市值: $2.2043T 0.58%
體積(24小時): $56.8553B 3.76%
  • 市值: $2.2043T 0.58%
  • 體積(24小時): $56.8553B 3.76%
  • 恐懼與貪婪指數:
  • 市值: $2.2043T 0.58%
加密
主題
加密植物
資訊
加密術
影片
頭號新聞
加密
主題
加密植物
資訊
加密術
影片
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

加密貨幣新聞文章

隨著加密貨幣價值回升,網路釣魚攻擊加速,10 月損失超過 4,100 萬美元

2024/10/16 05:06

隨著加密貨幣重新獲得其價值,並且推出更有價值的代幣,針對個人錢包的攻擊正在加速。僅在前兩個

隨著加密貨幣價值回升,網路釣魚攻擊加速,10 月損失超過 4,100 萬美元

Cryptocurrency scams are accelerating as the value of digital assets rises and new tokens are launched rapidly. According to recent reports, phishing attacks have already resulted in staggering losses of over $41 million in the first two weeks of October.

隨著數位資產價值的上升和新代幣的迅速推出,加密貨幣詐騙正在加速發生。根據最近的報告,10 月的前兩週網路釣魚攻擊已造成超過 4,100 萬美元的驚人損失。

These scams often target individual wallets, and the latest figures from Certik show a concerning increase in all types of attacks during Q3. As more people venture into the world of crypto, wallet phishing and malicious links are becoming prevalent threats to be aware of.

這些詐騙通常針對個人錢包,Certik 的最新數據顯示,第三季所有類型的攻擊都有令人擔憂的成長。隨著越來越多的人涉足加密世界,錢包網路釣魚和惡意連結正成為需要注意的普遍威脅。

In the last 24 hours, another victim has lost a significant amount of $1.57 million after signing a "permit" phishing signature. This incident highlights the urgency to stay vigilant and be cautious of any suspicious links or requests to sign transactions from unknown sources.

在過去 24 小時內,另一名受害者在簽署「許可」網路釣魚簽名後損失了 157 萬美元。這一事件凸顯了保持警惕的緊迫性,並對任何可疑連結或來自未知來源的交易簽名請求保持警惕。

According to DefiHackLabs, October has seen eight total exploits, ranging in attack value from $100K to $2.4M, targeting individual wallets. While these sums may seem small compared to the large-scale exchange exploits we've seen in recent weeks, the ubiquity of these attacks and their impact on retail traders make phishing a major threat in Web3.

據 DefiHackLabs 稱,10 月總共出現了 8 起針對個人錢包的攻擊,攻擊價值從 10 萬美元到 240 萬美元不等。雖然與我們最近幾週看到的大規模交易所攻擊相比,這些金額似乎很小,但這些攻擊的普遍性及其對零售交易者的影響使網路釣魚成為 Web3 中的主要威脅。

These losses are also proving harder to recover, as attackers are moving the funds through DEX or mixers to complicate tracking efforts. Phishing hacks are adding to the tally of losses from more elaborate attacks, such as the validator address hacks and MEV exploits.

事實證明,這些損失也更難恢復,因為攻擊者透過 DEX 或混合器轉移資金,使追蹤工作變得更加複雜。網路釣魚駭客正在增加更複雜的攻擊(例如驗證器位址駭客和 MEV 漏洞)造成的損失。

Typically, phishing attacks will ask for actions to be signed through the user's wallet, such as approving a contract or signing another type of transfer or permission. Another common tactic involves fake phishing tokens targeting wallets with crypto balances in an attempt to redirect funds to a fake address. Permit phishing is particularly damaging, as it can gain permission to move multiple tokens. We saw an example of this just days ago, where a wallet was hacked for $1.4M in meme tokens.

通常,網路釣魚攻擊會要求透過使用者的錢包簽署操作,例如批准合約或簽署其他類型的轉讓或許可。另一種常見策略涉及假冒網路釣魚代幣,以具有加密貨幣餘額的錢包為目標,試圖將資金重定向到假地址。允許網路釣魚尤其具有破壞性,因為它可以獲得移動多個令牌的許可。幾天前我們看到了一個這樣的例子,一個錢包被駭客竊取了價值 140 萬美元的 meme 代幣。

While these attacks are not entirely new, they are accelerating in October due to the massive inflow of users into crypto. Most of these attacks are centered around Ethereum, being one of the most liquid chains with well-understood smart contracts. Attackers often use open-source contracts to generate malicious links or even build specific smart contracts that look realistic to carry out these scams.

雖然這些攻擊並不是全新的,但由於用戶大量湧入加密貨幣領域,這些攻擊在 10 月正在加速。大多數攻擊都以以太坊為中心,以太坊是流動性最強的鏈之一,擁有易於理解的智能合約。攻擊者經常使用開源合約來產生惡意鏈接,甚至建立看起來很現實的特定智能合約來實施這些詐騙。

Hacked X accounts deliver fake links

被駭的 X 帳戶提供虛假鏈接

Since the crypto community is largely based on X, these accounts are vulnerable to being hacked, which can pose a serious risk to users, especially in October.

由於加密社群主要基於 X,因此這些帳戶很容易被駭客攻擊,這可能會給用戶帶來嚴重的風險,尤其是在 10 月。

With the meme token frenzy coinciding with the general market recovery, all assets are being targeted, from BTC and blue chips down to the latest new meme token that promises to grow 1,000 times or more.

隨著 Meme 代幣的狂熱與市場整體復甦的同時,所有資產都成為目標,從 BTC 和藍籌股到預計將增長 1,000 倍或更多的最新 Meme 代幣。

One common attack vector involves hacked X handles, which could belong to influencers or meme token accounts. Instead of signing to buy a token, users might find their wallets emptied. Even pressing ‘connect wallet’ to a link from social media can lead to losing all the assets within that wallet. Sometimes, a malicious link will be disguised as a token recovery tool or even a protection against hacks.

常見的攻擊媒介涉及被駭的 X 帳號,這些帳號可能屬於影響者或 meme 代幣帳戶。用戶可能會發現他們的錢包被掏空,而不是簽名購買代幣。即使按「連接錢包」到社群媒體上的連結也可能導致失去該錢包內的所有資產。有時,惡意連結會偽裝成令牌復原工具,甚至是針對駭客的保護。

Links may also appear through Google ads, inviting users to join new chains. In this case, the scam website will ask the user to connect a wallet - and in that case, it's best to only risk the test with a new empty wallet.

連結也可能透過Google廣告出現,邀請用戶加入新的連鎖店。在這種情況下,詐騙網站將要求用戶連接錢包 - 在這種情況下,最好只用新的空錢包進行測試。

Finally, promising airdrops or point farming can lull users into putting their skepticism to sleep and granting permission to their wallets. One of the latest X handles to be hacked belonged to the SPX6900 hot meme token, exposing potential buyers to a malicious address. Sometimes, links are hidden in what appear to be harmless offers or download links. As more newcomers flock to meme tokens, keeping their wallets ready for trading at all times, we can expect to see more of these incidents.

最後,承諾的空投或積分耕種可以讓用戶放下懷疑,並允許他們的錢包使用。最新被駭客攻擊的 X 帳號之一屬於 SPX6900 熱門 meme 代幣,使潛在買家面臨惡意地址。有時,連結隱藏在看似無害的優惠或下載連結中。隨著越來越多的新手湧向 meme 代幣,並隨時準備好錢包進行交易,我們預計會看到更多此類事件。

Scam advertising on social media, as well as scam replies, often carry malicious links. Additionally, be wary of compromised Discord servers or expired invitations, and never install software or open calls to do so, as they may be designed to drain wallets or compromise private keys.

社群媒體上的詐騙廣告以及詐騙回應通常會帶有惡意連結。此外,請警惕受損的 Discord 伺服器或過期的邀請,切勿安裝軟體或公開呼叫來執行此操作,因為它們可能旨在耗盡錢包或洩露私鑰。

原始來源:cryptopolitan

免責聲明:info@kdj.com

所提供的資訊並非交易建議。 kDJ.com對任何基於本文提供的資訊進行的投資不承擔任何責任。加密貨幣波動性較大,建議您充分研究後謹慎投資!

如果您認為本網站使用的內容侵犯了您的版權,請立即聯絡我們(info@kdj.com),我們將及時刪除。

2026年08月12日 其他文章發表於