简析Velocore黑客攻击事件:损失688万美元ETH,用户流动性全归零

Odaily星球日报Published on 2024-06-03Last updated on 2024-06-03

Abstract

团队表示会对受影响人提供补偿,并快照了攻击事件发生前的区块状态。

原文作者:Ting

原文来源:动区动趋 BlockTempo

昨日,去中心化交易平台 Velocore 遭到黑客攻击,被窃取 1807 枚 ETH(约 688 万美元),事后 Velocore 公布报告,说明受影响的资金池、攻击手法以及后续的补偿计划。

部署在 Layer 2 网路 zkSync 及 Linea 上的去中心化交易平台 Velocore 在昨(2)日遭到骇客攻击,损失达 1807 枚 ETH(约 688 万美元)

链上分析师余烬表示,该平台上所有用户的流动性资金都被盗取,骇客随后将窃取的资金通过跨链桥转移至以太坊主网,并且将 ETH 全部转移到 0x e 40 地址,并利用混币器协议 Tornado 将资金隐匿洗出。

另外,根据 DeFi 数据平台 DefiLlama 的数据显示,Velocore 遭到骇客攻击后,其总锁定价值从前一日的 1, 016 万美元暴跌至 83.5 万美元,下跌幅度高达 92% 。

简析Velocore黑客攻击事件:损失688万美元ETH,用户流动性全归零

合约漏洞导致

昨日,Velocore 团队针对本次骇客攻击事件发布了一份安全检讨报告。报告中指出,攻击的原因是 Balancer-style CPMM 池存在合约漏洞。报告详细列出了各个资金池的安全状况:

  • Linea 和 zkSync Era 链上的 Velocore 中所有 CPMM 池均受到影响。

  • 稳定池(stable pool)未受影响。

  • Telos 链上的 Velocore 也存在同样的问题,但团队已经在问题被利用前进行了处理。

  • Blast 链上的 Bladeswap 虽使用 Velocore 的核心合约,但由于 Bladeswap 采用的是 XYK 池而非 CPMM 池,故未受此次合约漏洞的影响。

    恒定乘积做市商 CPMM 是 DeFi 流动性矿池早期采用的函数之一,函式算法:x*y=k。其中 x 和 y 是池中资产的储存量,k 是一个不变的常数,该函式根据每个代币的可用数量 ( 流动性 ) 确定两种代币的价格范围,这代表著代币 X 的供应量增加,则代币 Y 的供应量减少以保持恒定值 k。

    又是闪电贷攻击?

    根据报告显示,攻击者先从混币器协议 Tornado 获取资金,并将合约漏洞触发条件满足,接者利用闪电贷款获取流动性提供者(LP)代币,并提取了大部分代币,使流动性池的规模大幅缩小。随后,攻击者利用代币合约漏洞铸造了异常大量的 LP 代币,从而偿还了闪电贷款。

    恢复运营才补偿用户

    针对本次黑客攻击,Velocore 团队表示正在积极追查骇客,同时也尝试和黑客进行链上协商,Velocore 在链上向和黑客沟通讯息显示:

    若黑客在 6 月 3 日下午 4 点钱归还剩余资金,团队愿意提供 10 % 的白帽骇客赏金

    不过目前黑客尚未对 Velocore 做出回应。

    另一方面,团队还表示会对受影响人提供补偿,并快照了攻击事件发生前的区块状态,只不过补偿计划需要等待 Velocore 恢复运营后才会著手执行。

    Trending Cryptos

    Related Reads

    When Billions Begin to Operate Everything by Voice, How Far is ‘All Assets on Chain’?

    In June 2026, WeChat began a limited rollout of "Xiaowei," its native AI assistant. This move is more than an upgrade to a smarter chatbot; it signals a crucial step from "universal internet access" toward the broader vision of "full asset tokenization." Xiaowei, powered primarily by WeChat's in-house WeLM model, demonstrates four key capabilities: 1) direct voice/web chat control of app functions, 2) automated access to mini-programs for services, 3) instant comprehension and summarization of complex documents like PDFs, and 4) generating functional mini-program prototypes from simple natural language requests. This represents a fundamental shift from GUI (Graphical User Interface) to LUI (Language User Interface), eliminating friction in human-digital interaction. The rollout is pivotal because it brings AI Agents to China's massive user base with zero friction—no new app downloads or accounts needed. This "seamless access" mirrors past platform revolutions like the App Store or WeChat Mini-Programs, potentially unlocking a global AI Agent market projected to grow from $7.92 billion in 2025 to nearly $295 billion by 2035. The article argues that China's internet evolution has moved from "connecting everyone" to "putting all services online." The next phase is "tokenizing all assets"—a concept broader than just Real World Assets (RWA) like real estate. It encompasses tokenizing personal assets like social influence, attention, and credit history. RWA tokenization itself is forecast to explode from $35 billion in 2025 to over $500 billion in 2026. The convergence of ubiquitous AI Agents and rapidly tokenizing assets points to a future paradigm for wealth management. Your AI Agent could autonomously manage a globally diversified, tokenized portfolio based on your preferences. Initiatives like EXIO Group's full-stack RWA services aim to lower investment barriers, paralleling WeChat's democratization of AI access. In conclusion, the launch of Xiaowei is not merely a technical upgrade but a historic inflection point. It marks AI Agents' transition from niche tools to essential utilities and accelerates the movement toward a future where voice commands seamlessly interact with tokenized value, redefining humanity's relationship with the digital and financial worlds.

    marsbit6m ago

    When Billions Begin to Operate Everything by Voice, How Far is ‘All Assets on Chain’?

    marsbit6m ago

    SoftBank CEO Masayoshi Son's New Trillion-Dollar "Gamble"

    SoftBank founder Masayoshi Son is embroiled in a new trillion-dollar "bet" on Physical AI and humanoid robotics, even as his massive wager on OpenAI faces uncertainty ahead of its potential IPO. Recent reports reveal OpenAI's steep losses—$85 billion net loss by Q1 2026 and a $38.5 billion loss in 2025—casting doubt on its path to a trillion-dollar valuation. SoftBank, OpenAI's second-largest external shareholder with a planned 13% stake, stands to gain hugely if OpenAI succeeds. Undeterred, Son is already pushing forward with his next ambitious venture: consolidating SoftBank's AI and robotics assets into a new U.S.-based company named "Roze," targeting a $100 billion IPO as early as late 2026. This move aligns with his belief that Physical AI, merging AI cognition with robotic physical execution, is the next trillion-dollar frontier. Son's confidence stems from recent AI wins; SoftBank's stock surged and he briefly regained the title of Asia's richest person, largely due to OpenAI's soaring valuation. However, his aggressive strategy has raised internal concerns about over-reliance on OpenAI and strained finances. With competitors like Anthropic advancing rapidly and OpenAI's IPO timing uncertain, Son is racing to capitalize on the AI boom. His long-term vision for Physical AI includes a decade of investments in robotics, from Boston Dynamics to recent acquisitions like ABB's robotics unit, and a planned $1 trillion investment in U.S.-based AI robotics industrial parks. Yet, challenges remain: humanoid robotics firms like Figure AI lack the clear revenue paths of AI software companies, and Roze's lofty valuation faces skepticism. For Son, these bets are also driven by an unfulfilled promise of massive returns to key investors like Saudi Arabia's PIF. Despite risks, he continues to double down, betting that the fusion of AI and physical machines will define the next technological era.

    marsbit13m ago

    SoftBank CEO Masayoshi Son's New Trillion-Dollar "Gamble"

    marsbit13m ago

    Trading

    Spot
    Futures

    Hot Articles

    Discussions

    Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of ETH (ETH) are presented below.

    活动图片