市值: $2.2043T 0.58%
成交额(24h): $56.8553B 3.76%
  • 市值: $2.2043T 0.58%
  • 成交额(24h): $56.8553B 3.76%
  • 恐惧与贪婪指数:
  • 市值: $2.2043T 0.58%
加密货币
话题
百科
资讯
加密话题
视频
热门新闻
加密货币
话题
百科
资讯
加密话题
视频
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

加密货币新闻

非对称研究帮助 Circle 识别并修复可能导致巨大损失的错误

2024/08/29 20:00

区块链网络安全公司 Asymmetry Research 帮助 Circle 发现了一个错误,如果不解决该错误可能会导致巨大损失。

非对称研究帮助 Circle 识别并修复可能导致巨大损失的错误

Blockchain cybersecurity firm Asymmetric Research has helped Circle identify a critical vulnerability that could've led to massive losses if not addressed. The vulnerability resided in Circle's Cross-Chain Transfer Protocol (CCTP) deployed on the Cosmos network, enabling the bridging of the firm's USDC stablecoin.

区块链网络安全公司 Asymmetry Research 帮助 Circle 发现了一个严重漏洞,如果不解决该漏洞可能会导致巨大损失。该漏洞存在于 Cosmos 网络上部署的 Circle 跨链传输协议(CCTP)中,可实现该公司 USDC 稳定币的桥接。

Asymmetric discovered the vulnerability in the noble-cctp module of the CCTP, which is used for cross-chain USDC transfers on the Cosmos-based Noble chain. The vulnerability allowed anyone to send a message to the CCTP, instructing it to burn (destroy) a specific amount of USDC tokens on the Cosmos Hub.

Asymmetry 发现了 CCTP 的 Nobel-cctp 模块中的漏洞,该模块用于在基于 Cosmos 的 Noble 链上进行跨链 USDC 转账。该漏洞允许任何人向 CCTP 发送消息,指示其在 Cosmos Hub 上销毁(销毁)特定数量的 USDC 代币。

However, due to a faulty verification process, the CCTP would instead mint (create) the specified amount of USDC tokens on the Noble chain. This vulnerability could've been exploited to mint an "infinite" amount of USDC tokens on the Noble chain, as observed by Asymmetric.

然而,由于验证过程错误,CCTP 会在 Noble 链上铸造(创建)指定数量的 USDC 代币。正如 Asymmetry 所观察到的,该漏洞可能被利用在 Noble 链上铸造“无限”数量的 USDC 代币。

“We privately disclosed a vulnerability to Circle via their bug bounty program,” the security firm noted in its report. “Notably, no malicious exploitation took place, and no user funds were lost. Circle promptly took action, once notified, to fix the bug.”

该安全公司在报告中指出:“我们通过其漏洞赏金计划私下向 Circle 披露了一个漏洞。” “值得注意的是,没有发生恶意利用,也没有用户资金损失。 Circle 在收到通知后立即采取行动修复该错误。”

The vulnerability could've enabled malicious actors to exploit the message sender verification process of the Noble Bridge, which is designed to ensure that only authorized parties (such as the TokenMessenger) can trigger USDC burns on the Cosmos Hub.

该漏洞可能使恶意行为者能够利用 Noble Bridge 的消息发送者验证过程,该过程旨在确保只有授权方(例如 TokenMessenger)才能触发 Cosmos Hub 上的 USDC 销毁。

This verification process is crucial to prevent unauthorized mints of USDC on the Noble chain. However, the verification was not being performed correctly, allowing anyone to send a message to the CCTP, instructing it to burn USDC on the Cosmos Hub.

此验证过程对于防止在 Noble 链上未经授权铸造 USDC 至关重要。然而,验证并未正确执行,任何人都可以向 CCTP 发送消息,指示其在 Cosmos Hub 上销毁 USDC。

As a result, an attacker could've exploited this vulnerability and triggered malicious USDC mints by sending a fake BurnMessage directly through a CCTP MessageTransmitter contract, using the noble-cctp module address and noble's chainid as the CCTP destination.

因此,攻击者可以利用此漏洞,通过使用 Nobel-cctp 模块地址和 Nobel 的 chainid 作为 CCTP 目的地,直接通过 CCTP MessageTransmitter 合约发送虚假 BurnMessage 来触发恶意 USDC 铸币。

“However, we did not identify any evidence of exploitation,” Asymmetric stated in its findings, adding that the vulnerability was patched quickly by Circle.

“但是,我们没有发现任何利用的证据,”Asymmetry 在其调查结果中表示,并补充说该漏洞已被 Circle 迅速修复。

Infinite Money Glitch at First Assumption

第一次假设时的无限金钱故障

Asymmetric initially observed that attackers could've exploited this vulnerability to mint as many USDC tokens as they wanted, which seemed like an "infinite money glitch" at first glance.

Asymmetry 最初观察到,攻击者可以利用此漏洞铸造任意数量的 USDC 代币,乍一看这似乎是一个“无限金钱故障”。

However, upon further investigation, they discovered that Noble enforced a mint limit of around 35 million USDC, preventing attackers from minting an unlimited amount of tokens. While this mint limit significantly reduced the potential impact of the vulnerability, it remained a critical issue that needed to be addressed promptly.

然而,经过进一步调查,他们发现 Noble 强制实施了约 3500 万个 USDC 的铸造限制,以防止攻击者无限量地铸造代币。虽然这一薄荷限制显​​着降低了漏洞的潜在影响,但它仍然是一个需要立即解决的关键问题。

Fortunately, thanks to Asymmetric's discovery and Circle's swift response, the vulnerability was patched before any malicious exploitation occurred. Additionally, no tokens were minted out of thin air, and no Noble Bridge users lost their funds.

幸运的是,由于 Asymmetry 的发现和 Circle 的迅速响应,该漏洞在任何恶意利用发生之前就得到了修补。此外,没有任何代币是凭空铸造的,Noble Bridge 用户也没有损失资金。

This incident highlights the importance of regular security audits and vulnerability scanning to identify and address potential risks in blockchain protocols and applications, especially those handling large volumes of user funds.

这一事件凸显了定期安全审计和漏洞扫描的重要性,以识别和解决区块链协议和应用程序中的潜在风险,特别是那些处理大量用户资金的协议和应用程序。

原文来源:livebitcoinnews

免责声明:info@kdj.com

所提供的信息并非交易建议。根据本文提供的信息进行的任何投资,kdj.com不承担任何责任。加密货币具有高波动性,强烈建议您深入研究后,谨慎投资!

如您认为本网站上使用的内容侵犯了您的版权,请立即联系我们(info@kdj.com),我们将及时删除。

2026年08月12日 发表的其他文章