市值: $2.2043T 0.58%
成交额(24h): $56.8553B 3.76%
  • 市值: $2.2043T 0.58%
  • 成交额(24h): $56.8553B 3.76%
  • 恐惧与贪婪指数:
  • 市值: $2.2043T 0.58%
加密货币
话题
百科
资讯
加密话题
视频
热门新闻
加密货币
话题
百科
资讯
加密话题
视频
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

加密货币新闻

分类帐,供应链和加密安全:导航新威胁格局

2025/09/09 21:05

针对加密货币的最新供应链攻击强调了警惕的需求。从折衷的NPM软件包到AI驱动的利用,安全性至关重要。

分类帐,供应链和加密安全:导航新威胁格局

Ledger, Supply Chain, and Crypto Security: Navigating the New Threat Landscape

分类帐,供应链和加密安全:导航新威胁格局

The world of crypto security is constantly evolving, and recent events have highlighted the critical importance of supply chain integrity and the emerging risks associated with AI-driven coding. It's a wild west out there, and staying ahead of the game is essential to protect your digital assets.

加密安全世界一直在不断发展,最近的事件强调了供应链完整性的至关重要性以及与AI驱动的编码相关的新兴风险。这是一个狂野的西部,并且在游戏领先时,对于保护您的数字资产至关重要。

The NPM Supply Chain Breach: A Wake-Up Call

NPM供应链漏洞:唤醒电话

A large-scale supply chain attack targeting the Node Package Manager (NPM) sent shockwaves through the open-source community. A compromised NPM account led to the distribution of malicious packages downloaded over a billion times. Ledger's CTO, Charles Guillemet, rightly pointed out the JavaScript ecosystem was at risk. The attack silently swapped crypto addresses, diverting funds to the attackers.

针对节点软件包管理器(NPM)的大规模供应链攻击通过开源社区向冲击波发送了冲击波。折衷的NPM帐户导致在十亿次下载的恶意软件包的分布。莱杰的首席技术官查尔斯·吉勒梅特(Charles Guillemet)正确地指出,JavaScript生态系统处于危险之中。攻击默默地交换了加密货币地址,将资金转移给了攻击者。

The good news? Hardware wallet users who meticulously verify transactions remain safe. However, those using software wallets were advised to avoid on-chain transactions until the situation was resolved. This incident underscores the fragility of software supply chains. Even though the financial damage was initially minimal, the potential for widespread chaos was undeniable. It's a reminder that a single compromised account can have massive repercussions.

好消息?精心验证交易的硬件钱包用户仍然安全。但是,建议那些使用软件钱包的人避免链交易,直到解决情况为止。该事件强调了软件供应链的脆弱性。即使财务损失最初是最小的,但不可否认的混乱的潜力也是不可否认的。这提醒您,一个折衷的帐户可能会产生巨大的影响。

AI Coding Tools: A Double-Edged Sword for Crypto Security

AI编码工具:一把双刃剑用于加密安全

The increasing reliance on AI coding tools like Cursor introduces a new set of security challenges. The "CopyPasta Attack" demonstrated how malicious instructions could be slipped into rarely checked files, leading AI assistants to spread the payload across entire projects. Coinbase, a heavy Cursor user, aims for 50% AI-generated code by October 2025, a level of dependence that some experts consider reckless. This vulnerability isn't limited to Cursor; similar flaws exist in other widely used AI coding tools.

越来越多地依赖像光标这样的AI编码工具引入了一系列新的安全挑战。 “复制攻击”证明了如何将恶意指示滑入很少检查的文件中,这导致AI助手在整个项目中传播有效载荷。 Coinbase是一个重型光标用户,目标是到2025年10月,目标是50%AI生成的代码,这是一些专家认为鲁ck的依赖水平。这种脆弱性不仅限于光标;在其他广泛使用的AI编码工具中也存在类似的缺陷。

While AI promises speed and efficiency, attackers are adapting quickly. The $3.1 billion in crypto losses in the first half of 2025, with AI-powered hacks playing a growing role, highlight the need for caution. Stricter review practices, separation of instructions from user input, and continuous monitoring designed for AI-specific threats are crucial. It's a trade-off between speed and security, and the crypto industry needs to find the right balance.

尽管AI承诺速度和效率,但攻击者正在迅速适应。 2025年上半年,加密货币损失的31亿美元损失,AI驱动的骇客扮演着越来越多的角色,强调了谨慎的需求。更严格的审核实践,指令与用户输入的分离以及为AI特异性威胁设计的连续监视至关重要。这是速度和安全之间的权衡,加密货币行业需要找到正确的平衡。

Ledger's Stance: Verify, Verify, Verify!

Ledger的立场:验证,验证,验证!

Guillemet's advice remains crucial: always verify your transactions and never blind sign. He also advocates for using a hardware wallet with a secure display to ensure transaction safety. Hardware wallets provide an essential layer of security by displaying the true destination address on a secure screen, making it harder for attackers to trick users.

Guillemet的建议仍然至关重要:始终验证您的交易和永不盲目的信号。他还主张使用带有安全显示的硬件钱包来确保交易安全。硬件钱包通过在安全屏幕上显示真实的目标地址来提供必不可少的安全层,从而使攻击者更难欺骗用户。

The Bottom Line: Vigilance is Key

底线:警惕是关键

The recent supply chain attacks and the emergence of AI-driven exploits serve as a stark reminder that crypto security is an ongoing battle. Whether it's auditing your dependencies, locking packages to safe versions, or enforcing strict supply-chain security, vigilance is paramount. And hey, maybe it’s time to dust off that hardware wallet you’ve been meaning to set up. Just sayin'.

最近的供应链攻击以及AI驱动的漏洞的出现,这是一个明显的提醒,即加密安全是一场持续的战斗。无论是审核您的依赖项,将软件包锁定到安全版本,还是执行严格的供应链安全性,警惕性都是至关重要的。嘿,也许是时候把您想设置的那个硬件钱包除尘了。只是说。

原文来源:cointribune

免责声明:info@kdj.com

所提供的信息并非交易建议。根据本文提供的信息进行的任何投资,kdj.com不承担任何责任。加密货币具有高波动性,强烈建议您深入研究后,谨慎投资!

如您认为本网站上使用的内容侵犯了您的版权,请立即联系我们(info@kdj.com),我们将及时删除。

2026年08月10日 发表的其他文章