市值: $2.2032T 1.06%
成交额(24h): $37.9282B -32.34%
  • 市值: $2.2032T 1.06%
  • 成交额(24h): $37.9282B -32.34%
  • 恐惧与贪婪指数:
  • 市值: $2.2032T 1.06%
加密货币
话题
百科
资讯
加密话题
视频
热门新闻
加密货币
话题
百科
资讯
加密话题
视频
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

加密货币新闻

中国交易员在币安黑客骗局中损失 100 万美元

2024/06/04 05:20

一名中国交易员在成为黑客骗局的受害者后损失了 100 万美元,该骗局涉及名为 Aggr 的 Google Chrome 促销插件。

中国交易员在币安黑客骗局中损失 100 万美元

A Chinese cryptocurrency trader has lost $1 million in a hacking scam perpetrated through a promotional Google Chrome plugin called Aggr. The plugin reportedly stole cookies from users, enabling hackers to bypass password and two-factor authentication (2FA) verification to access the victim’s Binance account.

一名中国加密货币交易商在通过名为 Aggr 的 Google Chrome 促销插件实施的黑客骗局中损失了 100 万美元。据报道,该插件窃取了用户的 cookie,使黑客能够绕过密码和双因素身份验证 (2FA) 验证来访问受害者的币安账户。

The trader, who goes by the handle CryptoNakamao on social media platform X, recounted the incident, which occurred on May 24. He noticed unusual trading activity in his Binance account after checking the Bitcoin price on the Binance app. By the time he sought assistance, the hacker had already withdrawn all the funds.

该交易员在社交媒体平台 X 上的账号为 CryptoNakamao,他讲述了 5 月 24 日发生的事件。在检查了币安应用程序上的比特币价格后,他注意到自己的币安账户中存在异常交易活动。当他寻求帮助时,黑客已经撤回了所有资金。

The trader claimed that the hackers accessed his web browser cookie data through the Aggr Chrome plugin. He had installed the plugin to gain insights from prominent traders, unaware that it was designed to steal browsing data and cookies. The hackers used the stolen cookies to hijack active user sessions without needing passwords or authentication, enabling them to carry out multiple leveraged trades and profit by manipulating low liquidity trading pairs.

该交易员声称,黑客通过 Aggr Chrome 插件访问了他的网络浏览器 cookie 数据。他安装该插件是为了从著名交易员那里获取见解,但没有意识到该插件的目的是窃取浏览数据和 cookie。黑客利用窃取的 cookie 劫持活跃用户会话,无需密码或身份验证,使他们能够进行多种杠杆交易,并通过操纵低流动性交易对来获利。

Despite the hacker's inability to directly withdraw funds due to 2FA, they used the cookies and active login sessions to execute trades. The hacker bought several tokens in the Tether (USDT) trading pair with high liquidity and placed limit sell orders at inflated prices in Bitcoin (BTC), USD Coin (USDC), and other low liquidity trading pairs. They then opened leveraged positions, bought large amounts, and completed cross-trading. Cross-trading involves offsetting buy and sell orders for the same asset without recording the trade on the exchange.

尽管由于 2FA,黑客无法直接提取资金,但他们还是使用 cookie 和主动登录会话来执行交易。黑客在高流动性的 Tether(USDT)交易对中购买了多个代币,并在比特币(BTC)、美元币(USDC)等低流动性交易对中以高价下达了限价卖单。然后他们开立杠杆头寸,大量买入,完成交叉交易。交叉交易涉及抵消同一资产的买卖订单,而不在交易所记录交易。

Accusations Against Binance

针对币安的指控

The trader accused Binance of failing to implement necessary security measures despite the unusually high trading activity on his account. He also claimed that the exchange did not take timely action even after he reported the issue. According to the trader, Binance was aware of the fraudulent plugin and was conducting an internal investigation but did not inform users or take preventive measures.

该交易员指责币安未能实施必要的安全措施,尽管其账户的交易活动异常高。他还声称,即使在他报告问题后,交易所也没有及时采取行动。该交易员表示,币安已意识到该欺诈性插件,并正在进行内部调查,但没有通知用户或采取预防措施。

“Binance did nothing even though it knew of the theft and frequent cross-trading. Hackers manipulated accounts for over an hour, causing extremely abnormal transactions in multiple currency pairs without any risk control; Binance failed to freeze the funds of the obvious hacker’s single account on the platform in time,” the trader wrote.

“尽管币安知道盗窃事件和频繁的交叉交易,但它没有采取任何行动。黑客操纵账户一个多小时,在没有任何风控的情况下导致多个货币对交易极度异常;币安未能及时冻结明显黑客在平台上的单一账户的资金,”该交易员写道。

Binance’s Response

币安的回应

Yi He, co-founder of Binance, refuted CryptoNakamao's claims and clarified the situation on social media, stating, “Look closely; this user's account was breached because their own computer was hacked; they are a lost cause. After the hack, the hacker could not withdraw funds, so the hacker sold the victim’s coins, which led to trading losses.”

币安联合创始人何一驳斥了 CryptoNakamao 的说法,并在社交媒体上澄清了情况,他表示:“仔细看;该用户的帐户因自己的计算机遭到黑客攻击而被泄露;他们是注定失败的。黑客入侵后,无法提取资金,于是黑客出售了受害者的币,从而导致交易损失。”

“We sympathize with your experience, but according to the information we have learned so far, the reason for your asset loss is that your related devices were manipulated because of the installation of malicious plug-ins. Unfortunately, we have no way to compensate for such cases that have nothing to do with Binance,” the exchange stated.

“我们对您的遭遇表示同情,但根据目前了解到的信息,您资产损失的原因是您的相关设备因安装恶意插件而被操纵。不幸的是,我们无法对此类与币安无关的案件进行赔偿。”该交易所表示。

Nakamao, however, disputed Binance's assessment, alleging that the exchange had been aware of the malicious plugin for some time and had even encouraged a key opinion leader (KOL) to gather more information from the hacker.

然而,Nakamao 对币安的评估提出异议,声称该交易所已经意识到该恶意插件有一段时间了,甚至鼓励关键意见领袖 (KOL) 从黑客那里收集更多信息。

On her part, Yi He warned users about the dangers of logging into accounts with active cookie plugins to avoid the inconvenience of typing their passwords each time. “Binance is not able to compensate users when their own login devices are compromised,” she stated.

何怡则警告用户使用活动cookie插件登录帐户的危险,以避免每次输入密码带来的不便。 “当用户自己的登录设备受到损害时,币安无法补偿用户,”她表示。

免责声明:info@kdj.com

所提供的信息并非交易建议。根据本文提供的信息进行的任何投资,kdj.com不承担任何责任。加密货币具有高波动性,强烈建议您深入研究后,谨慎投资!

如您认为本网站上使用的内容侵犯了您的版权,请立即联系我们(info@kdj.com),我们将及时删除。

2026年07月27日 发表的其他文章