|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
據 dYdX 稱,2024 年 7 月 23 日,當攻擊者更改 DNS 名稱伺服器並刪除 DNSSEC 時,「dYdX.exchange」網域遭到破壞

Two users lost approximately $31,000 in a recent DNS (Domain Name System) hijack of dYdX, according to a post-mortem analysis published by the decentralized exchange (DEX).
根據去中心化交易所 (DEX) 發布的事後分析,兩名用戶在 dYdX 最近的 DNS(網域名稱系統)劫持中損失了約 31,000 美元。
The incident occurred on July 23, 2024, when an attacker compromised the "dYdX.exchange" domain and changed the DNS nameservers, according to dYdX. The attacker also removed the DNSSEC, which is supposed to add a layer of trust to the DNS by providing authentication.
據 dYdX 稱,該事件發生於 2024 年 7 月 23 日,當時攻擊者入侵了「dYdX.exchange」網域並更改了 DNS 名稱伺服器。攻擊者還刪除了 DNSSEC,它應該透過提供身份驗證為 DNS 新增一層信任。
After discovering the attack, dYdX said it immediately contacted Squarespace's customer support, who began working to restore domain possession and fix the DNS nameserver resolution, which was completed within a few hours. However, there was a 30-minute delay in Squarespace's response due to third-party vendor maintenance.
dYdX 表示,發現攻擊後立即聯繫了 Squarespace 的客戶支持,後者開始努力恢復網域所有權並修復 DNS 網域伺服器解析,該工作在幾個小時內完成。不過,由於第三方供應商維護,Squarespace 的回應延遲了 30 分鐘。
During this delay, the attacker reportedly hosted a malicious site, which requested connected wallets to send ETH or any ERC20 token to the attacker's address. At the same time, dYdXs worked with SEAL to blacklist the site from crypto wallets such as Metamask and Phantom.
據報道,在此延遲期間,攻擊者託管了一個惡意網站,該網站要求連接的錢包將 ETH 或任何 ERC20 代幣發送到攻擊者的地址。同時,dYdXs 與 SEAL 合作,將該網站從 Metamask 和 Phantom 等加密錢包列入黑名單。
"2 users were affected with approximately $31,000 in lost funds due to this attack. dYdX trading is in contact with both affected users and is assisting in securing their wallets and is committed to recovering funds," dYdX explained in the post-mortem analysis.
「由於這次攻擊,2 名用戶受到影響,損失了約31,000 美元的資金。dYdX Trading 正在與這兩名受影響的用戶保持聯繫,協助保護他們的錢包,並致力於追回資金,」dYdX 在事後分析中解釋。
The identity of the attacker is still unknown, but they appear to be a fairly skilled actor, according to the post-mortem analysis, which raises the possibility of a social engineering attack, considering that the perpetrator deliberately chose a human-believable email address.
攻擊者的身份仍然未知,但根據事後分析,他們似乎是一個相當熟練的演員,考慮到犯罪者故意選擇了人類可信的電子郵件地址,這增加了社會工程攻擊的可能性。
Earlier this month, several decentralized finance (DeFi) applications were impacted by a large DNS hijacking incident, which also targeted multiple DEXs.
本月早些時候,多個去中心化金融(DeFi)應用程式受到大型 DNS 劫持事件的影響,該事件也針對多個 DEX。
The attack, which was later traced back to a vulnerability in Squarespace's domain registry, also compromised several other DeFi platforms, including Compound Finance and Pendle Finance.
這次攻擊後來被追溯到 Squarespace 網域註冊的漏洞,也損害了其他幾個 DeFi 平台,包括 Compound Finance 和 Pendle Finance。
免責聲明:info@kdj.com
所提供的資訊並非交易建議。 kDJ.com對任何基於本文提供的資訊進行的投資不承擔任何責任。加密貨幣波動性較大,建議您充分研究後謹慎投資!
如果您認為本網站使用的內容侵犯了您的版權,請立即聯絡我們(info@kdj.com),我們將及時刪除。
-
- 比特幣、eCash 分叉和空投動態:深入探討加密貨幣的最新爭議
- 2026-05-03 00:52:02
- 探索最近的 eCash 分叉、其作為高風險空投的分類,以及對比特幣和加密生態系統的更廣泛影響。
-
-
- 聯準會維持利率穩定,地緣政治緊張局勢引發比特幣價格下跌
- 2026-05-01 04:04:38
- 聯準會維持利率的決定,加上中東衝突,影響了比特幣的價格。分析近期趨勢和市場反應。
-
-
-
-
-
-

































