市值: $2.9256T 1.33%
體積(24小時): $103.1186B 3.45%
  • 市值: $2.9256T 1.33%
  • 體積(24小時): $103.1186B 3.45%
  • 恐懼與貪婪指數:
  • 市值: $2.9256T 1.33%
加密
主題
加密植物
資訊
加密術
影片
頭號新聞
加密
主題
加密植物
資訊
加密術
影片
bitcoin
bitcoin

$85882.489292 USD

2.66%

ethereum
ethereum

$2726.255136 USD

1.23%

tether
tether

$0.999653 USD

-0.01%

bnb
bnb

$776.085808 USD

1.09%

xrp
xrp

$1.521475 USD

1.66%

usd-coin
usd-coin

$0.999947 USD

-0.02%

solana
solana

$121.201562 USD

2.45%

tron
tron

$0.334191 USD

-0.95%

zcash
zcash

$1376.191162 USD

-3.52%

hyperliquid
hyperliquid

$89.815179 USD

0.93%

dogecoin
dogecoin

$0.095724 USD

0.60%

chainlink
chainlink

$14.345509 USD

0.03%

monero
monero

$548.721371 USD

-0.11%

cardano
cardano

$0.253733 USD

0.94%

unus-sed-leo
unus-sed-leo

$8.970136 USD

1.38%

加密貨幣新聞文章

SlowMist 發現 FlashLoopAdapter 耗盡安全錢包的缺陷:為 DeFi 整合敲響警鐘

2026/10/03 08:05

SlowMist 報告了第三方 Aave 整合 FlashLoopAdapter 中的一個嚴重漏洞,導致兩個 Safe 多重簽名錢包中的 114 ETH 被耗盡。這一事件凸顯了外部 DeFi 模組的固有風險,即使有像 Safe 這樣強大的核心協議。

SlowMist 發現 FlashLoopAdapter 耗盡安全錢包的缺陷:為 DeFi 整合敲響警鐘

In the ever-evolving landscape of decentralized finance (DeFi), security is paramount, yet a recent incident brought to light by blockchain security firm SlowMist serves as a stark reminder that even the most fortified systems can be vulnerable through their external connections. A flaw in a third-party integration, dubbed FlashLoopAdapter, allowed an attacker to siphon approximately 114 ETH (valued around $305,000 at the time of reporting) from two Safe multisig wallets.

在不斷發展的去中心化金融 (DeFi) 領域,安全至關重要,但區塊鏈安全公司 SlowMist 最近曝光的一起事件清楚地提醒我們,即使是最堅固的系統也可能透過外部連接而受到攻擊。第三方整合中的一個名為 FlashLoopAdapter 的缺陷允許攻擊者從兩個 Safe 多重簽名錢包中竊取大約 114 ETH(在報告時價值約為 305,000 美元)。

The Achilles' Heel: FlashLoopAdapter's Access Control

阿基里斯之踵:FlashLoopAdapter 的存取控制

SlowMist's investigation pinpointed FlashLoopAdapter as the weak link. This component, designed to manage leveraged Aave v3 positions, was an external adapter, not a core part of the Safe multisig wallet protocol or the Aave v3 itself. This distinction is crucial: the core Safe contracts remained uncompromised. The vulnerability lay in FlashLoopAdapter's access control mechanisms for its open() and close() functions. These functions merely checked if a module was enabled by calling ISafe(msg.sender).isModuleEnabled(address(this)), a check that was unfortunately spoofable.

SlowMist 的調查指出 FlashLoopAdapter 是弱點。該元件旨在管理槓桿 Aave v3 頭寸,是一個外部適配器,而不是 Safe multisig 錢包協議或 Aave v3 本身的核心部分。這種區別至關重要:核心安全合約仍然不受影響。此漏洞存在於 FlashLoopAdapter 的 open() 和 close() 函數的存取控制機制中。這些函數只是透過呼叫 ISafe(msg.sender).isModuleEnabled(address(this)) 來檢查模組是否已啟用,不幸的是,該檢查是可欺騙的。

The attacker cleverly exploited this by deploying a fake Safe contract that would always return 'true' to this module enablement query. Furthermore, the _swap() function within FlashLoopAdapter allowed the caller to dictate the swap router and its data. The attacker leveraged this to set the router to one of the victim Safe wallets and then, through the execTransactionFromModule function (a legitimate Safe function for enabled modules), executed unauthorized transactions. The consequence? Collateral locked in Aave v3 positions via FlashLoopAdapter was drained.

攻擊者巧妙地利用了這一點,部署了一個虛假的 Safe 合約,該合約始終向該模組啟用查詢返回「true」。此外,FlashLoopAdapter 中的 _swap() 函數允許呼叫者指定交換路由器及其資料。攻擊者利用這一點將路由器設定為受害者安全錢包之一,然後透過 execTransactionFromModule 函數(啟用模組的合法安全函數)執行未經授權的交易。結果呢?透過 FlashLoopAdapter 鎖定在 Aave v3 部位的抵押品已被耗盡。

A Pattern of Peripheral Vulnerabilities

外圍設備漏洞的模式

This isn't SlowMist's first rodeo in identifying vulnerabilities stemming from peripheral integrations. The firm has a consistent track record of tracing significant losses back to adjacent components rather than core protocols. This incident echoes previous findings, such as the Liquid Network exploit that minted 3,998 L-BTC, where a similar attack vector bypassed core defenses through an external module. These cases collectively underscore a critical trend: while core protocols may be robust, the security perimeter often expands with every third-party integration.

這並不是慢霧第一次辨識外圍整合漏洞。該公司擁有將重大損失追溯到相鄰組件而不是核心協議的一貫記錄。這事件與先前的調查結果相呼應,例如 Liquid Network 漏洞鑄造了 3,998 個 L-BTC,其中類似的攻擊向量透過外部模組繞過了核心防禦。這些案例共同強調了一個關鍵趨勢:雖然核心協議可能很強大,但安全範圍往往會隨著每次第三方整合而擴展。

The Broader Implications for Safe Wallets and DeFi

對安全錢包和 DeFi 的更廣泛影響

Safe wallets are widely celebrated for their enhanced security in DeFi, particularly through their multisig capabilities. However, the FlashLoopAdapter incident highlights a fundamental truth: security is only as strong as its weakest link. When users grant third-party adapters interaction privileges with their wallets, these adapters inherit significant execution power. A flaw in the adapter's logic, even if the wallet itself functions perfectly, can be weaponized.

安全錢包因其在 DeFi 中增強的安全性而廣受讚譽,特別是透過其多重簽名功能。然而,FlashLoopAdapter 事件凸顯了一個基本事實:安全性的強弱取決於其最薄弱的環節。當用戶授予第三方適配器與其錢包互動的權限時,這些適配器將繼承強大的執行能力。即使錢包本身功能完美,適配器邏輯的缺陷也可以被武器化。

This serves as a potent reminder for anyone engaging with DeFi strategies that involve external modules. Authorizing an adapter is not a trivial decision; it entails trusting the adapter's code as much as, if not more than, the core protocol. The true blast radius of this exploit—how many other wallets had authorized FlashLoopAdapter before the flaw was discovered—remains an open question, underscoring the ongoing challenge of securing the interconnected DeFi ecosystem.

對於任何參與涉及外部模組的 DeFi 策略的人來說,這都是一個有力的提醒。授權適配器並不是一個簡單的決定;它需要像信任核心協定一樣信任適配器的程式碼。該漏洞的真正爆炸半徑(在發現該缺陷之前有多少其他錢包已授權 FlashLoopAdapter)仍然是一個懸而未決的問題,這突顯了保護互連的 ​​DeFi 生態系統所面臨的持續挑戰。

Looking Ahead: A Call for Scrutiny and Enhanced Vigilance

展望未來:呼籲審查並提高警惕

While the attacker's identity remains unknown and remediation steps are not publicly detailed, this incident provides valuable lessons. It's a clear call for increased scrutiny of third-party integrations and robust access control mechanisms. As DeFi continues to innovate, the onus is on both developers and users to prioritize comprehensive security audits and understand the full implications of every integration. In the end, staying safe in the digital frontier often comes down to paying attention to the fine print—and the code behind it. Let's keep those wallets safe and sound, one secure integration at a time!

雖然攻擊者的身份仍然未知,補救措施也沒有公開詳細信息,但這一事件提供了寶貴的教訓。這明確呼籲加強對第三方整合和強大的存取控制機制的審查。隨著 DeFi 的不斷創新,開發人員和使用者都有責任優先考慮全面的安全審核並了解每次整合的全面影響。最後,在數位前沿保持安全通常歸結為關注細則及其背後的程式碼。讓我們確保這些錢包安全無虞,一次一個安全整合!

原始來源:coinmarketcap

免責聲明:info@kdj.com

所提供的資訊並非交易建議。 kDJ.com對任何基於本文提供的資訊進行的投資不承擔任何責任。加密貨幣波動性較大,建議您充分研究後謹慎投資!

如果您認為本網站使用的內容侵犯了您的版權,請立即聯絡我們(info@kdj.com),我們將及時刪除。

2026年10月03日 其他文章發表於