|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
在 Tectonic 借贷协议遭受 7500 万美元的攻击后,Cronos 网络经历了严重的停顿,暴露了 DeFi 抵押品估值的漏洞以及集中式区块链控制的影响。

New York, NY – The crypto world recently buzzed with unsettling news as the Cronos network came to a grinding halt, courtesy of a cunning exploit targeting its decentralized lending protocol, Tectonic. This incident, resulting in an estimated $75 million loss, has once again shone a spotlight on the intricate vulnerabilities within the DeFi landscape and the surprising trade-offs inherent in some blockchain architectures.
纽约——加密货币世界最近充斥着令人不安的消息,克罗诺斯网络因针对其去中心化借贷协议 Tectonic 的狡猾利用而陷入瘫痪。此次事件预计造成 7500 万美元的损失,再次让人们关注 DeFi 领域错综复杂的漏洞以及某些区块链架构中固有的令人惊讶的权衡。
The 'Mango-Market Style' Maneuver on Tectonic
构造上的“芒果市场式”策略
构造上的“芒果市场式”策略
At the heart of the Tectonic exploit was a sophisticated “Mango-market style” pump-and-borrow attack. As blockchain researcher Weilin Li meticulously detailed, the attacker capitalized on Tectonic's governance token (TONIC) having a 20% collateral factor and notably thin liquidity. In a breathtaking 20-minute window, the price of TONIC was artificially inflated by a staggering 100-fold. With this dramatically revalued (and effectively worthless) collateral, the perpetrator then borrowed substantial amounts of other, more valuable assets from the lending pools. Before the network was halted, approximately $6 million of the stolen funds were successfully bridged to Ethereum, while a hefty $60 million remained trapped on the frozen Cronos chain.
Tectonic 漏洞利用的核心是复杂的“芒果市场式”拉高借钱攻击。正如区块链研究员 Weilin Li 详细介绍的那样,攻击者利用了 Tectonic 的治理代币(TONIC),该代币具有 20% 的抵押因子,且流动性明显较低。在令人惊叹的 20 分钟窗口内,TONIC 的价格被人为抬高了惊人的 100 倍。凭借这种大幅重估(实际上一文不值)的抵押品,犯罪者随后从贷款池中借入了大量其他更有价值的资产。在网络停止之前,大约 600 万美元的被盗资金已成功转入以太坊,而高达 6000 万美元的资金仍被困在冻结的克罗诺斯链上。
This wasn't a hack in the traditional sense, where a security flaw in code is exploited or a private key stolen. Instead, the contracts performed exactly as designed, but under a manipulated assumption about the collateral's true value. It’s a stark reminder that even robust code can be circumvented by exploiting market mechanics and valuation discrepancies – a critical distinction for anyone trusting their assets to DeFi protocols.
这不是传统意义上的黑客攻击,即利用代码中的安全缺陷或窃取私钥。相反,合约完全按照设计执行,但对抵押品的真实价值进行了操纵假设。这是一个鲜明的提醒,即使是强大的代码也可以通过利用市场机制和估值差异来规避——这对于任何将资产托付给 DeFi 协议的人来说都是一个关键区别。
The Double-Edged Sword of a Chain Halt
链停的双刃剑
链停的双刃剑
The Cronos network's ability to halt block production quickly after the exploit proved to be a critical, albeit controversial, intervention. Running on Tendermint Core with a capped number of 100 permissioned validators, Cronos demonstrated its capacity for rapid, coordinated action. This immediate cessation of operations managed to freeze the majority of the stolen assets – roughly $60 million – on the chain, preventing further movement by the attacker. While this action salvaged a significant portion of the funds, it also brought all other activity on the Cronos network to a standstill, impacting legitimate users who had no connection to the exploit. Open loans, trading positions, and scheduled payouts were all immobilized, highlighting the trade-off between speed and the inherent
事实证明,克罗诺斯网络在漏洞利用后迅速停止区块生产的能力是一项至关重要的干预措施,尽管存在争议。 Cronos 在 Tendermint Core 上运行,许可验证者数量上限为 100 个,展示了其快速、协调行动的能力。立即停止操作成功冻结了链上大部分被盗资产(约 6000 万美元),防止攻击者进一步行动。虽然这一行动挽救了很大一部分资金,但也使克罗诺斯网络上的所有其他活动陷入停滞,影响了与该漏洞无关的合法用户。未平仓贷款、交易头寸和预定支付都被固定化,凸显了速度和固有成本之间的权衡。
免责声明:info@kdj.com
所提供的信息并非交易建议。根据本文提供的信息进行的任何投资,kdj.com不承担任何责任。加密货币具有高波动性,强烈建议您深入研究后,谨慎投资!
如您认为本网站上使用的内容侵犯了您的版权,请立即联系我们(info@kdj.com),我们将及时删除。
-
- 冰岛的欧盟拒绝使 MiCA 联盟搁置,投票预计推迟
- 2026-08-31 16:05:01
- 冰岛最近就加入欧盟举行的公投对其加密行业产生了重大影响,推迟了 MiCA 的全面调整并创造了新的监管环境。
-
-
-
-
-
- Polygon 修补缺陷:主动升级强化网络安全
- 2026-08-31 16:05:01
- Polygon Labs 已通过奥斯汀和京都这两个硬分叉成功修复了关键的网络安全漏洞,保护其权益证明网络免受潜在干扰。
-
-
-

































