|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Jupiter 是一家 DEX(去中心化交易所)聚合商,它警告用戶注意一種新的惡意軟體,該惡意軟體被打包為基於 Chrome 的擴展程序,名為 Bull Checker。

A new malware, disguised as a Chrome-based extension and named Bull Checker, has been targeting Solana-based DeFi users, leading to their assets being stolen. Jupiter, a DEX (decentralized exchange) aggregator, has warned users about this malicious extension.
一種新的惡意軟體偽裝成基於 Chrome 的擴充程序,名為 Bull Checker,一直針對基於 Solana 的 DeFi 用戶,導致他們的資產被盜。 DEX(去中心化交易所)聚合器 Jupiter 已向用戶發出有關此惡意擴充功能的警告。
The Bull Checker extension was reportedly advertised to show all the holders of any memecoin, and several Solana-based DeFi users encountered their assets being drained after installing the extension. As Jupiter's user base experienced and voiced similar incidents, the DEX aggregator investigated to find the source of the hacks. In an X post, it revealed its findings.
據報道,Bull Checker 擴充功能的廣告顯示了任何 memecoin 的所有持有者,一些基於 Solana 的 DeFi 用戶在安裝該擴充功能後遇到了資產被耗盡的情況。由於 Jupiter 的用戶群經歷並表達了類似事件,DEX 聚合器進行了調查,以找到駭客攻擊的根源。在一篇 X 帖子中,它透露了其發現。
"After extensive investigation, we have identified a malicious Chrome extension called “Bull Checker” that had targeted users on several Solana-related subreddits," the post stated. It further highlighted that those behind the extension advertised the product on Reddit, attempting to lure users by showing how they can make thousands of dollars with the extension.
貼文寫道:“經過廣泛調查,我們發現了一個名為“Bull Checker”的惡意 Chrome 擴展程序,它的目標是幾個與 Solana 相關的 Reddit 子版塊上的用戶。”它還進一步強調,該擴充背後的人在 Reddit 上宣傳該產品,試圖透過展示如何透過該擴充功能賺取數千美元來吸引用戶。
"Users with this extension would interact with the dApps as per normal, have the simulation show up as normal, but have the possibility of their tokens being maliciously transferred to another wallet upon transaction completion," the post explained. It also added, "If you have this extension (or similar extensions with extensive permissions you cannot trust), please remove it immediately."
該帖子解釋說:“使用此擴展程序的用戶將正常與 dApp 進行交互,模擬顯示正常,但交易完成後他們的代幣有可能被惡意轉移到另一個錢包。”它還補充說,“如果您有此擴展程序(或具有您無法信任的廣泛權限的類似擴展程序),請立即將其刪除。”
Upon installation, Bull Checker asks users for permission to read and change data, which should serve as a warning sign. However, many users might not notice this detail. Extensions that are safe to use typically only ask to read data. By allowing Bull Checker to modify data, it can manipulate recipient addresses on transactions, diverting funds from crypto transfers to a bad actor's wallet.
安裝後,Bull Checker 會詢問使用者讀取和更改資料的權限,這應作為警告信號。不過,很多用戶可能沒有註意到這個細節。可以安全使用的擴充功能通常只要求讀取資料。透過允許 Bull Checker 修改數據,它可以操縱交易中的收件人地址,將資金從加密貨幣轉移到不良行為者的錢包。
What's concerning about this malware is that the crypto drainer passes all simulation checks and cannot be detected as a tool developed and used by malicious entities. In a detailed report, Jupiter's pseudonymous founder, known as Meow, wrote, "Bull Checker is supposed to be a read-only extension that allows you to view the holders of memecoins. There should be no need for an extension like this to read or write data on all websites."
該惡意軟體令人擔憂的是,加密貨幣排水器通過了所有模擬檢查,並且無法被檢測為惡意實體開發和使用的工具。 Jupiter 的化名創始人 Meow 在一份詳細報告中寫道:「Bull Checker 應該是一個只讀擴展程序,允許您查看模因幣的持有者。應該不需要像這樣的擴展程序來讀取或在所有網站上寫入資料。
The report also includes advice for those interacting with offerings promoted in online communities: "Do not trust something just because someone mentioned it on Reddit or other media and it has many upvotes. Astroturfing and social engineering are very real."
該報告還為那些與線上社群推廣的產品互動的人提供了建議:「不要僅僅因為有人在Reddit 或其他媒體上提到某件事並且得到了很多支持就相信某件事。Astroturfing 和社會工程是非常真實的。
免責聲明:info@kdj.com
所提供的資訊並非交易建議。 kDJ.com對任何基於本文提供的資訊進行的投資不承擔任何責任。加密貨幣波動性較大,建議您充分研究後謹慎投資!
如果您認為本網站使用的內容侵犯了您的版權,請立即聯絡我們(info@kdj.com),我們將及時刪除。
-
- 比特幣、eCash 分叉和空投動態:深入探討加密貨幣的最新爭議
- 2026-05-03 00:52:02
- 探索最近的 eCash 分叉、其作為高風險空投的分類,以及對比特幣和加密生態系統的更廣泛影響。
-
-
- 聯準會維持利率穩定,地緣政治緊張局勢引發比特幣價格下跌
- 2026-05-01 04:04:38
- 聯準會維持利率的決定,加上中東衝突,影響了比特幣的價格。分析近期趨勢和市場反應。
-
-
-
-
-
-

































