除了“被反撸”,空投猎人更需警觉安全问题

PanewsPublished on 2023-10-25Last updated on 2023-10-25

Abstract

这次比特浏览器的黑客攻击事件是一个警钟,提醒所有涉足加密货币的个人和机构,特别是管理众多帐户地址的空投猎人或工作室,必须更加严格地注意自己的资讯安全和私钥管理。

出品:DODOResearch
作者:dt
编辑:Lisa
上周发生一起黑客攻击事件,比特浏览器的许多用户于社群反应其私钥被盗,有猜测称该情况因使用比特指纹浏览器所致,开启了扩展数据同步的用户钱包有被盗风险,建议立即采取措施,转走钱包资产。比特浏览器是一款多账户管理工具,允许用户轻易建立多个 IP 的浏览器视窗分页。
目前单一用户最高被盗资产高达 6 万美金,并有超过 3,000 个钱包遭到资产损失,总损失高达 41 万美元。比特浏览器官方表示目前比特服务端缓存数据遭到黑客入侵导致用户的私钥外泄和资产被不法转移,已经报案,并联系 MetaMask 冻结黑客钱包。然而,由于缺乏透明度和即时的危机处理,部分用户对其采取的措施表示质疑和不信任。
而根据昨日 8/29 最新消息,慢雾首席信息安全官 23pds 在推特上表示:“关于比特浏览器大量用户被盗的情况,目前我们已经联合合作伙伴成功拦截了一部分在洗的资金。比特浏览器正在立案,立案成功慢雾会正式介入。”
指纹浏览器与空投猎人
对于空投猎人来说,如何防止多账号关联一直是重点研究的一件事,除了最基础的隔离链上地址之间的关联外,IP 隔离也是很多人在意的点,而指纹浏览器便是为了这需求诞生的产品。指纹浏览器可以模拟不同的浏览器指纹,防止账号关联和被封禁,这对于多账户操作如跨境电商、社交媒体、广告投放等业务来说相当有用。
浏览器与钱包安全问题
但同时需要注意的是,无论是比特浏览器还是其他第三方修改的浏览器,或是其他类似的多账户管理工具,用户都需要高度警觉以下几个安全问题:

  • 浏览器或插件本身的安全性:由于此类型为了特殊需求衍生的浏览器大多在 Chrome 核心基础上修改,但在版本更新上可能因此会无法第一时间便更新至最新版本,以至于黑客能利用和新版本与第三方版本不同步的更新时差,在这段时间内找出漏洞攻击。因此,用户应选择信誉良好和安全性高的工具,并定期更新到最新版本。
  • 用户自身的操作安全:私钥管理是大多是加密货币使用第一堂便需要学习的课程,但久而久之有许多用户因为被黑这件事自己从未遇过便忽视了其重要性,私钥是必须备份且绝对不建议联网储存的或与他人分享的,尽管许多平台皆保证皆会加密处理,但将自己财务风险暴露在其他人的软件上,仍不是个明智之举。
  • 与第三方服务的互动:在链上与 Dapps 互动时需特别注意,是否为官方管道避免被仿冒的钓鱼网站骗走资产,而在与新协议互动式需要花费更多的时间来确保此项目是否有人背书或是团队是否正规,切勿一股脑上头便急忙的操作。


笔者观点
这次比特浏览器的黑客攻击事件是一个警钟,提醒所有涉足加密货币的个人和机构,特别是管理众多帐户地址的空投猎人或工作室,必须更加严格地注意自己的资讯安全和私钥管理,在这类型的第三方服务器下最好是使用无私钥的 AA 钱包,或是使用 wallet connect / coinbase wallet 等利用手机扫码操作的钱包,避免私钥直接曝露在第三方公司运营的平台上。
从比特浏览器官方的回应便可以知晓其团队对于区块链安全的了解有待提高,竟表示联系 MetaMask 冻结黑客钱包令人啼笑皆非。当资料泄漏一事发生在其他 Web2 使用者占多数的平台可能后果不是如此巨大,但当你的使用者大多是 Web3 用户时便不是这么一回事了。而对于用户来说只有建立全面的安全机制和紧急应对计划,才能在这个高风险但高报酬的领域中长期生存,毕竟为了空投奖励而损失本金便有些本末倒置了。

Related Reads

Bitcoin's 'Rally Ends,' Officially Entering the Later Stage of a Bear Market?

Bitcoin prices declined 13% this week, reversing the recent rebound and signaling a likely transition into the later stages of a bear market. Key on-chain metrics deteriorated, with the short-term holder cost basis falling below the Realized Price—a pattern last seen in early 2022, characteristic of bear market maturity. The rally to ~$82k proved to be a bear market bounce, as evidenced by the 90-day realized profit/loss ratio failing to sustain above the bullish threshold of 2. Daily realized losses surged to $1.35B, including significant selling from long-term holders who accumulated near cycle tops, indicating ongoing supply redistribution. Price was rejected almost precisely at the aggregate US spot ETF cost basis of ~$83k, turning that level into resistance and leaving the average ETF investor underwater again. Spot market selling pressure intensified, with the 7-day volume delta turning significantly negative to its weakest level since February. While a major long liquidation event cleared over $400M in leverage, spot demand has not yet stepped in to absorb the resulting supply. Options markets continue pricing in higher future volatility (elevated volatility risk premium) and maintain a skew toward put options, reflecting persistent demand for downside protection, though not yet panic. Overall, market structure remains fragile. Sustained recovery likely requires a reclaim of the ETF cost basis, a shift back to positive spot demand, and a slowdown in realized loss-taking. Until then, the market risks further downside or extended consolidation within the broader bear trend.

Foresight News1h ago

Bitcoin's 'Rally Ends,' Officially Entering the Later Stage of a Bear Market?

Foresight News1h ago

How Risky is the "Death Spiral" of MSTR and STRC?

Summary: This article explores the perceived "death spiral" risk between MicroStrategy (MSTR), its Bitcoin holdings, and its perpetual preferred stock (STRC), drawing comparisons to the LUNA-UST collapse. While both systems feature price anchors, high yields for holders, and potential feedback loops, their core mechanisms differ fundamentally. The MSTR-STRC structure relies on continuous financing to sustain its high dividend payouts, primarily through stock ATM offerings. A negative feedback cycle could occur: falling MSTR stock price makes raising equity capital harder, increasing pressure to sell Bitcoin, which undermines STRC confidence and further depresses MSTR. However, unlike LUNA-UST's automated, direct linkage, the MSTR-STRC loop is weaker and has brakes: STRC dividends can be deferred or rates lowered, and STRC holders have a $100/share liquidation preference in bankruptcy, providing a price floor. The company's sustainability hinges on its ability to continue financing. Its current ~$900 million USD reserves cover only about 6.3 months of its ~$1.71 billion annual interest/dividend burden. The next six months are critical, aligning with both the potential bottom in Bitcoin's four-year cycle and the depletion timeline of its reserves. While a LUNA-style catastrophic collapse is deemed highly unlikely due to structural differences, the key question is whether MicroStrategy can navigate this period through healthy deleveraging to restart its capital engine.

Foresight News1h ago

How Risky is the "Death Spiral" of MSTR and STRC?

Foresight News1h ago

Trading

Spot
Futures

Hot Articles

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of ETH (ETH) are presented below.

活动图片