|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
据 dYdX 称,2024 年 7 月 23 日,当攻击者更改 DNS 名称服务器并删除 DNSSEC 时,“dYdX.exchange”域遭到破坏

Two users lost approximately $31,000 in a recent DNS (Domain Name System) hijack of dYdX, according to a post-mortem analysis published by the decentralized exchange (DEX).
根据去中心化交易所 (DEX) 发布的事后分析,两名用户在 dYdX 最近的 DNS(域名系统)劫持中损失了约 31,000 美元。
The incident occurred on July 23, 2024, when an attacker compromised the "dYdX.exchange" domain and changed the DNS nameservers, according to dYdX. The attacker also removed the DNSSEC, which is supposed to add a layer of trust to the DNS by providing authentication.
据 dYdX 称,该事件发生于 2024 年 7 月 23 日,当时攻击者入侵了“dYdX.exchange”域并更改了 DNS 名称服务器。攻击者还删除了 DNSSEC,它应该通过提供身份验证为 DNS 添加一层信任。
After discovering the attack, dYdX said it immediately contacted Squarespace's customer support, who began working to restore domain possession and fix the DNS nameserver resolution, which was completed within a few hours. However, there was a 30-minute delay in Squarespace's response due to third-party vendor maintenance.
dYdX 表示,发现攻击后立即联系了 Squarespace 的客户支持,后者开始努力恢复域名所有权并修复 DNS 域名服务器解析,该工作在几个小时内完成。不过,由于第三方供应商维护,Squarespace 的响应延迟了 30 分钟。
During this delay, the attacker reportedly hosted a malicious site, which requested connected wallets to send ETH or any ERC20 token to the attacker's address. At the same time, dYdXs worked with SEAL to blacklist the site from crypto wallets such as Metamask and Phantom.
据报道,在此延迟期间,攻击者托管了一个恶意网站,该网站要求连接的钱包将 ETH 或任何 ERC20 代币发送到攻击者的地址。与此同时,dYdXs 与 SEAL 合作,将该网站从 Metamask 和 Phantom 等加密钱包列入黑名单。
"2 users were affected with approximately $31,000 in lost funds due to this attack. dYdX trading is in contact with both affected users and is assisting in securing their wallets and is committed to recovering funds," dYdX explained in the post-mortem analysis.
“由于这次攻击,2 名用户受到影响,损失了约 31,000 美元的资金。dYdX Trading 正在与这两名受影响的用户保持联系,协助保护他们的钱包,并致力于追回资金,”dYdX 在事后分析中解释道。
The identity of the attacker is still unknown, but they appear to be a fairly skilled actor, according to the post-mortem analysis, which raises the possibility of a social engineering attack, considering that the perpetrator deliberately chose a human-believable email address.
攻击者的身份仍然未知,但根据事后分析,他们似乎是一个相当熟练的演员,考虑到犯罪者故意选择了人类可信的电子邮件地址,这增加了社会工程攻击的可能性。
Earlier this month, several decentralized finance (DeFi) applications were impacted by a large DNS hijacking incident, which also targeted multiple DEXs.
本月早些时候,多个去中心化金融(DeFi)应用程序受到大型 DNS 劫持事件的影响,该事件还针对多个 DEX。
The attack, which was later traced back to a vulnerability in Squarespace's domain registry, also compromised several other DeFi platforms, including Compound Finance and Pendle Finance.
这次攻击后来被追溯到 Squarespace 域名注册中的漏洞,还损害了其他几个 DeFi 平台,包括 Compound Finance 和 Pendle Finance。
免责声明:info@kdj.com
所提供的信息并非交易建议。根据本文提供的信息进行的任何投资,kdj.com不承担任何责任。加密货币具有高波动性,强烈建议您深入研究后,谨慎投资!
如您认为本网站上使用的内容侵犯了您的版权,请立即联系我们(info@kdj.com),我们将及时删除。
-
- 比特币、eCash 分叉和空投动态:深入探讨加密货币的最新争议
- 2026-05-03 00:52:02
- 探索最近的 eCash 分叉、其作为高风险空投的分类,以及对比特币和加密生态系统的更广泛影响。
-
-
- 美联储维持利率稳定,地缘政治紧张局势引发比特币价格下跌
- 2026-05-01 04:04:38
- 美联储维持利率的决定,加上中东冲突,影响了比特币的价格。分析近期趋势和市场反应。
-
-
-
-
-
-

































