市值: $2.9256T 1.33%
成交额(24h): $103.1186B 3.45%
  • 市值: $2.9256T 1.33%
  • 成交额(24h): $103.1186B 3.45%
  • 恐惧与贪婪指数:
  • 市值: $2.9256T 1.33%
加密货币
话题
百科
资讯
加密话题
视频
热门新闻
加密货币
话题
百科
资讯
加密话题
视频
bitcoin
bitcoin

$85882.489292 USD

2.66%

ethereum
ethereum

$2726.255136 USD

1.23%

tether
tether

$0.999653 USD

-0.01%

bnb
bnb

$776.085808 USD

1.09%

xrp
xrp

$1.521475 USD

1.66%

usd-coin
usd-coin

$0.999947 USD

-0.02%

solana
solana

$121.201562 USD

2.45%

tron
tron

$0.334191 USD

-0.95%

zcash
zcash

$1376.191162 USD

-3.52%

hyperliquid
hyperliquid

$89.815179 USD

0.93%

dogecoin
dogecoin

$0.095724 USD

0.60%

chainlink
chainlink

$14.345509 USD

0.03%

monero
monero

$548.721371 USD

-0.11%

cardano
cardano

$0.253733 USD

0.94%

unus-sed-leo
unus-sed-leo

$8.970136 USD

1.38%

加密货币新闻

SlowMist 发现 FlashLoopAdapter 耗尽安全钱包的缺陷:为 DeFi 集成敲响警钟

2026/10/03 08:05

SlowMist 报告了第三方 Aave 集成 FlashLoopAdapter 中的一个严重漏洞,导致两个 Safe 多重签名钱包中的 114 ETH 被耗尽。这一事件凸显了外部 DeFi 模块的固有风险,即使有像 Safe 这样强大的核心协议。

SlowMist 发现 FlashLoopAdapter 耗尽安全钱包的缺陷:为 DeFi 集成敲响警钟

In the ever-evolving landscape of decentralized finance (DeFi), security is paramount, yet a recent incident brought to light by blockchain security firm SlowMist serves as a stark reminder that even the most fortified systems can be vulnerable through their external connections. A flaw in a third-party integration, dubbed FlashLoopAdapter, allowed an attacker to siphon approximately 114 ETH (valued around $305,000 at the time of reporting) from two Safe multisig wallets.

在不断发展的去中心化金融 (DeFi) 领域,安全至关重要,但区块链安全公司 SlowMist 最近曝光的一起事件清楚地提醒我们,即使是最坚固的系统也可能通过外部连接而受到攻击。第三方集成中的一个名为 FlashLoopAdapter 的缺陷允许攻击者从两个 Safe 多重签名钱包中窃取大约 114 ETH(在报告时价值约为 305,000 美元)。

The Achilles' Heel: FlashLoopAdapter's Access Control

阿喀琉斯之踵:FlashLoopAdapter 的访问控制

SlowMist's investigation pinpointed FlashLoopAdapter as the weak link. This component, designed to manage leveraged Aave v3 positions, was an external adapter, not a core part of the Safe multisig wallet protocol or the Aave v3 itself. This distinction is crucial: the core Safe contracts remained uncompromised. The vulnerability lay in FlashLoopAdapter's access control mechanisms for its open() and close() functions. These functions merely checked if a module was enabled by calling ISafe(msg.sender).isModuleEnabled(address(this)), a check that was unfortunately spoofable.

SlowMist 的调查指出 FlashLoopAdapter 是薄弱环节。该组件旨在管理杠杆 Aave v3 头寸,是一个外部适配器,而不是 Safe multisig 钱包协议或 Aave v3 本身的核心部分。这种区别至关重要:核心安全合约仍然不受影响。该漏洞存在于 FlashLoopAdapter 的 open() 和 close() 函数的访问控制机制中。这些函数只是通过调用 ISafe(msg.sender).isModuleEnabled(address(this)) 来检查模块是否已启用,不幸的是,该检查是可欺骗的。

The attacker cleverly exploited this by deploying a fake Safe contract that would always return 'true' to this module enablement query. Furthermore, the _swap() function within FlashLoopAdapter allowed the caller to dictate the swap router and its data. The attacker leveraged this to set the router to one of the victim Safe wallets and then, through the execTransactionFromModule function (a legitimate Safe function for enabled modules), executed unauthorized transactions. The consequence? Collateral locked in Aave v3 positions via FlashLoopAdapter was drained.

攻击者巧妙地利用了这一点,部署了一个虚假的 Safe 合约,该合约始终向该模块启用查询返回“true”。此外,FlashLoopAdapter 中的 _swap() 函数允许调用者指定交换路由器及其数据。攻击者利用这一点将路由器设置为受害者安全钱包之一,然后通过 execTransactionFromModule 函数(启用模块的合法安全函数)执行未经授权的交易。结果呢?通过 FlashLoopAdapter 锁定在 Aave v3 头寸的抵押品已被耗尽。

A Pattern of Peripheral Vulnerabilities

外围设备漏洞的模式

This isn't SlowMist's first rodeo in identifying vulnerabilities stemming from peripheral integrations. The firm has a consistent track record of tracing significant losses back to adjacent components rather than core protocols. This incident echoes previous findings, such as the Liquid Network exploit that minted 3,998 L-BTC, where a similar attack vector bypassed core defenses through an external module. These cases collectively underscore a critical trend: while core protocols may be robust, the security perimeter often expands with every third-party integration.

这并不是慢雾第一次识别外围集成漏洞。该公司拥有将重大损失追溯到相邻组件而不是核心协议的一贯记录。这一事件与之前的调查结果相呼应,例如 Liquid Network 漏洞利用铸造了 3,998 个 L-BTC,其中类似的攻击向量通过外部模块绕过了核心防御。这些案例共同强调了一个关键趋势:虽然核心协议可能很强大,但安全范围往往会随着每次第三方集成而扩展。

The Broader Implications for Safe Wallets and DeFi

对安全钱包和 DeFi 的更广泛影响

Safe wallets are widely celebrated for their enhanced security in DeFi, particularly through their multisig capabilities. However, the FlashLoopAdapter incident highlights a fundamental truth: security is only as strong as its weakest link. When users grant third-party adapters interaction privileges with their wallets, these adapters inherit significant execution power. A flaw in the adapter's logic, even if the wallet itself functions perfectly, can be weaponized.

安全钱包因其在 DeFi 中增强的安全性而广受赞誉,特别是通过其多重签名功能。然而,FlashLoopAdapter 事件凸显了一个基本事实:安全性的强弱取决于其最薄弱的环节。当用户授予第三方适配器与其钱包交互的权限时,这些适配器将继承强大的执行能力。即使钱包本身功能完美,适配器逻辑中的缺陷也可以被武器化。

This serves as a potent reminder for anyone engaging with DeFi strategies that involve external modules. Authorizing an adapter is not a trivial decision; it entails trusting the adapter's code as much as, if not more than, the core protocol. The true blast radius of this exploit—how many other wallets had authorized FlashLoopAdapter before the flaw was discovered—remains an open question, underscoring the ongoing challenge of securing the interconnected DeFi ecosystem.

对于任何参与涉及外部模块的 DeFi 策略的人来说,这都是一个有力的提醒。授权适配器并不是一个简单的决定;它需要像信任核心协议一样信任适配器的代码。该漏洞的真正爆炸半径(在发现该缺陷之前有多少其他钱包已授权 FlashLoopAdapter)仍然是一个悬而未决的问题,这突显了保护互连的 DeFi 生态系统所面临的持续挑战。

Looking Ahead: A Call for Scrutiny and Enhanced Vigilance

展望未来:呼吁审查和提高警惕

While the attacker's identity remains unknown and remediation steps are not publicly detailed, this incident provides valuable lessons. It's a clear call for increased scrutiny of third-party integrations and robust access control mechanisms. As DeFi continues to innovate, the onus is on both developers and users to prioritize comprehensive security audits and understand the full implications of every integration. In the end, staying safe in the digital frontier often comes down to paying attention to the fine print—and the code behind it. Let's keep those wallets safe and sound, one secure integration at a time!

虽然攻击者的身份仍然未知,补救措施也没有公开详细信息,但这一事件提供了宝贵的教训。这明确呼吁加强对第三方集成和强大的访问控制机制的审查。随着 DeFi 的不断创新,开发人员和用户都有责任优先考虑全面的安全审核并了解每次集成的全面影响。最后,在数字前沿保持安全通常归结为关注细则及其背后的代码。让我们确保这些钱包安全无虞,一次一个安全集成!

原文来源:coinmarketcap

免责声明:info@kdj.com

所提供的信息并非交易建议。根据本文提供的信息进行的任何投资,kdj.com不承担任何责任。加密货币具有高波动性,强烈建议您深入研究后,谨慎投资!

如您认为本网站上使用的内容侵犯了您的版权,请立即联系我们(info@kdj.com),我们将及时删除。

2026年10月03日 发表的其他文章