市值: $2.2032T 1.06%
成交额(24h): $37.9282B -32.34%
  • 市值: $2.2032T 1.06%
  • 成交额(24h): $37.9282B -32.34%
  • 恐惧与贪婪指数:
  • 市值: $2.2032T 1.06%
加密货币
话题
百科
资讯
加密话题
视频
热门新闻
加密货币
话题
百科
资讯
加密话题
视频
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

加密货币新闻

Dough Finance Protocol 在闪电贷攻击中损失 196 万美元

2024/07/13 13:00

周五早上,另一个 DeFi 协议成为了漏洞的受害者。 Dough Finance,一个用于创建非托管流动性市场的开源协议

Dough Finance Protocol 在闪电贷攻击中损失 196 万美元

DeFi protocol Dough Finance fell victim to a flash loan attack on Friday morning, leading to the theft of nearly $2 million in user funds. The project’s team announced they are working to resolve the situation promptly.

周五上午,DeFi 协议 Dough Finance 遭遇闪贷攻击,导致近 200 万美元的用户资金被盗。该项目团队宣布他们正在努力尽快解决这一问题。

According to Web3 blockchain security platform Cyvers, it detected multiple suspicious transactions involving Dough Finance. The attacker manipulated the protocol's smart contract and stole $1.8 million in USDC.

据Web3区块链安全平台Cyvers称,它检测到多笔涉及Dough Finance的可疑交易。攻击者操纵了协议的智能合约并窃取了 180 万美元的 USDC。

The attacker, funded through the zero-knowledge (ZK) protocol Railgun, swapped the misappropriated funds to Ethereum (ETH), initially obtaining 608 ETH.

攻击者通过零知识(ZK)协议 Railgun 资助,将挪用的资金交换到以太坊(ETH),最初获得了 608 ETH。

However, further analysis by Web3 security provider Olympix revealed that the exploit occurred due to “calldata within the ConnectorDeleverageParaswap contract.” The report highlighted that the contract failed to adequately check the flash loan calls data.

然而,Web3 安全提供商 Olympix 的进一步分析表明,该漏洞是由于“ConnectorDeleverageParaswap 合约内的调用数据”而发生的。该报告强调,该合约未能充分检查闪电贷款调用数据。

The unvalidated calldata allowed the exploiter to manipulate the contract's data and send the funds to an Externally Owned Account (EAO), enabling them to withdraw the stolen crypto.

未经验证的通话数据允许利用者操纵合约数据并将资金发送到外部拥有账户(EAO),从而使他们能够提取被盗的加密货币。

Following the initial reports, a second batch of attacks occurred, leading to the loss of another $141,000 in USDC, raising the total crypto heist to $1.96 million.

继最初的报告之后,第二批攻击发生,导致 USDC 又损失 141,000 美元,使加密货币盗窃总额达到 196 万美元。

However, lending protocol Aave's pools remained unaffected, according to Cyvers.

然而,Cyvers 表示,借贷协议 Aave 的资金池并未受到影响。

After the initial reports, the DeFi protocol acknowledged the attack and urged users to withdraw their remaining funds from the protocol. Later, Dough Finance announced it had identified and closed the exploit.

在收到初步报告后,DeFi 协议承认了此次攻击,并敦促用户从协议中提取剩余资金。随后,Dough Finance 宣布已发现并关闭了该漏洞。

The project confirmed that “a few early Dough DeFi Smart Accounts (DSAs)” were victim to a sophisticated exploit.

该项目证实,“一些早期的 Dough DeFi 智能账户(DSA)”是复杂漏洞的受害者。

In a statement, Dough Finance assured that its team is actively working to address the incident, aiming to recover the funds and making investors whole.

Dough Finance 在一份声明中保证,其团队正在积极努力解决这一事件,旨在收回资金并让投资者得到补偿。

Online reports also revealed that the team reached out to the exploiter through an on-chain message, offering to discuss a bounty if they had “exploited this vulnerability as a white or grey hat.”

在线报道还显示,该团队通过链上消息联系了漏洞利用者,提出如果他们“以白帽或灰帽身份利用此漏洞”,则可以讨论赏金。

The message also included the address where the funds should be directly transferred if the exploiter wished to return the stolen crypto.

该消息还包括如果攻击者希望归还被盗加密货币,则应直接将资金转移到的地址。

The exploiter has until Monday, July 15, 2024, at 23:00 UTC to contact the DeFi protocol. If the team doesn't receive an answer, they will “assume you appropriated the funds with unlawful intent and will pursue all criminal, legal, and administrative avenues available” to recover the misappropriated funds.

攻击者必须在世界标准时间 2024 年 7 月 15 日星期一 23:00 之前联系 DeFi 协议。如果团队没有收到答复,他们将“假设您出于非法目的挪用资金,并将采取所有可用的刑事、法律和行政途径”来追回被挪用的资金。

This incident highlights the ongoing threat posed by scammers to the DeFi sector. Earlier this week, several DeFi projects, including Compound Finance, were compromised in a phishing attack.

这一事件突显了诈骗者对 DeFi 行业构成的持续威胁。本周早些时候,包括 Compound Finance 在内的多个 DeFi 项目在网络钓鱼攻击中遭到破坏。

The projects were reportedly victims of a DNS domain attack, which redirected users to a fake website. The copy website functioned as a drainer tool, capable of draining users' funds if they interacted with it.

据报道,这些项目是 DNS 域攻击的受害者,该攻击将用户重定向到虚假网站。该复制网站充当了一种流失工具,如果用户与之互动,就会流失用户的资金。

As a result, the teams of the affected projects quickly urged customers not to interact with the websites until further notice, to prevent any potential losses.

因此,受影响项目的团队迅速敦促客户在收到进一步通知之前不要与网站互动,以防止任何潜在的损失。

原文来源:bitcoinist

免责声明:info@kdj.com

所提供的信息并非交易建议。根据本文提供的信息进行的任何投资,kdj.com不承担任何责任。加密货币具有高波动性,强烈建议您深入研究后,谨慎投资!

如您认为本网站上使用的内容侵犯了您的版权,请立即联系我们(info@kdj.com),我们将及时删除。

2026年07月27日 发表的其他文章