|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
周五早上,另一个 DeFi 协议成为了漏洞的受害者。 Dough Finance,一个用于创建非托管流动性市场的开源协议

DeFi protocol Dough Finance fell victim to a flash loan attack on Friday morning, leading to the theft of nearly $2 million in user funds. The project’s team announced they are working to resolve the situation promptly.
周五上午,DeFi 协议 Dough Finance 遭遇闪贷攻击,导致近 200 万美元的用户资金被盗。该项目团队宣布他们正在努力尽快解决这一问题。
According to Web3 blockchain security platform Cyvers, it detected multiple suspicious transactions involving Dough Finance. The attacker manipulated the protocol's smart contract and stole $1.8 million in USDC.
据Web3区块链安全平台Cyvers称,它检测到多笔涉及Dough Finance的可疑交易。攻击者操纵了协议的智能合约并窃取了 180 万美元的 USDC。
The attacker, funded through the zero-knowledge (ZK) protocol Railgun, swapped the misappropriated funds to Ethereum (ETH), initially obtaining 608 ETH.
攻击者通过零知识(ZK)协议 Railgun 资助,将挪用的资金交换到以太坊(ETH),最初获得了 608 ETH。
However, further analysis by Web3 security provider Olympix revealed that the exploit occurred due to “calldata within the ConnectorDeleverageParaswap contract.” The report highlighted that the contract failed to adequately check the flash loan calls data.
然而,Web3 安全提供商 Olympix 的进一步分析表明,该漏洞是由于“ConnectorDeleverageParaswap 合约内的调用数据”而发生的。该报告强调,该合约未能充分检查闪电贷款调用数据。
The unvalidated calldata allowed the exploiter to manipulate the contract's data and send the funds to an Externally Owned Account (EAO), enabling them to withdraw the stolen crypto.
未经验证的通话数据允许利用者操纵合约数据并将资金发送到外部拥有账户(EAO),从而使他们能够提取被盗的加密货币。
Following the initial reports, a second batch of attacks occurred, leading to the loss of another $141,000 in USDC, raising the total crypto heist to $1.96 million.
继最初的报告之后,第二批攻击发生,导致 USDC 又损失 141,000 美元,使加密货币盗窃总额达到 196 万美元。
However, lending protocol Aave's pools remained unaffected, according to Cyvers.
然而,Cyvers 表示,借贷协议 Aave 的资金池并未受到影响。
After the initial reports, the DeFi protocol acknowledged the attack and urged users to withdraw their remaining funds from the protocol. Later, Dough Finance announced it had identified and closed the exploit.
在收到初步报告后,DeFi 协议承认了此次攻击,并敦促用户从协议中提取剩余资金。随后,Dough Finance 宣布已发现并关闭了该漏洞。
The project confirmed that “a few early Dough DeFi Smart Accounts (DSAs)” were victim to a sophisticated exploit.
该项目证实,“一些早期的 Dough DeFi 智能账户(DSA)”是复杂漏洞的受害者。
In a statement, Dough Finance assured that its team is actively working to address the incident, aiming to recover the funds and making investors whole.
Dough Finance 在一份声明中保证,其团队正在积极努力解决这一事件,旨在收回资金并让投资者得到补偿。
Online reports also revealed that the team reached out to the exploiter through an on-chain message, offering to discuss a bounty if they had “exploited this vulnerability as a white or grey hat.”
在线报道还显示,该团队通过链上消息联系了漏洞利用者,提出如果他们“以白帽或灰帽身份利用此漏洞”,则可以讨论赏金。
The message also included the address where the funds should be directly transferred if the exploiter wished to return the stolen crypto.
该消息还包括如果攻击者希望归还被盗加密货币,则应直接将资金转移到的地址。
The exploiter has until Monday, July 15, 2024, at 23:00 UTC to contact the DeFi protocol. If the team doesn't receive an answer, they will “assume you appropriated the funds with unlawful intent and will pursue all criminal, legal, and administrative avenues available” to recover the misappropriated funds.
攻击者必须在世界标准时间 2024 年 7 月 15 日星期一 23:00 之前联系 DeFi 协议。如果团队没有收到答复,他们将“假设您出于非法目的挪用资金,并将采取所有可用的刑事、法律和行政途径”来追回被挪用的资金。
This incident highlights the ongoing threat posed by scammers to the DeFi sector. Earlier this week, several DeFi projects, including Compound Finance, were compromised in a phishing attack.
这一事件突显了诈骗者对 DeFi 行业构成的持续威胁。本周早些时候,包括 Compound Finance 在内的多个 DeFi 项目在网络钓鱼攻击中遭到破坏。
The projects were reportedly victims of a DNS domain attack, which redirected users to a fake website. The copy website functioned as a drainer tool, capable of draining users' funds if they interacted with it.
据报道,这些项目是 DNS 域攻击的受害者,该攻击将用户重定向到虚假网站。该复制网站充当了一种流失工具,如果用户与之互动,就会流失用户的资金。
As a result, the teams of the affected projects quickly urged customers not to interact with the websites until further notice, to prevent any potential losses.
因此,受影响项目的团队迅速敦促客户在收到进一步通知之前不要与网站互动,以防止任何潜在的损失。
免责声明:info@kdj.com
所提供的信息并非交易建议。根据本文提供的信息进行的任何投资,kdj.com不承担任何责任。加密货币具有高波动性,强烈建议您深入研究后,谨慎投资!
如您认为本网站上使用的内容侵犯了您的版权,请立即联系我们(info@kdj.com),我们将及时删除。
-
- 比特币、eCash 分叉和空投动态:深入探讨加密货币的最新争议
- 2026-05-03 00:52:02
- 探索最近的 eCash 分叉、其作为高风险空投的分类,以及对比特币和加密生态系统的更广泛影响。
-
-
- 美联储维持利率稳定,地缘政治紧张局势引发比特币价格下跌
- 2026-05-01 04:04:38
- 美联储维持利率的决定,加上中东冲突,影响了比特币的价格。分析近期趋势和市场反应。
-
-
-
-
-
-

































