|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
多方計算 (MPC) 錢包提供商 Liminal 於 7 月 19 日發布了一份關於 7 月 18 日 WazirX 黑客攻擊的事後分析報告,聲稱其用戶界面

Multiparty computation (MPC) technology provider Liminal has released a July 19 post-mortem report on the July 18 WazirX hack, disputing the exchange’s claim that its user interface was responsible for the attack.
多方計算 (MPC) 技術提供商 Liminal 於 7 月 19 日發布了一份關於 7 月 18 日 WazirX 黑客攻擊的事後分析報告,對該交易所關於其用戶界面對此次攻擊負責的說法提出了質疑。
According to Liminal's report, the hack occurred because three WazirX devices were compromised. The devices were used to initiate transactions that were then modified by the attacker before being sent to Liminal's servers for approval.
根據 Liminal 的報告,這次駭客攻擊是因為三台 WazirX 設備遭到入侵。這些設備用於啟動交易,然後攻擊者修改交易,然後將其發送到 Liminal 的伺服器進行批准。
Liminal also claimed that its multisignature wallet was set up to provide a fourth signature if WazirX provided the other three. This meant that the attacker only needed to compromise three devices to perform the attack. The wallet was set up this way at the behest of WazirX, the wallet provider claimed.
Liminal 還聲稱,如果 WazirX 提供了其他三個簽名,其多重簽名錢包將提供第四個簽名。這意味著攻擊者只需破壞三台設備即可執行攻擊。錢包提供者聲稱,錢包是應 WazirX 的要求而設置的。
In a July 18 social media post, WazirX claimed that its private keys were secured with hardware wallets. However, WazirX said the attack “stemmed from a discrepancy between the data displayed on Liminal’s interface and the transaction’s actual contents.”
在 7 月 18 日的社群媒體貼文中,WazirX 聲稱其私鑰由硬體錢包保護。然而,WazirX 表示,這次攻擊「源自於 Liminal 介面上顯示的資料與交易實際內容之間的差異」。
According to the Liminal report, one of WazirX’s devices initiated a valid transaction involving the Gala Games (GALA) token. In response, Liminal’s server provided a “safeTxHash,” verifying the transaction's validity. However, the attacker then replaced this transaction hash with an invalid one, causing the transaction to fail.
根據 Liminal 報告,WazirX 的一台設備發起了一筆涉及 Gala Games(GALA)代幣的有效交易。作為回應,Liminal 的伺服器提供了一個“safeTxHash”,以驗證交易的有效性。然而,攻擊者隨後用無效的哈希值替換了該交易哈希值,導致交易失敗。
In Liminal’s view, the fact that the attacker was able to change this hash implies that the WazirX device had already been compromised before the transaction was attempted.
Liminal 認為,攻擊者能夠更改此雜湊值的事實意味著 WazirX 裝置在嘗試交易之前就已經受到損害。
The attacker then initiated an additional two transactions: one GALA and one Tether (USDT) transfer. In each of these three transactions, the attacker used a different WazirX admin account, for a total of three accounts used. All three of the transactions failed.
然後,攻擊者發起了另外兩筆交易:一筆 GALA 和一筆 Tether (USDT) 轉帳。在這三筆交易中,攻擊者都使用了不同的 WazirX 管理員帳戶,總共使用了三個帳戶。這三筆交易全部失敗。
After initiating these three failed transactions, the attacker extracted signatures from the transactions and used them to initiate a new, fourth transaction. The fourth transaction “was crafted in such a way that the fields used to verify policies were using legit transaction details” and “used the Nonce from the failed USDT transaction because that was the latest transaction.”
在啟動這三個失敗的交易後,攻擊者從交易中提取簽名並使用它們啟動新的第四個交易。第四筆交易“的設計方式是,用於驗證策略的字段使用合法的交易詳細信息”,並且“使用失敗的 USDT 交易中的隨機數,因為那是最新的交易。”
Because it used these “legit transaction details,” the Liminal server approved the transaction and provided a fourth signature. As a result, the transaction was confirmed on the Ethereum network, resulting in a transfer of funds from the joint multisig wallet to the attacker’s Ethereum account.
由於 Liminal 伺服器使用了這些“合法交易詳細資料”,因此它批准了該交易並提供了第四個簽名。結果,交易在以太坊網路上得到確認,導致資金從聯合多重簽章錢包轉移到攻擊者的以太坊帳戶。
Liminal denied that its servers caused incorrect information to be displayed through the Liminal UI. Instead, it claimed that the incorrect information was provided by the attacker, who had compromised WazirX computers. In an answer to the posed question “How did the UI show a different value from the actual payload within the transaction?” Liminal said:
Liminal 否認其伺服器導致 Liminal UI 顯示錯誤訊息。相反,它聲稱攻擊者提供了不正確的信息,該攻擊者已經破壞了 WazirX 計算機。在回答所提出的問題“UI 如何顯示與交易中實際有效負載不同的值?”利米納爾說:
Liminal also claimed that its servers were programmed to automatically provide a fourth signature if WazirX admins provided the other three. “Liminal only provides the final signature once the required number of valid signatures are received from the client’s side,” it stated, adding that in this case, “the transaction was authorised and signed by three of our client’s employees.”
Liminal 還聲稱,如果 WazirX 管理員提供了其他三個簽名,其伺服器就會自動提供第四個簽名。它表示:「只有在從客戶端收到所需數量的有效簽名後,Liminal才會提供最終簽名。」並補充說,在這種情況下,「交易由我們客戶的三名員工授權和簽署的。
The multisig wallet “was deployed by WazirX as per their configuration well before onboarding with Liminal,” and was “imported” into Liminal “per WazirX's request.”
多重簽名錢包“在使用 Liminal 之前就已由 WazirX 根據其配置進行部署”,並“按照 WazirX 的請求”“導入”到 Liminal 中。
Related: WazirX breach post-mortem: Dismantling the $230M attack
相關:WazirX 漏洞事後分析:拆除價值 2.3 億美元的攻擊
WazirX’s post claimed that it had implemented “robust security features.” For example, it had required that all transactions be confirmed by four out of five keyholders. Four of these keys belonged to WazirX employees and one to the Liminal team. In addition, it required three of the WazirX keyholders to use hardware wallets. All destination addresses were required to be added to a whitelist ahead of time, WazirX stated, which was “earmarked and facilitated on the interface by Liminal.”
WazirX 的貼文聲稱它已經實現了「強大的安全功能」。例如,它要求所有交易均須由五分之四的金鑰持有者確認。其中四把鑰匙屬於 WazirX 員工,一把屬於 Liminal 團隊。此外,它需要三個 WazirX 金鑰持有者才能使用硬體錢包。 WazirX 表示,所有目標位址都必須提前添加到白名單中,「Liminal 在介面上指定並提供了便利」。
Despite taking all of these precautions, the attacker “appear[s] to have possibly breached such security features, and the theft occurred.” WazirX called the attack a “a force majeure event beyond [its] control.” Even so, it vowed that it was “leaving no stone unturned to locate and recover the funds.”
儘管採取了所有這些預防措施,攻擊者「似乎可能違反了此類安全功能,並且發生了盜竊事件」。 WazirX 稱此攻擊是「超出其控制範圍的不可抗力事件」。即便如此,它仍發誓將「不遺餘力地尋找並追回資金」。
An estimated $235 million was lost in the WazirX attack. It was the largest centralized exchange hack since the DMM exploit of May 31, which resulted in even greater losses of $305 million.
WazirX 攻擊估計造成 2.35 億美元損失。這是自 5 月 31 日 DMM 漏洞利用以來最大的集中式交易所駭客攻擊事件,造成了 3.05 億美元的更大損失。
Magazine: WazirX hackers prepped 8 days before attack, swindlers fake fiat for USDT: Asia Express
雜誌:WazirX 駭客在攻擊前 8 天做好準備,騙子假冒法幣換取 USDT:Asia Express
免責聲明:info@kdj.com
所提供的資訊並非交易建議。 kDJ.com對任何基於本文提供的資訊進行的投資不承擔任何責任。加密貨幣波動性較大,建議您充分研究後謹慎投資!
如果您認為本網站使用的內容侵犯了您的版權,請立即聯絡我們(info@kdj.com),我們將及時刪除。
-
- 比特幣、eCash 分叉和空投動態:深入探討加密貨幣的最新爭議
- 2026-05-03 00:52:02
- 探索最近的 eCash 分叉、其作為高風險空投的分類,以及對比特幣和加密生態系統的更廣泛影響。
-
-
- 聯準會維持利率穩定,地緣政治緊張局勢引發比特幣價格下跌
- 2026-05-01 04:04:38
- 聯準會維持利率的決定,加上中東衝突,影響了比特幣的價格。分析近期趨勢和市場反應。
-
-
-
-
-
-

































