|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Wormhole 協議的貢獻者 Asymmetry Research 在 Cosmos 區塊鏈生態系統中發現了一個“重入漏洞”,該漏洞可能導致超過 1.5 億美元的損失。據 Cosmos 漏洞賞金計畫營運商 Asymmetry 和 Amulet 稱,儘管該漏洞很嚴重,但在任何利用行為發生之前,該漏洞已被私下披露並進行了修補。

Cosmos Blockchain Bug Patched, Preventing Potential $150 Million Loss
Cosmos 區塊鏈漏洞已修復,避免了 1.5 億美元的潛在損失
Asymmetric Research, a security firm actively contributing to the Wormhole interoperability protocol, has uncovered a critical vulnerability within the Cosmos blockchain ecosystem. This reentrancy bug, if exploited, could have potentially compromised over $150 million worth of digital assets.
Asymmetry Research 是一家積極為 Wormhole 互通性協議做出貢獻的安全公司,它發現了 Cosmos 區塊鏈生態系統中的一個關鍵漏洞。這種重入漏洞如果被利用,可能會損害價值超過 1.5 億美元的數位資產。
Prompt Action Averts Disaster
及時採取行動避免災難
Asymmetric responsibly disclosed the vulnerability to the Cosmos development team, who promptly addressed the issue before any malicious actors could take advantage. "We privately disclosed the vulnerability through the Cosmos HackerOne Bug Bounty program and the issue is now patched," Asymmetric stated in an official release. "No malicious exploitation took place and no funds were lost."
Asym 負責任地向 Cosmos 開發團隊披露了漏洞,在任何惡意行為者利用之前立即解決了該問題。 「我們透過 Cosmos HackerOne Bug Bounty 計畫私下披露了該漏洞,該問題現已修復,」Asymmetry 在一份官方新聞稿中表示。 “沒有發生惡意利用,也沒有資金損失。”
Jessy Irwin, CEO of Amulet, an organization contracted by the Interchain Foundation to oversee the bug bounty program and coordinate security for the Cosmos ecosystem, confirmed the report and the subsequent release of an advisory notice.
Amulet 是 Interchain 基金會簽約的組織,負責監督漏洞賞金計畫並協調 Cosmos 生態系統的安全性,其執行長 Jessy Irwin 證實了該報告以及隨後發布的諮詢通知。
A First for Cosmos
Cosmos 的首次
The Cosmos ecosystem encompasses a network of blockchains that share common code and core modules. While no funds were lost due to this bug, its discovery marks a significant milestone for the ecosystem. It represents the first instance of a reentrancy vulnerability being identified within Cosmos, a platform widely regarded as one of the most secure blockchain technologies.
Cosmos 生態系統包含共享通用程式碼和核心模組的區塊鏈網路。雖然這個錯誤沒有造成任何資金損失,但它的發現標誌著生態系統的一個重要里程碑。它代表了 Cosmos 中發現的第一個可重入漏洞的實例,Cosmos 是一個被廣泛認為是最安全的區塊鏈技術之一的平台。
Inter-Blockchain Communication Vulnerability
區塊鏈間通訊漏洞
A key component of most Cosmos chains is the Inter-Blockchain Communication Protocol (IBC), a technology facilitating seamless communication and asset transfer between blockchains. Asymmetric's vulnerability discovery was specifically within ibc-go, a reference implementation of IBC utilized by numerous Cosmos chains.
大多數 Cosmos 鏈的關鍵組成部分是區塊鏈間通訊協議(IBC),這是一種促進區塊鏈之間無縫通訊和資產轉移的技術。 Asymmetry 的漏洞特別是在 ibc-go 中發現的,ibc-go 是眾多 Cosmos 鏈所使用的 IBC 參考實作。
"During the investigation of this issue, both Amulet and the IBC-go team independently assessed the potential impact to identify parties at risk and mitigate the severity," Irwin explained.
「在調查此問題期間,Amulet 和 IBC-go 團隊都獨立評估了潛在影響,以確定面臨風險的各方並減輕嚴重程度,」Irwin 解釋道。
Infinite Token Minting Threat
無限的代幣鑄造威脅
The vulnerability, categorized as a reentrancy bug, theoretically enabled an attacker to mint an infinite number of tokens on IBC-connected chains such as Osmosis, which hosts one of the largest decentralized finance (DeFi) ecosystems on Cosmos.
該漏洞被歸類為可重入漏洞,理論上使攻擊者能夠在IBC 連接的鏈上鑄造無限數量的代幣,例如Osmosis,它託管著Cosmos 上最大的去中心化金融(DeFi) 生態系統之一。
"While this vulnerability has been present in ibc-go since its inception, it only became exploitable due to recent developments in the Cosmos SDK ecosystem," Asymmetric revealed in a blog post. The vulnerability was triggered by the emergence of "IBC middleware," third-party applications built using CosmWasm, a WebAssembly-based smart contract runtime, that enables cross-blockchain token usage.
「雖然這個漏洞自 ibc-go 誕生以來就存在,但由於 Cosmos SDK 生態系統的最新發展,它才變得可利用,」Asymmetry 在一篇部落格文章中透露。該漏洞是由“IBC 中間件”的出現觸發的,“IBC 中間件”是使用CosmWasm 構建的第三方應用程序,CosmWasm 是一種基於WebAssembly 的智能合約運行時,可實現跨區塊鏈代幣使用。
Highlighting Cross-Chain Security Risks
凸顯跨鏈安全風險
"This vulnerability emphasizes the urgent need for intensified research into cross-chain security risks to safeguard the multichain ecosystem," remarked Jonathan Claudius, CEO of Asymmetric and former security chief at venture firm Jump Crypto. "This case demonstrates our commitment to identifying and neutralizing existential threats that could jeopardize the digital economy."
Asymmetry 執行長、創投公司 Jump Crypto 前安全主管 Jonathan Claudius 表示:“這一漏洞強調了加強對跨鏈安全風險研究的迫切需要,以保護多鏈生態系統。” “這個案例表明我們致力於識別和消除可能危及數位經濟的生存威脅。”
Conclusion
結論
The swift and effective response by Asymmetric Research and the Cosmos development team averted a potentially catastrophic loss of funds within the Cosmos blockchain ecosystem. This incident highlights the importance of continuous vulnerability monitoring and responsible disclosure practices within the blockchain industry. It also underscores the need for ongoing research into cross-chain security risks to ensure the resilience and security of the evolving multichain ecosystem.
Asymmetry Research 和 Cosmos 開發團隊迅速而有效的反應避免了 Cosmos 區塊鏈生態系統內潛在的災難性資金損失。這事件凸顯了區塊鏈產業持續漏洞監控和負責任的揭露實踐的重要性。它還強調需要持續研究跨鏈安全風險,以確保不斷發展的多鏈生態系統的彈性和安全性。
免責聲明:info@kdj.com
所提供的資訊並非交易建議。 kDJ.com對任何基於本文提供的資訊進行的投資不承擔任何責任。加密貨幣波動性較大,建議您充分研究後謹慎投資!
如果您認為本網站使用的內容侵犯了您的版權,請立即聯絡我們(info@kdj.com),我們將及時刪除。
-
- 比特幣、eCash 分叉和空投動態:深入探討加密貨幣的最新爭議
- 2026-05-03 00:52:02
- 探索最近的 eCash 分叉、其作為高風險空投的分類,以及對比特幣和加密生態系統的更廣泛影響。
-
-
- 聯準會維持利率穩定,地緣政治緊張局勢引發比特幣價格下跌
- 2026-05-01 04:04:38
- 聯準會維持利率的決定,加上中東衝突,影響了比特幣的價格。分析近期趨勢和市場反應。
-
-
-
-
-
-

































