr 的 Google Chrome 促銷外掛程式。

A Chinese cryptocurrency trader has lost $1 million in a hacking scam perpetrated through a promotional Google Chrome plugin called Aggr. The plugin reportedly stole cookies from users, enabling hackers to bypass password and two-factor authentication (2FA) verification to access the victim’s Binance account.
一名中國加密貨幣交易商在透過名為 Aggr 的 Google Chrome 促銷外掛程式實施的駭客騙局中損失了 100 萬美元。據報道,該外掛程式竊取了用戶的 cookie,使駭客能夠繞過密碼和雙重認證 (2FA) 驗證來存取受害者的幣安帳戶。
The trader, who goes by the handle CryptoNakamao on social media platform X, recounted the incident, which occurred on May 24. He noticed unusual trading activity in his Binance account after checking the Bitcoin price on the Binance app. By the time he sought assistance, the hacker had already withdrawn all the funds.
該交易員在社群媒體平台X 上的帳號為CryptoNakamao,他講述了5 月24 日發生的事件。交易活動。當他尋求幫助時,駭客已經撤回了所有資金。
The trader claimed that the hackers accessed his web browser cookie data through the Aggr Chrome plugin. He had installed the plugin to gain insights from prominent traders, unaware that it was designed to steal browsing data and cookies. The hackers used the stolen cookies to hijack active user sessions without needing passwords or authentication, enabling them to carry out multiple leveraged trades and profit by manipulating low liquidity trading pairs.
該交易員聲稱,駭客透過 Aggr Chrome 外掛程式存取了他的網頁瀏覽器 cookie 資料。他安裝該插件是為了從知名交易員那裡獲取見解,但沒有意識到該插件的目的是竊取瀏覽資料和 cookie。駭客利用竊取的 cookie 劫持活躍用戶會話,無需密碼或身份驗證,使他們能夠進行多種槓桿交易,並透過操縱低流動性交易對來獲利。
Despite the hacker's inability to directly withdraw funds due to 2FA, they used the cookies and active login sessions to execute trades. The hacker bought several tokens in the Tether (USDT) trading pair with high liquidity and placed limit sell orders at inflated prices in Bitcoin (BTC), USD Coin (USDC), and other low liquidity trading pairs. They then opened leveraged positions, bought large amounts, and completed cross-trading. Cross-trading involves offsetting buy and sell orders for the same asset without recording the trade on the exchange.
儘管由於 2FA,駭客無法直接提取資金,但他們還是使用 cookie 和主動登入會話來執行交易。駭客在高流動性的 Tether(USDT)交易對中購買了多個代幣,並在比特幣(BTC)、美元幣(USDC)等低流動性交易對中以高價下達了限價賣單。然後他們開立槓桿頭寸,大量買入,完成交叉交易。交叉交易涉及抵銷同一資產的買賣訂單,而不是在交易所記錄交易。
Accusations Against Binance
針對幣安的指控
The trader accused Binance of failing to implement necessary security measures despite the unusually high trading activity on his account. He also claimed that the exchange did not take timely action even after he reported the issue. According to the trader, Binance was aware of the fraudulent plugin and was conducting an internal investigation but did not inform users or take preventive measures.
該交易員指責幣安未能實施必要的安全措施,儘管其帳戶的交易活動異常高。他還聲稱,即使在他報告問題後,交易所也沒有及時採取行動。該交易員表示,幣安已意識到該欺詐性插件,並正在進行內部調查,但沒有通知用戶或採取預防措施。
“Binance did nothing even though it knew of the theft and frequent cross-trading. Hackers manipulated accounts for over an hour, causing extremely abnormal transactions in multiple currency pairs without any risk control; Binance failed to freeze the funds of the obvious hacker’s single account on the platform in time,” the trader wrote.
「儘管幣安知道盜竊事件和頻繁的交叉交易,但它沒有採取任何行動。駭客操縱帳戶一個多小時,在沒有任何風控的情況下導致多個貨幣對交易極度異常;幣安未能及時凍結明顯駭客在平台上的單一帳戶的資金,」該交易員寫道。
Binance’s Response
幣安的回應
Yi He, co-founder of Binance, refuted CryptoNakamao's claims and clarified the situation on social media, stating, “Look closely; this user's account was breached because their own computer was hacked; they are a lost cause. After the hack, the hacker could not withdraw funds, so the hacker sold the victim’s coins, which led to trading losses.”
幣安聯合創始人何一駁斥了 CryptoNakamao 的說法,並在社交媒體上澄清了情況,他說:「仔細看;該用戶的帳戶因自己的電腦遭到駭客攻擊而被洩露;他們是注定失敗的。駭客入侵後,無法提取資金,於是駭客出售了受害者的幣,從而導致交易損失。
“We sympathize with your experience, but according to the information we have learned so far, the reason for your asset loss is that your related devices were manipulated because of the installation of malicious plug-ins. Unfortunately, we have no way to compensate for such cases that have nothing to do with Binance,” the exchange stated.
「我們對您的遭遇表示同情,但根據目前了解到的信息,您資產損失的原因是您的相關設備因安裝惡意插件而被操縱。不幸的是,我們無法對此類與幣安無關的案件進行賠償。
Nakamao, however, disputed Binance's assessment, alleging that the exchange had been aware of the malicious plugin for some time and had even encouraged a key opinion leader (KOL) to gather more information from the hacker.
然而,Nakamao 對幣安的評估提出異議,聲稱該交易所已經意識到該惡意插件有一段時間了,甚至鼓勵關鍵意見領袖 (KOL) 從駭客那裡收集更多資訊。
On her part, Yi He warned users about the dangers of logging into accounts with active cookie plugins to avoid the inconvenience of typing their passwords each time. “Binance is not able to compensate users when their own login devices are compromised,” she stated.
何怡則警告使用者使用活動cookie外掛程式登入帳號的危險,以避免每次輸入密碼造成的不便。 「當用戶自己的登入設備受到損害時,幣安無法補償用戶,」她表示。
免責聲明:info@kdj.com
所提供的資訊並非交易建議。 kDJ.com對任何基於本文提供的資訊進行的投資不承擔任何責任。加密貨幣波動性較大,建議您充分研究後謹慎投資!
如果您認為本網站使用的內容侵犯了您的版權,請立即聯絡我們(info@kdj.com),我們將及時刪除。
-
- 比特幣、eCash 分叉和空投動態:深入探討加密貨幣的最新爭議
- 2026-05-03 00:52:02
- 探索最近的 eCash 分叉、其作為高風險空投的分類,以及對比特幣和加密生態系統的更廣泛影響。
-
-
- 聯準會維持利率穩定,地緣政治緊張局勢引發比特幣價格下跌
- 2026-05-01 04:04:38
- 聯準會維持利率的決定,加上中東衝突,影響了比特幣的價格。分析近期趨勢和市場反應。
-
-
-
-
-
-

































