|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
多方计算 (MPC) 钱包提供商 Liminal 于 7 月 19 日发布了一份关于 7 月 18 日 WazirX 黑客攻击的事后分析报告,声称其用户界面

Multiparty computation (MPC) technology provider Liminal has released a July 19 post-mortem report on the July 18 WazirX hack, disputing the exchange’s claim that its user interface was responsible for the attack.
多方计算 (MPC) 技术提供商 Liminal 于 7 月 19 日发布了一份关于 7 月 18 日 WazirX 黑客攻击的事后分析报告,对该交易所关于其用户界面对此次攻击负责的说法提出了质疑。
According to Liminal's report, the hack occurred because three WazirX devices were compromised. The devices were used to initiate transactions that were then modified by the attacker before being sent to Liminal's servers for approval.
根据 Liminal 的报告,此次黑客攻击是因为三台 WazirX 设备遭到入侵。这些设备用于启动交易,然后攻击者修改交易,然后将其发送到 Liminal 的服务器进行批准。
Liminal also claimed that its multisignature wallet was set up to provide a fourth signature if WazirX provided the other three. This meant that the attacker only needed to compromise three devices to perform the attack. The wallet was set up this way at the behest of WazirX, the wallet provider claimed.
Liminal 还声称,如果 WazirX 提供了其他三个签名,其多重签名钱包将提供第四个签名。这意味着攻击者只需破坏三台设备即可执行攻击。钱包提供商声称,钱包是应 WazirX 的要求而设置的。
In a July 18 social media post, WazirX claimed that its private keys were secured with hardware wallets. However, WazirX said the attack “stemmed from a discrepancy between the data displayed on Liminal’s interface and the transaction’s actual contents.”
在 7 月 18 日的社交媒体帖子中,WazirX 声称其私钥由硬件钱包保护。然而,WazirX 表示,此次攻击“源于 Liminal 界面上显示的数据与交易实际内容之间的差异”。
According to the Liminal report, one of WazirX’s devices initiated a valid transaction involving the Gala Games (GALA) token. In response, Liminal’s server provided a “safeTxHash,” verifying the transaction's validity. However, the attacker then replaced this transaction hash with an invalid one, causing the transaction to fail.
根据 Liminal 报告,WazirX 的一台设备发起了一笔涉及 Gala Games(GALA)代币的有效交易。作为回应,Liminal 的服务器提供了一个“safeTxHash”,以验证交易的有效性。然而,攻击者随后用无效的哈希值替换了该交易哈希值,导致交易失败。
In Liminal’s view, the fact that the attacker was able to change this hash implies that the WazirX device had already been compromised before the transaction was attempted.
Liminal 认为,攻击者能够更改此哈希值的事实意味着 WazirX 设备在尝试交易之前就已经受到损害。
The attacker then initiated an additional two transactions: one GALA and one Tether (USDT) transfer. In each of these three transactions, the attacker used a different WazirX admin account, for a total of three accounts used. All three of the transactions failed.
然后,攻击者发起了另外两笔交易:一笔 GALA 和一笔 Tether (USDT) 转账。在这三笔交易中,攻击者都使用了不同的 WazirX 管理员帐户,总共使用了三个帐户。这三笔交易全部失败。
After initiating these three failed transactions, the attacker extracted signatures from the transactions and used them to initiate a new, fourth transaction. The fourth transaction “was crafted in such a way that the fields used to verify policies were using legit transaction details” and “used the Nonce from the failed USDT transaction because that was the latest transaction.”
在启动这三个失败的交易后,攻击者从交易中提取签名并使用它们启动新的第四个交易。第四笔交易“的设计方式是,用于验证策略的字段使用合法的交易详细信息”,并且“使用失败的 USDT 交易中的随机数,因为那是最新的交易。”
Because it used these “legit transaction details,” the Liminal server approved the transaction and provided a fourth signature. As a result, the transaction was confirmed on the Ethereum network, resulting in a transfer of funds from the joint multisig wallet to the attacker’s Ethereum account.
由于 Liminal 服务器使用了这些“合法交易详细信息”,因此它批准了该交易并提供了第四个签名。结果,交易在以太坊网络上得到确认,导致资金从联合多重签名钱包转移到攻击者的以太坊账户。
Liminal denied that its servers caused incorrect information to be displayed through the Liminal UI. Instead, it claimed that the incorrect information was provided by the attacker, who had compromised WazirX computers. In an answer to the posed question “How did the UI show a different value from the actual payload within the transaction?” Liminal said:
Liminal 否认其服务器导致 Liminal UI 显示错误信息。相反,它声称攻击者提供了不正确的信息,该攻击者已经破坏了 WazirX 计算机。在回答所提出的问题“UI 如何显示与交易中实际有效负载不同的值?”利米纳尔说道:
Liminal also claimed that its servers were programmed to automatically provide a fourth signature if WazirX admins provided the other three. “Liminal only provides the final signature once the required number of valid signatures are received from the client’s side,” it stated, adding that in this case, “the transaction was authorised and signed by three of our client’s employees.”
Liminal 还声称,如果 WazirX 管理员提供了其他三个签名,其服务器就会自动提供第四个签名。它表示:“只有在从客户端收到所需数量的有效签名后,Liminal才会提供最终签名。”并补充说,在这种情况下,“交易是由我们客户的三名员工授权和签署的。”
The multisig wallet “was deployed by WazirX as per their configuration well before onboarding with Liminal,” and was “imported” into Liminal “per WazirX's request.”
多重签名钱包“在使用 Liminal 之前就已由 WazirX 根据其配置进行部署”,并“按照 WazirX 的请求”“导入”到 Liminal 中。
Related: WazirX breach post-mortem: Dismantling the $230M attack
相关:WazirX 漏洞事后分析:拆除价值 2.3 亿美元的攻击
WazirX’s post claimed that it had implemented “robust security features.” For example, it had required that all transactions be confirmed by four out of five keyholders. Four of these keys belonged to WazirX employees and one to the Liminal team. In addition, it required three of the WazirX keyholders to use hardware wallets. All destination addresses were required to be added to a whitelist ahead of time, WazirX stated, which was “earmarked and facilitated on the interface by Liminal.”
WazirX 的帖子声称它已经实现了“强大的安全功能”。例如,它要求所有交易均须由五分之四的密钥持有者确认。其中四把钥匙属于 WazirX 员工,一把属于 Liminal 团队。此外,它需要三个 WazirX 密钥持有者才能使用硬件钱包。 WazirX 表示,所有目标地址都必须提前添加到白名单中,“Liminal 在界面上指定并提供了便利”。
Despite taking all of these precautions, the attacker “appear[s] to have possibly breached such security features, and the theft occurred.” WazirX called the attack a “a force majeure event beyond [its] control.” Even so, it vowed that it was “leaving no stone unturned to locate and recover the funds.”
尽管采取了所有这些预防措施,攻击者“似乎可能违反了此类安全功能,并且发生了盗窃事件”。 WazirX 称此次攻击是“超出其控制范围的不可抗力事件”。即便如此,它仍发誓将“不遗余力地寻找并追回资金”。
An estimated $235 million was lost in the WazirX attack. It was the largest centralized exchange hack since the DMM exploit of May 31, which resulted in even greater losses of $305 million.
WazirX 攻击估计造成 2.35 亿美元损失。这是自 5 月 31 日 DMM 漏洞利用以来最大的集中式交易所黑客攻击事件,造成了 3.05 亿美元的更大损失。
Magazine: WazirX hackers prepped 8 days before attack, swindlers fake fiat for USDT: Asia Express
杂志:WazirX 黑客在攻击前 8 天做好准备,骗子假冒法币换取 USDT:Asia Express
免责声明:info@kdj.com
所提供的信息并非交易建议。根据本文提供的信息进行的任何投资,kdj.com不承担任何责任。加密货币具有高波动性,强烈建议您深入研究后,谨慎投资!
如您认为本网站上使用的内容侵犯了您的版权,请立即联系我们(info@kdj.com),我们将及时删除。
-
- 比特币、eCash 分叉和空投动态:深入探讨加密货币的最新争议
- 2026-05-03 00:52:02
- 探索最近的 eCash 分叉、其作为高风险空投的分类,以及对比特币和加密生态系统的更广泛影响。
-
-
- 美联储维持利率稳定,地缘政治紧张局势引发比特币价格下跌
- 2026-05-01 04:04:38
- 美联储维持利率的决定,加上中东冲突,影响了比特币的价格。分析近期趋势和市场反应。
-
-
-
-
-
-

































