市值: $2.209T 0.83%
體積(24小時): $68.1929B 8.38%
  • 市值: $2.209T 0.83%
  • 體積(24小時): $68.1929B 8.38%
  • 恐懼與貪婪指數:
  • 市值: $2.209T 0.83%
加密
主題
加密植物
資訊
加密術
影片
頭號新聞
加密
主題
加密植物
資訊
加密術
影片
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

加密貨幣新聞文章

Solana Memecoin 平台 Pump.fun 指控前員工利用價值 200 萬美元的資金

2024/05/18 14:21

Solana memecoins 平台 Pump.fun 指控一名前員工透過「聯合曲線」攻擊利用該平台獲利 190 萬美元。犯罪者利用特權存取來操縱協議的流動性,從 Raydium 借入資金並用它們在 Pump.fun 上購買代幣,然後用獲得的流動性償還貸款。

Solana Memecoin 平台 Pump.fun 指控前員工利用價值 200 萬美元的資金

Solana Memecoin Platform Pump.fun Alleges $2 Million Exploitation by Former Employee

Solana Memecoin 平台 Pump.fun 指控前員工剝削 200 萬美元

In a startling revelation, Solana-based memecoin creation tool, Pump.fun, has publicly accused a former employee of exploiting the platform for approximately $2 million through a meticulously executed "bonding curve" attack.

令人震驚的消息是,基於 Solana 的 memecoin 創建工具 Pump.fun 公開指控一名前員工通過精心執行的「聯合曲線」攻擊利用該平台獲取約 200 萬美元的利益。

Details of the Exploit

漏洞利用的詳細信息

According to Pump.fun's official statement released on May 16, the perpetrator, allegedly an ex-employee, exploited their privileged access to a "withdraw authority" mechanism, enabling them to manipulate the platform's internal systems.

根據 Pump.fun 5 月 16 日發布的官方聲明,肇事者據稱是一名前僱員,利用其特權訪問「撤回權限」機制,使他們能夠操縱平台的內部系統。

The attack unfolded strategically. The individual leveraged flash loans from Raydium, a Solana lending protocol, to acquire a substantial amount of Solana tokens. These tokens were then utilized to purchase as many memecoins as possible on Pump.fun.

進攻是戰略性展開的。該個人利用 Solana 借貸協議 Raydium 的閃電貸來獲取大量 Solana 代幣。然後,這些代幣被用來在 Pump.fun 上購買盡可能多的迷因幣。

As these memecoins reached their maximum value on their respective bonding curves, the exploiter accessed the liquidity within the bonding curves to repay the flash loans, leaving them with a net profit of approximately 12,300 SOL, valued at $1.9 million at the time of the incident. The entire operation was confined to a short window between 3:21 pm and 5:00 pm UTC on May 16.

當這些迷因幣在各自的聯合曲線上達到最大值時,剝削者利用聯合曲線內的流動性來償還閃電貸,從而獲得約 12,300 SOL 的淨利潤,在事件發生時價值 190 萬美元。整個作業僅限於世界標準時間 5 月 16 日下午 3:21 至下午 5:00 之間的短暫窗口內。

Platform Response and Investigations

平台回應和調查

Following the discovery of the attack, Pump.fun promptly suspended trading on its platform. However, trading has since resumed. The platform has provided assurances that its smart contracts remain intact and that affected users will receive a full refund of their liquidity within 24 hours.

發現攻擊後,Pump.fun 立即暫停了其平台上的交易。不過,交易已恢復。該平台已保證其智能合約保持完整,並且受影響的用戶將在 24 小時內獲得流動性全額退款。

Igor Igamberdiev, Head of Research at Wintermute, a prominent cryptocurrency market maker, initially suggested that the hack could be attributed to the leak of an internal private key, implicating a specific Pump.fun user known as "STACCoverflow." A series of cryptic posts by STACCoverflow seemingly acknowledged their involvement, expressing a nonchalant attitude towards the consequences and stating that they were "already fully doxxed."

著名加密貨幣做市商 Wintermute 的研究主管 Igor Igamberdiev 最初表示,這次駭客攻擊可能是由於內部私鑰洩漏造成的,這涉及到一個名為「STACoverflow」的特定 Pump.fun 用戶。 STACCoverflow 發布的一系列神秘貼文似乎承認了他們的參與,對後果表示了漠不關心的態度,並表示他們「已經完全被人肉搜尋」。

Pump.fun has confirmed that it is closely collaborating with law enforcement authorities in their investigation but has refrained from disclosing the identity of the former employee involved. The platform has also not responded to immediate requests for further clarification.

Pump.fun 已證實正在與執法部門密切合作進行調查,但沒有透露涉案前員工的身份。該平台也沒有立即回應進一步澄清的請求。

Market Impact and Lessons Learned

市場影響與經驗教訓

The Pump.fun exploit has sent shockwaves through the cryptocurrency community, highlighting the ongoing vulnerabilities associated with DeFi (decentralized finance) platforms. The incident underscores the critical need for comprehensive security measures and stringent internal controls within DeFi protocols.

Pump.fun 漏洞在加密貨幣社群引起了軒然大波,凸顯了與 DeFi(去中心化金融)平台相關的持續漏洞。這起事件凸顯了 DeFi 協議中迫切需要全面的安全措施和嚴格的內部控制。

As the investigation continues, it is imperative that lessons are learned to enhance the overall security posture of the emerging DeFi ecosystem. Robust risk management frameworks, thorough code audits, and robust governance mechanisms are crucial to prevent similar incidents in the future.

隨著調查的繼續,必須吸取教訓以增強新興 DeFi 生態系統的整體安全態勢。強大的風險管理框架、徹底的程式碼審計和強大的治理機制對於防止未來發生類似事件至關重要。

免責聲明:info@kdj.com

所提供的資訊並非交易建議。 kDJ.com對任何基於本文提供的資訊進行的投資不承擔任何責任。加密貨幣波動性較大,建議您充分研究後謹慎投資!

如果您認為本網站使用的內容侵犯了您的版權,請立即聯絡我們(info@kdj.com),我們將及時刪除。

2026年07月31日 其他文章發表於