简析Velocore黑客攻击事件:损失688万美元ETH,用户流动性全归零

Odaily星球日报Published on 2024-06-03Last updated on 2024-06-03

Abstract

团队表示会对受影响人提供补偿,并快照了攻击事件发生前的区块状态。

原文作者:Ting

原文来源:动区动趋 BlockTempo

昨日,去中心化交易平台 Velocore 遭到黑客攻击,被窃取 1807 枚 ETH(约 688 万美元),事后 Velocore 公布报告,说明受影响的资金池、攻击手法以及后续的补偿计划。

部署在 Layer 2 网路 zkSync 及 Linea 上的去中心化交易平台 Velocore 在昨(2)日遭到骇客攻击,损失达 1807 枚 ETH(约 688 万美元)

链上分析师余烬表示,该平台上所有用户的流动性资金都被盗取,骇客随后将窃取的资金通过跨链桥转移至以太坊主网,并且将 ETH 全部转移到 0x e 40 地址,并利用混币器协议 Tornado 将资金隐匿洗出。

另外,根据 DeFi 数据平台 DefiLlama 的数据显示,Velocore 遭到骇客攻击后,其总锁定价值从前一日的 1, 016 万美元暴跌至 83.5 万美元,下跌幅度高达 92% 。

简析Velocore黑客攻击事件:损失688万美元ETH,用户流动性全归零

合约漏洞导致

昨日,Velocore 团队针对本次骇客攻击事件发布了一份安全检讨报告。报告中指出,攻击的原因是 Balancer-style CPMM 池存在合约漏洞。报告详细列出了各个资金池的安全状况:

  • Linea 和 zkSync Era 链上的 Velocore 中所有 CPMM 池均受到影响。

  • 稳定池(stable pool)未受影响。

  • Telos 链上的 Velocore 也存在同样的问题,但团队已经在问题被利用前进行了处理。

  • Blast 链上的 Bladeswap 虽使用 Velocore 的核心合约,但由于 Bladeswap 采用的是 XYK 池而非 CPMM 池,故未受此次合约漏洞的影响。

    恒定乘积做市商 CPMM 是 DeFi 流动性矿池早期采用的函数之一,函式算法:x*y=k。其中 x 和 y 是池中资产的储存量,k 是一个不变的常数,该函式根据每个代币的可用数量 ( 流动性 ) 确定两种代币的价格范围,这代表著代币 X 的供应量增加,则代币 Y 的供应量减少以保持恒定值 k。

    又是闪电贷攻击?

    根据报告显示,攻击者先从混币器协议 Tornado 获取资金,并将合约漏洞触发条件满足,接者利用闪电贷款获取流动性提供者(LP)代币,并提取了大部分代币,使流动性池的规模大幅缩小。随后,攻击者利用代币合约漏洞铸造了异常大量的 LP 代币,从而偿还了闪电贷款。

    恢复运营才补偿用户

    针对本次黑客攻击,Velocore 团队表示正在积极追查骇客,同时也尝试和黑客进行链上协商,Velocore 在链上向和黑客沟通讯息显示:

    若黑客在 6 月 3 日下午 4 点钱归还剩余资金,团队愿意提供 10 % 的白帽骇客赏金

    不过目前黑客尚未对 Velocore 做出回应。

    另一方面,团队还表示会对受影响人提供补偿,并快照了攻击事件发生前的区块状态,只不过补偿计划需要等待 Velocore 恢复运营后才会著手执行。

    Trending Cryptos

    Related Reads

    Without It, There Would Be No ImageNet... Now It's Gone

    Amazon is shutting down its crowdsourcing platform, Mechanical Turk (MTurk), on September 30th, ending a 21-year run. Launched in 2005, MTurk connected businesses with a global online workforce to perform small, repetitive tasks—known as Human Intelligence Tasks (HITs)—that were easy for humans but difficult for computers at the time. At its peak, it hosted over 500,000 workers worldwide. MTurk played a pivotal, though often unseen, role in the rise of modern AI. Its most famous contribution was to the creation of the ImageNet dataset. In the late 2000s, researcher Fei-Fei Li and her team faced the monumental challenge of manually sorting and labeling millions of internet images to build a large-scale visual database for training AI. They turned to MTurk, distributing the work to nearly 50,000 workers from 167 countries. This "human-in-the-loop" effort made the massive ImageNet project feasible. ImageNet, in turn, became the foundational benchmark for the 2012 ImageNet Large Scale Visual Recognition Challenge. The victory of Geoffrey Hinton and his students' deep convolutional neural network, AlexNet, on this dataset dramatically demonstrated the power of deep learning, catalyzing the AI revolution that followed. Now, MTurk is closing. The platform has declined as the very AI it helped build has become capable of automating the simple tasks it once provided. Furthermore, the AI industry's data needs have evolved, shifting towards more specialized expertise for model tuning and evaluation, served by newer platforms. Ironically, some studies suggest MTurk workers themselves began using AI tools like ChatGPT to complete tasks, adding a layer of automation to the "artificial artificial intelligence" service. The shutdown marks the end of an era where human effort, distributed globally via the internet, laid the crucial groundwork for the intelligent machines of today.

    marsbit12m ago

    Without It, There Would Be No ImageNet... Now It's Gone

    marsbit12m ago

    Bill Gates' Latest Long-Form Article: The Real Trouble with AI is That We Aren't Ready

    Bill Gates' latest essay, "The turbulent AI era is here. The choices we make now are critical," warns that society is unprepared for the profound social and economic transition AI will bring. While optimistic about AI's long-term potential in healthcare, education, and other fields, Gates focuses on the "transition period" over the next 10-20 years. He argues this transition differs from past technological shifts like the Industrial Revolution because AI automates cognitive labor itself, potentially reducing the total number of future jobs. Risks like enhanced cyber-attacks and social disruption are already emerging, not distant future threats. A key concern is "low-cost intelligence substitution," where AI performs defined tasks cheaper than humans, gradually thinning workforces. Gates introduces the concept of "Human Reserved" jobs—roles like nursing or delivering serious medical news—where human judgment and empathy should remain central, even if AI is technically capable. To manage the transition, he calls for new governance, stronger social safety nets, retraining, and international cooperation, especially between the US and China. Crucially, he proposes taxing AI usage and robots to slow displacement and fund social programs. The core dilemma Gates presents is that AI could become humanity's "greatest equalizer" or its "worst source of injustice," depending on whether its immense productivity gains are broadly shared or concentrate wealth and power. The fundamental challenge is not just advancing the technology, but adapting our social and economic systems to it.

    marsbit28m ago

    Bill Gates' Latest Long-Form Article: The Real Trouble with AI is That We Aren't Ready

    marsbit28m ago

    Just Now, Anthropic Unveils Physical MCP: Claude Begins Controlling the Real World

    Anthropic has announced the Model Hardware Standard (MHS), a new standard enabling AI agents like Claude to safely control physical devices. Building on the Model Context Protocol (MCP), MHS standardizes communication between AI agents and hardware such as microscopes, robotic arms, and lasers, marking a significant step for AI from the digital into the physical world. Developed in collaboration with HHMI Janelia Research Campus, MHS uses standardized drivers to translate basic commands (e.g., read, write) into a format any programmable device can understand. This drastically reduces integration time from weeks to hours or minutes and allows agents to discover and operate new devices using natural language tags that describe machine properties and safety limits. Agents can control devices via MCP, command-line interfaces, or APIs. They can sequence operations, monitor results, adjust parameters in real-time, and generate deterministic scripts for long-running tasks. Early tests show Claude interacting with hardware exploratively, like a scientist, learning to calibrate a laser and scripting the process. Early adopters and partners include AWS, Automata, Danaher, Doosan Robotics, and Tecan, who are integrating MHS support into their platforms. While promising, challenges remain: Claude's physical reasoning is limited, requiring expert oversight, and MHS currently only works with programmable hardware. Anthropic plans further refinements and broader device support before open-sourcing the standard.

    marsbit1h ago

    Just Now, Anthropic Unveils Physical MCP: Claude Begins Controlling the Real World

    marsbit1h ago

    History's Only Asset with a 100% Win Rate After 4 Years of Holding

    **Title: The Only Asset with a 100% Win Rate Over Any 4-Year Holding Period** This article analyzes which major, freely-tradable assets have historically never produced a nominal loss over any rolling 4-year holding window. It concludes that only two distinct categories achieve this: ultra-low-risk contractual assets and Bitcoin. Among traditional risk assets, none maintain a perfect 4-year record. The S&P 500 had negative 4-year periods (e.g., 1929-1932: -64.8%). The Nasdaq 100 fell roughly 60% from 2000-2003. Gold saw a ~47.7% loss from 1981-1984. US real estate declined about 23.3% from 2007-2010. Even long-term US Treasury bonds (e.g., 2021-2024: -19.8%) and corporate bonds can produce 4-year losses due to interest rate and market price risks. In contrast, the first category achieving 100% nominal success includes assets like rolling 3-month US Treasury Bills, 4-year certificates of deposit (CDs), and US Treasuries held to maturity within 4 years. Their "guarantee" stems from contractual obligations and credit backing (e.g., FDIC insurance, US sovereign promise), not price appreciation. The sole exception in the high-risk category is Bitcoin. Analysis of daily data from 2010-2026 across 4,419 rolling 4-year windows shows a 100% positive return rate. The worst 4-year period (April 2021 to April 2025) still yielded a +32.6% total return (~7.3% CAGR). This record is unique because Bitcoin has no issuer, promises no cash flows, and has endured severe drawdowns (70-90%), yet its market price has always recovered within a 4-year span. The key distinction is the source of the "100%": contractual assets offer known, low nominal returns, while Bitcoin's record stems purely from historical price appreciation despite extreme volatility. The article suggests that for Bitcoin, the ability to hold for 4+ years is more critical than active trading strategies.

    marsbit1h ago

    History's Only Asset with a 100% Win Rate After 4 Years of Holding

    marsbit1h ago

    How One Article Moved 45 Billion: The Collapse of a 25-Year-Old 'AI Stock Guru'

    This article details the dramatic rise and near-collapse of a hedge fund built by Leopold Aschenbrenner, a 24-year-old former OpenAI researcher. The fund, named Situational Awareness, amassed $45 billion in assets within two years. Its explosive growth stemmed from Aschenbrenner's influential 165-page manifesto predicting AGI's arrival by 2027 and his high-profile Silicon Valley connections. The fund employed an extremely aggressive strategy: high concentration and 400% leverage to bet long on AI infrastructure stocks while shorting legacy software firms. In July, this structure backfired when both sides of the trade reversed simultaneously—AI stocks plunged while shorted stocks rallied—triggering massive losses that nearly wiped out all equity. Major player Jane Street reportedly lost billions. The fund's leveraged public portfolio was ultimately sold at a discount to Citadel. The SEC is now investigating banks like Goldman Sachs for their role in facilitating the fund's high-leverage trades. The article compares this to past blow-ups like Archegos, highlighting systemic failures in risk management where the pursuit of short-term profits overrode due diligence. It questions whether such risky leverage concentrated in the AI sector, currently at record highs, poses a broader systemic threat. Ironically, Aschenbrenner, who studied AI safety at OpenAI, designed a fund structure prone to uncontrolled failure. Days after the crisis, he reportedly raised another $400 million for new investments.

    marsbit1h ago

    How One Article Moved 45 Billion: The Collapse of a 25-Year-Old 'AI Stock Guru'

    marsbit1h ago

    Trading

    Spot

    Hot Articles

    Discussions

    Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of ETH (ETH) are presented below.

    活动图片