市值: $2.2043T 0.58%
成交额(24h): $56.8553B 3.76%
  • 市值: $2.2043T 0.58%
  • 成交额(24h): $56.8553B 3.76%
  • 恐惧与贪婪指数:
  • 市值: $2.2043T 0.58%
加密货币
话题
百科
资讯
加密话题
视频
热门新闻
加密货币
话题
百科
资讯
加密话题
视频
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

加密货币新闻

Penpie DeFi 协议被利用,损失数百万美元

2024/09/05 22:00

去中心化金融(DeFi)协议 Penpie 最近成为一次漏洞利用的受害者,该漏洞窃取了价值数百万美元的多种加密资产。

Penpie DeFi 协议被利用,损失数百万美元

A DeFi protocol based on Pendle, Penpie, recently fell victim to an exploit that saw millions of dollars worth of several crypto assets being drained from the protocol. Pendle addressed the incident in a post-mortem post, revealing that its quick response prevented further losses to the tune of over $100 million in users’ funds.

基于 Pendle 的 DeFi 协议 Penpie 最近成为漏洞利用的受害者,该漏洞导致价值数百万美元的多种加密资产被从该协议中流失。 Pendle 在事后分析帖子中谈到了这一事件,并透露其快速响应避免了用户资金进一步损失超过 1 亿美元。

According to reports, the crypto heist took place on Tuesday, with the malicious actor exploiting a vulnerability in Penpie’s reward distribution mechanism. The vulnerability stemmed from a Penpie-only feature that permitted permissionless listing of Pendle markets on Penpie.

据报道,加密货币盗窃案发生在周二,恶意行为者利用了 Penpie 奖励分配机制中的漏洞。该漏洞源于 Penpie 独有的功能,该功能允许 Penpie 上未经许可地列出 Pendle 市场。

The attacker used an “evil market” contract to inflate the staking balance and claim unwarranted rewards. As a result, they were able to drain $7.87 million in wstETH, $2.51 million in sUSDe, $3.4 million agETH, $2.22 million in rswETH, and four other Pendle-related Yield tokens from the protocol.

攻击者使用“邪恶市场”合约来夸大质押余额并索取不正当的奖励。结果,他们从该协议中抽走了 787 万美元的 wstETH、251 万美元的 sUSDe、340 万美元的 agETH、222 万美元的 rswETH 以及其他四种与 Pendle 相关的 Yield 代币。

Following the exploit, the hacker swapped the crypto assets for 11,113 ETH using the Li.fi protocol. The stolen funds, worth $27.3 million, were later transferred to crypto mixer Tornado Cash.

攻击发生后,黑客使用 Li.fi 协议将加密资产兑换成 11,113 ETH。价值 2730 万美元的被盗资金后来被转移到加密货币混合器 Tornado Cash 中。

The Penpie Team sent a message to the attacker, asking them to “amicably” resolve the incident. The protocol recognized the project’s vulnerability and the exploit’s role in bringing it forward, proposing a white hat bounty for the safe return of the funds.

Penpie 团队向攻击者发送了一条消息,要求他们“友好”解决该事件。该协议认识到该项目的漏洞以及该漏洞在推动该项目发展中的作用,并提出白帽赏金以安全返还资金。

Additionally, they offered the attacker an opportunity to “transition into a white-hat role, where your skills will be acknowledged and rewarded.” The team assured that the hacker’s identity would remain confidential and they would not pursue any legal action against them.

此外,他们还为攻击者提供了“转变为白帽角色的机会,你的技能将得到认可和奖励”。该团队保证,黑客的身份将保密,并且不会对他们采取任何法律行动。

As of this writing, there are no reports of a resolution between the exploiter and the protocol’s team.

截至撰写本文时,还没有关于利用者与协议团队之间达成解决方案的报告。

原文来源:bitcoinist

免责声明:info@kdj.com

所提供的信息并非交易建议。根据本文提供的信息进行的任何投资,kdj.com不承担任何责任。加密货币具有高波动性,强烈建议您深入研究后,谨慎投资!

如您认为本网站上使用的内容侵犯了您的版权,请立即联系我们(info@kdj.com),我们将及时删除。

2026年08月13日 发表的其他文章