市值: $2.1622T -0.84%
體積(24小時): $50.0999B -16.65%
  • 市值: $2.1622T -0.84%
  • 體積(24小時): $50.0999B -16.65%
  • 恐懼與貪婪指數:
  • 市值: $2.1622T -0.84%
加密
主題
加密植物
資訊
加密術
影片
頭號新聞
加密
主題
加密植物
資訊
加密術
影片
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

加密貨幣新聞文章

Dough Finance Protocol 在閃電貸攻擊中損失 196 萬美元

2024/07/13 13:00

週五早上,另一個 DeFi 協議成為了漏洞的受害者。 Dough Finance,一個用於創建非託管流動性市場的開源協議

Dough Finance Protocol 在閃電貸攻擊中損失 196 萬美元

DeFi protocol Dough Finance fell victim to a flash loan attack on Friday morning, leading to the theft of nearly $2 million in user funds. The project’s team announced they are working to resolve the situation promptly.

週五上午,DeFi 協議 Dough Finance 遭遇閃貸攻擊,導致近 200 萬美元的用戶資金被盜。該專案團隊宣布他們正在努力盡快解決這個問題。

According to Web3 blockchain security platform Cyvers, it detected multiple suspicious transactions involving Dough Finance. The attacker manipulated the protocol's smart contract and stole $1.8 million in USDC.

據Web3區塊鏈安全平台Cyvers稱,它檢測到多筆涉及Dough Finance的可疑交易。攻擊者操縱了協議的智能合約,竊取了 180 萬美元的 USDC。

The attacker, funded through the zero-knowledge (ZK) protocol Railgun, swapped the misappropriated funds to Ethereum (ETH), initially obtaining 608 ETH.

攻擊者透過零知識(ZK)協議 Railgun 資助,將挪用的資金交換到以太坊(ETH),最初獲得了 608 ETH。

However, further analysis by Web3 security provider Olympix revealed that the exploit occurred due to “calldata within the ConnectorDeleverageParaswap contract.” The report highlighted that the contract failed to adequately check the flash loan calls data.

然而,Web3 安全供應商 Olympix 的進一步分析表明,該漏洞是由於「ConnectorDeleverageParaswap 合約內的呼叫資料」而發生的。該報告強調,該合約未能充分檢查閃電貸款調用數據。

The unvalidated calldata allowed the exploiter to manipulate the contract's data and send the funds to an Externally Owned Account (EAO), enabling them to withdraw the stolen crypto.

未經驗證的通話資料允許利用者操縱合約資料並將資金發送到外部擁有帳戶(EAO),使他們能夠提取被盜的加密貨幣。

Following the initial reports, a second batch of attacks occurred, leading to the loss of another $141,000 in USDC, raising the total crypto heist to $1.96 million.

繼最初的報告之後,第二批攻擊發生,導致 USDC 又損失 141,000 美元,使加密貨幣盜竊總額達到 196 萬美元。

However, lending protocol Aave's pools remained unaffected, according to Cyvers.

然而,Cyvers 表示,借貸協議 Aave 的資金池並未受到影響。

After the initial reports, the DeFi protocol acknowledged the attack and urged users to withdraw their remaining funds from the protocol. Later, Dough Finance announced it had identified and closed the exploit.

在收到初步報告後,DeFi 協議承認了攻擊,並敦促用戶從協議中提取剩餘資金。隨後,Dough Finance 宣布已發現並關閉了漏洞。

The project confirmed that “a few early Dough DeFi Smart Accounts (DSAs)” were victim to a sophisticated exploit.

該計畫證實,「一些早期的 Dough DeFi 智慧帳戶(DSA)」是複雜漏洞的受害者。

In a statement, Dough Finance assured that its team is actively working to address the incident, aiming to recover the funds and making investors whole.

Dough Finance 在一份聲明中保證,其團隊正在積極努力解決這一事件,旨在收回資金並讓投資者獲得補償。

Online reports also revealed that the team reached out to the exploiter through an on-chain message, offering to discuss a bounty if they had “exploited this vulnerability as a white or grey hat.”

線上報導還顯示,該團隊透過鏈上訊息聯繫了漏洞利用者,提出如果他們“以白帽或灰帽身份利用此漏洞”,則可以討論賞金。

The message also included the address where the funds should be directly transferred if the exploiter wished to return the stolen crypto.

該訊息還包括如果攻擊者希望歸還被盜加密貨幣,則應直接將資金轉移到的地址。

The exploiter has until Monday, July 15, 2024, at 23:00 UTC to contact the DeFi protocol. If the team doesn't receive an answer, they will “assume you appropriated the funds with unlawful intent and will pursue all criminal, legal, and administrative avenues available” to recover the misappropriated funds.

攻擊者必須在世界標準時間 2024 年 7 月 15 日星期一 23:00 之前聯繫 DeFi 協定。如果團隊沒有收到答复,他們將「假設您出於非法目的挪用資金,並將採取所有可用的刑事、法律和行政途徑」來追回被挪用的資金。

This incident highlights the ongoing threat posed by scammers to the DeFi sector. Earlier this week, several DeFi projects, including Compound Finance, were compromised in a phishing attack.

這起事件突顯了詐騙者對 DeFi 產業的持續威脅。本週早些時候,包括 Compound Finance 在內的多個 DeFi 專案在網路釣魚攻擊中遭到破壞。

The projects were reportedly victims of a DNS domain attack, which redirected users to a fake website. The copy website functioned as a drainer tool, capable of draining users' funds if they interacted with it.

據報道,這些項目是 DNS 網域攻擊的受害者,該攻擊將用戶重定向到虛假網站。該複製網站充當了一種流失工具,如果用戶與之互動,就會流失用戶的資金。

As a result, the teams of the affected projects quickly urged customers not to interact with the websites until further notice, to prevent any potential losses.

因此,受影響專案的團隊迅速敦促客戶在收到進一步通知之前不要與網站互動,以防止任何潛在的損失。

原始來源:bitcoinist

免責聲明:info@kdj.com

所提供的資訊並非交易建議。 kDJ.com對任何基於本文提供的資訊進行的投資不承擔任何責任。加密貨幣波動性較大,建議您充分研究後謹慎投資!

如果您認為本網站使用的內容侵犯了您的版權,請立即聯絡我們(info@kdj.com),我們將及時刪除。

2026年08月02日 其他文章發表於