|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
该公司联系了信用协议 Aave,以检查其资金池是否受到影响。然而,Cyvers 确认 Aave 内的泳池是安全的。

Web3 decentralized finance (DeFi) protocol Dough Finance has become the latest victim of a flash loan attack, losing $1.8 million in digital assets. On July 12, Web3 security firm Cyvers detected multiple suspicious transactions and contacted credit protocol Aave to ascertain whether their pools were affected. While Cyvers confirmed that the Aave pools remained untouched, Dough Finance bore the brunt of the attack.
Web3 去中心化金融(DeFi)协议 Dough Finance 成为闪电贷攻击的最新受害者,损失了 180 万美元的数字资产。 7 月 12 日,Web3 安全公司 Cyvers 检测到多笔可疑交易,并联系信用协议 Aave 以确定其矿池是否受到影响。虽然 Cyvers 确认 Aave 矿池没有受到影响,但 Dough Finance 首当其冲地受到了攻击。
According to Cyvers, the attacker was funded through zero-knowledge (ZK) protocol Railgun and exchanged the stolen USD Coin for Ethereum. In total, the attacker managed to siphon off 608 ETH, valued at approximately $1.8 million at the time of the incident.
根据 Cyvers 的说法,攻击者通过零知识(ZK)协议 Railgun 获得资金,并将被盗的美元代币兑换成以太坊。攻击者总共窃取了 608 ETH,事件发生时价值约 180 万美元。
Web3 security provider Olympix further noted that the exploit was a result of unvalidated call data within the “ConnectorDeleverageParaswap” contract. “The contract did not properly check the data it received during flash loan calls, allowing the attacker to manipulate it to his advantage,” explained Olympix.
Web3 安全提供商 Olympix 进一步指出,该漏洞是“ConnectorDeleverageParaswap”合约中未经验证的调用数据造成的。 Olympix 解释说:“该合约没有正确检查在闪电贷调用过程中收到的数据,从而使攻击者能够利用这些数据来谋取利益。”
This manipulation of the data allowed the attacker to pilfer the platform’s funds. Olympix highlighted that those who had deposited funds into Dough Finance’s exploited contract may be impacted by the hack. However, they emphasized that the Aave pools were not affected by this particular exploit.
这种对数据的操纵使攻击者能够窃取平台的资金。 Olympix 强调,那些将资金存入 Dough Finance 被利用合约的人可能会受到黑客攻击的影响。然而,他们强调 Aave 矿池并未受到这一特定漏洞的影响。
“If you have deposited into the exploited contract on Dough Finance, please consider withdrawing your funds to a secure wallet and monitor announcements from the Dough Finance team,” advised Olympix.
Olympix 建议:“如果您已存入 Dough Finance 上的被利用合约,请考虑将资金提取到安全钱包并关注 Dough Finance 团队的公告。”
“Please refrain from interacting with the protocol until the situation is resolved.”
“在情况得到解决之前,请不要与协议进行交互。”
As Dough Finance users anxiously await further updates, the broader crypto space has already lost over $1 billion in digital assets due to various incidents throughout the year.
当 Dough Finance 用户焦急地等待进一步的更新时,由于全年的各种事件,更广泛的加密货币领域已经损失了超过 10 亿美元的数字资产。
On July 3, blockchain security firm CertiK released its security report, revealing that losses from onchain incidents in the first half of 2024 reached $1.19 billion. A significant portion of these losses — nearly $500 million — were attributed to phishing attacks, while private key breaches also took a heavy toll, amounting to approximately $409 million in losses.
7月3日,区块链安全公司CertiK发布安全报告,显示2024年上半年链上事件造成的损失达到11.9亿美元。其中很大一部分损失(近 5 亿美元)归因于网络钓鱼攻击,而私钥泄露也造成了严重损失,损失约为 4.09 亿美元。
CertiK co-founder Ronghui Gu emphasized the critical need to implement multi-factor authentication methods, such as two-factor authentication (2FA) and security keys, to bolster protection against phishing attempts.
CertiK 联合创始人 Ronghui Gu 强调,迫切需要实施双因素身份验证 (2FA) 和安全密钥等多因素身份验证方法,以加强防范网络钓鱼企图。
免责声明:info@kdj.com
所提供的信息并非交易建议。根据本文提供的信息进行的任何投资,kdj.com不承担任何责任。加密货币具有高波动性,强烈建议您深入研究后,谨慎投资!
如您认为本网站上使用的内容侵犯了您的版权,请立即联系我们(info@kdj.com),我们将及时删除。

































