市值: $2.2043T 0.58%
體積(24小時): $56.8553B 3.76%
  • 市值: $2.2043T 0.58%
  • 體積(24小時): $56.8553B 3.76%
  • 恐懼與貪婪指數:
  • 市值: $2.2043T 0.58%
加密
主題
加密植物
資訊
加密術
影片
頭號新聞
加密
主題
加密植物
資訊
加密術
影片
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

加密貨幣新聞文章

DeFi 平台Compound Finance 和 Celer Network 遭受網路釣魚攻擊

2024/07/11 21:05

加密借貸平台Compound Finance和Celer Network的網站遭到攻擊,將使用者重新導向到惡意釣魚網站

DeFi 平台Compound Finance 和 Celer Network 遭受網路釣魚攻擊

The websites of crypto lending platform Compound Finance and Celer Network have been attacked, redirecting users to a malicious phishing site, according to multiple security researchers on Friday.

據多名安全研究人員週五稱,加密借貸平台Compound Finance和Celer Network的網站遭到攻擊,將用戶重定向到惡意網路釣魚網站。

Compound, one of the longest-established decentralized finance (DeFi) applications, holds assets worth over $2 billion, according to data from DeFiLlama. Celer’s cBridge allows users to send tokens between 14 blockchains, processing over $200 million in volume last month.

根據 DeFiLlama 的數據,Compound 是歷史最悠久的去中心化金融 (DeFi) 應用程式之一,擁有價值超過 20 億美元的資產。 Celer 的 cBridge 允許用戶在 14 個區塊鏈之間發送代幣,上個月處理量超過 2 億美元。

Security advisor to the Compound DAO, Michael Lewellen, posted a community alert via X (formerly Twitter), urging users to avoid the platform’s website. A total of 90 minutes passed before the attack was confirmed by Compound Finance. The breach was highlighted earlier by ZachXBT via Telegram.

Compound DAO 的安全顧問 Michael Lewellen 透過 X(以前稱為 Twitter)發布了社群警報,敦促用戶避開該平台的網站。總共過了 90 分鐘,Compound Finance 才確認攻擊。 ZachXBT 早些時候透過 Telegram 強調了這個漏洞。

ALERT: The https://t.co/vSAGYl6wwJ URL has been compromised and is currently hosting a phishing site. DO NOT interact with the https://t.co/vSAGYl6wwJ website until further notice.The Compound protocol itself is not impacted and all smart contract funds are safe.

警報:https://t.co/vSAGYl6wwJ URL 已洩露,目前正在託管一個網路釣魚網站。在另行通知之前,請勿與 https://t.co/vSAGYl6wwJ 網站互動。

Celer Network alerted users four hours later to a similar attack that “seems to be hitting multiple projects at the same time.” Pseudonymous security researcher Samczsun suspects the breaches to have come from Squarespace. A list of other domains that may be at risk was compiled by DeFiLlama’s 0xngmi.

四小時後,Celer Network 向用戶發出類似攻擊的警報,該攻擊「似乎同時攻擊多個項目」。匿名安全研究員 Samczsun 懷疑這些漏洞來自 Squarespace。 DeFiLlama 的 0xngmi 編制了可能面臨風險的其他網域清單。

This type of attack, known as a “front-end” attack, is a relatively common vector for crypto hackers. The method doesn’t rely on finding a bug to exploit within the underlying smart contract code, instead simply replacing the project’s website with a malicious version.

這種類型的攻擊被稱為「前端」攻擊,是加密貨幣駭客相對常見的攻擊方式。此方法不依賴在底層智慧合約程式碼中尋找可利用的錯誤,而是簡單地用惡意版本取代專案的網站。

A potential attacker must compromise the domain name service (DNS) registrar, generally using financial incentives or social engineering techniques on an employee. In response to the front-end attack that hit Curve Finance in June 2022, the CEO of Namecheap (the DNS registrar responsible) stated that a customer service agent was compromised, either being hacked or exploited with bitcoin.

潛在的攻擊者必須破壞網域服務 (DNS) 註冊商,通常對員工使用經濟誘因或社會工程技術。針對 2022 年 6 月 Curve Finance 遭受的前端攻擊,Namecheap(負責 DNS 註冊商)的執行長表示,一名客戶服務代理受到了威脅,要么被駭客攻擊,要么被比特幣利用。

Dear @iwantmyname, looks like something is compromised on your side (most likely, name servers – they seem to override what the UI tells them to serve). Please do something.For everyone else: we switched nameserver, but don't rush to use https://t.co/vOeMYOTq0l – wait a bit

親愛的@iwantmyname,看起來您這邊的某些東西受到了損害(最有可能的是名稱伺服器 - 它們似乎覆蓋了 UI 告訴它們服務的內容)。請做點什麼。

Similar incidents have affected many major DeFi platforms, such as Curve Finance, Cream Finance, Pancake Swap, Balancer, Frax and Velodrome, among others.

類似事件影響了許多主要的 DeFi 平台,例如 Curve Finance、Cream Finance、Pancake Swap、Balancer、Frax 和 Velodrome 等。

Previous hacks often involve cloning the original website, but swapping out key elements which can lead to users’ wallets crafting malicious transactions. This could be to transfer funds directly to an address controlled by the hacker, or to “harvest” token approvals.

先前的駭客攻擊通常涉及克隆原始網站,但交換可能導致用戶的錢包進行惡意交易的關鍵元素。這可能是將資金直接轉移到駭客控制的地址,或「收穫」代幣批准。

This approvals harvesting technique was used to devastating effect in the $120 million BadgerDAO hack of December 2021.

這種批准收集技術在 2021 年 12 月發生的價值 1.2 億美元的 BadgerDAO 駭客事件中被利用,造成了毀滅性的影響。

Over the course of 12 days, BadgerDAO users inadvertently signed malicious approval transactions which granted the exploiter permission to spend tokens directly from the victims’ wallets. Now-bankrupt Celsius was among the victims, losing 897 BTC (then valued at over $40 million) before later forfeiting $22 million in compensation due to an ‘unforced error’.

在 12 天的時間裡,BadgerDAO 用戶無意中簽署了惡意批准交易,該交易允許攻擊者直接從受害者的錢包使用代幣。現已破產的攝氏度是受害者之一,損失了 897 比特幣(當時價值超過 4000 萬美元),後來由於「非受迫性錯誤」而失去了 2200 萬美元的賠償。

Here is the current whereabouts as well as the total loss: $120.3M (with ~2.1k BTC + 151 ETH) @BadgerDAO pic.twitter.com/fJ4hJcMWTq

以下是目前的行蹤以及總損失:1.203 億美元(約 2.1k BTC + 151 ETH)@BadgerDAO pic.twitter.com/fJ4hJcMWTq

Despite today’s incident, Compound’s back-end code is considered among the most secure in DeFi, with any changes requiring scrutiny via a fully on-chain governance process.

儘管發生了今天的事件,Compound 的後端程式碼被認為是 DeFi 中最安全的程式碼之一,任何變更都需要透過完全鏈上治理流程進行審查。

Low-effort “forks”, however, regularly find themselves exploited due to dodgy collateral or basic errors when setting up new markets.

然而,省力的「分叉」經常發現自己在建立新市場時由於不可靠的抵押品或基本錯誤而被利用。

Compound itself hasn’t been entirely without its issues in the past, though.

不過,Compound 本身過去並非完全沒有問題。

? Alert: @compoundfinance's Twitter account has been compromised. Do not click on any links posted from their account.A phishing link (compound-labs[.]xyz) was spotted 16 hours ago.Stay vigilant and ensure the safety of your assets by avoiding suspicious links. pic.twitter.com/yoa1RM4P4E

? 警報:@compoundfinance 的 Twitter 帳戶已被盜用。請勿點擊其帳戶發布的任何連結。 pic.twitter.com/yoa1RM4P4E

The project’s X account was compromised in December 2023 to spread a phishing link, promising free COMP, the project’s native token.

該項目的 X 帳戶於 2023 年 12 月被盜,傳播了一個網絡釣魚鏈接,承諾免費 COMP(該項目的原生代幣)。

In September and October of 2021, a total of almost $150 million worth of COMP was accidentally distributed as excess rewards to users. Another incident the following year saw the platform’s $830 million ETH market frozen for a week.

2021 年 9 月和 10 月,總計價值近 1.5 億美元的 COMP 作為超額獎勵意外分發給了用戶。第二年的另一起事件導致該平台價值 8.3 億美元的 ETH 市場被凍結一周。

原始來源:protos

免責聲明:info@kdj.com

所提供的資訊並非交易建議。 kDJ.com對任何基於本文提供的資訊進行的投資不承擔任何責任。加密貨幣波動性較大,建議您充分研究後謹慎投資!

如果您認為本網站使用的內容侵犯了您的版權,請立即聯絡我們(info@kdj.com),我們將及時刪除。

2026年08月08日 其他文章發表於