市值: $2.1693T -2.59%
成交额(24h): $67.3751B 30.24%
  • 市值: $2.1693T -2.59%
  • 成交额(24h): $67.3751B 30.24%
  • 恐惧与贪婪指数:
  • 市值: $2.1693T -2.59%
加密货币
话题
百科
资讯
加密话题
视频
热门新闻
加密货币
话题
百科
资讯
加密话题
视频
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

加密货币新闻

DeFi 平台Compound Finance 和 Celer Network 遭受网络钓鱼攻击

2024/07/11 21:05

加密借贷平台Compound Finance和Celer Network的网站遭到攻击,将用户重定向到恶意钓鱼网站

DeFi 平台Compound Finance 和 Celer Network 遭受网络钓鱼攻击

The websites of crypto lending platform Compound Finance and Celer Network have been attacked, redirecting users to a malicious phishing site, according to multiple security researchers on Friday.

据多名安全研究人员周五称,加密借贷平台Compound Finance和Celer Network的网站遭到攻击,将用户重定向到恶意网络钓鱼网站。

Compound, one of the longest-established decentralized finance (DeFi) applications, holds assets worth over $2 billion, according to data from DeFiLlama. Celer’s cBridge allows users to send tokens between 14 blockchains, processing over $200 million in volume last month.

根据 DeFiLlama 的数据,Compound 是历史最悠久的去中心化金融 (DeFi) 应用程序之一,拥有价值超过 20 亿美元的资产。 Celer 的 cBridge 允许用户在 14 个区块链之间发送代币,上个月处理量超过 2 亿美元。

Security advisor to the Compound DAO, Michael Lewellen, posted a community alert via X (formerly Twitter), urging users to avoid the platform’s website. A total of 90 minutes passed before the attack was confirmed by Compound Finance. The breach was highlighted earlier by ZachXBT via Telegram.

Compound DAO 的安全顾问 Michael Lewellen 通过 X(以前称为 Twitter)发布了社区警报,敦促用户避开该平台的网站。总共过了 90 分钟,Compound Finance 才确认此次攻击。 ZachXBT 早些时候通过 Telegram 强调了这一漏洞。

ALERT: The https://t.co/vSAGYl6wwJ URL has been compromised and is currently hosting a phishing site. DO NOT interact with the https://t.co/vSAGYl6wwJ website until further notice.The Compound protocol itself is not impacted and all smart contract funds are safe.

警报:https://t.co/vSAGYl6wwJ URL 已被泄露,目前正在托管一个网络钓鱼网站。在另行通知之前,请勿与 https://t.co/vSAGYl6wwJ 网站互动。Compound 协议本身不受影响,所有智能合约资金都是安全的。

Celer Network alerted users four hours later to a similar attack that “seems to be hitting multiple projects at the same time.” Pseudonymous security researcher Samczsun suspects the breaches to have come from Squarespace. A list of other domains that may be at risk was compiled by DeFiLlama’s 0xngmi.

四小时后,Celer Network 向用户发出类似攻击的警报,该攻击“似乎同时攻击多个项目”。匿名安全研究员 Samczsun 怀疑这些漏洞来自 Squarespace。 DeFiLlama 的 0xngmi 编制了可能面临风险的其他域名列表。

This type of attack, known as a “front-end” attack, is a relatively common vector for crypto hackers. The method doesn’t rely on finding a bug to exploit within the underlying smart contract code, instead simply replacing the project’s website with a malicious version.

这种类型的攻击被称为“前端”攻击,是加密货币黑客相对常见的攻击方式。该方法不依赖于在底层智能合约代码中查找可利用的错误,而是简单地用恶意版本替换项目的网站。

A potential attacker must compromise the domain name service (DNS) registrar, generally using financial incentives or social engineering techniques on an employee. In response to the front-end attack that hit Curve Finance in June 2022, the CEO of Namecheap (the DNS registrar responsible) stated that a customer service agent was compromised, either being hacked or exploited with bitcoin.

潜在的攻击者必须破坏域名服务 (DNS) 注册商,通常对员工使用经济激励或社会工程技术。针对 2022 年 6 月 Curve Finance 遭受的前端攻击,Namecheap(负责 DNS 注册商)的首席执行官表示,一名客户服务代理受到了威胁,要么被黑客攻击,要么被比特币利用。

Dear @iwantmyname, looks like something is compromised on your side (most likely, name servers – they seem to override what the UI tells them to serve). Please do something.For everyone else: we switched nameserver, but don't rush to use https://t.co/vOeMYOTq0l – wait a bit

亲爱的@iwantmyname,看起来您这边的某些东西受到了损害(最有可能的是名称服务器 - 它们似乎覆盖了 UI 告诉它们服务的内容)。请做点什么。对于其他人:我们切换了名称服务器,但不要急于使用 https://t.co/vOeMYOTq0l – 稍等一下

Similar incidents have affected many major DeFi platforms, such as Curve Finance, Cream Finance, Pancake Swap, Balancer, Frax and Velodrome, among others.

类似事件影响了许多主要的 DeFi 平台,例如 Curve Finance、Cream Finance、Pancake Swap、Balancer、Frax 和 Velodrome 等。

Previous hacks often involve cloning the original website, but swapping out key elements which can lead to users’ wallets crafting malicious transactions. This could be to transfer funds directly to an address controlled by the hacker, or to “harvest” token approvals.

以前的黑客攻击通常涉及克隆原始网站,但交换可能导致用户的钱包进行恶意交易的关键元素。这可能是将资金直接转移到黑客控制的地址,或者“收获”代币批准。

This approvals harvesting technique was used to devastating effect in the $120 million BadgerDAO hack of December 2021.

这种批准收集技术在 2021 年 12 月发生的价值 1.2 亿美元的 BadgerDAO 黑客事件中被利用,造成了毁灭性的影响。

Over the course of 12 days, BadgerDAO users inadvertently signed malicious approval transactions which granted the exploiter permission to spend tokens directly from the victims’ wallets. Now-bankrupt Celsius was among the victims, losing 897 BTC (then valued at over $40 million) before later forfeiting $22 million in compensation due to an ‘unforced error’.

在 12 天的时间里,BadgerDAO 用户无意中签署了恶意批准交易,该交易允许攻击者直接从受害者的钱包中使用代币。现已破产的摄氏度是受害者之一,损失了 897 比特币(当时价值超过 4000 万美元),后来由于“非受迫性错误”而失去了 2200 万美元的赔偿。

Here is the current whereabouts as well as the total loss: $120.3M (with ~2.1k BTC + 151 ETH) @BadgerDAO pic.twitter.com/fJ4hJcMWTq

以下是当前的行踪以及总损失:1.203 亿美元(约 2.1k BTC + 151 ETH)@BadgerDAO pic.twitter.com/fJ4hJcMWTq

Despite today’s incident, Compound’s back-end code is considered among the most secure in DeFi, with any changes requiring scrutiny via a fully on-chain governance process.

尽管发生了今天的事件,Compound 的后端代码被认为是 DeFi 中最安全的代码之一,任何更改都需要通过完全链上治理流程进行审查。

Low-effort “forks”, however, regularly find themselves exploited due to dodgy collateral or basic errors when setting up new markets.

然而,省力的“分叉”经常发现自己在建立新市场时由于不可靠的抵押品或基本错误而被利用。

Compound itself hasn’t been entirely without its issues in the past, though.

不过,Compound 本身过去也并非完全没有问题。

? Alert: @compoundfinance's Twitter account has been compromised. Do not click on any links posted from their account.A phishing link (compound-labs[.]xyz) was spotted 16 hours ago.Stay vigilant and ensure the safety of your assets by avoiding suspicious links. pic.twitter.com/yoa1RM4P4E

? 警报:@compoundfinance 的 Twitter 帐户已被盗用。请勿点击其帐户发布的任何链接。16 小时前发现钓鱼链接 (compound-labs[.]xyz)。保持警惕,避免可疑链接,确保您的资产安全。 pic.twitter.com/yoa1RM4P4E

The project’s X account was compromised in December 2023 to spread a phishing link, promising free COMP, the project’s native token.

该项目的 X 帐户于 2023 年 12 月被盗,传播了一个网络钓鱼链接,承诺免费 COMP(该项目的原生代币)。

In September and October of 2021, a total of almost $150 million worth of COMP was accidentally distributed as excess rewards to users. Another incident the following year saw the platform’s $830 million ETH market frozen for a week.

2021 年 9 月和 10 月,总计价值近 1.5 亿美元的 COMP 作为超额奖励意外分发给了用户。第二年的另一起事件导致该平台价值 8.3 亿美元的 ETH 市场被冻结一周。

原文来源:protos

免责声明:info@kdj.com

所提供的信息并非交易建议。根据本文提供的信息进行的任何投资,kdj.com不承担任何责任。加密货币具有高波动性,强烈建议您深入研究后,谨慎投资!

如您认为本网站上使用的内容侵犯了您的版权,请立即联系我们(info@kdj.com),我们将及时删除。

2026年07月28日 发表的其他文章