|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
在 Li.Fi 协议(一种用于跨区块链桥接和交换数字资产的 API)被利用 1160 万美元之后,Li.Fi 团队发布了

An exploit of the Li.Fi protocol resulted in the theft of $11.6 million in digital assets, prompting the Li.Fi team to release an update on the technical aspects of the breach.
Li.Fi 协议的漏洞导致 1160 万美元的数字资产被盗,促使 Li.Fi 团队发布了有关此次漏洞的技术方面的最新信息。
The breach occurred during the deployment of a new smart contract facet, which contained a vulnerability that enabled users calling the smart contract to initiate calls to any contract without prior validation.
该漏洞发生在部署新的智能合约方面时,其中包含一个漏洞,使调用智能合约的用户能够在未经事先验证的情况下发起对任何合约的调用。
This function stemmed from code taken from the LibSwap library, which facilitates calls between decentralized exchanges, service providers, and clients to coordinate the asset bridging and swapping processes.
该函数源于 LibSwap 库的代码,该库促进去中心化交易所、服务提供商和客户端之间的调用,以协调资产桥接和交换过程。
Normally, these calls are screened against whitelisted addresses to ensure validation. However, human error in deploying the offending smart contract facet resulted in these checks being bypassed, rendering the protocol vulnerable to exploitation.
通常,这些调用会根据白名单地址进行筛选,以确保验证。然而,部署有问题的智能合约方面的人为错误导致这些检查被绕过,使协议容易受到利用。
The Li.Fi team confirmed that the attack occurred on the Ethereum and Arbitrum networks and affected 156 wallets that had the “infinite approvals” option turned on. Those who did not enable this option were not affected by the exploit.
Li.Fi 团队确认,此次攻击发生在以太坊和 Arbitrum 网络上,影响了 156 个开启“无限批准”选项的钱包。那些没有启用此选项的人不会受到该漏洞的影响。
In statements to Cointelegraph, spokespeople for Li.Fi said they contained the exploit, addressed the critical vulnerability, and contacted the proper law enforcement authorities to trace the stolen funds. At the time of this writing, the issue has been fixed, and Li.Fi is operating normally.
Li.Fi 发言人在向 Cointelegraph 发表的声明中表示,他们遏制了该漏洞,解决了关键漏洞,并联系了适当的执法机构追查被盗资金。截至撰写本文时,该问题已得到解决,Li.Fi 运行正常。
Related: Lazarus is moving millions from $305M DMM Bitcoin hack — ZachXBT
相关:Lazarus 正在从价值 3.05 亿美元的 DMM 比特币黑客攻击中转移数百万美元 — ZachXBT
This is not the first time that a vulnerability in the Li.Fi protocol has been exploited. In March 2022, a similar exploit affected users who had the “infinite approval” option turned on, allowing hackers to drain $600,000 from the protocol from 29 wallets before the vulnerability was addressed.
这并不是 Li.Fi 协议中的漏洞第一次被利用。 2022 年 3 月,类似的漏洞影响了打开“无限批准”选项的用户,导致黑客在漏洞得到解决之前从 29 个钱包的协议中盗取了 60 万美元。
The protocol was quick to reimburse investors for their losses, refunding 24 wallets directly from its treasury and offering the remaining five wallets a voluntary compensation plan akin to that received by early angel investors of Li.Fi.
该协议很快就补偿了投资者的损失,直接从其金库退还 24 个钱包,并向其余 5 个钱包提供类似于 Li.Fi 早期天使投资者所收到的自愿补偿计划。
Crypto hacks put the damper on the industry in 2024
加密货币黑客攻击将在 2024 年对该行业造成阻碍
Hacks and exploits continue to plague the crypto industry and the decentralized financial sector, in particular.
黑客和漏洞继续困扰着加密行业,尤其是去中心化金融领域。
A recent report from security firm Cyvers showed that 2024 losses from crypto exploits are nearing $1.4 billion, driven primarily by phishing attacks, and have risen sharply since 2023.
安全公司 Cyvers 最近的一份报告显示,2024 年加密货币漏洞造成的损失接近 14 亿美元,主要由网络钓鱼攻击造成,并且自 2023 年以来急剧上升。
Magazine: Best and worst countries for crypto taxes — plus crypto tax tips
杂志:加密税最好和最差的国家 - 以及加密税提示
免责声明:info@kdj.com
所提供的信息并非交易建议。根据本文提供的信息进行的任何投资,kdj.com不承担任何责任。加密货币具有高波动性,强烈建议您深入研究后,谨慎投资!
如您认为本网站上使用的内容侵犯了您的版权,请立即联系我们(info@kdj.com),我们将及时删除。
-
- 比特币、eCash 分叉和空投动态:深入探讨加密货币的最新争议
- 2026-05-03 00:52:02
- 探索最近的 eCash 分叉、其作为高风险空投的分类,以及对比特币和加密生态系统的更广泛影响。
-
-
- 美联储维持利率稳定,地缘政治紧张局势引发比特币价格下跌
- 2026-05-01 04:04:38
- 美联储维持利率的决定,加上中东冲突,影响了比特币的价格。分析近期趋势和市场反应。
-
-
-
-
-
-

































