市值: $3.2738T 0.430%
成交额(24h): $102.3681B -31.980%
  • 市值: $3.2738T 0.430%
  • 成交额(24h): $102.3681B -31.980%
  • 恐惧与贪婪指数:
  • 市值: $3.2738T 0.430%
加密货币
话题
百科
资讯
加密话题
视频
热门新闻
加密货币
话题
百科
资讯
加密话题
视频
bitcoin
bitcoin

$104264.493076 USD

0.98%

ethereum
ethereum

$2508.729236 USD

0.68%

tether
tether

$1.000282 USD

0.00%

xrp
xrp

$2.161731 USD

2.69%

bnb
bnb

$656.133522 USD

1.15%

solana
solana

$154.931661 USD

1.51%

usd-coin
usd-coin

$0.999827 USD

0.00%

dogecoin
dogecoin

$0.189854 USD

0.63%

tron
tron

$0.267125 USD

0.95%

cardano
cardano

$0.677843 USD

1.34%

hyperliquid
hyperliquid

$32.573357 USD

4.91%

sui
sui

$3.241549 USD

4.65%

chainlink
chainlink

$13.871933 USD

2.24%

avalanche
avalanche

$20.696380 USD

3.56%

stellar
stellar

$0.264409 USD

1.04%

加密货币新闻

CETUS智能合约中的微小溢出错误是2.3亿美元的根本原因

2025/05/26 16:07

Slowmist确认了Checked_SHLW功能中的错误是$ 2.3亿美元Defi损失的根本原因。 CETUS智能合约中的微小溢出错误使攻击者可以伪造大规模的流动性沉积。

CETUS智能合约中的微小溢出错误是2.3亿美元的根本原因

On May 22, something alarming happened in the SUI blockchain world. Prices on the Cetus decentralized exchange (DEX) suddenly dropped, and its liquidity pools were drained. The total estimated loss was over $230 million.

5月22日,Sui区块链世界发生了一些令人震惊的事情。 CETUS分散交易所(DEX)的价格突然下降,其流动性池被排出。总估计损失超过2.3亿美元。

Several reports quickly implicated a single triple-entry arbitrageur who used a flash loan to crash a token price instantly and siphon off funds from multiple protocols. However, the precise technical vulnerability that enabled this massive exploit remained a subject of discussion.

几份报告迅速暗示了一个单一的三重套期,他使用Flash贷款立即崩溃了代币的价格,并从多个协议中删除了资金。但是,使这种大规模利用的确切技术脆弱性仍然是讨论的主题。

Now, renowned blockchain security team SlowMist has released a detailed analysis, revealing a tiny overflow bug in Cetus’ smart contract as the root cause of the staggering DeFi loss.

现在,著名的区块链安全团队Slowmist发布了详细的分析,揭示了Cetus智能合约中的一个微小的溢出错误是造成惊人的Defi损失的根本原因。

The checked_shlw function, designed to check for errors like overflows, failed to properly detect an overflow in the get_delta_a function, which is used to calculate the delta of token A when adding liquidity.

Checked_SHLW函数旨在检查诸如溢出之类的错误,无法正确检测GET_DELTA_A函数中的溢出,该功能用于计算添加流动性时,该功能用于计算令牌a的三角洲。

This bug allowed the attacker to claim to be adding a huge amount of liquidity by displaying a nearly impossible price and submitting only 1 token, while the system expected 367506680905089974005506088888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888

该错误使攻击者声称通过显示几乎不可能的价格并仅提交1个令牌,而系统预计,该错误可以增加大量流动性。

免责声明:info@kdj.com

所提供的信息并非交易建议。根据本文提供的信息进行的任何投资,kdj.com不承担任何责任。加密货币具有高波动性,强烈建议您深入研究后,谨慎投资!

如您认为本网站上使用的内容侵犯了您的版权,请立即联系我们(info@kdj.com),我们将及时删除。

2025年06月02日 发表的其他文章