市值: $2.6509T 0.02%
體積(24小時): $83.075B 46.64%
  • 市值: $2.6509T 0.02%
  • 體積(24小時): $83.075B 46.64%
  • 恐懼與貪婪指數:
  • 市值: $2.6509T 0.02%
加密
主題
加密植物
資訊
加密術
影片
頭號新聞
加密
主題
加密植物
資訊
加密術
影片
bitcoin
bitcoin

$77206.799877 USD

-0.54%

ethereum
ethereum

$2480.536928 USD

-1.49%

tether
tether

$0.999766 USD

0.02%

bnb
bnb

$717.768301 USD

-0.81%

xrp
xrp

$1.398854 USD

0.93%

usd-coin
usd-coin

$0.999946 USD

0.01%

solana
solana

$100.783952 USD

-0.71%

tron
tron

$0.337610 USD

-0.52%

hyperliquid
hyperliquid

$79.006439 USD

-1.08%

zcash
zcash

$1143.411926 USD

0.63%

dogecoin
dogecoin

$0.082676 USD

-1.89%

monero
monero

$513.505414 USD

1.54%

chainlink
chainlink

$11.403390 USD

-0.09%

unus-sed-leo
unus-sed-leo

$8.960483 USD

-0.02%

cardano
cardano

$0.204348 USD

-2.23%

加密貨幣新聞文章

分類帳,供應鍊和加密安全:導航新威脅格局

2025/09/09 21:05

針對加密貨幣的最新供應鏈攻擊強調了警惕的需求。從折衷的NPM軟件包到AI驅動的利用,安全性至關重要。

分類帳,供應鍊和加密安全:導航新威脅格局

Ledger, Supply Chain, and Crypto Security: Navigating the New Threat Landscape

分類帳,供應鍊和加密安全:導航新威脅格局

The world of crypto security is constantly evolving, and recent events have highlighted the critical importance of supply chain integrity and the emerging risks associated with AI-driven coding. It's a wild west out there, and staying ahead of the game is essential to protect your digital assets.

加密安全世界一直在不斷發展,最近的事件強調了供應鏈完整性的至關重要性以及與AI驅動的編碼相關的新興風險。這是一個狂野的西部,並且在遊戲領先時,對於保護您的數字資產至關重要。

The NPM Supply Chain Breach: A Wake-Up Call

NPM供應鏈漏洞:喚醒電話

A large-scale supply chain attack targeting the Node Package Manager (NPM) sent shockwaves through the open-source community. A compromised NPM account led to the distribution of malicious packages downloaded over a billion times. Ledger's CTO, Charles Guillemet, rightly pointed out the JavaScript ecosystem was at risk. The attack silently swapped crypto addresses, diverting funds to the attackers.

針對節點軟件包管理器(NPM)的大規模供應鏈攻擊通過開源社區向衝擊波發送了衝擊波。折衷的NPM帳戶導致在十億次下載的惡意軟件包的分佈。萊傑的首席技術官查爾斯·吉勒梅特(Charles Guillemet)正確地指出,JavaScript生態系統處於危險之中。攻擊默默地交換了加密貨幣地址,將資金轉移給了攻擊者。

The good news? Hardware wallet users who meticulously verify transactions remain safe. However, those using software wallets were advised to avoid on-chain transactions until the situation was resolved. This incident underscores the fragility of software supply chains. Even though the financial damage was initially minimal, the potential for widespread chaos was undeniable. It's a reminder that a single compromised account can have massive repercussions.

好消息?精心驗證交易的硬件錢包用戶仍然安全。但是,建議那些使用軟件錢包的人避免鏈交易,直到解決情況為止。該事件強調了軟件供應鏈的脆弱性。即使財務損失最初是最小的,但不可否認的混亂的潛力也是不可否認的。這提醒您,一個折衷的帳戶可能會產生巨大的影響。

AI Coding Tools: A Double-Edged Sword for Crypto Security

AI編碼工具:一把雙刃劍用於加密安全

The increasing reliance on AI coding tools like Cursor introduces a new set of security challenges. The "CopyPasta Attack" demonstrated how malicious instructions could be slipped into rarely checked files, leading AI assistants to spread the payload across entire projects. Coinbase, a heavy Cursor user, aims for 50% AI-generated code by October 2025, a level of dependence that some experts consider reckless. This vulnerability isn't limited to Cursor; similar flaws exist in other widely used AI coding tools.

越來越多地依賴像光標這樣的AI編碼工具引入了一系列新的安全挑戰。 “複製攻擊”證明瞭如何將惡意指示滑入很少檢查的文件中,這導致AI助手在整個項目中傳播有效載荷。 Coinbase是一個重型光標用戶,目標是到2025年10月,目標是50%AI生成的代碼,這是一些專家認為魯ck的依賴水平。這種脆弱性不僅限於光標;在其他廣泛使用的AI編碼工具中也存在類似的缺陷。

While AI promises speed and efficiency, attackers are adapting quickly. The $3.1 billion in crypto losses in the first half of 2025, with AI-powered hacks playing a growing role, highlight the need for caution. Stricter review practices, separation of instructions from user input, and continuous monitoring designed for AI-specific threats are crucial. It's a trade-off between speed and security, and the crypto industry needs to find the right balance.

儘管AI承諾速度和效率,但攻擊者正在迅速適應。 2025年上半年,加密貨幣損失的31億美元損失,AI驅動的駭客扮演著越來越多的角色,強調了謹慎的需求。更嚴格的審核實踐,指令與用戶輸入的分離以及為AI特異性威脅設計的連續監視至關重要。這是速度和安全之間的權衡,加密貨幣行業需要找到正確的平衡。

Ledger's Stance: Verify, Verify, Verify!

Ledger的立場:驗證,驗證,驗證!

Guillemet's advice remains crucial: always verify your transactions and never blind sign. He also advocates for using a hardware wallet with a secure display to ensure transaction safety. Hardware wallets provide an essential layer of security by displaying the true destination address on a secure screen, making it harder for attackers to trick users.

Guillemet的建議仍然至關重要:始終驗證您的交易和永不盲目的信號。他還主張使用帶有安全顯示的硬件錢包來確保交易安全。硬件錢包通過在安全屏幕上顯示真實的目標地址來提供必不可少的安全層,從而使攻擊者更難欺騙用戶。

The Bottom Line: Vigilance is Key

底線:警惕是關鍵

The recent supply chain attacks and the emergence of AI-driven exploits serve as a stark reminder that crypto security is an ongoing battle. Whether it's auditing your dependencies, locking packages to safe versions, or enforcing strict supply-chain security, vigilance is paramount. And hey, maybe it’s time to dust off that hardware wallet you’ve been meaning to set up. Just sayin'.

最近的供應鏈攻擊以及AI驅動的漏洞的出現,這是一個明顯的提醒,即加密安全是一場持續的戰鬥。無論是審核您的依賴項,將軟件包鎖定到安全版本,還是執行嚴格的供應鏈安全性,警惕性都是至關重要的。嘿,也許是時候把您想設置的那個硬件錢包除塵了。只是說。

原始來源:cointribune

免責聲明:info@kdj.com

所提供的資訊並非交易建議。 kDJ.com對任何基於本文提供的資訊進行的投資不承擔任何責任。加密貨幣波動性較大,建議您充分研究後謹慎投資!

如果您認為本網站使用的內容侵犯了您的版權,請立即聯絡我們(info@kdj.com),我們將及時刪除。

2026年09月16日 其他文章發表於