市值: $2.2043T 0.58%
成交额(24h): $56.8553B 3.76%
  • 市值: $2.2043T 0.58%
  • 成交额(24h): $56.8553B 3.76%
  • 恐惧与贪婪指数:
  • 市值: $2.2043T 0.58%
加密货币
话题
百科
资讯
加密话题
视频
热门新闻
加密货币
话题
百科
资讯
加密话题
视频
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

加密货币新闻

无限批准漏洞使 DeFi 行业面临新风险,LI.FI 遭受 1000 万美元损失

2024/07/17 06:03

LI.FI 泄露凸显了 DeFi 领域保持警惕和主动采取安全措施的重要性。

无限批准漏洞使 DeFi 行业面临新风险,LI.FI 遭受 1000 万美元损失

A preliminary breach was detected on the Ethereum blockchain and rapidly expanded to the Arbitrum community. In keeping with Cyvers safety agency, over $10 million in stablecoins, primarily USDC and USDT, had been stolen throughout this assault. Shortly after, the attackers started changing these stablecoins into ETH.

在以太坊区块链上发现了初步漏洞,并迅速扩展到 Arbitrum 社区。据 Cyvers 安全机构称,在这次攻击中,超过 1000 万美元的稳定币(主要是 USDC 和 USDT)被盗。不久之后,攻击者开始将这些稳定币兑换成 ETH。

The LI.FI protocol group confirmed the breach after the safety agency reported the incident. They said that the first vulnerability was coming from an infinite approval setting for transactions, which enabled attackers to steal all of the funds.

在安全机构报告该事件后,LI.FI 协议组确认了此次违规行为。他们表示,第一个漏洞来自交易的无限批准设置,这使得攻击者能够窃取所有资金。

Tips on how to Defend Your self From Infinite Approval Exploit

关于如何保护自己免受无限批准利用的提示

Infinite approval exploits happen when customers grant limitless permission for a wise contract to entry their funds. Whereas that is handy for repeated transactions with out requiring consumer affirmation every time, it additionally opens up important safety dangers. If the good contract or platform is compromised, attackers can use it to empty all funds from customers.

当客户授予明智合约无限的许可来进入他们的资金时,就会发生无限的批准漏洞。虽然这对于重复交易很方便,无需每次都需要消费者确认,但它也带来了严重的安全隐患。如果良好的合约或平台遭到破坏,攻击者就可以利用它来清空客户的所有资金。

LI.FI claimed that no additional funds had been in danger, whereas Cyvers urged customers to revoke approvals for the compromised addresses instantly. Instruments resembling Revoke.money will help customers handle and revoke token approvals simply.

LI.FI 声称没有其他资金处于危险之中,而 Cyvers 则敦促客户立即撤销对受损地址的批准。 Revoke.money 等工具将帮助客户轻松处理和撤销代币批准。

Customers ought to commonly verify their token approvals and revoke any which might be pointless or pose a possible danger. As an alternative of granting infinite approval, customers can set limits on the quantity a wise contract can entry. This fashion, even when a breach happens, the potential loss is capped.

客户应该经常验证他们的代币批准,并撤销任何可能毫无意义或构成可能危险的代币批准。作为授予无限批准的替代方案,客户可以对智能合约可以输入的数量设置限制。这样,即使发生违规,潜在的损失也受到限制。

Whereas DeFi protocols should guarantee sturdy safety measures, customers additionally bear accountability for his or her safety settings. By following these steps, customers can restrict the chance of falling sufferer to hacks.

尽管 DeFi 协议应保证可靠的安全措施,但用户还对其安全设置承担责任。通过遵循这些步骤,客户可以减少遭受黑客攻击的机会。

原文来源:cryptonewsbtc

免责声明:info@kdj.com

所提供的信息并非交易建议。根据本文提供的信息进行的任何投资,kdj.com不承担任何责任。加密货币具有高波动性,强烈建议您深入研究后,谨慎投资!

如您认为本网站上使用的内容侵犯了您的版权,请立即联系我们(info@kdj.com),我们将及时删除。

2026年08月11日 发表的其他文章