|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
在恶意行为者利用漏洞更改图形处理单元 (GPU) 网络设备元数据后,安全漏洞迫使物理基础设施网络 Io.net 实施更严格的措施。该攻击于 4 月 25 日检测到,利用 SQL 注入和用户 ID 令牌的暴露,但并未影响实际的 GPU 硬件。 Io.net 通过实施增强的身份验证、SQL 注入检查和增加日志记录来做出回应。

Cybersecurity Breach: Io.net Decisive Action Maintains Network Integrity
网络安全漏洞:Io.net 采取果断行动维护网络完整性
[Date] - Io.net, the decentralized physical infrastructure network (DePIN) provider, swiftly responded to a cybersecurity breach, protecting its network and mitigating potential damage. Malicious users exploited exposed user ID tokens to execute a SQL injection attack, leading to unauthorized changes in device metadata within the graphics processing unit (GPU) network.
[日期] - 去中心化物理基础设施网络 (DePIN) 提供商 Io.net 迅速响应网络安全漏洞,保护其网络并减轻潜在损害。恶意用户利用暴露的用户 ID 令牌执行 SQL 注入攻击,导致图形处理单元 (GPU) 网络内的设备元数据发生未经授权的更改。
Upon detection at 1:05 am Pacific Standard Time on April 25, Husky.io, Io.net's chief security officer, initiated immediate remedial actions to safeguard the network. Robust permission layers prevented the attack from compromising the GPUs' actual hardware, ensuring their continued security.
太平洋标准时间 4 月 25 日凌晨 1:05 发现这一情况后,Io.net 首席安全官 Husky.io 立即采取了补救措施来保护网络。强大的权限层可防止攻击损害 GPU 的实际硬件,从而确保其持续的安全性。
Swift Response and Security Upgrades
快速响应和安全升级
Io.net's swift response included implementing SQL injection checks on APIs, enhancing logging for unauthorized attempts, and deploying a user-specific authentication solution using Auth0 with OKTA. These measures effectively addressed vulnerabilities related to universal authorization tokens.
Io.net 的快速响应包括对 API 实施 SQL 注入检查、增强对未经授权尝试的日志记录,以及使用 Auth0 和 OKTA 部署特定于用户的身份验证解决方案。这些措施有效解决了与通用授权令牌相关的漏洞。
Challenges and Mitigations
挑战和缓解措施
Coincidentally, the security update overlapped with a snapshot of the rewards program, leading to a temporary decrease in supply-side participants. Legitimate GPUs that did not restart and update encountered difficulties accessing the uptime API, resulting in a drop in active GPU connections from 600,000 to 10,000.
无独有偶,安全更新与奖励计划快照重叠,导致供应方参与者暂时减少。未重新启动和更新的合法 GPU 在访问正常运行时间 API 时遇到困难,导致活动 GPU 连接从 600,000 下降至 10,000。
To address these challenges, Io.net initiated Ignition Rewards Season 2 in May to encourage supply-side participation. Ongoing efforts include collaborating with suppliers to upgrade, restart, and reconnect devices to the network.
为了应对这些挑战,Io.net 于 5 月启动了 Ignition Rewards 第二季,以鼓励供应方参与。持续的努力包括与供应商合作升级、重启设备并将其重新连接到网络。
Root Cause Analysis and Continuous Improvement
根本原因分析和持续改进
The breach originated from vulnerabilities introduced during the implementation of a proof-of-work mechanism designed to identify counterfeit GPUs. Aggressive security patches prior to the incident prompted an escalation in attack methods, necessitating continuous security reviews and improvements.
此次泄露源于实施旨在识别假冒 GPU 的工作量证明机制期间引入的漏洞。事件发生前的激进安全补丁促使攻击方法升级,需要持续的安全审查和改进。
Attacker Methodology
攻击者方法论
Attackers exploited a vulnerability in an API to display content in the input/output explorer, inadvertently revealing user IDs when searching by device IDs. They compiled this leaked information into a database weeks before the breach.
攻击者利用 API 中的漏洞在输入/输出浏览器中显示内容,在按设备 ID 搜索时无意中泄露用户 ID。他们在泄露事件发生前几周将这些泄露的信息编译到数据库中。
Using a valid universal authentication token, attackers accessed the "worker-API," enabling them to modify device metadata without requiring user-level authentication.
使用有效的通用身份验证令牌,攻击者可以访问“worker-API”,使他们能够修改设备元数据,而无需用户级身份验证。
Ongoing Security Enhancements
持续的安全增强
Husky.io emphasizes ongoing thorough reviews and penetration tests on public endpoints to proactively detect and neutralize threats. Despite the challenges encountered, efforts are underway to incentivize supply-side participation and restore network connections, ensuring the platform's integrity while serving tens of thousands of compute hours per month.
Husky.io 强调对公共端点进行持续的彻底审查和渗透测试,以主动检测和消除威胁。尽管遇到了挑战,但仍在努力激励供应方参与并恢复网络连接,确保平台的完整性,同时每月提供数万个计算小时的服务。
Future Plans
未来的计划
Io.net plans to integrate Apple silicon chip hardware in March to enhance its artificial intelligence and machine learning services, underscoring its commitment to providing a secure and performant platform for its users.
Io.net 计划于 3 月份集成 Apple 芯片硬件,以增强其人工智能和机器学习服务,强调其致力于为用户提供安全、高性能平台的承诺。
免责声明:info@kdj.com
所提供的信息并非交易建议。根据本文提供的信息进行的任何投资,kdj.com不承担任何责任。加密货币具有高波动性,强烈建议您深入研究后,谨慎投资!
如您认为本网站上使用的内容侵犯了您的版权,请立即联系我们(info@kdj.com),我们将及时删除。
-
- 比特币、eCash 分叉和空投动态:深入探讨加密货币的最新争议
- 2026-05-03 00:52:02
- 探索最近的 eCash 分叉、其作为高风险空投的分类,以及对比特币和加密生态系统的更广泛影响。
-
-
- 美联储维持利率稳定,地缘政治紧张局势引发比特币价格下跌
- 2026-05-01 04:04:38
- 美联储维持利率的决定,加上中东冲突,影响了比特币的价格。分析近期趋势和市场反应。
-
-
-
-
-
-

































