|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
在 Tectonic 借貸協議遭受 7500 萬美元的攻擊後,Cronos 網路經歷了嚴重的停頓,暴露了 DeFi 抵押品估值的漏洞以及集中式區塊鏈控制的影響。

New York, NY – The crypto world recently buzzed with unsettling news as the Cronos network came to a grinding halt, courtesy of a cunning exploit targeting its decentralized lending protocol, Tectonic. This incident, resulting in an estimated $75 million loss, has once again shone a spotlight on the intricate vulnerabilities within the DeFi landscape and the surprising trade-offs inherent in some blockchain architectures.
紐約——加密貨幣世界最近充斥著令人不安的消息,克羅諾斯網路因針對其去中心化借貸協議 Tectonic 的狡猾利用而陷入癱瘓。這次事件預計造成 7,500 萬美元的損失,再次讓人們關注 DeFi 領域錯綜複雜的漏洞以及某些區塊鏈架構中固有的令人驚訝的權衡。
The 'Mango-Market Style' Maneuver on Tectonic
構造上的「芒果市場式」策略
構造上的「芒果市場式」策略
At the heart of the Tectonic exploit was a sophisticated “Mango-market style” pump-and-borrow attack. As blockchain researcher Weilin Li meticulously detailed, the attacker capitalized on Tectonic's governance token (TONIC) having a 20% collateral factor and notably thin liquidity. In a breathtaking 20-minute window, the price of TONIC was artificially inflated by a staggering 100-fold. With this dramatically revalued (and effectively worthless) collateral, the perpetrator then borrowed substantial amounts of other, more valuable assets from the lending pools. Before the network was halted, approximately $6 million of the stolen funds were successfully bridged to Ethereum, while a hefty $60 million remained trapped on the frozen Cronos chain.
Tectonic 漏洞利用的核心是複雜的「芒果市場式」拉高借錢攻擊。正如區塊鏈研究員 Weilin Li 詳細介紹的那樣,攻擊者利用了 Tectonic 的治理代幣(TONIC),該代幣具有 20% 的抵押因子,且流動性明顯較低。在令人驚嘆的 20 分鐘窗口內,TONIC 的價格被人為提高了驚人的 100 倍。憑藉這種大幅重估(實際上一文不值)的抵押品,犯罪者隨後從貸款池中藉入了大量其他更有價值的資產。在網路停止之前,大約 600 萬美元的被盜資金已成功轉入以太坊,而高達 6000 萬美元的資金仍被困在凍結的克羅諾斯鏈上。
This wasn't a hack in the traditional sense, where a security flaw in code is exploited or a private key stolen. Instead, the contracts performed exactly as designed, but under a manipulated assumption about the collateral's true value. It’s a stark reminder that even robust code can be circumvented by exploiting market mechanics and valuation discrepancies – a critical distinction for anyone trusting their assets to DeFi protocols.
這不是傳統意義上的駭客攻擊,即利用程式碼中的安全缺陷或竊取私鑰。相反,合約完全按照設計執行,但對抵押品的真實價值進行了操縱假設。這是一個鮮明的提醒,即使是強大的代碼也可以透過利用市場機制和估值差異來規避——這對於任何將資產託付給 DeFi 協議的人來說都是一個關鍵區別。
The Double-Edged Sword of a Chain Halt
連鎖的雙面刃
連鎖的雙面刃
The Cronos network's ability to halt block production quickly after the exploit proved to be a critical, albeit controversial, intervention. Running on Tendermint Core with a capped number of 100 permissioned validators, Cronos demonstrated its capacity for rapid, coordinated action. This immediate cessation of operations managed to freeze the majority of the stolen assets – roughly $60 million – on the chain, preventing further movement by the attacker. While this action salvaged a significant portion of the funds, it also brought all other activity on the Cronos network to a standstill, impacting legitimate users who had no connection to the exploit. Open loans, trading positions, and scheduled payouts were all immobilized, highlighting the trade-off between speed and the inherent
事實證明,克羅諾斯網路在漏洞利用後迅速停止區塊生產的能力是一項至關重要的干預措施,儘管存在爭議。 Cronos 在 Tendermint Core 上運行,許可驗證者數量上限為 100 個,展示了其快速、協調行動的能力。立即停止操作成功凍結了鏈上大部分被盜資產(約 6000 萬美元),防止攻擊者進一步行動。雖然這項行動挽救了很大一部分資金,但也使克羅諾斯網路上的所有其他活動陷入停滯,影響了與該漏洞無關的合法用戶。未平倉貸款、交易部位和預定支付都被固定化,凸顯了速度和固有成本之間的權衡。
免責聲明:info@kdj.com
所提供的資訊並非交易建議。 kDJ.com對任何基於本文提供的資訊進行的投資不承擔任何責任。加密貨幣波動性較大,建議您充分研究後謹慎投資!
如果您認為本網站使用的內容侵犯了您的版權,請立即聯絡我們(info@kdj.com),我們將及時刪除。
-
-
-
- 比特幣市場更新:價格、網路和機構訊號顯示謹慎樂觀
- 2026-08-31 11:35:02
- 比特幣面臨著複雜的市場格局,價格復甦受到現貨交易量低和未經證實的網路數據的挑戰。機構情緒仍然是關鍵。
-
-
-
-
-
-

































